An AI robot responsibility authentication method based on digital certificate

By combining digital certificates with security authentication technology, the problem of attributing responsibility for AI robots has been solved, ensuring the non-repudiation of data and behavior, and achieving clear attribution of responsibility and provision of legal basis.

CN120582884BActive Publication Date: 2025-11-21SHANXI DIGITAL CERTIFICATE AUTHENTICATION CENT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510867658.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-26
Publication Date
2025-11-21
Estimated Expiration
2045-06-26

AI Technical Summary

Technical Problem

Existing technologies make it difficult to determine liability for AI robots when they are used maliciously or out of control, and there is a lack of effective legal basis for holding them accountable.

Method used

By combining digital certificates with security authentication technologies, the authenticity of entity identities, data integrity, and non-repudiation of behaviors are ensured throughout the lifecycle of AI robots. A hierarchical traceability credential system is adopted to provide a legal basis for attribution of responsibility, including signature and verification processes for datasets, models, integration, and application participants.

Benefits of technology

This achieves a clear attribution of responsibility for AI robots, provides a legal basis, ensures the non-repudiation of data and behavior, and enhances security and traceability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120582884B_ABST
    Figure CN120582884B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of security authentication, in particular to an AI robot responsibility authentication method based on a digital certificate, which comprises a CA institution, an AI robot and related participants in the whole life cycle of the AI robot; according to different stages, the participants include data set participants, model participants, integration participants and application participants; the AI robot and the participants acquire digital certificates through the CA institution; the participants in each stage form traceable credentials by signing data of corresponding structures with the help of the digital certificates, and bear corresponding responsibilities. The application combines the digital certificate with the security authentication technology, adds hierarchical traceable credentials in the whole life cycle of the AI robot, performs AI robot responsibility authentication through the hierarchical traceable credentials, ensures the authenticity of the entity identity related to the AI robot, the integrity of the data and the non-repudiation of the behavior, and provides a legal basis for the AI robot related responsibility attribution problem.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to the technical field of security authentication, and in particular to an AI robot responsibility authentication method based on a digital certificate. BACKGROUND

[0002] AI robots can learn rules from massive data through artificial intelligence technology, realize autonomous learning and decision-making, break through the technical limitations of traditional robots, and realize the leap from a tool executing preset instructions to an intelligent agent learning through data. With the progress of natural language processing and computer vision technology and the development of high-precision components and the Internet of Things, AI robots can analyze environmental information based on data, formulate action plans, and control execution modules to complete specific tasks.

[0003] AI robots, with the ability of autonomous learning, autonomous decision-making and adaptation to complex environments, provide services in practical applications while also posing risks of malicious use and loss of control. For example, malicious data, training bias or deep forgery can lead to AI robot decision-making errors, and may even pose a direct threat to human safety. When an AI robot causes an accident, it is difficult for existing technologies to determine exactly which specific link has failed or made a mistake. Therefore, it is difficult to determine the subject that bears responsibility for AI robot applications. SUMMARY

[0004] To solve the above problems, the application provides an AI robot responsibility authentication method based on a digital certificate, which combines digital certificates with security authentication technology to ensure the authenticity of the identity of entities related to AI robots, the integrity of data and the non-repudiation of behavior, and provides legal basis for AI robot-related responsibility attribution problems through hierarchical traceability credentials.

[0005] To achieve the above purpose, the technical solution of the application is as follows: an AI robot responsibility authentication method based on a digital certificate, comprising a CA agency, an AI robot and participants thereof, the participants involving the entire life cycle of the AI robot, and the participants including a dataset participant, a model participant, an integration participant and an application participant, the AI robot and the participants thereof obtaining digital certificates from the CA agency, the AI robot and the participants thereof signing respective corresponding information through the digital certificates and assuming corresponding responsibilities, comprising the following steps:

[0006] S1, the dataset participant generates and shares robot dataset, applies for a digital certificate from the CA agency, signs robot dataset information containing a DatasetMetadata metadata structure and is responsible for the signing;

[0007] S2, the model participant verifies the signature of the robot dataset provided by the dataset participant, trains and deploys the AI model using the robot dataset, applies for a digital certificate from the CA institution, signs the AI model information containing the ModelMetadata metadata structure generated, and is responsible for;

[0008] S3, the integration participant verifies the signature of the AI model information provided by the model participant, integrates the traditional robot and the AI model to form an AI robot, applies for a digital certificate from the CA institution, signs the AIRobotInfo information of the AI robot, applies for a device certificate for the AI robot, and is responsible for;

[0009] S4, the application participant verifies the validity of the AI robot device certificate, applies for a digital certificate from the CA institution, signs the data generated in the process of managing or using the AI robot, and is responsible for.

[0010] As a further scheme of the application: in step S1, the robot dataset is derived from actual operation of the physical world, including sensor data, motion trajectory and environmental interaction, and the generation of the robot dataset includes the following steps:

[0011] S11, analyze the skills required by the robot according to the scene and determine the corresponding task;

[0012] S12, split the task into multiple subtasks;

[0013] S13, decompose each subtask into multiple continuous time steps;

[0014] S14, record the observation, action, reward and other related data related to each step to form trajectory data;

[0015] S15, standardize the generated trajectory data according to a common format;

[0016] S16, store any metadata related to the dataset in the standardized format to generate a robot dataset; the metadata related to the dataset includes dataset description information, specifically dataset name, version information, use scenario, robot type, license, data collector, task code, number of trajectories, and dataset generation time;

[0017] S17, apply for a digital certificate;

[0018] S18, sign the robot dataset;

[0019] S19, share the robot dataset.

