Large model data protection method and device based on trusted environment, equipment and medium

By employing a method of slicing, encrypting, verifying, and decrypting large model data in a trusted environment, combined with a trusted strategy and key system, the problem of insufficient protection for large model data in existing technologies is solved, achieving comprehensive data security assurance.

CN120850332APending Publication Date: 2025-10-28BEIJING CREDIBLE HUATAI TECHNICAL SERVICE CO LTD
View PDF 0 Cites 5 Cited by

Patent Information

Application Number
CN202510782997.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-12
Publication Date
2025-10-28

AI Technical Summary

Technical Problem

In existing technologies, core data such as knowledge bases and model files lack effective security protection in traditional data storage and transmission scenarios, making it difficult to prevent illegal copying, tampering, or abuse, and failing to meet the protection requirements of local model deployment environments.

Method used

A large model data protection method based on a trusted environment is adopted. The original large model data is sliced, encrypted, and signed by the server before being sent to the target application. The target application performs anomaly checks and signature verification before calling the data. If the verification is successful, the original data is obtained by decrypting using the encrypted information table. The method combines a trusted strategy and a key system for dual protection.

Benefits of technology

It achieves comprehensive protection for large model data, prevents attackers from obtaining or tampering with sensitive data, ensures the security of data during transmission, storage and operation, and provides comprehensive data protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120850332A_ABST
    Figure CN120850332A_ABST
Patent Text Reader

Abstract

The invention relates to a large model data protection method and device based on a trusted environment, equipment and a medium. In the scheme, after a server side obtains original large model data, the original large model data needs to be encrypted and signed, and then the original large model data and an encrypted information table are issued to a target application side; when the target application end calls the large model data, performing exception check according to a credible strategy; if the check is passed, performing signature verification on each encrypted data slice; if the signature verification succeeds, decrypting the encrypted slice data by using the encrypted information table to obtain original large model data; wherein the server side and the target application side are both in a trusted environment. It can be seen that the trusted environment and the key system are combined, and a dual protection mechanism for large model data is achieved; moreover, before the large model data is called, the operation environment of the target application end needs to be subjected to exception check, so that an attacker is prevented from acquiring or tampering the sensitive data, and all-around data protection is provided for the large model data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of large model data processing technology, and in particular to a method, apparatus, device and medium for large model data protection based on a trusted environment. Background Technology

[0002] In recent years, with the rapid development of deep learning technology, large-scale pre-trained models have achieved significant breakthroughs in fields such as natural language processing. Furthermore, the release of platforms such as intelligent large-scale model systems has significantly reduced the costs of model training and local deployment, enabling data owners to assetize their data in the form of knowledge bases or fine-tuned expert models to provide products and services. However, in this scenario, core data assets such as knowledge bases and model files face serious security threats.

[0003] Current technologies lack sufficient protection for core data such as knowledge bases and model files, failing to effectively prevent the unauthorized copying, tampering, or misuse of the model's knowledge base or expert model. Furthermore, existing technologies primarily target traditional data storage and transmission scenarios, lacking security solutions tailored to model-specific environments, and thus struggle to meet the protection needs of locally deployed models.

[0004] Therefore, how to provide full access protection for core data such as knowledge bases and model files, and ensure the security of core data, is a problem that needs to be solved by those skilled in the art. Summary of the Invention

[0005] This application provides a method, apparatus, device, and medium for protecting large model data in a trusted environment to ensure the security of large model data.

[0006] Firstly, this application provides a method for protecting large model data based on a trusted environment. The method is applied to a target application and includes:

[0007] The system receives target large model data sent by the server. The target large model data includes: encrypted slice data and an encryption information table. Each encrypted slice data is generated by the server slicing the original large model data, encrypting the slice data using a target key, signing each encrypted slice data, and then sending it to the target application. The encryption information table includes the target key number used for each slice data.

[0008] When calling large model data, anomaly checks are performed according to a trusted policy; if the check passes, each encrypted data slice is verified.

[0009] If the signature verification is successful, the target key corresponding to each encrypted slice of data is determined according to the number in the encrypted information table.

[0010] The original large model data is obtained by decrypting each encrypted slice of data using the target key; wherein both the server and the target application are in a trusted environment.

[0011] Secondly, this application provides a large model data protection device based on a trusted environment, wherein the large model data protection device is applied to the target application end, and the large model data protection device includes:

[0012] A receiving module is used to receive target large model data sent by the server; wherein, the target large model data includes: each encrypted slice data and an encryption information table; each encrypted slice data is generated by the server slicing the original large model data, encrypting the slice data using a target key, and then signing each encrypted slice data before sending it to the target application; the encryption information table includes the number of the target key used for each slice data;

[0013] The inspection module is used to perform anomaly checks according to a trust strategy when calling large model data; if the check passes, the signature verification module is triggered.

[0014] The signature verification module is used to verify the signatures of each encrypted data slice; if the signature verification is successful, the decryption module is triggered.

[0015] The decryption module is used to determine the target key corresponding to each encrypted slice of data according to the number in the encrypted information table, and to decrypt each encrypted slice of data using the target key to obtain the original large model data; wherein, both the server and the target application are in a trusted environment.

[0016] Thirdly, this application provides an electronic device, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus;

[0017] Memory, used to store computer programs;

[0018] When the processor executes the program stored in memory, it implements the steps of the above-mentioned large model data protection method.

[0019] Fourthly, this application also provides a computer storage medium storing computer-executable instructions for performing the steps of the large model data protection method described above.

[0020] Compared with the prior art, the technical solution provided in this application has the following advantages: This application provides a method, apparatus, device, and medium for protecting large model data based on a trusted environment. In this solution, after the server obtains the original large model data, it needs to encrypt and sign it before sending it along with an encryption information table to the target application. When the target application calls the large model data, it performs anomaly checks according to a trusted policy. If the check passes, it verifies the signature of each encrypted data slice. If the signature verification is successful, it decrypts each encrypted data slice using the encryption information table to obtain the original large model data. Both the server and the target application are in a trusted environment. Therefore, this application combines a trusted environment with a key system to achieve a dual protection mechanism for large model data. Furthermore, before calling the large model data, this application needs to perform anomaly checks on the target application's operating environment to prevent attackers from obtaining or tampering with sensitive data, providing comprehensive data protection for the large model data. Attached Figure Description

[0021] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.

[0022] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0023] One or more embodiments are illustrated by way of example with reference numerals in the accompanying drawings. These illustrations do not constitute a limitation on the embodiments. Elements with the same reference numerals in the drawings are denoted as similar elements. Unless otherwise stated, the figures in the drawings are not to be limited by scale.

[0024] Figure 1 A schematic diagram illustrating the overall concept of a large-scale model data protection system based on trusted computing, provided in this application embodiment;

[0025] Figure 2 A schematic diagram of a large model data protection method based on a trusted environment is provided for an embodiment of this application;

[0026] Figure 3 This is a schematic diagram of the architecture of a large model data protection system based on a trusted system, provided in an embodiment of this application.

