An architecture system and method for a secure and trustworthy execution environment for running an artificial intelligence model

By introducing TEE pipelines, key management modules and cryptographic modules into the artificial intelligence model operation environment, combined with encryption technology, the security and reliability problems of the model in the training, deployment and execution process are solved, and efficient and secure model protection is achieved, suitable for a variety of operating systems and platforms.

CN117786694BActive Publication Date: 2025-07-22BEIJING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311717652.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-14
Publication Date
2025-07-22
Estimated Expiration
2043-12-14

AI Technical Summary

Technical Problem

The existing technology cannot effectively protect the security and reliability of artificial intelligence models during training, deployment and execution, especially when facing emerging threats such as quantum computing, traditional encryption technologies and access control mechanisms have limitations and risks. The TEE architecture relies on the security of host operating systems and hardware platforms to be easily affected.

Method used

An artificial intelligence model operation security and trusted execution environment architecture is designed, including TEE pipelines, key management modules, cryptographic modules and computing modules. Data transmission and security detection are realized through dedicated channels. The integrated computing modules are trained, deployed and executed by model, and independent cryptographic modules are encrypted and decrypted. Key management is generated and stored in a trusted execution environment. It is protected by attributes, homomorphism, zero-knowledge and hybrid encryption technologies.

Benefits of technology

It improves the security of the artificial intelligence model, prevents theft and tampering, provides hardware isolation and encryption protection, supports multi-level algorithm logic, has high computing efficiency, good compatibility, reduces development and maintenance costs, and enhances trustworthiness and flexibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117786694B_ABST
    Figure CN117786694B_ABST
Patent Text Reader

Abstract

An architecture and method for a secure and trustworthy execution environment for running an artificial intelligence model, belonging to the field of artificial intelligence model security protection. The architecture includes a TEE pipeline, a key management module, a cryptographic module, a computing module, and a controller. Data transmission and security detection are achieved through the TEE channel to ensure the security and effectiveness of data; the computing module is used for model training, deployment, and execution, and the independent cryptographic module and key management module are used to encrypt the trained model and decrypt the encrypted model transmitted from the external environment, greatly improving the security of the artificial intelligence model. Moreover, the key generation process, key storage, and cryptographic module are all integrated into the trusted execution environment architecture, the key will not be leaked, and the operation of the model is also protected by the trusted execution environment architecture, effectively preventing the model from being stolen and modified by attackers. The present invention has high operation efficiency, high security, strong trustworthiness, high flexibility, good compatibility, and low cost.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of artificial intelligence model security protection, and specifically relates to an architecture and method for a secure and trustworthy execution environment for the operation of an artificial intelligence model. Background Art

[0002] An artificial intelligence model is a computational model that uses data and algorithms to simulate human intelligence. Artificial intelligence models can perform various tasks, such as image recognition, natural language processing, speech recognition, recommendation systems, etc. Artificial intelligence models usually require a large amount of data and computing resources for training and deployment. Artificial intelligence models also face security issues, such as being stolen, tampered with, or attacked. Stealing an artificial intelligence model means obtaining the parameters or structure of the model, thereby replicating or exploiting the functions of the model. Tampering with an artificial intelligence model means modifying the parameters or structure of the model, thereby changing or reducing the performance of the model. Attacking an artificial intelligence model means inputting specific data or noise, thereby causing the model to produce incorrect or unexpected outputs.

[0003] TEE (Trusted Execution Environment) is an independent processing environment with computing and storage functions that can provide security and integrity protection. Its basic idea is: allocate a separate isolated memory for sensitive data in the hardware, and all calculations of sensitive data are performed in this memory. And except for authorized interfaces, other parts of the hardware cannot access the information in this isolated memory, so as to achieve the privacy calculation of sensitive data. TEE can protect application programs from external interference and attacks, and at the same time protect the sensitive data processed by the application programs from being leaked or tampered with. There are various implementation methods of TEE, such as hardware-based TEE (such as Intel SGX, ARM TrustZone, etc.) and software-based TEE (such as SEV, Sanctuary, etc.). Different TEE architectures have different characteristics and limitations. For example, hardware-based TEE usually requires specific costs and support, while software-based TEE usually requires more overhead and complexity. A trusted environment is a security solution based on TEE technology, which can provide trusted services and applications for fields such as cloud computing, edge computing, and the Internet of Things. A trusted environment can ensure the confidentiality, integrity, and availability of data, and at the same time support multi-party collaboration and computing. There are also some problems with the trusted environment, such as the existing TEE not meeting the requirements for the secure execution of artificial intelligence models.

