Cloud Inference Method, Device, Storage Medium and System Based on Data Protection

By establishing user security domains and large-model service security domains in the cloud, using controllable computing technology and strict data isolation and encryption transmission, the problem of user data privacy protection in large-model services is solved, and the security and performance balance of cloud inference is achieved.

CN119520164BActive Publication Date: 2025-07-01北京熠智科技有限公司 +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510066016.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-16
Publication Date
2025-07-01
Estimated Expiration
2045-01-16

AI Technical Summary

Technical Problem

In big model services, how to conduct cloud inference on the premise of protecting user data privacy solves the contradiction between the big model service providers need data to train models and users are worried about privacy leakage.

Method used

By establishing user security domains and large model service security domains in the cloud, using controlled computing technology and strict data isolation and encryption transmission, user data and historical session data are placed in their respective security domains, and the security domain keys of the model party are generated by each user key, realizing the isolation of user data and model data.

Benefits of technology

While meeting the model inference needs of big model service providers, it protects user privacy, takes into account system performance and security, and prevents data leakage and unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119520164B_ABST
    Figure CN119520164B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention discloses a cloud inference method, device, storage medium and system based on data protection; the method includes: receiving an inference request initiated by a user; according to the inference request, calling a user service process to access multiple user security domains to read user data and the user's historical session data; sending the user data and the user's historical session data to an inference service process through the user service process; loading an inference model from a large model service security domain through the inference service process to perform inference on the user data and the user's historical session data to obtain an inference result; returning the inference result to the user through the inference service process and the user service process. The present invention protects the privacy of users while meeting the needs of the large model service provider for model inference, and takes into account both system performance and security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of software engineering, and particularly relates to a cloud inference method, device, storage medium and system based on data protection. Background Art

[0002] With the advent of the era of large models, people's lives have achieved great convenience, but it has also exacerbated the dilemma of data privacy and model privacy protection. During the process of user data transmission, if encryption measures are not adopted, it is vulnerable to man-in-the-middle attacks, resulting in the leakage of sensitive data. At the same time, user data is stored in the cloud, and it may be leaked or misused due to reasons such as internal employees of cloud service providers, third-party access rights or configuration errors. Large model services usually run in a multi-tenant environment. If the isolation mechanism is not perfect, it is also easy to cause data leakage. In large model services, the access control of historical session data and current requests is not strict, which may also lead to the leakage of user privacy. During the inference process of large models, if not properly handled, it may leak sensitive data input by users. Therefore, in an industrial environment, how to infer models in the cloud while protecting user data privacy has become the technical focus to be solved.

[0003] A data controllable usage method is disclosed in the prior art, which defines a new paradigm of privacy computing, that is, the storage / computation nodes of the data usage party are divided into security domains controlled by the data provider, and private data can only be processed within the security domains. A security domain is a logical concept, referring to the storage and computation units protected by corresponding keys and encryption algorithms. This data controllable usage method can ensure that the private data of the data provider is visible to the data usage party, and at the same time prevent the data usage party from copying the data out of the corresponding security domain in various ways for secondary trafficking. In addition, the above new paradigm of privacy computing also has non-intrusiveness to the original business system, that is, it will not make any modification or any restriction to the original business code.

[0004] The above new paradigm of privacy computing has some advantages, but it cannot meet the requirements of model inference of large model service providers and cannot solve the contradiction between the need for data by large model service providers to train models and users' concerns about privacy leakage. Summary of the Invention

[0005] The purpose of the embodiments of the present invention is to provide a cloud inference method, device, storage medium and system based on data protection to solve the contradiction between the need for data by large model service providers to train models and users' concerns about privacy leakage on the premise of meeting the model inference requirements of large model service providers.

[0006] To achieve the above purpose, in the first aspect, the embodiments of the present invention provide a cloud inference method based on data protection, including:

[0007] Receive an inference request initiated by a user;

[0008] According to the inference request, call the user service process to access multiple user security domains to read user data and the historical session data of the user;

[0009] Send the user data and the historical session data of the user to the inference service process through the user service process;

[0010] Load an inference model from the large model service security domain through the inference service process to perform inference on the user data and the historical session data of the user, and obtain an inference result;

[0011] Return the inference result to the user through the inference service process and the user service process;

[0012] Among them, multiple user security domains and the large model service security domain are both stored in the cloud server, and the cloud server provides the user service process and the inference service process.

