Abstract: Disclosed are a client apparatus a server apparatus and an access control system for authorized access. The client apparatus comprises a request generating unit configured to generate a request for authorized access to a protected resource and send the request to a server apparatus; a recording unit configured to record the request in a public database wherein the public database is a decentralized distributive database and records in the public database are inalterable; and an access unit configured to utilize response information sent by the server apparatus in response to the request to execute a corresponding operation for accessing the protected resource. According to embodiments of the present invention network attacks such as replay attacks man-in-the-middle attacks and the like can be effectively resisted and the access security of the authorized data is thereby improved.
[0001]This application claims the December 23, 2015 submitted to the China Patent Office Application No. 201510977455.3, entitled "authorized client device for accessing the server device and access control system," the priority of Chinese patent application in its entirety incorporated by reference in the present application.
FIELD
[0002]The present disclosure relates to a client apparatus of information security and access control, and more particularly, relates to the center of the common database to achieve secure authorized access, the server apparatus, an access control system and a corresponding method.
Background technique
[0003]
Access control is a mechanism for all computer systems need to be addressed, whether it is a client / server system, the client / browser system, or a cloud system, from the most simple username / password authentication code to the widespread use / verification code ( CAPTCHA), and text messaging is now widely used in the verification code and hardware-based UKey, among which, SMS verification codes and UKey need to support external devices. The main part of the contents of access control is to confirm the authenticity and validity of access applications. Can effectively resist judging by the authenticity and validity of the parts of the network attacks, such as replay attack, middle attack, and thus can reduce the risk of denial of service attacks.
[0004]
SUMMARY
[0005]
It gives a brief summary of the present disclosure hereinafter, in order to provide a basic understanding of some aspects of the present disclosure. However, it should be understood that this summary is not an exhaustive overview of the disclosure. It is not intended to be used or the critical portion of the present disclosure determines an important part of, nor is it intended to limit the scope of the present disclosure. Its sole purpose is to present some concepts in a simplified form on the present disclosure, as a prelude to the more detailed description that is presented later.
[0006]
In view of the above problems, an object of the present disclosure is to provide a part of the network effectively resist attack for a client device authorized to access, the server apparatus, an access control system and a corresponding method.
[0007]
According to an aspect of the present disclosure, there is provided a client device for authorizing access, comprising: a request generating unit configured to generate a protected resource access authorization request and sends the request to the server apparatus; a recording unit, configured to request records in public databases, wherein the center of the public database to distributed database, and the records in the common database can not be changed; and an access unit is configured to utilize the server apparatus in response to the response information transmission request, perform a corresponding operation for accessing protected resources.
[0008]
According to embodiments of the present disclosure preferred embodiment, a public database comprising a block chain (Blockchain).
[0009]
According to another preferred embodiment of the present disclosure, the request generating unit is further configured to sign the request using the client private key and sends the signed request to the server device, and the recording unit is further configured to request records the signature in public databases.
[0010]
According to another embodiment of the present disclosure preferably, the request generating unit is further configured to transmit the location information request also in public databases to the server apparatus.
[0011]
According to another embodiment of the present disclosure preferably, the access unit is further configured to utilize the information recorded in the server public key public databases to verify the response, and performs a corresponding operation according to the result of the verification.
[0012]
According to another embodiment of the present disclosure preferably, the server apparatus comprising a server and a resource server authorization.
[0013]
According to another preferred embodiment of the present disclosure, a request for authorization request access credentials includes transmitting to the authorization server, and the response message includes an authorization from the authorization server access credentials.
[0014]
According to another embodiment of the present disclosure preferably comprise credentials authorize access restriction information relating to the protected resources.
[0015]
According to another preferred embodiment of the present disclosure, the restriction information includes an identification of the protected resource manager, allowing the client device to access the resources authorized access credentials and the expiration date.
[0016]
According to another preferred embodiment of the present disclosure, the access restriction information further includes the number of settings within the validity period, and the access unit and perform a corresponding operation is provided for access to protected resources according to the access number.
[0017]
According to another preferred embodiment of the present disclosure, a data access request includes sending a request to the resource server, and the response from the resource information includes data resource server.
[0018]
According to another embodiment of the present disclosure preferably, the authorization server, and the resource server are the same server.
[0019]
According to another aspect of the present disclosure also provides a server device for authorizing access, comprising: a response generating unit configured to respond to the client device from the request for authorization to access protected resources to generate the corresponding response information, and sends the response message to the client device; and a recording unit configured to record the response information in public databases, wherein the center of the public database to distributed database, and the records are not available in public databases fixed one.
