Request processing method and system and readable storage medium
By using zero-knowledge proof technology in AI model services, anonymous requests are generated and legality verification is carried out, the problems of user privacy protection and security in AI model services are solved, and anonymity and security are improved.
Patent Information
- Application Number
- CN202510695567.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-28
- Publication Date
- 2025-07-18
AI Technical Summary
The existing AI model services have shortcomings in user privacy protection and security. The traditional token statistics method is susceptible to man-in-the-middle attacks and replay attacks, and cannot achieve true anonymity and flexibility.
Using zero-knowledge proof technology, we generate real-name credential encrypted ciphertexts, anonymous statistical auxiliary sequences and anonymous statistical credential initialization variables by extracting random numbers from a large prime-order integer set, and generate zero-knowledge proofs, and perform anonymous request verification in the AI model service.
It achieves the improvement of user anonymity and security, prevents man-in-the-middle attacks and replay attacks, and supports malicious behavior tracking, improving verification efficiency and security.
Smart Images

Figure CN120342638A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and particularly to a request processing method, system and readable storage medium. Background Art
[0002] AI (Artificial Intelligence) models are increasingly widely used in fields such as education, medical care, and finance. Currently, mainstream large AI model services generally adopt a service measurement and statistics method based on tokens (basic processing units), that is, the quantification of services is determined based on the number of tokens.
[0003] Existing statistical systems have deficiencies in user privacy protection. For example, some statistical methods require users to provide real identity information (such as email, mobile phone number) for authentication and statistics when using AI models, resulting in service providers being able to obtain user behavior portraits (including sensitive data such as user usage behaviors, query contents, consumption habits, etc.) through full-link tracking, forming a risk of privacy leakage; the statistical process lacks security guarantees. For example, traditional token statistical methods mainly rely on simple API key authentication and counting mechanisms, and there are problems such as being vulnerable to man-in-the-middle attacks, resulting in the leakage of API keys; the statistical process is vulnerable to replay attacks, causing duplicate statistics, and there are various security risks such as statistical data being tampered with or forged.
[0004] Current solutions mainly include: some decentralized solutions still have high latency and high costs; traditional encryption authentication solutions, although providing basic security protection, cannot achieve true anonymity; coupon models, although supporting anonymous use, have poor flexibility and are difficult to track abuse behaviors.
[0005] In summary, how to effectively solve problems such as information security in the process of using AI model services is an urgent technical problem for those skilled in the art at present. Summary of the Invention
[0006] The purpose of the present application is to provide a request processing method, system and readable storage medium. This solution can not only achieve the anonymity of user identities, but also ensure the security and efficiency of the statistical process. In addition, it also supports the tracking of malicious behaviors, and has important theoretical value and practical significance.
[0007] To solve the above technical problems, the present application provides the following technical solutions:
[0008] A request processing method, applied to the client of an AI model service, includes:
[0009] During the process of accessing the AI model service, extract a number of random numbers from a set of large prime order integers that match a bilinear group;
[0010] Determine the encrypted ciphertext of the real-name credential, the anonymous statistical auxiliary sequence, and the initialization variable of the anonymous statistical credential by using the random number;
[0011] Generate a zero-knowledge proof by using the encrypted ciphertext of the real-name credential, the anonymous statistical auxiliary sequence, and the initialization variable of the anonymous statistical credential;
[0012] After adding the zero-knowledge proof to the anonymous request, send the anonymous request to the server where the AI model service is located;
[0013] Receive the response result feedback by the server after verifying the legality of the anonymous request based on the zero-knowledge proof and in combination with the bilinear group.
[0014] Preferably, the random number includes a first random number, a second random number, and a third random number. Determining the encrypted ciphertext of the real-name credential, the anonymous statistical auxiliary sequence, and the initialization variable of the anonymous statistical credential by using the random number includes:
[0015] Calculate the identity hash identifier of the server;
[0016] Encrypt the real-name credential by using the first random number and the identity hash identifier to obtain the encrypted ciphertext of the real-name credential;
[0017] Determine the anonymous statistical auxiliary sequence by using the second random number in combination with a random private key;
[0018] Determine the initialization variable of the anonymous statistical credential by using the third random number in combination with the bilinear group.
[0019] Preferably, the process of obtaining the real-name credential includes:
[0020] Determine the random private key from the set of integers of large prime order;
[0021] Determine a random element from the target cyclic group corresponding to the bilinear group;
[0022] Encrypt the random private key by using the random element to obtain the encrypted ciphertext of the private key;
[0023] Send the real-name registration request carrying the encrypted ciphertext of the private key to the server;
[0024] Receive the real-name credential feedback by the server.
