Access control method and device for model, electronic equipment and storage medium

By generating and saving user-specific vectors and matrices, access control of neural network model services is achieved, which solves the problems of high resource occupation and uncontrollable access time and number of times, and improves the security and stability of the service.

CN119945767APending Publication Date: 2025-05-06中国邮政储蓄银行股份有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510077203.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

Neural network model services face the problem of high resource utilization when providing services to the outside world, and it is difficult to effectively control the user's access time and number of times.

Method used

By generating and saving user-specific vectors and matrices, authentication of user identity is realized and controlled based on preset opening time and access restrictions. The specific method includes responding to the user's access request, generating and comparing vectors, judging the user's access rights, and updating the user's access times and offsets if necessary.

Benefits of technology

It effectively solves the risk problem caused by uncontrollable opening time and limiting the number of requests during neural network model services, ensures the security of user identity authentication information, and improves the security and stability of the overall model services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945767A_ABST
    Figure CN119945767A_ABST
Patent Text Reader

Abstract

The invention discloses an access control method and device used for a model, electronic equipment and a storage medium, and the method comprises the steps: responding to a first access service request of a user, generating a first vector based on the user, multiplying the first vector by a first matrix generated by a first offset according to a rule to obtain a second vector, the second vector is stored; in response to a second access service request of the user, receiving a third vector input by the user, the third vector being obtained by multiplying a second matrix generated by the first vector and a second offset according to a rule; judging whether the third vector is the same as the second vector or not; if yes, the user access authentication is passed, and the model service can be continuously accessed. According to the invention, the safety and stability of the whole model service are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of access control of model reasoning services, and in particular to an access control method, device, electronic device, and storage medium for a model. Background Art

[0002] In recent years, thanks to the massive increase in computing power and data resources, neural network models, with their powerful prediction, language understanding and generation capabilities, are gradually becoming an important force driving innovative applications. They have achieved excellent performance results in the fields of finance, medical care, education, etc., and are gradually being promoted and deployed in practical applications.

[0003] Currently, many neural network model service providers attempt to provide application services to commercial customers. However, in the process of providing external services through neural network models, they also face the challenge of high resource usage. Summary of the invention

[0004] The embodiments of the present application provide an access control method, device, electronic device, and storage medium for a model to implement access control of identity authentication, access time, access times, etc. of a network model.

[0005] The present application embodiment adopts the following technical solutions:

[0006] In a first aspect, an embodiment of the present application provides an access control method for a model, wherein the method comprises:

[0007] In response to a first access service request from a user, a first vector is generated based on the user, the first vector is multiplied by a first matrix generated according to a rule by a first offset to obtain a second vector, and the second vector is saved;

[0008] In response to a second access service request from the user, receiving a third vector input by the user, wherein the third vector is obtained by multiplying the first vector by a second matrix generated according to a rule by a second offset;

[0009] Determining whether the third vector is the same as the second vector;

[0010] If they are the same, the user access authentication is passed and the user can continue to access the model service.

[0011] In some embodiments, in response to the first access service request of the user, generating a first vector based on the user, multiplying the first vector by a first matrix generated according to a rule by a first offset to obtain a second vector, and saving the second vector includes:

[0012] In response to the user's first access service request, a vector is randomly selected from the initialized vector group and the vector key is k,1As the initial vector of the current user, the vector key k,1 The first subscript k represents the user's identification code, and the second subscript 1, 2, 3...i is the number of times the user currently accesses the service. Each user includes a corresponding set of vectors, offsets, and matrices.

[0013] In some embodiments, if they are the same, the user access authentication passes and the model service can continue to be accessed, further comprising:

[0014] Based on the preset service opening time setting, determine whether the current time is within the opening time period maxtime set by the model service publisher for the current user.

[0015] In some embodiments, if the two are the same, the user access authentication can continue to access the model service, including:

[0016] Based on the maxN setting of limiting the number of accesses, determine whether the number of accesses of the current user is less than the maximum number of accesses set by the service publisher for the current user;

[0017] If it is less than the maximum number of visits or the maximum number of visits is negative, the model service output and the vector key are i+1 Return to the user. Each time the user visits the service, the corresponding access count value of the user is increased by 1, and an offset value offset is randomly generated. i+1 And calculate the vector key i+2 and save it.

