Model operation method, embedded device and storage medium

By calculating the encryption key of the neural network model in the embedded device, and separating and encrypting the running file and operator parameters, the problem of insufficient data protection of the neural network model in the prior art is solved, and higher data security and key protection are achieved.

CN119939629APending Publication Date: 2025-05-06杭州溪棠感芯科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510044044.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-10
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The prior art lacks data protection for neural network models in embedded devices, keys are easily leaked, and models are also easily attacked when running inference, resulting in data leakage.

Method used

The encryption key of the neural network model is obtained by computing, and the running file and operator parameters are separated, rearranged and encrypted separately. The root key of the system chip is used for decryption and verification, reducing the risk of key leakage and model parameters being identified.

Benefits of technology

It improves the security of neural network model data, reduces the risk of key leakage, and further enhances data protection by encrypting output results and key transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939629A_ABST
    Figure CN119939629A_ABST
Patent Text Reader

Abstract

The invention provides a model operation method, embedded equipment and a storage medium. The method comprises the following steps: calculating to obtain an encryption key of a neural network model; compiling the neural network model to obtain a compiled operation file; encrypting the running file through the encryption key to obtain a first ciphertext; encrypting operator parameters of the neural network model through the encryption key to obtain a second ciphertext; and decrypting the first ciphertext and the second ciphertext through a root key of the system chip, and operating the neural network model based on the operation file and the operator parameters obtained through decryption. According to the method and the device, one model corresponds to one encryption key, the encryption key does not need to be stored outside and is stored in a secure memory of a system chip, the running file and operator parameters of the model are separated, rearranged and independently encrypted, and in addition, encryption output and remote transmission protection of the encryption key are realized; therefore, the protection capability of the model data is improved, and the safety is high.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of neural network models (NN for short), and in particular to a model operation method, an embedded device, and a storage medium. Background Art

[0002] With the development and popularization of artificial intelligence (AI) and machine learning (ML) technologies, neural network models represented by NPU (Neural Processing Unit) models have been widely used in embedded devices such as smartphones, IoT devices, consumer electronics devices, and self-driving cars. In an embedded environment, after being loaded and trained, the neural network model runs the inference task and outputs the inference results. At the same time, as an important digital asset, the security issues of neural network models are becoming increasingly important. For example, it is urgent to protect model-related parameters and sensitive inference results.

[0003] Currently, embedded devices usually use a key to encrypt the complete neural network model, and then drive the decryption of the entire model before running the inference. However, this method has at least the following problems: First, the encryption and decryption keys are vulnerable to attacks and leakage during the generation, management, transmission and storage processes; second, the decrypted model is also vulnerable to attacks when running inference. For example, some devices directly decrypt the entire model into ordinary memory, and some devices lack access protection mechanisms, which leads to data leakage. It can be seen that the existing technology needs to improve the data protection of neural network models. Summary of the invention

[0004] In view of this, the present application provides a model operation method, an embedded device, and a storage medium, which can improve the problem of insufficient data protection of neural network models by embedded devices.

[0005] A model operation method provided in this application includes:

[0006] Calculate the encryption key of the neural network model;

[0007] Compiling the neural network model to obtain a compiled running file;

[0008] Encrypt the running file using the encryption key to obtain a first ciphertext;

[0009] Encrypting the operator parameters of the neural network model by using the encryption key to obtain a second ciphertext;

[0010] The first ciphertext and the second ciphertext are decrypted by the root key of the system chip, and the neural network model is run based on the running file and operator parameters obtained by decryption.

[0011] Optionally, the calculation to obtain an encryption key of the neural network model includes:

[0012] Calculate and obtain the first hash value of the neural network model;

[0013] Obtain a random number from the system chip;

[0014] Encrypting the random number using the authentication key to obtain a third ciphertext;

[0015] Sending the first hash value and the third ciphertext to a system chip;

[0016] The control system chip uses its built-in root key to decrypt the third ciphertext, and performs identity authentication based on the decryption result and the random number;

[0017] In response to passing the identity authentication, controlling the system chip to encrypt the first hash value using the root key to obtain an encryption key; and,

[0018] Receive the encryption key returned by the system chip.

