Artificial Intelligence System Protection Method, Device, AI Analysis Device and Control Center
Through the trusted verification and asymmetric encryption technology of AI analysis equipment and AI management and control centers, the frequent update of algorithm programs and parameters is solved, and secure online updates and protection are achieved.
Patent Information
- Application Number
- CN202211110485.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-13
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2042-09-13
AI Technical Summary
The prior art is difficult to meet the requirements of frequent updates while protecting the algorithm programs and algorithm parameters of artificial intelligence systems, and traditional dongle solutions cannot support online upgrades.
Using AI analysis equipment and AI management and control centers based on trusted verification technology, the secure distribution and update of algorithm programs and parameters is achieved through regular trusted verification, AIK certificate application and asymmetric encryption.
Effectively protect algorithm programs and parameters from being illegally tampered with, support frequent updates, and improve the security and flexibility of artificial intelligence systems.
Smart Images

Figure CN115470473B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of artificial intelligence security, and particularly to a method and device for protecting an artificial intelligence system, an AI analysis device, and a control center. Background Art
[0002] An artificial intelligence system is generally divided into two stages: one is the learning stage, in which learning samples are used for learning and algorithm parameters are obtained through training; the other is the analysis stage, in which the input data is analyzed using the algorithm parameters and the analysis result of the artificial intelligence is output. In the learning stage, the main assets of the artificial intelligence system include an algorithm program, sample data, and algorithm parameters obtained through training; in the analysis stage, the main assets of the artificial intelligence system include an algorithm program, algorithm parameters, actual data, and its analysis result. The algorithm program and algorithm parameters, as the core assets, are the core focus of protecting the artificial intelligence system.
[0003] In the training stage, the algorithm program and its data usually run in a data center, and the physical environment and network environment where they are located are relatively controllable. In the analysis stage, the usage side is usually located on the user side. For example, an autonomous driving system runs in a vehicle, a medical image recognition intelligent system runs in a hospital, a substation inspection robot runs in a substation, etc. The physical environment and network environment where the algorithm program and parameters are located are uncontrollable, and at the same time, there is also a risk of malicious data theft by humans.
[0004] To protect the core assets of the artificial intelligence system, the traditional protection method is to adopt the "dongle" solution. This solution uses a small encryption device as the medium for distributing and running the AI analysis software (i.e., the AI analysis device), stores and runs the algorithm program and algorithm parameters in the small encryption device, and provides them in a hardware manner. Since the traditional solution is a hardware-based solution, it does not support online upgrade. If an update is required, the AI analysis device needs to be recalled, and maintenance personnel need to update the AI analysis software for each device one by one and then redeploy it.
[0005] With the development and wide application of artificial intelligence, the update of the algorithm program and algorithm parameters is becoming increasingly frequent, and the traditional method is difficult to meet the requirements. Summary of the Invention
[0006] The present invention provides a method and device for protecting an artificial intelligence system, an AI analysis device, and a control center, which solves the technical problem of how to protect the algorithm program and algorithm parameters while meeting the frequent update requirements of the algorithm program and algorithm parameters.
[0007] In a first aspect of the present invention, a method for protecting an artificial intelligence system is provided. The method is executed by an AI analysis device, and the method includes:
[0008] Periodically perform trusted verification on its own target programs and systems based on trusted verification technology to obtain trusted verification results; the target programs and systems include BIOS, BootLoader, and / or operating systems;
[0009] Send an AIK query request carrying the current trusted verification result to the embedded trusted password module, and receive and save the AIK feedback by the trusted password module when it determines that the device is in a trusted state based on the current trusted verification result;
[0010] Send an AIK certificate application carrying the AIK to the AI management and control center, and receive and save the AIK certificate feedback by the AI management and control center based on the AIK;
[0011] Periodically report the trusted verification results obtained during trusted verification to the AI management and control center;
[0012] Send an application request for AI operation information including the AI algorithm program and algorithm parameters to the AI management and control center; the application request includes the AIK certificate and the public key generated by the trusted password module;
[0013] Receive the encrypted AI operation information feedback by the AI management and control center when it determines that the device is in a trusted state based on the received current trusted verification result; the encrypted AI operation information is obtained by encrypting the corresponding latest AI operation information using the public key;
[0014] Use the trusted password module to decrypt the received encrypted AI operation information according to the generated private key to obtain the AI algorithm program and algorithm parameters.
[0015] According to an implementable manner of the first aspect of the present invention, the method further includes:
[0016] When performing AI analysis based on the obtained AI algorithm program and algorithm parameters, store the obtained AI algorithm program and algorithm parameters only in the memory.
[0017] According to an implementable manner of the first aspect of the present invention, the method further includes:
[0018] Before shutting down or restarting, forcibly clear the AI algorithm program and algorithm parameters in the memory.
