Security verification method for large model service operation environment, medium, equipment and product
By deploying virtual machines and container groups of large-model services in a hardware trusted execution environment and generating security reports using remote proof services, the security issues of the machine learning platform are solved, and trustworthiness verification of virtual machines and container stacks is achieved, and user trust is enhanced.
Patent Information
- Application Number
- CN202510830571.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-19
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-06-19
AI Technical Summary
How to ensure the security of large-model services in machine learning platforms, especially while defending against attacks at the infrastructure-as-a-service level, and provide trustworthiness verification of virtual machines and container stacks to improve users' trust in service providers.
By deploying large-model services in virtual machines and container groups in a trusted hardware-based execution environment, remote proof services are used to obtain environment metrics and generate remote proof reports to verify the security of the runtime environment, including the trustworthiness of virtual machines and container stacks.
It effectively blocks attacks from the IaaS layer, provides full-dimensional security verification of virtual machines and container stacks, and improves users' trust in service providers.
Smart Images

Figure CN120354404A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technologies, and in particular, to a method, medium, device, and product for security verification of a large model service running environment. Background Art
[0002] In related technologies, a service provider can provide a machine learning platform for a user to deploy a large model service. Generally, the machine learning platform provides a PaaS (Platform as a Service) service, enabling the user to deploy the large model service through the PaaS service. In this scenario, the user has very high requirements for the security of the machine learning platform, and how to ensure the security of the machine learning platform is extremely important. Summary of the Invention
[0003] This Summary of the Invention section is provided to introduce concepts in a brief form, which will be described in detail in the following Detailed Implementation section. This Summary of the Invention section is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.
[0004] In a first aspect, the present disclosure provides a method for security verification of a large model service running environment, including: Obtaining, through a remote attestation service, an environment metric corresponding to a running environment for deploying a large model service; the large model service is deployed in a container group created in a virtual machine, the virtual machine is deployed in a hardware-based trusted execution environment, and the remote attestation service is deployed in the hardware-based trusted execution environment; the environment metric at least includes a first metric corresponding to the trusted execution environment where the virtual machine is located and a container metric in the container stack dimension corresponding to the container group; Generating, through the remote attestation service, a remote attestation report according to the environment metric, where the remote attestation report is used for a user to perform security verification on the running environment.
[0005] In a second aspect, the present disclosure provides a security verification device for a large model service running environment, including: An obtaining module configured to obtain, through a remote attestation service, an environment metric corresponding to a running environment for deploying a large model service; the large model service is deployed in a container group created in a virtual machine, the virtual machine is deployed in a hardware-based trusted execution environment, and the remote attestation service is deployed in the hardware-based trusted execution environment; the environment metric at least includes a first metric corresponding to the trusted execution environment where the virtual machine is located and a container metric in the container stack dimension corresponding to the container group; A generation module, configured to generate a remote attestation report according to the environmental metrics through the remote attestation service, where the remote attestation report is used for a user to perform security verification on the operating environment.
[0006] In a third aspect, the present disclosure provides a computer-readable medium, on which a computer program is stored, and when the computer program is executed by a processing device, the steps of the method described in the first aspect are implemented.
[0007] In a fourth aspect, the present disclosure provides an electronic device, including: A storage device, on which a computer program is stored; A processing device, configured to execute the computer program in the storage device to implement the steps of the method described in the first aspect.
[0008] In a fifth aspect, the present disclosure provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of the method described in the first aspect are implemented.
[0009] Based on the above technical solutions, by deploying the large model service in a container group created in a virtual machine, and the virtual machine is deployed in a hardware-based trusted execution environment, then obtaining environmental metrics corresponding to the operating environment of the large model service through a remote attestation service deployed in the hardware-based trusted execution environment, and the environmental metrics at least include a first metric corresponding to the trusted execution environment where the virtual machine is located and container metrics in the container stack dimension corresponding to the container group. Then, through the remote attestation service, a remote attestation report is generated according to the environmental metrics, so that the user can verify the security of the operating environment through the remote attestation report. Since the container group runs in a virtual machine fortified by a hardware-based trusted execution environment, attacks from the IaaS (Infrastructure as a Service) layer can be blocked. Moreover, through the first metric and the container metrics, credibility verification in the virtual machine dimension and credibility verification in the container stack dimension can be provided, thereby improving the user's trust in the services provided by the service provider.
[0010] Other features and advantages of the present disclosure will be described in detail in the subsequent specific implementation part. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] Combined with the drawings and referring to the following specific implementation manners, the above and other features, advantages and aspects of the embodiments of the present disclosure will become more obvious. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic, and the original components and elements are not necessarily drawn to scale. In the drawings: Figure 1 is a flowchart of a method for security verification of the operating environment of a large model service shown according to an exemplary embodiment.
