Access control method and device based on dynamic trusted network, terminal and storage medium
By querying the communication trust chain through a dynamic trust network, the problem of insufficient data security in traditional access control methods is solved, and a secure network access path and adaptive control are realized, thereby improving the security and responsiveness of network access.
Patent Information
- Application Number
- CN202511790414.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-01
- Publication Date
- 2026-02-27
AI Technical Summary
Traditional access control methods only verify device identity through permissions, which cannot guarantee that data will not be interfered with by external factors during the access process, thus reducing the security of network access.
A dynamic trust network is adopted to provide a secure access path by querying the communication trust chain between the first target device and the second target device, ensuring that the data is not interfered with by external factors during the access process.
It improves network access security, enables context-aware and behavior-driven adaptive access control, and enhances real-time response and defense capabilities against internal threats and abnormal access.
Smart Images

Figure CN121585442A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security. More particularly, the present application relates to a method and device for access control based on a dynamic trust network, a terminal and a storage medium. BACKGROUND
[0002] A conventional method for access control is to dynamically determine whether a first target device has the permission to access a second target device according to an access request of the first target device. If the first target device has the permission to access the second target device, feedback information is generated and sent to the first target device so that the first target device starts to access the second target device. If the first target device does not have the permission to access the second target device, access denial information is generated and sent to the first target device so as to deny the first target device to access the second target device. This method determines whether the first target device can access the second target device by permission. However, the permission determination can only verify the identity of the device and cannot guarantee that the data carried by the first target device when accessing the second target device is not interfered by the outside world, thereby reducing the security of network access. SUMMARY
[0003] The purpose of the embodiments of the present application is to provide a method and device for access control based on a dynamic trust network, a terminal and a storage medium, which can improve the security of network access. The embodiments of the present application mainly achieve the purpose by the following technical solutions: In a first aspect, the embodiments of the present application provide a method for access control based on a dynamic trust network, comprising: receiving a first access request sent by a first target device; querying and processing a communication trust chain of the first target device and a second target device in a dynamic trust network based on the first access request, to obtain a first target communication trust chain; sending the first target communication trust chain to the first target device, so that the first target device accesses the second target device through the first target communication trust chain.
[0004] According to an embodiment of the present application, the dynamic trust network at least includes a leader node, a plurality of group leader nodes, a first group member node corresponding to the first target device and a second group member node corresponding to the second target device. The plurality of group leader nodes are connected with the leader node. The first group member node is connected with a target group leader node. The second group member node is connected with any one of the plurality of group leader nodes except the target group leader node. The target group leader node is any one of the plurality of group leader nodes.
[0005] According to an embodiment of the present application, the number of nodes in the first target communication trust chain is greater than or equal to 3.
[0006] According to an embodiment of the present application, the step of querying and processing the communication trust chain between the first target device and the second target device in the dynamic trust network based on the first access request to obtain the first target communication trust chain comprises: parsing and processing the first access request to obtain first ID information corresponding to the first target device and second ID information corresponding to the second target device; querying and processing the communication trust chain between the first target device and the second target device in the dynamic trust network based on the first ID information and the second ID information using a policy information point of a policy framework to obtain the first target communication trust chain.
[0007] According to an embodiment of the present application, after the step of querying and processing the communication trust chain between the first target device and the second target device in the dynamic trust network based on the first access request to obtain the first target communication trust chain, the access control method based on the dynamic trust network further comprises: performing logical evaluation processing on the first target communication trust chain using a policy rule to obtain a first evaluation result.
[0008] According to an embodiment of the present application, after the step of sending the first target communication trust chain to the first target device to enable the first target device to access the second target device through the first target communication trust chain, the access control method based on the dynamic trust network further comprises: receiving a second access request sent by the first target device; querying and processing the communication trust chain between the first target device and a third target device in the dynamic trust network based on the second access request to obtain a second target communication trust chain; updating the dynamic trust network based on the second target communication trust chain and the second access request.