[0018] In some embodiments, the method further comprises:

[0019] When the model service is suspended, the key and offset information of all current users will be saved in the configuration file before the model service is shut down;

[0020] When the model service is restarted, the information is read again to continue providing services to users who have already used the service.

[0021] In some embodiments, before responding to the user's first access service request, the method further includes:

[0022] Initialize a set of vector keys as parameters and set the dimension of each vector in the vector group;

[0023] Randomly extract numbers from the model service parameter weights to generate an array A, wherein the array A is used to generate a matrix with the offset;

[0024] Set the service control opening time maxtime and limit the number of access times maxN for each user.

[0025] In some embodiments, in response to a second access service request from a user, receiving a third vector input by the user, wherein the third vector is obtained by multiplying a second matrix generated according to a rule based on the first vector and the second offset, comprises:

[0026] In response to a non-first access service request from a user, the third vector is obtained by multiplying the first vector and a second matrix generated according to a rule by a second offset, wherein the second offset and the second matrix are randomly generated when the user accesses the service for the non-first time, and the first vector is an initial vector of the user;

[0027] The third vector sent by the user is received.

[0028] In a second aspect, an embodiment of the present application further provides an access control device for a model, wherein the device comprises:

[0029] A first response module, configured to respond to a first access service request of a user, generate a first vector based on the user, multiply the first vector by a first matrix generated according to a rule by a first offset to obtain a second vector, and save the second vector;

[0030] A second response module, configured to respond to a second access service request of the user and receive a third vector input by the user, wherein the third vector is obtained by multiplying the first vector by a second matrix generated according to a rule by the second offset;

[0031] A judging module, used for judging whether the third vector is the same as the second vector;

[0032] The authentication module is used to determine if the user has passed the authentication and can continue to access the model service.

[0033] In a third aspect, an embodiment of the present application further provides an electronic device, comprising: a processor; and a memory arranged to store computer executable instructions, wherein the executable instructions, when executed, cause the processor to perform the above method.

[0034] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, which stores one or more programs. When the one or more programs are executed by an electronic device including multiple application programs, the electronic device executes the above method.

[0035] At least one of the above technical solutions adopted in the embodiments of the present application can achieve the following beneficial effects: In response to the user's first access service request, a first vector is generated based on the user. A second vector is obtained by multiplying the first matrix generated according to the rule based on the first vector and the first offset, and the second vector is saved on the server. In response to the user's second access service request, a third vector input by the user is received, and the third vector is obtained by multiplying the second matrix generated according to the rule based on the first vector and the second offset. By judging whether the third vector is the same as the second vector; if they are the same, the user access authentication passes and can continue to access the model service. Through the above method, the user request and the model service are highly coupled, which can effectively solve a series of risk problems caused by uncontrollable opening time and limit on the number of requests when calling the neural network model service. At the same time, the security of user identity authentication information and methods is guaranteed from a mechanism perspective, and the security and stability of the overall model service are improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0037] Figure 1 A flowchart of an access control method for a model in an embodiment of the present application;

[0038] Figure 2 A schematic diagram of the implementation principle of the access control method for the model in the embodiment of the present application;

[0039] Figure 3 It is a sample schematic diagram of generating the upper matrix based on array A and offset in the access control method of the model in the embodiment of the present application;

[0040] Figure 4 The process of generating a matrix in the access control method of the model in the embodiment of the present application, and generating the next vector by multiplying the current vector by the matrix and repeating the process;

[0041] Figure 5 It is a schematic diagram of the structure of the access control device of the model in the embodiment of the present application;

[0042] Figure 6 This is a schematic diagram of the structure of an electronic device in an embodiment of the present application. DETAILED DESCRIPTION

[0043] In order to make the purpose, technical solution and advantages of the present application clearer, the technical solution of the present application will be clearly and completely described below in combination with the specific embodiments of the present application and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present application.

[0044] Since neural network models usually contain hundreds of millions of parameters, running such models requires not only high-performance computing hardware as support, such as high-end GPU servers, but also the need to maintain the model resident in video memory in order to ensure response speed and user experience, which further increases the occupation of server resources. After these providers open neural network model services to customer systems, there is a need to control the time and number of times users use the services when providing model prediction services to customers. For example, it is hoped that the access time and maximum number of visits to the service can be controlled. The above problems urgently need to introduce technical methods for service access restrictions and solve them by further optimizing relevant measures in the service call process.

