Model invocation configuration method, medium, device and product for large model security
Patent Information
- Application Number
- CN202411017808.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-26
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2044-07-26
AI Technical Summary
相关技术中,该授权过程通常需要用户在平台外获取,并在代码里面手动填入,并且可能会涉及多次跳转并需要用户多次手动填入,不便于用户操作使用
[0009]通过上述技术方案,不同授权模式对应有不同的授权界面,以便于用户能够基于该不同的授权界面实现对不同授权模式的感知,为其选择合适的授权模式提供参考,加快对授权模式的决策效率。并且在进行目标模型调用的授权过程中,可以通过在授权码界面中的选择和配置而直接生成目标授权命令,则用户仅需要对授权码进行选择便可以生成完整的目标授权命令,则后续对目标授权指令的使用过程中用户仅需进行一次复制,便可以在模型配置环境中进行配置,无需进行多次页面跳转以及多次复制粘贴等操作,节省用户操作,并且该过程中为用户展示目标授权模式对应的授权命令,并基于可视化的流程将用户对候选授权码进行选择而生成目标授权命令进行展示,从而可以对用户配置目标授权命令进行明确的流程化引导,有效降低用户对配置操作的理解成本,降低目标模型调用的授权配置对用户的技能要求,提升用户使用体验。
Smart Images

Figure CN118643488B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of computer technology, and more specifically, to a model invocation configuration method, medium, device, and product for large model security. Background Technology
[0002] With the development of large model technology, its applications are increasing. Large model service platforms can integrate various large models, catering to individuals and enterprises by providing functions and services such as fine-tuning, evaluation, and inference. To ensure the security of model calls, authorization verification is usually required. In related technologies, this authorization process typically requires users to obtain the authorization outside the platform and manually enter it into the code, potentially involving multiple redirects and manual input, which is inconvenient for users. Summary of the Invention
[0003] This summary section is provided to briefly introduce the concepts, which will be described in detail in the subsequent detailed description section. This summary section is not intended to identify key or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.
[0004] Firstly, this disclosure provides a model invocation configuration method for large model security, the method comprising: In response to determining the target model and calling the corresponding target authorization mode, the authorization interface corresponding to the target authorization mode is displayed, wherein the authorization interface displays authorization code operation controls; In response to the selection of the authorization code operation control, an authorization code interface is displayed, wherein the authorization code interface is used to display the corresponding authorization command and candidate authorization codes for the target model to invoke; In response to the user's selection of a candidate authorization code, a target authorization command corresponding to the target model call is generated based on the selected candidate authorization code and the authorization command. The target authorization command is used to verify the permission for the target model call.
[0005] Secondly, this disclosure provides a model invocation configuration device for large model security, the device comprising: The first display module is used to respond to the determination of the target model and call the corresponding target authorization mode, and to display the authorization interface corresponding to the target authorization mode, wherein the authorization interface displays the authorization code operation control; The second display module is used to display the authorization code interface in response to the selection of the authorization code operation control, wherein the authorization code interface is used to display the corresponding authorization command and candidate authorization codes for the target model to call; The generation module is used to respond to the user's selection of a candidate authorization code, and generate a target authorization command corresponding to the target model call based on the selected candidate authorization code and the authorization command. The target authorization command is used to verify the permission of the target model call.
[0006] Thirdly, this disclosure provides a computer-readable medium having a computer program stored thereon, which, when executed by a processing device, implements the steps of the method described in the first aspect.
[0007] Fourthly, this disclosure provides an electronic device, comprising: A storage device on which computer programs are stored; A processing device for executing the computer program in the storage device to implement the steps of the method described in the first aspect.
[0008] Fifthly, this disclosure provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the method described in the first aspect.
[0009] Through the above technical solution, different authorization modes correspond to different authorization interfaces, enabling users to perceive different authorization modes based on these interfaces, providing a reference for selecting the appropriate authorization mode, and accelerating the decision-making efficiency of authorization mode. Furthermore, during the authorization process for calling the target model, the target authorization command can be directly generated through selection and configuration in the authorization code interface. Users only need to select the authorization code to generate the complete target authorization command. Subsequently, in the use of the target authorization command, users only need to copy it once and configure it in the model configuration environment, eliminating the need for multiple page jumps and multiple copy-paste operations, saving user operations. This process also displays the authorization command corresponding to the target authorization mode to the user, and shows the user's selection of candidate authorization codes and the generation of the target authorization command based on a visual flow. This provides clear and streamlined guidance for users to configure the target authorization command, effectively reducing the understanding cost of configuration operations, lowering the skill requirements for users in configuring the target model call authorization, and improving the user experience.
[0010] Other features and advantages of this disclosure will be described in detail in the following detailed description section. Attached Figure Description
[0011] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the originals and elements are not necessarily drawn to scale. In the drawings: Figure 1This is a flowchart of a model invocation configuration method for large model security provided according to one embodiment of the present disclosure.
[0012] Figure 2 This is a schematic diagram of an authorized interface provided according to one embodiment of the present disclosure.
[0013] Figure 3 This is a schematic diagram of an authorization code interface provided according to one embodiment of the present disclosure.
[0014] Figures 4A-4C This is a schematic diagram of an authorization code interface provided according to another embodiment of the present disclosure.
[0015] Figure 5 This is a schematic diagram of an authorization code creation interface provided according to one embodiment of the present disclosure.
[0016] Figure 6 This is a schematic diagram of an authorized interface provided according to another embodiment of the present disclosure.
[0017] Figure 7 This is a block diagram of a model invocation configuration apparatus for large model security provided according to one embodiment of the present disclosure.
[0018] Figure 8 A schematic diagram of the structure of an electronic device suitable for implementing embodiments of the present disclosure is shown. Detailed Implementation
[0019] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.
[0020] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.
[0021] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below.
[0022] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.
[0023] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".
[0024] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.
[0025] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in this disclosure in an appropriate manner in accordance with relevant laws and regulations, and user authorization should be obtained.
