AI interactive data protection method and system based on security context protocol

By introducing security context management services and security context protocols into the AI ​​interaction system, the problem of context data security risks in AI interaction is solved, efficient data protection and compliance are achieved, and data security of AI applications is improved.

CN120200863AActive Publication Date: 2025-06-24CENTURY LONGMAI TECH

Patent Information

Application Number
CN202510686752.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-06-24
Estimated Expiration
2045-05-27

AI Technical Summary

Technical Problem

The prior art has significant data security risks when processing contextual data in AI interactions, including transmission risks, processing risks, storage risks, compliance risks and rough access control issues.

Method used

Using an AI interactive data protection method based on security context protocols, by introducing a trusted security context management service (SCS) and defining a new context protocol (SCP), secure reference/tokens are used instead of original sensitive data when transmitting and processing context data, ensuring secure storage, retrieval and access control of data.

Benefits of technology

It greatly reduces the chances of sensitive data transmission and processing on networks and AI models, reduces the risk of data leakage, improves compliance, realizes fine-grained access control and flexible security policy configuration, and enhances the data security of AI applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200863A_ABST
    Figure CN120200863A_ABST
Patent Text Reader

Abstract

The invention discloses an AI interactive data protection method and system based on a security context protocol. According to the method, a client application sends a user request carrying a session identifier to an application gateway; the gateway queries a required context range and a security processing strategy according to the request type, and transmits a strategy instruction; after the SCS verifies the gateway permission, the context data is retrieved and processed according to the strategy instruction, and a security context data block is generated; the gateway assembles the user input and the security context data block into a final request according to an SCP protocol, and sends the final request to an AI model; the AI model processes the request and returns a response; after receiving the response, the gateway updates the session context and updates the stored context data; and finally, the gateway returns the response of the AI model to the client application to complete interaction. According to the method, the exposure of the sensitive context data in the system can be reduced to the greatest extent while the AI interaction effect is ensured, so that the data security and compliance of the AI application are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and particularly to an AI interaction data protection method and system based on a secure context protocol. Background Art

[0002] With the rapid development of artificial intelligence (AI) technology, especially the wide application of large language models (LLMs) in various applications, when an AI system realizes coherent, personalized, and effective interactions, it needs to access a large amount of context information, such as user historical conversation records, personally identifiable information (PII), preference settings, session states and intermediate data, and real-time information retrieved from external systems. However, there are significant data security risks in the existing technologies when processing this context information, which are mainly reflected in the following aspects:

[0003] Transmission risk: Although channel encryption technologies such as TLS / SSL can be used, when processing data at the endpoints (client, gateway, AI model server), the data may still exist in plain text, increasing the risk of data leakage when the intermediate nodes are attacked.

[0004] Processing risk: AI models (especially third-party closed-source models) will come into contact with the complete context data when processing requests, and their internal data processing and storage policies may not be controllable, posing risks of data abuse or accidental leakage.

[0005] Storage risk: If the context information is stored improperly (e.g., logging, caching), it may lead to the persistence of sensitive data in insecure locations.

[0006] Compliance risk: Directly transmitting and processing context information containing PII makes it difficult to meet the requirements of data protection regulations such as GDPR and CCPA for data minimization, purpose limitation, and user consent.

[0007] Coarse access control: It is difficult to perform fine-grained access control on context information, and often the entire context block is exposed to multiple components in the processing flow.

[0008] Therefore, there is an urgent need for a new technical solution that can minimize the exposure of sensitive context data within the system (especially during transmission and submission to the AI model) while ensuring the AI interaction effect, thereby improving the data security and compliance of AI applications. Summary of the Invention

[0009] Based on this, the embodiments of the present application provide an AI interaction data protection method and system based on a secure context protocol, which solve the security risk problems in the transmission and processing of AI interaction context data in the prior art.

