Access control system, access control method
The access control system addresses computational and security challenges by employing contextual analysis and random trust parameter selection to ensure secure and efficient access control in data exchange platforms.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- HITACHI SYST LTD
- Filing Date
- 2022-05-19
- Publication Date
- 2026-04-27
AI Technical Summary
Existing attribute-based access control systems face computational load issues and vulnerability to unauthorized access due to predictable confidence score calculations, making them inefficient and insecure.
An access control system that includes an access gateway for contextual analysis, a trust score management unit for random selection of trust parameters, and an access determination unit to calculate and validate access requests based on dynamically selected trust parameters, ensuring secure and robust access control.
The system achieves safe and robust access control by reducing computational load and preventing unauthorized access through unpredictable trust score calculations, enhancing security in data exchange platforms.
Smart Images

Figure 0007851790000002 
Figure 0007851790000003 
Figure 0007851790000004
Abstract
Description
[Technical Field]
[0001] The present invention relates to a system and method for controlling access to predetermined information. [Background technology]
[0002] Traditionally, a technique known as role-based access control (RBAC) has been used to control access to sensitive information and personal information. Role-based access control grants access rights to each piece of protected information according to the role of the user requesting access to that information, and denies access requests from users without access rights, thereby controlling access to protected information. However, with role-based access control, access control is performed according to pre-set access rights, making it difficult to achieve flexible access control.
[0003] To address the above challenges, a method called attribute-based access control (ABAC) is known. Attribute-based access control controls access to protected information by determining whether an access request is permitted based on pre-configured policies, the attributes of the user making the access request, the attributes of the protected information to which the access request is made, and the attributes of the environment at the time of the access request. This provides more flexible access control compared to role-based access control.
[0004] As an example of attribute database access control, the technology described in Patent Document 1 is known. Patent Document 1 describes a method for calculating reliability by weighting various attribute information according to their respective importance, and determining whether access is permitted or not based on the calculation result.
[0005] Furthermore, a method called Trust-Based Access Control (TBAC), such as that described in Patent Document 2, has also been proposed. Patent Document 2 describes a method for calculating a trust score based on parameters such as the number of suspicious packets and the number of fake requests from a user making an access request, and for determining whether access is permitted by comparing the calculated trust score with a predetermined threshold. [Prior art documents] [Patent Documents]
[0006] [Patent Document 1] Chinese Patent Application Publication No. 113051602 Specification [Patent Document 2] Chinese Patent Application Publication No. 112737824 Specification [Overview of the project] [Problems that the invention aims to solve]
[0007] The technology described in Patent Document 1 suffers from an excessive computational load when attempting to calculate confidence using a large amount of attribute information. Therefore, it presents a challenge in its application to actual access control systems. Furthermore, the technology described in Patent Document 2 has the problem that malicious users can easily guess how the confidence score is calculated, thus failing to prevent unauthorized access.
[0008] This invention has been made in view of the above-mentioned problems, and its main objective is to realize safe and robust access control. [Means for solving the problem]
[0009] The access control system according to the present invention is used in a data exchange platform that mediates access-restricted data between a data requester and a data provider, and comprises: an access gateway that performs contextual analysis of access requests from the data requester to the access-restricted data; a trust score management unit that, based on the results of the contextual analysis by the access gateway, randomly selects one or more trust parameters from a plurality of trust parameters obtained from a workflow system provided by the data exchange platform, and calculates a trust score for the access request based on the selected trust parameters; and an access determination unit that determines whether the access request is permissible or not based on the trust score calculated by the trust score management unit. The access control method according to the present invention is Using a computer An access control method in a data exchange platform that mediates access-restricted data between data requesters and data providers, The aforementioned computer, Contextual analysis is performed on the access request from the data requester to the data subject to access restrictions. The aforementioned computer, Based on the results of the context analysis, one or more trust parameters are randomly selected from a set of trust parameters obtained from the workflow system provided by the data exchange platform. The aforementioned computer, The confidence score of the access request is calculated based on the selected confidence parameters. The aforementioned computer, The access request is deemed valid or invalid based on the aforementioned confidence score. [Effects of the Invention]
[0010] According to the present invention, safe and robust access control can be achieved. [Brief explanation of the drawing]
[0011] [Figure 1] This block diagram shows an overview of a data exchange platform including an access control system according to one embodiment of the present invention. [Figure 2]It is a block diagram showing the detailed structure of an access control system according to an embodiment of the present invention. [Figure 3] It is a diagram showing an example of the progress of a workflow system and access request information. [Figure 4] It is a diagram showing an example of context types. [Figure 5] It is a diagram showing an example of the categorical classification of trust parameters. [Figure 6] It is a flowchart showing the flow of access control processing. [Figure 7] It is a flowchart showing the flow of access control processing. [Figure 8] It is a diagram showing an example of trust parameters and warning count values. [Figure 9] It is an example of a flowchart showing the flow of trust score calculation processing. [Figure 10] It is a diagram showing an example of multi-dimensional analysis of trust parameters. [Figure 11] It is a diagram showing an example of a trust score analysis screen. [Figure 12] It is a sequence diagram showing an example of the actual operation of an access control system according to an embodiment of the present invention.
Embodiments for Carrying Out the Invention
[0012] Hereinafter, embodiments of the present invention will be described with reference to the drawings. For the sake of clarity of explanation, the following description and drawings have been appropriately omitted and simplified. The present invention is not limited to this embodiment, and all application examples that conform to the idea of the present invention are included in the technical scope of the present invention. Unless otherwise specified, each component may be plural or singular.
[0013] In the following explanation, the subject of the process may sometimes be "program" or its process. However, since a program is executed by a processor (e.g., a CPU (Central Processing Unit)) to perform defined processes using memory resources (e.g., memory) and / or communication interface devices (e.g., communication ports) as appropriate, the subject of the process may also be the processor. The processor operates as a functional unit that realizes predetermined functions by operating according to the program. Devices and systems including a processor are devices and systems that include these functional units.