[0026] For example, upon receiving a user's active request, a prompt message is sent to the user to explicitly inform them that the requested operation will require the acquisition and use of the user's personal information. This allows the user to independently choose whether to provide personal information to the software or hardware, such as the electronic device, application, server, or storage medium performing the operations of this disclosed technical solution, based on the prompt message.
[0027] As an optional but non-limiting implementation, in response to a user's active request, sending a prompt message to the user can be done via a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide personal information to the electronic device.
[0028] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.
[0029] Meanwhile, it is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) shall comply with the requirements of relevant laws, regulations and related provisions.
[0030] As described in the background section, the applicant's research has found that in related technologies, authorization verification typically requires users to obtain authorization instructions from the authorization service of a large model service platform, copy and paste them into the model configuration environment, and then obtain the authorization code from the authorization code management service of the large model service platform again, copying and pasting the authorization code into the model configuration environment. This process involves users switching interfaces multiple times and manually concatenating the instructions, making the operation cumbersome. Based on this, the present disclosure provides the following embodiments.
[0031] Figure 1 The diagram shown is a flowchart of a model invocation configuration method for large model security provided according to one embodiment of this disclosure. Figure 1 As shown, the method may include: In step 11, in response to determining the target model and calling the corresponding target authorization mode, the authorization interface corresponding to the target authorization mode is displayed, wherein the authorization interface displays authorization code operation controls.
[0032] As an example, this method can be applied to large model service platforms to enable the invocation of large models within the platform. Specifically, when a user invokes a model on the platform, a corresponding inference access point can be created, which can be an API (Application Programming Interface). Users can then utilize the model through this inference access point.
[0033] Before a model is invoked, authorization verification is required. The authorization code serves as authentication proof for the inference access point, ensuring the compliance and security of the model invocation. Multiple authorization modes are available, configurable based on the specific application scenario, and displayed side-by-side in the authorization interface, allowing users to select their preferred authorization mode for verification. Figure 2 As shown, the authorization mode can include API key authorization mode and IAM (Identity and Access Management) authorization mode. Users can choose the appropriate authorization mode based on their usage needs. After the user makes a selection, the authorization interface corresponding to the target authorization mode can be displayed. In this embodiment, different authorization interfaces can be displayed to the user by selecting different authorization modes, so that the user can perceive the operation under different authorization modes and provide effective prompts and references for the user to select the desired authorization mode.
[0034] As an example, when a user triggers an authorization operation on the platform, an authorization interface can be displayed. During this process, a default authorization mode can be pre-set, which will be the default authorization mode if the user does not select a target authorization mode. For example, the default authorization mode can be set to API key authorization mode, and when the authorization operation is triggered, the authorization interface corresponding to this API key authorization mode can be displayed, such as... Figure 2 As shown, users can select an IAM authorization mode. In response to this selection, it can be determined that the target model calls the corresponding target authorization mode as IAM mode, and then the authorization interface corresponding to the IAM mode will be displayed.
[0035] The authorization interface displays an authorization code operation control, which prompts the user to select an authorization code. Figure 2 As shown at point 21. As an example, this authorization interface can also contain the authorization command corresponding to the target authorization model. The authorization code in this authorization command can be represented by its field identifier, such as... Figure 2 As shown at point 22 in the middle.
[0036] In step 12, in response to the selection of the authorization code operation control, the authorization code interface is displayed, wherein the authorization code interface is used to display the corresponding authorization command and candidate authorization codes for the target model to invoke.
[0037] Users can select an option by clicking the authorization code control, thereby triggering the authorization code interface. For example, the authorization code interface can be displayed on top of the authorization interface as a floating layer or pop-up, thus reducing page jumps during the authorization process, ensuring the continuity of the user's operation flow, making it clear to the user what the current operation is, reducing the user's understanding cost of the authorization operation, and improving authorization efficiency. For example, as... Figure 3 As shown in section 31, the authorization code interface can display the authorization command and candidate authorization codes. Similarly, the authorization code in the authorization command can be represented by its field identifier, such as... Figure 3 As shown in point 32.
[0038] In step 13, in response to the user's selection of a candidate authorization code, a target authorization command corresponding to the target model call is generated based on the selected candidate authorization code and the authorization command. The target authorization command is used to verify the permission for the target model call.
[0039] As an example, a user can select one of the candidate authorization codes to authorize an application. In this step, the selected candidate authorization code is automatically concatenated into the authorization command to obtain the complete target authorization command. Afterwards, the user can directly copy and paste this target authorization command into the model configuration environment so that permissions for calling the target model can be verified based on this target authorization command during the target model invocation process.
[0040] Therefore, through the above technical solution, different authorization modes correspond to different authorization interfaces, enabling users to perceive different authorization modes based on these interfaces, providing a reference for selecting the appropriate authorization mode, and accelerating the decision-making efficiency of authorization mode. Furthermore, during the authorization process for calling the target model, the target authorization command can be directly generated through selection and configuration in the authorization code interface. Users only need to select the authorization code to generate the complete target authorization command. Subsequently, in the use of the target authorization command, users only need to copy it once and configure it in the model configuration environment, eliminating the need for multiple page jumps and multiple copy-paste operations, saving user time. This process also displays the authorization command corresponding to the target authorization mode to the user, and shows the user's selection of candidate authorization codes and the generation of the target authorization command based on a visual process. This provides clear and streamlined guidance for users to configure the target authorization command, effectively reducing the understanding cost of configuration operations, lowering the skill requirements for users in configuring the target model call authorization, and improving the user experience.
[0041] In one possible embodiment, the interface for displaying the authorization code may include: The authorization command is displayed in the command area of the authorization code interface, wherein the authorization code in the authorization command is displayed as the field identifier corresponding to the authorization code; The authorization code area in the authorization code interface displays the identifier, encrypted authorization code, and operation identifier of each candidate authorization code.
