Network security access method and device for large model task, equipment and medium

By receiving and judging access requests from authorized devices or users, and collecting access logs on the trusted log platform, the problem of low security in large-model task processing in cloud computing is solved, and secure and reliable access control and logging are achieved.

CN120342698AActive Publication Date: 2025-07-18BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510504177.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-21
Publication Date
2025-07-18
Estimated Expiration
2045-04-21

AI Technical Summary

Technical Problem

In cloud computing scenarios, the existing technology blocks partial access through task-level network isolation, but the effect is poor, resulting in low security in large-scale task processing, which may lead to unauthorized access and data leakage.

Method used

By receiving the target access request, we determine whether the sending device and the user are authorized, and collect access logs on the trusted log platform. Only authorized devices or users are allowed to access the target container group, realizing security control and logging of access.

Benefits of technology

It effectively improves the security of large-scale task processing, prevents unauthorized access, and records and transmits user operations through trusted log platforms to ensure traceability of the access process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342698A_ABST
    Figure CN120342698A_ABST
Patent Text Reader

Abstract

The embodiment of the invention relates to a network security access method and device for a large model task, equipment and a medium, and the method comprises the steps: receiving a target access request which comprises current access user information; in response to determining that sending equipment of the target access request is authorized equipment or determining that a current access user is an authorized user based on current access user information, the target access request is sent to a target container group, and the target container group is used for executing a large model task; and acquiring an access log of the target access request through the trusted log platform, and sending the access log to a user corresponding to the target container group. According to the embodiment of the invention, only authorized equipment or authorized users are allowed to access the container group, unauthorized access of related personnel is prevented, the safety of model task processing is effectively improved, access logs are recorded through a trusted log platform and are transparently transmitted to the users, and safe operation traceability is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technologies, and in particular, to a network security access method, apparatus, device, and medium for large model tasks. Background Art

[0002] In the cloud computing scenario, the cloud server of Model as a Service (MaaS) can provide a large model as a service to the user. The user hopes that the container group (pod) of their model-related tasks runs in an isolated network environment to ensure security. Relevant personnel may log in to the user's container group without authorization to obtain some data for inference or fine-tuning, resulting in low security for the user's model task processing. In related technologies, some access is blocked through network isolation at the task level, but the effect is not good and needs to be improved. Summary of the Invention

[0003] To solve the above technical problems, the present disclosure provides a network security access method, apparatus, device, and medium for large model tasks.

[0004] An embodiment of the present disclosure provides a network security access method for large model tasks. The method includes:

[0005] Receiving a target access request, where the target access request includes current access user information;

[0006] In response to determining that the sending device of the target access request is an authorized device or determining that the current access user is an authorized user based on the current access user information, sending the target access request to a target container group, where the target container group is used to execute large model tasks;

[0007] Collecting an access log of the target access request through a trusted log platform and sending the access log to the corresponding user of the target container group.

[0008] An embodiment of the present disclosure further provides a network security access apparatus for large model tasks. The apparatus includes:

[0009] A receiving module, configured to receive a target access request, where the target access request includes current access user information;

[0010] A sending module, configured to, in response to determining that the sending device of the target access request is an authorized device or determining that the current access user is an authorized user based on the current access user information, send the target access request to a target container group, where the target container group is used to execute large model tasks;

[0011] A log module for collecting access logs of the target access request through a trusted log platform and sending the access logs to the user corresponding to the target container group.

[0012] An embodiment of the present disclosure also provides an electronic device, which includes: a processor; a memory for storing executable instructions executable by the processor; the processor is configured to read the executable instructions from the memory and execute the executable instructions to implement the network security access method for large model tasks provided by the embodiments of the present disclosure.

[0013] An embodiment of the present disclosure also provides a computer-readable storage medium, which stores a computer program for executing the network security access method for large model tasks provided by the embodiments of the present disclosure.