[0004] Currently, the closest prior art to the present invention is as follows:

[0005] 1. ARM TrustZone: ARM TrustZone is an architecture proposed by ARM for the security of consumer electronic devices. ARM processors with TrustZone implement architectural security extensions, where each physical processor core provides two virtual cores, one considered non-secure and the other secure. TEE system based on TrustZone: TrustZone provides the TEE through a securely isolated secure world. Depending on the different trusted programs running in the secure world, the TEE it provides can be divided into two categories: TEE kernel and TEE services. In the TEE kernel, the trusted program implements a set of basic OS functions to manage multiple TEE instances, and each instance hosts a specific application. The functions implemented by the TEE kernel are: managing the memory of the secure world, implementing memory protection for each TEE, handling the communication between the TEE and the OS, and providing APIs for TEE applications. Different from the TEE kernel, TEE services only implement a specific function, and they do not require any low-level OS logic to manage their own memory and cross-world communication. To avoid interference with each other, only one TEE service can be deployed on the device. Compared with the TEE kernel, this is a disadvantage, as the latter allows multiple applications to run in independent TEE instances. However, the disadvantage of the TEE kernel is that, compared with a system deploying a single TEE service, they usually rely on a larger TCB, which means that there may be more vulnerabilities in the TEE kernel compared to TEE services. Common TEE services include: trusted storage, secure authentication and encryption, Rich OS verification and monitoring, trusted I / O, etc.

[0006] 2. Intel SGX: Intel SGX (Software Guard eXtensions) is a TEE architecture proposed by Intel, which can provide hardware-level isolation and protection in a computer system. SGX protects applications and data by running applications in a protected execution environment. An enclave is a protected content container for storing sensitive application data and code. SGX allows applications to specify the parts of code and data that need to be protected. Before creating an enclave, these codes and data do not have to be inspected or analyzed, but the codes and data loaded into the enclave must be measured. When the parts of the application that need to be protected are loaded into the enclave, SGX protects them from being accessed by external software. An enclave can prove its identity to a remote authenticator and provide the necessary functional structures for securely providing keys. Users can also request unique keys, which are made unique by combining the enclave identity and the platform identity and can be used to protect keys or data stored outside the enclave. All enclaves reside in the EPC (enclave page cache), which is a protected physical memory area within the system for storing enclaves and SGX data structures. Enclaves have the following characteristics: (1) having their own code and data; (2) providing confidentiality protection; (3) providing integrity protection; (4) having a controllable entry point; (5) supporting multi-threading; (6) having the highest access rights to application memory.

[0007] In the prior art, the security protection of artificial intelligence models mainly relies on traditional encryption technologies and access control mechanisms. For example, symmetric encryption or asymmetric encryption algorithms are used to encrypt the model, and cryptographic protocols or digital signatures are used to implement access control. However, these technologies have great limitations and risks in the face of emerging technologies such as quantum computers. For example, a quantum computer can use quantum algorithms to crack traditional encryption algorithms, thereby obtaining the plaintext or key of the model; a quantum computer can also use quantum attack technologies to bypass the access control mechanism, thereby obtaining the access rights of the model or tampering with the content of the model.

[0008] There are many ways to implement TEE, such as hardware-based TEE such as Intel SGX and ARM TrustZone. The purpose of these TEEs is to protect sensitive data and code from malicious software or hardware attacks. However, Intel SGX and ARM TrustZone also have some problems. Intel SGX and ARM TrustZone are not based on an independent piece of hardware, but use a dedicated memory area or CPU core to isolate and execute protected applications. This means that they still rely on the security of the host operating system and hardware platform. If these components are compromised, the TEE may also be affected. Intel SGX and ARM TrustZone are not designed specifically for artificial intelligence models. When artificial intelligence models run in these environments, there is a high risk of model leakage.

