Service providing method and device, storage medium and electronic device

By implementing identity authentication and encrypting databases to generate security prompt words in large language models, the problem that the model may disclose user privacy when processing sensitive information is solved, achieving higher privacy and security.

CN120124099APending Publication Date: 2025-06-10HUANENG CLEAN ENERGY RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510185135.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-19
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

Large language models may leak sensitive information in training data during training, causing user privacy and security to be compromised.

Method used

By obtaining the identity authentication information of the target object and verifying that it logs in successfully, obtaining the instructions it inputs and generating corresponding prompt words from the preset encrypted database based on the semantic information of the instructions to generate secure instructions, thereby avoiding the leakage of private data.

Benefits of technology

It effectively protects users' privacy and security, prevents sensitive information from being accidentally leaked in model response, and improves the security of data processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120124099A_ABST
    Figure CN120124099A_ABST
Patent Text Reader

Abstract

The invention discloses a service providing method and device, a storage medium, an electronic device and a computer program product, and the method comprises the steps: obtaining identity authentication information of a target object, and determining that the target object is successfully logged in under the condition that the identity authentication information passes verification; under the condition that the target object is successfully logged in, obtaining a first instruction input by the target object; according to the semantic information of the first instruction, a corresponding prompt word is generated from a preset first database to obtain a second instruction, and the preset first database comprises encrypted target object data; and in response to the second instruction, providing a corresponding service. Isolation and de-identification are carried out through the first database, it is guaranteed that the generated second instruction comprises a safe prompt word, and leakage of private data is avoided. The second instruction is composed of the safe prompt words generated by the first database, so that the privacy data of the target object cannot be leaked in the provided service, and the privacy security of the target object is protected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of service access. Specifically, it relates to a method and apparatus for providing a service, a storage medium, an electronic device, and a computer program product. Background Art

[0002] In today's era of high integration of digitalization and the Internet, the collection, storage, and analysis of data have become increasingly common. Especially in critical fields such as the electricity spot market, the volume of data transmission and processing is huge, and it involves highly sensitive information, such as real-time transaction data, user electricity consumption patterns, geographical locations, etc. With the evolution of technology, especially the wide application of large language models (LLMs), the efficiency and intelligence level of data processing have been significantly improved. However, while enjoying the benefits of these technologies, the risk of privacy leakage is also faced.

[0003] During the training process of large language models, they can "memorize" a large amount of text data. This memorization ability may inadvertently lead to the leakage of sensitive information in the training data in the model's response in some cases. For example, if the historical transaction records of the electricity spot market are used to train the model, attackers may use special prompt techniques to induce the model to output sensitive information contained in the training data, such as the electricity consumption or transaction records of specific users. Therefore, how to protect the privacy and security of users is a problem that needs to be solved currently. Summary of the Invention

[0004] Embodiments of this application provide a method and apparatus for providing a service, a storage medium, an electronic device, and a computer program product.

[0005] According to one aspect of the embodiments of this application, a method for providing a service is provided, including: obtaining the identity authentication information of a target object, and determining that the target object has logged in successfully when the identity authentication information is verified; when the target object has logged in successfully, obtaining a first instruction input by the target object; generating a corresponding prompt word from a preset first database according to the semantic information of the first instruction to obtain a second instruction, where the preset first database includes encrypted target object data; and providing a corresponding service in response to the second instruction.

[0006] In an exemplary embodiment, obtaining the identity authentication information of a target object and determining that the target object has logged in successfully when the identity authentication information is verified includes: obtaining the identity identification information and timestamp information of the target object, where the identity authentication information includes the identity identification information and timestamp information; and determining that the target object has logged in successfully when both the identity identification information and the timestamp information are verified.

[0007] In an exemplary embodiment, when both the identity identification information and the timestamp information pass the verification, it is determined that the target object has successfully logged in, including: obtaining a first moment corresponding to the timestamp information; when it is determined that the time difference between the first moment and a second moment for verifying the timestamp information is less than or equal to a time threshold, determining that the timestamp information passes the verification; when it is determined that the timestamp information passes the verification, determining whether the identity identification information is recorded in a preset second database; and when it is determined that the identity identification information is recorded in the preset second database, determining that the identity identification information passes the verification.

[0008] In an exemplary embodiment, after determining that the identity identification information passes the verification when it is determined that the identity identification information is recorded in the preset second database, the method further includes determining a target server that the target object needs to access; sending an access request to the target server; and when it is determined that the time difference between the second moment and a third moment when the target server receives the access request is less than or equal to the time threshold, allowing the target object to access the target server.

[0009] In an exemplary embodiment, before obtaining the identity identification information and the timestamp information of the target object, the method further includes obtaining a biometric feature, an account, and a password input by the target object; performing an encryption process on the account and password of the target object and performing a blurring process on the biometric feature of the target object to generate the identity identification information of the target object; and authenticating the identity identification information, where the target object whose identity identification information passes the authentication is a legitimate target object.

[0010] In an exemplary embodiment, before selecting a corresponding prompt word in a preset first database according to the semantic information of the first instruction to generate a second instruction, the method further includes obtaining encrypted data to be encrypted of multiple target objects; encrypting the encrypted data to be encrypted of the multiple target objects by using a preset encryption algorithm to obtain an encrypted data set; and performing a normalization process on the encrypted data set to obtain the first database.

