Digital product uniqueness identification and access authority control method based on block chain

By combining blockchain technology, elliptic curve digital signature and ABAC model, decentralized identity authentication and optimized access decision-making process are built, which solves the problems of complex authorization management and identification forgery in the access control method, and realizes efficient and secure unique identification and access rights control of digital products, which is suitable for the protection and management of large-scale digital resources.

CN120342574AActive Publication Date: 2025-07-18SHENZHEN JIURI INFORMATION TECHNOLOGY CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510616481.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-14
Publication Date
2025-07-18
Estimated Expiration
2045-05-14

AI Technical Summary

Technical Problem

The existing blockchain-based access control method has complex authorization management and insufficient flexibility when large-scale users and resources change, and there is a risk of forgery and tampering in a decentralized environment. Traditional Boolean logic optimization methods have failed to effectively improve access decision efficiency and system stability.

Method used

Combining blockchain technology, elliptic curve digital signature and optimization ABAC access control model, by building decentralized identity authentication, optimized access decision process and on-chain proof storage mechanism, the access user's public and private key pairs are generated, and the access control policy is processed using hash algorithm and Boolean logic optimization mechanism, and the access behavior is recorded to the blockchain to realize dynamic management of access permissions and tamper-proof storage.

Benefits of technology

It improves access decision efficiency, enhances the security and traceability of access control, reduces the consumption of computing resources, ensures efficient management of unique identification and access rights of digital products, and is suitable for the protection and access management of large-scale digital resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342574A_ABST
    Figure CN120342574A_ABST
Patent Text Reader

Abstract

The invention discloses a digital product unique identification and access authority control method based on a block chain, and the method comprises the following steps: S1, collecting data, and constructing a digital product data set and an access user attribute data set; s2, distributing a decentralized identity label for the access user, and generating an access user public key and an access user private key; s3, generating a request digest value through a Hash algorithm, and generating a signature access request structural body; s4, constructing an ABAC model, and formulating an access control strategy rule set; s5, introducing a Boolean operation optimization mechanism into the ABAC model to obtain an optimized ABAC model; s6, verifying the question request signature in the signature access request structural body, and generating an access authorization token; and S7, based on the access authorization token, extracting an access behavior and recording the access behavior to the block chain. According to the method, the unique identification and access authority control of the digital product are realized by combining the block chain evidence storage, the ECDSA digital signature and the Boolean logic to optimize the ABAC access control strategy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of blockchain access control, and particularly to a method for uniquely identifying digital products and controlling access rights based on blockchain. Background Art

[0002] With the development of the digital economy and the wide application of Internet technologies, various digital products have been rapidly popularized in fields such as e-commerce, cultural and entertainment creation, software distribution, and intellectual property protection. How to effectively identify the uniqueness of digital products and perform fine-grained control over their access rights has become an important research direction in the field of information security and data governance. In this context, blockchain technology has been widely applied to the confirmation of rights, traceability, and access control of digital products due to its characteristics such as decentralization, immutability, and traceability. By recording the key information of digital products on the blockchain, transparent management of the resource distribution process can be achieved, enhancing the security and credibility of the system.

[0003] Existing blockchain-based access control methods mainly rely on traditional access control models, such as identity-based access control (IBAC), role-based access control (RBAC), etc. These methods usually define access control rules in blockchain smart contracts to bind access rights between users and resources. However, the IBAC model has problems of complex authorization management and insufficient flexibility when faced with a large number of users and dynamic changes in resources; while RBAC simplifies authorization management through role mediation, but the static binding of roles makes the model difficult to handle fine-grained and dynamically changing access requirements. In addition, in practical applications, context factors such as user identity, geographical location, device type, and access time have an important impact on access decisions. Relying solely on simple identity or role attributes is difficult to cover all access control requirements, resulting in the traditional model being ineffective in complex application scenarios.

[0004] To improve the flexibility and accuracy of access control, researchers have proposed the attribute-based access control (ABAC) model. The ABAC model defines access policies through multi-dimensional features such as user attributes, resource attributes, and environmental attributes, enabling more dynamic and fine-grained permission management. In recent years, some studies have combined the ABAC model with blockchain, attempting to store access control policies on the chain and make access decisions. However, existing technologies mostly use a direct mapping of attribute conditions, lacking in-depth optimization of the access decision-making process. As a result, when the number of attributes increases and the policy conditions become complex, the access decision-making process has problems such as long decision-making chains, low matching efficiency, and high consumption of computing resources. In addition, making access decisions on the chain is easily restricted by the execution performance of smart contracts. When access requests are frequent and attribute conditions are complex, the system response speed drops significantly, affecting the overall system availability.

[0005] In digital product management, the unique identification of digital products is also a technical challenge that cannot be ignored. Existing identification methods mostly rely on traditional centralized databases or single-signature mechanisms, which pose risks of identification conflicts, forgery, and tampering in a decentralized environment. Although blockchain provides an immutable foundation, in the actual process of identification generation and verification, it may still be forged or misused without the support of an effective cryptographic signature. Among existing technologies, digital signature technologies based on public-key cryptosystems such as RSA and ECDSA are widely used, which can generate unique and verifiable identifiers for digital products. However, simply applying the signature mechanism without a tight integration with the access control system often fails to form a closed-loop management, resulting in the disconnection between identification authentication and access control and reducing the overall security protection ability.

[0006] Regarding the issue of access control efficiency, some existing research has proposed using boolean logic to optimize access policies, logically simplifying complex attribute conditions to reduce the depth of decision trees and improve matching efficiency. However, such methods usually remain at the theoretical level and lack engineering implementation in combination with actual blockchain systems. Existing methods mostly adopt single-round simplification and do not consider factors such as access attribute frequencies and matching path weights, resulting in limited policy optimization effects. In addition, traditional boolean optimization often ignores the evolution requirements of access control policies in a dynamic environment and lacks a mechanism to adaptively adjust the policy structure according to real-time access patterns, affecting the long-term stability and scalability of the system.

[0007] Therefore, how to provide a method for unique identification of digital products and access permission control based on blockchain is an urgent problem to be solved by those skilled in the art. Summary of the Invention

[0008] An object of the present invention is to propose a method for unique identification of digital products and access permission control based on blockchain. The present invention fully combines blockchain technology, elliptic curve digital signature, and an optimized ABAC access control model, and details the complete processes of digital product identification generation, access permission verification, and access behavior evidence storage. By constructing a decentralized identity authentication, optimizing the access decision process, and an on-chain evidence storage mechanism, the present invention solves the problems of identification forgery, permission abuse, and audit omission existing in traditional access control methods. This method has the advantages of high security, high access decision efficiency, and strong traceability, and is suitable for the protection and access management of large-scale digital resources, with broad application prospects and practical engineering value.

