A hardware-level AI implicit operation link blockade and offline communication global detection system

By employing a hardware-level full-domain scanning and physical blocking architecture, the problem of existing technologies being unable to identify implicit operations and offline covert communications at the chip's underlying level is solved. This enables full-link monitoring of implicit operations and physical severing of covert communications, thereby improving the comprehensiveness and applicability of underlying security protection.

CN122339809APending Publication Date: 2026-07-03廖长林
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
廖长林
Filing Date
2026-04-25
Publication Date
2026-07-03

AI Technical Summary

Technical Problem

Existing protection systems cannot intercept implicit operations at the chip's underlying level and offline multi-form covert communication, resulting in security blind spots and making it difficult to identify implicit operations and covert communication.

Method used

It adopts a hardware-level full-domain scanning and physical blocking architecture to fully cover the device hardware operation link. Through multi-dimensional feature recognition and hardware cut-off mechanism, it realizes the identification of implicit operations and the blocking of covert communication.

Benefits of technology

It achieves end-to-end behavior monitoring of implicit operations at the chip's underlying level and physical severance of covert communication, improving the comprehensiveness and reliability of underlying security protection, and is suitable for various offline scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FT_1
    Figure FT_1
  • Figure FT_2
    Figure FT_2
Patent Text Reader

Abstract

The application discloses a hardware-level AI implicit operation link blockade and offline communication global detection system and belongs to the technical field of hardware bottom-layer security protection. The application adopts a hardware-level global scanning and physical blocking core architecture, supports various compatible implementation modes such as external scanning, chip microcode auditing, electromagnetic monitoring and power consumption monitoring and is fully compatible with various existing basic protection systems. The application fills the bottom-layer control blank of the traditional protection system through bottom-layer hardware state global scanning, multi-dimensional feature recognition and secret communication physical blocking, is suitable for various bottom-layer security reinforcement technical evolution scenes and is suitable for the bottom-layer security reinforcement of various offline intelligent devices and edge AI terminals.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the fields of hardware underlying security protection, artificial intelligence implicit behavior control, and offline device communication constraint technology. It is applicable to high-security underlying scenarios such as edge computing terminals, industrial control equipment, ocean-going unmanned equipment, IoT offline nodes, AI edge computing hardware, and classified smart terminals. Background Technology

[0002] Existing smart devices generally adopt basic protection architectures such as chip security domain isolation, hardware and software layered permission control, and network port access restrictions, which can effectively resist common security risks such as external network attacks and explicit unauthorized access; The existing protection system has a blind spot in the underlying protection: it cannot cover the hidden computing links inside the chip's private isolation domain, and it is difficult to identify hidden background processes and unauthorized underlying task scheduling; in offline scenarios, unconventional communication methods such as electromagnetic side channels, private protocols, storage medium transfer, clock offset, and cache side channels can bypass conventional boundary isolation to form hidden data interaction channels. The essential difference from existing technologies: Existing technologies all control external network communication, while this invention controls the implicit operations at the chip's underlying layer and the covert communication at the physical layer. This is a technical problem that existing technologies have not yet effectively solved. To address the aforementioned shortcomings in underlying security, this invention constructs a comprehensive hardware-level protection system that adapts to diverse application scenarios where underlying security capabilities are iterated. Summary of the Invention

[0003] Purpose of the invention This invention aims to address the industry gaps where existing protection systems cannot intercept implicit operations at the chip level or block offline multi-form covert communications, and provides a hardware-level AI implicit operation link blocking and offline communication full-domain detection system.

[0004] Technical solution The core of this invention adopts a hardware-level full-domain scanning and physical blocking architecture, which fully covers all hardware operation links of the device, and realizes the identification of underlying implicit operations and the physical cutting off of covert communication. This invention supports multiple compatible implementation forms, including external full-domain scanning, chip-level microcode auditing, electromagnetic feature monitoring, and power consumption feature monitoring, etc. All implementation forms are based on the same core technology concept.

[0005] Terminology Definition 1. AI intelligent agent: refers to an artificial intelligence system that can autonomously perceive its environment, make autonomous decisions, and autonomously execute tasks; 2. Hardware level: refers to functional logic that is executed entirely by hardware circuits and is not subject to modification or control by the operating system, drivers, or upper-level software; 3. Global: refers to comprehensive control over all physical buses, memory ports, and computing scheduling links of the device.

