Edge processing methods, apparatus, devices and storage media

By verifying the trusted execution environment on edge computing devices and using hardware TEE for confidential computation, the trustworthiness and privacy leakage issues of AI models in MEC environments are resolved, achieving secure, low-latency business information processing and model protection.

CN119520316BActive Publication Date: 2025-10-28CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411645289.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-15
Publication Date
2025-10-28
Estimated Expiration
2044-11-15

AI Technical Summary

Technical Problem

In multi-access edge computing environments, there are risks of trustworthiness and privacy breaches in the deployment of artificial intelligence models, especially in AI model applications deployed on MEC servers, which face data security issues.

Method used

By interacting with the remote verification server through the business device, the trusted execution environment instance of the artificial intelligence model on the edge computing device is verified, ensuring that the AI ​​model is deployed in a trusted environment and that confidential computing is performed using hardware TEE to ensure that the data is processed in encrypted form.

Benefits of technology

It enables secure, low-latency business information processing in edge computing environments, protects AI model applications, avoids the risk of data leakage, and ensures data privacy and model security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119520316B_ABST
    Figure CN119520316B_ABST
Patent Text Reader

Abstract

This application provides an edge processing method, apparatus, device, and storage medium, relating to the field of communication technology, for implementing edge trusted verification of artificial intelligence models to securely and with low latency realize business information processing, avoid the risk of business data leakage, and effectively protect artificial intelligence model applications. The method is applied to a business device and includes: sending a service request to an edge computing device; the service request is used to request information processing services from an artificial intelligence model on the edge computing device; receiving remote authentication information from the edge computing device; the remote authentication information is authentication information of a trusted execution environment instance with an artificial intelligence model deployed, pre-registered in a remote authentication server; sending a first authentication request to the remote authentication server; and, upon receiving a first pass response from the remote authentication server, sending an information processing request carrying information to be processed to the edge computing device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of communication technology, and in particular relates to an edge processing method, apparatus, device and storage medium. Background Technology

[0002] With the rapid development of 5G technology, multi-access edge computing (MEC) has been widely adopted. Furthermore, numerous artificial intelligence (AI) models are deployed on MEC servers to perform inference tasks such as image recognition-based product quality inspection and traffic violation identification, thereby reducing inference response latency and data transmission bandwidth.

[0003] However, MEC servers are deployed at the network edge, with their infrastructure and usage rights belonging to different owners. This creates a complex network environment and poses a privacy risk for businesses involving sensitive data such as facial recognition, location data, and production data. Furthermore, it is necessary to consider protecting third-party AI model applications deployed in the MEC environment. Summary of the Invention

[0004] This application provides an edge processing method, apparatus, device, and storage medium for implementing edge-trusted verification of artificial intelligence models, thereby enabling secure and low-latency business information processing, avoiding the risk of business data leakage, and effectively protecting artificial intelligence model applications.

[0005] To achieve the above objectives, this application adopts the following technical solution:

[0006] Firstly, an edge processing method is provided, applied to a business device, comprising: sending a service request to an edge computing device. The service request is used to request information processing services from an artificial intelligence model on the edge computing device. Receiving remote authentication information from the edge computing device. The remote authentication information is authentication information of a trusted execution environment instance with an artificial intelligence model deployed, pre-registered in a remote authentication server. Sending a first authentication request to the remote authentication server. The first authentication request is used to request verification of the remote authentication information. Upon receiving a first pass response from the remote authentication server, sending an information processing request carrying information to be processed to the edge computing device. The information processing request is used to request the information processing result of the artificial intelligence model on the information to be processed.

[0007] Optionally, the remote verification information includes the identifier of the trusted execution environment instance deployed by the artificial intelligence model, the activation certificate of the trusted execution environment instance, the private key signature corresponding to the activation certificate, the trusted execution environment software version number, the processor identifier, and the trusted computing base information.

[0008] Optionally, a method for sending an information processing request carrying information to be processed to an edge computing device includes: establishing a transport layer security protocol (TLP) connection between the device and the trusted execution environment instance based on an activation certificate; and sending the information to be processed to the edge computing device through the TLP connection.

[0009] Optionally, after sending an information processing request carrying information to be processed to the edge computing device, the method further includes: receiving the information processing result from the edge computing device.

[0010] Optionally, the artificial intelligence model is deployed on the edge computing device when the operator equipment determines that the remote verification server has passed the verification of the remote verification information. The operator equipment includes an operation support system, a multi-access edge computing orchestrator, multiple mobile edge platform managers, and a virtualization infrastructure management module. The operation support system, in response to a first model instantiation request from the service provider device, sends a second model instantiation request to the multi-access edge computing orchestrator. The multi-access edge computing orchestrator, in response to the second model instantiation request, identifies an edge computing device that meets preset conditions and sends a third model instantiation request to the target mobile edge platform manager corresponding to the edge computing device among the multiple mobile edge platform managers. The preset conditions include having instantiation resources corresponding to the artificial intelligence model and having trusted execution environment capabilities. The target mobile edge platform manager, in response to the third model instantiation request, sends a fourth model instantiation request to the virtualization infrastructure management module. The virtualization infrastructure management module, in response to the fourth model instantiation request, determines the instantiation resources of the artificial intelligence model on the edge computing device, and the remote verification information of the trusted execution environment instance corresponding to the instantiation resources, and sends a second verification request to the remote verification server. The second verification request is used to request verification of the trustworthiness of the Trusted Execution Environment instance. Instantiated resources include computing resources, storage resources, network resources, and Trusted Execution Environment resources. The virtualization infrastructure management module is also used to instantiate an artificial intelligence model within the Trusted Execution Environment instance based on the image information of the artificial intelligence model, upon receiving a second pass response from the remote verification server.

[0011] Optionally, the operator equipment also includes a mobile edge platform. The mobile edge platform manager is also used to send service configuration requests to the edge computing platform. In response to the service configuration request, the edge computing platform obtains remote authentication information and sends a third authentication request to the remote authentication server. The third authentication request is used to verify whether the trusted execution environment instance is trustworthy. The edge computing platform is also used to determine the configuration information of the artificial intelligence model upon receiving a third authentication response from the remote authentication server. The configuration information includes Domain Name System (DNS) rule information, service discovery configuration information, flow rule information, and trusted execution environment remote authentication configuration information.