[0020]
According to another aspect of the present disclosure also provides an access control system for authorizing access, the access control system includes a client apparatus, a server apparatus and a public database, wherein the database is common to the center of the distributed database, recording in the public databases and can not be changed, and wherein the client device comprising: a request generating unit configured to generate for authorizing access to a protected resource request and sends a request to the server apparatus; first recording unit , configured to request records in the common database; and an access unit is configured to utilize the server apparatus in response to the request and the response information transmitted, performs a corresponding operation to access a protected resource; and a server apparatus comprising: a response generation unit configured to generate a corresponding response to the request response information, and sends the response message to the client device, and a second recording unit configured to record the response information in public databases.
[0021]
According to another aspect of the present disclosure also provides a method for authorizing access a client device executing the method comprising: generating a request for authorizing access to protected resources, and sends a request to the server apparatus; the request is recorded in public databases, wherein the center of the public database to distributed database, and the records in the common database can not be changed; and the use of the server apparatus in response to the request and the response information transmitted for performing access the appropriate action to protect the resource.
[0022]
According to another aspect of the present disclosure also provides a method for authorizing access executed in the server apparatus, the method comprising: a corresponding response from the client apparatus a request for authorization to access protected resources generated in response to information, and sends the response message to the client device; and in response to recording information in public databases, wherein the center of the public database to distributed database, and the records in the common database can not be changed.
[0023]
According to another aspect of the present disclosure, an electronic device is also provided, the electronic device may include a transceiver and the one or more processors, the one or more processors may be configured to perform the above-described according to the present disclosure authorization access.
[0024]
According to other aspects of the present disclosure is also provided for implementing the above-described computer program code recorded thereon a computer program product and method of the present disclosure and the computer on which the computer program code for realizing the above-described method according to the present disclosure readable storage media.
[0025]
According to the present embodiment of the present disclosure, may be implemented effectively secure access to protected resources authorized by public databases using decentralized.
[0026]
In the present specification are given in the following section embodiments disclosed in other aspects of the embodiment, wherein, for a detailed description of preferred embodiments of the present disclosure embodiment fully disclosed embodiments without applied thereto is defined.
BRIEF DESCRIPTION
[0027]
The present disclosure may be better understood by reference to the following detailed description given in conjunction with the accompanying drawings, in which the same or similar reference numerals in the drawings to refer to the same or like parts. The drawings together with the detailed description are included in a part of the present specification and form of the specification, it serves to further illustrate the embodiments and explain the principles and advantages of the present disclosure of the preferred embodiment of the disclosure. among them:
[0028]
FIG 1 is a schematic diagram showing an exemplary embodiment of an access control system architecture of the embodiment of the present disclosure;
[0029]
FIG 2 is a block diagram illustrating a functional configuration example of a client device according to embodiments of the present disclosure;
[0030]
FIG 3 is a block diagram of a functional configuration example of a server apparatus of the present disclosure illustrated embodiment;
[0031]
FIG 4 is a schematic diagram illustrating authorizing access according to an embodiment of the present disclosure is an example of the interaction process;
[0032]
FIG 5 is a schematic diagram illustrating an exemplary embodiment of the present disclosure based access control block chain implemented;
[0033]
FIG 6 is a schematic diagram showing an example of the format and content of the entries in the block chain embodiment of the present disclosure in embodiments of;
[0034]
FIG. 7 is a flow chart illustrating a method for authorizing access according to an embodiment of the present disclosure an example;
[0035]
FIG 8 is a schematic diagram of the system architecture based on the access control block chain and OAuth protocols exemplary embodiments of the present disclosure illustrated embodiment;
[0036]
FIG 9 is a diagram illustrating an embodiment of the present disclosure based on exemplary block chain OAuth protocol implemented in accordance with;
[0037]
FIG 10 is a flowchart illustrating techniques of this disclosure an example application of a limited number authorized to access interactive process implemented;
[0038]
11A and 11B are diagrams illustrating the technique of the present disclosure for implementing the exemplary finite number of authorized access;
[0039]
FIG 12 is a flowchart showing an example of a process of a method for authorizing access to the client device to perform an embodiment of the present disclosure;
[0040]
FIG 13 is a flowchart showing the procedure of Example of the present disclosure a method for authorizing access is performed in a server apparatus according to an example;
[0041]
FIG 14 is a diagram illustrating a first exemplary application of the techniques of the present disclosure;
[0042]
FIG 15 is a schematic view of a second exemplary application of the techniques of the present disclosure is shown; and
[0043]
FIG 16 is a block diagram illustrating a configuration of a personal computer as the information processing apparatus of the present disclosure may be employed in the embodiment of the embodiment.
