Large model authentication and authorization system and method based on remote networking

By parsing network requests and establishing encrypted virtual network tunnels, combined with DID and distributed ledger technologies, the network security and access control issues of large-scale model services are solved, enabling secure remote access and fine-grained authorization, and simplifying network interconnection and auditing.

CN120915601AActive Publication Date: 2025-11-07HANGZHOU MEITENG TECH CO LTD

Patent Information

Application Number
CN202511417688.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-30
Publication Date
2025-11-07
Estimated Expiration
2045-09-30

AI Technical Summary

Technical Problem

Traditional large-scale services are inadequate in terms of network security, access control, fine-grained logging, and auditing mechanisms, resulting in a complex and unscalable network environment that makes it difficult to achieve secure remote access and fine-grained authorization.

Method used

By parsing network requests and using identifiers to determine terminal types, an encrypted virtual network tunnel is established. Decentralized identity (DID) and distributed ledger technologies are combined for identity management and authorization. A zero-trust security approach is adopted for rigorous verification, enabling fine-grained authorization and auditing.

Benefits of technology

It reduces the risk of API transmission leakage, provides coarse-grained and fine-grained access control, simplifies network interconnection and authentication, supports secure access in different network environments, and enables fine-grained logging and auditing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915601A_ABST
    Figure CN120915601A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of digital data processing, and discloses a large model authentication and authorization system and method based on remote networking, and the method comprises the steps: analyzing a networking request, obtaining an ID, determining the legitimacy of a large model of remote networking in a terminal lightweight agent rule, and carrying out the authentication and authorization of the large model. An encrypted virtual network tunnel is established between a user / application end and a large model service providing end, and all calling requests are transmitted through the tunnel, so that the leakage risk probability of an API transmission path is reduced, an attacker is prevented from abusing a model service, and economic loss or data leakage is reduced. Autonomous management of the user identity is realized by using the ID, judging the type of the ID, decentralizing the identity (DID) or similar technologies, and the storage and verification of an authorization strategy are carried out by combining a distributed account book technology.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to a large model authentication and authorization system and method based on remote networking, and belongs to the technical field of digital data processing. BACKGROUND

[0002] Large model technology represented by large language models is developing rapidly and has shown great application potential in various industries. These models are usually deployed in the cloud or enterprise private data centers and provide services to the outside in the form of APIs (application program interfaces) through the network. Users, including developers, data analysts, business personnel, and downstream applications, need to access these models for inference, fine-tuning, or management through remote networks. As the application scenarios of large models expand and deepen, network security problems arise in the process of communication and interaction between user terminals operated by different personnel and models. In enterprise, alliance, or multi-tenant scenarios, users or services in different network environments need to securely access remotely deployed large models. The network environment of the large model is, for example, a private cloud, a public cloud, or a local deployment. Traditional network interconnection and authentication methods have the following problems: The traditional API key or token management method has a risk of leakage. Once the key is stolen, attackers can misuse the model service, causing economic losses or data breaches. Existing large model services usually provide coarse-grained permission control (for example, by API or by user). For scenarios that require fine-grained authorization of model functions (such as allowing access to specific knowledge bases, calling specific plugins, limiting inference times, etc.), existing systems are difficult to meet. In enterprise, alliance, or multi-tenant scenarios, users or services in different network environments (for example, private clouds, public clouds, or local deployments) need to securely access remotely deployed large models. Traditional network interconnection and authentication methods are complex and not easily scalable. There is a lack of fine-grained recording and auditing mechanism for large model invocation behavior, making it difficult to trace back and define responsibilities afterwards. Therefore, it is necessary to propose a large model authentication and authorization system and method based on remote networking to address the problem of secure authentication and authorization of model deployment. SUMMARY

[0003] The application provides a large model authentication and authorization system and method based on remote networking to solve the problem of secure authentication and authorization of model deployment.

[0004] The application provides a large model authentication and authorization method based on remote networking, which includes: Receiving a networking request to parse the networking request and obtain an identifier ID; Using the identifier ID to determine whether the type of the identifier ID is a client; If the type of the identification ID is a client, a lightweight agent program of the client is called; If the type of the identification ID is not a client, it is determined that the type of the identification ID is a networking node, and a lightweight agent program of the client is called by using the networking node; Based on the called lightweight agent program of the client, identity authentication information of the networking target is obtained; The identity authentication information of the networking target is included in an authorization algorithm; The result instruction of the authorization algorithm is obtained; The large model authentication and authorization are performed by using the record audit log algorithm, and the received networking request is returned to parse the networking request, obtain the identification ID, and receive the instruction of ending the record.

[0005] Further, the data platform level of the system itself is defined; Based on the data platform level of the system itself, a data response log is established; The networking request is received; The data information of the networking request is included in the first receiving data storage area of the data response log; The information of the networking request is obtained by using the data information of the first receiving data storage area of the data response log.

[0006] Specifically, by parsing the networking request and obtaining the identification ID, the legality of the large model of remote networking in the terminal lightweight agent program rule is determined, an encrypted virtual network tunnel is established between the user / application end and the large model service providing end, and all calling requests are transmitted through the tunnel, thereby reducing the leakage risk probability of the API transmission path.

[0007] Further, the information of the networking request of the first receiving data storage area is called; The information ID classification characteristics of the networking request in the first receiving data storage area are obtained; The data platform level of the system itself is called; By using the data platform level, it is judged whether the level of the parsed information ID classification characteristics is consistent with the data platform level of the system itself; If the level of the parsed information ID classification characteristics is consistent with the data platform level of the system itself, the identification ID is obtained; If the level of the parsed information ID classification characteristics is not consistent with the data platform level of the system itself, invalid information of entering the network is fed back, and the invalid information of this time of entering the network is included in the second receiving data storage area of the data response log.