[0014] The technical solution provided by the embodiments of the present disclosure has the following advantages compared with the prior art: The network access solution provided by the embodiments of the present disclosure receives a target access request, where the target access request includes current access user information; in response to determining that the sending device of the target access request is an authorized device or determining that the current access user is an authorized user based on the current access user information, the target access request is sent to a target container group, where the target container group is used to execute large model tasks; the access log of the target access request is collected through a trusted log platform and the access log is sent to the user corresponding to the target container group. By adopting the above technical solution, for the received access request, if it is determined that the sending device of the access request is an authorized device or the access user is an authorized user, access is allowed to send the access request to the container group, and the access log is collected through a trusted log platform and sent to the user of the container group, so as to realize that only authorized devices or authorized users can access the container group for executing large model tasks, prevent unauthorized access by relevant personnel, effectively improve the security of large model task processing, and record the access log through a trusted log platform and transmit it to the user, so as to realize that security operations can be traced. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] In combination with the accompanying drawings and with reference to the following specific embodiments, the above and other features, advantages and aspects of the embodiments of the present disclosure will become more obvious. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and the original elements and elements are not necessarily drawn to scale.

[0016] Figure 1 It is a flowchart of a network security access method for large model tasks provided by some embodiments of the present disclosure;

[0017] Figure 2 It is a flowchart of another network security access method for large model tasks provided by some embodiments of the present disclosure;

[0018] Figure 3 Schematic diagram of the network access process provided by some embodiments of the present disclosure;

[0019] Figure 4 Schematic diagram of the log recording process provided by some embodiments of the present disclosure;

[0020] Figure 5 Schematic diagram of the architecture of the control plane provided by some embodiments of the present disclosure;

[0021] Figure 6 Schematic diagram of the structure of the network security access device for large model tasks provided by some embodiments of the present disclosure;

[0022] Figure 7 Schematic diagram of the structure of an electronic device provided by some embodiments of the present disclosure. Detailed implementation manners

[0023] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not used to limit the protection scope of the present disclosure.

[0024] It should be understood that the various steps recorded in the method embodiments of the present disclosure can be executed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this regard.

[0025] As used herein, the term "including" and its variants are open-ended, that is, "including but not limited to". The term "based on" is "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description.

[0026] It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependent relationships.

[0027] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly specified in the context, it should be understood as "one or more".

[0028] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are for illustrative purposes only and are not used to limit the scope of these messages or information.

[0029] In the cloud computing scenario, Model as a Service can provide cloud services as the cloud server to serve model entities of different model providers (Vendors). Specifically, it can undertake large models from model providers and then provide services such as inference and fine-tuning based on the large model. The user hopes that their model-related tasks run in an isolated network environment.

[0030] If relevant personnel can log in to the container group at will, it may lead to the extraction or abuse of the user's data such as prompt words, or it may disrupt the established program behavior in the user's container group. In severe cases, it may cause the service to be unavailable, resulting in low security for the user's model task processing. In the related art, partial access is blocked through network isolation at the task level, but the effect is not good and needs to be improved.

[0031] To solve the above problems, the embodiments of the present disclosure provide a network security access method for large model tasks, which will be introduced below in combination with specific embodiments.

[0032] Figure 1 It is a schematic flowchart of the network security access method for large model tasks provided by some embodiments of the present disclosure. This method can be executed by a network security access device for large model tasks, where the device can be implemented by software and / or hardware and is generally integrated in an electronic device. As Figure 1 shown, the method includes:

[0033] Step 101, receive a target access request, where the target access request includes current access user information.

[0034] The network security access method for large model tasks in the embodiments of the present disclosure can be executed by the cloud service platform of Model as a Service. The cloud service platform can provide cloud services for different models and provide services such as inference and fine-tuning based on the models. The cloud service platform can manage the network access of the task corresponding container group of the model user.

[0035] The target access request can be a request for initiating network access to a target container group. The target access request can come from other container groups or other devices, without specific limitations. The target access request may include current access user information, which can be specific information characterizing the current access user. For example, it may include the user identifier, user name, etc. of the current access user. The target container group can be a container group that receives network access. The number of target container groups can be one or more, specifically set according to the actual situation. The target container group is located in a container cluster management system, which can include multiple physical machines or virtual machines, referred to as nodes or hosts. One or more container groups can be set on one node or host. The target container group is used to execute large model tasks, which can include inference tasks and / or fine-tuning tasks of the large model, etc. The model in the embodiments of the present disclosure can be a large language model, which can be a natural language-based processing model, can learn the rules, structures, etc. of natural language, understand the meaning of natural language, and generate coherent text with correct grammar and semantics based on the understood meaning, and even images or videos, etc. A container group can be the smallest scheduling unit in container technology. A container group can include one or more containers. Each container in the same container group shares resources, and tasks such as model inference and model supervised fine-tuning (SFT) can be executed in the container group. The container group can be used to execute tasks such as model inference or model fine-tuning of the user.

