Campus digital asset access control method and system of dynamic permission blockchain
By constructing a multi-dimensional permission verification payload and anonymous overlay replacement, combined with the targeted delivery and smart contract parsing of the campus alliance blockchain, dynamic verification credentials are generated and temporary authorization tokens are minted. This solves the problems of permission rules not being able to be changed in real time and the verification process being cumbersome in existing technologies, and achieves efficient and secure access control of campus digital assets.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- TIANJIN JUNYAN TECH CO LTD
- Filing Date
- 2026-04-28
- Publication Date
- 2026-05-29
AI Technical Summary
In existing campus digital asset access control solutions, permission rules cannot be changed in real time according to user access scenarios, identity identifiers are transmitted in plaintext, leading to information leakage and malicious tampering. Furthermore, permission verification transaction data packets lack a precise routing and delivery mechanism, the verification process is cumbersome and time-consuming, temporary authorizations are not bound to one-time session keys, there is no local persistent caching synchronization strategy, and the stability and controllability of authorization credentials are poor.
Construct a multi-dimensional permission verification payload and complete the anonymous overwriting replacement of the original identifier. Relying on the unique target sub-chain of the campus alliance blockchain, complete the targeted delivery of the permission verification transaction package. Based on the routing mapping record, perform smart contract parsing, generate dynamic verification pass credentials, and mint temporary authorization tokens strongly bound to the one-time session key. Simultaneously complete token issuance and local persistent caching.
It achieves privacy protection for user and asset identifiers, a precise and stable permission verification process, improves the execution efficiency and reliability of access control credentials, and forms a complete and traceable authorization token stub, realizing dynamic and refined authorization management of campus digital assets.
Smart Images

Figure CN122120036A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data processing technology, and in particular to a method and system for access control of campus digital assets using dynamic permission blockchain. Background Technology
[0002] Current access control for campus digital assets generally adopts a static permission management model. The permission rules cannot be changed in real time according to the user's access scenario, and the identity identifier is transmitted and verified in plaintext, which makes it easy for information leakage and malicious tampering to occur, making it difficult to guarantee the identity security of the campus digital asset access process.
[0003] Traditional access control schemes do not rely on the campus alliance blockchain to build a sub-chain targeted verification system. The data packets for permission verification transactions lack a precise routing and delivery mechanism. The verification process is cumbersome and time-consuming. Temporary authorizations are not bound to one-time session keys and there is no local persistent caching synchronization strategy. The stability and controllability of authorization credentials are poor, making it impossible to achieve efficient and secure dynamic access control of campus digital assets. Summary of the Invention
[0004] This invention provides a method and system for access control of campus digital assets using dynamic permission blockchain, in order to solve the problems mentioned in the background art.
[0005] To achieve the above objectives, this invention provides a campus digital asset access control method based on dynamic permission blockchain, comprising: Pt.1 After informing and obtaining the target user's consent, receive the target user's access request, combine the original access data packet of the access request with the target user's user identifier and the target campus's asset identifier to obtain the target campus's multi-dimensional permission verification payload. Pt.2. Based on the anonymous user identifier and anonymous asset identifier in the multi-dimensional permission verification payload, the original identifiers of the multi-dimensional permission verification payload are overwritten and replaced to obtain the permission verification transaction data packet of the target campus. Pt.3. Directly deliver the authorization verification transaction package to the unique target sub-chain of the campus alliance blockchain in the target campus to obtain the routing mapping record of the target campus; Pt.4. Based on the routing mapping record, perform smart contract parsing on the permission verification transaction package to obtain the dynamic verification pass certificate of the target campus; Pt.5. Based on the validity period mapped by the current permission level in the dynamic verification credentials, a temporary authorization token strongly bound to the one-time session key is forged. The temporary authorization token is then sent to the asset gateway of the target campus and a copy is synchronized to the local persistent cache to obtain the authorization token stub of the target campus.
[0006] In a preferred embodiment, after informing and obtaining the target user's consent, the step of receiving the target user's access request, combining the original access data packet of the access request with the target user's user identifier and the target campus's asset identifier, yields a multi-dimensional permission verification payload for the target campus, including: Extract the target user's user identifier and the target campus's asset identifier from the specified fields in the request message to obtain the target campus's temporary identity credential pair; Based on the temporary identity credential pair, the target user's current geolocation tag, device hardware fingerprint, network access point identifier, action feature code of the most recent operation, and timestamp of the request are captured and encapsulated to obtain the original context-attached data packet of the target campus. The user identifier and asset identifier in the temporary identity credential pair are sequentially concatenated with the geolocation tag, device hardware fingerprint, network access point identifier, action signature code and timestamp in the original context attached data packet to obtain the multi-dimensional permission verification payload of the target campus.
[0007] In a preferred embodiment, the original identifiers of the multi-dimensional permission verification payload are overwritten and replaced based on the user anonymity identifier and asset anonymity identifier in the multi-dimensional permission verification payload to obtain the permission verification transaction data packet of the target campus, including: The multi-dimensional permission verification payload is parsed to obtain the original identifier field group and context parameter field group of the target campus; Anonymize and replace the original user identifiers in the original identifier field group to obtain anonymous user identifiers for the target campus. The original asset identifiers of the original identifier field group are hashed and obfuscated to obtain the anonymous asset identifiers of the target campus. Based on anonymous user identifiers and anonymous asset identifiers, the original identifier field group is overwritten to obtain the complete payload of the target campus; The complete payload is encapsulated in a transaction format and a timestamp of the current operation is added to obtain the target campus's authorization verification transaction data packet.
[0008] In a preferred embodiment, the step of anonymizing and replacing the original user identifier in the original identifier field group to obtain the anonymous user identifier includes: The last segment of the binary string in the user's original identifier is extracted as the permutation seed to obtain the initial permutation vector of the target campus. Based on the initial permutation vector and the preset irreversible character mapping table, the characters in the user's original identifier are permuted in a single round to obtain the first permutation identifier of the target campus; Using the first permutation identifier as a feedback parameter, a second round of mapping and permutation is performed on the irreversible character mapping table after dynamic offsetting, to obtain the anonymous identifier of the target campus user.