[0045] In some solutions in the related art, the service provider sets IP or IP network segments that are prohibited for users to access on the server side. When the IP corresponding to the access request received by the server is the prohibited IP or IP network segment, the access request is rejected. The disadvantage of this solution is that the relationship between the user and the service is weak and the degree of mutual dependence is not high. The user can bypass the prohibited IP or IP network segment and request the service normally by simply changing the IP or using a proxy IP.

[0046] In some other schemes in the related technology, when accessing, the user passes in the authorization credentials and service identification for authentication. The server determines whether the authorization credentials and service identification match the requested service and the service status is normal, then the authentication is passed, otherwise the request fails; the problem with this method is that the user's authentication credentials may be stolen, and the identity information stored by the server may be stolen, resulting in illegal access or a substantial violation of the user's access limit or time period.

[0047] Based on the above situation, the present application provides an access control method for model reasoning service, where the model generally refers to a large-scale neural network. The core computing part of the present application uses a large number of matrix operations to increase the speed and is naturally adapted to parallel computing.

[0048] Based on the internal parameters of the neural network model, the user identity is identified each time the service is called up, allowing the service provider to flexibly set personalized access time and maximum number of visits based on each user, while ensuring the security and controllability of the neural network model service.

[0049] The technical solutions provided by various embodiments of the present application are described in detail below in conjunction with the accompanying drawings.

[0050] The present application embodiment provides an access control method for a model, such as Figure 1 As shown, a schematic flow chart of an access control method for a model in an embodiment of the present application is provided, and the method at least includes the following steps S110 to S140:

[0051] Step S110, in response to a first access service request from a user, generating a first vector based on the user, multiplying the first vector by a first matrix generated according to a rule using a first offset to obtain a second vector, and saving the second vector.

[0052] "User" refers to a user who needs to access a neural network model, a model generally refers to a neural network, and a neural network model service provider attempts to provide application services to commercial customers. At the service end, according to the user's first access service request, a first vector is generated according to the user.

[0053] It can be understood that the "first access service request" refers to the user's first or initial access service request. The first vector generated by the user can be used as the user's initialization vector. The server multiplies the first vector and the first offset according to the first matrix generated according to the rule to obtain the second vector, and saves the second vector on the server without sending it to the user.

[0054] It should be noted that the "first offset" and "first matrix" are the offsets and matrices randomly assigned when the user first accesses. For example, the user randomly agrees on the offset offset1, and its value range is a non-zero integer less than the length of array A. In subsequent use, array A and offset of f set i Will be used to generate the square matrix M i .

[0055] Step S120 , in response to the user's second access service request, receiving a third vector input by the user, wherein the third vector is obtained by multiplying the first vector by a second matrix generated according to a rule by the second offset.

[0056] It can be understood that the "second access service request" refers to a non-first access service request by the user. That is, when the user issues a call request, assuming that the user calls the model for the i-th time (i is greater than or equal to 1) to request access to the service, the vector key entered by the user is i The random offset value corresponding to the user i The matrix M generated by the rule iThe "third vector" is obtained by multiplying the first vector and the second matrix generated according to the rule of the second offset, and the third vector needs to be compared with the second vector.

[0057] Step S130, determining whether the third vector is the same as the second vector.

[0058] key′ i With key i+1 Compare and determine whether the two result vectors are the same.

[0059] Among them, key′ i It is based on user input and is calculated according to the same rules. i+1 It is calculated by the server.

[0060] Step S140: If they are the same, the user access authentication is passed and the user can continue to access the model service.

[0061] If the two vectors are the same, the user identity authentication is successful, and the service proceeds to the next step normally. If the user access authentication is successful, the model service can continue to be accessed. Otherwise, this request fails.

[0062] Through the above method, based on the internal parameters of the neural network model, the user identity is identified each time the service is called up, so that the service provider can flexibly set personalized access time and maximum number of visits based on each user, while ensuring the security and controllability of the neural network model service.

[0063] Through the above method, user requests are highly coupled with model services, which can effectively solve a series of risk problems caused by uncontrollable opening time and limit on the number of requests when calling neural network model services. At the same time, it ensures the security of user identity authentication information and methods from a mechanism perspective, thereby improving the security and stability of the overall model service.