[0036] Specifically, when the current access user needs to access the target container group, a target access request carrying the current access user information can be sent to the network security access device for the large model task, and the network security access device for the large model task can receive the target access request.

[0037] Step 102, in response to determining that the sending device of the target access request is an authorized device or determining that the current access user is an authorized user based on the current access user information, send the target access request to the target container group, where the target container group is used to execute the large model task.

[0038] Among them, the sending device can be the hardware device through which the current access user sends the target access request. The authorized device can be a device that has been authorized to allow access to the target container group. In the embodiments of the present disclosure, the authorized devices can include the cluster bastion host corresponding to the container cluster management system where the target container group is located, as well as the host of the target container group and the host bastion host. The authorized user can be a user who has been authorized to allow access to the target container group device. The authorized user can be relevant personnel for performing operation and maintenance on the target container group when needed.

[0039] Specifically, after receiving a target access request, the network security access device for large model tasks can determine whether the target access request meets the access conditions, that is, determine whether the sending device of the target access request is an authorized device, and determine whether the current access user corresponding to the current access user information is an authorized user. If the judgment result of either of these two judgment steps is yes, that is, the sending device is an authorized device or the current access user is an authorized user, it is determined that access is allowed, and the target access request can be sent to the target container group for access.

[0040] In some embodiments, Figure 2 is a schematic flowchart of another network security access method for large model tasks provided by some embodiments of the present disclosure. As Figure 2 shown, in a feasible implementation manner, determining whether the target access request meets the access conditions, that is, determining whether the sending device of the target access request is an authorized device or determining whether the current access user is an authorized user based on the current access user information, includes the following steps:

[0041] Step 201: Based on the access source information in the target access request, determine whether the sending device is the host of the target container group, the host bastion machine, or the cluster bastion machine corresponding to the management container group. If so, execute step 202; otherwise, execute step 203.

[0042] Among them, the access source information can be information representing the access source of the target access request, and the access source information can include information about the specific sending device of the access source. The bastion host can be an intermediate access device between the container group to be accessed and the outside, used to control and record all access behaviors in and out of the network to ensure security. All accesses to the container group to be accessed must pass through the bastion host. The host of the target container group can be the node where the target container group is located in the container cluster management system, and this host can allow access. For example, the host can be an Elastic Compute Service Virtual Machine (ECS VM). The host bastion host can be the bastion host between the host and the outside, and the host bastion host of the target container group can be the bastion host between the host of the target container group and the outside, and can access the target container group through the remote management protocol (Secure Shell, SSH) provided by the target container group. The cluster bastion host can be the bastion host for managing the container group and the outside. Through this cluster bastion host, the management container group can be accessed, and other container groups can be accessed through the management container group. The target container group only allows other container groups belonging to the same task to access, realizing network isolation at the task level. The management container group can be a container group in the container cluster management system used to control the network access of the container group. This management container group can belong to the same task as the target container group. The task label of the management container group is the service label, and it can be regarded as belonging to the same task as the task labels of each container group included in the container cluster management system, so as to allow the management container group to access each container group.

[0043] Specifically, the network security access device for the large model task can extract the access source information in the target access request and determine the sending device according to this access source information. The access source information of different sending settings can be different; it is judged whether the sending device is the host or host bastion host of the target container group, or whether the sending device is the cluster bastion host corresponding to the management container group. If so, step 202 is executed; otherwise, step 203 is executed.

[0044] The order of step 201 and step 203 is Figure 2 only an example, and step 203 can also be executed first and then step 201 step by step, or step 201 and step 203 can be executed in parallel.

[0045] Step 202: Determine that the sending device of the target access request is an authorized device.