[0042] like Figure 4A The diagram shows the authorization code interface. Command area 41 displays the authorization command, but the corresponding authorization code has not yet been determined. The authorization code in the authorization command can be displayed as its corresponding field identifier to prompt the user. Authorization code area 42 displays information related to candidate authorization codes. As an example, to ensure the security of candidate authorization codes, it can display the encrypted authorization code corresponding to that code. This encrypted code can be identified by the encrypted identifier "...". " is indicated as shown in 43.
[0043] As an example, the operation identifier could be a "view" identifier, allowing the user to view the plaintext of the candidate authorization code by clicking the "view" identifier. Afterward, the operation identifier could be updated to a "use" identifier, allowing the user to further select and use the authorization code for verification by clicking the "use" identifier. Alternatively, the operation identifier could be a "view and select" identifier (such as...). Figure 4A As shown in the image, users can click on the icon to view the candidate authorization code and directly select to use the authorization code for verification, further simplifying the user operation.
[0044] As an example, the candidate authorization code is determined in the following way: Obtain multiple authorization codes corresponding to the user. These multiple authorization codes may be all the authorization codes that the user possesses in the large model service platform, and can be obtained from the authorization code management service in the large model platform after obtaining user authorization.
[0045] Based on the permission information corresponding to the multiple authorization codes, the multiple authorization codes are filtered to obtain the candidate authorization codes, wherein the permission information includes usage permission information and / or usage time information.
[0046] As an example, if the permission information includes usage permission information, then an authorization code that matches the usage permission information with the permissions of the target model being called can be used as a candidate authorization code. As another example, if the permission information includes usage time information, then an authorization code whose usage time information includes the time of call to the target model can be used as a candidate authorization code. As yet another example, if the permission information includes both usage permission information and usage time information, then an authorization code whose usage permission information matches the permissions of the target model being called, and whose usage time information includes the time of call to the target model, can be used as a candidate authorization code.
[0047] Therefore, the above technical solution can filter multiple authorization codes of users and display the currently available and valid authorization codes in the authorization code interface, thereby ensuring the validity and accuracy of the subsequently generated target authorization commands and realizing the accurate invocation of the target model.
[0048] In one possible embodiment, the target authorization mode is an API key authorization mode, and the authorization command corresponding to the API key authorization mode includes an authorization field. For example, the authorization command corresponding to the API key authorization mode is represented as follows: export ARK_API_KEY="YOUR_API_KEY" In the model configuration environment, set the API Key as an environment variable. ARK_API_KEY is the authorization field, and YOUR_API_KEY is the field identifier corresponding to the authorization field. When generating the target authorization command, it needs to be replaced with the API Key created on the platform, i.e., the authorization code.
[0049] Accordingly, an exemplary implementation of generating a target model and invoking the corresponding target authorization command based on the selected candidate authorization code and the authorization command in response to the user's selection of a candidate authorization code may include: In response to receiving the user's selection of the operation identifier for the candidate authorization code, determine whether the user has authorization code operation permission.
[0050] To ensure the security of authorization codes, the encrypted authorization code is displayed on the authorization code interface, while the corresponding plaintext, i.e., the key value of the authorization code itself, is displayed to the user when they select an authorization code. Therefore, in this step, in response to receiving the user's selection of the operation identifier for a candidate authorization code, it is determined whether the user has authorization code operation permissions to verify the user's access operation. As an example, in response to receiving the user's selection of the operation identifier for a candidate authorization code, a permission verification pop-up window can be displayed. The user can enter an access password in the pop-up window. If the entered access password matches the access password in the user information, it is determined that the user has authorization code operation permissions; if the entered access password does not match the access password in the user information, it is determined that the user does not have authorization code operation permissions, and the user can be further prompted to re-enter the password for verification, so as to re-verify if the user fails verification due to an incorrect password.
[0051] Subsequently, after confirming that the user has authorization code operation permissions, the encrypted authorization code of the candidate authorization code selected in the authorization code area is updated to the plaintext authorization code.
[0052] In this example, the identifier for the candidate authorization code can be the name of the candidate authorization code. If it's determined that the user has authorization code operation permissions, it means that the user can view the authorization code itself. In this case, the encrypted authorization code of the selected candidate authorization code can be updated to plaintext authorization code in the authorization code area to display the specific content of the authorization code to the user. Figure 4B As shown.
[0053] Further, in the command area, the field identifier of the authorization field is updated to the plaintext of the authorization code to obtain the target authorization command.
[0054] In this step, the target authorization command can be obtained by concatenating the candidate authorization code selected by the user with the authorization command. As an example, the target authorization command is represented as follows: export ARK_API_KEY="123XXX" Therefore, the above technical solution can verify user permissions for authorization codes, ensuring access security. It can also automatically generate target authorization commands based on the user-selected authorization code, simplifying the authorization code acquisition process by eliminating the need for manual searching and command generation. This further simplifies the user's workflow and avoids potential errors during command generation, improving the accuracy of the target authorization command and supporting accurate subsequent model invocation. Furthermore, a visual flowchart allows users to clearly understand the target authorization command generation process, facilitating a quick understanding of the model invocation configuration process.
[0055] In one possible embodiment, the target authorization mode is an Identity and Access Management (IAM) authorization mode, and the authorization command corresponding to the IAM authorization mode contains multiple authorization fields. As an example, the authorization command corresponding to this IAM authorization mode is represented as follows: export VOLC_ACCESSKEY="YOUR_AK" export VOLC_SECRETKEY="YOUR_SK" In the model configuration environment, set ACCESSKEY and SECRETKEY as environment variables. VOLC_ACCESSKEY and VOLC_SECRETKEY represent the authorization fields in the authorization command. YOUR_AK is the field identifier corresponding to the authorization field VOLC_ACCESSKEY, and YOUR_SK is the field identifier corresponding to the authorization field VOLC_SECRETKEY. When generating the target authorization command, these need to be replaced with the authorization code created on the platform.