[0012] Figure 2 It is a schematic diagram of a security verification system for a large model service running environment shown according to an exemplary embodiment.
[0013] Figure 3 It is a schematic structural diagram of a security verification device for a large model service running environment shown according to an exemplary embodiment.
[0014] Figure 4 It is a schematic structural diagram of an electronic device shown according to an exemplary embodiment. Detailed implementation manners
[0015] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Instead, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not used to limit the protection scope of the present disclosure.
[0016] It should be understood that the various steps recited in the method embodiments of the present disclosure can be executed in a different order and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this regard.
[0017] As used herein, the term "including" and its variations are open-ended, that is, "including but not limited to". The term "based on" is "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description.
[0018] It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order of the functions executed by these devices, modules or units or their interdependent relationships.
[0019] It should be noted that the modifications of "one" and "plural" mentioned in the present disclosure are illustrative rather than restrictive. Those skilled in the art should understand that, unless otherwise clearly specified in the context, it should be understood as "one or more".
[0020] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only for illustrative purposes and are not used to limit the scope of these messages or information.
[0021] Figure 1 is a flowchart of a security verification method for a large model service running environment shown according to an exemplary embodiment. As Figure 1 shown, an embodiment of the present disclosure provides a security verification method for a large model service running environment. This method can specifically be executed by a security verification device for a large model service running environment, and this device can be implemented in a software and / or hardware manner. As Figure 1 shown, this method can include the following steps.
[0022] In step 110, obtain an environmental metric corresponding to the running environment for deploying the large model service; the large model service is deployed in a container group created in a virtual machine, the virtual machine is deployed in a hardware-based trusted execution environment, and the remote attestation service is deployed in the hardware-based trusted execution environment; the environmental metric at least includes a first metric corresponding to the trusted execution environment where the virtual machine is located and a container metric in the container stack dimension corresponding to the container group.
[0023] Here, the large model service may refer to a large language model service. For example, the large model service may refer to a training task or an inference service of a large language model deployed by a user. The large model service is deployed in a container group (Pod) created in a virtual machine. For a machine learning platform, in fact, a user purchases corresponding IaaS resources (such as a file system, a network, an ECS (Elastic Compute Service, cloud server), etc.), and what the user can see during specific use is the created Pod.
[0024] In the embodiment of the present disclosure, the virtual machine for deploying the large model service is fortified through a hardware-based trusted execution environment (Trusted Execution Environment, TEE). Exemplarily, the hardware-based trusted execution environment may be a CPU (Central Processing Unit) TEE. The CPU TEE is an isolated area running on the CPU.
[0025] It should be understood that since the container group for deploying the large model service is created in a virtual machine fortified through a hardware-based trusted execution environment, the service provider cannot dump the memory of the virtual machine by means of a VMM (Virtual Machine Monitor, also known as a Hypervisor). Therefore, through the method provided by the embodiment of the present disclosure, attacks from the IaaS layer can be blocked to ensure the security of the running environment of the large model service.
[0026] A remote attestation service is a security mechanism for verifying the trustworthiness of a platform and the integrity of code. In the embodiments of the present disclosure, the remote attestation service is deployed in a hardware-based trusted execution environment. That is to say, the remote attestation service can be fortified through the hardware-based trusted execution environment to ensure the trustworthiness of the remote attestation service. Exemplarily, the hardware-based trusted execution environment for deploying the remote attestation service can be a CPU TEE.
[0027] Measurement refers to performing integrity verification and security inspection on each component of the running environment. In the embodiments of the present disclosure, the environment measurement is the value obtained by measuring the running environment for deploying the large model service. Exemplarily, the environment measurement can be presented in the form of a hash value or a digital signature, used to prove that the running environment has not been tampered with and is trustworthy. For example, hash calculations can be performed on software, configuration files, etc. in the running environment to generate corresponding hash values, which are used to verify whether the corresponding software and configuration files have been tampered with.
[0028] In the embodiments of the present disclosure, the environment measurement at least includes a first measurement corresponding to the trusted execution environment where the virtual machine is located and a container measurement in the container stack dimension corresponding to the container group.
[0029] Among them, the first measurement refers to the measurement value obtained by measuring the hardware-based trusted execution environment where the virtual machine is located. Exemplarily, the first measurement can include the measurement value for the Bootloader, the measurement value for the firmware, and the measurement value for the kernel.
[0030] It should be noted that the first measurement is actually performed in the dimension of the trusted execution environment where the virtual machine is located to verify the trustworthiness of the trusted execution environment.