[0019] Optionally, encrypting the operator parameters of the neural network model by using the encryption key includes:

[0020] According to the compiled mapping rules, the operator parameters of the neural network model are rearranged;

[0021] The rearranged operator parameters are encrypted using the encryption key.

[0022] Optionally, the method further includes:

[0023] Calculate and obtain a second hash value of the running file;

[0024] Calculate and obtain a third hash value of the operator parameter of the neural network model;

[0025] Sending the second hash value and the third hash value to the system chip;

[0026] The control system chip performs hash calculation on the decryption results of the first ciphertext and the second ciphertext, and performs verification according to the calculated hash value, the second hash value and the third hash value;

[0027] In response to passing the verification, the step of running the neural network model is performed.

[0028] Optionally, encrypting the running file by using the encryption key includes:

[0029] Calculate and obtain a second hash value of the running file;

[0030] encrypting the second hash value using the encryption key;

[0031] The encrypting the operator parameters of the neural network model by using the encryption key comprises:

[0032] Calculate and obtain a third hash value of the operator parameter of the neural network model;

[0033] Encrypting the third hash value using the encryption key;

[0034] The method further comprises:

[0035] The control system chip performs verification according to the decryption results of the first ciphertext and the second ciphertext, the second Hash value and the third Hash value;

[0036] In response to passing the verification, the step of running the neural network model is performed.

[0037] Optionally, the method further includes:

[0038] The output result of running the neural network model is encrypted using the encryption key.

[0039] Optionally, the system chip includes a first memory and a second memory, and a security level of the first memory is higher than a security level of the second memory;

[0040] The method further comprises:

[0041] storing the encryption key, the first ciphertext, and the second ciphertext in the first memory;

[0042] The encrypted output result is stored in the second memory.

[0043] Optionally, the method further includes:

[0044] The encryption key is encrypted and transmitted using a preset standard public key and private key.

[0045] An embedded device provided by the present application includes a processor and a memory, wherein a model running program is stored in the memory, and when the model running program is executed by the processor, the steps of the model running method described in any one of the above items are implemented.

[0046] The present application provides a storage medium storing a computer program, which, when executed by a processor, implements the steps of the model operation method as described in any one of the above items.

[0047] As described above, the present application obtains the encryption key of the neural network model by calculating the neural network model, thereby realizing one model corresponding to one encryption key. The encryption key does not need to be stored externally, but can be stored in a secure memory such as a system chip, thereby reducing the risk of leakage of the encryption key; in addition, the present application separates and separately encrypts the running files and operator parameters of the neural network model, which can reduce the risk of leakage of both at the same time, and further improve the security of the model data.

[0048] The present application can also rearrange the operator parameters of the neural network model and encrypt the rearranged operator parameters, thereby further reducing the risk of the model parameters being identified.

[0049] In addition, the present application can also encrypt the output results of the neural network model to achieve encrypted output, and encrypt and transmit the encryption key to achieve remote transmission protection of the encryption key. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] Figure 1 It is a flowchart of a model operation method according to an embodiment of the present application;

[0051] Figure 2 It is a schematic diagram of a process for calculating an encryption key provided in an embodiment of the present application. DETAILED DESCRIPTION

[0052] In order to solve the above problems existing in the prior art, the present application provides a model operation method, an embedded device, and a storage medium. These protection themes are based on the same concept, and the principles of solving the problems are basically the same or similar. The implementation methods of each protection theme can refer to each other, and the repeated parts will not be repeated.

[0053] In the scheme of the present application, the encryption key of the neural network model is obtained by calculating the neural network model, so that one model corresponds to one encryption key. The encryption key does not need to be stored externally, but can be stored in a secure memory such as a system chip, and the running files and operator parameters of the neural network model are separated, rearranged and encrypted separately; in addition, the output results of the neural network model can be encrypted, and the encryption key can be encrypted and transmitted.