[0027] Figure 4 This is a schematic diagram of a data encryption method using a large-scale encryption tool provided in an embodiment of this application;

[0028] Figure 5 A schematic diagram of a large-scale model data protection system architecture based on a trusted system is provided for embodiments of this application;

[0029] Figure 6 The key initialization process for a large model data protection system based on trusted computing provided in this application embodiment;

[0030] Figure 7 A flowchart of key management for a large model data protection system based on trusted computing, provided for embodiments of this application;

[0031] Figure 8 This is a schematic diagram of the composition structure of the integrated device based on a large trusted computing model provided in the embodiments of this application;

[0032] Figure 9 A schematic diagram of the trusted subsystem structure provided in the embodiments of this application;

[0033] Figure 10 This is a schematic diagram of the support subsystem structure provided in an embodiment of this application;

[0034] Figure 11 This is a schematic diagram illustrating the trusted protection process initiated by the target application in an embodiment of this application.

[0035] Figure 12 A schematic diagram of the regulatory subsystem structure provided in this application embodiment;

[0036] Figure 13 This is a schematic diagram of the main control subsystem structure provided in an embodiment of this application;

[0037] Figure 14 This is a schematic diagram of the intelligent subsystem structure provided in an embodiment of this application;

[0038] Figure 15 This is a schematic diagram of the regulatory process for an integrated device based on a large trusted computing model, provided in an embodiment of this application.

[0039] Figure 16 A schematic diagram of the process for monitoring the operation of large model data based on trusted computing, provided in an embodiment of this application;

[0040] Figure 17 A schematic diagram illustrating the data decryption and usage method within the large-scale integrated device provided in this application embodiment;

[0041] Figure 18 A flowchart for managing large model data protection strategies based on trusted computing, provided for embodiments of this application. Detailed Implementation

[0042] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application. The following disclosure provides many different embodiments or examples to implement different structures of the present invention. To simplify the disclosure of the present invention, the components and arrangements of specific examples are described below. Of course, they are merely examples and are not intended to limit the present invention. In addition, the present invention may repeat reference numerals and / or letters in different examples. Such repetition is for the purpose of simplification and clarity and does not in itself indicate the relationship between the various embodiments and / or arrangements discussed.

[0043] This application discloses a method, apparatus, device, and medium for protecting large model data in a trusted environment to ensure the security of large model data. In this application, large model data files include, but are not limited to: large model applications, large model knowledge base files, and model files (basic files or trained files). Among these, the private knowledge base files and model files of the large model are key assets for users to build core AI (Artificial Intelligence) competitiveness: the private knowledge base carries industry-specific data resources, enabling the model to possess vertical domain expertise through targeted training, forming a technological barrier; the model files embody millions of dollars in training costs and intellectual property, and their leakage could lead to the leakage of trade secrets (such as model duplication or data reverse engineering). Both are directly related to business security and commercial value. This method ensures the security and trustworthiness of large model data during its use through a systematic protection approach including data encryption, access control, and proactive defense in a trusted environment.

[0044] See Figure 1 This is a schematic diagram illustrating the overall concept of a large model data protection system based on trusted computing, provided in an embodiment of this application. This protection system is a model data protection system based on Trusted Computing 3.0 technology, including a server and an application. The server is... Figure 1 The trusted large model management device in the middle, the application end is Figure 1 A trusted large-scale integrated device. For example... Figure 1As shown, when a user uses the large model system, the system first initializes its password. After initialization, the server and application store their respective keys and certificates in a secure area for data signing and encryption. Large model data is encrypted throughout its transmission (plaintext exists only in memory or video memory). Large model data is encrypted at the client's location and enters the server. After encryption conversion on the server, it is distributed to the application's secure storage area (a protected, isolated environment) via a secure path. When the large model or system application uses the large model data file, it is decrypted through a transparent decryption component and then stored in the application's memory (processor) or video memory (computing card).

[0045] This application employs a combination of a trusted environment and a key system to encrypt and protect large model data, while simultaneously monitoring the runtime environment to prevent attackers from obtaining or tampering with sensitive data. The data protection process is described below:

[0046] (1) Trusted execution environment: This application places the model in a secure environment protected by a trusted root, such as a privacy computing environment or a trusted AI all-in-one machine, to ensure that the knowledge base and model files can only be loaded and run in this environment.

[0047] (2) Key Protection Mechanism: The data owner uses symmetric encryption technology to encrypt the knowledge base / expert model. The symmetric encryption key is then encrypted again using a trusted storage key, forming a protection mechanism similar to a "data envelope". The trusted root stores the trusted storage private key, ensuring the security and immutability of the encryption key.

[0048] (3) Runtime Environment Monitoring: Dynamically analyzes the system environment and process behavior to identify and defend against potential security threats. Knowledge base / model decryption services are only provided when the system environment is secure and trustworthy. The root of trust measures and controls the process state in the trusted execution environment in real time, preventing attackers from obtaining data loaded into memory through methods such as memory dumping.

[0049] As can be seen, this application provides a comprehensive data protection solution for building a trusted integrated security device for large-scale model scenarios. By combining a trusted environment and a key system as a dual protection mechanism, this solution can prevent physical attacks and ensure the security of knowledge bases and model files during transmission, storage, and operation. It can provide a comprehensive technical solution for the protection of core assets such as knowledge bases and expert models, ensuring that the rights and interests of data owners are not infringed, while promoting the healthy development of the data economy.

[0050] See also Figure 2This is a schematic diagram of a large model data protection method based on a trusted environment, provided in an embodiment of this application. The large model data protection method is applied to the target application and specifically includes the following steps:

[0051] S101. Receive target large model data sent by the server; wherein, the target large model data includes: each encrypted slice data and an encryption information table; each encrypted slice data is generated by the server slicing the original large model data, encrypting the slice data using the target key, generating encrypted slice data, signing each encrypted slice data, and sending it to the target application; the encryption information table includes the number of the target key used for each slice data;

[0052] S102. When calling large model data, perform anomaly checks according to the trust policy; if the check passes, verify the signature of each encrypted data slice.

[0053] S103. If the signature verification is successful, determine the target key corresponding to each encrypted slice of data based on the number in the encrypted information table.

[0054] S104. Decrypt each encrypted slice of data using the target key to obtain the original large model data; wherein, both the server and the target application are in a trusted environment.

[0055] In this application, protection of large model data is mainly achieved through a server-side and an application-side approach; the server-side can be a trusted large model management device, and the application-side can be a trusted large model integrated device; see [link to relevant documentation]. Figure 3 This is a schematic diagram of the structure of a large model data protection system based on a trusted architecture provided in an embodiment of this application; as shown below. Figure 3 As shown, the trusted large model management device (server) is a device for managing, maintaining, and securing the trusted large model integrated device. It ensures the security and trustworthiness of the data throughout the entire process by encrypting and protecting the large model data. The trusted large model integrated device (application end) is the carrier for the large model's operation. It ensures the security of the big data's operational status by establishing a trusted dual-system architecture and protects the integrity and confidentiality of the large model data through cryptographic mechanisms. In this application, there can be multiple trusted large model integrated devices; that is, the server manages multiple application ends. Therefore, this application refers to the application end currently interacting with by the server as the target application end, and the large model data currently requiring protection as the original large model data.

