Configuration Method, System, Device and Storage Medium of an Algorithm Engine Library

By introducing a dual authentication mechanism and full life cycle log tracking in the algorithm engine library, the problems of high computer capabilities, poor security and high coupling in the existing technology of algorithm research and development and management have been solved, and more efficient, secure and flexible algorithm management and research and development have been achieved.

CN115865512BActive Publication Date: 2025-06-27CHINA RESOURCES SMART ENERGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211621253.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-16
Publication Date
2025-06-27
Estimated Expiration
2042-12-16

AI Technical Summary

Technical Problem

The existing technology has problems such as high computer capability requirements, poor algorithm security, difficulty in log tracking and high algorithm coupling in algorithm research and development and management. Especially in complex business scenarios, it is difficult to meet the needs of poor data quality and complex business needs.

Method used

A configuration method of the algorithm engine library is designed. Through the algorithm engine, a unique request ID is assigned to the call encrypted request data, and a dual authentication mechanism, algorithm management and full life cycle log tracking is carried out, which reduces the computer capability requirements for algorithm engineers and eliminates the coupling between different algorithms.

Benefits of technology

It improves the security and performance of the algorithm, reduces the computer capability requirements for algorithm engineers, simplifies the algorithm management and iterative update process, and enhances the log tracking capability of the algorithm execution process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115865512B_ABST
    Figure CN115865512B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of computer application technologies, and particularly to a configuration method, system, device, and storage medium for an algorithm engine library, including: The algorithm engine assigns a unique request ID to an algorithm call request, and after detecting the legality of the algorithm path accessed by the client, it successively performs the first authentication, detects the algorithm service allocation quota and the online status of the algorithm service, and the second authentication. After the second authentication passes, the algorithm service instance processes the algorithm call request of the client to obtain operation result data. By using the method provided by the present invention, not only can a dual authentication mechanism and algorithm management for algorithm services and algorithm applications in the algorithm engine be realized, with high security, but also the computer ability requirements for algorithm engineers are reduced, the algorithm R & D efficiency and human resource utilization rate are improved. At the same time, full-life-cycle log tracking is realized through the assigned request ID, and by adopting independent algorithm applications, the coupling between different algorithms is eliminated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer application technologies, and in particular, to a method, system, device, and storage medium for configuring an algorithm engine library. Background Art

[0002] In the current environment of the rapid popularization of 5G and IoT, all industries have started to transform towards digitalization and intelligence. In order to seek better development, enterprises' investment in algorithm research and development has been increasing day by day. Algorithm research and development is an intellectual activity that integrates business knowledge, mathematical theory, and computer engineering, and it is inevitably a highly difficult task. If the algorithm is implemented by personnel who are not good at engineering research and development, there will be more or less problems in the robustness and security of the code. Generally, the industry uses the form of operator and strategy combination to solve this problem. Algorithm engineers develop basic operators for some scenarios and register them in the operator library. When using, corresponding operators can be selected in the graphical interface and connected in the form of a graph to form a strategy configuration diagram to construct an algorithm that meets the actual needs. In addition to using the strategy configuration diagram to construct an algorithm, currently, source code is also used to concatenate basic operators to construct an algorithm.

[0003] The advantage of developing algorithms in the way of operator and strategy combination is that operators generally are responsible for functions that are relatively simple, have a lower research and development difficulty, a smaller workload, are more convenient for update and iteration, and only need to select basic operators and set logical parameters to connect them into a configuration diagram or write a piece of call code to form an algorithm that can be externally called. However, the way of using a configuration diagram is generally limited by the platform and the underlying technical architecture. In complex business scenarios, the number of operators required for algorithm research and development and the complexity of the graph increase sharply. Generally, the research and development specifications of operators are relatively strict, which restricts highly capable algorithm engineers too much and is more difficult to apply to scenarios with poor data quality. Compared with the way of concatenating operators using a configuration diagram, source code concatenating basic operators can add some business logic code of the algorithm engineer himself at the operator connection link. Although this improves the flexibility of algorithm research and development to a certain extent, it is also restricted by the interface specifications of the operators. Therefore, this way of developing algorithms is applicable to industrial scenarios with high-quality data sources, simple and clear business requirements, strong business capabilities of algorithm engineers, and weak engineering capabilities. In industrial scenarios, affected by various factors, the data quality generally does not reach the ideal situation, and the business requirements are mostly professional and complex. The way of developing algorithms by the operator and strategy configuration method is not very applicable in this case.

[0004] Most of the statistics-based algorithms discover patterns from historical data, refine the patterns and solidify them into data formulas. As time changes, the patterns in the data also change, which requires algorithm engineers to regularly update the algorithms to solve the timeliness problem. However, the abnormal execution of algorithms caused by problems such as data missing, low data quality, and outliers will also lead to frequent algorithm updates by algorithm engineers. The existing solutions mainly achieve algorithm iteration updates by modifying the basic operators and operator combination logics. However, an operator is generally used by multiple algorithms, and the update operation also needs to consider the impact on the running algorithms. Therefore, algorithm engineers generally create a new operator to avoid this problem. Over time, this method will inevitably lead to a bloated and difficult-to-manage operator library. In summary, although the algorithm iteration can be quickly and simply achieved by modifying the operator combination logic, it cannot meet the iterative scenarios with large modification amplitudes.

