AI data security management method and system based on model context protocol

By collecting model context information in real time to generate dynamic security policies, the problems of rigid security policies and privacy leakage in traditional AI systems are solved, adaptive encryption and fine-grained access control are achieved, and the efficiency and compliance of AI data security management are improved.

CN120223438BActive Publication Date: 2025-09-12CENTURY LONGMAI TECH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510686041.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-09-12
Estimated Expiration
2045-05-27

AI Technical Summary

Technical Problem

Traditional AI systems cannot adapt to dynamically changing model contexts, pose risks of privacy leakage, and their communication protocols do not deeply integrate security mechanisms, resulting in low efficiency.

Method used

By collecting model context information in real time, dynamic security policies are generated to achieve adaptive encryption and fine-grained access control, and combined with the MCP protocol for security aggregation and permission synchronization.

Benefits of technology

Improves data security and efficiency, reduces communication overhead, and meets data privacy regulations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223438B_ABST
    Figure CN120223438B_ABST
Patent Text Reader

Abstract

This application discloses a method and system for AI data security management based on the Model Context Protocol. This method can collect and analyze model status, environmental parameters, and user session information in real time, generating dynamic encryption policies and permission tokens. Each node uploads encrypted gradients via the MCP protocol and adds differential privacy noise. The federated learning coordinator aggregates parameters using secure multi-party computing technology to generate a global model and synchronizes model versions across all nodes via the MCP protocol. This method and system can be applied to scenarios such as intelligent customer service and medical diagnosis, significantly improving data security and compliance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of intersection of artificial intelligence and data security, and in particular to an AI data security management method and system based on a model context protocol. Background Art

[0002] With the rapid development of AI technology, data privacy protection, model security transmission and dynamic access control have become urgent issues to be addressed.

[0003] Traditional AI systems typically employ fixed encryption and access control rules, making them unable to adapt to dynamically changing model contexts, such as real-time resource status and changes in user permissions. Furthermore, centralized data storage and transmission are vulnerable to attacks, while distributed solutions like federated learning can protect privacy but lack fine-grained contextual awareness. Existing communication protocols (such as HTTP / RPC) also lack deeply integrated security mechanisms, requiring the design of additional encryption and auditing modules, resulting in inefficiencies. Summary of the Invention

[0004] Based on this, an embodiment of the present application provides an AI data security management method and system based on the model context protocol. This application realizes adaptive encryption, fine-grained access control and privacy protection by dynamically perceiving the model context (such as model version, user session, hardware resources), thereby solving the problems of rigid security policies and high risk of privacy leakage in traditional solutions.

[0005] In a first aspect, a method for AI data security management based on a model context protocol is provided, the method comprising:

[0006] Collecting model context information in real time; wherein the context information includes at least model status, environment parameters and user session information;

[0007] In response to a security management request initiated by a client, parsing the collected context information to generate a dynamic security policy; wherein the dynamic security policy at least includes the selection of an encryption algorithm and the generation of a dynamic authority token;

[0008] According to the generated dynamic security policy, perform data encryption operations and access control, and record operation logs;

[0009] Securely aggregate model parameters among distributed nodes to generate a global model, and synchronize the model version to all nodes through the MCP protocol, while notifying all nodes to update access rights.

[0010] Optionally, collect contextual information of the model in real time, including:

[0011] Continuously monitor the model's weight version and gradient changes; specifically, record the weight updates and gradient values ​​after each model training;

[0012] Get the CPU and GPU load of the current running environment in real time; specifically, regularly sample the CPU and GPU usage, temperature, and memory usage parameters;

[0013] Capture the user's permission level, geographic location, and session state; specifically, record the user's IP address, device type, login time, and the user's role and permission level in the system.

[0014] Optionally, the collected context information is parsed to generate a dynamic security policy, including:

[0015] Determine the encryption algorithm based on the model state and user session information, specifically including selecting different encryption algorithms based on the data type;

[0016] A dynamic permission token is generated by combining the user role and the model version. The dynamic permission token includes the user role, allowed operations, model version, and expiration time.

[0017] Optionally, data encryption and access control are performed based on the generated dynamic security policy, including:

[0018] Verify that the authorization token provided by the user complies with the current security policy; specifically, check whether the signature in the JWT is valid, whether the expiration time has passed, and whether the user role and allowed operations match the request;

[0019] If the verification passes, the data is encrypted according to the encryption algorithm specified in the policy. This includes calling the encryption library to perform the encryption operation and storing or transmitting the encrypted data.