[0064] Through the above method, the vector key used for user identification i With the matrix M i All are stored in the computer memory. Dynamic random access memory, as a memory medium, will automatically lose data after power failure, that is, data will not reside in the storage medium for a long time, which can effectively reduce data security risks.

[0065] By the above method, the matrix M i It comes from the weight parameters of the neural network model. The number of neural network model parameters is large, up to tens of billions or even hundreds of billions, which can support the construction of a large enough and random enough M each time it is used. iIn addition, the neural network model parameters are invisible to the outside world on the server side, making them difficult to crack, which can effectively reduce the risk of data leakage. The server and the user each retain a portion of the identity key. Even if an attacker can decipher the key of one party, it is not enough to crack the defense system and break through the access restrictions.

[0066] Different from related technologies, in order to ensure response speed and user experience, it is often necessary to maintain the model resident in the video memory, which further increases the occupation of server resources. In addition, after the provider opens the neural network model service to the client system, there is a problem of the need to control the time and frequency of user use of the service when providing model prediction services to customers. Through the above method, based on the internal parameters of the neural network model, the user identity is identified each time the service is called up, so that the service provider can provide access control based on each user.

[0067] In one embodiment of the present application, in response to the user's first access service request, generating a first vector based on the user, multiplying the first vector by a first matrix generated according to a rule by a first offset to obtain a second vector, and saving the second vector, including: in response to the user's first access service request, randomly taking a vector from the initialized vector group, and storing the vector key k,1 As the initial vector of the current user, the vector key k,1 The first subscript k represents the user's identification code, and the second subscript 1, 2, 3...i is the number of times the user currently accesses the service. Each user includes a corresponding set of vectors, offsets, and matrices.

[0068] like Figure 2 As shown in the figure, when a user k visits the service for the first time, a vector is randomly selected from the initialized vector group and the random n-dimensional vector key is agreed with the user. k,1 is the initial vector of the user, where the vector key k,1 The first digit k in the subscript represents the identification code of the user, and the second digit 1, 2, 3, ..., i represents the current service access times of the user. This initial vector can be passed into the service program in the form of a command line or a configuration file.

[0069] Each user has his or her own set of vectors, offsets, and matrices, and the processing logic of each set is the same. k,i Referred to as key i , offset k,i Abbreviated as offset i , the matrix M k,i Abbreviated as M i .

[0070] like Figure 3 As shown in the figure, the user randomly agrees on the offset offset1, whose value range is a non-zero integer less than the length of array A. In subsequent use, array A and offset offset i Will be used to generate the square matrix M i (an upper triangular matrix of size n×n, necessarily full rank), its generation rule is to start from the offset of the array i Start by filling the square matrix M in order i For each element in , if the elements in array A are exhausted, the array will be cycled again from the first element. i It is temporarily generated each time it is used and is not saved.

[0071] like Figure 4 As shown, the vector key1 is multiplied by the matrix M1 generated according to the rule by the offset value offset1. To avoid the appearance of 0 components in the result vector, all 0 components are changed to 1, and the excess elements are processed according to the maximum and minimum value rules. Finally, the vector key2 is generated. This vector is saved on the server side and is not sent to the user.

[0072] When a user issues a call request, assuming that the user calls the model for the i-th time (i is greater than or equal to 1) to request access to the service, let the vector key entered by the user i The random offset value corresponding to the user i The matrix M generated by the rule i Multiply to generate a vector. Similarly, avoid the appearance of 0 components in this vector. Change all components 0 in the result vector to 1, and process the excess elements according to the maximum and minimum value rules of the vector to generate the result vector key′ i . i With key i+1 Compare and determine whether the two result vectors are the same. To determine whether the two vectors are the same, you can subtract the two vectors and then determine whether the vector modulus is 0. You can also use other vector calculation methods. If the two vectors are the same, the user identity authentication is passed and the service proceeds to the next step normally. Otherwise, this request fails.

[0073] In one embodiment of the present application, if they are the same, the user access authentication passes and the user can continue to access the model service, which also includes: based on the preset service opening time setting, determining whether the current time is within the open time period maxtime set by the model service publisher for the current user.

[0074] The service request of the service caller enters the service opening time judgment step. At this time, based on the service opening time setting, it is judged whether the current time is within the open time period maxtime set by the service publisher for the user. If it is within the open time period or maxtime is a negative value, it proceeds to the next step, otherwise the request fails.

