Artificial intelligence trusted computing platform based on pk system
By using a trusted computing platform based on the PKS architecture, the problem of insufficient autonomous controllability of artificial intelligence systems in hardware and network communication is solved. It enhances data protection and identity authentication, ensures the security and robustness of the system, and adapts to the needs of heterogeneous hardware environments.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-23
- Publication Date
- 2026-03-24
AI Technical Summary
Existing artificial intelligence systems lack autonomous control over hardware, operating systems, and network communications, leading to data leaks and system security risks. This is especially true in edge data processing, where the exposure surface expands and the risk of attacks increases.
A trusted computing platform is built based on the PKS architecture. Through physical isolation and trusted measurement between the operating system and the basic hardware platform, combined with built-in trusted technology in the CPU and built-in physical protection in memory, it realizes resource access control and isolation of the computing environment, provides dynamic trusted measurement and behavior detection, supports heterogeneous hardware environments, and loads a trusted computing module in the operating system kernel.
It improves the inherent security of artificial intelligence systems, enhances data protection and identity authentication, prevents malicious behavior, ensures secure data transmission, realizes smooth and reliable computing across cloud, edge, and device, and improves the robustness and security of the system.
Smart Images

Figure CN115391757B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to the technical field of artificial intelligence application security, and in particular to an artificial intelligence trusted computing platform based on a PKS system. BACKGROUND
[0002] In recent years, with the deep integration and continuous penetration of artificial intelligence technology with the Internet, big data and the real economy, the security of artificial intelligence itself and the significant influence on the security of politics, economy, military and society have attracted increasing attention from all sectors of society. High-tech enterprises in various industries at home and abroad are constantly researching the combination of products and artificial intelligence and actively launching intelligent products.
[0003] The characteristics of the overall computing power network from the edge to the center of artificial intelligence pose new network security problems for the development of artificial intelligence. First, the attack exposure surface is expanded. The originally closed production network and business system begin to open to the outside world, and the network, application and data have more exposure surfaces, bringing new security risks. Second, the risk of data leakage is intensified. The opening, sharing and continuous flow of data intensify the risk of information data leakage. A large amount of terminal-side data causes a large real-time throughput of data, not only increasing the attack points and expanding the attack range, but also being more easily tampered with and stolen. Third, the security demand of the industry chain supply is improved. The artificial intelligence application industry chain is long and widely used in various fields, and the continuous innovation of its security foundation technology and industry support capability has a major impact on its application.
[0004] In various application scenarios, a cloud, edge and end collaborative data processing mechanism is usually adopted, and the system integration and communication technology are basically the same. In the design of the underlying hardware system, ARM or Intel CPU, NVIDIA GPU and Linux open source operating system framework are basically adopted, and their mature ecological advantages are fully utilized to accelerate product research and development and production; in the design of the upper application software architecture, a microservice architecture based on a message mechanism is mainly adopted, and through the transmission of network messages, scheduling and communication between services in the cloud, edge and end are completed.
[0005] The design and implementation of the above architecture result in the complete loss of the ability of products from the underlying hardware, operating system to the upper network communication to be self-controllable, and illegal personnel can steal data, destroy systems and the like by exploiting vulnerabilities in hardware, operating systems or network communication, causing overall system and data security risks. However, domestic manufacturers, due to the large amount of product function demand development work, often only invest funds and technology mainly into technological innovation and engineering practice, and pay less attention to trusted security. However, with the proposal of the relationship between data security and national security, governments and enterprises have gradually begun to pay attention to the application of trusted security in artificial intelligence products. SUMMARY
[0006] In order to solve the problems in the prior art, the application provides an artificial intelligence trusted computing platform based on a PKS system, which comprises an artificial intelligence application layer, a middleware layer, an operating system and a basic hardware platform;
[0007] The operating system is connected with the basic hardware platform information, resource access control and resource scheduling are carried out for application access of the artificial intelligence application layer, and the middleware layer provides necessary resources for resource access control of the operating system;
[0008] The operating system and the basic hardware platform realize isolation of a protection component and a computing component through physical isolation of CPU and memory, wherein the protection component comprises a trusted basic software in the operating system and a trusted hardware platform in the basic hardware platform, the trusted hardware platform is scheduled through the trusted basic software to complete resource access control; the computing component comprises an application behavior access control interface in the operating system and a computing hardware platform in the basic hardware platform, the computing hardware platform is scheduled through the application behavior access control interface to complete resource access; the trusted basic software is connected with the application behavior access control interface to dynamically measure, identify and control the operation access strategy of the computing component through the protection component.