[0054] In order to make the purpose, technical solutions and advantages of the present application clearer, the technical solutions of the present application will be clearly described below in conjunction with specific embodiments and corresponding drawings. Obviously, the embodiments described below are only part of the embodiments of the present application, not all of the embodiments. In the absence of conflict, the following embodiments and their technical features can be combined with each other and also belong to the technical solutions of the present application.

[0055] Figure 1 It is a flowchart of a model operation method of an embodiment of the present application. The model operation method can be referred to as "method", and the execution subject of each step can be an embedded device, a system on chip (SoC), a model compilation tool, or a storage medium, processor, controller, etc. with model embedding and operation functions. The model is a neural network model, including but not limited to an NPU model.

[0056] See also Figure 1 The method at least includes the following steps S1 to S5.

[0057] S1: Calculate the encryption key of the neural network model.

[0058] S2: Compile the neural network model to obtain the compiled running file.

[0059] S3: Encrypt the running file using the encryption key to obtain a first ciphertext.

[0060] S4: Encrypt the operator parameters of the neural network model using the encryption key to obtain a second ciphertext.

[0061] S5: Decrypt the first ciphertext and the second ciphertext using the root key of the system chip, and run the neural network model based on the decrypted running file and operator parameters.

[0062] In one example, combining Figure 2 As shown, the method for calculating the encryption key includes the following steps:

[0063] S11: Calculate and obtain a first hash value of the neural network model;

[0064] S12: Obtain a random number from the system chip;

[0065] S13: Encrypt the random number using the authentication key to obtain a third ciphertext;

[0066] S14: Send the first hash value and the third ciphertext to the system chip;

[0067] S15: The control system chip decrypts the third ciphertext using its built-in root key, and performs identity authentication based on the decryption result and the random number;

[0068] S16: In response to passing the identity authentication, the control system chip encrypts the first hash value using the root key to obtain an encryption key; and,

[0069] S17: Receive the encryption key returned by the system chip.

[0070] Taking the NPU model as an example, after completing the training of the NPU model, the user submits the model to the local model compilation tool, called the NPU model compilation tool, which is mainly used to optimize the neural network model to be suitable for running on embedded system hardware including the NPU. This application can select an appropriate model compilation tool according to the embedded environment. For example, the Vela compiler can be used to optimize the neural network model to be suitable for running on an embedded system including the Arm Ethos-U NPU; the Paddle Lite compiler can be used to optimize the neural network model to be suitable for running on embedded systems including ARM CPUs, Mali GPUs, Adreno GPUs, and FPGAs. The Ascend Extension for PyTorch compiler can be used to optimize the neural network model to an embedded system that supports the PyTorch framework running on the Ascend series NPU. Of course, the model compilation tool is not limited to this.

[0071] The protection unit in the model compilation tool performs hash calculation on the NPU model to obtain a hash value (hash) of the NPU model, and the hash value is used as the first hash value; then, the model compilation tool obtains a random number from a system chip with a built-in NPU unit; the protection unit in the model compilation tool has a built-in authentication key, also called an NPU authentication key, and the random number is encrypted by the NPU authentication key. The obtained ciphertext is the third ciphertext, and then the third ciphertext, the first hash value of the NPU model, and the calculation information of the authentication key are sent to the system chip.

[0072] The user's root key, such as AES256 or SM4 key, is built into the TEE (Trusted Execution Environment) or SE (Secure Elements) environment of the system chip. In its TEE or SE environment, the system chip uses the root key and the calculation information of the authentication key to calculate the NPU authentication key, and then uses the NPU authentication key to decrypt the third ciphertext and authenticate the identity based on the decryption result. For example, the decryption result (i.e., the random number obtained by decryption) is compared with the random number obtained from the system chip in step S12. If they are the same, it means that the identity authentication is passed. If they are different, it means that the identity authentication is not passed. After the identity authentication is passed, it means that the user identity is legal, and the first hash value can be used as the ID of the NPU model.