[0011] On the other hand, the present application provides a service providing device, including: a login verification module, configured to obtain identity authentication information of a target object and determine that the target object has successfully logged in when the identity authentication information passes the verification; an instruction obtaining module, configured to obtain a first instruction input by the target object when the target object has successfully logged in; an instruction generating module, configured to select a corresponding prompt word in a preset first database according to the semantic information of the first instruction to generate a second instruction, where the preset first database includes encrypted target object data; and a service providing module, configured to provide a corresponding service in response to the second instruction.

[0012] According to another aspect of the embodiments of the present application, there is also provided a computer-readable storage medium storing a computer program, wherein the computer program is configured to execute the service providing method described above when running.

[0013] According to another aspect of the embodiments of the present application, there is also provided an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the above-mentioned processor executes the above-mentioned service providing method through the computer program.

[0014] According to another aspect of the embodiments of the present application, there is also provided a computer program product including a computer program, and the steps of the methods described in the various embodiments of the present application are implemented when the computer program is executed by a processor.

[0015] For the above-mentioned service providing method, first, the identity authentication information of the target object is obtained. When the identity authentication information is verified to be passed, it is determined that the target object has logged in successfully, thereby first verifying the identity of the target object. Only when the login is successful can subsequent access be carried out, improving security. Then, 3. obtain the first instruction input by the target object, and generate a corresponding prompt word from a preset first database according to the semantic information of the first instruction to obtain a second instruction. Thus, through de-identification and semantic analysis technologies, it is ensured that the large language model can generate accurate responses. Through isolation and de-identification by the first database, it is ensured that the generated second instruction includes safe prompt words, avoiding the leakage of private data. Then, in response to the second instruction, the corresponding service is provided. Since the second instruction is composed of safe prompt words generated by the first database, the privacy data of the target object will not be leaked in the provided service, protecting the privacy security of the target object. Description of the Drawings

[0016] The drawings here are incorporated into the specification and constitute a part of this specification, showing the embodiments in line with the present application, and are used together with the specification to explain the principles of the present application.

[0017] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0018] Figure 1 is the hardware structure block diagram of the service providing method in the embodiments of the present application;

[0019] Figure 2 is the flowchart of a service providing method according to the embodiments of the present application;

[0020] Figure 2a It is a schematic diagram of a method for providing a service according to an embodiment of the present application;

[0021] Figure 3 It is the second flowchart of a method for providing a service according to an embodiment of the present application;

[0022] Figure 4 It is the third flowchart of a method for providing a service according to an embodiment of the present application;

[0023] Figure 5 It is the fourth flowchart of a method for providing a service according to an embodiment of the present application;

[0024] Figure 6 It is the fifth flowchart of a method for providing a service according to an embodiment of the present application;

[0025] Figure 7 It is the sixth flowchart of a method for providing a service according to an embodiment of the present application;

[0026] Figure 8 It is a structural block diagram of a device for providing a service according to an embodiment of the present application. Detailed implementation manners

[0027] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0028] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily need to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0029] The method embodiments provided in the embodiments of the present application can be executed on a computer terminal or a similar computing device. Taking running on a computer terminal as an example,Figure 1 It is a hardware block diagram of a computer terminal for the service providing method according to an embodiment of the present application. As Figure 1 shown, the computer terminal may include one or more ( Figure 1 only one is shown in the figure) processors 102 (the processor 102 may include, but is not limited to, a microprocessor (abbreviated as MPU) or a programmable logic device (abbreviated as PLD)) and a memory 104 for storing data. In an exemplary embodiment, the above computer terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only schematic and does not limit the structure of the above computer terminal. For example, the computer terminal may further include more or fewer components than Figure 1 shown in the figure, or have an equivalent function to Figure 1 shown in the figure or different configurations with more functions than Figure 1 shown in the figure.

[0030] The memory 104 can be used to store computer programs. For example, software programs and modules of application software, such as the computer program corresponding to the service providing method in the embodiment of the present application. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implements the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely disposed relative to the processor 102, and these remote memories can be connected to the computer terminal through a network. Examples of the above network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0031] The transmission device 106 is used to receive or send data via a network. Specific examples of the above network may include a wireless network provided by a communication provider of the computer terminal. In one instance, the transmission device 106 includes a network adapter (abbreviated as NIC), which can be connected to other network devices through a base station and thus can communicate with the Internet. In one instance, the transmission device 106 may be a radio frequency (abbreviated as RF) module, which is used to communicate with the Internet wirelessly.

[0032] In this embodiment, a service providing method is provided. Figure 2It is a flowchart of an optional service providing method according to an embodiment of the present application. The process includes the following steps S200 - S230:

[0033] Step S200, obtain the identity authentication information of the target object. When the identity authentication information is verified, it is determined that the target object has successfully logged in.

[0034] Specifically, the identity of the target object (such as a user, supplier, or regulatory agency in the electricity spot market, etc.) is verified. In the electricity spot market, the verification of user identity is crucial to ensure that only authorized entities can access sensitive data and services. When the identity authentication information provided by the target object matches the preset and encrypted stored information, the system confirms that the object's login attempt is legal and allows it to access the system.

[0035] Exemplarily, a multi - factor authentication method can be adopted, including but not limited to using a combination of username and password, biometrics (such as fingerprint, facial recognition), security tokens, or behavior - based authentication (such as the regular time and location of user login). For example, before accessing electricity spot market data or services, a user must enter their pre - registered username and password and further verify their identity through biometric scanning. These authentication information will be compared with the encrypted user data stored in the cloud server to ensure the accuracy and security of the information. After the multi - factor authentication information is verified, the system will generate a temporary and encrypted login session ID, which will be used as the basis for identity authentication in subsequent data transmission and instruction processing to ensure that all interactions come from authenticated users. In addition, the system can record the user's login timestamp for subsequent replay attack prevention checks.

