AI agent data protection method and device based on controlled execution environment

By integrating TEE and eBPF technologies into the AI ​​agent, a controlled execution environment is constructed, solving privacy and compliance issues in the AI ​​agent and achieving full lifecycle data protection and compliance.

CN120915513AActive Publication Date: 2025-11-07NANKAI UNIV

Patent Information

Application Number
CN202511057920.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-30
Publication Date
2025-11-07
Estimated Expiration
2045-07-30

AI Technical Summary

Technical Problem

Existing technologies cannot effectively address privacy and compliance issues in AI agents, especially due to the lack of observable, interventionist, and verifiable means in the data processing process. Traditional methods are also unable to meet the compliance requirements of regulations such as GDPR and HIPAA.

Method used

By combining Trusted Execution Environment (TEE) and Extended Berkeley Packet Filter (eBPF) technologies, a controlled execution environment is constructed. Through a security decision monitoring module, the behavior of the AI ​​agent and data flow are monitored and verified in real time to ensure the security and compliance of the data processing process.

Benefits of technology

It achieves a trusted, observable, and revocable privacy sandbox for the entire lifecycle of the AI ​​agent, ensuring data confidentiality and compliance, preventing privacy data leakage and unauthorized access, and meeting regulatory requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915513A_ABST
    Figure CN120915513A_ABST
Patent Text Reader

Abstract

The invention discloses an AI agent data protection method and device based on a controlled execution environment, and the method comprises the steps: verifying the integrity of a safety decision monitoring module in each service node kernel of a cloud side through a remote authentication service in a trusted execution environment, and verifying whether the service nodes of the cloud side are all operated in the trusted execution environment or not; the starting environment is safe and credible; the cloud side receives the security configuration from the user side and distributes the security configuration to the security decision monitoring module of each service node; firstly, security check is executed on a service request to be sent by an AI agent, the service request is received by a cloud side service node after compliance, and a security decision monitoring module of a cloud side gateway service node intercepts a received network packet and judges whether the service request is normal traffic; when other service node services of the cloud need to be called, continuing to judge whether the traffic meets the security configuration configured by the user; and the security decision monitoring module is established based on an eBPF and is used for intercepting a received or sent network packet and realizing verification and auditing functions.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of AI large model and data security, and particularly relates to an AI agent data protection method and device based on a controlled execution environment for behavior monitoring and data protection of an AI agent. BACKGROUND

[0002] In recent years, AI agents driven by large language models (LLMs) have rapidly popularized in scenarios such as intelligent customer service, code generation, and knowledge question answering. A typical AI agent architecture consists of three layers: perception, reasoning, and action. The perception layer is responsible for collecting user input and context, the reasoning layer calls cloud-based large models to complete understanding and decision-making, and the action layer calls external tools or APIs to complete the final task. Under this architecture, user original text, conversation history, and even enterprise private domain knowledge need to be explicitly stored in the cloud, resulting in a sharp increase in privacy leakage risks. On the one hand, model providers may retain or resell data under the pretext of fine-tuning or log analysis. On the other hand, the long chain and multiple entry points of the agent action layer for calling third-party plugins further expand the attack surface. Regulations such as GDPR and HIPAA require "data minimization, auditability, and revocability", and traditional governance models relying on contract clauses or organizational processes have been unable to meet compliance demands.

[0003] To reduce privacy risks, the industry has proposed differential privacy, federated learning, and homomorphic encryption schemes. Differential privacy protects individual records by injecting noise into gradients or outputs, but there is an inherent contradiction between noise and utility, and it cannot prevent overall data set leakage caused by model memory. Federated learning distributes the training process to terminals, reducing the storage of the original data set, but it brings communication overhead, slow model convergence, gradient inversion attacks, and other problems. Homomorphic encryption can achieve "calculable but invisible", but it is limited by the type of calculation and performance bottlenecks, making it difficult to cover the complex multi-round reasoning and tool call chain of AI agents. The above methods all stay at the "protect data" level and lack observable, intervenable, and verifiable means for AI agent runtime behavior.