[0031] The container measurement in the container stack dimension corresponding to the container group refers to the measurement value obtained by measuring in the container stack dimension. Exemplarily, the container measurement includes a second measurement corresponding to the components included in the container orchestration platform corresponding to the container group and a third measurement of the image related to the large model service.
[0032] Among them, the container orchestration platform corresponding to the container group can be k8s (Kubernetes, an open-source platform for managing containers). A Pod is the smallest deployable unit in Kubernetes. A Pod contains at least one application container, storage resources, a unique network address, and some options that determine how the container should run. The components included in the container orchestration platform can be kubelet (a component for managing containers and Pods on nodes), containerd (a container runtime for managing the lifecycle of containers), runc (a reference implementation for creating and running containers), and docker (an application container engine for developing, running, and deploying applications). Correspondingly, the second metric includes the metric values of kubelet, containerd, runc, and docker.
[0033] It should be noted that by performing trustworthiness measurement on the components included in the container orchestration platform, the trustworthiness of the components of the used container orchestration platform can be verified.
[0034] The image related to the large model service refers to the file related to the large model service. In a Pod, the image of the large model service provided by the user is instantiated into a container to package the image as a standardized unit for deployment. By measuring the image related to the large model service, it can be verified whether the large model service has been tampered with.
[0035] It should be noted that through the first metric and container metrics, trustworthiness measurement can be performed not only in the dimension of the trusted execution environment but also in the container stack dimension, greatly ensuring the trustworthiness of the running environment where the large model service is located.
[0036] Of course, in the case where the virtual machine is mounted with a trusted acceleration device, the environment measurement also includes the fourth metric corresponding to the trusted execution environment of the trusted acceleration device.
[0037] A trusted acceleration device is a hardware device used to accelerate computing tasks and provide a trusted execution environment. Exemplarily, the trusted acceleration device can be a GPU (Graphics Processing Unit) and / or MPU (Micro Processor Unit) with a trusted execution environment. Correspondingly, the fourth metric corresponding to the trusted execution environment of the trusted acceleration device can refer to the metric value of GPU TEE and / or the metric value of MPU TEE.
[0038] Therefore, the environment measurement provided by the embodiments of the present disclosure can include the first metric corresponding to the trusted execution environment where the virtual machine is located, container metrics in the container stack dimension, and the fourth metric of the trusted acceleration device.
[0039] It should be noted that the security verification method for the large model service running environment provided by the embodiments of the present disclosure can not only provide security verification at the virtual machine dimension, but also provide security verification at the trusted acceleration device dimension and provide security verification at the container stack dimension, so as to perform full-dimensional security verification on the running environment of the large model service in the scenario of the large model service.
[0040] In the embodiments of the present disclosure, the remote attestation service can actively pull the corresponding environment metrics from the device where the large model service is deployed. Of course, the device where the large model service is deployed can also actively send the corresponding environment metrics to the remote attestation service.
[0041] In step 120, through the remote attestation service, a remote attestation report is generated according to the environment metrics, and the remote attestation report is used for the user to perform security verification on the running environment.
[0042] Here, after the remote attestation service receives the environment metrics corresponding to the running environment for deploying the large model service, the remote attestation service generates a remote attestation report corresponding to the running environment according to the environment metrics. Among them, the remote attestation report may include the trusted state of the running environment (such as trusted or untrusted, whether the trusted execution environment is complete and not tampered), the value corresponding to the environment metrics, and the metric log for recording the detailed operations in the attestation process.
[0043] Through the remote attestation report provided by the remote attestation service, the user can verify the trustworthiness of the running environment of the large model service according to the information held by the user itself. For example, since the user holds its own image, through the remote attestation report provided by the remote attestation service, the user can check whether the deployed image has been tampered. For another example, the source code or the corresponding benchmark hash value of each component in the running environment can be provided in the remote attestation service, and the user can verify whether the running environment has been tampered by comparing the source code or the benchmark hash value. It should be noted that if the running environment is tampered, the corresponding environment metrics will inevitably change. Correspondingly, the environment metrics will be inconsistent with the benchmark hash value provided by the remote attestation service, indicating that the running environment has been tampered and is in an untrusted state.
[0044] It should be noted that the remote attestation service can generate a remote attestation report through chain authentication. Among them, chain authentication is through a series of encryption verification steps to ensure the trustworthiness of each component and link in the system. This mechanism starts from a trusted root and gradually verifies each component and module in the system to form a complete trust chain. In the embodiments of the present disclosure, first, the trustworthiness of the firmware and the bootloader is verified, then the trustworthiness of the kernel is verified, then the trustworthiness of the components included in the container orchestration platform is verified, and then the trustworthiness of the image of the large model service is verified, so as to form a trusted chain authentication.