Detailed ways
[0044]
The exemplary embodiments of the present disclosure will be described below in conjunction with the accompanying drawings. For clarity and conciseness, in the specification are not all features of an actual implementation. However, it should be understood that many decisions must be made to the specific embodiments of the development of any such actual embodiment of the process in order to achieve the developer's specific goals, such as compliance with those restrictions related systems and services, and these restrictions may be subject to change with different embodiments. In addition, it should be understood that, although the development work can be very complex and time-consuming, but the benefit of this disclosure to those skilled in the, this development is only a routine task.
[0045]
Here, also be noted that, in order to avoid unnecessarily obscure the details of the present disclosure, the drawings only shows a program according to the present disclosure closely related device structures, and / or processing steps, omitted additional details of this little public relations.
[0046]
Next, an embodiment 16 of the present disclosure will be described in detail with reference to FIG. 1 to FIG.
[0047]
FIG 1 is a schematic diagram showing an exemplary embodiment of an access control system architecture of the embodiment of the present disclosure.
[0048]
1, the access control system according to this embodiment may include a common database 100, the client device 200 and server device 300.
[0049]
In the present embodiment of the present disclosure, in order to ensure that the client device 200 to secure access to protected resources, can be such that the customer authorized to access the process of the client device key operations 200 and server device 300 are recorded in 100 public databases, since 100 is the center of a public database of the distributed database to which the data will not change, and delete records once, thereby facilitating resist network attacks, secure access control. Next, FIG. 2 and described in detail in FIG client device 200 and server device 300 the function configuration example of the reference, respectively.
[0050]
FIG 2 is a block diagram illustrating a functional configuration example of a client device according to embodiments of the present disclosure.
[0051]
, According to the embodiment of the client terminal device 2 200 may include a request generating unit 210, a recording unit 220 and access unit 230.
[0052]
Request generating unit 210 may be configured to generate the authorization to access protected resource request and sends the request to the server apparatus 300.
[0053]
The recording unit 220 may be configured to record to the request 100 in public databases.
[0054]
Access unit 230 may be configured to utilize the server apparatus 300 in response to the request and the response information transmitted, performs a corresponding operation to access a protected resource.
[0055]
Preferably, in order to enhance security, request generating unit 210 may further utilize identity key generation center for the client device 200 generates a key pair (private key comprises a (private key, referred to as SK) and a public key (public key, that is, PK) the private key) of the signing requests, sends a request to the signature server 300, and requests the recording unit 220 may record the signatures in the public databases 100. This process can be represented, for example, by the following expression (1):
[0056]
Record 1=Sign SK of Client(Hash(Request)) (1)
[0057]
Wherein, Request represents a request from the client apparatus, SK of Client indicates the client device private key 200, the Hash () denotes a hash function, Sign SK of Client indicates the client device private key 200 using the sign, and indicates Record1 request public records in the database after the signature.
[0058]
Preferably, the request generating unit 210 described above may also request location information recorded in public databases (herein referred to as e.g. Addrl) transmits to the server device 300. Thus, the server device 300 may be a request to find the signature record in the common database 100 (described above Record1) based on the position information received in the common database 100, and 200 using the public key of the client apparatus from the client apparatus verification authenticity of the request 200, for example, the verification process can be represented by the following expression (2):
[0059]
Addr 1→Record 1
[0060]
Verify(Rec ord 1)=Verify PK of Client(Record 1)=?Hash(Request) (2)
[0061]
Wherein, the Verify () represents a function used to verify, and PK of Client 200 represents a public key of the client apparatus.
[0062]
Then, a request for a reasonable validated, server device 300 may generate corresponding response information (referred to herein as Response) to send to the client apparatus 200, and also the response information 100 is recorded in public databases. Preferably, in order to further ensure security, the server device 300 may also use the private key of the server response information sign, and sends the signed response message to the client apparatus 200, and the signed response information in a common database record 100 . This process can be represented, for example, by the following expression (3):
[0063]
Record 2=Sign SK of Server(Hash(Response)) (3)
[0064]
Wherein, Response shows the response generated by the information server apparatus, SK of Server represents the private key of the server apparatus 300, the Hash () denotes a hash function, Sign SK of Server expressed using the private key of the server apparatus 300 performs signature, and the signature indicates Record2 after the response information 100 recorded in the public databases.