[0009] In a preferred embodiment, the step of using the first-round permutation identifier as a feedback parameter to dynamically offset the irreversible character mapping table and then performing a second round of mapping permutation to obtain the anonymous user identifier of the target campus includes: Extract the lower eight bits of the first permutation identifier as the first offset factor, and extract the higher eight bits of the first permutation identifier as the second offset factor. Based on the preset mapping table length constant and perturbation basis constant, the dynamic offset is calculated according to the following formula: ; In the formula, This is a dynamic offset. This represents the value of the first offset factor. This represents the value of the second offset factor. Let be the perturbation basis constant. The length of the mapping table is a constant. This indicates a left shift by two bits. This indicates a bitwise XOR operation. This represents the modulo operation; Based on the dynamic offset, the character mapping entries in the irreversible character mapping table are cyclically shifted to the left in the irreversible character mapping table, with the shift step size equal to the dynamic offset, to obtain the offset mapping table of the target campus. Based on the offset mapping table, the characters in the first permutation identifier are sequentially mapped and permuted in the second round to obtain the anonymous user identifier of the target campus.
[0010] In a preferred embodiment, the step of directing the authorization verification transaction packet to the unique target sub-chain of the campus consortium blockchain in the target campus to obtain the routing mapping record of the target campus includes: The authorization verification transaction packet is unpacked according to the protocol to obtain the identity fingerprint string of the target campus. The high-order prefix segment of the identity fingerprint string is extracted as the routing key value. The sub-chain routing table in the blockchain gateway of the target campus is queried to obtain the sub-chain location record of the target campus. The sub-links are mapped by a mapping table that records the mapping relationship between different high-order prefix segments and the network addresses of the parallel verification sub-links. Based on the network address of the unique target subchain in the subchain location record, the authorization verification transaction packet is reconstructed into a transaction commit frame that conforms to the subchain communication specification, and then pushed to the unique target subchain network address in a one-way manner to obtain the routing mapping record of the target campus.
[0011] In a preferred embodiment, the step of parsing the authorization verification transaction packet based on the routing mapping record to obtain the dynamic verification pass credential for the target campus includes: The fields of the authorization verification transaction package are destructured to obtain the verification element tuple of the target campus; Based on the user anonymous identifier in the authentication element tuple of the authentication transaction package, obtain the dynamic policy record associated with the user anonymous identifier in the state database of the routing mapping record, and obtain the policy record object of the target campus. Perform a Boolean state check on the permission revocation flag in the policy record object; If the permission revocation flag is true, then the subsequent operations are terminated and a verification rejection credential is generated; If false, continue to perform time window membership detection on the timestamp of the verification element tuple to determine whether the timestamp falls within the range of the valid time window, and obtain the time window detection pass flag of the target campus; Under the premise that the time window detection pass flag is true, extract the on-chain dynamic permission factor copy from the policy record object, perform string conversion mapping on the on-chain dynamic permission factor copy, and obtain the on-chain comparison hash digest of the target campus. The on-chain comparison hash digest is compared with the permission verification hash digest in the verification element tuple. If the comparison is consistent, the dynamic verification pass credential for the target campus is obtained.
[0012] In a preferred embodiment, the step of forging a temporary authorization token strongly bound to a one-time session key based on the validity period mapped from the current permission level in the credential through dynamic verification, issuing the temporary authorization token to the asset gateway of the target campus, and synchronizing a copy to the local persistent cache to obtain the authorization token stub of the target campus includes: Based on the current permission level of the credentials through dynamic verification, the preset level-duration mapping table is accessed to obtain the effective duration value of the target campus. The dynamic verification is achieved by binding the one-time session key of the credential with the validity period value to obtain a temporary authorization token for the target campus. Create an authorization record entry in the authorization cache of the target campus; Based on the temporary authorization token, the temporary authorization token is written into the token field of the authorization record entry to obtain the gateway-side authorization record of the target campus; Synchronize a complete copy of the temporary authorization token to the token stub table of the target campus to obtain the authorization token stub of the target campus.
[0013] In a preferred embodiment, the step of binding and assembling the one-time session key of the dynamic verification credential with a validity period value to obtain a temporary authorization token for the target campus includes: Extract the first part of the binary string in the one-time session key as the binding header identifier, and extract the last part of the binary string in the one-time session key as the binding tail verification; The binding header identifier, the binary representation of the effective duration value, and the binding tail check are concatenated in sequence to form the original binding payload. Cyclic redundancy check is then performed on the original binding payload to obtain the binding check code of the target campus. The binding checksum is appended to the end of the original binding payload to form the binding data block to be encapsulated; Based on the preset token structure template, fields are written to the bound data block to obtain the temporary authorization token for the target campus.
[0014] To address the aforementioned problems, this invention also provides a campus digital asset access control system based on a dynamic permission blockchain, the system comprising: The multi-dimensional payload module is used to receive the target user's access request after informing and obtaining the target user's consent, and combine the original access data packet of the access request with the target user's user identifier and the target campus's asset identifier to obtain the target campus's multi-dimensional permission verification payload. The anonymous overlabeling module is used to overwrite and replace the original identifiers of the multi-dimensional permission verification payload based on the anonymous user identifier and the anonymous asset identifier in the multi-dimensional permission verification payload, so as to obtain the permission verification transaction data packet of the target campus. The sub-chain delivery module is used to deliver the permission verification transaction package to the unique target sub-chain of the campus alliance blockchain in the target campus, and obtain the routing mapping record of the target campus. The contract verification module is used to parse the smart contract of the permission verification transaction package based on the routing mapping record to obtain the dynamic verification pass certificate of the target campus. The token minting module is used to mint a temporary authorization token that is strongly bound to the one-time session key based on the validity period mapped by the current permission level in the dynamic verification credentials. The temporary authorization token is then sent to the asset gateway of the target campus and a copy is synchronized to the local persistent cache to obtain the authorization token stub of the target campus.
[0015] Compared with the prior art, the present invention has the following beneficial effects: 1. This invention, by constructing a multi-dimensional permission verification payload and completing the anonymous overlay replacement of the original identifier, can ensure the privacy of users and asset identifiers throughout the process. Relying on the unique target sub-chain of the campus alliance blockchain to complete the targeted delivery of permission verification transaction packets, it can form accurate and stable routing mapping records, making the permission verification process more standardized and secure.
[0016] 2. This invention uses routing mapping records to complete smart contract parsing to generate dynamic verification credentials, and casts temporary authorization tokens according to the permission level and effective duration. It simultaneously completes token issuance and local persistent caching, which can realize dynamic and refined authorization control of campus digital asset access, improve the execution efficiency of access control and the reliability of credentials, and form a complete and traceable authorization token stub. Attached Figure Description
[0017] Figure 1 A flowchart illustrating a campus digital asset access control method based on dynamic permission blockchain, provided in an embodiment of the present invention; Figure 2 A functional block diagram of a campus digital asset access control system based on a dynamic permission blockchain provided in an embodiment of the present invention; The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0018] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.