[0014] The following describes one embodiment of the present invention.
[0015] Figure 1 is a block diagram illustrating an overview of a data exchange platform including an access control system according to one embodiment of the present invention. The data exchange platform 1 shown in Figure 1 is a type of information platform used for collaboration between different industries, and provides an environment in which data that should be restricted from access by an unspecified number of people (hereinafter referred to as "access-restricted data") can be securely exchanged between a specified data requester 2 and a data provider 3. The data exchange platform 1 provides a workflow system that packages various UIs (User Interfaces) for data requesters 2 and data providers 3 to use the data exchange platform 1, as well as a series of processes related to the exchange of access-restricted data. This workflow system mediates the exchange of access-restricted data between data requesters 2 and data providers 3, thereby realizing a safe and reliable transfer of access-restricted data.
[0016] Data provider 3 provides, via the data exchange platform 1, personal information of end users (income certificates, employment status, credit information, etc.) held by data provider 3, and information such as a confidence score calculated when data provider 3 has previously made an access request to any access-restricted data as a data requester, as access-restricted data. The confidence score is a value that represents the reliability of the access request and is calculated by the access control system 100 of the data exchange platform 1 as described below. Data requester 2 requests access to the access-restricted data provided by data provider 3 from the data exchange platform 1, and if the access request is permitted, the data requester 2 can obtain the access-restricted data via the data exchange platform 1.
[0017] Data Requester 2 includes various service providers that offer a range of services to end users, and end users who receive services from these service providers. For example, when an end user enters into a real estate lease agreement, a rental guarantee company, as Data Requester 2, requests the end user's personal information, which is restricted access data, and uses it to determine the guarantee terms. Similarly, when an end user applies for a mortgage or insurance, a financial company or insurance company, as Data Requester 2, requests the end user's personal information, which is restricted access data, and uses it to determine the contract terms. However, companies or individuals in other industries may also be considered Data Requester 2.
[0018] Data provider 3 includes end users who provide personal information that is subject to access restrictions, service providers that hold personal information, and third-party companies. The access-restricted data held by data provider 3 is collected on data exchange platform 1, for example, through a web-based API (Application Programming Interface) or EDI (Electronic Data Interchange), and provided to data requester 2 in response to an access request from data requester 2.
[0019] When a data requester 2 makes an access request for restricted access data on the workflow system, the access control system 100 calculates a confidence score representing the reliability of the access request. Based on the calculated confidence score and other access statuses in the workflow system, it determines whether or not to grant access to the restricted access data provided by the data provider 3. This prevents unauthorized use of restricted access data and ensures security for the exchange of restricted access data between different industries.
[0020] The access control system 100 comprises the following functional blocks: an access gateway 110, a trust score management unit 120, a policy management unit 130, and an access determination unit 140. These functional blocks are implemented, for example, by combining a computer (CPU: Central Processing Unit) that executes a predetermined program, and storage devices such as an HDD (Hard Disk Drive) or SSD (Solid State Drive). Some or all of these functional blocks may be implemented using a GPU (Graphics Processing Unit) or FPGA (Field Programmable Gate Array).
[0021] Figure 2 is a block diagram showing the detailed structure of an access control system 100 according to one embodiment of the present invention. In the access control system 100, the access gateway 110 includes a context analysis unit 111, an access request information generation unit 112, a log management unit 113, and an access log 114. The trust score management unit 120 includes a trust parameter acquisition unit 121, a trust category analysis unit 122, a trust parameter selection unit 123, a trust score calculation unit 124, a warning unit 125, a trust parameter storage unit 127, a trust threshold storage unit 128, and a trust score storage unit 129. The policy management unit 130 includes a policy update unit 131 and a policy storage unit 132.
[0022] When the context analysis unit 111 receives an access request from a data requester 2 for access to restricted data, it obtains attribute information related to the access request from the workflow system and performs context analysis on the access request based on this attribute information. The context analysis performed by the context analysis unit 111 is the process of analyzing (estimating) the circumstances under which the data requester 2 is attempting to access the restricted data. The result of this context analysis is dynamically determined according to the attributes of the data requester 2, the attributes of the restricted data for which access has been requested, the progress of the workflow system, etc., and is represented by one of three context types, such as Ct1, Ct2, or Ct3. Therefore, the context analysis unit 111 can perform context analysis by obtaining this information as attribute information related to the access request. The attribute information of the access request obtained by the context analysis unit 111 and the result of the context analysis by the context analysis unit 111 are output to the access request information generation unit 112 and the trust score management unit 120, respectively. Details of the context analysis method used by the context analysis unit 111 will be described later.
[0023] The access request information generation unit 112 generates attribute information of the access request obtained by the context analysis unit 111, such as the subject attribute s described later. rt Action attribute a rt , resource attribute r rt , environmental attributes w rt Based on the attribute information of each element and the confidence score calculated by the confidence score calculation unit 124 in the confidence score management unit 120, access request information related to the access request received from the data requester 2 is generated. The access request information generated by the access request information generation unit 112 is output to the access determination unit 140.
[0024] The log management unit 113 records the access request from the data requester 2 and the response result to that access request in the access log 114, combined with the attribute information acquired at that time. The access log 114 provides historical information regarding the access request made by the data requester 2. This historical information is used by the confidence score calculation unit 124 when calculating the confidence score.
[0025] The trust parameter acquisition unit 121 acquires the trust parameters necessary for calculating the trust score and stores them in the trust parameter storage unit 127. For example, information such as the IP address of the information device used when data requester 2 connected to the data exchange platform 1 and made an access request, the virus protection status, and the number of suspicious packets on the network are acquired as trust parameters. In addition, information such as the past access request history and response history of data requester 2 and access time may also be acquired as trust parameters. These trust parameters may be acquired from a security monitoring system (not shown) or from the access requests of data requester 2. Various other types of information on the data exchange platform 1 can also be acquired as trust parameters.