[0036] Step S210, when the target object has successfully logged in, obtain the first instruction input by the target object.

[0037] Specifically, when the target object has successfully logged in, it can start interacting with the system and input queries or instructions related to the electricity spot market, such as "Analyze the electricity price fluctuations in the past week" or "Predict the electricity demand in the next three days".

[0038] Exemplarily, the user sends the first instruction to the system through a secure and encrypted channel. The instruction may contain specific keywords or expressions for the system to understand and respond. After receiving the instruction, the system first checks the timestamp to ensure the real - time nature of the instruction, and then uses a secure decryption mechanism to interpret the instruction to avoid the interception and tampering of the instruction content during transmission.

[0039] Step S220, according to the semantic information of the first instruction, generate a corresponding prompt word from the preset first database to obtain a second instruction.

[0040] Among them, the preset first database includes encrypted target object data.

[0041] Specifically, based on the understood content of the first instruction, the system generates one or more prompts from the preset, encrypted first database. These prompts will guide the subsequent large language model (LLM) to generate more detailed responses or analyses, while ensuring that these prompts do not contain any sensitive information that can directly point to the user.

[0042] Exemplarily, the system uses natural language processing technology to analyze the semantics of the first instruction and extract keywords and concepts from it. Then, the system searches for information related to the keywords in the preset first database (containing de-identified user data and market information) to generate a secure prompt. This prompt undergoes a de-privatization process and only contains information related to the first instruction that does not include user privacy data, so it can be safely used as input for the large language model.

[0043] Step S230, in response to the second instruction, provide the corresponding service.

[0044] Specifically, when the system generates and provides the de-privatized prompts based on the first instruction, the large language model will generate detailed responses or analysis results based on these prompts, and then the system will return these results to the user as a service response to the first instruction.

[0045] Exemplarily, after receiving the de-privatized prompts, the large language model uses its training ability on massive data to generate information or prediction results related to the instruction. After the system receives these responses, it performs necessary security checks (for example, ensuring that the response does not contain sensitive information), and then decrypts and presents it to the user.

[0046] Exemplarily, as Figure 2a shown, the first instructions issued by multiple different users (User 1, User 2, User 3) can all be converted into second instructions with de-privatized data through the first database, and then after being fused with the system enhancement instruction, they are transmitted to the large model LLM to obtain the corresponding service provided by the LLM. The system enhancement instruction means that the system can enhance the second instruction through the enhancement instruction, add additional data or optimize the prompt, so that it better conforms to the operation mode of the LLM and guides the model to use a specific language style and information structure when answering.

[0047] In this embodiment, first, obtain the identity authentication information of the target object. When the identity authentication information is verified, it is determined that the target object has logged in successfully. Thus, the identity of the target object is verified first, and only after successful login can subsequent access be performed, improving security. Then, obtain the first instruction input by the target object. According to the semantic information of the first instruction, generate a corresponding prompt word from a preset first database to obtain a second instruction. Thus, through de-identification and semantic analysis techniques, it is ensured that the large language model can generate accurate responses. Through isolation and de-identification by the first database, it is ensured that the generated second instruction includes safe prompt words, avoiding the leakage of private data. Then, in response to the second instruction, provide the corresponding service. Since the second instruction is composed of safe prompt words generated by the first database, the privacy data of the target object will not be leaked in the provided service, protecting the privacy and security of the target object.

[0048] In one embodiment, as Figure 3 shown, step S200, obtain the identity authentication information of the target object. When the identity authentication information is verified, it is determined that the target object has logged in successfully. It includes: steps S300 - S310:

[0049] Step S300, obtain the identity identification information and timestamp information of the target object.

[0050] Among them, the identity authentication information includes identity identification information and timestamp information.

[0051] Specifically, it is necessary to collect the identity identification information provided by the target object (such as electricity market users, suppliers, or regulators) and the timestamp of the current operation for subsequent authentication and security verification. The identity identification information can be any form of user identifier, such as a username, device ID, or encrypted user ID; while the timestamp information is used to verify the real-time nature of the operation, ensuring that the data has not been reused or there is no replay attack.

[0052] Exemplarily, the user submits a data packet containing identity identification and timestamp to the system through a secure channel. The timestamp in the data packet is generated by the user's device when sending the request, indicating the sending time of the request. After the system receives the data packet, it first checks whether the difference between the timestamp and the current system time is within the set threshold to prevent replay attacks and ensure the real-time nature of the operation. If the time difference is within the allowable range, the system will compare the identity identification information with the pre-stored encrypted user information to further verify the user's identity.

[0053] Step S310, when both the identity identification information and the timestamp information are verified, determine that the target object has logged in successfully.

[0054] Specifically, once the identity identification information and the timestamp information are confirmed to be correct, the system will determine that the login attempt of the target object is legal and allow it to access the corresponding services or data. This step is a crucial link in multi-factor authentication, ensuring that only users who have passed all security checks can log in to the system and access the resources within their authorized scope.

[0055] Exemplarily, during the verification process, the system will compare the received identity identification information and timestamp information with the pre-stored user data. The pre-stored user data includes encrypted identity identification, public keys, and the most recent authentication records. If the received information is consistent with the pre-stored information and the timestamp does not exceed the set security threshold (e.g., within 1 minute), the system will generate a temporary security token that is valid for a certain period of time and is used for subsequent service access and data requests.