[0020] All encryption, decryption, and access control operations are recorded and an operation log is generated; specifically, the operation time, user ID, operation type, data type, encryption algorithm, and operation results are recorded.

[0021] Optionally, securely aggregating model parameters among distributed nodes to generate a global model includes:

[0022] Each node uploads the local gradient through the MCP protocol and adds differential privacy noise that meets the preset noise level to the gradient value;

[0023] The SMPC protocol is used to perform collaborative calculations of encrypted gradients between multiple nodes to ensure that data is not leaked during the aggregation process;

[0024] The aggregated gradients are applied to the parameter update of the global model, and the updated model parameters are broadcast to all nodes.

[0025] Optionally, the synchronous updating of the model version to all nodes through the MCP protocol includes:

[0026] Send the updated model version information to all distributed nodes via the MCP protocol; the MCP protocol message contains the model version number, update timestamp, and hash value of the model parameters;

[0027] Send an update instruction to each node, instructing the node to regenerate a dynamic permission token that matches the new model version and update the local access control policy.

[0028] In the second aspect, an AI data security management system based on a model context protocol is provided, which includes:

[0029] A context-aware module, configured to collect context information of the model in real time; wherein the context information includes at least model status, environmental parameters, and user session information;

[0030] The MCP protocol engine is used to respond to security management requests initiated by the client, parse the collected context information and generate a dynamic security policy; wherein the dynamic security policy at least includes the selection of an encryption algorithm and the generation of a dynamic permission token;

[0031] The security control module is used to perform data encryption operations and access control according to the generated dynamic security policy, and record operation logs;

[0032] The federated learning coordinator is used to securely aggregate model parameters among distributed nodes to generate a global model, and synchronously update the model version to all nodes through the MCP protocol, while notifying all nodes to update access rights.

[0033] In a third aspect, an electronic device is provided, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the AI ​​data security management method described in any one of the first aspects is implemented.

[0034] In a fourth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the AI ​​data security management method described in any one of the first aspects is implemented.

[0035] In a fifth aspect, a computer program product is provided, on which a computer program is stored. When the computer program is executed by a processor, the AI ​​data security management method described in any one of the first aspects is implemented.

[0036] The beneficial effects of the technical solutions provided in the embodiments of the present application include at least:

[0037] (1) Improved security: Reduce the risk of data leakage through dynamic encryption and fine-grained access control;

[0038] (2) Efficiency optimization: Context-aware strategies reduce redundant encryption operations and lower communication overhead;

[0039] (3) Compliance: Meet the requirements of data privacy regulations such as GDPR and HIPAA. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] To more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for the embodiments or the description of the prior art. Obviously, the drawings described below are merely exemplary, and those skilled in the art can derive other implementation drawings based on the provided drawings without inventive effort.

[0041] Figure 1 A flowchart of the steps of the AI ​​data security management method provided in an embodiment of the present application;

[0042] Figure 2 A diagram of the system architecture provided for an embodiment of the present application;

[0043] Figure 3 A flow chart for generating dynamic security policies provided in an embodiment of the present application;

[0044] Figure 4 Schematic diagram of the federated learning security aggregation process provided in the embodiment of this application;

[0045] Figure 5 A schematic diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0046] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0047] In the description of the present invention, the terms "comprise", "have" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or apparatus comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may also include other steps or units that are not explicitly listed but are inherent to these processes, methods, products or apparatuses, or steps or units that are added based on further optimization schemes conceived by the present invention.

[0048] From the background technology, it can be seen that the existing technology has the following technical problems:

[0049] Static security policies: Traditional AI systems use fixed encryption and access control rules and cannot adapt to dynamically changing model contexts (such as real-time resource status and user permission changes).

[0050] Privacy leakage risk: Centralized data storage and transmission are vulnerable to attacks, and distributed solutions such as federated learning lack fine-grained context awareness capabilities.

[0051] Disconnect between protocols and security: Existing communication protocols (such as HTTP / RPC) do not have deeply integrated security mechanisms, requiring the design of additional encryption and audit modules, resulting in low efficiency.