[0009] According to an embodiment of the present application, the step of updating the dynamic trust network based on the second target communication trust chain and the second access request comprises: parsing and processing the second access request to obtain third ID information corresponding to the third target device; In the case where the second target communication trust chain is without a communication trust chain, the third ID information is connected as a third member node to any group leader node in the dynamic trust network according to a preset rule, or the third ID information is connected as a member child node to a target member node in the dynamic trust network. The number of member nodes corresponding to the group leader node connected to the target member node meets a preset number, and the target member node is any member node in the dynamic trust network.
[0010] A second aspect of this application provides an access control device based on a dynamic trust network, comprising: The receiving module is used to receive the first access request sent by the first target device; The query module is used to query the communication trust chain between the first target device and the second target device in the dynamic trust network based on the first access request, and obtain the first target communication trust chain. The sending module is used to send the first target communication trust chain to the first target device, so that the first target device can access the second target device through the first target communication trust chain.
[0011] A third aspect of this application provides a terminal device, including a processor and a memory, wherein the memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory to perform the steps of the access control method based on a dynamic trust network provided in the first aspect of this application.
[0012] A fourth aspect of this application provides a computer-readable storage medium for storing a computer program that causes a computer to perform the steps of the access control method based on a dynamic trust network provided in the first aspect of this application.
[0013] The beneficial effects of the embodiments of this application include: This application embodiment designs a dynamic trust network that provides a secure communication trust chain for a first target device. Specifically, this application embodiment receives a first access request sent by the first target device; based on the first access request, it queries the communication trust chain between the first target device and a second target device in the dynamic trust network to obtain a first target communication trust chain; and sends the first target communication trust chain to the first target device, enabling the first target device to access the second target device through the first target communication trust chain. Therefore, compared with the prior art that only determines whether the first target device can access the second target device through permissions, this application embodiment can provide the first target device with a secure (i.e., trustworthy) first target communication trust chain, enabling the first target device to securely access the second target device. This effectively ensures that the data carried by the first target device when accessing the second target device is not interfered with by external factors, thereby improving the security of network access. Attached Figure Description
[0014] To more clearly illustrate the technical solutions in the embodiments of this application or the conventional technology, the drawings used in the description of the embodiments or the conventional technology will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0015] Figure 1 The flowcharts for some embodiments of the access control method based on dynamic trust networks of this application are shown below. Figure 2 The following is a reference diagram for some embodiments of the dynamic trust network of this application; Figure 3 Reference diagrams for the dynamic trust network of this application in other embodiments; Figure 4 Reference diagrams for the dynamic trust network of this application in some further embodiments; Figure 5 Reference diagrams for the dynamic trust network of this application in some further embodiments; Figure 6 Reference diagrams for the dynamic trust network of this application in some further embodiments; Figure 7 Reference diagrams for the dynamic trust network of this application in some further embodiments; Figure 8 This is a block diagram illustrating the principle of the access control device based on a dynamic trust network in some embodiments of this application. Figure 9 This is a schematic block diagram of the terminal device of this application in some embodiments. Detailed Implementation
[0016] To make the above-mentioned objectives, features, and advantages of this application more apparent and understandable, the specific embodiments of this application are described in detail below with reference to the accompanying drawings. Many specific details are set forth in the following description to provide a thorough understanding of this application. However, this application can be implemented in many other ways different from those described herein, and those skilled in the art can make similar modifications without departing from the spirit of this application. Therefore, this application is not limited to the specific embodiments disclosed below.
[0017] It should be noted that the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this application, "multiple" means at least two, such as two, three, etc., unless otherwise explicitly specified.
[0018] The terms "exemplary" or "for example" are used to indicate that something is an example, illustration, or illustration. Any embodiment or design described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of terms such as "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.
[0019] The terms “comprising,” “including,” or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, system, product, or apparatus that includes a series of steps or units is not necessarily limited to those steps or units that are expressly listed, but may include other steps or units that are not expressly listed or that are inherent to such process, method, product, or apparatus.
[0020] Unless otherwise defined, all technical and scientific terms used in this application have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The term "and / or" as used in this application includes any and all combinations of one or more of the associated listed items.