[0005] If classified by type, algorithms can be divided into three categories: supervised learning algorithms, unsupervised learning algorithms, and reinforcement learning. If classified by scenario, algorithms can be divided into categories such as machine vision, speech processing, and text recognition. Coupled with industries and demand types, more categories can be generated. It can be seen from this that in the actual application process, different users have different functional requirements for algorithms. Even the same algorithm will have some differences due to the differences in training data. At the same time, the algorithm center also needs to provide service registration and management functions for a large number of algorithms, provide external access ports, and ensure the security and reliability of service calls. Therefore, a mechanism for managing and calling authentication of algorithm services is urgently needed. However, in the existing solutions, algorithms are generally published on the API gateway in the form of APIs. Users send request data and secret keys to the interfaces provided by the API gateway to obtain the calculation results of the algorithms. The security, performance, service registration, and service management of the algorithms are all borne by the API gateway. This makes each algorithm service have a unique authentication information. Once a hacker obtains the public key of the algorithm, the algorithm can be called at will. Moreover, the same algorithm may be called by multiple different users. If the same user needs to call multiple algorithms, multiple different secret keys need to be used, which increases the management difficulty. At the same time, the API gateway can only monitor the request parameters and return requests of user requests, and cannot trace the logs during the algorithm execution process. Summary of the Invention

[0006] The purpose of the present invention is to provide a configuration method, system, device, and storage medium for an algorithm engine library to reduce the computer ability requirements for algorithm engineers, and at the same time design a dual authentication mechanism, algorithm management, and full-life cycle log tracing to eliminate the coupling between different algorithms.

[0007] To solve the above technical problems, the present invention provides a configuration method, system, device, and storage medium for an algorithm engine library.

[0008] In a first aspect, the present invention provides a method for configuring an algorithm engine library, the method comprising the following steps:

[0009] Encrypt the algorithm call request generated by the client according to the public key allocated by the algorithm engine to obtain a call encrypted request data, and send the call encrypted request data to the algorithm engine;

[0010] The algorithm engine allocates a unique request ID to the call encrypted request data, and detects the legality of the algorithm path accessed by the client. If the algorithm path is legal, perform a first authentication according to the call encrypted request data, and obtain encrypted request parsing data;

[0011] When the first authentication passes, the algorithm engine sequentially detects the allocation quota of the algorithm service in the algorithm application and the online status of the algorithm service in the call encrypted request data, and when the allocation quota is not used up and the algorithm service is in an online state, encrypt the encrypted request parsing data to obtain secondary encrypted request data;

[0012] Generate encrypted request update data according to the secondary encrypted request data and the request ID, and send the encrypted request update data to the algorithm service instance;

[0013] The algorithm service instance performs a second authentication according to the encrypted request update data and obtains encrypted request update parsing data;

[0014] After the second authentication passes, the algorithm service instance executes algorithm logic according to the encrypted request update parsing data to obtain operation result data, and feeds back the operation result data to the client.

[0015] In a further embodiment, the step of performing the first authentication according to the call encrypted request data includes:

[0016] If it is determined that the algorithm path is legal, extract the number of the algorithm application from the algorithm path, and query the algorithm application private key in the algorithm engine according to the number of the algorithm application;

[0017] Parse the call encrypted request data by using the algorithm application private key to obtain encrypted request parsing data;

[0018] Judge the validity of the encrypted request parsing data. If it is detected that the encrypted request parsing data is valid, determine that the first authentication passes.

[0019] In a further embodiment, the step of, when the first authentication passes, the algorithm engine sequentially detecting the allocation quota of the algorithm service in the algorithm application and the online status of the algorithm service in the call encryption request data specifically includes:

[0020] When the first authentication passes, detecting the allocation quota of the algorithm service in the algorithm application in the call encryption request data;

[0021] If it is detected that the allocation quota has been used up, the algorithm engine feeds back an abnormal signal to the client and records relevant log information;

[0022] If it is detected that the allocation quota has not been used up, the algorithm engine detects the online status of the algorithm service, and when it is detected that the algorithm service is in an online state, queries the algorithm service instance access address and the algorithm service instance public key from the algorithm service list of the algorithm engine, so as to encrypt the encrypted request parsing data according to the algorithm service instance public key to obtain secondary encrypted request data;

[0023] When it is detected that the algorithm service is in an offline state, the algorithm engine feeds back an abnormal signal to the client and records relevant log information.

[0024] In a further embodiment, the step that the algorithm service instance performs a second authentication according to the encrypted request update data and obtains the encrypted request update parsing data includes:

[0025] When the algorithm service instance receives the encrypted request update data sent by the algorithm engine, parses the encrypted request update data according to the algorithm service instance private key to obtain the encrypted request update parsing data;

[0026] Judging the validity of the encrypted request update parsing data, if it is detected that the encrypted request update parsing data is valid, it is determined that the second authentication passes; otherwise, the algorithm service instance feeds back an abnormal signal and records relevant log information.