[0025] Preferably, after receiving the real-name credential feedback by the server, it further includes:
[0026] Determine the user private key and the user public key by using the real-name credential.
[0027] Preferably, it further includes:
[0028] During the process of accessing the AI model service for query, determine the target quantity of basic processing units required for this query;
[0029] Update the total consumption quantity of basic processing units by using the target quantity;
[0030] Calculate an anonymous credential by using the total consumption quantity;
[0031] Generate a zero-knowledge proof of anonymous query by combining the bilinear group and the anonymous credential;
[0032] Send an anonymous query request carrying the zero-knowledge proof of anonymous query to the server;
[0033] Receive the query result feedback by the server after verifying the legality of the anonymous query request based on the zero-knowledge proof of anonymous query.
[0034] Preferably, generating a zero-knowledge proof of anonymous query by combining the bilinear group and the anonymous credential includes:
[0035] Obtain a target random number from the set of integers of large prime order;
[0036] Calculate an anonymous statistical auxiliary verification item and an anonymous statistical credential verification item by using the target random number;
[0037] After determining an anonymous statistical credential hash item and an anonymous credential ciphertext item by combining the bilinear group, generate the zero-knowledge proof of anonymous query by using the anonymous statistical auxiliary verification item, the anonymous statistical credential verification item, the anonymous statistical credential hash item, and the anonymous credential ciphertext item.
[0038] A request processing method, applied to the server of an AI model service, includes:
[0039] Receive an anonymous request sent by a client of the AI model service, and obtain a zero-knowledge proof from the anonymous request;
[0040] Calculate its own identity hash identifier;
[0041] Restore the verification item of the client's registration credential, the anonymous statistical auxiliary sequence verification item, and the verification item of the anonymous statistical credential initialization variable by using the zero-knowledge proof;
[0042] Determine whether the anonymous adjustment information hash item has changed by combining the verification item of the registration credential, the anonymous statistical auxiliary sequence verification item, and the verification item of the anonymous statistical credential initialization variable;
[0043] If the answer is no, determine that the anonymous request passes the legality verification and feedback the response result to the client.
[0044] Preferably, it further includes:
[0045] Receive the anonymous query request sent by the client, and obtain the anonymous query zero-knowledge proof and the target quantity of the basic processing units required for this query from the anonymous query request;
[0046] Determine whether the target quantity is abnormal;
[0047] If it is, determine that the anonymous query request is a malicious request;
[0048] If the answer is no, use the anonymous query zero-knowledge proof to perform legality verification on the anonymous query request, and after the verification passes, feedback the query result to the client.
[0049] A request processing system includes:
[0050] The client of the AI model service and the server of the AI model service;
[0051] The client and the server have a communication connection;
[0052] The client is used to execute the steps of the above request processing method;
[0053] The server is used to execute the steps of the request processing method as described above.
[0054] A readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the steps of the above request processing method.
[0055] Applying the method provided by the embodiments of the present application, during the process of the client of the AI model service accessing the AI model service, several random numbers are extracted from the set of large prime-order integers matching the bilinear group; the real-name credential encryption ciphertext, the anonymous statistical auxiliary sequence, and the anonymous statistical credential initialization variable are determined using the random numbers; a zero-knowledge proof is generated using the real-name credential encryption ciphertext, the anonymous statistical auxiliary sequence, and the anonymous statistical credential initialization variable; after adding the zero-knowledge proof to the anonymous request, the anonymous request is sent to the server where the AI model service is located; the response result feedback by the server after performing legality verification on the anonymous request based on the zero-knowledge proof and in combination with the bilinear group is received.
[0056] In this application, when the client of the AI model service needs to increase the number of tokens during the process of accessing the AI model service, instead of directly using real-name information for adjustment, an anonymous request is sent to the server of the AI model service with the help of zero-knowledge proof. Among them, to generate the zero-knowledge proof in the client, several random numbers can be first extracted from the set of large prime-order integers matching the bilinear group. Then, the real-name credential encryption ciphertext, anonymous statistical auxiliary sequence, and anonymous statistical credential initialization variables are determined using the random numbers. Finally, the zero-knowledge proof is generated by using the real-name credential encryption ciphertext, anonymous statistical auxiliary sequence, and anonymous statistical credential initialization variables. Then, the server of the AI model service performs a legality verification on the anonymous request based on the zero-knowledge proof in the anonymous request, thereby realizing the legality verification and Token quantity adjustment processing.
