Access control method, device and equipment for externally-mounted knowledge base large model

By setting permission tags for external knowledge base documents and recognizing user intent, and dynamically obtaining recommendation tags and over-permission tags, the problem of insufficient granularity of user personalization needs and permission control in existing technologies is solved, realizing fine-grained access control and intelligent management, and improving data access efficiency and security.

CN119293812BActive Publication Date: 2025-11-25CHINA CONSTRUCTION BANK +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411310257.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-19
Publication Date
2025-11-25
Estimated Expiration
2044-09-19

AI Technical Summary

Technical Problem

Existing technologies, when combined with access control systems and large-scale question-and-answer systems, cannot meet users' personalized needs, have overly coarse access control granularity, cannot dynamically adjust access control strategies, and cannot meet the enterprise's need for refined management of different users.

Method used

By setting permission control tags for documents in the plug-in knowledge base, the system can identify user intent and query based on user questions and selected tags, dynamically obtain recommended tags and over-permission tags, achieve personalized permission control, and support temporary permission requests and permission sharing group management.

Benefits of technology

It enables customized knowledge base access permissions based on user needs, improving user experience and data access efficiency, ensuring information security and effectiveness, dynamically adjusting access control strategies, and supporting intelligent access management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119293812B_ABST
    Figure CN119293812B_ABST
Patent Text Reader

Abstract

The application provides an access control method, device and equipment of an externally hung knowledge base large model, and relates to the technical field of artificial intelligence; wherein the method comprises obtaining a user question and identifying the intention of the user question; when the intention is to query the knowledge base, based on the user question and a first label selected by the user, querying within a knowledge base document set corresponding to the first label to obtain a query result corresponding to the first label; when the query result does not satisfy a knowledge base query feedback condition, obtaining a second label and / or a first candidate label that the user has the right to select; and based on the user question, querying within a knowledge base document set corresponding to the second label and / or the first candidate label to obtain a query result corresponding to the second label and / or the first candidate label; and when the query result corresponding to the second label and / or the first candidate label satisfies the knowledge base query feedback condition, prompting the user to enable the second label and / or the first candidate label to achieve access control of the externally hung knowledge base large model.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of access control, and particularly relates to an access control method, device and equipment for an externally plugged knowledge base large model. BACKGROUND

[0002] In the related art, in an enterprise, especially in the management of a knowledge base involving large-scale data or files, there are requirements for the confidentiality and compliance of information. At present, a common method is to use a permission control system to manage the data access permissions of different users. However, for a large model question and answer system, it is necessary to provide a customized knowledge base for different users to meet their specific needs.

[0003] The prior art has many shortcomings when combining the permission control system with the large model question and answer system, including but not limited to: insufficient support for user individual needs, inability to customize knowledge base access permissions according to user identity, role or needs; too coarse access control granularity, unable to meet the fine-grained management needs of different users for the knowledge base within an enterprise; unable to dynamically adjust the permission control strategy according to user interaction with the system. SUMMARY

[0004] The present application provides an access control method, device, equipment and storage medium for an externally plugged knowledge base large model to at least solve one problem in the related art. The technical solution of the present application is as follows:

[0005] According to a first aspect of an embodiment of the present application, an access control method for an externally plugged knowledge base large model is provided, wherein each document in the externally plugged knowledge base is provided with a label for permission control, and the method comprises:

[0006] obtaining a user question and identifying the intent of the user question;

[0007] when the intent is to query the externally plugged knowledge base, based on the user question and a first label selected by the user, querying within a set of knowledge base documents corresponding to the first label in the externally plugged knowledge base to obtain a query result corresponding to the first label; the first label is a label selected from at least one permission label possessed by the user; the document types in the externally plugged knowledge base include public documents and field documents, and the knowledge base documents corresponding to the first label belong to the public documents;

[0008] when the query result corresponding to the first label does not meet the library query feedback condition, obtaining a second label and / or a first candidate label; the second label includes a field label that is not selected from the at least one permission label possessed by the user, and the first candidate label includes a recommended label obtained according to the historical questions of the user and corresponding historical query documents;

[0009] based on the user question, the second label and / or the first candidate label, querying in a knowledge base document set corresponding to the second label and / or the first candidate label to obtain a query result corresponding to the second label and / or the first candidate label; the knowledge base document corresponding to the second label belongs to the domain document, and the knowledge base document corresponding to the first candidate label belongs to the historical query document;

[0010] when the query result corresponding to the second label and / or the first candidate label meets the library query feedback condition, prompting the user to open the second label and / or the first candidate label, and the document information corresponding to the second label and / or the first candidate label is used for the large model to generate answer information to answer the user question.

[0011] In some implementations, the method further comprises:

[0012] when the query result corresponding to the second label and / or the first candidate label does not meet the library query feedback condition, based on the user question, querying in all domain documents of the external knowledge base to obtain a super permission query result;

[0013] when the super permission query result meets the library query feedback condition, obtaining a third label corresponding to the document of the super permission query result, and prompting the user to apply for the permission of the document corresponding to the third label; the third label includes a domain label which the user does not have the permission.

[0014] In some implementations, the querying, based on the user question and the first label selected by the user, in a knowledge base document set corresponding to the first label in the external knowledge base to obtain a query result corresponding to the first label, comprises:

[0015] matching the user question with a paragraph in the knowledge base document set corresponding to the first label to obtain a target document paragraph with a relevance greater than or equal to a first threshold;

[0016] taking the target document paragraph as the query result corresponding to the first label.

[0017] In some implementations, different levels of administrators are set for the public document and the domain document, and the different levels of administrators can set different permission issuing authorities; the method further comprises:

[0018] in response to a temporary permission application raised by the user based on an event sheet, based on an emergency type and an emergency degree in the event sheet and a post level of the user, obtaining a target administrator level corresponding to the temporary permission application;

[0019] Send the temporary permission application to the administrator of the target administrator level.

[0020] In some implementations, the method further includes:

[0021] The project manager is given a shared permission to create a permission sharing group, which is used by the project manager to invite team members to join the permission sharing group and set the scope and validity period of the shared permission.

[0022] In some implementations, the external knowledge base further includes confidential documents, and the confidential documents in the external knowledge base constitute a confidential knowledge base. When the confidential documents are stored in the external knowledge base, a separate table is built and a permission person field is added. The method further includes:

[0023] Determine whether to enable the confidential knowledge base;

[0024] The query in the knowledge base document set corresponding to the first tag in the external knowledge base includes:

[0025] Determine to enable the confidential knowledge base, and query in the knowledge base document set corresponding to the first tag and the confidential knowledge base.