[0010] In a first aspect, a method for protecting AI interaction data based on a security context protocol is provided. The method includes:

[0011] The client application sends a user request to the application gateway, carrying a session identifier;

[0012] After receiving the request, the gateway queries the policy engine for the context scope and security processing policy required for this interaction according to the request type and the target AI model;

[0013] The gateway requests the required context data from the security context service using the session identifier and passes the policy instruction;

[0014] After verifying the gateway's permissions, the SCS retrieves the complete context data and processes it according to the policy instruction;

[0015] The gateway assembles the user's current input and the security context data block obtained from the SCS into a final request according to the SCP protocol format and sends it to the AI model;

[0016] After receiving the request, the AI model processes it based on the received information;

[0017] The AI model returns the processing result. The gateway receives the response and updates the context of the session as needed; the gateway interacts with the SCS again to request an updated context; after verifying the permissions, the SCS updates the stored complete context;

[0018] The gateway returns the final response of the AI model to the client application, completing the entire interaction process.

[0019] Optionally, after receiving the request, the gateway queries the policy engine for the context scope and security processing policy required for this interaction, including:

[0020] The gateway parses the user request to extract the request type, target AI model information, and session identifier;

[0021] Based on the extracted information, the gateway constructs a query request that includes the session identifier, request type, and target AI model identifier;

[0022] The gateway sends the query request to the policy engine to request the context data scope and security processing policy related to this interaction;

[0023] Based on the query request, the policy engine returns the context data scope required for this interaction, including but not limited to the user's historical conversation records, user personal identity information, user preference settings, session status and intermediate data, and real-time information related to the user retrieved from external systems, as well as the corresponding security processing policy.

[0024] Optionally, the gateway requests the required context data from the Security Context Service (SCS) using the session identifier and passes policy instructions, including:

[0025] The gateway constructs a request message based on the context data scope and security processing policy returned by the policy engine. The request message contains the session identifier, the required context data scope, and security processing policy instructions;

[0026] The gateway sends the constructed request message to the SCS via a secure communication channel to request context data related to the session identifier;

[0027] The SCS receives the request message sent by the gateway and parses the session identifier, context data scope, and security processing policy instructions therein.

[0028] Optionally, after verifying the gateway's permissions, the SCS retrieves the complete context data and processes it according to the policy instructions, including:

[0029] The SCS verifies the identity of the gateway in the received request message to confirm that the gateway has the permission to request context data;

[0030] After successful verification, the SCS retrieves the complete context data related to the session from the context data it stores according to the session identifier, including the user's historical conversation records, user personal identity information, user preference settings, session status and intermediate data, and real-time information related to the user retrieved from external systems;

[0031] The SCS classifies and processes the retrieved context data according to the policy instructions. For non-sensitive data that is allowed to be directly passed, it remains unchanged; for sensitive data that needs to be protected, instead of returning the original data, one or more security references / tokens are generated and these references / tokens are placed in the context fields of the response; for data that the policy requires to be completely filtered, it is directly removed; for data that needs to be de-sensitized, the de-sensitized data is returned.

[0032] Optionally, the gateway assembles the user's current input and the secure context data block obtained from the SCS into a final request according to the SCP protocol format and sends it to the AI model, including:

[0033] The gateway receives the "secure context" data block returned by the SCS that contains references / tokens and non-sensitive / de-sensitized data;

[0034] The gateway integrates the user's current input and the secure context data block according to the format specified by the SCP protocol to form a complete request message. The context field of this request message structurally contains non-sensitive data, de-sensitized data, and references / tokens pointing to sensitive data in the SCS;

[0035] The gateway sends the integrated request message to the AI model via a secure communication channel for the AI model to process.

[0036] Optionally, the AI model returns a processing result. The gateway receives the response and updates the context of the session as needed; the gateway interacts with the SCS again to request an updated context; after verifying the permissions, the SCS updates the stored complete context, including:

[0037] After the AI model finishes processing, it returns the processing result as a response to the gateway;

[0038] The gateway receives the response from the AI model and determines whether to update the context of the session based on the response content, such as adding the new user input and the AI reply to the conversation history;

[0039] If an update is needed, the gateway constructs a request message containing the update content, which includes the session identifier and the context data to be updated;

[0040] The gateway sends the constructed update request message to the SCS via the secure communication channel again;

[0041] The SCS receives the gateway's update request, verifies the identity of the gateway in the received request message, and confirms that the gateway has the permission to update the context data;

[0042] After the verification passes, the SCS updates the stored complete context data related to the session identifier according to the session identifier and the context data in the update request.