[0056] In this embodiment, by combining the dual verification of identity identification and timestamp, the system can effectively prevent replay attacks, ensuring the real-time nature and security of user operations. At the same time, the use of the timestamp provides a time benchmark for subsequent steps, helping to protect user data from time-related security threats. Through multi-factor authentication, especially by combining identity identification information with the timestamp, the system can significantly improve the security of the login process and effectively resist identity theft and replay attacks. The use of the security token also ensures that each service access is based on the latest and valid login status, further enhancing the security of the system and the protection of user privacy.

[0057] In one embodiment, as Figure 4 shown, in step S310, when both the identity identification information and the timestamp information are verified to pass, it is determined that the target object has logged in successfully. It includes: steps S400 - S430:

[0058] Step S400, obtain the first moment corresponding to the timestamp information.

[0059] Specifically, this step is the key to ensuring the real-time nature of operations and preventing replay attacks. It involves extracting the timestamp information from the request submitted by the target object, which is usually generated by the user device and reflects the actual time point of the operation.

[0060] Exemplarily, when a user attempts to log in to the system or request a service, the request contains a timestamp generated by the user device at the operation moment. After receiving the request, the system will immediately parse the timestamp to obtain the corresponding first moment (i.e., the time when the operation occurred). To ensure the accuracy of the timestamp and prevent tampering, the system can require the use of an encrypted timestamp, and the encryption process can be completed using the shared key between the user device and the system.

[0061] In step S410, when it is determined that the time difference between the first moment and the second moment for verifying the timestamp information is less than or equal to the time threshold, it is determined that the timestamp information passes the verification.

[0062] Specifically, this step is used to check the time difference between the timestamp of the user request and the current system time (the second moment) to ensure the real-time nature and freshness of the request.

[0063] Exemplarily, after the system parses the first moment of the user operation, it obtains the current system time as the second moment, and then calculates the time difference between the two. If the time difference is less than or equal to the preset time threshold (for example, 1 minute), the system will determine that the timestamp information is valid, that is, the verification passes. The time threshold can be adjusted according to specific application requirements and network latency conditions to balance security and user experience.

[0064] In step S420, when it is determined that the timestamp information passes the verification, it is determined whether the identity identification information is recorded in the preset second database.

[0065] Specifically, once the timestamp verification is successful, the system needs to further confirm whether the identity identification information in the request is legal, that is, to check whether the identification exists in the legal user database maintained by the system.

[0066] Exemplarily, the system extracts the identity identification information from the decrypted request, and then queries the internal second database (legal user database) to check whether the identification has been registered and is valid. The second database usually contains information such as the encrypted identity identification, public key, and authentication status of the user. If the identity identification exists in the second database, the system will mark that the identity identification information passes the verification.

[0067] In step S430, when it is determined that the identity identification information is recorded in the preset second database, it is determined that the identity identification information passes the verification.

[0068] Specifically, this step is a process in which the system finally confirms the legality of the user login attempt based on the legality and validity of the identity identification information.

[0069] Exemplarily, after finding the identity identification information matching the request in the second database, the system will check the information status of the identification, including the authentication status, whether the account is activated, etc. If all conditions are met and there are no security warnings (such as the account being frozen, the authentication times exceeding the limit, etc.), the system will determine that the identity identification information passes the verification and the user login attempt is legal.

[0070] Exemplarily, when a user wishes to access a service, the system requests the user to input their identity information, and the user needs to select a timestamp (to prevent replay attacks) T1 and then express it as the following formula: W 1←h(T id ∥P id ), Then summarize these data: Co←{J 1 , J 2 , P id , T 1}, where T id is the password, P id is the account number, T1 is the first moment, and T2 is the second moment.

[0071] After the system receives the data, it first checks the timestamp, and then verifies whether the user exists through the user's Pid. If the time difference T2 - T1 is less than or equal to the time threshold ΔT, the following calculations are performed:

[0072]

[0073] If J2 * = the preset correct value J2, the user is authenticated as a legitimate user, is the encrypted password. Through the timestamp and the hash value of the user characteristic information, the service provider can verify the real-time nature of the user, prevent replay attacks, and check whether the user is a legitimate user.

[0074] In this embodiment, by accurately recording the first moment of the user's operation, the system can verify the request based on time, prevent malicious use of outdated or pre-recorded operation data, thereby enhancing the security of the system and the timeliness of the data. Through the time threshold verification, the system can effectively prevent replay attacks, that is, an attacker attempts to use old and verified operation data for deception. This step enhances the real-time check of the user's operation, ensures that the system can respond to the latest and verified requests, thereby improving the overall security of the system. By checking the validity of the user identification, the authentication process of the user identity is further strengthened, preventing unauthorized access. Combined with the timestamp verification, the system can ensure that only users who are legally registered and whose current operation is in a real-time state can log in or request services, significantly improving the accuracy and security of the system's user identity authentication. By comprehensively checking the validity and security of the user identity identification information, the system ensures the protection of user data and privacy, while avoiding unauthorized access attempts. Once the identity identification information is verified, the user will be granted access rights and can safely perform subsequent operations, such as data access, service requests, etc. This provides a solid technical guarantee for data security and personal privacy protection in sensitive fields such as the electricity spot market.