[0026] The Trust Category Analysis Unit 122, based on the context analysis results from the Context Analysis Unit 111, performs a trust category analysis for the access request from the data requester 2. A trust category represents the type of trust parameter according to the context analysis results. For example, the trust categories "device," "network," "access," and "application" are pre-set in the Trust Score Management Unit 120. Based on the context analysis results, the Trust Category Analysis Unit 122 can select one of the above trust categories.
[0027] The trust parameter selection unit 123 receives the results of the trust category analysis by the trust category analysis unit 122 and selects a trust parameter stored in the trust parameter storage unit 127. The trust score management unit 120 has pre-configured combinations of trust parameters corresponding to each of the aforementioned trust categories. The trust parameter selection unit 123 can select a combination of trust parameters corresponding to the trust category selected by the trust category analysis unit 122 in the trust parameter storage unit 127.
[0028] The confidence score calculation unit 124 calculates a confidence score for the access request from the data requester 2 using the confidence parameters selected by the confidence parameter selection unit 123 and the threshold values for each confidence parameter stored in the confidence threshold storage unit 128. Details of how the confidence score calculation unit 124 calculates the confidence score will be described later. The confidence score calculation unit 124 stores the confidence score calculation result in the confidence score storage unit 129 and also outputs it to the access gateway 110.
[0029] The warning unit 125 monitors each trust parameter stored in the trust parameter storage unit 127, and if any trust parameter's value has decreased, it outputs a warning to the administrator of the access control system 100.
[0030] The policy storage unit 132 stores policies that describe the conditions for granting permission for access requests to various data requesters 2 and personal information combinations. The policies stored in the policy storage unit 132 are written, for example, according to the specifications of XACML (eXtensible Access Control Markup Language) and are read by the access determination unit 140.
[0031] The policy update unit 131 refers to the history of access requests from data requester 2, their response results, and attribute information recorded in the access log 114, and dynamically updates the policies stored in the policy storage unit 132 based on these reference results. For example, if a new access request is made from data requester 2, or if new personal information is provided by data provider 3, the policy is updated to reflect these changes. This ensures that even if there are changes in the participants in the workflow system (data requester 2 or data provider 3), the policy content can be appropriately updated according to the changes.
[0032] The access determination unit 140, based on the access request information input from the access request information generation unit 112, refers to the policies stored in the policy storage unit 132 and determines whether the access request is permitted. The result of the access determination unit 140's determination of whether the access request is permitted is output to the access gateway 110. Based on this determination result from the access determination unit 140, the access gateway 110 decides how to respond to the access request from the data requester 2. If the access request is permitted, it sends the specified access-restricted data to the data requester 2.
[0033] Figure 3 shows an example of the progress of the workflow system in the data exchange platform 1 and the access request information generated by the access control system 100. The workflow system is a series of procedures for correctly carrying out data transactions in the data exchange platform 1, and represents the processes that various participants participating in the data exchange platform 1 as data requesters 2 and data providers 3 should each perform. The workflow system 150 shown in Figure 3 is an example of a workflow system in which a real estate company, a rental guarantee company, and an insurance company use the data exchange platform 1 to exchange personal information of end-user user A in order to determine the contract terms when user A enters into a rental agreement.
[0034] In the workflow system 150, a real estate company that receives a rental contract application from user A enters user A's personal information into the workflow system 150. The entered personal information of user A is transmitted to the rental guarantee company via the workflow system 150 and used by the rental guarantee company to determine the contract terms. At this time, the insurance company, as data requester 2, requests access to user A's personal information, such as the rental guarantee contract application form and income certificate, in order to determine the contract terms applicable to user A.
[0035] If the rental guarantee company is still considering the contract terms, the workflow system 150 puts the rental guarantee company's procedures on hold. At time t1, when the insurance company requests access to user A's personal information, the access control system 100 uses the access request information generation unit 112 to generate access request information, for example, as shown in reference numeral 151. In this access request information 151, the value indicating the progress of the workflow system 150 is set to "pending" to indicate that the rental guarantee company's procedures are on hold.
[0036] Subsequently, at time t2, when the rental guarantee company determines the contract terms, the workflow system 150 completes the rental guarantee company's procedures. After time t2, when the insurance company requests access to user A's personal information, the access control system 100 uses the access request information generation unit 112 to generate access request information, for example, as shown in reference numeral 152. In this access request information 152, the value indicating the progress of the workflow system 150 is set to "completed" to indicate that the rental guarantee company's procedures have been completed.
[0037] Furthermore, at time t2, the policy update unit 131 updates the policy in the access control system 100 to reflect the change in the progress status of the workflow system 150 from "pending" to "completed". At this time, the policy update unit 131 executes, for example, the instruction shown by reference numeral 153.
[0038] As described above, the access control system 100 generates access request information in real time, reflecting the progress of the workflow system, and uses this access request information to determine whether or not the access request is permitted.
[0039] Furthermore, if the progress of the workflow system cannot be confirmed for any reason, the access control system 100 may return "failed" as the value indicating the progress of the workflow system 150. In this case, the access control system 100 will reject the access request from the insurance company until the progress of the workflow system 150 becomes "completed". This way, for example, if a rental guarantee company decides to withdraw a contract, the entire procedure up to that point in the workflow system 150 can be invalidated, preventing unintended leakage of personal information.
[0040] Figure 4 shows an example of context types determined by context analysis performed by the context analysis unit 111. In the access control system 100, when the context analysis unit 111 receives an access request from the data requester 2 as described above, it performs context analysis on that access request. At this time, the context analysis unit 111 can perform context analysis by determining which of the three context types, for example Ct1, Ct2, or Ct3, the access request belongs to, based on attribute information obtained from the workflow system.