[0027] In a further embodiment, before the step of encrypting the algorithm call request generated by the client according to the public key allocated by the algorithm engine to obtain the call encryption request data, the method further includes:

[0028] According to the obtained user call demand information, select several algorithm services in the algorithm service list, configure the allocation quota of each algorithm service, and package the configured algorithm services to generate an algorithm application;

[0029] The algorithm engine allocates an algorithm application main access path and an algorithm application private key for the algorithm application, and allocates an algorithm service sub-path for each algorithm service;

[0030] According to the main access path of the algorithm and the algorithm service sub-path, the algorithm path accessed by the client is obtained.

[0031] In a further embodiment, the method further includes updating the algorithm service according to the obtained repair change requirement information, specifically including:

[0032] According to the obtained repair change requirement information, update the algorithm logic, and perform local testing on the updated algorithm logic;

[0033] After passing the local test, send the updated algorithm logic to the algorithm engine for packaging, and archive it to the algorithm service list in the algorithm engine;

[0034] Update the parameters of the corresponding algorithm service according to the updated algorithm logic to obtain algorithm service update parameters; wherein, the algorithm service update parameters include an algorithm service update image and an algorithm service update private key;

[0035] When the algorithm engine detects the algorithm service update parameters, set the corresponding algorithm service to an unusable state until the algorithm service instance loads and executes all the algorithm logic, and update the original image release instance according to the algorithm service update parameters to obtain a new image release instance, completing the algorithm service update.

[0036] In a further embodiment, the method further includes: querying relevant log information in the algorithm engine according to the request ID and preset algorithm index information, where the log information includes the request ID; wherein, the algorithm index information includes an algorithm query date, an algorithm service name, and an algorithm application name.

[0037] In a second aspect, the present invention provides a configuration system for an algorithm engine library, the system includes:

[0038] A preliminary encryption module, configured to encrypt the algorithm call request generated by the client according to the public key assigned by the algorithm engine to obtain call encrypted request data, and send the call encrypted request data to the algorithm engine;

[0039] A first authentication module, configured to assign a unique request ID to the call encrypted request data by the algorithm engine, and detect the legality of the algorithm path accessed by the client. If the algorithm path is legal, perform the first authentication according to the call encrypted request data, and obtain encrypted request parsing data;

[0040] The secondary encryption module is used to, when the first authentication is passed, the algorithm engine sequentially detects the allocation quota of the algorithm service in the algorithm application and the online status of the algorithm service in the call encryption request data, and encrypts the encrypted request parsing data to obtain secondary encrypted request data when the allocation quota is not used up and the algorithm service is in an online state;

[0041] The second authentication module is used to generate encrypted request update data according to the secondary encrypted request data and the request ID, and send the encrypted request update data to the algorithm service instance; it is also used for the algorithm service instance to perform a second authentication according to the encrypted request update data and obtain encrypted request update parsing data;

[0042] The algorithm operation module is used to, after the second authentication is passed, the algorithm service instance executes algorithm logic according to the encrypted request update parsing data to obtain operation result data, and feedback the operation result data to the client.

[0043] In a third aspect, the present invention further provides a computer device, including a processor and a memory, the processor is connected to the memory, the memory is used to store a computer program, and the processor is used to execute the computer program stored in the memory so that the computer device executes the steps of implementing the above method.

[0044] In a fourth aspect, the present invention further provides a computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, the steps of implementing the above method are realized.

[0045] The present invention provides a configuration method, system, device and storage medium of an algorithm engine library. The method assigns a unique request ID to the call encryption request data through the algorithm engine, and after detecting the legality of the algorithm path accessed by the client, performs the first authentication, detects the allocation quota and online status of the algorithm service in sequence, and performs a second authentication according to the detection results of the first authentication, the allocation quota of the algorithm service and the online status, so as to execute the algorithm logic. Compared with the prior art, in this embodiment, the algorithm engine randomly generates private keys of the algorithm service and the algorithm application, and processes the algorithm instance after both the first algorithm application authentication and the second algorithm service authentication are passed, so as to avoid direct interaction between the client and the algorithm service, improve the algorithm security factor and algorithm performance. At the same time, the algorithm engine in the present invention is responsible for communication, authentication, scheduling, etc. during the process of the client calling the algorithm, reduces the computer ability requirements for algorithm engineers, and saves human resources. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] Figure 1 is a schematic flowchart of a configuration method of an algorithm engine library provided by an embodiment of the present invention;

[0047] Figure 2 It is a schematic diagram of the R & D and release time sequence of the algorithm service provided by an embodiment of the present invention;

[0048] Figure 3 It is a schematic diagram of the call time sequence of the algorithm service provided by an embodiment of the present invention;

[0049] Figure 4 It is a block diagram of the configuration system of an algorithm engine library provided by an embodiment of the present invention;

[0050] Figure 5 It is a schematic diagram of the structure of a computer device provided by an embodiment of the present invention. Specific embodiments

[0051] The following specifically illustrates the implementation manner of the present invention in conjunction with the accompanying drawings. The given embodiments are only for illustrative purposes and should not be construed as a limitation of the present invention. The accompanying drawings are only for reference and illustration, and do not constitute a limitation on the scope of patent protection of the present invention, because many changes can be made to the present invention without departing from the spirit and scope of the present invention.

