Privacy protection method and device for knowledge base, storage medium and program product

By performing privacy fusion and encrypted inference in a secure computing environment, the encrypted inference sub-model and plain-text inference sub-model work together, the challenge of privacy protection of knowledge bases in RAG applications is solved, and efficient and secure privacy protection effect is achieved.

CN119939670AActive Publication Date: 2025-05-06BEIJING ELECTRONIC DIGITAL INTELLIGENCE TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510427296.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-07
Publication Date
2025-05-06
Estimated Expiration
2045-04-07

AI Technical Summary

Technical Problem

In current RAG applications, the effective protection of knowledge bases faces significant challenges, especially in the complex scenario of three-party identities, ensuring the privacy of knowledge bases is extremely difficult in data transmission and access.

Method used

By performing privacy fusion and encrypted inference in a secure computing environment, the encrypted inference submodel and plaintext inference submodel work together to ensure that the search results and prompt words are processed in a secure environment and reduce the risk of data leakage.

Benefits of technology

Effectively protect the data privacy and security of the knowledge base and maintain the data rights and interests of the knowledge management platform. Even if the knowledge base is called many times, sensitive information will not be leaked, which improves the security and computing efficiency of privacy protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939670A_ABST
    Figure CN119939670A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a privacy protection method and device for a knowledge base, a storage medium and a program product. The method comprises the steps that when a business application system initiates a query request, if the business application system and a knowledge management platform are not the same subject, cross-platform privacy matching is conducted on cue words and a knowledge base, and a retrieval result is obtained; if yes, directly performing local calculation; the retrieval result and the cue word are fused into context information in the safe computing environment; splitting the preset reasoning model into an encryption reasoning sub-model and a plaintext reasoning sub-model, and deploying the encryption reasoning sub-model and the plaintext reasoning sub-model into a secure computing environment and a plaintext computing Firstly, the encryption reasoning sub-model is used for carrying out secret state reasoning on context information to obtain intermediate parameters, then the plaintext reasoning sub-model is used for plaintext reasoning, and a reasoning result is obtained and fed back to a service application system. According to the method, the privacy data of the knowledge base can be protected by using a secure computing environment, and sensitive information cannot be leaked even if the data of the knowledge base are called for multiple times, so that data rights and interests of a knowledge management platform are maintained.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of privacy protection technology, and in particular to a knowledge base privacy protection method, device, storage medium and program product. Background Art

[0002] With the advancement of big model technology, RAG (Retrieval-Augmented Generation) reasoning methods have been widely used in fields such as natural language processing. RAG is suitable for scenarios such as question-answering systems, document generation, and intelligent assistants. The workflow mainly includes three steps: retrieval, enhancement, and generation. Usually, relevant information is retrieved from an external knowledge base based on user queries, embedded with the query content into a preset prompt word template, and then the enhanced prompt words are input into the big language model to generate output.

[0003] However, in the current retrieval enhancement generation (RAG) application, the effective protection of the knowledge base faces significant challenges. Especially in complex scenarios where the business application system, knowledge management platform and retrieval service system have different identities, the three parties need to integrate data to complete the problem answering. However, in the links involving three-party interaction such as data transmission and access, it is extremely difficult to ensure that the privacy of the knowledge base is not leaked throughout the entire workflow. Summary of the invention

[0004] In view of this, the embodiments of the present disclosure provide a knowledge base privacy protection method, device, storage medium and program product, which can use a secure computing environment to protect the privacy data of the knowledge base. Even if the knowledge base is called multiple times, sensitive information will not be leaked, thereby maintaining the data rights and interests of the knowledge management platform.

[0005] In a first aspect, the present disclosure provides a method for protecting the privacy of a knowledge base, which adopts the following technical solution: When the business application system initiates a query request, it is determined whether the business application system and the knowledge management platform are the same entity; If not, a cross-platform privacy match is performed on the prompt words provided by the business application system and the knowledge base provided by the knowledge management platform to obtain the search results; If yes, then locally calculate the prompt word and the knowledge base to obtain the search result; Transmitting the search results to a secure computing environment provided by a search service system for isolation; In the secure computing environment, privately fuse the search result with the prompt word to obtain context information; Splitting the preset reasoning model into an encrypted reasoning sub-model and a plaintext reasoning sub-model, deploying the encrypted reasoning sub-model in the secure computing environment, and deploying the plaintext reasoning sub-model in the plaintext computing environment of the retrieval service system; Use the encrypted reasoning sub-model to perform encrypted reasoning on the context information to obtain intermediate parameters; The plaintext reasoning sub-model is used to perform plaintext reasoning on the intermediate parameters to obtain reasoning results, and the reasoning results are sent to the business application system.

[0006] Optionally, the determining whether the business application system and the knowledge management platform are the same entity includes: Comparing the first identity identifier of the business application system with the second identity identifier of the knowledge management platform; If the comparison is consistent, it is determined that the business application system and the knowledge management platform are the same entity; If the comparison is inconsistent, it is determined that the business application system and the knowledge management platform are not the same entity.

[0007] Optionally, performing cross-platform privacy matching on the prompt words provided by the business application system and the knowledge base provided by the knowledge management platform to obtain search results includes: The prompt word is sent to the knowledge management platform, and the received prompt word is searched using the local knowledge base of the knowledge management platform to obtain the search result.

[0008] Optionally, the transmitting the search result to a secure computing environment provided by the search service system for isolation includes: When the search service system has access authorization to the search results; then encrypting the search result based on the authorization information to generate an encrypted file containing the authorization information; The encrypted file is re-encrypted using the public key provided by the retrieval service system to generate a secondary encrypted file and send it to the retrieval service system; The secondary encrypted file is decrypted using a private key and a decryption key preset by the retrieval service system, and the decrypted retrieval result is stored in a secure memory area of ​​the secure computing environment based on the decrypted authorization information.