[0041] In Figure 4, the part indicated by reference numeral 401 shows an example of an access request corresponding to context type Ct1. In this case, for example, an insurance company or a rental guarantee company becomes the data requester 2 and requests access to the personal information of end users held by the data provider 3, which is the end user or third-party company, via the data exchange platform 1.
[0042] The part indicated by reference numeral 402 shows an example of an access request corresponding to context type Ct2. In this case, for example, a financial company or insurance company that provides services to end users becomes data requester 2 and makes an access request to a real estate company that provides services to the same end users, via the data exchange platform 1, for the purpose of reviewing contract terms, regarding the confidence score calculated from past access requests made by the real estate company.
[0043] The part indicated by reference numeral 403 shows an example of an access request corresponding to context type Ct3. In this case, for example, an end user becomes data requester 2 and makes an access request to an insurance company that provides services to the end user via the data exchange platform 1 to determine whether to receive services from this insurance company. This request is based on a confidence score calculated from past access requests made by the insurance company.
[0044] In each of the context types Ct1 to Ct3 described above, the content of data requester 2 and data provider 3 may differ. The method can be applied to any data transaction as long as it can determine which of the three context types applies. Furthermore, the context analysis unit 111 is not limited to determining Ct1 to Ct3; it may also determine which of other context types applies.
[0045] Figure 5 shows an example of the categorization of trust parameters in the trust category analysis unit 122. In the trust category analysis unit 122, for example, trust category 500 is set to include category 501 corresponding to "device", category 502 corresponding to "network", category 503 corresponding to "access", and category 504 corresponding to "application". Categories 501 to 504 are associated with the aforementioned context types Ct1 to Ct3, and information representing these correspondences is pre-stored in the trust category analysis unit 122. Based on this information, the trust category analysis unit 122 can dynamically select one of categories 501 to 504 from the context analysis results by the context analysis unit 111.
[0046] Category 501, which corresponds to "device," is a category that summarizes the trust parameters regarding the security status of the device to which data requester 2 has requested access from data exchange platform 1. Category 501 includes trust parameters such as the security patch update status of the device, whether or not the device's IP address is blacklisted, the device's vulnerability to viruses and malware, and the adoption status of other security measures on the device. The values of these trust parameters are expressed as either 1 (positive) or -1 (negative), for example.
[0047] Category 502, which corresponds to "Network," is a category that summarizes trust parameters regarding the security status of the network used by data requester 2 to connect to data exchange platform 1 when making an access request. Category 502 includes trust parameters such as the presence or absence of suspicious packets from the network and the presence or absence of encryption measures on the network. The values of these trust parameters are expressed as either 1 (positive) or -1 (negative), for example.
[0048] Category 503, which corresponds to "Access," is a category that summarizes the reliability parameters regarding the access status from data requester 2, and is obtained from the access log 114 recorded in the access gateway 110. Category 503 includes, for example, the access attempt rate and access frequency, which are calculated using the following formulas. Access attempt rate = (Number of invalid access attempts) / (Total number of access attempts) Access frequency = (Number of access attempts) / (Total number of access attempts per unit of time)
[0049] Category 504, which corresponds to "Applications," is a category that summarizes the trust parameters related to the internal processing of Data Exchange Platform 1. Category 504 includes trust parameters such as the reputation and service quality of Data Requester 2, which made the access request, as well as feedback to the Data Requester 2 registered by the administrator, the processing speed for Data Requester 2's access request, and the recommendation history which represents the popularity of Data Requester 2 on Data Exchange Platform 1.
[0050] The contents of categories 501 to 504 in the confidence category 500 described above are just examples, and other confidence parameters may be included in each category. Furthermore, the category classification of confidence parameters in the confidence category analysis unit 122 is not limited to the confidence category 500 exemplified in Figure 5; other category classifications may also be adopted.
[0051] Figures 6 and 7 are flowcharts showing the flow of access control processing performed by the access control system 100.
[0052] In step S101, the access gateway 110 receives an access request from data requester 2.
[0053] In step S102, the context analysis unit 111 of the access gateway 110 obtains attribute information of the access request received in step S101 from the workflow system. Specifically, for example, subject attribute s representing the attributes of data requester 2. rt Action attribute a, which represents the type of access request (view, edit, delete, etc.) rt , the resource attribute r represents the access-restricted data that is the target of the access request. rt , an environment attribute that represents the state of the workflow system at the time of the access request w rt Attribute information such as these is acquired in real time from the workflow system. This attribute information is used in standard XACML processing models.
[0054] In step S103, the context analysis unit 111 performs context analysis based on the attribute information acquired in step S102. Here, it selects one of the context types Ct1 to Ct3, for example, according to the relationship between each attribute piece of pre-configured attribute information and the context type. Once a context type has been selected in step S103, the context analysis unit 111 outputs the selection result to the confidence score management unit 120.
[0055] In step S104, the trust category analysis unit 122 of the trust score management unit 120 determines whether the context type selected by the context analysis unit 111 in step S103 is one of the context types Ct1 to Ct3. If the result is that it is context type Ct1, the process proceeds to step S105; if it is context type Ct2, it proceeds to step S106; and if it is context type Ct3, it proceeds to step S107.
[0056] In step S105, the trust category analysis unit 122 selects the trust categories 501 to 503 that correspond to "device," "network," and "access" respectively from the categories 501 to 504 exemplified in Figure 5.
[0057] In step S106, the trust category analysis unit 122 selects the respective trust categories of categories 503 and 504 corresponding to "Access" and "Application" among the categories 501 to 504 illustrated in FIG. 5.
[0058] In step S107, the trust category analysis unit 122 selects the trust category of category 504 corresponding to "Application" among the categories 501 to 504 illustrated in FIG. 5.
[0059] If any one of steps S105 to S107 is executed, the process proceeds to step S108. In step S108, the trust parameter selection unit 123 selects the trust parameters corresponding to the trust categories selected in steps S105 to S107 according to the combination of trust parameters corresponding to the categories 501 to 504 illustrated in FIG. 5 respectively.