[0008] Specifically, by using the identification ID, the type of the identification ID is judged, the decentralized identity (DID) or similar technology is used to realize the autonomous management of the user identity, and the distributed ledger technology is combined to store and verify the authorization strategy.

[0009] Further, the calling identification ID and the classification features of the identification ID are obtained; The identification ID is parsed to obtain a parsed result of the identification ID; The parsed result and the classification features of the identification ID are used to obtain a device level of the network request; It is judged whether the classification features of the identification ID match the device level of the network request; If the classification features of the identification ID match the device level of the network request, it is determined that the type of the identification ID is not a client; If the classification features of the identification ID do not match the device level of the network request, it is determined that the type of the identification ID is a client.

[0010] Further, the identification ID is used to determine a data flow direction of the network process; The identification ID and the data flow direction are used to form an information path of data information reverse transmission; The information path is used to establish an information tunneling tunnel; Based on the identification ID, a connection request is initiated by a remote network node of a lightweight agent program of the client; A feedback of the verification result is obtained; Based on the feedback of the verification result, the stability of the information tunneling tunnel called by the lightweight agent program is determined.

[0011] Specifically, when the terminal of the network request is a client, the lightweight agent program of the client can be directly called through the network request and the obtained identification ID. The server provides coarse-grained permission control, for example, according to the interface level of the API. For scenarios that need to subdivide the authorization of model functions, such as allowing access to specific knowledge bases, calling specific plug-ins, limiting the number of reasoning times, etc., based on the called lightweight agent program of the client, the identity authentication information of the network target is obtained, the identity authentication information of the network target is included in the authorization algorithm, and the result instruction of the authorization algorithm is obtained.

[0012] Further, the information tunneling tunnel is established by using the network node; The API calling instruction of each network node is received by using the information tunneling tunnel; The identity information of the API calling instruction sender is parsed; The identification ID to be verified after parsing the identity information is obtained; The identification ID to be verified and the identification ID are used to judge whether the identification ID to be verified matches the identification ID of the network request; If the identification ID to be verified matches the identification ID of the network request, it is determined that the lightweight agent program calling the information tunneling tunnel is stable; If the to-be-verified identifier ID does not match the identifier ID of the networking request, it is determined that the lightweight agent program call information tunnels an unstable tunnel.

[0013] Further, each call request is parsed in turn to obtain a parsing result. From the parsing result, a data flow characteristic parameter is extracted, the data flow characteristic parameter including a data packet quantity per unit time and a data packet average size; based on the data packet quantity per unit time and the data packet average size, an equivalent cylinder volume formed by the data flow per unit time is calculated, the cylinder base area being determined by the data packet average size and the cylinder height being determined by the data packet quantity per unit time; an authentication characteristic parameter is extracted from the parsing result, the authentication characteristic parameter including an authentication data packet quantity and an authentication protocol header size; Based on the authentication data packet quantity and the authentication protocol header size, an equivalent sphere volume formed in the authentication process is calculated, the sphere radius being determined by the product of the authentication protocol header size and the authentication data packet quantity. The information path in the selected parsing result is determined, and it is judged whether the information path is an information tunneling tunnel. If the information path is not an information tunneling tunnel, information of a request failure is fed back, the call request at the timestamp is included in a third received data storage area of a data response log, a timestamp is returned, a parsing result at the current time is selected, and the process is repeated until each parsing result is traversed. If the information path is an information tunneling tunnel, the ratio of the data flow equivalent cylinder volume to the authentication equivalent sphere volume is compared, dynamic and fine-grained authorization of the networking object is performed based on the comparison result of the ratio and a preset threshold, a timestamp is returned, a parsing result at the current time is selected, and the process is repeated until each parsing result is traversed.

[0014] Specifically, in enterprise, alliance or multi-tenant scenarios, different network environments, such as private cloud, public cloud and local deployment, users or services need to securely access remotely deployed large models. If the type of the identifier ID is not a client, it is determined that the type of the identifier ID is a networking node, the lightweight agent program of the client is called by the networking node, the identity authentication information of the networking target is obtained based on the called lightweight agent program of the client, the identity authentication information of the networking target is included in the authorization algorithm, the result instruction of the authorization algorithm is obtained, an encrypted virtual network tunnel is established between the user / application end and the large model service provider end, all call requests are transmitted through the tunnel, and the zero trust (Zero Trust) security concept can be used. Do not trust any internal or external network connection, all requests need to pass through strict identity verification and authorization check, which expands the network interconnection and authentication mode.

[0015] Further, the identity of the authorized networking device is bound to the virtual network identity. Verify the virtual network identity by using the identity authentication module, and obtain the connection state information of three key nodes in the virtual network; Based on the connection state information of the three key nodes, determine a virtual triangular region composed of the three nodes; Calculate the coverage area of the virtual triangular region, wherein the calculation of the triangular area is based on the relative position relationship of the three nodes; Determine the distribution strategy of the information tunneling tunnel according to the coverage area of the virtual triangular region by using the authorization policy engine, wherein the greater the coverage area, the higher the distribution density of the tunneling tunnel; Record the authentication and authorization events of each virtual network identity in the data response log by using the audit log module, and include the calculation result of the virtual triangular region coverage area and the corresponding relationship of the authorization policy in the audit range; The calculation results and policy distribution of the identity authentication module, the authorization policy engine and the audit log module are included in the authorization algorithm, and the dynamic authorization management of the network coverage area is realized.

[0016] Further, record the record information of the gateway; Receive the authorized request from the authentication and authorization center; Forward the request to the large model API; Store the permission relationship of users, roles, devices and resources.