[0052] This application proposes a method and system for AI data security management based on the MCP protocol. By dynamically sensing model context (such as model version, user session, and hardware resources), this method implements adaptive encryption, fine-grained access control, and privacy protection, addressing the rigidity of security policies and high privacy leakage risks inherent in traditional solutions. Specifically, this method is used to implement data privacy protection, secure model transmission, and dynamic access control during distributed AI model training and inference.

[0053] Please refer to Figure 1 , which shows a flowchart of an AI data security management method based on a model context protocol provided in an embodiment of the present application. The method may include the following steps:

[0054] S1, collects model context information in real time.

[0055] The context information includes at least model status, environment parameters and user session information.

[0056] Specifically, the built-in monitoring module provides real-time access to the model's weight updates and gradient changes. This is achieved by setting up hooks during model training to capture weight updates and gradient values ​​after each training session. This information is stored in a local database or memory for subsequent processing.

[0057] Regularly sample the CPU and GPU load of the current running environment. This can be achieved by using monitoring tools (such as psutil or nvidia-smi) to periodically obtain parameters such as CPU usage, GPU usage, temperature, and memory usage. These parameters are recorded in a log file and updated in real time.

[0058] Capture the user's permission level, geographic location, and session state when they log in. This includes recording the user's IP address, device type, login time, and the user's role and permission level. This information is stored in the user session management module for access control when needed.

[0059] S2, in response to the security management request initiated by the client, parse the collected context information to generate a dynamic security policy.

[0060] The dynamic security policy at least includes the selection of encryption algorithms and the generation of dynamic permission tokens.

[0061] Specifically, it receives a security management request from a client, which includes the user ID, the requested operation type (such as model inference, parameter update, etc.), and the target model version. It first verifies the legitimacy of the request, including user identity verification and request format verification.

[0062] Based on the collected context information, the model state, environment parameters, and user session information are parsed. Specific implementation methods include reading the model weight version and gradient information from the local database or memory, obtaining environment parameters from log files, and obtaining user permission level and session status from the user session management module.

[0063] Generate dynamic security policies based on parsed context information. Specific implementation methods include:

[0064] Encryption algorithm selection: Select different encryption algorithms based on the data type (such as medical data, financial data, etc.). For example, medical data uses the SM4 algorithm, while other data uses the ChaCha20-Poly1305 algorithm.

[0065] Dynamic permission token generation: Generate a dynamic permission token (such as JWT) by combining the user role and model version. The generated JWT token contains the user role (such as "researcher"), allowed operations (such as "model_inference"), model version (such as "v2.3"), and expiration timestamp.

[0066] S3, based on the generated dynamic security policy, performs encryption operations and access control on the data and records operation logs.

[0067] Specifically, it verifies whether the authorization token provided by the user complies with the current security policy. This includes checking whether the signature in the JWT is valid, whether the expiration time has passed, and whether the user role and allowed operations match the request.

[0068] If the verification passes, the data is encrypted using the encryption algorithm specified in the policy. This is done by calling an encryption library (such as pycryptodome or cryptography) to perform the encryption operation and then storing or transmitting the encrypted data.

[0069] Enforce access control based on dynamic security policies, ensuring only authorized users can access specific versions of models.

[0070] Record all encryption, decryption, and access control operations and generate operation logs. Specific implementation methods include recording the operation time, user ID, operation type, data type, encryption algorithm, and operation results.

[0071] S4 securely aggregates model parameters among distributed nodes to generate a global model, and synchronously updates the model version to all nodes through the MCP protocol, while notifying all nodes to update access rights.

[0072] Specifically, each node uploads its local gradient through the MCP protocol and adds differential privacy noise. This is achieved by adding differential privacy noise that meets a preset noise level (e.g., ε = 0.1) to the gradient value to ensure data privacy during transmission.

[0073] The Federated Learning Coordinator uses Secure Multi-Party Computation (SMPC) to securely aggregate encrypted gradients. This is achieved by using the SMPC protocol to collaboratively compute encrypted gradients across multiple nodes, ensuring data is not leaked during the aggregation process.

[0074] The global model is updated based on the aggregated results. This is achieved by applying the aggregated gradients to update the parameters of the global model and broadcasting the updated model parameters to all nodes.

[0075] The updated model version information is sent to all distributed nodes via the MCP protocol. The specific implementation method includes including the model version number, update timestamp, and hash value of the model parameters in the MCP protocol message.