[0009] The protection component constructs a trusted computing environment based on a trusted cryptographic module in the trusted hardware platform, creates a trusted root through the trusted cryptographic module, and transmits a trust chain from the trusted root to the operating system through trusted measurement in a start-up measurement, a secure initial state acquisition and a booting process.
[0010] The operating system comprises a kernel trusted computing interface connected with the trusted basic software and the application behavior access control interface, the kernel trusted computing interface comprises a software trusted module, a compatible conversion interface, a sensitive business interface, a privacy computing interface and an artificial intelligence behavior security detection interface; wherein,
[0011] The software trusted module is used to provide a software level trusted computing function when the trusted computing environment is not constructed in the trusted hardware platform;
[0012] The compatible conversion interface is used to automatically identify a safe computing related call and convert it into a trusted environment computing, so as to realize seamless compatibility between the artificial intelligence upper application and the protection component;
[0013] The sensitive business interface is used to import a sensitive business related to artificial intelligence into the trusted computing environment in the trusted hardware platform;
[0014] The privacy computing interface is used to provide an interface of user identity authentication authorization;
[0015] The artificial intelligence behavior security detection interface is used to prevent, intercept and safely fuse malicious behaviors and data commonly seen in artificial intelligence.
[0016] The protective component constructs a trusted computing environment based on a trusted cryptographic module in a trusted hardware platform, either externally, internally in the CPU, or internally in the NPU. When performing resource access control, the protective component automatically identifies and selects the computing method with the highest security level.
[0017] Supported by the native security capabilities of the PKS system, this invention addresses core issues such as trusted computing and secure authentication in artificial intelligence infrastructure (hardware platform, operating system, and edge devices). It unifies hardware-level computing power and secure computing in software systems, embeds the core capabilities of the unified framework into the operating system, and designs a unified approach for general-purpose and embedded operating systems. This results in a smooth application of trusted computing across cloud, edge, and device, provides a unified interface for upper-layer applications, and enhances the inherent security of artificial intelligence. Attached Figure Description
[0018] Figure 1 The logical framework diagram of the AI trusted computing platform based on the PKS system of the present invention.
[0019] Figure 2 The present invention provides a logical principle diagram of the heterogeneous security environment of an artificial intelligence trusted computing platform based on the PKS system. Detailed Implementation
[0020] To gain a better understanding of the technical solution and beneficial effects of the present invention, the technical solution of the present invention and its beneficial effects are described in detail below with reference to the accompanying drawings.
[0021] In the process of implementing artificial intelligence technology, ensuring the security of network communication between the underlying system and upper-layer applications still faces many challenges. These security challenges mainly come from two aspects: internal and external. The internal challenge is ensuring the security of computing power and data; the external challenge is the high intensity of targeted network attacks. How to cope with high-intensity network threats requires continuous exploration and evolution of security technologies.
[0022] After years of exploration and practice, my country has developed fully independent and controllable products such as the PKS system in fields such as chips and operating systems. These products have been widely used in government affairs, energy, finance, military industry and other fields, becoming the core foundation of my country's independent, secure and green computing information system.
[0023] To address trust and security issues in the field of artificial intelligence, research can focus on the domestic implementation of AI technology security frameworks and security authentication control for edge devices, based on PKS system security and trusted computing technology. Leveraging the native security capabilities and mature ecosystem of the domestically developed PKS system, we can ensure the independent controllability and security of AI application data.
[0024] The PKS system is a completely independent, controllable, green, open, and shared information system technology architecture and ecosystem built by my country. P represents Phytium processor, K represents Kylin operating system, and S represents Security. It has eight built-in security protections and is equipped with three innovative technologies: the first use of CPU-embedded trusted technology internationally, the first use of memory-embedded physical protection technology internationally, and a unified security center on the terminal and unified security management in the cloud.
[0025] The PKS system deeply integrates proactive security defense and trusted computing technologies with underlying basic software and hardware, fundamentally embedding security capabilities into information systems and completely changing the current situation of lacking underlying independent security capabilities. Based on this, it further extends security capabilities to the network, cloud computing, application, and data layers, achieving deep integration and comprehensive coverage of security capabilities and information technology. Currently, the PKS system has replaced the Wintel system in core national sectors and some industries.