[0043] In a second aspect, an AI interaction data protection system based on a secure context protocol is provided, and the system includes:

[0044] A client application for sending a user request to an application gateway and carrying a session identifier;

[0045] A gateway for, after receiving a request, querying the context scope and security processing policy required for this interaction from a policy engine according to the request type and the target AI model; requesting the required context data from a secure context service using the session identifier and passing a policy instruction; after the SCS verifies the gateway's permissions, retrieving the complete context data and processing it according to the policy instruction; assembling the user's current input and the secure context data block obtained from the SCS into a final request according to the SCP protocol format and sending it to the AI model; the gateway receiving the response from the AI model module and updating the context of the session as needed, interacting with the SCS again to request an updated context; after the SCS verifies the permissions, updating the stored complete context; and returning the final response of the AI model to the client application to complete the entire interaction process;

[0046] The AI model module is used to process the received information based on the received request and return the processing result.

[0047] In a third aspect, an electronic device is provided, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the AI interaction data protection method described in any one of the first aspects above is implemented.

[0048] In a fourth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the AI interaction data protection method described in any one of the first aspects above is implemented.

[0049] In a fifth aspect, a computer program product is provided, on which a computer program is stored. When the computer program is executed by a processor, the AI interaction data protection method described in any one of the first aspects above is implemented.

[0050] The beneficial effects brought by the technical solutions provided in the embodiments of the present application at least include:

[0051] Enhanced data security: Greatly reduce the chance of raw sensitive data being transmitted over the network and directly processed by the AI model. Sensitive data is securely isolated in the trusted SCS.

[0052] Reduced leakage risk: Even if the AI model service or transmission link is compromised, attackers can only obtain meaningless references / tokens or non-sensitive / desensitized data, and the original sensitive data remains secure.

[0053] Better compliance: It is easier to meet data protection regulations (such as the data minimization and purpose limitation principles of GDPR) because it is possible to precisely control which data is processed and how it is processed.

[0054] Fine-grained access control: Through the policy engine and SCS, fine-grained access control and dynamic desensitization of context data based on roles and purposes can be achieved.

[0055] Flexibility and scalability: The SCS can be deployed and extended as an independent service, and the security policy can be flexibly configured and updated without affecting the AI model itself. It can support docking different internal or third-party AI models and apply a unified security policy.

[0056] Auditability: The SCS and the policy engine can provide detailed context access and processing logs, which are convenient for security auditing and tracking. Description of the Drawings

[0057] To more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings described below are only exemplary. For those of ordinary skill in the art, without creative efforts, other implementation drawings can also be obtained based on the provided drawings.

[0058] Figure 1 It is a flowchart of the steps of the AI interaction data protection method provided by the embodiment of the present application;

[0059] Figure 2 It is a schematic diagram of the interaction process provided by the embodiment of the present application;

[0060] Figure 3 It is an architecture diagram of the AI interaction data protection system based on the secure context protocol provided by the embodiment of the present application;

[0061] Figure 4 It is an example diagram of the context data structure in the SCP protocol provided by the embodiment of the present application;

[0062] Figure 5 It is a schematic diagram of an electronic device provided by the embodiment of the present application. Detailed implementation manners

[0063] In order to make the purpose, technical solutions and advantages of the present application more clear, the following further details the present application in combination with the drawings and embodiments. It should be understood that the specific embodiments described here are only used to explain the present application and are not used to limit the present application.

[0064] In the description of the present invention, the terms "include", "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily limit to the clearly listed steps or units, but may also include other steps or units inherent to these processes, methods, products or devices, or steps or units added based on the further optimized solutions conceived by the present invention.

[0065] Currently, artificial intelligence models (such as large language models LLM) play an increasingly important role in various applications. To achieve coherent, personalized and effective interactions, these models usually need to access a large amount of context information, including but not limited to:

[0066] User historical conversation records, user personal identity information (PII), user preference settings, session status and intermediate data, real-time information related to the user retrieved from external systems (databases, APIs).

[0067] In the prior art, these context information (or their summaries) are usually directly packed in the requests sent to the AI model. This approach has significant data security risks:

[0068] Transmission risk: Although channels such as TLS / SSL can be used for encryption, the data may still exist in plain text when being processed at endpoints (clients, gateways, AI model servers), increasing the risk of data leakage when intermediate nodes are attacked.