[0019] The second aspect of the present invention provides an artificial intelligence system protection method, which is executed by the AI management and control center. The method includes:
[0020] Receive the trusted verification results regularly reported by the AI analysis device; the trusted verification results are obtained when the AI analysis device performs regular trusted verification on its own target programs and systems based on trusted verification technology, and the target programs and systems include BIOS (Basic Input / Output System), BootLoader (Boot Loader), and / or operating system;
[0021] Receive the AIK (Identity Authentication Key) certificate application carried by the AI analysis device, and feedback the corresponding AIK certificate to the AI analysis device based on the AIK; the AIK is applied for by the AI analysis device to the embedded trusted password module, and is the identity authentication key feedback by the trusted password module when it determines that the device is in a trusted state based on the current trusted verification result of the AI analysis device;
[0022] Receive the application request for AI operation information including the AI algorithm program and algorithm parameters sent by the AI analysis device; the application request includes the AIK certificate and the public key generated by the trusted password module embedded in the AI analysis device;
[0023] According to the application request, when it is determined that the device is in a trusted state based on the received current trusted verification result, encrypt the corresponding latest AI operation information using the public key, and feedback the obtained encrypted AI operation information to the AI analysis device.
[0024] According to an implementable manner of the second aspect of the present invention, the feedback of the corresponding AIK certificate to the AI analysis device based on the AIK includes:
[0025] Review the AIK certificate application according to the preset security policy, and generate and feedback the AIK certificate corresponding to the AIK to the AI analysis device after the review passes.
[0026] The third aspect of the present invention provides an AI analysis device, including:
[0027] A trusted verification module, configured to perform regular trusted verification on its own target programs and systems based on trusted verification technology to obtain trusted verification results; the target programs and systems include BIOS, BootLoader, and / or operating system;
[0028] An AIK acquisition module, configured to send an AIK query request carrying the current trusted verification result to the embedded trusted password module, and receive and save the AIK feedback by the trusted password module when it determines that the device is in a trusted state based on the current trusted verification result;
[0029] The AIK certificate acquisition module is used to send an AIK certificate application carrying the AIK to the AI management and control center, and receive and save the AIK certificate fed back by the AI management and control center based on the AIK;
[0030] The trusted verification result reporting module is used to regularly report the trusted verification results obtained during trusted verification to the AI management and control center;
[0031] The AI operation information application module is used to send an application request for AI operation information including the AI algorithm program and algorithm parameters to the AI management and control center; the application request includes the AIK certificate and the public key generated by the trusted password module;
[0032] The AI operation information receiving module is used to receive the encrypted AI operation information fed back by the AI management and control center when it determines that the device is in a trusted state based on the currently received trusted verification result; the encrypted AI operation information is obtained by encrypting the corresponding latest AI operation information using the public key;
[0033] The AI operation information decryption module is used to use the trusted password module to decrypt the received encrypted AI operation information according to the generated private key to obtain the AI algorithm program and algorithm parameters.
[0034] According to an implementable manner of the third aspect of the present invention, the AI analysis device further includes:
[0035] The storage module is used to only store the obtained AI algorithm program and algorithm parameters in the memory when performing AI analysis based on the obtained AI algorithm program and algorithm parameters.
[0036] According to an implementable manner of the third aspect of the present invention, the AI analysis device further includes:
[0037] The information forced clearing module is used to forcibly clear the AI algorithm program and algorithm parameters in the memory before shutdown or restart.
[0038] The fourth aspect of the present invention provides an AI management and control center, including:
[0039] The first receiving module is used to receive the trusted verification results regularly reported by the AI analysis device; the trusted verification results are obtained by the AI analysis device based on trusted verification technology to perform regular trusted verification on its own target programs and systems, and the target programs and systems include BIOS, BootLoader, and / or operating system;
[0040] The AIK certificate distribution module is used to receive the AIK certificate application carried by the AI analysis device and feedback the corresponding AIK certificate to the AI analysis device based on the AIK. The AIK is an identity authentication key applied by the AI analysis device to the embedded trusted password module and feedback when the trusted password module determines that the device is in a trusted state based on the current trusted verification result of the AI analysis device.
[0041] The second receiving module is used to receive the application request for AI operation information including the AI algorithm program and algorithm parameters sent by the AI analysis device. The application request includes the AIK certificate and the public key generated by the trusted password module embedded in the AI analysis device.
[0042] The AI operation information encryption module is used to encrypt the corresponding latest AI operation information using the public key when it is determined that the device is in a trusted state based on the received current trusted verification result according to the application request, and feedback the obtained encrypted AI operation information to the AI analysis device.
[0043] According to an implementable manner of the fourth aspect of the present invention, the AIK certificate distribution module includes:
[0044] The review unit is used to review the AIK certificate application according to the preset security policy, generate the AIK certificate corresponding to the AIK after the review is passed, and feedback it to the AI analysis device.
[0045] The fifth aspect of the present invention provides an artificial intelligence system protection device, including an AI analysis device and an AI control center, and the AI analysis device is embedded with a trusted password module;
[0046] The AI analysis device is used to perform regular trusted verification on its own target programs and systems based on trusted verification technology to obtain a trusted verification result. The target programs and systems include BIOS, BootLoader, and / or operating system. The AI analysis device is also used to send an AIK query request carrying the current trusted verification result to the embedded trusted password module;
[0047] The trusted password module is used to feedback the AIK to the AI analysis device according to the AIK query request when it is determined that the device is in a trusted state based on the current trusted verification result.