[0057] That is to say, this application allows users to anonymously adjust the Token quantity and anonymously access during the process of using the AI model query; while the AI service provider can only obtain the user's question content and cannot obtain the user's real identity, enhancing the user's privacy protection.
[0058] Correspondingly, the embodiment of this application also provides a request processing system and a readable storage medium corresponding to the above request processing method, which have the above technical effects and will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] In order to more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are only some embodiments of this application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0060] Figure 1 It is the flowchart of the implementation of a request processing method in the embodiment of this application;
[0061] Figure 2 It is the schematic structural diagram of a request processing system in the embodiment of this application;
[0062] Figure 3 It is the interaction schematic diagram in a request processing method in the embodiment of this application;
[0063] Figure 4 It is the schematic diagram of a real-name registration in the embodiment of this application;
[0064] Figure 5 It is the schematic diagram of anonymously adjusting Token in the embodiment of this application;
[0065] Figure 6This is a schematic diagram of anonymous query in the embodiments of the present application. Detailed implementation manners
[0066] To enable those skilled in the art of the present technology to better understand the solution of the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific implementation manners. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of the present application.
[0067] Please refer to Figure 1 , Figure 1 This is a flowchart of a request processing method in the embodiments of the present application. This method can be applied to the client of the AI model service. The method includes the following steps:
[0068] S101. During the process of accessing the AI model service, extract a plurality of random numbers from the set of large prime order integers matching the bilinear group.
[0069] The bilinear group in the embodiments of the present application is as follows:
[0070] ;
[0071] Wherein: is a large prime number; the group and the group are cyclic groups of prime order , and the group elements are points on the elliptic curve; is a cyclic group of prime order ; the element and are respectively the generators of the group and the group ; is a random element on the group ; is the homomorphism mapping from the group to the group ; is an asymmetric bilinear mapping and ; is the integer set ; and are cryptographic hash functions, which respectively map any bit string input to an integer on the integer set and an element on the group ; is the public-private key pair of the AI service provider.
[0072] Specifically, it is possible to select from the group Randomly sample 3 random integers from .
[0073] In the embodiment of the present application, as Figure 3 shown, at the initial stage of accessing the AI model service, the client can perform real-name registration. After completing the real-name registration, a real-name certificate can be obtained. That is to say, the initial acquisition of the real-name certificate is the real-name registration process, that is, the real-name registration protocol is executed. Specifically, the process of obtaining the real-name certificate includes:
[0074] Determine a random private key from the set of integers of large prime order;
[0075] Determine a random element from the target cyclic group corresponding to the bilinear group;
[0076] Encrypt the random private key with the random element to obtain a private key ciphertext;
[0077] Send a real-name registration request carrying the private key ciphertext to the server;
[0078] Receive the real-name certificate feedback by the server.
[0079] For ease of description, the above steps will be combined and described below.
[0080] As Figure 4 shown, when executing the real-name registration protocol, the client (i.e., the user side) selects a random private key , calculates the private key ciphertext , and sends to the AI service provider (i.e., the server). After receiving the private key ciphertext , the AI service provider generates a user certificate random number , calculates the user registration certificate (real-name certificate) , and returns to the user and records the user registration information list , where the ID is the user's real identity information (which can be an email address, a mobile phone number, etc.), is the user certificate information binding item, and the user detects and tracks malicious users.
[0081] After receiving the real-name certificate, the user can detect the validity of the registration certificate. The specific method is as follows: First, check whether the equation holds. If it holds, it indicates that the registration certificate is valid; otherwise, it means that the certificate is an invalid certificate.
[0082] In a specific implementation manner of the present application, after receiving the real-name certificate feedback by the server, it further includes: determining the user private key and the user public key using the real-name certificate. That is, after receiving a valid registration certificate, the user will set the user public key to , set the user's private key as .
[0083] S102. Use random numbers to determine the encrypted ciphertext of the real-name certificate, the anonymous statistical auxiliary sequence, and the initialization variables of the anonymous statistical certificate.
[0084] In this embodiment, except that the request sent during real-name registration is a real-name request, the rest of the requests can be anonymous requests. To ensure that the legality of anonymous requests can be verified without revealing the user's privacy, zero-knowledge proof is used for verification in this application. Before generating the zero-knowledge proof, first determine the encrypted ciphertext of the real-name certificate, the anonymous statistical auxiliary sequence, and the initialization variables of the anonymous statistical certificate for further use in generating the zero-knowledge proof.