[0065]
In addition, access to the above-described response information is similar to the server apparatus 300 may also be a signature location information in public databases (herein, for example, referred to as Addr2) to the client apparatus 200, so that the client device 200 of unit 230 may be in accordance with the Finding the location information received in response to the signature information in the common database 100 records in the common database 100 to verify the record, and performs a corresponding operation according to the verification result using the public key of the server. This process can be represented, for example, by the following expression (4):
[0066]
Addr 2→Record 2
[0067]
Verify(Rec ord2)=Verify PK of Server(Record 2)=?Hash(Response) (4)
[0068]
Wherein, the Verify () represents a function used to verify, and PK of Server device 300 represents a key server.
[0069]
FIG 2 describes the function of the client device for authorizing access configuration example, corresponding to the above reference, a configuration example will now be described with reference to the server means for authorizing access function of FIG. FIG 3 is a block diagram of a functional configuration example of a server apparatus of the present disclosure illustrated embodiment.
[0070]
3, the server apparatus 300 according to this embodiment may include a response generation unit 310 and the recording unit 320.
[0071]
Response generation unit 310 may be configured to respond to the client device from the request for authorization to access protected resources to generate corresponding response information, and sends the response message to the client device 200.
[0072]
Preferably, as described above, the response generating unit 310 may use a client public key (i.e., the above-described PK of Client) 200 to client requests recorded in public databases (i.e., the recording Record1) verification means, and in accordance with result of the verification to generate response information (i.e., response). The process may, for example, by the above-mentioned expression (2) below.
[0073]
The recording unit 320 may be configured to record information in response to a public database 100.
[0074]
Preferably, as described above, the response generation unit 310 may be further configured to utilize the private key of the server response information and transmits response information for signing the signature to the client apparatus 200, and the recording unit 320 may be further configured to signature after the response information 100 recorded in the public databases. This process may, for example, above-mentioned expression (3) below. Further, in response to the response generation unit 310 may also position information in public databases (i.e., above Addr2) to the client apparatus 200.
[0075]
It should be understood, the function configuration example of the server apparatus 300 is a function of the client apparatus 200 is a configuration example corresponding to the respective position and therefore not described above refer to the detailed description is not repeated.
[0076]
To facilitate understanding of the implementation process of the above-described unauthorized access, will be described with reference to FIG. 4 for the client authorized to access the client device 200, server device 300 and the interaction processes between 100 public databases. FIG 4 is a schematic diagram illustrating an example access authorization according to an embodiment of the present disclosure of the interaction process.
[0077]
First, in step S101, the client device 4200 shown in FIG sign the request to generate a request for authorization to access the protected resource by the client private key, and in step S102 the recording request public database 100. In step S103, the common database 100 to add to the request to record, and the record (i.e., Record1) position, for example Addr1. Then, in step S104, the client apparatus 200 requests the signature and the position information in public databases Addr1 100 transmits to the server device 300. Next, in step S105, the server apparatus 300 according to the location information Addrl, using a client public key corresponding to the request for recording Record1 verification, validation and if the request is reasonable, then generate the corresponding response information in step S106 and with the server private key to sign the response information. Then, in step S107, the server apparatus 300 in response to the information recorded in the signature of the public databases 100, and in step S108, in response to the common database 100 to add its information is recorded in the recording, and the recording (i.e., record2) position, for example, Addr2. Next, in step S109, the server apparatus 300 in response to the information and the position information of the signature Addr2 sent to the client apparatus 200 in the public databases. If desired, the client device 200 may, in step S110 (Alternatively, as shown in phantom) in accordance with the position information Addr2, using the public key of the server response information recorded in the common database 100 Record2 be verified, and in accordance with the verification result and perform the appropriate actions, for example, access to protected resources.
[0078]
It should be understood, the above-described interaction merely exemplary and not limitation, and executes the order of individual steps is only shown for convenience of description and is not limited thereto, as needed, some steps may be performed in parallel or it may change the order of execution.
