A JWT-based access control method and system for large model knowledge bases

By combining JWT and MySQL databases, precise access control and security management of the large-model knowledge base is achieved, which solves the complexity and insufficient security of identity authentication and access control in the existing technology, and improves user experience and system security.

CN117972787BActive Publication Date: 2025-07-11XINGZHI INTELLIGENT (BEIJING) TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410203711.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-02-23
Publication Date
2025-07-11
Estimated Expiration
2044-02-23

AI Technical Summary

Technical Problem

Prior Art In large AI models deployed offline, authentication and access control methods have complexity, insufficient security, and lack of flexibility and granular control, especially in OAuth, OpenID Connect, API key authentication, and non-JWT authentication.

Method used

JSON Web Token (JWT) is used to combine it with MySQL database, and user authentication and permission management are performed through JWT, ensuring that only authorized users can access the big model knowledge base, and permission query and management are performed in combination with MySQL database.

Benefits of technology

It realizes accurate management of access rights of the big model knowledge base, ensures the security of user identity information, prevents unauthorized data access, improves the efficiency and security of access control, reduces user waiting time, and enhances the system's defense ability against emerging security threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117972787B_ABST
    Figure CN117972787B_ABST
Patent Text Reader

Abstract

The present invention provides a JWT-based large model knowledge base access control method and system, which relates to the field of computer security technology, including: a user sends a login request to a front-end application, and the front-end application sends the login information to a back-end server; the back-end server interacts with a MySQL database to verify the login information, generates a JWT and sends it to the user for storage; the user initiates a large model knowledge base access request to the front-end application, and the access request carries the JWT; the back-end server verifies the JWT, and if it is valid, the user's authority is judged through the MySQL database; if the user has the authority of the requested knowledge base, the back-end server processes the access request, the large model knowledge base answers, the large model knowledge base returns the answer to the back-end server, the back-end server forwards the answer of the large model knowledge base to the front-end application, and the front-end application displays the answer to the user. The present invention realizes that only authorized users can access the corresponding knowledge base and ask questions to the large model service.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer security technology, and more particularly to a method and system for access control of a large model knowledge base based on JWT. Background Art

[0002] In today's digital age, the application of artificial intelligence (AI) has made great progress in various fields. Question answering systems are an important application in the field of natural language processing (NLP), which aims to enable computers to understand and answer natural language questions posed by users. In recent years, AI question answering systems have been widely used in fields such as search engines, virtual assistants, customer support, and knowledge base management.

[0003] With the continuous development and increasing scale of AI models, the offline deployment of large AI models has become increasingly common. These large models can provide more accurate and natural answers, but they also need to process sensitive information and classified data, so security and authentication have become crucial. In the offline deployment of large AI models, ensuring that only authorized users can access the corresponding knowledge base and call the model to ask questions is a challenging task.

[0004] Currently, in terms of authentication and access control of offline-deployed AI large models, there are some common technologies and methods, but they are also accompanied by some problems, especially in the application of artificial intelligence. For example: (1) OAuth and OpenID Connect, working principle: OAuth and OpenID Connect are open standards for single sign-on and authorization. Users can use a third-party identity provider for authentication. Existing problems: Although OAuth and OpenID Connect provide a certain level of security, their implementation in offline-deployed AI large models becomes complex, requires adaptation, and is not designed specifically for this purpose. (2) API key-based authentication, working principle: Users obtain an API key to access protected resources. Existing problems: The management and distribution of API keys are not secure enough, vulnerable to malicious attacks and key leakage threats, and lack flexibility and fine-grained control in user authentication. (3) Non-JWT authentication, working principle: Use a custom token or authentication scheme instead of JWT. Existing problems: Non-JWT authentication methods lack standardization and widespread adoption, so the interoperability between different applications and services is limited. In addition, non-JWT authentication is not sufficient to provide advanced security features such as token expiration and claim-based authorization.

[0005] Another common method for protecting confidential interfaces is JSON Web Token (JWT), which is a compact, self-contained security token used to verify the identity of the user. However, in large AI models deployed offline, it is often necessary to manage user identity permissions and isolate plug-ins and knowledge bases in the system, which requires deeper integration and customization to ensure security and performance.

[0006] Therefore, how to provide a more efficient, secure, and suitable authentication and access control method for large AI models has become an urgent problem to be solved. Summary of the invention

[0007] In response to the above problems, the present invention provides a JWT-based large model knowledge base access control method and system, which innovatively integrates JSON Web Token (JWT) into the offline deployed AI large model to achieve better user identity authentication and access control.