[0004] Trusted Execution Environment (TEE) is a hardware-level isolation mechanism provided by the CPU, which creates an encrypted memory area inside the processor (such as Intel TDX, AMD SEV-SNP, ARM CCA) to ensure the confidentiality and integrity of code and data at runtime, and resist OS, Hypervisor, and even physical bus monitoring attacks. TEE has been widely used in key management, cryptocurrency wallet, privacy computing, and other fields. By introducing TEE into the AI agent service, the "perception-reasoning-action" full-link critical logic (such as prompt construction, model reasoning, tool invocation) can be encapsulated into a trusted domain:

[0005] Prevent raw data from being stolen in DRAM using memory encryption;

[0006] Verify the reasoning code to the user through Remote Attestation that it has not been tampered with;

[0007] Complete data desensitization, access control, and audit log generation within the trusted domain to achieve "data usability and invisibility".

[0008] However, TEE itself lacks fine-grained observability of system behavior and cannot perceive the indirect effects of external untrusted components (such as container runtime, network protocol stack) on the agent.

[0009] Extended Berkeley Packet Filter (eBPF) is a security bytecode virtual machine in the Linux kernel that can dynamically hook system calls, network protocol stacks, file systems, schedulers, and other critical paths without modifying or recompiling the kernel. It can achieve real-time tracking and policy execution with millisecond-level overhead. eBPF programs are verified by a static verifier to ensure that they do not crash the kernel and have been widely used in observability (Cilium, Falco), network policy (Calico), security audit (Tracee), and other scenarios. In the AI agent service, eBPF can be used to:

[0010] Dynamically capture the system call sequence of the agent process, identify unauthorized file reading and writing, and abnormal network connections;

[0011] Inject policies at the socket layer to block HTTP / gRPC outbound traffic containing sensitive information;

[0012] Trace the data flow path between containers and pods, generate a timestamped audit graph, and use it for post-tracing.

[0013] In summary, the privacy and compliance of AI agents are not only about static encryption of data, but also about uncontrolled runtime behavior. TEE provides a "trusted execution boundary", and eBPF provides a "system-level behavior visibility and intervention" capability. The two complement each other but have not yet formed a systematic solution in the AI agent scenario. Therefore, a controlled execution environment that combines TEE and eBPF is needed to achieve a trusted, observable, and revocable privacy sandbox for the entire life cycle of AI agents. SUMMARY

[0014] In order to better solve the behavior monitoring and data privacy protection problem in AI agent service, and enhance the effective data flow monitoring and management mechanism, the application provides an AI agent data protection method and device based on a controlled execution environment, which combines a trusted execution environment and eBPF technology to effectively realize the controllability and auditability of data.

[0015] The first aspect of the application is to provide an AI agent data protection method based on a controlled execution environment, comprising:

[0016] Step one: In the trusted execution environment, verify the integrity of the security decision monitoring module in the kernel of each service node on the cloud side through the remote authentication service, and verify whether each service node on the cloud side is running in a trusted execution environment (TEE) and whether the startup environment is secure and trusted. If the above three verification conditions are passed, execute the next step, otherwise, if any of the verification conditions is not met, do not send the request;

[0017] Step two: the cloud side receives the security configuration from the user side, and distributes it to the security decision monitoring module of each service node; wherein each service node on the cloud side is deployed in a trusted execution environment, and the kernel of each trusted execution environment is deployed with the security decision monitoring module;

[0018] Step three: the AI agent is deployed in a trusted execution environment containing the security decision monitoring module; before the AI agent sends a service request, the security decision monitoring module will first perform a security check on the service request to determine whether the request is compliant, if so, execute the next step, otherwise, do not send the request;

[0019] Step four: the cloud side service node receives the service request from the AI agent, and the security decision monitoring module deployed in the kernel of the gateway service node on the cloud side first intercepts the received network packet to determine whether the service request from the AI agent is normal traffic or abnormal traffic. If it is normal traffic, the security decision monitoring module releases the network packet, otherwise, the security decision monitoring module discards the network packet and triggers an alarm;

[0020] If it is necessary to call other service nodes of the cloud, it is judged whether the traffic meets the security configuration configured by the user;

[0021] If yes, the security decision monitoring module in the gateway service node records audit information (such as traffic path information), combines the audit information into the original network packet, reconstructs a new network packet, and sends the new network packet to the target service node;

[0022] Otherwise, the security decision monitoring module discards the network packet and triggers an alarm to inform the user of the violation information;

[0023] The security decision monitoring module is established based on an extended Berkeley Packet Filter (eBPF) and is used to intercept received or sent network packets to realize verification and audit functions.