[0079]
The process described above can be seen that, since the interaction the client apparatus 200 and the server device 300 is recorded in the public databases 100, 100 and the common database is a decentralized distributed database, and wherein the record is not change (ie, can not be deleted and / or modified), so that the client and server private key and private key pair interaction is signed by each use and recorded in public databases, can effectively resist network attacks. Here, it should be noted that since the public database 100 is shared by all network entities distributed database, so in theory, if more than half or two-thirds of the network entities have agreed to change the data in the database of public records, the It may allow them to make changes to records. However, in practice it is difficult to make more than half or two-thirds of the network entities have agreed to change the data records, so here is generally considered a public database data once recorded will not be modified or deleted.
[0080]
Preferably, as an example, the common database may include block chain. Block chain (Blockchain) is regarded as a major technology innovator Bitcoin (Bitcoin) behind. Because it acts as a mechanism to prove without having to trust, to prove the network for all transactions. Block chain is a "non-trusted" architecture. "Untrusted" architecture is the entire system of multiple parties without having to trust each other to be able to complete various types of transactions and collaboration. This is precisely the Internet so far has been the traditional weakest one. Compared with the need to establish and maintain a counterparty (other people) or third-party intermediaries (such as banks) trust can be trusted by the user "diggers - Audit (miner-accountants)" maintained, stored in the world public accounting system on a plurality of different decentralized nodes. As the new trading architecture untrusted systems for decentralized block chain is the key to innovation. All transactions carried out without intervention of any kind and to the center of the block chain between all the entities allowed in the world. Another like a chain block for the application layer that runs on the existing Internet protocol stack for the Internet adds a new layer to achieve economic transactions, including real-time digital currency payment (case widely used currency in the global encryption ) and longer-term, more complex economic contracts. Any currency, economic contracts or hard or soft assets can be traded through block chain system. Further, the block chain not only for the transaction, and can also be used for recording, tracking, and monitoring all transactions of assets and inventory registration system. Block chain literally like a huge extension table for the registration of all assets and accounting system for trading of these assets on a global scale, including all forms of all entities worldwide assets held. Therefore, the block chain can be used for any form of asset registers, stock and exchange, including the fields of finance, economics and money; hard assets (physical assets) and intangible assets (Votes, ideas, reputation, intentions, health data, etc. ). Bitcoin peer to peer network all transaction history are stored in the "block chain" (Blockchain) in. Block chain continues to lengthen, but once the new block added to the block in the chain, it will not be removed. Block chain is actually a P2P network platform is a group of client nodes scattered by all participants composed of a distributed database, it is a record of all bitcoin transaction history. However, with the development of the block chain technology, it is not just the payment application in the field of virtual currency. To the center of the block chain technology without having to trust point model means that the most basic level, No middleman trading. Block chain is the Bitcoin network infrastructure, but the block chain itself means more. If the block chain 1.0 technology for virtual currency was born, and the block chain technology core features of credit trust 2.0 applications become an important direction, it is recommended block chain contract notarization. The block chain technology were positioned 3.0 applications other than financial applications, such as in the government sector, health, science, culture and the arts.
[0081]
Block chain is a decentralized, distributed, arranged in chronological order public records, accounting system, or called the public. Block chain shared by all users as well as to jointly safeguard. Record block chain can be used to verify double spending, if the block chain is applied to the bill virtual currency, it can be used to verify a permanent Bitcoin transactions and to prevent double spending. Block chain in the present invention can be used to avoid multiple times using the same authentication code, the block chains in the authorization service platform technology may be by chronological record set common, the steps associated license verification and prevention of replay attacks.
[0082]
In addition to bit credits, according to the present disclosure public databases embodiment may also be employed such as litecoin block chain based decentralized public accounts (public ledger) platform, so that there Hyperledger a "consensus" instead of decentralized distributed mining accounting system.
[0083]
Authorized service of the present invention can also be based on Hyperledger platform applications, for example, the request and response consensus pool information recorded in Hyperledger, such as testing pool (testpool), a pool of users (custompool), etc., testpool free and open to everyone, custompool allows a user to customize the pond. By Hyperledger "consensus" mechanism, effective after confirmation record, then the record can not be falsified.
[0084]
Here an example will be described block chain access control according to the present embodiment is implemented disclosure, it should be understood that the present disclosure is of course not limited thereto, but may be applied to any decentralized, distributed and recorded therein You can not delete and modify database system. FIG 5 is a diagram illustrating a schematic diagram of an example embodiment of the present disclosure based access control block chain implemented.