[0009] In summary, how to ensure the security, reliability and efficiency of artificial intelligence models during model training, model deployment and model execution, and prevent the models from being maliciously tampered with or stolen is the primary issue that needs to be addressed in this field. Summary of the invention

[0010] In order to solve the problems existing in the prior art, the present invention proposes a secure and trusted execution environment architecture and method for artificial intelligence model operation. The present invention can effectively ensure the security, reliability and efficiency of artificial intelligence models during model training, model deployment and model execution, and prevent the models from being maliciously tampered with or stolen.

[0011] The technical solution adopted by the present invention to solve the technical problem is as follows:

[0012] An artificial intelligence model running secure and trusted execution environment architecture of the present invention mainly includes the following modules:

[0013] The TEE pipeline is used to receive function selection requests from the external environment, open the corresponding function data transmission channel, and make corresponding requests to the controller according to the request content; and, to receive data input from the external environment to the internal environment, and perform security detection on the input data; and, to input the encrypted artificial intelligence model with secure detection results into the cryptographic module for decryption; and, to input the secure detection result data and model parameters into the computing module for prediction or deployment; and, to receive data output from the internal environment to the external environment,

[0014] A key management module, used to receive a request from the cryptographic module to read the key, and return the key of the corresponding artificial intelligence model according to the request content; and, used to receive a request from the cryptographic module to store the key, and store the transmitted key and related information;

[0015] A password module, which is used to receive encryption and decryption requests from a controller, communicate with a key management module according to the request content, and perform corresponding encryption and decryption operations; and, which is used to encrypt an artificial intelligence model using encryption technology, sign the encrypted artificial intelligence model file; and, which is used to decrypt the input encrypted artificial intelligence model according to the input user information and the key information stored in the key management module.

[0016] A computing module, which is used to receive artificial intelligence model deployment and execution requests from a controller, and load corresponding artificial intelligence model files according to the request content; and, which is used to receive the decrypted artificial intelligence model from the password module, parse and compile the artificial intelligence model file, and convert the structure and parameters of the artificial intelligence model into a format and instructions suitable for the computing module; and, which is used to receive the secure data and model parameters of the detection results from the TEE pipeline, and perform network construction; and, which is used to perform calculations and inferences on the artificial intelligence model, and output corresponding results according to the input data.

[0017] A controller, which is used to receive requests from the TEE pipeline, and schedule each module according to the request content; and, which is used to select a suitable computing module for the deployment and execution of the artificial intelligence model according to the parameters of the artificial intelligence model file; and, which is used to dynamically adjust various parameters of the computing module to optimize the performance and efficiency of the artificial intelligence model; and, which is used to monitor the status and operation of the computing module in real time; and, which is used to send control commands to the password module and the key management module.

[0018] Furthermore, the data input from the external environment to the internal environment includes: an encrypted artificial intelligence model, a training data set, model parameters, test data, and user information.

[0019] Furthermore, the security detection of the input data includes: data integrity, data representativeness, noise detection, deviation between training data and test data, data poisoning or hostile information, and whether there is a backdoor in the model.

[0020] Furthermore, the output data includes: an encrypted trained artificial intelligence model and model output results.

[0021] Furthermore, the encryption technology is: attribute-based endogenous access control encryption technology, homomorphic encryption technology, zero-knowledge proof technology, or hybrid encryption technology.

[0022] An artificial intelligence model operation security and trusted execution method provided by the present invention is implemented by using the above-mentioned artificial intelligence model operation security and trusted execution environment architecture. The method includes the following steps:

[0023] Select a specific function through the TEE pipeline. The functions include the function of training a model and the function of model prediction. When the function of training a model is selected, the training data set, model parameters, and user information are input through the TEE pipeline. The TEE pipeline will perform security detection on the input data. If the input data is secure, the detected secure training data set and model parameters will be directly input into the computing module to build a network and train. The trained model will be input into the password module. The password module will select the corresponding encryption technology to encrypt the model according to the input user information and store the key in the key management module. After the model is encrypted, it will be output from the TEE pipeline, and the model training ends. If the input data is not secure, a prompt message will be directly output and the process will end.