[0009] Optionally, the transmitting the search results to a secure computing environment provided by the search service system for isolation further includes: When the search service system does not have access authorization to the search results; then encrypting the search result to generate an encrypted search result and a first key, and encrypting the first key using the public key of the secure computing environment to generate an encryption key; loading the encrypted search result and the encryption key into the secure computing environment, and decrypting the encryption key using a private key of the secure computing environment; The encrypted search result is decrypted using the decrypted first key, and the decrypted search result is stored in the secure memory area.

[0010] Optionally, the privacy fusion of the search result and the prompt word to obtain context information includes: When the number of the search results is 1, the search results and the prompt words are concatenated in a preset order to generate the context information; When the number of the search results is not 1, all the search results are merged into a new search result; The new search result and the prompt word are concatenated according to the preset order to generate the context information.

[0011] Optionally, the privacy protection method of the knowledge base further includes: Encrypt the intermediate parameter using the public key provided by the knowledge management platform to generate an encrypted parameter; The encryption parameters are sent from the secure computing environment to the plaintext computing environment for authorized decryption.

[0012] In a second aspect, the disclosed embodiment further provides a knowledge base privacy protection system, which adopts the following technical solution: The subject judgment module is used to judge whether the business application system and the knowledge management platform are the same subject when the business application system initiates a query request; if not, the privacy calculation module is executed; if so, the local calculation module is executed; The privacy computing module is used to perform cross-platform privacy matching between the prompt words provided by the business application system and the knowledge base provided by the knowledge management platform to obtain search results; A local calculation module, used for performing local calculation on the prompt word and the knowledge base to obtain a search result; A data isolation module, used to transmit the search results to a secure computing environment provided by a search service system for isolation; A privacy fusion module is used to perform privacy fusion on the search result and the prompt word in the secure computing environment to obtain context information; a model splitting module is used to split the preset reasoning model into an encrypted reasoning sub-model and a plaintext reasoning sub-model, deploy the encrypted reasoning sub-model in the secure computing environment, and deploy the plaintext reasoning sub-model in the plaintext computing environment of the retrieval service system; A dense reasoning module, used to perform dense reasoning on the context information using the encrypted reasoning sub-model to obtain intermediate parameters; The plaintext reasoning module is used to perform plaintext reasoning on the intermediate parameters using the plaintext reasoning sub-model, obtain reasoning results, and send the reasoning results to the business application system.

[0013] In a third aspect, the embodiments of the present disclosure further provide a computer device, which adopts the following technical solution: The computer device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute any of the above-mentioned knowledge base privacy protection methods.

[0014] In a fourth aspect, an embodiment of the present disclosure further provides a computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable a computer to execute any of the above-mentioned knowledge base privacy protection methods.

[0015] In a fifth aspect, an embodiment of the present disclosure further provides a computer program product, including a computer program / instruction, which implements the steps of any of the above methods when executed by a processor.

[0016] The privacy protection method of the knowledge base provided by the disclosed embodiment is applicable to the scenario where the business application system, the knowledge management platform and the retrieval service system are different entities, and is also compatible with the simplified scenario where the business application system and the knowledge management platform are the same entity. In particular, when the business application system and the knowledge management platform are not the same entity, the method enables the retrieval service system to obtain the retrieval results through a secure computing environment, and performs privacy fusion of the retrieval results and prompt words in the secure computing environment to generate context information, while ensuring data privacy security. The secure computing environment of this solution provides a relatively independent and secure computing space. After the retrieval results enter the environment, the relevant calculations and processing can be completed autonomously internally without the need for frequent interaction with the outside to verify the calculation results of each step. The isolation characteristics of the secure computing environment effectively prevent data leakage during the calculation process. In addition, this solution combines the secure computing environment and adopts a mechanism for the encrypted reasoning sub-model and the plaintext reasoning sub-model to work together. The encrypted reasoning sub-model first performs part of the reasoning, reducing the risk of leaking private data from intermediate parameters. At the same time, the front end of the reasoning process is placed in the privacy computing environment, avoiding the large amount of computing power overhead brought by the overall privacy computing, ensuring the efficiency and accuracy of the reasoning process; the plaintext reasoning sub-model fully utilizes the advantages of the plaintext computing environment to quickly complete subsequent reasoning tasks and further improve the reasoning efficiency. Through privacy computing technology, this method protects the data privacy security of the knowledge base and maintains the data rights and interests of the knowledge management platform. Even if the knowledge base data is called multiple times, sensitive information will not be leaked, thereby bringing knowledge payment related benefits to the knowledge management platform.

[0017] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the following preferred embodiments are specifically cited and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0019] Figure 1 A flowchart of a method for protecting the privacy of a knowledge base provided in an embodiment of the present disclosure; Figure 2 A schematic diagram of a flow chart of a search result isolation method provided in an embodiment of the present disclosure; Figure 3 A schematic diagram of a flow chart of a method for encrypting and sending intermediate parameters provided in an embodiment of the present disclosure; Figure 4 A principle block diagram of a privacy protection system for a knowledge base provided by an embodiment of the present disclosure; Figure 5 A schematic diagram of the structure of a computer device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0020] The embodiments of the present disclosure are described in detail below with reference to the accompanying drawings.

[0021] It should be clear that the following embodiments of the present disclosure are described by specific specific examples, and those skilled in the art can easily understand other advantages and effects of the present disclosure from the contents disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all of the embodiments. The present disclosure can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present disclosure. It should be noted that the following embodiments and features in the embodiments can be combined with each other in the absence of conflict. Based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in the field without making creative work are within the scope of protection of the present disclosure.

[0022] It should be noted that various aspects of the embodiments within the scope of the appended claims are described below. It should be apparent that the aspects described herein may be embodied in a wide variety of forms, and any specific structure and / or function described herein is merely illustrative. Based on the present disclosure, it should be understood by those skilled in the art that an aspect described herein may be implemented independently of any other aspect, and two or more of these aspects may be combined in various ways. For example, any number of aspects described herein may be used to implement the device and / or practice the method. In addition, other structures and / or functionalities other than one or more of the aspects described herein may be used to implement this device and / or practice this method.