[0056] To ensure the security of the original large model data during storage, transmission, and operation, this application requires the server to encrypt and store the original large model data. Before accessing the original large model data, the application performs anomaly detection using a trusted strategy. Only after the anomaly detection passes and decryption is successful is the use of the large model data permitted. Specifically, the server-side encryption of the original large model data is primarily accomplished using a dedicated large model encryption tool.

[0057] See also Figure 4 This is a schematic diagram illustrating a data encryption method using a large model encryption tool provided in this application embodiment. Before encrypting the original large model data, the user first needs to call the large model encryption tool module to set an encryption strategy. During encryption, the encryption key from the key information table is used to encrypt the original large model data. This encryption strategy includes the strategies used during the encryption process, such as the slicing method of the original large model data, the encryption method, and the encryption key used. Any strategy involved in the encryption process is considered an encryption strategy. The key information table is a pre-set data table for storing encryption keys. This table records multiple encryption keys, each with a unique number. The server can select the encryption key used for encrypting the original large model data from the key information table. This application refers to the encryption key used in this encryption as the target key. After receiving the original large model data input by the user, the server-side large model encryption tool needs to select the corresponding encryption strategy and perform the following encryption processing operations:

[0058] (1) The large model encryption tool classifies the original large model data file according to its characteristics, slices the original large model data content, and generates multiple slice data.

[0059] (2) Extract digest values ​​from each slice data as a unit, and use the target key in the key information table to perform data encryption operation on each slice data to obtain each encrypted slice data; wherein, in order to ensure the integrity of each slice data, this application can calculate the digest value of each slice data. After the application decrypts each encrypted slice data, it can compare the recalculated digest value with the digest value calculated by the server. If the two digest values ​​are the same, it means that the slice data decrypted by the application is correct; if the two digest values ​​are different, it means that the slice data has been tampered with.

[0060] (3) Identify each encrypted slice data and determine the tag value of each encrypted slice data. The tag value is used by the application to identify each slice data when calling the large model data.

[0061] (4) Establish a mapping relationship between the tag value of each encrypted slice data and the key information; wherein, the mapping relationship established in this application specifically refers to the correspondence between the tag value of each encrypted slice data and the number of the target key used. By recording this correspondence, the application can understand which encryption key was used to encrypt each slice data so as to use the correct key to decrypt each encrypted slice data.

[0062] (5) Package all encrypted slice data corresponding to the original large model data and sign it with its own private key;

[0063] (6) Send the data to the target application through a secure channel or secure carrier.

[0064] It should be noted that when this application sends each encrypted slice data to the target application, it also needs to send the encryption information table along with each encrypted slice data to the target application and store it in the root of trust. The encryption information table records the associated information generated after each slice data is confidentialized, including the target key number used by each slice data, the fragmentation method, the digest value, etc.

[0065] Table 1

[0066]

[0067] Referring to Table 1, this application provides an embodiment of encrypted information representation. As shown in Table 1, the encrypted information table in this application may include: total information of the large model file, segment number, main information, tag value, segment length, digest value, encryption strategy, target device information, encryption number, etc. The target device information is the basic information of the target application, which can be a unique identifier for the target application device or other parameters related to the target application, without specific limitations here. The encryption number is the number of the target key used by the server. This application associates the tag value with the encryption number to facilitate mapping each encrypted slice data to the key in the key information table during decryption. In the encryption strategy, the encryption method and key conversion model type are set in a trusted manner. The encryption method includes: national cryptographic / international / general encryption methods, etc., generally defaulting to symmetric encryption, but asymmetric encryption can also be selected according to requirements. The key conversion model is used to generate the key in the key information table. The key conversion model type of the server is matched with the key conversion model type of the application so that the server and the application generate the same key.

[0068] When the target application calls and runs large model data, it needs to transparently decrypt the data according to the encryption information table and key information table to ensure data security and the secure operation of the large model. However, before decryption, the target application also needs to perform anomaly checks according to a trusted policy; only if the checks pass can the subsequent decryption process be executed. In this application, the trusted policy is the policy used for trusted verification of the target application, including trusted measurement policies for the application startup process, trusted measurement policies for the application during operation, and handling policies for measurement failures, etc., which are not specifically limited here. When the target application calls large model data, it needs to perform anomaly checks according to the trusted policy. If no anomalies are detected, it means that the current target application is secure. At this time, the encrypted data slices can continue to be verified and decrypted before being used by the target application. The anomaly checks in this application may include: checking whether there are any anomalies in irrelevant processes, kernel code segments, system processes, etc.

[0069] In summary, this application combines a trusted environment with a key system to achieve a dual protection mechanism for large model data. Furthermore, before accessing the large model data, this application needs to perform anomaly checks on the target application's operating environment to prevent attackers from obtaining or tampering with sensitive data, thus providing comprehensive data protection for the large model data.

[0070] In another embodiment of this application, before the server encrypts the slice data using the target key, a password initialization process is included. This password initialization process generates a trusted storage key pair. Therefore, in this application, before the target application receives the target large model data sent by the server, the process further includes:

[0071] The server receives a second digital certificate sent by the server; wherein the generation process of the second digital certificate includes: the server applying for a first digital certificate; the first digital certificate containing a first key; and the server generating a second digital certificate based on the first digital certificate and the basic information of the target application.

[0072] The target application generates a trusted storage key pair based on the second digital certificate. The trusted storage key pair includes a private key and a public key. The public key of the trusted storage key pair is then sent to the server.

[0073] See also Figure 5This document presents a schematic diagram of a large-scale model data protection system architecture based on a trusted system, as provided in an embodiment of this application. It shows that this application establishes a trusted operating environment according to a trusted dual-system architecture to ensure the security of large-scale model data throughout the entire process. The server side includes: large-scale model encryption tools, model policy management, key management, trusted management, and other functional modules. The application side includes a computing component environment and a protection component environment. The computing component environment mainly includes a main control computing environment, a large-scale model operating environment, and large-scale model files, etc. The protection component environment mainly includes large-scale model monitoring components, a trusted software base, a trusted root, etc. This application can ensure the security of the large-scale model's operating status through a dynamic monitoring mechanism.

[0074] On the server side, the large-scale model encryption tool is a module for encrypting large-scale model data, including functions such as certificate distribution, data encryption / decryption, data integrity verification, and data signing. The tool is based on national cryptographic standards and includes other encryption methods, which can be expanded as needed. Model policy management primarily formulates and manages security and trust policies for large-scale model data on the application side. This module interfaces with security resources such as vulnerability databases, trust policy databases, and large-scale model risk databases, updating security policies within the module in real time. Key management is a functional module for unified management of application-side keys, including management of lower-level certificates, generation and management of encryption keys, and secure key storage. The trust management module manages and configures trusted applications on the application side. It can be configured with functions such as trusted management, trusted auditing, and trusted policies according to actual needs. Under certain conditions, based on the large-scale model trusted management module, the server can be used as a "trust management center" for unified management of trusted applications. Depending on different usage needs, the server may also have other functions, including but not limited to: identity authentication, operation and maintenance configuration, operation and maintenance audit, operation status display, operation and maintenance information, security posture, external expansion interface and other functional modules.