[0019] This application provides a method for access control of campus digital assets using a dynamic permission blockchain. The executing entity of this method includes, but is not limited to, at least one electronic device that can be configured to execute the method provided in this application, such as a server or a terminal. In other words, the method can be executed by software or hardware installed on a terminal device or server device. The server includes, but is not limited to, a single server, a server cluster, a cloud server, or a cluster of cloud servers. The server can be an independent server or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms.
[0020] Reference Figure 1 The diagram shown is a flowchart illustrating a campus digital asset access control method based on a dynamic permission blockchain, according to an embodiment of the present invention. In this embodiment, the campus digital asset access control method based on a dynamic permission blockchain includes: Pt.1 After informing and obtaining the target user's consent, receive the target user's access request, combine the original access data packet of the access request with the target user's user identifier and the target campus's asset identifier to obtain the target campus's multi-dimensional permission verification payload. In this embodiment of the invention, after informing and obtaining the target user's consent, receiving the target user's access request, and combining the original access data packet of the access request with the target user's user identifier and the target campus's asset identifier to obtain the target campus's multi-dimensional permission verification payload, includes: Extract the target user's user identifier and the target campus's asset identifier from the specified fields in the request message to obtain the target campus's temporary identity credential pair; Based on the temporary identity credential pair, the target user's current geolocation tag, device hardware fingerprint, network access point identifier, action feature code of the most recent operation, and timestamp of the request are captured and encapsulated to obtain the original context-attached data packet of the target campus. The user identifier and asset identifier in the temporary identity credential pair are sequentially concatenated with the geolocation tag, device hardware fingerprint, network access point identifier, action signature code and timestamp in the original context attached data packet to obtain the multi-dimensional permission verification payload of the target campus.
[0021] The system directly locates the identity information storage field corresponding to the preset offset address in the request message header, reads all the character content of the user identifier unique to the target user segment by segment according to the byte order, and then extracts all the character content of the asset identifier unique to the target campus digital assets according to the same reading rules. The extracted user identifier and asset identifier are combined and bound in a fixed order without misalignment or missing parts to obtain the temporary identity credential pair of the target campus.
[0022] Before the system performs any user data collection operations, it must first display a personal information processing notice to the target user in a prominent manner, such as a pop-up window or a separate page. The notice must be clearly and understandably stated in full: the purpose of processing is multi-dimensional dynamic permission verification and access control of campus digital assets; the processing methods include automated collection, encrypted transmission, storage on the campus alliance blockchain sub-chain, smart contract parsing, and the minting and issuance of temporary authorization tokens; the types of information involved include user identifiers, asset identifiers, current geolocation tags, device hardware fingerprints, network access point identifiers, action feature codes of the most recent operation, and timestamps when the request was initiated; the information retention period is during the current access session or within 30 days after the expiration of the issued temporary authorization token, and the deletion method is irreversible anonymization; the necessity of processing is explained as follows: if the user does not agree to provide the above information, dynamic permission verification cannot be completed, but the user can still continue to use the public functions of campus digital assets that do not rely on this verification; the impact on personal rights is limited to legitimate access control within the campus and not to any other commercial or analytical purposes. Meanwhile, the notification must clearly state the specific ways for users to refuse or withdraw their consent: users can withdraw their consent to all or part of the information at any time through the "Authorization Management" module in the system settings page, or reselect the scope of authorization upon their next login. After withdrawal, the system will immediately stop collecting new data and anonymize the stored historical data within 24 hours. Based on this, the system will obtain separate consent from users again through a separate pop-up window for sensitive personal information such as geolocation tags and device fingerprints. This separate consent pop-up window must emphasize the specific uses of these two types of information: geolocation is only used for geofence verification, device fingerprints are only used for device trustworthiness detection, alternative verification methods when not provided, and additional safeguards. Users must actively check "I have read and agree" and click the "Confirm" button in each pop-up window. The system will simultaneously generate an immutable consent log, recording the user identifier, consent time, notification version hash, scope of authorization for sensitive information, and specific terms of consent. This log is stored in a separate audit database and can only be accessed during compliance audits.Only after the entire process of informed consent and individual consent has been completed and the user has given explicit affirmation, does the system begin collecting the various types of user data. This ensures that all user data acquisition is based on legal, valid, and traceable informed consent. Temporary identity credentials are then used as the basis for precise retrieval. The system reads the WGS84 standard latitude and longitude format geographic location tag output by the satellite and network fusion positioning module built into the target user's access terminal. The unique feature combination of the three core hardware components of the access terminal—CPU serial number, hard disk serial number, and network card MAC address—is collected to form an unalterable device hardware fingerprint. The exclusive physical codes of the switch port and wireless AP in the campus network transmission link are extracted as network access point identifiers. The access type, operation object, and execution duration of the target user's last operation are retrieved to form an action feature code. The standard time value of Beijing time, accurate to milliseconds, at the time the access request was initiated is recorded as a timestamp. The above five types of information are fully integrated and encapsulated according to a preset fixed field length and separator arrangement to obtain the original context-attached data packet of the target campus.
[0023] The original character content and length are strictly preserved. The temporary identity credential pair content is organized in a fixed order with the user identifier first and the asset identifier last. The preset field order is strictly followed without being changed or deleted. The original context attached data packet content is organized in a fixed order of geolocation tag, device hardware fingerprint, network access point identifier, action feature code and timestamp. The two sets of organized information are connected and spliced sequentially using fixed boundary separators to form a complete and continuous information carrier without breaks, redundancy and missing information. It fully carries all identity and context verification information to obtain the multi-dimensional permission verification payload of the target campus.
[0024] Pt.2. Based on the anonymous user identifier and anonymous asset identifier in the multi-dimensional permission verification payload, the original identifiers of the multi-dimensional permission verification payload are overwritten and replaced to obtain the permission verification transaction data packet of the target campus. In this embodiment of the invention, the process of overwriting and replacing the original identifiers of the multi-dimensional permission verification payload based on the user anonymity identifier and asset anonymity identifier in the multi-dimensional permission verification payload to obtain the permission verification transaction data packet of the target campus includes: The multi-dimensional permission verification payload is parsed to obtain the original identifier field group and context parameter field group of the target campus; Anonymize and replace the original user identifiers in the original identifier field group to obtain anonymous user identifiers for the target campus. The original asset identifiers of the original identifier field group are hashed and obfuscated to obtain the anonymous asset identifiers of the target campus. Based on anonymous user identifiers and anonymous asset identifiers, the original identifier field group is overwritten to obtain the complete payload of the target campus; The complete payload is encapsulated in a transaction format and a timestamp of the current operation is added to obtain the target campus's authorization verification transaction data packet.