[0046] When the network security access device for the large model task determines whether the sending device is the host, host bastion host or cluster bastion host corresponding to the management container group of the target container group, it determines that the sending device of the target access request is an authorized device, and then executes step 205.

[0047] Optionally, after determining that the current access user is an authorized user, the authorized device forwards the target access request.

[0048] The authorized user set is stored in the authorized device. When receiving a target access request, the current access user information can be matched in the authorized user set. If the current access user information is included in the authorized user set, it is determined that the match is successful, and the target access request can be forwarded to the target container group; if the current access user information is not included in the authorized user set, it is determined that the match fails, and the target access request will not be forwarded. Therefore, the access request from the authorized device can be regarded as having been judged to allow access to the container group, and it can be determined that the access condition is met.

[0049] Step 203: When it is determined that the target access request comes from the system command line tool, determine whether the current access user information matches successfully in the authorized user set. If so, execute Step 204; otherwise, execute Step 206.

[0050] Among them, the system command line tool can be the command line tool of the container cluster management system, allowing users to interact with and manage the container groups in the container cluster management system. The authorized user set can be a set of one or more authorized users who have been pre-set with the permission to access the container group. Each authorized user is set with an expiration time. When the time reaches the expiration time, the permission management system can delete the authorized user from the authorized user set. The authorized user set can be updated through the permission management system to improve the flexibility of authorized user management.

[0051] Specifically, when the network security access device for the large model task determines that the target access request comes from the system command line tool according to the access source information, the current access user information can be matched in the authorized user set. If the current access user information is included in the authorized user set, it is determined that the match is successful, and Step 204 is executed; if the current access user information is not included in the authorized user set, it is determined that the match fails and the current access user is not an authorized user, and Step 206 is executed.

[0052] Step 204: Determine that the current access user is an authorized user.

[0053] Step 205: Determine that the target access request meets the access condition.

[0054] Step 206: Determine that the target access request does not meet the access condition.

[0055] In the above solution, it is determined whether to allow access to the container group by judging whether the access source is an authorized device or whether the accessing user is an authorized user. Only authorized users or through authorized devices can access the container group. Based on the technical control of network isolation at the task level, only the established access path is directed, and other accesses are refused, effectively improving the security of model task processing.

[0056] Step 103: Collect the access logs of the target access request through a trusted log platform and send the access logs to the corresponding user of the target container group.

[0057] Among them, the trusted log platform can be a log platform implemented based on trusted hardware. The trusted log platform is deployed in a trusted execution environment (Trusted Execution Environment, TEE) based on trusted hardware. The trusted execution environment (TEE) is a secure area of device hardware or software, isolated from the main operating system, and provides a trusted environment to execute sensitive or critical code and data. The security in the TEE mainly comes from its isolation from the main operating system and hardware protection measures. The TEE provides a secure execution environment where the stored and executed code and data are protected. The TEE itself is composed of special hardware in the processor and prevents external tampering or theft of the code and data in the TEE through some security protection mechanisms. In addition, the TEE does not allow ordinary applications to access the code and data therein, thereby improving the security of the system. The access logs can be the logs of all devices involved in the process of network access of the target access request, including operation logs at various levels, such as the Infrastructure as a Service (IaaS) layer, the Platform as a Service (PaaS) layer (container cluster management system), the MaaS layer, etc.

[0058] In some embodiments, collecting the access logs of the target access request through a trusted log platform includes: collecting the device logs of the authorized device for the target access request, the container group logs of the target container group, and the platform logs of the associated platform of the target container group through the trusted log platform, and combining them to obtain the access logs.

[0059] The device log can be a log of the process of authorized devices operating the target access request through screenshots, etc. The authorized device records all accesses through screen recording. The container group log can be a log obtained by recording the specific access operations of the target container group on the target access request. The associated platform of the target container group can be other platforms participating in the network access process of the target container group, and the platform log can be a platform-related log collected through the log collection process.

[0060] Specifically, the network security access device of the large model task can collect the device logs of authorized devices, the container group logs of the target container group, and the platform logs of the associated platform of the target container group through the trusted log platform for the target access request to the target container group, and combine them to obtain the access log of the target access request, and then send the access log to the user of the target container group.