[0026] In some implementations, the method further includes:

[0027] When the intent is to query structured query language (SQL) table data, obtain first table information to which the user has permission;

[0028] Based on the first table information and the user question, generate an SQL query statement through the large model; and confirm the SQL query statement with the user;

[0029] Based on the SQL query statement, query the data table corresponding to the first table information to obtain a first table information query result;

[0030] When the first table information query result does not satisfy the table query feedback condition, query the data table corresponding to the second table information based on the SQL query statement to obtain a second table information query result; the second table information is table information to which the user has no permission but is not confidential;

[0031] When the second table information query result satisfies the table query feedback condition, feed back the first table name in the second table information query result to the user to prompt the user to apply for the data table permission corresponding to the first table name, and the data table corresponding to the first table name is used by the large model to generate corresponding answer information in combination with the user question to answer the user question.

[0032] In some implementations, the querying, based on the SQL query statement, the data table corresponding to the second table information comprises:

[0033] obtaining a second candidate label, the second candidate label comprising a recommended label obtained according to a historical question of the user and a corresponding historical query data table;

[0034] querying, based on the SQL query statement, the data table corresponding to the second table information and the data table corresponding to the second candidate label.

[0035] According to a second aspect of the embodiments of the present application, an access control device of an external knowledge base large model is provided, wherein the documents in the external knowledge base are each provided with a label for permission control, and the device comprises:

[0036] an intent recognition module, configured to obtain a user question and recognize an intent of the user question;

[0037] a library matching module, configured to, when the intent is to query the external knowledge base, query, based on the user question and a first label selected by the user, in a knowledge base document set corresponding to the first label in the external knowledge base, to obtain a query result corresponding to the first label; the first label is a label selected from at least one permission label possessed by the user; the document types in the external knowledge base include public documents and field documents, and the knowledge base documents corresponding to the first label belong to the public documents;

[0038] an information recommendation module, configured to, when the query result corresponding to the first label does not satisfy a library query feedback condition, obtain a second label and / or a first candidate label; the second label comprises a field label that is not selected from the at least one permission label possessed by the user, and the first candidate label comprises a recommended label obtained according to a historical question of the user and a corresponding historical query document;

[0039] the library matching module is further configured to, based on the user question, the second label and / or the first candidate label, query in a knowledge base document set corresponding to each of the second label and / or the first candidate label, to obtain a query result corresponding to the second label and / or the first candidate label; the knowledge base documents corresponding to the second label belong to the field documents, and the knowledge base documents corresponding to the first candidate label belong to the historical query documents;

[0040] an information feedback module, configured to, when the query result corresponding to the second label and / or the first candidate label satisfies the library query feedback condition, prompt the user to turn on the second label and / or the first candidate label, and document information corresponding to the second label and / or the first candidate label is used for the large model to generate answer information to answer the user question.

[0041] In some implementations, the library matching module is further configured to:

[0042] When the query result corresponding to the second label and / or the first candidate label does not satisfy the library query feedback condition, querying all domain documents in the external knowledge base based on the user question to obtain a super-privilege query result;

[0043] When the super-privilege query result satisfies the library query feedback condition, obtaining a third label corresponding to the super-privilege query result, and prompting the user to apply for a privilege of a document corresponding to the third label; the third label includes a domain label that the user does not have a privilege of.

[0044] In some implementations, when the library matching module queries the knowledge base document set corresponding to the first label in the external knowledge base based on the user question and the first label selected by the user to obtain a query result corresponding to the first label, the library matching module is specifically configured to:

[0045] Match the user question with a paragraph in the knowledge base document set corresponding to the first label to obtain a target document paragraph with a relevance greater than a first threshold;

[0046] The target document paragraph is used as the query result corresponding to the first label.

[0047] In some implementations, different levels of administrators are set for the public documents and the domain documents, and the different levels of administrators can set different privileges; the device further includes a privilege management module configured to:

[0048] In response to a temporary privilege application submitted by a user based on an event sheet, obtaining a target administrator level corresponding to the temporary privilege application based on an emergency type and an emergency degree in the event sheet and a post level of the user;

[0049] Sending the temporary privilege application to the administrator of the target administrator level.

[0050] In some implementations, the privilege management module is further configured to:

[0051] Granting a project manager a privilege of creating a privilege sharing group, so that the project manager can invite team members to join the privilege sharing group and set a range and a validity period of the shared privilege.

[0052] In some implementations, the document types in the knowledge base further include confidential documents, the confidential documents in the knowledge base constitute a confidential knowledge base, and the confidential documents are stored in the knowledge base by being separately tabled and having a privilege person field added; the library matching module is further configured to:

[0053] determine whether to enable the confidential knowledge base;

[0054] The library matching module queries in the knowledge base document set corresponding to the first tag in the external knowledge base, and is specifically configured to:

[0055] determine to enable the confidential knowledge base, and query in the knowledge base document set corresponding to the first tag and the confidential knowledge base.

[0056] In some implementations, the library matching module is further configured to:

[0057] When the intent is to query structured query language (SQL) table data, obtain first table information to which the user has access;

[0058] Based on the first table information and the user question, generate an SQL query statement through the large model; and confirm the SQL query statement with the user;

[0059] Based on the SQL query statement, query a data table corresponding to the first table information to obtain a first table information query result;

[0060] When the first table information query result does not satisfy a table query feedback condition, query a data table corresponding to second table information based on the SQL query statement to obtain a second table information query result; the second table information is table information to which the user has no access but is not confidential;

[0061] When the second table information query result satisfies the table query feedback condition, feed back a first table name in the second table information query result to the user to prompt the user to apply for access to a data table corresponding to the first table name, the data table corresponding to the first table name being used to generate corresponding answer information by the large model in combination with the user question to answer the user question.

[0062] In some implementations, the library matching module is further configured to:

[0063] Obtain a second candidate tag, the second candidate tag including a recommended tag obtained based on historical questions of the user and corresponding historical query data tables;

[0064] Query a data table corresponding to the second table information and a data table corresponding to the second candidate tag based on the SQL query statement.

[0065] According to a third aspect of the embodiments of the present application, an electronic device is provided, comprising a processor and a memory connected with the processor in communication; the memory stores computer-executable instructions; and the processor executes the computer-executable instructions stored in the memory to implement the method of the first aspect.

[0066] According to a fourth aspect of the embodiments of the present application, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are executed by a processor to implement the method of the first aspect.

[0067] According to a fifth aspect of the embodiments of the present application, a computer program product is provided, comprising a computer program, and the computer program is executed by a processor to implement the method of the first aspect.