[0075] In one embodiment, such as Figure 5As shown in the figure, in step S430, after determining that the identity identification information is recorded in the preset second database and the identity identification information is verified to pass, the method further includes steps S500 - S520:

[0076] Step S500, determine the target server that the target object needs to access.

[0077] Specifically, it is necessary to determine the specific server or service that the target object (user) desires to access based on the needs of the target object, in order to carry out a further secure data access process.

[0078] Exemplarily, the system parses the request content of the target object. For example, a user may need to query the real - time electricity price in the electricity spot market or submit a trading instruction. The system determines a suitable server or service node based on the request type and content. For example, the real - time electricity price query may be provided by the market data server, while the trading instruction processing may be the responsibility of the trading processing server. After determining the target server, the system will start to prepare the necessary security verification and data access processes.

[0079] Step S510, send an access request to the target server.

[0080] Specifically, once the target server is determined, the system will prepare an access request containing the target object identifier and the verified timestamp, and then send it to the target server through a secure channel to request access to specific data or services.

[0081] Exemplarily, the system will generate an access request packet, which contains the encrypted identifier of the target object, the verified timestamp, and the specific content of the request (such as the service type or data requirement). The request packet is transmitted in an encrypted manner to ensure the privacy and security of the data during transmission. The system sends the request packet to the target server through a preset secure communication protocol and waits for the response of the target server.

[0082] Step S520, when the time difference between the second moment and the third moment when the target server receives the access request is less than or equal to the time threshold, allow the target object to access the target server.

[0083] Specifically, this step is to further confirm the real - time nature and validity of the request, prevent replay attacks, and ensure that the access request of the target object is fresh and legal.

[0084] Exemplarily, after receiving the request, the target server records the specific time when the request is received as the third moment. Then, the target server compares the third moment with the second moment included in the request (i.e., the moment when the system verifies the timestamp), and checks whether the time difference between the two is within a preset time threshold. If the time difference meets the requirements, the target server considers the request valid and thus allows the target object to access the server or the corresponding service. Otherwise, the request will be rejected to prevent old or malicious access attempts.

[0085] In this embodiment, it is clear that the target server can not only improve the efficiency and accuracy of data access, but also provide a specific context for subsequent security verification to ensure precise control of data access permissions, thereby enhancing the overall security of the system. The encrypted access request and secure data transmission protocol can effectively prevent data from being intercepted or tampered with during transmission, ensuring the integrity and authenticity of the information received by the target server, and thus improving the access security of the overall system and the data privacy protection ability. By introducing the time difference check mechanism, the target server can effectively defend against replay attacks and ensure the real-time nature and security of data access and interaction. The setting of the time threshold provides a trusted time benchmark between the server and the user, helps to maintain the synchronization of system operations and the timeliness of data, and further strengthens the data security and privacy protection strategies in the power spot market.

[0086] In one embodiment, as Figure 6 shown, before obtaining the identity identification information and timestamp information of the target object in step S300, the method further includes steps S600 - S620:

[0087] Step S600, obtain the biometric features, account number, and password input by the target object.

[0088] Specifically, in the context of information security, obtaining the user's biometric data and traditional account number and password information is the initial step in verifying the user's identity. The use of biometric data increases the complexity and security of the authentication process because it is based on the user's unique physiological or behavioral characteristics and is difficult to be replicated or misused.

[0089] Exemplarily, the user inputs biometric information through a dedicated authentication device (such as a smart terminal with fingerprint recognition or face recognition function), and manually inputs the account number and password at the same time. There is a secure communication channel between these devices and the system to ensure the privacy security of the data during transmission. For example, when a user logs in to the power spot market information system, they need to first submit their fingerprint or face image through the biometric recognition function of the device, and then input the registered account number and password.

[0090] Step S610, encrypt the account and password of the target object, and obfuscate the biometric features of the target object to generate the identity identification information of the target object.

[0091] Specifically, encrypting the account and password, and obfuscating the biometric features aims to protect the privacy of user data and at the same time form a more secure identity identification information for subsequent authentication processes.

[0092] Exemplarily, the account and password are encrypted through an advanced encryption algorithm (such as Elliptic Curve Cryptography ECC) to form the encrypted account and password, preventing them from being stolen or cracked during storage and transmission. At the same time, the biometric data is processed through a fuzzy generation function to generate a stable and obfuscated biometric variable, ensuring the accuracy of authentication even if the biometric features change slightly. These encrypted account passwords and obfuscated biometric data together constitute the encrypted identity identification information.

[0093] Step S620, authenticate the identity identification information.

[0094] Among them, the target object whose identity identification information is authenticated is a legitimate target object.

[0095] Specifically, the authentication process is a key step in verifying the user's identity, ensuring that only legitimate users can access the system or service.

[0096] Exemplarily, after the system receives the encrypted identity identification information, it will compare it with the pre-stored encrypted user data. This includes decrypting the account password submitted by the user using the key, and matching the biometric variable generated during user registration with the submitted obfuscated biometric data. If all the data matches successfully, that is, the account password is correct and the error between the biometric variable and the pre-stored data is less than or equal to the security threshold, the system will determine that the authentication of the target object is passed and confirm that it is a legitimate user.

[0097] Exemplarily, during the registration phase, each user U a 's smart device (such as a mobile phone) is regarded as its unique identity identification ID. In addition, the user needs to select a unique password PW and biometric feature Bio (such as a fingerprint image). Considering that the biometric features may change, the system uses a fuzzy generation function Gen to generate a stable biometric variable σ: which can be expressed as (σ,δ)←Gen(Bio)

[0098] Among them, Gen() is the fuzzy generation function, σ is the generated robust biometric variable, and δ is the tolerance error. Then, the system selects a random number l, l∈Z * , and this random number is used to protect the user's ID and password.

