计算机科学
访问控制
许可
计算机安全
认证(法律)
身份管理
基于角色的访问控制
计算机访问控制
钥匙(锁)
身份(音乐)
加密
资源(消歧)
计算机网络
法学
物理
政治学
声学
作者
Qikun Zhang,Liang Zhu,Kunyuan Zhao,Yimeng Wu,Beihong Jin,Jianyong Li,Yinghui Meng,Sikang Hu
标识
DOI:10.1007/s11235-022-00937-8
摘要
Access control technology is one of the key technologies to ensure safe resource sharing. Identity authentication and authority distribution are two key technologies for access control technology to restrict unauthorized users from accessing resources, and only authorised legal users can access resources. However, user privacy protection and frequent permission changes are two thorny issues that need to be solved urgently by access control technology. In this paper, a dynamic access control model based on privacy protection is proposed to deal with these problems. Compared with existing access control technologies, the main advantages of this paper are as follows: (1) Encrypt and hide the attributes of entities, and use attribute-based identity authentication technology for identity authentication, which not only achieves the purpose of traditional identity authentication, but also ensures the attributes and privacy of entities are not leaked; (2) Binding resource access permissions with entity attributes, dynamically assigning and adjusting resource access control permissions through changes in entity attributes, making resource access control more fine-grained and more flexible. Security proof and performance analysis show that the proposed protocol is secure under the hardness assumption of the discrete logarithm problem and the decision bilinear Diffie–Hellman problem. Compared with the cited references, this model has the advantages of low computational complexity, short computational time, and low communication overhead.
科研通智能强力驱动
Strongly Powered by AbleSci AI