[0068] The technical solutions provided by the embodiments of the present application at least bring the following beneficial effects:

[0069] The access control method of the external knowledge base large model provided by the embodiments of the present application can realize personalized permission control by limiting the knowledge base query document range through tags, can provide customized knowledge base access permissions according to user needs, and improves user experience. The knowledge base query document range can be changed according to the interactive results of the user and the large model system to obtain query results, dynamically prompt the user to increase the search range, dynamically adjust the permission control strategy, realize intelligent permission control, and improve the efficiency and quality of data access to ensure the security and effectiveness of information. The recommended tags can also be obtained according to the user query history, so that the required document information can be quickly obtained.

[0070] It should be understood that the foregoing general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF DRAWINGS

[0071] The accompanying drawings incorporated in the specification and forming a part of the specification illustrate the embodiments consistent with the present application and, together with the specification, serve to explain the principles of the present application, and do not limit the present application.

[0072] Figure 1 is a flowchart of an access control method of an external knowledge base large model according to an embodiment of the present application.

[0073] Figure 2 is a flowchart of an access control method of an external knowledge base large model according to another embodiment of the present application.

[0074] Figure 3 is a flowchart of an access control method of an external knowledge base large model according to still another embodiment of the present application.

[0075] Figure 4 is a block diagram of an access control device of an external knowledge base large model according to an embodiment of the present application.

[0076] Figure 5 is a block diagram of an electronic device provided according to an embodiment of the present application. DETAILED DESCRIPTION

[0077] In order for those skilled in the art to better understand the technical solutions of the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings.

[0078] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. The implementation described in the following exemplary embodiments does not represent all implementations consistent with the present application. On the contrary, they are only examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.

[0079] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data for analysis, stored data, displayed data, etc.) and signals involved in the present application are authorized by the user or fully authorized by all parties, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards of relevant countries and regions.

[0080] It should also be noted that the acquisition, transmission, storage, use, processing, etc. of data in the technical solutions of the present application comply with the relevant provisions of national laws and regulations.

[0081] It should also be noted that in the embodiments of the present application, some industry existing solutions of software, components, models, etc. may be mentioned, which should be considered as exemplary, and the purpose is only to illustrate the feasibility of the implementation of the technical solutions of the present application, but it does not mean that the applicant has or will necessarily use the solution.

[0082] Figure 1 is a flowchart of an access control method of an external knowledge base large model according to an exemplary embodiment, as shown in Figure 1 The access control method of the external knowledge base large model is used in the access control of the external knowledge base large model, which can include steps S101-S105.

[0083] In step S101, a user question is acquired, and an intention of the user question is identified.

[0084] It should be noted that the execution subject of the access control method in the embodiment of the present application is a permission control system of a large model.

[0085] It should be noted that the large model in the large model question and answer system is externally connected with a document knowledge base, and is also externally connected with a database. A user can query the document knowledge base through the large model, or can query a SQL (Structured Query Language) table data of the database through the large model.

[0086] As an implementation manner, when a user initiates an inquiry, the permission control system identifies an intention of the user question through the intention identification module 401, and determines whether the user wants to query content of the knowledge base or wants to query SQL table data of the database.

[0087] Exemplarily, the intention of the user question can be identified through a natural language processing technology.

[0088] In step S102, when the intention is to query the externally connected knowledge base, based on the user question and a first label selected by the user, a query is performed in a knowledge base document set corresponding to the first label in the externally connected knowledge base, to obtain a query result corresponding to the first label; the first label is a label selected from at least one permission label possessed by the user; and a document type in the externally connected knowledge base includes public documents and field documents, and the knowledge base document corresponding to the first label belongs to the public documents.

[0089] It should be noted that each document in the externally connected knowledge base is provided with a label for permission control, and different labels correspond to different knowledge base document ranges.

[0090] It should be noted that the user can have knowledge base document permissions corresponding to multiple labels at the same time, and when inquiring, the user can select a knowledge base document range corresponding to one of the labels to query a question. Before starting a new round of dialogue with the large model question and answer system, the user can select one of the multiple label permissions to be selected, and then issue a query instruction.

[0091] That is, when the user inquires about the content of the knowledge base, the documents will be filtered according to the label selected by the user in advance, and only the document paragraphs in the document range selected by the user will be matched.

[0092] Exemplarily, an implementation manner of the large model externally connected document knowledge base can include the following contents:

[0093] 1) Preprocessing and splitting: first, the document materials are preprocessed, including removing irrelevant formats, unifying coding, etc. Subsequently, the document is split into paragraphs for subsequent retrieval and processing.

[0094] 2) Storage: The split documents will be stored in a vector database, which facilitates fast retrieval in the future. The vector database converts document content into vectors in a high-dimensional space, enabling fast retrieval and similarity calculation.

[0095] 3) Retrieval and Answering: When a user asks a question, the large model needs to retrieve the most relevant document fragments from the document knowledge base based on the content of the question. This process usually involves understanding and analyzing the content of the question, as well as matching and sorting the content of the documents. The large model answers the question based on the retrieved document information, ensuring the accuracy and relevance of the answer.

[0096] In some embodiments, based on the user question, the method for querying in the knowledge base document set corresponding to the first label to obtain the query result corresponding to the first label includes: matching the user question with the text paragraphs in the knowledge base document set corresponding to the first label to obtain target document paragraphs with a relevance greater than a first threshold; and taking the target document paragraphs as the query result corresponding to the first label.

[0097] If the target document paragraphs with a relevance greater than the first threshold are matched, the document to which the target document paragraphs belong is taken as the context to answer the user question.

[0098] In some embodiments, while querying in the knowledge base document set corresponding to the first label, a plurality of documents corresponding to the user's last N historical queries are obtained, the semantic vectors of the summaries of the plurality of documents are averaged and input into a document recommendation model to obtain document information of recommended documents, so that the user can obtain the recommended documents or apply for the permission of the recommended documents; the document recommendation model is obtained by periodically training based on the user's historical query records.

[0099] It should be noted that the average processing here can be direct summation for average processing, or weighted summation for average processing. The vector corresponding to the document is the semantic vector of the summary of the document, which can be obtained by the bert model.

[0100] In some implementations, the feature input of the document recommendation model can also include project name and department features. During model training, it is not cross-project (it can also be set to not cross both project and department, or more conditions remain unchanged). Assuming that the last n query records (M>n>2, M is the maximum number of query records), the average value of the first n-1 times (it can also be set to weighted average with increasing weight, and the weight of the last time is the largest) is taken as one of the inputs, and the last time is taken as the target value, and the model is trained. The model can take K (preset) recommended results when predicting.