[0085] In a specific implementation manner of this application, the random numbers include a first random number, a second random number, and a third random number. Using the random numbers to determine the encrypted ciphertext of the real-name certificate (ElGamal encryption), the anonymous statistical auxiliary sequence, and the initialization variables of the anonymous statistical certificate includes:
[0086] Calculate the identity hash identifier of the server;
[0087] Use the first random number and the identity hash identifier to encrypt the real-name certificate to obtain the encrypted ciphertext of the real-name certificate;
[0088] Use the second random number and combine it with the random private key to determine the anonymous statistical auxiliary sequence;
[0089] Use the third random number and combine it with the bilinear group to determine the initialization variables of the anonymous statistical certificate.
[0090] For ease of description, the above steps will be combined and described below.
[0091] Specifically, calculate the identity hash identifier of the AI model service provider ;
[0092] Calculate the encrypted ciphertext of the user registration certificate (i.e., the encrypted ciphertext of the real-name certificate): ;
[0093] Calculate the user's anonymous statistical auxiliary sequence:
[0094] ;
[0095] Calculate the initialization variables of the user's anonymous statistical certificate:
[0096] .
[0097] S103. Use the encrypted ciphertext of the real-name certificate, the anonymous statistical auxiliary sequence, and the initialization variables of the anonymous statistical certificate to generate a zero-knowledge proof.
[0098] Among them, represents a zero-knowledge proof, and its formal representation is as follows:
[0099] ;
[0100] Among them, a, b, and c are the first, second, and third random numbers, x is the user credential random number, y is the user private key, is the boundary trapdoor; S is the public key of the AI service provider, is the registration credential auxiliary proof random number, Rpt is the document for the user to anonymously consume the Token, T is the total number of Tokens applied for by the user, and the zero-knowledge can prove the following relationship:
[0101] 1. Prove that the user has a valid registration credential Cert, and the generated registration credential ciphertext is a valid ciphertext (α sequence). The proof relationship can be verified through this formula (signature verification):
[0102] ;
[0103] 2. Prove that the power of the user's anonymous statistical auxiliary sequence (β sequence) is the correct sequence generated by the user private key , that is: ;
[0104] 3. Prove that the user's anonymous statistical credential (γ sequence) is a valid credential: .
[0105] 4. The three relationships proved above all use the same user private key y. That is, the finally generated zero-knowledge proof can ensure that the user not only has a legal registration credential (α sequence), and the generation of the user's anonymous statistical auxiliary sequence (β sequence) is in a binding relationship with this registration credential (preventing impersonation), and the generated user's anonymous statistical credential (γ sequence) is a valid anonymous statistical credential for it (preventing forgery).
[0106] Specifically, the specific implementation details of generating the zero-knowledge proof are as follows:
[0107] (a) Randomly generate 7 random numbers from the group for assisting in generating the zero-knowledge proof;
[0108] (b) Calculate the verification items of α, β, and γ respectively:
[0109] (b.1) Calculate the verification item of the registration credential (α sequence):
[0110] ;
[0111] (b.2) Calculate the verification items of the user anonymous statistical auxiliary sequence (β sequence):
[0112] ;
[0113] (b.3) Calculate the verification items of the user anonymous statistical credential boundary trapdoor (γ sequence): ; ;
[0114] (c) Calculate the anonymous adjustment information hash item (the input is the public key of the AI service provider, the total number of applied Tokens, the transfer voucher Rpt, the α / β / γ sequences and their corresponding verification items):
[0115] ;
[0116] (g) Using the hash item h, for all privacy information , calculate its ciphertext ;
[0117] (i) Finally, the zero-knowledge proof is .
[0118] S104. After adding the zero-knowledge proof to the anonymous request, send the anonymous request to the server where the AI model service is located.
[0119] Send the anonymous request carrying to the server.
[0120] S105. Receive the response result feedback by the server after verifying the legality of the anonymous request based on the zero-knowledge proof and combined with the bilinear group.
[0121] Please refer to Figure 5 , and take the anonymous adjustment Token request as an example of the anonymous request below to illustrate the processing process of the server.