[0023] It should also be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present disclosure. The drawings only show components related to the present disclosure rather than being drawn according to the number, shape and size of components in actual implementation. In actual implementation, the type, quantity and proportion of each component may be changed arbitrarily, and the component layout may also be more complicated.

[0024] Additionally, in the following description, specific details are provided to facilitate a thorough understanding of the examples. However, it will be understood by those skilled in the art that the aspects described may be practiced without these specific details.

[0025] Reference Figure 1 The present disclosure provides a knowledge base privacy protection method, comprising the following steps: S1: When the business application system initiates a query request, determine whether the business application system and the knowledge management platform are the same entity; if not, execute S2; if yes, execute S3; S2: Perform cross-platform privacy matching on the prompt words provided by the business application system and the knowledge base provided by the knowledge management platform to obtain search results; S3: Perform local calculations on the prompt words and knowledge base to obtain search results; S4: The search results are transmitted to a secure computing environment provided by the search service system for isolation; S5: In a secure computing environment, the search results are privately fused with the prompt words to obtain context information; S6: Split the preset reasoning model into an encrypted reasoning sub-model and a plaintext reasoning sub-model, deploy the encrypted reasoning sub-model in a secure computing environment, and deploy the plaintext reasoning sub-model in a plaintext computing environment of the retrieval service system; S7: Use the encrypted reasoning sub-model to perform encrypted reasoning on the context information to obtain intermediate parameters; S8: Use the plaintext reasoning sub-model to perform plain-state reasoning on the intermediate parameters, obtain the reasoning results, and send the reasoning results to the business application system.

[0026] The privacy protection method of the knowledge base provided by the present disclosure is applicable to the scenario where the business application system, the knowledge management platform and the retrieval service system are different entities, and is also compatible with the simplified scenario where the business application system and the knowledge management platform are the same entity. When the business application system and the knowledge management platform are not the same entity, the method enables the retrieval service system to obtain the retrieval results through a secure computing environment, and performs privacy fusion of the retrieval results and prompt words in the secure computing environment to generate context information while ensuring data privacy security. When the business application system and the knowledge management platform are the same entity, the retrieval calculation is completed locally and then stored in the secure computing environment.

[0027] Compared with traditional privacy protection methods, this scheme significantly reduces the number of interaction rounds and improves computing efficiency. Traditional methods usually rely on complex multi-party secure computing protocols, and the parties need to frequently exchange data and intermediate results to ensure the correctness and privacy of the calculation, which not only increases the number of interaction rounds but also reduces computing efficiency. The secure computing environment of this scheme provides a relatively independent and secure computing space. After the retrieval results enter the environment, the relevant calculations and processing can be completed autonomously internally without the need for frequent external interactions to verify the calculation results of each step. The isolation characteristics of the secure computing environment effectively prevent data leakage during the calculation process.

[0028] In addition, this solution combines the secure computing environment and adopts a mechanism for the encrypted reasoning sub-model and the plaintext reasoning sub-model to work together. The encrypted reasoning sub-model first performs part of the reasoning, reducing the risk of leaking private data from intermediate parameters. At the same time, the front end of the reasoning process is placed in the privacy computing environment, avoiding the large amount of computing power overhead brought by the overall privacy computing, ensuring the efficiency and accuracy of the reasoning process; the plaintext reasoning sub-model makes full use of the advantages of the plaintext computing environment to quickly complete subsequent reasoning tasks and further improve the reasoning efficiency.

[0029] In summary, this method protects the data privacy security of the knowledge base and maintains the data rights and interests of the knowledge management platform through privacy computing technology. Even if the knowledge base is called multiple times, sensitive information will not be leaked, thereby bringing knowledge payment-related benefits to the knowledge management platform.

[0030] In S1, the business application system is supported to input prompt words and trigger query requests in multiple ways. The first is text input triggering. When the query personnel input the prompt word in the input box and press the "Enter" key or click the "Submit" button, the system will trigger the query request; the second is voice interaction triggering. In the voice interaction system, when the query personnel say a specific instruction (such as "query..."), the voice recognition system will recognize it as a query request and extract the prompt word; the third is API interface triggering. The business application system can programmatically input the prompt word and initiate a query request by calling the API interface provided by the system. This method is suitable for automation tools, third-party applications or developer integration scenarios, allowing the business application system to trigger queries without directly interacting with the user interface.

[0031] Obtain the identity identifiers (digital certificates, unique IDs, etc.) of the business application system and the knowledge management platform. The identity identifier of the business application system is called the first identity identifier, and the identity identifier of the knowledge management platform is called the second identity identifier. Compare the first identity identifier of the business application system with the second identity identifier of the knowledge management platform; if the comparison is consistent, it means that the two identities are consistent, and it is determined that the business application system and the knowledge management platform are the same entity; if the comparison is inconsistent, it is determined that the business application system and the knowledge management platform are not the same entity.

[0032] The above method is also applicable to situations where there are multiple business application systems or multiple knowledge management platforms. By clarifying the subject qualifications, illegal access to the knowledge base by external personnel can be effectively prevented, and the security and confidentiality of the knowledge base data can be guaranteed. When the business application system and the knowledge management platform belong to the same subject, the knowledge base can be modified, updated, and other operations can be performed directly based on the search results and the final query results; if the subjects are different, the business application system cannot directly access the knowledge base, but can still use the knowledge base to complete the search with the help of a certain mechanism. Therefore, in addition to protecting privacy data, this method can also achieve precise permission control of the knowledge base and improve data management efficiency.