[0073] In the TEE, the system chip uses the root key to encrypt the first hash value of the NPU model to obtain the encryption key of the NPU model. Then, the system chip returns the ID and encryption key of the NPU model to the model compilation tool on the user side, so that the model compilation tool uses the ID and encryption key of the NPU model to perform subsequent encryption operations on the NPU model.

[0074] In an example of steps S2 and S3, the NPU model compilation tool compiles the NPU model submitted by the user, and converts the operator information in the NPU model into a binary file that can be run on the NPU, and the binary file serves as the compiled running file; then, the NPU model compilation tool performs hash calculation on the running file to obtain a hash value of the running file, which serves as the second hash value, and encrypts the running file using the authentication key to obtain a first ciphertext, and then sends the first ciphertext, the second hash value, and the calculation information of the authentication key to the system chip.

[0075] In an example of step S4, the NPU model compilation tool performs hash calculation on the operator parameters of the neural network model to calculate the hash value of the operator parameters, i.e., as the third hash value; and encrypts the operator parameters by the authentication key to obtain the second ciphertext, and then sends the second ciphertext, the third hash value, and the calculation information of the authentication key to the system chip. The operator parameters refer to the data corresponding to each operator used by the NPU model.

[0076] The system chip uses the root key in its TEE or SE environment, and uses the calculation information of the authentication key to calculate the NPU authentication key, and then uses the NPU authentication key to decrypt the first ciphertext and the second ciphertext respectively, and then performs hash calculations on the decryption results (i.e., the running file obtained by decrypting the first ciphertext and the operator parameters obtained by decrypting the second ciphertext); further, verification is performed based on the calculated hash value, the second hash value and the third hash value. For example, the hash value calculated based on the decrypted running file is compared with the second hash value, and the hash value calculated based on the decrypted operator parameter is compared with the third hash value. If they are the same, it means that the verification has passed; if they are different, it means that the verification has not passed; after the system chip passes the verification, the NPU model compilation tool responds to the result of passing the verification, and runs the NPU model based on the decrypted running file and operator parameters.

[0077] Optionally, in another example of step S4, the NPU model compilation tool can rearrange the operator parameters of the NPU model according to the compiled mapping rules, and then the system chip performs hash calculation and encryption on the rearranged operator parameters through the encryption key. Among them, the compiled mapping rules correspond one-to-one to the calculation rules of the operators of the NPU model on the NPU. Here, the NPU model is compiled by the NPU model compilation tool and output as two files: one is a running file, and the other is a rearranged operator parameter file, which can further reduce the risk of model parameters being identified.

[0078] In another example of step S3, the present application can calculate a second Hash value of the running file, and then encrypt the second Hash value using the encryption key to obtain the first ciphertext. That is, encrypting the running file also includes encrypting the Hash value of the running file.

[0079] Correspondingly, in the example of step S4, the present application can calculate the third Hash value of the operator parameter, and then encrypt the third Hash value by the encryption key to obtain the second ciphertext. That is, encrypting the operator parameter also includes encrypting the Hash value of the operator parameter.

[0080] It should be understood that the NPU model compilation tool also encrypts the operation file and operator parameters by the encryption key, and can be carried in the corresponding ciphertext after encryption, for example, the encrypted operation file can be carried in the first ciphertext, and the encrypted operator parameters can be carried in the second ciphertext, and then the NPU model compilation tool sends the first ciphertext and the second ciphertext to the system chip. Alternatively, the NPU model compilation tool can send the encrypted operation file independently of the first ciphertext and the encrypted operator parameters independently of the second ciphertext to the system chip.