[0085]
As shown, the client apparatus 5200 and the server device 300, respectively, after each addition request and response information to the signature block chain, these records are arranged in chronological order in a block chain, and not upon the recording modify, and delete, so that the client device 200 and server device 300 may locate the appropriate record in accordance with location information request and the response information in a block chain, respectively, in the recording block chain to verify the public key, to ensure that the access control security.
[0086]
FIG 6 is a diagram illustrating an example of the format and content of the present block chain entries disclosed embodiment of FIG.
[0087]
6, the recording block chain may include an address, a signature of the content creator and other application-related information. For example, client device 200 requests the recording block in the chain comprises a recording location information request in a block chain (Addrl) and signing requests, and the server apparatus 300 in response to the information recorded after the block chain, at this time, the entries in the block chain response including position information in a block chain (Addr2), the signed response, the position information in a block chain (Addrl) request, requesting a signature, etc., i.e., recording block chain in chronological order of recording and growth, and can not be deleted, and modified.
[0088]
It should be understood, the format and content of the entries given herein is merely exemplary, and may be provided wherein the format and content of the entries according to actual needs, the present disclosure is not limited to this.
[0089]
Interaction with the above-described corresponding to FIG. 7 will be described a method of authorizing access procedure according to an embodiment of the present disclosure with reference to exemplary embodiments. FIG. 7 is a flow chart illustrating a method for authorizing access according to an embodiment of the present disclosure is exemplary.
[0090]
As shown in FIG 7, the method begins at step S701, the then proceeds to step S702. In step S702, the client device 200 generates a request for authorization to access the protected resource using client after recording the private key signature block chain, and to obtain location information of the request in a block chain. Then, the method proceeds to step S703. In step S703, it requests the client 200 and the server apparatus 300 transmits a signature request block chain in the position information to the device. Next, in step S704, the server device 300 requests the recording block chain obtained in accordance with the received location information, and authentication using a client public key of the record. Then, the process proceeds to step S705, S705 is determined in the step whether the record is valid. If the determination is invalid, the method ends. If it is determined valid, the method proceeds to step S706, the in step S706, the server device 300 generates a request for a valid response information by using the server private key signature record in a block chain, and the response information obtained in block chains the location information. Next, in step S707, the server device 300 in response to the signature information and the position information in a block chain to the client apparatus 200, and the method ends.
[0091]
7 depicts a process example of a method for authorizing access according to the present disclosure with reference to the above, it is to be understood that this is merely exemplary and not limiting, and those skilled in the art may modify the above process as needed. For example, as described above, if desired, the client device 200 may also be in the next step according to the received location information obtained in response to the information recording block in the chain, using the server's public key to verify the record, according to the verification and results and perform a corresponding operation.
[0092]
7 depicts an example of a general access authorization control above with reference to FIGS. 1 to 3, below with the OAuth (open authorization, http: //oauth.net/) to achieve access to authorized standard techniques of the present disclosure will be described in the application control.
[0093]
Prior art combined OAuth protocol detailed description of the invention, this section introduces OAuth protocol. OAuth is an open network protocol concerning authorization (authorization) of (standard). In the OAuth protocol, we introduced authorize layer and the role of the client's role and resource owners of separation, and the client requests access to a resource owned by the resource server controlled by the resource owner, and are issued with the resource owner a different set of credentials credentials. In the OAuth protocol defines the following four roles: resource owners, it is able to authorized entities access to protected resources, when the resource owner is a person, also known as end-user; server resources, it is to have protected server resources, the access token can be used to receive and respond to a request for access to protected resources; client, which is performed on behalf of the resource owner and the protected application resource request grants resources use the owner, it is not imply any particular implementation characteristics (for example, the application is executed on the server, desktop or other device); and after authorization server, which is successfully authenticated resource owners and obtain an authorization issued access token server to the client , which may be the same server or may be different entities, and may issue a single authorization server received by the plurality of resource servers to access the resource server token.
[0094]
OAuth promote the development of open API in the field of development of new applications. OAuth provides a method for access to protected resources for the application. Before application to access a protected resource, it must be obtained first from the owner of the resource authorization (access permissions), and then use the access permissions access token exchange (representatives of access permission scope, duration and other attributes). Application by presenting the access token to the resource server to access a protected resource. Currently recommended using OAuth 2.0 standard. However, OAuth 2.0 protocol itself does not provide security and integrity protection mechanisms, developers use OAuth 2.0, require additional protection mechanisms to provide communications security.