[0061] In the above scheme, the trusted log platform can capture the logs of network access operations at all levels, so that network access operations such as operation and maintenance operations have nowhere to hide, and the access process is fully recorded. In addition, the trusted log platform is deployed in a trusted execution environment based on trusted hardware, which can ensure that the relevant logs will not be maliciously tampered with, and measure the platform code to ensure the credibility of related tasks.

[0062] The network access scheme provided by the embodiment of the present disclosure receives a target access request, wherein the target access request includes the current access user information; in response to determining that the sending device of the target access request is an authorized device or the current access user is determined to be an authorized user based on the current access user information, the target access request is sent to the target container group; the access log of the target access request is collected through a trusted log platform, and the access log is sent to the corresponding user of the target container group. Using the above technical scheme, for the received access request, if it is determined that the sending device of the access request is an authorized device or the access user is an authorized user, access is allowed to send the access request to the container group, and the access log is collected through the trusted log platform and sent to the user of the container group, so that only authorized devices or authorized users are allowed to access the container group, preventing unauthorized access by relevant personnel, effectively improving the security of model task processing, and recording and transmitting the access log to the user through the trusted log platform, so that safe operations can be traced.

[0063] Next, the network access scheme of the embodiment of the present disclosure is further described by a specific example. For example, Figure 3 A schematic diagram of a network access process provided by some embodiments of the present disclosure, such as Figure 3As shown in the figure, the container cluster management system may include a management container group, container group A for task a, and container group B for task b. The target container group may be container group A and / or container group B. Taking container group A as an example, the network access to container group A can be controlled in the following ways:

[0064] 1. Adopt a task-level network isolation policy. Container group A allows other container groups belonging to the same task to access. The management container group and container group A belong to the same task, blocking access from container groups that do not belong to the same task and shielding access to all paths that can be shielded and are not allowed.

[0065] 2. Set authorized devices. The authorized devices include the cluster bastion host, host bastion host, and hosts in the figure. Only allow access to container group A through the authorized devices. For example, using the cluster bastion host can access container group A through the management container group, and using the host bastion host can directly access container group A.

[0066] Regarding access through the host, that is, the security at the PaaS layer. In principle, these are not managed by the MaaS layer or the machine learning platform layer. However, since there are corresponding passwords or certificates in the IaaS layer, a small number of operation and maintenance personnel can directly log in to these hosts.

[0067] 3. Restrict the system command-line tool to only allow access by authorized users. All other users except authorized users are prohibited from accessing container group A through the system command-line tool.

[0068] 4. Record all accesses to the above-mentioned authorized devices and the system command-line tool.

[0069] For example, for the host, strict recording measures are taken for logging in or manipulating the container group through some container group or container-related commands on the host, including recording the login of users at any time period; capturing any operations related to the operation and maintenance of the container group on the host; and performing subsequent analysis and processing to analyze which user has operated on the container group, such as finding some operation behaviors of the logged-in users during the corresponding time period.

[0070] Exemplarily, Figure 4 is a schematic diagram of the log recording process provided by some embodiments of the present disclosure, as Figure 4As shown in the figure, the logging process may include: 1. Initialization. The security initialization process includes: a. The authority of the operation and maintenance personnel is converged, and only a few users are set as authorized users. b. The security sandbox for user loads is mainly the setting of the network isolation mechanism, which uses the network isolation policy to prevent unauthorized login. The configuration of the log acquisition software at each level, such as the IaaS layer, PaaS layer, MaaS layer or machine learning platform layer. 2. Real-time control of container group access and log collection. When the container group is running, the log collection mechanism at each level will operate to collect the corresponding logs. Of course, the credibility of the corresponding logs needs to be guaranteed. 3. The trusted log platform collects logs and can deliver them to specific users and for internal investigation. The logs for internal investigation can be internal operation and maintenance data that is not related to user data after data desensitization.

[0071] Through the trusted log platform, logs of network access operations at all levels can be captured, making network access operations such as operation and maintenance operations nowhere to hide, and achieving full record of the access process.