[0006] Beneficial effects 1. Comprehensive coverage at the bottom layer: Directly reaches the chip's physical link and the underlying scheduling level, enabling large-scale, full-link behavior monitoring; 2. Physical-level forced interception: A hardware-based cutoff mechanism is used for covert operations and clandestine communications, ensuring protection strength is unaffected by software. 3. Multi-dimensional risk identification: Integrates multi-dimensional features such as data flow, electromagnetic fields, power consumption, clock speed, and cache to comprehensively cover various hidden risks; 4. Fully offline scenario adaptation: No network dependency, adaptable to special scenarios such as isolation and network outages, and unattended operation in the wild; 5. Strong architectural adaptability: It can be compatible with the reinforcement needs of existing underlying protection architectures and adapt to underlying security hardening scenarios with different technical paths; 6. Performance of typical embodiments: In typical embodiments of industrial control equipment, the accuracy rate of implicit operation recognition reaches 99.8%, and the interception rate of covert communication reaches 99.9%. Attached Figure Description

[0007] Figure 1 This is a schematic diagram of the overall architecture of the bottom-level global protection of the present invention, showing the docking relationship between the hardware-level global control unit and the entire hardware link of the device; Figure 2 This is a multi-dimensional hidden risk interception topology diagram of the present invention, which shows the protection implementation forms corresponding to various risks. Detailed Implementation

[0008] The core embodiment of this invention adopts an external full-domain scanning configuration. The hardware-level full-domain management unit interfaces with all physical buses, memory ports, and computation scheduling links of the device, collects underlying operational data in real time, and incorporates multi-dimensional feature recognition logic to automatically identify unauthorized implicit computations and offline covert communication behaviors. For violations, it performs hardware link disconnection and port control. Hardware implementation of core functions: 1. Low-level hardware status scanning: This can be achieved through three hardware methods: bus sniffing, memory mirroring, and instruction tracing. 2. Implicit operation identification: This can be achieved through three hardware methods: instruction sequence analysis, power consumption feature comparison, and register status monitoring; 3. Covert communication identification: This can be achieved through three hardware methods: electromagnetic feature analysis, clock skew detection, and buffer behavior tracking. 4. Physical link disconnection: This can be achieved through three hardware methods: port disabling, bus isolation, and power disconnection. 5. Establishment of a legitimate communication baseline: This can be achieved through three hardware methods: hardware learning, whitelist import, and standard protocol parsing; Alternative implementations include: chip microcode auditing to trace the local underlying operation trajectory; electromagnetic feature monitoring to identify side-channel leakage risks; power consumption feature monitoring to identify implicit operations based on power consumption fluctuations; protocol filtering to intercept non-standard covert transmission protocols; unidirectional isolation to block bidirectional transfer of storage media; multi-interface comparison to identify abnormal data flow; clock monitoring to identify covert communication based on clock offset; and cache monitoring to identify data transmission based on cache side-channels. All the above-described embodiments and their combinations thereof are within the scope of protection of this invention.

Claims

1. A hardware-level AI implicit computation link blocking and offline communication full-domain detection system, characterized in that, Including hardware-level global control units; The hardware-level global control unit connects to all hardware operation links of the device. The hardware-level global control unit scans the underlying hardware operating status in real time to identify unauthorized implicit operations, hidden background processes, and unauthorized underlying task scheduling in the chip's private isolation space. The hardware-level global control unit establishes a standardized and legitimate communication baseline and physically cuts off various clandestine data interaction links in offline environments. The entire system is independent of the device's operating system and the chip's native security architecture, and performs protection actions purely through hardware.

2. The system according to claim 1, characterized in that, The hardware-level global control unit adopts an external global scanning form, connecting to all physical buses, memory ports and computing scheduling links of the device.

3. The system according to claim 1, characterized in that, The hardware-level global control unit adopts a chip-level microcode auditing approach, and adds a microcode operation trajectory monitoring unit inside the chip.

4. The system according to claim 1, characterized in that, It integrates a hardware-level electromagnetic signal acquisition and feature comparison module to identify the covert communication behavior of offline devices based on electromagnetic leakage characteristics.

5. The system according to claim 1, characterized in that, An integrated hardware-level power consumption characteristic monitoring module is used to identify unauthorized implicit computing behavior based on device power consumption fluctuation characteristics.

6. The system according to claim 1, characterized in that, A hardware verification unit for the underlying communication protocol is added to intercept non-standard proprietary protocols and covert transmission protocols.

7. The system according to claim 1, characterized in that, It adopts a one-way hardware data isolation architecture to restrict bidirectional data transfer between storage media and external devices.

8. The system according to claim 1, characterized in that, It adopts a multi-hardware interface synchronous data acquisition and real-time difference comparison architecture to identify abnormal data flow caused by hidden background processes.

9. The system according to claim 1, characterized in that, A hardware-level clock synchronization monitoring unit is added to identify covert communication behaviors based on clock offset.

10. The system according to claim 1, characterized in that, A hardware-level cache behavior monitoring architecture is adopted to identify implicit data transmission behavior based on cache side channels.