Interface authentication method and system based on large model
Through the interface authentication method based on the large model, the private key management module is used to generate and manage user key information, generate tokens by signature, and perform multiple verifications. This solves the problem that traditional interface security measures are vulnerable to attacks and achieves all-round security protection and data integrity of the interface.
Patent Information
- Application Number
- CN202511026049.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-24
- Publication Date
- 2025-10-10
AI Technical Summary
Traditional interface security measures are easily attacked by hackers by exploiting vulnerabilities in large model scenarios, resulting in low interface security.
An interface authentication method based on a large model is adopted. New user key information is created through the private key management module, and a token is generated using the user's private key signature. Multiple verifications are performed, including timestamp verification, random number ID verification, key status verification, and signature verification, to ensure the security of interface calls.
Improves the security of the interface, prevents replay attacks, repeated requests and invalid key usage, ensures data integrity and security, and enhances the security of externally exposed interfaces.
Smart Images

Figure CN120768543A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer, in particular to an interface authentication method and system based on a large model. BACKGROUND
[0002] With the rapid development of Internet technology, various application systems are emerging. E-commerce platforms, social media applications and enterprise-level management systems all rely on the interaction and data exchange of external systems. As the bridge for communication between systems, the security of the interface is directly related to the stable operation of the entire system and the security of user data.
[0003] Currently, the traditional interface security measures generally use simple username and password authentication or static tokens.
[0004] However, in the context of large models, the interface calling frequency is higher, the data interaction volume is larger, and the business logic involved is more complex. The traditional interface security measures are vulnerable to hacking and data theft through vulnerabilities, resulting in low interface security. SUMMARY
[0005] The embodiments of the present application provide an interface authentication method and system based on a large model, which can improve the security of the interface.
[0006] In a first aspect, the embodiments of the present application provide an interface authentication method based on a large model, which comprises:
[0007] A1: creating at least one user key information using a private key management module and storing it in a database, wherein each user key information includes: a user identity, a key pair composed of a user private key and a user public key, a salt value, user information, a key expiration time and a key state;
[0008] A2: obtaining the request parameters assembled by the client based on the interface calling requirements, wherein the request parameters include: business data to be processed, a timestamp, and a random number ID;
[0009] A3: obtaining the signature of the request parameters by the client using the user private key, generating a token for interface authentication, wherein the token includes: signature information and the associated user identity;
[0010] A4: when receiving an interface calling request, performing target verification on the interface calling request based on the token, and triggering a large model to process business data after verification, wherein the target verification includes: timestamp verification, random number ID verification, key state verification, key expiration time verification, and signature verification.
[0011] Preferably,
[0012] Before the above A1, further comprising:
[0013] D1: Obtain the interface code information entered by the current user and perform uniqueness verification;
[0014] D2: Check whether the current user has valid user key information. If so, execute step D3; otherwise, execute step A1;
[0015] D3: Returns error information.
[0016] Preferably,
[0017] Said A1 includes:
[0018] Using the private key management module to create the user identity in at least one user key information;
[0019] Convert the user identity into a byte array, and use an asymmetric encryption algorithm to generate a key pair consisting of the corresponding user private key and user public key;
[0020] Generate a salt value of a preset length, encrypt the user identity, the user private key, and the user public key based on the salt value using a salt encryption algorithm, and generate an encrypted user identity, an encrypted user private key, and an encrypted user public key;
[0021] The salt value, the encrypted user identity, the encrypted user private key, the encrypted user public key, and the user information input by the current user, the key expiration time, and the key status are stored in a database.
[0022] Preferably,
[0023] The A4 includes:
[0024] E1: upon receiving the interface call request, verifying based on the token whether the timestamp carried in the interface call request is within the preset validity period; if so, executing step E2; otherwise, executing step E7;
[0025] E2: Compare the random number ID in the interface call request with the stored historical random number ID to determine whether they have the same ID. If so, execute step E7; otherwise, execute step E3;
[0026] E3: Store the current random number ID, and based on the user identity associated with the token, query the key status of the corresponding user key information in the database to determine whether it is in a deactivated state. If so, execute step E7; otherwise, execute step E4;
[0027] E4: Query the expiration time corresponding to the user key information in the database to determine whether the expiration time is earlier than the current time. If so, execute step E7; otherwise, execute step E5;
[0028] E5: Using the user public key corresponding to the user private key, verify the signature information of the request parameter to determine whether the signature verification passes. If so, execute step E6; otherwise, execute step E7;
[0029] E6: Trigger the large model to process business data and return the processing results;
[0030] E7: The verification is determined to have failed and a verification failure message is returned.