[0024] Further, the steps of receiving and sending network packets between the service nodes on the cloud side include:

[0025] The service node on the cloud side receives network packets from the gateway service node or from other service nodes, and the security decision monitoring module of the service node receiving the network packets first intercepts, judges whether the traffic meets the security configuration configured by the user, and if yes, releases the network packet and updates the traffic path audit information; otherwise, discards the network packet and triggers an alarm.

[0026] All steps of the data protection method are deployed in a trusted execution environment.

[0027] Further, the service request contains user identity information, service demand, and required service node information.

[0028] Further, the abnormal traffic refers to a case where a service node sends private data to a node that does not meet the security configuration or even a third-party entity.

[0029] The second aspect of the application provides an AI agent data protection device based on a controlled execution environment, which includes an authentication module and a security decision monitoring module;

[0030] Among them, the connection between the user side and the cloud side and between the service nodes on the cloud side is controlled by the authentication module, and the behavior monitoring and auditing are performed by the security decision monitoring module; the AI agent, the gateway service node, and the service nodes on the cloud side are all deployed in a trusted execution environment, and the security decision monitoring module is deployed in the kernel of each trusted execution environment;

[0031] The authentication module is used for the user terminal side device to verify the integrity of the security decision monitoring module of the cloud side through a remote authentication service, to verify whether the service nodes of the cloud side are all running in a trusted execution environment (TEE), and whether the starting environment is safe and credible; if yes, the service request is executed normally, and if no, the request is not sent;

[0032] The security decision monitoring module is used for intercepting the received or sent network packets, judging whether the intercepted network packets are in line with the security configuration, triggering an alarm if it is abnormal traffic, and releasing the network packets and recording audit information if it is normal traffic, and merging the audit information into the original network packets to reconstruct a new network packet and send it to the target service node.

[0033] The security decision monitoring module can realize verification and audit functions; the traffic between the user terminal side service application and the cloud side service node and the traffic between the cloud side service nodes are verified and audited through the security decision monitoring module.

[0034] Furthermore, the end side user formulates the security configuration according to the service function and privacy demand, and embeds the security configuration into the security decision monitoring module of the end side trusted execution environment and the security decision monitoring module deployed in the kernel of the cloud side service node, and the security configurations of the security decision monitoring modules deployed in the whole device are the same.

[0035] Further, the data protection device further comprises a security configuration module, which is used for distributing the security configuration provided by the user terminal side to all the security decision monitoring modules.

[0036] The data protection device also realizes the separation and cooperation of the security configuration customization and execution of the end side and the cloud side, that is, the formulation of the security configuration of the user terminal side and the execution of the security configuration of the cloud side, and the user can configure the required security configuration on the end side, and it can be ensured that the configuration can be correctly and credibly executed.

[0037] The traffic between the cloud side service nodes is completely verified and audited by the security decision monitoring module, and the security configuration is embedded in the security decision monitoring module of each cloud service node, only the traffic allowed by the configuration is released by the security decision monitoring module and the audit information is recorded, otherwise it will be discarded and an alarm will be triggered.

[0038] Further, the security configuration is uploaded to the cloud by the user terminal through a secure channel.

[0039] The remote authentication service provides the security proof and audit information of the cloud service to the user terminal side; wherein the security proof includes the integrity proof of the starting environment and the related open source code, and the audit information at least includes the data flow path.

[0040] To achieve the above object, the third aspect of the present application provides an electronic device, comprising: at least one processor; and a memory connected with the at least one processor in communication; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method of the first aspect.