[0020] As a further further scheme of the present application: the signature of the data set participant on the robot data set information and the verification of the signature of the model participant on the robot data set information include the following steps:

[0021] a11, the data set participant adds metadata in the data set;

[0022] a12, the data set is processed by slicing;

[0023] a13, the digest value is calculated for each slice respectively;

[0024] a14, the data set participant signs the slice digest value using a private key;

[0025] a15, share the robot data set and the signature;

[0026] a16, the model participant downloads the data set and the signature when using the data set;

[0027] a17, extract the data set metadata;

[0028] a18, parse the data set signature;

[0029] a19, verify the validity of the data set participant certificate, if valid, verify the slice signature using the data set participant public key, if the verification is passed, use the data set; if invalid or verification fails, the model participant assumes the risk of using the data set;

[0030] Wherein, since the data volume of the robot data set is usually large, the robot data set can be divided into several sub data sets, the data set is processed by slicing, the data set is split into multiple slices, and independent signature is generated for each slice, which is convenient for incremental updating and verification.

[0031] As a further further scheme of the present application: in step S2, the model participant trains the AI model using the robot data set as follows:

[0032] S21, select robot data set to obtain data;

[0033] S22, verify the signature of the robot data set information, if the verification is passed, use the data set, if the verification is not passed, the model participant assumes the risk of using the data set;

[0034] S23, pre-process the obtained robot data set, the pre-processing includes dividing training set, validation set and test set, cleaning, word segmentation, embedding, padding, normalization, feature extraction and enhancement of data;

[0035] S24, select a model architecture suitable for the robot task and configure the model parameters for model training;

[0036] S25, model optimization by fine-tuning to adapt to specific needs;

[0037] S26, selecting a suitable deployment platform according to actual needs to deploy the trained model and generating an AI model;

[0038] S27, applying for a digital certificate;

[0039] S28, signing the AI model information;

[0040] The metadata related to the AI model includes model name, record number, version number, parameter size, software framework, hardware configuration, data-related parameters, model architecture parameters, training strategy parameters, and evaluation optimization parameters; the data-related parameters include dataset name, dataset size, training set proportion, data cleaning filter, preprocessing method, and expansion part; the model architecture parameters include basic architecture, model layer number and hidden layer dimension, activation function, normalization method, attention head number and dimension of each head, and expansion part; the training strategy parameters include optimizer, learning rate, training round number, batch size, evaluation interval, and expansion part.

[0041] As a further scheme of the present application: the model participant signs and integrates the AI model information, and the integrator verifies the AI model includes the following steps:

[0042] a21, filing the AI model, which needs to submit a filing application to the local provincial information office, and after preliminary examination, it is reviewed by the national information office and publicized;

[0043] a22, editing the AI model metadata file;

[0044] a23, calculating the digest value of the metadata file;

[0045] a24, the model participant signs the file digest value using a private key;

[0046] a25, providing the metadata file and signature;

[0047] a26, the integrator obtains the metadata file and signature;

[0048] a27, verifying the AI model record number, if the AI model record number is accurate, verifying the model participant certificate validity, if valid, the integrator uses the model participant's public key to verify the file signature, if the verification is passed, the AI model can be used, if the AI model record number is not accurate, the certificate is invalid or the verification is not passed, the integrator assumes the risk of using the AI model.

[0049] As a further scheme of the present application: when the AI robot causes certain consequences in practical application and needs to be held accountable, the model participant can be required to allow the AI model source code to be viewed and check whether the corresponding parameter settings in the source code are consistent with those described in the signed metadata file, if not, the model participant shall bear the corresponding responsibility; if completely consistent, the accuracy rate test is carried out using the test set, if the accuracy rate is low, the model participant needs to bear certain responsibility, if the accuracy rate is high, it can be attributed to the defects of AI technology itself, and the responsibility of the model participant is reduced or exempted.

[0050] As a further scheme of the present application: in step S3, the step of integrating the AI robot by the integration participant is as follows:

[0051] S31, demand analysis is carried out according to the actual application scene;

[0052] S32, overall system architecture design is carried out;

[0053] S33, hardware selection and construction are carried out according to the comprehensive demand and cost;

[0054] S34, software environment configuration is carried out;

[0055] S35, the AI model information used is verified, if the verification passes, the AI model is integrated and optimized;

[0056] S36, the software and hardware system is debugged and tested, and the AI robot is generated;

[0057] S37, digital certificate is applied for;

[0058] S38, the AI robot information is signed, and the equipment certificate of the AI robot is applied for;

[0059] S39, the product and service of the AI robot are provided;

[0060] Among them, the integration participant allocates a unique code for each AI robot, and when the integration participant applies for the equipment certificate of the AI robot, needs to submit information related to the identity of the AI robot to the CA organization, the AI robot information is composed of basic information, hardware information, software information, model information and communication mode.