[0017] The application also provides a large model authentication and authorization system based on remote networking, comprising: A server for executing the large model authentication and authorization method based on remote networking.

[0018] A memory in communication connection with the server.

[0019] The application has the following advantages: By analyzing the networking request and obtaining the identification ID, the legality of the large model in the remote networking is determined by the terminal lightweight proxy algorithm, an encrypted virtual network tunnel is established between the user / application end and the large model service provider end, all call requests are transmitted through the tunnel, the leakage risk probability of API transmission path is reduced, the model service is prevented from being abused by attackers, and economic loss or data leakage is reduced. By using the identification ID, the type of the identification ID is determined, the decentralized identity (DID) or similar technology is used to realize the autonomous management of the user identity, and the distributed ledger technology is used for the storage and verification of the authorization policy.

[0020] When the terminal of the networking request is a client, the lightweight agent program of the client can be directly called through the networking request and the obtained identifier ID. The server provides coarse-grained permission control, for example, according to the interface level of API. For scenarios that require fine-grained authorization of model functions, such as allowing access to a specific knowledge base, calling a specific plug-in, limiting the number of reasoning times, and the like, based on the called lightweight agent program of the client, the identity authentication information of the networking target is obtained, the identity authentication information of the networking target is included in the authorization algorithm, and the result instruction of the authorization algorithm is obtained. The server can also realize the autonomous management of user identity based on its own service level decentralized identity (DID) or similar technology, and store and verify the authorization strategy in combination with the distributed ledger technology.

[0021] In enterprise, alliance or multi-tenant scenarios, different network environments, such as private cloud, public cloud, local deployment, users or services need to securely access remotely deployed large models. When the type of the identifier ID is not a client, the type of the identifier ID is determined to be a networking node, the lightweight agent program of the client is called by the networking node, based on the called lightweight agent program of the client, the identity authentication information of the networking target is obtained, the identity authentication information of the networking target is included in the authorization algorithm, and the result instruction of the authorization algorithm is obtained, an encrypted virtual network tunnel is established between the user / application end and the large model service providing end, all call requests are transmitted through the tunnel, and the zero trust (Zero Trust) security concept can be used, which does not trust any internal or external network connection, and all requests need to pass through strict identity verification and authorization check, thereby expanding the network interconnection and authentication mode.

[0022] The large model authentication and authorization can be performed by using the record audit log algorithm to record and audit the fine-grained behavior of the large model, so that the network security management, network authorization, cross-network access, and traceability are simple and clear in the tracing process and responsibility definition. BRIEF DESCRIPTION OF DRAWINGS

[0023] Figure 1 A flowchart of a large model authentication and authorization method based on remote networking according to an embodiment of the present application.

[0024] Figure 2 A structure connection diagram of a large model authentication and authorization system based on remote networking according to an embodiment of the present application. BRIEF DESCRIPTION OF DRAWINGS: 100 - server; 200 - memory. DETAILED DESCRIPTION

[0026] In order to make the objects, technical solutions and advantages of the present application clearer, the technical solutions of the present application will be described in detail below with reference to the drawings. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present application.

[0027] As shown in Figure 1 The method for large model authentication and authorization based on remote networking provided by the present application comprises: S100, receiving a networking request to parse the networking request and obtain an identification ID.

[0028] S200, using the identification ID to determine whether the type of the identification ID is a client.

[0029] S300, if the type of the identification ID is a client, calling a lightweight proxy program of the client.

[0030] S400, if the type of the identification ID is not a client, determining that the type of the identification ID is a networking node, and calling the lightweight proxy program of the client using the networking node.

[0031] S500, obtaining identity authentication information of a networking target based on the called lightweight proxy program of the client.

[0032] S600, including the identity authentication information of the networking target into an authorization algorithm.

[0033] S700, obtaining a result instruction of the authorization algorithm.

[0034] S800, using a record audit log algorithm to perform large model authentication and authorization, and returning the receiving of the networking request to parse the networking request and obtain the identification ID until receiving an instruction to end the record.

[0035] Specifically, the data center with the server as the core can receive the networking request, parse the networking request and obtain the identification ID. The data center serves as a data hub, undertakes the tasks of data storage, processing, transmission and acceleration, and supports cloud computing, online services and enterprise-level application running. The main types of data centers include enterprise data centers, enterprise data centers and edge data centers.

[0036] It can be understood that the enterprise data center serves the private data processing needs of a single organization. The cloud data center is operated by a third-party provider, providing on-demand allocation of computing resources. The edge data center is deployed close to the user side, reducing latency and supporting real-time data processing. Among them, the edge data center is in the middle layer of the end-edge-cloud architecture, and can be connected in communication with the networking node. In enterprise, alliance or multi-tenant scenarios, different network environments, such as private cloud, public cloud, and local deployment, users or services can securely access large models deployed remotely by receiving a networking request, analyzing the networking request, and obtaining an identification ID to optimize network interconnection and authentication methods.

[0037] Briefly, in the connection process of the communication network, the networking request is analyzed and the identification ID is obtained, which is one of the basic operations of data processing. The core goal is to accurately extract, verify and use unique identifiers from raw data.

[0038] Large models represented by large language models (LLM) are often laid out relying on network architecture. Generally speaking, network architecture includes hierarchical network architecture, flat network architecture, and distributed network architecture. Enterprise private cloud can use local area network. The network architecture of such a local area network is generally flat network architecture. Enterprise private cloud is generally connected directly by encrypted communication tunnel between client and server of data center. The client is a computing terminal, and a lightweight proxy program of the client can be deployed.

