Attribute-based access control methods, devices, electronic devices, and storage media

By setting policy identifiers in the extended domain of digital certificates and generating real-time identity authentication policies, the security risks and operational costs caused by fixed-strength verification processes are resolved. This enables dynamic adjustment of authentication policies based on business scenarios, meeting access security control requirements.

CN120301712BActive Publication Date: 2025-10-31CHINA FINANCIAL CERTIFICATION AUTHORITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510779548.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-12
Publication Date
2025-10-31
Estimated Expiration
2045-06-12

AI Technical Summary

Technical Problem

In existing access control methods based on digital certificates, the fixed-strength identity verification process cannot automatically adjust the verification strength according to the risk level of the business scenario. This results in low-level security policies leading to low verification strength in high-risk scenarios, posing security risks, or high-level security policy verification processes being enforced in low-risk scenarios, increasing operating costs.

Method used

Set a policy identifier in the extended domain of the digital certificate. The policy identifier, subject attribute, object attribute and environment attribute in the certificate are parsed by the attribute-based access control system engine to generate a real-time identity authentication policy. The policy is then compared with the digital policy required by the business and an access control decision is output.

Benefits of technology

It enables dynamic adjustment of authentication policies based on business scenarios, meets access security control requirements, avoids increased security risks and operating costs, and ensures the authenticity of the certificate holder's identity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301712B_ABST
    Figure CN120301712B_ABST
Patent Text Reader

Abstract

This invention provides an attribute-based access control method, apparatus, electronic device, and storage medium, relating to the field of computer network security technology. By setting a policy identifier in the extended domain of a digital certificate, when a subject initiates an access request, the digital certificate carried in the access request is input into an attribute-based access control system engine. The attribute-based access control system engine parses the digital certificate, obtains the policy identifier from the digital certificate, and the subject attributes, object attributes, and environment attributes related to the current access request, generating a real-time identity authentication policy. The real-time identity authentication policy is compared with the digital policy corresponding to the parsed policy identifier, which corresponds to the business requirements. Based on the comparison result, an access control decision is output. This invention, by identifying the policy identifier, can match the policy to the business requirements and verify whether the current authentication policy is appropriate, thereby enabling the selection of different authentication policies under the same digital identity to meet access security control requirements.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer network security technology, and in particular to an attribute-based access control method, apparatus, electronic device, and storage medium. Background Technology

[0002] Currently, Attribute Based Access Control (ABAC) technology is mainly applied in emerging computing environments such as cloud computing and the Internet of Things (IoT) to address access control issues in large-scale, highly dynamic, and privacy-sensitive environments. Access control relies on digital certificate authentication; however, existing digital certificate application solutions lack tiered management of identity verification before certificate issuance, failing to meet the differentiated needs of complex business scenarios. For example, in a lending system, the required authentication strength differs between querying repayment records and signing loan contracts. Querying repayment records only requires basic real-name authentication (such as verifying name and ID number), while signing loan contracts requires high-strength verification of the subject's liveness, status, and bank card information before issuance. A fixed-strength identity verification process cannot automatically adjust the verification strength according to the risk level of the business scenario. This can lead to low-level security policies in high-risk scenarios resulting in low verification strength and security risks, or force high-level security policies in low-risk scenarios, increasing operational costs. Summary of the Invention

[0003] This invention provides an attribute-based access control method, apparatus, electronic device, and storage medium to address the shortcomings of traditional digital certificate-based access security control methods, which employ fixed-strength identity verification processes that may pose security risks or increase operating costs.

[0004] This invention provides an attribute-based access control method, comprising:

[0005] Set a policy identifier in the extended field of the digital certificate, the policy identifier being used to identify the digital policy required by the business;

[0006] When a subject initiates an access request, the digital certificate carried in the access request is input into the attribute-based access control system engine. The attribute-based access control system engine parses the digital certificate, obtains the policy identifier in the digital certificate, as well as the subject attributes, object attributes, and environment attributes related to this access request, and generates a real-time identity authentication policy based on the subject attributes, object attributes, and environment attributes.