[0072] This solution mainly solves the following problems: the user's container group is not allowed to be accessed without permission. If access is required, the user must authorize it or use an authorized device. And the following points must be met: 1. The container group needs to be accessed using a pre-set entry, and there must be corresponding log records for subsequent tracing; 2. If a non-standard method is used, if technical means can be used to prohibit it, then technical means must be used to block it; if technical means cannot be used to prohibit it, there can be corresponding log records for tracing the source to locate potential problems; 3. Regardless of whether the access to the container group is successful (if unsuccessful, there must be a corresponding judgment in the log), or whether it is an expected login, there must be a corresponding trusted log for subsequent tracing or monitoring.

[0073] This solution restricts the access of personnel related to large models to container groups through technology and processes, enabling traceability of security operations and ensuring trusted operation and maintenance of container groups. It mainly consists of two aspects: at the MaaS or machine learning platform layer, task-level network isolation technology is used to prevent abnormal network access, and only permitted entry points are set. That is, technology is used to block unauthorized access by users as much as possible and only direct traffic to established access paths. All network access behaviors of container groups (including unsuccessful ones) are recorded, including log aggregation. Since security is hierarchical, for operations below the MaaS layer that have high permissions, all actions of high-permission operators are recorded. The logs of both the technical control and process means of this solution are sent to a trusted log platform running in a trusted environment for subsequent processing, which can further detect unauthorized user access and ensure that relevant log data is not maliciously tampered with. The corresponding logs can be delivered to users, and through trusted computing, the trustworthiness of the entire log can be proven to users.

[0074] Next, a specific example is used to further illustrate the architecture of the control plane in the network security access method for large model tasks in the embodiments of the present disclosure. The application program of the network security access method for large model tasks can provide corresponding services based on the control plane. Exemplarily, Figure 5 is a schematic diagram of the architecture of the control plane (ControlPlane) provided by some embodiments of the present disclosure. Figure 5 The hardware in it includes a central processing unit, a network interface card (Network Interface Card, NIC), and an accelerator (Accelerated Devices). Among them, the network interface card may include a data processing unit (Data Processing Unit, DPU). The accelerator may include a graphics processing unit, a tensor processing unit (Tensor Processing Unit, TPU), a field programmable gate array (Field Programmable Gate Array, FPGA), or an application specific integrated circuit (Application Specific Integrated Circuit, ASIC). Figure 5 The storage service in it can be a cloud storage service implemented based on a cloud server. In this embodiment, no specific restrictions are imposed on the specific hardware devices for implementing this storage service, and this storage service may include one or more databases. As Figure 5 shown, in this embodiment, the model of the control plane can undertake large models from various model providers as model as a service, and then use these large models to provide services such as inference services and fine-tuning services externally. Essentially, model as a service is platform as a service.

[0075] On the data plane, it depends on Infrastructure as a Service. The data plane can have a corresponding software stack, which can be scheduled and deployed as a service container group on the managed Elastic Compute Service (ECS) nodes. In response to user scheduling, it will perform corresponding scheduling according to the scheduler. Figure 5 There are multiple user pods and service pods in the cloud server virtual machine.

[0076] Generally, tasks related to Model as a Service can be divided into inference tasks and training tasks (e.g., dynamic fine-tuning tasks), etc. And there are three types of roles in this task: cloud server side, model side, and user.

[0077] Specifically, the cloud server side provides cloud services (e.g., Infrastructure as a Service or Platform as a Service) to serve entities of different model providers. The model side has a large model and uses the cloud server side to build entities for its own inference tasks and other services. The user is an entity that runs the application programs provided by the cloud server side and the model side. The user has corresponding isolation requirements for the model side and the cloud server side. Specifically, when the user obtains Model as a Service from the cloud server side, the user hopes that the container group of their model-related tasks is isolated in terms of network, computing, and storage dimensions to ensure security.

[0078] Figure 6 The following is a schematic structural diagram of a network security access device for large model tasks provided by an embodiment of the present disclosure. This device can be implemented by software and / or hardware and is generally integrated in an electronic device. As Figure 6 shown, this device includes:

[0079] A receiving module 601, configured to receive a target access request, where the target access request includes current access user information;

[0080] A sending module 602, configured to, in response to determining that the sending device of the target access request is an authorized device or determining that the current access user is an authorized user based on the current access user information, send the target access request to a target container group, where the target container group is used to execute large model tasks;

[0081] A log module 603, configured to collect the access log of the target access request through a trusted log platform and send the access log to the user corresponding to the target container group.