[0039] Public cloud generally adopts hierarchical network architecture and distributed network architecture. Briefly, hierarchical network architecture is divided into three layers: core layer, aggregation layer, and access layer. Distributed network architecture is divided into network resources distributed in multiple geographic locations and connected by high-speed network. The server of the data center can determine the networking node according to the type of the identification ID, and call the lightweight proxy program of the client using the networking node.

[0040] The present application relates to a large model authentication and authorization method based on remote networking. By using an encrypted tunnel and a zero-trust architecture, it effectively prevents man-in-the-middle attacks and credential leaks. By analyzing the networking request and obtaining the identification ID, the legality of the large model in the remote networking is determined in the terminal lightweight proxy program. An encrypted virtual network tunnel is established between the user / application end and the large model service provider end. All call requests are transmitted through the tunnel, reducing the risk probability of API transmission leakage and preventing attackers from abusing model services, reducing economic losses or data leaks. By using the identification ID, the type of the identification ID is determined, and the decentralized identity (DID) or similar technology is used to realize the autonomous management of user identity, and the distributed ledger technology is used to store and verify the authorization policy.

[0041] Cross-network interconnection can seamlessly connect clients and large model services in different network environments, simplifying deployment and management.

[0042] When the terminal of the networking request is a client, the lightweight agent program of the client can be directly called through the networking request and the obtained identifier ID. The server provides coarse-grained permission control, for example, according to the interface level of API. For scenarios that require fine-grained authorization of model functions, such as allowing access to specific knowledge bases, calling specific plugins, and limiting the number of reasoning times, based on the called lightweight agent program of the client, the identity authentication information of the networking target is obtained, the identity authentication information of the networking target is included in the authorization algorithm, and the result instruction of the authorization algorithm is obtained. The server can also realize the autonomous management of user identity based on its own service level decentralized identity (DID) or similar technology, and store and verify the authorization strategy combined with distributed ledger technology.

[0043] In enterprise, alliance or multi-tenant scenarios, different network environments such as private cloud, public cloud and local deployment require users or services to securely access remotely deployed large models. When the type of the identifier ID is not a client, the type of the identifier ID is determined to be a networking node, the lightweight agent program of the client is called by the networking node, based on the called lightweight agent program of the client, the identity authentication information of the networking target is obtained, the identity authentication information of the networking target is included in the authorization algorithm, and the result instruction of the authorization algorithm is obtained. An encrypted virtual network tunnel is established between the user / application end and the large model service provider end, all call requests are transmitted through the tunnel, and the zero trust (Zero Trust) security concept can be used, which does not trust any internal or external network connection. All requests need to pass through strict identity verification and authorization check, which expands the network interconnection and authentication mode.

[0044] In an embodiment of the present application, S100 comprises: S111, defining the data platform level of the system itself.

[0045] S112, based on the data platform level of the system itself, establishing a data response log.

[0046] S113, receiving a networking request.

[0047] S114, including the data information of the networking request in the first received data storage area of the data response log.

[0048] S115, obtaining the information of the networking request by using the data information of the first received data storage area of the data response log.

[0049] It can be understood that the network architecture includes star network, bus network, mesh network and the like from the perspective of structure. In terms of the network architecture of the star network, the data center can connect multiple peripheral nodes through the central node. The server in the data center can respond to data according to the data platform level of the system itself. Based on the data platform level of the system itself, a data response log is established. Such a data response log makes the fine-grained recording and auditing mechanism of the large model calling behavior, so that the subsequent tracing and responsibility definition become simple.

[0050] In this embodiment, the method of establishing a data response log can provide a large model authentication and authorization system and method based on remote networking technology. By constructing a secure virtual network, fine-grained authentication, authorization and auditing of large model calling are realized.

[0051] In an embodiment of the present application, S100 further comprises: S121, calling the information of the networking request of the first received data storage area.

[0052] S122, obtaining the information ID classification feature of the networking request in the first received data storage area.

[0053] S123, calling the data platform level of the system itself.

[0054] S124, using the data platform level to determine whether the level of the parsed information ID classification feature is consistent with the data platform level of the system itself. S125a, if the level of the parsed information ID classification feature is consistent with the data platform level of the system itself, obtaining the identification ID.

[0055] S125b, if the level of the parsed information ID classification feature is not consistent with the data platform level of the system itself, feeding back the invalid information of entering the network, and including the invalid information of entering the network this time into the second received data storage area of the data response log.

[0056] It can be understood that in the information ID classification feature of the networking request information in the first received data storage area, the information ID classification feature is generally distinguished by ID type, such as pure digital type, letter + number combination, separator, incremental sequence, and ID type generated by external system.

[0057] In the process of calling the networking request information of the first received data storage area, the information ID generated by the external system is the key of the server to parse the information ID. These information IDs generated by the external system have a relatively specific identification ID, which can be used for permission management of secondary network equipment for cross-network and cross-organization access.

[0058] Briefly, in the network architecture of the bus network in the public cloud, the A-level server can broadcast data information to the data clients with the information ID classification features of A, B, and C levels. The B-level server can broadcast data information to the data clients with the information ID classification features of B and C levels.

[0059] In this embodiment, by obtaining the information ID classification features of the networking request in the first received data storage area, the remote network access model is implemented for reasoning, fine-tuning, or management. The determination of the identification ID can be associated with multiple operations of the same user in a large number of logs. The detection of different account registration behaviors of the same device in a short time. The identity authentication of cross-service calls under the micro-service architecture is determined by analyzing the networking request and obtaining the identification ID to determine the legality of the large model of remote networking in the terminal lightweight proxy program rule. An encrypted virtual network tunnel is established between the user / application end and the large model service provider end, and all call requests are transmitted through the tunnel, reducing the risk probability of API transmission leakage and preventing attackers from abusing model services, reducing economic losses or data leakage. By using the identification ID and judging the type of the identification ID, the decentralized identity (DID) or similar technology is used to realize the autonomous management of the user identity, and the distributed ledger technology is used for the storage and verification of the authorization strategy, which can realize the construction of auxiliary index in high-frequency query dimension.