[0069] Processing risk: AI models (especially third-party provided closed-source models) will come into contact with the complete context data when processing requests, and their internal data processing and storage policies may not be controlled, presenting risks of data abuse or accidental leakage.

[0070] Storage risk: If the context information is stored improperly (e.g., logging, caching), it may lead to the persistence of sensitive data in insecure locations.

[0071] Compliance risk: It is difficult to meet the requirements of data protection regulations such as GDPR and CCPA for data minimization, purpose limitation, and user consent by directly transmitting and processing context information containing PII.

[0072] Coarse access control: It is difficult to perform fine-grained access control on context information, and often the entire context block is exposed to multiple components in the processing flow.

[0073] Therefore, there is an urgent need for a new technical solution that can minimize the exposure of sensitive context data within the system (especially during transmission and submission to the AI model) while ensuring the AI interaction effect, thereby improving the data security and compliance of AI applications.

[0074] The present invention relates to the fields of artificial intelligence (AI), data security, and computer network communication, and particularly relates to a system, method, and communication protocol for securely managing and transmitting context information during the interaction of an AI system (especially conversational AI, large language model applications) to prevent sensitive data leakage.

[0075] The present invention aims to solve the security risk problems in the process of AI interaction context data transmission and processing in the prior art, and provides a system and method that can effectively protect sensitive information, reduce the risk of data leakage, and meet compliance requirements. To solve the above problems, the present invention proposes an AI interaction data protection system and method based on the Secure Context Protocol (SCP, where SCP herein is the concept of MCP with enhanced security). Its core idea is: introduce a trusted and independent Secure Context Service (SCS), and define a new context protocol (SCP). When transmitting context, this protocol uses Secure References / Tokens to replace the original sensitive data fragments, and the SCS is responsible for the secure storage, retrieval, on-demand de-sensitization / filtering, and access control of sensitive data.

[0076] Please refer to Figure 1 , which shows a flowchart of an AI interaction data protection method provided by an embodiment of the present application. This method may include the following steps:

[0077] Step 1: The client application sends a user request to the application gateway, carrying a session identifier.

[0078] The client application receives user input, such as text, voice, or other forms of interaction requests. The client application encapsulates the user input into a request message and attaches a session identifier (Session ID), which is used to uniquely identify the current interaction session. The request message is sent to the application gateway through the network, usually using HTTPS or other secure communication protocols to ensure the confidentiality and integrity of data during transmission. For example, the client application can be a mobile application, a web application, or an interaction interface on a smart device.

[0079] Step 2: After receiving the request, the gateway queries the policy engine for the context scope and security processing policy required for this interaction according to the request type and the target AI model.

[0080] The application gateway receives requests sent by the client application and parses the user input and session identifier in the request. The gateway determines the scope of context information to be queried based on the type of the request (such as query, command, conversation, etc.) and the target AI model (such as a specific conversational AI model or a large language model). The gateway constructs a query request containing the session identifier, request type, and the identifier of the target AI model, and sends this query request to the policy engine. The policy engine returns the scope of context data required for this interaction and the security processing policy according to the preset policy rules, such as which data needs to be desensitized, which data needs to generate references / tokens, etc.

[0081] Step 3: The gateway requests the required context data from the security context service using the session identifier and passes the policy instructions.

[0082] The application gateway constructs a request message according to the scope of context data and security processing policy returned by the policy engine. This request message contains the session identifier and the policy instructions. The gateway sends this request message to the security context service (SCS) to request the context data related to the session identifier. The request message is sent through a secure communication channel to ensure data security. After receiving the request message, the SCS parses the received request and extracts the session identifier and the policy instructions.

[0083] Step 4: After verifying the gateway's permissions, the SCS retrieves the complete context data and processes it according to the policy instructions.