[0076] Notify all nodes to update their local access permissions based on the new model version. This is achieved by sending an update instruction to each node, instructing it to regenerate a dynamic permission token that matches the new model version and update its local access control policy.

[0077] Please refer to Figure 2 , which shows an architecture diagram of an AI data security management system based on a model context protocol provided by an embodiment of the present application. The system may include:

[0078] The system includes the following core modules:

[0079] MCP protocol engine: responsible for context synchronization, dynamic generation of security policies and communication management.

[0080] Context-aware module: collects model status (weight version, gradient), environment parameters (CPU / GPU load), and user sessions (permissions, geographic location) in real time.

[0081] Security control module: integrates dynamic encryption, access control and audit functions.

[0082] Federated Learning Coordinator: securely aggregates model parameters across distributed nodes (supporting differential privacy and secure multi-party computation).

[0083] Specifically, the context awareness module is used to collect context information of the model in real time; wherein the context information includes at least model status, environmental parameters and user session information;

[0084] The MCP protocol engine is used to respond to security management requests initiated by the client, parse the collected context information and generate a dynamic security policy; wherein the dynamic security policy at least includes the selection of an encryption algorithm and the generation of a dynamic permission token;

[0085] The security control module is used to perform data encryption operations and access control according to the generated dynamic security policy, and record operation logs;

[0086] The federated learning coordinator is used to securely aggregate model parameters between distributed nodes to generate a global model, and synchronize the model version to all nodes through the MCP protocol, while notifying all nodes to update their access rights. Figure 3 A technical flow chart is given, in which:

[0087] The client initiates a request with context information (such as user ID and model version).

[0088] The MCP protocol engine generates security policies (encryption algorithms, access rights) based on the context.

[0089] The security control module verifies permissions and performs encryption operations.

[0090] The federated learning coordinator aggregates the encrypted parameters and updates the global model.

[0091] The audit module records all operation logs and supports post-event tracing.

[0092] Specifically, the client sends a request to the MCP protocol engine, along with the model's contextual information. This contextual information includes at least the model state, environment parameters, and user session information. For example, a client might request access to a specific version of a model for inference operations, providing the user's authentication information and the model version number.

[0093] After receiving the request, the MCP protocol engine first parses the accompanying context information to determine the model version and user role. This step is the basis for dynamic security policy generation, ensuring that subsequent security policies can be adjusted based on real-time context information.

[0094] Based on the parsed context, the MCP protocol engine generates a dynamic security policy. This includes selecting an appropriate encryption algorithm and generating a dynamic permission token (such as a JWT). For example, if the context indicates that the data type is medical data, the MCP protocol engine might select the SM4 encryption algorithm. Furthermore, based on the user's role and the requested operation type, the MCP protocol engine generates a JWT token containing the role, permitted operations, model version, and expiration time.

[0095] The generated dynamic policy is sent to the security control module. The security control module is responsible for verifying the validity of the authorization token and performing cryptographic operations based on the dynamic policy. This includes checking whether the signature of the JWT token is valid, whether the user role is authorized to perform the requested operation, and whether the model version matches.

[0096] The security control module returns the verification result to the MCP protocol engine. If the verification succeeds, the request will be allowed to continue; if the verification fails, the request will be rejected, and the security control module will notify the MCP protocol engine of the reason for the rejection.

[0097] Based on the verification results of the security control module, the MCP protocol engine sends a response to the client. If the request is allowed, the client can continue model inference or other operations; if the request is denied, the client will receive an error message indicating that the request failed security verification.

[0098] From the above, it can be seen that the innovative features of this application include:

[0099] Dynamic security policy generation: Dynamically adjust encryption and access rules based on real-time context (such as model version and network latency).

[0100] Lightweight federated secure aggregation: Secure multi-party computation (SMPC) is embedded in the MCP protocol to achieve efficient privacy protection.

[0101] Fine-grained context binding: Bind user permissions to model versions and hardware environments to prevent unauthorized operations.

[0102] Two other specific embodiments are given below:

[0103] Example 1: Security reasoning of an intelligent customer service system.

[0104] Scenario: Users query medical information through voice assistants.

[0105] Implementation steps:

[0106] The context-aware module captures user identity (anonymous ID) and query content sensitivity (medical data).

[0107] The MCP protocol engine triggers dynamic encryption (SM4) and limits the model version to "Medical Specific v1.2".

[0108] The security control module verifies the JWT token and only allows calls to the specified model version.