[0056] Accordingly, the step of responding to the user's selection of a candidate authorization code, generating a target model based on the selected candidate authorization code and the authorization command to invoke the corresponding target authorization command, includes: In response to receiving the user's selection of the operation identifier for the candidate authorization code, determine whether the user has authorization code operation permission; If it is determined that the user has authorization code operation permissions, the encrypted authorization code of the candidate authorization code selected in the authorization code area is updated to the plaintext authorization code.
[0057] In this embodiment, ACCESSKEY and SECRETKEY are typically created and used in pairs. They can be created using methods commonly used in the art, and this disclosure does not limit this. ACCESSKEY can usually be included in the transmission, while SECRETKEY needs to be securely stored to prevent leakage. Therefore, in this embodiment, ACCESSKEY can serve as an identifier for the candidate authorization code, displayed in plaintext in the authorization code interface, while SECRETKEY can serve as the candidate authorization code itself, displayed in encrypted form in the authorization code interface. Once it is determined that the user has the authorization code operation permission, the encrypted authorization code is updated to plaintext. Figure 4C As shown. The specific implementation of the above steps is similar to that described above and will not be repeated here.
[0058] Based on the authorization fields in the command area, determine the field value corresponding to each authorization field from the authorization information of the selected candidate authorization code, and update the field identifier of each authorization field in the authorization command to the field value corresponding to that authorization field to obtain the target authorization command.
[0059] like Figure 4C As shown in Figure 44, if the selected authorization code is as shown in Figure 44, then in this step, for the authorization fields VOLC_ACCESSKEY and VOLC_SECRETKEY, the field values of VOLC_ACCESSKEY and VOLC_SECRETKEY can be determined from the authorization information of authorization code 44. Specifically, the field value of VOLC_ACCESSKEY determined from the authorization information is XXX111, and the field value of VOLC_SECRETKEY is XXX222. These field values can then be concatenated into the authorization command to obtain the target authorization command as follows: export VOLC_ACCESSKEY="XXX111" export VOLC_SECRETKEY="XXX222" Therefore, the above technical solution can verify user permissions for authorization codes, ensuring access security. It can also automatically generate target authorization commands based on the user-selected authorization code, eliminating the need for manual code retrieval from the authorization code service and simplifying the user's workflow. Furthermore, it eliminates the need for manual command generation, improving accuracy and preventing potential errors during command generation, thus supporting accurate model invocation. When the authorization command contains multiple authorization fields, users don't need to configure values for each field; the values are automatically determined based on a single authorization code selection, further simplifying the user process. Additionally, a visual flowchart clearly illustrates the command generation process, allowing users to quickly understand the model invocation configuration flow.
[0060] As an example, the authorization code interface can also include the creation time corresponding to the candidate authorization codes, so that users can select the authorization code they need based on the creation time, providing users with multi-dimensional information for selecting authorization codes.
[0061] In one possible embodiment, the method may further include: The command area displays prompt information and command operation identifiers corresponding to the target authorization command. The prompt information is used to provide operation flow information for the target authorization command, and the command operation identifiers are used to perform target operations on the target authorization command.
[0062] The target authorization command is typically used for authorization verification as an environment variable in the model configuration environment during copy-paste. Therefore, the command operation identifier can be a copy identifier. Users can copy the target authorization command (i.e., the target operation) by clicking the copy identifier, and then switch to the model configuration environment to paste it and configure the environment variable. To further clarify the user's understanding of the target authorization command configuration process, prompts can be provided in the authorization interface, such as "The system has automatically filled the selected authorization code into the following authorization command code. You can directly copy and paste the value to use in your local configuration environment." This prompt helps users further understand the required configuration process, improving the guidance and direction of the model call configuration process, thereby improving the accuracy and effectiveness of model call configuration and avoiding configuration errors to some extent.
[0063] In one possible embodiment, the authorization code interface may further include an authorization code creation control for real-time creation of authorization codes. Accordingly, the method may further include: In response to the user's selection of the authorization code creation control, the authorization code creation interface is displayed.
[0064] Among them, such as Figure 4A As shown, users can click the authorization code creation control 45 to create an authorization code. In response to this selection, the authorization code creation interface is displayed. As an example, this authorization code creation interface can redirect to the authorization code management interface within the large model service platform. Users can display the authorization code creation interface by clicking the create authorization code control. This authorization code creation interface can be displayed as a pop-up window, such as... Figure 5 As shown, users can configure the authorization code creation interface to create new authorization codes.
[0065] In response to the user's configuration operation on the authorization code creation interface, an authorization code is generated and the authorization code interface is displayed, which contains the generated authorization code.
[0066] The pop-up window can randomly generate a name for the authorization code, and the user can select the permissions for that authorization code based on their needs, thus configuring the permissions. After clicking "OK" to complete the configuration, the platform can generate and store the authorization code corresponding to that name and permissions. Afterwards, the user can be redirected to the authorization code interface to view the newly generated authorization code for selection.
[0067] Therefore, the above technical solution can support users in creating new authorization codes and displaying them synchronously on the authorization code interface, thereby meeting users' needs for using new authorization codes, further simplifying the operation process, and improving the user experience.
[0068] In one possible embodiment, the authorization code operation control is displayed in the authorization area of the authorization interface, which also includes sample code for calling the target model, and the target model is called based on the sample code.
[0069] Accordingly, the authorization interface displaying the target authorization mode may include: The first area of the authorization interface displays labels for different types of Software Development Kits (SDKs) side by side, with different sample code for each type of SDK.
[0070] The SDK type can include platform-in-house models and third-party models. The example code differs depending on the model being called, and the corresponding type is unique for a given target model. Therefore, the steps can display labels for different types of SDKs side-by-side, such as... Figure 6As shown, this display method prompts users to choose one of the options, avoiding the situation where novice users configure the sample code of each SDK separately, which may lead to model call failure.
[0071] The target example code corresponding to the target label determined in the first area is displayed in the second area of the authorization interface, wherein the authorization area, the first area, and the second area are displayed in the order from top to bottom in the authorization interface.