[0052] Refer to Figure 1 An embodiment of the present invention provides a method for configuring an algorithm engine library. As Figure 1 shown, the method includes the following steps:

[0053] S1. Encrypt the algorithm call request generated by the client according to the public key assigned by the algorithm engine to obtain the call encrypted request data, and send the call encrypted request data to the algorithm engine.

[0054] As Figure 2 shown, before the algorithm service is called in this embodiment, it is necessary to publish the algorithm service according to the obtained algorithm R & D requirement information. Among them, the algorithm service publishing steps include:

[0055] Generate an algorithm logic according to the obtained algorithm R & D requirement information, perform local testing on the algorithm logic, and after the local testing is passed, send the algorithm logic to the algorithm engine and set the algorithm logic parameters; among them, the algorithm logic parameters include algorithm input parameters, static resources required to run the algorithm, and expected output results of the algorithm;

[0056] The algorithm engine performs an online test according to the algorithm logic parameters. After the online test passes, the algorithm logic is packaged to obtain an image package. During the packaging process of the algorithm logic, the algorithm application private key and the algorithm service instance private key generated by the encryption algorithm randomly selected by the algorithm engine are uploaded to the image library, and the public key, algorithm name, algorithm version, algorithm parameter description and other algorithm key information assigned by the algorithm engine are archived in the image library of the algorithm engine;

[0057] Configure the instance information of the image package and send an algorithm service deployment request to the algorithm engine;

[0058] After receiving the algorithm service deployment request, the algorithm engine deploys an algorithm service instance in the container cluster according to the configured instance information, and archives the algorithm service instance access address, algorithm service instance port and algorithm service instance public key in the algorithm service list of the algorithm engine.

[0059] Specifically, the algorithm engineer designs a model and an algorithm process according to the algorithm R & D requirement information, and uses the basic features of a computer high-level language (such as C, C++, JAVA, Python, etc.) to complete the algorithm engineering. After the algorithm engineer completes and passes the local test of the algorithm logic code, the algorithm logic code is submitted to the algorithm engine library. At the same time, the input parameters of the algorithm, the static resources required to run the algorithm, and the expected output results of the algorithm are set, and an online test is executed. After the online test passes, the algorithm is packaged into an image package using the algorithm engine. During the packaging process, the algorithm engine will randomly select an encryption algorithm and generate a pair of secret keys, write privately to the image library, and at the same time archive the public key, algorithm name, version, algorithm parameter description and other algorithm key information in the image library of the algorithm engine.

[0060] The algorithm engineer logs in to the image library of the algorithm engine, selects the packaged image in the previous step, and after configuring the instance information such as the number of algorithm service instances, the cpu, memory, hard disk resources, and service name occupied by each algorithm service instance, submits an algorithm service deployment request. After receiving the algorithm service deployment request, the algorithm engine deploys an algorithm service instance on the container cluster according to the configuration parameters, and archives the access address, port, and public key of the algorithm service instance in the algorithm service list of the algorithm engine.

[0061] After this embodiment completes the algorithm service publishing step, the user encrypts the algorithm call request generated by the client according to the public key allocated by the algorithm engine to obtain the call encrypted request data, and sends the call encrypted request data to the algorithm engine through the client. After the scheduling module of the algorithm engine receives the call encrypted request data, it starts the algorithm service call process. Among them, before encrypting the algorithm call request generated by the client according to the public key allocated by the algorithm engine to obtain the call encrypted request data, the method further includes obtaining the algorithm path that the client can access according to the user call demand information, specifically including:

[0062] According to the obtained user call demand information, select several algorithm services that meet the user's needs from the algorithm service list, configure the allocation quota of each algorithm service, and package the configured algorithm services to generate an algorithm application;

[0063] The algorithm engine allocates an algorithm application main access path and an algorithm application private key for the algorithm application, and allocates an algorithm service sub-path for each algorithm service;

[0064] According to the algorithm application main access path and the algorithm service sub-path, obtain the algorithm path accessed by the client.

[0065] Specifically, the user selects several algorithm services that meet the user's needs from the algorithm service list, configures the usage amount of each algorithm service, packages these algorithm services into an algorithm application, and the algorithm engine will allocate a main access path and a secret key for the algorithm application, and will also allocate a sub-path for each algorithm service, and combine the algorithm application main access path and the algorithm service sub-path to obtain the algorithm path that the client can access.

[0066] This embodiment manages algorithms through a two-level mechanism of algorithm services and algorithm applications, enabling users to select multiple algorithm services according to their needs, configure the usage amount and then package them into an algorithm application. Thus, when using, the user only needs to change the sub-path of the access address to call different algorithms, and only one secret key needs to be used inside the same algorithm application, which is more convenient. Moreover, each user uses an independent algorithm application, and this isolation mechanism is also more convenient and reliable to maintain.

[0067] S2. The algorithm engine assigns a unique request ID to the call encrypted request data, and detects the legality of the algorithm path accessed by the client. If the algorithm path is legal, perform the first authentication according to the call encrypted request data, and obtain the encrypted request parsing data.

