Multi-tenant fine-grained authority control system based on large-model intelligent agent and implementation method of multi-tenant fine-grained authority control system

Through a multi-tenant fine-grained permission control system based on large model agents, the problem of inflexible permission allocation in traditional methods is solved, and the isolation of tenant resources and dynamic allocation of permissions is realized to ensure system security and availability.

CN120337184APending Publication Date: 2025-07-18SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510415666.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

Traditional methods have difficulty in flexibly allocating and managing big model agent permissions for each tenant, resulting in abuse or inadequate permissions, affecting the security and availability of the system.

Method used

It provides a multi-tenant fine-grained permission control system based on large-model agents, including large-model agent management module, multi-tenant management module, tenant authorized agent module and fine-grained permission list display module. Through these modules, the isolation of tenant resources and dynamic allocation of permissions is realized.

Benefits of technology

The isolation and optimization allocation of tenant resources are realized, ensuring that the data and operations between different tenants do not interfere with each other, and ensuring the security and efficient management of large-scale models.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337184A_ABST
    Figure CN120337184A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of artificial intelligence, in particular to a multi-tenant fine-grained permission control system based on a large-model agent and an implementation method thereof, and the system comprises a large-model agent management module, a multi-tenant management module, a tenant authorization agent module, a fine-grained permission list display module and a fine-grained permission quota setting module. The method has the advantages that isolation and optimal distribution of tenant resources are achieved through the multi-tenant authorization agent module, it is ensured that data and operation between different tenants do not interfere with each other, and the large-model agent management module can achieve large-model agent registration access and large-model interface calling permission distribution.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of artificial intelligence technology, and particularly to a multi-tenant fine-grained permission control system based on large model agents and its implementation method. Background Art

[0002] With the continuous development of artificial intelligence technology, significant achievements have been made by large models in various fields. However, in a multi-tenant environment, multiple tenants share the same set of system resources, but each tenant needs to independently manage and use these resources. As an important resource in the system, the permission management of large model agents is crucial. Traditional methods are difficult to flexibly allocate and manage agent permissions for each tenant, easily leading to problems such as permission abuse or insufficient permissions, which affect the security and availability of the system. Summary of the Invention

[0003] The purpose of the present invention is to provide a multi-tenant fine-grained permission control system based on large model agents and its implementation method to solve the problems raised in the above background art.

[0004] To achieve the above purpose, the present invention provides the following technical solution: A multi-tenant fine-grained permission control system based on large model agents, including a large model agent management module, which is used to provide the function of presetting agent APP application information for the agent platform accessing the large model service;

[0005] The large model agent management module supports creating agent types and creating corresponding agent types for specific agent platforms;

[0006] Supports registering agents. After filling in the agent name, agent Code, agent description, selecting the agent type, and checking the set of large model interfaces to be accessed through a pop-up form, submit a registration request;

[0007] After receiving the registration request, the server performs verification. If the restriction conditions are not met, it responds with a prompt message. If they are met, it stores the agent data and the binding relationship data between the agent and the large model in the database, and responds with the agent details to the front end;

[0008] According to the response result of the server, the front end pops up the reason for failure in case of registration failure and refreshes the data on the agent list page in case of successful registration.

[0009] Preferably, it includes a multi-tenant management module, which is used to maintain information of multiple tenants. Tenant information includes tenant accounts, tenant names, enterprise names, mobile phone numbers, email addresses, and tenant statuses; The multi-tenant management module supports operations such as creating, disabling, modifying, deleting, and viewing tenants to achieve comprehensive management of tenant information.

[0010] Preferably, it includes a tenant authorization agent module, which is used to realize the authorization association between the tenant and the agent; an authorization button is provided in the operation column of the multi-tenant management list. Clicking the authorization button pops up a form, and one or more agents can be selected for the tenant and then the tenant authorization agent request is submitted. After receiving the request, the server first clears the original old association data of the tenant and the agent, and then re-enters the association relationship data of the tenant and the agent into the database.

