Chip supporting data encryption transmission and data encryption transmission method
By using a data encryption transmission chip, a secure microprocessor, and an unmodifiable private key, the risk of misuse after the sale of large model weight data is solved, achieving data security and reduced deployment costs, adapting to market demands and improving the ease of client deployment.
Patent Information
- Application Number
- CN202410554502.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-07
- Publication Date
- 2025-11-07
AI Technical Summary
In existing technologies, the sale of large model weight data poses a risk of misuse, leading to increased losses on the service supply side and increased difficulty in private deployment on the client side. How to improve data usage security and reduce deployment difficulty has become an urgent problem to be solved.
It employs chips that support encrypted data transmission, including a secure microprocessor, a programmable electronic fuse, and a TMR unit. Data is transmitted in encrypted form through an encryption engine and an unmodifiable private key, ensuring that plaintext data can only be decrypted and used on specific devices.
It effectively prevents clients from abusing large model weight data, reduces data prices, adapts to market demands, lowers private deployment costs, and supports quantity-based billing strategies and trial services, thereby improving the ease of client deployment.
Smart Images

Figure CN120910922A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of information security, and in particular to a chip supporting data encrypted transmission and a data encrypted transmission method. BACKGROUND
[0002] With the development of artificial intelligence technology, large models with massive weight data have been gradually applied to intelligent interaction and other scenarios. Since the weight data of a large model is large, the training cost of the weight data of the large model is also high. Therefore, the service provider side often sells the trained weight data of the large model to different clients, and the clients can purchase the weight data of the large model for private deployment.
[0003] However, after the clients purchase the weight data of the large model, there may be misuse of the weight data of the large model, such as publicizing the data, which will cause great loss to the service provider side. In the existing method, the service provider side usually sets a high purchase price for the weight data of the large model to reduce the loss in the case of misuse. However, this method undoubtedly increases the difficulty of private deployment of the weight data of the large model for the clients.
[0004] Therefore, how to improve the security of data use and thus reduce the data selling price for the service provider side, that is, reduce the difficulty of private deployment of data, has become a problem to be solved. SUMMARY
[0005] To solve the above technical problems, an embodiment of the present application provides a chip supporting data encrypted transmission, which comprises a register access bus RN, a data access bus DN, N slave devices {slave1, slave2, …, slaveN}, M master devices {master1, master2, …, masterM} and a memory. n , …, slave N , …, master m , …, master M , wherein slave n is the nth slave device, n is an integer in the range of [1, N], master m is the mth master device, m is an integer in the range of [1, M].
[0006] The N slave devices, the M master devices, the eFUSE and the SMP are connected with the RN, the M master devices, the SMP and the memory are connected with the DN, and the N slave devices are used to provide cache space for the M master devices.
[0007] K encryption engines are included in the SMP, SMP={CE1, CE2, …, CE k , …, CE K}, wherein CE k is the kth encryption engine, k is an integer in the range of [1, K], and the encryption engine is used to decrypt encrypted data received by the chip to obtain a decryption result.
[0008] A specific private key that cannot be modified is burned in the eFUSE, and the eFUSE is used to provide the specific private key for the SMP as key information for decrypting the encrypted data, which is obtained by encrypting original data by a public key corresponding to the specific private key.
[0009] The TMR unit divides a privacy area in the memory, the privacy area can only be accessed by a specific host device, and the privacy area is used to store the decryption result.
[0010] Embodiment two of the present application provides a chip-based data encryption transmission method, which comprises:
[0011] S21, accepting symmetric ciphertext data bF encrypted by a symmetric encryption key bkey and asymmetric ciphertext data bF encrypted by an asymmetric encryption public key ckey j 0 encrypted by bkey j 0 and a chip D j 1 containing a specific asymmetric encryption private key ckey j , wherein j is an integer in the range of [1, J], J is the number of chips, ckey j 0 is the jth asymmetric encryption public key, ckey j 0 is the jth key ciphertext, ckey j 1 is the jth asymmetric encryption private key, ckey j 0 and ckey j 1 have a corresponding relationship, D j is the jth chip, the chip is a chip supporting data encryption transmission according to any one of claims 1 to 9, the chip comprises a secure microprocessor SMP, a programmable electronic fuse eFUSE, a TMR unit, and a nest, the TMR unit divides a privacy area and a shared area in the memory, the privacy area can only be accessed by a specific host device, and the privacy area is used to store the decryption result, ckey j 1Burned in the eFUSE of D j , ctext j 0 Stored in the shared area.
[0012] S22, using D j Decryption is performed on bF to obtain a decryption result.
[0013] The S22 step further comprises the following steps:
[0014] S221, D i SMP in SMP obtains ckey j 1 from the eFUSE.
[0015] S222, the SMP uses ckey j 1 to decrypt ctext j 0 stored in the shared area to obtain bkey.
[0016] S223, the SMP uses bkey to decrypt bF to obtain the decryption result.
[0017] S224, the decryption result is stored in the privacy area.