[0024] When the function of model prediction is selected, the test data, encrypted model, and user information are input through the TEE pipeline. The TEE pipeline will perform security detection on the input data. If the input data is secure, the detected secure encrypted model and user information will be input into the password module. The password module will decrypt the model according to the input user information and the key stored in the key management module. If the user information does not match, the decryption will fail and a prompt message will be directly output and the process will end. The decrypted model will be deployed to the computing module and wait for the input of test data. The test data that passes the security detection will be input into the computing module as the input of the model, and the prediction result will be obtained. The prediction result will be output from the TEE pipeline to complete the prediction model function.

[0025] The beneficial effects of the present invention are as follows:

[0026] The present invention designs a dedicated TEE channel for the communication between the inside and outside of the trusted execution environment architecture. This TEE channel can achieve data transmission and security detection, thereby ensuring the security and effectiveness of the data entering the internal environment of the trusted execution environment architecture. At the same time, a computing module is integrated in the trusted execution environment architecture for the training, deployment, and execution of the model. An independent password module and key management module are integrated to encrypt the trained model and decrypt the encrypted model transmitted from the external environment, greatly improving the security of the artificial intelligence model. And the key generation process is in the internal environment of the trusted execution environment architecture, the key is stored in the internal environment of the trusted execution environment architecture, and the password module is also integrated in the internal environment of the trusted execution environment architecture. Therefore, the key will not be leaked, and the operation of the model is also protected by the trusted execution environment architecture, effectively preventing the artificial intelligence model from being stolen and modified by attackers, and can effectively resist side-channel attacks and physical attacks.

[0027] In addition, the present invention also has the following advantages:

[0028] 1. The trusted execution environment architecture supports the implementation of multi-level and highly complex algorithm logics;

[0029] 2. The trusted execution environment architecture has high computing efficiency;

[0030] 3. High security; The trusted execution environment architecture can provide hardware isolation and encryption protection to protect the security and privacy of sensitive data and code. The data and code in the trusted execution environment architecture cannot be accessed or tampered with by malware, thus improving security.

[0031] 4. Strong trustworthiness; The trusted execution environment architecture provides a trusted execution environment to ensure that applications run in a protected environment. At the same time, it can verify the source and integrity of the applications to ensure that the applications have not been tampered with.

[0032] 5. High flexibility; The trusted execution environment architecture is a programmable execution environment that can support multiple applications and security protocols. Its software can be upgraded or updated as needed to adapt to different security requirements.

[0033] 6. Good compatibility; The trusted execution environment architecture can be compatible with various operating systems and platforms, such as Android, iOS, Windows, and Linux, etc., and can be used in different environments.

[0034] 7. Cost savings; The trusted execution environment architecture can provide a secure execution environment, reducing the cost of developing and deploying secure applications. Since the trusted execution environment architecture is hardware-isolated, it can reduce the dependence on software security and lower the cost of software development and maintenance. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 It is a structural diagram of a secure and trusted execution environment architecture for running an artificial intelligence model according to the present invention.

[0036] Figure 2 It is a flowchart of a secure and trusted execution method for running an artificial intelligence model according to the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0037] The present invention will be further described in detail below with reference to the accompanying drawings.

[0038] In a first aspect, the present invention provides a secure and trusted execution environment architecture for running an artificial intelligence model.

[0039] See Figure 1 For a detailed description, a secure and trusted execution environment architecture for running an artificial intelligence model according to the present invention mainly includes the following modules: TEE pipeline, key management module, cryptographic module, computing module, and controller.

[0040] 1. TEE pipeline

[0041] The TEE pipeline is a component that controls the communication between the internal and external environments of the trusted execution environment architecture. It is used to input data from the external environment, such as encrypted artificial intelligence models, training datasets, model parameters, test data, user information, etc., and determine whether the input data is secure; and to output data from the internal environment (the trusted execution environment of the artificial intelligence model), such as the encrypted trained artificial intelligence model, model output results, etc.