[0013] As a preferred implementation manner of the present application, before receiving an inference request initiated by a user, the method further includes creating multiple user security domains, specifically:

[0014] The user terminal generates or imports a Chang key; the Chang key is used to encrypt the master key in LUKS, representing the control right of the user security domain; the Chang key includes a Chang public key and a Chang private key;

[0015] The cloud server generates a Wen key based on the current system environment information; the Wen key includes a Wen private key and a Wen public key, and the Wen private key is sealed in the TPM;

[0016] Seal the Chang private key using the Wen public key;

[0017] Use the Chang private key as a key file to create multiple user security domains for multiple users.

[0018] As a preferred implementation manner of the present application, before receiving an inference request initiated by a user, the method further includes creating a large model service security domain, specifically:

[0019] Obtain multiple user keys, and each user key includes a user private key and a user public key;

[0020] According to multiple user private keys, calculate a model service private key using an elliptic curve-based asymmetric key algorithm;

[0021] Calculate a model service party public key according to the model service private key;

[0022] Create a large model service security domain according to the model service private key and the model service public key.

[0023] As a specific implementation manner of the present application, the private key of the computing model service and the public key of the model service are specifically as follows:

[0024] If the number of users is n, assuming the order of the elliptic curve is p and the generator is G, then:

[0025] The private key of user i is k i , and the public key is P i ;

[0026] Calculate the private key of the model service in the user service process as The public key of the model service is

[0027] In a second aspect, an embodiment of the present invention further provides a cloud inference device based on data protection, including a processor, an input device, an output device, and a memory. The processor, the input device, the output device, and the memory are interconnected. Among them, the memory is used to store a computer program, and the computer program includes program instructions. The processor is configured to call the program instructions to execute the method in the first aspect above. An embodiment of the present invention also provides a computer-readable storage medium, in which a computer program is stored. The computer program includes program instructions. When the program instructions are executed by a processor, the processor is caused to execute the method in the first aspect above.

[0028] In a fourth aspect, an embodiment of the present invention provides a cloud inference system based on data protection, including a user side and a cloud service side. The user side is used to initiate an inference request;

[0029] The cloud service side stores multiple user security domains and a large model service security domain, and the cloud service side provides a user service process and an inference service process; the cloud service side is used for:

[0030] According to the inference request, call the user service process to access multiple user security domains to read user data and the historical session data of the user;

[0031] Send the user data and the historical session data of the user to the inference service process through the user service process;

[0032] Load an inference model from the large model service security domain through the inference service process to perform inference on the user data and the historical session data of the user to obtain an inference result;

[0033] Return the inference result to the user through the inference service process and the user service process.

[0034] Implementing the embodiments of the present invention, a security domain is established through controllable computing technology, and strict data isolation and encrypted transmission are implemented. User data and historical session data are placed in their respective security domains. The security domain key of the model side is generated from each user key, and the isolation of user data and model data is achieved through the user service process and the inference service process. While performing model inference, user privacy is protected. Compared with traditional methods, this method protects user privacy while meeting the model inference requirements of the large model service side, taking into account both system performance and security. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for use in the description of the specific embodiments or the prior art.

[0036] Figure 1 is a flowchart of a cloud inference method based on data protection provided by an embodiment of the present invention;

[0037] Figure 2 is another flowchart of a cloud inference method based on data protection provided by an embodiment of the present invention;

[0038] Figure 3 is a structural diagram of a cloud inference device based on data protection provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0039] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0040] It should be understood that when used in this specification and the appended claims, the terms "comprises" and "comprising" indicate the presence of the described features, wholes, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.

[0041] The descriptions of relevant terms are as follows:

[0042] Security domain technology: Using controllable computing products as the underlying technology to ensure the security during the data processing process. By constructing different security domains, data classification isolation is achieved to ensure the security of each user's data and model data.