[0031] In a second aspect, an embodiment of the present invention provides an interface authentication system based on a large model, the system comprising:
[0032] Private key management module: used to create at least one user key information and store it in the database, wherein each user key information includes: user identity, key pair consisting of user private key and user public key, salt value, user information, key expiration time and key status;
[0033] Parameter collection module: used to obtain the request parameters assembled by the client based on the interface call requirements, wherein the request parameters include: business data to be processed, timestamp, and random number ID;
[0034] Signature collection module: used to obtain the signature of the request parameters collected by the parameter collection module using the user private key by the client, and generate a token for interface authentication, wherein the token includes: signature information and the associated user identity;
[0035] Interface call module: used to perform target verification on the interface call request based on the token collected by the signature collection module when receiving the interface call request, and trigger the large model to process business data after the verification is passed, wherein the target verification includes: timestamp verification, random number ID verification, key status verification, key expiration time verification, and signature verification.
[0036] Preferably,
[0037] Before the private key management module, it further includes: an information verification module;
[0038] The information verification module is used to perform:
[0039] D1: Obtain the interface code information entered by the current user and perform uniqueness verification;
[0040] D2: check whether the current user has valid user key information, if yes, execute step D3, otherwise, execute step Al;
[0041] D3: return error information prompt.
[0042] Preferably,
[0043] The private key management module is further configured to execute:
[0044] The user identity in the at least one user key information is newly created by using the private key management module;
[0045] The user identity is converted into a byte array, and a corresponding key pair composed of a user private key and a user public key is generated by using an asymmetric encryption algorithm;
[0046] A salt value of a preset length is generated, and the user identity, the user private key, and the user public key are encrypted based on the salt value by using a salted encryption algorithm, and an encrypted user identity, an encrypted user private key, and an encrypted user public key are generated;
[0047] The salt value, the encrypted user identity, the encrypted user private key, and the encrypted user public key, as well as user information input by the current user, a key invalidation time, and a key state are stored in a database.
[0048] Preferably,
[0049] The interface calling module is further configured to execute:
[0050] E1: upon receiving the interface calling request, verifying whether a timestamp carried in the interface calling request is within a preset valid time length based on the token, if yes, executing step E2, otherwise, executing step E7;
[0051] E2: comparing the random number ID in the interface calling request with a stored historical random number ID to determine whether there is a same ID, if yes, executing step E7, otherwise, executing step E3;
[0052] E3: storing a current random number ID, querying a key state of the user key information in the database based on the user identity associated with the token, and determining whether it is in a deactivated state, if yes, executing step E7, otherwise, executing step E4;
[0053] E4: querying an invalidation time corresponding to the user key information in the database, and determining whether the invalidation time is earlier than a current time, if yes, executing step E7, otherwise, executing step E5;
[0054] E5: Using the user public key corresponding to the user private key, verify the signature information of the request parameter to determine whether the signature verification passes. If so, execute step E6; otherwise, execute step E7;
[0055] E6: Trigger the large model to process business data and return the processing results;
[0056] E7: The verification is determined to have failed and a verification failure message is returned.
[0057] In a third aspect, an embodiment of the present invention provides an interface authentication system based on a large model, comprising: at least one memory and at least one processor;
[0058] The at least one memory is configured to store a machine-readable program;
[0059] The at least one processor is configured to call the machine-readable program to execute any one of the methods described in the first aspect.
[0060] In a fourth aspect, an embodiment of the present invention provides a computer-readable medium having computer instructions stored thereon. When the computer instructions are executed by a processor, the processor is caused to execute any of the methods described in the first aspect.