[0060] In step S109, the trust score calculation unit 124 calculates a trust score based on the trust parameters selected in step S108. Here, based on the selection result of the context type in step S103, for example, a trust score can be calculated from the trust parameters by a method as described later. After calculating the trust score in step S109, the trust score calculation unit 124 stores the calculation result in the trust score storage unit 129 and outputs it to the access gateway 110.
[0061] In step S110, the access request information generation unit 112 of the access gateway 110 uses the attribute information of the access request obtained by the context analysis unit 111 in step S102, for example, the aforementioned subject attribute s rt , action attribute a rt , resource attribute r rt , environmental attribute w rtEach attribute information is obtained from the context analysis unit 111. In addition, the confidence score calculation result calculated by the confidence score calculation unit 124 in step S109, for example, the confidence score value of "satisfied" or "not satisfied" as described later, is obtained. Then, based on this obtained information, access request information is generated and the generated access request information is output to the access determination unit 140.
[0062] In step S111, the access determination unit 140 performs an access determination for the access request received in step S101 based on the access request information received from the access request information generation unit 112 in step S110. This allows the access determination to be made based on the confidence score calculated by the confidence score calculation unit 124 in step S109. The result of the access determination in step S111 is output from the access determination unit 140 to the access gateway 110.
[0063] In step S112, the access gateway 110 determines whether to allow the data requester 2 to access the restricted data based on the access determination result received from the access determination unit 140 in step S111. If it determines to allow access, it proceeds to step S113; if it determines not to allow access, it proceeds to step S114.
[0064] In step S113, the access gateway 110 sends the access restriction data corresponding to the access request to the data requester 2 as a response to the access request received in step S101.
[0065] In step S114, the access gateway 110 rejects the access request received in step S101 and blocks access to the restricted data specified by the data requester 2.
[0066] After executing the process in step S113 or step S114, in the following step S115, the log management unit 113 combines the attribute information obtained in step S102, the result of the context analysis performed in step S103, and the access judgment result in step S111, and records these contents in the access log 114. After executing the process in step S115, the flowcharts in Figures 6 and 7 are terminated.
[0067] When an access request is made by data requester 2, the access control system 100 executes the access control process described above to determine whether the access request is permitted. If the access request is permitted, it returns the personal information and other access-restricted data specified in the access request to data requester 2. This enables secure mediation of access-restricted data between data requester 2 and data provider 3 using a workflow system.
[0068] Figure 8 shows an example of confidence parameters and warning count values. Figure 8(a) shows an example of confidence parameters acquired by the confidence parameter acquisition unit 121 and stored in the confidence parameter storage unit 127. In the confidence parameter storage unit 127, as shown in Figure 8(a), for example, the parameter values P1, P2, P5, P7 of each acquired confidence parameter are stored in a table format along with their respective confidence categories and weights W1, W2, W5, W7 in weight order. The weights W1, W2, W5, W7 of each confidence parameter are set according to their respective importance, for example, in the range of 0 to 100.
[0069] Figure 8(b) shows an example of a warning count value used by the warning unit 125 when outputting a warning. As shown in Figure 8(b), for example, the warning unit 125 compares the product of the parameter values P1, P2, P5, P7 of each reliability parameter and the weights W1, W2, W5, W7 with the respective thresholds Th1, Th2, Th5, Th7 in order of weight. If the product is less than the threshold, the warning count value is incremented by 1. When the warning count value reaches a predetermined upper limit, a warning is output to the administrator. As shown in Figure 8(a), the warning count value of each reliability parameter is stored in the reliability parameter storage unit 127 along with the parameter values P1, P2, P5, P7 and the weights W1, W2, W5, W7.
[0070] The weights W1, W2, W5, W7 and thresholds Th1, Th2, Th5, Th7 mentioned above are pre-set in the access control system 100 and may change dynamically according to the properties of each reliability parameter. For example, in the case of access frequency, which is one of the reliability parameters, the access frequency during peak hours is higher than during other times, so the parameter value changes periodically. Therefore, in this case, it is preferable to change the weights and thresholds for access frequency according to the time of day. In addition to this, it is possible to dynamically change the weights and thresholds according to any rule that corresponds to the properties of each reliability parameter.
[0071] Next, we will explain how to calculate the confidence score. Figure 9 is an example of a flowchart showing the flow of the confidence score calculation process. For example, if the context analysis unit 111 selects the aforementioned context type Ct1, the confidence score calculation unit 124 executes the process shown in the flowchart of Figure 9 and calculates the confidence score.
[0072] In step S201, the confidence score calculation unit 124 obtains the number of confidence parameters N. Here, the total number of confidence parameters selected by the confidence parameter selection unit 123 in step S108 of Figure 6 is obtained as the number of confidence parameters N.
[0073] In step S202, the trust score calculation unit 124 randomly selects (x - n + 1) trust parameters Pn to Px from the trust parameters selected by the trust parameter selection unit 123 in step S108 of FIG. 6. Here, for example, values of x and n that satisfy the conditions of 0 < n ≤ x ≤ N are randomly selected, and the trust parameters of each category of "device", "network", and "access" selected by the trust parameter selection unit 123 are arranged in descending order of weight, and each trust parameter from the nth to the xth can be selected as the trust parameters Pn to Px. Alternatively, the trust parameters Pn to Px can be randomly selected by any method.
[0074] After selecting the trust parameters Pn to Px in step S202, the trust score calculation unit 124 repeatedly executes the loop processing of the following steps S203 to S205 from i = n to i = x.
[0075] In step S203, the trust score calculation unit 124 acquires the threshold Thi of the trust parameter Pi (i = n to x) from the trust threshold storage unit 128.