[0009] According to an embodiment of the present invention, a method for unique identification of digital products and access permission control based on blockchain includes the following steps:

[0010] S1. Collect digital product data and attribute information of access users, and construct a digital product data set and an access user attribute data set;

[0011] S2. Based on the access user attribute dataset, assign a decentralized identity identifier to the access user. Using the elliptic curve cryptography algorithm, generate the access user's public key and private key to form a key pair.

[0012] S3. Based on the digital product dataset and the access user attribute dataset, generate a request digest value through the hash algorithm, and use the access user's private key to perform an elliptic curve digital signature on the request digest value to generate a signed access request structure.

[0013] S4. Construct an ABAC model, model the access user as an access request body with the ability to observe attributes and make access decisions, and based on the digital product dataset, formulate an access control policy rule set.

[0014] S5. Introduce a boolean operation optimization mechanism into the ABAC model, initialize multiple boolean logic expression units, process the access control policy, and obtain an optimized ABAC model.

[0015] S6. Verify the access request signature in the signed access request structure, input the access user attribute dataset into the optimized ABAC model for matching and judgment, and generate an access authorization token.

[0016] S7. Based on the access authorization token, extract the access behavior and record it in the blockchain to achieve the auditing and traceability of the access process.

[0017] Optionally, the digital product dataset includes a resource identifier, a resource type, a security level, a version information, and metadata information, and the access user attribute dataset includes a role attribute, a geographical attribute, a device attribute, an access time attribute, and an optional dynamic attribute.

[0018] Optionally, the S2 specifically includes:

[0019] S21. Based on the access user attribute dataset, extract the information including the role attribute, the geographical attribute, and the device attribute, and construct an access user identity feature vector.

[0020] S22. Concatenate the access user identity feature vector with the time stamp of the current generation moment, and through the decentralized identity generation hash function processing, generate the decentralized identity identifier of the access user:

[0021] ;

[0022] Wherein, is the decentralized identity identifier of the access user, is the identifier namespace prefix, is the binary concatenation operator, is the first-layer encryption hash function, is the second-layer encryption hash function, is the access user identity feature vector, is the randomly generated encryption salt value, is the current system timestamp;

[0023] S23. Based on the decentralized identity identifier of the access user, using the elliptic curve encryption algorithm, perform scalar multiplication operation between the private key of the access user and the base point of the elliptic curve to generate the key pair of the access user, where the public key of the access user is the point coordinates obtained by multiplying the private key of the access user by the standard elliptic curve base point, forming a public key and private key pair exclusive to the access user;

[0024] S24. Store the generated private key of the access user in the local terminal device of the access user, and at the same time bind and register the generated public key of the access user with the decentralized identity identifier.

[0025] Optionally, the S3 specifically includes:

[0026] S31. Extract the resource identifier from the digital product dataset, extract the role attribute, geographical attribute, device attribute, and access time attribute from the access user attribute dataset, arrange them in order, and combine them into an access request vector;

[0027] S32. Pass the access request vector as input data to the hash function, and perform one-way digest calculation on all field contents of the access request vector, including the resource identifier, role attribute, geographical attribute, device attribute, and access time attribute, through the hash algorithm, and output the corresponding access request digest value;

[0028] S33. Use the private key of the access user to perform elliptic curve digital signature on the request digest value, and generate an access request signature through the elliptic curve digital signature algorithm;

[0029] S34. Combine the decentralized identity identifier of the access user, the access request vector, the request digest value, the access request signature, and the access user attribute dataset to construct a signed access request structure.

[0030] Optionally, the elliptic curve digital signature algorithm includes randomly selecting an integer greater than or equal to 1 and less than the order of the elliptic curve as the signature random number; subsequently, multiply the random number by the base point of the elliptic curve to obtain a coordinate point on the elliptic curve; extract the abscissa from the point coordinates and take the modulus of the order of the elliptic curve to obtain the first component in the signature ;

[0031] Calculate the second component in the signature:

[0032] ;

[0033] Among them, is the second component in the signature, is a random number is the multiplicative inverse under the modulus in the sense of, is the access request digest value, is the access request vector, is the private key of the accessing user, is the accessing user, is the first component in the signature, is the modulo operation, is the order of the elliptic curve;

[0034] Combine the first component in the signature and the second component in the signature to obtain the access request signature.

[0035] Optionally, the S4 specifically includes:

[0036] S41. Model the accessing user as an access request body, the access request body has the capabilities of attribute observation and access decision-making, based on the user attribute dataset and the digital product dataset, extract the role attribute, geographical attribute, device attribute, access time attribute, resource type attribute and resource security level attribute, and combine them to form the attribute observation vector of the access request body;

[0037] S42. According to the attribute observation vector of the access request body, set the initial attribute state value for each access request body, and the initial state value is determined according to the real-time identity information, device state, geographical location and time period classification of the user when the access request occurs;

[0038] S43. Allocate an access sensitivity parameter for the access request body according to the role attribute and the device attribute. When the role attribute is the system administrator and the device attribute is a trusted device, When the role attribute is an ordinary user and the device attribute is a trusted device, When the device attribute is an untrusted device, regardless of the user role, ;

[0039] S44. Set an access confidence parameter for the access request body according to the geographical attribute and the access time attribute. When the geographical attribute is in the trusted area and the access time attribute is in the working time period, When the geographical attribute is in the unknown area or the access time attribute is in the non-working time period, , when the geographical attribute is in a high-risk area, ;

[0040] S45. Integrate the attribute observation vector, access sensitivity parameter and the access confidence parameter to form an access control feature vector;

[0041] S46. Based on the access control feature vector, formulate access control policy rules according to a preset Boolean logic condition combination method, and generate an access control policy set according to the access decision result.

[0042] Optionally, the S5 specifically includes:

[0043] S51. Based on the access control attribute vector and the access control policy set, extract each access control policy rule, and convert the attribute combination condition in the access control policy rule into an initial Boolean logic expression;

[0044] S52. Perform logical simplification on the initial Boolean logic expression, merge like terms and eliminate redundant logical conditions according to Boolean algebra rules to obtain a simplified Boolean logic expression;

[0045] S53. For the simplified Boolean logic expression, perform short-circuit optimization processing, rearrange the judgment path according to the probability order of attribute values, determine the access decision output in advance, and generate a short-circuit optimized Boolean logic expression;

[0046] S54. Perform path pruning processing on the short-circuit optimized Boolean logic expression, delete redundant judgment nodes and unreachable paths, and generate a pruned Boolean logic expression;

[0047] S55. Based on the pruned Boolean logic expression, perform performance evaluation according to the attribute matching complexity index and the access decision efficiency index, and screen out an optimized expression set that meets the optimal threshold;

[0048] S56. Integrate the optimized expression set to form an optimized access control policy rule set, and update the ABAC model based on the optimized access control policy rule set to form an optimized ABAC model.