[0068] Specifically, the scheduling module of the algorithm engine first assigns a unique request ID to the encrypted request data being called, uses the request ID as the unique identifier for all the following operation log information, and at the same time uses the request ID as one of the parameters in the result returned to the client. Then, it detects the legality of the algorithm path accessed by the client. It should be noted that in this embodiment, detecting the legality of the algorithm path accessed by the client includes detecting whether the syntax rules of the algorithm path are legal and whether the algorithm application corresponding to the algorithm path exists. When and only when both the algorithm path syntax rules are legal and the algorithm application exists, this embodiment performs the first authentication based on the encrypted request data being called. Otherwise, it determines that the algorithm path is illegal and feeds back an abnormal signal to the client. Among them, the step of performing the first authentication based on the encrypted request data being called includes:

[0069] If it is determined that the algorithm path is legal, extract the algorithm application number from the algorithm path, and query the algorithm application private key in the algorithm engine according to the algorithm application number;

[0070] Use the algorithm application private key to parse the encrypted request data being called to obtain encrypted request parsing data;

[0071] Judge the validity of the encrypted request parsing data. If it is detected that the encrypted request parsing data is valid, it is determined that the first authentication passes; otherwise, it is determined that the first authentication fails, and an abnormal signal is fed back to the client and relevant log information is recorded.

[0072] S3. When the first authentication passes, the algorithm engine sequentially detects the allocation quota of the algorithm service in the algorithm application and the online status of the algorithm service in the encrypted request data being called, and when the allocation quota has not been used up and the algorithm service is in an online state, encrypt the encrypted request parsing data to obtain secondary encrypted request data.

[0073] In this embodiment, the step of when the first authentication passes, the algorithm engine sequentially detects the allocation quota of the algorithm service in the algorithm application and the online status of the algorithm service in the encrypted request data being called specifically includes:

[0074] When the first authentication passes, detect the allocation quota of the algorithm service in the encrypted request data being called;

[0075] If it is detected that the allocation quota has been used up, the algorithm engine feeds back an abnormal signal to the client and records relevant log information;

[0076] If it is detected that the allocated quota is not used up, the algorithm engine detects the online status of the algorithm service. When it is detected that the algorithm service is in an online state, the algorithm service instance access address and the public key of the algorithm service instance are queried from the algorithm service list of the algorithm engine, so as to encrypt the encrypted request parsing data according to the public key of the algorithm service instance to obtain the secondary encrypted request data. It should be noted that in this embodiment, the request needs to meet three conditions: the first authentication is passed, the allocated quota is not used up, and the algorithm service is online, before the request is forwarded to the algorithm instance;

[0077] When it is detected that the algorithm service is in an offline state, the algorithm engine feeds back an abnormal signal to the client and records relevant log information.

[0078] S4. Generate encrypted request update data according to the secondary encrypted request data and the request ID, and send the encrypted request update data to the algorithm service instance.

[0079] In this embodiment, after encrypting the encrypted request parsing data according to the public key of the algorithm service instance to obtain the secondary encrypted request data, the secondary encrypted request data and the request ID allocated by the algorithm engine are constructed together as encrypted request update data (new request data), and the scheduling module of the algorithm engine sends the encrypted request update data to the algorithm service instance through the algorithm service instance access address.

[0080] S5. The algorithm service instance performs a second authentication according to the encrypted request update data and obtains encrypted request update parsing data.

[0081] In this embodiment, the steps for the algorithm service instance to perform a second authentication according to the encrypted request update data and obtain encrypted request update parsing data include:

[0082] When the algorithm service instance receives the encrypted request update data sent by the algorithm engine, it parses the encrypted request update data according to the private key of the algorithm service instance to obtain encrypted request update parsing data;

[0083] Judge the validity of the encrypted request update parsing data. If it is detected that the encrypted request update parsing data is valid, it is determined that the second authentication is passed; otherwise, the algorithm service instance feeds back an abnormal signal to the client and records relevant log information.

[0084] In the second authentication, after the algorithm service instance receives the encrypted request update data, it checks whether the public key in the encrypted request update data matches the private key of the algorithm service instance held by the algorithm service instance. If they do not match, it feeds back an abnormal signal to the client and records relevant log information.

[0085] In this embodiment, the algorithm service and the algorithm application both have independent keys. After the algorithm service is updated, its key will also be updated. The algorithm call request sent by the client needs to be authenticated twice before it can be processed by the algorithm service instance, which greatly improves the security of the algorithm. Among them, the two authentication keys are randomly generated by the algorithm engine. The scheduling module of the algorithm engine holds the private key of the first authentication (algorithm application authentication) and the public key of the second authentication (algorithm service authentication). The algorithm service instance in the algorithm engine holds the private key of the second authentication, and the user only holds the public key of the first authentication. The client does not directly interact with the algorithm service, and the algorithm engine has a high security factor.

[0086] S6. After the second authentication is passed, the algorithm service instance updates the parsed data according to the encryption request to execute the algorithm logic, obtains the calculation result data, and feeds back the calculation result data to the client; this embodiment returns the calculation result data to the scheduling module of the algorithm engine, and after the scheduling module of the algorithm engine receives the calculation result data, it forwards the calculation result data to the client, and the algorithm call is completed.