[0099] Then a temporary ID and an encrypted password can be generated: The user calculates the temporary ID T according to the following formula id and the encrypted password H pw :

[0100] where h is a hash function, denotes the exclusive OR operation, and ∥ here denotes the concatenation operation, which is used to represent the combination of two different data. For example, ID ∥ l = "User123" ∥ "456" = "User123456". Provide a lightweight encryption authentication mechanism based on the user ID and password, while protecting the user's biometric data to ensure that even in the case of data leakage, the password and biometric features cannot be directly cracked.

[0101] Then the cloud server can also generate a public key K u and a random number p i , and then use this information to generate the encrypted user identity identifier Hid, as well as two other encrypted values A i and C i .

[0102]

[0103] After calculating Hid, A i and C i , send these values to the user U a :

[0104] U a ← {A i , C i , h(.)}

[0105] When the user logs in, the user enters their ID * , biometric feature Bio * and password PW * , and the smart device performs authentication. Generate the current biometric variable using the following formula:

[0106] σ * ← Gen(Bio * )

[0107] Generate the user-calculated random number l * :

[0108]

[0109] Calculate the verification values R 1 * , R 2 * :

[0110]

[0111] If R 2 * = the preset correct value R 2 , the login is successful, and the user identity is authenticated as a legitimate user. By combining public key encryption and biometrics, the cloud server can generate a series of verification values for subsequent user identity authentication processes. These values include encrypted information of user identification, password, and biometrics, increasing the security of authentication.

[0112] In this embodiment, by combining biometrics with the input of traditional account passwords, the system can obtain more comprehensive and secure user identity information, reducing the risk of being easily guessed or forged by a single authentication method. Through encryption and obfuscation, even if an attacker can obtain some user data, it is difficult to directly use this data for identity impersonation. This step significantly enhances the privacy protection of user data while improving the accuracy and security of identity authentication. Through this authentication process, the system not only verifies the correctness of the information submitted by the user but also ensures the uniqueness of the information and the authenticity of the identity, effectively preventing identity theft and fraud, providing a solid security guarantee for data access in the electricity spot market. At the same time, the multi-factor authentication mechanism improves the overall security level of the system and reduces the risk of being vulnerable to attacks by a single authentication method.

[0113] In one embodiment, as Figure 7 shown, before step S220 of generating a corresponding prompt word from the preset first database according to the semantic information of the first instruction to obtain the second instruction, the method further includes: steps S700 - S720:

[0114] Step S700, obtaining the data to be encrypted of multiple target objects.

[0115] Specifically, this is the starting point of the data processing and privacy protection process. The system needs to collect the original data of multiple target objects (such as different participants in the electricity spot market), and this data may contain sensitive information such as real-time electricity consumption and transaction records.

[0116] Exemplarily, the system obtains the data to be encrypted from each target object through a secure interface. This data may come from the user's device, smart meter, trading system, etc., and is transmitted to the centralized processing node through a pre-set secure channel. During the collection process, the system needs to ensure the integrity and privacy of the data to avoid being intercepted or tampered with during transmission.

[0117] Step S710, encrypting the data to be encrypted of multiple target objects using a preset encryption algorithm to obtain an encrypted data set.

[0118] Specifically, data encryption is the core link of data privacy protection. By converting the original data into an encrypted form, it can prevent the unauthorized access or leakage of data during storage and transmission.

[0119] Exemplarily, the system uses a preset encryption algorithm (e.g., using Elliptic Curve Cryptography (ECC) or Advanced Encryption Standard (AES) algorithm) to encrypt the data of each target object collected. The selection of the encryption algorithm should be based on the balance between data security requirements and processing efficiency. The encrypted data constitutes an encrypted data set and is stored in the encrypted storage area inside the system to ensure the security and privacy of the data during subsequent processing.

[0120] Step S720, perform a standardization process on the encrypted data set to obtain the first database.

[0121] Specifically, the standardization process is an important task in data preprocessing, aiming to ensure the consistency and operability of the data set, facilitating subsequent data analysis and model training.

[0122] Exemplarily, the system performs a standardization process on the received encrypted data set, including but not limited to data format conversion, outlier detection and removal, and data standardization. The standardization process needs to be carried out in the encrypted state using homomorphic encryption technology to avoid the decryption and exposure of data during processing. The standardized encrypted data set is integrated into a unified first database, ready for subsequent analysis or model training.

[0123] Exemplarily, the data set X of user V j may contain the power privacy data provided by the user, and the data needs to be encrypted and converted. X j ′ is the encrypted data. The data is encrypted using the Elliptic Curve method ECC, and a hash function F is used to generate a hash value of a fixed length to ensure the security of the data. The formula is expressed as follows: j ′ = F(G(X

[0124] X j ′, L)) j

[0125] Wherein, G(X j , L) is the process of encrypting the original data X j using the key L, and F is a hash function used to generate an encrypted output of a fixed length. Ensure that the sensitive data in the power spot market is not leaked during transmission and storage, protecting the privacy of users. Use the hash function (F) to generate a hash value X j ′ of a fixed length for the encrypted data X. The hash value can be used to verify the integrity of the data, detect whether the data has been tampered with, and at the same time does not reveal any specific information about the data.​​

[0126] The system aggregates the encrypted data X of all users j to generate a de-identified secure dataset X′ and generates a prompt Q from it:

[0127]

[0128] Q = CreatePrompt(X′)

[0129] After receiving the prompt Q, the LLM generates a response R, which is processed based on the de-identified dataset to ensure privacy security: R = LLM(Q). This means that by aggregating multiple de-identified datasets X′, a de-identified secure dataset is generated, and then a prompt Q is generated from this dataset for input to the large model. Ensure that the data received by the large language model does not contain any sensitive information that can directly or indirectly identify the user, thus protecting user privacy.