[0042] The present invention designs a dedicated TEE channel for the communication between the internal and external parts of the trusted execution environment architecture. This TEE channel can achieve data transmission and security detection, thereby ensuring the security and effectiveness of the data entering the internal environment of the trusted execution environment architecture.

[0043] Among them, the TEE pipeline can be implemented using technologies such as the GlobalPlatform TEE Internal Core API Specification or the TEE Client API Specification.

[0044] The TEE pipeline has the following functions:

[0045] (1) Receive a function selection request from the external environment, open the corresponding function data transmission channel, and make a corresponding request to the controller according to the request content.

[0046] (2) Receive the data input from the external environment to the internal environment. The input data can be an encrypted artificial intelligence model, training dataset, model parameter, test data, user information, etc., and perform a security detection on the input data and determine whether the input data is secure, such as data integrity, data representativeness, noise detection, deviation between training data and test data, data poisoning or hostile information, whether there is a backdoor in the model, etc.

[0047] (3) For the encrypted artificial intelligence model with a secure detection result, input it into the cryptographic module for decryption.

[0048] (4) For the data and model parameters with a secure detection result, input them into the computing module for prediction or deployment.

[0049] (5) Receive the data output from the internal environment to the external environment. The output data can be the encrypted trained artificial intelligence model, model output results, etc.

[0050] 2. Key management module

[0051] The key management module is a component that provides storage functions for the cryptographic module, used to store keys, provide keys, etc.

[0052] The key management module has the following functions:

[0053] (1) Receive requests for reading keys from the cryptographic module and return the keys of the corresponding artificial intelligence model according to the request content.

[0054] (2) Receive requests for storing keys from the cryptographic module and store the transmitted keys and related information.

[0055] (3) The controller sends a key storage request and a key distribution request to the key management module: the key storage request allows the key management module to store the keys from the cryptographic module; the key distribution request allows it to send the keys of the corresponding model to the cryptographic module.

[0056] 3. Cryptographic module

[0057] The cryptographic module is a component that provides cryptographic services for the controller and is used to generate keys, encryption algorithms, decryption algorithms, signature algorithms, etc.

[0058] Among them, the cryptographic module can be a dedicated hardware device, such as a quantum random number generator, a quantum key distributor, etc.

[0059] The cryptographic module has the following functions:

[0060] (1) Receive encryption and decryption requests from the controller and communicate with the key management module according to the request content to perform corresponding encryption and decryption operations.

[0061] (2) Use encryption technology to encrypt the artificial intelligence model, and the encrypted artificial intelligence model file can be signed to achieve protection of the integrity, non-repudiation, traceability, etc. of the artificial intelligence model. Among them, the encryption technology mentioned can specifically select: attribute-based endogenous access control encryption technology, homomorphic encryption technology, zero-knowledge proof technology, or hybrid encryption technology, etc. But not limited to this.

[0062] (3) Decrypt the input encrypted artificial intelligence model according to the input user information and the key information stored in the key management module.

[0063] 4. Computing module

[0064] The computing module is a module specifically designed for artificial intelligence applications. It can accelerate the operation and processing of artificial intelligence algorithms at the hardware level, improving the efficiency and performance of artificial intelligence algorithms.

[0065] Among them, the computing module can specifically use an AI chip. An AI chip is an integrated circuit chip specifically designed for artificial intelligence applications. It can accelerate the operation and processing of artificial intelligence algorithms at the hardware level, improving the efficiency and performance of the algorithms. The core of the AI chip is to use a multiplier and accumulation (MAC) array to accelerate the most important convolution operation in the convolutional neural network.

[0066] The computing module has the following functions:

[0067] (1) Receive the artificial intelligence model deployment and execution requests from the controller, and load the corresponding artificial intelligence model files according to the request content.

[0068] (2) Receive the decrypted artificial intelligence model from the cryptographic module, parse and compile the artificial intelligence model file, and convert the structure and parameters of the artificial intelligence model into a format and instructions suitable for the computing module.

[0069] (3) Receive the secure data and model parameters of the detection results from the TEE pipeline, and perform network construction.

[0070] (4) Perform calculations and inferences on the artificial intelligence model, and output corresponding results according to the input data.