[0061] As a further scheme of the present application: the steps of signing and verifying the AI robot information are as follows:

[0062] a31, digital certificate of the integration participant is applied for;

[0063] a32, the integration participant edits the AI robot information file;

[0064] a33, calculating a digest value for the AI robot information file;

[0065] a34, signing the digest value of the AI robot information by the integrated participant using a private key;

[0066] a35, submitting the AI robot information file and the signature;

[0067] a36, the CA institution obtaining the AI robot information file and the signature;

[0068] a37, extracting the integrated participant certificate and the AI robot unique code;

[0069] a38, verifying the validity of the integrated participant certificate, if valid, verifying the signature of the information file using the integrated participant public key, if the verification is passed, issuing the AI robot device certificate, if invalid or the verification is not passed, not issuing the AI robot device certificate;

[0070] The AI robot unique code can be formed into a list in batches, which facilitates the integrated participant to apply for a device certificate for the batch-produced AI robot, and the AI robot information signature can be placed in the extension field of the AI robot device certificate, if the same batch of AI robots has a large proportion of information inconsistency or failure, it is determined that the integrator should bear the corresponding responsibility, if only a few of the same batch of AI robots have failures, the AI robot information in the extension field can be compared with the actual robot, if the information is completely consistent, the integrator bears the responsibility, if the information is inconsistent, it means that the AI robot has been changed by its manager or user, and the responsibility needs to be determined according to the actual use.

[0071] As a further scheme of the present application, the application participant using the AI robot comprises the following steps:

[0072] S41, verifying whether the device certificate of the AI robot is valid, and verifying whether the actual information of the AI robot is consistent with the stored information in the extension field of the device certificate, if valid and consistent, continuing to select and purchase, if invalid or inconsistent, giving up the selection and purchase;

[0073] S42, the application participant applying for a digital certificate;

[0074] S43, managing the AI robot;

[0075] S44, using the AI robot;

[0076] S45, generating the use data of the AI robot;

[0077] S46, the application participant signing the use data and deciding whether to share the use data;

[0078] The use data can be shared for use by a data set participant, and the data set participant needs to sign the use data when using, if the signature is passed, the use data can be standardized and subsequent processed, if the signature is not passed, the data set participant still uses the data, and the data set participant bears the risk caused by generating and sharing the data set.

[0079] As a further scheme of the application, the CA institution issues a digital certificate as follows:

[0080] S51, the CA institution accepts the application of the AI robot and the digital certificate of the entity related to different participants;

[0081] S52, judging the application type, if the applicant is a person, verifying the identity information, if the identity information is correct, issuing a personal certificate, if the applicant is an organization, verifying whether the organization information is legal, if legal, issuing an organization certificate, if the applicant is a device, signing the AI robot information, if the signature is passed, issuing a device certificate;

[0082] S53, managing the life cycle of the digital certificate.

[0083] Compared with the prior art, the application has the beneficial effects that:

[0084] The application combines the digital certificate with the security authentication technology, adds a hierarchical traceable certificate in the whole life cycle of the AI robot, ensures the authenticity of the entity identity related to the AI robot, the integrity of the data and the non-repudiation of the behavior, and provides a legal basis for the AI robot related responsibility attribution problem. BRIEF DESCRIPTION OF DRAWINGS

[0085] Fig. 1 It is a whole flowchart of the AI robot responsibility authentication method based on the digital certificate of the application;

[0086] Fig. 2 It is a signature and signature verification flowchart of the data set participant of the AI robot responsibility authentication method based on the digital certificate of the application;

[0087] Fig. 3 It is a signature and signature verification flowchart of the model participant of the AI robot responsibility authentication method based on the digital certificate of the application;

[0088] Fig. 4 It is a signature and signature verification flowchart of the integrated participant of the AI robot responsibility authentication method based on the digital certificate of the application. DETAILED DESCRIPTION

[0089] With reference to the drawings of the embodiments of the present application, the technical solutions in the embodiments of the present application will be described clearly and completely. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the protection scope of the present application.

[0090] Embodiment 1

[0091] Reference Figs. 1 to 4 A digital certificate-based AI robot responsibility certification method, including a CA agency, an AI robot and participants thereof, the participants involve the whole life cycle of the AI robot, and the participants include dataset participants, model participants, integration participants and application participants, the AI robot and the participants thereof obtain digital certificates through the CA agency, the AI robot and the participants thereof sign respective corresponding information through the digital certificates and bear corresponding responsibilities, including the following steps:

[0092] S1, the dataset participants generate and share robot dataset, and apply for a digital certificate from the CA agency, sign the robot dataset information containing the DatasetMetadata metadata structure and take responsibility;

[0093] S2, the model participants verify the signature of the robot dataset provided by the dataset participants, train and deploy AI models using the robot dataset, and apply for a digital certificate from the CA agency, sign the AI model information containing the ModelMetadata metadata structure generated by the model participants and take responsibility;

[0094] S3, the integration participants verify the signature of the AI model information provided by the model participants, integrate the traditional robot and the AI model to form an AI robot, and apply for a digital certificate from the CA agency, sign the AIRobotInfo information of the AI robot, apply for a device certificate for the AI robot and take responsibility;

[0095] S4, the application participants verify the validity of the AI robot device certificate, apply for a digital certificate from the CA agency, sign the data generated in the process of managing or using the AI robot and take responsibility.