[0012] Optionally, the edge computing platform is also used to send a service configuration response to the target mobile edge platform manager. The target mobile edge platform manager is also used to send a first model instantiation response to the multi-access edge computing orchestrator. The multi-access edge computing orchestrator is also used to send a second model instantiation response to the service provider device via the operation support system.

[0013] Secondly, an edge processing device is provided, applied to a business device, including: a sending module and a receiving module. The sending module is used to send a service request to the edge computing device. The service request is used to request information processing services from an artificial intelligence model on the edge computing device. The receiving module is used to receive remote authentication information from the edge computing device. The remote authentication information is authentication information of a trusted execution environment instance with an artificial intelligence model deployed, pre-registered in a remote authentication server. The sending module is also used to send a first authentication request to the remote authentication server. The first authentication request is used to request verification of the remote authentication information. The sending module is further used to send an information processing request carrying information to be processed to the edge computing device upon receiving a first pass response from the remote authentication server. The information processing request is used to request the information processing result of the artificial intelligence model for the information to be processed.

[0014] Optionally, the remote verification information includes the identifier of the trusted execution environment instance deployed by the artificial intelligence model, the activation certificate of the trusted execution environment instance, the private key signature corresponding to the activation certificate, the trusted execution environment software version number, the processor identifier, and the trusted computing base information.

[0015] Optionally, the sending module is specifically used for: establishing a transport layer security protocol (TLG) connection with the edge computing device based on the activation certificate of the trusted execution environment instance; and sending the information to be processed to the edge computing device through the TLG connection.

[0016] Optionally, the receiving module is also used to receive information processing results from the edge computing device.

[0017] Optionally, the artificial intelligence model is deployed on the edge computing device when the operator equipment determines that the remote verification server has passed the verification of the remote verification information. The operator equipment includes an operation support system, a multi-access edge computing orchestrator, multiple mobile edge platform managers, and a virtualization infrastructure management module. The operation support system, in response to a first model instantiation request from the service provider device, sends a second model instantiation request to the multi-access edge computing orchestrator. The multi-access edge computing orchestrator, in response to the second model instantiation request, identifies an edge computing device that meets preset conditions and sends a third model instantiation request to the target mobile edge platform manager corresponding to the edge computing device among the multiple mobile edge platform managers. The preset conditions include having instantiation resources corresponding to the artificial intelligence model and having trusted execution environment capabilities. The target mobile edge platform manager, in response to the third model instantiation request, sends a fourth model instantiation request to the virtualization infrastructure management module. The virtualization infrastructure management module, in response to the fourth model instantiation request, determines the instantiation resources of the artificial intelligence model on the edge computing device, and the remote verification information of the trusted execution environment instance corresponding to the instantiation resources, and sends a second verification request to the remote verification server. The second verification request is used to request verification of the trustworthiness of the Trusted Execution Environment instance. Instantiated resources include computing resources, storage resources, network resources, and Trusted Execution Environment resources. The virtualization infrastructure management module is also used to instantiate an artificial intelligence model within the Trusted Execution Environment instance based on the image information of the artificial intelligence model, upon receiving a second pass response from the remote verification server.

[0018] Optionally, the operator equipment also includes a mobile edge platform. The mobile edge platform manager is also used to send service configuration requests to the edge computing platform. In response to the service configuration request, the edge computing platform obtains remote authentication information and sends a third authentication request to the remote authentication server. The third authentication request is used to verify whether the trusted execution environment instance is trustworthy. The edge computing platform is also used to determine the configuration information of the artificial intelligence model upon receiving a third authentication response from the remote authentication server. The configuration information includes Domain Name System (DNS) rule information, service discovery configuration information, flow rule information, and trusted execution environment remote authentication configuration information.

[0019] Optionally, the edge computing platform is also used to send a service configuration response to the target mobile edge platform manager. The target mobile edge platform manager is also used to send a first model instantiation response to the multi-access edge computing orchestrator. The multi-access edge computing orchestrator is also used to send a second model instantiation response to the service provider device via the operation support system.

[0020] Thirdly, a computer device is provided, including a memory and a processor; the memory is used to store computer execution instructions, and the processor is connected to the memory via a bus; when the computer device is running, the processor executes the computer execution instructions stored in the memory to cause the base station to perform any of the optional edge processing methods in the first aspect.

[0021] The computer device may be a network device or a component of a network device, such as a chip system within the network device. The chip system supports the network device in implementing the functions involved in the first aspect and any of its possible implementations, such as receiving, determining, and offloading data and / or information involved in the aforementioned edge processing methods. The chip system includes chips and may also include other discrete devices or circuit structures.

[0022] Fourthly, a computer-readable storage medium is provided, comprising computer-executable instructions that, when executed on a base station, cause the base station to perform any of the optional edge processing methods described in the first aspect.

[0023] It should be noted that the aforementioned computer instructions may be stored, in whole or in part, on the first computer-readable storage medium. The first computer-readable storage medium may be packaged together with the processor of the routing device, or it may be packaged separately from the processor of the routing device; this application does not impose any limitation on this.

[0024] In this application, the names of the aforementioned routing devices do not limit the devices or functional modules themselves. In actual implementation, these devices or functional modules may appear under other names. As long as the functions of each device or functional module are similar to those in this application, they fall within the scope of the claims of this application and their equivalents.

[0025] These or other aspects of this application will become more readily apparent in the following description.