[0011] Preferably, it includes a fine-grained permission list display module, which performs an associated query on the data generated by the large model agent management module and the multi-tenant authorized agent module; divides and displays each piece of data at the fine-grained level of tenant-agent-large model, and the number in the quota column shows the specific value or 0 according to whether the quota is set.

[0012] Preferably, it includes a fine-grained permission setting quota module, which is used to set quotas for fine-grained permissions; a set quota button is provided in the operation column of the fine-grained permission list. Clicking this button triggers a query, obtains the configured quota number of the fine-grained permission and displays it on the form; after modifying the quota on the form, submit the request to modify the fine-grained permission quota to the server; after receiving the request, the server determines whether the fine-grained permission in the tenant-agent-large model dimension exists. If it does not exist, a piece of data is entered into the database and the quota is set. If it exists, the data quota is updated, thus completing the setting of the fine-grained permission quota.

[0013] An implementation method of a multi-tenant fine-grained permission control system based on a large model agent includes a large model agent management method, and the specific steps are as follows:

[0014] Create an agent type: Click the create agent type button on the large model agent management module page to create a corresponding agent type for a specific agent platform. For example, create an agent type named "Agent Platform 1" for Agent Platform 1;

[0015] Register an agent: Click the register agent button on the large model agent management module page, a form pops up, fill in the agent name, agent Code, agent description, select the agent type, check the set of large model interfaces to be accessed, and then submit the registration request;

[0016] Server verification and response: After the server receives the request to register an agent, it verifies according to the restrictive conditions that the agent type cannot be repeated, the agent name cannot be repeated, the agent Code cannot be repeated, and at least one large model interface must be selected. If the restrictive conditions are not met, prompt information is responded to the front-end page; if the restrictive conditions are met, a piece of agent data and the binding relationship data between the agent and the large model are entered into the database, and the agent details are responded to the front-end page;

[0017] Front-end processing of responses: After the front-end page receives the server response, if the registration fails, the reason for the failure is popped up; if the registration is successful, the data on the agent list page is refreshed.

[0018] Preferably, it includes a multi-tenant management method, specifically: maintaining multiple tenant information through a multi-tenant management module, where the tenant information covers tenant accounts, tenant names, enterprise names, mobile phone numbers, email addresses, and tenant statuses; supporting operations such as creating, disabling, modifying, deleting, and viewing tenants to achieve comprehensive management of tenant information.

[0019] Preferably, it includes a method for tenant authorizing agents, and the specific steps are as follows:

[0020] Initiate an authorization request: Click the authorization button in the operation column of the multi-tenant management list to pop up a form. After selecting one or more agents for the tenant and clicking the submit button, initiate a request for the tenant to authorize the agent;

[0021] Server processes the request: After the server receives this request, first clears the original old association data between this tenant and the agent, and then re-enters the association relationship between this tenant and the agent into the database.

[0022] Preferably, it includes a method for displaying a fine-grained permission list, specifically: associatively querying the data generated by the large model agent management module and the multi-tenant authorized agent module through the fine-grained permission list display module; performing tenant-agent-large model fine-grained level division and display for each piece of data, and the number in the quota column shows the specific value or 0 according to whether the quota is set.

[0023] Preferably, it includes a method for setting quotas for fine-grained permissions, and the specific steps are as follows:

[0024] Query the configured quota: Click the set quota button in the operation column of the fine-grained permission list to trigger a query, obtain the configured quota number for this fine-grained permission, and display this quota number on the form;

[0025] Modify and submit the quota: After modifying the quota on the form, click submit to initiate a request to modify the fine-grained permission quota to the server;

[0026] Server processes the quota request: After the server receives the request, it judges whether the fine-grained permission in the tenant-agent-large model dimension exists. If it does not exist, it enters a piece of data into the database and sets the quota; if it exists, it updates the data quota, thereby completing the setting of the fine-grained permission quota.