[0041] To achieve the above object, the fourth aspect of the present application provides a non-transitory computer readable storage medium storing computer instructions for causing the computer to execute the method of the first aspect.

[0042] The present application has the following beneficial effects:

[0043] The present application provides a secure isolation environment for data processing according to the security configuration made by the user or the terminal manufacturer, in combination with the trusted execution environment (TEE), and realizes the confidentiality of the whole process of data processing on the cloud.

[0044] The cloud side uses a security decision monitoring module constructed based on the eBPF technology to perform real-time monitoring on the network communication between services, execute verification and audit of the traffic, dynamically track the flow path of the data, and ensure that the traffic will not violate the established security configuration.

[0045] The TEE provides a trusted isolation environment for the data processing process, guarantees the integrity and reliability of the execution of the core logic, and assists the end-side audit work with the help of the remote authentication protocol. BRIEF DESCRIPTION OF DRAWINGS

[0046] Figure 1 is a flowchart of the AI agent data protection method based on the controlled execution environment according to the method of embodiment 1 of the present application;

[0047] Figure 2 is a flowchart of the sending / receiving network packet of each service node of the cloud side in the method according to embodiment 1 of the present application;

[0048] Fig. 3 is a working process of the security decision monitoring module in the step of the cloud side request in the method according to embodiment 1 of the present application, wherein Figure 3a is a flowchart of sending network packets, Figure 3b is a flowchart of receiving network packets. DETAILED DESCRIPTION

[0049] To make the purposes, technical solutions, beneficial effects and significant progress of the embodiments of the present application clearer, below, the technical solutions in the embodiments of the present application will be clearly and completely described with reference to the drawings provided in the examples of the present application. Obviously, all the described embodiments are only part of the embodiments of the present application, rather than all the embodiments; based on the examples in the present application, all other embodiments obtained by those skilled in the art without creative labor according to the content and embodiments of the present application and the drawings all belong to the scope of protection of the present application.

[0050] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data for analysis, stored data, displayed data, etc.) and signals involved in the present application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards of relevant countries and regions.

[0051] It should also be noted that the following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.

[0052] Embodiment 1

[0053] As shown in Figure 1 , an AI agent data protection method based on a controlled execution environment, wherein the end side and the cloud side are deployed in a TEE environment to assist in establishing user side trust; specifically including:

[0054] Step 1. Steps of remote authentication service:

[0055] The user end side device first verifies the integrity of the security decision monitoring module on the cloud side through the remote authentication service, ensures that the security decision monitoring module on the cloud side has not been tampered with, to ensure the correct execution of the key code logic; at the same time, it also needs to ensure that the service nodes involved are running in a trusted execution environment (TEE), and whether the startup environment is safe and trustworthy, to ensure the integrity of the initial state of the system and the trustworthiness of the system running.

[0056] The end side user formulates its own security configuration according to the service functions it needs to use and privacy requirements, and embeds it into the security decision monitoring module deployed inside the TEE of the end side AI intelligent agent, and the security decision monitoring module deployed in the kernel of each service node on the cloud side.

[0057] The cloud-side service nodes are deployed in a TEE, and a security decision monitoring module is deployed in the TEE of each cloud-side service node, which can intercept all network traffic, verify and audit the privacy data network packet, ensure that the traffic between services is limited to authorized nodes, and prevent unauthorized service nodes or entities from accessing sensitive data.

[0058] The end-side AI agent is deployed in a trusted execution environment to prevent malicious disclosure of collected user privacy data. When the agent sends a service request, the security decision monitoring module first performs a security check on the request to determine whether it is compliant, and only allows compliant requests to pass. Non-compliant requests are recorded and an alarm is triggered in a timely manner to protect the privacy and security of user data.

[0059] After confirming compliance, the end-side AI agent sends the service request to the cloud service through a secure channel to ensure the confidentiality of the privacy data during transmission. All network traffic between cloud-side service nodes is verified and audited by the security decision monitoring module to ensure that only traffic that complies with the security configuration can be released, ensuring that the preset security configuration is correctly executed.