[0026] The technical solution provided in this application brings at least the following beneficial effects:

[0027] Based on any of the above aspects, in this application, before sending the information to be processed to the edge computing device, the business device can first obtain remote proof information of the trusted execution environment instance where the artificial intelligence model is deployed from the edge computing device, and verify the remote proof information through interaction with the remote proof server, thereby realizing edge trusted verification of the artificial intelligence model. Furthermore, if the remote proof information verification is successful, the business device can send the information to be processed to the edge computing device for processing, thereby achieving secure and low-latency business information processing and avoiding the risk of business data leakage. Moreover, the deployment of the artificial intelligence model in a trusted execution environment instance can effectively protect the artificial intelligence model application. Attached Figure Description

[0028] Figure 1 This is a schematic diagram of the structure of an edge processing system provided in an embodiment of this application;

[0029] Figure 2 A schematic diagram of the hardware structure of a service provider device provided in this application embodiment;

[0030] Figure 3 A flowchart illustrating an edge processing method provided in an embodiment of this application;

[0031] Figure 4 A flowchart illustrating the deployment of an artificial intelligence model provided in this application embodiment;

[0032] Figure 5 A flowchart illustrating yet another edge processing method provided in an embodiment of this application;

[0033] Figure 6 A flowchart illustrating yet another edge processing method provided in an embodiment of this application;

[0034] Figure 7 A flowchart illustrating yet another edge processing method provided in an embodiment of this application;

[0035] Figure 8 This is a schematic diagram of the structure of an edge processing device provided in an embodiment of this application. Detailed Implementation

[0036] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0037] It should be noted that in the embodiments of this application, the words "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the words "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0038] To facilitate a clear description of the technical solutions of the embodiments of this application, the terms "first" and "second" are used in the embodiments of this application to distinguish the same or similar items with essentially the same function and effect. Those skilled in the art can understand that the terms "first" and "second" are not intended to limit the quantity or execution order.

[0039] Furthermore, the terms "comprising" and "having" in the embodiments, claims, and drawings of this application are not exclusive. For example, a process, method, system, product, or device that includes a series of steps or modules is not limited to the listed steps or modules, but may also include steps or modules not listed.

[0040] To facilitate understanding of this application, the relevant elements involved in this application are described below.

[0041] 1. Confidential computing technology - Trusted execution environment (TEE).

[0042] A Trusted Execution Environment (TEE) is an execution environment that requires authorized program code to be executed within a processor, and the data used by that program code cannot be read or modified by code outside the TEE.

[0043] A TEE (Transmission Equipment) is a secure area within a central processing unit (CPU) or graphics processing unit (GPU), running in an independent environment and in parallel with the operating system. The CPU or GPU ensures the confidentiality and integrity of code and data within the TEE. Trusted applications running in the TEE can access the full functionality of the device's main processor and memory, while hardware isolation protects these applications from interference from other applications running on the main operating system. Therefore, some data-sensitive processing tasks can be performed within a TEE. Examples include key generation and storage, payment account authentication, privacy data processing, and algorithm protection. Optionally, the hardware corresponding to the TEE can be deployed in a general-purpose x86 server or in some network devices.

[0044] 2. Multi-access edge computing (MEC).

[0045] MEC (Multi-access Edge Computing) is a system that provides network services and cloud computing capabilities at the edge of an access network that incorporates one or more access technologies. MEC's ​​proximity to users allows it to better support low-latency processing and data processing services with high privacy requirements. MEC receives user-side requests through the MEC orchestrator (MEO) network element, and performs unified orchestration of MEC Infrastructure as a Service (IaaS) resources to manage the lifecycle of MEC applications (APPs). The Virtualization Infrastructure Manager (VIM) module manages IaaS resources in the local data center, including resource reporting and allocation, as well as operations such as starting and deregistering virtual machines (VMs) and Docker containers.

[0046] 3. Artificial intelligence (AI) reasoning.

[0047] In machine learning, AI inference is the process of using a trained model to run on real-time data to make predictions or solve tasks. Inference is the process by which an AI model generates output by applying its knowledge from its training data to previously unseen data. The goal of AI inference is to compute and output actionable results.

[0048] Various AI model training services, such as image recognition, video recognition, speech recognition, and judgment and decision-making, are ultimately provided as AI inference services, such as traffic violation recognition, product quality inspection, and autonomous driving.

[0049] The following is a brief introduction to the application background of this application.

[0050] With the deployment of 5G, especially 5G private networks, the demand for data processing at the network edge is increasing. On the one hand, there are low-latency requirements for specific services, demanding agile and rapid responses; on the other hand, data management policies necessitate that business data be processed within the campus. MEC (Multi-access Edge Computing) can provide network services and cloud computing capabilities in data centers close to the network edge, and is increasingly being used by video and data services (over-the-top, OTT) and operators as a necessary infrastructure for building edge business ecosystems.

[0051] With the maturity of AI technology, a large number of AI models are deployed in MEC (Multi-access Edge Computing) to perform inference tasks, such as product quality inspection based on image recognition in production parks, traffic violation recognition, and autonomous driving. This reduces inference response latency and the bandwidth required for data uploads to the cloud. Edge inference technology improves performance and reduces reliance on network connectivity by shortening the time from input data to inference decisions, ultimately increasing business profits. Because AI model training is costly and requires significant computing resources, some small and medium-sized enterprises (SMEs) often prefer to use pre-trained AI model algorithms from third parties, with the third-party AI model algorithm provider responsible for the maintenance and updates of the AI ​​model algorithm on the MEC side.

[0052] However, MEC deployments at the network edge present a complex environment, with infrastructure and applications owned by different parties, posing a privacy risk for services involving sensitive data such as facial recognition, location data, and production data. Furthermore, it is necessary to consider protecting the inference algorithms of third-party AI models deployed in the MEC environment.

[0053] To address the aforementioned issues, this application provides an edge processing method. Before sending information to be processed to the edge computing device, the business device can first obtain remote verification information of the trusted execution environment instance where the artificial intelligence model is deployed from the edge computing device. This remote verification information is then verified through interaction with a remote verification server, achieving edge-based trusted verification of the artificial intelligence model. Subsequently, if the remote verification information passes, the business device can send the information to be processed to the edge computing device for processing, thus achieving secure and low-latency business information processing and avoiding the risk of business data leakage.