[0049] Optionally, the S6 specifically includes:

[0050] S61. Extract the centralized identity identifier, access request vector, request digest value, access request signature and access user attribute data set contained in the signature access request structure, and combine them into an access request verification data packet;

[0051] S62. Use the public key of the accessing user to perform digital signature verification on the request digest value and the access request signature in the access request verification data packet. When the verification is successful, confirm that the source of the access request is trustworthy and the content has not been tampered with, and allow entry into the attribute matching phase; otherwise, reject subsequent processing.

[0052] S63. Based on the user attribute data set and the access request vector in the access request verification data packet, construct an access request attribute observation vector and input it into the optimized ABAC model to perform access decision-making judgment:

[0053] ;

[0054] where, is the matching decision result, is the result of the access request signature verification, is the logical AND operator, is the logical OR operator, is the total number of rules in the optimized access control policy rule set, is the policy rule index variable, is the matching judgment function, is the attribute observation vector corresponding to the current access request, is the th access control policy Boolean logic expression after optimization;

[0055] S64. If the matching decision result is true and the signature verification passes, generate an access authorization token.

[0056] Optionally, the generation of the access authorization token includes generating identity and resource binding data, generating an access authorization timestamp, and extracting the access permission range; the generation of the identity and resource binding data is to extract the decentralized identity identifier and the resource identifier; combine the decentralized identity identifier, the resource identifier, the access authorization timestamp, and the extracted access permission range to generate an access authorization token.

[0057] Optionally, the specific steps of S7 include:

[0058] S71. Extract the decentralized identity identifier, the resource identifier, the access permission range, the authorization timestamp, and the access decision result in the access authorization token, and combine them to form an access behavior basic information set;

[0059] S72. After the access behavior is completed, collect the actual access timestamp when the access occurs, and merge the access behavior basic information set with the actual access timestamp to form an access behavior record data structure;

[0060] S73. Perform a secure hash operation on the access behavior record data structure, and use the SHA-256 algorithm to generate an access behavior record hash value;

[0061] S74, constructing a blockchain transaction data structure based on the hash value of the access behavior record combined with the address information of the accessing user in the blockchain network and the current transaction generation time;

[0062] S75. Broadcast the blockchain transaction data structure to the blockchain network, confirm it through the consensus mechanism of the blockchain system and write it into the blockchain ledger, forming an unalterable access behavior certificate, and realizing the complete audit and traceability of the access behavior.

[0063] The beneficial effects of the present invention are:

[0064] Based on blockchain technology and the attribute-based access control (ABAC) model, this invention integrates the ECDSA digital signature mechanism and the Boolean logic optimization decision framework into the digital product unique identification and access permission control system for the first time. Different from the existing access management methods that rely on traditional identity control or role control, this invention combines user attributes, resource attributes and environmental attributes to build a dynamic and fine-grained access control system, and innovatively introduces a Boolean logic optimization mechanism to perform logical simplification, short-circuit evaluation and path clipping on the access control strategy, effectively reducing the complexity of the access attribute decision link, improving the decision-making efficiency and system responsiveness in high-frequency access request scenarios, and breaking through the technical bottlenecks of the existing blockchain access control execution delay and high resource overhead.

[0065] In terms of unique identification of digital products, the present invention generates a key pair for access users based on the ECDSA elliptic curve cryptography system, and digitally signs the access request summary value through the user's private key to form a verifiable signature access request structure on the chain, thereby ensuring the authenticity and integrity of the access request and preventing the risks of forgery, impersonation and tampering in traditional centralized identification systems. At the same time, the present invention constructs a decentralized identity identification (DID) system, deeply integrates identity authentication and access control, and opens up the entire chain of user identity generation, resource access authorization and behavior auditing, providing complete and reliable technical support for digital product management and protection.

[0066] At the access control policy optimization level, the present invention introduces dynamic path selection and redundant clipping mechanisms in the attribute condition matching process through multiple rounds of logic simplification and short-circuit optimization, reconstructs decision expressions based on attribute complexity and decision priority, avoids the performance bottleneck brought by traditional static attribute matching tables, and realizes the structural optimization of the access control policy system. Through this method, the present invention significantly reduces the computing resources and delay time required in the access decision process, especially in the actual application environment of high concurrency, multi-users, and multi-resources, and has better system scalability and maintainability.

[0067] In terms of access behavior auditing and tracing, the present invention constructs a unified access behavior record data structure, combines access authorization information with access execution timestamps, uses the SHA-256 hash algorithm to perform summary processing on access behavior, and submits the hash value and related transaction information as tamper-proof evidence to the blockchain account book, forming a complete and continuous access operation evidence chain. Different from the existing system that only records a single resource status or access action, the present invention realizes the audit link of the entire process from access request initiation, permission verification, access execution to behavior evidence, effectively enhancing the system's responsibility definition capabilities and compliance, and meeting the needs of high-standard digital governance and data security audits.

[0068] In general, the present invention has opened up a complete closed loop of digital product management for the first time, from unique identification generation, access identity authentication, dynamic attribute authorization to evidence storage on the behavior chain, forming an integrated technical system of "identification-control-verification-traceability". Compared with existing methods, the present invention has multiple advantages in system architecture, such as clear data flow, module decoupling, excellent computing efficiency, high security, and complete audit traceability. It provides a new technical path and engineering implementation foundation for future practical applications in the fields of digital content rights confirmation, intellectual property protection, supply chain traceability, data sharing and secure access. BRIEF DESCRIPTION OF THE DRAWINGS

[0069] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:

[0070] Figure 1 This is a flowchart of the blockchain-based digital product unique identification and access permission control method proposed by the present invention;

[0071] Figure 2 This is a schematic diagram of the optimized ABAC model structure in the blockchain-based digital product unique identification and access authority control method proposed by the present invention;

[0072] Figure 3 This is a flowchart of access behavior recording and on-chain evidence storage in the blockchain-based digital product unique identification and access permission control method proposed by the present invention. DETAILED DESCRIPTION

[0073] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, which only illustrate the basic structure of the present invention in a schematic manner, and therefore only show the components related to the present invention.