[0075] In one embodiment of the present application, if the same, the user access authentication can continue to access the model service, including: based on the setting of limiting the number of accesses maxN, judging whether the number of accesses of the current user is less than the maximum number of accesses set by the service publisher for the current user; if it is less than the maximum number of accesses or the maximum number of accesses is a negative value, the model service output and the vector key i+1 Return to the user. Each time the user visits the service, the corresponding access count value of the user is increased by 1, and an offset value offset is randomly generated. i+1 And calculate the vector key i+2 and save it.

[0076] When the service caller's service request enters the access limit judgment phase, the access limit setting determines whether the current user's access count i is less than the maximum access count maxN set by the service publisher for this user. If it is less than the maximum access count or maxN is a negative value, the neural network model output and vector key i+1 Return to the user and randomly generate an offset value i+1 , calculate the vector key i+2 And save it on the server side, and enter the next round of service access process, otherwise the request fails and returns the error code '0'. Every time a user accesses a service, the corresponding access count value of the user is increased by 1. When a user k accesses the service for the first time, a vector is randomly selected from the initialized vector group, and the random n-dimensional vector key is agreed with the user. k,1 is the initial vector of the user.

[0077] In one embodiment of the present application, the method also includes: when the model service is suspended, the key and offset information of all current users are saved in a configuration file before the model service is shut down; when the model service is restarted, if the service needs to be suspended, the key and offset information of all current users are saved in a configuration file before the service is shut down, and when the service is restarted, this information is read in again to continue to provide services to users who have used the service.

[0078] The above mechanism means that when the service is shut down and restarted, there is no need to re-agree on the key with the existing users. The service provider can also choose to re-agree on the initial vector with the user to provide services again. If the service is shut down, no new vector will be obtained, and the correct vector in the server will not be updated. When the information is read in again, the service will continue to be provided to users who have already used the service.

[0079] In one embodiment of the present application, before responding to the user's first access service request, it also includes: initializing a set of vectors key as parameters, and setting the dimension of each vector in the vector group; randomly taking numbers from the model service parameter weights to generate an array A, and the array A is used to generate a matrix with the offset; setting the service control opening time maxtime for each user and limiting the number of accesses maxN.

[0080] Before the user initially registers, that is, before the model service is released, the number of access restrictions and model opening hours can be set for each user. Before the service is released, a custom control opening time and limited number of accesses are introduced. When the service is initialized, a sufficient set of vector keys is initialized as parameters. Based on the scale of model parameters, security and computational cost are weighed comprehensively, and the dimension of each vector in the vector group can be set to an appropriate value, such as 128. Then each vector in the vector group is checked. If there is a component of 0 in the vector, it is regenerated (due to the principle of matrix operation, the presence of 0 components in the vector will invalidate the parameter column corresponding to the 0 component in the matrix M1 during subsequent multiplication calculations) until there are no 0 components in all vectors.

[0081] For each element in all the vectors involved in the embodiments of the present application, there is a maximum and minimum range. If an element is found to exceed the upper limit after each random generation, number acquisition or calculation step of the vector and the matrix, the element should be repeatedly subtracted from the upper limit of the maximum range and then checked until the element value is within the normal range (if the element is less than the lower limit, the minimum range lower limit (negative number) should be repeatedly subtracted and checked until the element is within the normal range). This rule is referred to as the maximum and minimum value rule of the vector.

[0082] In addition, it is necessary to randomly select numbers from the neural network parameter weights to generate array A (constructing a square array also includes the authentication step). When generating array A, all parameters that are 0 in the neural network should be skipped to ensure that it does not contain any 0 elements, and after array A is generated, each element in it should be scaled to ensure that its value range is within a reasonable range. The length of array A should be a reasonable value, such as 65536 bits. Each client (assuming it is k) will use one vector keyk1 in the vector group as the initial vector. Different initial vectors are agreed upon for different users, which will allow the model service to support multi-concurrency.

[0083] In addition, the service control opening time maxtime and the access limit maxN for each user should be set to support the restriction of user access from the perspective of the service caller. The time setting period is accurate to seconds. If there is no restriction on the service opening time or access limit for a user, the corresponding parameters can be set to negative values.