[0021] The specific embodiments of this application will be further described below with reference to the accompanying drawings.
[0022] refer to Figure 1 The diagram shown is a flowchart of an access control method based on a dynamic trust network provided in the first aspect of an embodiment of this application. Figure 1 The access control method based on a dynamic trust network includes: S1. Receive the first access request sent by the first target device.
[0023] The first target device can be a computer, tablet, or mobile phone, etc.
[0024] The first access request includes a first ID information corresponding to the first target device and a second ID information corresponding to the second target device. The first access request is used to query whether the first target device can access the second target device. The access behavior can be understood as a contact behavior, a communication connection behavior, or a data communication behavior.
[0025] The second target device can be a computer, tablet, or mobile phone.
[0026] S2. Based on the first access request, query the communication trust chain between the first target device and the second target device in the dynamic trust network to obtain the first target communication trust chain.
[0027] The dynamic trust network includes at least a leader node, multiple group leader nodes, a first group member node corresponding to the first target device, and a second group member node corresponding to the second target device. The multiple group leader nodes are all connected to the leader node, the first group member node is connected to the target group leader node, and the second group member node is connected to any one of the multiple group leader nodes except the target group leader node. The target group leader node is any one of the multiple group leader nodes.
[0028] For details regarding the dynamic trust network, please refer to Example 1 and Example 2 below.
[0029] Example 1, for reference Figure 2 As shown, the dynamic trust network includes a leader node A, M group leader nodes, a first group member node C1 corresponding to the first target device, and a second group member node C2 corresponding to the second target device. The M group leader nodes are all connected to the leader node A, and the first group member node C1 and the second group member node C2 are both connected to the first group leader node B1.
[0030] Example 2, see reference Figure 3 As shown, the dynamic trust network includes a leader node A, M group leader nodes, a first group member node C1 corresponding to the first target device, and a second group member node D1 corresponding to the second target device. The M group leader nodes are all connected to the leader node A, the first group member node C1 is connected to the first group leader node B1, and the second group member node D1 is connected to the second group leader node B2.
[0031] In the two examples above, M is the total number of group leader nodes, and M is 20. In other embodiments, the value of M can be set by those skilled in the art according to actual needs.
[0032] In other embodiments, the specific content of the dynamic trust network can be set in other forms, which can be set by those skilled in the art according to actual needs.
[0033] Furthermore, the number of nodes in the first target communication trust chain is greater than or equal to 3.
[0034] The first target communication trust chain can be C1-B1-C2 (see reference). Figure 2 As shown in the figure, that is, the first member node - the first leader node - the second member node.
[0035] The first target communication trust chain can also be C1-B1-A-B2-D1 (see reference). Figure 3 As shown in the figure, that is, the first group member node - the first group leader node - the leader node - the second group leader node - the second group member node.
[0036] In other embodiments, the first target communication trust chain can also be other communication trust chains, which can be set by those skilled in the art according to actual needs.
[0037] Further, step S2 includes: parsing the first access request to obtain the first ID information corresponding to the first target device and the second ID information corresponding to the second target device; using a policy information point of a policy architecture to query the communication trust chain between the first target device and the second target device in the dynamic trust network based on the first ID information and the second ID information to obtain the first target communication trust chain.
[0038] The first ID information and the second ID information are static attribute information.
[0039] The strategy architecture includes strategy decision points, strategy execution points, strategy information points, and the service interface of the dynamic trust network.
[0040] The policy execution point is used to intercept the first access request after the terminal device receives the first access request, and send the first access request to the policy decision point.
[0041] The policy decision point is used to receive the first access request sent by the policy execution point, and to parse the first access request to obtain the first ID information corresponding to the first target device and the second ID information corresponding to the second target device.
[0042] The policy information point is used to query the communication trust chain between the first target device and the second target device in the dynamic trust network based on the first ID information and the second ID information, so as to obtain the first target communication trust chain.
[0043] The policy information point communicates with the dynamic trust network through the service interface.