[0122] After the AI service provider receives the anonymous adjustment Token request (including the user's ), it verifies the relevant information:
[0123] Step 1: Calculate the identity hash identifier of the AI model service provider ;
[0124] Step 2: Restore the verification items of the registration credential:
[0125] ;
[0126] Step 3: Restore the verification items of the user anonymous statistical auxiliary sequence:
[0127] ;
[0128] Step 4: Restore the verification items of the initialization variables of the user's anonymous statistical credentials: ;
[0129] Step 5: Second check equation: whether it holds; if it does not hold, it means that the anonymous adjustment information is invalid, and the AI service provider will reject the anonymous request; if it holds, receive the anonymous adjustment information and save the relevant information items to the database: and return Ind to the user, where: Ind is the database index, is the number of Tokens adjusted for this anonymous user, is the number of Tokens already used by this anonymous user (initialized to 0), is the anonymous statistical credential for the most recent anonymous query (initialized to the identity element of the group ).
[0130] When applying the method provided by the embodiments of the present application, during the process of the client of the AI model service accessing the AI model service, several random numbers are extracted from the set of large prime-order integers matching the bilinear group; the encrypted ciphertext of the real-name credential, the anonymous statistical auxiliary sequence, and the initialization variables of the anonymous statistical credential are determined by using the random numbers; a zero-knowledge proof is generated by using the encrypted ciphertext of the real-name credential, the anonymous statistical auxiliary sequence, and the initialization variables of the anonymous statistical credential; after adding the zero-knowledge proof to the anonymous request, the anonymous request is sent to the server where the AI model service is located; the response result feedback by the server after verifying the legality of the anonymous request based on the zero-knowledge proof and in combination with the bilinear group is received.
[0131] In the present application, during the process of the client of the AI model service accessing the AI model service, when the number of tokens needs to be increased, instead of directly using the real-name information for adjustment, an anonymous request is sent to the server of the AI model service by means of a zero-knowledge proof. Among them, for the generation of the zero-knowledge proof in the client, several random numbers can be first extracted from the set of large prime-order integers matching the bilinear group, and then, the encrypted ciphertext of the real-name credential, the anonymous statistical auxiliary sequence, and the initialization variables of the anonymous statistical credential are determined by using the random numbers, and finally a zero-knowledge proof is generated by using the encrypted ciphertext of the real-name credential, the anonymous statistical auxiliary sequence, and the initialization variables of the anonymous statistical credential. Then, the server of the AI model service performs a legality check on the anonymous request based on the zero-knowledge proof in the anonymous request, so as to implement the legality verification and the Token quantity adjustment process.
[0132] That is to say, this application allows users to anonymously adjust the number of tokens and access anonymously during the process of querying using the AI model. The AI service provider can only obtain the user's question content and cannot obtain the user's real identity, thus enhancing user privacy protection.
[0133] In the embodiment of this application, to improve the query efficiency, the zero-knowledge proof used in the query process can be simplified as follows: 1. The valid identity proof (i.e., the validity of the user registration certificate) has been completed during the anonymous adjustment of tokens and the validity of the anonymous statistical auxiliary sequence, which can ensure that the user owns the user private key bound to the registration certificate (preventing impersonation). Then, during the anonymous query process, the user only needs to generate a zero-knowledge proof of the anonymous query certificate, prove the validity of the certificate, and associate it with the zero-knowledge of token adjustment / query. This includes:
[0134] During the process of accessing the AI model service for query, determine the target number of basic processing units required for this query;
[0135] Update the total consumption quantity of the basic processing units using the target quantity;
[0136] Calculate the anonymous certificate using the total consumption quantity;
[0137] Combine the bilinear group and the anonymous certificate to generate a zero-knowledge proof of anonymous query;
[0138] Send the anonymous query request carrying the zero-knowledge proof of anonymous query to the server;
[0139] Receive the query result feedback by the server after verifying the legality of the anonymous query request based on the zero-knowledge proof of anonymous query.
[0140] Among them, combining the bilinear group and the anonymous certificate to generate a zero-knowledge proof of anonymous query includes:
[0141] Obtain the target random number from the set of integers of large prime order;
[0142] Use the target random number to calculate the anonymous statistical auxiliary verification item and the anonymous statistical certificate verification item;
[0143] After determining the anonymous statistical certificate hash item and the anonymous certificate ciphertext item by combining the bilinear group, generate a zero-knowledge proof of anonymous query using the anonymous statistical auxiliary verification item, the anonymous statistical certificate verification item, the anonymous statistical certificate hash item, and the anonymous certificate ciphertext item.
[0144] For the convenience of description, the above steps will be combined and described below.