[0074] refer to Figures 1 - 3 , a method for unique identification and access control of digital products based on blockchain, comprising the following steps:

[0075] S1. Collect digital product data and access user attribute information to construct a digital product data set and an access user attribute data set;

[0076] S2. Based on the access user attribute data set, assign a decentralized identity identifier to the access user, and use the elliptic curve cryptography algorithm to generate an access user public key and an access user private key to form a key pair;

[0077] S3. Based on the digital product data set and the access user attribute data set, generate a request digest value through the hash algorithm, and use the access user private key to perform an elliptic curve digital signature on the request digest value to generate a signed access request structure;

[0078] S4. Construct an ABAC model, model the access user as an access request body with the ability of attribute observation and access decision-making, and based on the digital product data set, formulate an access control policy rule set;

[0079] S5. Introduce a Boolean operation optimization mechanism into the ABAC model, initialize multiple Boolean logic expression units, process the access control policy, and obtain an optimized ABAC model;

[0080] S6. Verify the access request signature in the signed access request structure, input the access user attribute data set into the optimized ABAC model for matching judgment, and generate an access authorization token;

[0081] S7. Based on the access authorization token, extract the access behavior and record it on the blockchain to implement the audit and traceability of the access process.

[0082] The present invention proposes a method for digital product uniqueness identification and access permission control based on the blockchain, and constructs a complete process from data collection, digital signature generation, ABAC model construction, Boolean optimization, access verification to on-chain evidence storage. In the method, by introducing a decentralized identity identifier and an elliptic curve digital signature technology, the security and immutability of the access request are ensured; the access decision-making efficiency of the ABAC model is improved through Boolean logic optimization, and the consumption of computing resources is significantly reduced in a high-concurrency environment. Compared with traditional access control methods, the present invention enhances the flexibility and security of access control, provides complete access audit and traceability capabilities, has stronger system scalability and adaptability, and can effectively meet the diverse digital product management requirements.

[0083] In this embodiment, the digital product data set includes a resource identifier, a resource type, a security level, a version information, and metadata information, and the access user attribute data set includes a role attribute, a geographical attribute, a device attribute, an access time attribute, and an optional dynamic attribute.

[0084] By defining in detail the digital product data set and the access user attribute data set, the present invention ensures that the input data covers key attributes such as the resource identifier, resource type, security level, version information, and metadata information of digital products, as well as the role attribute, geographical attribute, device attribute, access time attribute, and optional dynamic attribute of the access user. After being processed by standardization, this data set is input into the ABAC model, ensuring that access control decisions can accurately reflect the dynamic changes of multi-dimensional user and resource information. In a changing access request environment, the method of the present invention effectively improves the adaptability of the system to complex access scenarios, enhances the flexibility and security of access control policies, ensures the efficient management and auditing of the unique identifier of digital products and access permissions, and has broad application prospects and practical value.

[0085] In this embodiment, the S2 specifically includes:

[0086] S21. Based on the access user attribute data set, extract information including role attribute, geographical attribute, and device attribute, and construct an access user identity feature vector;

[0087] S22. Concatenate the access user identity feature vector with the time stamp of the current generation moment, and process it through a decentralized identity generation hash function to generate a decentralized identity identifier of the access user:

[0088] ;

[0089] Wherein, is the decentralized identity identifier of the access user, is the identifier namespace prefix, is the binary concatenation operator, is the first-layer encryption hash function, is the second-layer encryption hash function, is the access user identity feature vector, is a randomly generated encryption salt value, is the current system time stamp;

[0090] S23. Based on the decentralized identity identifier of the access user, adopt the elliptic curve encryption algorithm, and generate a key pair of the access user in the way of scalar multiplication operation between the private key of the access user and the base point of the elliptic curve. Among them, the public key of the access user is the point coordinate obtained by multiplying the private key of the access user by the standard elliptic curve base point, forming a public key and private key pair exclusive to the access user;

[0091] S24. Store the generated private key of the access user in the local terminal device of the access user, and at the same time bind and register the generated public key of the access user with the decentralized identity identifier.

[0092] Through the decentralized identity generation mechanism based on user attributes, the present invention realizes the efficient management and secure control of digital product access permissions. Specifically, by extracting features from data such as the role attributes, geographical attributes, and device attributes of the accessing user, constructing an identity feature vector of the accessing user, and combining it with the current timestamp to generate a decentralized identity identifier, the uniqueness and anti-tampering property of each user identity are ensured. In addition, the elliptic curve encryption algorithm is used to generate user key pairs, further enhancing the security and privacy of identity authentication. By binding the public key to the decentralized identity identifier, the system realizes the entire process of decentralized identity authentication, thus avoiding the single point of failure and security risks in traditional centralized identity authentication.

[0093] In this embodiment, step S3 specifically includes:

[0094] S31. Extract the resource identifier from the digital product dataset, extract the role attribute, geographical attribute, device attribute, and access time attribute from the accessing user attribute dataset, arrange them in sequence, and combine them into an access request vector;

[0095] S32. Use the access request vector as input data and pass it to the hash function. Through the hash algorithm, perform a one-way digest calculation on all field contents of the access request vector, including the resource identifier, role attribute, geographical attribute, device attribute, and access time attribute, and output the corresponding access request digest value;

[0096] S33. Use the private key of the accessing user to perform an elliptic curve digital signature on the request digest value, and generate an access request signature through the elliptic curve digital signature algorithm;

[0097] S34. Combine the decentralized identity identifier of the accessing user, the access request vector, the request digest value, the access request signature, and the accessing user attribute dataset to construct a signed access request structure.

[0098] Through the hash algorithm of the access request vector and the elliptic curve digital signature mechanism, the present invention realizes an efficient security verification and anti-tampering mechanism in digital product access control. Specifically, by extracting the resource identifier, role attribute, geographical attribute, device attribute, and access time attribute from the digital product dataset and the accessing user attribute dataset, constructing an access request vector, and performing a one-way digest calculation on it to generate an access request digest value. Combining with the private key of the accessing user to generate an elliptic curve digital signature ensures the authenticity and integrity of each access request. In addition, by combining the decentralized identity identifier with information such as the access request vector and signature to construct a signed access request structure, the secure, complete, and tamper-proof transmission of the access request is realized.

[0099] In this embodiment, the elliptic curve digital signature algorithm includes randomly selecting a number greater than or equal to 1 and less than the order of the elliptic curve an integer as the signature random number; subsequently, multiply the random number by the elliptic curve base point to obtain a coordinate point on the elliptic curve; extract the abscissa from the point coordinates and take the modulus with respect to the order of the elliptic curve to obtain the first component in the signature ;

[0100] Calculate the second component in the signature :

[0101] ;

[0102] wherein, is the second component in the signature, is the random number under the modulus in the sense of multiplication inverse, is the access request digest value, is the access request vector, is the private key of the access user, is the access user, is the first component in the signature, is the modulo operation, is the order of the elliptic curve;

[0103] Combine the first component in the signature and the second component in the signature to obtain the access request signature.