[0048] The AI analysis device is also used to send an AIK certificate application carrying the AIK to the AI control center. The AI control center is used to feedback the corresponding AIK certificate to the AI analysis device based on the AIK;
[0049] The AI analysis device is further configured to receive and save the AIK certificate, regularly report the trust verification results obtained during trust verification to the AI management and control center, and send a request for application for AI operation information including the AI algorithm program and algorithm parameters to the AI management and control center; the application request includes the AIK certificate and the public key generated by the trusted password module;
[0050] The AI management and control center is further configured to, according to the application request, when determining that the device is in a trusted state based on the currently received trust verification result, encrypt the corresponding latest AI operation information using the public key, and feed back the obtained encrypted AI operation information to the AI analysis device;
[0051] The AI analysis device is further configured to use the trusted password module to decrypt the received encrypted AI operation information according to the generated private key to obtain the AI algorithm program and algorithm parameters.
[0052] According to an implementable manner of the fifth aspect of the present invention, the AI analysis device is further configured to:
[0053] When performing AI analysis based on the obtained AI algorithm program and algorithm parameters, store the obtained AI algorithm program and algorithm parameters only in the memory.
[0054] According to an implementable manner of the fifth aspect of the present invention, the AI analysis device is further configured to:
[0055] Before shutting down or restarting, forcibly clear the AI algorithm program and algorithm parameters in the memory.
[0056] According to an implementable manner of the fifth aspect of the present invention, the AI management and control center is specifically configured to:
[0057] Review the AIK certificate application according to the preset security policy, and generate and feed back the AIK certificate corresponding to the AIK to the AI analysis device after the review is passed.
[0058] The sixth aspect of the present invention provides an artificial intelligence system protection device, including:
[0059] A memory for storing instructions; wherein, the instructions are used to implement the artificial intelligence system protection method according to any implementable manner of the first aspect above, or the instructions are used to implement the artificial intelligence system protection method according to any implementable manner of the second aspect above;
[0060] A processor for executing the instructions in the memory.
[0061] A seventh aspect of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the artificial intelligence system protection method described in any of the ways achievable in the first aspect above, or when the computer program is executed by a processor, it implements the artificial intelligence system protection method described in any of the ways achievable in the second aspect above.
[0062] As can be seen from the above technical solutions, the present invention has the following advantages:
[0063] The AI analysis device of the present invention performs regular trusted verification on its own target program and system based on trusted verification technology, interacts with the embedded trusted password module according to the trusted verification result to obtain the AIK, regularly reports the obtained trusted verification result to the AI management and control center, and sends an AIK certificate application carrying the AIK to the AI management and control center; the AI management and control center conducts the review of the certificate application and issues the AIK certificate, and according to the AI operation information application request sent by the AI analysis device, when it is determined that the device is in a trusted state based on the currently received trusted verification result, encrypts the corresponding latest AI operation information using the public key carried in the application request and feeds it back to the AI analysis device; the AI analysis device decrypts the received encrypted AI operation information using the trusted password module to obtain the AI algorithm program and algorithm parameters; the present invention is responsible for the update and maintenance of the AI algorithm program and algorithm parameters by the AI management and control center, distributes the algorithm program and parameters to the AI analysis device according to the request, and provides a basic trusted verification function based on the trusted password module and provides security guarantee for the distribution of the AI algorithm program and parameters, avoiding the illegal tampering of the BIOS, operating system, memory, running programs, etc. of the AI analysis device, so as to effectively protect the algorithm program and algorithm parameters while meeting the frequent update requirements of the algorithm program and algorithm parameters. Description of the Drawings
[0064] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0065] Figure 1 It is a flowchart of an artificial intelligence system protection method provided in an embodiment of the first aspect of the present invention;
[0066] Figure 2 It is a flowchart of an artificial intelligence system protection method provided in an embodiment of the second aspect of the present invention;
[0067] Figure 3A structural connection block diagram of an AI analysis device provided by an embodiment of the third aspect of the present invention;
[0068] Figure 4 A structural connection block diagram of an AI management and control center provided by an embodiment of the fourth aspect of the present invention;
[0069] Figure 5 A schematic diagram of the interaction between an AI analysis device, a trusted password module, and an AI management and control center provided by an embodiment of the fifth aspect of the present invention.
[0070] Reference numerals:
[0071] 1 - Trusted verification module; 2 - AIK acquisition module; 3 - AIK certificate acquisition module; 4 - Trusted verification result reporting module; 5 - AI operation information application module; 6 - AI operation information receiving module; 7 - AI operation information decryption module; 10 - First receiving module; 20 - AIK certificate distribution module; 30 - Second receiving module; 40 - AI operation information encryption module. Detailed implementation manners
[0072] Embodiments of the present invention provide an artificial intelligence system protection method, device, AI analysis device, and management and control center, which are used to solve the technical problem of how to protect algorithm programs and algorithm parameters while meeting the frequent update requirements of algorithm programs and algorithm parameters.