[0007] The real-time identity authentication policy is compared with the digital policy of the business requirements corresponding to the parsed policy identifier, and an access control decision is output based on the comparison result.

[0008] According to the attribute-based access control method provided by the present invention, the policy identifier is a string generated by structured encoding according to the identifier characteristics.

[0009] According to the attribute-based access control method provided by the present invention, the identification characteristics include:

[0010] Authentication strength, wherein the authentication strength level is used to identify the strength of the identity authentication associated with the digital certificate;

[0011] The identity authentication type is used to identify the identity authentication type associated with the digital certificate. The identity authentication type corresponds to the authentication validity period. When there are multiple identity authentication types, each identity authentication type corresponds to an authentication validity period.

[0012] The authentication validity period rule is used to identify the validity period information of the identity authentication associated with the digital certificate. The identity authentication validity period information includes the authentication validity period value and the authentication validity period unit.

[0013] According to the attribute-based access control method provided by the present invention, the step of inputting the digital certificate carried in the access request into the attribute-based access control system engine, wherein the attribute-based access control system engine parses the digital certificate to obtain the policy identifier in the digital certificate, as well as the subject attribute, object attribute, and environment attribute related to the current access request, including:

[0014] The attribute-based access control system engine parses the policy identifier field, subject field, and object field in the digital certificate carried in the access request to obtain the policy identifier in the policy identifier field, the subject attribute in the subject field, and the object attribute in the object field.

[0015] The attribute-based access control system engine obtains the environmental information of the access request and generates environmental attributes.

[0016] According to the attribute-based access control method provided by the present invention, the attribute-based access control system engine includes: an authorization component, an attribute providing component, and a policy management component;

[0017] The real-time identity authentication strategy generated based on the subject attribute, object attribute, and environmental attribute includes:

[0018] When a subject initiates an access request, the attribute providing component provides subject attributes, object attributes, and environment attributes. The policy management component generates a real-time identity authentication policy based on the subject attributes, object attributes, and environment attributes. The authorization component evaluates the real-time identity authentication policy and outputs an access control decision.

[0019] According to the attribute-based access control method provided by the present invention, the attribute providing component includes:

[0020] The attribute repository is used to store the collections of subject attributes and the collections of object attributes;

[0021] Attribute information provider: used to retrieve the subject attribute set and object attribute set based on the subject field and object field in the digital certificate, determine the attribute information of the subject executing the access request and the accessed object in the workflow process, and generate environment attributes based on the environment information of the access request;

[0022] The policy management component includes: a policy management point and a policy repository;

[0023] The policy management point is used to create, manage, test, and debug real-time identity authentication policies, and to store the debugged real-time identity authentication policies in the policy repository.

[0024] According to the attribute-based access control method provided by the present invention, the authorization component includes: a policy decision point and a policy enforcement point;

[0025] The policy decision point is used to evaluate the real-time identity authentication policy, mediate policy conflicts, and generate application control decisions.

[0026] The policy execution point is used to execute the application control decision generated by the policy decision point, respond to the access request, and output whether to allow or deny the access request.

[0027] The present invention also provides an attribute-based access control device, comprising:

[0028] The configuration module is used to set a policy identifier in the extended field of the digital certificate, wherein the policy identifier is used to identify the digital policy required by the business.

[0029] The generation module is used to input the digital certificate carried in the access request into the attribute-based access control system engine when the subject initiates an access request. The attribute-based access control system engine parses the digital certificate, obtains the policy identifier in the digital certificate, as well as the subject attributes, object attributes and environment attributes related to this access request, and generates a real-time identity authentication policy based on the subject attributes, object attributes and environment attributes.

[0030] The output module is used to compare the real-time identity authentication policy with the digital policy of the business requirements corresponding to the parsed policy identifier, and output an access control decision based on the comparison result.

[0031] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, implements the attribute-based access control method as described in any of the preceding claims.

[0032] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the attribute-based access control method described in any of the preceding claims.