[0033] In S2, the business application system sends the prompt word to the knowledge management platform, and the knowledge management platform matches the knowledge base suitable for the prompt word locally and obtains the search results. For example, when there are multiple different types of knowledge bases, the data is structured according to the different types of knowledge bases (such as text knowledge base, image knowledge base, database, etc.) to obtain knowledge features. Among them, for the text knowledge base, operations such as word segmentation, part-of-speech tagging, and named entity recognition are performed to obtain text features; for the image knowledge base, image features such as color features and texture features are extracted. An index is created according to the position of the knowledge feature in the knowledge base. For the text knowledge base, an inverted index is used to record the position of each text feature in it; for the image knowledge base, a KD tree index is used to record the position of each image feature in the image knowledge base. The prompt word is preprocessed, including operations such as cleaning and normalization, to generate a standard prompt word. According to the characteristics and semantics of the prompt word, the required knowledge type is analyzed, and a knowledge base with a type that matches the knowledge type is selected. Using the created index, search for content that completely matches the standard prompt word in the matching knowledge base. If the exact match fails to obtain a result, fuzzy matching is performed, such as using the edit distance, semantic similarity, etc. The matching results are screened according to the preset conditions, such as excluding results with a small matching degree, limiting the number of results, etc., and the matching results that meet the preset conditions are combined into the final search results.

[0034] In S3, when the first identity identifier of the business application system is consistent with the second identity identifier of the knowledge management platform, it means that the knowledge management platform is also the business application system, and the prompt word is searched in the knowledge base locally stored in the business application system to obtain the search result.

[0035] In S4, the knowledge management platform sends the search results to a secure computing environment for isolation. The secure computing environment is created in advance by the search service system on its computing nodes and is specifically used for data computing to ensure data security and privacy. The secure computing environment can be implemented using technologies such as the Trusted Execution Environment (TEE) or data sandbox. In this environment, a secure memory area is initialized that is invisible to the outside world, thereby effectively isolating and protecting data.

[0036] Reference Figure 2 The flowchart of the search result isolation method shown in the figure, "transmitting the search results to the secure computing environment provided by the search service system for isolation" includes the following steps: S41: Determine whether the search service system has access authorization to the search results; if so, execute S42; if not, execute S45; S42: Encrypt the search result based on the authorization information to generate an encrypted file containing the authorization information; S43: using the public key provided by the retrieval service system to encrypt the encrypted file again, generating a secondary encrypted file and sending it to the retrieval service system; S44: decrypting the secondary encrypted file using the private key and decryption key preset by the search service system, and storing the decrypted search result in the secure memory area of ​​the secure computing environment based on the decrypted authorization information; S45: Encrypt the search result to generate an encrypted search result and a first key, and encrypt the first key using a public key of the secure computing environment to generate an encryption key; S46: loading the encrypted search result and the encryption key into the secure computing environment, and decrypting the encryption key using the private key of the secure computing environment; S47: Decrypt the encrypted search result using the decrypted first key, and store the decrypted search result in the secure memory area.

[0037] In S41, the knowledge management platform maintains an authorization list, which records the identification information of all authorized retrieval service systems. When the retrieval service system initiates an access request to the retrieval results, the knowledge management platform determines whether it has access authorization by comparing the third identity identifier (such as a digital certificate, unique ID, etc.) of the retrieval service system with the authorization list, or the knowledge management platform actively sends the retrieval results and the first identity identifier of the business application system to the retrieval service system, and determines whether the retrieval service system has access authorization to the retrieval results through the authorization list before sending. This determination process can be implemented on the server side of the knowledge management platform through an automated program, and the program will return authorization status information (such as "authorization passed" or "unauthorized") based on the comparison results.

[0038] In S42-S44, when the search service system has access authorization to the search results, it is allowed to directly decrypt the search results. First, the search service system generates a pair of public and private keys before starting the operation, and sends the public key in a secure manner to the knowledge management platform. At the same time, the knowledge management platform securely transmits the decryption key to the search service system. The knowledge management platform then uses a symmetric encryption algorithm (such as AES) to encrypt the search results. During the encryption operation, the authorization information (such as the authorization validity period, access permission range, etc.) is embedded in the header or metadata of the encrypted file in a specific data structure (such as JSON format). The encrypted file generated in this way contains both the encrypted search result data and the authorization information, thereby ensuring the correlation between the authorization information and the search result data.

[0039] The knowledge management platform uses the public key provided by the retrieval service system to perform secondary encryption on the encrypted file containing the authorization information through an asymmetric encryption algorithm (such as the RSA algorithm), generates a secondary encrypted file, and sends the secondary encrypted file to the retrieval service system using a secure network channel (such as HTTPS). After receiving the secondary encrypted file, the retrieval service system performs two decryption operations in sequence, first using its own pre-set private key to perform the first decryption of the secondary encrypted file, and then using the decryption key provided by the knowledge management platform to perform the secondary decryption, and finally obtains the decrypted authorization information and the decrypted retrieval results.

[0040] The retrieval service system strictly verifies the legality and validity of the authorization information, such as checking whether the authorization validity period is within a reasonable range and whether the scope of access rights meets the established requirements. After the verification is passed, the decrypted retrieval results are stored in the secure memory area of ​​the secure computing environment. The secure memory area is protected by both hardware and software mechanisms, which can effectively ensure the security and integrity of the data. If the authorization information verification fails, the retrieval service system refuses to store the decrypted retrieval results, properly saves the relevant files, and feedbacks the verification failure and reasons to the knowledge management platform according to the preset process, while preventing unauthorized data access and leakage, and continues to store the retrieval results after resolving the reasons for the verification failure.

[0041] In S45-S47, a pair of public and private keys will be generated when the secure computing environment is first created. When the retrieval service system does not have access authorization to the retrieval results, in order to prevent it from obtaining the privacy data of the retrieval results, the retrieval service system is not supported to directly decrypt the retrieval results. However, the public key of the secure computing environment will be securely provided to the knowledge management platform.