[0075] In this application, the server secures the source of the password by applying for a digital certificate from a CA (Certificate Authority) / RA (Registration Authority); the server's key management generates subordinate certificates of the CA through a cryptographic mechanism and exports them to the application's trusted root; the application uses the digital certificate issued by the server to complete local cryptographic applications. See also Figure 6 The following is a key initialization process for a large model data protection system based on trusted computing provided in this application embodiment. The process specifically includes the following steps:

[0076] (1) The server-side large-scale encryption tool applies for a digital certificate from a CA / RA;

[0077] (2) The CA authorizes the server with the first digital certificate (certificate 0);

[0078] (3) Certificate 0 associates the basic information of the target application in the key management module to derive a lower-level certificate: the second digital certificate (certificate 1), which contains the server's signature verification public key (key 1).

[0079] (4) The server sends Certificate 1 to the target application through a secure channel or secure carrier;

[0080] (5) Certificate 1 is stored in the trusted root of the target application;

[0081] (6) Based on certificate 1, the root of trust generates a trusted storage key pair whose private key cannot be exported. The trusted storage key pair includes private key 2 and public key 2.

[0082] (7) Export public key 2 to the large model encryption tool on the server through a secure channel or secure carrier and store it in the key management module; public key 2 is used by the large model encryption tool to encrypt the key and other information.

[0083] In another embodiment of this application, after the password initialization process is completed, it is also necessary to generate an encryption key for the data. In this embodiment, before the target application receives the target large model data sent by the server, the following steps are also included:

[0084] The target application receives a signed encrypted key information table sent by the server. The generation process of the encrypted key information table is as follows: the server generates each encrypted key based on the root key, and generates a key sequence number corresponding to each encrypted key using a key conversion model and the target application's basic information; based on the key sequence number and its number corresponding to each encrypted key, a key information table is generated; and the key information table is encrypted using the public key of a trusted storage key pair to generate the encrypted key information table. The target key used by the server is at least one encrypted key.

[0085] The target application verifies the encrypted key information table in the root of trust. If the verification is successful, the encrypted key information table is decrypted using the private key of the trusted storage key pair to obtain the key information table. Through the key conversion model, the key sequence numbers in the key information table are converted to obtain each encrypted key. A new target key information table is generated based on each encrypted key and its corresponding number and stored in the root of trust of the target application.

[0086] See also Figure 7This is a flowchart of the key management process for a large model data protection system based on trusted computing, provided in an embodiment of this application. The server-side large model encryption tool generates encryption keys for encrypting large model data. A key information table is established to create a cryptographic correspondence between encryption and decryption. All keys are cryptographically processed and stored in a secure environment. The specific method is as follows:

[0087] (1) On the server side, the large model encryption tool generates multiple lower-level keys for use in encrypting large model file data based on the root key distributed by the CA. These lower-level keys are encryption keys.

[0088] (2) On the server side, the large-scale encryption tool contains a key conversion model. By inputting each encryption key and the corresponding basic information of the target application into the key conversion model, a new key sequence number that conceals the original information can be obtained. Each encryption key is converted into the corresponding key sequence number. In this application, the key conversion model can adopt a variety of different algorithm models.

[0089] (3) On the server side, by numbering multiple encryption keys, a correspondence is established between the target application, the number, the encryption key and the key sequence number, and the encrypted data. Based on the key sequence number and number corresponding to each encryption key, a key information table is generated.

[0090] (4) On the server side, the public key of the trusted storage key pair of the target application is used to encrypt the key information table, and the key information table is encrypted and sent to the target application through a signature mechanism.

[0091] (5) At the application end, the encrypted key information table is received, and the signature is verified and the integrity is verified in the trusted root.

[0092] (6) On the application side, after the signature verification and integrity verification are passed, the encrypted key information table is decrypted using the private key of the trusted storage key pair to obtain the decrypted key information table. The key sequence number is extracted from the key information table, and the matching key conversion model is called to perform key conversion to obtain the converted encryption keys.

[0093] (7) On the application side, restore the correspondence between each encryption key and its number and tag, and form a new key information table to be stored in the trusted subsystem and trusted root on the application side;

[0094] (8) The key information table can be updated actively or periodically to ensure the security of cryptographic information.

[0095] In summary, this application demonstrates that in the password initialization process, by using a CA-authorized digital certificate to associate with the target application and generate a lower-level certificate, which is then sent to the target application, a trusted storage key pair can be generated based on the lower-level certificate. When generating encryption keys for data, the server can input each encryption key and the corresponding basic information of the target application into the key conversion model to obtain a new key sequence number that conceals the original information. After generating a key information table from the key sequence number and its number, it is necessary to encrypt and send the key to the target application using the public key of the trusted storage key pair, thereby achieving double encryption of the encryption key and ensuring key security.

[0096] In another embodiment of this application, the target application includes an intelligent subsystem, a main control subsystem, a support subsystem, a monitoring subsystem, and a trusted subsystem. Correspondingly, the large model data protection method further includes:

[0097] When the target application starts, the trusted subsystem and the logic control module in the support subsystem are started first. The trusted subsystem performs a trust measurement on the logic control module. If the measurement is successful, the logic control module starts the monitoring subsystem, the main control subsystem, the support subsystem, and the intelligent subsystem in a predetermined startup order. The trusted subsystem then sequentially measures the startup of the monitoring subsystem, the main control subsystem, the support subsystem, and the intelligent subsystem.

[0098] If any one of the logic control module, the monitoring subsystem, the main control subsystem, the support subsystem, and the intelligent subsystem fails to perform a measurement, a predetermined processing operation will be executed according to the trusted strategy.

[0099] See also Figure 8 This is a schematic diagram of the composition structure of the integrated device for a large-scale trusted computing model provided in this application embodiment; this integrated device for a large-scale trusted computing model is the application end, which is a large-scale model application device built with a trusted computing dual-system architecture as the framework and trusted root protection as the security foundation. Figure 8 As shown, the application consists of a trusted subsystem, a monitoring subsystem, a main control subsystem, an intelligent subsystem, and a support subsystem. Among them, the monitoring subsystem and the trusted subsystem are protective components, while the other subsystems are computing components; the protective components and computing components are securely isolated from each other through an isolation mechanism.

[0100] The Trusted Subsystem is the foundation of the entire device's trustworthiness, enabling trust measurement and monitoring of other subsystems. The Supervisory Subsystem monitors the operational status of the Main Control Subsystem and the Intelligent Subsystem, performing monitoring and control according to the large model strategy to ensure the safety of the large model's operation and input / output behavior. The Main Control Subsystem is the device's computation and control subsystem, enabling application operations and management of the large model. The Intelligent Subsystem is the main computational subsystem for the large model's operation, storing the large model's knowledge base and model files. The Support Subsystem is the foundation of the entire device, ensuring the basic operating environment, including the device's power supply, communication, various interfaces, and shared storage.