[0033] The present invention provides an attribute-based access control method, apparatus, electronic device, and storage medium. By setting a policy identifier in the extended domain of a digital certificate, the policy identifier identifies the digital policy required by the business. When a subject initiates an access request, the digital certificate carried in the access request is input into an attribute-based access control system engine. The attribute-based access control system engine parses the digital certificate, obtains the policy identifier in the digital certificate, and the subject attributes, object attributes, and environment attributes related to the current access request, and generates a real-time identity authentication policy based on the subject attributes, object attributes, and environment attributes. The real-time identity authentication policy is compared with the digital policy required by the business corresponding to the parsed policy identifier, and an access control decision is output based on the comparison result. During certificate use, by identifying the policy identifier, the policy required by the business can be matched, and the appropriateness of the current authentication policy can be verified, thereby enabling the selection of different authentication policies under the same digital identity to meet access security control requirements. Attached Figure Description

[0034] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0035] Figure 1 This is a flowchart of an attribute-based access control method provided in an embodiment of the present invention;

[0036] Figure 2 This is a schematic diagram of the certificate application model based on attribute management access control provided in an embodiment of the present invention;

[0037] Figure 3 This is a schematic diagram illustrating an application model example provided in an embodiment of the present invention;

[0038] Figure 4 This is a schematic diagram of the architecture of the attribute-based access control system engine provided in an embodiment of the present invention;

[0039] Figure 5 This is a flowchart of the digital certificate generation method provided in an embodiment of the present invention;

[0040] Figure 6 This is a flowchart of a digital certificate application process with embedded policy identifiers provided in an embodiment of the present invention;

[0041] Figure 7 This is a schematic diagram of the functional structure of an attribute-based access control device provided in an embodiment of the present invention;

[0042] Figure 8 This is a functional structure diagram of the electronic device provided in an embodiment of the present invention. Detailed Implementation

[0043] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0044] Figure 1 A flowchart of an attribute-based access control method provided in an embodiment of the present invention is shown below. Figure 1 As shown, the attribute-based access control method provided in this embodiment of the invention includes:

[0045] Step 101: Set a policy identifier in the extended field of the digital certificate. The policy identifier is used to identify the digital policy required by the business.

[0046] Step 102: When a subject initiates an access request, the digital certificate carried in the access request is input into the attribute-based access control system engine. The attribute-based access control system engine parses the digital certificate, obtains the policy identifier in the digital certificate, as well as the subject attributes, object attributes, and environment attributes related to this access request, and generates a real-time identity authentication policy based on the subject attributes, object attributes, and environment attributes.

[0047] Step 103: Compare the real-time identity authentication policy with the digital policy of the business requirements corresponding to the parsed policy identifier, and output the access control decision based on the comparison result.

[0048] In this embodiment of the invention, the real-time identity authentication policy is compared with the digital policy of the business requirements corresponding to the parsed policy identifier, and an access control decision is output based on the comparison result, including:

[0049] When the real-time identity authentication policy matches the digital policy of the business requirements corresponding to the parsed policy identifier, the access request of the subject is allowed. When the real-time identity authentication policy does not match the digital policy of the business requirements corresponding to the parsed policy identifier, the access request of the subject is denied. After denying the access request of the subject, the subject is reminded to upgrade the digital certificate so as to match the authentication policy applicable to the current access.

[0050] Traditional identity verification processes using fixed-strength authentication cannot automatically adjust the verification strength according to the risk level of the business scenario. This can lead to situations where low-level security strategies result in weak verification strength in high-risk scenarios, posing security risks. Conversely, forcing high-level security strategies into low-risk scenarios increases operational costs. Currently, there are no unified standards for classifying and grading digital certificates, nor are there specific requirements for the identity verification strength associated with issuing digital certificates for different business scenarios. For example, a bank's mobile banking app requires digital certificates for login, transfers, and loan contract signing. However, digital certificates can have different levels, and this level mainly depends on the strength of the verification of the certificate holder (e.g., an individual) before the digital certificate is issued. Existing digital certificates lack indicators of identity verification strength, making it impossible to obtain key information from the certificate to determine its authentication strength during the application process. For example, the required authentication strength differs between scenarios such as querying repayment records and signing loan contracts in a lending system. Querying repayment records only requires a basic real-name certificate (such as verifying the name and ID number), while the certificate used to sign loan contracts requires high-strength verification of the subject's liveness, survival status, bank card information, etc., before issuance.