[0061] The embodiment of the present invention provides an interface authentication method and system based on a large model. The method creates a new user key information including user identity, key pair, salt value, expiration time, and key status information through a private key management module and stores it in a database, which facilitates the management of user key information, and the random salt value also improves the security of key storage; the client assembles request parameters based on the business data to be processed, timestamp, and random number ID and generates a token using a private key signature, further improving security; when the interface is called, timestamp verification can prevent replay attacks, random number ID verification can avoid repeated requests, key status and expiration time verification can eliminate the use of invalid or expired keys, and combined with signature verification, data can be verified to have not been tampered with. The above-mentioned multiple verification mechanisms form a full range of security protection, which controls the entire process from key generation and management, request construction to interface call verification, and can effectively resist risks such as illegal access, data tampering and leakage. It can not only ensure the security of data, but also significantly improve the security of the interface exposed to the outside world. BRIEF DESCRIPTION OF THE DRAWINGS
[0062] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0063] Figure 1 This is a flow chart of a large model-based interface authentication method provided by one embodiment of the present invention;
[0064] Figure 2 This is a flow chart of another interface authentication method based on a large model provided by one embodiment of the present invention;
[0065] Figure 3 This is a schematic diagram of an interface authentication system based on a large model provided by one embodiment of the present invention;
[0066] Figure 4 This is a schematic diagram of another interface authentication system based on a large model provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0067] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0068] like Figure 1 As shown, an embodiment of the present invention provides an interface authentication method based on a large model, which may include the following steps:
[0069] Step 101: Create at least one user key information using a private key management module and store it in a database. Each user key information includes: a user identity, a key pair consisting of a user private key and a user public key, a salt value, user information, key expiration time, and key status.
[0070] Step 102: Obtain request parameters assembled by the client based on the interface call requirements, wherein the request parameters include: business data to be processed, timestamp, and random number ID;
[0071] Step 103: Obtain the signature of the client on the request parameters using the user's private key, and generate a token for interface authentication, wherein the token includes: signature information and associated user identity;
[0072] Step 104: When an interface call request is received, the interface call request is subjected to target verification based on the token, and the large model is triggered to process the business data after the verification passes. The target verification includes: timestamp verification, random number ID verification, key status verification, key expiration time verification, and signature verification.
[0073] In an embodiment of the present invention, an interface authentication method based on a large model is provided. The method creates a new user key information including a user identity, a key pair, a salt value, an expiration time, and a key status information through a private key management module and stores it in a database, which facilitates the management of the user key information, and the random salt value also improves the security of the key storage; the client assembles the request parameters based on the business data to be processed, the timestamp, and the random number ID and generates a token using the private key signature, which further improves the security; when the interface is called, the timestamp check can prevent replay attacks, the random number ID check can avoid repeated requests, the key status and expiration time check can prevent the use of invalid or expired keys, and the signature verification can verify that the data has not been tampered with. The above-mentioned multiple verification mechanism forms a full range of security protection, which controls the entire process from key generation and management, request construction to interface call verification, and can effectively resist risks such as illegal access, data tampering and leakage, and can not only ensure the security of data, but also significantly improve the security of the interface exposed to the outside world.
[0074] In order to further improve the security of the interface in a large model scenario, in one embodiment of the present invention, before step 101 in the above embodiment, the following steps may be specifically included:
[0075] D1: Obtain the interface person code information entered by the current user and perform uniqueness verification;
[0076] D2: Check whether the current user has valid user key information. If so, execute step D3; otherwise, execute step A1;
[0077] D3: Returns error information.
[0078] In an embodiment of the present invention, by obtaining the interface code input by the current user and performing a uniqueness check, the uniqueness of each user's identity can be ensured, and identity confusion and authority confusion caused by repeated codes can be avoided; at the same time, on this basis, it is checked whether the current user already has valid user key information. If so, an error prompt is returned, which can strictly limit the generation of multiple sets of valid keys by the same user, further prevent management loopholes and security risks, and implement strict control from the source of user key information creation, thereby building a solid initial security line for subsequent token-based interface authentication, and further improving the overall security of interface authentication in large model scenarios.
[0079] Specifically, in terms of user key information management, the system provides functions such as list display, private key generation, and setting private key expiration time. The system provides a one-click key generation function to ensure the security and uniqueness of the key. In particular, the new interface key function includes uniqueness verification of the interface code and allows users to set an expiration time when creating the key. The key is enabled by default. In addition, the displayed user identity APIKey and user private key APISecret are only displayed once, and subsequent displays are the base64-encoded data. The user identity serves as the key identifier and is used in subsequent interface calls.