[0060] In one embodiment of the present application, S200 includes: S210, calling the identification ID and the classification features of the identification ID.

[0061] S220, analyzing the identification ID to obtain the analysis result of the identification ID.

[0062] S230, obtaining the device level of the networking request by using the analysis result and the classification features of the identification ID.

[0063] S240, judging whether the classification features of the identification ID match the device level of the networking request.

[0064] S251, if the classification features of the identification ID match the device level of the networking request, determining that the type of the identification ID is not a client.

[0065] S252, if the classification features of the identification ID do not match the device level of the networking request, determining that the type of the identification ID is a client.

[0066] It can be understood that the identification ID can be parsed using a regular expression, and a targeted regular expression can be written according to the observed pattern. The parsed sub-segments are stored in separate fields for quick query, which is beneficial for data storage of data response logs. It lays a solid foundation for data analysis, system integration and security control. Parsing the identification ID obtains the parsing result of the identification ID, and using the parsing result and the classification characteristics of the identification ID, the level of the device sending the networking request is obtained. The model is usually deployed in the cloud or enterprise private data center, and provides services to the device sending the networking request in the form of API (Application Program Interface) through the network.

[0067] After obtaining the level of the device sending the networking request, the server can infer the indirect connection relationship from the client to the proxy end and from the proxy end to the server by analyzing the records in the network request or response content, and then complete multi-dimensional data collection, hierarchical matching strategy, weight scoring and node proxy determination.

[0068] In this embodiment, the zero trust (Zero Trust) security concept is adopted, which does not trust any internal or external network connection, and all requests need to pass through strict identity verification and authorization check. The identity of the user (for example, user ID, device ID, application ID, etc.) is bound with the virtual network identity, and dynamic and fine-grained authorization is performed based on the policy engine.

[0069] In an embodiment of the present application, S300 comprises: S310, using the identification ID, determining the data flow direction of the networking process.

[0070] S320, using the identification ID and the data flow direction, forming an information path for reverse transmission of data information.

[0071] S330, using the information path to establish an information tunneling tunnel.

[0072] S340, based on the identification ID, verifying the connection request initiated by the remote networking node of the lightweight proxy program of the client.

[0073] S350, obtaining the feedback of the verification result.

[0074] S360, based on the feedback of the verification result, determining the stability of the lightweight proxy program calling the information tunneling tunnel.

[0075] It can be understood that the server can infer the indirect connection relationship from the client to the proxy end and from the proxy end to the server.

[0076] The server can also infer the direct LAN connection relationship from the client to the gateway and from the gateway to the server itself.

[0077] It can be understood that, by using decentralized identity (DID) or similar technology, the user identity is managed autonomously, and the storage and verification of the authorization strategy are combined with the distributed ledger technology.

[0078] An encrypted virtual network tunnel is established between the user or application end and the large model service provider end, and all calling requests are transmitted through the tunnel. The user or application client (Client Agent) can use a lightweight agent program deployed on the user device or application server.

[0079] Briefly, the data flow direction of the networking process is determined, the information path of the reverse transmission of data information is formed, the information tunneling tunnel is established, and the remote networking node of the lightweight agent program of the client initiates a connection request. By using the transmitted information of the established information tunneling tunnel, the stability of the lightweight agent program calling the information tunneling tunnel can be determined.

[0080] In an embodiment of the present application, S400 comprises: S410, using the networking node, establishing an information tunneling tunnel.

[0081] S420, using the information tunneling tunnel, receiving API calling instructions of each networking node.

[0082] S430, parsing the identity information of the API calling instruction sender.

[0083] S440, obtaining the to-be-verified identifier ID after parsing the identity information.

[0084] S450, using the to-be-verified identifier ID and the identifier ID, determining whether the to-be-verified identifier ID matches the identifier ID of the networking request.

[0085] S461, if the to-be-verified identifier ID matches the identifier ID of the networking request, it is determined that the lightweight agent program calling the information tunneling tunnel is stable.

[0086] S462, if the to-be-verified identifier ID does not match the identifier ID of the networking request, it is determined that the lightweight agent program calling the information tunneling tunnel is unstable.

[0087] It can be understood that the lightweight agent deployed on the user equipment or the application server. Deployed at the network edge, used to establish and maintain virtual network tunnels. The authentication and authorization center based on the information channel of the virtual network tunnel is the core of the system of the entire network, and the authentication and authorization center has an identity authentication module, which verifies the identity credentials submitted by the client, such as digital certificates, DIDs, and OAuth2.0 Token. The authentication and authorization center has an authorization policy engine, which makes authorization decisions based on preset or dynamic policies. The authentication and authorization center has an audit log module that records all authentication and authorization events and generates logs with timestamps and signatures.

[0088] In this embodiment, the large model authentication and authorization are performed by using the record audit log algorithm, which can realize the fine-grained recording and auditing mechanism of the large model calling behavior, so that the network security management, network authorization, cross-network access, and traceability become simple and clear in the tracing process and responsibility definition.

[0089] In one embodiment of the present application, S500 includes: S510, sequentially parsing each calling request to obtain a parsing result.