[0054] Furthermore, confidential computing based on hardware TEEs is considered a scalable solution for achieving data availability without direct accessibility. By deploying AI models within TEE instances of edge computing infrastructure, sensitive data is input into the TEE in encrypted form to complete AI inference, and the inference results are output, thereby effectively protecting artificial intelligence model applications.

[0055] Thus, edge inference based on confidential computing can protect the privacy of business information on the one hand, and protect the artificial intelligence model application on the other hand, so that the tenants of the edge computing device, system administrators and infrastructure providers cannot access or change the artificial intelligence model application.

[0056] This edge processing method is applicable to the business-side equipment in an edge processing system. For example... Figure 1The diagram shown is a structural schematic of an edge processing system provided in an embodiment of this application. The edge processing system may include: a service provider device 101, an edge computing device 102, and a remote verification server 103. The service provider device 101 can be connected to both the edge computing device 102 and the remote verification server 103.

[0057] In practical applications, the number of business device 101, edge computing device 102, and remote verification server 103 in the edge processing system can all be multiple. For ease of explanation, this application will use the example of having only one business device 101, one edge computing device 102, and one remote verification server 103.

[0058] The business device 101 can be used to manage business operations such as product quality inspection, traffic violation recognition, or autonomous driving. The business device 101 can send image processing information related to these business operations to the edge computing device 102 to obtain the information processing results of the edge computing device 102 on the information to be processed, thereby realizing business operations such as product quality inspection, traffic violation recognition, or autonomous driving.

[0059] Optionally, the business device 101 can be a terminal or a server.

[0060] Edge computing device 102 is an edge infrastructure belonging to the operator. It can be used to provide virtual resources or physical host resources, and can have confidential computing capabilities based on hardware TEE, supporting the deployment of artificial intelligence models in TEE instances. Hardware TEE can be implemented based on CPU and GPU.

[0061] Optionally, the edge computing device 102 can be a physical device (such as a server) or a virtual device deployed on a physical device.

[0062] Remote verification server 103 is used to provide remote verification services. These services verify the authenticity and trustworthiness of the trusted execution environment provided by the MEC operator. Optionally, the remote verification service can be a remote verification service for TEE instances provided by a CPU or GPU manufacturer, a data center-based remote verification service proxy provided by an infrastructure provider, or a local remote verification service proxy provided by the MEC operator.

[0063] Optionally, the server involved in this application can be a single server, or it can be a server cluster consisting of multiple servers. In some embodiments, the server cluster can also be a distributed cluster. This application does not impose any limitations on this.

[0064] The terminal involved in this application can be user equipment (UE), access terminal, terminal unit, user terminal equipment (TE), mobile device, wireless communication device, terminal agent, tablet computer, handheld device with wireless communication function, computing device or other processing device connected to a wireless modem, wearable device, or terminal device or other processing device connected to a wireless modem in a 5G network or a public land mobile network (PLMN) evolved from 5G. Furthermore, the terminal can be mobile or fixed. This application does not limit this.

[0065] like Figure 2 The diagram shown is a hardware structure schematic of a service provider device according to an embodiment of this application. The service provider device includes a processor 21, a memory 22, a communication interface 23, and a bus 24. The processor 21, memory 22, and communication interface 23 are connected via the bus 24.

[0066] Processor 21 is the control center of the business equipment. It can be a single processor or a collective term for multiple processing elements. For example, processor 21 can be a CPU or other general-purpose processors. Among them, general-purpose processors can be microprocessors or any conventional processors.

[0067] As one embodiment, processor 21 may include one or more CPUs, for example Figure 2 CPU0 and CPU1 are shown in the diagram.

[0068] The memory 22 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto.

[0069] In one possible implementation, the memory 22 can exist independently of the processor 21. The memory 22 can be connected to the processor 21 via a bus 24 and is used to store instructions or program code. When the processor 21 calls and executes the instructions or program code stored in the memory 22, it can implement the edge processing method provided in the following embodiments of this application.

[0070] In another possible implementation, the memory 22 can also be integrated with the processor 21.

[0071] Communication interface 23 is used for the service device to connect with other devices via a communication network, such as Ethernet, wireless access network, or wireless local area network (WLAN). Communication interface 23 may include a receiving unit for receiving data and a sending unit for sending data.

[0072] Bus 24 can be an industry standard architecture (ISA) bus, a peripheral component interconnect (PCI) bus, or an extended industry standard architecture (EISA) bus, etc. This bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 2 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0073] It should be pointed out that, Figure 2 The structure shown does not constitute a limitation on the equipment of the business party, except Figure 2 In addition to the components shown, the business equipment may include more or fewer components than illustrated, or combine certain components, or have different component arrangements.

[0074] like Figure 3 The diagram shown is a flowchart illustrating an edge processing method provided in an embodiment of this application. This edge processing method can be applied to... Figure 1 or Figure 2 The business-side equipment shown. This edge processing method includes: S301-S304.

[0075] S301, The service provider's device sends a service request to the edge computing device.

[0076] The service request is used to request information processing services from an artificial intelligence model on the edge computing device. The service request may include identification information used to identify the artificial intelligence model.

[0077] Alternatively, the artificial intelligence model can be a pre-trained machine learning model used to process data such as video data, image data, audio data, or text data, or it can be a non-machine learning model.

[0078] Optionally, the information processing service could be a service for recognizing product image data in a workshop, or a service for recognizing traffic intersection image data, etc. This application does not impose any limitations on this.

[0079] When a business device needs to process information, it can send a service request to the edge computing device. The edge computing device can then receive the service request and retrieve the verification information of the trusted execution environment instance where the AI ​​model is deployed. Furthermore, the edge computing device can send the retrieved verification information to the business device, allowing it to verify the trustworthiness of the AI ​​model's deployment environment and thus improve the security of the information processed by the AI ​​model.

[0080] It should be noted that the artificial intelligence model is deployed on the edge computing device to determine when the remote verification server verifies the remote verification information for the operator equipment.

[0081] In addition to edge computing devices, the operator equipment also includes operation support systems (OSS), multi-access edge computing orchestrators (MEO), multiple mobile edge platform managers (MEPM), and virtualization infrastructure management modules.

[0082] The operations support system is used to send a second model instantiation request to the multi-access edge computing orchestrator in response to the first model instantiation request from the service provider device.

[0083] The multi-access edge computing orchestrator, in response to the second model instantiation request, identifies edge computing devices that meet preset conditions and sends a third model instantiation request to the target mobile edge platform manager corresponding to the edge computing device among multiple mobile edge platform managers. The preset conditions include having instantiation resources corresponding to the artificial intelligence model and having trusted execution environment capabilities.

[0084] The target mobile edge platform manager sends a fourth model instantiation request to the virtualization infrastructure management module in response to the third model instantiation request.

[0085] The virtualization infrastructure management module, in response to the fourth model instantiation request, determines the instantiation resources of the artificial intelligence model on the edge computing device, as well as the remote proof information of the trusted execution environment instance corresponding to the instantiation resources, and sends a second proof request to the remote proof server. The second proof request is used to request verification of whether the trusted execution environment instance is trustworthy. Instantiated resources include computing resources, storage resources, network resources, and trusted execution environment resources.

[0086] The virtualization infrastructure management module is also used to instantiate the artificial intelligence model in a trusted execution environment instance based on the image information of the artificial intelligence model upon receiving a second pass response from a remote verification server.

[0087] Alternatively, the operator equipment may also include a Mobile Edge Platform (MEP). The MEP manager is also used to send service configuration requests to the edge computing platform. In response to the service configuration request, the edge computing platform obtains remote authentication information and sends a third authentication request to the remote authentication server. The third authentication request is used to verify whether the Trusted Execution Environment instance is trustworthy. The edge computing platform is also used to determine the configuration information of the artificial intelligence model upon receiving a third authentication response from the remote authentication server. The configuration information includes Domain Name System (DNS) rule information, service discovery configuration information, flow rule information, and Trusted Execution Environment remote authentication configuration information.

[0088] Alternatively, the edge computing platform may also send a service configuration response to the target mobile edge platform manager. The target mobile edge platform manager may also send a first model instantiation response to the multi-access edge computing orchestrator. The multi-access edge computing orchestrator may also send a second model instantiation response to the service provider device via the operations support system.

[0089] It should be understood that the aforementioned operator equipment, including edge computing devices, operation support systems, multi-access edge computing orchestrators, mobile edge platform managers, virtualization infrastructure management modules, and mobile edge platforms, can be deployed on the same physical device or on different physical devices. This application embodiment does not impose any restrictions on this.

[0090] like Figure 4 The diagram shown is a flowchart of the deployment of an artificial intelligence model provided in an embodiment of this application. Figure 4 The process shown includes S1-S10, which involves pre-deploying an artificial intelligence model on an edge computing device.

[0091] S1. The service device sends the first model instantiation request to the operation support system.

[0092] The first model instantiation request is used to request the instantiation of a virtual container or VM on an edge computing device, and to instantiate an artificial intelligence model within that virtual container or VM.

[0093] S2. The operation support system sends a second model instantiation request to the multi-access edge computing orchestrator.

[0094] S3. The multi-access edge computing orchestrator processes the second model instantiation request and sends the third model instantiation request to the target mobile edge platform manager.

[0095] The preset conditions include having instantiated resources corresponding to the artificial intelligence model and having a trusted execution environment capability.

[0096] The multi-access edge computing orchestrator can respond to a second model instantiation request by identifying edge computing devices that meet preset conditions, as well as the target mobile edge platform manager (MEPM) corresponding to the edge computing devices among multiple mobile edge platform managers. Specifically, the multi-access edge computing orchestrator can identify the configuration of the application package of the artificial intelligence model, and select edge computing devices and associated MEPMs that meet preset conditions based on the resource requirements and TEE capability requirements in its description file.

[0097] S4. The target mobile edge platform manager sends a fourth model instantiation request to the virtualization infrastructure management module.

[0098] The Virtualization Infrastructure Management module is used to manage edge computing devices with TEE capabilities.

[0099] The fourth model instantiation request is used to request the allocation of instantiation resources and to instantiate the artificial intelligence model. It may carry image information of the artificial intelligence model application (such as image address).

[0100] S5. The virtualization infrastructure management module determines the instantiated resources of the artificial intelligence model on the edge computing device, as well as the remote proof information of the trusted execution environment instance corresponding to the instantiated resources, and sends a second proof request to the remote proof server.

[0101] The second proof request is used to request verification of whether the trusted execution environment instance is trusted. Instantiated resources include computing resources, storage resources, network resources, and trusted execution environment resources.

[0102] S6. Upon receiving a second pass response from the remote verification server, the virtualization infrastructure management module instantiates the artificial intelligence model in the trusted execution environment instance based on the image information of the artificial intelligence model, and sends an instantiation response to the target mobile edge platform manager.

[0103] The virtualization infrastructure management module can allocate appropriate resources on edge computing devices to create container or VM instances. Furthermore, it can obtain remote authentication information from the TEE instance environment allocated on the edge computing device and initiate remote authentication verification with the remote authentication service. If the remote authentication verification passes, the virtualization infrastructure management module can download the AI ​​model software image and instantiate the AI ​​model within the container or VM.

[0104] S7. The Mobile Edge Platform Manager sends a service configuration request to the edge computing platform.

[0105] S8. The edge computing platform obtains remote proof information from the edge computing device and sends a third proof request to the remote proof server.

[0106] The third proof request is used to verify whether the trusted execution environment instance is trusted.

[0107] S9. Upon receiving a third-party verification response from the remote verification server, the edge computing platform determines the configuration information of the artificial intelligence model and sends a service configuration response to the target mobile edge platform manager.

[0108] The configuration information includes Domain Name System (DNS) rules, service discovery configuration information, flow rules, and trusted execution environment remote verification configuration information.

[0109] S10, the target mobile edge platform manager sends a model instantiation response to the service device through the multi-access edge computing orchestrator and operation support system.