[0051] The attribute-based access control method provided in this invention sets a policy identifier in the extended domain of a digital certificate. This policy identifier identifies the digital policy required by the business. When a subject initiates an access request, the digital certificate carried in the access request is input into an attribute-based access control system engine. The engine parses the digital certificate to obtain the policy identifier, as well as subject attributes, object attributes, and environment attributes related to the current access request. Based on these attributes, a real-time identity authentication policy is generated. This real-time identity authentication policy is compared with the digital policy required by the business corresponding to the parsed policy identifier. An access control decision is output based on the comparison result. By identifying the policy identifier during certificate use, the appropriateness of the current authentication policy can be verified, allowing different authentication policies to be selected under the same digital identity to meet access security control requirements.

[0052] Based on any of the above embodiments, the policy identifier is a string generated through structured encoding according to identifier characteristics. This policy identifier is managed by an organization with an electronic authentication service license issued by an authoritative body.

[0053] In this embodiment of the invention, the identification characteristics include:

[0054] Authentication strength, the authentication strength level is used to identify the identity authentication strength associated with the digital certificate; the strength is ranked from high to low as follows: A > B > C > D > E.

[0055] The identity authentication type is used to identify the identity authentication type associated with the digital certificate. The identity authentication type corresponds to the authentication validity period. When there are multiple identity authentication types, each identity authentication type corresponds to an authentication validity period.

[0056] Identity authentication types include, for example, ID card element authentication, bank card element authentication, and telecom operator element authentication.

[0057] The authentication validity period rule is used to identify the validity period information of the identity authentication associated with the digital certificate. This validity period information includes a numerical value and a unit of measurement for the authentication validity period. For example, the validity period information could be one year.

[0058] In this embodiment of the invention, the authentication policy identification rules and examples include:

[0059] Certification strength identifier | [{Certification type identifier 1, Certification validity value 1, Certification validity unit 1}, {Certification type identifier 2, Certification validity value 2, Certification validity unit 2}];

[0060] Example as follows:

[0061] A| [{idcard,1,year}, {bankcard,6,week}].

[0062] In this embodiment of the invention, a "policy identifier" is added to the extended field of the digital certificate. This identifier is used to mark the authentication strength of the digital certificate. During certificate use, the policy identifier is identified to match the digital policy required by the business and select a digital certificate that meets the policy under the same digital identity. For example, if a person has three digital certificates with different policy identifiers, we temporarily define three levels: Level A > Level B > Level C. Level A involves six verification methods before certificate issuance: mobile NFC reading of ID card information (verifying ID card authenticity), data source comparison (five elements: name, ID number, photo, ID card validity start date, ID card validity end date), identity status verification (verifying citizen's survival status), facial liveness recognition, and SMS verification. Level B involves three verification methods before certificate issuance: mobile NFC reading of ID card information (verifying ID card authenticity), facial liveness recognition, and SMS verification. Level C involves one verification method before certificate issuance: SMS verification. Level C certificates are used for login, Level B certificates for transfers, and Level C certificates for signing loan contracts.

[0063] In existing technologies, digital certificates only contain basic information identifying the user's identity, such as the applicant's identity information, name, ID number, and public key information. However, in this invention, binding the digital certificate to a policy identifier endows the digital certificate with new functional attributes. Therefore, this invention embodies an identity authentication strategy during the digital certificate application process.

[0064] Based on any of the above embodiments, the step of inputting the digital certificate carried in the access request into the attribute-based access control system engine (ABAC system engine), and the attribute-based access control system engine parsing the digital certificate to obtain the policy identifier in the digital certificate, as well as the subject attributes, object attributes, and environment attributes related to this access request, including:

[0065] The attribute-based access control system engine parses the policy identifier field, subject field, and object field in the digital certificate carried in the access request to obtain the policy identifier in the policy identifier field, the subject attribute in the subject field, and the object attribute in the object field.

[0066] The attribute-based access control system engine obtains the environmental information of the access request and generates environmental attributes.