[0082] Optionally, the sending module 602 includes a first unit, configured to:

[0083] In response to determining that the sending device is the host of the target container group, the host bastion host, or the cluster bastion host corresponding to the management container group based on the access source information in the target access request, it is determined that the sending device of the target access request is an authorized device.

[0084] Optionally, the management container group and the target container group belong to the same task.

[0085] Optionally, after determining that the current access user is an authorized user, the authorized device forwards the target access request.

[0086] Optionally, the sending module 602 includes a second unit for:

[0087] In response to determining that the current access user information successfully matches in the authorized user set when the target access request comes from the system command line tool, it is determined that the current access user is an authorized user.

[0088] Optionally, the log module 603 is used for:

[0089] Collect the device logs of the authorized device for the target access request, the container group logs of the target container group, and the platform logs of the associated platform of the target container group through the trusted log platform, and combine them to obtain the access log.

[0090] Optionally, the trusted log platform is deployed in a trusted execution environment based on trusted hardware.

[0091] The network security access device for the large model task provided by the embodiments of the present disclosure can execute the network security access method for the large model task provided by any embodiment of the present disclosure, and has the corresponding functional modules and beneficial effects for executing the method.

[0092] The embodiments of the present disclosure also provide a computer program product, including computer programs / instructions, which when executed by a processor implement the network security access method for the large model task provided by any embodiment of the present disclosure.

[0093] Figure 7 It is a schematic structural diagram of an electronic device provided by the embodiments of the present disclosure.

[0094] Specifically refer to the following Figure 7, which shows a schematic structural diagram of an electronic device 700 suitable for implementing the embodiments of the present disclosure. The electronic device 700 in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, personal digital assistants (PDAs), tablet computers (PADs), portable media players (PMPs), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 7 The electronic device shown is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.

[0095] As Figure 7 shown, the electronic device 700 may include a processing device 701 (such as a central processing unit, a graphics processing unit, etc.), which may perform various appropriate actions and processes according to the programs stored in the read-only memory (ROM) 702 or the programs loaded from the storage device 708 into the random access memory (RAM) 703. In the RAM 703, various programs and data required for the operation of the electronic device 700 are also stored. The processing device 701, the ROM 702, and the RAM 703 are connected to each other through a bus 704. The input / output (I / O) interface 705 is also connected to the bus 704.

[0096] Generally, the following devices may be connected to the I / O interface 705: an input device 706 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 707 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 708 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 709. The communication device 709 may allow the electronic device 700 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 7 the electronic device 700 with various devices is shown, it should be understood that it is not required to implement or include all the shown devices. Instead, more or fewer devices may be implemented or included.

[0097] In particular, according to embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program including program code for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network via a communication device 709, or installed from a storage device 708, or installed from a ROM 702. When the computer program is executed by a processing device 701, the above-described functions defined in the network security access method for large model tasks of the embodiments of the present disclosure are performed.

[0098] It should be noted that the above-mentioned computer-readable medium in the present disclosure can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of a computer-readable storage medium can include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory, a read-only memory, an erasable programmable read-only memory (EPROM), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, a computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present disclosure, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wires, optical cables, radio frequency (RF), etc., or any suitable combination of the above.

[0099] In some embodiments, the client and the server can communicate using any currently known or future-developed network protocol such as the HyperText Transfer Protocol (HTTP), and can be interconnected with digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include Local Area Networks (LANs), Wide Area Networks (WANs), the Internet (e.g., the Internet), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.

[0100] The above computer-readable medium can be included in the above electronic device; it can also exist separately without being assembled into the electronic device.

[0101] The above computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device is caused to: receive a target access request, where the target access request includes current access user information; in response to determining that the sending device of the target access request is an authorized device or determining that the current access user is an authorized user based on the current access user information, send the target access request to the target container group; collect an access log of the target access request through a trusted log platform, and send the access log to the user corresponding to the target container group.