[0101] For example, the user query record is obtained in real time, a plurality of documents corresponding to the last five queries of the user are obtained, and a document required by the user is predicted based on a semantic vector of a summary of the plurality of documents and recommended by a document recommendation model.

[0102] As an implementation manner, when the user usage amount and usage frequency of the permission control system of the large model of the embodiment of the present application reach a certain number, the machine learning model or the neural network model is periodically trained according to the documents queried by the user in real time, and the documents that the user may need are dynamically recommended.

[0103] Therefore, by using the document real-time recommendation function, the work efficiency of the employee can be improved, the employee does not need to manually search or inquire others for the document name that still needs permission, and potential useful data can be found, so that the data assets of the enterprise can be fully utilized. Therefore, the document required by the user can be predicted according to the user query history record, and the document permission is dynamically recommended.

[0104] In step S103, when the query result corresponding to the first label does not satisfy the library query feedback condition, a second label and / or a first candidate label are obtained, the second label includes a domain label that is not selected from at least one permission label possessed by the user, and the first candidate label includes a recommended label obtained according to the historical problem of the user and the corresponding historical query document.

[0105] In the embodiment, the library query feedback condition is that a target document paragraph with a relevance greater than a first threshold value is matched, and the target document paragraph with the relevance greater than the first threshold value indicates that the current knowledge base document range has a document capable of answering the user question; and the library query feedback condition is not satisfied when a target document paragraph with a relevance greater than the first threshold value is not matched, which indicates that the document range corresponding to the current label cannot answer the user question.

[0106] When the query result corresponding to the first label does not satisfy the library query feedback condition, the second label that the user has the right to select can be obtained, that is, the domain label that the user has the right to select is obtained.

[0107] When the query result corresponding to the first label does not satisfy the library query feedback condition, the first candidate label can also be obtained, and the first candidate label is a recommended label obtained according to the historical problem of the user and the corresponding historical query document.

[0108] In some embodiments, the document types in the knowledge base include confidential documents, public documents, and domain documents, the knowledge base document corresponding to the first label belongs to the public document, and the knowledge base document corresponding to the second label belongs to the domain document. In some embodiments, different levels of administrators are set for the public documents and the domain documents, and different levels of administrators can set different permission issuing authorities.

[0109] For example, different levels of administrators are set for non-confidential documents and data tables, such as senior, intermediate, and junior administrators, and different levels of administrators can set different distribution permissions, such as senior administrators can set permanent permissions, intermediate administrators can set permissions for at most N days, and junior administrators can set permissions for M times of query.

[0110] In some embodiments, the access control method further comprises: in response to a temporary permission application submitted by a user based on an event sheet, obtaining a target administrator level corresponding to the temporary permission application based on the type and severity of the emergency in the event sheet and the user's post level; and sending the temporary permission application to the administrator of the target administrator level.

[0111] Thus, in an emergency, based on the type and severity of the emergency obtained from the event sheet, and the user's post and level, the permission application should be assigned to what level of administrator is automatically calculated and evaluated.

[0112] In some embodiments, the access control method further comprises: granting the project manager the right to create a permission sharing group, so that the project manager can invite team members to join the permission sharing group and set the scope and validity period of the shared permission.

[0113] Thus, the project manager is allowed to create a "permission sharing group", invite team members to join, and set the scope and validity period of the shared permission, which realizes the project internal collaborative permission and greatly saves the operation of permission issuance and recovery when the project adds or reduces personnel.

[0114] In some embodiments, the confidential documents in the knowledge base constitute a confidential knowledge base, and the confidential documents are stored in the knowledge base separately and increase the permission person field; the first label selected by the user is obtained, and it is also determined whether to enable the confidential knowledge base; and the query is performed in the knowledge base document set corresponding to the first label in the external knowledge base, including: determining to enable the confidential knowledge base, and performing the query in the knowledge base document set and the confidential knowledge base corresponding to the first label.

[0115] Whether to enable the confidential knowledge base can be determined according to the selection operation of the user; or whether to enable the confidential knowledge base can also be determined according to the use scenario of the user, or whether to enable the confidential knowledge base can also be determined according to the semantic information of the user's question; or whether to enable the confidential knowledge base can also be determined according to the security of the hardware environment, such as whether there is a network attack or other security risks.

[0116] Example 1, for different document types, when splitting and storing into a vector database, the following processing is performed:

[0117] 1) Confidential document: Confidential documents will be built into a table separately from other documents when split into the warehouse. At the same time, the authorized person field is added, and only administrators can add or delete authorized persons.

[0118] 2) Public document: After splitting, it is normally warehoused and set to the general label 0.

[0119] 3) Domain document: After splitting into the warehouse, the domain label is set separately. Each user will also set the corresponding domain label to facilitate filtering when searching. The permissions of the domain document will be set separately by the domain document administrator, and will be managed separately. Considering that domain documents are usually documents with a certain degree of specialization, users who are not in this field usually do not ask for information related to the document, and if they are searched together, it will increase the search time.

[0120] 4) Keyword extraction: After splitting the above documents, keywords are extracted from each document paragraph and stored in a separate field to facilitate subsequent searching and matching.

[0121] When a user queries a public document by selecting a first label, if no document paragraph with a relevance exceeding a first threshold is matched, the user will enter the domain recommendation process through the domain label to which the user has access. First, the user's question is matched with the document paragraph keywords in the range of documents that have access but have not been selected. If there is a document paragraph exceeding the first threshold, the target document paragraph is obtained.

[0122] In step 104, based on the user question, the second label and / or the first candidate label, a query is performed in the knowledge base document set corresponding to the second label and / or the first candidate label to obtain a query result corresponding to the second label and / or the first candidate label; the knowledge base document corresponding to the second label belongs to a domain document, and the knowledge base document corresponding to the first candidate label belongs to a historical query document.

[0123] That is, when the query result corresponding to the first label does not satisfy the library query feedback condition, the second label to which the user has access can be obtained, that is, the domain label to which the user has access is obtained, so as to perform document matching in the range of documents corresponding to the domain label to obtain a query result corresponding to the second label. When the query result corresponding to the first label does not satisfy the library query feedback condition, the first candidate label can also be obtained, which is a recommended label obtained according to the user's historical question and the corresponding historical query document. According to the first candidate label, the user can quickly and accurately obtain the required document by querying the history.