[0043] Data isolation and access control: Implementing strict access control for different types of data to ensure that only authorized users can access the corresponding data.

[0044] Balance between system performance and security: While meeting the model inference requirements of the large model service provider, protect user privacy and balance system performance and security.

[0045] The inventive concept of the present invention is: placing the user data, historical session data, model parameters, and intermediate data of each user in different security domains, which can protect user privacy and provide an effective solution for the cloud inference model in the industrial environment.

[0046] Please refer to Figure 1 and Figure 2 , the cloud inference method based on data protection provided by the embodiments of the present invention includes:

[0047] S1. Create multiple user security domains.

[0048] In specific implementation, security domains are created for each user respectively, and the data files of each user are stored in the user security domains. The process of creating each user security domain is as follows:

[0049] (1) The user generates or imports Chang keys. The Chang keys are a pair of asymmetric keys (Chang public key, Chang private key), which are used to encrypt the master key in LUKS and represent the control right of the security domain.

[0050] (2) The system generates Wen keys based on the environmental information of the current system (hardware, firmware, operating system, etc.). The Wen keys are a pair of asymmetric keys, and the Wen private key is sealed in the TPM, and the Wen public key can be made public. The TPM will generate a proof (Quote) for the Wen keys, that is, the Wen key proof, including the signature of the public key and the PCR value.

[0051] (3) The Chang private key is sealed using the Wen public key for subsequent use of the Chang private key.

[0052] (4) Create a security domain with the Chang private key as the key file.

[0053] S2. Create a large model service security domain.

[0054] In specific implementation, step S2 includes:

[0055] Obtain multiple user keys, and each user key includes a user private key and a user public key;

[0056] According to the multiple user private keys, calculate the model service private key using an asymmetric key algorithm based on elliptic curves; the asymmetric key algorithm based on elliptic curves includes but is not limited to Secp256k1, SM2, etc.;

[0057] Calculate the model service provider public key according to the model service private key;

[0058] Create a large model service security domain based on the model service private key and the model service public key.

[0059] Among them, the calculation of the model service private key and the model service public key is specifically as follows:

[0060] If the number of users is n, let the order of the elliptic curve be p and the generator be G, then:

[0061] The private key of user i is k i , and the public key is P i ;

[0062] Calculate the model service private key in the user service process as The public key is

[0063] S3, receive the inference request initiated by the user.

[0064] S4, according to the inference request, call the user service process to access multiple user security domains to read the user data and the historical session data of this user.

[0065] The user service process accesses multiple user security domains. Generally, after a process reads a security domain, it cannot perform write operations on other security domains or non-security domains. However, this user service process is a trusted process and can be unrestricted by the security domain read and write constraints. This process reads the user data and the historical session data of this user and sends them to the inference service process. When the model inference ends, the user service process receives the inference result from the inference service process and presents it to the user and the corresponding user security domain.

[0066] S5, the inference service process receives the user data and the historical session data of this user sent by the user service process, loads the inference model from the large model service security domain for inference, and obtains the inference result.

[0067] S6, the inference service process sends the inference result to the user service process.

[0068] S7, the user service process returns the inference result to the corresponding user.

[0069] Implement the cloud inference method based on data protection provided by the embodiments of the present invention. By establishing a security domain through controllable computing technology and implementing strict data isolation and encrypted transmission, the user data and historical session data are placed in their respective security domains. The security domain key of the model party is generated by each user key, and the isolation of user data and model data is achieved through the user service process and the inference service process. While performing model inference, the user privacy is protected. Compared with the traditional method, this method protects the user privacy while meeting the model inference requirements of the large model service party, and takes into account both system performance and security.

[0070] It should be emphasized that the advantages of the present invention are as follows:

[0071] 1. User privacy protection: Protects user data and can prevent man-in-the-middle attacks and data leakage caused by unencrypted data.

[0072] 2. Model privacy protection: Can protect model parameters from unauthorized access or leakage and ensure the security of the model.

[0073] 3. User data separation: Can implement strict access control for data flow, optimize cache mechanisms, debug logging, etc., to ensure that sensitive data input by users does not leak.