[0102] Computer program code for performing the operations of the present disclosure can be written in one or more programming languages or combinations thereof. The programming languages include, but are not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network or a wide area network, or can be connected to an external computer (e.g., by using an Internet service provider to connect through the Internet).

[0103] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions noted in the blocks may occur in a different order than noted in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0104] The units described in the embodiments of the present disclosure can be implemented in software or in hardware. Among them, the name of the unit does not constitute a limitation to the unit itself in some cases.

[0105] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that can be used include: Field-Programmable Gate Array (FPGA), Application Specific Integrated Circuit (ASIC), Application Specific Standard Parts (ASSP), System on Chip (SOC), Complex Programmable Logic Device (CPLD), and so on.

[0106] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory, a read-only memory, an erasable programmable read-only memory, a flash memory, an optical fiber, a portable compact disk read-only memory, an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0107] It should be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the type, scope of use, usage scenarios, etc. of the information involved in the present disclosure should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.

[0108] The above description is only a preferred embodiment of the present disclosure and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of disclosure involved in the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosure concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) having similar functions disclosed in the present disclosure.

[0109] In addition, although the operations are depicted in a particular order, this should not be construed as requiring that the operations be performed in the particular order shown or in sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of the present disclosure. Certain features described in the context of separate embodiments can also be implemented combinatorially in a single embodiment. Conversely, the various features described in the context of a single embodiment can also be implemented separately or in any suitable sub-combination in multiple embodiments.

[0110] Although the subject matter has been described in language specific to structural features and / or methodological acts, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are merely example forms of implementing the claims.

Claims

1. A network security access method for large model tasks, characterized in that, Including: Receiving a target access request, where the target access request includes current access user information; In response to determining that the sending device of the target access request is an authorized device or determining that the current access user is an authorized user based on the current access user information, sending the target access request to a target container group, where the target container group is used to execute a large model task; Collecting the access log of the target access request through a trusted log platform and sending the access log to the user corresponding to the target container group.

2. The method according to claim 1, characterized in that, Determining that the sending device of the target access request is an authorized device includes: In response to determining that the sending device is the host of the target container group, the host bastion host, or the cluster bastion host corresponding to the management container group based on the access source information in the target access request, determining that the sending device of the target access request is an authorized device.

3. The method according to claim 2, wherein The management container group and the target container group belong to the same task.

4. The method according to claim 1, characterized in that, The authorized device forwards the target access request after determining that the current access user is an authorized user.

5. The method according to claim 1, characterized in that, Determining that the current access user is an authorized user based on the current access user information includes: In response to determining that the current access user information matches successfully in the authorized user set when the target access request comes from a system command-line tool, determining that the current access user is an authorized user.

6. The method according to claim 1, wherein Collecting the access log of the target access request through a trusted log platform includes: Collecting the device log of the authorized device for the target access request, the container group log of the target container group, and the platform log of the associated platform of the target container group through the trusted log platform, and combining them to obtain the access log.

7. The method according to claim 1, wherein The trusted log platform is deployed in a trusted execution environment based on trusted hardware.

8. A network security access device for large model tasks, characterized in that, Including: A receiving module, configured to receive a target access request, where the target access request includes current access user information; A sending module, configured to send the target access request to a target container group in response to determining that the sending device of the target access request is an authorized device or determining that the current access user is an authorized user based on the current access user information, where the target container group is used to execute a large model task; A log module, configured to collect the access log of the target access request through a trusted log platform and send the access log to the user corresponding to the target container group.

9. An electronic device, characterized in that, The electronic device includes: A processor; A memory for storing executable instructions executable by the processor; The processor is configured to read the executable instructions from the memory and execute the executable instructions to implement the network security access method for a large model task according to any one of claims 1-7 above.

10. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, and the computer program is used to execute the network security access method for a large model task according to any one of claims 1-7 above.

Citation Information

Patent Citations

  • Container access method and device, electronic equipment and readable storage medium

    CN115469965A

  • Container log query method, related equipment and storage medium

    CN117056387A

  • JWT-based large model knowledge base access control method and system

    CN117972787A

  • Large model security protection method, computer program product and server

    CN118797630A

  • Container access control method and device, equipment and storage medium

    CN119808042A