[0104] Through the elliptic curve digital signature algorithm, the present invention provides high security and high efficiency in the access control of digital products. Specifically, the present invention generates a unique signature value by calculating with a randomly selected signature random number and the elliptic curve base point. This signature process not only ensures the immutability of the signature, but also utilizes the operational characteristics of the private key and the random number to ensure the authenticity and integrity of the request without revealing the private key. By combining the first and second components of the signature, the access request signature is finally generated, ensuring that the access process of digital products has high security and anti-tampering properties. This method effectively improves the access control ability of the system, reduces the risk of illegal access, and has significant technical advantages.

[0105] In this embodiment, the S4 specifically includes:

[0106] S41. Model the accessing user as an access request body, which has the capabilities of attribute observation and access decision-making. Based on the user attribute dataset and the digital product dataset, extract role attributes, geographical attributes, device attributes, access time attributes, resource type attributes, and resource security level attributes, and combine them to form the attribute observation vector of the access request body.

[0107] S42. According to the attribute observation vector of the access request body, set the initial attribute state value for each access request body. The initial state value is determined according to the user's real-time identity information, device status, geographical location, and time period classification when the access request occurs.

[0108] S43. Assign an access sensitivity parameter to the access request body according to the role attribute and the device attribute , when the role attribute is a system administrator and the device attribute is a trusted device, , when the role attribute is an ordinary user and the device attribute is a trusted device, , when the device attribute is an untrusted device, regardless of the user role, ;

[0109] S44. Set an access confidence parameter for the access request body according to the geographical attribute and the access time attribute , when the geographical attribute is in a trusted area and the access time attribute is during the working period, , when the geographical attribute is in an unknown area or the access time attribute is during a non-working period, , when the geographical attribute is in a high-risk area, ;

[0110] S45. Integrate the attribute observation vector, access sensitivity parameter and the access confidence parameter of the access request body to form an access control feature vector.

[0111] S46. Based on the access control feature vector, formulate access control policy rules according to the preset Boolean logic condition combination method, and generate an access control policy set according to the access decision result.

[0112] By constructing an access request body based on user attributes and digital product attributes, the present invention realizes the precise modeling of access control decisions. Specifically, the present invention constructs an access request body with attribute observation and access decision-making capabilities by extracting multi-dimensional attributes such as user roles, regions, devices, and access times. Each request body sets an initial state according to parameters such as real-time identity information, device status, and geographical location, and further optimizes the access control policy by setting access sensitivity and access confidence parameters. Based on these attribute information, the present invention generates an access control feature vector and combines a Boolean logic optimization strategy rule to ensure efficient decision-making for each access request. Compared with traditional methods, the present invention not only enhances the flexibility and accuracy of access control, but also improves the adaptability and security of the system in a changing environment.

[0113] In this embodiment, step S5 specifically includes:

[0114] S51. Based on the access control attribute vector and the access control policy set, extract each access control policy rule, and convert the attribute combination conditions in the access control policy rule into an initial Boolean logic expression;

[0115] S52. Perform logical simplification on the initial Boolean logic expression, merge like terms and eliminate redundant logical conditions according to Boolean algebra rules to obtain a simplified Boolean logic expression;

[0116] S53. For the simplified Boolean logic expression, perform short-circuit optimization processing, rearrange the judgment paths according to the probability order of attribute values, determine the access decision output in advance, and generate a short-circuit optimized Boolean logic expression;

[0117] S54. Perform path pruning processing on the short-circuit optimized Boolean logic expression, delete redundant judgment nodes and unreachable paths, and generate a pruned Boolean logic expression;

[0118] S55. Based on the pruned Boolean logic expression, perform performance evaluation according to the attribute matching complexity index and the access decision efficiency index, and screen out an optimized expression set that meets the optimal threshold;

[0119] S56. Integrate the optimized expression set to form an optimized access control policy rule set, and update the ABAC model based on the optimized access control policy rule set to form an optimized ABAC model.

[0120] By introducing a Boolean logic optimization mechanism, the present invention significantly improves the decision-making efficiency and computational performance of the ABAC access control model. Specifically, by performing logical simplification, short-circuit optimization, and path pruning on the access control policy rules, the present invention reduces redundant logical conditions, optimizes the judgment path, and significantly reduces the computational complexity in the access decision-making process. The simplified Boolean logic expression not only improves the speed of attribute matching but also selects the optimal set of optimized expressions through performance evaluation, thereby forming a more efficient access control policy rule set. This optimization method can ensure the response speed and accuracy of the system in scenarios with high concurrency and high-frequency access requests.

[0121] In this embodiment, step S6 specifically includes:

[0122] S61. Extract the centralized identity identifier, access request vector, request digest value, access request signature, and access user attribute data set contained in the signature access request structure, and combine them into an access request verification data packet;

[0123] S62. Use the public key of the access user to perform digital signature verification on the request digest value and access request signature in the access request verification data packet. When the verification is successful, confirm that the access request source is trustworthy and the content has not been tampered with, and allow it to enter the attribute matching stage; otherwise, reject subsequent processing;

[0124] S63. According to the user attribute data set and access request vector in the access request verification data packet, construct an access request attribute observation vector, input it into the optimized ABAC model, and perform access decision judgment:

[0125] ;

[0126] Wherein, is the matching decision result, is the result of the access request signature verification, is the logical AND operator, is the logical OR operator, is the total number of rules in the optimized access control policy rule set, is the policy rule index variable, is the matching judgment function, is the attribute observation vector corresponding to the current access request, is the th access control policy Boolean logic expression after optimization;

[0127] S64. If the matching decision result is true and the signature verification is passed, generate an access authorization token.

[0128] Through the access request verification mechanism, the present invention effectively improves the security and credibility of digital product access control. Specifically, the present invention extracts the signature, digest value, and user attribute dataset from the access request, generates an access request verification data packet, and uses the public key of the accessing user to verify the signature, ensuring that the source of the access request is credible and the content has not been tampered with. This process effectively prevents the risk of forged requests or malicious tampering of access content. Once the verification is successful, the system generates an access request attribute observation vector based on the user attributes and request vector, and makes an access decision judgment according to the optimized ABAC model. This method significantly improves the accuracy of access decisions and the system response speed, ensures the efficiency and security of access control, has high scalability, and is applicable to the protection and management of large-scale digital resources. Compared with traditional methods, the present invention shows stronger advantages in aspects such as anti-tampering, security verification, and decision-making efficiency, providing a more reliable digital product access control solution.

[0129] In this embodiment, the generation of the access authorization token includes generating identity and resource binding data, generating an access authorization timestamp, and extracting the access permission scope; the generation of identity and resource binding data is to extract the decentralized identity identifier and resource identifier; combining the decentralized identity identifier, resource identifier, access authorization timestamp, and the extracted access permission scope to generate an access authorization token.