[0073] To make the objectives, features, and advantages of the present invention more obvious and understandable, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the embodiments described below are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0074] An embodiment of the first aspect of the present invention provides an artificial intelligence system protection method.
[0075] Please refer to Figure 1 , Figure 1 which shows a flowchart of an artificial intelligence system protection method provided by an embodiment of the present invention.
[0076] An artificial intelligence system protection method provided by an embodiment of the present invention is executed by an AI analysis device. The AI analysis device is a field device that runs an AI algorithm program and provides data intelligent analysis for field users; a trusted password module is embedded in the AI analysis device.
[0077] An artificial intelligence system protection method provided by an embodiment of the present invention includes steps S1 - S7.
[0078] Step S1, based on the trusted verification technology, periodically perform trusted verification on the target program and system to obtain a trusted verification result; the target program and system include BIOS, BootLoader and / or operating system.
[0079] Among them, BIOS is a set of programs fixed to a ROM chip on the mainboard of the AI analysis device, which stores the most important basic input and output programs of the AI analysis device, the self-test program after power-on, and the system self-starting program. It can read and write specific information of system settings from CMOS. BootLoader is used to load the operating system, which runs after BIOS on the AI analysis device.
[0080] When performing regular trust verification on its own target program and system based on the trusted verification technology, the AI analysis device performs trust verification on the target program and system during the startup process, records the trusted verification results, and performs trusted verification regularly during operation.
[0081] It should be noted that the process of performing trustworthy verification on the target program and system itself based on the trustworthy verification technology can refer to the existing technology, and the embodiments of the present invention do not limit this.
[0082] Step S2, sending an AIK query request carrying a current trusted verification result to the embedded trusted cryptographic module, receiving and saving the AIK fed back by the trusted cryptographic module when determining that the device is in a trusted state based on the current trusted verification result.
[0083] Specifically, the trusted cryptographic module determines whether the AI analysis device is in a trusted state based on the trusted verification result obtained in step S1. If it is in a trusted state, it returns AIK; otherwise, it refuses to return and issues an alarm. AIK is preset according to the trusted standard when the trusted cryptographic module leaves the factory. It is unique, and the AIKs of any two modules are different. AIK serves as the identity identifier of the AI analysis device to ensure the uniqueness of the identity of the AI analysis device.
[0084] In the embodiment of the present invention, a trusted cryptographic module is used to provide a basic trusted verification function to ensure that the BIOS, operating system, memory, running programs, etc. of the AI analysis device are not illegally tampered with, thereby providing security protection for the distribution of AI algorithm programs and parameters.
[0085] Step S3: Send an AIK certificate application carrying the AIK to the AI control center, and receive and save the AIK certificate fed back by the AI control center based on the AIK.
[0086] In the embodiments of the present invention, the AI control center is responsible for managing the AIK certificates of all AI analysis devices. As a specific implementation, the AI control center reviews the AIK certificate applications according to the security policy, generates AIK certificates after the review is passed, and returns the AIK certificates to the AI analysis devices.
[0087] Among them, the security policy can be set according to the actual situation. For example, the AIK list is stored in the AI control center in advance. When receiving the AIK certificate application sent by the AI analysis device carrying the AIK, the AIK is matched with each standard AIK in the AIK list, and when the matching is successful, it is determined that the AIK certificate application is reviewed and passed.
[0088] Step S4: Regularly report to the AI control center the trusted verification results obtained during the trusted verification.
[0089] Since the AI analysis device performs trusted verification regularly, it can report to the AI control center immediately or with a certain delay each time the trusted verification result is obtained.
[0090] In the embodiments of the present invention, the AI control center manages the trusted verification results of all AI analysis devices.
[0091] As a specific real-time method, when the AI analysis device fails to regularly report the trusted verification results or the reported verification results are untrusted, the AI control center suspends providing the AI algorithm program and parameter distribution and update services to it.
[0092] Step S5: Send an application request for AI operation information including the AI algorithm program and algorithm parameters to the AI control center; the application request includes the AIK certificate and the public key generated by the trusted password module.
[0093] Among them, the application request for the AI operation information is generated when the AI analysis device needs to perform data intelligent analysis or needs to upgrade the AI algorithm program and algorithm parameters. It can also be generated when receiving instructions uploaded by other preset terminals.
[0094] As a specific implementation, the public key generated by the trusted password module is the public key of the asymmetric key. The trusted password module generates the corresponding private key and stores it while generating the public key, and the private key always remains in the trusted password module.
[0095] By encrypting the AI operation information including the AI algorithm program and algorithm parameters through the encryption method based on the asymmetric key, the security of the AI algorithm program and algorithm parameters during the distribution process can be guaranteed.
[0096] Step S6: Receive the encrypted AI operation information fed back by the AI control center when it determines that the device is in a trusted state based on the received current trusted verification result; the encrypted AI operation information is obtained by encrypting the corresponding latest AI operation information using the public key.