[0145] Please refer to Figure 6, when executing the AI service anonymous query protocol (anonymous query), assume that the user's current query requires consuming t Tokens (1 ≤ t ≤ T), and the database index item corresponding to this anonymous user is , the user side performs the following steps:
[0146] Step 1: Update the total consumed Token quantity to , and calculate the anonymous query credential ;
[0147] Step 2: Generate a zero - knowledge proof , and its calculation method is as follows:
[0148] (a) Generate a random number from the group ;
[0149] (b) Calculate the anonymous statistical auxiliary verification item and the anonymous statistical credential verification item ;
[0150] (c) Calculate the anonymous statistical credential hash item ;
[0151] (d) Calculate the anonymous credential ciphertext item ;
[0152] (e) Let the zero - knowledge proof be ;
[0153] Step 3: The user sends the query request and the corresponding anonymous query statistical credential (i.e., the zero - knowledge proof) to the AI service provider.
[0154] When the AI service provider receives the anonymous query request and the anonymous statistical credential , the verifier performs the following calculation steps:
[0155] Step 1: According to the database index, search for the relevant information item ;
[0156] Step 2: If , it means that the user is a malicious user, then calculate , and search for the corresponding identity ID from the user real - name registration information list , and then corresponding penalty measures can be taken for this ID (such as disabling the query service, etc.);
[0157] Step 3: If , it means that the user has not exceeded the access Token quantity limit, then restore the anonymous statistical auxiliary verification item and the anonymous statistical credential verification item ;
[0158] Step 4: Check the equation to see if it holds. If it does not hold, it means that the anonymous credential is invalid, and the anonymous query is rejected; if it holds, the anonymous query is accepted, the user query result is returned, and the database is updated.
[0159] .
[0160] This application also provides a request processing method for the server side of an AI model service, and the method includes:
[0161] Receive an anonymous request sent by the client of the AI model service, and obtain a zero-knowledge proof from the anonymous request;
[0162] Calculate its own identity hash identifier;
[0163] Use the zero-knowledge proof to restore the verification items of the client's registration credential, the verification items of the anonymous statistical auxiliary sequence, and the verification items of the anonymous statistical credential initialization variable;
[0164] Combine the verification items of the registration credential, the verification items of the anonymous statistical auxiliary sequence, and the verification items of the anonymous statistical credential initialization variable to determine whether the anonymous adjustment information hash item has changed;
[0165] If not, it is determined that the anonymous request passes the legality verification, and the response result is fed back to the client.
[0166] In a specific implementation manner of this application, it further includes:
[0167] Receive an anonymous query request sent by the client, and obtain an anonymous query zero-knowledge proof and the target quantity of the basic processing units required for this query from the anonymous query request;
[0168] Judge whether the target quantity is abnormal;
[0169] If so, it is determined that the anonymous query request is a malicious request;
[0170] If not, use the anonymous query zero-knowledge proof to perform legality verification on the anonymous query request, and after the verification passes, feed back the query result to the client.
[0171] The above method is the request processing process corresponding to the server of the AI model service. For the specific description of the above request processing method, please refer to it and will not be elaborated here. Using the zero-knowledge proof method and embedding it into the AI large model Token anonymous statistics system can not only protect the identity of users during the query process from being exposed, but also prevent attacks such as man-in-the-middle replay. Moreover, only the user side with the secret key can calculate the anonymous query credential, which can ensure that the attacker cannot forge the credential. For malicious users who access more than the specified number of Tokens, their real IDs can be traced, ensuring the anonymity, non-forgeability of the entire query process and the traceability of malicious users.
[0172] Corresponding to the above method embodiments, the embodiment of the present application also provides a request processing system. The request processing system described below can be correspondingly referred to the request processing method described above.
[0173] See Figure 2 As shown, the request processing system includes:
[0174] The client 100 of the AI model service and the server 200 of the AI model service;
[0175] The client and the server have a communication connection;
[0176] The client is used to execute the steps of the request processing method applicable to the client described in the above embodiments;
[0177] The server is used to execute the steps of the request processing method applicable to the server described in the above embodiments.
[0178] In the application scenario of the AI service platform, when the client is used for the first time, real-name registration is required to ensure the authenticity of the identity. The system will execute the real-name registration protocol (i.e., real-name registration). The user needs to provide key information such as real name, ID number, and mobile phone number. After submitting this information, the AI service provider will use an encryption algorithm to encrypt the user's key information, generate a unique user identifier, and bind it to the user ID. This process ensures the security of user information and lays a foundation for subsequent anonymous operations.