[0080] In order to enhance the security of user key information, in one embodiment of the present invention, step 101 in the above embodiment may specifically include the following steps:
[0081] Using the private key management module to create the user identity in at least one user key information;
[0082] Convert the user identity into a byte array, and use an asymmetric encryption algorithm to generate a key pair consisting of the corresponding user private key and user public key;
[0083] Generate a salt value of a preset length, encrypt the user identity, the user private key, and the user public key based on the salt value using a salt encryption algorithm, and generate an encrypted user identity, an encrypted user private key, and an encrypted user public key;
[0084] The salt value, the encrypted user identity, the encrypted user private key, the encrypted user public key, and the user information input by the current user, the key expiration time, and the key status are stored in a database.
[0085] In the embodiment of the present invention, first, a new user identity is created through the private key management module (for example, a 32-bit APIKey is generated using base64 encoding) to establish a unique and traceable identity for each user; then the user identity is converted into a byte array, and the corresponding key pair is generated using an asymmetric encryption algorithm (for example, the RSA algorithm). With the help of the characteristics of asymmetric encryption, it is ensured that the private key (for example, ApiSecret) is only controlled by the user and the public key can be safely used for signature verification, thereby fundamentally ensuring the confidentiality and matching of the key pair; then a salt value of a preset length (for example, 8 bits) is generated, and the salt is added. The user identity, private key, and public key are encrypted twice using an encryption algorithm (for example, AES with salt), and the randomness of the salt value is used to enhance the encryption strength, thus preventing the leakage of key information due to cracking of a single encryption method. Finally, the salt value, encrypted key information, and user information, expiration time, and key status entered by the user are uniformly stored in the database. At the same time, the user identity ApiKey, the base64-encrypted user private key ApiSecret, and the salt value are returned to the front end for display, prompting the user to save them. The user needs to keep these key information properly to ensure the security of the interface call. This process not only realizes the structured management of key information, but also prevents the direct leakage of keys when the database is illegally accessed through encrypted storage. The entire process from key generation, encryption to storage strengthens the security of user key information, lays a solid foundation for the effectiveness of subsequent interface authentication, and thus improves the security of the overall interface.
[0086] To ensure the security of the interface call and the integrity of the data, in one embodiment of the present invention, step 104 in the above embodiment may specifically include the following steps:
[0087] E1: upon receiving the interface call request, verifying based on the token whether the timestamp carried in the interface call request is within the preset validity period; if so, executing step E2; otherwise, executing step E7;
[0088] E2: Compare the random number ID in the interface call request with the stored historical random number ID to determine whether they have the same ID. If so, execute step E7; otherwise, execute step E3;
[0089] E3: Store the current random number ID, and based on the user identity associated with the token, query the key status of the corresponding user key information in the database to determine whether it is in a deactivated state. If so, execute step E7; otherwise, execute step E4;
[0090] E4: Query the invalid time corresponding to the user key information in the database, determine whether the invalid time is earlier than the current time, if so, execute step E7, otherwise, execute step E5;
[0091] E5: Use the user public key corresponding to the user private key to verify the signature information of the request parameter, determine whether the verification is passed, if so, execute step E6, otherwise, execute step E7;
[0092] E6: Trigger the large model to process the business data and return the processing result;
[0093] E7: Determine that the verification fails and return the verification failure information prompt.
[0094] In the embodiments of the present application, in order to further improve the security of the interface, multiple target verification can be set. First, the timestamp verification (such as limiting 5 seconds) can effectively intercept the timeout request and prevent the attacker from using the intercepted request to perform a replay attack; the random number ID verification can identify and reject repeated requests by comparing with the stored historical ID, so as to avoid malicious repeated calls to cause burden to the system or bypass the security mechanism, and store the current random number ID as a basis for subsequent verification; the key state verification checks the key state of the user in the database, only the enabled key can be used, and the disabled key will be rejected, so as to ensure that only the legal user can access the interface; the key invalid time verification checks whether the key invalid time is earlier than the current time by comparing the invalid time with the current time, if the key has expired, an error prompt is returned, so as to prevent the use of expired key to call the interface; finally, the client uses the user private key to sign the request parameter to generate a signature value, and the server uses the user public key to verify the request parameter and the signature value, so as to ensure the integrity and authenticity of the data. If the verification fails, an error prompt is returned to prevent data tampering. When all verifications are passed, the system will process the interface business data and return the corresponding interface data. In this way, the security of the interface call and the integrity of the data are ensured.