[0025] The process of anonymizing and replacing the original user identifier in the original identifier field group to obtain the anonymous user identifier includes: The last segment of the binary string in the user's original identifier is extracted as the permutation seed to obtain the initial permutation vector of the target campus. Based on the initial permutation vector and the preset irreversible character mapping table, the characters in the user's original identifier are permuted in a single round to obtain the first permutation identifier of the target campus; Using the first permutation identifier as a feedback parameter, a second round of mapping and permutation is performed on the irreversible character mapping table after dynamic offsetting, to obtain the anonymous identifier of the target campus user.
[0026] The process of using the first-round permutation identifier as a feedback parameter, dynamically offsetting the irreversible character mapping table, and then performing a second round of mapping permutation to obtain the anonymous user identifier of the target campus includes: Extract the lower eight bits of the first permutation identifier as the first offset factor, and extract the higher eight bits of the first permutation identifier as the second offset factor. Based on the preset mapping table length constant and perturbation basis constant, the dynamic offset is calculated according to the following formula: ; In the formula, This is a dynamic offset. This represents the value of the first offset factor. This represents the value of the second offset factor. Let be the perturbation basis constant. The length of the mapping table is a constant. This indicates a left shift by two bits. This indicates a bitwise XOR operation. This represents the modulo operation; Based on the dynamic offset, the character mapping entries in the irreversible character mapping table are cyclically shifted to the left in the irreversible character mapping table, with the shift step size equal to the dynamic offset, to obtain the offset mapping table of the target campus. Based on the offset mapping table, the characters in the first permutation identifier are sequentially mapped and permuted in the second round to obtain the anonymous user identifier of the target campus.
[0027] Based on the predefined byte-level separators and fixed field length thresholds within the multi-dimensional permission verification payload, the information is checked field by field to ensure completeness and absence of omissions or errors. All information within the payload is precisely split into a set of identity identifier fields containing only the user's original identifier and the asset's original identifier, and a set of access context parameter fields containing geolocation tags, device hardware fingerprints, network access point identifiers, action signatures, and timestamps. After separation, the target campus's original identifier field group and context parameter field group are obtained.
[0028] According to the system's preset 16-bit binary fixed length standard, the last 16 consecutive bits of the user's original identifier binary string are precisely extracted as the replacement seed. This replacement seed is directly used as the reference for character mapping. Then, the system's built-in irreversible character mapping table is called. According to the one-to-one character correspondence in the table, a single-round mapping replacement operation is performed on each character in the user's original identifier without omission or repetition. The resulting new character sequence is the first replacement identifier. Then, according to the preset 8-bit binary fixed length standard, the lower 8 bits and the higher 8 bits of the first replacement identifier binary string are extracted as two sets of offset factors. Based on the numerical characteristics of the two sets of offset factors, all character mapping entries in the irreversible character mapping table are adjusted by a directional cyclic left shift. After adjustment, an offset mapping table adapted to the current user identifier is formed. The offset mapping table is used to perform a complete mapping replacement on each character in the first replacement identifier again. After replacement, the anonymous user identifier of the target campus, whose original information cannot be restored, is obtained.
[0029] Following the system's preset fixed hash conversion processing rules, all characters in the original asset identifier are subjected to irreversible bit-by-bit conversion processing. The conversion process does not change the baseline of the total character length. After conversion, a character sequence of fixed length, irregularity, and original asset identifier that cannot be deduced in reverse is generated, thereby completing the privacy processing of the asset identifier and obtaining the anonymous asset identifier of the target campus.
[0030] The generated anonymous user identifier is completely filled into the fixed field position originally occupied by the original user identifier in the original identifier field group. The generated anonymous asset identifier is completely filled into the fixed field position originally occupied by the original asset identifier in the original identifier field group. The overwrite process does not change the field length and storage format. At the same time, all contents, field order and storage format of the context parameter field group remain completely unchanged. The overwritten original identifier field group and the unchanged context parameter field group are reintegrated to form a continuous and complete information carrier without breaks or redundancy, thus obtaining the complete payload of the target campus.
[0031] In accordance with the standard structure specifications for blockchain transactions, the complete payload is subjected to field classification and sorting, format encapsulation and calibration, and data integrity verification operations. After the processing is completed, a standard time value accurate to the millisecond level is appended to the end of the payload to indicate when the current identifier replacement operation was completed. After the format integration and time stamp addition are completed, a data packet that meets the requirements for blockchain on-chain processing is formed, and the target campus's permission verification transaction data packet is obtained.
[0032] According to the system's preset 16-bit binary fixed length standard, the 16-bit continuous bit string content at the end of the user's original identifier binary bit string is accurately extracted. This bit string serves as the basis for mapping and permutation. The extraction operation is error-free and uninterrupted. After completion, the initial permutation vector of the target campus is obtained.
[0033] Using the initial permutation vector as the core reference for character matching, the system calls the pre-set irreversible character mapping table. According to the pre-defined one-to-one correspondence of characters in the table, a single round of mapping replacement is performed on each character in the user's original identifier. The replacement process covers all characters without changing the character arrangement order. After the replacement is completed, a permutation identifier of the target campus is obtained.
[0034] The complete binary bit string of the first permutation identifier is extracted as the core basis for the mapping table adjustment. According to the preset eight-bit binary fixed length standard, the lower eight bits and the higher eight bits of the binary bit string of the first permutation identifier are extracted respectively. Based on the numerical characteristics of these two parts, all mapping entries in the irreversible character mapping table are cyclically shifted to the left. After the adjustment is completed, the updated offset mapping table is used to perform a second round of complete mapping replacement on each character in the first permutation identifier. The replacement process has no missing characters and no disordered order. After the replacement is completed, the anonymous user identifier of the target campus is obtained.
[0035] According to the preset eight-bit binary fixed length standard, the last eight consecutive bits of the binary bit string of the first permutation identifier are accurately extracted. This segment is used as one of the core parameters for offset calculation to obtain the first offset factor.
[0036] According to the preset eight-bit binary fixed length standard, the first eight consecutive bits of the binary bit string of the first permutation identifier are accurately extracted. This segment is used as one of the core parameters for offset calculation to obtain the second offset factor.
[0037] The decimal value corresponding to the first offset factor is multiplied by the pre-set and fixed perturbation basis constant in the authorization verification system to obtain the first operation result. The binary bit string corresponding to the second offset factor is shifted two bits to the left to obtain the second operation result. The first operation result and the second operation result are XORed to obtain the third operation result. The third operation result is then divided by the system's preset mapping table length constant, and the remainder obtained after this division operation is taken as the final dynamic offset.