[0110] Based on the above process, this application can achieve trusted deployment of artificial intelligence models in edge computing devices through the interaction between the operator's equipment and the remote verification server, effectively determining a trusted deployment environment. In this way, the artificial intelligence model can be instantiated in a trusted execution environment instance of the edge computing device, effectively protecting the service provider's artificial intelligence model application.

[0111] S302, The business device receives remote authentication information from the edge computing device.

[0112] Among them, remote proof information refers to the proof information of trusted execution environment instances that have deployed artificial intelligence models and are pre-registered in remote proof servers.

[0113] Remote authentication information includes the identifier of the Trusted Execution Environment (TEE) instance deployed by the AI ​​model, the TEE instance's activation certificate, the private key signature corresponding to the activation certificate, the TEE software version number, the processor identifier, and the trusted computing base information. The processor identifier can be a CPU identifier or a GPU identifier.

[0114] S303, The business device sends the first proof request to the remote proof server.

[0115] The first proof request includes remote proof information of the trusted execution environment instance, which is used to request verification of the remote proof information to determine whether the trusted execution environment instance is trusted.

[0116] S304. Upon receiving the first pass response from the remote verification server, the business device sends an information processing request carrying the information to be processed to the edge computing device.

[0117] Among them, the information processing request is used to request the information processing result of the artificial intelligence model on the information to be processed.

[0118] The first response can be used to indicate that the remote verification of the authentication information has passed, and that the trusted execution environment instance in which the artificial intelligence model is deployed is trustworthy.

[0119] Optionally, the information to be processed can be video data, image data, audio data, or text data, etc.

[0120] If a first pass response is received from the remote verification server, it indicates that the information possesses a high level of security during the processing by the artificial intelligence model. The business device can then send an information processing request carrying the information to be processed to the edge computing device. Subsequently, the edge computing device can process the information to be processed using the artificial intelligence model, obtain the information processing result, and return the result to the business device.

[0121] As can be seen from the above embodiments, this application can realize the trusted verification of the artificial intelligence model's operating environment through the interaction between the business device and the edge computing device and the remote verification server, so as to realize the business information processing process in a secure and low-latency manner and avoid the risk of business information leakage.

[0122] In one possible implementation, such as Figure 5 The diagram shown is a flowchart illustrating another edge processing method provided in an embodiment of this application. Combined with... Figure 3 In the above S304, when the service device sends an information processing request carrying information to be processed to the edge computing device, this application embodiment provides an optional implementation method, including: S3041-S3042.

[0123] S3041. The business device establishes a transport layer security protocol connection with the edge computing device based on the activation certificate of the Trusted Execution Environment instance.

[0124] In other words, the business device establishes a transport layer security protocol connection with the artificial intelligence model on the edge computing device based on the activation certificate of the Trusted Execution Environment instance.

[0125] S3042. The service provider device sends the information to be processed to the edge computing device through a transport layer security protocol connection.

[0126] Based on this, the business device and the edge computing device can use the activation certificate of the TEE instance as a certificate authority (CA) certificate to establish a transport layer security (TLS) connection to realize the transmission of information to be processed.

[0127] In one possible implementation, such as Figure 6 The diagram shown is a flowchart illustrating another edge processing method provided in an embodiment of this application. Combined with... Figure 3 Following S304 above, the edge processing method provided in this application embodiment further includes: S305.

[0128] S305. The business device receives the information processing results from the edge computing device.

[0129] Edge computing devices can process information based on artificial intelligence models deployed in trusted execution environment instances, obtaining processing results. These results can then be sent to business devices to facilitate their management of products in workshops or at traffic intersections.

[0130] In one possible implementation, such as Figure 7 The diagram shown is a flowchart illustrating another edge processing method provided in an embodiment of this application. Figure 7 The edge processing method shown is a remote proof process, including: S401-S404.

[0131] S401, The business device obtains remote authentication information from the edge computing device.

[0132] S402. The business device sends a remote certification request to the remote certification server.

[0133] S403. The remote certification server verifies whether the remote certification information is correct.

[0134] S404. The remote certification server sends a remote certification response to the business device.

[0135] Based on this, the business device can obtain remote proof information from the edge computing device and generate a remote proof report. Then, the business device sends a remote proof request (such as a first proof request) carrying the remote proof report to the remote proof server. The remote proof server can verify the correctness of the remote proof information based on the pre-registered information of the TEE instance stored locally to determine whether the current TEE instance environment is trustworthy, and further return a remote proof response to the business device to indicate whether the current TEE instance environment is trustworthy. If the remote proof response indicates that the current TEE instance environment is untrustworthy, the business device can terminate its interaction with the application (such as an artificial intelligence model) in the TEE instance. If the remote proof response indicates that the current TEE instance environment is trustworthy (such as a first pass response), the business device can send inference information to the application (such as an artificial intelligence model) in the TEE instance to realize the relevant business.

[0136] Before sending information to be processed to the edge computing device, the business device can first obtain remote proof information of the trusted execution environment instance where the artificial intelligence model is deployed from the edge computing device. This remote proof information is then verified through interaction with the remote proof server, achieving edge-based trusted verification of the artificial intelligence model. Subsequently, if the remote proof information is verified successfully, the business device can send the information to be processed to the edge computing device for processing, thus achieving secure and low-latency business information processing and avoiding the risk of business data leakage.

[0137] Furthermore, confidential computing based on hardware TEEs is considered a scalable solution for achieving data availability without direct accessibility. By deploying AI models within TEE instances of edge computing infrastructure, sensitive data is input into the TEE in encrypted form to complete AI inference, and the inference results are output, thereby effectively protecting artificial intelligence model applications.

[0138] Thus, edge inference based on confidential computing can protect the privacy of business information on the one hand, and protect the artificial intelligence model application on the other hand, so that the tenants of the edge computing device, system administrators and infrastructure providers cannot access or change the artificial intelligence model application.