[0018] The present application has obvious beneficial effects compared with the prior art. By the above technical solution, the chip supporting data encryption transmission provided by the present application can achieve considerable technical progress and practicality, and has wide industrial utilization value. It has at least the following beneficial effects:
[0019] The present application provides a chip supporting data encryption transmission, which comprises a register access bus RN, a data access bus DN, N slave devices {slave1, slave2, …, slave n , …, slave N}, M master devices {master1, master2, …, master m , …, master M} and a memory. The chip further comprises a secure microprocessor SMP, a programmable electronic fuse eFUSE and a TMR unit, wherein slave n is the nth slave device, n is an integer in the range of [1, N], master m is the mth master device, m is an integer in the range of [1, M].
[0020] The N controlled devices, the M master devices, the eFUSE and the SMP are connected with the RN, the M master devices, the SMP and the memory are connected with the DN, and the N controlled devices are used for providing cache space for the M master devices.
[0021] The SMP includes K encryption engines, and the SMP={CE1, CE2, CE k , …, CE K}, wherein CE k is the kth encryption engine, k is an integer in the range of [1, K], and the encryption engine is used for decrypting encrypted data received by the chip to obtain a decryption result.
[0022] The eFUSE is burned with a specific private key that cannot be modified, and the eFUSE is used to provide the specific private key for the SMP as key information for decrypting the encrypted data, wherein the encrypted data is obtained by encrypting original data by a public key corresponding to the specific private key.
[0023] The TMR unit divides a privacy area in the memory, and the privacy area can only be accessed by a specific master device, and the privacy area is used to store the decryption result.
[0024] It can be known that the data is transmitted in an encrypted manner, and the client can avoid directly obtaining plaintext data and a key corresponding to the encryption information of the plaintext data, especially in the case that the security requirement of the plaintext data is high, in the embodiment, the plaintext data can be large model weight data, the large model weight data is transmitted in an encrypted manner, the client can avoid abusing the large model weight data, and the client can only use the large model weight data on the corresponding chip in the manner of jointly providing the chip and the ciphertext data to the client, so that the vender does not need to set a high data selling price to avoid abuse, thereby reducing the pricing of the large model weight data to meet the marginal cost and adapt to market demand, and since the chip provides security and use limitation for the large model weight data, the vender can adopt a quantity billing strategy to sell the large model weight data, thereby reducing the cost of private deployment of the large model, for example, a personal client can also perform private deployment by purchasing a small amount of large model weight data and chips, on the other hand, the scheme can support the vender to provide a trial service, that is, a small-scale inference cluster is formed by providing a small amount of chips and large model weight data, so that the client can decide whether to purchase a large-scale inference cluster according to the use condition, thereby improving the convenience of private deployment of the client. BRIEF DESCRIPTION OF DRAWINGS
[0025] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0026] Figure 1 This is a schematic diagram of the structure of a chip that supports encrypted data transmission according to Embodiment 1 of the present invention;
[0027] Figure 2 This is a flowchart illustrating a chip-based data encryption transmission method provided in Embodiment 2 of the present invention;
[0028] Figure 3 This is a flowchart illustrating a chip-based inference service verification method provided in Embodiment 3 of the present invention.
[0029] Figure 4 This is a schematic flowchart of a chip-based page table checking method provided in Embodiment 4 of the present invention;
[0030] Figure 5 This is a schematic diagram of the architecture of a chip-based data encryption transmission system provided in Embodiment 5 of the present invention;
[0031] Figure 6 This is a flowchart illustrating a data encryption method provided in Embodiment Six of the present invention;
[0032] Figure 7 This is a flowchart illustrating a chip-based encrypted reasoning method provided in Embodiment 7 of the present invention. Detailed Implementation
[0033] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0034] See Figure 1 This is a schematic diagram of the structure of a chip supporting encrypted data transmission according to Embodiment 1 of the present invention. The chip includes a register access bus RN, a data access bus DN, and N controlled devices {slave1, slave2, ..., slave...} n ..., slave N}, M master control devices {master1, master2, ..., master m ..., masterM} and a memory, the chip further comprising: a secure microprocessor SMP, a programmable electronic fuse eFUSE and a TMR unit, wherein, slave n is the nth controlled device, n is an integer in the range of [1, N], master m is the mth master device, m is an integer in the range of [1, M];
[0035] The N controlled devices, M master devices, eFUSE and SMP are connected with RN, the M master devices, SMP and memory are connected with DN, and the N controlled devices are used to provide cache space for the M master devices.
[0036] The SMP includes K encryption engines, SMP = {CE1, CE2, …, CE k , …, CE K}, wherein CE k is the kth encryption engine, k is an integer in the range of [1, K], and the encryption engine is used to decrypt encrypted data received by the chip to obtain a decryption result.
[0037] The eFUSE has a non-modifiable specific private key burned therein, and the eFUSE is used to provide a specific private key for the SMP as key information for decrypting the encrypted data, wherein the encrypted data is obtained by encrypting original data by a public key corresponding to the specific private key.