[0095]
OAuth 2.0 protocol itself unable to resist replay attacks and middle attack, such as a replay attack when network traffic, authentication code can be intercepted and used to grant access to documents and other multiple applications. As described above, in the public databases (e.g., block chain), i.e., by the block chain OAuth protocol technology, can effectively resist middle attacks and replay attacks by the interaction of the authorization record. By way of example, will be described below in detail an example implementation of block chains and OAuth authorized access protocol control.
[0096]
FIG 8 is a diagram illustrating an example access control system based on the architecture and the block chain OAuth protocol according to an embodiment of the present disclosure is shown.
[0097]
As shown, the access control system of this embodiment may include a block chain 100, the client apparatus 8200, the authorization server 400, the resource server 500 and resource 600 owner. Wherein the block chain 100 and client device 200 and the common database 100 and client device 200 has the same configuration, it will not be repeated. The authorization server 400 and the resource server 500 may have the same configuration as the server apparatus 300, i.e., the server device 300 may include an authorization server 400 and the resource server 500, and the two servers may be the same server apparatus, therefore not repeated description of its configuration. It will be only briefly OAuth role in each of the above protocol means.
[0098]
600 resource owner is an entity access to protected resources can be licensed; resource server 500 is protected resource has a server, which can receive and respond to requests for protected resources using the access token; client device 200 is a resource owner and an authorized representative of the owner of the resources the application requests a protected resource, it is not limited to any particular implementation form, i.e., it can be implemented on a server, computer, mobile device or other device; and an authorization server 400 after successful authentication is the resource owner and authorized client device 200 server issues an access token.
[0099]
The reference to the following exemplary implementation of FIG. 9 based on the block chain OAuth protocol described in detail. FIG 9 is a diagram showing an example based on the block chain OAuth protocol implemented according to an embodiment of the present disclosure.
Claims
[Claim 1]Client device for authorizing access, comprising: a request generating unit configured to generate for authorizing access to a protected resource request, and the request to the server apparatus; a recording unit, configured to the recording the request in a public database, wherein said database is common to the center of the distributed database, and the records in the public databases is unchangeable; and an access unit configured to, with the server device in response to in response to the request information transmitted, performs a corresponding operation for accessing the protected resource.
[Claim 2]
The client apparatus according to claim 1, wherein said database comprises a common block chain.
[Claim 3]
The client device according to claim 1, wherein said request generating unit is further configured to sign the request using the client private key and sends the signed request to the server apparatus, and the recording unit is further configured to request the signature record in the public databases.
[Claim 4]
The client device according to claim 1, wherein said request generating unit is further configured to request the location information is also in the public databases to the server device.
[Claim 5]
The client device according to claim 1, wherein the access unit is further configured to utilize the information server public key recorded in the common database to verify the response, and is performed according to the result of the verification the corresponding operation.
[Claim 6]
The client device according to claim 1, wherein said apparatus comprises a license server and a server resource server.
[Claim 7]
The client device according to claim 6, wherein the authorization request comprises a request for access credentials sent to the authorization server, and the response information including authorization credentials from the access authorization server.
[Claim 8]
The client device according to claim 7, wherein the authorization ticket includes access restriction information relating to the protected resources.
[Claim 9]
The authorization and resource access credentials Validity client device according to claim 8, wherein the restriction information includes an identification of the protected resource manager, allowing the client device access.
[Claim 10]
The client device according to claim 9, wherein said access restriction information further includes the number of disposed within the validity period, and the access unit is provided in accordance with the number of accesses performed for accessing the protected resources the corresponding operation.
[Claim 11]
The client device according to claim 6, wherein the request comprises transmitting the resource server to a data access request and the response data includes resource information from the resource server.
[Claim 12]
The client device according to claim 6, wherein the authorization server and the resource server are the same server.
[Claim 13]
Other authorization to access server device, comprising: a response generating unit configured to respond to the client device from the request for authorization to access protected resources to generate corresponding response information and the response information is transmitted to the the client device; and a recording unit configured to record the response information in public databases, wherein said database is common to the center of the distributed database, and the records are not available in public databases changes of.
[Claim 14]
The server apparatus according to claim 13, wherein said database comprises a common block chain.
[Claim 15]
The server apparatus according to claim 13, wherein said response generation unit is further configured to utilize said private key of the server response information and transmits response information is signed after the signature to the client device, and the the recording unit is further configured to in response to the signature record information in the common database.
