《计算机应用》唯一官方网站 ›› 2024, Vol. 44 ›› Issue (4): 1148-1157.DOI: 10.11772/j.issn.1001-9081.2023040529

• 网络空间安全 • 上一篇    

基于主从多链的数据分类分级访问控制模型

陈美宏1, 袁凌云1,2(), 夏桐1   

  1. 1.云南师范大学 信息学院,昆明 650500
    2.民族教育信息化教育部重点实验室(云南师范大学),昆明 650500
  • 收稿日期:2023-05-06 修回日期:2023-08-03 接受日期:2023-08-07 发布日期:2023-12-04 出版日期:2024-04-10
  • 通讯作者: 袁凌云
  • 作者简介:陈美宏(1999—),女(土家族),湖北恩施人,硕士研究生,主要研究方向:区块链、访问控制、联邦学习
    袁凌云(1980—),女,云南昭通人,教授,博士,CCF会员,主要研究方向:物联网安全、区块链、传感器网络 blues520@sina.com
    夏桐(1998—),女,河南信阳人,硕士研究生,主要研究方向:访问控制、可解释机器学习。
  • 基金资助:
    国家自然科学基金资助项目(62262073);云南省重大科技专项计划项目(202202AE090011);云南省应用基础研究计划项目(202101AT070098);云南省万人计划青年拔尖人才项目(YNWR?QNBJ?2019?237);云南师范大学研究生创新基金资助项目(YJSJJ23?B179)

Data classified and graded access control model based on master-slave multi-chain

Meihong CHEN1, Lingyun YUAN1,2(), Tong XIA1   

  1. 1.School of Information Science and Technology,Yunnan Normal University,Kunming Yunnan 650500,China
    2.Key Laboratory of Educational Informatization for Nationlities,Ministry of Education (Yunnan Normal University),Kunming Yunnan 650500,China
  • Received:2023-05-06 Revised:2023-08-03 Accepted:2023-08-07 Online:2023-12-04 Published:2024-04-10
  • Contact: Lingyun YUAN
  • About author:CHEN Meihong, born in 1999, M. S.candidate. Her research interests include blockchain, access control, federated learning.
    YUAN Lingyun, born in 1980, Ph. D., professor. Her research interests include IoT security, blockchain, sensor network.
    XIA Tong, born in 1998, M. S.candidate. Her research interests include access control, interpretable machine learning.
  • Supported by:
    National Natural Science Foundation of China(62262073);Yunnan Province Major Science and Technology Special Plan(202202AE090011);Applied Basic Research Program Project of Yunnan Province(202101AT070098);Youth Top Talent Project of Yunnan Ten-Thousand Talents Plan(YNWR-QNBJ-2019-237);Graduate Innovation Fund of Yunnan Normal University(YJSJJ23-B179)

摘要:

为解决数据混合存储导致精准查找速度慢、数据未分类分级管理造成安全治理难等问题,构建基于主从多链的数据分类分级访问控制模型,实现数据的分类分级保障与动态安全访问。首先,构建链上链下混合式可信存储模型,以平衡区块链面临的存储瓶颈问题;其次,提出主从多链架构,并设计智能合约,将不同隐私程度的数据自动存储于从链;最后,以基于角色的访问控制为基础,构建基于主从多链与策略分级的访问控制(MCLP-RBAC)机制并给出具体访问控制流程设计。在分级访问控制策略下,所提模型的吞吐量稳定在360 TPS(Transactions Per Second)左右。与BC-BLPM方案相比,发送速率与吞吐量之比达到1∶1,具有一定优越性;与无访问策略相比,内存消耗降低35.29%;与传统单链结构相比,内存消耗平均降低52.03%;与数据全部上链的方案相比,平均存储空间缩小36.32%。实验结果表明,所提模型能有效降低存储负担,实现分级安全访问,具有高扩展性,适用于多分类数据的管理。

关键词: 区块链, 星际文件系统, 访问控制, 多分类, 数据安全

Abstract:

In order to solve the problems of slow accurate search speed due to mixed data storage and difficult security governance caused by unclassified and graded data management, a data classified and graded access control model based on master-slave multi-chain was built to achieve classified and graded protection of data and dynamic secure access. Firstly, a hybrid on-chain and off-chain trusted storage model was constructed to balance the storage bottleneck faced by blockchain. Secondly, a master-slave multi-chain architecture was proposed and smart contracts were designed to automatically store data with different privacy levels in the slave chain. Finally, based on Role-Based Access Control, a Multi-Chain and Level Policy-Role Based Access Control (MCLP-RBAC) mechanism was constructed and its specific access control process design was provided. Under the graded access control policy, the throughput of the proposed model is stabilized at around 360 TPS (Transactions Per Second). Compared with the BC-BLPM scheme, it has a certain superiority in throughput, with the ratio of sending rate to throughput reaching 1∶1. Compared with no access strategy, the memory consumption is reduced by about 35.29%; compared with the traditional single chain structure, the memory average consumption is reduced by 52.03%. And compared with the scheme with all the data on the chain, the average storage space is reduced by 36.32%. The experimental results show the proposed model can effectively reduce the storage burden, achieve graded secure access, and suitable for the management of multi-class data with high scalability.

Key words: blockchain, Inter Planetary File System (IPFS), access control, multi-class, data security

中图分类号: