Large model authentication and authorization system and method based on remote networking
By establishing an encrypted virtual network tunnel through a remote networking authentication and authorization system, utilizing identifiers and lightweight proxy programs, the network security and access control issues of large-scale services are resolved. This enables secure, fine-grained access and auditing, and enhances the flexibility and security of network interconnection and authentication.
Patent Information
- Application Number
- CN202511417688.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-30
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2045-09-30
AI Technical Summary
Traditional large model services have shortcomings in terms of network security, access control, fine-grained logging and auditing mechanisms. Especially in enterprise, alliance or multi-tenant scenarios, users or services have difficulty securely accessing remotely deployed large models, and existing authentication methods have leakage risks and complexity issues.
An authentication and authorization system based on remote networking is adopted. By parsing the identifier ID, determining its type, calling a lightweight agent program, and establishing an encrypted virtual network tunnel, the system combines decentralized identity and distributed ledger technology to manage identity and authorization policies, thereby achieving fine-grained authentication and auditing.
It reduces the risk of API transmission leakage, provides coarse-grained and fine-grained access control, simplifies network interconnection and authentication methods, supports secure access in different network environments, and implements fine-grained logging and auditing mechanisms.
Smart Images

Figure CN120915601B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to a remote networking-based large model authentication and authorization system and method, and belongs to the technical field of digital data processing. BACKGROUND
[0002] Large model technology represented by large language models is developing rapidly and has shown great application potential in various industries. These models are usually deployed in the cloud or enterprise private data centers and provide services to the outside in the form of APIs (application program interfaces) through the network. Users, including developers, data analysts, business personnel, and downstream applications, need to access these models for inference, fine-tuning, or management through remote networks. As the application scenarios of large models expand and deepen, network security problems arise in the process of communication and interaction between user terminals operated by different personnel and models. In enterprise, alliance, or multi-tenant scenarios, users or services in different network environments need to securely access remotely deployed large models. The network environment of the large model is, for example, a private cloud, a public cloud, or a local deployment. Traditional network interconnection and authentication methods have the following problems:
[0003] The traditional API key or token management method has a risk of leakage. Once the key is stolen, attackers can misuse the model service, causing economic losses or data breaches.
[0004] Existing large model services usually provide coarse-grained permission control (for example, by API or by user). For scenarios that require fine-grained authorization of model functions (such as allowing access to specific knowledge bases, calling specific plugins, limiting inference times, etc.), existing systems are difficult to meet;
[0005] In enterprise, alliance, or multi-tenant scenarios, users or services in different network environments (for example, private clouds, public clouds, or local deployments) need to securely access remotely deployed large models. Traditional network interconnection and authentication methods are complex and not easily scalable;
[0006] There is a lack of fine-grained recording and auditing mechanism for large model calling behavior, making it difficult to trace back and define responsibilities;
[0007] Therefore, it is necessary to propose a remote networking-based large model authentication and authorization system and method to address the problem of secure authentication and authorization of model deployment. SUMMARY
[0008] The application provides a remote networking-based large model authentication and authorization system and method to solve the problem of secure authentication and authorization of model deployment.
[0009] The application provides a remote networking-based large model authentication and authorization method, which includes:
[0010] Receiving a networking request to parse the networking request and obtain an identification ID;
[0011] Determining whether the type of the identification ID is a client using the identification ID;
[0012] If the type of the identification ID is a client, calling a lightweight agent program of the client;
[0013] If the type of the identification ID is not a client, determining that the type of the identification ID is a networking node, and calling the lightweight agent program of the client using the networking node;
[0014] Obtaining identity authentication information of a networking target based on the called lightweight agent program of the client;
[0015] Including the identity authentication information of the networking target into an authorization algorithm;
[0016] Obtaining a result instruction of the authorization algorithm;
[0017] Performing large model authentication and authorization using a record audit log algorithm, and returning the receiving of the networking request to parse the networking request and obtain the identification ID until receiving an instruction to end the record.
[0018] Further, defining a data platform level of the system itself;
[0019] Based on the data platform level of the system itself, establishing a data response log;
[0020] Receiving a networking request;
[0021] Including data information of the networking request into a first receiving data storage area of the data response log;
[0022] Obtaining information of the networking request using the data information of the first receiving data storage area of the data response log.
[0023] Specifically, by parsing the networking request and obtaining the identification ID, determining the legality of the large model of the remote networking in the terminal lightweight agent program rule, establishing an encrypted virtual network tunnel between the user / application end and the large model service providing end, and all calling requests are transmitted through the tunnel, reducing the leakage risk probability of the API transmission path.
[0024] Further, calling the information of the networking request of the first receiving data storage area;
[0025] Obtaining information ID classification characteristics of the networking request in the first receiving data storage area;
[0026] Calling the data platform level of the system itself;
[0027] Determine whether the level of the parsed information ID classification feature is consistent with the data platform level of the system itself by using the data platform level.
[0028] If the level of the parsed information ID classification feature is consistent with the data platform level of the system itself, obtain the identification ID.
[0029] If the level of the parsed information ID classification feature is not consistent with the data platform level of the system itself, feed back the invalid information into the network, and include the invalid information into the second receiving data storage area of the data response log.
[0030] Specifically, determine the type of the identification ID, decentralized identity (DID) or similar technology, to realize the autonomous management of user identity, and store and verify the authorization strategy in combination with distributed ledger technology.
[0031] Further, call the identification ID and the classification feature of the identification ID.
[0032] Parse the identification ID to obtain the parsing result of the identification ID.
[0033] Obtain the level of the device sending the networking request by using the parsing result and the classification feature of the identification ID.
[0034] Determine whether the classification feature of the identification ID matches the level of the device sending the networking request.
[0035] If the classification feature of the identification ID matches the level of the device sending the networking request, determine that the type of the identification ID is not a client.
[0036] If the classification feature of the identification ID does not match the level of the device sending the networking request, determine that the type of the identification ID is a client.
[0037] Further, determine the data flow direction of the networking process by using the identification ID.
[0038] Form an information channel for reverse transmission of data information by using the identification ID and the data flow direction.
[0039] Establish an information tunnel by using the information channel.
[0040] Initiate a connection request based on the identification ID to verify the remote networking node of the lightweight agent program of the client.
[0041] Obtain the feedback of the verification result.
[0042] Determine the stability of the information tunnel called by the lightweight agent program based on the feedback of the verification result.
[0043] Specifically, when the terminal making the network request is a client, the lightweight agent program of the client can be directly invoked through the network request and the obtained identifier ID. The server provides coarse-grained access control, for example, according to the API interface level. For scenarios that require detailed authorization of model functions, such as allowing access to specific knowledge bases, calling specific plugins, or limiting the number of inferences, the identity authentication information of the network target is obtained based on the invoked lightweight agent program of the client. The identity authentication information of the network target is incorporated into the authorization algorithm to obtain the result instruction of the authorization algorithm.
[0044] Furthermore, information tunnels can be established by utilizing network nodes;
[0045] Utilizing the information tunnel, API call instructions are received from each network node;
[0046] Parse the identity information of the party issuing the API call command;
[0047] Obtain the identifier ID to be verified after parsing the identity information;
[0048] Using the ID to be verified and the ID, determine whether the ID to be verified matches the ID in the network request;
[0049] If the identifier ID to be verified matches the identifier ID in the network request, then the stability of the lightweight agent program calling information tunneling tunnel is confirmed.
[0050] If the identifier ID to be verified does not match the identifier ID in the network request, it is determined that the lightweight agent program is calling the information tunneling tunnel is unstable.
[0051] Furthermore, each call request is parsed sequentially to obtain the parsing results;
[0052] Extract data flow feature parameters from the parsing results. These parameters include the number of data packets per unit time and the average size of the data packets. Based on the number of data packets per unit time and the average size of the data packets, calculate the equivalent cylinder volume formed by the data flow per unit time. The base area of the cylinder is determined by the average size of the data packets, and the height of the cylinder is determined by the number of data packets per unit time. Extract authentication feature parameters from the parsing results. These parameters include the number of authentication data packets and the size of the authentication protocol header.
[0053] Based on the number of authentication packets and the size of the authentication protocol header, the volume of the equivalent sphere formed during the authentication process is calculated, and the radius of the sphere is determined by the product of the size of the authentication protocol header and the number of authentication packets.
[0054] Determine the information path in the selected parsing results and determine whether the information path is an information tunnel.
[0055] If the information channel is not an information tunneling tunnel, feedback the information of the failed request, include the calling request at the time stamp in the third receiving data storage area of the data response log, return a parsing result selected from the current time using the time stamp, and iterate until each parsing result is completed; if the information channel is an information tunneling tunnel, compare the ratio of the data flow equivalent cylinder volume and the authentication equivalent sphere volume, dynamically and finely authorize the object of networking based on the comparison result of the ratio and the preset threshold, return a parsing result selected from the current time using the time stamp, and iterate until each parsing result is completed.
[0056] Specifically, in an enterprise, alliance or multi-tenant scenario, different network environments, such as private cloud, public cloud, local deployment, users or services need to securely access remotely deployed large models. When the type of the identifier ID is not a client, the type of the identifier ID is determined to be a networking node, a lightweight agent program of the client is called using the networking node, identity authentication information of the networking target is obtained based on the called lightweight agent program of the client, the identity authentication information of the networking target is included in the authorization algorithm, the result instruction of the authorization algorithm is obtained, an encrypted virtual network tunnel is established between the user / application end and the large model service provider end, all calling requests are transmitted through the tunnel, and a zero trust (Zero Trust) security concept can be used, which does not trust any internal or external network connection, and all requests need to pass through strict identity verification and authorization check, thereby expanding the network interconnection and authentication mode.
[0057] Further, the identity of the authorized networking device is bound to the virtual network identity;
[0058] The virtual network identity is verified by the identity authentication module, and the connection state information of three key nodes in the virtual network is obtained;
[0059] Based on the connection state information of the three key nodes, a virtual triangular region composed of the three nodes is determined;
[0060] The coverage area of the virtual triangular region is calculated, and the calculation of the triangular area is based on the relative position relationship of the three nodes;
[0061] The distribution strategy of the information tunneling tunnel is determined by the authorization policy engine according to the coverage area of the virtual triangular region, and the greater the coverage area, the higher the distribution density of the tunneling tunnel;
[0062] The authentication and authorization events of each virtual network identity in the data response log are recorded by the audit log module, and the calculation result of the virtual triangular region coverage area and the corresponding relationship of the authorization policy are included in the audit range;
[0063] The calculation results of the identity authentication module, the authorization policy engine and the audit log module are incorporated into the authorization algorithm together with the policy allocation to realize dynamic authorization management of the network coverage area.
[0064] Further, record the record information of the record gateway;
[0065] Receive an authorized request from the authentication and authorization center;
[0066] Forward the request to the large model API;
[0067] Store the permission relationship of users, roles, devices and resources.
[0068] The application also provides a large model authentication and authorization system based on remote networking, comprising:
[0069] A server for executing the large model authentication and authorization method based on remote networking.
[0070] A memory in communication connection with the server.
[0071] The application has the following advantages:
[0072] By analyzing the networking request and obtaining the identification ID, the legality of the large model in the remote networking is determined by the terminal lightweight proxy program, an encrypted virtual network tunnel is established between the user / application end and the large model service provider end, and all call requests are transmitted through the tunnel, reducing the leakage risk probability of the API transmission path, preventing the model service from being abused by attackers, and reducing economic losses or data leakage.
[0073] When the terminal of the networking request is a client, the lightweight proxy program of the client can be directly called through the networking request and the obtained identification ID, the server provides coarse-grained permission control, for example, according to the interface level of the API, for the scene that needs to subdivide the authorization of the model function, such as allowing to access a specific knowledge base, calling a specific plug-in, limiting the number of reasoning, etc.
[0074] In enterprise, alliance or multi-tenant scenarios, different network environments such as private cloud, public cloud and local deployment, users or services need to securely access large models deployed remotely. When the type of identification ID is not a client, the type of identification ID is determined to be a networking node, the lightweight agent program of the client is called by the networking node, based on the called lightweight agent program of the client, the identity authentication information of the networking target is obtained, the identity authentication information of the networking target is included in the authorization algorithm, the result instruction of the authorization algorithm is obtained, the encrypted virtual network tunnel is established between the user / application end and the large model service providing end, all calling requests are transmitted through the tunnel, and the zero trust (Zero Trust) security concept can be used, which does not trust any internal or external network connection, and all requests need to pass through strict identity verification and authorization check, which expands the network interconnection and authentication mode.
[0075] The large model authentication and authorization method can record and audit the fine-grained behavior of the large model calling, so that the network security management, network authorization, cross-network access and traceability are simple and clear in the tracing process and responsibility definition. BRIEF DESCRIPTION OF DRAWINGS
[0076] Figure 1 A flowchart of a large model authentication and authorization method based on remote networking according to an embodiment of the present application.
[0077] Figure 2 A structure connection diagram of a large model authentication and authorization system based on remote networking according to an embodiment of the present application. BRIEF DESCRIPTION OF DRAWINGS
[0079] 100-server; 200-memory. DETAILED DESCRIPTION
[0080] In order to make the purpose, technical scheme and advantages of the present application clearer, the technical scheme of the present application will be described in detail below with reference to the drawings. Obviously, the described embodiments are only part of the embodiments of the present application, not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.
[0081] As shown in Figure 1 A large model authentication and authorization method based on remote networking provided by the present application comprises:
[0082] S100, receiving a networking request to parse the networking request and obtain an identification ID.
[0083] S200, using the identification ID to determine whether the type of identification ID is a client.
[0084] S300, if the type of the identification ID is a client, a lightweight agent program of the client is invoked.
[0085] S400, if the type of the identification ID is not a client, it is determined that the type of the identification ID is a networking node, and a lightweight agent program of the client is invoked by using the networking node.
[0086] S500, based on the invoked lightweight agent program of the client, identity authentication information of a networking target is obtained.
[0087] S600, the identity authentication information of the networking target is included in an authorization algorithm.
[0088] S700, a result instruction of the authorization algorithm is obtained.
[0089] S800, a large model is authenticated and authorized by using a record audit log algorithm, and the received networking request is returned to parse the networking request, obtain the identification ID, and until the instruction of ending the record is received.
[0090] Specifically, a server-centered data center can receive a networking request, parse the networking request, and obtain an identification ID. The data center serves as a data hub, undertakes data storage, processing, transmission, and acceleration tasks, and supports cloud computing, online services, and enterprise-level application running. The main types of data centers include enterprise data centers, enterprise data centers, and edge data centers.
[0091] It can be understood that an enterprise data center serves the private data processing needs of a single organization. A cloud data center is operated by a third-party provider and provides on-demand allocation of computing resources. An edge data center is deployed close to the user side to reduce latency and support real-time data processing. Among them, the edge data center is in the middle layer of the end-edge-cloud architecture and can be connected in communication with the networking node. In enterprise, alliance, or multi-tenant scenarios, different network environments, such as private clouds, public clouds, and local deployments, users or services can securely access remotely deployed large models by receiving a networking request, parsing the networking request, and obtaining an identification ID, which can optimize network interconnection and authentication methods.
[0092] Simply put, in the connection process of a communication network, parsing a networking request and obtaining an identification ID is generally achieved by parsing the ID (Identifier) in the data, and obtaining an identification ID is one of the basic operations of data processing, and the core goal is to accurately extract, verify, and utilize unique identifiers from raw data.
[0093] Large language model (LLM) is a large model that relies on network architecture. Generally, network architecture includes hierarchical network architecture, flat network architecture, and distributed network architecture. Enterprise private cloud can use local area network. The network architecture of this local area network is generally flat network architecture. Enterprise private cloud is generally connected directly through an encrypted communication tunnel between the client and the server of the data center. The client is a computing terminal, and a lightweight agent program of the client can be deployed.
[0094] Public cloud generally uses hierarchical network architecture and distributed network architecture. Simply put, hierarchical network architecture is divided into three layers: core layer, aggregation layer, and access layer. Distributed network architecture is divided into network resources distributed in multiple geographic locations and connected through high-speed networks. The server of the data center can determine the networking node according to the type of identification ID and call the lightweight agent program of the client using the networking node.
[0095] The present application relates to a large model authentication and authorization method based on remote networking. The method uses an encrypted tunnel and a zero-trust architecture to effectively prevent man-in-the-middle attacks and credential leaks. By analyzing the networking request and obtaining the identification ID, the legality of the large model in the terminal lightweight agent program is determined. An encrypted virtual network tunnel is established between the user / application end and the large model service provider end. All call requests are transmitted through the tunnel, reducing the risk of leakage of API transmission routes and preventing attackers from abusing model services, reducing economic losses or data leaks. Using the identification ID, the type of identification ID is determined, and the decentralized identity (DID) or similar technology is used to achieve self-management of user identity. In combination with distributed ledger technology, the storage and verification of authorization policies are achieved.
[0096] Cross-network interconnection can seamlessly connect clients and large model services in different network environments, simplifying deployment and management.
[0097] When the terminal of the networking request is a client, the lightweight agent program of the client can be directly called through the networking request and the obtained identification ID. The server provides coarse-grained permission control, such as API interface level. For scenarios that require fine-grained authorization of model functions, such as allowing access to specific knowledge bases, calling specific plugins, and limiting inference times, the identity authentication information of the networking target is obtained based on the called lightweight agent program of the client. The identity authentication information of the networking target is included in the authorization algorithm, and the result instruction of the authorization algorithm is obtained. The server can also use its own service level decentralized identity (DID) or similar technology to achieve self-management of user identity, and combine distributed ledger technology to store and verify authorization policies.
[0098] In an enterprise, alliance or multi-tenant scenario, different network environments, such as private cloud, public cloud, local deployment, users or services need to securely access remotely deployed large models. When the type of the identification ID is not a client, the type of the identification ID is determined to be a networking node, a lightweight agent program of the client is called by the networking node, based on the called lightweight agent program of the client, identity authentication information of the networking target is obtained, the identity authentication information of the networking target is included in the authorization algorithm, the result instruction of the authorization algorithm is obtained, an encrypted virtual network tunnel is established between the user / application end and the large model service providing end, all calling requests are transmitted through the tunnel, and a zero trust (Zero Trust) security concept can be used, which does not trust any internal or external network connection, and all requests need to pass through strict identity verification and authorization check, which expands the network interconnection and authentication mode.
[0099] In an embodiment of the present application, S100 comprises:
[0100] S111 defines the data platform level of the system itself.
[0101] S112 establishes a data response log based on the data platform level of the system itself.
[0102] S113 receives a networking request.
[0103] S114 includes the data information of the networking request in the first received data storage area of the data response log.
[0104] S115 obtains the information of the networking request by using the data information of the first received data storage area of the data response log.
[0105] It can be understood that from the perspective of structure, the network architecture includes star network, bus network, mesh network, etc. In terms of star network architecture, the data center can connect multiple peripheral nodes through the central node. The servers in the data center can respond to data according to the data platform level of the system itself. Based on the data platform level of the system itself, a data response log is established. Such a data response log provides a fine-grained record and audit mechanism for large model calling behavior, making it easy to trace back and define responsibilities.
[0106] In the embodiment, the method for establishing a data response log can provide a large model authentication and authorization system and method based on remote networking technology, which realizes fine-grained authentication, authorization and auditing of large model calling by constructing a secure virtual network.
[0107] In an embodiment of the present application, S100 further comprises:
[0108] S121, call the information of networking request of the first receiving data storage area.
[0109] S122, obtain the information ID classification characteristics of the networking request in the first receiving data storage area.
[0110] S123, call the data platform level of the system itself.
[0111] S124, use the data platform level to determine whether the level of the parsed information ID classification characteristics is consistent with the data platform level of the system itself.
[0112] S125a, if the level of the parsed information ID classification characteristics is consistent with the data platform level of the system itself, obtain the identification ID.
[0113] S125b, if the level of the parsed information ID classification characteristics is not consistent with the data platform level of the system itself, feedback the invalid information of network access, and include the invalid information of this network access in the second receiving data storage area of the data response log.
[0114] It can be understood that in the information ID classification characteristics of the networking request in the first receiving data storage area, the information ID classification characteristics is generally distinguished by ID type, such as pure number type, letter + number combination, separator, self-increment sequence, and ID type generated by an external system.
[0115] In the process of calling the information of networking request of the first receiving data storage area, the information ID generated by the external system is the focus of server parsing information ID, and these information IDs generated by the external system have relatively specific identification IDs, which can be used for permission management of secondary network devices accessed across networks and organizations.
[0116] Simply, in the network architecture of the bus-shaped network in the public cloud, the A-level server can broadcast data information to data clients with information ID classification characteristics of A, B, and C levels. The B-level server can broadcast data information to data clients with information ID classification characteristics of B and C levels.
[0117] In this embodiment, by obtaining the information ID classification characteristics of the networking request in the first received data storage area, the remote network access model is realized for inference, fine-tuning or management. The determination of the identification ID can be in the massive logs that need to associate multiple operations of the same user. The detection of different account registration behaviors of the same device in a short time. The identity authentication of cross-service calls under the micro-service architecture is realized by analyzing the networking request and obtaining the identification ID to determine the legality of the remote networking of the large model in the terminal lightweight proxy program. A virtual network tunnel is established between the user / application end and the large model service provider end, and all call requests are transmitted through the tunnel, reducing the risk probability of API transmission leakage and preventing attackers from abusing model services, reducing economic losses or data leakage. By using the identification ID, the type of the identification ID is judged, the decentralized identity (DID) or similar technology is used to realize the autonomous management of the user identity, and the distributed ledger technology is used to store and verify the authorization strategy, which can realize the construction of auxiliary index in high-frequency query dimension.
[0118] In one embodiment of the present application, S200 includes:
[0119] S210, calling the identification ID and the classification characteristics of the identification ID.
[0120] S220, analyzing the identification ID to obtain the analysis result of the identification ID.
[0121] S230, using the analysis result and the classification characteristics of the identification ID to obtain the device level of the networking request.
[0122] S240, judging whether the classification characteristics of the identification ID match the device level of the networking request.
[0123] S251, if the classification characteristics of the identification ID match the device level of the networking request, it is determined that the type of the identification ID is not a client.
[0124] S252, if the classification characteristics of the identification ID do not match the device level of the networking request, it is determined that the type of the identification ID is a client.
[0125] It can be understood that the identification ID can be parsed using a regular expression, and a targeted regular expression can be written according to the observed pattern. The parsed sub-sections are stored in independent fields for quick query, which is beneficial for data storage of data response logs. It lays a solid foundation for data analysis, system integration and security control. By parsing the identification ID, the analysis result of the identification ID is obtained, and the device level of the networking request is obtained by using the analysis result and the classification characteristics of the identification ID. The model is usually deployed in the cloud or enterprise private data center, and services are provided to the device that sends the networking request in the form of API (application program interface) through the network.
[0126] After obtaining the issuing device level of the networking request, the server can infer the indirect connection relationship from the client to the proxy end and from the proxy end to the service end by analyzing the records in the network request or response content, and then complete multi-dimensional data collection, hierarchical matching strategy, weight scoring, and determination of node proxy.
[0127] In this embodiment, the zero trust (Zero Trust) security concept is adopted, which does not trust any internal or external network connection, and all requests need to pass through strict identity verification and authorization check. The identity of the user (for example, user ID, device ID, application ID, etc.) is bound with the virtual network identity, and dynamic and fine-grained authorization is performed based on the policy engine.
[0128] In one embodiment of the present application, S300 includes:
[0129] S310 determines the data flow direction of the networking process by using the identifier ID.
[0130] S320 forms an information path for reverse transmission of data information by using the identifier ID and the data flow direction.
[0131] S330 establishes an information tunnel by using the information path.
[0132] S340 verifies the connection request initiated by the remote networking node of the lightweight proxy program of the client based on the identifier ID.
[0133] S350 obtains the feedback of the verification result.
[0134] S360 determines the stability of the lightweight proxy program calling the information tunnel based on the feedback of the verification result.
[0135] It can be understood that the server can infer the indirect connection relationship from the client to the proxy end and from the proxy end to the service end.
[0136] The server can also infer the direct LAN connection relationship from the client to the gateway and from the gateway to the server itself.
[0137] It can be understood that the self-management of user identity is realized by using decentralized identity (DID) or similar technology, and the storage and verification of authorization policies are realized by combining with distributed ledger technology.
[0138] An encrypted virtual network tunnel is established between the user or application end and the large model service providing end, and all calling requests are transmitted through the tunnel. The user or application client (Client Agent) can use the lightweight proxy program deployed on the user device or application server.
[0139] Briefly, the data flow direction of the networking process is determined, the information path of the reverse transmission of data information is formed, the information tunnel is established, and the remote networking node initiates a connection request by using the lightweight agent program of the client. The transmission information of the established information tunnel can be used to determine the stability of the information tunnel called by the lightweight agent program.
[0140] In one embodiment of the present application, S400 comprises:
[0141] S410, establishing an information tunnel by using the networking node.
[0142] S420, receiving API call instructions of each networking node by using the information tunnel.
[0143] S430, parsing the identity information of the API call instruction sender.
[0144] S440, obtaining the to-be-verified identifier ID after parsing the identity information.
[0145] S450, determining whether the to-be-verified identifier ID matches the identifier ID of the networking request by using the to-be-verified identifier ID and the identifier ID.
[0146] S461, if the to-be-verified identifier ID matches the identifier ID of the networking request, determining that the information tunnel called by the lightweight agent program is stable.
[0147] S462, if the to-be-verified identifier ID does not match the identifier ID of the networking request, determining that the information tunnel called by the lightweight agent program is unstable.
[0148] It can be understood that the lightweight agent program deployed on the user equipment or the application server is deployed at the network edge and is used for establishing and maintaining a virtual network tunnel. The authentication and authorization center based on the information path of the virtual network tunnel is the core of the entire network system, and the authentication and authorization center has an identity authentication module, which verifies the identity credentials submitted by the client, such as a digital certificate, a DID, and an OAuth2.0 Token. The authentication and authorization center has an authorization policy engine, which makes authorization decisions based on preset or dynamic policies. The authentication and authorization center has an audit log module, which records all authentication and authorization events and generates logs with timestamps and signatures.
[0149] In this embodiment, the large model authentication and authorization are performed by using the record audit log algorithm, the fine-grained record and audit mechanism of the large model calling behavior are realized, and network security management, network authorization, cross-network access, and traceability are simple and clear in the tracing process and responsibility definition.
[0150] In one embodiment of the present application, S500 comprises:
[0151] S510, sequentially analyze each call request to obtain an analysis result.