[0027] Compared with the prior art, the beneficial effects of the present invention are:

[0028] The multi-tenant fine-grained permission control system and its implementation method based on large model agents proposed by the present invention realize the isolation and optimal allocation of tenant resources through the multi-tenant authorization agent module, ensuring that data and operations between different tenants do not interfere with each other. The large model agent management module can realize the registration and access of large model agents and the allocation of permissions to call large model interfaces. Description of the Drawings

[0029] Figure 1 This is the flowchart of the present invention. Detailed Implementation Modes

[0030] In order to clearly and completely describe the purpose, technical solution of the present invention and make the advantages more clear, the following further details the embodiments of the present invention with reference to the drawings. It should be understood that the specific embodiments described here are part of the embodiments of the present invention, not all of the embodiments, and are only used to explain the embodiments of the present invention, not to limit the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the protection scope of the present invention.

[0031] Embodiment 1, the present invention provides a technical solution: including three modules: large model agent management, multi-tenant authorization agent, and quota management module. Through these three modules, a multi-tenant fine-grained permission control system and its implementation method based on large model agents can be provided, which can support the efficient management and dynamic allocation of agent permissions in a multi-tenant environment, realize the dynamic adjustment and real-time effectiveness of permissions, and have the advantages of ensuring data isolation and security in a multi-tenant environment. The main functions of each module are as follows:

[0032] Large model agent management module: For all agent platforms that require large model services, all agent APP application information under the agent platform needs to be pre-set in advance, including information such as agent name, agent Code, agent type, agent description, etc. Multiple agent platforms distinguish the agent APP application sets by agent type. Through the large model agent management module, the registration of agent APP applications on the agent platform can be realized. Then, the large model interface call permission can be allocated to the registered agents, thus realizing the preliminary operations from the registration of agent APP applications on the agent platform to the allocation of large model service interface permissions.

[0033] Multi-tenant authorization agent module: First, there is a multi-tenant management function in this module, which is used to maintain and display multi-tenant detailed information. There is a multi-tenant authorization agent function on the multi-tenant management list page, which can allocate the usage permissions of one or more agent APP applications of a certain type to tenants. In this way, it can ensure that multiple tenants can dynamically allocate the required agent APP application permissions as needed.

[0034] Quota Management Module: This functional module consists of two parts. One is the display of the fine-grained permission list, and the other is setting quotas for the fine-grained permissions. First, the data of the fine-grained permission list comes from the associated query of the data of both the large model agent management module and the multi-tenant authorized agent module. Each piece of data is the fine-grained association of tenant-agent-large model. Then, based on this fine-grained permission data, quota settings are added, and dynamic configuration of permission quotas is carried out according to the actual needs of the tenant. Thus, it ensures the reasonable allocation and efficient utilization of the large model service.

[0035] Next, refer to Figure 1 for a detailed explanation of the implementation of these three major modules:

[0036] 1) Large Model Agent Management Module: The purpose of this module is to provide a function for pre-setting all the agent APP application information under the agent platform for all intelligent agent platforms that need to access the large model service. The following is a more detailed description:

[0037] a) Suppose the intelligent agent platform that needs to access the large model service is called Agent Platform 1, and there are 3 agent APP applications under this Agent Platform 1, namely Agent APP Application 1, Agent APP Application 2, and Agent APP Application 3. Then, suppose there are two large model service interfaces, namely Large Model Interface 1 and Large Model Interface 2.

[0038] b) Prerequisite restrictions: The agent types cannot be repeated, the agent names cannot be repeated, the agent Codes cannot be repeated, and at least one large model interface must be selected.

[0039] c) On the page of the large model agent management module, click the button to create an agent type, and create an agent type called Agent Platform 1 for this agent platform.

[0040] d) On the page of the large model agent management module, click the button to register an agent, and a form will pop up. Fill in the agent name, agent Code, agent description, select the agent type, and check the set of large model interfaces that need to be accessed. Finally, click the submit button to initiate a request to register the agent to the server.