[0084] The security context service (SCS) verifies the identity of the gateway in the received request and confirms that the gateway has the permission to request the context data. After successful verification, the SCS retrieves the complete context data related to this session from the context data it stores according to the session identifier, including the user's historical conversation records, user personal identity information (PII), user preference settings, session status and intermediate data, and real-time information related to the user retrieved from external systems. The SCS classifies and processes the retrieved context data according to the policy instructions: for non-sensitive data that allows direct transmission, it remains unchanged; for sensitive data that needs to be protected, such as PII, sensitive conversations, etc., the original data is not returned, but one or more security references / tokens are generated and these references / tokens are placed in the response context field; for data that the policy requires to be completely filtered, it is directly removed; for data that needs to be desensitized, such as masking part of the number, the desensitized data is returned. The processed "secure context" data block is returned to the gateway.

[0085] Step 5: The gateway assembles the user's current input and the secure context data block obtained from the SCS into a final request according to the SCP protocol format and sends it to the AI model.

[0086] The application gateway receives the "security context" data block returned by the SCS, which contains references / tokens and non-sensitive / desensitized data. The gateway integrates the user's current input and the "security context" data block in the format specified by the SCP protocol to form a complete request message. The context field of this request message structurally contains non-sensitive data, desensitized data, and references / tokens pointing to sensitive data in the SCS. The gateway sends the integrated request message to the AI model via a secure communication channel for processing by the AI model. For example, the request message can adopt protocol formats such as JSON-RPC 2.0, gRPC, or HTTP RESTful API.

[0087] Step 6: After receiving the request, the AI model processes it based on the received information.

[0088] The AI model receives the request message sent by the gateway and parses the user input and the "security context" data block therein. The AI model processes based on the parsed information and generates a corresponding response. Since the context data in the request only contains non-sensitive data, desensitized data, and references / tokens that cannot be directly parsed, the AI model cannot access the original sensitive information, thus ensuring data security. The processing process of the AI model can include natural language understanding, dialogue management, knowledge retrieval, etc., depending on the design and function of the AI model.

[0089] Step 7: The AI model returns the processing result. The gateway receives the response and updates the context of the session as needed; the gateway interacts with the SCS again to request an update of the context; after verifying the permissions, the SCS updates the stored complete context.

[0090] After the AI model completes processing, it returns the processing result as a response to the gateway. The gateway receives the response from the AI model and determines whether to update the context of the session based on the response content, such as adding the new user input and the AI reply to the conversation history. If an update is needed, the gateway constructs a request message containing the update content, which includes the session identifier and the context data to be updated. The gateway sends the constructed update request message to the SCS via a secure communication channel again. The SCS receives the update request from the gateway, verifies the identity of the gateway in the received request, and confirms that the gateway has the permission to update the context data. After successful verification, the SCS updates the stored complete context data related to the session identifier according to the session identifier and the context data in the update request.

[0091] Step 8: The gateway returns the final response of the AI model to the client application, completing the entire interaction process.

[0092] The application gateway encapsulates the processing result returned by the AI model into a response message and sends this response message back to the client application via the network. The client application receives the response message and presents it to the user, completing the entire interaction process. The response message usually adopts the same protocol format as the request, such as JSON, XML, etc., to ensure that the client application can correctly parse and process the response content.

[0093] In summary, as Figure 2 shown, the schematic diagram of the interaction process provided by the embodiments of this application is as follows (taking one interaction as an example):

[0094] 1. Request initiation: The client application sends a user request (for example, new user input) to the application gateway and carries a session identifier (SessionID).

[0095] 2. Context requirement analysis: The gateway receives the request and queries the policy engine for the context scope and corresponding security processing policies required for this interaction based on the request type and the target AI model (for example, the need for the last 5 rounds of conversation history, the need for the user nickname but the need to mask the user's real name).

[0096] 3. Secure context acquisition: The gateway uses the session ID to request the required context data from the Secure Context Service (SCS) and passes the policy instructions obtained from the policy engine.

[0097] 4. SCS processing and response:

[0098] The SCS verifies the gateway's permissions. Retrieves the complete context data based on the session ID.

[0099] Processes the context data according to the policy instructions:

[0100] For non-sensitive data that is allowed to be directly passed, keep it as it is.

[0101] For sensitive data that needs to be protected (such as PII, sensitive conversations), the SCS does not return the original data, but generates one or more security references / tokens and places these references / tokens in the context fields of the response.

[0102] For data that the policy requires to be completely filtered, directly remove it.