[0072] In this embodiment, different types of SDK labels are displayed in the first area, and sample code is shown in the second area, thus allowing the user to see a target sample code for one type of SDK. Figure 6 The diagram shows the authorization interface. The authorization area 61, the first area 62, and the second area 63 are displayed from top to bottom in the authorization interface. If the platform SDK tag is selected in the first area 62, the target sample code corresponding to the platform SDK tag will be displayed in the second area 63.
[0073] Therefore, through the above technical solution, the configuration process of model invocation can be guided in the authorization interface based on the display order, so that users can clearly understand the process steps of model invocation configuration. Furthermore, by displaying the corresponding sample code when selecting the SDK type in the authorization interface, the operation items can be highlighted and the clarity of the process guidance can be improved. This avoids redundant information when displaying sample code for each type of SDK to users, and to a certain extent prompts users to choose the sample code, thereby improving the efficiency and accuracy of user operations.
[0074] In one possible embodiment, the first area further includes a code type control corresponding to the example code. In real-world application scenarios, the code type corresponding to the user's model invocation environment may differ; therefore, this embodiment can set different example codes for different code types. As an example, the code type can be represented by a tab. As another example, the code type control can be represented by a drop-down menu, such as... Figure 6 As shown at position 64. Users can click this dropdown menu to select their desired code type.
[0075] Accordingly, displaying the target example code corresponding to the target label determined in the first area in the second area of the authorization interface may include: The second area of the authorization interface displays the target label identified in the first area and the target sample code corresponding to the target code type under the code type control.
[0076] When determining the target code type for the code type control, the user-selected code type will be used if they make a choice, otherwise the default code type will be used. For example, if the target label is "Platform SDK" and the target code type is "python", then sample code for calling the "Platform SDK" under the "python" type can be displayed in the second area.
[0077] In practical application scenarios, the target code type required by the user is usually unique. Therefore, in this embodiment, a code type control is set so that the user can select the code type they need. This allows only the target sample code required by the user to be displayed in the second area, thereby effectively reducing redundant information in the authorization interface and enabling the user to quickly obtain the information and guidance they need, making it convenient for new users.
[0078] In one possible embodiment, the example code includes development code and command configuration code corresponding to the target model. The command configuration code is used for tool installation and management, and the development code is used to implement the development process of calling the model. In this case, the development code and command configuration code need to be pasted into different locations in the model call configuration.
[0079] Accordingly, displaying the target example code corresponding to the target label determined in the first area in the second area of the authorization interface may include: The command configuration code and the copy identifier corresponding to the command configuration code are displayed in the command configuration area of the second region. The development configuration area in the second region displays the development code and the copy identifier corresponding to the development code.
[0080] like Figure 6 As shown, in the second area, development code and command configuration code can be displayed in different areas. For example, command configuration area 631 displays the command configuration code and its corresponding copy identifier 632, while development configuration area 633 displays the development code and its corresponding copy identifier 634. Users can then select and copy all the code displayed in that area by clicking the corresponding copy identifier.
[0081] Therefore, the above technical solution enables the segmented display of command configuration code and development code when showcasing target example code. This allows users to have a clearer understanding of each part of the example code, eliminating the need for users to manually split the example code. This improves the accuracy of using the target example code and reduces the skill requirements for model configuration.
[0082] As another example, prompt message 635 corresponding to the command configuration code can be displayed in the command configuration area, prompting the user to paste the copied command configuration code into the command configuration area of the model invocation environment to set up the pre-installed environment. Prompt message 636 corresponding to the development code can be displayed in the development configuration area, prompting the user to paste the copied development code into the local development environment of the model invocation environment to perform development.
[0083] Therefore, the above technical solution can provide prompts to users, enabling them to understand the usage specifications and configuration methods of each part of the code in the model call configuration process, providing clear and accurate configuration guidance, and improving the efficiency and accuracy of model configuration.
[0084] Based on the same inventive concept, this disclosure also provides a model invocation configuration device for large model security, such as... Figure 7 As shown, the device 10 includes: The first display module 101 is used to respond to the determination of the target model and call the corresponding target authorization mode, and to display the authorization interface corresponding to the target authorization mode, wherein the authorization interface displays the authorization code operation control; The second display module 102 is used to display an authorization code interface in response to the selection of the authorization code operation control, wherein the authorization code interface is used to display the corresponding authorization command and candidate authorization codes for the target model to call; The generation module 103 is used to respond to the user's selection of a candidate authorization code, and generate a target authorization command corresponding to the target model call based on the selected candidate authorization code and the authorization command. The target authorization command is used to verify the permission of the target model call.
[0085] Optionally, the second display module includes: The first display submodule is used to display the authorization command in the command area of the authorization code interface, wherein the authorization code in the authorization command is displayed as the field identifier corresponding to the authorization code; The second display submodule is used to display the identifier, encrypted authorization code, and operation identifier of each candidate authorization code in the authorization code area of the authorization code interface.
[0086] Optionally, the target authorization mode is an API key authorization mode, and the authorization command corresponding to the API key authorization mode contains an authorization field; The generation module includes: The first determining submodule is used to determine whether the user has authorization code operation permission in response to receiving the user's selection of the operation identifier of the candidate authorization code; The first update submodule is used to update the encrypted authorization code of the candidate authorization code selected in the authorization code area to the plaintext authorization code when it is determined that the user has authorization code operation permission; The second update submodule is used to update the field identifier of the authorization field to the plaintext of the authorization code in the command area, thereby obtaining the target authorization command.
[0087] Optionally, the target authorization mode is the Identity and Access Management (IAM) authorization mode, and the authorization command corresponding to the IAM authorization mode contains multiple authorization fields; The generation module includes: The first determining submodule is used to determine whether the user has authorization code operation permission in response to receiving the user's selection of the operation identifier of the candidate authorization code; The first update submodule is used to update the encrypted authorization code of the candidate authorization code selected in the authorization code area to the plaintext authorization code when it is determined that the user has authorization code operation permission; The third update submodule is used to determine the field value corresponding to each authorization field from the authorization information of the selected candidate authorization code based on the authorization field in the command area, and update the field identifier of each authorization field in the authorization command to the field value corresponding to that authorization field, so as to obtain the target authorization command.