[0008] To achieve the above object, the present invention provides a large model knowledge base access control method based on JWT, comprising:

[0009] The user sends a login request including credential information to the front-end application, and the front-end application sends the credential information to the back-end server;

[0010] The backend server interacts with the MySQL database to verify the credential information, generates a JWT based on the verification result and sends it to the user for storage, including the encrypted user identity information;

[0011] The user initiates a large model knowledge base access request to the front-end application, and the access request carries the JWT;

[0012] The backend server accepts and verifies the JWT. If the JWT is valid, the backend server determines whether the user has the permission to access the requested knowledge base through the MySQL database.

[0013] If the user has permission to the requested knowledge base, the back-end server processes the access request and requests the large model knowledge base to respond. The large model knowledge base returns the response to the back-end server. The back-end server forwards the response from the large model knowledge base to the front-end application, and the front-end application displays the response to the user.

[0014] As a further improvement of the present invention, if the user does not have the authority to access the requested knowledge base, the back-end server returns a no-authorization response to the front-end application, and the front-end application displays no-authorization information to the user.

[0015] As a further improvement of the present invention, if the JWT is invalid, the backend server returns an authentication failure to the frontend application, and the frontend application displays a re-login prompt message to the user.

[0016] As a further improvement of the present invention, the situations where the JWT is invalid include expiration and being tampered with;

[0017] The frontend application displays a re-login prompt message to the user to guide the user to obtain a new JWT.

[0018] As a further improvement of the present invention, the credential information includes a username and a password.

[0019] As a further improvement of the present invention, the user identity information includes a user ID.

[0020] As a further improvement of the present invention, generating a JWT according to the verification result and sending it to the user for saving includes:

[0021] The backend server sends the JWT to the frontend application, and the frontend application passes the JWT to the user and guides the user to store the JWT in a secure location.

[0022] As a further improvement of the present invention, the backend server accepts and verifies the JWT. If the JWT is valid, it determines whether the user has the permission to access the requested knowledge base through the MySQL database; including:

[0023] The backend server first parses the JWT and then verifies the validity of the JWT;

[0024] If the JWT is valid, the backend server interacts with the MySQL database to query the user's permission information;

[0025] Based on the permission information, it checks whether the user has the right to access the requested knowledge base.

[0026] As a further improvement of the present invention, the MySQL database manages and stores the permission information of each user.

[0027] The present invention also provides a large model knowledge base access control system based on JWT, including: a user login module, a JWT generation module, a large model knowledge base request access module, a JWT and permission verification module, and a large model knowledge base response module;

[0028] The user login module is used for:

[0029] The user sends a login request to the frontend application, including credential information, and the frontend application sends the credential information to the backend server;

[0030] The JWT generation module is used to:

[0031] The backend server interacts with the MySQL database to verify the credential information, generates a JWT based on the verification result and sends it to the user for storage, including the encrypted user identity information;

[0032] The large model knowledge base request access module is used to:

[0033] The user initiates a large model knowledge base access request to the front-end application, and the access request carries the JWT;

[0034] The JWT and permission verification module is used to:

[0035] The backend server accepts and verifies the JWT. If the JWT is valid, the backend server determines whether the user has the permission to access the requested knowledge base through the MySQL database.

[0036] The large model knowledge base response module is used to:

[0037] If the user has permission to the requested knowledge base, the back-end server processes the access request and requests the large model knowledge base to respond. The large model knowledge base returns the response to the back-end server. The back-end server forwards the response from the large model knowledge base to the front-end application, and the front-end application displays the response to the user.

[0038] Compared with the prior art, the present invention has the following beneficial effects:

[0039] The present invention is based on the combination of JSON Web Token (JWT) and MySQL database, and realizes the precise management of access rights to the large model knowledge base. Specifically, by using JWT for identity authentication, it can ensure that only verified users can access the large model knowledge base. At the same time, the encryption feature of JWT protects user identity information from leakage and prevents unauthorized data access. In combination with MySQL database, access to a specific knowledge base can be controlled according to the different roles and permissions of users. At the same time, JWT is obtained at login to ensure that the identity authentication and permission query process during access requests are fast and efficient, thereby reducing user waiting time and improving user experience.

[0040] The present invention has significant advantages in protecting user privacy and security. The introduction of JWT provides a safe and efficient verification method for accessing the large model knowledge base, enhancing the defense capability of the large model knowledge base against emerging security threats. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] Figure 1Schematic diagram of the access control process for a large model knowledge base based on JWT disclosed in an embodiment of the present invention;

[0042] Figure 2 Schematic diagram of the access control system for a large model knowledge base based on JWT disclosed in an embodiment of the present invention. Detailed implementation manners

[0043] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0044] The present invention will be further described in detail below with reference to the accompanying drawings:

[0045] As Figure 1 shown, a method for access control of a large model knowledge base based on JWT provided by the present invention includes the steps:

[0046] S1. The user sends a login request to the front-end application, including credential information, and the front-end application sends the credential information to the back-end server;

[0047] Among them,

[0048] The credential information includes the username and password.