[0067] In this embodiment of the invention, the attribute management access control model is as follows: Figure 2As shown, this is applied to certificate services, illustrating the relationships between subjects, objects, environments, and attributes in certificate applications. It focuses on managing the identity verification strategies used before certificate issuance and constructing a management process for classifying and grading digital certificate issuance. In the certificate application model based on attribute management access control, attributes refer to the named entity properties such as subjects, objects, operations (actions), and environments, including information given by name-value pairs.

[0068] Subject attributes refer to the attributes possessed by the entity that actively initiates the digital certificate application request. For example, if a company uses a digital certificate to log in to a bank's online banking system, then this company entity is the subject, and the company's name, unified social credit code, legal person name, registered address, etc. are all subject attributes.

[0069] Object attributes refer to the attributes possessed by the entity that is accessed and uses digital certificate technology. For example, as an object accessed by an enterprise, the object attributes of a bank's online banking system include the bank to which the system belongs, the full name of the system, the system domain name, the server IP address, and the filing number of the telecommunications and information service business operation license.

[0070] Environmental attributes refer to entity attributes that can exist independently of the subject and object, such as the time when the subject requests the object, the name of the digital certificate issuing authority, and the key algorithm used by the digital certificate.

[0071] Authentication policy: refers to the strategy for setting the identity verification method and identity authentication strength for issuing digital certificates based on specific business rules. The management right of the authentication policy is held by the system owner.

[0072] Operation: An executable image of a program that performs certain functions for the main body when invoked.

[0073] A subject initiates an access request (including a certificate application request) to an object. Upon receiving the request, the object first uses the ABAC system engine to parse the policy identifier in the digital certificate and obtain information such as subject attributes, object attributes, and environment attributes related to the request. The ABAC system engine then determines whether the request meets the authentication policy requirements. If the authentication policy requirements are met, the request is allowed to proceed. If the authentication policy requirements are not met, the request is rejected.

[0074] The system owner has the authority to set the authentication policy and maintain the ABAC system engine. The system owner can initialize the authentication policy according to their own business needs.

[0075] A bank's application model for querying personal credit reports, such as Figure 3As shown, the bank sets up an authentication policy in its electronic credit report inquiry system, requiring the inquirer to use a digital certificate for authentication, and to undergo triple authentication: two-factor authentication of the ID card, facial recognition, and SMS verification code verification. After an individual initiates an electronic credit report inquiry request to the bank system, the system parses the policy identifier in the individual's digital certificate to determine whether the individual performed the required authentication strength before obtaining the digital certificate. If the individual's digital certificate meets the authentication policy requirements, the system allows the individual to inquire about the electronic credit report; otherwise, the system refuses the inquiry.

[0076] In this embodiment of the invention, the attribute-based access control system engine, such as Figure 4 As shown, it includes: an authorization component, an attribute provisioning component, and a policy management component;

[0077] The real-time identity authentication strategy generated based on the subject attribute, object attribute, and environmental attribute includes:

[0078] When a subject initiates an access request, the attribute providing component provides subject attributes, object attributes, and environment attributes. The policy management component generates a real-time identity authentication policy based on the subject attributes, object attributes, and environment attributes. The authorization component evaluates the real-time identity authentication policy and outputs an access control decision.

[0079] In this embodiment of the invention, the attribute providing component includes:

[0080] The attribute repository is used to store the collections of subject attributes and the collections of object attributes;

[0081] Attribute information provider: used to retrieve the subject attribute set and object attribute set based on the subject field and object field in the digital certificate, determine the attribute information of the subject executing the access request and the accessed object in the workflow process, and generate environment attributes based on the environment information of the access request;

[0082] One of the tasks of the attribute providing component is to ensure the accuracy and consistency of attributes. When the lifecycle state of the subject or object changes or the entity characteristics change, the attribute providing component is responsible for timely updates.

[0083] The policy management component includes: a policy management point and a policy repository;

[0084] The policy management point is used to create, manage, test, and debug real-time identity authentication policies, and to store the debugged real-time identity authentication policies in the policy repository.