[0060] When the cloud service node processes the request, if it needs to call an external service and the service is authorized in the security configuration, the service can access and use the user privacy data. For example, if the user allows the A service to access the data, the security decision monitoring module in the service node will release the network packet, and the corresponding security decision monitoring module in the A service node will also release the network traffic to allow the application layer service to process it, ensuring the successful execution of the service request. Conversely, when a service node behaves maliciously and wants to send privacy data to a node that does not comply with the security configuration or even a third-party entity, the system can still ensure the security of the privacy data. For example, the user chooses not to enable the B service, and since this traffic is prohibited in the security configuration, the security decision monitoring module in the service node will intercept and discard the network packet, thus intercepting malicious operations and preventing unauthorized access, ensuring data privacy compliance.

[0061] Step 2. Upload security configuration:

[0062] The user uploads the custom security configuration to the security decision monitoring module in the cloud-side gateway service node and each cloud-side service node. The security configuration specifies that the B service node cannot use user privacy data, which is abnormal traffic, and the A service node can use user privacy data for processing, which is normal traffic.

[0063] Step 3. End-side request:

[0064] The end-side AI agent is deployed in a trusted execution environment ( Figure 1The inside of the dashed box on the middle end side is the trusted execution environment, which prevents malicious disclosure of collected user privacy data. When the agent sends a service request, the security decision monitoring module in the trusted execution environment on the end side first performs a security check on the request to determine whether it is compliant, and only allows compliant requests to pass. Non-compliant requests are recorded and an alarm is triggered in a timely manner to protect the privacy and security of user data.

[0065] The service request contains user identity information, service requirements, and required service node information, which is uploaded through a secure channel to ensure the confidentiality of privacy data during transmission. The AI agent in this context refers to an agent system that uses existing large models to understand user requirements to achieve the goal of executing tasks. Since the agent is not the focus of the invention, it is not limited here.

[0066] Step 4. Processing steps when the user layer service application sends network packets to the cloud side gateway service node:

[0067] The cloud side gateway service node receives service requests from the end side, first uses the security decision monitoring module deployed in the trusted execution environment ( Figure 1 The inside of the two dashed boxes on the middle cloud side is the trusted execution environment) to verify whether the application received from the user end side is normal traffic or abnormal traffic. If it is normal traffic, it is determined that the service has the right to use user privacy data. If it is abnormal traffic, the security decision monitoring module in the gateway service node kernel will discard the relevant network packet and trigger an alarm.

[0068] Step 5. Steps for processing by each service node on the cloud side:

[0069] When other cloud service nodes need to be called, it is necessary to continue to determine whether the traffic meets the user's configured security configuration;

[0070] If so, the security decision monitoring module in the gateway service node records audit information (such as traffic path information), merges the audit information into the original network packet, and reconstructs a new network packet to send to the target service node;

[0071] Otherwise, the security decision monitoring module will discard the network packet and trigger an alarm to inform the user of the violation information.

[0072] The security decision monitoring module uses the extended Berkeley Packet Filter (eBPF) technology to realize real-time monitoring and dynamic tracking of data flow paths, and the security decision monitoring module based on eBPF is deployed in each service node on the cloud side. The working process of the security decision monitoring module includes:

[0073] For example Figure 3aAs shown, when the gateway service node sends a network packet to other service nodes on the cloud side, it is first intercepted by the security decision monitoring module, and the traffic is judged according to the audit information and security configuration. If it is normal traffic, the audit information and the original network packet P1 are reconstructed to form a new network packet P2, and then sent to other service nodes through the security decision monitoring module. If it is abnormal traffic, the network packet is discarded and an alarm is triggered.

[0074] As shown in Figure 3b As shown, when the gateway service node sends a network packet to other service nodes on the cloud side, it is first intercepted by the security decision monitoring module, and the traffic is judged according to the audit information and security configuration. If it is normal traffic, the audit information and the original network packet P1 are reconstructed to form a new network packet P2, and then sent to other service nodes through the security decision monitoring module. If it is abnormal traffic, the network packet is discarded and an alarm is triggered.

[0075] When sending / receiving network packets between service nodes on the cloud side, it is also consistent with Figures 3a-3b and the above two paragraphs, which will not be repeated here.