[0038] The TMR unit divides a privacy area in the memory, the privacy area can only be accessed by a specific master device, and the privacy area is used to store the decryption result.
[0039] Optionally, the master device master m corresponds to a unit identifier UnitID m , and the privacy area has an accessible identifier set AUnitID = {AUnitID1, AUnitID2, …, AUnitID w , …, AUnitID W}, when UnitID m ∈ AUnitID, the master m is the specific master device, and the privacy area allows the master m to access, wherein W is a positive integer, and w is an integer in the range of [1, W].
[0040] Specifically, the unit identifier corresponding to the master device and the accessible identifier set of the privacy area can be set by the SMP, and the SMP can control the access permission of different master devices to the privacy area by setting the accessible identifier set, so as to avoid that the data with high security requirement in the privacy area is accessed by the master device with low security level, and in this embodiment, the data with high security requirement can be the decryption result, thereby improving the security of data encryption transmission.
[0041] Optionally, the controlled device slave n corresponding to the first security level threshold mlevel n , the master device master m corresponding to the security level slevel n , when slevel n ≥ mlevel n , the master device master m is allowed to access the controlled device slave n .
[0042] Specifically, the first security level threshold and the security level corresponding to the master device can be set by the SMP, so as to control the access permission of different master devices to different controlled devices, so as to avoid that the intermediate data with high security requirement in the controlled device is accessed by the master device with low security level, and in this embodiment, the intermediate data with high security requirement can be the intermediate calculation data in the decryption calculation.
[0043] Optionally, the security level corresponding to the SMP is slevel N+1 , and the second security level threshold state is further included in the eFUSE, wherein state>max(slevel n ), n∈[1,N], when slevel N+1 ≥ state, the SMP is allowed to access the eFUSE.
[0044] Specifically, since state>max(slevel n ), the eFUSE does not allow any master device to access, and slevel N+1 ≥ state, which means that the eFUSE only allows the SMP to access.
[0045] Optionally, when the SMP updates state with nstate, if nstate>state, state is set to nstate in the eFUSE.
[0046] Specifically, since nstate>state, state=nstate in the eFUSE, so the eFUSE update can only increase its second security level threshold, but cannot decrease the second security level threshold, to avoid malicious update instructions to reduce the second security level threshold of the eFUSE to enable the host device with a poor security level to access the eFUSE.
[0047] Optionally, the M host devices at least include a DMA unit, a core computing unit Xcore and a CPU unit.
[0048] The DMA unit can be a direct memory access unit to provide high-speed data transmission between peripherals and memories or between memories, the core computing unit Xcore can be used for floating point calculation, texture unit and vertex processing tasks, and the CPU unit can provide instructions to be executed for the chip.
[0049] Optionally, the encryption engine CE k includes an asymmetric encryption algorithm RSA.
[0050] In an embodiment, the encryption engine can further include a hash algorithm SHA256, a symmetric encryption algorithm AES, etc., to provide signature verification, symmetric encryption, etc.
[0051] Optionally, the chip performs firmware signature verification at runtime.
[0052] Specifically, the chip needs to ensure the integrity of the program running to prevent the firmware application from being tampered with, so it needs firmware signature verification, to establish a trust relationship between the firmware and the application, so that unsigned firmware or programs will not be able to run on the chip, at this time, the firmware application can be signed using the firmware signature private key burned in the eFUSE to perform firmware signature verification at runtime.
[0053] Optionally, the SMP uses a RISC-V instruction set.
[0054] The RISC-V instruction set can be a modular instruction set architecture that allows the design of various microprocessors, in this embodiment, the SMP is designed by using the RISC-V instruction set.
[0055] In an embodiment, the memory can be first divided into a plurality of physical address segments as user storage areas, and then a dedicated privacy area and a shared area are divided for each user storage area, so as to adapt to the single-chip multi-user situation, so that the vender can provide chip rental services, while ensuring that data with high security requirements between different users cannot be obtained by other users, further enabling the vender to provide trial services for private deployment of large model weight data in a more lightweight scale.
[0056] Referring to Figure 2 , a flowchart of a chip-based data encryption transmission method is provided for Embodiment Two of the present application. Based on the chip for data encryption transmission provided in Embodiment One, the data encryption transmission method is applied to a client, and the data encryption transmission method comprises the following steps:
[0057] S21, the license Server deployed by the service provider side accepts the symmetric ciphertext data bF encrypted by the symmetric encryption key bkey and the asymmetric ciphertext data bF encrypted by the asymmetric encryption public key ckey sent by the service provider side vender through the license Server. j 0 The key ciphertext ctext obtained by encrypting bkey j 0 and the chip D containing the specific asymmetric encryption private key ckey j 1 j wherein j is an integer in the range of [1, J], J is the number of chips, ckey j 0 is the jth asymmetric encryption public key, ctext j 0 is the jth key ciphertext, ckey j 1 is the jth asymmetric encryption private key, ckey j 0 and ckey j 1 There is a corresponding relationship, D j is the jth chip, which is the chip supporting data encryption transmission as described in Embodiment One above, and the chip comprises a secure microprocessor SMP, a programmable electronic fuse eFUSE, a TMR unit, and a memory, wherein the TMR unit divides a private area and a shared area in the memory, the private area can only be accessed by a specific host device, and the private area is used to store the decryption result, ckey j 1 burned into the eFUSE of D j , ctext j 0 is stored in the shared area.