[0095] As Figure 2 shown, in order to more clearly illustrate the technical solutions and advantages of the present application, the embodiments of the present application provide a detailed description of the interface authentication method based on a large model, which can specifically include the following steps:
[0096] Step 201: Obtain the interface human code information input by the current user and perform a uniqueness verification operation;
[0097] Step 202: Check whether the current user has valid user key information, if so, execute step 216, otherwise, execute step 203;
[0098] Step 203: Create at least one new user identity in the user key information using the private key management module;
[0099] Step 204: Convert the user identity into a byte array and use an asymmetric encryption algorithm to generate a key pair consisting of a corresponding user private key and a user public key;
[0100] Step 205: Generate a salt value of a preset length, encrypt the user identity, user private key, and user public key based on the salt value using a salt encryption algorithm, and generate an encrypted user identity, an encrypted user private key, and an encrypted user public key;
[0101] Step 206: Store the salt value, encrypted user identity, encrypted user private key, encrypted user public key, user information entered by the current user, key expiration time, and key status into the database;
[0102] Step 207: Obtain the request parameters assembled by the client based on the interface call requirements, wherein the request parameters include: business data to be processed, timestamp, and random number ID;
[0103] Step 208: Obtain the signature of the client on the request parameters using the user's private key, and generate a token for interface authentication, wherein the token includes: signature information and associated user identity;
[0104] Step 209: upon receiving the interface call request, verify based on the token whether the timestamp carried in the interface call request is within the preset validity period. If yes, proceed to step 210; otherwise, proceed to step 215.
[0105] Step 210: Compare the random number ID in the interface call request with the stored historical random number ID to determine whether there is an identical ID. If yes, execute step 215; otherwise, execute step 211.
[0106] Step 211: Store the current random number ID, and based on the user identity associated with the token, query the database for the key status of the corresponding user key information to determine whether it is in a deactivated state. If so, execute step 215; otherwise, execute step 212.
[0107] Step 212: Query the expiration time of the corresponding user key information in the database to determine whether the expiration time is earlier than the current time. If so, execute step 215; otherwise, execute step 213;
[0108] Step 213: Use the user public key corresponding to the user private key to verify the signature information of the request parameter to determine whether the signature verification passes. If so, execute step 214; otherwise, execute step 215;
[0109] Step 214: trigger the large model to process the business data and return the processing results;
[0110] Step 215: Determine that the verification has failed and return a verification failure message prompt;
[0111] Step 216: Return an error message prompt.
[0112] like Figure 3 As shown, an embodiment of the present invention provides an interface authentication system based on a large model, the system comprising:
[0113] Private key management module 301: used to create at least one user key information and store it in the database, wherein each user key information includes: user identity, key pair consisting of user private key and user public key, salt value, user information, key expiration time and key status;
[0114] Parameter collection module 302: used to obtain request parameters assembled by the client based on the interface call requirements, wherein the request parameters include: business data to be processed, timestamp, and random number ID;
[0115] Signature collection module 303: used to obtain the signature of the client using the user private key on the request parameters collected by the parameter collection module 302, and generate a token for interface authentication, wherein the token includes: signature information and the associated user identity;
[0116] Interface call module 304: is used to perform target verification on the interface call request based on the token collected by the signature collection module 303 when receiving the interface call request, and trigger the large model to process business data after the verification is passed, wherein the target verification includes: timestamp verification, random number ID verification, key status verification, key expiration time verification, and signature verification.
[0117] based on Figure 3 The interface authentication system based on the large model shown in Figure 4 As shown, before the private key management module 301, it further includes: an information verification module 305;
[0118] The information verification module 305 is used to perform:
[0119] D1: Obtain the interface code information entered by the current user and perform uniqueness verification;
[0120] D2: Check whether the current user has valid user key information. If so, execute step D3; otherwise, execute step A1;
[0121] D3: Returns error information.
[0122] like Figure 4 As shown, the private key management module 301 is further configured to execute:
[0123] Using the private key management module to create the user identity in at least one user key information;
[0124] Convert the user identity into a byte array, and use an asymmetric encryption algorithm to generate a key pair consisting of the corresponding user private key and user public key;
[0125] Generate a salt value of a preset length, encrypt the user identity, the user private key, and the user public key based on the salt value using a salt encryption algorithm, and generate an encrypted user identity, an encrypted user private key, and an encrypted user public key;
[0126] The salt value, the encrypted user identity, the encrypted user private key, the encrypted user public key, and the user information input by the current user, the key expiration time, and the key status are stored in a database.