[0103] For data that needs to be desensitized (such as masking part of the number), return the desensitized data.

[0104] The SCS returns the processed "secure context" data block containing references / tokens and non-sensitive / desensitized data to the gateway.

[0105] Building an AI Request: The gateway assembles the user's current input with the "secure context" data block obtained from the SCS (where the sensitive parts have been replaced by references / tokens) according to the SCP protocol format into a final request and sends it to the AI model.

[0106] 5. Features of the SCP Protocol: Its context field structurally contains non-sensitive data, de-sensitized data, and references / tokens pointing to sensitive data in the SCS.

[0107] 6. AI Model Processing: The AI model receives the request. Since the context in the request only contains non-sensitive data, de-sensitized data, and references / tokens that cannot be directly parsed, the AI model itself cannot access the original sensitive information. It processes based on the received information.

[0108] 7. Response and Context Update: The AI model returns a response. After receiving the response, the gateway may need to update the context of the session (for example, adding the new user input and the AI's reply to the conversation history). The gateway interacts with the SCS again to request an update of the context. After verifying the permissions, the SCS securely updates the stored complete context.

[0109] 8. Return to the Client: The gateway returns the final response of the AI to the client application.

[0110] Please refer to Figure 3 , which shows the architecture diagram of the AI interaction data protection system provided by the embodiments of the present application. The system may include:

[0111] The system mainly includes the following components:

[0112] Client Application: The front-end interface for users to interact with the AI system.

[0113] Application Gateway / Orchestrator: Receives client requests, is responsible for interacting with the secure context service and the AI model, and assembles and parses messages according to the SCP protocol.

[0114] As Figure 4 shown, it gives an example diagram of the context data structure in the SCP protocol. Specifically, the Secure Context Service (SCS):

[0115] Core Trusted Component: Responsible for securely storing, managing, and retrieving the user's complete context data (conversation history, user profile, session status, etc.).

[0116] Data Storage: Stores context data using encryption and implements strict access control.

[0117] Reference / Token Generation and Resolution: Capable of generating unique and secure reference identifiers or temporary tokens for sensitive data fragments in the context (such as PII, specific historical record segments). Can resolve back to the original data (or its de-identified / filtered version) based on the reference / token under authorization conditions.

[0118] Policy Enforcement: Filter, de-identify, or provide only the necessary non-sensitive parts of the context data to be provided according to the instructions of the policy engine.

[0119] Lifecycle Management: Manage the storage period and secure deletion of context data.

[0120] Policy Engine:

[0121] Define data access and processing policies (e.g., which roles / services can access which types of context data, what kind of de-identification processing is required during access, which data is prohibited from being sent to specific AI models).

[0122] Provide decision support to the gateway / orchestrator and SCS.

[0123] AI Model: Perform core AI inference tasks. Can be an on-premises model or a third-party model.

[0124] Specifically, the system may include:

[0125] A client application for sending user requests to the application gateway and carrying a session identifier;

[0126] A gateway that, after receiving a request, queries the policy engine for the required context scope and security processing policy for this interaction based on the request type and the target AI model; uses the session identifier to request the required context data from the security context service and passes the policy instructions; after the SCS verifies the gateway's permissions, retrieves the complete context data and processes it according to the policy instructions; assembles the user's current input and the security context data block obtained from the SCS into a final request in accordance with the SCP protocol format and sends it to the AI model; the gateway receives the response from the AI model module and updates the session context as needed, and interacts with the SCS again to request an updated context; after the SCS verifies the permissions, updates the stored complete context; and returns the final response of the AI model to the client application to complete the entire interaction process;

[0127] An AI model module that, after receiving a request, processes it based on the received information and returns a processing result.

[0128] Reference / Token Mechanism: UUID, cryptographic hash, or time-bound tokens based on JWT can be used as secure references. The SCS maintains a mapping of references / tokens to actual data internally. For example, JWT tokens contain metadata (validity period, access scope, digital signature).

[0129] SCS Implementation: It can be implemented based on a secure database (such as an encrypted NoSQL or relational database) and cache. A strong authentication and authorization mechanism (such as OAuth2, mTLS) is required.