[0139] The foregoing mainly describes the solutions provided by the embodiments of this application from a methodological perspective. To achieve the above functions, it includes corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should readily recognize that, based on the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0140] This application embodiment can divide the service device into functional modules according to the above method example. For example, each function can be divided into a separate functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. Optionally, the module division in this application embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.

[0141] like Figure 8 The diagram shows a structural schematic of an edge processing device provided in an embodiment of this application. This edge processing device can be applied to a business device and includes: a sending module 501 and a receiving module 502. The sending module 501 is used to send a service request to the edge computing device. The service request is used to request information processing services from an artificial intelligence model on the edge computing device. The receiving module 502 is used to receive remote verification information from the edge computing device. The remote verification information is verification information of a trusted execution environment instance with an artificial intelligence model deployed, pre-registered in a remote verification server. The sending module 501 is also used to send a first verification request to the remote verification server. The first verification request is used to request verification of the remote verification information. The sending module 501 is also used to send an information processing request carrying information to be processed to the edge computing device when the receiving module 502 receives a first pass response from the remote verification server. The information processing request is used to request the information processing result of the artificial intelligence model for the information to be processed.

[0142] Optionally, the remote verification information includes the identifier of the trusted execution environment instance deployed by the artificial intelligence model, the activation certificate of the trusted execution environment instance, the private key signature corresponding to the activation certificate, the trusted execution environment software version number, the processor identifier, and the trusted computing base information.

[0143] Optionally, the sending module 501 is specifically used for: establishing a transport layer security protocol connection with the edge computing device based on the activation certificate of the trusted execution environment instance; and sending the information to be processed to the edge computing device through the transport layer security protocol connection.

[0144] Optionally, the receiving module 502 is also used to receive information processing results from the edge computing device.

[0145] Optionally, the artificial intelligence model is deployed on the edge computing device when the operator equipment determines that the remote verification server has passed the verification of the remote verification information. The operator equipment includes an operation support system, a multi-access edge computing orchestrator, multiple mobile edge platform managers, and a virtualization infrastructure management module. The operation support system, in response to a first model instantiation request from the service provider device, sends a second model instantiation request to the multi-access edge computing orchestrator. The multi-access edge computing orchestrator, in response to the second model instantiation request, identifies an edge computing device that meets preset conditions and sends a third model instantiation request to the target mobile edge platform manager corresponding to the edge computing device among the multiple mobile edge platform managers. The preset conditions include having instantiation resources corresponding to the artificial intelligence model and having trusted execution environment capabilities. The target mobile edge platform manager, in response to the third model instantiation request, sends a fourth model instantiation request to the virtualization infrastructure management module. The virtualization infrastructure management module, in response to the fourth model instantiation request, determines the instantiation resources of the artificial intelligence model on the edge computing device, and the remote verification information of the trusted execution environment instance corresponding to the instantiation resources, and sends a second verification request to the remote verification server. The second verification request is used to request verification of the trustworthiness of the Trusted Execution Environment instance. Instantiated resources include computing resources, storage resources, network resources, and Trusted Execution Environment resources. The virtualization infrastructure management module is also used to instantiate an artificial intelligence model within the Trusted Execution Environment instance based on the image information of the artificial intelligence model, upon receiving a second pass response from the remote verification server.

[0146] Optionally, the operator equipment also includes a mobile edge platform. The mobile edge platform manager is also used to send service configuration requests to the edge computing platform. In response to the service configuration request, the edge computing platform obtains remote authentication information and sends a third authentication request to the remote authentication server. The third authentication request is used to verify whether the trusted execution environment instance is trustworthy. The edge computing platform is also used to determine the configuration information of the artificial intelligence model upon receiving a third authentication response from the remote authentication server. The configuration information includes Domain Name System (DNS) rule information, service discovery configuration information, flow rule information, and trusted execution environment remote authentication configuration information.

[0147] Optionally, the edge computing platform is also used to send a service configuration response to the target mobile edge platform manager. The target mobile edge platform manager is also used to send a first model instantiation response to the multi-access edge computing orchestrator. The multi-access edge computing orchestrator is also used to send a second model instantiation response to the service provider device via the operation support system.

[0148] Those skilled in the art will recognize that, in one or more of the examples above, the functions described in this application can be implemented using hardware, software, firmware, or any combination thereof. When implemented in software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium. Computer-readable media include computer-readable storage media and communication media, wherein communication media include any medium that facilitates the transmission of a computer program from one place to another. Storage media can be any available medium accessible to a general-purpose or special-purpose computer.

[0149] Through the above description of the embodiments, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.