[0026] Based on the native security capabilities of the domestically developed PKS system, this invention mainly focuses on research into the secure application of artificial intelligence technology frameworks and security authentication control methods for edge devices. The research will concentrate on enhancing the inherent security of artificial intelligence, primarily addressing core issues such as trusted computing and security authentication for artificial intelligence infrastructure (hardware platforms, operating systems, and edge devices).
[0027] This invention, based on the PKS autonomous security system, designs a unified trusted computing framework. It implements the core trusted computing environment directly on the hardware platform and operating system kernel module, constructing a trusted computing environment for artificial intelligence and improving the robustness of trusted computing. According to the needs of trusted computing for artificial intelligence, it forms a unified interface platform that adapts to complex heterogeneous hardware platforms and systems in different cloud, edge, and terminal environments, supporting a smooth connection between secure computing on the cloud, edge, and terminal. It also integrates user privacy and security with the system, providing a reliable privacy computing interface.
[0028] I. Building a Trusted Computing Environment for Artificial Intelligence
[0029] Figure 1 This is a logical framework diagram of the PKS-based trusted artificial intelligence computing platform of the present invention, as shown below. Figure 1As shown, the PKS-based trusted computing platform for artificial intelligence of this invention includes: an artificial intelligence application layer, a middleware layer, an operating system, and a basic hardware platform; the operating system is interconnected with the basic hardware platform, performing resource access control and resource scheduling for application access in the artificial intelligence application layer, and the middleware layer provides necessary resources for the operating system to perform resource access control; the PKS system implements a dual-system secure and trusted operating system architecture based on the isolation of the CPU trusted core and the computing core. Under this architecture, through the physical isolation of the CPU and memory, the entire computer is divided into two parts: a protective component and a computing component, and the computing environment of the computing component is isolated from the measurement environment of the protective component.
[0030] The protection components include trusted basic software in the operating system and trusted hardware platform in the basic hardware platform. The trusted basic software schedules the trusted hardware platform to complete resource access control. The computing components include application behavior access control interface in the operating system and computing hardware platform in the basic hardware platform. The application behavior access control interface schedules the computing hardware platform to complete resource access. Based on this architecture, artificial intelligence security capabilities can be effectively improved while taking into account system performance.
[0031] To ensure security and trustworthiness, this invention also implements whole-machine protection based on trust metrics within a dual-system secure and trustworthy operating system architecture. The protection component creates a root of trust based on a trusted cryptographic module and transfers the trust chain from the root of trust to the operating system through processes such as startup metrics, acquisition of the initial security state, and trusted metrics during the boot process. This constructs the initial trusted computing environment for the protection component. When there is a need to ensure data security, algorithm security, application security, device security, and communication security at the artificial intelligence application layer, the trusted basic software schedules the trusted computing environment to obtain the root of trust and performs verification based on it. By performing identity authentication and encrypted computation on the protection component side rather than the computing component side, only after the protection component passes encryption and decryption verification can the application behavior access control interface in the computing component schedule resources in the computing hardware platform. This achieves enhanced security extensions for user identity authentication and enhanced encrypted storage for file storage.
[0032] In this invention, the trusted basic software is connected to the application behavior access control interface. Through the protection component, the four elements of the operation access strategy of the computing component (subject, object, operation, and environment) are dynamically trusted, identified and controlled, so as to achieve effective proactive defense against viruses, Trojans and vulnerabilities.
[0033] Please continue reading. Figure 1 As shown, the operating system includes a kernel trusted computing interface connected to trusted basic software and application behavior access control interfaces. The kernel trusted computing interface includes a software trusted module, a compatibility conversion interface, a sensitive business interface, a privacy computing interface, and an artificial intelligence behavior security detection interface.
[0034] The software trust module is used to provide software-level trusted computing functionality when a trusted computing environment is not built on a trusted hardware platform, as detailed below.
[0035] The Sensitive Business Interface provides a mechanism to import AI-sensitive business processes such as payment and authentication from the user space into the trusted computing environment. The Sensitive Business Interface provides the ability to execute AI security-related sensitive business processes such as payment and authentication in the trusted computing environment.