[0038] Based on the specific number of moves corresponding to the dynamic offset, all character mapping entries in the irreversible character mapping table are moved to the left in a loop. During the movement, character mapping entries that exceed the starting position of the mapping table are filled in from the end position of the mapping table in a loop. After the movement is completed, a unique mapping table adapted to the current replacement identifier is formed, and the offset mapping table of the target campus is obtained.
[0039] According to the pre-defined one-to-one correspondence of characters in the offset mapping table, each character in a replacement identifier is replaced one by one in sequence. During the replacement process, the original arrangement order of the characters is strictly maintained and all characters are covered without omission or misalignment. After the replacement is completed, the anonymous user identifier of the target campus is obtained.
[0040] The first offset factor is obtained by extracting eight consecutive bits from the end of the binary string of the permutation identifier according to a preset eight-bit binary fixed length standard. This value directly participates in the calculation process of the dynamic offset and is the core feature value for the generation of the dynamic offset.
[0041] The second offset factor is obtained by extracting eight consecutive bits from the beginning of the binary string of the permutation identifier according to the preset eight-bit binary fixed length standard. This value directly participates in the calculation process of dynamic offset and is the core feature value for generating dynamic offset.
[0042] The perturbation basis constant is a baseline value that is pre-set during the deployment phase of the authorization verification system and remains fixed throughout the process. This value is specifically used to provide basic perturbation parameters for dynamic offset calculation, avoiding regularity in the offset generation process.
[0043] The mapping table length constant is a fixed value obtained by accurately counting the total number of all character mapping entries in the irreversible character mapping table. This value is used to limit the range of dynamic offset values, ensuring that the offset is always within the effective range of the mapping table that can be moved.
[0044] The intermediate value is obtained by multiplying the first offset factor with the perturbation basis constant. The binary bit string of the second offset factor is shifted two bits to the left to obtain the converted value. The intermediate value and the converted value are then XORed, and the result is divided by the mapping table length constant and the remainder is taken. This yields the dynamic offset steps that fully adapt to the irreversible character mapping table.
[0045] The calculation process for dynamic offset steps uses multiple layers of numerical transformation and fixed numerical constraints to ensure that the generated offset steps are always within the valid range of the irreversible character mapping table that can be cyclically moved, thus avoiding invalid offset operations that exceed the range of the mapping table.
[0046] The calculation process of dynamic offset steps incorporates the unique binary characteristics of a single permutation identifier and the system's preset perturbation benchmark value, making the generated offset mapping table unique to the user and irreversible in reverse, thus ensuring the security and uncrackability of the user's anonymous identifier generation process from the root.
[0047] Pt.3. Directly deliver the authorization verification transaction package to the unique target sub-chain of the campus alliance blockchain in the target campus to obtain the routing mapping record of the target campus; In this embodiment of the invention, the step of directing the authorization verification transaction packet to the unique target sub-chain of the campus consortium blockchain in the target campus, and obtaining the routing mapping record of the target campus, includes: The authorization verification transaction packet is unpacked according to the protocol to obtain the identity fingerprint string of the target campus. The high-order prefix segment of the identity fingerprint string is extracted as the routing key value. The sub-chain routing table in the blockchain gateway of the target campus is queried to obtain the sub-chain location record of the target campus. The sub-links are mapped by a mapping table that records the mapping relationship between different high-order prefix segments and the network addresses of the parallel verification sub-links. Based on the network address of the unique target subchain in the subchain location record, the authorization verification transaction packet is reconstructed into a transaction commit frame that conforms to the subchain communication specification, and then pushed to the unique target subchain network address in a one-way manner to obtain the routing mapping record of the target campus.
[0048] Following the exclusive communication protocol specification of the campus alliance blockchain adapted to the permission verification transaction package, starting from the outermost layer of the transaction package, the protocol header encapsulation field, data verification field, transmission padding field and other multiple outer encapsulation structures are stripped in sequence. The core identity feature characters such as user anonymity identifier and asset anonymity identifier inside the transaction package are accurately extracted. These core characters are combined into a continuous and uninterrupted character sequence in their original order to obtain the identity fingerprint string of the target campus.
[0049] According to the 16-character length standard pre-fixed during the system deployment phase, starting from the starting character position of the identity fingerprint string, 16 characters are continuously extracted to form the high-order prefix segment. This segment is used as the unique routing key value. Using the routing key value as the precise retrieval condition, a character-by-character full match query is performed on the sub-link mapping table that is locally fixed and stored in the target campus blockchain gateway. After finding the unique matching mapping entry, the sub-link network address, node identifier, and other information associated with the entry are completely extracted to obtain the sub-link location record of the target campus.
[0050] The sub-links are fully configured and permanently stored by the mapping table during the system initialization and deployment phase. The table fully stores the one-to-one binding relationship between all compliant high-order prefix segments and the corresponding parallel verification sub-link network addresses. Each high-order prefix segment corresponds to only one fixed and unique parallel verification sub-link network address, and there are no multiple address mappings or address conflicts.
[0051] Based on the unique target subchain-specific network address recorded in the subchain location record, and following the fixed frame header, data segment, and frame tail structure standard stipulated by the subchain communication, while keeping the core data of the authorization verification transaction packet unchanged, the field arrangement order and outer encapsulation format are rearranged to form a transaction commit frame that conforms to the subchain on-chain transmission specification. Through the dedicated peer-to-peer network channel of the campus alliance blockchain, a one-way data push without receipt is performed to the unique target subchain network address to complete the on-chain commit operation. Simultaneously, all information such as the transmission path of this delivery, the millisecond time of operation completion, and the successful on-chain status are recorded, and integrated to form a traceable and complete record, thus obtaining the routing mapping record of the target campus.
[0052] Pt.4. Based on the routing mapping record, perform smart contract parsing on the permission verification transaction package to obtain the dynamic verification pass certificate of the target campus; In this embodiment of the invention, the step of parsing the permission verification transaction packet based on the routing mapping record to obtain the dynamic verification pass credential of the target campus includes: The fields of the authorization verification transaction package are destructured to obtain the verification element tuple of the target campus; Based on the user anonymous identifier in the authentication element tuple of the authentication transaction package, obtain the dynamic policy record associated with the user anonymous identifier in the state database of the routing mapping record, and obtain the policy record object of the target campus. Perform a Boolean state check on the permission revocation flag in the policy record object; If the permission revocation flag is true, then the subsequent operations are terminated and a verification rejection credential is generated; If false, continue to perform time window membership detection on the timestamp of the verification element tuple to determine whether the timestamp falls within the range of the valid time window, and obtain the time window detection pass flag of the target campus; Under the premise that the time window detection pass flag is true, extract the on-chain dynamic permission factor copy from the policy record object, perform string conversion mapping on the on-chain dynamic permission factor copy, and obtain the on-chain comparison hash digest of the target campus. The on-chain comparison hash digest is compared with the permission verification hash digest in the verification element tuple. If the comparison is consistent, the dynamic verification pass credential for the target campus is obtained.