[0130] In this embodiment, by collecting data from multiple sources, the system can build a comprehensive dataset to support subsequent privacy protection and data processing operations. At the same time, the secure data collection mechanism lays the foundation for data privacy security. The generation of the encrypted dataset not only protects the privacy of the data but also provides a secure data source for subsequent data processing. Even if the dataset is stolen, attackers cannot directly read or utilize the sensitive information in the data, thus greatly enhancing the security of the data. The first database after standardization processing not only maintains the encrypted state of the data but also ensures the unity and quality of the dataset, providing a reliable data basis for model training and data analysis. The application of homomorphic encryption enables the data processing process to be carried out without decrypting the data, further strengthening data privacy protection, which is a key step in balancing security and efficiency in the data processing of the electricity spot market.

[0131] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation method. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disc), including several instructions for causing a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of the present application.

[0132] In this embodiment, a service providing device is further provided. The service providing device is used to implement the above embodiments and preferred implementation manners, and those that have been described will not be repeated. As used hereinafter, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.

[0133] Figure 8 is a structural block diagram of an optional service providing device according to an embodiment of the present application. As Figure 8 shown, it includes:

[0134] A login verification module 801, configured to obtain the identity authentication information of the target object, and determine that the target object has successfully logged in when the identity authentication information is verified.

[0135] An instruction acquisition module 802, configured to obtain a first instruction input by the target object when the target object has successfully logged in.

[0136] An instruction generation module 803, configured to select a corresponding prompt word from a preset first database according to the semantic information of the first instruction to generate a second instruction, where the preset first database includes encrypted target object data.

[0137] A service providing module 804, configured to provide a corresponding service in response to the second instruction.

[0138] Through the above device, first, the identity authentication information of the target object is obtained. When the identity authentication information is verified, it is determined that the target object has successfully logged in, thus first verifying the identity of the target object. Only when the login is successful can subsequent access be performed, improving security. Then, 3. obtain the first instruction input by the target object, and according to the semantic information of the first instruction, generate a corresponding prompt word from the preset first database to obtain the second instruction. Thus, through de-identification and semantic analysis technologies, it is ensured that the large language model can generate accurate responses, and through isolation and de-identification by the first database, it is ensured that the generated second instruction includes safe prompt words, avoiding the leakage of privacy data. Then, in response to the second instruction, a corresponding service is provided. Since the second instruction is composed of safe prompt words generated by the first database, the privacy data of the target object will not be leaked in the provided service, protecting the privacy security of the target object.

[0139] In an exemplary embodiment, the above login verification module 801 is further configured to obtain the identity identification information and timestamp information of the target object, where the identity authentication information includes the identity identification information and timestamp information. When both the identity identification information and the timestamp information are verified, it is determined that the target object has successfully logged in.

[0140] In an exemplary embodiment, the above-mentioned login verification module 801 is further configured to obtain the first moment corresponding to the timestamp information. When it is determined that the time difference between the first moment and the second moment for verifying the timestamp information is less than or equal to the time threshold, it is determined that the timestamp information passes the verification. When it is determined that the timestamp information passes the verification, it is determined whether the identity identification information is recorded in a preset second database. When it is determined that the identity identification information is recorded in the preset second database, it is determined that the identity identification information passes the verification.

[0141] In an exemplary embodiment, the above-mentioned device further includes:

[0142] A server determination module, configured to determine the target server that the target object needs to access.

[0143] A request sending module, configured to send an access request to the target server.

[0144] An access judgment module, configured to allow the target object to access the target server when it is determined that the time difference between the second moment and the third moment when the target server receives the access request is less than or equal to the time threshold.

[0145] In an exemplary embodiment, the above-mentioned device further includes:

[0146] An information acquisition module, configured to acquire the biometric features, account number, and password input by the target object.

[0147] A processing module, configured to perform encryption processing on the account number and password of the target object and perform blurring processing on the biometric features of the target object to generate the identity identification information of the target object.

[0148] An authentication module, configured to authenticate the identity identification information, where the target object whose identity identification information passes the authentication is a legal target object.

[0149] In an exemplary embodiment, the above-mentioned device further includes:

[0150] A data acquisition module, configured to acquire the data to be encrypted of multiple target objects.

[0151] An encryption module, configured to encrypt the data to be encrypted of multiple target objects by using a preset encryption algorithm to obtain an encrypted data set.

[0152] A standardization module, configured to perform standardization processing on the encrypted data set to obtain a first database.

[0153] An embodiment of the present application further provides a storage medium, which includes a stored program, where the above-mentioned program executes the method of any one of the above when running.

[0154] Optionally, in this embodiment, the above storage medium may be configured to store program code for performing the following steps:

[0155] S1. Obtain the identity authentication information of the target object, and determine that the target object has logged in successfully when the identity authentication information is verified.

[0156] S2. When the target object has logged in successfully, obtain the first instruction input by the target object.