[0084] Vector key for user identification i With the matrix M i All are stored in the computer memory. Dynamic random access memory, as a memory medium, will automatically lose data after power failure, that is, data will not reside in the storage medium for a long time, which can effectively reduce data security risks. i It comes from the weight parameters of the neural network model. The number of neural network model parameters is large, up to tens of billions or even hundreds of billions, which can support the construction of a large enough and random enough M each time it is used. i .

[0085] In one embodiment of the present application, in response to a user's second access service request, a third vector input by the user is received, and the third vector is obtained by multiplying a second matrix generated according to a rule based on a first vector and a second offset, including: in response to a user's non-first access service request, the third vector is obtained by multiplying a second matrix generated according to a rule based on the first vector and a second offset, the second offset and the second matrix are randomly generated when the access is not the first time, and the first vector is the user's initial vector; and the third vector sent by the user is received.

[0086] like Figure 2 As shown in the figure, when a user issues a call request, assuming that the user calls the model for the i-th time (i is greater than or equal to 1) to request access to the service, the vector key entered by the user is i The random offset value corresponding to the user i The matrix M generated by the rule i Multiply to generate a vector. Similarly, avoid the appearance of 0 components in this vector. Change all components 0 in the result vector to 1, and process the excess elements according to the maximum and minimum value rules of the vector to generate the result vector key′ i . i With key i+1 Compare and determine whether the two result vectors are the same.

[0087] The present application embodiment also provides an access control device 500 for a model, such as Figure 5 As shown, a schematic diagram of the structure of an access control device for a model in an embodiment of the present application is provided. The access control device 500 for a model at least includes: a first response module 510, a second response module 520, a judgment module 530 and an authentication module 540, wherein:

[0088] In one embodiment of the present application, the first response module 510 is specifically used to: respond to a first access service request from a user, generate a first vector based on the user, multiply the first vector by a first matrix generated according to a rule using a first offset to obtain a second vector, and save the second vector.

[0089] "User" refers to a user who needs to access a neural network model, a model generally refers to a neural network, and a neural network model service provider attempts to provide application services to commercial customers. At the service end, according to the user's first access service request, a first vector is generated according to the user.

[0090] It can be understood that the "first access service request" refers to the user's first or initial access service request. The first vector generated by the user can be used as the user's initialization vector. The server multiplies the first vector and the first offset according to the first matrix generated according to the rule to obtain the second vector, and saves the second vector on the server without sending it to the user.

[0091] It should be noted that the "first offset" and "first matrix" are the offset and matrix randomly assigned when the user first accesses the database. For example, the user randomly agrees on an offset offset1, whose value range is a non-zero integer less than the length of array A. In subsequent use, array A and offset offset i Will be used to generate the square matrix M i .

[0092] In one embodiment of the present application, the second response module 520 is specifically used to: respond to the user's second access service request, receive a third vector input by the user, and the third vector is obtained by multiplying the first vector and the second offset according to the rule-generated second matrix.

[0093] It can be understood that the "second access service request" refers to a non-first access service request by the user. That is, when the user issues a call request, assuming that the user calls the model for the i-th time (i is greater than or equal to 1) to request access to the service, the vector key entered by the user is i The random offset value corresponding to the user i The matrix M generated by the rule i The "third vector" is obtained by multiplying the first vector and the second matrix generated according to the rule of the second offset, and the third vector needs to be compared with the second vector.

[0094] In one embodiment of the present application, the judgment module 530 is specifically used to: judge whether the third vector is the same as the second vector.

[0095] key′ i With key i+1 Compare and determine whether the two result vectors are the same.

[0096] Among them, key′ i It is based on user input and is calculated according to the same rules. i+1 It is calculated by the server.

[0097] In one embodiment of the present application, the authentication module 540 is specifically used to: if the two are the same, the user access authentication is passed and the user can continue to access the model service.

[0098] If the two vectors are the same, the user identity authentication is successful, and the service proceeds to the next step normally. If the user access authentication is successful, the model service can continue to be accessed. Otherwise, this request fails.

[0099] In one embodiment of the present application, the first response module 510 is further configured to:

[0100] In response to the user's first access service request, a vector is randomly selected from the initialized vector group and the vector key is k,1 As the initial vector of the current user, the vector key k,1 The first subscript k represents the user's identification code, and the second subscript 1, 2, 3...i is the number of times the user currently accesses the service. Each user includes a corresponding set of vectors, offsets, and matrices.