[0053] According to the field splitting rules formed by the combination of byte order, field length and delimiter in the system deployment phase of the permission verification transaction package, all information inside the transaction package is split independently according to the field types of identity characteristics, time parameters and verification digest. The core verification information such as user anonymity identifier, request timestamp and permission verification hash digest are completely extracted and integrated into an information set with an irreversible order according to a fixed field order and storage structure, so as to obtain the verification element tuple of the target campus.
[0054] Using the unique and non-repeatable anonymous user identifier in the verification element tuple as the precise retrieval condition, a full-character consistency lookup is performed in the blockchain state database associated with the routing mapping record through index matching. This fully retrieves the permission management-related records such as dynamic permission level, effective time window, and dynamic permission factor directly bound to the anonymous user identifier, thus obtaining the policy record object of the target campus.
[0055] Read the binary status value corresponding to the permission revocation flag inside the policy record object, and directly compare the status value with the system's preset fixed Boolean true value and fixed Boolean false value. Based on the comparison result, complete the Boolean status detection of the permission revocation flag.
[0056] When the status value of the permission revocation flag is exactly the same as the fixed value of the Boolean truth value preset by the system, all subsequent field parsing, time verification, and digest comparison operations are immediately terminated. The system generates a credential content marked with verification failure and permission expiration information according to the credential format specification preset by the system, and obtains the verification rejection credential of the target campus.
[0057] When the status value of the permission revocation flag is exactly the same as the fixed value of the Boolean false value preset by the system, the timestamp value accurate to the millisecond level is extracted from the verification element tuple. The timestamp value is compared with the start and end millisecond time values of the system's preset valid time window. When the timestamp value is greater than or equal to the start time value and less than or equal to the end time value, a valid status identifier for permission access time compliance is generated, and the time window detection pass mark of the target campus is obtained.
[0058] Under the premise that the time window detection passes and the status is valid, the complete content of the dynamic permission factor copy in the trusted storage on the blockchain is extracted from the policy record object. According to the system's preset irreversible character conversion rules, the dynamic permission factor copy is converted bit by bit into a fixed-length random character digest sequence to obtain the on-chain comparison hash digest of the target campus.
[0059] Each character of the hash digest on the chain is compared with the corresponding character in the permission verification hash digest of the verification element tuple. If all corresponding characters are completely identical and indistinguishable, a credential content containing the valid permission level and access permission information is generated according to the system's preset credential format specification, thus obtaining the dynamic verification pass credential for the target campus.
[0060] Pt.5. Based on the validity period mapped by the current permission level in the dynamic verification credentials, a temporary authorization token strongly bound to the one-time session key is forged. The temporary authorization token is then sent to the asset gateway of the target campus and a copy is synchronized to the local persistent cache to obtain the authorization token stub of the target campus.
[0061] In this embodiment of the invention, the step of casting a temporary authorization token strongly bound to a one-time session key based on the validity period mapped from the current permission level in the credential through dynamic verification, issuing the temporary authorization token to the asset gateway of the target campus, and synchronizing a copy to the local persistent cache to obtain the authorization token stub of the target campus includes: Based on the current permission level of the credentials through dynamic verification, the preset level-duration mapping table is accessed to obtain the effective duration value of the target campus. The dynamic verification is achieved by binding the one-time session key of the credential with the validity period value to obtain a temporary authorization token for the target campus. Create an authorization record entry in the authorization cache of the target campus; Based on the temporary authorization token, the temporary authorization token is written into the token field of the authorization record entry to obtain the gateway-side authorization record of the target campus; Synchronize a complete copy of the temporary authorization token to the token stub table of the target campus to obtain the authorization token stub of the target campus.
[0062] The process of binding and assembling a one-time session key and a validity period value of the dynamic verification credentials to obtain a temporary authorization token for the target campus includes: Extract the first part of the binary string in the one-time session key as the binding header identifier, and extract the last part of the binary string in the one-time session key as the binding tail verification; The binding header identifier, the binary representation of the effective duration value, and the binding tail check are concatenated in sequence to form the original binding payload. Cyclic redundancy check is then performed on the original binding payload to obtain the binding check code of the target campus. The binding checksum is appended to the end of the original binding payload to form the binding data block to be encapsulated; Based on the preset token structure template, fields are written to the bound data block to obtain the temporary authorization token for the target campus.
[0063] The dynamic verification extracts the character content of the current permission level that is pre-marked and cannot be modified within the credential. Using this permission level character content as the unique matching condition, a full character consistency lookup is performed in the level-duration mapping table that is pre-fixed and stored during the system deployment phase. The millisecond-level duration value that is uniquely bound to this permission level is directly obtained from the table, thus obtaining the effective duration value of the target campus.
[0064] Extract the complete character and binary bit string of the one-time session key carried within the dynamic verification credential and valid only once. Then, seamlessly concatenate and encapsulate the one-time session key and the validity duration value according to the system's preset fixed field position order and separator combination structure to form an inseparable and strongly associated authorization information carrier, thus obtaining the temporary authorization token of the target campus.
[0065] Within the dedicated storage area of the pre-defined and independently isolated authorization cache zone in the target campus system, a new independent storage item is created according to the system's preset authorization record standard format. This storage item is specifically used to carry the token, time, and status-related information of this authorization. After the creation of the independent storage item is completed, a standard authorization record entry is formed.
[0066] The entire character and binary content of the temporary authorization token are filled into the pre-defined token-specific storage field inside the authorization record entry without any errors. After filling, the initial default state of other auxiliary fields in the authorization record entry is kept unchanged, forming an authorization information record that can be directly read, parsed, and verified by the asset gateway, thus obtaining the gateway-side authorization record of the target campus.
[0067] Completely copy all characters, binary data, and verification information of the temporary authorization token to generate a complete copy without any missing information. Accurately store this copy in the specified index storage location of the local persistent token stub table of the target campus. After the copy is stored, token registration information that can be retained for a long time and traced and queried is formed, thus obtaining the authorization token stub of the target campus.