[0081] The system chip uses the root key in its TEE or SE environment, and uses the calculation information of the authentication key received from the NPU model compilation tool to calculate the NPU authentication key, and then uses the NPU authentication key to decrypt the first ciphertext and the second ciphertext respectively, and then verifies according to the decryption results (i.e., the hash value obtained by decrypting the first ciphertext and the hash value obtained by decrypting the second ciphertext), the second hash value and the third hash value. For example, the hash value obtained by decrypting the first ciphertext is compared with the second hash value, and the hash value obtained by decrypting the second ciphertext is compared with the third hash value. If they are the same, it means that the verification has passed; if they are different, it means that the verification has not passed; after the system chip passes the verification, the NPU model compilation tool responds to the result of passing the verification, decrypts the running file and operator parameters received from the NPU model compilation tool (refer to the above for the decryption process), and runs the NPU model based on the decrypted running file and operator parameters.

[0082] Based on the above, the present application obtains the encryption key of the neural network model by calculating the neural network model, thereby realizing one model corresponding to one encryption key. The encryption key does not need to be stored externally, but can be stored in the secure memory of the system chip, thereby reducing the risk of leakage of the encryption key; for example, in step S5, before the user runs the NPU model on the embedded device, the system chip driver loads the running file and the operator parameter files into the secure memory, and calls the security program of the TEE of the system chip. The security program uses the root key, the encryption key, the second hash value and the third hash value to decrypt the above two files, save the decryption result to the secure memory of the TEE, and then verify the above decryption result, and save the verification result.

[0083] In addition, the present application separates and separately encrypts the running files and operator parameters of the neural network model, which can reduce the risk of leakage of both at the same time and further improve the security of the model data.

[0084] In such Figure 1 After step S5, the method may further include S6: encrypting the output result of running the neural network model by using an encryption key. In this way, the present application can achieve encrypted output.

[0085] In an example, the system chip may include a first memory and a second memory, wherein a security level of the second memory is lower than a security level of the first memory.

[0086] Based on this, the method may further include: storing the encryption key, the first ciphertext and the second ciphertext in a first memory; and storing the encrypted output result in a second memory.

[0087] Taking the NPU model as an example, the first memory can be what is commonly called a secure memory, and the second memory can be what is commonly called a normal memory. In actual scenarios, the output result of the NPU model is first stored in the TEE secure memory of the system chip, and then the output result is encrypted by the security program in the TEE using an encryption key, output to the normal memory, and finally output to the user.

[0088] It should be understood that the aforementioned hash values ​​may also be stored in the secure memory of the system chip.

[0089] In one example, the method may further include: encrypting and transmitting the encryption key using a preset standard public key and private key. In this way, the present application can achieve remote transmission protection of the encryption key.

[0090] The preset standard may be PKCS (Public Key Cryptography Standards). The public key and private key generated based on the preset standard together constitute an asymmetric encryption key pair. The public key is the non-secret half of the key pair. The embedded device can safely disclose and widely distribute it to another device. The encryption key is encrypted by the public key and sent to another device that needs to be transmitted after encryption, ensuring that only the other device with the corresponding private key can decrypt and obtain the encryption key. Optionally, the public key can also be used to verify the digital signature so that the other device decrypts only after confirming the sender of the information and the integrity of the data.

[0091] An embodiment of the present application also provides a storage medium, on which a model running program is stored. The model running program is essentially a computer program, and when the model running program is executed by a processor, the steps of the model running method as in any example are implemented.

[0092] The storage medium includes but is not limited to any one of a read-only memory (ROM), a random access memory (RAM), a magnetic disk and an optical disk.

[0093] Since the program stored in the storage medium can execute the steps in the model operation method of any embodiment provided in the present application, the beneficial effects that can be achieved by the model operation method of any of the aforementioned embodiments can be achieved. Please see the aforementioned embodiments for details and will not be repeated here.

[0094] An embodiment of the present application also provides an embedded device or chip, including a memory and a processor, wherein a model running program is stored in the memory, and when the model running program is executed by the processor, the steps of the model running method of any of the aforementioned embodiments are implemented; and / or, the embedded device or chip is provided with a storage medium as exemplified above, and the processor loads the storage medium to execute the steps of the model running method, thereby achieving the beneficial effects that can be achieved by the model running method of the corresponding embodiment.