[0101] The target application in this application needs to execute a startup trusted protection process through the trusted subsystem and supporting subsystem upon startup; see [link to relevant documentation]. Figure 9 This is a schematic diagram of the trusted subsystem structure provided in the embodiments of this application. Figure 9 As can be seen, the trusted subsystem consists of a trusted management module, a trusted platform control module, a trusted cryptography module, a trusted storage module, and an interface module. The trusted management module contains a trusted software base, which manages and controls the implementation of the trusted mechanism for the trusted subsystem and the entire device. The Trusted Platform Control Module (TPCM) is a fundamental core module used by the entire device to establish and secure trusted sources, providing functions such as proactive measurement, proactive control, trusted verification, encryption protection, trusted reporting, and cryptographic retrieval.

[0102] The Trusted Cryptography Module (TCM) provides cryptographic operations for the entire device and has protected storage space. The Trusted Storage Module is a secure storage area within the Trusted Subsystem; its stored content is protected by the Trusted Platform Control Module and the Trusted Cryptography Module, and is used for backing up important information and core parts of the knowledge base and model files in large model data. The Interface Module is the external interface of the Trusted Subsystem, including internal and external interfaces. The internal interface is used for communication and data exchange with other subsystems within the device; the external interface is used for remote communication with the Trusted Management Center.

[0103] See also Figure 10 This is a schematic diagram of the support subsystem structure provided in the embodiments of this application, such as... Figure 10As shown, the support subsystem consists of an external bus, a logic control module, a general-purpose storage module, an input / output module, a power supply, a motherboard, and interface modules. The external bus provides the connection and information exchange between the various subsystems, serving as the control and communication channel between the modules. The logic control module manages and controls the timing of the access process for each subsystem, ensuring that after the trusted subsystem starts, each subsystem or module starts and is measured according to a trusted and secure startup sequence, thus guaranteeing the establishment of a trusted chain within the integrated device.

[0104] The general-purpose storage module stores data within the device, meeting the general storage needs of various subsystems. The input / output module serves as the channel for interaction between the integrated device and the outside world, generally consisting of interfaces and drivers for input devices (mice, keyboards, biometric data acquisition peripherals, etc.) and interfaces and drivers for output devices (monitors, printers, etc.). The interface module provides external connections for the device, including network interfaces, debugging interfaces, and reserved interfaces. The power supply module provides power to the entire device; the motherboard is the module that enables communication and power supply to the modules and functional components in each subsystem, serving as the fundamental carrier for ensuring the normal operation of each subsystem. Support modules also include other essential basic modules necessary for the operation of the integrated device.

[0105] This application implements a trusted protection startup process, which requires connecting the intelligent subsystem, main control subsystem, support subsystem, and monitoring subsystem to the device's power supply via logic switches. The power-on sequence is controlled by the logic control module of the support subsystem. The startup process ensures the establishment of the trusted chain, powering on sequentially and performing trusted measurements. The predetermined startup sequence in this application can be customized according to requirements. In this embodiment, the predetermined startup sequence can be set as follows: monitoring subsystem - main control subsystem and support subsystem - intelligent subsystem.

[0106] See also Figure 11 This is a schematic diagram of the trusted protection process initiated by the target application in an embodiment of this application. The specific process is as follows:

[0107] (1) When the power is turned on, the trusted subsystem and the logic control module start up and are initialized. The trusted subsystem performs a trust measurement on the configuration file in the logic control module.

[0108] (2) After the trust measurement of the logic control module is completed, the logic control module controls the logic switch to start the supervision subsystem and performs the trust measurement.

[0109] (3) After the trust measurement of the regulatory subsystem is completed, the logic control module controls the logic switch to start the main control subsystem and the support subsystem, and performs the trust measurement.

[0110] (4) After the trust measurement of the main control subsystem and the support subsystem is completed, the logic control module starts the intelligent subsystem and performs trust measurement.

[0111] (5) After the trust measurement of the intelligent subsystem startup process is completed, the trust measurement of the startup process of the integrated device is completed; if the measurement result is untrustworthy in the above steps, it shall be handled in accordance with the trust strategy in the trustworthy subsystem, such as auditing, alarm, termination, etc.

[0112] In summary, this application can ensure the secure startup of each subsystem by activating a trusted protection mechanism when the target application starts, prevent malicious tampering of each subsystem, establish a multi-layered trust chain, and ensure the secure operation of the large model on the target application.

[0113] In another embodiment of this application, when the target application is running, the large model data protection method further includes a trusted protection process during runtime, which mainly includes the following processes:

[0114] The trusted subsystem performs dynamic measurement on the target subsystem according to the trusted policy; if the measurement fails, it executes the predetermined processing operation according to the trusted policy; the target subsystem includes the intelligent subsystem, the main control subsystem, the support subsystem, and the supervisory subsystem; the content of the dynamic measurement includes: system calls, kernel code segments, kernel driver lists, system processes, application code segments of model-related processes, and dynamic library dependencies of each target subsystem.

[0115] Specifically, during operation, the trusted subsystem needs to monitor other subsystems and dynamically measure and manage process states. The specific implementation method is as follows:

[0116] (1) The trusted platform control module of the trusted subsystem obtains the real-time status of the trusted management module of the trusted subsystem by actively accessing memory, and measures and judges it by customizing the strategy. If there is any abnormality, it will be handled according to the strategy, such as auditing, alarming, termination, etc.

[0117] (2) The trusted management module of the trusted subsystem actively obtains all system calls of other subsystems, initiates measurement and judgment according to the customized strategy, and handles any abnormalities according to the strategy, such as auditing, alarming, termination, etc.

[0118] (3) The trusted platform control module of the trusted subsystem checks the kernel code segment, kernel driver list, application code segment of model-related processes, process and dynamic library dependencies of other subsystems according to the customized strategy. If there are any abnormalities, it will be handled according to the strategy, such as auditing, alarm, termination, etc.

[0119] In summary, this application, when running on the target application, uses a trusted protection mechanism during the runtime process to dynamically measure and control other subsystems, thereby blocking abnormal behaviors in the system, improving the security of each subsystem, and ensuring the security of the large model's operation.

[0120] In another embodiment of this application, the large model data protection method further includes:

[0121] The monitoring subsystem monitors the operational status of the intelligent subsystem and the main control subsystem; if any abnormality is found in the operational status, it calls the operation and maintenance management tools for real-time operation and maintenance; the intelligent subsystem is used to store large model data and realize the computing environment for the training and inference process of large models; the main control subsystem is used to realize the application operation and management of large models;

[0122] The regulatory subsystem monitors and handles risks during the operation of the large model in accordance with the security regulatory strategy; these risks include at least one of the following: large model vulnerability risk, large model content risk, and large model behavior risk.

[0123] See also Figure 12 This is a schematic diagram of the supervisory subsystem structure provided in this application embodiment. The supervisory subsystem consists of an operation and maintenance module, a model supervision module, and an interface module. The operation and maintenance module is responsible for monitoring the basic parameters of the operating status of each subsystem within the device and connecting with a remote operation and maintenance management center or local operation and maintenance tools to ensure the realization of remote real-time operation and maintenance of the integrated device. The model supervision module supervises the operating status and security behavior of the large model through security supervision strategies, ensuring the security of the large model's operation, use, and output. The interface module is the external interface of the supervisory subsystem, including internal and external interfaces. The internal interface is used for communication and data interaction with other subsystems within the device; the external interface is used for communication with the operation and maintenance management center or local operation and maintenance tools.