[0101] In one embodiment of the present application, the authentication module 540 is also used to

[0102] Based on the preset service opening time setting, determine whether the current time is within the opening time period maxtime set by the model service publisher for the current user.

[0103] In one embodiment of the present application, the authentication module 540 is also used to

[0104] Based on the maxN setting of limiting the number of accesses, determine whether the number of accesses of the current user is less than the maximum number of accesses set by the service publisher for the current user;

[0105] If it is less than the maximum number of visits or the maximum number of visits is negative, the model service output and the vector key are i+1 Return to the user. Each time the user visits the service, the corresponding access count value of the user is increased by 1, and an offset value offset is randomly generated. i+1 And calculate the vector key i+2 and save it.

[0106] In one embodiment of the present application, it further includes: a service suspension module for

[0107] When the model service is suspended, the key and offset information of all current users will be saved in the configuration file before the model service is shut down;

[0108] When the model service is restarted, the information is read again to continue providing services to users who have already used the service.

[0109] In one embodiment of the present application, a pre-configuration module is also included for

[0110] Initialize a set of vector keys as parameters and set the dimension of each vector in the vector group;

[0111] Randomly extract numbers from the model service parameter weights to generate an array A, wherein the array A is used to generate a matrix with the offset;

[0112] Set the service control opening time maxtime and limit the number of access times maxN for each user.

[0113] In one embodiment of the present application, the second response module 520 is further used to

[0114] In response to a non-first access service request from a user, the third vector is obtained by multiplying the first vector and a second matrix generated according to a rule by a second offset, wherein the second offset and the second matrix are randomly generated when the user accesses the service for the non-first time, and the first vector is an initial vector of the user;

[0115] The third vector sent by the user is received.

[0116] It can be understood that the above-mentioned access control device for a model can implement the various steps of the access control method for a model provided in the aforementioned embodiment. The relevant explanations about the access control method for a model are applicable to the access control device for a model and will not be repeated here.

[0117] Figure 6 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present application. Figure 6 At the hardware level, the electronic device includes a processor, and optionally also includes an internal bus, a network interface, and a memory. The memory may include a memory, such as a high-speed random access memory (RAM), and may also include a non-volatile memory (non-volatile memory), such as at least one disk storage. Of course, the electronic device may also include hardware required for other services.

[0118] The processor, network interface and memory can be interconnected through an internal bus, which can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 6 Only one bidirectional arrow is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0119] The memory is used to store the program. Specifically, the program may include a program code, and the program code includes a computer operation instruction. The memory may include a memory and a non-volatile memory, and provides instructions and data to the processor.

[0120] The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it, forming an access control device for the model at the logical level. The processor executes the program stored in the memory and is specifically used to perform the following operations:

[0121] In response to a first access service request from a user, a first vector is generated based on the user, the first vector is multiplied by a first matrix generated according to a rule by a first offset to obtain a second vector, and the second vector is saved;

[0122] In response to a second access service request from the user, receiving a third vector input by the user, wherein the third vector is obtained by multiplying the first vector by a second matrix generated according to a rule by a second offset;

[0123] Determining whether the third vector is the same as the second vector;

[0124] If they are the same, the user access authentication is passed and the user can continue to access the model service.

[0125] The above application Figure 1The method for executing the access control device for the model disclosed in the illustrated embodiment can be applied to a processor or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by an integrated logic circuit of hardware in the processor or an instruction in the form of software. The above processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The methods, steps and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in the embodiments of the present application can be directly embodied as a hardware decoding processor for execution, or a combination of hardware and software modules in the decoding processor for execution. The software module can be located in a storage medium mature in the art, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware.

[0126] The electronic device may also perform Figure 1 A method for executing an access control device for a model in Figure 1 The functions of the illustrated embodiment will not be described in detail in the embodiments of the present application.

[0127] The present application also provides a computer-readable storage medium, which stores one or more programs, wherein the one or more programs include instructions, which, when executed by an electronic device including multiple application programs, enable the electronic device to execute Figure 1 The method executed by the access control device for the model in the illustrated embodiment is specifically used to execute:

[0128] In response to a first access service request from a user, a first vector is generated based on the user, the first vector is multiplied by a first matrix generated according to a rule by a first offset to obtain a second vector, and the second vector is saved;

[0129] In response to a second access service request from the user, receiving a third vector input by the user, wherein the third vector is obtained by multiplying the first vector by a second matrix generated according to a rule by a second offset;

[0130] Determining whether the third vector is the same as the second vector;

[0131] If they are the same, the user access authentication is passed and the user can continue to access the model service.