[0076] In step S204, the trust score calculation unit 124 compares the trust parameter Pi with the threshold Thi acquired in step S203, and determines whether the condition of Pi ≥ Thi is satisfied. As a result, if the condition is satisfied, that is, when the trust parameter Pi is greater than or equal to the threshold Thi, it proceeds to step S205, increments the count value Cn of the trust score by 1, and then proceeds to the next loop processing. On the other hand, if the condition is not satisfied, that is, when the trust parameter Pi is less than the threshold Thi, the count value Cn of the trust score remains unchanged and proceeds to the next loop processing.
[0077] After completing the loop processing in steps S203 to S205, in step S206, the confidence score calculation unit 124 determines whether the count value Cn of the confidence score finally obtained in the loop processing is equal to or greater than a predetermined percentage (e.g., 0.6) of the sum of the values when all (x-n+1) confidence parameters are 1. If the count value Cn is 0.6(x-n+1) or greater, that is, if 60% or more of the randomly selected confidence scores represent a positive result, the process proceeds to step S207. On the other hand, if the count value Cn is less than 0.6(x-n+1), the process proceeds to step S208.
[0078] In step S207, the confidence score calculation unit 124 sends the confidence score value "satisfied," which indicates "reliable," as the result of calculating the confidence score for the access request from data requester 2, to the access gateway 110, for example, in a message in JSON (JavaScript® Object Notation) format.
[0079] In step S208, the confidence score calculation unit 124 sends the confidence score value "not satisfied," which represents "not trustworthy," as the result of calculating the confidence score for the access request from data requester 2, to the access gateway 110, for example, in a message in JSON format.
[0080] After completing the process in step S207 or S208, the confidence score calculation unit 124 terminates the confidence score calculation process shown in the flowchart of Figure 9.
[0081] In the confidence score calculation process described above, the confidence parameters Pn to Px used in calculating the confidence score are randomly selected by dynamically choosing the values of x and n. This makes it difficult to predict the access judgment patterns in the access control system 100, thereby preventing attacks from malicious hackers and other attackers.
[0082] Alternatively, the confidence score may be calculated using the method described below. For example, if the context analysis unit 111 selects the aforementioned context type Ct2 or Ct3, the confidence score calculation unit 124 calculates the confidence score using the following method.
[0083] The confidence score calculation unit 124 can calculate the confidence score Ts using, for example, the following equation (1). In equation (1), N represents the number of confidence parameters mentioned above, and Pj represents the value of the j-th confidence parameter among the confidence parameters selected by the confidence parameter selection unit 123 in step S108 of Figure 6. Wj represents the weight set in advance for the j-th confidence parameter.
number
[0084] The confidence score Ts calculated by formula (1) above corresponds to weighted summation of all selected confidence parameters. That is, the confidence score calculation unit 124 can calculate the confidence score Ts by weighted summation of the confidence parameters corresponding to categories 501 to 504 as illustrated in Figure 5, specifically the confidence parameters for categories 503 and 504 that correspond to "Access" and "Application," respectively, which are pre-set to correspond to context type Ct2, or the confidence parameters for category 504 that correspond to "Application," which are pre-set to correspond to context type Ct3. In addition, the confidence score Ts may be normalized within the range of 0 to 1 to facilitate comparison between confidence scores.
[0085] As mentioned above, in context types Ct2 and Ct3, past trust scores of various service providers (financial companies, insurance companies, etc.) are provided as data subject to access restrictions in order to consider contract terms and service provision to end users. Therefore, unlike in context type Ct1, where the permissibility of access requests to end users' personal information is determined, there is less need to make it difficult to predict access decision patterns. Accordingly, the trust score is calculated by weighting and adding all selected trust parameters using equation (1) to appropriately reflect the situation at the time of the access request.
[0086] Next, the method for analyzing the reliability parameters will be described. For example, if the context analysis unit 111 selects context type Ct2 or Ct3, the access gateway 110 provides the end user with a user interface for multidimensional analysis of the reliability parameters used to calculate the reliability score. In this user interface, the end user can receive the information necessary for analyzing the reliability parameters from the access control system 100 by setting desired conditions.
[0087] Figure 10 shows an example of multidimensional analysis of trust parameters. Figure 10(a) shows an example of a user interface displayed on an end-user's terminal when performing multidimensional analysis of trust parameters. In Figure 10(a), figure 1000 shows the value of the number of unauthorized access attempts, one of the trust parameters used to calculate a company's trust score, broken down by branch and month. Figure 1005 shows the value of the number of unauthorized access attempts for the same company, broken down by region and year. These figures 1000 and 1005 have three dimensions, one of which represents the organizational hierarchy of the service provider company, such as branch or region, and the other dimension represents the acquisition period for the trust parameter, the number of unauthorized access attempts, such as month or year.
[0088] Figure 10(b) shows examples of item selection for each dimension in figures 1000 and 1005. On the screen displayed on the terminal, the end user can select the company name, region, and branch items for one dimension of these figures as appropriate, either drilling up or drilling down. Similarly, for the other dimensions, the year, quarter, and month items can be selected as appropriate, either drilling up or drilling down.
[0089] Furthermore, the user interface exemplified in Figure 10 may be provided not only to end users, but also to, for example, administrators of the access control system 100. The trust parameters used to calculate the trust score change according to various levels such as user level, role level, and company level. By using the information shown in the user interface of Figure 10, administrators can appropriately issue warnings to each company connecting to the access control system 100 as data requesters 2 or data providers 3 regarding changes in trust parameters.
[0090] Next, the method for analyzing the confidence score will be explained. The access gateway 110 provides the end user with a user interface for analyzing the confidence score, for example. Through this user interface, the end user can receive the information necessary for analyzing the confidence score from the access control system 100 by selecting the desired items.
[0091] Figure 11 shows an example of a trust score analysis screen. The trust score analysis screen 1100 shown in Figure 11 is a screen displayed on an end user's terminal by, for example, an access gateway 110, and has selection boxes 1101, 1102, 1103 and a trust score graph 1104. When an end user is considering a contract for a new service, for example, they can request the access control system 100 to display a trust score analysis screen 1100 like the one in Figure 11 in order to analyze the trust scores of each company providing the service.