[0127] like Figure 4 As shown, the interface calling module 304 is further used to execute:
[0128] E1: upon receiving the interface call request, verifying based on the token whether the timestamp carried in the interface call request is within the preset validity period; if so, executing step E2; otherwise, executing step E7;
[0129] E2: Compare the random number ID in the interface call request with the stored historical random number ID to determine whether they have the same ID. If so, execute step E7; otherwise, execute step E3;
[0130] E3: Store the current random number ID, and based on the user identity associated with the token, query the key status of the corresponding user key information in the database to determine whether it is in a deactivated state. If so, execute step E7; otherwise, execute step E4;
[0131] E4: Query the expiration time corresponding to the user key information in the database to determine whether the expiration time is earlier than the current time. If so, execute step E7; otherwise, execute step E5;
[0132] E5: Using the user public key corresponding to the user private key, verify the signature information of the request parameter to determine whether the signature verification passes. If so, execute step E6; otherwise, execute step E7;
[0133] E6: Trigger the large model to process business data and return the processing results;
[0134] E7: The verification is determined to have failed and a verification failure message is returned.
[0135] It should be understood that the structure illustrated in the embodiment of the present invention does not constitute a specific limitation on the interface authentication system based on the big model. In other embodiments of the present invention, the interface authentication system based on the big model may include more or fewer components than shown in the figure, or combine or split some components, or arrange the components differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.
[0136] The information interaction, execution process, etc. between the units in the above-mentioned device are based on the same concept as the embodiment of the method of the present invention. For specific contents, please refer to the description in the embodiment of the method of the present invention and will not be repeated here.
[0137] The embodiment of the present invention also provides an interface authentication system based on a large model, comprising: at least one memory and at least one processor;
[0138] at least one memory for storing a machine-readable program;
[0139] At least one processor is configured to call a machine-readable program to execute the interface authentication method based on a large model in any embodiment of the present invention.
[0140] An embodiment of the present invention further provides a computer-readable medium having computer instructions stored thereon. When the computer instructions are executed by a processor, the processor executes the interface authentication method based on a large model in any embodiment of the present invention.
[0141] Specifically, a system or device equipped with a storage medium can be provided, on which software program codes that implement the functions of any of the above-mentioned embodiments are stored, and a computer (or CPU or MPU) of the system or device can be enabled to read and execute the program codes stored in the storage medium.
[0142] In this case, the program code itself read from the storage medium can realize the function of any one of the above-mentioned embodiments, and thus the program code and the storage medium storing the program code constitute part of the present invention.
[0143] Examples of storage media for providing program code include floppy disks, hard disks, magneto-optical disks, optical disks (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), magnetic tapes, non-volatile memory cards, and ROMs. Alternatively, the program code can be downloaded from a server computer via a communication network.
[0144] In addition, it should be clear that the functions of any of the above embodiments can be achieved not only by executing the program code read by the computer, but also by enabling the operating system operating on the computer to complete part or all of the actual operations based on the instructions of the program code.
[0145] In addition, it can be understood that the program code read from the storage medium is written into the memory provided in the expansion board inserted into the computer or into the memory provided in the expansion unit connected to the computer, and then based on the instructions of the program code, the CPU installed on the expansion board or expansion unit is enabled to perform part or all of the actual operations, thereby realizing the functions of any of the above embodiments.