[0076] As shown in Figure 2 As shown in the cloud traffic processing stage, each service node (such as the gateway service node) in the cloud has a security decision monitoring module deployed in the kernel, and all network traffic between service nodes in the cloud will be verified and audited through the security decision monitoring module. If the request complies with the user's configured security configuration, it can pass the verification of the security decision monitoring module, and the corresponding service node can normally use the user's private data; if the request violates the security configuration, the security decision monitoring module immediately prevents illegal operations and triggers an alarm; thus ensuring that only traffic that complies with the security configuration can be properly released, ensuring the confidentiality of the entire life cycle of data flow, and thus ensuring that the pre-configured security configuration is correctly executed.

[0077] The processing of normal traffic is as follows: the language network packet sent by the user through the AI agent is first intercepted by the security decision monitoring module of the gateway service node, and after verification by the security decision monitoring module according to the security configuration and audit information, it is sent to the user layer service. If external A service needs to be called, the network packet sent by the application layer service is also first intercepted by the security decision monitoring module, and verification and audit are performed. After verification, the new network packet constructed is sent to the A service node; the received network packet is transmitted to the application layer service after being verified and audited by the security decision monitoring module deployed in the A service node.

[0078] The processing flow of abnormal traffic is as follows: since the user sets the B service to be disabled in the security configuration in step 2, such traffic is prohibited in the security configuration, and the security decision monitoring module performs interception and triggers an alarm for such traffic, thereby achieving interception of illegal operations, preventing unauthorized access, and ensuring data privacy compliance.

[0079] During the process, the security decision monitoring module will record any required audit information (such as traffic path information, abnormal traffic alarm information, etc.) for auditing by the end-side user.

[0080] Embodiment 2

[0081] The embodiment provides an AI agent data protection device based on a controlled execution environment, which includes an authentication module, a security decision monitoring module, and a security configuration module.

[0082] The authentication module: the end-side device first verifies the integrity of the security decision monitoring module (an open-source component) on the cloud side through the RemoteAttestation service provided by the TEE in the trusted execution environment, and verifies whether the service nodes on the cloud side are all running in the trusted execution environment (TEE) and whether the startup environment is secure and trusted; if the verification is passed, the service request is normally executed, otherwise, the request is not sent;

[0083] The security decision monitoring module: based on the eBPF technology, it is implemented in the system kernel, used to intercept received or sent network packets, implement verification and audit functions, judge whether the intercepted network packets meet the security configuration, and record traffic path audit information or trigger an alarm as appropriate; the traffic between the user layer service application and the service nodes on the cloud side and the traffic between the service nodes on the cloud side are all verified and audited through the security decision monitoring module;

[0084] The security configuration module is used to distribute the security configuration provided by the user end side to all security decision monitoring modules.

[0085] The above embodiments are only used to illustrate the technical solutions of the present application, but not to limit it, although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part or all of the technical features, and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application, and the non-essential improvements, adjustments or replacements made by those skilled in the art according to the content of the present application are all within the scope of the present application.

Claims

1. A method for AI agent data protection based on a controlled execution environment, characterized in that, Comprise: Step one: in the trusted execution environment through remote authentication service verification cloud side of each service node kernel security decision monitoring module integrity, and verify the cloud side of the service node whether all run in the trusted execution environment, and its start environment is safe and reliable; if the above three verification conditions are passed, execute next step, otherwise any verification condition is not satisfied, do not send request; Step two: cloud side receives the security configuration from the user side, distribute to each service node security decision monitoring module; wherein, the cloud side each service node is deployed in the trusted execution environment, and each trusted execution environment kernel is deployed with the security decision monitoring module; Step three: AI agent is deployed in the trusted execution environment containing the security decision monitoring module; the security decision monitoring module will first perform security check on the service request to be sent by AI agent, judge whether the request is compliant, if yes, execute next step, otherwise, do not send the request; Step four: cloud side service node receives the service request from AI agent, the security decision monitoring module deployed in the gateway service node kernel first intercepts the received network packet, judges whether the service request from AI agent is normal traffic or abnormal traffic, if it is normal traffic, the security decision monitoring module passes the network packet, otherwise, the security decision monitoring module discards the network packet and triggers alarm; If you need to call other cloud service nodes, continue to judge whether the traffic meets the user's security configuration; If yes, the security decision monitoring module in the gateway service node records the audit information, merges the audit information into the original network packet to reconstruct a new network packet and sends it to the target service node; Otherwise, the security decision monitoring module will discard the network packet and trigger an alarm to inform the user of the violation information; The security decision monitoring module is established based on extended Berkeley packet filter (eBPF) to intercept received or sent network packets, realize verification and audit functions.