[0085] The policy management component is responsible for providing capabilities such as policy management, storage, verification, updating, prioritization, conflict resolution, sharing, policy decommissioning, and execution.

[0086] The authorization components include: policy decision points and policy execution points;

[0087] The policy decision point is used to evaluate the real-time identity authentication policy, mediate policy conflicts, and generate application control decisions.

[0088] The policy execution point is used to execute the application control decision generated by the policy decision point, respond to the access request, and output whether to allow or deny the access request. The policy repository is responsible for storing ABAC rules, policies, and policy sets.

[0089] The authorization component evaluates the digital policy, combines various elements in ABAC, generates an application control policy, and executes it.

[0090] This invention applies the ABAC model to digital certificate services, promoting effective risk management on the application side of digital certificates through policy management. For example, when signing interface agreements, the policy requires identity status verification in an identity information database and multi-channel verification of liveness before applying for a digital certificate, ensuring the authenticity of the certificate holder's identity and preventing fraudulent or unauthorized entities from conducting business operations.

[0091] Typical application scenarios for digital certificates include transaction signing and electronic signatures. Transaction signing refers to electronically signing business information at critical business stages to prevent tampering and repudiation. For example, when using a bank's mobile banking app to make a large transfer (over 50,000 yuan), a certificate PIN code verification is required. Essentially, this process involves the backend using a digital certificate representing our identity to sign the transaction, ensuring the transfer is unalterable and irrepudiable. Electronic signatures refer to signing electronic contracts or electronic certificates. Generally, the platform (such as a bank's loan system) verifies the identity of the subject, obtains the subject's willingness to sign, and then applies for a certificate from a Certificate Authority (CA) or uses an existing certificate to electronically sign the electronic document, forming a compliant electronic contract. The method for generating digital certificates is as follows: Figure 5 As shown, it includes: forming a standard area and an extended area in the digital certificate; storing certificate information in the standard area; and binding a policy identifier in the extended area.

[0092] The digital certificate application process with embedded policy identifiers is as follows: Figure 6 As shown, it mainly includes the following steps:

[0093] (1) The user initiates a digital certificate application from the client and submits the user information for the application to use the digital certificate;

[0094] (2) The business system calls the identity authentication system to verify the user's identity online;

[0095] (3) The identity authentication system verifies the authenticity and accuracy of user information with authoritative data sources, records the verification trajectory of the current verification, and generates an identity verification traceability code that is uniquely associated with the current verification.

[0096] (4) The identity verification system returns the verification result to the business system;

[0097] (5) The business system calls the Registration Authority (RA) system to initiate a certificate application;

[0098] (6) The RA system determines the authentication strength and authentication strategy identifier according to the identity authentication classification and grading standards issued by the authoritative CA institution, and initiates a certificate application to the CA system;

[0099] (7) The CA issues a digital certificate with an embedded authentication policy identifier, and the result is returned to the RA system;

[0100] (8) The RA system returns the certificate application result to the business system;

[0101] (9) Users obtain digital certificates issued by authoritative CA institutions.

[0102] The attribute-based access control method provided in this invention applies the ABAC model to digital certificate services, promoting effective risk management on the application side of digital certificates through policy management. For example, when signing interface agreements, the policy requires identity status verification from an identity information database and multi-channel verification of liveness before applying for a digital certificate, ensuring the authenticity of the certificate holder's identity and preventing fraudulent or unauthorized entities from conducting business operations. The authentication policy identifier assigns authentication strength-related attributes to digital certificates. For instance, the required authentication strength differs in two scenarios: querying repayment records and signing loan contracts. Querying repayment records only requires a basic real-name certificate (such as verifying name and ID number), while the certificate used for signing loan contracts requires high-strength verification of the subject's liveness, survival status, bank card information, etc., before issuance. Different scenarios and authentication policies are reflected in the authentication policy identifier in the digital certificate.

[0103] The attribute-based access control device provided by the present invention will be described below. The attribute-based access control device described below can be referred to in correspondence with the attribute-based access control method described above.