[0090] S520, extracting data flow feature parameters from the parsing result, the data flow feature parameters including the number of data packets per unit time and the average size of data packets, calculating the equivalent cylindrical volume formed by the data flow per unit time based on the number of data packets per unit time and the average size of data packets, the bottom area of the cylindrical body being determined by the average size of data packets, and the height of the cylindrical body being determined by the number of data packets per unit time, extracting authentication feature parameters from the parsing result, the authentication feature parameters including the number of authentication data packets and the size of the authentication protocol header.

[0091] S530, calculating the equivalent spherical volume formed in the authentication process based on the number of authentication data packets and the size of the authentication protocol header, the radius of the spherical body being determined by the product of the size of the authentication protocol header and the number of authentication data packets.

[0092] S540, determining the information channel in the selected parsing result, and judging whether the information channel is an information tunneling tunnel.

[0093] S550, if the information channel is not the information tunneling tunnel, feedback information of request failure, put the calling request under the timestamp into the third receiving data storage area of the data response log, return a parsing result selected from the current time by using the timestamp, and iterate each parsing result until all the parsing results are iterated, if the information channel is the information tunneling tunnel, compare the ratio of the data flow equivalent cylinder volume and the authentication equivalent sphere volume, dynamically and finely authorize the object of networking based on the comparison result of the ratio and the preset threshold, return a parsing result selected from the current time by using the timestamp, and iterate each parsing result until all the parsing results are iterated.

[0094] It can be understood that the message in the message queue usually contains a timestamp, and the message queue timestamp is used to mark the business occurrence time of the message, and is suitable for event traceability recorded in the data response log.

[0095] The timestamp of the message queue can support complex business logic and performance optimization.

[0096] Briefly, the first receiving data storage area of the data response log is used to receive the data information of the networking request, and putting the data information of the networking request into the data response log is beneficial to determining the lightweight proxy program of the client through the regular expression. Then the establishment of the information tunneling tunnel is realized.

[0097] The invalid information of the network access is put into the second receiving data storage area of the data response log, and the ID (Identifier) in the data is parsed by using the data in the second receiving data storage area of the data response log. The unique identifier can be accurately extracted, verified and used from the original data, and the regular expression with strong pertinence is written according to the obtained mode, so as to confirm that each part after parsing meets the business logic of audit and traceability.

[0098] The lightweight proxy program of the calling client can realize the data flow conduction of the communication channel from the server to the model demand object. The calling request of the model demand object can realize the performance allocation of the model and the transmission of the model operation result.

[0099] The third receiving data storage area of the data response log is used to calculate the case of irregular calling information tunneling tunnel of the external user end.

[0100] In the embodiment, all model calls through the virtual network are recorded and signed to form an unalterable audit log. By using decentralized identity (DID) or similar technology, the self-management of the user identity is realized, and the storage and verification of the authorization policy are realized in combination with the distributed ledger technology.

[0101] In an embodiment of the present application, S600 comprises: S610, the identity of the authorized networking device is bound with the virtual network identity.

[0102] S620, verifying the virtual network identity by the identity authentication module, and obtaining the connection state information of three key nodes in the virtual network.

[0103] S630, determining a virtual triangle area composed of the three key nodes based on the connection state information of the three key nodes.

[0104] S640, calculating the coverage area of the virtual triangle area, wherein the calculation of the triangle area is based on the relative position relationship of the three nodes.

[0105] S650, determining the distribution strategy of the information tunneling tunnel by the authorization policy engine according to the coverage area of the virtual triangle area, wherein the greater the coverage area, the higher the distribution density of the tunneling tunnel.

[0106] S660, recording the authentication and authorization events of each virtual network identity in the data response log by the audit log module, and including the calculation result of the virtual triangle area coverage and the corresponding relationship of the authorization policy in the audit range.

[0107] S670, including the calculation results of the identity authentication module, the authorization policy engine and the audit log module and the policy distribution in the authorization algorithm, and realizing the dynamic authorization management of the network coverage area.

[0108] Specifically, an encrypted tunnel is established with a remote networking node. A large model invocation request is captured. The request is encapsulated and sent to the authentication and authorization center. The user or device identity certificate is carried. The connection of the client is managed. Tunnel encryption and decryption are performed. The encapsulated request is forwarded to the authentication and authorization center. WireGuard or custom protocol can be used to implement it.

[0109] Verify the identity certificate submitted by the client, such as digital certificate, DID, OAuth2.0 Token. Based on the preset or dynamic policy, make authorization decision on the request. Record all authentication and authorization events, and generate logs with timestamp and signature.

[0110] Receive authorized requests from the authentication and authorization center. Forward the request to the actual large model API. May include load balancing, traffic control and other functions. Store the permission relationship of users, roles, devices and resources, which can use relational databases, NoSQL databases or distributed ledgers.

[0111] In an embodiment of the present application, S800 includes: S810, recording the record information of the gateway.

[0112] S820, receiving authorized requests from the authentication and authorization center.

[0113] S830, forward the request to the large model API.

[0114] S840, store the permission relationship of user, role, device and resource.

[0115] It can be understood that the client agent starts and initiates a connection request to the remote networking node. Identity authentication and key exchange are completed between the client and the node, and an end-to-end encrypted tunnel is established.

[0116] The user's application program initiates an API call to the large model, for example, / v1 / chat / completions. The client agent captures the request and adds the user's identity information, such as DID, device ID, in the request header or payload.

[0117] The encapsulated request is sent through the tunnel to the remote networking node and forwarded to the authentication and authorization center. The authentication and authorization center first verifies whether the identity credentials of the request are valid. If the identity is valid, the policy engine makes a decision according to the pre-set authorization policy. The policy engine decides to "allow" or "reject" the request. For example: Policy 1: User A can call the gpt-4-turbo model during Monday to Friday 9:00-18:00, with a maximum of 1000 requests per day.