[0124] In step S105, when the query result corresponding to the second label and / or the first candidate label satisfies the library query feedback condition, the user is prompted to open the second label and / or the first candidate label, and the document information corresponding to the second label and / or the first candidate label is used to generate answer information to answer the user's question.

[0125] That is, after obtaining the target document paragraph that meets the demand through document query by the second label, it is indicated that the document range corresponding to the second label can answer the user's question, and the user is prompted to open the second label to obtain the target document paragraph, so as to realize dynamic adjustment of permission control according to the interaction between the user and the system. After obtaining the target document paragraph that meets the demand through document query by the first candidate label, it is indicated that the document range corresponding to the first candidate label can answer the user's question, and the user is prompted to open the first candidate label to obtain the target document paragraph, so as to realize dynamic adjustment of permission control according to the interaction between the user and the system.

[0126] The access control method of the external knowledge base large model according to the embodiments of the present application can realize personalized permission control by limiting the document range of the knowledge base query through labels, can provide customized knowledge base access permission according to user demand, and improves user experience. The document range of the knowledge base query can be changed according to the interaction result between the user and the large model system to obtain a query result, and the user is dynamically prompted to increase the search range, so as to realize dynamic adjustment of the permission control strategy, realize intelligent permission control, and improve the efficiency and quality of data access to ensure the security and effectiveness of information. Recommended labels can also be obtained according to the user query history, so as to quickly obtain the required document information. In addition, the required document of the user can be predicted according to the user query history record, and dynamic recommendation of the document permission is realized.

[0127] On the basis of the above-mentioned embodiments, the following further describes the permission dynamic adjustment strategy when the query result corresponding to the second label does not satisfy the library query feedback condition, that is, the following steps are further included after step S104.

[0128] Figure 2 is a flowchart of an access control method of an external knowledge base large model according to another exemplary embodiment, as shown in Figure 2 The access control method of the external knowledge base large model can further include steps S106-S107.

[0129] In step S106, when the query result corresponding to the second label and / or the first candidate label does not satisfy the library query feedback condition, the user's question is based on the query in all field documents of the external knowledge base to obtain a super permission query result.

[0130] In step S107, when the super permission query result meets the library query feedback condition, the third label corresponding to the Chinese document of the super permission query result is obtained, and the user is prompted to apply for the permission of the document corresponding to the third label; the third label includes a domain label that the user does not have the permission of.

[0131] As illustrated in Example 1, if the domain label that the user has the permission of still does not match the document paragraph with a relevance greater than the first threshold value, the paragraph keywords are matched in all domain documents. If a match is found, the user is informed that the document of a certain domain can possibly answer the user's question, the label corresponding to the domain is the third label, the third label is a domain label that the user does not have the permission of, and the user is suggested to apply for the permission of the domain label, that is, to apply for the permission of the related domain document.

[0132] By implementing the present embodiment, the knowledge base query document range can be further changed according to the interaction result of the user and the large model system, the query result is obtained, the user is dynamically prompted to apply for the corresponding data permission, the permission control strategy is dynamically adjusted, and intelligent permission control is realized.

[0133] The above embodiments are descriptions of the problem query of the large model external document knowledge base, and the problem query of the large model external database is described below.

[0134] Figure 3 is a flowchart of an access control method of an external knowledge base large model according to still another exemplary embodiment, as shown in Figure 3 The access control method of the external knowledge base large model can include steps S201-S206.

[0135] In step S201, when the intent is to query SQL table data, the first table information to which the user has the permission of is obtained.

[0136] When it is identified that the intent is to query SQL table data, the first table information to which the user has the permission of is obtained for database table query. Exemplarily, the table information can include but is not limited to the table name, the field name, the Chinese explanation of the table name, and the Chinese explanation of the field name.

[0137] In some embodiments, for the SQL data table in the database, considering the security and prevention of information leakage, the user applies for the table permission through the system for permission management, such as the data table permission system, the permission control system of the large model can access the data table permission system, and it is ensured that the user can only access the data table to which the user has the permission of. The information of the data table with the permission is directly transmitted to the large model as text, and other non-permission but non-confidential table information can be separately stored in a certain place for backup use of the large model.

[0138] In one implementation, the first table information to which the user has the permission of is obtained through the data table permission control system.

[0139] In step S202, based on the first table information and the user question, an SQL query statement is generated by the large model; and the SQL query statement is confirmed with the user.

[0140] In some embodiments, the first table information and the user question are input into the large model to generate the SQL query statement.

[0141] In an implementation manner, the manner of confirming the SQL query statement with the user includes: asking the user whether the SQL query statement needs to be executed or modified, and if the user modifies the SQL query statement, the modified SQL query statement is determined as the SQL query statement to be executed.

[0142] Exemplarily, the implementation manner of the large model externally connecting the database can include the following contents:

[0143] 1) Constructing an SQL query statement: the large model needs to construct a database query SQL statement according to the content of the user question, which usually involves understanding and converting the user question, and matching the database structure and the query condition.

[0144] 2) Executing the query: the large model needs to establish a connection with the database to execute the query statement. The query result will be returned to the large model for further processing and display.

[0145] 3) Result processing and display: after receiving the query result, the large model will further process it to present it to the user in a user-friendly manner, which can include sorting, filtering, formatting, etc.

[0146] In step S203, based on the SQL query statement, the data table corresponding to the first table information is queried to obtain the first table information query result.

[0147] That is, for the data table corresponding to the first table information that the user has the right to access, the confirmed SQL query statement is executed to obtain the query result.

[0148] In step S204, when the first table information query result does not satisfy the table query feedback condition, the data table corresponding to the second table information is queried based on the SQL query statement to obtain the second table information query result; the second table information is table information that the user has no right to access but is not secret.

[0149] In some embodiments, the table query feedback condition can be that the query result is not empty, and not satisfying the table query feedback condition means that no data is matched after executing the SQL query statement. When the first table information query result is empty, the data table corresponding to the second table information is queried based on the SQL query statement.

[0150] Thus, when the query on the table accessible to the user does not obtain a reply matching the user's question, the query on the table not accessible to the user but not confidential is continued.

[0151] In some embodiments, the second table information corresponds to a database table stored separately for calling by the large model.

[0152] In step S205, when the second table information query result meets the table query feedback condition, the first table name in the second table information query result is fed back to the user, so that the user applies for the data table permission corresponding to the first table name, and the data table corresponding to the first table name is used by the large model to generate corresponding answer information in combination with the user's question to answer the user's question.

[0153] That is, the query on the table not accessible to the user but not confidential is continued, and after the query result meeting the table query feedback condition is obtained, the table name matching the result is obtained, and the user is prompted to apply for the permission of the table, so as to dynamically adjust the permission control strategy according to the interaction between the user and the large model system.