[0104] Figure 7This is a schematic diagram of the structure of an attribute-based access control device provided in an embodiment of the present invention, as shown below. Figure 7 As shown, the attribute-based access control device provided in this embodiment of the invention includes:

[0105] Setting module 701 is used to set a policy identifier in the extended field of a digital certificate, wherein the policy identifier is used to identify the digital policy required by the business.

[0106] The generation module 702 is used to input the digital certificate carried in the access request into the attribute-based access control system engine when the subject initiates an access request. The attribute-based access control system engine parses the digital certificate, obtains the policy identifier in the digital certificate, as well as the subject attributes, object attributes and environment attributes related to the current access request, and generates a real-time identity authentication policy based on the subject attributes, object attributes and environment attributes.

[0107] The output module 703 is used to compare the real-time identity authentication policy with the digital policy of the business requirements corresponding to the parsed policy identifier, and output an access control decision based on the comparison result.

[0108] The attribute-based access control device provided in this invention sets a policy identifier in the extended domain of a digital certificate. This policy identifier identifies the digital policy required by the business. When a subject initiates an access request, the digital certificate carried in the access request is input into the attribute-based access control system engine. The engine parses the digital certificate to obtain the policy identifier, as well as the subject attributes, object attributes, and environment attributes related to the current access request. Based on these attributes, a real-time identity authentication policy is generated. The real-time identity authentication policy is compared with the digital policy required by the business corresponding to the parsed policy identifier. An access control decision is output based on the comparison result. By identifying the policy identifier during certificate use, the appropriateness of the current authentication policy can be verified, thereby enabling the selection of different authentication policies under the same digital identity to meet access security control requirements.

[0109] Figure 8 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 8As shown, the electronic device may include: a processor 810, a communications interface 820, a memory 830, and a communication bus 840. The processor 810, communications interface 820, and memory 830 communicate with each other via the communication bus 840. The memory 830 includes computer programs, an operating system, and acquired data. The processor 810 can call logical instructions in the memory 830 to execute an attribute-based access control method. This method includes: setting a policy identifier in the extended domain of a digital certificate, the policy identifier being used to identify the digital policy of the business requirement; when a subject initiates an access request, inputting the digital certificate carried in the access request into an attribute-based access control system engine; the attribute-based access control system engine parsing the digital certificate, obtaining the policy identifier in the digital certificate, and subject attributes, object attributes, and environment attributes related to the current access request, and generating a real-time identity authentication policy based on the subject attributes, object attributes, and environment attributes; comparing the real-time identity authentication policy with the digital policy of the business requirement corresponding to the parsed policy identifier, and outputting an access control decision based on the comparison result.

[0110] Furthermore, the logical instructions in the aforementioned memory 830 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to related technologies, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0111] On the other hand, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the attribute-based access control method provided by the above methods. The method includes: setting a policy identifier in an extended domain of a digital certificate, the policy identifier being used to identify a digital policy for business requirements; when a subject initiates an access request, inputting the digital certificate carried in the access request into an attribute-based access control system engine, the attribute-based access control system engine parsing the digital certificate to obtain the policy identifier in the digital certificate, as well as subject attributes, object attributes, and environment attributes related to the current access request, and generating a real-time identity authentication policy based on the subject attributes, object attributes, and environment attributes; comparing the real-time identity authentication policy with the digital policy for business requirements corresponding to the parsed policy identifier, and outputting an access control decision based on the comparison result.

[0112] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0113] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the parts that contribute to the related technology, can be embodied in the form of software products. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0114] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. An attribute-based access control method, characterized in that, include: Set a policy identifier in the extended field of the digital certificate, the policy identifier being used to identify the digital policy required by the business; When a subject initiates an access request, the digital certificate carried in the access request is input into the attribute-based access control system engine. The attribute-based access control system engine parses the digital certificate, obtains the policy identifier in the digital certificate, as well as the subject attributes, object attributes, and environment attributes related to this access request, and generates a real-time identity authentication policy based on the subject attributes, object attributes, and environment attributes. The real-time identity authentication policy is compared with the digital policy of the business requirements corresponding to the parsed policy identifier, and an access control decision is output based on the comparison result. The strategy identifier is a string generated by structured encoding according to the identifier characteristics; The identification characteristics include: Authentication strength, wherein the authentication strength level is used to identify the strength of the identity authentication associated with the digital certificate; The identity authentication type is used to identify the identity authentication type associated with the digital certificate. The identity authentication type corresponds to the authentication validity period. When there are multiple identity authentication types, each identity authentication type corresponds to an authentication validity period. The authentication validity period rule is used to identify the validity period information of the identity authentication associated with the digital certificate. The identity authentication validity period information includes the authentication validity period value and the authentication validity period unit.