[0071] 5. Controller

[0072] The controller is a component responsible for managing and scheduling the deployment and operation of artificial intelligence models in a trusted execution environment.

[0073] The controller has the following functions:

[0074] (1) Receive requests from the TEE pipeline, and schedule each module according to the request content.

[0075] (2) Select a suitable computing module for the deployment and execution of the artificial intelligence model according to parameters such as the type, scale, and complexity of the artificial intelligence model file.

[0076] (3) Dynamically adjust the parameters of the computing module to optimize the performance and efficiency of the artificial intelligence model.

[0077] (4) Monitor the status and operation of the computing module in real time to ensure the security and reliability of the artificial intelligence model.

[0078] (5) Control the cryptographic module and the key management module by sending control commands to them.

[0079] In a second aspect, the present invention provides a method for securely and trustworthily executing the operation of an artificial intelligence model.

[0080] See Figure 2 For a detailed description, a method for securely and trustworthily executing an artificial intelligence model of the present invention mainly includes the following steps:

[0081] First, it is necessary to select the specific function to be used through the TEE pipeline. For example, whether to train the model. If so, that is, when using the model training function, input the training data set, model parameters, and user information through the TEE pipeline. The TEE pipeline will perform security detection on the input data to ensure that the data has not been tampered with or leaked. If the input data is secure, the detected secure training data set and model parameters will be directly input into the computing module to build a network and train. The trained model will be input into the password module. The password module will select the corresponding encryption technology according to the input user information to encrypt the model and store the key in the key management module. After the model is encrypted, it will be output from the TEE pipeline, and the model training ends. If the input data is not secure, a prompt message will be directly output and the process will end.

[0082] If the model training function is not used but the model prediction function is used, input the test data, encrypted model, and user information through the TEE pipeline. The TEE pipeline will perform security detection on the input data to ensure that the data has not been tampered with or leaked. If the input data is secure, the detected secure encrypted model and user information will be input into the password module. The password module will decrypt the model according to the input user information and the key stored in the key management module. If the user information does not match, the decryption will fail and a prompt message will be directly output and the process will end. The decrypted model will be deployed to the computing module and wait for the input of test data. The test data that passes the security detection will be input into the computing module as the input of the model, and the prediction result will be obtained. The prediction result will be output from the TEE pipeline to complete the prediction model function.

[0083] Among them, the said password module will select the corresponding encryption technology according to the input user information to encrypt the model. The encryption technologies mainly used are as follows:

[0084] (1) Use the attribute-based endogenous access control encryption technology to encrypt the model in the trusted execution environment (TEE) and protect the integrity and non-repudiation of the model. The attribute encryption technology can encrypt and decrypt according to the attributes of the model or the identity of the user, realizing fine-grained access control.

[0085] (2) Use the homomorphic encryption technology to encrypt the model in the trusted execution environment (TEE) and protect the integrity and non-repudiation of the model. The homomorphic encryption technology can perform calculations on the model in the ciphertext state without decryption, ensuring the privacy and correctness of the calculation process.

[0086] (3) Encrypt the model using zero - knowledge proof technology under the trusted execution environment (TEE), and protect the integrity and non - repudiation of the model. Zero - knowledge proof technology allows the owner of the model to prove to other parties that they own a certain model without disclosing any information about the model, achieving maximum privacy protection.

[0087] (4) Encrypt the model using hybrid encryption technology under the trusted execution environment (TEE), and protect the integrity and non - repudiation of the model. This technology combines the advantages of symmetric encryption and asymmetric encryption, abandons their respective disadvantages, and forms an efficient hybrid encryption scheme, enabling users to communicate securely and efficiently with the inside of the trusted execution environment (TEE).

[0088] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.