[0152] S520, extract a data flow characteristic parameter from the analysis result, the data flow characteristic parameter including a data packet quantity in a unit time and a data packet average size, calculate an equivalent cylinder volume formed by the data flow in the unit time based on the data packet quantity in the unit time and the data packet average size, a cylinder base area being determined by the data packet average size, a cylinder height being determined by the data packet quantity in the unit time, extract an authentication characteristic parameter from the analysis result, the authentication characteristic parameter including an authentication data packet quantity and an authentication protocol header size.
[0153] S530, calculate an equivalent sphere volume formed in an authentication process based on the authentication data packet quantity and the authentication protocol header size, a sphere radius being determined by a product of the authentication protocol header size and the authentication data packet quantity.
[0154] S540, determine an information path in the selected analysis result, and judge whether the information path is an information tunneling tunnel.
[0155] S550, if the information path is not the information tunneling tunnel, feedback information of a request failure, include the call request at the timestamp in a third receiving data storage area of the data response log, return to use the timestamp, select an analysis result at a current time, and repeat until each analysis result is traversed, if the information path is the information tunneling tunnel, compare a ratio of the data flow equivalent cylinder volume and the authentication equivalent sphere volume, dynamically and finely authorize an object of networking based on a comparison result of the ratio and a preset threshold, return to use the timestamp, select an analysis result at a current time, and repeat until each analysis result is traversed.
[0156] It can be understood that a message in a message queue usually includes a timestamp, and the message queue timestamp is used to mark a business occurrence time of the message, and is suitable for event traceability recorded in the data response log.
[0157] The timestamp of the message queue can support complex business logic and performance optimization.
[0158] Briefly, the first receiving data storage area of the data response log is used to receive data information of a networking request, and including the data information of the networking request in the data response log is conducive to determining a lightweight proxy program of a client through a regular expression, and then establishing an information tunneling tunnel.
[0159] The information of invalid network access is included in the second received data storage area of the data response log, and the ID (Identifier) in the data can be accurately extracted, verified and used from the original data using the data in the second received data storage area of the data response log. According to the obtained mode, a specific regular expression is written to confirm that each part after parsing meets the business logic of audit and traceability.
[0160] The lightweight agent of the called client can realize the data flow conduction of the communication channel of the server to the model demand object. The calling request of the model demand object can realize the performance allocation of the model and the transmission of the model operation result.
[0161] The third received data storage area of the data response log is used to calculate the tunneling of the irregular calling information of the external user end.
[0162] In this embodiment, all model calls through the virtual network are recorded and signed to form an unalterable audit log. Using decentralized identity (DID) or similar technology, the user's identity is managed autonomously, and the distributed ledger technology is used to store and verify the authorization policy.
[0163] In one embodiment of the present application, S600 includes:
[0164] S610, the identity of the authorized networking device is bound to the virtual network identity.
[0165] S620, the virtual network identity is verified by the identity authentication module, and the connection state information of the three key nodes in the virtual network is obtained.
[0166] S630, based on the connection state information of the three key nodes, a virtual triangle area composed of the three nodes is determined.
[0167] S640, the coverage area of the virtual triangle area is calculated, wherein the calculation of the area of the triangle is based on the relative position relationship of the three nodes.
[0168] S650, the distribution strategy of the information tunneling tunnel is determined by the authorized policy engine according to the coverage area of the virtual triangle area, wherein the greater the coverage area, the higher the distribution density of the tunneling tunnel.
[0169] S660, the audit log module records the authentication and authorization events of each virtual network identity in the data response log, and the corresponding relationship between the calculation result of the coverage area of the virtual triangle area and the authorized policy is included in the audit range.
[0170] S670, incorporate the calculation results of the identity authentication module, authorization policy engine and audit log module into the authorization algorithm with the policy allocation, and realize dynamic authorization management of the network coverage area.
[0171] Specifically, an encrypted tunnel is established with the remote networking node. The large model invocation request is captured. The request is encapsulated and sent to the authentication and authorization center. The user or device identity certificate is carried. The connection of the client is managed. Tunnel encryption and decryption are performed. The encapsulated request is forwarded to the authentication and authorization center. WireGuard or a custom protocol can be used to implement it.
[0172] Verify the identity credentials submitted by the client, such as digital certificates, DIDs, OAuth2.0 tokens. Based on pre-set or dynamic policies, make authorization decisions on requests. Record all authentication and authorization events and generate timestamped and signed logs.
[0173] Receive authorized requests from the authentication and authorization center. Forward the request to the actual large model API. May include load balancing, traffic control, etc. Store the permission relationship of users, roles, devices and resources, which can use relational databases, NoSQL databases or distributed ledgers.
[0174] In an embodiment of the present application, S800 includes:
[0175] S810, record the record information of the gateway.
[0176] S820, receive authorized requests from the authentication and authorization center.
[0177] S830, forward the request to the large model API.
[0178] S840, store the permission relationship of users, roles, devices and resources.
[0179] It can be understood that the client agent starts and initiates a connection request to the remote networking node. Identity authentication and key exchange are completed between the client and the node, and an end-to-end encrypted tunnel is established.
[0180] The user's application program initiates an API call to the large model, for example, / v1 / chat / completions. The client agent captures the request and adds the user's identity information, such as DID, device ID, in the request header or payload.
[0181] The encapsulated request is sent to the remote networking node through the tunnel and forwarded to the authentication and authorization center. The authentication and authorization center first verifies whether the identity certificate of the request is valid. If the identity is valid, the policy engine makes a decision according to the pre-set authorization policy. The policy engine decides to "allow" or "reject" the request. For example:
[0182] Policy 1: User A can call the gpt-4-turbo model during Monday to Friday 9:00-18:00, with a maximum of 1000 requests per day.