[0118] Policy 2: Device B can only call the model-b model and is limited to accessing knowledge base C.

[0119] If the request is "allowed", the authentication and authorization center forwards the request with authorization credentials to the large model service gateway. The large model service gateway receives the request and calls the corresponding large model API. At the same time, the audit log module records all information of this call, such as caller, timestamp, model name, authorization result, etc., and signs it to ensure that the log cannot be tampered with. The large model returns the result, which is returned to the client through the service gateway and the remote networking node through the encrypted tunnel.

[0120] This embodiment effectively prevents man-in-the-middle attacks and credential leaks through end-to-end encrypted tunnels and zero-trust architecture. It can perform flexible and dynamic authorization based on user, device, time, number of calls, model type, and even model functions such as plugin calls, greatly improving the flexibility of permission management. It can seamlessly connect clients and large model services in different network environments, simplifying deployment and management. Automatically generate tamper-proof audit logs to provide strong support for post-tracing and security compliance. Modular design makes the system easy to extend, allowing easy access to new authentication methods, policy engines or large model services.

[0121] For example, Figure 2As shown, the application also provides a large model authentication and authorization system based on remote networking, which comprises: The server 100 is used to execute the large model authentication and authorization method based on remote networking.

[0122] The memory 200 is in communication connection with the server 100.

[0123] The server 100 and the memory 200 of the embodiment are flexible and dynamic in authorization, greatly improving the flexibility of permission management. It can seamlessly connect clients and large model services in different network environments, simplifying deployment and management. Automatically generate tamper-proof audit logs to provide strong support for post-tracing and security compliance. Modular design makes the system easy to extend, allowing easy access to new authentication methods, policy engines, or large model services.

[0124] When the terminal of the networking request is a client, the server 100 can directly call the lightweight agent program of the client through the networking request and the obtained identifier ID. The server 100 provides coarse-grained permission control, such as API interface level, for scenarios that require fine-grained authorization of model functions, such as allowing access to specific knowledge bases, calling specific plugins, limiting inference times, etc. Based on the called lightweight agent program of the client, obtain the identity authentication information of the networking target, and include the identity authentication information of the networking target in the authorization algorithm to obtain the result instruction of the authorization algorithm. The server 100 can also realize the autonomous management of user identity based on its own service level decentralized identity (DID) or similar technology, and store and verify the authorization policy in combination with distributed ledger technology.

[0125] In enterprise, alliance or multi-tenant scenarios, different network environments such as private cloud, public cloud, local deployment, users or services need to securely access remotely deployed large models. When the type of identifier ID is not a client, the type of identifier ID is determined to be a networking node, the lightweight agent program of the client is called by the networking node, the identity authentication information of the networking target is obtained based on the called lightweight agent program of the client, the identity authentication information of the networking target is included in the authorization algorithm, and the result instruction of the authorization algorithm is obtained. A secure virtual network tunnel is established between the user / application end and the large model service provider end, and all call requests are transmitted through the tunnel. The concept of Zero Trust security can be used, which does not trust any internal or external network connection, and all requests need to undergo strict identity verification and authorization checks, expanding the network interconnection and authentication methods.

[0126] The server 100 and the memory 200 use a record audit log algorithm for large model authentication and authorization, and can have a fine-grained record and audit mechanism for large model calling behavior, so that network security management, network authorization, cross-network access, traceability, and responsibility definition in the traceability process become simple and clear.

[0127] It is obvious to those skilled in the art that the present application is not limited to the details of the above exemplary embodiments, and the present application can be implemented in other specific forms without departing from the spirit or essential characteristics of the present application.

[0128] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and are not limiting. Although the present application has been described in detail with reference to the preferred embodiments, it should be understood by those skilled in the art that the technical solutions of the present application can be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present application.

Claims

1. A method for large model authentication and authorization based on remote networking, characterized in that, The method comprises the following steps: receiving a networking request to parse the networking request and obtain an identification ID; determining whether the type of the identification ID is a client by using the identification ID; if the type of the identification ID is a client, calling a lightweight agent program of the client; if the type of the identification ID is not a client, determining that the type of the identification ID is a networking node, and calling the lightweight agent program of the client by using the networking node; obtaining identity authentication information of a networking target based on the called lightweight agent program of the client; including the identity authentication information of the networking target into an authorization algorithm; obtaining a result instruction of the authorization algorithm; carrying out large model authentication and authorization by using a record audit log algorithm, and returning the received networking request to parse the networking request and obtain the identification ID until an instruction of ending record is received.

2. The remote group-based networking based large model authentication and authorization method according to claim 1, characterized in that, The method of receiving a networking request to parse the networking request and obtain an identification ID comprises the following steps: defining a data platform level of a system itself; establishing a data response log based on the data platform level of the system itself; receiving a networking request; including data information of the networking request into a first receiving data storage area of the data response log; obtaining information of the networking request by using the data information of the first receiving data storage area of the data response log.

3. The remote group-based networking based large model authentication and authorization method according to claim 2, characterized in that, The method of receiving a networking request to parse the networking request and obtain an identification ID further comprises the following steps: calling information of the networking request of the first receiving data storage area; obtaining an information ID classification feature of the networking request in the first receiving data storage area; calling a data platform level of the system itself; determining whether the classification level of the parsed information ID matches the data platform level of the system itself by using the data platform level; if the classification level of the parsed information ID matches the data platform level of the system itself, obtaining the identification ID; if the classification level of the parsed information ID does not match the data platform level of the system itself, feeding back invalid information of network access, and including the invalid information of network access into a second receiving data storage area of the data response log.