[0049] S2. The back-end server interacts with the MySQL database to verify the credential information, generates a JWT according to the verification result, and sends it to the user for saving. The JWT includes the encrypted user identity information;

[0050] Among them,

[0051] The user identity information includes the user ID;

[0052] The encrypted user identity information can ensure the security of the user identity information.

[0053] Further,

[0054] After successfully generating the JWT, the back-end server sends the JWT to the front-end application. The front-end application passes the JWT to the user and instructs the user to store the JWT in a secure location, such as an HTTP Only Cookie or the local storage of the browser. This process ensures the security verification of the user identity and establishes a basis for the subsequent permission verification process.

[0055] S3. The user initiates a large model knowledge base access request to the front-end application, and the access request carries JWT;

[0056] in,

[0057] When users try to access protected resources or large model knowledge bases, they need to initiate a request through the front-end application; during this process, the user's request will carry the previously stored JWT as a credential for identity and permissions.

[0058] S4. The backend server accepts and verifies the JWT. If the JWT is valid, the MySQL database is used to determine whether the user has the permission to access the requested knowledge base.

[0059] in,

[0060] After receiving this request, the backend server needs to confirm the validity of the user's identity and whether it is authorized.

[0061] First, parse the JWT and then verify the validity of the JWT;

[0062] If the JWT is valid, the backend server interacts with the MySQL database to query the user's permission information;

[0063] Based on the permission information, check whether the user has the right to access the requested knowledge base.

[0064] Furthermore,

[0065] If the JWT is invalid, the backend server returns an authentication failure to the frontend application, and the frontend application displays a re-login prompt to the user.

[0066] Furthermore,

[0067] Invalid situations of JWT include expiration and tampering;

[0068] The front-end application displays a re-login prompt to the user to guide the user to obtain a new JWT.

[0069] Specifically,

[0070] This step is the core of the present invention, and involves the logic of identity authentication and authority management, ensuring that only users with corresponding authority can access specific large model knowledge bases or data.

[0071] S5. If the user has permission to the requested knowledge base, the back-end server processes the access request and requests the large model knowledge base to respond. The large model knowledge base returns the response to the back-end server. The back-end server forwards the response from the large model knowledge base to the front-end application, and the front-end application displays the response to the user.

[0072] in,

[0073] If the user does not have permission to access the requested knowledge base, the backend server returns an error or unauthorized response to the frontend application. After receiving such a response, the frontend application displays error or unauthorized information to the user, such as "No permission to access" or "Authentication failed", and may require the user to log in again to obtain a new JWT.

[0074] This step ensures the security and proper access control of resources and data in the large model knowledge base to prevent unauthorized access.

[0075] In the present invention, the MySQL database manages and stores the permission information of each user in a fine-grained manner. The system administrator can easily manage user permissions, including adding, modifying and deleting permissions. This centralized permission management simplifies the maintenance and management of the system. It also means that the system can control access to specific knowledge bases in a large model based on the different roles and permissions of users. This permission management mechanism is highly flexible and configurable, and is applicable to a variety of scenarios.

[0076] like Figure 2 As shown, the present invention also provides a large model knowledge base access control system based on JWT, including: a user login module, a JWT generation module, a large model knowledge base request access module, a JWT and authority verification module, and a large model knowledge base response module;

[0077] User login module, used for:

[0078] The user sends a login request including credential information to the front-end application, and the front-end application sends the credential information to the back-end server;

[0079] JWT generation module, used for:

[0080] The backend server interacts with the MySQL database to verify the credential information, generates a JWT based on the verification result and sends it to the user for storage, including the encrypted user identity information;

[0081] Large model knowledge base request access module, used for:

[0082] The user initiates a request to the front-end application to access the large model knowledge base, and the access request carries JWT;

[0083] JWT and permission verification module, used for:

[0084] The backend server accepts and verifies the JWT. If the JWT is valid, it checks the MySQL database to determine whether the user has the permissions for the requested knowledge base.

[0085] Large model knowledge base response module for:

[0086] If the user has the permission to access the requested knowledge base, the backend server processes the access request, requests the large model knowledge base to answer, the large model knowledge base returns the answer to the backend server, the backend server forwards the answer of the large model knowledge base to the front-end application, and the front-end application displays the answer to the user.

[0087] The technical solution of the present invention allows for flexible deployment in different application scenarios and environments. At the same time, due to its modular design, the system functions can be easily expanded as needed, including adding new knowledge bases, updating verification mechanisms, etc.