[0183] Policy 2: Device B can only call the model-b model and is limited to accessing knowledge base C.
[0184] If the request is "allowed", the authentication and authorization center forwards the request with authorization credentials to the large model service gateway. The large model service gateway receives the request and calls the corresponding large model API. At the same time, the audit log module records all information of this call, such as caller, timestamp, model name, authorization result, etc., and signs it to ensure that the log is tamper-proof. The large model returns the result, which passes through the service gateway and remote networking nodes, and finally returns to the client through an encrypted tunnel.
[0185] This embodiment effectively prevents man-in-the-middle attacks and credential leaks through end-to-end encrypted tunnels and zero-trust architecture. It can perform flexible and dynamic authorization based on user, device, time, number of calls, model type, and even model functions such as plugin calls, greatly improving the flexibility of permission management. It can seamlessly connect clients and large model services in different network environments, simplifying deployment and management. Automatically generate tamper-proof audit logs to provide strong support for post-tracing and security compliance. Modular design makes the system easy to extend, allowing easy access to new authentication methods, policy engines, or large model services.
[0186] As shown in Figure 2 The application also provides a large model authentication and authorization system based on remote networking, which includes:
[0187] The server 100 is used to execute the large model authentication and authorization method based on remote networking.
[0188] The memory 200 is in communication connection with the server 100.
[0189] The server 100 and the memory 200 of this embodiment perform flexible and dynamic authorization, greatly improving the flexibility of permission management. It can seamlessly connect clients and large model services in different network environments, simplifying deployment and management. Automatically generate tamper-proof audit logs to provide strong support for post-tracing and security compliance. Modular design makes the system easy to extend, allowing easy access to new authentication methods, policy engines, or large model services.
[0190] When the terminal of the networking request is a client, the server 100 can directly call the lightweight agent program of the client through the networking request and the obtained identifier ID. The server 100 provides coarse-grained permission control, for example, according to the interface level of the API. For scenarios that require fine-grained authorization of model functions, such as allowing access to a specific knowledge base, calling a specific plug-in, limiting the number of reasoning times, and the like, the server 100 obtains the identity authentication information of the networking target based on the called lightweight agent program of the client, incorporates the identity authentication information of the networking target into an authorization algorithm, and obtains the result instruction of the authorization algorithm. The server 100 can also realize the autonomous management of the user identity according to its own service level decentralized identity (DID) or similar technology, and store and verify the authorization strategy in combination with the distributed ledger technology.
[0191] In an enterprise, alliance, or multi-tenant scenario, different network environments, such as a private cloud, a public cloud, and local deployment, require users or services to securely access a remotely deployed large model. When the type of the identifier ID is not a client, the type of the identifier ID is determined to be a networking node. The lightweight agent program of the client is called by the networking node. The identity authentication information of the networking target is obtained based on the called lightweight agent program of the client. The identity authentication information of the networking target is incorporated into an authorization algorithm, and the result instruction of the authorization algorithm is obtained. An encrypted virtual network tunnel is established between the user / application end and the large model service provider end. All calling requests are transmitted through the tunnel. The concept of Zero Trust security can be adopted, which does not trust any internal or external network connection. All requests need to undergo strict identity verification and authorization checks, thereby expanding the network interconnection and authentication methods.
[0192] The server 100 and the storage 200 use a record audit log algorithm to perform large model authentication and authorization. The fine-grained record and audit mechanism of the large model calling behavior makes network security management, network authorization, cross-network access, and traceability simple and clear in the tracing process and responsibility definition.
[0193] It is apparent for those skilled in the art that the present application is not limited to the details of the foregoing exemplary embodiments, and the present application can be implemented in other concrete forms without departing from the spirit or essential characteristics of the present application.
[0194] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application but not limit the present application. Although the present application has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present application can be modified or replaced by equivalents without departing from the spirit and scope of the present application.
Claims
1. A method for large model authentication and authorization based on remote networking, characterized in that, Comprise: Receiving a networking request to parse the networking request and obtain an identification ID; Using the identification ID, determining whether the type of the identification ID is a client; If the type of the identification ID is a client, calling a lightweight agent program of the client; If the type of the identification ID is not a client, determining that the type of the identification ID is a networking node, and calling the lightweight agent program of the client using the networking node; Based on the called lightweight agent program of the client, obtaining identity authentication information of a networking target; Parsing each calling request in turn to obtain a parsing result; Extracting data flow characteristic parameters from the parsing result, The data flow characteristic parameters include the number of data packets per unit time and the average size of data packets; Based on the number of data packets per unit time and the average size of data packets, calculating the equivalent cylindrical volume formed by the data flow per unit time, the base area of the cylinder being determined by the average size of the data packets, and the height of the cylinder being determined by the number of data packets per unit time; extracting authentication characteristic parameters from the parsing result, the authentication characteristic parameters including the number of authentication data packets and the size of the authentication protocol header; Based on the number of authentication data packets and the size of the authentication protocol header, calculating the equivalent spherical volume formed in the authentication process, the radius of the sphere being determined by the product of the size of the authentication protocol header and the number of authentication data packets; determining an information path in the selected parsing result, and determining whether the information path is an information tunneling tunnel; If the information path is not an information tunneling tunnel, feeding back information of a failed request, including the calling request under the timestamp in a third receiving data storage area of a data response log, returning a parsing result at the current time using a timestamp, and iterating until each parsing result is completed; if the information path is an information tunneling tunnel, comparing the ratio of the data flow equivalent cylindrical volume to the authentication equivalent spherical volume, dynamically and finely authorizing the networking object based on the comparison result of the ratio and a preset threshold, returning a parsing result at the current time using a timestamp, and iterating until each parsing result is completed; Including the identity authentication information of the networking target in an authorization algorithm; Obtaining a result instruction of the authorization algorithm; The result instruction is to establish an encrypted virtual network tunnel between the user / application end and the large model service providing end; Using a record audit log algorithm to authenticate and authorize the large model, returning the step of receiving a networking request to parse the networking request and obtain an identification ID until receiving an instruction to end the record.