[0045] Thus, by deploying the large model service in a container group created in a virtual machine, and deploying the virtual machine in a hardware-based trusted execution environment, then obtaining, through a remote attestation service deployed in the hardware-based trusted execution environment, the environmental metrics corresponding to the operating environment of the large model service, where the environmental metrics at least include a first metric corresponding to the trusted execution environment where the virtual machine is located and container metrics in the dimension of the container stack corresponding to the container group, and then generating, through the remote attestation service, a remote attestation report based on the environmental metrics, so that users can verify the security of the operating environment through the remote attestation report. Since the container group runs in a virtual machine fortified by a hardware-based trusted execution environment, attacks from the IaaS layer can be blocked. Moreover, through the first metric and the container metrics, it is possible to provide trustworthiness verification in the dimension of the virtual machine and provide trustworthiness verification in the dimension of the container stack, thereby enhancing the users' trust in the services provided by the service provider.
[0046] In some implementable embodiments, in step 110, in response to deploying the large model service in the container group, environmental metrics can be collected through an initialization container created in the container group, and then the environmental metrics can be uploaded to the remote attestation service through the initialization container.
[0047] Here, an initialization container is a special type of container used to run some initialization tasks before the application container starts. Deploying the large model service in the container group can be understood as starting the large model service in the container group. Starting the large model service in the container group can be understood as creating a container corresponding to the large model service in the container group according to the image related to the large model service. When deploying the large model service in the container group, the environmental metrics corresponding to the operating environment can be collected through the initialization container created in the container group. Then, the initialization container sends the collected environmental metrics to the remote attestation service.
[0048] It should be noted that after the large model service is deployed, the initialization container will be recycled, so the collected environmental metrics are static environmental metrics of the operating environment.
[0049] It should be noted that in the embodiments of the present disclosure, if the environmental metrics indicate that the operating environment has been tampered with, the startup of the large model service can be terminated.
[0050] Thus, through the above embodiments, when deploying the large model service, the environmental metrics of the operating environment can be collected to measure the security of the operating environment where the container group is located.
[0051] In some implementable embodiments, in step 110, in response to initializing a virtual machine, a second measurement and a first measurement corresponding to components may be sent to a remote attestation service. Correspondingly, in step 120, the remote attestation service may generate a first remote attestation report based on the second measurement and the first measurement, and then, through the remote attestation service, the first remote attestation report is used for a user to verify the trustworthiness of the virtual machine.
[0052] Here, for a detailed description of the first measurement and the second measurement, reference may be made to the relevant descriptions of the above embodiments, which will not be elaborated here. When initializing the virtual machine, the second measurement and the first measurement may be sent to the remote attestation service.
[0053] A user may purchase a corresponding virtual machine instance from a service provider. During the initialization of the IaaS service, operations for initializing the virtual machine instance and sending the first measurement to the remote attestation service are performed. During the initialization of the PaaS service, operations for joining the k8s cluster, installing k8s-related components on the virtual machine instance, and sending the second measurement to the remote attestation service are performed.
[0054] Of course, following the above embodiments, if the virtual machine instance is mounted with a trusted acceleration device, during the initialization of the IaaS service, an operation of sending a fourth measurement corresponding to the trusted acceleration device to the remote attestation service may also be performed.
[0055] When the remote attestation service receives the second measurement and the first measurement, it generates a first remote attestation report based on the second measurement and the first measurement. It should be noted that when initializing the virtual machine, since the large model service has not been launched yet, the third measurement of the image related to the large model service is not included in the first remote attestation report. Since the first measurement and the second measurement are carried in the first remote attestation report, the first remote attestation report can be used for a user to verify the security of the virtual machine for deploying the large model service.
[0056] When a user specifies to deploy a large model service through a virtual machine, the user may request the remote attestation service to provide a first remote attestation report including the first measurement and the second measurement, and the user determines whether the virtual machine is suitable for deploying the large model service through the first remote attestation report.
[0057] Exemplarily, the remote attestation service may output the first remote attestation report in response to a query request sent by the user.
[0058] Thus, through the above embodiments, when initializing the virtual machine and before deploying the large model service, a first remote attestation report may be provided to the user, so that the user can verify the trustworthiness of the virtual machine through the first remote attestation report, and the user can determine whether to deploy the large model service in the virtual machine.
[0059] In some implementable embodiments, in step 110, in response to deploying a large model service in a container group, a first metric, a second metric, and a third metric may be sent to a remote attestation service. Correspondingly, in step 120, the remote attestation service may generate a second remote attestation report based on the first metric, the second metric, and the third metric, and the second remote attestation report is used for the user to verify the trustworthiness of the running environment.