[0146] Each embodiment of the present invention has at least the following beneficial effects:
[0147] 1. In an embodiment of the present invention, an interface authentication method based on a large model is provided. This method creates a new user key information including user identity, key pair, salt value, expiration time, and key status information through a private key management module and stores it in a database, which facilitates the management of user key information, and the random salt value also improves the security of key storage; the client assembles request parameters based on the business data to be processed, timestamp, and random number ID and generates a token using a private key signature, which further improves security; when the interface is called, timestamp verification can prevent replay attacks, random number ID verification can avoid repeated requests, key status and expiration time verification can eliminate the use of invalid or expired keys, and combined with signature verification, it can verify that the data has not been tampered with. The above-mentioned multiple verification mechanisms form a full range of security protection, which controls the entire process from key generation and management, request construction to interface call verification, and can effectively resist risks such as illegal access, data tampering and leakage. It can not only ensure the security of data, but also significantly improve the security of external exposure of the interface;
[0148] 2. In the embodiment of the present invention, by obtaining the interface code entered by the current user and performing a uniqueness check, the uniqueness of each user's identity can be ensured, avoiding identity confusion and authority confusion caused by repeated codes; at the same time, based on this, it is checked whether the current user already has valid user key information. If so, an error prompt is returned, which can strictly restrict the generation of multiple sets of valid keys by the same user, further preventing management loopholes and security risks, and achieving strict control from the source of user key information creation, building a solid initial security line for subsequent token-based interface authentication, and further improving the overall security of interface authentication in large-scale model scenarios;
[0149] 3. In an embodiment of the present invention, first, a new user identity is created through the private key management module to establish a unique and traceable identity for each user; then the user identity is converted into a byte array, and the corresponding key pair is generated using an asymmetric encryption algorithm. With the help of the characteristics of asymmetric encryption, the private key is ensured to be controlled only by the user and the public key can be safely used for signature verification, thereby fundamentally protecting the confidentiality and matching of the key pair; then a salt value of a preset length is generated, and the user identity, private key, and public key are encrypted twice using a salt encryption algorithm. The randomness of the salt value enhances the encryption strength and avoids the leakage of key information due to the cracking of a single encryption method; finally, the salt value, encrypted key information, and user information entered by the user, expiration time, and key status are uniformly stored in the database. At the same time, the user identity, base64 encrypted user private key, and salt value are returned to the front end for display, prompting the user to save them. The user needs to properly keep these key information to ensure the security of the interface call. This process not only realizes the structured management of key information, but also prevents the direct leakage of keys when the database is illegally accessed through encrypted storage. The entire process from key generation, encryption to storage strengthens the security of user key information, lays a solid foundation for the effectiveness of subsequent interface authentication, and thus improves the security of the overall interface.
[0150] It should be noted that not all steps and modules in the above processes and system structure diagrams are required, and certain steps or modules can be omitted according to actual needs. The execution order of each step is not fixed and can be adjusted as needed. The system structure described in the above embodiments can be a physical structure or a logical structure, that is, some modules may be implemented by the same physical entity, or some modules may be implemented by multiple physical entities, or may be implemented by certain components in multiple independent devices.
[0151] In the above embodiments, the hardware unit can be realized by mechanical means or electrical means. For example, a hardware unit can include permanent dedicated circuits or logic (such as special processors, FPGA or ASIC) to complete the corresponding operations. The hardware unit can also include programmable logic or circuits (such as general-purpose processors or other programmable processors), which can be temporarily set up by software to complete the corresponding operations. Concrete implementation (mechanical means or dedicated permanent circuits or temporarily set circuits) can be determined based on the consideration on cost and time.
[0152] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. The interface authentication method based on the large model is characterized by: The method includes: A1: Create at least one user key information using the private key management module and store it in a database, wherein each user key information includes: a user identity, a key pair consisting of a user private key and a user public key, a salt value, user information, a key expiration date, and a key status; A2: Obtain request parameters assembled by the client based on the interface call requirements, wherein the request parameters include: business data to be processed, timestamp, and random number ID; A3: Obtain the signature of the request parameters by the client using the user private key, and generate a token for interface authentication, wherein the token includes: signature information and the associated user identity; A4: When an interface call request is received, the interface call request is subjected to target verification based on the token, and the large model is triggered to process business data after the verification passes. The target verification includes: timestamp verification, random number ID verification, key status verification, key expiration time verification, and signature verification.
2. The method according to claim 1, characterized in that Before the above A1, further comprising: D1: Obtain the interface code information entered by the current user and perform uniqueness verification; D2: Check whether the current user has valid user key information. If so, execute step D3; otherwise, execute step A1; D3: Returns error information.
3. The method according to claim 1, characterized in that Said A1 includes: Using the private key management module to create the user identity in at least one user key information; Convert the user identity into a byte array, and use an asymmetric encryption algorithm to generate a key pair consisting of the corresponding user private key and user public key; Generate a salt value of a preset length, encrypt the user identity, the user private key, and the user public key based on the salt value using a salt encryption algorithm, and generate an encrypted user identity, an encrypted user private key, and an encrypted user public key; The salt value, the encrypted user identity, the encrypted user private key, the encrypted user public key, and the user information input by the current user, the key expiration time, and the key status are stored in a database.