[0044] Furthermore, the step of using the policy information point of the policy architecture to query the communication trust chain between the first target device and the second target device in the dynamic trust network based on the first ID information and the second ID information to obtain the first target communication trust chain includes: using the policy information point to obtain the first dynamic attribute corresponding to the first ID information and the second dynamic attribute corresponding to the second ID information; if both the first dynamic attribute and the second dynamic attribute are valid, the following steps are performed: searching for the node corresponding to the first ID information and the node corresponding to the second ID information in the dynamic trust network, and taking the connection path where the node corresponding to the first ID information and the node corresponding to the second ID information are located as the first target communication trust chain.
[0045] The first dynamic attribute includes the certificate validity, key matching status, and IP reputation corresponding to the first ID information.
[0046] The second dynamic attribute includes the certificate validity, key matching status, and IP reputation corresponding to the second ID information.
[0047] S3. Send the first target communication trust chain to the first target device so that the first target device can access the second target device through the first target communication trust chain.
[0048] It should be understood that the step of "the first target device accessing the second target device through the first target communication trust chain" can be understood as the first target device communicating with the second target device through the first target communication trust chain.
[0049] Through the above implementation methods, the embodiments of this application can provide a secure (i.e. trustworthy) first target communication trust chain for the first target device, so that the first target device can securely access the second target device, effectively ensuring that the data carried by the first target device when accessing the second target device is not interfered with by the outside world, thereby improving the security of network access.
[0050] The embodiments of this application can also realize context-aware, behavior-driven adaptive access control, which effectively improves the method's real-time response and defense capabilities against internal threats and abnormal access.
[0051] The access control method based on dynamic trust networks can be applied to terminal devices or servers. The terminal devices can be computers, tablets, mobile phones, etc.
[0052] In some implementations, after step S2, the access control method based on a dynamic trust network further includes: performing a logical evaluation on the first target communication trust chain using policy rules to obtain a first evaluation result.
[0053] Further, the step of performing logical evaluation processing on the first target communication trust chain using policy rules to obtain a first evaluation result includes: performing role identification processing on the node corresponding to the first ID information in the first target communication trust chain to obtain a first identification result; performing resource sensitivity identification processing on the node corresponding to the first ID information in the first target communication trust chain to obtain a second identification result; performing trust level identification processing on the first target communication trust chain to obtain a third identification result; and obtaining the first evaluation result based on the first identification result, the second identification result, and the third identification result.
[0054] Further, the step of obtaining the first evaluation result based on the first identification result, the second identification result, and the third identification result includes: if the first identification result, the second identification result, and the third identification result all meet the first preset condition, the first evaluation result is to allow the first target device to access the second target device based on the first target communication trust chain; if the first identification result, the second identification result, and / or the third identification result do not meet the first preset condition, the first evaluation result is to deny the first target device from accessing the second target device based on the first target communication trust chain.
[0055] The first preset condition is that the first identification result is "role is employee", the second identification result is "high resource sensitivity", and the third identification result is "trust level greater than 1". In other embodiments, the first preset condition can also be other preset conditions, which can be set by those skilled in the art according to actual needs.
[0056] In this application embodiment, trust level is used to evaluate the first evaluation result (which can be understood as using trust level as a decision attribute), which enables the access rights of the first target device to be dynamically adjusted according to the entity's behavior reputation.
[0057] This application introduces uncertainty to evaluate the first evaluation result, enabling a conservative strategy to be adopted when information is insufficient, thereby improving security.
[0058] Furthermore, the step of performing logical evaluation processing on the first target communication trust chain using policy rules to obtain the first evaluation result includes: performing uncertainty identification processing on the node corresponding to the first ID information in the first target communication trust chain to obtain a fourth identification result; and combining the fourth identification result with the first identification result, the second identification result, and the third identification result to obtain the first evaluation result.
[0059] Further, the step of combining the fourth identification result with the first identification result, the second identification result, and the third identification result to obtain the first evaluation result includes: if the first identification result, the second identification result, the third identification result, and the fourth identification result all meet the second preset condition, the first evaluation result is to allow the first target device to access the second target device based on the first target communication trust chain; if the first identification result, the second identification result, the third identification result, and / or the fourth identification result do not meet the second preset condition, the first evaluation result is to deny the first target device from accessing the second target device based on the first target communication trust chain.