[0060] Here, when deploying a large model service in a container group, a first metric, a second metric, and a third metric are sent to a remote attestation service. For a detailed description of the first metric, the second metric, and the third metric, reference may be made to the relevant descriptions of the above embodiments, which will not be elaborated here.
[0061] Continuing with the above method, the first metric, the second metric, and the third metric may be collected through an initialization container. Of course, continuing with the above embodiments, if a trusted acceleration device is mounted on a virtual machine instance, during the initialization of the IaaS service, an operation of sending a fourth metric corresponding to the trusted acceleration device to the remote attestation service may also be performed. That is to say, when deploying a large model service in a container group, the first metric, the second metric, the third metric, and the fourth metric may be collected through an initialization container, and the first metric, the second metric, the third metric, and the fourth metric may be sent to the remote attestation service through the initialization container to verify the trustworthiness of the entire running environment of the large model service.
[0062] Continuing with the above embodiments, when initializing a virtual machine, the trustworthiness of the virtual machine may be verified through a first remote attestation report generated based on the first metric and the second metric. When deploying a container corresponding to a large model service in a container group, the trustworthiness of the running environment where the container group is located will be measured again. The user may obtain a second remote attestation report from the remote attestation service, and then verify the trustworthiness of the running environment of the large model service through the second remote attestation report. When the running environment of the large model service changes, the deployment of the large model service may be terminated.
[0063] It should be noted that the second remote attestation report is actually equivalent to adding the trustworthiness verification of the third metric to the first remote attestation report. Through the second remote attestation report generated based on the first metric, the second metric, and the third metric, the user can not only verify the trustworthiness of the virtual machine when deploying a large model service, but also verify the trustworthiness of the container stack, greatly improving the user's trust in the machine learning platform. The remote attestation service may output the first remote attestation report and the second remote attestation report simultaneously, so that the user can verify whether the running environment of the virtual machine has changed after deploying the large model service according to the first remote attestation report and the second remote attestation report.
[0064] Thus, through the above-described embodiments, when deploying a large model service, a second remote attestation report including a first measurement in the dimension of the trusted execution environment, a second measurement, and a third measurement in the dimension of the container stack can be provided to the user, enabling the user to verify the trustworthiness of the virtual machine and the container stack through the second remote attestation report, and greatly improving the user's trust in the machine learning platform.
[0065] In some implementable embodiments, the virtual machine has an access interface for accessing the virtual machine. Correspondingly, in response to an access operation for the access interface, the access operation can also be recorded in the access control system.
[0066] Here, the access control system is a tool or service for recording access operations. Exemplarily, the access control system can be a security audit platform. The access control system is deployed in a hardware-based trusted execution environment. That is to say, the access control system can be fortified through the hardware-based trusted execution environment to ensure the trustworthiness of the access control system. Exemplarily, the hardware-based trusted execution environment can be a CPU TEE.
[0067] In the embodiments of the present disclosure, the access control system is used to display the recorded access operations to the user. Exemplarily, the access control system can, in response to a query request from the user, display the recorded access operations for the virtual machine to the user.
[0068] For the operation and maintenance personnel at the PaaS layer, through the access interface provided by the virtual machine, the operation and maintenance personnel can access the running environment of the user's Pod and maintain the running environment. In this process, all access operations through this access interface will be recorded in the access control system and finally the recorded access operations will be displayed to the user. Therefore, all access operations for the virtual machine are visible and transparent to the user.
[0069] It should be noted that the access operations for the virtual machine can be recorded in the access control system in the form of screen recording and / or logs.
[0070] Thus, by recording the access operations for the virtual machine in the access control system, all access operations can be recorded and transmitted to the user transparently to ensure the security of the running environment of the large model service.
[0071] In some implementable embodiments, the environment metrics can also be synchronized to the access control system through the remote attestation service, and the access control system is used to generate a running log of the running environment according to the environment metrics, and the running log is used for the user to perform security verification on the running environment.
[0072] Here, the remote attestation service can synchronize the environment metrics corresponding to the running environment to the access control system. Since the access control system runs in a hardware-based trusted execution environment, the trustworthiness of the access control system can be guaranteed. Therefore, the environment metrics stored in the access control system are also trustworthy.
[0073] It should be noted that by synchronizing the environment metrics corresponding to the running environment to the access control system, users can not only verify the security of the running environment through the remote attestation service, but also obtain the environment metrics from the access control system to verify the security of the running environment through the environment metrics.