[0095] The above descriptions are only some embodiments of the present application, and are not intended to limit the patent scope of the present application. For ordinary technicians in this field, all equivalent structural changes made using the contents of this specification and drawings are also included in the patent protection scope of the present application.

[0096] Although this article uses step codes such as S1, S2, etc., their purpose is to express the corresponding content more clearly and concisely, and does not constitute a substantial limitation on the order. Technical personnel in this field may execute S314 first and then S311, etc. during specific implementation, but these should all be within the scope of protection of this application.

[0097] Although the terms "first, second", etc. are used herein to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. In addition, the singular forms "one", "an", and "the" are intended to include plural forms as well. The terms "or" and "and / or" are interpreted as inclusive, or mean any one or any combination. Only when the combination of elements, functions, steps, or operations is inherently mutually exclusive in some way, an exception to this definition will occur.

Claims

1. A model operation method, characterized in that: include: Calculate the encryption key of the neural network model; Compiling the neural network model to obtain a compiled running file; Encrypt the running file using the encryption key to obtain a first ciphertext; Encrypting the operator parameters of the neural network model by using the encryption key to obtain a second ciphertext; The first ciphertext and the second ciphertext are decrypted by the root key of the system chip, and the neural network model is run based on the running file and operator parameters obtained by decryption.

2. The model operation method according to claim 1, characterized in that: The calculation to obtain the encryption key of the neural network model includes: Calculate and obtain a first hash value of the neural network model; Obtain a random number from the system chip; Encrypting the random number using the authentication key to obtain a third ciphertext; Sending the first hash value and the third ciphertext to the system chip; Controlling the system chip to use its built-in root key to decrypt the third ciphertext, and perform identity authentication according to the decryption result and the random number; In response to passing the identity authentication, controlling the system chip to encrypt the first hash value using the root key to obtain an encryption key; and, Receive the encryption key returned by the system chip.

3. The model operation method according to claim 1, characterized in that: The encrypting the operator parameters of the neural network model by using the encryption key comprises: Rearranging operator parameters of the neural network model according to the compiled mapping rules; The rearranged operator parameters are encrypted using the encryption key.

4. The model operation method according to claim 1 or 3, characterized in that: Also includes: Calculate and obtain a second hash value of the running file; Calculate and obtain a third hash value of the operator parameter of the neural network model; Sending the second hash value and the third hash value to the system chip; Controlling the system chip to perform hash calculation on the decryption results of the first ciphertext and the second ciphertext, and performing verification according to the calculated hash value, the second hash value and the third hash value; In response to passing the verification, the step of running the neural network model is performed.

5. The model operation method according to claim 1 or 3, characterized in that: The step of encrypting the operation file by using the encryption key comprises: Calculate and obtain a second hash value of the running file; encrypting the second hash value using the encryption key; The encrypting the operator parameters of the neural network model by using the encryption key comprises: Calculate and obtain a third hash value of the operator parameter of the neural network model; Encrypting the third hash value using the encryption key; The method further comprises: Controlling the system chip to perform verification according to the decryption results of the first ciphertext and the second ciphertext, the second Hash value, and the third Hash value; In response to passing the verification, the step of running the neural network model is performed.

6. The model operation method according to claim 1, characterized in that: The method further comprises: The output result of running the neural network model is encrypted using the encryption key.

7. The model operation method according to claim 6, characterized in that: The system chip includes a first memory and a second memory with a security level lower than that of the first memory; The method further comprises: storing the encryption key, the first ciphertext, and the second ciphertext in the first memory; The encrypted output result is stored in the second memory.

8. The model operation method according to claim 1, characterized in that: The method further comprises: The encryption key is encrypted and transmitted using a preset standard public key and private key.

9. An embedded device, characterized in that: The method comprises a processor and a memory, wherein a model running program is stored in the memory, and when the model running program is executed by the processor, the steps of the model running method according to any one of claims 1 to 8 are implemented.

10. A storage medium, characterized in that: A computer program is stored, and when the computer program is executed by a processor, the steps of the model operation method according to any one of claims 1 to 8 are implemented.