[0096] In step S1, the robot dataset is derived from actual operation of the physical world, including sensor data, motion trajectory and environmental interaction, and the generation of the robot dataset includes the following steps:

[0097] S11, analyze the skills required by the robot according to the scene and determine the corresponding task;

[0098] S12, split the task into multiple subtasks;

[0099] S13, decompose each subtask into a plurality of continuous time steps;

[0100] S14, record observations, actions, rewards and other related data associated with each step to form trajectory data;

[0101] S15, standardize the generated trajectory data in a common format;

[0102] S16, store any metadata associated with the dataset in the standardized format to generate a robot dataset; the metadata associated with the dataset includes dataset description information, specifically dataset name, version information, use scenario, robot type, license, data collector, task code, number of trajectories, and dataset generation time;

[0103] S17, apply for a digital certificate;

[0104] S18, sign the robot dataset;

[0105] S19, share the robot dataset.

[0106] The signature of the robot dataset information by the dataset participant and the verification of the signature of the robot dataset information by the model participant include the following steps:

[0107] a11, the dataset participant adds metadata to the dataset;

[0108] a12, the dataset is processed by slicing;

[0109] a13, the digest value is calculated for each slice respectively;

[0110] a14, the dataset participant signs the slice digest value using a private key;

[0111] a15, share the robot dataset and the signature;

[0112] a16, the model participant downloads the dataset and the signature when using the dataset;

[0113] a17, extract the dataset metadata;

[0114] a18, parse the dataset signature;

[0115] a19, verify the validity of the dataset participant certificate, if valid, verify the slice signature using the dataset participant public key, if the verification is passed, use the dataset; if invalid or the verification is not passed, the model participant assumes the risk of using the dataset;

[0116] Wherein, since the data volume of the robot dataset is usually large, the robot dataset can be divided into several sub-datasets, and the dataset is processed in a sharding manner, the dataset is split into multiple shards, and an independent signature is generated for each shard, facilitating incremental updating and verification.

[0117] In step S2, the model participant trains the AI model using the robot dataset as follows:

[0118] S21, select robot dataset to obtain data;

[0119] S22, sign the robot dataset information, if the signature is passed, use the dataset, if the signature is not passed, the model participant assumes the risk of using the dataset;

[0120] S23, pre-process the obtained robot dataset, including dividing the training set, validation set and test set, cleaning, tokenizing, embedding, padding, normalizing, feature extraction and enhancing the data;

[0121] S24, select a model architecture suitable for the robot task and configure the model parameters for model training;

[0122] S25, optimize the model through fine-tuning to adapt to specific needs;

[0123] S26, select a suitable deployment platform according to actual needs to deploy the trained model and generate an AI model;

[0124] S27, apply for a digital certificate;

[0125] S28, sign the AI model information;

[0126] Wherein, the metadata related to the AI model includes model name, record number, version number, parameter size, software framework, hardware configuration, data-related parameters, model architecture parameters, training strategy parameters and evaluation optimization parameters; data-related parameters include dataset name, dataset size, training set proportion, data cleaning filter, preprocessing method, expansion part; model architecture parameters include basic architecture, model layer number and hidden layer dimension, activation function, normalization method, attention head number and dimension of each head, expansion part; training strategy parameters include optimizer, learning rate, training rounds, batch size, evaluation interval, expansion part.

[0127] The model participant signs the AI model information and the integrator verifies the AI model, including the following steps:

[0128] a21, record the AI model, the AI model needs to submit a record application to the local provincial information office, and after preliminary examination, it is reviewed by the national information office and publicized;

[0129] a22, edit the AI model metadata file;

[0130] a23, calculate the digest value of the metadata file;

[0131] a24, the model participant signs the file digest value using a private key;

[0132] a25, provide the metadata file and signature;

[0133] a26, the integration participant obtains the metadata file and signature;

[0134] a27, verify the AI model registration number, if the AI model registration number is accurate, verify the validity of the model participant certificate, if valid, the integration participant uses the public key of the model participant to verify the signature of the file, if the verification is passed, the AI model can be used, if the AI model registration number is not accurate, the certificate is invalid or the verification is not passed, the integration participant assumes the risk of using the AI model.

[0135] When the AI robot causes certain consequences in actual application and needs to be held accountable, the model participant can be required to allow the source code of the AI model to be viewed and checked whether the corresponding parameter settings in the source code are consistent with those described in the signed metadata file. If not, the model participant shall bear the corresponding responsibility; if they are completely consistent, the accuracy rate test is performed using the test set, if the accuracy rate is low, the model participant shall bear certain responsibility, if the accuracy rate is high, it can be attributed to the defects of AI technology itself, and the responsibility of the model participant is reduced or exempted.

[0136] In step S3, the integration participant integrates the AI robot as follows:

[0137] S31, analyze the requirements according to the actual application scenario;

[0138] S32, overall system architecture design;

[0139] S33, select and build hardware based on comprehensive requirements and costs;

[0140] S34, software environment configuration;

[0141] S35, verify the AI model information used, if the verification is passed, integrate and optimize the AI model;

[0142] S36, system integration and testing of software and hardware, generate AI robot;

[0143] S37, apply for digital certificate;

[0144] S38, sign the AI robot information and apply for equipment certificate for the AI robot;

[0145] S39, providing products and services of the AI robot;

[0146] The integrated participant allocates a unique code for each AI robot, and when applying for a device certificate for the AI robot, the integrated participant needs to submit information related to the identity of the AI robot to the CA agency. The AI robot information consists of basic information, hardware information, software information, model information, and communication methods.