[0074] After receiving the environment metrics, the access control system can generate a running log based on the environment metrics. Among them, the running log can include the environment metrics. Through the running log, users can verify the trustworthiness of the running environment of the large model service according to the information they hold. For example, users can verify whether the deployed image has been tampered with through the running log.
[0075] Thus, through the access control system, users can verify the trustworthiness of the running environment for deploying the large model service, thereby improving the user's trust in the machine learning platform provided by the service provider.
[0076] Figure 2 It is a schematic diagram of a security verification system for the running environment of a large model service shown according to an exemplary embodiment. As Figure 2As shown in the figure, the container group is deployed in a virtual machine that runs in the CPU TEE. That is to say, the bootloader, firmware, kernel, virtual machine, container group, kubelet, containerd, runc, etc. are all fortified through the CPU TEE. When deploying the target container corresponding to the large model service in the container group, the environment metrics corresponding to the running environment are collected through the init container created in the container group. Among them, the environment metrics include the first metric of the CPU TEE, the second metric corresponding to the components included in the container orchestration platform, the third metric of the large model service, and the fourth metric of the trusted acceleration device (which may include a graphics processor and / or other trusted acceleration devices). And the collected environment metrics are sent to the remote attestation service through the init container. The remote attestation service generates a remote attestation report based on the environment metrics. The user can obtain the corresponding remote attestation report from the remote attestation service by accessing the remote attestation service to perform security verification on the running environment of the large model service. Moreover, the remote attestation service can also synchronize the environment metrics to the access control system. The access control system can generate a running log based on the environment metrics. The user can perform security verification on the running environment of the large model service through the running log exposed by the access control system. Of course, the virtual machine has an access interface. When the operation and maintenance personnel at the PaaS layer access the virtual machine through the access interface, the access operation is recorded in the access control system. The user can view the access operations and / or the generated running logs recorded in the access control system by accessing the access control system to perform security verification on the running environment of the large model service.
[0077] In addition, since the container group runs in a virtual machine fortified by a hardware-based trusted execution environment, the operation and maintenance personnel at the IaaS layer cannot access the virtual machine without the password of the virtual machine, thus shielding attacks from the IaaS layer.
[0078] Figure 3 It is a schematic structural diagram of a security verification device for the running environment of a large model service shown according to an exemplary embodiment. As Figure 3 shown, the present disclosure embodiment provides a security verification device 300 for the running environment of a large model service. The security verification device 300 for the running environment of the large model service includes: An acquisition module 301, configured to obtain, through a remote attestation service, environment metrics corresponding to the running environment for deploying a large model service; the large model service is deployed in a container group created in a virtual machine, the virtual machine is deployed in a hardware-based trusted execution environment, and the remote attestation service is deployed in a hardware-based trusted execution environment; the environment metrics at least include the first metric corresponding to the trusted execution environment where the virtual machine is located and the container metrics in the container stack dimension corresponding to the container group. A generation module 302, configured to generate a remote attestation report according to the environmental metrics through the remote attestation service, where the remote attestation report is used for a user to perform security verification on the operating environment.
[0079] Optionally, the obtaining module 301 is specifically configured to: In response to deploying the large model service in the container group, collect the environmental metrics through an initialization container created in the container group; Upload the environmental metrics to the remote attestation service through the initialization container.
[0080] Optionally, the container metrics include second metrics corresponding to components included in the container orchestration platform for deploying the container group; The obtaining module 301 is specifically configured to: In response to initializing the virtual machine, send the second metrics corresponding to the components and the first metrics to the remote attestation service; The generation module 302 is specifically configured to: Generate a first remote attestation report through the remote attestation service according to the second metrics and the first metrics, where the first remote attestation report is used for a user to perform security verification on the virtual machine.
[0081] Optionally, the container metrics include second metrics corresponding to components included in the container orchestration platform for the container group and third metrics of an image related to the large model service; The obtaining module 301 is specifically configured to: In response to deploying the large model service in the container group, send the first metrics, the second metrics, and the third metrics to the remote attestation service; The generation module 302 is specifically configured to: Generate a second remote attestation report through the remote attestation service according to the first metrics, the second metrics, and the third metrics, where the second remote attestation report is used for a user to perform security verification on the operating environment.
[0082] Optionally, in response to the virtual machine being mounted with a trusted acceleration device, the environmental metrics further include fourth metrics corresponding to the trusted execution environment of the trusted acceleration device.
[0083] Optionally, the virtual machine has an access interface for accessing the virtual machine; the security verification device 300 for the large model service operating environment further includes: A recording module, configured to record the access operation in an access control system in response to an access operation for the access interface, where the access control system is deployed in a hardware-based trusted execution environment, and the access control system is used to display the recorded access operation to a user.