[Claim 16]
The server apparatus according to claim 13, wherein said response generation unit is further configured to end the response means also transmits position information in the common database to the client.
[Claim 17]
The server apparatus according to claim 13, wherein said response generation unit is further configured to utilize a client public key recorded in the common database in the authentication request, and generates a result of the verification the response information.
[Claim 18]
The server apparatus according to claim 13, wherein said apparatus comprises a license server and a server resource server.
[Claim 19]
The server apparatus according to claim 18, wherein the authorization request comprises a request for access credentials sent to the authorization server and the response from the authorization information includes authorization server access credentials.
[Claim 20]
The server apparatus according to claim 19, wherein the authorization ticket includes access restriction information relating to the protected resources.
[Claim 21]
Resource access credentials and the authorization server Validity apparatus according to claim 20, wherein the restriction information includes an identification of the protected resource manager, allowing the client device access.
[Claim 22]
The generating unit of the client device access to the protected resources decremented as claimed in claim 21, said server device, wherein said information further includes the number of access restriction within the validity period is provided, the response visits disposed above, and the number of visits recorded after recording unit disposed in said decreasing public databases.
[Claim 23]
The server apparatus according to claim 18, wherein said data access request comprises transmitting a request to the resource server, and said response data from said resource information includes resource server.
[Claim 24]
The server apparatus according to claim 18, wherein the authorization server and the resource server are the same server.
[Claim 25]
Access control system for authorizing access, the access control system includes a client apparatus, a server apparatus and a public database, wherein said database is common to the center of the distributed database, and the records in the public databases It can not be changed, and wherein said client apparatus comprising: a request generating unit configured to generate for authorizing access to a protected resource request and send the request to the server apparatus, a first recording unit appropriate, the request is configured to record in the common database, and an access unit configured to, with the information server apparatus in response to the request response transmission is performed for accessing the protected resources operation; and the server apparatus comprising: a response generating unit configured to generate corresponding to the request response information in response, and transmits the response information to the client device, and a second recording unit configured to in response to the recording information in public databases.
[Claim 26]
A method for authorizing access executed in the client device, the method comprising: generating a request for authorizing access to protected resources, and sends the request to the server device; the request records in the common database in which the database is common to the center of the distributed database, and the records in the public databases is unchangeable; and response information by using the server apparatus in response to the transmitted request, performs a operating the respective access protected resources.
[Claim 27]
A method for authorizing access means executing server, the method comprising: from a client device a request for authorization to access a protected resource to generate a corresponding response message, and transmits the response information in response to the client device; and the response information is recorded in a public database, wherein said database is common to the center of the distributed database, and the records in the public databases is unchangeable.
| # | Name | Date |
|---|---|---|
| 1 | 201817026475-TRANSLATIOIN OF PRIOIRTY DOCUMENTS ETC. [16-07-2018(online)].pdf | 2018-07-16 |
| 2 | 201817026475-STATEMENT OF UNDERTAKING (FORM 3) [16-07-2018(online)].pdf | 2018-07-16 |
| 3 | 201817026475-PROOF OF RIGHT [16-07-2018(online)].pdf | 2018-07-16 |
| 4 | 201817026475-PRIORITY DOCUMENTS [16-07-2018(online)].pdf | 2018-07-16 |
| 5 | 201817026475-FORM 1 [16-07-2018(online)].pdf | 2018-07-16 |
| 6 | 201817026475-DRAWINGS [16-07-2018(online)].pdf | 2018-07-16 |
| 7 | 201817026475-DECLARATION OF INVENTORSHIP (FORM 5) [16-07-2018(online)].pdf | 2018-07-16 |
| 8 | 201817026475-COMPLETE SPECIFICATION [16-07-2018(online)].pdf | 2018-07-16 |
| 9 | 201817026475.pdf | 2018-07-31 |
| 10 | 201817026475-Proof of Right (MANDATORY) [01-08-2018(online)].pdf | 2018-08-01 |
| 11 | 201817026475-OTHERS-030818.pdf | 2018-08-06 |
| 12 | 201817026475-Correspondence-030818.pdf | 2018-08-06 |
| 13 | abstract.jpg | 2018-08-18 |
| 14 | 201817026475-OTHERS-030818..pdf | 2018-09-10 |
| 15 | 201817026475-FORM 18 [11-12-2019(online)].pdf | 2019-12-11 |
| 16 | 201817026475-FER.pdf | 2021-10-18 |
| 1 | searchstratE_11-03-2021.pdf |