[0147] The steps of signing and verifying the AI robot information are as follows:

[0148] a31, applying for an integrated participant digital certificate;

[0149] a32, the integrated participant edits the AI robot information file;

[0150] a33, calculating the digest value of the AI robot information file;

[0151] a34, the integrated participant signs the digest value of the AI robot information using a private key;

[0152] a35, submitting the AI robot information file and the signature;

[0153] a36, the CA agency obtains the AI robot information file and the signature;

[0154] a37, extracting the integrated participant certificate and the AI robot unique code;

[0155] a38, verifying the validity of the integrated participant certificate, if valid, using the integrated participant public key to verify the signature of the information file, if the verification is passed, issuing an AI robot device certificate; if invalid or the verification is not passed, not issuing an AI robot device certificate;

[0156] The AI robot unique code can be formed into a list in batches, which is convenient for the integrated participant to apply for a device certificate for the AI robot produced in batches. The AI robot information signature can be placed in the extension field of the AI robot device certificate. If the same batch of AI robots has a large proportion of information inconsistency or failure, it is determined that the integrator should bear the corresponding responsibility; if only a few AI robots in the same batch fail, the AI robot information in the extension field can be compared with the actual robot, if the information is completely consistent, the integrator bears the responsibility; if the information is inconsistent, it means that the AI robot has been modified by its manager or user, and the responsibility needs to be determined according to the actual use.

[0157] The application participant uses the AI robot, including the following steps:

[0158] S41, first verify whether the device certificate of the AI robot is valid, and verify whether the actual information of the AI robot is consistent with the stored information in the extension domain of the device certificate, if valid and consistent, continue to select and purchase, if invalid or inconsistent, give up selecting and purchasing;

[0159] S42, apply for a digital certificate by the participant;

[0160] S43, manage the AI robot;

[0161] S44, use the AI robot;

[0162] S45, generate the use data of the AI robot;

[0163] S46, the participant signs the use data and decides whether to share the use data;

[0164] The use data can be shared to the dataset participant for use, and the dataset participant needs to sign the use data when using, if the signature is passed, the use data can be standardized and processed subsequently, if the signature is not passed, the dataset participant bears the risk brought by generating and sharing the dataset.

[0165] The steps of issuing a digital certificate by the CA agency are as follows:

[0166] S51, the CA agency accepts the application of the digital certificate of the AI robot and the related entity of the participant in different stages;

[0167] S52, judge the application type, if the applicant is an individual, verify the identity information, if the identity information is correct, issue a personal certificate, if the applicant is an organization, verify whether the organization information is legal, if legal, issue an organization certificate, if the applicant is a device, sign the AI robot information, if the signature is passed, issue a device certificate;

[0168] S53, manage the life cycle of the digital certificate.

[0169] Embodiment 2

[0170] On the basis of embodiment 1, the robot dataset metadata in step S1 is described by using ASN.1 as follows:

[0171] DatasetMetadata ::= SEQUENCE {

[0172] datasetName UTF8String, -- dataset name

[0173] version UTF8String, -- version number

[0174] usageScenario UTF8String, -- usageScenario

[0175] robotType UTF8String, -- robotType

[0176] license UTF8String, -- license

[0177] dataCollector Certificate, -- dataCollector

[0178] taskId UTF8String, -- taskId

[0179] trajectoryCount INTEGER, -- trajectoryCount

[0180] generationTime GeneralizedTime, -- generationTime

[0181] extensions SEQUENCE OF Extension OPTIONAL -- extensions

[0182] }

[0183] Extension ::= SEQUENCE {

[0184] key UTF8String,

[0185] value OCTET STRING

[0186] }

[0187] The data quality of the robot dataset is a core influencing factor of the AI model training effect. If malicious data is added in the dataset, it may cause serious consequences. Therefore, the shared dataset needs the dataset participant to sign the dataset information and bear the corresponding responsibility. The signing and verification of the robot dataset aims to ensure the integrity of the data and the authenticity of the source, and prevent unauthorized tampering or forgery.

[0188] The AI model related metadata in step S2 is described using the structure of ASN.1 as follows:

[0189] ModelMetadata ::= SEQUENCE {

[0190] modelName UTF8String, -- modelName

[0191] recordNumber UTF8String, -- Record Number

[0192] version UTF8String, -- Version Number

[0193] parameterScale INTEGER, -- Parameter Scale (unit: billion level)

[0194] softwareFramework UTF8String, -- Software Framework

[0195] hardwareConfig HardwareConfiguration, -- Hardware Configuration

[0196] dataParameters DataParameters, -- Data Related Parameters

[0197] modelArchParams ModelArchitectureParams, -- Model Architecture Parameters

[0198] trainingStrategy TrainingStrategyParams -- Training Strategy Parameters

[0199] extensions SEQUENCE OF Extension OPTIONAL -- Extension Field

[0200] }

[0201] HardwareConfiguration ::= SEQUENCE {

[0202] gpuType UTF8String, -- GPU Model

[0203] gpuCount INTEGER, -- GPU Quantity

[0204] memoryPerGPU INTEGER, -- Memory per GPU (unit: GB)