[0084] Optionally, the security verification device 300 for the large model service operating environment further includes: A synchronization module, configured to synchronize the environment metrics to the access control system through the remote attestation service, where the access control system is used to generate an operating log of the operating environment according to the environment metrics, and the operating log is used for the user to perform security verification on the operating environment.
[0085] Regarding the security verification device 300 for the large model service operating environment in the above embodiments, the method logics executed by each functional module have been described in detail in the part regarding the method, and will not be elaborated here.
[0086] Figure 4 is a schematic structural diagram of an electronic device shown according to an exemplary embodiment. Referring below to Figure 4 , which shows a schematic structural diagram of an electronic device (such as a terminal device or a server) 400 suitable for implementing the embodiments of the present disclosure. The terminal device in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Tablet Computers), PMPs (Portable Multimedia Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 4 The electronic device shown is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.
[0087] As Figure 4 shown, the electronic device 400 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 401, which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 402 or a program loaded from a storage device 408 into a random access memory (RAM) 403. In the RAM 403, various programs and data required for the operation of the electronic device 400 are also stored. The processing device 401, the ROM 402, and the RAM 403 are connected to each other through a bus 404. An input / output (I / O) interface 405 is also connected to the bus 404.
[0088] Typically, the following devices can be connected to the I / O interface 405: an input device 406 including, for example, a touch screen, a touch pad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 407 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 408 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 409. The communication device 409 can allow the electronic device 400 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 4 the electronic device 400 with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices can be implemented or had.
[0089] In particular, according to an embodiment of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, an embodiment of the present disclosure includes a computer program product that includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes program codes for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through the communication device 409, or installed from the storage device 408, or installed from the ROM 402. When the computer program is executed by the processing device 401, the above-mentioned functions defined in the methods of the embodiments of the present disclosure are executed.
[0090] It should be noted that the above-mentioned computer-readable medium in the present disclosure may be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, a computer-readable storage medium may be any tangible medium that contains or stores a program, and the program can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present disclosure, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which computer-readable program code is carried. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium, and the computer-readable signal medium can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on a computer-readable medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0091] In some embodiments, communication can be performed using any currently known or future-developed network protocol such as HTTP (HyperText Transfer Protocol), and can be interconnected with digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include local area networks ("LAN"), wide area networks ("WAN"), the Internet (e.g., the Internet), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.
[0092] The above-mentioned computer-readable medium may be included in the above-mentioned electronic device; or it may exist separately and not be assembled into the electronic device.
[0093] The above computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to: obtain, through a remote attestation service, an environmental metric corresponding to a running environment for deploying a large model service; the large model service is deployed in a container group created in a virtual machine, the virtual machine is deployed in a hardware-based trusted execution environment, and the remote attestation service is deployed in the hardware-based trusted execution environment; the environmental metric at least includes a first metric corresponding to the trusted execution environment where the virtual machine is located and a container metric in the container stack dimension corresponding to the container group; generate, through the remote attestation service, a remote attestation report according to the environmental metric, and the remote attestation report is used for a user to perform security verification on the running environment.
[0094] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages or combinations thereof. The programming languages include, but are not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0095] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that, in some alternative implementations, the functions marked in the blocks may occur in an order different from that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.
[0096] The modules involved in the embodiments of the present disclosure can be implemented in software or in hardware. In some cases, the names of the modules do not constitute a limitation on the modules themselves.
[0097] The functions described above herein can be performed, at least in part, by one or more hardware logic components. By way of example, and without limitation, the types of hardware logic components that may be used include: Field Programmable Gate Arrays (FPGA), Application Specific Integrated Circuits (ASIC), Application Specific Standard Products (ASSP), System on a Chip (SOC), Complex Programmable Logic Devices (CPLD), and the like.
[0098] In the context of the present disclosure, a machine-readable medium may be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a Random Access Memory (RAM), a Read-Only Memory (ROM), an Erasable Programmable Read-Only Memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0099] The above description is only a preferred embodiment of the present disclosure and an explanation of the technical principles applied. Those skilled in the art should understand that the scope of the disclosure involved in the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosure concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) having similar functions disclosed in the present disclosure.
[0100] In addition, although the operations are depicted in a particular order, this should not be construed as requiring that the operations be performed in the particular order shown or in sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of the present disclosure. Certain features described in the context of separate embodiments may also be implemented combinatorially in a single embodiment. Conversely, the various features described in the context of a single embodiment may also be implemented separately or in any suitable sub-combination in multiple embodiments.
[0101] Although the subject matter has been described in language specific to structural features and / or methodological logical acts, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. On the contrary, the specific features and acts described above are merely example forms of implementing the claims. Regarding the apparatus in the above embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments related to the method, and will not be elaborated here.