[0058] S22, decrypt bF using D j to obtain the decryption result.
[0059] The step S22 further comprises the following steps:
[0060] S221, the SMP in D i obtains ckey from the eFUSE.j 1 ;
[0061] S222, SMP uses ckey j 1 ctext stored in the shared area j 0 Decrypt to obtain bkey;
[0062] S223, SMP uses bkey to decrypt bF to obtain the decryption result;
[0063] S224, Store the decryption result in the privacy area.
[0064] Among them, ckey j 1 With D j There is a correspondence, meaning that different chips correspond to different asymmetric encryption private keys. This is because in asymmetric encryption algorithms, the public key and private key also have a one-to-one correspondence. j 1 Only can decrypt via ckey j 0 The encrypted key ciphertext ctext j 0 Each chip can be considered to possess a unique set of public and private keys. The private key is programmed into the chip's eFUSE, while the public key is provided by the chip to the service provider (vender). The service provider (vender) uses the received public key to encrypt the symmetric encryption key bkey, and then outputs the encrypted ctext. j 0 Transmitted to the client.
[0065] Specifically, due to ckey j 1 It is burned into the chip D i On top, that is, D i ckey on j 1 Unchangeable; the client obtains D i After that, only the ckey burned onto it can be used. j 1 And cannot directly read ckey j 1 .
[0066] In one implementation, a license server deployed on the service provider side receives the asymmetric encrypted public key akey sent by the service provider vendor. i 0 Encrypted data aFi 0 and a chip C comprising a specific asymmetric encryption private key akey i 1 i wherein C i comprises a secure microprocessor SMP, a programmable electronic fuse eFUSE and a memory, the memory comprising a private area and a shared area, wherein i is an integer in the range of [1, I], I is the number of chips, akey i 0 is the i-th asymmetric encryption public key, aF i 0 is the i-th encrypted data, akey i 1 is the i-th asymmetric encryption private key, akey i 1 and akey i 0 exist a corresponding relationship, C i is the i-th chip, using C i to decrypt aF i 0 , obtaining a decryption result, wherein the SMP in C i obtains akey i 1 from the eFUSE, the SMP uses akey i 1 to decrypt aF i 0 stored in the shared area, obtaining a decryption result, and stores the decryption result in the private area.
[0067] In an embodiment, when using at least two chips for mirror docker deployment, k8s pulls the corresponding key ciphertext ctext j 0 from the license server according to ckey j 0 .
[0068] This solution avoids the client directly obtaining plaintext data and the keys to the corresponding encrypted information, especially when plaintext data security requirements are high. In this embodiment, the plaintext data can be large model weight data. Encrypting the transmission of large model weight data prevents the client from abusing it. Furthermore, by providing the client with both encrypted data and chips, the client can only use the large model weight data on the corresponding chips. This eliminates the need for vendors to set high data prices to prevent abuse, thereby reducing the pricing of large model weight data to meet marginal costs and adapt to market demands. At the same time, since the chips provide security and usage restrictions for large model weight data, vendors can adopt a quantity-based billing strategy to sell large model weight data, reducing the cost of private deployment of large models. For example, individual clients can also perform private deployment by purchasing only a small amount of large model weight data and chips. On the other hand, this solution supports vendors in providing trial services, that is, providing a small number of chips and large model weight data to form a small-scale inference cluster. This allows clients to purchase additional large-scale inference clusters based on usage, improving the convenience of private deployment for clients.
[0069] See Figure 3 This is a flowchart illustrating a chip-based inference service verification method provided in Embodiment 3 of the present invention. This method is applied to a client and, based on the chip-based data encryption transmission method provided in Embodiment 2, further includes the following steps:
[0070] S31, Receive chip D provided by the chip supplier. i The inference service program kernel provided by the service provider vendor, the program signature ciphertext asign encrypted with the second private key dkey, and the public key ekey corresponding to dkey;
[0071] S32, from chip D i Verify the signature of the signature based on the ekey, where D i The i-th chip includes a programmable electronic fuse eFUSE, in which a third private key fkey is programmed.
[0072] S33, after verification and approval, by D i Execute kernel;
[0073] S34, D i Use the third private key fkey described in eFUSE to access D. i The firmware information is signed to obtain the firmware information signature ciphertext bsign;
[0074] S35, send the public key gkey corresponding to the firmware information, bsign and fkey to the vender, so that the vender verifies the bsign using the gkey.