[0060] The second preset condition is that the first identification result is "role is employee", the second identification result is "high resource sensitivity", the third identification result is "trust level greater than 1", and the fourth identification demerit is "uncertainty less than 2". In other embodiments, the second preset condition can also be other preset conditions, which can be set by those skilled in the art according to actual needs.
[0061] In some implementations, after step S2, the access control method based on a dynamic trust network further includes: using policy rules to perform logical evaluation processing on the static attributes and the first target communication trust chain to obtain a second evaluation result.
[0062] In some implementations, the access control method based on a dynamic trust network further includes: returning the first evaluation result or the second evaluation result to the policy enforcement point for execution.
[0063] In some implementations, after step S3, the access control method based on a dynamic trust network further includes: receiving a second access request sent by the first target device; querying the communication trust chain between the first target device and the third target device in the dynamic trust network based on the second access request to obtain a second target communication trust chain; and updating the dynamic trust network based on the second target communication trust chain and the second access request.
[0064] The second access request includes the first ID information and the third ID information corresponding to the third target device. The second access request is used to query whether the first target device can access the third target device.
[0065] The third target device can be a computer, tablet, or mobile phone, etc.
[0066] Further, the step of updating the dynamic trust network based on the second target communication trust chain and the second access request includes: parsing the second access request to obtain the third ID information corresponding to the third target device; when the second target communication trust chain is without a communication trust chain, connecting the third ID information as a third member node to any group leader node in the dynamic trust network according to a preset rule, or connecting the third ID information as a member child node to a target member node in the dynamic trust network, wherein the number of member nodes corresponding to the group leader node connected to the target member node meets a preset number, and the target member node is any member node in the dynamic trust network.
[0067] Furthermore, the preset rule is random or based on the order of group member nodes. In other embodiments, the preset rule can also be other rules, which can be set by those skilled in the art according to actual needs.
[0068] Furthermore, when the preset rule is based on the order of group member nodes, the step of "connecting the third ID information as the third group member node with any group leader node in the dynamic trust network" can be "connecting the third ID information as the third group member node with the group leader node corresponding to the first group member node".
[0069] For example, refer to Figure 4 As shown, the third ID information is used as the third member node C3 and connected to the group leader node B1 corresponding to the first member node C1. Figure 4 The meanings of the other symbols in the text can be found in the reference section. Figure 2 The meaning of the superscript number.
[0070] Furthermore, when the preset rule is random, the step of "connecting the third ID information as a third member node to any group leader node in the dynamic trust network" can also be "connecting the third ID information as a third member node to a third group leader node".
[0071] For example, refer to Figure 5 As shown, the third ID information is used as the third member node E1 and connected to the third leader node B3. Figure 5 The meanings of the other symbols in the text can be found in the reference section. Figure 2 The meaning of the superscript number.
[0072] Furthermore, the step of connecting the third ID information as a group member child node to the target group member node in the dynamic trust network, wherein the number of group member nodes corresponding to the group leader node connected to the target group member node meets a preset number, and the target group member node is any group member node in the dynamic trust network can be implemented through the following Examples 3 and 4.
[0073] Example 3, for reference Figure 6 As shown, taking the target member node as the first member node as an example, in this embodiment of the application, the third ID information is used as a member child node F1 and connected to the first member node C1. The number of member nodes corresponding to the first group leader node B1 connected to the first member node C1 satisfies a preset number N. Figure 6 In this context, CN is the Nth member node corresponding to the first group leader node B1. Figure 6 The meanings of other symbols in the text are the same as those in the text. Figure 2 The meanings referred to by the numbers are the same. It should also be understood that after the group member child node F1 is added to the dynamic trust network, all group leader nodes are promoted to clan leader nodes, and all group member nodes are promoted to group leader nodes.