[0154] It can be understood that, if the query based on the first table information does not match the data, the large model can perform relevance matching on the user's question and the table information within the range allowed by the data table permission system, feed back the table name with a matching degree greater than a certain threshold to the user, and suggest the user to apply for the permission to view these tables.

[0155] In some embodiments, the query on the data table corresponding to the second table information based on the SQL query statement includes: obtaining a second candidate label, the second candidate label including a recommended label obtained according to the user's historical question and corresponding historical query data table; and querying the data table corresponding to the second table information and the data table corresponding to the second candidate label based on the SQL query statement. In some embodiments, while querying the data table corresponding to the first table information based on the SQL query statement, a plurality of data table information corresponding to the user's recent N times of historical query is obtained, the semantic vectors of the table descriptions of the plurality of data tables are averaged and input into a table recommendation model to obtain table information of a recommended table, so that the user obtains the recommended table or applies for the permission of the recommended table; and the table recommendation model is obtained by periodically training based on the user's historical query record.

[0156] It should be noted that the table description of the data table can be directly obtained by the large model or other models, or can be obtained by splicing the table name, the field name and the field content.

[0157] Optionally, the input features of the table permission recommendation model can include but are not limited to: user historical query access record topN, work role, department and project name.

[0158] Therefore, it is beneficial to improve the work efficiency of employees, without manually searching or asking others for data table names that still need permissions, discovering potentially useful data, and fully utilizing the data assets of the enterprise.

[0159] By implementing the present embodiment, the query range of the database table is limited by the table information, achieving personalized permission control, and providing customized knowledge base access permissions according to user needs, improving user experience. The database table query range can be changed according to the user interaction results with the large model system, the query results are obtained, the user is dynamically prompted to apply for the corresponding data permissions, the permission control strategy is dynamically adjusted, the intelligent permission control is realized, and the efficiency and quality of data access are improved to ensure the security and effectiveness of information. It is also possible to predict the tables required by the user according to the user query history record, and to realize dynamic recommendation of table permissions.

[0160] As an implementation of the method shown in the above figures, the present embodiment also provides an access control device for an externally attached knowledge base large model, Figure 4 is a block diagram of an access control device for an externally attached knowledge base large model according to an example embodiment. Referring to Figure 4 The device can include an intent recognition module 401, a library matching module 402, an information recommendation module 403, and an information feedback module 404.

[0161] The intent recognition module 401 is configured to obtain a user question and identify the intent of the user question.

[0162] The library matching module 402 is configured to, when the intent is to query the externally attached knowledge base, based on the user question and a first label selected by the user from at least one permission label owned by the user, query within a knowledge base document set corresponding to the first label in the externally attached knowledge base, to obtain a query result corresponding to the first label; the first label is a label selected from at least one permission label owned by the user; the document types in the externally attached knowledge base include public documents and domain documents, and the knowledge base documents corresponding to the first label belong to public documents.

[0163] The information recommendation module 403 is configured to, when the query result corresponding to the first label does not satisfy a library query feedback condition, obtain a second label and / or a first candidate label; the second label includes a domain label that is not selected from at least one permission label owned by the user, and the first candidate label includes a recommended label obtained based on a historical question of the user and a corresponding historical query document.

[0164] The library matching module 402 is further configured to, based on the user question, the second label, and / or the first candidate label, query within the knowledge base document set corresponding to the second label and / or the first candidate label, to obtain a query result corresponding to the second label and / or the first candidate label; the knowledge base documents corresponding to the second label belong to domain documents, and the knowledge base documents corresponding to the first candidate label belong to historical query documents.

[0165] The information feedback module 404 is configured to prompt the user to open the second label and / or the first candidate label when the query result corresponding to the second label and / or the first candidate label satisfies the library query feedback condition, and the document information corresponding to the second label and / or the first candidate label is used to generate answer information by the large model to answer the user question. In some implementations, the library matching module 402 is further configured to:

[0166] When the query result corresponding to the second label and / or the first candidate label does not satisfy the library query feedback condition, query in all domain documents of the external knowledge base based on the user question to obtain a super-privilege query result;

[0167] When the super-privilege query result satisfies the library query feedback condition, obtain a third label corresponding to the document of the super-privilege query result, and prompt the user to apply for the privilege of the document corresponding to the third label; the third label includes a domain label for which the user does not have the privilege.

[0168] In some implementations, when the library matching module 402 queries in the knowledge base document set corresponding to the first label in the external knowledge base based on the user question and the first label selected by the user to obtain the query result corresponding to the first label, the library matching module 402 is specifically configured to:

[0169] Match the user question with the text paragraphs in the knowledge base document set corresponding to the first label to obtain a target document paragraph with a relevance greater than a first threshold;

[0170] Take the target document paragraph as the query result corresponding to the first label.

[0171] In some implementations, different levels of administrators are set for the public document and the domain document, and the different levels of administrators can set different issued privileges; the apparatus further includes a privilege management module 405 configured to:

[0172] In response to a temporary privilege application submitted by the user based on an event sheet, obtain a target administrator level corresponding to the temporary privilege application based on an emergency type and an emergency degree in the event sheet and a post level of the user;

[0173] Send the temporary privilege application to the administrator of the target administrator level.

[0174] In some implementations, the privilege management module 405 is further configured to:

[0175] Give the project manager the privilege of creating a privilege sharing group, so that the project manager can invite team members to join the privilege sharing group and set the range and validity period of the shared privilege.

[0176] In some implementations, the document types in the knowledge base further include confidential documents, the confidential documents in the knowledge base constitute a confidential knowledge base, the confidential documents are stored in the knowledge base separately and a permission person field is added; the library matching module 402 is further configured to:

[0177] determine whether to enable the confidential knowledge base;

[0178] When the library matching module 402 queries in the knowledge base document set corresponding to the first tag in the external knowledge base, the library matching module 402 is specifically configured to:

[0179] determine to enable the confidential knowledge base, and query in the knowledge base document set corresponding to the first tag and the confidential knowledge base.

[0180] In some implementations, the library matching module 402 is further configured to:

[0181] when the intent is to query structured query language (SQL) table data, obtain first table information to which the user has permission;

[0182] generate an SQL query statement based on the first table information and the user question through a large model; and confirm the SQL query statement with the user;

[0183] query a data table corresponding to the first table information based on the SQL query statement to obtain a first table information query result;

[0184] when the first table information query result does not satisfy a table query feedback condition, query a data table corresponding to second table information based on the SQL query statement to obtain a second table information query result; the second table information is table information to which the user has no permission but is not confidential;

[0185] when the second table information query result satisfies the table query feedback condition, feed back a first table name in the second table information query result to the user to prompt the user to apply for permission of a data table corresponding to the first table name, the data table corresponding to the first table name being used to generate corresponding answer information by the large model in combination with the user question to answer the user question.