[0097] Specifically, the AI control center verifies the AIK certificate in the application request, determines the device identity, and checks the trusted state of the device; for a device in a trusted state, it encrypts the current latest AI algorithm program and parameters and other AI operation information using the public key and sends it to the AI analysis device.
[0098] Step S7: Use the trusted password module to decrypt the received encrypted AI operation information according to the generated private key to obtain the AI algorithm program and algorithm parameters.
[0099] In an implementable manner, the method further includes:
[0100] When performing AI analysis based on the obtained AI algorithm program and algorithm parameters, store the obtained AI algorithm program and algorithm parameters only in the memory.
[0101] In an implementable manner, the method further includes:
[0102] Before shutting down or restarting, forcibly clear the AI algorithm program and algorithm parameters in the memory.
[0103] In the above embodiments of the present invention, the AI analysis device starts the AI program for analysis. During the operation, the AI algorithm program and algorithm parameters are only in the memory and not stored on the local disk. Before the AI analysis device shuts down or restarts, the AI algorithm program and algorithm parameters in the memory will be forcibly cleared. Through these two methods, it is possible to prevent the AI algorithm program and algorithm parameters from being illegally stolen and improve the protection intensity of the core assets of the artificial intelligence system. In addition, since the private key always remains in the trusted password module, the decryption process will be performed in the trusted password module, and the decryption result will be finally output.
[0104] An embodiment of the second aspect of the present invention provides an artificial intelligence system protection method, which is executed by the AI control center.
[0105] Please refer to Figure 2 , Figure 2 , which shows a flowchart of an artificial intelligence system protection method provided by an embodiment of the present invention.
[0106] An embodiment of the present invention provides an artificial intelligence system protection method, including:
[0107] Step S10: Receive the regular trust verification results reported by the AI analysis device; the trust verification results are obtained when the AI analysis device performs regular trust verification on its own target programs and systems based on trust verification technology, and the target programs and systems include BIOS, BootLoader, and / or operating systems.
[0108] Step S20: Receive the AIK certificate application carried by the AI analysis device and send back the corresponding AIK certificate to the AI analysis device based on the AIK; the AIK is an identity authentication key applied for by the AI analysis device from the embedded trusted password module and fed back when the trusted password module determines that the device is in a trusted state based on the current trust verification results of the AI analysis device.
[0109] Step S30: Receive the application request for AI operation information including the AI algorithm program and algorithm parameters sent by the AI analysis device; the application request includes the AIK certificate and the public key generated by the trusted password module embedded in the AI analysis device.
[0110] Step S40: According to the application request, when it is determined that the device is in a trusted state based on the currently received trust verification results, encrypt the corresponding latest AI operation information using the public key and send the encrypted AI operation information back to the AI analysis device.
[0111] In an implementable manner, the sending back the corresponding AIK certificate to the AI analysis device based on the AIK includes:
[0112] Review the AIK certificate application according to the preset security policy, and generate and send back the AIK certificate corresponding to the AIK to the AI analysis device after the review passes.
[0113] In the above embodiments of the present invention, the specific processes and functions of each step can refer to the corresponding processes and beneficial effects in the method embodiments described in the foregoing first aspect, and will not be elaborated herein.
[0114] The embodiments of the third aspect of the present invention provide an AI analysis device, which can be used to implement the artificial intelligence system protection method described in any one of the embodiments of the first aspect of the present invention.
[0115] Please refer to Figure 3 , Figure 3 which shows the structural connection block diagram of an AI analysis device provided by the embodiments of the present invention.
[0116] The AI analysis device provided by the embodiments of the present invention includes:
[0117] A trusted verification module 1, configured to perform regular trusted verification on its own target programs and systems based on trusted verification technology to obtain trusted verification results; the target programs and systems include BIOS, BootLoader, and / or operating systems;
[0118] An AIK acquisition module 2, configured to send an AIK query request carrying the current trusted verification result to the embedded trusted password module, and receive and save the AIK fed back by the trusted password module when determining that the device is in a trusted state based on the current trusted verification result;
[0119] An AIK certificate acquisition module 3, configured to send an AIK certificate application carrying the AIK to the AI control center, and receive and save the AIK certificate fed back by the AI control center based on the AIK;
[0120] A trusted verification result reporting module 4, configured to regularly report the trusted verification results obtained during trusted verification to the AI control center;
[0121] An AI operation information application module 5, configured to send an application request for AI operation information including AI algorithm programs and algorithm parameters to the AI control center; the application request includes the AIK certificate and the public key generated by the trusted password module;
[0122] An AI operation information receiving module 6, configured to receive the encrypted AI operation information fed back by the AI control center when determining that the device is in a trusted state based on the currently received trusted verification result; the encrypted AI operation information is obtained by encrypting the corresponding latest AI operation information using the public key;
[0123] An AI operation information decryption module 7, configured to use the trusted password module to decrypt the received encrypted AI operation information according to the generated private key to obtain the AI algorithm program and algorithm parameters.