[0088] Advantages of the present invention:

[0089] The present invention is based on the combination of JSON Web Token (JWT) and MySQL database, realizing precise management of the access permissions to the large model knowledge base. Specifically, by using JWT for identity authentication, it can be ensured that only authenticated users can access the large model knowledge base. At the same time, the encryption feature of JWT protects the user identity information from being leaked and prevents unauthorized data access. Combined with the MySQL database, the access to specific knowledge bases can be controlled according to the different roles and permissions of users. At the same time, JWT is obtained during login to ensure that the identity authentication and permission query processes during access requests are fast and efficient, thus reducing the user waiting time and improving the user experience.

[0090] The present invention realizes the secure access and management of the large model knowledge base, and has significant advantages in protecting user privacy and security. The introduction of JWT provides a secure and efficient verification method for accessing the large model knowledge base, enhancing the defense ability of the large model knowledge base against emerging security threats.

[0091] The present invention uses JWT as the medium for user identity authentication and permission transfer, and this method has significant advantages in protecting user privacy and security. The introduction of JWT provides a secure and efficient verification method for accessing the large model knowledge base. The use of the MySQL database realizes fine-grained control of user permissions, including access permissions to specific knowledge bases. This method makes the permission management more flexible and configurable. Directly associating the user's permissions with the access permissions of specific knowledge bases ensures that only authorized users can access the corresponding large model knowledge base. In short, using JWT and MySQL database for identity authentication and permission control is a practice that conforms to modern security standards, which not only improves the overall security of the system but also increases the system's defense ability against emerging security threats.

[0092] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A JWT-based access control method for large model knowledge bases, characterized in that, include: The user sends a login request including credential information to the front-end application, and the front-end application sends the credential information to the back-end server; The backend server interacts with the MySQL database to verify the credential information, generates a JWT based on the verification result and sends it to the user for storage, including the encrypted user identity information, wherein the backend server sends the JWT to the frontend application, and the frontend application passes the JWT to the user and instructs the user to store the JWT in a safe location; The user initiates a large model knowledge base access request to the front-end application, and the access request carries the JWT; The backend server accepts and verifies the JWT. If the JWT is valid, the MySQL database is used to determine whether the user has the permission to access the requested knowledge base. The backend server first parses the JWT and then verifies the validity of the JWT. If the JWT is valid, the backend server interacts with the MySQL database to query the user's permission information. Based on the permission information, the backend server checks whether the user has the right to access the requested knowledge base. The MySQL database performs fine-grained management and storage of each user's permission information, including the addition, modification, and deletion of permissions. The MySQL database controls access to specific knowledge bases based on different user roles and permissions; If the JWT is invalid, the backend server returns an identity authentication failure to the frontend application, and the frontend application displays a re-login prompt to the user to guide the user to obtain a new JWT; If the user has the permission of the requested knowledge base, the back-end server processes the access request and requests the large model knowledge base to answer. The large model knowledge base returns the answer to the back-end server. The back-end server forwards the answer of the large model knowledge base to the front-end application, and the front-end application displays the answer to the user. If the user does not have the permission to access the requested knowledge base, the backend server returns an error or unauthorized response to the frontend application. After receiving the error or unauthorized response, the frontend application displays the error or unauthorized information to the user and requires the user to log in again to obtain a new JWT. The JWT-based large model knowledge base access control method is applied to the AI ​​large model deployed offline.

2. The JWT-based large model knowledge base access control method according to claim 1, wherein: The invalid situations of the JWT include expiration and tampering; The front-end application displays a re-login prompt message to the user to guide the user to obtain a new JWT.

3. The access control method for the large model knowledge base based on JWT according to claim 1, wherein: The credential information includes a username and a password.

4. The JWT-based large model knowledge base access control method according to claim 1, wherein: The user identity information includes a user ID.

5. A large model knowledge base access control system based on JWT, which implements the JWT-based large model knowledge base access control method of the method described in any one of claims 1 to 4, characterized in that include: User login module, JWT generation module, large model knowledge base request access module, JWT and authority verification module, large model knowledge base response module; The user login module is used to: The user sends a login request including credential information to the front-end application, and the front-end application sends the credential information to the back-end server; The JWT generation module is used to: The backend server interacts with the MySQL database to verify the credential information, generates a JWT based on the verification result and sends it to the user for storage, including the encrypted user identity information; The large model knowledge base request access module is used to: The user initiates a large model knowledge base access request to the front-end application, and the access request carries the JWT; The JWT and permission verification module is used to: The backend server accepts and verifies the JWT. If the JWT is valid, the backend server determines whether the user has the permission to access the requested knowledge base through the MySQL database. The large model knowledge base response module is used to: If the user has permission to the requested knowledge base, the back-end server processes the access request and requests the large model knowledge base to respond. The large model knowledge base returns the response to the back-end server. The back-end server forwards the response from the large model knowledge base to the front-end application, and the front-end application displays the response to the user.

Citation Information

Patent Citations

  • Question and answer data processing method and equipment

    CN117131237A

  • Traffic information intelligent management system

    CN117198046A