2. The AI agent data protection method in a controlled execution environment according to claim 1, wherein, The steps of receiving and sending network packets between cloud side service nodes include: The service node of the cloud side receives network packets from the gateway service node or from other service nodes, and the security decision monitoring module of the service node receiving the network packet first intercepts, judges whether the traffic meets the user's security configuration, if yes, passes the network packet and updates the traffic path audit information; otherwise, discards the network packet and triggers an alarm.

3. The AI agent data protection method in a controlled execution environment according to claim 1, wherein, The service request contains user identity information, service demand and required service node information.

4. The AI agent data protection method in a controlled execution environment according to claim 1, wherein, The abnormal traffic refers to the case that a service node sends private data to a node that does not meet the security configuration or even a third party entity.

5. An AI agent data protection apparatus based on a controlled execution environment, characterized by Comprise authentication module and security decision monitoring module; Among them, the connection between the user side and the cloud side, and between each service node of the cloud side is controlled by the authentication module, and the behavior monitoring and auditing are carried out by the security decision monitoring module; AI agent, gateway service node and each cloud side service node are deployed in the trusted execution environment, and each trusted execution environment kernel is deployed with the security decision monitoring module; The authentication module is configured to verify the integrity of the security decision monitoring module on the cloud side by the remote authentication service on the user side device, verify whether the service nodes on the cloud side are all running in a trusted execution environment and whether the start environment is safe and trusted, if yes, normally execute the service request, if not, do not send the request; The security decision monitoring module is configured to intercept the received or sent network packets, judge whether the intercepted network packets conform to the security configuration, if yes, trigger an alarm, if no, release the network packets and record audit information, combine the audit information into the original network packets to reconstruct a new network packet and send the new network packet to the target service node.

6. The apparatus according to claim 5, wherein, The traffic between the service application on the user side and the service nodes on the cloud side and the traffic between the service nodes on the cloud side are verified and audited by the security decision monitoring module.

7. The apparatus according to claim 5, wherein the controlled execution environment is a Java Virtual Machine (JVM) or a Common Language Runtime (CLR) environment. The user on the end side formulates the security configuration according to the service function and privacy demand, embeds the security configuration into the security decision monitoring module in the trusted execution environment on the end side and the security decision monitoring module deployed in the kernel of the service nodes on the cloud side, and the security configuration of the security decision monitoring module deployed in the device is the same.

8. The apparatus according to claim 5, wherein the apparatus is configured to: The data protection device further comprises a security configuration module configured to distribute the security configuration provided by the user on the end side to all the security decision monitoring modules.

9. An electronic device comprising: at least one processor; and a memory connected with the at least one processor in communication, wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to claim 1 or 2.

10. A non-transitory computer readable storage medium storing computer instructions for causing a computer to perform the method according to claim 1 or 2.

Citation Information

Patent Citations

  • Kernel architecture based on PKS system

    CN114707140A

  • Host protection system, method and device and storage medium

    CN116702128A

  • Method and system for carrying out privacy protection on data API (Application Program Interface) service

    CN116821951A

  • Trusted execution environment enhanced security system and method based on intelligent network card

    CN118627057A

  • Cross-platform dynamic security baseline and loophole closed-loop repair method and system based on federated learning

    CN120257288A

Cited By

  • User service demand processing method and device, equipment and medium

    CN121690863A

  • User service requirement processing method, apparatus, device, and medium

    CN121690863B

  • Governance record generation method for non-deterministic processing systems

    TWI923536B