[0124] In an implementable manner, the AI analysis device further includes:
[0125] A storage module, configured to only store the obtained AI algorithm program and algorithm parameters in the memory when performing AI analysis based on the obtained AI algorithm program and algorithm parameters.
[0126] In an implementable manner, the AI analysis device further includes:
[0127] An information forced clearing module, configured to forcibly clear the AI algorithm program and algorithm parameters in the memory before shutdown or restart.
[0128] In the above embodiments of the present invention, for the specific processes and functions of each module, reference may be made to the corresponding processes and beneficial effects in the method embodiments described in the foregoing first aspect, and details are not described herein again.
[0129] An embodiment of the fourth aspect of the present invention provides an AI management and control center, which can be used to implement the artificial intelligence system protection method described in any one of the embodiments of the second aspect of the present invention.
[0130] Please refer to Figure 4 , Figure 4 , which shows a structural connection block diagram of an AI management and control center provided by an embodiment of the present invention.
[0131] The AI management and control center provided by the embodiment of the present invention includes:
[0132] A first receiving module 10, configured to receive a trusted verification result regularly reported by an AI analysis device; the trusted verification result is obtained when the AI analysis device performs regular trusted verification on its own target program and system based on trusted verification technology, and the target program and system include BIOS, BootLoader, and / or an operating system;
[0133] An AIK certificate issuing module 20, configured to receive an AIK certificate application carrying an AIK sent by the AI analysis device, and feedback a corresponding AIK certificate to the AI analysis device based on the AIK; the AIK is an identity authentication key applied by the AI analysis device to an embedded trusted password module and fed back when the trusted password module determines that the device is in a trusted state based on the current trusted verification result of the AI analysis device;
[0134] A second receiving module 30, configured to receive an application request for AI operation information including an AI algorithm program and algorithm parameters sent by the AI analysis device; the application request includes the AIK certificate and a public key generated by a trusted password module embedded in the AI analysis device;
[0135] An AI operation information encryption module 40, configured to encrypt the corresponding latest AI operation information using the public key according to the application request when it is determined that the device is in a trusted state based on the currently received trusted verification result, and feedback the obtained encrypted AI operation information to the AI analysis device.
[0136] In an implementable manner, the AIK certificate issuing module 20 includes:
[0137] An auditing unit, configured to audit the AIK certificate application according to a preset security policy, and generate and feedback an AIK certificate corresponding to the AIK to the AI analysis device after the audit passes.
[0138] In the above embodiments of the present invention, the specific processes and functions of each module can refer to the corresponding processes and beneficial effects in the method embodiments described in the foregoing first aspect, and will not be elaborated herein.
[0139] An embodiment of the fifth aspect of the present invention provides an artificial intelligence system protection device.
[0140] Please refer to Figure 5 , Figure 5 which shows a schematic diagram of the interaction between the AI analysis device, the trusted password module, and the AI management and control center provided by the embodiments of the present invention.
[0141] The artificial intelligence system protection device provided by the embodiments of the present invention includes an AI analysis device and an AI management and control center, and a trusted password module is embedded in the AI analysis device;
[0142] The AI analysis device is used to perform regular trusted verification on its own target program and system based on trusted verification technology to obtain a trusted verification result; the target program and system include BIOS, BootLoader, and / or an operating system; the AI analysis device is also used to send an AIK query request carrying the current trusted verification result to the embedded trusted password module;
[0143] The trusted password module is used to, according to the AIK query request, when determining that the device is in a trusted state based on the current trusted verification result, feedback the AIK to the AI analysis device;
[0144] The AI analysis device is also used to send an AIK certificate application carrying the AIK to the AI management and control center; the AI management and control center is used to feedback a corresponding AIK certificate to the AI analysis device based on the AIK;
[0145] The AI analysis device is also used to receive and save the AIK certificate, regularly report the trusted verification result obtained during trusted verification to the AI management and control center, and send an application request for AI operation information including an AI algorithm program and algorithm parameters to the AI management and control center; the application request includes the AIK certificate and a public key generated by the trusted password module;
[0146] The AI management and control center is also used to, according to the application request, when determining that the device is in a trusted state based on the currently received trusted verification result, encrypt the corresponding latest AI operation information using the public key, and feedback the obtained encrypted AI operation information to the AI analysis device;
[0147] The AI analysis device is also used to use the trusted password module to decrypt the received encrypted AI operation information according to the generated private key to obtain the AI algorithm program and algorithm parameters.
[0148] In an implementable manner, the AI analysis device is further configured to:
[0149] When performing AI analysis based on the obtained AI algorithm program and algorithm parameters, store the obtained AI algorithm program and algorithm parameters only in the memory.
[0150] In an implementable manner, the AI analysis device is further configured to:
[0151] Before shutting down or restarting, forcibly clear the AI algorithm program and algorithm parameters in the memory.
[0152] In an implementable manner, the AI control center is specifically configured to:
[0153] Review the AIK certificate application according to the preset security policy, and generate an AIK certificate corresponding to the AIK and feedback it to the AI analysis device after the review is passed.