[0068] According to the system's pre-defined 16-bit binary length standard, the first 16 consecutive bits of the one-time session key binary string are precisely extracted as the binding header identifier, and the last 16 consecutive bits of the one-time session key binary string are precisely extracted as the binding tail check. The extraction process is free of misalignment, truncation, and loss.
[0069] The binding header identifier, the valid duration value converted to a standard value, and the binding tail check are seamlessly spliced together in a fixed order from front to back to form a continuous data combination without interruption or redundancy. This constitutes the complete original binding payload. A bit-by-bit cyclic redundancy check operation is performed on all binary bits in the original binding payload. After the operation is completed, a check character sequence of a preset fixed length is generated to obtain the binding check code of the target campus.
[0070] All characters of the binding check code and the binary content are directly appended to the last bit of the original binding payload, so that the original payload content and the check code content form a continuous, complete, and verifiable integrated data combination, resulting in the binding data block to be encapsulated.
[0071] According to the system's preset standard structure template for temporary authorization tokens, the bound data block is completely written into the token data field specified in the template. After filling, a complete token entity that conforms to the campus blockchain transmission specification and asset gateway verification specification is formed, and a temporary authorization token for the target campus is obtained.
[0072] like Figure 2 The diagram shown is a functional block diagram of a campus digital asset access control system based on a dynamic permission blockchain, provided in an embodiment of the present invention.
[0073] The campus digital asset access control system based on dynamic permission blockchain described in this invention can be installed in electronic devices. Depending on the functions implemented, the system may include a multi-dimensional group loading module, an anonymous tagging module, a sub-chain delivery module, a contract verification module, and a token minting module. The modules described in this invention can also be referred to as units, which are a series of computer program segments that can be executed by the processor of an electronic device and perform a fixed function, stored in the memory of the electronic device.
[0074] In this embodiment, the functions of each module / unit are as follows: The multi-dimensional payload module is used to receive the target user's access request after informing and obtaining the target user's consent, and combine the original access data packet of the access request with the target user's user identifier and the target campus's asset identifier to obtain the target campus's multi-dimensional permission verification payload. The anonymous overlabeling module is used to overwrite and replace the original identifiers of the multi-dimensional permission verification payload based on the user anonymous identifier and asset anonymous identifier in the multi-dimensional permission verification payload, so as to obtain the permission verification transaction data packet of the target campus. The sub-chain delivery module is used to deliver the permission verification transaction package to the unique target sub-chain of the campus alliance blockchain in the target campus, so as to obtain the routing mapping record of the target campus. The contract verification module is used to perform smart contract parsing on the permission verification transaction package based on the routing mapping record to obtain the dynamic verification pass certificate of the target campus. The token casting module is used to cast a temporary authorization token strongly bound to the one-time session key based on the validity period mapped by the current permission level in the dynamic verification credentials, distribute the temporary authorization token to the asset gateway of the target campus, and synchronize a copy to the local persistent cache to obtain the authorization token stub of the target campus.
[0075] In the several embodiments provided by this invention, it should be understood that the disclosed methods and systems can be implemented in other ways. For example, the system embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and other division methods may be used in actual implementation.
[0076] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0077] Furthermore, the functional modules in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in the form of hardware plus software functional modules.
[0078] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.
[0079] This application embodiment can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.
[0080] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A method for access control of campus digital assets using a dynamic permission blockchain, characterized in that, The method includes: Pt.1 After informing and obtaining the target user's consent, receive the target user's access request, combine the original access data packet of the access request with the target user's user identifier and the target campus's asset identifier to obtain the target campus's multi-dimensional permission verification payload. Pt.
2. Based on the anonymous user identifier and anonymous asset identifier in the multi-dimensional permission verification payload, the original identifiers of the multi-dimensional permission verification payload are overwritten and replaced to obtain the permission verification transaction data packet of the target campus. Pt.
3. Directly deliver the authorization verification transaction package to the unique target sub-chain of the campus alliance blockchain in the target campus to obtain the routing mapping record of the target campus; Pt.
4. Based on the routing mapping record, perform smart contract parsing on the permission verification transaction package to obtain the dynamic verification pass certificate of the target campus; Pt.
5. Based on the validity period mapped by the current permission level in the dynamic verification credentials, a temporary authorization token strongly bound to the one-time session key is forged. The temporary authorization token is then sent to the asset gateway of the target campus and a copy is synchronized to the local persistent cache to obtain the authorization token stub of the target campus.
2. The campus digital asset access control method based on dynamic permission blockchain as described in claim 1, characterized in that, After informing and obtaining the target user's consent, the system receives the target user's access request, combines the original access data packet of the access request with the target user's user identifier and the target campus's asset identifier, and obtains the target campus's multi-dimensional permission verification payload, including: Extract the target user's user identifier and the target campus's asset identifier from the specified fields in the request message to obtain the target campus's temporary identity credential pair; Based on the temporary identity credential pair, the target user's current geolocation tag, device hardware fingerprint, network access point identifier, action feature code of the most recent operation, and timestamp of the request are captured and encapsulated to obtain the original context-attached data packet of the target campus. The user identifier and asset identifier in the temporary identity credential pair are sequentially concatenated with the geolocation tag, device hardware fingerprint, network access point identifier, action signature code and timestamp in the original context attached data packet to obtain the multi-dimensional permission verification payload of the target campus.
3. The campus digital asset access control method based on dynamic permission blockchain as described in claim 1, characterized in that, The user anonymity identifier and asset anonymity identifier in the multi-dimensional permission verification payload are used to overwrite and replace the original identifiers in the multi-dimensional permission verification payload to obtain the permission verification transaction data packet of the target campus, including: The multi-dimensional permission verification payload is parsed to obtain the original identifier field group and context parameter field group of the target campus; Anonymize and replace the original user identifiers in the original identifier field group to obtain anonymous user identifiers for the target campus. The original asset identifiers of the original identifier field group are hashed and obfuscated to obtain the anonymous asset identifiers of the target campus. Based on anonymous user identifiers and anonymous asset identifiers, the original identifier field group is overwritten to obtain the complete payload of the target campus; The complete payload is encapsulated in a transaction format and a timestamp of the current operation is added to obtain the target campus's authorization verification transaction data packet.
4. The campus digital asset access control method based on dynamic permission blockchain as described in claim 3, characterized in that, The process of anonymizing and replacing the original user identifier in the original identifier field group to obtain the anonymous user identifier includes: The last segment of the binary string in the user's original identifier is extracted as the permutation seed to obtain the initial permutation vector of the target campus. Based on the initial permutation vector and the preset irreversible character mapping table, the characters in the user's original identifier are permuted in a single round to obtain the first permutation identifier of the target campus; Using the first permutation identifier as a feedback parameter, a second round of mapping and permutation is performed on the irreversible character mapping table after dynamic offsetting, to obtain the anonymous identifier of the target campus user.