[0130] Policy Engine Implementation: OPA (Open Policy Agent) or a custom rule engine can be used.

[0131] Protocol Carrier: The context structure defined by SCP can be carried over multiple protocols, such as JSON-RPC 2.0, gRPC (using Protobuf to define message structures), HTTP RESTful API, etc. The core lies in the construction method of its data content (using references / tokens).

[0132] Performance Considerations: The performance of SCS is crucial. The efficiency of data retrieval, token generation / parsing, and policy execution needs to be optimized. A caching mechanism can be used to reduce latency.

[0133] Context Compression / Summarization: This solution can be combined with context compression or summarization techniques. When SCS returns the "secure context", it can first compress / summarize the non-sensitive parts or historical records, and then perform reference / token replacement. Then the gateway puts the result part (or its subset) into the context field of the SCP request sent to the AI model.

[0134] In one embodiment, an electronic device is provided. The electronic device can be a computer, and its internal structure diagram can be as Figure 5 shown. The electronic device includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the device is used to provide computing and control capabilities. The memory of the device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to protect data based on AI interaction data of the secure context protocol. The network interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements a method for protecting AI interaction data based on the secure context protocol.

[0135] Those skilled in the art can understand that as Figure 5The structure shown is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0136] In an embodiment of the present application, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above-mentioned AI interaction data protection method based on the security context protocol are implemented.

[0137] In an embodiment of the present application, a computer program product is provided, including a computer program / instructions. When the computer program is executed by a processor, the steps of the above-mentioned AI interaction data protection method based on the security context protocol are implemented.

[0138] The computer-readable storage medium and the computer program product provided in this embodiment have the same implementation principles and technical effects as the above method embodiment, and will not be elaborated here.

[0139] Those of ordinary skill in the art can understand that all or part of the processes in the above-mentioned method embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above-mentioned method embodiments. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in M forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (SyMchliMk), DRAM (SLDRAM), memory bus (RaMbus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0140] The technical features of the above-mentioned embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above-mentioned embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0141] The embodiments described above merely represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the patent application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the appended claims.

Claims

1. An AI interaction data protection method based on a security context protocol, characterized in that The method includes: The client application sends a user request to the application gateway, carrying a session identifier; After receiving the request, the gateway queries the policy engine for the context scope and security processing policy required for this interaction according to the request type and the target AI model; The gateway requests the required context data from the security context service using the session identifier and passes the policy instructions; After verifying the gateway's permissions, the SCS retrieves the complete context data and processes it according to the policy instructions; The gateway assembles the user's current input and the security context data block obtained from the SCS into a final request in accordance with the SCP protocol format and sends it to the AI model; After receiving the request, the AI model processes it based on the received information; The AI model returns the processing result. The gateway receives the response and updates the context of the session as needed; the gateway interacts with the SCS again to request an update of the context; after verifying the permissions, the SCS updates the stored complete context; The gateway returns the final response of the AI model to the client application, completing the entire interaction process.

2. The AI interaction data protection method according to claim 1, wherein After receiving the request, the gateway queries the policy engine for the context scope and security processing policy required for this interaction, including: The gateway parses the user request to extract the request type, target AI model information, and session identifier; Based on the extracted information, the gateway constructs a query request that includes the session identifier, request type, and target AI model identifier; The gateway sends the query request to the policy engine to request the context data scope and security processing policy related to this interaction; Based on the query request, the policy engine returns the context data scope required for this interaction, including but not limited to the user's historical conversation records, user personal identity information, user preference settings, session status and intermediate data, and real-time information related to the user retrieved from external systems, as well as the corresponding security processing policies.

3. The AI interaction data protection method according to claim 1, wherein, The gateway requests the required context data from the security context service (SCS) using the session identifier and passes the policy instructions, including: Based on the context data scope and security processing policy returned by the policy engine, the gateway constructs a request message that includes the session identifier, the required context data scope, and the security processing policy instructions; The gateway sends the constructed request message to the SCS through a secure communication channel to request the context data related to the session identifier; The SCS receives the request message sent by the gateway and parses the session identifier, context data scope, and security processing policy instructions therein.