[0179] After completing the registration, the user can anonymously adjust the number of Tokens, following the anonymous adjustment protocol (i.e., the process of anonymously adjusting Tokens). The user can choose to obtain different numbers of Tokens at this stage, such as 100 or 500. Calculate the zero-knowledge proof from the obtained credential of the Token and the real-name credential generated during real-name registration, and submit it to the server. This zero-knowledge proof ensures that the user's identity information will not be leaked. The system only records information such as index credentials, Token numbers, and zero-knowledge proofs, without associating any real-name registration information.
[0180] After completing the anonymous adjustment of the number of Tokens (i.e., obtaining more Tokens to increase the number of Tokens), the user can conduct an anonymous query. At this time, the system will count the number of Tokens required for this query. The user generates the corresponding zero-knowledge proof by using the private key generated during real-name registration and the index certificate returned by the anonymous adjustment protocol, and sends it to the server for verification. After the server verification passes, the system will search for the corresponding Token record according to the index certificate, deduct the corresponding number of Tokens, and provide the user with an anonymous AI query service.
[0181] It can be seen that the security of the zero-knowledge proof: ensuring that the generated zero-knowledge proof can effectively verify the user's adjustment record without disclosing any user personal information.
[0182] The relevance between the anonymous adjustment record and the legitimate user: A mechanism can be designed to securely associate the anonymous adjustment record with the user's real-name registration information within the system, so that legitimate identity verification can be carried out when needed without exposing the user's identity. And attackers cannot forge or impersonate the user's identity.
[0183] The relevance between the anonymous adjustment record and the anonymous query authentication: A mechanism can be designed to securely associate the anonymous adjustment record with the user's anonymous query authentication, preventing attacks such as impersonation and forgery while not disclosing the user's information.
[0184] Through the above measures, the user's identity security and privacy can be effectively protected, while providing a convenient anonymous service and improving the user experience.
[0185] When applying the request processing system provided by the embodiments of the present application, the client of the AI model service extracts a number of random numbers from the set of large prime order integers matching the bilinear group during the process of accessing the AI model service; determines the encrypted ciphertext of the real-name certificate, the anonymous statistical auxiliary sequence, and the initialization variable of the anonymous statistical certificate by using the random numbers; generates a zero-knowledge proof by using the encrypted ciphertext of the real-name certificate, the anonymous statistical auxiliary sequence, and the initialization variable of the anonymous statistical certificate; adds the zero-knowledge proof to the anonymous request and then sends the anonymous request to the server where the AI model service is located; receives the response result feedback by the server after verifying the legality of the anonymous request based on the zero-knowledge proof and in combination with the bilinear group.
[0186] In this application, when the client of the AI model service needs to increase the number of tokens during the process of accessing the AI model service, instead of directly using real-name information for adjustment, an anonymous request is sent to the server of the AI model service with the help of zero-knowledge proof. Among them, the generation of zero-knowledge proof in the client can first extract several random numbers from the set of large prime-order integers matching the bilinear group, and then use the random numbers to determine the encrypted ciphertext of the real-name credential, the anonymous statistical auxiliary sequence, and the initialization variable of the anonymous statistical credential. Finally, the zero-knowledge proof is generated by using the encrypted ciphertext of the real-name credential, the anonymous statistical auxiliary sequence, and the initialization variable of the anonymous statistical credential. Then, the server of the AI model service performs a legality check on the anonymous request based on the zero-knowledge proof in the anonymous request, so as to implement the legality verification and the processing of token number adjustment.
[0187] That is to say, this application allows users to anonymously adjust the token number and anonymously access during the process of using the AI model query; while the AI service provider can only obtain the user's question content and cannot obtain the user's real identity, which improves the privacy protection of users.
[0188] Corresponding to the above method embodiment, this application embodiment also provides a readable storage medium, and a readable storage medium described below can be correspondingly referred to the request processing method described above.
[0189] A readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the steps of the request processing method in the above method embodiment.
[0190] The readable storage medium can specifically be various readable storage media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc that can store program codes.
[0191] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method part.
[0192] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in the form of hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0193] The steps of the methods or algorithms described in combination with the embodiments disclosed herein can be directly implemented by hardware, software modules executed by a processor, or a combination of both. The software modules can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field.
[0194] Finally, it should also be noted that in this article, relationships such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "including", "comprising" or any other variant is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device.
[0195] Specific examples are used in this article to elaborate on the principles and implementation manners of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to this application.