[0042] The knowledge management platform uses a symmetric encryption algorithm (such as AES) to encrypt the search results, generate encrypted search results and the corresponding first key (i.e., symmetric key), and the knowledge management platform uses the public key provided by the secure computing environment to encrypt the first key through an asymmetric encryption algorithm to obtain an encryption key. The knowledge management platform sends the encrypted search results and encryption key to the search service system, which then loads them into the secure computing environment. During this process, the search service system cannot complete the decryption operation by itself because it does not have the secure computing environment private key for decrypting the encryption key.

[0043] In the secure computing environment, the encrypted key is decrypted using its own private key to obtain the original first key. This decryption process is under the security protection of the secure computing environment, which can ensure that the first key will not be leaked. The encrypted search result is decrypted using the first key obtained by decryption to obtain the original search result data, and the decrypted search result is stored in the secure memory area of ​​the secure computing environment, thereby completing the isolated storage of the search result in the secure computing environment.

[0044] In the above process, the knowledge management platform and the retrieval service system respectively record detailed logs of authorization and data access operations, including authorization time, access content, operation results, etc. By analyzing the log data, it is detected whether there are abnormal authorization requests or data access behaviors. Once an abnormality is found, timely measures such as suspending authorization and conducting security audits are taken.

[0045] In S5, the business application system also sends the prompt word to the secure computing environment of the retrieval service system. In the secure computing environment, the search results and the prompt word are spliced ​​in a preset order to achieve the fusion of the two and generate context information. Among them, the preset order includes the following two: the first is to put the prompt word in the front and the search results are spliced ​​immediately after; the second is to put the search results in the front and the prompt word in the back for splicing. In practical applications, the first splicing order is usually selected, that is, the prompt word is in front and the search results are in the back. This is because the prompt word often represents the core problem or key demand of the user. Putting it in the front can make the context information clearly convey the core intention at the beginning, which is convenient for the subsequent processing flow (such as semantic understanding, model reasoning, etc.) to quickly focus on the key points. At the same time, it conforms to people's daily expression and information reception habits, and it is easier to understand and parse the complete semantics expressed by the context, thereby improving the efficiency and accuracy of the entire information processing process.

[0046] When there is only one knowledge base, there is only one search result generated based on the knowledge base. At this time, the context information generated by the search result is directly input into the encrypted reasoning sub-model. The encrypted reasoning sub-model reasons it in a secure computing environment and outputs intermediate parameters. This reasoning process can focus on the information provided by a single knowledge base, reduce computing resource consumption, and improve reasoning speed. Moreover, the context information generated by a single search result has clear directionality and does not contain too much redundant and irrelevant information. This allows the encrypted reasoning sub-model to focus more on the core content during the reasoning process and avoid being disturbed by other irrelevant information.

[0047] When there are multiple knowledge bases, there may be multiple knowledge bases that match the prompt word. In this case, after searching for the prompt word in multiple knowledge bases, the number of search results will increase accordingly. In order to make full use of the information of multiple knowledge bases and improve the accuracy of reasoning, these search results are fused. During the fusion process, the search results are carefully compared, the repeated parts are deleted, and only the non-repeated parts are retained to obtain new search results. The new search results and the prompt word are spliced ​​in a preset order to generate context information. This method can integrate the advantages of different knowledge bases, make the information of each knowledge base complement each other, and form a more comprehensive and richer information set. The encrypted reasoning sub-model performs reasoning based on this fused comprehensive information, which can generate more accurate and reliable intermediate parameters, providing more powerful support for subsequent analysis and decision-making.

[0048] In S6, a detailed architectural analysis of the preset reasoning model is performed to identify the specific role of each functional module in the preset reasoning model. Taking the natural language processing model based on deep learning as an example, it includes modules such as input layer, embedding layer, hidden layer, and output layer. When splitting the preset reasoning model, it is split into two consecutive parts. The first M layers constitute the encrypted reasoning sub-model, and the last N layers constitute the plaintext reasoning sub-model, where K is the total number of functional modules of the preset reasoning model, satisfying K=M+N. The key basis for the split is to ensure that the data output by the encrypted reasoning sub-model composed of the first M layers is difficult to be reversed to the original data, and the plaintext reasoning sub-model composed of the last N layers can perform efficient operations in a plaintext environment to balance the security and computing performance during the model processing process.

[0049] After the split, the encrypted reasoning sub-model is deployed to a secure computing environment for isolation. During the deployment, a secure loading mechanism is used to ensure its integrity and confidentiality, complete the initialization operation, and establish a secure communication channel with the outside for data interaction. The plaintext reasoning sub-model is deployed in the plaintext computing environment of the retrieval service system. At the same time, an interactive interface is set between the encrypted reasoning sub-model and the plaintext reasoning sub-model. The data format, transmission protocol and interaction process are clarified in the interface to ensure that the two sub-models in different environments can work together efficiently and stably.

[0050] In S7, in a secure computing environment, the encrypted reasoning sub-model will conduct in-depth logical analysis and data mining on the context information in a secret form, and gradually generate a series of intermediate parameters. These intermediate parameters are essentially the interim results generated by the encrypted reasoning sub-model when performing reasoning operations on the context information, and are the data sets obtained after completing some reasoning tasks. After the operation of the encrypted reasoning sub-model, the intermediate parameters themselves have a high degree of privacy, and it is difficult for the outside world to glimpse the privacy of the knowledge base from the intermediate parameters. However, in order to further strengthen the protection of the security of the knowledge base and prevent potential risks that may arise during the data transmission process, it is still encrypted and sent to the plaintext computing environment.

[0051] Reference Figure 3 The flowchart of the method for sending the intermediate parameter encryption is shown. The method for sending the intermediate parameter from the secure computing environment to the plaintext computing environment includes the following steps: S71: Encrypt the intermediate parameter using the public key provided by the knowledge management platform to generate an encrypted parameter; S72: Send the encryption parameters from the secure computing environment to the plaintext computing environment for authorized decryption.