[0036] The compatibility conversion interface is designed to support different artificial intelligence framework platforms. It can automatically identify secure computing-related calls and convert them into trusted environment computing, enabling upper-layer applications to be seamlessly compatible with the protection components.
[0037] The privacy computing interface provides a user authentication and authorization interface, storing important personal privacy information involved in artificial intelligence applications in a trusted computing environment. Only authorized interfaces after user authentication can access the information. The privacy computing interface provides hierarchical access control for privacy data, offering different levels of data support for feature data and raw data. Core information is output using a mask, and verification is achieved through the privacy computing interface.
[0038] The AI behavior security detection interface builds upon existing research findings on AI application security behavior rules to construct behavior security detection capabilities. It prevents and intercepts malicious behaviors and data commonly found in AI, such as adversarial attacks, data poisoning, deepfakes, and algorithm backdoors, and, when necessary, implements security circuit breakers for application operations. Under the support of a unified trusted computing framework, it provides trusted traceability and intellectual property protection capabilities for AI algorithms, data, and behaviors.
[0039] II. Support for Heterogeneous Hardware Environments
[0040] Figure 2 This is a schematic diagram of the heterogeneous security environment of the AI trusted computing platform based on the PKS architecture of the present invention. Addressing the complexity of hardware platforms, operating systems, and middleware in AI applications, the differences between cloud, edge, and terminal environments, and the diversity of server systems, desktop systems, and embedded systems of terminal devices, the protective components of this invention support heterogeneous systems and environments by identifying the following hardware categories:
[0041] (1) A hardware platform with TEE (Trusted Execution Environment), which is also known as a trusted computing environment (currently, domestic CPUs represented by Phytium and Loongson already support this).
[0042] (2) NPU built-in TEE (a trusted computing module can be built into the NPU, and the trusted computing of artificial intelligence is directly implemented in the computing unit, with a higher level of security).
[0043] (3) External TEE chip for hardware platform (integrated into the platform in the form of SOC, ASIC, etc.);
[0044] (4) Hardware environment without TEE function (In order to improve compatibility and support the original platform, software TEE is implemented through secure computing in the software to support upper-layer artificial intelligence applications. The software trusted module mentioned above is for the purpose of implementing this function. However, the framework has degenerated into a traditional single-system security mode, and its ability to protect data privacy is somewhat lacking compared to the hardware solution).
[0045] The above hardware modes represent different implementations of a Trusted Computing Environment (TEE) built by a Trusted Cryptographic Module. When performing resource access control, the operating system traverses the interfaces from the CPU's built-in TEE to the peripheral TEE according to priority. If an interface exists, the corresponding hardware's interface library and driver are obtained, and the trusted computing environment built into the trusted hardware platform is used for security control to select the appropriate implementation method. If no interface exists, the operating system's software trusted module (which needs to be added to the operating system's kernel beforehand) is called to implement secure access control of resources.
[0046] III. Optimization Design for the Operating System
[0047] Operating systems are a crucial foundational environment for trusted computing in artificial intelligence, encompassing server systems, desktop systems, and embedded systems of end devices. This invention optimizes the design of a unified framework for trusted computing in artificial intelligence by analyzing operating systems, and constructs an operating system for trusted computing in artificial intelligence.
[0048] The support for heterogeneous hardware environments by the operating system has been discussed in Part Two and will not be repeated here. Other optimizations to the operating system in this invention mainly focus on kernel optimization.
[0049] For server and desktop operating systems, as well as monolithic kernel embedded systems, the operating system loads and runs the trusted computing component in kernel mode. For microkernel embedded systems, a secure, authenticated microkernel that enables access to the trusted hardware environment provides interfaces for switching between normal and secure modes, ensuring the isolation and secure access to trusted computing resources. The operating system should meet the highest security level (e.g., Level 4 of the highest domestic security standard GB / T 20272). The trusted computing module should be located at Ring 0 of the x86 architecture and EL3 level of the ARM TrustZone to enable the loading and use of the trusted computing environment.
[0050] The PKS-based trusted computing platform for artificial intelligence provided by this invention can ensure the security of data and communication throughout the entire process of artificial intelligence applications in the following aspects.
[0051] 1. In underlying data applications, the PKS system's protection components dynamically and reliably measure, identify, and control the access policies of computing components, supporting behavioral security detection interfaces to effectively and proactively defend against and detect abnormal behaviors in artificial intelligence. Simultaneously, the privacy computing interface can employ built-in encryption and decryption algorithms to encrypt sensitive underlying data such as faces, fingerprints, ID cards, and bank cards, providing multiple layers of protection to prevent the leakage of privacy data.