[0132] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0133] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0134] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0135] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0136] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0137] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0138] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0139] It should also be noted that the terms "include", "comprising" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of further restrictions, an element defined by the sentence "comprising a ..." does not exclude the presence of other identical elements in the process, method, commodity or device comprising the element.

[0140] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0141] The above is only an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.

Claims

1. A method for access control of a model, wherein: The method comprises: In response to a first access service request from a user, a first vector is generated based on the user, the first vector is multiplied by a first matrix generated according to a rule by a first offset to obtain a second vector, and the second vector is saved; In response to a second access service request from the user, receiving a third vector input by the user, wherein the third vector is obtained by multiplying the first vector by a second matrix generated according to a rule by a second offset; Determining whether the third vector is the same as the second vector; If they are the same, the user access authentication is passed and the user can continue to access the model service.

2. The method of claim 1, wherein: The method of responding to a first access service request from a user, generating a first vector based on the user, multiplying the first vector by a first matrix generated according to a rule by a first offset to obtain a second vector, and saving the second vector includes: In response to the user's first access service request, a vector is randomly selected from the initialized vector group and the vector key is k1 As the initial vector of the current user, the vector key k,1 The first subscript k represents the user's identification code, and the second subscript 1, 2, 3...i is the number of times the user currently accesses the service. Each user includes a corresponding set of vectors, offsets, and matrices.

3. The method of claim 2, wherein: If they are the same, the user access authentication is passed and the user can continue to access the model service, which also includes: Based on the preset service opening time setting, determine whether the current time is within the opening time period maxtime set by the model service publisher for the current user.

4. The method of claim 2, wherein: If they are the same, the user has passed the authentication and can continue to access the model service, including: Based on the maxN setting of limiting the number of accesses, determine whether the number of accesses of the current user is less than the maximum number of accesses set by the service publisher for the current user; If it is less than the maximum number of visits or the maximum number of visits is negative, the model service output and the vector key are i+1 Return to the user. Each time the user visits the service, the corresponding access count value of the user is increased by 1, and an offset value offset is randomly generated. i+1 And calculate the vector key i+2 and save it.

5. The method according to claim 1, further comprising: When the model service is suspended, the key and offset information of all current users will be saved in the configuration file before the model service is shut down; When the model service is restarted, the information is read again to continue providing services to users who have already used the service.

6. The method of claim 1, wherein: Before responding to the user's first access service request, the method further includes: Initialize a set of vector keys as parameters and set the dimension of each vector in the vector group; Randomly extract numbers from the model service parameter weights to generate an array A, wherein the array A is used to generate a matrix with the offset; Set the service control opening time maxtime and limit the number of access times maxN for each user.

7. The method of claim 1, wherein: In response to a second access service request from the user, receiving a third vector input by the user, wherein the third vector is obtained by multiplying the first vector by a second matrix generated according to a rule by the second offset, including: In response to a non-first access service request from a user, the third vector is obtained by multiplying the first vector and a second matrix generated according to a rule by a second offset, wherein the second offset and the second matrix are randomly generated when the user accesses the service for the non-first time, and the first vector is an initial vector of the user; The third vector sent by the user is received.

8. An access control device for a model, wherein: The device comprises: A first response module, configured to respond to a first access service request of a user, generate a first vector based on the user, multiply the first vector by a first matrix generated according to a rule by a first offset to obtain a second vector, and save the second vector; A second response module, configured to respond to a second access service request of the user and receive a third vector input by the user, wherein the third vector is obtained by multiplying the first vector by a second matrix generated according to a rule by the second offset; A judging module, used for judging whether the third vector is the same as the second vector; The authentication module is used to determine if the user has passed the authentication and can continue to access the model service.

9. An electronic device, comprising: processor; as well as A memory arranged to store computer executable instructions, which when executed cause the processor to perform the method of any one of claims 1 to 7.

10. A computer-readable storage medium storing one or more programs, which, when executed by an electronic device including a plurality of application programs, causes the electronic device to execute any one of the methods of claims 1 to 7.