[0087] In one embodiment, a configuration method of an algorithm engine library provided by this embodiment further includes: performing an algorithm service update according to the acquired repair change requirement information, wherein the algorithm service update specifically includes:

[0088] According to the acquired repair change requirement information, the algorithm logic is updated, and the updated algorithm logic is tested locally;

[0089] After the local test passes, the updated algorithm logic is sent to the algorithm engine for packaging and archived in the algorithm service list in the algorithm engine;

[0090] Update the parameters of the corresponding algorithm service according to the updated algorithm logic to obtain the algorithm service update parameters; wherein the algorithm service update parameters include the algorithm service update image and the algorithm service update private key;

[0091] When the algorithm engine detects the algorithm service update parameters, it sets the corresponding algorithm service to an unusable state until the algorithm service instance loads and executes all algorithm logics, updates the original image publishing instance according to the algorithm service update parameters, obtains a new image publishing instance, and completes the algorithm service update.

[0092] Specifically, according to the need for requirement change or exception repair, the algorithm engineer modifies or redevelops the specified algorithm logic code, updates the algorithm logic according to the modified algorithm logic code, and conducts local testing on the updated algorithm logic. After passing the local test, it is submitted to the algorithm engine for packaging and archiving. Then, the algorithm engineer enters the algorithm service list of the algorithm engine, updates the image and secret key parameters of the corresponding algorithm service to the new image and secret key parameters, and keeps other parameters unchanged. When the algorithm engine detects a change in the algorithm service parameters, it immediately sets the algorithm service to the unusable state. In this state, the scheduling module of the algorithm engine will reject all client requests accessing this algorithm and inform the client in the returned information that the service is temporarily unavailable. After all requests in the algorithm service instance have been run, the algorithm engine uses the new image to publish an instance to replace the original image publishing instance. Thus, the algorithm service update is completed.

[0093] The algorithm service instance designed in this embodiment is deployed in a containerized manner, sharing computer resources at the physical level. Each algorithm service instance is independent of each other and is not affected by coupling. Therefore, adopting the technical solution of the embodiment of the present invention, when the business requirements change, the algorithm engineer only needs to modify several relevant algorithms, with a small scope of influence. The update operation only needs to repackage the new code and modify the algorithm image in the algorithm service table to the new image to complete the update, and the operation is simple. At the same time, the built-in update mechanism of the algorithm engine can ensure that the requests submitted before the update run normally, and the requests sent during the update process will be informed that the algorithm is unavailable. The update process can be carried out online and is safe and reliable.

[0094] In one embodiment, the method further includes: querying relevant log information in the algorithm engine according to the request ID and preset algorithm index information, where the log information includes the request ID; and the algorithm index information includes the algorithm query date, algorithm service name, and algorithm application name.

[0095] In this embodiment, the algorithm engine assigns a unique request ID to each request initiated by the client. The logs generated during the entire process of the algorithm from receiving input parameters, executing the algorithm, to returning results are all attached with the assigned request ID. The algorithm engineer or user can log in to the log system of the algorithm engine and retrieve and view the logs using information such as the assigned request ID, date, algorithm service name, and algorithm application name. It should be noted that the logs and the data that need to be recorded within the algorithm instance will all be attached with the assigned request ID for later tracking and analysis.

[0096] In this embodiment, since the algorithm engine is responsible for communication, authentication, scheduling, etc. during the client's call of the algorithm, the algorithm engineer only needs to master the basic part of a computer language to complete the algorithm development, which greatly reduces the energy and time required for the algorithm engineer to learn the basic part of a computer language. This enables the algorithm engineer to focus mainly on sorting out the business logic and overcoming difficulties, thus fully ensuring the flexibility of algorithm development, the usability of the developed algorithm, and its scene coverage ability is significantly better than the development method of operators and policy configuration. At the same time, all the logs generated by the requests initiated by the client contain the unique request ID assigned by the algorithm engine scheduling module. Based on this request ID, all the logs of data interaction during the algorithm execution can be traced, and these logs can help the algorithm engineer analyze the customer's behavior habits and improve the algorithm performance.

[0097] The embodiment of the present invention provides a configuration method for an algorithm engine library. The method includes that the algorithm engine assigns a unique request ID to the algorithm call request and detects the legality of the algorithm path accessed by the client. If the algorithm path is legal, the first authentication is performed according to the encrypted call request data. When the first authentication passes, the algorithm engine sequentially detects the allocation quota of the algorithm service in the algorithm application and the online status of the algorithm service in the encrypted call request data, and then performs the second authentication. After the second authentication passes, the algorithm service instance updates the parsing data according to the encrypted request, loads and executes the algorithm logic, and obtains the operation result data. Compared with the prior art, the technical solution adopted in this embodiment is that the algorithm engine is responsible for communication, authentication, scheduling, etc. during the client's call of the algorithm, which improves the algorithm development efficiency and the utilization rate of human resources. Moreover, the algorithm call request sent by the client needs to pass two-step authentication before being processed by the algorithm service instance, which greatly improves the security factor. At the same time, through the assigned request ID, it is more convenient to track and analyze later, and the algorithm performance can be improved.