[0075] Specifically, in the embodiment, the vender provides the client with the large model weight data and at the same time provides the inference service program, so that the client can apply the large model weight data for inference calculation, but after providing the inference service program, it is still necessary to avoid the client from tampering with the related data saved by the CPU host, and in the embodiment, the related data can include the driver, the MQL packet and the kernel object, so as to obtain the large model weight data plaintext by writing the large model weight data in the privacy area to the unsafe position, and in the embodiment, the unsafe position can refer to the shared area.
[0076] After the verification passes, the D i Execute the kernel, which can refer to moving the verified kernel to the memory of the privacy area, and use the address of the privacy area by the kernel driver (Kernel Mode Driver, KMD) to start the kernel.
[0077] Optionally, the chip further includes a secure processing unit SMP, and the step S32 further includes the following steps:
[0078] S321, the D i Hash the kernel by the SMP to obtain a first hash value;
[0079] S322, the SMP decrypts the asign using the ekey to obtain a second hash value;
[0080] S323, compare the first hash value and the second hash value, and if the comparison result is consistent, it is considered that the verification passes.
[0081] Optionally, the step S34 further includes the following steps:
[0082] S341, the D i Hash the firmware information by the SMP to obtain a third hash value;
[0083] S342, the SMP reads the fkey from the eFUSE;
[0084] S343, the SMP encrypts the third hash value using the fkey to obtain the bsign.
[0085] Optionally, the hash calculation uses the SHA256 algorithm.
[0086] In an embodiment, the hash calculation can also be implemented using MD5, SHA384, SHA512, and other hash algorithms, without limitation.
[0087] Optionally, the firmware information includes at least firmware status, timestamp, and firmware program.
[0088] The firmware status and firmware program can be used by the vender to verify whether the firmware has been tampered with by the client, and the timestamp can be used by the vender to verify whether the firmware usage time meets the provisions at the time of sale, so that the vender can provide large model weight data and inference service program according to the time limit and effectively supervise it, further improving the reliability of private deployment of large models.
[0089] Optionally, after receiving the firmware information, bsign, and gkey, the vender performs the following steps:
[0090] Hash calculation is performed on the firmware information to obtain a fourth hash value;
[0091] The bsign is decrypted using the gkey to obtain the third hash value;
[0092] The third hash value and the fourth hash value are compared, and if the comparison result is consistent, it is considered that the signature verification is passed.
[0093] Optionally, if the comparison result of the comparison of the third hash value and the fourth hash value is inconsistent, it is considered that the signature verification is not passed, and the vender stops providing the kernel through the license server.
[0094] Optionally, the vender performs signature verification on the received firmware information at a preset time point.
[0095] The vender can use a spot-checking method to verify the firmware information, that is, spot-checking verification is performed at a preset time point. Since the vender needs to provide data and services to different clients, the spot-checking method can better adapt to the vender and reduce the verification pressure of the vender. In this embodiment, the preset time point can be determined according to an initial time point atime and a time interval btime, and the preset time point ctime = atime + a * btime, where a is a positive integer. The implementer should know that the preset time point can also be determined by manually setting, and any method used by the implementer to determine the preset time point is within the scope of protection of the present scheme.
[0096] The embodiment verifies the inference service program kernel provided by the vender through the chip, and executes the kernel only after the verification is passed, thereby avoiding the tampering of the client to the kernel, and reducing the risk of the decryption result being read from the privacy area by the client, the encryption key being stolen, and other attacks. Meanwhile, the firmware information and the signature are provided to the vender, the vender can perform spot check verification on the firmware information to accurately obtain the firmware execution condition of the inference service program, and can also supervise the chip and data use timeout and the like.
[0097] Referring to Figure 4 A flowchart of a chip-based page table checking method is provided for the fourth embodiment of the present application. The method applies a chip, and based on the chip-based inference service verification method provided in the third embodiment, further includes the following steps:
[0098] S41, receiving program information kernel obj and a page table sent by a client, wherein the kernel obj at least includes address information of an inference service program kernel in a memory, and the page table includes an indication mapping relationship between a virtual address and a physical address;
[0099] S42, checking the page table using a preset mapping table to obtain a first checking result, wherein the preset mapping table includes a reference mapping relationship between a virtual address and a physical address;
[0100] S43, when the first checking result is passed, storing the page table in a privacy area of the memory;
[0101] S44, converting the address information belonging to the virtual address into a target physical address using a security management unit SMP;
[0102] S45, checking whether the target physical address is in the privacy area using the page table in the privacy area to obtain a second checking result;
[0103] S46, when the second checking result is passed, executing the kernel corresponding to the address information.
[0104] Optionally, the kernel obj is obtained by processing the inference service program kernel through a user interface driver UMD in the client.
[0105] The UMD can be used to allocate a buffer for the kernel.
[0106] Optionally, the virtual address comprises a privacy virtual address segment, the physical address comprises a privacy physical address segment, and the preset mapping table comprises a reference mapping relationship mapping1 between the privacy virtual address segment and the privacy physical address segment, and the page table comprises an indication mapping relationship mapping2 between the privacy virtual address segment and the privacy physical address segment.