[0074] Based on the same inventive concept, an embodiment of the present invention provides a cloud inference system based on data protection, including a user side and a cloud service side.

[0075] Among them, the user side is used to initiate an inference request and cooperate with the cloud service side to create multiple user security domains.

[0076] Specifically, the process of creating multiple user security domains is as follows:

[0077] The user side generates or imports a Chang key; the Chang key is used to encrypt the master key in LUKS and represents the control right of the user security domain; the Chang key includes a Chang public key and a Chang private key;

[0078] The cloud service side generates a Wen key based on the current system environment information; the Wen key includes a Wen private key and a Wen public key, and the Wen private key is sealed in the TPM;

[0079] The Chang private key is sealed using the Wen public key;

[0080] Using the Chang private key as the key file, multiple user security domains are created for multiple users.

[0081] Furthermore, the cloud service side is used to create a large model service security domain and complete model inference according to the inference request.

[0082] Specifically, when creating a large model service security domain, it is as follows:

[0083] Obtain multiple user keys, each user key including a user private key and a user public key;

[0084] According to multiple user private keys, calculate the model service private key using an elliptic curve-based asymmetric key algorithm;

[0085] Calculate the model service public key according to the model service private key;

[0086] Create a large model service security domain according to the model service private key and the model service public key.

[0087] Among them, the private key of the computing model service and the public key of the model service are specifically as follows:

[0088] If the number of users is n, let the order of the elliptic curve be p and the generator be G, then:

[0089] The private key of user i is k i , and the public key is P i ;

[0090] Calculate the private key of the model service party in the user service process as The public key is

[0091] Furthermore, the process of completing model inference according to the inference request is specifically as follows:

[0092] According to the inference request, call the user service process to access multiple user security domains to read user data and the historical session data of this user;

[0093] Send the user data and the historical session data of this user to the inference service process through the user service process;

[0094] Load the inference model from the large model service security domain through the inference service process to perform inference on the user data and the historical session data of this user, and obtain an inference result;

[0095] Return the inference result to the user through the inference service process and the user service process.

[0096] Please also refer to Figure 3 , an embodiment of the present invention further provides a cloud inference device based on data protection, which may include: one or more processors 101, one or more input devices 102, one or more output devices 103, and a memory 104. The above-mentioned processors 101, input devices 102, output devices 103, and memory 104 are interconnected through a bus 105. The memory 104 is used to store a computer program, the computer program includes program instructions, and the processor 101 is configured to call the program instructions to execute the methods in the method embodiment part.

[0097] It should be understood that in the embodiments of the present invention, the so-called processor 101 may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0098] The input device 102 may include a keyboard, etc., and the output device 103 may include a display (such as an LCD), a speaker, etc.

[0099] The memory 104 may include a read-only memory and a random access memory, and provide instructions and data to the processor 101. A part of the memory 104 may also include a non-volatile random access memory. For example, the memory 104 may also store information about the device type.

[0100] In a specific implementation, the processor 101, the input device 102, and the output device 103 described in the embodiments of the present invention may execute the implementation manners described in the embodiments of the cloud inference method based on data protection provided by the embodiments of the present invention, which will not be elaborated here.

[0101] Correspondingly, the embodiments of the present invention provide a computer-readable storage medium. The computer-readable storage medium stores a computer program, and the computer program includes program instructions. When the program instructions are executed by a processor, the following is implemented: the above-mentioned cloud inference method based on data protection.

[0102] The computer-readable storage medium may be an internal storage unit of the system described in any of the foregoing embodiments, such as the hard disk or memory of the system. The computer-readable storage medium may also be an external storage device of the system, such as a plug-in hard disk equipped on the system, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. Further, the computer-readable storage medium may also include both the internal storage unit and the external storage device of the system. The computer-readable storage medium is used to store the computer program and other programs and data required by the system. The computer-readable storage medium may also be used to temporarily store data that has been output or will be output.

[0103] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0104] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed couplings or direct couplings or communication connections to each other can be indirect couplings or communication connections through some interfaces, devices or units, and can also be electrical, mechanical or other forms of connection.

[0105] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of the embodiment of the present invention.