[0130] Through the access authorization token generation mechanism, the present invention realizes the efficient and credible authentication of digital product access permissions. Specifically, by extracting the decentralized identity identifier and resource identifier, combining the access authorization timestamp and access permission scope, an access authorization token containing identity and resource binding data is generated. This method ensures the precise control of identity verification and resource access for each access request, enhancing the flexibility and security of resource protection. At the same time, the generation process of the authorization token makes the access permission have a clear time limit, avoiding potential security risks brought by long-term valid authorizations. Compared with traditional access control methods, the present invention provides a more secure, transparent, and efficient authorization management mechanism, which is applicable to the access protection and management of large-scale digital resources.

[0131] In this embodiment, the S7 specifically includes:

[0132] S71. Extract the decentralized identity identifier, resource identifier, access permission scope, authorization timestamp, and access decision result from the access authorization token, and combine them to form a basic access behavior information set;

[0133] S72. After the access behavior is executed, collect the actual access timestamp when the access occurs, and merge the basic access behavior information set with the actual access timestamp to form an access behavior record data structure;

[0134] S73. Perform a secure hashing operation on the access behavior record data structure, and use the SHA-256 algorithm to generate an access behavior record hash value;

[0135] S74. Based on the access behavior record hash value, combine the address information of the accessing user in the blockchain network and the current transaction generation time to construct a blockchain transaction data structure;

[0136] S75. Broadcast the blockchain transaction data structure to the blockchain network, and confirm it through the consensus mechanism of the blockchain system and write it into the blockchain ledger to form an immutable access behavior record, realizing the complete audit and traceability of access behavior

[0137] Through the access behavior record mechanism of the blockchain, the present invention ensures the complete audit and traceability of the digital product access process. Specifically, by combining the key data in the access authorization token with the actual access timestamp, an access behavior record data structure is formed, and the access behavior record hash value is generated through the SHA-256 hashing algorithm, ensuring the security and immutability of the record. Further combined with the blockchain transaction data structure, and using the consensus mechanism of the blockchain system to write it into the blockchain ledger, a complete and transparent access behavior audit chain is provided. This method significantly improves the security and transparency of digital resource management, ensures the traceability of each access, and provides strong technical support for the security management and compliance audit of digital products.

[0138] Example 1:

[0139] In order to verify the feasibility of the present invention in implementation, the present invention is applied to a large national digital content distribution and intellectual property protection platform, and a typical operation period from February 1st to February 7th is used to test the blockchain-based digital product uniqueness identification and access permission control method proposed by the present invention. The platform covers various types of digital content resources such as e-books, music, movies, and design works. The average daily online active users exceed 4.2 million, and the peak of the system access request volume can reach about 180,000 times per hour. It has typical characteristics such as frequent access requests, rich data types, and variable user dynamic attributes.

[0140] In this platform, the traditional access control system mainly relies on centralized identity authentication and role-based permission management, and there are problems such as insufficient flexibility in access authorization, high decision-making delay, weak anti-counterfeiting of resource identification, and broken access audit chain. Especially during peak periods, the access control module is prone to become a system performance bottleneck, resulting in a decline in user experience and an increase in resource management risks. The present invention has carried out systematic deployment and verification for the above problems.

[0141] In the specific application process, the blockchain subsystem proposed by the present invention is first deployed at the platform data center node to store access behavior evidence data and manage DID identities. The system collects six types of key attribute information, including user role, geographical location, device type, login time period, resource type, and resource access level, and constructs a digital product data set and a user attribute data set. By introducing the ECDSA elliptic curve cryptography algorithm, the platform generates a corresponding key pair for each registered user and dynamically assigns DID identity identifiers based on user attributes. In the access request stage, the system digitally signs the request digest based on the user's private key to generate a signed access request structure, ensuring identity authentication and request integrity in the access link.

[0142] In the access control decision-making process, the system takes the collected user attribute data and resource attribute data as inputs, constructs a standard ABAC access control policy model, and introduces a Boolean logic optimization mechanism on this basis. For access control rules, the system implements three rounds of processing: Boolean simplification, logical short-circuit optimization, and path pruning, generating an optimized access control decision expression, which greatly improves the execution efficiency of the decision link. In the access verification stage, the platform verifies the authenticity of the access request signature, and then inputs the user attribute data into the optimized ABAC model for decision-making. If the decision is true, an access authorization token is generated and issued, which contains DID identity, resource identifier, access scope, and authorization time information.

[0143] All access behaviors, including request initiation, decision authorization, and access execution, are standardized and recorded by the system, and the access behavior hash value is generated using the SHA-256 algorithm, and then submitted to the blockchain ledger to achieve non-tamperable access evidence throughout the chain, forming a complete access audit evidence chain. The blockchain adopts a consortium chain architecture, and the nodes are jointly maintained by the platform main center, content distribution nodes, and cooperative institution servers to ensure efficient and stable data redundant storage and consensus mechanism.

[0144] During this verification period, the platform selects high-frequency access resources (such as popular film and television resources, best-selling e-books) and general access resources (such as niche design works) as test objects, and also covers user access request samples from different regions and different terminal devices (mobile terminals, PC terminals, smart TVs). To ensure the objectivity of the data, the test data is cross-verified through system logs and blockchain ledgers.

[0145] The verification results show that after the deployment of the present invention, the overall access control response time of the platform has decreased significantly. During the access request verification phase, the average response time has decreased from 184 ms in the traditional system to 112 ms, a reduction of nearly 39%; during peak hours (20:00 - 22:00 every day), the maximum processing capacity of the optimized access decision module reaches 510 requests per second, an increase of about 27% compared with the traditional method. The accuracy rate of resource access authorization has been increased to 99.92%, and the unauthorized access blocking rate has been increased to 99.98%. The number of digital product identity forgery incidents is zero during the verification cycle, and the authenticity of all key access behaviors has been verified through on-chain data, and the integrity rate of audit evidence collection reaches 100%.

[0146] In terms of resource access auditing, in the traditional system, due to the breakage of the recording chain in high-concurrency scenarios, the missing rate of audit data reaches 5.2%, while the system of the present invention realizes 0 missing through a complete access record chain, greatly improving the audit reliability. At the same time, in terms of security, through ECDSA signature protection, the present invention achieves a 100% success rate in preventing access request tampering, effectively blocking man-in-the-middle forged request attacks.

[0147] Overall, the present invention has achieved remarkable results in improving the real-time response ability of access control, enhancing the uniqueness authentication of digital products, preventing forgery and tampering, and improving the integrity of audit evidence collection, fully verifying the engineering feasibility and promotion value of the present invention in actual complex application scenarios.