[0098] It should be noted that the magnitudes of the serial numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0099] In one embodiment, as Figure 4 shown, the embodiment of the present invention provides a configuration system for an algorithm engine library. The system includes:

[0100] A preliminary encryption module 101, configured to encrypt the algorithm call request generated by the client according to the public key assigned by the algorithm engine to obtain the encrypted call request data, and send the encrypted call request data to the algorithm engine;

[0101] The first authentication module 102 is configured to assign a unique request ID to the invoked encrypted request data through the algorithm engine, and detect the legality of the algorithm path accessed by the client. If the algorithm path is legal, perform the first authentication based on the invoked encrypted request data, and obtain encrypted request parsing data;

[0102] The secondary encryption module 103 is configured to, when the first authentication passes, the algorithm engine sequentially detects the allocation quota of the algorithm service in the algorithm application and the online status of the algorithm service in the invoked encrypted request data, and encrypt the encrypted request parsing data to obtain secondary encrypted request data when the allocation quota is not used up and the algorithm service is in an online state;

[0103] The second authentication module 104 is configured to generate encrypted request update data according to the secondary encrypted request data and the request ID, and send the encrypted request update data to the algorithm service instance; it is also configured to perform a second authentication by the algorithm service instance according to the encrypted request update data, and obtain encrypted request update parsing data;

[0104] The algorithm operation module 105 is configured to, after the second authentication passes, the algorithm service instance execute algorithm logic according to the encrypted request update parsing data to obtain operation result data, and feedback the operation result data to the client.

[0105] For the specific limitations of a configuration system of an algorithm engine library, reference can be made to the above limitations on a configuration method of an algorithm engine library, which will not be elaborated here. Those of ordinary skill in the art can realize that the various modules and steps described in combination with the embodiments disclosed in this application can be implemented by hardware, software, or a combination of both. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0106] The embodiment of the present invention provides a configuration system of an algorithm engine library. The system realizes two-level authentication and management of algorithm services and algorithm applications in the algorithm engine through the first authentication module, the secondary encryption module, and the second authentication module. When both authentications pass, the algorithm service instance processes the algorithm call request sent by the client. Compared with the prior art, the present application is easy to operate and manage, has high security through secondary authentication and tracking data interaction during the algorithm execution process through the request ID. At the same time, the embodiment of the present invention uses independent algorithm applications, eliminates the coupling between different algorithms, and makes the iterative update of the algorithm more convenient.

[0107] Figure 5A computer device provided by an embodiment of the present invention includes a memory, a processor, and a transceiver, which are connected through a bus; the memory is used to store a set of computer program instructions and data, and can transmit the stored data to the processor, and the processor can execute the program instructions stored in the memory to execute the steps of the above method.

[0108] Among them, the memory may include a volatile memory or a non-volatile memory, or may include both a volatile and a non-volatile memory; the processor may be a central processing unit, a microprocessor, an application specific integrated circuit, a programmable logic device, or a combination thereof. By way of example but not limitation, the above programmable logic device may be a complex programmable logic device, a field programmable gate array, a generic array logic, or any combination thereof.

[0109] In addition, the memory may be a physically independent unit or may be integrated with the processor.

[0110] Those of ordinary skill in the art can understand that Figure 5 the structure shown in

[0111] is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have the same component arrangement.

[0112] A configuration method, system, device, and storage medium for an algorithm engine library provided by an embodiment of the present invention. In a configuration method of an algorithm engine library, the algorithm engine is responsible for processes such as communication, authentication, and scheduling during the client's call of the algorithm, reducing the requirements for the computer capabilities of algorithm engineers, enabling algorithm engineers to focus more on solving professional problems. At the same time, through the design of a two-level authentication mechanism, the addition of algorithm management and full-life cycle log tracking, the friendliness, security, and reliability of the algorithm center are improved, and it is more convenient for the iteration and update of the algorithm.

[0113] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as an SSD), etc.

[0114] Those skilled in the art can understand that all or part of the processes in the above embodiments of the method can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed, it can include the processes of the above embodiments of each method.

[0115] The above embodiments only represent several preferred implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the technical principle of the present invention, several improvements and substitutions can be made, and these improvements and substitutions should also be regarded as the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the protection scope of the claims.

Claims

1. A configuration method for an algorithm engine library, characterized in that It includes the following steps: Encrypt the algorithm call request generated by the client according to the public key allocated by the algorithm engine to obtain the call encrypted request data, and send the call encrypted request data to the algorithm engine; The algorithm engine allocates a unique request ID for the call encrypted request data, and detects the legality of the algorithm path accessed by the client. If the algorithm path is legal, perform the first authentication according to the call encrypted request data, and obtain the encrypted request parsing data; When the first authentication passes, the algorithm engine sequentially detects the allocation quota of the algorithm service in the algorithm application and the online status of the algorithm service in the call encrypted request data, and when the allocation quota is not used up and the algorithm service is in the online state, encrypt the encrypted request parsing data to obtain the secondary encrypted request data; Generate the encrypted request update data according to the secondary encrypted request data and the request ID, and send the encrypted request update data to the algorithm service instance; The algorithm service instance performs the second authentication according to the encrypted request update data and obtains the encrypted request update parsing data; After the second authentication passes, the algorithm service instance executes the algorithm logic according to the encrypted request update parsing data to obtain the operation result data, and feeds back the operation result data to the client.