[0092] Selection box 1101 is a box for end users to select the types of services to be analyzed for the trust score. In this selection box 1101, end users can select the types of companies corresponding to the service type, for example, to select the items to be analyzed for the trust score displayed on the trust score analysis screen 1100.
[0093] Selection box 1102 is a box for end users to select security levels and other requirements. In this selection box 1102, end users can select various requirements related to the trust score.
[0094] Selection box 1103 is a box for the end user to select the hierarchical level of the service provider. In this selection box 1103, the end user can select the hierarchical level of the service provider to be analyzed for the confidence score from various hierarchical levels, such as company name, region, and branch office.
[0095] The Trust Score Graph 1104 visualizes the trust score values corresponding to the items selected in selection boxes 1101 to 1103. By referring to this Trust Score Graph 1104, end users can compare the trust scores of each service provider and consider which service provider to enter into a new service contract with.
[0096] In the real estate industry, it is known that fraudulent practices exist in which real estate companies falsify documents such as income certificates and employment status of end-users (customers or tenants) without informing the end-users in order to obtain loan approval from financial companies. Below, an example of the practical operation of access control system 100 to prevent such fraudulent activities will be explained with reference to Figure 12.
[0097] Figure 12 is a sequence diagram showing an example of the actual operation of an access control system 100 according to one embodiment of the present invention. When an end user submits personal information such as income certificates and employment status to a real estate company, the real estate company, on behalf of the user, inputs the personal information into the data exchange platform 1. Based on the input personal information, the access control system 100 manages policies and workflow systems and notifies the financial company that a new loan application has been made. Upon receiving this notification, the financial company checks the application details from the end user via the access control system 100, performs a trust score analysis on the real estate company that entered the information as needed, and determines whether to approve (OK) or deny (NG) the loan. The financial company's decision is notified to the end user via the access control system 100.
[0098] According to the embodiment of the present invention described above, the following effects are achieved.
[0099] (1) The access control system 100 is used in a data exchange platform 1 that mediates access-restricted data between a data requester 2 and a data provider 3. The access control system 100 includes an access gateway 110 that performs contextual analysis of access requests from data requesters 2 to access-restricted data, a trust score management unit 120 that randomly selects one or more trust parameters from a plurality of trust parameters obtained from a workflow system provided by the data exchange platform 1 based on the results of the contextual analysis by the access gateway 110 and calculates a trust score for the access request based on the selected trust parameters, and an access determination unit 140 that determines whether the access request is permissible based on the trust score calculated by the trust score management unit 120. In this way, secure and robust access control can be achieved.
[0100] (2) In context analysis, the access gateway 110 acquires attribute information including the attributes of data requester 2, the attributes of the data subject to access restrictions, and the progress of the workflow system (step S102), and determines whether the access request belongs to the first context (context type Ct1), the second context (context type Ct2), or the third context (context type Ct3) based on the acquired attribute information (step S103). As shown by reference numerals 401 to 403 in Figure 4, in context type Ct1, data requester 2 is a service provider that provides services to the end user, data provider 3 is another service provider or the end user, and the data subject to access restrictions is personal information relating to the end user. In context type Ct2, data requester 2 is a service provider, data provider 3 is another service provider, and the data subject to access restrictions is information about the confidence score calculated when another service provider previously made an access request as data requester 2. Furthermore, in context type Ct3, data requester 2 is an end user, data provider 3 is a service provider, and access-restricted data is information about the confidence score calculated when the service provider previously made an access request as data requester 2. In this way, contextual analysis of access requests from data requester 2 to access-restricted data can be performed appropriately.
[0101] (3) When the access gateway 110 determines that the access request corresponds to context type Ct1 (step S105), the trust score management unit 120 randomly selects a predetermined number of trust parameters in order of priority from among a predetermined number of trust parameters that are set in advance to correspond to context type Ct1 (step S202), and calculates a trust score by determining whether a predetermined proportion or more of the selected trust parameters are above a predetermined threshold (steps S203 to S206). Furthermore, when the access gateway 110 determines that the access request corresponds to context type Ct2 or context type Ct3 (steps S106 to S107), the trust score management unit 120 calculates a trust score by weighting and adding each of the trust parameters that are set in advance to correspond to context type Ct2 or context type Ct3 among the multiple trust parameters according to formula (1). In this way, the trust score can be appropriately calculated according to the situation at the time of the access request.
[0102] (4) When the access gateway 110 determines that the access request falls under context type Ct2 or context type Ct3, it provides the end user with a user interface for multidimensional analysis of the trust parameters used to calculate the trust score, for example, as shown in figures 1000 and 1005 in Figure 10. This user interface includes a section for selecting the organizational hierarchy of the service provider or the period for acquiring the trust parameters on the screen. In this way, the end user can receive the information necessary for analyzing the trust parameters from the access control system 100.
[0103] (5) The confidence score management unit 120 selects one of several pre-set confidence categories (categories 501 to 504) based on the results of the context analysis, and then randomly selects one or more confidence parameters from a combination of pre-set confidence parameters for the selected confidence category (step S108). In this way, it is possible to reliably select confidence parameters suitable for calculating the confidence score using the results of the context analysis.
[0104] (6) The access gateway 110 has a trust score and attribute information of the access request according to the progress of the workflow system (subject attribute s rt Action attribute a rt , resource attribute r rt , environmental attributes w rt The system has an access request information generation unit 112 that generates access request information corresponding to an access request based on the following. The access request information generation unit 112 transmits the generated access request information to the access determination unit 140 (step S110). The access determination unit 140 determines whether the access request is permissible or not based on the access request information received from the access request information generation unit 112 (step S111). In this way, it is possible to accurately determine whether the access request is permissible or not, taking into account the confidence score and the progress of the workflow.