[0088] Optionally, the device further includes: The third display module is used to display prompt information and command operation identifiers corresponding to the target authorization command in the command area. The prompt information is used to prompt the operation process information of the target authorization command, and the command operation identifiers are used to perform target operations on the target authorization command.
[0089] Optionally, the candidate authorization code is determined in the following way: Obtain multiple authorization codes corresponding to the user; Based on the permission information corresponding to the multiple authorization codes, the multiple authorization codes are filtered to obtain the candidate authorization codes, wherein the permission information includes usage permission information and / or usage time information.
[0090] Optionally, the authorization code interface also includes an authorization code creation control; The device further includes: The fourth display module is used to display the authorization code creation interface in response to the user's selection operation on the authorization code creation control; A processing module is used to respond to the user's configuration operation in the authorization code creation interface, generate an authorization code and display the authorization code interface, wherein the authorization code interface contains the generated authorization code.
[0091] Optionally, the authorization code interface is displayed on top of the authorization interface in the form of a floating layer or a pop-up window.
[0092] Optionally, the authorization interface may further include sample code for calling the target model, and the authorization code operation control may be displayed in the authorization area of the authorization interface; The first display module includes: The third display submodule is used to display labels for different types of Software Development Kits (SDKs) side by side in the first area of the authorization interface, wherein the sample code corresponding to different types of SDKs is different; The fourth display submodule is used to display the target example code corresponding to the target label determined in the first area in the second area of the authorization interface, wherein the authorization area, the first area, and the second area are displayed in the authorization interface in a top-to-bottom order.
[0093] Optionally, the example code includes development code and command configuration code corresponding to the target model, wherein the command configuration code is used for tool installation and management; The fourth display submodule includes: The fifth display submodule is used to display the command configuration code and the copy identifier corresponding to the command configuration code in the command configuration area of the second region; and to display the development code and the copy identifier corresponding to the development code in the development configuration area of the second region.
[0094] Optionally, the first area may also include a code type control corresponding to the example code; The fourth display submodule includes: The sixth display submodule is used to display the target label determined in the first area and the target sample code corresponding to the target code type under the target code type control in the second area of the authorization interface.
[0095] The following is for reference. Figure 8 The diagram illustrates a structural schematic of an electronic device (e.g., a terminal device or a server) 600 suitable for implementing embodiments of the present disclosure. The terminal device in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 8 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.
[0096] like Figure 8 As shown, electronic device 600 may include a processing device (e.g., a central processing unit, a graphics processor, etc.) 601, which can perform various appropriate actions and processes according to a program stored in read-only memory (ROM) 602 or a program loaded from storage device 608 into random access memory (RAM) 603. RAM 603 also stores various programs and data required for the operation of electronic device 600. Processing device 601, ROM 602, and RAM 603 are interconnected via bus 604. Input / output (I / O) interface 605 is also connected to bus 604.
[0097] Typically, the following devices can be connected to I / O interface 605: input devices 606 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 607 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 608 including, for example, magnetic tapes, hard disks, etc.; and communication devices 609. Communication device 609 allows electronic device 600 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 8 An electronic device 600 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively.
[0098] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 609, or installed from a storage device 608, or installed from a ROM 602. When the computer program is executed by the processing device 601, it performs the functions defined in the methods of embodiments of this disclosure.
[0099] It should be noted that the computer-readable medium described in this disclosure can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this disclosure, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.
[0100] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol) and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any currently known or future-developed networks.
[0101] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.
[0102] The aforementioned computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to: in response to determining a target authorization mode corresponding to a target model invocation, display an authorization interface corresponding to the target authorization mode, wherein the authorization interface displays an authorization code operation control; in response to the authorization code operation control being selected, display an authorization code interface, wherein the authorization code interface is used to display an authorization command and candidate authorization codes corresponding to the target model invocation; and in response to the user's selection of a candidate authorization code, generate a target authorization command corresponding to the target model invocation based on the selected candidate authorization code and the authorization command, wherein the target authorization command is used to verify the permissions of the target model invocation.
[0103] Computer program code for performing the operations of this disclosure can be written in one or more programming languages or a combination thereof, including but not limited to object-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0104] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0105] The modules described in the embodiments of this disclosure can be implemented in software or hardware. The names of the modules do not necessarily limit the module itself; for example, the first display module can also be described as "a module that displays the authorization interface corresponding to the target authorization mode in response to determining the target model and calling the corresponding target authorization mode."
[0106] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), and so on.
[0107] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0108] According to one or more embodiments of this disclosure, Example 1 provides a model invocation configuration method for large model security, wherein the method includes: In response to determining the target model and calling the corresponding target authorization mode, the authorization interface corresponding to the target authorization mode is displayed, wherein the authorization interface displays authorization code operation controls; In response to the selection of the authorization code operation control, an authorization code interface is displayed, wherein the authorization code interface is used to display the corresponding authorization command and candidate authorization codes for the target model to invoke; In response to the user's selection of a candidate authorization code, a target authorization command corresponding to the target model call is generated based on the selected candidate authorization code and the authorization command. The target authorization command is used to verify the permission for the target model call.
[0109] According to one or more embodiments of this disclosure, Example 2 provides the method of Example 1, wherein the interface for displaying the authorization code includes: The authorization command is displayed in the command area of the authorization code interface, wherein the authorization code in the authorization command is displayed as the field identifier corresponding to the authorization code; The authorization code area in the authorization code interface displays the identifier, encrypted authorization code, and operation identifier of each candidate authorization code.
[0110] According to one or more embodiments of this disclosure, Example 3 provides the method of Example 2, wherein the target authorization mode is an API key authorization mode, and the authorization command corresponding to the API key authorization mode includes an authorization field; The step of responding to the user's selection of a candidate authorization code, generating a target model based on the selected candidate authorization code and the authorization command, and invoking the corresponding target authorization command includes: In response to receiving the user's selection of the operation identifier for the candidate authorization code, determine whether the user has authorization code operation permission; If it is determined that the user has authorization code operation permission, the encrypted authorization code of the candidate authorization code selected in the authorization code area is updated to the plaintext authorization code; In the command area, the field identifier of the authorization field is updated to the plaintext of the authorization code to obtain the target authorization command.