4. The AI interaction data protection method according to claim 1, wherein, After verifying the gateway's permissions, the SCS retrieves the complete context data and processes it according to the policy instructions, including: The SCS verifies the identity of the gateway in the received request message to confirm that the gateway has the permission to request context data; After successful verification, the SCS retrieves the complete context data related to the session from the context data it stores according to the session identifier, including the user's historical conversation records, user personal identity information, user preference settings, session status and intermediate data, and real-time information related to the user retrieved from external systems; The SCS classifies the retrieved context data according to the policy instructions. For non-sensitive data that allows direct transmission, it remains unchanged. For sensitive data that needs to be protected, instead of returning the original data, one or more security references / tokens are generated and these references / tokens are placed in the context field of the response. For data that the policy requires to be completely filtered, it is directly removed. For data that needs to be de-sensitized, the de-sensitized data is returned.

5. The AI interaction data protection method according to claim 1, wherein Based on the SCP protocol format, the gateway assembles the user's current input and the security context data block obtained from the SCS into a final request and sends it to the AI model, including: The gateway receives the "security context" data block returned by the SCS, which contains references / tokens and non-sensitive / de-sensitized data; The gateway integrates the user's current input and the security context data block according to the format specified by the SCP protocol to form a complete request message. The context field of this request message structurally contains non-sensitive data, de-sensitized data, and references / tokens pointing to sensitive data in the SCS; The gateway sends the integrated request message to the AI model through a secure communication channel for the AI model to process.

6. The AI interaction data protection method according to claim 1, wherein The AI model returns the processing result. The gateway receives the response and updates the context of the session as needed; The gateway interacts with the SCS again to request an update of the context; After verifying the permissions, the SCS updates the stored complete context, including: After the AI model finishes processing, it returns the processing result as a response to the gateway; The gateway receives the response from the AI model and determines whether it is necessary to update the context of the session based on the response content, such as adding the new user input and the AI reply to the conversation history; If an update is needed, the gateway constructs a request message containing the update content, which includes the session identifier and the context data to be updated; The gateway sends the constructed update request message to the SCS again through a secure communication channel; The SCS receives the update request from the gateway, verifies the identity of the gateway in the received request message, and confirms that the gateway has the permission to update the context data; After the verification passes, the SCS updates the stored complete context data related to the session identifier according to the session identifier and the context data in the update request.

7. An AI interaction data protection system based on a security context protocol, characterized in that, The system includes: A client application for sending a user request to the application gateway and carrying the session identifier; A gateway for, after receiving a request, querying the context scope and security processing policy required for this interaction from the policy engine according to the request type and the target AI model; requesting the required context data from the security context service using the session identifier and passing the policy instructions; after the SCS verifies the gateway's permissions, retrieving the complete context data and processing it according to the policy instructions; assembling the user's current input and the security context data block obtained from the SCS into a final request according to the SCP protocol format and sending it to the AI model; the gateway receiving the response from the AI model module and updating the context of the session as needed, interacting with the SCS again to request an update of the context; the SCS updating the stored complete context after verifying the permissions; and returning the final response of the AI model to the client application to complete the entire interaction process; The AI model module is used to process the received information based on the received request and return the processing result.

8. An electronic device, characterized in that, It includes a memory and a processor. The memory stores a computer program, and when the computer program is executed by the processor, it implements the AI interaction data protection method according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, A computer program is stored thereon, and when the computer program is executed by a processor, it implements the AI interaction data protection method according to any one of claims 1 to 6.

10. A computer program product, comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, it implements the AI interaction data protection method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Data management method and system, data service gateway and storage medium

    CN115934202A

  • Session interaction method and device, electronic equipment and storage medium

    CN118413505A

  • Management method for managing security gateway of AI large language model

    CN118713858A

  • Generative artificial intelligence security engine in item list system

    CN119940422A

  • Query response generation using structured and unstructured data for conversational ai systems and applications

    US20240176808A1

Cited By

  • Secure MCP protocol authentication method and system

    CN120896794A

  • A secure MCP protocol authentication method and system

    CN120896794B

  • Large model gateway security protection system and security protection method

    CN120951390A

  • Data desensitization method and system based on combination of MCP protocol and rule driving

    CN121118117A

  • Communication agent system and communication processing method based on model context protocol

    CN121261967A