[0205] interconnectType UTF8String -- Interconnection Method

[0206] }

[0207] DataParameters ::= SEQUENCE {

[0208] datasetName UTF8String, -- Dataset Name

[0209] datasetSize INTEGER, -- Dataset size (unit: number of samples)

[0210] trainValSplit INTEGER, -- Training set percentage (e.g., 80 means 80%)

[0211] dataFilters SEQUENCE OF UTF8String, -- List of data cleaning filters

[0212] preprocessing SEQUENCE OF UTF8String, -- List of preprocessing methods

[0213] Extensions Sequence of Extension Optimal -- Extended Fields

[0214] }

[0215] ModelArchitectureParams ::= SEQUENCE {

[0216] baseArchitecture UTF8String, -- Basic Model Architecture

[0217] numLayers INTEGER, -- Number of model layers

[0218] hiddenDim INTEGER, -- Hidden layer dimension

[0219] activation UTF8String, -- activation function

[0220] normalization UTF8String, -- normalization method

[0221] attentionHeads INTEGER, -- Number of attention heads

[0222] headDim INTEGER, -- Dimensions of each head

[0223] Extensions Sequence of Extension Optimal -- Extended Fields

[0224] }

[0225] TrainingStrategyParams ::= SEQUENCE {

[0226] optimizer UTF8String, -- optimizer type

[0227] learningRate REAL, -- learning rate (e.g., 3e-5)

[0228] epochs INTEGER, -- Number of training epochs

[0229] batchSize INTEGER, -- Batch size

[0230] evalInterval INTEGER, -- Evaluation interval (in epochs)

[0231] Extensions Sequence of Extension Optimal -- Extended Fields

[0232] }

[0233] According to current Chinese policy, large models need to submit a filing application to the provincial-level Cyberspace Administration of my country. After preliminary review, the National Cyberspace Administration of China will conduct a second review and make the application public. If only the hyperparameters (such as learning rate and batch size) or non-core layers are fine-tuned without changing the overall architecture or core logic of the model, it usually does not need to be re-filed, but it must be recorded in the annual report. If the parameter update involves a major modification to the model architecture, such as the number of neural network layers or the adjustment of key parameters that leads to a significant change in output results and behavior patterns, it may be considered a major change and requires re-filing. Therefore, model participants must sign the large model data metadata file so that model users can verify the signature.

[0234] In step S3, the structure of the AI ​​robot information described using ASN.1 is as follows:

[0235] AIRobotInfo ::= SEQUENCE {

[0236] baseInfo, -- Basic Information

[0237] hardwareInfo -- Hardware Information

[0238] softwareInfo -- Software Information

[0239] modelInfo, -- Model Information

[0240] commProtocols CommunicationInfo, -- CommunicationInfo

[0241] extensions SEQUENCE OF Extension OPTIONAL-- Extension field

[0242] }

[0243] BaseInfo ::= SEQUENCE {

[0244] manufacturer UTF8String, -- Integrator

[0245] modelNumbers UTF8String, -- AI robot model number

[0246] uniqueId SEQUENCE OF UTF8String, -- AI robot unique code list

[0247] productionDate GeneralizedTime -- Production date

[0248] }

[0249] HardwareInfo ::= SEQUENCE {

[0250] sensors SEQUENCE OF UTF8String, -- Sensor list

[0251] actuators SEQUENCE OF UTF8String, -- Actuator list

[0252] controlUnit ControlChip, -- Control chip

[0253] degreesOfFreedom INTEGER -- Degrees of freedom

[0254] }

[0255] ControlChip ::= SEQUENCE {

[0256] vendor UTF8String, -- Chip vendor

[0257] chipModel UTF8String -- Chip model

[0258] }

[0259] SoftwareInfo ::= SEQUENCE {

[0260] operatingSystem UTF8String, -- Operating System

[0261] middleware SEQUENCE OF UTF8String, -- Middleware list

[0262] applications SEQUENCE OF UTF8String, -- List of application software

[0263] }

[0264] ModelInfo ::= SEQUENCE {

[0265] modelName UTF8String, -- Model Name

[0266] registrationId UTF8String, -- Model registration number

[0267] deployment DeploymentMode, -- Model deployment mode

[0268] }

[0269] DeploymentMode ::= ENUMERATED { -- Deployment mode enumeration

[0270] cloud (0), -- Cloud deployment

[0271] edge (1), -- edge deployment

[0272] hybrid (2) -- hybrid deployment

[0273] }

[0274] CommunicationInfo ::= SEQUENCE {

[0275] protocols SEQUENCE OF UTF8String, -- Communication protocols

[0276] interfaces SEQUENCE OF UTF8String, -- Physical interface

[0277] }

[0278] In the practical application of AI robots, digital certificates can provide identity authentication, data encryption, integrity protection, and other security guarantees for AI robots. In the Internet of Things, AI robots act as device nodes and need to establish a trusted identity through digital certificates to ensure secure communication between devices. For example, collaborative robots in smart manufacturing need to verify each other's certificates to prevent malicious devices from accessing the production network. Data is encrypted using public keys to protect the confidentiality of communication between AI robots and users or systems. For example, medical AI systems encrypt patient data through certificates to ensure privacy compliance. Digital signatures ensure that data is not tampered with during transmission. Digital certificates support auditing and logging, helping to track the operating history of AI robots and provide evidence for security incident investigations. Third-party CA agencies issue device certificates for AI robots by signing and verifying AI robot information.