4. The remote group-based networking based large model authentication and authorization method according to claim 3, characterized in that, The method of determining whether the type of the identification ID is a client by using the identification ID comprises the following steps: calling the identification ID and a classification feature of the identification ID; parsing the identification ID to obtain a parsed result of the identification ID; obtaining a device level of a sending device of the networking request by using the parsed result and the classification feature of the identification ID; determining whether the classification feature of the identification ID matches the device level of the sending device of the networking request; if the classification feature of the identification ID matches the device level of the sending device of the networking request, determining that the type of the identification ID is not a client; if the classification feature of the identification ID does not match the device level of the sending device of the networking request, determining that the type of the identification ID is a client.

5. The remote group-based networking based large model authentication and authorization method according to claim 4, characterized in that, The method of calling a lightweight agent program of a client if the type of the identification ID is a client comprises the following steps: determining a data flow direction of a networking process by using the identification ID; forming an information channel of reverse data information transmission by using the identification ID and the data flow direction; establishing an information tunnel by using the information channel; verifying a remote networking node initiated connection request of the lightweight agent program of the client based on the identification ID; obtaining a feedback of a verification result; determining the stability of the information tunnel called by the lightweight agent program based on the feedback of the verification result.

6. The remote group-based model authentication and authorization method according to claim 5, wherein, If the type of the identifier ID is not the client, it is determined that the type of the identifier ID is the networking node, and a lightweight agent program of the client is invoked by the networking node, including: An information tunneling tunnel is established by the networking node; API calling instructions of each networking node are received by the information tunneling tunnel; Identity information of a sending party of the API calling instructions is parsed; An identifier ID to be verified after the identity information is parsed is obtained; It is determined whether the identifier ID to be verified matches the identifier ID requested by the networking by using the identifier ID to be verified and the identifier ID; If the identifier ID to be verified matches the identifier ID requested by the networking, it is determined that the lightweight agent program calls the information tunneling tunnel stably; If the identifier ID to be verified does not match the identifier ID requested by the networking, it is determined that the lightweight agent program calls the information tunneling tunnel unstably.

7. The remote group-based model authentication and authorization method according to claim 6, wherein, The identity authentication information of the networking target includes: Each calling request is parsed in sequence to obtain a parsing result; Data stream characteristic parameters including a data packet quantity in a unit time and a data packet average size are extracted from the parsing result; based on the data packet quantity in the unit time and the data packet average size, an equivalent cylinder volume formed by the data stream in the unit time is calculated, a cylinder bottom area is determined by the data packet average size, and a cylinder height is determined by the data packet quantity in the unit time; authentication characteristic parameters including an authentication data packet quantity and an authentication protocol header size are extracted from the parsing result; Based on the authentication data packet quantity and the authentication protocol header size, an equivalent sphere volume formed in the authentication process is calculated, and a sphere radius is determined by a product of the authentication protocol header size and the authentication data packet quantity; It is determined that an information channel in the selected parsing result is an information tunneling tunnel; If the information channel is not the information tunneling tunnel, information of a request failure is fed back, the calling request at the timestamp is included in a third receiving data storage area of a data response log, a parsing result at a current time is selected by using the timestamp, and the selection is performed until each parsing result is traversed completely; if the information channel is the information tunneling tunnel, a ratio of the data stream equivalent cylinder volume to the authentication equivalent sphere volume is compared, a dynamic and fine-grained authorization is performed on the networking object based on a comparison result of the ratio and a preset threshold, a parsing result at a current time is selected by using the timestamp, and the selection is performed until each parsing result is traversed completely.

8. The remote group-based model authentication and authorization method according to claim 7, wherein, The identity authentication information of the networking target is included in the authorization algorithm, including: An identity of the authorized networking device is bound to a virtual network identity; The virtual network identity is verified by using an identity authentication module, and connection state information of three key nodes in the virtual network is obtained; Based on the connection state information of the three key nodes, a virtual triangle region formed by the three nodes is determined; An area of the virtual triangle region is calculated, and the calculation of the triangle area is based on a relative position relationship of the three nodes; A distribution strategy of the information tunneling tunnel is determined by the authorization strategy engine according to the area of the virtual triangle region, and the larger the area is, the higher the distribution density of the tunneling tunnel is. The authentication and authorization events of each virtual network identity in the data response log are recorded by the audit log module, and the calculation results of the virtual triangular area coverage and the corresponding relationship of the authorization policy are included in the audit range; The calculation results of the identity authentication module, the authorization policy engine and the audit log module and the policy distribution are included in the authorization algorithm to realize dynamic authorization management of the network coverage area.

9. The remote group-based model authentication and authorization method of claim 8, wherein, The large model authentication and authorization using the record audit log algorithm includes: Recording the record information of the gateway; Receiving the authorized request from the authentication and authorization center; Forwarding the request to the large model API; Storing the permission relationship of users, roles, devices and resources.

10. A large model authentication and authorization system based on remote networking, characterized in that, It includes: A server for executing the large model authentication and authorization method based on remote networking as claimed in any one of claims 1 to 9; A memory in communication connection with the server.

Citation Information

Patent Citations

  • System and method for operating a head mounted display system based on user identity

    CN115053270A

  • Big data system security protection method, device and equipment based on zero-trust architecture

    CN118300797A

  • Zero-trust-based traffic security audit protection method and system, and readable medium

    CN118337532A

  • Quadruple port hiding method and device based on zero-trust architecture

    CN119383002A

  • Decentralized identity authentication method, system, device and medium

    CN119939547A

Cited By

  • Edge node remote access method and device based on cloud edge collaboration and electronic equipment

    CN121691324A