2. The attribute-based access control method according to claim 1, characterized in that, The digital certificate carried in the access request is input into the attribute-based access control system engine. The attribute-based access control system engine parses the digital certificate to obtain the policy identifier in the digital certificate, as well as the subject attributes, object attributes, and environment attributes related to this access request, including: The attribute-based access control system engine parses the policy identifier field, subject field, and object field in the digital certificate carried in the access request to obtain the policy identifier in the policy identifier field, the subject attribute in the subject field, and the object attribute in the object field. The attribute-based access control system engine obtains the environmental information of the access request and generates environmental attributes.

3. The attribute-based access control method according to claim 2, characterized in that, The attribute-based access control system engine includes: an authorization component, an attribute provisioning component, and a policy management component; The real-time identity authentication strategy generated based on the subject attribute, object attribute, and environmental attribute includes: When a subject initiates an access request, the attribute providing component provides subject attributes, object attributes, and environment attributes. The policy management component generates a real-time identity authentication policy based on the subject attributes, object attributes, and environment attributes. The authorization component evaluates the real-time identity authentication policy and outputs an access control decision.

4. The attribute-based access control method according to claim 3, characterized in that, The attribute providing components include: The attribute repository is used to store the collections of subject attributes and the collections of object attributes; Attribute information provider: used to retrieve the subject attribute set and object attribute set based on the subject field and object field in the digital certificate, determine the attribute information of the subject executing the access request and the accessed object in the workflow process, and generate environment attributes based on the environment information of the access request; The policy management component includes: a policy management point and a policy repository; The policy management point is used to create, manage, test, and debug real-time identity authentication policies, and to store the debugged real-time identity authentication policies in the policy repository.

5. The attribute-based access control method according to claim 4, characterized in that, The authorization components include: policy decision points and policy execution points; The policy decision point is used to evaluate the real-time identity authentication policy, mediate policy conflicts, and generate application control decisions. The policy execution point is used to execute the application control decision generated by the policy decision point, respond to the access request, and output whether to allow or deny the access request.

6. An attribute-based access control device, characterized in that, include: The configuration module is used to set a policy identifier in the extended domain of the digital certificate, wherein the policy identifier is used to identify the digital policy required by the business. The strategy identifier is a string generated by structured encoding according to identifier characteristics; the identifier characteristics include: authentication strength, the authentication strength level is used to identify the authentication strength associated with the digital certificate; authentication type, the authentication type is used to identify the authentication type associated with the digital certificate, the authentication type corresponds to the authentication validity period, and when there are multiple authentication types, each authentication type corresponds to an authentication validity period; authentication validity period, the authentication validity period rule is used to identify the validity period information of the authentication associated with the digital certificate, the authentication validity period information includes the authentication validity period value and the authentication validity period unit; The generation module is used to input the digital certificate carried in the access request into the attribute-based access control system engine when the subject initiates an access request. The attribute-based access control system engine parses the digital certificate, obtains the policy identifier in the digital certificate, as well as the subject attributes, object attributes and environment attributes related to this access request, and generates a real-time identity authentication policy based on the subject attributes, object attributes and environment attributes. The output module is used to compare the real-time identity authentication policy with the digital policy of the business requirements corresponding to the parsed policy identifier, and output an access control decision based on the comparison result.

7. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the attribute-based access control method as described in any one of claims 1 to 5.

8. A non-transitory readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the attribute-based access control method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Power grid access control method and system based on user attributes and storage medium

    CN113259137A

  • Flow control method, device and equipment

    CN117938544A