[0186] In some implementations, the library matching module 402 is further configured to:

[0187] obtain a second candidate tag, the second candidate tag including a recommended tag obtained according to a historical question of the user and a corresponding historical query data table;

[0188] query the data table corresponding to the second table information and the data table corresponding to the second candidate tag based on the SQL query statement. As to the apparatus in the above embodiments, the specific manners in which various modules perform operations have been described in detail in the embodiments of the method, and will not be described in detail here.

[0189] The access control device of the external knowledge base large model according to the embodiments of the present application can realize personalized permission control by limiting the knowledge base query document range through tags, can provide customized knowledge base access permissions according to user needs, and improves user experience. The knowledge base query document range can be changed according to the interactive results of the user and the large model system, the query result is obtained, the user is dynamically prompted to increase the search range or apply for the corresponding data permission, and the permission control strategy is dynamically adjusted. The access control device of the external knowledge base large model according to the embodiments of the present application can realize personalized permission control by limiting the database table query range through table information, can provide customized knowledge base access permissions according to user needs, and improves user experience. The database table query range can be changed according to the interactive results of the user and the large model system, the query result is obtained, the user is dynamically prompted to apply for the corresponding data permission, and the permission control strategy is dynamically adjusted. The intelligent permission control is realized, the efficiency and quality of data access are improved, and the safety and effectiveness of information are ensured.

[0190] According to the embodiments of the present application, the present application also provides an electronic device and a readable storage medium.

[0191] As shown in Figure 5 , it is a block diagram of an electronic device for implementing the method of access control of the external knowledge base large model according to the embodiments of the present application. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, workstations, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular telephones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions, are meant to be examples only, and are not intended to limit the implementations of the present application described and / or claimed in this document.

[0192] As shown in Figure 5 , the electronic device includes one or more processors 501, memories 502, and interfaces for connecting components, including high-speed interfaces and low-speed interfaces. The components are connected to each other by different buses, and can be installed on a common motherboard or otherwise installed as needed. The processor can process instructions executed within the electronic device, including instructions stored in the memory or on the memory to display a GUI on an external input / output device, such as a display device coupled to the interface. In other embodiments, multiple processors and / or multiple buses can be used with multiple memories and multiple memories, if desired. Similarly, multiple electronic devices can be connected, each device providing part of the necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 5 In the embodiment shown in

[0193] The memory 502 is a non-transitory computer-readable storage medium provided by the present application. The memory stores instructions executable by at least one processor, so that the at least one processor executes the method of access control of the externally hung knowledge base large model provided by the present application. The non-transitory computer-readable storage medium of the present application stores computer instructions for causing a computer to execute the method of access control of the externally hung knowledge base large model provided by the present application.

[0194] The memory 502 is a non-transitory computer-readable storage medium, which can be used to store non-transitory software programs, non-transitory computer executable programs and modules, such as program instructions / modules (for example, the externally hung knowledge base large model access control method in the embodiments of the present application) of the externally hung knowledge base large model access control method. Figure 4 The processor 501 executes various functional applications and data processing of the server by running the non-transitory software programs, instructions and modules stored in the memory 502, that is, implements the externally hung knowledge base large model access control method in the above method embodiments.

[0195] The memory 502 can include a program storage area and a data storage area, wherein the program storage area can store an operating system and application programs required by at least one function; the data storage area can store data created according to the use of the externally hung knowledge base large model access control electronic device, etc. In addition, the memory 502 can include a high-speed random access memory, and can also include a non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state memory device. In some embodiments, the memory 502 can optionally include a memory disposed remotely with respect to the processor 501, and these remote memories can be connected to the externally hung knowledge base large model access control electronic device through a network. Examples of the above network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.

[0196] The externally hung knowledge base large model access control electronic device can further include an input device 503 and an output device 504. The processor 501, the memory 502, the input device 503 and the output device 504 can be connected through a bus or other means, Figure 5 For example, by way of bus connection.

[0197] The input device 503 can receive input digital or character information, and generate key signal inputs in relation to user settings of the electronic device accessing the external knowledge base large model and function control, such as a touch screen, a keypad, a mouse, a trackpad, a touchpad, a pointing stick, one or more mouse buttons, a trackball, a joystick, etc. The output device 504 can include a display device, an auxiliary lighting device (e.g., an LED), a haptic feedback device (e.g., a vibration motor), etc. The display device can include, but is not limited to, a liquid crystal display (LCD), a light emitting diode (LED) display, and a plasma display. In some embodiments, the display device can be a touch screen.

[0198] Various embodiments of the systems and techniques described here can be realized in digital electronic circuitry, integrated circuitry, specially designed ASICs (application specific integrated circuits), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.

[0199] These computer programs (also known as programs, software, software applications or code) include machine instructions for a programmable processor, and can be implemented in a high-level procedural and / or object-oriented programming language, and / or in assembly / machine language. As used herein, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, apparatus and / or device (e.g., magnetic discs, optical disks, memory, Programmable Logic Devices (PLDs)) used to provide machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. The term "machine-readable signal" refers to any signal used to provide machine instructions and / or data to a programmable processor.

[0200] To provide for interaction with a user, the systems and techniques described here can be implemented on a computer having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.

[0201] The systems and techniques described here can be implemented in a computing system that includes a back end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front end component (e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), the Internet, and a blockchain network.

[0202] The computer system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other.

[0203] In an example embodiment, there is also provided a computer program product, which when the instructions in the computer program product are executed by a processor of an electronic device, enables the electronic device to perform the above method.

[0204] It should be understood that the various forms of flow shown above can be re-ordered, added to, or deleted from without departing from the spirit of the present disclosure. For example, the steps recited in the present application can be executed in parallel, executed in sequence, or executed in different orders, as long as the desired results of the technology disclosed in the present application are achieved, and the present application is not limited herein.

[0205] The above detailed description does not limit the scope of the application. Various modifications, combinations, sub-combinations and alternatives can be made to the detailed embodiment disclosed herein without departing from the spirit and the principles of the application. Any modification, equivalent replacement or improvement made within the spirit and principles of the application shall fall within the scope of the application.