[0150] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules or units is only a logical functional division, and other division methods may exist in actual implementation. For example, multiple units or components may be combined or integrated into another device, or some features may be ignored or not executed. Furthermore, the shown or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms. Units described as separate components may or may not be physically separate; components shown as units may be one physical unit or multiple physical units, i.e., they may be located in one place or distributed in multiple different places. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0151] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. An edge processing method, characterized in that, Applied to the equipment of the business party, including: Send a service request to the edge computing device; the service request is used to request information processing services from the artificial intelligence model on the edge computing device; Receive remote authentication information from the edge computing device; the remote authentication information is authentication information of a trusted execution environment instance in which the artificial intelligence model is deployed, which is pre-registered in a remote authentication server; the remote authentication information includes the identifier of the trusted execution environment instance in which the artificial intelligence model is deployed, the activation certificate of the trusted execution environment instance, and the private key signature corresponding to the activation certificate, the trusted execution environment software version number, the processor identifier, and the trusted computing base information; Send a first proof request to the remote proof server; the first proof request is used to request verification of the remote proof information; Upon receiving a first pass response from the remote verification server, an information processing request carrying information to be processed is sent to the edge computing device; the information processing request is used to request the information processing result of the artificial intelligence model on the information to be processed. The artificial intelligence model is deployed on the edge computing device when the operator equipment determines that the remote verification server has successfully verified the remote verification information; the operator equipment includes an operation support system, a multi-access edge computing orchestrator, multiple mobile edge platform managers, and a virtualization infrastructure management module. The operation support system is used to send a second model instantiation request to the multi-access edge computing orchestrator in response to a first model instantiation request from the service provider device. The multi-access edge computing orchestrator is used to respond to the second model instantiation request, determine the edge computing device that meets the preset conditions, and send a third model instantiation request to the target mobile edge platform manager corresponding to the edge computing device among the multiple mobile edge platform managers; the preset conditions include having instantiation resources corresponding to the artificial intelligence model and having trusted execution environment capabilities; The target mobile edge platform manager is used to send a fourth model instantiation request to the virtualization infrastructure management module in response to the third model instantiation request; The virtualization infrastructure management module is used to respond to the fourth model instantiation request, determine the instantiation resources of the artificial intelligence model on the edge computing device, and the remote proof information of the trusted execution environment instance corresponding to the instantiation resources, and send a second proof request to the remote proof server; the second proof request is used to request verification of whether the trusted execution environment instance is trustworthy; the instantiation resources include computing resources, storage resources, network resources, and trusted execution environment resources; The virtualization infrastructure management module is also used to instantiate the artificial intelligence model in the trusted execution environment instance based on the image information of the artificial intelligence model upon receiving a second pass response from the remote proof server. The operator equipment also includes a mobile edge platform; The mobile edge platform manager is also used to send service configuration requests to the edge computing platform; The edge computing platform is used to respond to the service configuration request, obtain the remote proof information, and send a third proof request to the remote proof server; the third proof request is used to verify whether the trusted execution environment instance is trustworthy. The edge computing platform is also used to determine the configuration information of the artificial intelligence model upon receiving a third pass response from the remote verification server; the configuration information includes domain name system rule information, service discovery configuration information, flow rule information, and trusted execution environment remote verification configuration information.

2. The edge processing method according to claim 1, characterized in that, Sending an information processing request carrying information to be processed to the edge computing device includes: Based on the activation certificate of the Trusted Execution Environment instance, a transport layer security protocol connection is established between the device and the edge computing device; The information to be processed is sent to the edge computing device via the transport layer security protocol connection.

3. The edge processing method according to claim 1, characterized in that, After sending an information processing request carrying information to be processed to the edge computing device, the method further includes: Receive the information processing results from the edge computing device.

4. The edge processing method according to claim 1, characterized in that, The edge computing platform is also used to send a service configuration response to the target mobile edge platform manager; The target mobile edge platform manager is also used to send a first model instantiation response to the multi-access edge computing orchestrator; The multi-access edge computing orchestrator is also used to send a second model instantiation response to the service provider device through the operation support system.

5. An edge processing device, characterized in that, Applied to the equipment of the business party, including: sending module and receiving module; The sending module is used to send a service request to the edge computing device; the service request is used to request information processing services from the artificial intelligence model on the edge computing device. The receiving module is used to receive remote authentication information from the edge computing device; the remote authentication information is authentication information of a trusted execution environment instance in which the artificial intelligence model is deployed, which is pre-registered in a remote authentication server; the remote authentication information includes the identifier of the trusted execution environment instance in which the artificial intelligence model is deployed, the activation certificate of the trusted execution environment instance, and the private key signature corresponding to the activation certificate, the trusted execution environment software version number, the processor identifier, and the trusted computing base information; The sending module is further configured to send a first proof request to the remote proof server; the first proof request is used to request verification of the remote proof information; The sending module is further configured to send an information processing request carrying information to be processed to the edge computing device when the receiving module receives a first pass response from the remote verification server; the information processing request is used to request the information processing result of the artificial intelligence model on the information to be processed. The artificial intelligence model is deployed on the edge computing device when the operator equipment determines that the remote verification server has successfully verified the remote verification information; the operator equipment includes an operation support system, a multi-access edge computing orchestrator, multiple mobile edge platform managers, and a virtualization infrastructure management module. The operation support system is used to send a second model instantiation request to the multi-access edge computing orchestrator in response to a first model instantiation request from the service provider device. The multi-access edge computing orchestrator is used to respond to the second model instantiation request, determine the edge computing device that meets the preset conditions, and send a third model instantiation request to the target mobile edge platform manager corresponding to the edge computing device among the multiple mobile edge platform managers; the preset conditions include having instantiation resources corresponding to the artificial intelligence model and having trusted execution environment capabilities; The target mobile edge platform manager is used to send a fourth model instantiation request to the virtualization infrastructure management module in response to the third model instantiation request; The virtualization infrastructure management module is used to respond to the fourth model instantiation request, determine the instantiation resources of the artificial intelligence model on the edge computing device, and the remote proof information of the trusted execution environment instance corresponding to the instantiation resources, and send a second proof request to the remote proof server; the second proof request is used to request verification of whether the trusted execution environment instance is trustworthy; the instantiation resources include computing resources, storage resources, network resources, and trusted execution environment resources; The virtualization infrastructure management module is also used to instantiate the artificial intelligence model in the trusted execution environment instance based on the image information of the artificial intelligence model upon receiving a second pass response from the remote proof server. The operator equipment also includes a mobile edge platform; The mobile edge platform manager is also used to send service configuration requests to the edge computing platform; The edge computing platform is used to respond to the service configuration request, obtain the remote proof information, and send a third proof request to the remote proof server; the third proof request is used to verify whether the trusted execution environment instance is trustworthy. The edge computing platform is also used to determine the configuration information of the artificial intelligence model upon receiving a third pass response from the remote verification server; the configuration information includes domain name system rule information, service discovery configuration information, flow rule information, and trusted execution environment remote verification configuration information.

6. A computer device, characterized in that, It includes a memory and a processor; the memory is used to store computer execution instructions, and the processor is connected to the memory via a bus; when the computer device is running, the processor executes the computer execution instructions stored in the memory to cause the computer device to perform the edge processing method as described in any one of claims 1-4.

7. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes computer-executable instructions that, when executed on a computer device, cause the computer device to perform the edge processing method as described in any one of claims 1-4.

Citation Information

Patent Citations

  • Remote attestation method and device, electronic equipment and storage medium

    CN117579331A

  • Remote attestation method and device and storage medium

    CN118540704A