[0105] (7) The access control system 100 includes a policy storage unit 132 that stores policies describing the conditions for granting access requests and allows the access determination unit 140 to refer to these policies, and a policy update unit 131 that updates the policies stored in the policy storage unit 132. The policy update unit 131 updates the policies in response to changes in the participants of the workflow system. In this way, even if there are changes in the data requester 2 or data provider 3 in the workflow system, the contents of the policies can be appropriately updated according to the changes.
[0106] (8) The access control method by the access control system 100 is an access control method in the data exchange platform 1 that mediates access-restricted data between the data requester 2 and the data provider 3. In this access control method, a context analysis is performed on the access request from the data requester 2 to the access-restricted data (step S103), and based on the results of the context analysis, one or more trust parameters are randomly selected from a plurality of trust parameters obtained from the workflow system provided by the data exchange platform 1 (step S108). Then, a trust score for the access request is calculated based on the selected trust parameters (step S109), and the permission or non-permission of the access request is determined based on the trust score (step S111). In this way, safe and robust access control can be achieved.
[0107] It should be noted that the present invention is not limited to the embodiments described above, and can be implemented using any components without departing from the spirit of the invention. The embodiments and modifications described above are merely examples, and the present invention is not limited to these as long as the features of the invention are not impaired. Furthermore, although various embodiments and modifications have been described above, the present invention is not limited to these. Other embodiments that can be conceivable within the scope of the technical idea of the present invention are also included within the scope of the present invention. [Explanation of Symbols]
[0108] 1…Data exchange platform, 2…Data requester, 3…Data provider, 100…Access control system, 110…Access gateway, 111…Context analysis unit, 112…Access request information generation unit, 113…Log management unit, 114…Access log, 120…Trust score management unit, 121…Trust parameter acquisition unit, 122…Trust category analysis unit, 123…Trust parameter selection unit, 124…Trust score calculation unit, 125…Warning unit, 127…Trust parameter storage unit, 128…Trust threshold storage unit, 129…Trust score storage unit, 130…Policy management unit, 131…Policy update unit, 132…Policy storage unit, 140…Access determination unit, 150…Workflow system
Claims
1. An access control system used in a data exchange platform that mediates access-restricted data between data requesters and data providers, An access gateway that performs contextual analysis on access requests from data requesters to the access-restricted data, A trust score management unit randomly selects one or more trust parameters from a plurality of trust parameters obtained from the workflow system provided by the data exchange platform based on the results of the context analysis by the access gateway, and calculates a trust score for the access request based on the selected trust parameters. An access control system comprising: an access determination unit that determines whether or not to grant the access request based on the trust score calculated by the trust score management unit.
2. In the access control system according to claim 1, The access gateway, in the context analysis, acquires attribute information including the attributes of the data requester, the attributes of the data subject to access restrictions, and the progress of the workflow system, and determines, based on the acquired attribute information, whether the access request falls under the first, second, or third context. In the first context described above, the data requester is a service provider that provides services to an end user, the data provider is another service provider or the end user, and the data subject to access restrictions is information relating to the end user. In the second context described above, the data requester is the service provider, the data provider is the other service provider, and the access-restricted data is information relating to the confidence score calculated when the other service provider made the access request as the data requester in the past. In the third context described above, the data requester is the end user, the data provider is the service provider, and the access-restricted data is an access control system relating to the confidence score calculated when the service provider previously made the access request as the data requester.
3. In the access control system according to claim 2, If the access gateway determines that the access request falls under the first context, the trust score management unit selects a randomly determined number of trust parameters in order of priority from among the plurality of trust parameters, which are set in advance in accordance with the first context, and calculates the trust score by determining whether a predetermined proportion or more of the selected trust parameters are above a predetermined threshold. An access control system in which, when the access gateway determines that the access request falls under the second context or the third context, the trust score management unit calculates the trust score by weighting and adding up each of the multiple trust parameters that have been set in advance to correspond to the second context or the third context.
4. In the access control system according to claim 3, When the access gateway determines that the access request falls under the second or third context, it provides the end user with a user interface for multidimensional analysis of the confidence parameters used to calculate the confidence score. The user interface is an access control system that includes a section on the screen for selecting the organizational hierarchy of the service provider or the acquisition period for the trust parameters.
5. In the access control system according to claim 1, The trust score management unit is an access control system that selects trust parameters by selecting one of a plurality of pre-set trust categories based on the results of the context analysis, and randomly selecting one or more trust parameters from a combination of pre-set trust parameters for the selected trust category.
6. In the access control system according to claim 1, The access gateway has an access request information generation unit that generates access request information corresponding to the access request based on the trust score and attribute information of the access request according to the progress of the workflow system, The access request information generation unit transmits the generated access request information to the access determination unit. The access determination unit is an access control system that determines whether or not to grant an access request based on the access request information received from the access request information generation unit.
7. In the access control system according to claim 1, A policy storage unit stores a policy describing the permission conditions for the access request, and causes the access determination unit to refer to the policy. The system comprises a policy update unit for updating the policies stored in the policy storage unit, The policy update unit is an access control system that updates the policy in response to changes in the participants of the workflow system.
8. An access control method in a data exchange platform that uses a computer to mediate access-restricted data between a data requester and a data provider, The aforementioned computer performs contextual analysis on the access request from the data requester to the access-restricted data, Based on the results of the context analysis, the computer randomly selects one or more trust parameters from a plurality of trust parameters obtained from the workflow system provided by the data exchange platform. The computer calculates a confidence score for the access request based on the selected confidence parameters. An access control method in which the computer determines whether or not to grant the access request based on the confidence score.
Citation Information
Patent Citations
User trust measurement method in zero-trust SDN network
CN112737824A
Database fine-grained access control method based on zero-trust architecture
CN113051602A
System and method for protecting terminal devices on dynamically configured network
JP2015212939A
Dynamic determination of access rights
US20120054826A1