[0111] According to one or more embodiments of this disclosure, Example 4 provides the method of Example 2, wherein the target authorization mode is an Identity and Access Management (IAM) authorization mode, and the authorization command corresponding to the IAM authorization mode contains multiple authorization fields; The step of responding to the user's selection of a candidate authorization code, generating a target model based on the selected candidate authorization code and the authorization command, and invoking the corresponding target authorization command includes: In response to receiving the user's selection of the operation identifier for the candidate authorization code, determine whether the user has authorization code operation permission; If it is determined that the user has authorization code operation permission, the encrypted authorization code of the candidate authorization code selected in the authorization code area is updated to the plaintext authorization code; Based on the authorization fields in the command area, determine the field value corresponding to each authorization field from the authorization information of the selected candidate authorization code, and update the field identifier of each authorization field in the authorization command to the field value corresponding to that authorization field to obtain the target authorization command.
[0112] According to one or more embodiments of this disclosure, Example 5 provides the method of Example 3 or 4, wherein the method further includes: The command area displays prompt information and command operation identifiers corresponding to the target authorization command. The prompt information is used to provide operation flow information for the target authorization command, and the command operation identifiers are used to perform target operations on the target authorization command.
[0113] According to one or more embodiments of this disclosure, Example 6 provides the method of Example 2, wherein the candidate authorization code is determined in the following manner: Obtain multiple authorization codes corresponding to the user; Based on the permission information corresponding to the multiple authorization codes, the multiple authorization codes are filtered to obtain the candidate authorization codes, wherein the permission information includes usage permission information and / or usage time information.
[0114] According to one or more embodiments of this disclosure, Example 7 provides the method of Example 2, wherein the authorization code interface further includes an authorization code creation control; The method further includes: In response to the user's selection of the authorization code creation control, the authorization code creation interface is displayed; In response to the user's configuration operation on the authorization code creation interface, an authorization code is generated and the authorization code interface is displayed, which contains the generated authorization code.
[0115] According to one or more embodiments of this disclosure, Example 8 provides the method of Example 1, wherein the authorization code interface is displayed on top of the authorization interface in the form of a floating layer or a pop-up window.
[0116] According to one or more embodiments of this disclosure, Example 9 provides the method of Example 1, wherein the authorization interface further includes the example code corresponding to the target model calling, and the authorization code operation control is displayed in the authorization area of the authorization interface; The authorization interface that displays the target authorization mode includes: The first area of the authorization interface displays labels for different types of Software Development Kits (SDKs) side by side, with different sample code for each type of SDK. The target example code corresponding to the target label determined in the first area is displayed in the second area of the authorization interface, wherein the authorization area, the first area, and the second area are displayed in the order from top to bottom in the authorization interface.
[0117] According to one or more embodiments of this disclosure, Example 10 provides the method of Example 9, wherein the example code includes development code and command configuration code corresponding to the target model, and the command configuration code is used for tool installation and management; The step of displaying the target example code corresponding to the target label determined in the first area in the second area of the authorization interface includes: The command configuration code and the copy identifier corresponding to the command configuration code are displayed in the command configuration area of the second region. The development configuration area in the second region displays the development code and the copy identifier corresponding to the development code.
[0118] According to one or more embodiments of this disclosure, Example 11 provides the method of Example 9, wherein the first area further includes a code type control corresponding to the example code; The step of displaying the target example code corresponding to the target label determined in the first area in the second area of the authorization interface includes: The second area of the authorization interface displays the target label identified in the first area and the target sample code corresponding to the target code type under the code type control.
[0119] According to one or more embodiments of this disclosure, Example 12 provides a model invocation configuration apparatus for large model security, the apparatus comprising: The first display module is used to respond to the determination of the target model and call the corresponding target authorization mode, and to display the authorization interface corresponding to the target authorization mode, wherein the authorization interface displays the authorization code operation control; The second display module is used to display the authorization code interface in response to the selection of the authorization code operation control, wherein the authorization code interface is used to display the corresponding authorization command and candidate authorization codes for the target model to call; The generation module is used to respond to the user's selection of a candidate authorization code, and generate a target authorization command corresponding to the target model call based on the selected candidate authorization code and the authorization command. The target authorization command is used to verify the permission of the target model call.
[0120] According to one or more embodiments of the present disclosure, Example 13 provides a computer-readable medium having a computer program stored thereon that, when executed by a processing device, implements the steps of the method described in any one of Examples 1-11.
[0121] According to one or more embodiments of this disclosure, Example 14 provides an electronic device comprising: A storage device on which computer programs are stored; A processing device for executing the computer program in the storage device to implement the steps of any one of the methods in Examples 1-11.
[0122] According to one or more embodiments of the present disclosure, Example 15 provides a computer program product including a computer program that, when executed by a processor, implements the steps of the method described in any one of Examples 1-11.
[0123] The above description is merely a preferred embodiment of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features disclosed in this disclosure that have similar functions.
[0124] Furthermore, while the operations are described in a specific order, this should not be construed as requiring these operations to be performed in the specific order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.
[0125] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative forms of implementing the claims. Regarding the apparatus in the above embodiments, the specific manner in which the various modules perform their operations has been described in detail in the embodiments relating to the method, and will not be elaborated upon here.