[0041] e) After the server receives the request to register the agent, it first checks the restriction conditions. If the conditions are not met, it responds with prompt information to the front-end page. If the conditions are met, it stores a piece of agent data and the data of the binding relationship between the agent and the large model in the database, and responds with the agent details to the front-end page.

[0042] f) After the front - end page receives the server response, if the registration fails, the reason for the failure is popped up. If the registration is successful, the data on the agent list page is refreshed.

[0043] 2) Multi - tenant authorized agent module: This module includes two functional modules, namely multi - tenant management and tenant - authorized agent. The following is a more detailed implementation description for each:

[0044] a) Multi - tenant management module: This module is used to maintain information about multiple tenants, including: tenant accounts, tenant names, enterprise names, mobile phone numbers, email addresses, and tenant status, etc. It supports functions such as tenant creation, disabling, modification, deletion, and viewing.

[0045] b) Tenant - authorized agent module:

[0046] i. Suppose there are two tenants in the multi - tenant list: Tenant A, Tenant B, and Tenant C. And there are three agents: Agent A, Agent B, and Agent C.

[0047] ii. There is an authorization button in the operation column of the multi - tenant management list. Click the authorization button, and a form pops up. Select one or more agents for this tenant. Then click the submit button to initiate a request for tenant - authorized agent.

[0048] iii. When the server receives this request, it will first clear the original old associated data between this tenant and the agents. Then re - store the associated relationship between this tenant and the agents.

[0049] 1) Quota management module: This functional module includes two parts. One is the display of a fine - grained permission list, and the other is setting quotas for fine - grained permissions. The following is a more detailed implementation description for each:

[0050] a) Fine - grained permission list display module: This module performs an associated query on the data generated by the large - model agent management module and the multi - tenant authorized agent module, and divides and displays each piece of data at the tenant - agent - large - model fine - grained level. The meaning of the number in the quota column: If the quota has been set for this piece of data, the specific value is displayed; if the quota has not been set, it is displayed as 0.

[0051] b) Fine - grained permission quota setting module:

[0052] i. First, there is a button for setting quotas in the operation column of the fine - grained permission list. Click this button to trigger a query, obtain the configured quota number for this fine - grained permission, and display this quota number on the form.

[0053] ii. Then, the quota can be modified on this form. Click submit to initiate a request to modify the fine - grained permission quota to the server.

[0054] iii. After the server receives this request, it will determine whether the fine-grained permission for this tenant-agent-large model dimension exists. If it does not exist, a piece of data will be stored in the database and a quota will be set. If it exists, the quota for this piece of data will be updated.

[0055] iv. Through these two functional modules, the setting of fine-grained permission quotas can be completed.

[0056] Embodiment 2, based on Embodiment 1, proposes an implementation method of a multi-tenant fine-grained permission control system based on a large model agent, which is characterized in that: it includes a large model agent management method, and the specific steps are as follows: Create an agent type: Click the create agent type button on the large model agent management module page to create a corresponding agent type for a specific agent platform. For example, create an agent type named "Agent Platform 1" for Agent Platform 1; Register an agent: Click the register agent button on the large model agent management module page, a form will pop up, fill in the agent name, agent Code, agent description, select the agent type, check the set of large model interfaces that need to be accessed, and then submit a registration request; Server verification and response: After the server receives the request to register an agent, it will verify according to the restrictions that the agent type cannot be repeated, the agent name cannot be repeated, the agent Code cannot be repeated, and at least one large model interface must be selected. If the restrictions are not met, a prompt message will be responded to the front-end page; if the restrictions are met, a piece of agent data and the binding relationship data between the agent and the large model will be stored in the database, and the agent details will be responded to the front-end page; Front-end processing response: After the front-end page receives the server response, if the registration fails, the reason for the failure will pop up; if the registration is successful, the data on the agent list page will be refreshed.

[0057] It includes a multi-tenant management method, specifically: maintaining multiple tenant information through the multi-tenant management module, and the tenant information covers tenant accounts, tenant names, enterprise names, mobile phone numbers, email addresses, and tenant statuses; supporting operations such as creating, disabling, modifying, deleting, and viewing tenants to achieve comprehensive management of tenant information.