2. The remote group-based networking based large model authentication and authorization method according to claim 1, characterized in that, The receiving a networking request to parse the networking request and obtain an identification ID comprises: Defining the data platform level of the system itself; Based on the data platform level of the system itself, establishing a data response log; Receiving a networking request; Including the data information of the networking request in a first receiving data storage area of the data response log; Using the data information of the first receiving data storage area of the data response log to obtain the information of the networking request.
3. The remote group-based networking based large model authentication and authorization method according to claim 2, characterized in that, The receiving a networking request to parse the networking request and obtain an identification ID further comprises: Calling the information of the networking request in the first receiving data storage area; Obtaining the ID classification characteristics of the information of the networking request in the first receiving data storage area; Calling the data platform level of the system itself; The data platform level is used to determine whether the level of the parsed information ID classification feature is consistent with the data platform level of the system itself. If the level of the parsed information ID classification feature is consistent with the data platform level of the system itself, the identification ID is obtained. If the level of the parsed information ID classification feature is not consistent with the data platform level of the system itself, the feedback of invalid information is fed into the network, and the invalid information is included in the second received data storage area of the data response log.
4. The remote group-based networking based large model authentication and authorization method according to claim 3, characterized in that, The identification ID is used to determine whether the type of the identification ID is a client, including: The identification ID and the classification feature of the identification ID are called. The identification ID is parsed to obtain a parsed result of the identification ID. The parsed result and the classification feature of the identification ID are used to obtain the level of the device that sends the networking request. It is determined whether the classification feature of the identification ID matches the level of the device that sends the networking request. If the classification feature of the identification ID matches the level of the device that sends the networking request, it is determined that the type of the identification ID is not a client. If the classification feature of the identification ID does not match the level of the device that sends the networking request, it is determined that the type of the identification ID is a client.
5. The remote group-based networking based large model authentication and authorization method according to claim 4, characterized in that, If the type of the identification ID is a client, a lightweight proxy program of the client is called, including: The identification ID is used to determine the data flow direction of the networking process. The identification ID and the data flow direction are used to form an information channel for reverse transmission of data information. The information channel is used to establish an information tunneling tunnel. Based on the identification ID, a connection request initiated by a remote networking node according to the lightweight proxy program of the client is verified. A feedback of the verification result is obtained. Based on the feedback of the verification result, the stability of the information tunneling tunnel called by the lightweight proxy program is determined.
6. The remote group-based networking based large model authentication and authorization method according to claim 5, characterized in that, If the type of the identification ID is not a client, it is determined that the type of the identification ID is a networking node, and the lightweight proxy program of the client is called by the networking node, including: The information tunneling tunnel is established by the networking node. The API calling instruction of each networking node is received by the information tunneling tunnel. The identity information of the API calling instruction sender is parsed. The identification ID to be verified after parsing the identity information is obtained. The identification ID to be verified and the identification ID are used to determine whether the identification ID to be verified matches the identification ID of the networking request. If the identification ID to be verified matches the identification ID of the networking request, it is determined that the lightweight proxy program calls the information tunneling tunnel stably. If the identification ID to be verified does not match the identification ID of the networking request, it is determined that the lightweight proxy program calls the information tunneling tunnel unstably.
7. The remote group-based model authentication and authorization method according to claim 6, wherein, The identity authentication information of the networking target is included in the authorization algorithm, including: The identity of the authorized networking device is bound with the virtual network identity. The virtual network identity is verified by the identity authentication module, and the connection state information of three key nodes in the virtual network is obtained. Based on the connection state information of the three key nodes, a virtual triangular area formed by the three key nodes is determined. The coverage area of the virtual triangular area is calculated, and the calculation of the triangular area is based on the relative position relationship of the three nodes. The authorization policy engine determines the distribution policy of the information tunneling tunnel according to the coverage area of the virtual triangular area, that is, the larger the coverage area, the higher the distribution density of the tunneling tunnel; The audit log module records the authentication and authorization events of each virtual network identity in the data response log, and the calculation result of the virtual triangular area coverage area and the corresponding relationship of the authorization policy are included in the audit range; The calculation results of the identity authentication module, the authorization policy engine and the audit log module are included in the authorization algorithm, and the dynamic authorization management of the network coverage area is realized.
8. The remote group-based model authentication and authorization method of claim 7, wherein, The large model authentication and authorization using the record audit log algorithm includes: Recording the record information of the gateway; Receiving the authorized request from the authentication and authorization center; Forwarding the request to the large model API; Storing the permission relationship of users, roles, devices and resources.
9. A large model authentication and authorization system based on remote networking, characterized in that, It includes: A server for executing the large model authentication and authorization method based on remote networking as claimed in any one of claims 1 to 8; A memory in communication connection with the server.
Citation Information
Patent Citations
Big data system security protection method, device and equipment based on zero-trust architecture
CN118300797A
Decentralized identity authentication method, system, device and medium
CN119939547A