Claims
1. A model invocation configuration method for large model security, characterized in that, The method includes: In response to determining the target model and calling the corresponding target authorization mode, the authorization interface corresponding to the target authorization mode is displayed, wherein the authorization interface displays authorization code operation controls; In response to the selection of the authorization code operation control, an authorization code interface is displayed, wherein the authorization code interface is used to display the corresponding authorization command and candidate authorization codes for the target model to call. The authorization command is displayed in the command area of the authorization code interface, and the authorization code in the authorization command is displayed as the field identifier corresponding to the authorization code. In response to the user's selection of a candidate authorization code, the field identifier in the authorization command in the command area is updated to the plaintext of the authorization code corresponding to the selected candidate authorization code, and a target authorization command corresponding to the target model call is generated. The target authorization command is used to verify the permission of the target model call. The copy identifier corresponding to the target authorization command is displayed in the command area of the authorization code interface.
2. The method according to claim 1, characterized in that, The interface for displaying the authorization code includes: The authorization code area in the authorization code interface displays the identifier, encrypted authorization code, and operation identifier of each candidate authorization code.
3. The method according to claim 2, characterized in that, The target authorization mode is the API key authorization mode, and the authorization command corresponding to the API key authorization mode contains an authorization field; In response to the user's selection of a candidate authorization code, the field identifier in the authorization command in the command area is updated to the plaintext of the authorization code corresponding to the selected candidate authorization code, and the target model is generated to invoke the corresponding target authorization command, including: In response to receiving the user's selection of the operation identifier for the candidate authorization code, determine whether the user has authorization code operation permission; If it is determined that the user has authorization code operation permission, the encrypted authorization code of the candidate authorization code selected in the authorization code area is updated to the plaintext authorization code; In the command area, the field identifier of the authorization field is updated to the plaintext of the authorization code to obtain the target authorization command.
4. The method according to claim 2, characterized in that, The target authorization mode is the Identity and Access Management (IAM) authorization mode, and the authorization command corresponding to the IAM authorization mode contains multiple authorization fields; In response to the user's selection of a candidate authorization code, the field identifier in the authorization command in the command area is updated to the plaintext of the authorization code corresponding to the selected candidate authorization code, and the target model is generated to invoke the corresponding target authorization command, including: In response to receiving the user's selection of the operation identifier for the candidate authorization code, determine whether the user has authorization code operation permission; If it is determined that the user has authorization code operation permission, the encrypted authorization code of the candidate authorization code selected in the authorization code area is updated to the plaintext authorization code; Based on the authorization fields in the command area, determine the field value corresponding to each authorization field from the authorization information of the selected candidate authorization code, and update the field identifier of each authorization field in the authorization command to the field value corresponding to that authorization field to obtain the target authorization command.
5. The method according to claim 3 or 4, characterized in that, The method further includes: The command area displays prompt information and command operation identifiers corresponding to the target authorization command. The prompt information is used to provide operation flow information for the target authorization command, and the command operation identifiers are used to perform target operations on the target authorization command.
6. The method according to claim 2, characterized in that, The candidate authorization code is determined in the following way: Obtain multiple authorization codes corresponding to the user; Based on the permission information corresponding to the multiple authorization codes, the multiple authorization codes are filtered to obtain the candidate authorization codes, wherein the permission information includes usage permission information and / or usage time information.
7. The method according to claim 2, characterized in that, The authorization code interface also includes an authorization code creation control; The method further includes: In response to the user's selection of the authorization code creation control, the authorization code creation interface is displayed; In response to the user's configuration operation on the authorization code creation interface, an authorization code is generated and the authorization code interface is displayed, which contains the generated authorization code.
8. The method according to claim 1, characterized in that, The authorization code interface is displayed on top of the authorization interface in the form of a floating layer or a pop-up window.
9. The method according to claim 1, characterized in that, The authorization interface also includes sample code for calling the target model, and the authorization code operation control is displayed in the authorization area of the authorization interface; The authorization interface that displays the target authorization mode includes: The first area of the authorization interface displays labels for different types of Software Development Kits (SDKs) side by side, with different sample code for each type of SDK. The target example code corresponding to the target label determined in the first area is displayed in the second area of the authorization interface, wherein the authorization area, the first area, and the second area are displayed in the order from top to bottom in the authorization interface.
10. The method according to claim 9, characterized in that, The example code includes development code and command configuration code corresponding to the target model. The command configuration code is used for tool installation and management. The step of displaying the target example code corresponding to the target label determined in the first area in the second area of the authorization interface includes: The command configuration code and the copy identifier corresponding to the command configuration code are displayed in the command configuration area of the second region. The development configuration area in the second region displays the development code and the copy identifier corresponding to the development code.
11. The method according to claim 9, characterized in that, The first area also contains code type controls corresponding to the example code; The step of displaying the target example code corresponding to the target label determined in the first area in the second area of the authorization interface includes: The second area of the authorization interface displays the target label identified in the first area and the target sample code corresponding to the target code type under the code type control.
12. A model invocation configuration device for large model security, characterized in that, The device includes: The first display module is used to respond to the determination of the target model and call the corresponding target authorization mode, and to display the authorization interface corresponding to the target authorization mode, wherein the authorization interface displays the authorization code operation control; The second display module is used to display the authorization code interface in response to the selection of the authorization code operation control. The authorization code interface is used to display the authorization command and candidate authorization codes corresponding to the target model call. The authorization command is displayed in the command area of the authorization code interface, and the authorization code in the authorization command is displayed as the field identifier corresponding to the authorization code. The generation module is used to respond to the user's selection of a candidate authorization code, update the field identifier in the authorization command in the command area to the plaintext of the authorization code corresponding to the selected candidate authorization code, and generate a target authorization command corresponding to the target model call. The target authorization command is used to verify the permission of the target model call. The third display module is used to display the copy identifier corresponding to the target authorization command in the command area of the authorization code interface.
13. A computer-readable medium having a computer program stored thereon, characterized in that, When executed by a processing device, the computer program performs the steps of the method described in any one of claims 1-11.
14. An electronic device, characterized in that, include: A storage device on which computer programs are stored; A processing device for executing the computer program in the storage device to implement the steps of the method according to any one of claims 1-11.
15. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1-11.
Citation Information
Patent Citations
Calendar data synchronization method and electronic equipment
CN115705121A
Model calling method and device and storage medium
CN116775322A