[0107] Optionally, the first check result is passed when the condition mapping2 mapping1 is met.
[0108] When mapping2 mapping1, it is indicated that the execution mapping relationship of the privacy virtual address segment to the privacy physical address segment in the page table has been defined in the preset mapping table, and at this time, the content of the privacy region will not be mapped to the shared region, and it can be considered that the content of the privacy region is safe.
[0109] Optionally, converting the address information belonging to the virtual address into the target physical address using the security management unit SMP comprises:
[0110] The address information belonging to the virtual address is converted into the target physical address using the TestXVM Function in the encryption engine CE in the SMP.
[0111] Optionally, the second check result is passed when the condition that the target physical address is in the privacy region is met.
[0112] Optionally, the kernel obj further comprises an execution mode.
[0113] The execution mode can include kernel execution, data copying, etc.
[0114] In this embodiment, in the case that the client can tamper with the page table to make the chip write the data in the privacy region to the insecure shared region, the range of the privacy region is determined by the preset mapping table agreed by the chip manufacturer and the vender, and then it is checked whether the obtained page table is compliant according to the mapping range of the privacy region corresponding address segment in the preset mapping table, thereby avoiding the risk of tampering with the page table, and the target physical address is checked before execution, thereby avoiding the risk of executing the unagreed kernel by the chip, and effectively avoiding the case that the client tampers with the page table to steal the data with higher security.
[0115] Referring to Figure 5For the fifth embodiment of the present application, a chip-based data encryption transmission system is provided, which comprises a CPU module and a GPU module, wherein the CPU module comprises a host memory, and the GPU module comprises a core computing unit Xcore, a security management unit SMP and a GDDR display memory;
[0116] The host memory is configured to store ciphertext data xdata and an inference service program kernel;
[0117] The GDDR display memory comprises a private area and a shared area, and the shared area is configured to communicate with the host memory to obtain the xdata;
[0118] The shared area is configured to store the xdata and a to-be-verified ring buffer, and the to-be-verified ring buffer is obtained by processing the kernel by the CPU module and then sent to the shared area;
[0119] The private area is configured to store the kernel in an experienced signature ring buffer, and the experienced signature ring buffer is a result of signature verification on the to-be-verified ring buffer by the SMP;
[0120] The Xcore comprises a shared memory, and the shared memory is configured to store decrypted data ydata, which is obtained by decrypting the xdata by the Xcore.
[0121] Optionally, the host memory is further configured to store signature ciphertext, which is provided to the SMP to perform signature verification on the to-be-verified ring buffer.
[0122] Optionally, the GPU module further comprises a data transmission unit DMA, which is configured to perform data transmission between the host memory and the shared area.
[0123] Optionally, the shared area is further configured to store a page table, computing intermediate data of the Xcore and multi-card inference intermediate data.
[0124] Optionally, the SMP and the Xcore are connected with the GDDR display memory only.
[0125] Optionally, the SMP is further configured to divide the GDDR display memory into the private area and the shared area.
[0126] Optionally, the shared area communicates with the host memory through PCIe.
[0127] It should be noted that the scheme can be applied to a graphics card using less secure video memory, and GDDR video memory is only an example and is not limited to GDDR video memory. Less secure video memory can also include DDR video memory and the like.
[0128] In this embodiment, for the case of using GDDR video memory and the like less secure video memory for GPU module, since the data transmission process of GDDR is easy to be stolen, the default GDDR memory is not secure enough. In such a case, Xcore is prohibited from communicating with the host memory to avoid xcore directly writing the decrypted data to the insecure host memory. In addition, unlike the above embodiment, the privacy area is only used to store the kernel and not the decrypted data, thereby avoiding the case that the decrypted data is read on the GDDR video memory. It should be noted that when applied to large model weight data, since Xcore needs to be frequently swapped in and out, and shared memory can only store a small amount of data, when swapping in and out, the data needs to be decrypted to obtain new data, thereby sacrificing part of the inference efficiency, but effectively improving the security of data in the GDDR video memory environment.
[0129] Referring to Figure 6 A data encryption method provided by the sixth embodiment of the application is applied to a service provider side vender. On the basis of the data encryption transmission method based on a chip provided in the above-mentioned second embodiment, the method further includes the following steps:
[0130] S61, performing P times random sampling on the original weight data Odata={odata1, odata2, …, odataQ} to obtain P sampling results, wherein odataq is the qth weight, and q is an integer in the range of [1, Q]; q Q q
[0131] S62, performing occlusion processing on the P sampling results in Odata to obtain occlusion data Mdata;
[0132] S63, configuring a preset model using Mdata;
[0133] S64, performing an inference service program kernel on a verification sample using the configured preset model to obtain an inference result out1;
[0134] S65, calculating a difference degree value between the real inference result out2 corresponding to the verification sample and out1;
[0135] S66, when the difference degree value is greater than a preset threshold, encrypting the sampling result using a symmetric key gkey to obtain symmetric ciphertext data gtext;
[0136] S67, sending gtext, Mdata, the asymmetric encryption public key hkey, the key ciphertext htext obtained by encrypting gkey using hkey, and the chip burned with the asymmetric encryption private key ikey corresponding to hkey to the client.