5. The campus digital asset access control method based on dynamic permission blockchain as described in claim 4, characterized in that, The process of using the first-round permutation identifier as a feedback parameter, dynamically offsetting the irreversible character mapping table, and then performing a second round of mapping permutation to obtain the anonymous user identifier of the target campus includes: Extract the lower eight bits of the first permutation identifier as the first offset factor, and extract the higher eight bits of the first permutation identifier as the second offset factor. Based on the preset mapping table length constant and perturbation basis constant, the dynamic offset is calculated according to the following formula: ; In the formula, This is a dynamic offset. This represents the value of the first offset factor. This represents the value of the second offset factor. Let be the perturbation basis constant. The length of the mapping table is a constant. This indicates a left shift by two bits. This indicates a bitwise XOR operation. This represents the modulo operation; Based on the dynamic offset, the character mapping entries in the irreversible character mapping table are cyclically shifted to the left in the irreversible character mapping table, with the shift step size equal to the dynamic offset, to obtain the offset mapping table of the target campus. Based on the offset mapping table, the characters in the first permutation identifier are sequentially mapped and permuted in the second round to obtain the anonymous user identifier of the target campus.
6. The campus digital asset access control method based on dynamic permission blockchain as described in claim 1, characterized in that, The step of directing the authorization verification transaction packet to the unique target sub-chain of the campus consortium blockchain in the target campus, and obtaining the routing mapping record of the target campus, includes: The authorization verification transaction packet is unpacked according to the protocol to obtain the identity fingerprint string of the target campus. The high-order prefix segment of the identity fingerprint string is extracted as the routing key value. The sub-chain routing table in the blockchain gateway of the target campus is queried to obtain the sub-chain location record of the target campus. The sub-links are mapped by a mapping table that records the mapping relationship between different high-order prefix segments and the network addresses of the parallel verification sub-links. Based on the network address of the unique target subchain in the subchain location record, the authorization verification transaction packet is reconstructed into a transaction commit frame that conforms to the subchain communication specification, and then pushed to the unique target subchain network address in a one-way manner to obtain the routing mapping record of the target campus.
7. The campus digital asset access control method based on dynamic permission blockchain as described in claim 1, characterized in that, The method of parsing the authorization verification transaction packet based on the routing mapping record to obtain the dynamic verification pass credential for the target campus includes: The fields of the authorization verification transaction package are destructured to obtain the verification element tuple of the target campus; Based on the user anonymous identifier in the authentication element tuple of the authentication transaction package, obtain the dynamic policy record associated with the user anonymous identifier in the state database of the routing mapping record, and obtain the policy record object of the target campus. Perform a Boolean state check on the permission revocation flag in the policy record object; If the permission revocation flag is true, then the subsequent operations are terminated and a verification rejection credential is generated; If false, continue to perform time window membership detection on the timestamp of the verification element tuple to determine whether the timestamp falls within the range of the valid time window, and obtain the time window detection pass flag of the target campus; Under the premise that the time window detection pass flag is true, extract the on-chain dynamic permission factor copy from the policy record object, perform string conversion mapping on the on-chain dynamic permission factor copy, and obtain the on-chain comparison hash digest of the target campus. The on-chain comparison hash digest is compared with the permission verification hash digest in the verification element tuple. If the comparison is consistent, the dynamic verification pass credential for the target campus is obtained.
8. The campus digital asset access control method based on dynamic permission blockchain as described in claim 1, characterized in that, The process involves dynamically verifying the validity period mapped from the current permission level in the credentials, forging a temporary authorization token strongly bound to the one-time session key, distributing the temporary authorization token to the target campus's asset gateway, and synchronizing a copy to the local persistent cache to obtain the target campus's authorization token stub, including: Based on the current permission level of the credentials through dynamic verification, the preset level-duration mapping table is accessed to obtain the effective duration value of the target campus. The dynamic verification is achieved by binding the one-time session key of the credential with the validity period value to obtain a temporary authorization token for the target campus. Create an authorization record entry in the authorization cache of the target campus; Based on the temporary authorization token, the temporary authorization token is written into the token field of the authorization record entry to obtain the gateway-side authorization record of the target campus; Synchronize a complete copy of the temporary authorization token to the token stub table of the target campus to obtain the authorization token stub of the target campus.
9. A campus digital asset access control method based on dynamic permission blockchain as described in claim 8, characterized in that, The process of binding and assembling a one-time session key and a validity period value of the dynamic verification credentials to obtain a temporary authorization token for the target campus includes: Extract the first part of the binary string in the one-time session key as the binding header identifier, and extract the last part of the binary string in the one-time session key as the binding tail verification; The binding header identifier, the binary representation of the effective duration value, and the binding tail check are concatenated in sequence to form the original binding payload. Cyclic redundancy check is then performed on the original binding payload to obtain the binding check code of the target campus. The binding checksum is appended to the end of the original binding payload to form the binding data block to be encapsulated; Based on the preset token structure template, fields are written to the bound data block to obtain the temporary authorization token for the target campus.
10. A campus digital asset access control system based on dynamic permission blockchain, characterized in that, The system is used to implement the campus digital asset access control method of dynamic permission blockchain as described in claim 1, the system comprising: The multi-dimensional payload module is used to receive the target user's access request after informing and obtaining the target user's consent, and combine the original access data packet of the access request with the target user's user identifier and the target campus's asset identifier to obtain the target campus's multi-dimensional permission verification payload. The anonymous overlabeling module is used to overwrite and replace the original identifiers of the multi-dimensional permission verification payload based on the anonymous user identifier and the anonymous asset identifier in the multi-dimensional permission verification payload, so as to obtain the permission verification transaction data packet of the target campus. The sub-chain delivery module is used to deliver the permission verification transaction package to the unique target sub-chain of the campus alliance blockchain in the target campus, and obtain the routing mapping record of the target campus. The contract verification module is used to parse the smart contract of the permission verification transaction package based on the routing mapping record to obtain the dynamic verification pass certificate of the target campus. The token minting module is used to mint a temporary authorization token that is strongly bound to the one-time session key based on the validity period mapped by the current permission level in the dynamic verification credentials. The temporary authorization token is then sent to the asset gateway of the target campus and a copy is synchronized to the local persistent cache to obtain the authorization token stub of the target campus.