[0058] It includes a tenant-authorize-agent method, and the specific steps are as follows: Initiate an authorization request: Click the authorization button in the operation column of the multi-tenant management list, a form will pop up, select one or more agents for the tenant, and then click the submit button to initiate a request for the tenant to authorize the agent; Server process the request: After the server receives this request, it will first clear the original old association data between this tenant and the agent, and then re-store the association relationship between this tenant and the agent in the database.

[0059] It includes a method for displaying a fine-grained permission list, specifically: the fine-grained permission list display module performs an associated query on the data generated by the large model agent management module and the multi-tenant authorization agent module; for each piece of data, it performs a fine-grained level division and display of tenant-agent-large model, and the quota column number displays the specific value or 0 according to whether the quota is set or not.

[0060] It includes a method for setting quotas for fine-grained permissions, and the specific steps are as follows: Query the configured quota: Click the set quota button in the operation column of the fine-grained permission list to trigger a query, obtain the configured quota number of this fine-grained permission, and display this quota number on the form; Modify and submit the quota: After modifying the quota on the form, click submit to initiate a request to modify the fine-grained permission quota to the server; The server processes the quota request: After receiving the request, the server determines whether the fine-grained permission in the tenant-agent-large model dimension exists. If it does not exist, it stores a piece of data and sets the quota; if it exists, it updates the data quota, thus completing the setting of the fine-grained permission quota.

[0061] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A multi-tenant fine-grained permission control system based on large model agents, characterized in that: It includes a large model agent management module, which is used to provide the function of presetting intelligent agent APP application information for the intelligent agent platform accessing the large model service; The large model agent management module supports creating agent types and creating corresponding agent types for specific intelligent agent platforms; It supports registering agents. After filling in the agent name, agent Code, agent description, selecting the agent type, and checking the set of large model interfaces to be accessed in the pop-up form, submit a registration request; After receiving the registration request, the server performs verification. If the restriction conditions are not met, it responds with a prompt message. If they are met, it stores the agent data and the binding relationship data between the agent and the large model in the database, and responds with the agent details to the front end; Based on the response result of the server, the front end pops up the reason for failure in case of registration failure and refreshes the data on the agent list page in case of successful registration.

2. The multi-tenant fine-grained permission control system based on a large model agent according to claim 1, wherein: It includes a multi-tenant management module, which is used to maintain information of multiple tenants. The tenant information includes tenant account, tenant name, enterprise name, mobile phone number, email, and tenant status. The multi-tenant management module supports operations such as creating, disabling, modifying, deleting, and viewing tenants to achieve comprehensive management of tenant information.

3. A multi-tenant fine-grained permission control system based on a large model agent according to claim 2, characterized in that: It includes a tenant-authorizing agent module, which is used to realize the authorization association between tenants and agents. There is an authorization button in the operation column of the multi-tenant management list. Clicking the authorization button pops up a form, and one or more agents can be selected for the tenant and then submit a tenant-authorizing agent request. After receiving the request, the server first clears the original old association data between the tenant and the agent, and then stores the association relationship between the tenant and the agent in the database again.

4. The multi-tenant fine-grained permission control system based on large model agents according to claim 3, characterized in that: It includes a fine-grained permission list display module, which performs an associated query on the data generated by the large model agent management module and the multi-tenant authorizing agent module; it divides and displays the data at the fine-grained level of tenant-agent-large model for each piece of data, and the number in the quota column shows the specific value or 0 according to whether the quota is set.

5. The multi-tenant fine-grained permission control system based on the large model agent according to claim 4, wherein: It includes a fine-grained permission setting quota module, which is used to set quotas for fine-grained permissions; there is a set quota button in the operation column of the fine-grained permission list. Clicking this button triggers a query, obtains the configured quota number of this fine-grained permission and displays it on the form; After modifying the quota on the form, submit a request to modify the fine-grained permission quota to the server. After receiving the request, the server determines whether the fine-grained permission in the dimension of tenant-agent-large model exists. If it does not exist, it stores a piece of data and sets the quota. If it exists, it updates the data quota, thus completing the setting of the fine-grained permission quota.