[0106] In addition, the functional units in each embodiment of the present invention can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0107] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0108] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.

Claims

1. A cloud-based reasoning method based on data protection, characterized in that: include: Create a security domain for each user, and store each user's data files in the user security domain; Create a large model service security domain; Receive inference requests initiated by users; According to the inference request, calling a user service process to access multiple user security domains to read user data and historical session data of the user; Sending the user data and the historical session data of the user to the inference service process through the user service process; Loading the inference model from the large model service security domain through the inference service process to infer the user data and the historical session data of the user to obtain an inference result; Returning the inference result to the user through the inference service process and the user service process; Wherein, the plurality of user security domains and large model service security domains are stored in a cloud service end, and the cloud service end provides the user service process and the reasoning service process; Create a large model service security domain, specifically: Obtain multiple user keys, each user key includes a user private key and a user public key; Based on multiple user private keys, the model service private key is calculated using an asymmetric key algorithm based on elliptic curves; Calculate a model service public key based on the model service private key; Create a large model service security domain according to the model service private key and the model service public key; Among them, the computing model service private key and model service public key are specifically: If the number of users is n, the order of the elliptic curve is p, and the generator is G, then: User i's private key is k i , the public key is P i ; The model service private key is calculated in the user service process: The model service public key is Among them, create multiple user security domains, specifically: The user end generates or imports a Chang key; the Chang key is used to encrypt the master key in LUKS, indicating the control right of the user's security domain; the Chang key includes a Chang public key and a Chang private key; The cloud service generates a document key based on the current system environment information; the document key includes a document private key and a document public key, and the document private key is sealed in the TPM; Use the public key to seal the private key; Using the private key as a key file, multiple user security domains are created for multiple users.

2. The cloud-based reasoning method based on data protection according to claim 1, characterized in that: Asymmetric key algorithms based on elliptic curves include the Secp256k1 algorithm and the SM2 algorithm.

3. A cloud-based reasoning device based on data protection, characterized in that: The method comprises a processor, an input device, an output device and a memory, wherein the processor, the input device, the output device and the memory are interconnected, wherein the memory is used to store a computer program, the computer program comprises program instructions, and the processor is configured to call the program instructions to execute the method as claimed in claim 1 or 2.

4. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a processor, the processor is caused to perform the method according to claim 1 or 2.

5. A cloud-based reasoning system based on data protection, comprising a user end and a cloud service end, characterized in that: The user terminal is used to initiate an inference request; The cloud service end stores multiple user security domains and large model service security domains, and the cloud service end provides user service processes and reasoning service processes; the cloud service end is used to: Create a security domain for each user, and store each user's data files in the user security domain; Create a large model service security domain; According to the inference request, calling a user service process to access multiple user security domains to read user data and historical session data of the user; Sending the user data and the historical session data of the user to the inference service process through the user service process; Loading the inference model from the large model service security domain through the inference service process to infer the user data and the historical session data of the user to obtain an inference result; Returning the inference result to the user through the inference service process and the user service process; Create a large model service security domain, specifically: Obtain multiple user keys, each user key includes a user private key and a user public key; Based on multiple user private keys, the model service private key is calculated using an asymmetric key algorithm based on elliptic curves; Calculate a model service public key based on the model service private key; Create a large model service security domain according to the model service private key and the model service public key; Among them, the computing model service private key and model service public key are specifically: If the number of users is n, the order of the elliptic curve is p, and the generator is G, then: User i's private key is k i , the public key is P i ; The model service private key is calculated in the user service process: The model service public key is The user terminal is also used to generate or import a Chang key; the Chang key is used to encrypt the master key in LUKS, indicating the control right of the user security domain; the Chang key includes a Chang public key and a Chang private key; The cloud server is used for: Generate a text key based on the current system environment information; the text key includes a text private key and a text public key, and the text private key is sealed in the TPM; Use the public key to seal the private key; Using the private key as a key file, multiple user security domains are created for multiple users.

Citation Information

Patent Citations

  • Large model reasoning method, device and equipment and storage medium

    CN118035988A

  • User behavior data processing method and electronic equipment

    CN119167420A