[0279] In step S4, the input information received by the AI robot from the user or the external environment is processed to drive its decision, response or action. The input information of the AI robot may include text, voice, image, video, sensor data, structured data from databases or APIs, and real-time data from Internet of Things devices, and other multi-modal information. The data generated during the use of the AI robot can become a resource of the data set in some cases, although different types and sources of data need to be processed in combination with hardware, algorithms and scene requirements, but the authenticity, integrity and non-repudiation of the data need to be guaranteed through digital certificates and signature verification.

[0280] Although embodiments of the present application have been shown and described, it will be understood by those having ordinary skill in the art that various changes, modifications, substitutions and alterations can be made thereto without departing from the principles and spirit of the present application, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A digital certificate-based AI robot responsibility authentication method, characterized by: The CA mechanism, the AI robot and its participants are involved in the whole life cycle of the AI robot, the participants include dataset participants, model participants, integration participants and application participants, the AI robot and its participants obtain digital certificates through the CA mechanism, the AI robot and its participants sign their corresponding information through the digital certificates and bear corresponding responsibilities, including the following steps: S1, the dataset participant generates and shares the robot dataset, and applies for a digital certificate from the CA mechanism, signs the robot dataset information containing the DatasetMetadata metadata structure and is responsible for it; S2, the model participant verifies the signature of the robot dataset provided by the dataset participant, trains and deploys the AI model using the robot dataset, applies for a digital certificate from the CA mechanism, signs the AI model information containing the ModelMetadata metadata structure generated by the model participant and is responsible for it; S3, the integration participant verifies the signature of the AI model information provided by the model participant, integrates the traditional robot and the AI model to form the AI robot, applies for a digital certificate from the CA mechanism, signs the AIRobotInfo information of the AI robot, applies for a device certificate for the AI robot and is responsible for it; S4, the application participant verifies the validity of the AI robot device certificate, applies for a digital certificate from the CA mechanism, signs the data generated in the process of managing or using the AI robot and is responsible for it. 2.The AI robot responsibility certification method based on digital certificate according to claim 1, wherein: In step S1, the robot dataset is derived from actual operation of the physical world, including sensor data, motion trajectory and environmental interaction, and the generation of the robot dataset includes the following steps: S11, analyze the skills required by the robot according to the scene and determine the corresponding task; S12, divide the task into multiple subtasks; S13, decompose each subtask into multiple continuous time steps; S14, record the observations, actions, rewards and other related data of each step to form trajectory data; S15, standardize the generated trajectory data according to a common format; S16, store any metadata related to the dataset in the standardized format to generate the robot dataset; the metadata related to the dataset includes dataset description information, specifically dataset name, version information, use scenario, robot type, license, data collector, task code, number of trajectories and dataset generation time; S17, apply for a digital certificate; S18, sign the robot dataset; S19, share the robot dataset. 3.The AI robot responsibility certification method based on digital certificate according to claim 2, characterized in that: The signature of the robot dataset information by the dataset participant and the verification of the robot dataset information by the model participant include the following steps: a11, the dataset participant adds metadata in the dataset; a12, perform sharding processing on the dataset; a13, calculate the digest value of each shard respectively; a14, the dataset participant signs the shard digest value using a private key; a15, share the robot dataset and the signature; a16, the model participant downloads the dataset and the signature when using the dataset; a17, extract the dataset metadata; a18, parse the dataset signature; a19, verify the validity of the dataset participant certificate, if valid, use the dataset participant public key to verify the shard signature, if the verification is passed, use the dataset; if invalid or verification fails, the model participant assumes the risk of using the dataset; Wherein, since the data volume of the robot dataset is usually large, the robot dataset can be divided into several sub-datasets, and the dataset is processed in a shard manner, that is, the dataset is split into multiple shards, and an independent signature is generated for each shard, which is convenient for incremental updating and verification. 4.The AI robot liability certification method based on digital certificate according to claim 3, characterized in that: In step S2, the model participant trains the AI model using the robot dataset as follows: S21, select the robot dataset to obtain data; S22, verify the robot dataset information, if the verification is passed, use the dataset, if the verification is not passed, the model participant assumes the risk of using the dataset; S23, pre-process the obtained robot dataset, the pre-processing includes dividing training set, validation set and test set, cleaning, word segmentation, embedding, padding, normalization, feature extraction and enhancement of data; S24, select a model architecture suitable for the robot task and configure the model parameters for model training; S25, optimize the model through fine-tuning to adapt to specific needs; S26, select a suitable deployment platform according to actual needs to deploy the trained model, and generate an AI model; S27, apply for a digital certificate; S28, sign the AI model information; Wherein, the metadata related to the AI model includes model name, filing number, version number, parameter size, software framework, hardware configuration, data related parameters, model architecture parameters, training strategy parameters and evaluation optimization parameters; the data related parameters include dataset name, dataset size, training set proportion, data cleaning filter, preprocessing method, expansion part; the model architecture parameters include basic architecture, model layer number and hidden layer dimension, activation function, normalization method, attention head number and dimension of each head, expansion part; the training strategy parameters include optimizer, learning rate, training round number, batch size, evaluation interval, expansion part. 5.The AI robot responsibility certification method based on digital certificate according to claim 4, characterized in that: The model participant signs and integrates the AI model information, and the AI model includes the following steps: a21, file the AI model, the AI model needs to submit a filing application to the local provincial information office, and after preliminary examination, it is reviewed by the national information office and publicized; a22, edit the AI model metadata file; a23, calculate the digest value of the metadata file; a24, the model participant signs the file digest value using the private key; a25, provide the metadata file and signature; a26, the integrated participant obtains the metadata file and signature; a27, verify the AI model registration number, if the AI model registration number is accurate, verify the model participant certificate validity, if valid, the integrated participant uses the model participant's public key to sign the file signature, if the signature is passed, the AI model can be used, if the AI model registration number is not accurate, the certificate is invalid or the signature is not passed, the integrated participant bears the risk of using the AI model. 6.The AI robot responsibility certification method based on digital certificate according to claim 5, characterized in that: When the AI robot causes certain consequences in practical application and needs to be held accountable, the model participant can be required to allow the AI model source code to be viewed and checked whether the corresponding parameter settings in the source code are consistent with the description in the signed metadata file. If not, the model participant shall bear the corresponding responsibility; if completely consistent, the accuracy rate test is carried out using the test set, if the accuracy rate is low, the model participant needs to bear certain responsibility, if the accuracy rate is high, it can be attributed to the defects of AI technology itself, and the responsibility of the model participant is reduced or exempted.