[0148] Table 1 Comparison data of key performance of the access control system during platform deployment

[0149] Item Traditional method Method of the present invention Improvement rate Average access verification response time (ms) 184 112 39.1% Peak access processing capacity (times / second) 402 510 26.9% Accuracy rate of resource access authorization 98.7% 99.92% +1.22% Unauthorized access blocking rate 99.5% 99.98% +0.48% Integrity rate of audit evidence collection 94.8% 100% +5.2% Number of access forgery incidents 3 incidents / week 0 incidents / week Eliminate forgery Coverage rate of blockchain evidence storage records 92.3% 100% +7.7%

[0150] From the comparison data in Table 1 above, it can be seen that in the scenario of large-scale digital product distribution and access control, the present invention is significantly superior to the traditional centralized access control system in multiple key performance indicators, fully verifying its application value and engineering feasibility in an environment with high-frequency access and dynamically changing multi-source attributes. Specifically, in terms of the access verification response speed, by constructing an optimized Boolean logic ABAC decision link, the present invention has greatly shortened the access request processing time, and the average verification response time has decreased from 184 milliseconds in the traditional method to 112 milliseconds, a decrease of 39.1%. This improvement is particularly obvious during peak hours, effectively alleviating the system bottleneck caused by high-concurrency access and improving the overall user experience and platform service continuity.

[0151] In terms of access processing capabilities, the optimized access control module of the present invention has a peak processing capacity of 510 requests per second under high load conditions, which is a 26.9% increase compared to 402 requests of the traditional method. This shows that the present invention not only has advantages under static conditions but also can maintain efficient and stable access control output in a dynamic load-changing environment, demonstrating good system scalability and stress resistance.

[0152] In terms of the access authorization accuracy index, by introducing the DID identity identification and signature verification mechanism, the present invention has increased the resource access authorization accuracy from 98.7% of the traditional method to 99.92%, and the unauthorized access blocking rate has been further increased from 99.5% to 99.98%. This not only effectively reduces the risks of illegal access and resource abuse but also greatly enhances the protection of digital content resources and strengthens the overall data security guarantee system of the platform.

[0153] In terms of the integrity of audit evidence collection, through the blockchain on-chain evidence storage mechanism, the present invention completely records the entire access process from request initiation, decision authorization to access execution, successfully achieving a 100% audit data integrity rate, while the traditional method has a 5.2% data loss in high-concurrency scenarios. The complete audit chain greatly enhances the traceability of access behaviors and provides strong support for digital property protection and compliance auditing.

[0154] In terms of security, the present invention adopts the ECDSA signature mechanism to ensure the integrity and non-repudiation of access requests during transmission and verification. During the entire test cycle, no access forgery events occurred in the system of the present invention, while the traditional method had an average of 3 forgery attacks per week, showing the absolute advantage of the present invention in resisting forgery and tampering risks. At the same time, with a 100% on-chain evidence storage coverage rate, the present invention further ensures that all access behaviors have trustworthy and verifiable on-chain records, improving the anti-tampering and responsibility traceability system for the access process.

[0155] Generally speaking, through dynamic perception of user attributes, optimization of Boolean logic access decisions, ECDSA signature authentication, and blockchain evidence storage system, the present invention systematically improves the access control response speed, processing capacity, authorization accuracy, security, and audit integrity. In a complex, high-concurrency, and multi-source attribute-changing actual operating environment, the present invention demonstrates excellent stability and robustness. Compared with the traditional method, it not only comprehensively surpasses in performance indicators but also provides a higher-standard solution in terms of system security guarantee, data trustworthy protection, and responsibility traceability capabilities, laying a solid technical foundation for the intelligent upgrade of future digital resource management platforms in the fields of access control, security auditing, and compliance governance.

[0156] As described above, it is only a preferred specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution of the present invention and its inventive concept, makes equivalent substitutions or changes, and should be covered by the protection scope of the present invention.

Claims

1. A method for uniquely identifying digital products and controlling access rights based on blockchain, characterized in that, It includes the following steps: S1. Collect digital product data and access user attribute information, and construct a digital product data set and an access user attribute data set; S2. Based on the access user attribute data set, assign a decentralized identity identifier to the access user, and use the elliptic curve cryptography algorithm to generate an access user public key and an access user private key to form a key pair; S3. Based on the digital product data set and the access user attribute data set, generate a request digest value through the hash algorithm, and use the access user private key to perform an elliptic curve digital signature on the request digest value to generate a signed access request structure; S4. Construct an ABAC model, model the access user as an access request body with attribute observation and access decision-making capabilities, and formulate an access control policy rule set based on the digital product data set; S5. Introduce a Boolean operation optimization mechanism into the ABAC model, initialize multiple Boolean logic expression units, process the access control policy, and obtain an optimized ABAC model; S6. Verify the access request signature in the signed access request structure, input the access user attribute data set into the optimized ABAC model for matching judgment, and generate an access authorization token; S7. Based on the access authorization token, extract the access behavior and record it in the blockchain to implement the audit and traceability of the access process.

2. The method for uniquely identifying digital products and controlling access rights based on blockchain according to claim 1, wherein The digital product data set includes a resource identifier, a resource type, a security level, version information, and metadata information, and the access user attribute data set includes a role attribute, a geographical attribute, a device attribute, an access time attribute, and an optional dynamic attribute.

3. The method for uniquely identifying digital products and controlling access rights based on blockchain according to claim 1, characterized in that The specific content of S2 includes: S21. Based on the access user attribute data set, extract information including role attributes, geographical attributes, and device attributes, and construct an access user identity feature vector; S22. Concatenate the access user identity feature vector with the time stamp of the current generation moment, and process it through a decentralized identity generation hash function to generate a decentralized identity identifier of the access user: ; Among them, is the decentralized identity identifier of the accessing user, is the identifier namespace prefix, is the binary concatenation operator, is the first-layer encryption hash function, is the second-layer encryption hash function, is the access user identity feature vector, is the randomly generated encryption salt value, is the current system timestamp; S23. Based on the decentralized identity identifier of the access user, use the elliptic curve encryption algorithm to perform a scalar multiplication operation between the access user private key and the elliptic curve base point to generate a key pair of the access user, where the access user public key is the point coordinate obtained by multiplying the access user private key by the standard elliptic curve base point, forming a public key and private key pair exclusive to the access user; S24. Store the generated access user private key in the access user's local terminal device, and at the same time bind and register the generated access user public key with the decentralized identity identifier.

4. The method for uniquely identifying digital products and controlling access rights based on blockchain according to claim 1, wherein The specific content of S3 includes: S31. Extract the resource identifier from the digital product data set, extract the role attribute, geographical attribute, device attribute, and access time attribute from the access user attribute data set, arrange them in order, and combine them into an access request vector; S32. Use the access request vector as input data and pass it to the hash function. Through the hash algorithm, perform a one-way digest calculation on all field contents of the access request vector, including the resource identifier, role attribute, geographical attribute, device attribute, and access time attribute, and output the corresponding access request digest value; S33. Use the private key of the accessing user to perform an elliptic curve digital signature on the request digest value, and generate an access request signature through the elliptic curve digital signature algorithm; S34. Combine the decentralized identity identifier of the accessing user, the access request vector, the request digest value, the access request signature, and the accessing user attribute data set to construct a signed access request structure.