[0052] In S71, before the secure computing environment sends the intermediate parameters to the plaintext computing environment, in order to further ensure the security and privacy of the data, the knowledge management platform will randomly generate a public key, which can be temporary or fixed. The public key is sent to the secure computing environment through a secure transmission channel. The secure transmission channel can use encryption protocols such as SSL / TLS to ensure that the public key is not stolen or tampered with during transmission. After receiving the public key, the secure computing environment will encrypt the intermediate parameters according to the public key provided by the knowledge management platform. This encryption process follows a specific encryption algorithm (such as the RSA algorithm) to generate encryption parameters. After encryption is completed, the secure computing environment sends the encrypted parameters to the plaintext computing environment.

[0053] In S72, the encrypted parameters can be authorized for decryption in a variety of ways. For example, in the first embodiment, a decryption application is sent to the knowledge management platform or a third-party authorization agency. After the decryption application is approved, the second key preset by the knowledge management platform is obtained; based on the second key, the encrypted parameters are decrypted and restored to intermediate parameters and stored in a plaintext computing environment.

[0054] Among them, the second key is pre-set by the knowledge management platform. Like the public key of the knowledge management platform, the second key can be temporary or fixed, and is strictly kept by the knowledge management platform itself or a reliable third-party authorized agency to prevent data security risks caused by the leakage of the second key.

[0055] When the retrieval service system detects the presence of new encryption parameters in the plaintext computing environment, the retrieval service system initiates a decryption application to the knowledge management platform or a third-party authorized agency that holds the second key. When initiating the application, the retrieval service system needs to provide detailed application information, including the reason for the decryption application, the specific encryption parameter identifiers involved, the expected usage scenarios, etc., so that the knowledge management platform or the third-party authorized agency can review it.

[0056] After receiving the decryption application, the knowledge management platform or third-party authorization agency will strictly review the application according to the pre-set security policies and authorization rules. The review content covers multiple aspects such as the legality, rationality and security of the application. If the application passes the review, the knowledge management platform or third-party authorization agency will securely send the authentication license information and the second key to the retrieval service system. The authentication license information includes the license identification, authorization subject information, applicant information, license validity period, scope of use and digital signature.

[0057] After receiving the authentication permission information and the second key, the retrieval service system verifies the validity and authenticity of the authentication permission information, and ensures that the information has not been tampered with and is within the validity period by comparing the digital signature and other methods. After the verification is passed, the retrieval service system uses the second key to decrypt the encrypted parameters based on the authentication permission information. The decryption process follows the decryption algorithm corresponding to the encryption process, so that the plaintext computing environment can safely and legally obtain the original intermediate parameters for subsequent reasoning operations.

[0058] In the second embodiment, a decryption application containing encryption parameters is sent to the knowledge management platform or a third-party authorization agency. After the decryption application is approved, the encryption parameters are decrypted using a second key local to the knowledge management platform or the third-party authorization agency; the decrypted intermediate parameters are sent back to the plaintext computing environment of the retrieval service platform.

[0059] The main difference between the second embodiment and the first embodiment is that the decryption environment of the encryption parameters is different. In the first embodiment, the retrieval service system performs decryption operations on the encryption parameters by itself, which enables the retrieval service system to independently control the timing and rhythm of decryption and make full use of its own computing resources, which not only ensures the continuity of business processes, but also reduces dependence on external services. In the second embodiment, the decryption operation is completed by the knowledge management platform or a third-party authorized agency. By leveraging the professional security protection and compliance management capabilities of these platforms and agencies, centralized management and auditing of decryption operations are achieved, effectively reducing the risk of data leakage and compliance costs.

[0060] During the encryption and decryption process of the intermediate parameters, detailed log records are kept for each link in the entire process, and the decryption application process of the retrieval service system is stored for subsequent auditing and supervision, thereby ensuring the compliance and traceability of the operation.

[0061] In S8, the plaintext reasoning sub-model takes the intermediate parameters as input, completes the subsequent reasoning process with the help of the preset calculation logic inside the model, and outputs the final reasoning result. The retrieval service system encapsulates the reasoning results and adds necessary metadata, such as reasoning task identifier, reasoning time, result type, etc., so that the business application system can correctly identify and process them. The encapsulated reasoning results are sent to the business application system through a secure communication protocol (such as HTTPS). During the transmission process, encryption technology is used to encrypt the data to prevent the data from being stolen or tampered with during the transmission process. After receiving and decrypting the reasoning results, the business application system sends a receipt confirmation message to the retrieval service system to ensure that the results are successfully transmitted.

[0062] In summary, the privacy protection method of the knowledge base disclosed in the present invention uses a secure computing environment (TEE) to protect data at key nodes of data processing before exposing intermediate parameters to a plaintext computing environment. Even if there are security vulnerabilities in the entire system, sensitive content such as context information and intermediate parameters will not be obtained by unauthorized entities. Taking the medical data reasoning scenario as an example, the patient's sensitive health data is used as context information and reasoned in the TEE, which can effectively prevent data leakage and effectively protect patient privacy. Moreover, the secure computing environment has the function of ensuring that the code running in it is not tampered with. For example, when encrypting intermediate parameters, it can resist interference with the encryption process by malware or attackers, ensure the accuracy and integrity of the encryption operation, and avoid encryption failure or data leakage risks caused by code tampering.

[0063] Moreover, the secure computing environment is optimized for key computing tasks related to privacy protection. For example, encryption and decryption operations can be completed efficiently without occupying too many computing resources of the large model. The encrypted reasoning sub-model has simple computing logic and only processes some reasoning tasks related to privacy protection, avoiding the performance loss caused by complex security protection operations. In addition, the data interaction between the secure computing environment and the plaintext computing environment has been carefully designed, and the intermediate parameter sending process is efficient and orderly, which reduces the impact of data sending delays and inconsistencies on the performance of the large model, and ensures the security, efficiency and accuracy of the reasoning process. It can be seen that by utilizing the secure computing environment, this method can achieve relatively high performance while ensuring that the knowledge base is not exposed throughout the process.