6. A method for implementing a multi-tenant fine-grained permission control system based on a large model agent according to claim 5, characterized in that: It includes a large model agent management method, and the specific steps are as follows: Create an agent type: Click the create agent type button on the page of the large model agent management module to create a corresponding agent type for a specific intelligent agent platform. For example, create an agent type named "Intelligent Agent Platform 1" for Intelligent Agent Platform 1; Register an agent: Click the register agent button on the page of the large model agent management module, a form will pop up. Fill in the agent name, agent Code, agent description, select the agent type, check the set of large model interfaces to be accessed and then submit a registration request; Server - side Verification and Response: After the server receives the request to register an intelligent agent, it verifies according to the restrictive conditions that the intelligent agent type cannot be repeated, the intelligent agent name cannot be repeated, the intelligent agent Code cannot be repeated, and at least one large - model interface must be selected. If the restrictive conditions are not met, it responds with a prompt message to the front - end page; If the restrictive conditions are met, it stores a piece of intelligent agent data and the binding relationship data between the intelligent agent and the large - model, and responds with the intelligent agent details to the front - end page; Front - end Processing of Response: After the front - end page receives the server response, if the registration fails, it pops up the reason for failure; If the registration is successful, it refreshes the data on the intelligent agent list page.

7. The implementation method of a multi-tenant fine-grained permission control system based on a large model agent according to claim 6, characterized in that: It includes a multi - tenant management method, specifically: maintaining multiple tenant information through a multi - tenant management module, where the tenant information covers tenant accounts, tenant names, enterprise names, mobile phone numbers, email addresses, and tenant statuses; supporting operations such as creating, disabling, modifying, deleting, and viewing tenants to achieve comprehensive management of tenant information.

8. The implementation method of a multi-tenant fine-grained permission control system based on a large model agent according to claim 7, characterized in that: It includes a method for a tenant to authorize an intelligent agent, and the specific steps are as follows: Initiate an authorization request: Click the authorization button in the operation column of the multi - tenant management list, a form pops up. After selecting one or more intelligent agents for the tenant and clicking the submit button, it initiates a request for the tenant to authorize the intelligent agent; Server - side Processing of the Request: After the server receives this request, it first clears the original old association data between this tenant and the intelligent agent, and then re - stores the association relationship between this tenant and the intelligent agent.

9. The implementation method of a multi-tenant fine-grained permission control system based on a large model agent according to claim 8, characterized in that: It includes a method for displaying a fine - grained permission list, specifically: associatively querying the data generated by the large - model intelligent agent management module and the multi - tenant authorized intelligent agent module through the fine - grained permission list display module; performing tenant - intelligent agent - large - model fine - grained level division and display for each piece of data, and the number in the quota column shows the specific value or 0 according to whether the quota is set.

10. The implementation method of a multi-tenant fine-grained permission control system based on a large model agent according to claim 9, characterized in that: It includes a method for setting a quota for fine - grained permissions, and the specific steps are as follows: Query the configured quota: Click the set - quota button in the operation column of the fine - grained permission list to trigger a query, obtain the configured quota number for this fine - grained permission, and display this quota number on the form; Modify and submit the quota: After modifying the quota on the form and clicking submit, it initiates a request to modify the fine - grained permission quota to the server; Server - side Processing of the Quota Request: After the server receives the request, it determines whether the fine - grained permission in the tenant - intelligent agent - large - model dimension exists. If it does not exist, it stores a piece of data and sets the quota; If it exists, it updates the data quota, thus completing the setting of the fine - grained permission quota.

Citation Information

Cited By

  • Intelligent agent collaborative management system and method based on multi-tenant isolation and dynamic role permission

    CN120896736A

  • Intelligent agent development and safe operation method and system based on private cloud

    CN121711148A