[0124] See also Figure 13This is a schematic diagram of the main control subsystem structure provided in this application embodiment. The monitoring subsystem consists of a startup module, a control management module, a data encryption module, and an interface module. The startup module is the startup firmware module of the main control subsystem, implementing initialization before the control management module starts and system startup boot functions. The control management module is the main controller of the device, implementing data computation and control management functions within the device. It is a large model application configuration module, used to manage large model inputs, receive large model output results, and configure the running process. The data encryption module is used to provide cryptographic support for the knowledge base and model files of the large model. It mainly encrypts locally generated knowledge bases and model files; for migrated knowledge bases and model files, it performs local verification, decryption, local encryption conversion, and signing functions. The interface module is the external interface of the main control subsystem, including internal and external interfaces. The internal interface is used for communication and data interaction with other subsystems within the device; the external interface is used for remote communication with other external devices.

[0125] See also Figure 14 This is a schematic diagram of the intelligent subsystem structure provided in an embodiment of this application. The intelligent subsystem consists of an intelligent computing module, a knowledge base module, a model file module, and an interface module. The intelligent computing module performs calculations on large model data, providing the computing environment for the training and inference processes of the large model; its main component is a computing card (GPU). The knowledge base module stores knowledge files from the large model, including facts, relationships, rules, or text fragments from a specific domain; these are typically explicit and searchable. Knowledge base files include both transferred knowledge bases and locally generated knowledge bases. The model file module stores model files from the large model, providing persistent storage for trained model parameters and structures; model files include transferred model files and newly learned implicit knowledge from local training. The interface module is the external interface of the intelligent subsystem, used for communication and data interaction with other subsystems within the device. Depending on the specific working environment of the large model integrated machine, the knowledge base module and model files can be stored in an isolated execution environment or a protected component environment under the protection of a trusted subsystem. If the large model data includes other data besides the knowledge base and model files, a storage module for other data can also be added to the intelligent subsystem.

[0126] See also Figure 15The figure illustrates the regulatory process of the integrated large-scale model device based on trusted computing provided in this application embodiment. As shown, this solution uses a regulatory subsystem to monitor the status parameters and risks of the large model during device operation. Specifically, the operation and maintenance module within the regulatory subsystem monitors the operating status of the intelligent subsystem and the main control subsystem, and manages their configuration through a remote operation and maintenance center or locally connected operation and maintenance tools. The model regulatory module within the regulatory subsystem mainly focuses on the risks during the operation of the large module, and regulates them according to security regulatory strategies. It mainly monitors and handles the relevant risks during the operation of the large model, including but not limited to: large model vulnerability risks, large model content risks (inputting inappropriate information, outputting non-compliant content, model illusions, etc.), and large model behavioral risks (illegal behavior, unauthorized behavior, etc.).

[0127] See Figure 16 This is a schematic diagram of the process for monitoring the operation of large model data based on trusted computing, provided in an embodiment of this application. The process specifically includes the following steps:

[0128] ① The trusted management module of the trusted subsystem initializes the trusted agent within the control management module of the main control subsystem and monitors the system status through the trusted agent;

[0129] ②Real-time monitoring of the trusted agent system and the operational status of the large model;

[0130] ③ The status monitoring unit monitors the system and large model's operating status in real time;

[0131] The model supervision module within the supervision subsystem includes a status monitoring unit, a large model vulnerability set, a large model behavior constraint set, a non-compliant keyword set, a content retrieval unit, a management unit, and security supervision strategies. The model supervision module utilizes security supervision strategies, the status monitoring unit, the large model vulnerability set, and the large model behavior constraint set to detect large model vulnerability risks and large model behavior risks.

[0132] ④ Large-scale model operation, with content input and output via interfaces;

[0133] ⑤ Intercept input and output content and supervise the content; for example, when retrieving large model data, it is necessary to perform anomaly detection through a trust strategy before loading the large model data.

[0134] ⑥ Security retrieval; The model supervision module uses security supervision strategies, content retrieval units, and non-compliant keyword sets to check the content information of the control management module and find content risks in the large model;

[0135] ⑦ The security information of the model monitoring module is uploaded to the trusted subsystem;

[0136] ⑧ The trusted subsystem distributes security supervision policies and performs trust measurement to the model supervision module.

[0137] In summary, this application, through its monitoring subsystem, can monitor the operational status of the intelligent subsystem and the main control subsystem, ensuring the safe conduct of the large model's training and inference processes, as well as the safe operation and management of the large model. Furthermore, the monitoring subsystem can also perform risk monitoring on the large model's operation process according to security monitoring strategies, monitoring for risks such as large model vulnerabilities, content risks, and behavioral risks during the large model's operation, thereby improving the security of the large model's operation.

[0138] In another embodiment of this application, the anomaly check performed by the target application when calling large model data according to the trust strategy specifically includes the following steps:

[0139] The trusted subsystem of the target application acquires all system calls; if it detects that the model startup process is reading large model data, it performs the following anomaly checks according to the trusted policy:

[0140] Traverse all processes in the current system and check for the existence of model-independent processes; if they exist, perform the predetermined processing operations according to the trusted policy.

[0141] Check for anomalies in at least one of the following: kernel code segment, kernel driver list, system processes, application code segment of model-related processes, and dynamic library dependencies; if anomalies are found, perform predetermined processing operations according to the trust policy.

[0142] The signature public key certificate is verified; if the verification fails, the predetermined processing operation is performed according to the trust policy; if the verification passes and there are no abnormalities, the signature of each encrypted data slice is verified using the signature public key certificate.

[0143] In this application, the large model data file is encrypted and stored throughout the application process. After being decrypted by a transparent file decryption component, it is loaded into the processor's memory or the video memory of the intelligent computing module for execution. See also Figure 17 This is a schematic diagram of the data decryption and usage method within the large-scale integrated device provided in this application embodiment. The process specifically includes the following steps:

[0144] ① The trusted management module of the trusted subsystem initializes the trusted agent within the control management module of the main control subsystem and monitors the system status through the trusted agent; when monitoring the system and the running status of the large model, the trusted management module needs to actively obtain all system calls, and actively initiate verification when it finds that the model starts related processes to read knowledge base / model files;

[0145] ②Real-time monitoring of the trusted agent system and the operational status of the large model;

[0146] ③ Run the large model and load the model file or knowledge base file;

[0147] ④ The trusted management module intercepts the loaded file and initiates the decryption process;

[0148] ⑤ The control and management module obtains the encrypted AI model / knowledge base from the intelligent subsystem;

[0149] ⑥ The encrypted AI model / knowledge base data is sent to the trusted subsystem via a trusted proxy;

[0150] ⑦ Use the trusted control platform module to decrypt the encrypted data;

[0151] Before entering the decryption process, anomaly detection is performed using a trusted policy. In this application, anomaly detection includes: the trusted platform control module, based on the trusted policy, traversing all processes currently running in the system; if any process is unrelated to the model, an alarm is triggered and the system stops; the trusted platform control module, based on the trusted policy, checks the kernel code segment, kernel driver list, application code segment of model-related processes, process and dynamic library dependencies; if any anomalies are found, the system terminates and an alarm is triggered. Supported by the trusted cryptography module, the trusted platform control module uses the certificate chain stored during initialization to verify the public key certificate signed by the large model encryption tool; if verification fails, an alarm is triggered and the system stops; if verification succeeds, the decryption process proceeds.