Claims

1. An access control method for a large-scale external knowledge base model, characterized in that, The documents in the external knowledge base are all labeled with access control tags, and the method includes: Obtain user questions and identify the intent behind those questions; When the intention is to query the plug-in knowledge base, based on the user's question and the first tag selected by the user, a query is performed in the knowledge base document set corresponding to the first tag in the plug-in knowledge base to obtain the query result corresponding to the first tag; the first tag is a tag selected from at least one permission tag owned by the user; the document types in the plug-in knowledge base include public documents and domain documents, and the knowledge base document corresponding to the first tag belongs to the public documents; When the query result corresponding to the first tag does not meet the library query feedback conditions, a second tag and / or a first candidate tag are obtained. The second tag includes a domain tag that has not been selected from at least one of the user's permission tags. The first candidate tag includes recommended tags obtained based on the user's historical questions and corresponding historical query documents. Based on the user question, the second tag and / or the first candidate tag, a query is performed in the knowledge base document set corresponding to the second tag and / or the first candidate tag respectively to obtain the query results corresponding to the second tag and / or the first candidate tag; the knowledge base document corresponding to the second tag belongs to the domain document, and the knowledge base document corresponding to the first candidate tag belongs to the historical query document. When the query results corresponding to the second tag and / or the first candidate tag meet the library query feedback conditions, the user is prompted to enable the second tag and / or the first candidate tag. The document information corresponding to the second tag and / or the first candidate tag is used by the large model to generate answer information to answer the user's question.

2. The method according to claim 1, characterized in that, The method further includes: When the query results corresponding to the second tag and / or the first candidate tag do not meet the library query feedback conditions, based on the user question, a query is performed in all domain documents of the plug-in knowledge base to obtain the over-privilege query results. When the over-permission query result meets the library query feedback conditions, the third tag corresponding to the document in the over-permission query result is obtained, and the user is prompted to apply for permission to the document corresponding to the third tag; the third tag includes domain tags that the user does not have permission for.

3. The method according to claim 1, characterized in that, Based on the user's question and the first tag selected by the user, a query is performed within the knowledge base document set corresponding to the first tag in the external knowledge base to obtain the query results corresponding to the first tag, including: The user question is matched with the text segments in the knowledge base document set corresponding to the first tag to obtain the target document segments with a relevance greater than or equal to the first threshold. The target document paragraph is used as the query result corresponding to the first tag.

4. The method according to claim 1, characterized in that, For both the publicly available documents and the domain-specific documents, different levels of administrators are assigned, and these administrators can be configured with different distribution permissions; the method further includes: In response to the user's temporary permission request based on an event ticket, the target administrator level corresponding to the temporary permission request is obtained based on the emergency type and urgency level in the event ticket and the user's job level. The temporary permission request is sent to the administrator at the target administrator level.

5. The method according to claim 1, characterized in that, The method further includes: Grant project managers the right to create shared permission groups. These shared permission groups are used by project managers to invite team members to join the shared permission groups, and the scope and validity period of the shared permission are set.

6. The method according to claim 1, characterized in that, The plug-in knowledge base also includes confidential documents. The confidential documents in the plug-in knowledge base constitute a confidential knowledge base. When the confidential documents are stored in the plug-in knowledge base, a separate table is created and an access control field is added. The method further includes: Determine whether to enable the confidential knowledge base; The process of querying the knowledge base document set corresponding to the first tag in the external knowledge base includes: The confidential knowledge base is activated, and a query is performed in the knowledge base document set corresponding to the first tag and in the confidential knowledge base.

7. The method according to claim 1, characterized in that, The method further includes: When the intent is to query data in a Structured Query Language (SQL) table, obtain the first table information for which the user has permissions; Based on the information in the first table and the user's question, an SQL query statement is generated using the large model; and the SQL query statement is confirmed with the user. Based on the SQL query statement, the data table corresponding to the information in the first table is queried to obtain the query result of the information in the first table; When the query result of the first table information does not meet the table query feedback conditions, the data table corresponding to the second table information is queried based on the SQL query statement to obtain the query result of the second table information; the second table information is table information that the user does not have permission to access but is not confidential. When the query result of the second table information meets the table query feedback conditions, the first table name in the query result of the second table information is fed back to the user to prompt the user to apply for the data table permission corresponding to the first table name. The data table corresponding to the first table name is used by the large model to generate corresponding answer information in combination with the user's question to answer the user's question.

8. The method according to claim 7, characterized in that, The step of querying the data table corresponding to the second table information based on the SQL query statement includes: Obtain a second candidate tag, which includes recommended tags obtained based on the user's historical questions and corresponding historical query data tables; The SQL query statement is used to query the data table corresponding to the second table information and the data table corresponding to the second candidate label.

9. An access control device for a large-scale external knowledge base model, characterized in that, The documents in the external knowledge base are all labeled with access control tags, and the device includes: An intent recognition module is used to acquire user questions and identify the intent behind those questions. The library matching module is used to, when the intent is to query the plug-in knowledge base, perform a query within the knowledge base document set corresponding to the first tag in the plug-in knowledge base based on the user's question and the first tag selected by the user, and obtain the query result corresponding to the first tag; the first tag is a tag selected from at least one permission tag owned by the user; the document types in the plug-in knowledge base include public documents and domain documents, and the knowledge base document corresponding to the first tag belongs to the public documents; The information recommendation module is used to obtain a second tag and / or a first candidate tag when the query result corresponding to the first tag does not meet the library query feedback conditions. The second tag includes a domain tag that has not been selected from at least one permission tag owned by the user. The first candidate tag includes recommended tags obtained based on the user's historical questions and corresponding historical query documents. The library matching module is further configured to perform a query within the knowledge base document set corresponding to each of the second tag and / or the first candidate tag based on the user question, the second tag, and / or the first candidate tag, to obtain the query results corresponding to the second tag and / or the first candidate tag; the knowledge base document corresponding to the second tag belongs to the domain document, and the knowledge base document corresponding to the first candidate tag belongs to the historical query document; The information feedback module is used to prompt the user to enable the second tag and / or the first candidate tag when the query results corresponding to the second tag and / or the first candidate tag meet the library query feedback conditions. The document information corresponding to the second tag and / or the first candidate tag is used by the large model to generate answer information to answer the user's question.

10. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; the processor executes the computer-executable instructions stored in the memory to implement the method as described in any one of claims 1-8.

11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-8.

12. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1-8.

Citation Information

Patent Citations

  • Document recommendation method and system, terminal and storage medium

    CN115630170A

  • Row-level data permission control method and system, computer equipment and storage medium

    CN117725617A