[0074] Example 4, Reference Figure 7 As shown, taking the target member node as the second member node as an example, in this embodiment of the application, the third ID information is used as a member child node F1 and connected to the second member node D1. The number of member nodes corresponding to the second group leader node B2 connected to the second member node D1 satisfies a preset number N. Figure 7 In this context, DN is the Nth member node corresponding to the second group leader node B2, and D2 is the second member node corresponding to the second group leader node B2. Figure 7 The meanings of other symbols in the text are the same as those in the text. Figure 3The meanings referred to by the numbers are the same. It should also be understood that after the group member child node F1 is added to the dynamic trust network, all group leader nodes are promoted to clan leader nodes, and all group member nodes are promoted to group leader nodes.
[0075] In other embodiments, the third ID information is used as a member sub-node to connect with the target member node in the dynamic trust network. The number of member nodes corresponding to the group leader node connected to the target member node meets a preset number. The step of the target member node being any member node in the dynamic trust network can also be implemented in other ways. Specifically, it can be set by those skilled in the art according to actual needs.
[0076] The preset quantity is 10. In other embodiments, the preset quantity can also be other values, which can be set by those skilled in the art according to actual needs.
[0077] Further, the step of querying the communication trust chain between the first target device and the third target device in the dynamic trust network based on the second access request to obtain the second target communication trust chain includes: using the policy information point to query the communication trust chain between the first target device and the third target device in the dynamic trust network based on the first ID information and the third ID information to obtain the second target communication trust chain.
[0078] Further, the step of using the policy information points to query the communication trust chain between the first target device and the third target device in the dynamic trust network based on the first ID information and the third ID information to obtain the second target communication trust chain includes: using the policy information points to obtain the third dynamic attribute corresponding to the first ID information and the fourth dynamic attribute corresponding to the third ID information; if both the third dynamic attribute and the fourth dynamic attribute are valid, the following steps are performed: searching for the node corresponding to the first ID information and the node corresponding to the third ID information in the dynamic trust network, and taking the connection path where the node corresponding to the first ID information and the node corresponding to the third ID information are located as the second target communication trust chain; if there is no connection path where the node corresponding to the first ID information and the node corresponding to the third ID information are located, then no communication trust chain is taken as the second target communication trust chain.
[0079] The third dynamic attribute is the same as the first dynamic attribute.
[0080] The fourth dynamic attribute includes the certificate validity, key matching status, and IP reputation corresponding to the third ID information.
[0081] In some implementations, the access control method based on dynamic trust networks provided in this application can be integrated as a software module into existing ABAC (Attribute-Based Access Control) or zero-trust architectures. It can also be encapsulated as an independent microservice in a microservice architecture, where dynamic trust queries and access decisions are encapsulated.
[0082] In some implementations, the dynamic trust network can be implemented and updated using blockchain or distributed ledger technology to enhance decentralization.
[0083] refer to Figure 8 The diagram shown is a schematic block diagram of an access control device based on a dynamic trust network, provided in the second aspect of an embodiment of this application. Figure 8 The access control device 100 based on a dynamic trust network includes: The receiving module 101 is used to receive a first access request sent by the first target device; The query module 102 is used to query the communication trust chain between the first target device and the second target device in the dynamic trust network based on the first access request, and obtain the first target communication trust chain. The sending module 103 is used to send the first target communication trust chain to the first target device, so that the first target device can access the second target device through the first target communication trust chain.
[0084] A third aspect of this application provides a terminal device, the schematic diagram of which is as follows: Figure 9 As shown. The terminal device includes a processor, memory, network interface, display screen, and temperature sensor connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The network interface of the terminal device is used for communication with external terminals via a network connection. When the computer program is executed by the processor, it implements an access control method based on a dynamic trust network. The display screen can be a liquid crystal display (LCD) or an e-ink display. The temperature sensor is pre-installed inside the terminal device to detect the operating temperature of the internal components.
[0085] Those skilled in the art will understand that Figure 9The schematic diagram shown is only a partial structural diagram related to the present invention and does not constitute a limitation on the terminal device to which the present invention is applied. The specific terminal device may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements.