5. The method for uniquely identifying digital products and controlling access rights based on blockchain according to claim 4, wherein, The elliptic curve digital signature algorithm includes randomly selecting an integer greater than or equal to 1 and less than the order of the elliptic curve as the signature random number; subsequently, multiplying the random number by the base point of the elliptic curve to obtain a coordinate point on the elliptic curve; extracting the abscissa from the point coordinates and taking the modulus of the order of the elliptic curve to obtain the first component in the signature ; ; Calculate the second component in the signature : ; Among them, is the second component in the signature, is a random number in the modulo multiplicative inverse sense, is the access request digest value, is the access request vector, is the private key of the accessing user, is the accessing user, is the first component in the signature, is the modulo operation, is the elliptic curve order; Combine the first component in the signature and the second component in the signature to obtain the access request signature.

6. The method for uniquely identifying digital products and controlling access rights based on blockchain according to claim 1, characterized in that, The specific steps of S4 are as follows: S41. Model the accessing user as an access request body. The access request body has the capabilities of attribute observation and access decision-making. Based on the user attribute data set and the digital product data set, extract the role attribute, geographical attribute, device attribute, access time attribute, resource type attribute, and resource security level attribute, and combine them to form an attribute observation vector of the access request body; S42. According to the attribute observation vector of the access request body, set an initial attribute state value for each access request body. The initial state value is determined according to the real-time identity information, device state, geographical location, and time period classification of the user when the access request occurs; S43. Assign an access sensitivity parameter to the access request body according to the role attribute and the device attribute , when the role attribute is a system administrator and the device attribute is a trusted device , when the role attribute is an ordinary user and the device attribute is a trusted device , when the device attribute is a non-trusted device, regardless of the user role ; S44. Set an access confidence parameter for the access request body according to the geographical attribute and the access time attribute , when the geographical attribute is in a trusted area and the access time attribute is during working hours , when the geographical attribute is in an unknown area or the access time attribute is outside working hours , when the geographical attribute is in a high-risk area ; S45. Integrate the attribute observation vector of the access request body and the access sensitivity parameter with the access confidence parameter to form an access control feature vector; S46. Based on the access control feature vector, formulate access control policy rules according to the preset Boolean logic condition combination method, and generate an access control policy set according to the access decision result.

7. The method for uniquely identifying digital products and controlling access rights based on blockchain according to claim 1, wherein The specific steps of S5 are as follows: S51. Based on the access control attribute vector and the access control policy set, extract each access control policy rule, and convert the attribute combination condition in the access control policy rule into an initial Boolean logic expression; S52. Perform logical simplification on the initial Boolean logic expression, merge like terms and eliminate redundant logical conditions according to the Boolean algebra rules to obtain a simplified Boolean logic expression; S53. For the simplified Boolean logic expression, perform short-circuit optimization processing, rearrange the judgment path according to the probability order of attribute values, determine the access decision output in advance, and generate a short-circuit optimized Boolean logic expression; S54. Perform path pruning processing on the short-circuit optimized Boolean logic expression, delete redundant judgment nodes and unreachable paths, and generate a pruned Boolean logic expression; S55. Based on the pruned Boolean logic expression, perform performance evaluation according to the attribute matching complexity index and the access decision efficiency index, and screen out an optimized expression set that meets the optimal threshold; S56. Integrate the optimized expression set to form an optimized access control policy rule set, and update the ABAC model based on the optimized access control policy rule set to form an optimized ABAC model.

8. The method for uniquely identifying digital products and controlling access rights based on blockchain according to claim 1, wherein The specific steps of S6 are as follows: S61. Extract the centralized identity identifier, access request vector, request digest value, access request signature, and accessing user attribute data set contained in the signed access request structure, and combine them into an access request verification data packet; S62. Use the public key of the accessing user to verify the digital signature of the request digest value and the access request signature in the access request verification data packet. When the verification is successful, confirm that the access request source is trustworthy and the content has not been tampered with, and allow it to enter the attribute matching stage; otherwise, reject subsequent processing. S63. Verify the user attribute dataset and access request vector in the data packet according to the access request, construct an access request attribute observation vector, input it into the optimized ABAC model, and perform access decision judgment: ; Among them, is the matching decision result, is the result of access request signature verification, is the logical AND operator, is the logical OR operator, is the total number of rules in the optimized access control policy rule set, is the policy rule index variable, is the matching judgment function, is the attribute observation vector corresponding to the current access request, is the th access control policy Boolean logic expression after optimization; S64. If the matching decision result is true and the signature verification passes, generate an access authorization token.

9. The method for uniquely identifying digital products and controlling access rights based on blockchain according to claim 8, wherein, The generation of the access authorization token includes generating identity-resource binding data, generating an access authorization timestamp, and extracting the access permission scope; the generation of the identity-resource binding data is to extract the decentralized identity identifier and the resource identifier; Combine the decentralized identity identifier, the resource identifier, the access authorization timestamp, and the extracted access permission scope to generate an access authorization token.

10. The method for uniquely identifying digital products and controlling access rights based on blockchain according to claim 1, wherein, The specific steps of S7 are as follows: S71. Extract the decentralized identity identifier, the resource identifier, the access permission scope, the authorization timestamp, and the access decision result in the access authorization token, and combine them to form an access behavior basic information set; S72. After the access behavior is executed, collect the actual access timestamp when the access occurs, and merge the access behavior basic information set with the actual access timestamp to form an access behavior record data structure; S73. Perform a secure hash operation on the access behavior record data structure, and use the SHA-256 algorithm to generate an access behavior record hash value; S74. Based on the access behavior record hash value, combine the address information of the accessing user in the blockchain network and the current transaction generation time to construct a blockchain transaction data structure; S75. Broadcast the blockchain transaction data structure to the blockchain network, confirm it through the consensus mechanism of the blockchain system, and write it into the blockchain ledger to form an immutable access behavior evidence, realizing the complete audit and traceability of the access behavior.

Citation Information

Patent Citations

  • Attribute-based access control method and system based on blockchain

    CN113162907A

  • Digital object access control method and device

    CN115277242A

  • Internet of Things ciphertext access control method based on block chain

    CN117081803A

  • Distributed digital identity authentication method and system with privacy protection and access control

    CN119316156A

  • Distributed device identity authentication and access control method and system based on block chain

    CN119363318A