[0154] In the above embodiments of the present invention, for the specific execution processes and effects of the AI analysis device, the trusted password module, and the AI control center, reference may be made to the corresponding processes and beneficial effects in the method embodiments described in the foregoing first aspect, and details are not described herein again.
[0155] An embodiment of the sixth aspect of the present invention provides an artificial intelligence system protection device, including:
[0156] A memory for storing instructions; wherein, the instructions are used to implement the artificial intelligence system protection method described in any implementable manner of the above first aspect embodiment, or, the instructions are used to implement the artificial intelligence system protection method described in any implementable manner of the above second aspect embodiment;
[0157] A processor for executing the instructions in the memory.
[0158] An embodiment of the seventh aspect of the present invention provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the artificial intelligence system protection method described in any implementable manner of the above first aspect embodiment, or, when the computer program is executed by a processor, it implements the artificial intelligence system protection method described in any implementable manner of the above second aspect embodiment.
[0159] In the above embodiments of the present invention, a trusted password module is used to provide a basic trusted verification function to ensure that the BIOS, operating system, memory, running programs, etc. of the AI analysis device are not illegally tampered with, providing security for the distribution of AI algorithm programs and parameters; the algorithm programs and algorithm parameters are not stored locally, but are applied to the AI management center only when in use, and the security of the distribution of algorithm programs and parameters is protected through trusted technologies, which can effectively protect the core assets of the artificial intelligence system; when the AI analysis device needs to perform data intelligent analysis or needs to upgrade the AI algorithm program and algorithm parameters, an application request for AI operation information including the AI algorithm program and algorithm parameters is generated, and then the AI management center uses the public key carried in the request to update the corresponding latest AI operation information, which can realize the update of the AI algorithm program and algorithm parameters according to the request, thus meeting the requirements of frequent updates of the AI algorithm program and algorithm parameters, and the method is simple and convenient.
[0160] In several embodiments provided in the present application, it should be understood that the disclosed devices, equipment, management centers, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division. In actual implementation, there may be other division methods. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or modules can be in electrical, mechanical, or other forms.
[0161] The modules described as separate components may or may not be physically separated. The components shown as modules may or may not be physical modules, that is, they may be located in one place, or may be distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0162] In addition, in each embodiment of the present invention, the functional modules can be integrated into one processing module, or each module can exist physically alone, or two or more modules can be integrated into one module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules.
[0163] When the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs.
[0164] As described above, the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A method for protecting an artificial intelligence system, characterized in that, The method is executed by an AI analysis device, and the method includes: Performing regular trusted verification on its own target programs and systems based on trusted verification technology to obtain trusted verification results; the target programs and systems include BIOS, BootLoader, and / or operating systems; Sending an AIK query request carrying the current trusted verification result to the embedded trusted password module, and receiving and saving the AIK fed back by the trusted password module when it determines that the device is in a trusted state based on the current trusted verification result; Sending an AIK certificate application carrying the AIK to the AI management center, and receiving and saving the AIK certificate fed back by the AI management center based on the AIK; Regularly reporting the trusted verification results obtained during trusted verification to the AI management center; Sending an application request for AI operation information including AI algorithm programs and algorithm parameters to the AI management center; the application request includes the AIK certificate and the public key generated by the trusted password module of the AI analysis device; Receiving the encrypted AI operation information fed back by the AI management center when it determines that the device is in a trusted state based on the received current trusted verification result; the encrypted AI operation information is obtained by encrypting the corresponding latest AI operation information using the public key; Using the trusted password module to decrypt the received encrypted AI operation information according to the generated private key to obtain the AI algorithm program and algorithm parameters.
2. The method for protecting an artificial intelligence system according to claim 1, wherein The method further includes: When performing AI analysis based on the obtained AI algorithm program and algorithm parameters, storing the obtained AI algorithm program and algorithm parameters only in the memory.
3. The method for protecting an artificial intelligence system according to claim 2, wherein, The method further includes: Before shutting down or restarting, forcibly clearing the AI algorithm program and algorithm parameters in the memory.
4. A method for protecting an artificial intelligence system, characterized in that, The method is executed by an AI management center, and the method includes: Receiving the trusted verification results regularly reported by the AI analysis device; the trusted verification results are obtained by the AI analysis device performing regular trusted verification on its own target programs and systems based on trusted verification technology, and the target programs and systems include BIOS, BootLoader, and / or operating systems; Receiving the AIK certificate application carrying the AIK sent by the AI analysis device, and feeding back the corresponding AIK certificate to the AI analysis device based on the AIK; the AIK is an identity authentication key applied for by the AI analysis device to the embedded trusted password module and fed back by the trusted password module when it determines that the device is in a trusted state based on the current trusted verification result of the AI analysis device; Receiving the application request for AI operation information including AI algorithm programs and algorithm parameters sent by the AI analysis device; the application request includes the AIK certificate and the public key generated by the trusted password module embedded in the AI analysis device; According to the application request, when it is determined that the device is in a trusted state based on the received current trusted verification result, encrypting the corresponding latest AI operation information using the public key, and feeding back the obtained encrypted AI operation information to the AI analysis device.