[0152] The decryption process is as follows: With the support of the trusted cryptography module, the trusted platform control module verifies the signature of the public key certificate signed by the model-large model encryption tool against the knowledge base / model file. If the verification fails, an alarm is triggered and the process stops. Then, with the support of the trusted cryptography module, the trusted platform control module decrypts the knowledge base / model file using the key information table stored in the trusted root. Since the knowledge base / model file received by the target application is an encrypted data slice, this application, after successfully verifying the signature of each encrypted data slice, determines the target key corresponding to each encrypted slice from the key information table based on the number in the encryption information table. Finally, the target key is used to decrypt each encrypted slice to obtain the decrypted large model data.

[0153] ⑧ Send the decrypted large model data to the intelligent computing module of the intelligent subsystem. If the decrypted data includes system files, send the system files to the system management component of the control and management module.

[0154] In this application, the large model strategy includes a trust strategy and a security oversight strategy. The server-side model strategy management module mainly formulates and manages the security oversight and trust strategies for large model data in the application. The model strategy management module has interfaces with security resources such as vulnerability databases, trust strategy databases, and large model risk databases, and updates the security oversight strategies within the module in real time. Model strategy management is a dynamic security protection system built on the entire lifecycle of the large model. It integrates a reinforcement learning-driven adaptive strategy engine, a multi-source intelligence fusion platform (interfacing with vulnerability databases, risk knowledge graphs, and trust strategy databases), a trusted computing environment, and a cross-platform collaborative defense network to form a full-link protection covering data input, model inference, and result output.

[0155] See also Figure 18 This is a flowchart illustrating the management process of a large model data protection strategy based on trusted computing, as provided in this embodiment of the application. As shown, trusted strategies and security monitoring strategies are formulated and distributed on the server side, while the application side executes the strategies and provides status feedback, forming a closed-loop security protection mechanism. On the server side, the trusted management module generates trusted strategies, and the large model security strategy generates relevant security risk management strategies. These are then combined by the model strategy management module into a large model strategy and distributed to the application side, where they are stored in the trusted root. On the application side, the trusted root decomposes the large model strategy into trusted strategies and security monitoring strategies, which are then pushed to the trusted subsystem and model monitoring module for execution. The execution status of the strategies is summarized by the trusted subsystem into a trusted report and uploaded to the trusted management module on the server side for analysis. Based on the analysis results, existing strategies are optimized and updated.

[0156] It should be noted that the decrypted original large model data in this application only exists in the control and management module and its memory, and the intelligent computing module and its video memory, and is used for the large model system during runtime. After the operation is completed, the decrypted original large model data is not saved locally on the target application. For example, after the operation is completed, the decrypted original large model data in the target application can be automatically deleted to prevent the leakage of large model data.

[0157] In summary, this application establishes a security framework for a trusted computing large-scale model device based on a trusted subsystem, enabling secure verification and encryption / decryption of large-scale model data under a cryptographic mechanism. The large-scale model encryption tool in this application can bind data to the device, establishing a key protection mechanism based on symmetric encryption and secondary encryption using trusted storage keys, facilitating large-scale model data migration and cross-platform use. Furthermore, this application can customize model-specific strategies based on the trusted subsystem, enabling process loading control beyond system root privileges and monitoring the operational status of large-scale model-related service applications. Moreover, this application establishes a key conversion model based on the trusted computing system, implementing a key concealment conversion mechanism to ensure the security of the large-scale model encryption key.

[0158] In another embodiment of this application, a large model data protection device based on a trusted environment is also disclosed. This large model data protection device is applied to a target application and includes:

[0159] A receiving module is used to receive target large model data sent by the server; wherein, the target large model data includes: each encrypted slice data and an encryption information table; each encrypted slice data is generated by the server slicing the original large model data, encrypting the slice data using a target key, and then signing each encrypted slice data before sending it to the target application; the encryption information table includes the number of the target key used for each slice data;

[0160] The inspection module is used to perform anomaly checks according to a trust strategy when calling large model data; if the check passes, the signature verification module is triggered.

[0161] The signature verification module is used to verify the signatures of each encrypted data slice; if the signature verification is successful, the decryption module is triggered.

[0162] The decryption module is used to determine the target key corresponding to each encrypted slice of data according to the number in the encrypted information table, and to decrypt each encrypted slice of data using the target key to obtain the original large model data; wherein, both the server and the target application are in a trusted environment.

[0163] This application also provides a large model data protection system based on a trusted environment, comprising:

[0164] The server slices the original large model data to generate slice data; it encrypts the slice data using a target key to generate encrypted slice data; after signing each encrypted slice data, it sends it along with an encryption information table to the target application; wherein, the encryption information table includes the number of the target key used for each slice data;

[0165] When the target application calls the large model data, it performs anomaly checks according to a trusted policy. If the check passes, it verifies the signature of each encrypted data slice. If the signature verification is successful, it determines the target key corresponding to each encrypted data slice based on the number in the encrypted information table, and decrypts each encrypted data slice using the target key to obtain the original large model data. Both the server and the target application are in a trusted environment.

[0166] The server side includes a large model encryption tool module, a model policy management module, a key management module, and a trusted management module. The target application side includes an intelligent subsystem, a main control subsystem, a support subsystem, a supervision subsystem, and a trusted subsystem.

[0167] It should be noted that the functions and specific execution methods of each module in the server and each subsystem in the application have been described in detail in the embodiments of the relevant method, and will not be elaborated here.

[0168] This application provides a schematic diagram of an electronic device structure, including a processor, a communication interface, a memory, and a communication bus. The processor, communication interface, and memory communicate with each other through the communication bus. The memory is used to store computer programs. When the processor executes the program stored in the memory, it implements the steps of the large model data protection method described in any of the above method embodiments, which will not be repeated here.

[0169] The communication bus mentioned above can be a peripheral component interconnection standard bus or an extended industry standard structure bus, etc. The communication interface is used for communication between the terminal and other devices. The memory can include random access memory or non-volatile memory. The processor mentioned above can be a general-purpose processor; it can also be a digital signal processor, application-specific integrated circuit, field-programmable gate array (FPGA), or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component.

[0170] In another exemplary embodiment, a computer storage medium is also provided, wherein the program instructions, when executed by a processor, implement the steps of the large model data protection method described in any of the above method embodiments.

[0171] Optionally, specific examples in this embodiment can refer to the examples described in the above embodiments, and will not be repeated here.