[0157] S3. Generate a corresponding prompt word from a preset first database according to the semantic information of the first instruction to obtain a second instruction, where the preset first database includes encrypted target object data.

[0158] S4. Provide a corresponding service in response to the second instruction.

[0159] An embodiment of the present application also provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.

[0160] Optionally, the above electronic device may further include a transmission device and an input / output device, where the transmission device is connected to the above processor, and the input / output device is connected to the above processor.

[0161] Optionally, in this embodiment, the above processor may be configured to execute the following steps through a computer program:

[0162] S1. Obtain the identity authentication information of the target object, and determine that the target object has logged in successfully when the identity authentication information is verified.

[0163] S2. When the target object has logged in successfully, obtain the first instruction input by the target object.

[0164] S3. Generate a corresponding prompt word from a preset first database according to the semantic information of the first instruction to obtain a second instruction, where the preset first database includes encrypted target object data.

[0165] S4. Provide a corresponding service in response to the second instruction.

[0166] Optionally, in this embodiment, the above storage medium may include but is not limited to: various media such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk, or an optical disc that can store program code.

[0167] An embodiment of the present application further provides a computer program product, including a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores the computer program product. When the computer program is executed by a processor, the steps of the methods in various embodiments of the present application are implemented.

[0168] Optionally, in this embodiment, the above computer program may be configured to implement the following steps when executed by a processor:

[0169] S1, obtain the identity authentication information of the target object. If the identity authentication information is verified successfully, determine that the target object has logged in successfully.

[0170] S2, when the target object has logged in successfully, obtain the first instruction input by the target object.

[0171] S3, according to the semantic information of the first instruction, generate a corresponding prompt word from a preset first database to obtain a second instruction, where the preset first database includes encrypted target object data.

[0172] S4, in response to the second instruction, provide the corresponding service.

[0173] Optionally, specific examples in this embodiment may refer to the examples described in the above embodiments and optional implementation manners, and will not be elaborated herein.

[0174] Obviously, those skilled in the art should understand that the above-mentioned modules or steps of the present application can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed on a network composed of multiple computing devices. Optionally, they can be implemented by program codes executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described can be executed in a different order than here, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module to implement. In this way, the present application is not limited to any specific combination of hardware and software.

[0175] The above are only the preferred embodiments of the present application and are not used to limit the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the principle of the present application shall be included in the protection scope of the present application.

Claims

1. A method for providing a service, characterized in that: The method comprises: Acquire the identity authentication information of the target object, and if the identity authentication information is verified, determine that the target object has successfully logged in; When the target object logs in successfully, obtaining a first instruction input by the target object; According to the semantic information of the first instruction, a corresponding prompt word is generated from a preset first database to obtain a second instruction, wherein the preset first database includes encrypted target object data; In response to the second instruction, a corresponding service is provided.

2. The method for providing services according to claim 1, characterized in that: The acquiring the identity authentication information of the target object, and determining that the target object has successfully logged in if the identity authentication information is verified, includes: Acquire the identity information and timestamp information of the target object, wherein the identity authentication information includes the identity information and the timestamp information; When both the identity identification information and the timestamp information are verified, it is determined that the target object has successfully logged in.

3. The method for providing services according to claim 2, characterized in that: When both the identity information and the timestamp information are verified, determining that the target object has successfully logged in includes: Obtaining a first moment corresponding to the timestamp information; In the case where it is determined that the time difference between the first moment and the second moment of verifying the timestamp information is less than or equal to a time threshold, determining that the timestamp information verification is passed; If it is determined that the timestamp information is verified, determining whether the identity information is recorded in a preset second database; In the case where it is determined that the identity identification information is recorded in the preset second database, it is determined that the identity identification information verification is passed.

4. The method for providing services according to claim 3, characterized in that: In the case where it is determined that the identity information is recorded in the preset second database, after it is determined that the identity information is verified, the method further includes: Determine a target server that the target object needs to access; Sending an access request to the target server; In a case where it is determined that the time difference between the second moment and a third moment when the target server receives the access request is less than or equal to the time threshold, the target object is allowed to access the target server.

5. The method for providing services according to claim 2, characterized in that: Before obtaining the identity information and timestamp information of the target object, the method further includes: Obtaining biometrics, account number, and password input by the target object; Encrypting the target object's account number and password and blurring the target object's biometric features to generate the target object's identity information; The identity identification information is authenticated, wherein the target object whose identity identification information passes the authentication is a legal target object.

6. The method for providing services according to any one of claims 1 to 5, characterized in that: Before selecting a corresponding prompt word in a preset first database according to the semantic information of the first instruction to generate a second instruction, the method further includes: Obtaining data to be encrypted of multiple target objects; Encrypting the data to be encrypted of the multiple target objects using a preset encryption algorithm to obtain an encrypted data set; The encrypted data set is standardized to obtain the first database.

7. A service providing device, characterized in that: The device comprises: A login verification module, used to obtain the identity authentication information of the target object, and if the identity authentication information is verified, determine that the target object has successfully logged in; An instruction acquisition module, used for acquiring a first instruction input by the target object when the target object logs in successfully; An instruction generation module, configured to select a corresponding prompt word from a preset first database according to the semantic information of the first instruction to generate a second instruction, wherein the preset first database includes encrypted target object data; The service providing module is used to provide corresponding services in response to the second instruction.

8. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored program, wherein the program executes the method according to any one of claims 1 to 6 when executed.

9. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to execute the method according to any one of claims 1 to 6 through the computer program.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.