2. The configuration method of an algorithm engine library according to claim 1, characterized in that, The step of performing the first authentication according to the call encrypted request data includes: If it is determined that the algorithm path is legal, extract the number of the algorithm application from the algorithm path, and query the algorithm application private key in the algorithm engine according to the number of the algorithm application; Use the algorithm application private key to parse the call encrypted request data to obtain the encrypted request parsing data; Judge the validity of the encrypted request parsing data. If it is detected that the encrypted request parsing data is valid, it is determined that the first authentication passes.

3. The configuration method of an algorithm engine library according to claim 1, characterized in that The step that when the first authentication passes, the algorithm engine sequentially detects the allocation quota of the algorithm service in the algorithm application and the online status of the algorithm service in the call encrypted request data specifically includes: When the first authentication passes, detect the allocation quota of the algorithm service in the call encrypted request data; If it is detected that the allocation quota has been used up, the algorithm engine feeds back an abnormal signal to the client and records the relevant log information; If it is detected that the allocation quota is not used up, the algorithm engine detects the online status of the algorithm service, and when it is detected that the algorithm service is in the online state, query the access address of the algorithm service instance and the public key of the algorithm service instance from the algorithm service list of the algorithm engine, so as to encrypt the encrypted request parsing data according to the public key of the algorithm service instance to obtain the secondary encrypted request data; When it is detected that the algorithm service is in the offline state, the algorithm engine feeds back an abnormal signal to the client and records the relevant log information.

4. The configuration method of an algorithm engine library according to claim 1, characterized in that, The step that the algorithm service instance performs the second authentication according to the encrypted request update data and obtains the encrypted request update parsing data includes: When the algorithm service instance receives the encrypted request update data sent by the algorithm engine, it parses the encrypted request update data according to the private key of the algorithm service instance to obtain the encrypted request update parsed data; Judge the validity of the encrypted request update parsed data. If it is detected that the encrypted request update parsed data is valid, it is determined that the second authentication passes; otherwise, the algorithm service instance feeds back an abnormal signal and records relevant log information.

5. The configuration method of an algorithm engine library according to claim 1, characterized in that Before the step of encrypting the algorithm call request generated by the client with the public key assigned by the algorithm engine to obtain the call encrypted request data, the method further includes: According to the obtained user call requirement information, select several algorithm services in the algorithm service list, configure the allocation quota for each algorithm service, and package the configured algorithm services to generate an algorithm application; The algorithm engine assigns an algorithm application main access path and an algorithm application private key to the algorithm application, and assigns an algorithm service sub-path to each algorithm service; According to the algorithm application main access path and the algorithm service sub-path, obtain the algorithm path accessed by the client.

6. The configuration method of an algorithm engine library according to claim 1, wherein, The method further includes updating the algorithm service according to the obtained repair change requirement information, specifically including: According to the obtained repair change requirement information, update the algorithm logic and perform local testing on the updated algorithm logic; After passing the local test, send the updated algorithm logic to the algorithm engine for packaging and archive it in the algorithm service list in the algorithm engine; Update the parameters of the corresponding algorithm service according to the updated algorithm logic to obtain algorithm service update parameters; wherein, the algorithm service update parameters include an algorithm service update image and an algorithm service update private key; When the algorithm engine detects the algorithm service update parameters, set the corresponding algorithm service to an unusable state until the algorithm service instance loads and executes all the algorithm logic, and update the original image release instance according to the algorithm service update parameters to obtain a new image release instance, completing the algorithm service update.

7. The configuration method of an algorithm engine library according to claim 1, characterized in that The method further includes: querying relevant log information in the algorithm engine according to the request ID and the preset algorithm index information, where the log information includes the request ID; wherein, the algorithm index information includes an algorithm query date, an algorithm service name, and an algorithm application name.

8. A configuration system for an algorithm engine library, characterized in that The system includes: A preliminary encryption module, configured to encrypt the algorithm call request generated by the client with the public key assigned by the algorithm engine to obtain call encrypted request data, and send the call encrypted request data to the algorithm engine; A first authentication module, configured to assign a unique request ID to the call encrypted request data by the algorithm engine, and detect the legality of the algorithm path accessed by the client. If the algorithm path is legal, perform the first authentication according to the call encrypted request data and obtain encrypted request parsed data; The secondary encryption module is used to, when the first authentication is passed, the algorithm engine sequentially detects the allocation quota of the algorithm service in the algorithm application and the online status of the algorithm service in the encrypted request data to be called, and encrypts the encrypted request parsing data to obtain secondary encrypted request data when the allocation quota is not used up and the algorithm service is in an online state; The second authentication module is used to generate encrypted request update data according to the secondary encrypted request data and the request ID, and send the encrypted request update data to the algorithm service instance; it is also used for the algorithm service instance to perform a second authentication according to the encrypted request update data and obtain encrypted request update parsing data; The algorithm operation module is used to, after the second authentication is passed, the algorithm service instance executes algorithm logic according to the encrypted request update parsing data to obtain operation result data, and feeds back the operation result data to the client.

9. A computer device, characterized in that: It includes a processor and a memory, the processor is connected to the memory, the memory is used to store a computer program, and the processor is used to execute the computer program stored in the memory so that the computer device executes the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: A computer program is stored in the computer-readable storage medium, and when the computer program is run, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Remote two-way access control system and method based on trusted computing

    CN106789059A

  • GNSS positioning service-oriented fault treatment system and method

    CN111143097A