5. The method for protecting an artificial intelligence system according to claim 4, wherein The feeding back the corresponding AIK certificate to the AI analysis device based on the AIK includes: Review the AIK certificate application according to the preset security policy. After the review is passed, generate an AIK certificate corresponding to the AIK and feedback it to the AI analysis device.
6. An AI analysis device, characterized in that, Including: A trusted verification module, configured to perform regular trusted verification on its own target programs and systems based on trusted verification technology to obtain trusted verification results; the target programs and systems include BIOS, BootLoader, and / or operating systems; An AIK acquisition module, configured to send an AIK query request carrying the current trusted verification result to the embedded trusted password module, and receive and save the AIK feedback by the trusted password module when determining that the device is in a trusted state based on the current trusted verification result; An AIK certificate acquisition module, configured to send an AIK certificate application carrying the AIK to the AI management center, and receive and save the AIK certificate feedback by the AI management center based on the AIK; A trusted verification result reporting module, configured to regularly report the trusted verification results obtained during trusted verification to the AI management center; An AI operation information application module, configured to send an application request for AI operation information including AI algorithm programs and algorithm parameters to the AI management center; the application request includes the AIK certificate and the public key generated by the trusted password module; An AI operation information receiving module, configured to receive the encrypted AI operation information feedback by the AI management center when determining that the device is in a trusted state based on the currently received trusted verification result; the encrypted AI operation information is obtained by encrypting the corresponding latest AI operation information using the public key; An AI operation information decryption module, configured to use the trusted password module to decrypt the received encrypted AI operation information according to the generated private key to obtain the AI algorithm program and algorithm parameters.
7. An AI control center, characterized in that, Including: A first receiving module, configured to receive the trusted verification results regularly reported by the AI analysis device; the trusted verification results are obtained by the AI analysis device performing regular trusted verification on its own target programs and systems based on trusted verification technology, and the target programs and systems include BIOS, BootLoader, and / or operating systems; An AIK certificate distribution module, configured to receive the AIK certificate application carrying the AIK sent by the AI analysis device, and feedback the corresponding AIK certificate to the AI analysis device based on the AIK; the AIK is an identity authentication key applied by the AI analysis device to the embedded trusted password module and feedback when the trusted password module determines that the device is in a trusted state based on the current trusted verification result of the AI analysis device; A second receiving module, configured to receive the application request for AI operation information including AI algorithm programs and algorithm parameters sent by the AI analysis device; the application request includes the AIK certificate and the public key generated by the trusted password module embedded in the AI analysis device; The AI operation information encryption module is used to encrypt the corresponding latest AI operation information with the public key when it is determined that the device is in a trusted state based on the received current trusted verification result according to the application request, and feedback the obtained encrypted AI operation information to the AI analysis device.
8. An artificial intelligence system protection device, characterized in that, It includes an AI analysis device and an AI management and control center, and the AI analysis device is embedded with a trusted password module; The AI analysis device is used to perform regular trusted verification on its own target programs and systems based on trusted verification technology to obtain a trusted verification result; the target programs and systems include BIOS, BootLoader, and / or operating system; the AI analysis device is also used to send an AIK query request carrying the current trusted verification result to the embedded trusted password module; The trusted password module is used to feedback AIK to the AI analysis device when it is determined that the device is in a trusted state based on the current trusted verification result according to the AIK query request; The AI analysis device is also used to send an AIK certificate application carrying the AIK to the AI management and control center; the AI management and control center is used to feedback the corresponding AIK certificate to the AI analysis device based on the AIK; The AI analysis device is also used to receive and save the AIK certificate, regularly report the trusted verification result obtained during trusted verification to the AI management and control center, and send an application request for AI operation information including AI algorithm programs and algorithm parameters to the AI management and control center; the application request includes the AIK certificate and the public key generated by the trusted password module; The AI management and control center is also used to encrypt the corresponding latest AI operation information with the public key when it is determined that the device is in a trusted state based on the received current trusted verification result according to the application request, and feedback the obtained encrypted AI operation information to the AI analysis device; The AI analysis device is also used to decrypt the received encrypted AI operation information with the private key generated by the trusted password module to obtain the AI algorithm program and algorithm parameters.
9. An artificial intelligence system protection device, characterized in that, It includes: A memory for storing instructions; wherein, the instructions are used to implement the artificial intelligence system protection method described in any one of claims 1-3, or the instructions are used to implement the artificial intelligence system protection method described in claim 4 or 5; A processor for executing the instructions in the memory.
10. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is executed by the processor, it implements the artificial intelligence system protection method described in any one of claims 1-3, or when the computer program is executed by the processor, it implements the artificial intelligence system protection method described in claim 4 or 5.
Citation Information
Patent Citations
Anonymous digital certificate system and verification method of trustable computing environment
CN102594558A
Method and system for credible authentication between modules in intelligent networked vehicle
CN112187459A