Claims

1. An architecture system for a secure and trustworthy execution environment for running an artificial intelligence model, characterized in that, Including: A TEE pipeline for receiving a function selection request from an external environment, opening a corresponding function data transmission channel, and making a corresponding request to a controller according to the request content; And, for receiving data input from the external environment into the internal environment and performing security detection on the input data; And, for securely encrypting the detection result and inputting the artificial intelligence model into a cryptographic module for decryption; And, for inputting the securely detected data and model parameters into a computing module for prediction or deployment; And, for receiving data output from the internal environment to the external environment, A key management module for receiving a request to read a key from the cryptographic module and returning the key of the corresponding artificial intelligence model according to the request content; and, for receiving a request to store a key from the cryptographic module and storing the transmitted key and related information; A cryptographic module for receiving an encryption / decryption request from the controller, communicating with the key management module according to the request content, and performing corresponding encryption / decryption operations; And, for encrypting the artificial intelligence model using encryption technology and signing the encrypted artificial intelligence model file; And, for decrypting the input encrypted artificial intelligence model according to the input user information and the key information stored in the key management module; A computing module for receiving an artificial intelligence model deployment and execution request from the controller and loading the corresponding artificial intelligence model file according to the request content; And, for receiving the decrypted artificial intelligence model from the cryptographic module, parsing and compiling the artificial intelligence model file, and converting the structure and parameters of the artificial intelligence model into a format and instructions suitable for the computing module; And, for receiving the securely detected data and model parameters from the TEE pipeline and constructing a network; And, for performing calculations and inferences on the artificial intelligence model and outputting corresponding results according to the input data; A controller for receiving a request from the TEE pipeline and scheduling each module according to the request content; and, for selecting a suitable computing module for deploying and executing the artificial intelligence model according to the parameters of the artificial intelligence model file; And, for dynamically adjusting various parameters of the computing module to optimize the performance and efficiency of the artificial intelligence model; And, for real-time monitoring of the status and operation of the computing module; and, for sending control commands to the cryptographic module and the key management module.

2. The secure and trustworthy execution environment architecture system for running an artificial intelligence model according to claim 1, characterized in that, The data input from the external environment into the internal environment includes: an encrypted artificial intelligence model, a training data set, model parameters, test data, and user information.

3. An artificial intelligence model running secure and trustworthy execution environment architecture system according to claim 1, characterized in that, The security detection of the input data includes: data integrity, data representativeness, noise detection, deviation between training data and test data, data poisoning or hostile information, and whether there is a backdoor in the model.

4. An artificial intelligence model operation secure and trustworthy execution environment architecture system according to claim 1, characterized in that, The output data includes: an encrypted trained artificial intelligence model and a model output result.

5. An artificial intelligence model operation security and trusted execution environment architecture system according to claim 1, characterized in that, The encryption technology is: attribute-based endogenous access control encryption technology, homomorphic encryption technology, zero-knowledge proof technology, or hybrid encryption technology.

6. A method for securely and trustworthily executing an artificial intelligence model, characterized in that, Implemented by using an artificial intelligence model operation security and trusted execution environment architecture system described in any one of claims 1-5, the method comprising the following steps: Select a specific function through the TEE pipeline, the functions including a model training function and a model prediction function; when the model training function is selected, input a training data set, model parameters and user information through the TEE pipeline, and the TEE pipeline will perform security detection on the input data. If the input data is secure, directly input the detected secure training data set and model parameters into the computing module to construct a network and train, input the trained model into the cryptographic module, and the cryptographic module will select a corresponding encryption technology to encrypt the model according to the input user information and store the key in the key management module. After the model is encrypted, it will be output from the TEE pipeline, and the model training ends; if the input data is not secure, directly output a prompt message and end; When the model prediction function is selected, input test data, an encrypted model and user information through the TEE pipeline, and the TEE pipeline will perform security detection on the input data. If the input data is secure, input the detected secure encrypted model and user information into the cryptographic module, and the cryptographic module will decrypt the model according to the input user information and the key stored in the key management module. If the user information does not match, the decryption fails, and a prompt message will be directly output and end; the decrypted model will be deployed to the computing module to wait for the input of test data, and the test data that passes the security detection will be input into the computing module as the input of the model, and the prediction result will be obtained; output the prediction result from the TEE pipeline to complete the prediction model function.

Citation Information

Patent Citations

  • Digital wallet security framework system based on security unit and trusted execution environment

    CN114465726A

  • Centralized computing method and device based on trusted execution environment

    CN116401671A