[0052] 2. Regarding identity authentication, by performing identity verification and encrypted computation on the protection component side rather than the computing component side, a security enhancement extension is achieved for both user identity verification and device identity verification, which is more secure and efficient than traditional token verification. This allows sensitive business interfaces to import sensitive business processes such as payment and identity verification into a trusted computing environment.
[0053] 3. In terms of network transmission, the CPU's built-in hardware encryption features are highly efficient and fast, improving the data encryption and decryption speed. Sensitive data that was previously transmitted in plaintext is encrypted to ensure that even if the data is stolen during transmission, it cannot be deciphered, thus guaranteeing the security of data transmission.
[0054] Supported by the native security capabilities of the PKS system, this invention addresses core issues such as trusted computing and secure authentication in artificial intelligence infrastructure (hardware platform, operating system, and edge devices). It unifies hardware-level computing power and secure computing in software systems, embeds the core capabilities of the unified framework into the operating system, and designs a unified approach for general-purpose and embedded operating systems. This results in a smooth application of trusted computing across cloud, edge, and device, provides a unified interface for upper-layer applications, and enhances the inherent security of artificial intelligence.
[0055] Although the present invention has been described using the above preferred embodiments, it is not intended to limit the scope of protection of the present invention. Any changes and modifications made by those skilled in the art to the above embodiments without departing from the spirit and scope of the present invention shall still fall within the scope of protection of the present invention. Therefore, the scope of protection of the present invention shall be defined by the claims.
Claims
1. A trusted artificial intelligence computing platform based on the PKS architecture, characterized in that... include: Artificial intelligence application layer, middleware layer, operating system, and basic hardware platform; The application layer of artificial intelligence includes data security, algorithm security, application security, device security, and communication security. The middleware layer includes cryptography, certificates, encryption / decryption, authentication / authorization, and trusted tracing, providing the necessary resources for the operating system to perform resource access control; The operating system connects with the basic hardware platform, performs resource access control and resource scheduling for applications accessed at the AI application layer, and the middleware layer provides the necessary resources for the operating system to perform resource access control. The operating system and the basic hardware platform achieve isolation between the protection component and the computing component through physical isolation of the CPU and memory. The protection component includes trusted basic software in the operating system and trusted hardware platform in the basic hardware platform. The trusted basic software schedules the trusted hardware platform to complete resource access control. The computing component includes application behavior access control interface in the operating system and computing hardware platform in the basic hardware platform. The application behavior access control interface schedules the computing hardware platform to complete resource access. The trusted basic software is also connected to the application behavior access control interface to dynamically and reliably measure, identify, and control the operation access policies of the computing component through the protection component. The protection component constructs a trusted computing environment based on the trusted cryptographic module in the trusted hardware platform. The trusted cryptographic module creates a trusted root and transmits the trust chain from the trusted root to the operating system through startup measurement, security initial state acquisition, and trusted measurement during the boot process. The operating system includes a kernel trusted computing interface that connects to trusted infrastructure software and application behavior access control interfaces. This kernel trusted computing interface includes a software trusted module, a compatibility conversion interface, a sensitive business interface, a privacy computing interface, and an artificial intelligence behavior security detection interface. The software trusted module is used to provide trusted computing functions at the software level when a trusted computing environment is not built on a trusted hardware platform. The compatibility conversion interface is used to automatically identify secure computing-related calls and convert them into trusted environment computing, achieving seamless compatibility between upper-layer artificial intelligence applications and protection components. Sensitive business interfaces are used to import AI-related sensitive business processes into a trusted computing environment within a trusted hardware platform; The privacy computing interface is used to provide an interface for user authentication and authorization; The AI behavior security detection interface is used to prevent, intercept, and securely disconnect common malicious behaviors and data in artificial intelligence.
2. The AI trusted computing platform based on the PKS system as described in claim 1, characterized in that: The protective component constructs a trusted computing environment based on a trusted cryptographic module in a trusted hardware platform, either externally, internally in the CPU, or internally in the NPU. When performing resource access control, the protective component automatically identifies and selects the computing method with the highest security level.
Citation Information
Patent Citations
Dual-system trusted computing system and method
CN109918916A