[0137] Optionally, the original weight data Odata = {odata1, odata2, …, odata q , …, odata Q} is subjected to P times of random sampling to obtain P sampling results, including:
[0138] Taking 1 / P as the sampling probability of each weight;
[0139] According to the sampling probability of all weights, the weights in Odata are subjected to P times of random sampling to obtain the P sampling results.
[0140] Optionally, when the P sampling results do not satisfy a preset condition, returning to execute step S61.
[0141] Specifically, in an embodiment, the implementer can also sequentially perform P times of non-replacement sampling on the weights in Odata to directly obtain P sampling results different from each other, and the sampling probability of each unsampled weight is 1 / R, R being the number of unsampled weights.
[0142] Optionally, the preset condition is that the P sampling results are different from each other.
[0143] Optionally, the P sampling results in Xdata are subjected to occlusion processing to obtain occlusion data Mdata, including:
[0144] Setting the weight corresponding to the sampling result in Odata to a preset value to obtain Mdata.
[0145] Optionally, the preset value is set to zero.
[0146] Specifically, for example, if odata1 is a sampling result, then Mdata = {0, odata2, …, odata q , …, odata Q}.
[0147] Optionally, the difference degree value is calculated using the Euclidean distance.
[0148] Optionally, when the difference degree value is less than or equal to a preset threshold, returning to perform S61.
[0149] Specifically, when the difference degree value is less than or equal to a preset threshold, it indicates that the weights blocked at this time are difficult to effectively affect the inference accuracy of the weight data, and at this time, only encrypting the sampling result cannot play an encryption effect.
[0150] Optionally, the client decrypts htext using ikey to obtain gkey;
[0151] Decrypt gtext using gkey to obtain the sampling result;
[0152] According to the sampling result and Mdata, determine Odata, Odata is used to configure the local model of the client to execute kernel.
[0153] In the embodiment, the encryption processing of the large model weight data is performed by encrypting part of the weight data, which reduces the calculation amount of encryption and decryption while ensuring the encryption effect, improves the efficiency of the data encryption and decryption process, and for example, when facing the situation described in Embodiment Five, the data encryption transmission scheme can be effectively applied to chips using GDDR memory and other less secure memory.
[0154] Referring to Figure 7 A flowchart of an encryption inference method based on a chip provided by Embodiment Seven of the present application, based on the data encryption transmission method provided by Embodiment Two, further includes the following steps:
[0155] S71, receiving the first parameter ciphertext itext, the second parameter ciphertext jtext, the key ciphertext ktext encrypted by the asymmetric encryption private key lkey of the symmetric key jkey, the plaintext weight data Ndata, the plaintext bias data Rdata, and the chip provided by the chip supply side and burned with the corresponding lkey asymmetric encryption private key mkey sent by the service provider side vender;
[0156] S72, using the mkey in the chip to decrypt ktext to obtain jkey;
[0157] S73, using jkey to decrypt itext and jtext to obtain the first parameter β and the second parameter γ;
[0158] S74, multiplying β and Ndata to obtain the first multiplication result as the inference weight data Pdata;
[0159] S75, multiply the gamma and the Rdata to obtain a second multiplication result as inference bias data Qdata;
[0160] S76, according to the Pdata and the Qdata, execute the inference service program.
[0161] Optionally, the chip comprises an eFUSE, and the mkey is burned in the eFUSE.
[0162] Optionally, the chip further comprises a secure microprocessor SMP, and the SMP is used for decryption operation.
[0163] Optionally, the eFUSE can only be accessed by the SMP.
[0164] Optionally, the chip further comprises a TMR unit and a memory, and the TMR unit divides a privacy area in the memory, and the privacy area is used for storing the beta and the gamma.
[0165] Optionally, the TMR unit further divides a shared area in the memory, and the shared area is used for storing the itext, the jtext, the ktext, the Ndata and the Rdata.
[0166] Optionally, the chip further comprises a core computing unit Xcore, and the Xcore is used for executing the inference service program according to the Pdata and the Qdata.
[0167] Optionally, the Xcore accesses the shared area to obtain the Ndata and the Odata, and accesses the privacy area to obtain the beta and the gamma, and the steps S74 to S76 are executed by the Xcore.
[0168] In the embodiment, by changing the calculation method of the inference service program, a new first parameter and a second parameter are additionally added, only the first parameter and the second parameter are encrypted, and the weight and the bias conforming to the inference service program can be recovered at the client, the calculation amount of encryption and decryption is greatly reduced while ensuring the encryption effect, the efficiency of the data encryption and decryption process is improved, and in the case of multiple clients, the service provider vender can provide different first parameters and second parameters and corresponding plaintext weight data and plaintext bias data for different clients, so that the data provided by the vender can be effectively prevented from being misused.