[0064] Reference Figure 4 The present disclosure provides a knowledge base privacy protection system, comprising: The subject judgment module 101 is used to judge whether the business application system and the knowledge management platform are the same subject when the business application system initiates a query request; if not, the privacy calculation module 102 is executed; if so, the local calculation module 103 is executed; The privacy calculation module 102 is used to perform cross-platform privacy matching on the prompt words provided by the business application system and the knowledge base provided by the knowledge management platform to obtain search results; A local calculation module 103 is used to perform local calculations on the prompt words and the knowledge base to obtain search results; The data isolation module 104 is used to transmit the search results to a secure computing environment provided by the search service system for isolation; The privacy fusion module 105 is used to perform privacy fusion of the search results and the prompt words in a secure computing environment to obtain context information; the model splitting module is used to split the preset reasoning model into an encrypted reasoning sub-model and a plaintext reasoning sub-model, deploy the encrypted reasoning sub-model in the secure computing environment, and deploy the plaintext reasoning sub-model in the plaintext computing environment of the retrieval service system; A dense reasoning module 106, used to perform dense reasoning on context information using an encrypted reasoning sub-model to obtain intermediate parameters; The plain text reasoning module 107 is used to perform plain text reasoning on the intermediate parameters using the plain text reasoning sub-model, obtain reasoning results, and send the reasoning results to the business application system.

[0065] The various variations and specific examples of the privacy protection method for the knowledge base provided above are also applicable to the privacy protection system for the knowledge base provided in the present disclosure. Through the above detailed description of the privacy protection method for the knowledge base, those skilled in the art can clearly know the implementation method of the privacy protection system for the knowledge base. For the sake of brevity of the specification, it will not be described in detail here.

[0066] The computer device according to the embodiment of the present disclosure includes a memory and a processor. The memory is used to store non-temporary computer-readable instructions. Specifically, the memory may include one or more computer program products, and the computer program product may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, a random access memory (RAM) and / or a cache memory (cache), etc. The non-volatile memory may include, for example, a read-only memory (ROM), a hard disk, a flash memory, etc.

[0067] The processor may be a central processing unit (CPU) or other forms of processing units with data processing capabilities and / or instruction execution capabilities, and may control other components in the computer device to perform desired functions. In one embodiment of the present disclosure, the processor is used to run the computer-readable instructions stored in the memory, so that the computer device performs all or part of the steps of the privacy protection method of the knowledge base in each embodiment of the present disclosure.

[0068] Those skilled in the art should be able to understand that in order to solve the technical problem of how to obtain a good user experience, the present embodiment may also include well-known structures such as a communication bus and an interface, and these well-known structures should also be included in the protection scope of the present disclosure.

[0069] like Figure 5 A schematic diagram of the structure of a computer device provided in an embodiment of the present disclosure is shown, which is a schematic diagram of the structure of a computer device suitable for implementing the embodiment of the present disclosure. Figure 5 The computer device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.

[0070] like Figure 5 As shown, the computer device may include a processor (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) or a program loaded from a storage device into a random access memory (RAM). In the RAM, various programs and data required for the operation of the computer device are also stored. The processor, ROM, and RAM are connected to each other via a bus. An input / output (I / O) interface is also connected to the bus.

[0071] Typically, the following devices can be connected to the I / O interface: input devices such as sensors or visual information acquisition devices; output devices such as display screens; storage devices such as tapes, hard disks, etc.; and communication devices. The communication device can allow the computer device to communicate with other devices (such as edge computing devices) wirelessly or by wire to exchange data. Figure 5 A computer device having various devices is shown, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead.

[0072] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program contains program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by a processor, all or part of the steps of the privacy protection method of the knowledge base of the embodiment of the present disclosure are executed.

[0073] For detailed description of this embodiment, reference may be made to the corresponding descriptions in the aforementioned embodiments, which will not be repeated here.

[0074] According to the computer-readable storage medium of the embodiment of the present disclosure, non-transitory computer-readable instructions are stored thereon. When the non-transitory computer-readable instructions are executed by a processor, all or part of the steps of the privacy protection method of the knowledge base of each embodiment of the present disclosure are executed.

[0075] The above-mentioned computer-readable storage media include, but are not limited to: optical storage media (e.g., CD-ROM and DVD), magneto-optical storage media (e.g., MO), magnetic storage media (e.g., magnetic tape or mobile hard disk), media with built-in rewritable non-volatile memory (e.g., memory card) and media with built-in ROM (e.g., ROM box).

[0076] For detailed description of this embodiment, reference may be made to the corresponding descriptions in the aforementioned embodiments, which will not be repeated here.

[0077] The basic principles of the present disclosure are described above in conjunction with specific embodiments. However, it should be noted that the advantages, strengths, effects, etc. mentioned in the present disclosure are only examples and not limitations, and it cannot be considered that these advantages, strengths, effects, etc. are required by each embodiment of the present disclosure. In addition, the specific details disclosed above are only for the purpose of illustration and ease of understanding, and are not limitations. The above details do not limit the present disclosure to the necessity of adopting the above specific details to be implemented.

[0078] In the present disclosure, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply that there is any such actual relationship or order between these entities or operations. The block diagrams of the devices, devices, equipment, and systems involved in the present disclosure are only illustrative examples and are not intended to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagram. As will be appreciated by those skilled in the art, these devices, devices, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including", "comprising", "having", etc. are open words, referring to "including but not limited to", and can be used interchangeably with them. The words "or" and "and" used here refer to the words "and / or" and can be used interchangeably with them, unless the context clearly indicates otherwise. The words "such as" used here refer to the phrase "such as but not limited to", and can be used interchangeably with them.