Claims
1. A security verification method for the operating environment of large model services, characterized in that, Including: Obtain the environmental metrics corresponding to the operating environment for deploying the large model service through a remote attestation service; the large model service is deployed in a container group created in a virtual machine, the virtual machine is deployed in a hardware-based trusted execution environment, and the remote attestation service is deployed in the hardware-based trusted execution environment; the environmental metrics at least include a first metric corresponding to the trusted execution environment where the virtual machine is located and a container metric in the dimension of the container stack corresponding to the container group; Generate a remote attestation report through the remote attestation service according to the environmental metrics, and the remote attestation report is used for the user to perform security verification on the operating environment.
2. The method according to claim 1, wherein The obtaining, through the remote attestation service, of the environmental metrics corresponding to the operating environment for deploying the large model service includes: In response to deploying the large model service in the container group, collect the environmental metrics through an initialization container created in the container group; Upload the environmental metrics to the remote attestation service through the initialization container.
3. The method according to claim 1, wherein The container metric includes a second metric corresponding to the components included in the container orchestration platform for deploying the container group; The obtaining, through the remote attestation service, of the environmental metrics corresponding to the operating environment for deploying the large model service includes: In response to initializing the virtual machine, send the second metric corresponding to the component and the first metric to the remote attestation service; The generating, through the remote attestation service, of a remote attestation report according to the environmental metrics includes: Generate a first remote attestation report through the remote attestation service according to the second metric and the first metric, and the first remote attestation report is used for the user to perform security verification on the virtual machine.
4. The method according to claim 1, characterized in that, The container metric includes a second metric corresponding to the components included in the container orchestration platform corresponding to the container group and a third metric of the image related to the large model service; The obtaining, through the remote attestation service, of the environmental metrics corresponding to the operating environment for deploying the large model service includes: In response to deploying the large model service in the container group, send the first metric, the second metric, and the third metric to the remote attestation service; The generating, through the remote attestation service, of a remote attestation report according to the environmental metrics includes: Generate a second remote attestation report through the remote attestation service according to the first metric, the second metric, and the third metric, and the second remote attestation report is used for the user to perform security verification on the operating environment.
5. The method according to any one of claims 1 to 4, characterized in that In response to the virtual machine being mounted with a trusted acceleration device, the environmental metrics further include a fourth metric corresponding to the trusted execution environment of the trusted acceleration device.
6. The method according to any one of claims 1 to 4, characterized in that, The virtual machine has an access interface for accessing the virtual machine; the method further includes: In response to an access operation for the access interface, record the access operation in an access control system, the access control system is deployed in a hardware-based trusted execution environment, and the access control system is used to display the recorded access operation to the user.
7. The method according to claim 6, characterized in that, The method further includes: Through the remote attestation service, synchronize the environment metrics to the access control system, which is used to generate an operation log of the operating environment according to the environment metrics, and the operation log is used for a user to perform security verification on the operating environment.
8. A security verification device for the operating environment of large model services, characterized in that, Comprising: An acquisition module, configured to obtain environment metrics corresponding to an operating environment for deploying a large model service through a remote attestation service; the large model service is deployed in a container group created in a virtual machine, the virtual machine is deployed in a hardware-based trusted execution environment, and the remote attestation service is deployed in a hardware-based trusted execution environment; the environment metrics at least include a first metric corresponding to the trusted execution environment where the virtual machine is located and container metrics in the container stack dimension corresponding to the container group; A generation module, configured to generate a remote attestation report according to the environment metrics through the remote attestation service, and the remote attestation report is used for a user to perform security verification on the operating environment.
9. A computer-readable medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processing device, the steps of the method according to any one of claims 1-7 are implemented.
10. An electronic device, characterized in that, Comprising: A storage device on which a computer program is stored; A processing device for executing the computer program in the storage device to implement the steps of the method according to any one of claims 1-7.
11. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, the steps of the method according to any one of claims 1-7 are implemented.
Citation Information
Patent Citations
Method and device for verifying credibility, electronic equipment and medium
CN117574384A
Zero-trust remote authentication service deployment system based on confidential virtual machine
CN118171257A
Edge processing method and device, equipment and storage medium
CN119520316A
Securing Pods in a Container Orchestration Environment
US20230068221A1
Cited By
Remote attestation method and device based on trusted execution environment, medium, equipment and product
CN120602215A
Remote attestation method and apparatus based on trusted execution environment, medium, device and product
CN120602215B
Model service verification method and model service system
CN120832681A
Model service verification method and model service system
CN120832681B
Credible verification method and device for model application deployed by public cloud, and program product
CN121278729A