Claims
1. A request processing method, characterized in that, A client applied to an AI model service, including: During the process of accessing the AI model service, extracting a number of random numbers from a set of large prime-order integers matching a bilinear group; Using the random numbers to determine a real-name credential encrypted ciphertext, an anonymous statistical auxiliary sequence, and an anonymous statistical credential initialization variable; Generating a zero-knowledge proof using the real-name credential encrypted ciphertext, the anonymous statistical auxiliary sequence, and the anonymous statistical credential initialization variable; After adding the zero-knowledge proof to an anonymous request, sending the anonymous request to the server where the AI model service is located; Receiving a response result feedback by the server after verifying the legality of the anonymous request based on the zero-knowledge proof and in combination with the bilinear group.
2. The method according to claim 1, wherein The random numbers include a first random number, a second random number, and a third random number. Using the random numbers to determine a real-name credential encrypted ciphertext, an anonymous statistical auxiliary sequence, and an anonymous statistical credential initialization variable includes: Calculating the identity hash identifier of the server; Using the first random number and the identity hash identifier to encrypt the real-name credential to obtain the real-name credential encrypted ciphertext; Using the second random number and in combination with a random private key to determine the anonymous statistical auxiliary sequence; Using the third random number and in combination with the bilinear group to determine the anonymous statistical credential initialization variable.
3. The method according to claim 2, wherein The process of obtaining the real-name credential includes: Determining the random private key from the set of large prime-order integers; Determining a random element from the target cyclic group corresponding to the bilinear group; Using the random element to encrypt the random private key to obtain a private key ciphertext; Sending a real-name registration request carrying the private key ciphertext to the server; Receiving the real-name credential feedback by the server.
4. The method according to claim 3, wherein After receiving the real-name credential feedback by the server, it further includes: Using the real-name credential to determine a user private key and a user public key.
5. The method according to any one of claims 1 to 4, characterized in that, It further includes: During the process of querying by accessing the AI model service, determining the target quantity of basic processing units required for this query; Updating the total consumption quantity of basic processing units using the target quantity; Calculating an anonymous credential using the total consumption quantity; Generating an anonymous query zero-knowledge proof in combination with the bilinear group and the anonymous credential; Sending an anonymous query request carrying the anonymous query zero-knowledge proof to the server; Receiving a query result feedback by the server after verifying the legality of the anonymous query request based on the anonymous query zero-knowledge proof.
6. The method according to claim 5, wherein Generating an anonymous query zero-knowledge proof in combination with the bilinear group and the anonymous credential includes: Obtaining a target random number from the set of large prime-order integers; Using the target random number to calculate an anonymous statistical auxiliary verification item and an anonymous statistical credential verification item; After determining an anonymous statistical credential hash item and an anonymous credential ciphertext item in combination with the bilinear group, generating the anonymous query zero-knowledge proof using the anonymous statistical auxiliary verification item, the anonymous statistical credential verification item, the anonymous statistical credential hash item, and the anonymous credential ciphertext item.
7. A request processing method, characterized in that, A server applied to an AI model service, including: Receive an anonymous request sent by a client of the AI model service, and obtain a zero-knowledge proof from the anonymous request; Calculate its own identity hash identifier; Use the zero-knowledge proof to recover the verification items of the client's registration credential, the verification items of the anonymous statistical auxiliary sequence, and the verification items of the anonymous statistical credential initialization variable; Combine the verification items of the registration credential, the verification items of the anonymous statistical auxiliary sequence, and the verification items of the anonymous statistical credential initialization variable to determine whether the anonymous adjustment information hash item has changed; If not, determine that the anonymous request passes the legality verification and feedback the response result to the client.
8. The method according to claim 7, wherein It further includes: Receive an anonymous query request sent by the client, and obtain an anonymous query zero-knowledge proof and the target quantity of the basic processing units required for this query from the anonymous query request; Judge whether the target quantity is abnormal; If so, determine that the anonymous query request is a malicious request; If not, use the anonymous query zero-knowledge proof to verify the legality of the anonymous query request, and after the verification passes, feedback the query result to the client.
9. A request processing system, characterized in that, It includes: A client of the AI model service and a server of the AI model service; The client and the server have a communication connection; The client is used to execute the steps of the request processing method according to any one of claims 1 to 6; The server is used to execute the steps of the request processing method according to claim 7 or 8.
10. A readable storage medium, characterized in that, A computer program is stored on the readable storage medium, and when the computer program is executed by a processor, the steps of the request processing method according to any one of claims 1 to 8 are implemented.