[0079] Additionally, as used herein, "or" used in a list of items beginning with "at least one" indicates a separate list, so that, for example, a list of "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the word "exemplary" does not mean that the example described is preferred or better than other examples.

[0080] It should also be noted that in the system and method of the present disclosure, each component or each step can be decomposed and / or recombined. Such decomposition and / or recombination should be regarded as equivalent solutions of the present disclosure.

[0081] Various changes, substitutions, and modifications of the techniques described herein may be made without departing from the teachings defined by the appended claims. Furthermore, the scope of the claims of the present disclosure is not limited to the specific aspects of the processes, machines, manufactures, compositions of events, means, methods, and actions described above. Currently existing or later to be developed processes, machines, manufactures, compositions of events, means, methods, or actions that perform substantially the same functions or achieve substantially the same results as the corresponding aspects described herein may be utilized. Thus, the appended claims include such processes, machines, manufactures, compositions of events, means, methods, or actions within their scope.

[0082] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the present disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of the present disclosure. Therefore, the present disclosure is not intended to be limited to the aspects shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.

[0083] The above description has been given for the purpose of illustration and description. In addition, this description is not intended to limit the embodiments of the present disclosure to the forms disclosed herein. Although multiple example aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, changes, additions and sub-combinations thereof.

Claims

1. A knowledge base privacy protection method, characterized in that: include: When the business application system initiates a query request, it is determined whether the business application system and the knowledge management platform are the same entity; If not, a cross-platform privacy match is performed on the prompt words provided by the business application system and the knowledge base provided by the knowledge management platform to obtain the search results; If yes, then locally calculate the prompt word and the knowledge base to obtain the search result; Transmitting the search results to a secure computing environment provided by a search service system for isolation; In the secure computing environment, privately fuse the search result with the prompt word to obtain context information; Splitting the preset reasoning model into an encrypted reasoning sub-model and a plaintext reasoning sub-model, deploying the encrypted reasoning sub-model in the secure computing environment, and deploying the plaintext reasoning sub-model in the plaintext computing environment of the retrieval service system; Use the encrypted reasoning sub-model to perform encrypted reasoning on the context information to obtain intermediate parameters; The plaintext reasoning sub-model is used to perform plaintext reasoning on the intermediate parameters to obtain reasoning results, and the reasoning results are sent to the business application system.

2. The method for protecting the privacy of a knowledge base according to claim 1, characterized in that: The determining whether the business application system and the knowledge management platform are the same entity includes: Comparing the first identity identifier of the business application system with the second identity identifier of the knowledge management platform; If the comparison is consistent, it is determined that the business application system and the knowledge management platform are the same entity; If the comparison is inconsistent, it is determined that the business application system and the knowledge management platform are not the same entity.

3. The method for protecting the privacy of a knowledge base according to claim 1, characterized in that: The cross-platform privacy matching of the prompt words provided by the business application system and the knowledge base provided by the knowledge management platform to obtain the search results includes: The prompt word is sent to the knowledge management platform, and the received prompt word is searched using the local knowledge base of the knowledge management platform to obtain the search result.

4. The method for protecting the privacy of a knowledge base according to any one of claims 1 to 3, characterized in that: The transmitting the search results to a secure computing environment provided by the search service system for isolation includes: When the search service system has access authorization to the search results; then encrypting the search result based on the authorization information to generate an encrypted file containing the authorization information; The encrypted file is re-encrypted using the public key provided by the retrieval service system to generate a secondary encrypted file and send it to the retrieval service system; The secondary encrypted file is decrypted using a private key and a decryption key preset by the retrieval service system, and the decrypted retrieval result is stored in a secure memory area of ​​the secure computing environment based on the decrypted authorization information.

5. The method for protecting the privacy of a knowledge base according to claim 4, characterized in that: The transmitting the search results to a secure computing environment provided by the search service system for isolation also includes: When the search service system does not have access authorization to the search results; then encrypting the search result to generate an encrypted search result and a first key, and encrypting the first key using the public key of the secure computing environment to generate an encryption key; loading the encrypted search result and the encryption key into the secure computing environment, and decrypting the encryption key using a private key of the secure computing environment; The encrypted search result is decrypted using the decrypted first key, and the decrypted search result is stored in the secure memory area.

6. The method for protecting the privacy of a knowledge base according to claim 1, characterized in that: The step of privately fusing the search result with the prompt word to obtain context information includes: When the number of the search results is 1, the search results and the prompt words are concatenated in a preset order to generate the context information; When the number of the search results is not 1, all the search results are merged into a new search result; The new search result and the prompt word are concatenated according to the preset order to generate the context information.

7. The method for protecting the privacy of a knowledge base according to claim 1, characterized in that: Also includes: Encrypt the intermediate parameter using the public key provided by the knowledge management platform to generate an encrypted parameter; The encryption parameters are sent from the secure computing environment to the plaintext computing environment for authorized decryption.

8. A computer device, characterized in that: The computer device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the privacy protection method of the knowledge base described in any one of claims 1-7.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the knowledge base privacy protection method described in any one of claims 1-7.

10. A computer program product comprising computer instructions, characterized in that: When the computer instructions are executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Privacy-protecting graph data query method and device

    CN117708381A

  • Method and device for carrying out privacy protection on data in large model reasoning

    CN119382871A

  • Data isolation and privacy protection method and system for large data security model

    CN119442290A

  • WEDI: an encryption-based method and system for the identification and protection of printed documents or those being transmitted by electronic means

    US20080307228A1

Cited By

  • Knowledge base construction and use method and device of trusted data space, equipment and medium

    CN120338085A

  • Model reasoning method and device for protecting sensitive data, medium and program product

    CN120354456A

  • Large language model reasoning method, device and equipment and readable storage medium

    CN120893580A