4. The method according to any one of claims 1 to 3, characterized in that The A4 includes: E1: upon receiving the interface call request, verifying based on the token whether the timestamp carried in the interface call request is within the preset validity period; if so, executing step E2; otherwise, executing step E7; E2: Compare the random number ID in the interface call request with the stored historical random number ID to determine whether they have the same ID. If so, execute step E7; otherwise, execute step E3; E3: Store the current random number ID, and based on the user identity associated with the token, query the key status of the corresponding user key information in the database to determine whether it is in a deactivated state. If so, execute step E7; otherwise, execute step E4; E4: Query the expiration time corresponding to the user key information in the database to determine whether the expiration time is earlier than the current time. If so, execute step E7; otherwise, execute step E5; E5: Using the user public key corresponding to the user private key, verify the signature information of the request parameter to determine whether the signature verification passes. If so, execute step E6; otherwise, execute step E7; E6: Trigger the large model to process business data and return the processing results; E7: The verification is determined to have failed and a verification failure message is returned.
5. The interface authentication system based on the large model is characterized by: The system includes: Private key management module: used to create at least one user key information and store it in the database, wherein each user key information includes: user identity, key pair consisting of user private key and user public key, salt value, user information, key expiration time and key status; Parameter collection module: used to obtain the request parameters assembled by the client based on the interface call requirements, wherein the request parameters include: business data to be processed, timestamp, and random number ID; Signature collection module: used to obtain the signature of the request parameters collected by the parameter collection module using the user private key by the client, and generate a token for interface authentication, wherein the token includes: signature information and the associated user identity; Interface call module: used to perform target verification on the interface call request based on the token collected by the signature collection module when receiving the interface call request, and trigger the large model to process business data after the verification is passed, wherein the target verification includes: timestamp verification, random number ID verification, key status verification, key expiration time verification, and signature verification.
6. The system according to claim 5, characterized in that Before the private key management module, it further includes: an information verification module; The information verification module is used to perform: D1: Obtain the interface code information entered by the current user and perform uniqueness verification; D2: Check whether the current user has valid user key information. If so, execute step D3; otherwise, execute step A1; D3: Returns error information.
7. The system according to claim 5, characterized in that The private key management module is further configured to execute: Using the private key management module to create the user identity in at least one user key information; Convert the user identity into a byte array, and use an asymmetric encryption algorithm to generate a key pair consisting of the corresponding user private key and user public key; Generate a salt value of a preset length, encrypt the user identity, the user private key, and the user public key based on the salt value using a salt encryption algorithm, and generate an encrypted user identity, an encrypted user private key, and an encrypted user public key; The salt value, the encrypted user identity, the encrypted user private key, the encrypted user public key, and the user information input by the current user, the key expiration time, and the key status are stored in a database.
8. The system according to any one of claims 5 to 7, characterized in that: The interface calling module is further used to execute: E1: upon receiving the interface call request, verifying based on the token whether the timestamp carried in the interface call request is within the preset validity period; if so, executing step E2; otherwise, executing step E7; E2: Compare the random number ID in the interface call request with the stored historical random number ID to determine whether they have the same ID. If so, execute step E7; otherwise, execute step E3; E3: Store the current random number ID, and based on the user identity associated with the token, query the key status of the corresponding user key information in the database to determine whether it is in a deactivated state. If so, execute step E7; otherwise, execute step E4; E4: Query the expiration time corresponding to the user key information in the database to determine whether the expiration time is earlier than the current time. If so, execute step E7; otherwise, execute step E5; E5: Using the user public key corresponding to the user private key, verify the signature information of the request parameter to determine whether the signature verification passes. If so, execute step E6; otherwise, execute step E7; E6: Trigger the large model to process business data and return the processing results; E7: The verification is determined to have failed and a verification failure message is returned.
9. The interface authentication system based on the large model is characterized by: include: at least one memory and at least one processor; The at least one memory is configured to store a machine-readable program; The at least one processor is configured to call the machine-readable program to execute the method according to any one of claims 1 to 4.
10. A computer-readable medium, characterized in that The computer-readable medium stores computer instructions, which, when executed by a processor, cause the processor to perform the method according to any one of claims 1 to 4.