[0172] It should be understood that the terminology used herein is for the purpose of describing particular exemplary embodiments only and is not intended to be limiting. Unless the context clearly indicates otherwise, the singular forms “a,” “an,” and “described” as used herein may also include the plural forms. The terms “comprising,” “including,” “containing,” and “having” are inclusive and therefore indicate the presence of the stated features, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, elements, components, and / or combinations thereof. The method steps, processes, and operations described herein are not construed as requiring them to be performed in a particular order described or illustrated unless the order of performance is explicitly indicated. It should also be understood that additional or alternative steps may be used.

[0173] The above description is merely a specific embodiment of the present invention, enabling those skilled in the art to understand or implement the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the present invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features claimed herein.

Claims

1. A method for protecting large model data based on a trusted environment, characterized in that, The large model data protection method is applied to the target application and includes: The system receives target large model data sent by the server. The target large model data includes: encrypted slice data and an encryption information table. Each encrypted slice data is generated by the server slicing the original large model data, encrypting the slice data using a target key, signing each encrypted slice data, and then sending it to the target application. The encryption information table includes the target key number used for each slice data. When calling large model data, anomaly checks are performed according to a trusted policy; if the check passes, each encrypted data slice is verified. If the signature verification is successful, the target key corresponding to each encrypted slice of data is determined according to the number in the encrypted information table. The original large model data is obtained by decrypting each encrypted slice of data using the target key; wherein both the server and the target application are in a trusted environment.

2. The large model data protection method according to claim 1, characterized in that, Before receiving the target large model data sent by the server, the process also includes: The server receives a signed encryption key information table sent by the server. The generation process of the encryption key information table is as follows: the server generates each encryption key based on the root key, and generates a key sequence number corresponding to each encryption key using a key conversion model and the basic information of the target application; based on the key sequence number and number corresponding to each encryption key, a key information table is generated, and the key information table is encrypted using the public key of a trusted storage key pair to generate the encryption key information table; wherein the target key used by the server is at least one encryption key. The encryption key information table is verified in the root of trust. If the signature verification is successful, the encrypted key information table is decrypted using the private key of the trusted storage key pair to obtain the key information table. The key sequence number in the key information table is converted using a key conversion model to obtain each encryption key. A new target key information table is generated based on each encryption key and its corresponding number, and stored in the root of trust of the target application.

3. The large model data protection method according to claim 2, characterized in that, Before receiving the target large model data sent by the server, the process also includes: The server receives a second digital certificate sent by the server; wherein the generation process of the second digital certificate includes: the server applying for a first digital certificate; the first digital certificate containing a first key; and generating a second digital certificate based on the first digital certificate and the basic information of the target application. A trusted storage key pair is generated based on the second digital certificate, the trusted storage key pair including a private key and a public key; Send the public key of the trusted storage key pair to the server.

4. The large model data protection method according to claim 1, characterized in that, The anomaly check performed according to the trust strategy when calling large model data includes: The trusted subsystem of the target application acquires all system calls; if it detects that the model startup process is reading large model data, it performs the following anomaly check operation according to the trusted policy: Traverse all processes in the current system and check for the existence of model-independent processes; if they exist, perform the predetermined processing operations according to the trusted policy. Check for anomalies in at least one of the following: kernel code segment, kernel driver list, system processes, application code segment of model-related processes, and dynamic library dependencies; if anomalies are found, perform predetermined processing operations according to the trust policy. The signature public key certificate is verified; if the verification fails, the predetermined processing operation is performed according to the trust policy; if the verification passes and there are no abnormalities, the signature of each encrypted data slice is verified using the signature public key certificate.

5. The large model data protection method according to any one of claims 1 to 4, characterized in that, The target application includes an intelligent subsystem, a main control subsystem, a support subsystem, a monitoring subsystem, and a trusted subsystem. Therefore, the large model data protection method further includes: When the target application starts, the trusted subsystem and the logic control module in the support subsystem are started first, and the trusted subsystem performs a trust measurement on the logic control module. If the measurement is successful, the logic control module will start the monitoring subsystem, the main control subsystem, the support subsystem, and the intelligent subsystem in a predetermined startup order, and then measure the monitoring subsystem, the main control subsystem, the support subsystem, and the intelligent subsystem in sequence through the trusted subsystem. If any one of the logic control module, the monitoring subsystem, the main control subsystem, the support subsystem, and the intelligent subsystem fails to perform a measurement, a predetermined processing operation will be executed according to the trusted strategy.

6. The large model data protection method according to claim 5, characterized in that, When the target application is running, the large model data protection method further includes: The trusted subsystem performs dynamic measurement on the target subsystem according to the trusted policy; if the measurement fails, it performs a predetermined processing operation according to the trusted policy. The target subsystem includes the intelligent subsystem, the main control subsystem, the support subsystem, and the monitoring subsystem; the dynamic measurement includes: system calls, kernel code segments, kernel driver lists, system processes, application code segments of model-related processes, and dynamic library dependencies of each target subsystem.

7. The large model data protection method according to claim 5, characterized in that, The large model data protection method also includes: The monitoring subsystem monitors the operating status of the intelligent subsystem and the main control subsystem; if an abnormality is found in the operating status, the operation and maintenance management tool is invoked for real-time operation and maintenance; the intelligent subsystem is used to store large model data and realize the computing environment for the training and inference process of large models; the main control subsystem is used to realize the application operation and management of large models. The regulatory subsystem monitors and handles risks during the operation of the large model in accordance with the security regulatory strategy; wherein the risks include at least one of the following: large model vulnerability risk, large model content risk, and large model behavior risk.

8. A large model data protection device based on a trusted environment, characterized in that, The large model data protection device is applied to the target application and includes: A receiving module is used to receive target large model data sent by the server; wherein, the target large model data includes: each encrypted slice data and an encryption information table; each encrypted slice data is generated by the server slicing the original large model data, encrypting the slice data using a target key, and then signing each encrypted slice data before sending it to the target application; the encryption information table includes the number of the target key used for each slice data; The inspection module is used to perform anomaly checks according to a trust strategy when calling large model data; if the check passes, the signature verification module is triggered. The signature verification module is used to verify the signatures of each encrypted data slice; if the signature verification is successful, the decryption module is triggered. The decryption module is used to determine the target key corresponding to each encrypted slice of data according to the number in the encrypted information table, and to decrypt each encrypted slice of data using the target key to obtain the original large model data; wherein, both the server and the target application are in a trusted environment.

9. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; Memory, used to store computer programs; When a processor executes a program stored in memory, it implements the steps of the large model data protection method according to any one of claims 1 to 7.

10. A computer storage medium, characterized in that, The computer storage medium stores computer-executable instructions, which are used to perform the steps of the large model data protection method according to any one of claims 1 to 7 of this application.

Citation Information

Cited By

  • Large model safety protection system, large model safety protection method and medium

    CN121711199A

  • A large model security protection system, a large model security protection method and a medium

    CN121711199B

  • Industrial large model deployment method, operation method, device and all-in-one machine equipment

    CN121727741A

  • A method, operation method, device, and integrated equipment for deploying large-scale industry models

    CN121727741B

  • Dynamic generation method, system and device of trusted white list and electronic equipment

    CN122093179A