7. The AI robot responsibility certification method based on a digital certificate according to claim 6, characterized in that: In step S3, the steps of the integrated participant integrating the AI robot are as follows: S31, demand analysis according to actual application scene; S32, overall system architecture design; S33, hardware selection and construction based on comprehensive demand and cost; S34, software environment configuration; S35, signature verification of AI model information used, if the signature verification is passed, the AI model integration and optimization are carried out; S36, soft and hardware system joint debugging and testing, generating AI robot; S37, applying for digital certificate; S38, signing AI robot information and applying for equipment certificate for AI robot; S39, providing AI robot products and services; Wherein, the integrated participant allocates a unique code for each AI robot, and when applying for equipment certificate for the AI robot, the integrated participant needs to submit information related to the identity of the AI robot to the CA institution, and the AI robot information consists of basic information, hardware information, software information, model information and communication mode.

8. The AI robot responsibility certification method based on a digital certificate according to claim 7, characterized in that: The steps of AI robot information signature and verification are as follows: a31, apply for integrated participant digital certificate; a32, integrated participant edits AI robot information file; a33, calculate the digest value of AI robot information file; a34, integrated participant signs the digest value of AI robot information using private key; a35, submit AI robot information file and signature; a36, CA institution obtains AI robot information file and signature; a37, extract integrated participant certificate and AI robot unique code; a38, verify the validity of integrated participant certificate, if valid, use integrated participant public key to verify the signature of information file, if the signature is passed, issue AI robot equipment certificate; if invalid or the signature is not passed, do not issue AI robot equipment certificate; The AI robot unique code can form a list in batches, which facilitates the integrated participants to apply for equipment certificates for batch-produced AI robots. The AI robot information signature can be placed in the extension field of the AI robot equipment certificate. If the same batch of AI robots has a large proportion of information inconsistency or failure, it is determined that the integrator should bear the corresponding responsibility. If only a few AI robots in the same batch have failures, the AI robot information in the extension field can be compared with the actual robot. If the information is completely consistent, the integrator bears the responsibility. If the information is inconsistent, it means that the AI robot has been changed by its manager or user, and the responsibility needs to be determined according to the actual use. 9.The AI robot responsibility certification method based on digital certificate according to claim 8, characterized in that: The application participant uses the AI robot, which includes the following steps: S41, verify whether the equipment certificate of the AI robot is valid, and check whether the actual information of the AI robot is consistent with the stored information in the extension field of the equipment certificate. If it is valid and consistent, continue to select and purchase. If it is invalid or inconsistent, give up the selection and purchase; S42, the application participant applies for a digital certificate; S43, manage the AI robot; S44, use the AI robot; S45, generate the use data of the AI robot; S46, the application participant signs the use data and decides whether to share the use data; The use data can be shared with the data set participant for use. When the data set participant uses it, the use data needs to be signed. If the signature is passed, the use data can be standardized and processed subsequently. If the signature is not passed, the data set participant bears the risk brought by generating and sharing the data set. 10.The AI robot responsibility certification method based on digital certificate according to claim 9, characterized in that: The steps of the CA agency issuing a digital certificate are as follows: S51, the CA agency accepts the application for the digital certificate of the AI robot and the related entities of the participants in different stages; S52, judge the application type. If the applicant is an individual, verify the identity information. If the identity information is correct, issue a personal certificate; If the applicant is an organization, verify whether the organization information is legal. If it is legal, issue an organization certificate; If the applicant is a device, sign the AI robot information. If the signature is passed, issue a device certificate; S53, manage the life cycle of the digital certificate.

Citation Information

Patent Citations

  • Right and interest allocation method and device

    CN117670340A

  • Authentication method and system for content works generated by artificial intelligence

    CN118862019A