[0086] In some embodiments, this application provides a terminal device, which includes a processor and a memory for storing computer programs. The processor is used to call and run the computer programs stored in the memory to perform the steps of the access control method based on a dynamic trust network provided in the first aspect of this application.
[0087] A fourth aspect of this application provides a computer-readable storage medium for storing a computer program that causes a computer to perform the steps of the access control method based on a dynamic trust network provided in the first aspect of this application.
[0088] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided by this invention can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0089] The technical features of the above embodiments can be combined without changing the basic principles of this application. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0090] The above embodiments merely illustrate several implementation methods of this application, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the patent protection scope of this application should be determined by the appended claims.
Claims
1. An access control method based on a dynamic trust network, characterized in that, include: Receive the first access request sent by the first target device; Based on the first access request, the communication trust chain between the first target device and the second target device is queried in the dynamic trust network to obtain the first target communication trust chain. The first target communication trust chain is sent to the first target device so that the first target device can access the second target device through the first target communication trust chain.
2. The access control method based on a dynamic trust network according to claim 1, characterized in that, The dynamic trust network includes at least a leader node, multiple group leader nodes, a first group member node corresponding to the first target device, and a second group member node corresponding to the second target device. The multiple group leader nodes are all connected to the leader node, the first group member node is connected to the target group leader node, and the second group member node is connected to any one of the multiple group leader nodes except the target group leader node. The target group leader node is any one of the multiple group leader nodes.
3. The access control method based on a dynamic trust network according to claim 1, characterized in that, The number of nodes in the first target communication trust chain is greater than or equal to 3.
4. The access control method based on a dynamic trust network according to claim 1, characterized in that, The steps of querying the communication trust chain between the first target device and the second target device in the dynamic trust network based on the first access request to obtain the first target communication trust chain include: The first access request is parsed to obtain the first ID information corresponding to the first target device and the second ID information corresponding to the second target device. The policy information point using the policy architecture queries the communication trust chain between the first target device and the second target device in the dynamic trust network based on the first ID information and the second ID information to obtain the first target communication trust chain.
5. The access control method based on a dynamic trust network according to claim 1, characterized in that, After the step of querying the communication trust chain between the first target device and the second target device in the dynamic trust network based on the first access request to obtain the first target communication trust chain, the access control method based on the dynamic trust network further includes: The first target communication trust chain is logically evaluated using policy rules to obtain the first evaluation result.
6. The access control method based on a dynamic trust network according to claim 1, characterized in that, After the step of sending the first target communication trust chain to the first target device so that the first target device can access the second target device through the first target communication trust chain, the access control method based on the dynamic trust network further includes: Receive the second access request sent by the first target device; Based on the second access request, the communication trust chain between the first target device and the third target device is queried in the dynamic trust network to obtain the second target communication trust chain. The dynamic trust network is updated based on the second target communication trust chain and the second access request.
7. The access control method based on a dynamic trust network according to claim 6, characterized in that, The steps for updating the dynamic trust network based on the second target communication trust chain and the second access request include: The second access request is parsed to obtain the third ID information corresponding to the third target device; In the case where the second target communication trust chain is without a communication trust chain, the third ID information is connected as a third member node to any group leader node in the dynamic trust network according to a preset rule, or the third ID information is connected as a member child node to a target member node in the dynamic trust network. The number of member nodes corresponding to the group leader node connected to the target member node meets a preset number, and the target member node is any member node in the dynamic trust network.
8. An access control device based on a dynamic trust network, characterized in that, include: The receiving module is used to receive the first access request sent by the first target device; The query module is used to query the communication trust chain between the first target device and the second target device in the dynamic trust network based on the first access request, and obtain the first target communication trust chain. The sending module is used to send the first target communication trust chain to the first target device, so that the first target device can access the second target device through the first target communication trust chain.
9. A terminal device, characterized in that, include: A processor and a memory, the memory being used to store a computer program, the processor being used to invoke and run the computer program stored in the memory, performing the steps of the access control method based on a dynamic trust network as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, Used to store a computer program that causes a computer to perform the steps of the access control method based on a dynamic trust network as described in any one of claims 1 to 7.