[0169] While certain specific embodiments of the application have been described in detail herein for the purposes of exemplification, numerous other variations and modifications will be apparent to persons skilled in the art. Alterations and modifications of detail can be made by those skilled in the art, having the benefit of the above description, without departing from the spirit and scope of the application. It is intended that all such alterations and modifications be included within the scope of the application whose limits are to be determined only by the appended claims.
Claims
1. A chip supporting encrypted data transmission, the chip comprising a register access bus RN, a data access bus DN, and N controlled devices {slave1, slave2, ..., slave...} n ..., slave N }, M master control devices {master1, master2, ..., master m ..., master M } and memory, characterized in that, The chip further comprises a secure microprocessor SMP, a programmable electronic fuse eFUSE and a TMR unit, wherein the slave n For the nth controlled device, n is an integer in the range of [1, N], master m For the mth master device, m is an integer in the range of [1, M]. The N controlled devices, the M master devices, the eFUSE and the SMP are connected with the RN, the M master devices, the SMP and the memory are connected with the DN, and the N controlled devices are configured to provide cache space for the M master devices; SMP includes K encryption engines, SMP = {CE1, CE2, ..., CE...} k , ..., CE K }, where CE k Here, k is the kth encryption engine, where k is an integer in the range [1, K]. The encryption engine is used to decrypt the encrypted data received by the chip to obtain the decryption result. The eFUSE is burned with a specific private key which cannot be modified, and the eFUSE is configured to provide the specific private key for the SMP as key information for decrypting the encrypted data, wherein the encrypted data is obtained by encrypting original data by a public key corresponding to the specific private key; The TMR unit divides a privacy area in the memory, the privacy area can only be accessed by a specific master device, and the privacy area is configured to store the decryption result.
2. The chip supporting data encrypted transmission according to claim 1, characterized in that, master m corresponding to the unit identifier UnitID m , the accessible identifier set AUnitID of the privacy area is AUnitID = {AUnitID1, AUnitID2, …, AUnitID w , …, AUnitID W}, when UnitID m ∈ AUnitID, the master m is allowed to access by the privacy area as the specific master m , wherein W is a positive integer, and w is an integer in the range of [1, W].
3. The chip supporting data encrypted transmission according to claim 1, characterized in that, slave n corresponding to a first security level threshold mlevel n master m corresponding to a security level slevel n when slevel n ≥ mlevel n , master m is allowed to access slave n .
4. The chip supporting the encrypted transmission of data according to claim 3, characterized in that, The security level corresponding to the SMP is slevel N+1 The second security level threshold state is further included in the eFUSE, where state>max(slevel n ), n∈[1, N], and the SMP is allowed to access the eFUSE when slevel N+1 ≥state.
5. The chip supporting the encrypted transmission of data according to claim 4, characterized in that, When the SMP updates the state by nstate, if nstate>state, the state is set as nstate in the eFUSE.
6. The chip supporting a data encrypted transmission according to claim 1, characterized in that, The M master devices at least include a DMA unit, a core calculation unit Xcore and a CPU unit.
7. The chip supporting a data encrypted transmission according to claim 1, characterized in that, The encryption engine CE k at least an asymmetric encryption algorithm RSA.
8. The chip supporting a data encrypted transmission according to claim 1, characterized in that, The chip performs firmware signature verification when running.
9. The chip supporting a data encrypted transmission according to claim 1, characterized in that, The SMP uses a RISC-V instruction set.
10. A method for chip-based data encryption transmission, characterized in that, The data encryption transmission method comprises the following steps: S21, receiving symmetric cipher data bF encrypted by symmetric encryption key bkey and asymmetric cipher data encrypted by asymmetric encryption public key ckey sent by service supply side vendor j 0 Key cipher ctext encrypted by bkey j 0 and chip D containing specific asymmetric encryption private key ckey j 1 j wherein j is an integer in the range of [1, J], J is the number of chips, ckey j 0 is the jth asymmetric encryption public key, ctext j 0 is the jth key cipher, ckey j 1 is the jth asymmetric encryption private key, ckey j 0 and ckey j 1 have a corresponding relationship, D j is the jth chip, the chip is a chip supporting data encrypted transmission according to any one of claims 1 to 9, the chip comprises a secure microprocessor SMP, a programmable electronic fuse eFUSE, a TMR unit and a memory, the TMR unit divides a private area and a shared area in the memory, the private area can only be accessed by a specific host device, the private area is used to store the decryption result, ckey j 1 is burned in the eFUSE of D j , ctext j 0 is stored in the shared area; S22, using D j decrypting the bF to obtain a decryption result; The S22 step further comprises the following steps: S221, D i SMP in S221 gets ckey from eFUSE j 1 ; S222, SMP uses ckey j 1 ctext stored in the shared area j 0 Decrypt to obtain bkey; S223, the SMP decrypts the bF by using the bkey to obtain the decryption result; S224, the decryption result is stored in the privacy area.