[0109] Before the inference results are returned, the audit module records the operation logs and desensitizes sensitive fields.

[0110] Example 2: Distributed model training.

[0111] Scenario: Jointly train a tumor detection model across hospitals.

[0112] Implementation steps:

[0113] Each hospital node uploads the local gradient through the MCP protocol, and the protocol automatically adds differential privacy noise (ε=0.1).

[0114] The federated learning coordinator uses SMPC to securely aggregate gradients and generate a global model.

[0115] The MCP protocol synchronously updates the model version to v3.0 and notifies all nodes to update their access rights.

[0116] like Figure 4 This paper presents a schematic diagram of the secure aggregation process for federated learning. Each node uploads encrypted gradients and adds differentially private noise via the MCP protocol. The federated learning coordinator aggregates parameters using secure multi-party computation (SMPC) to generate a global model. The updated model version is synchronized to all nodes via the MCP protocol.

[0117] Specifically, after completing model training locally, each hospital node (e.g., hospital node A, hospital node B, and hospital node C) generates gradient information. This gradient information is first encrypted using the MCP protocol to ensure data security and privacy during transmission.

[0118] Before uploading encrypted gradients, each node adds differential privacy noise. This step further enhances privacy protection by introducing randomness to prevent the leakage of sensitive information. For example, when hospital node B uploads gradients, it adds noise based on a preset privacy protection parameter (e.g., ε = 0.1).

[0119] The encrypted and noisy gradient information is sent to the federated learning coordinator, which is responsible for collecting gradient information from various nodes and preparing it for secure aggregation.

[0120] Before aggregation, the federated learning coordinator verifies the digital signature of the received gradients to ensure the integrity of the data and the authenticity of the source. This step helps prevent malicious nodes from sending forged or tampered data.

[0121] The federated learning coordinator securely aggregates the collected encrypted gradients using secure multi-party computation (SMPC). SMPC allows multiple nodes to jointly compute the result of a function without disclosing their own data. In this case, the gradients are aggregated to generate a global model. This process ensures data privacy and security.

[0122] The aggregated gradients are used to update the parameters of the global model. The federated learning coordinator encapsulates the updated model parameters into a new global model version (e.g., v3.0).

[0123] The updated global model version is synchronized to all nodes participating in federated learning through the MCP protocol. This step ensures that all nodes can obtain the latest model version in a timely manner, thereby ensuring the consistency and accuracy of the model.

[0124] As new model versions are released, each node needs to update its local access permissions to ensure that only authorized users and systems can access and use the new model version. This step is implemented through the MCP protocol, ensuring the timeliness and effectiveness of access control.

[0125] In one embodiment, an electronic device is provided. The electronic device may be a computer, and its internal structure diagram may be as follows: Figure 5 As shown. The electronic device includes a processor, a memory and a network interface connected via a system bus. The processor of the device is used to provide computing and control capabilities. The memory of the device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used for AI data security management data based on the model context protocol. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements an AI data security management method based on the model context protocol.

[0126] Those skilled in the art will understand that Figure 5 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0127] In one embodiment of the present application, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above-mentioned AI data security management method based on the model context protocol are implemented.

[0128] In one embodiment of the present application, a computer program product is provided, including a computer program / instructions, which implements the steps of the above-mentioned AI data security management method based on the model context protocol when the computer program is executed by a processor.

[0129] The computer-readable storage medium and computer program product provided in this embodiment have similar implementation principles and technical effects to those of the above-mentioned method embodiments, and are not described in detail here.

[0130] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in M ​​forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (SyMchliMk) DRAM (SLDRAM), memory bus (RaMbus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0131] The technical features of the above-mentioned embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above-mentioned embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0132] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the patent application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present patent application shall be determined by the appended claims.

Claims

1. A method for AI data security management based on model context protocol, characterized in that: The method comprises: Collecting model context information in real time; wherein the context information includes at least model status, environment parameters and user session information; In response to a security management request initiated by a client, parsing the collected context information to generate a dynamic security policy; wherein the dynamic security policy at least includes the selection of an encryption algorithm and the generation of a dynamic authority token; According to the generated dynamic security policy, perform data encryption operations and access control, and record operation logs; Securely aggregate model parameters across distributed nodes to generate a global model, synchronize the model version to all nodes through the MCP protocol, and notify all nodes of the updated access rights. Collect model context information in real time, including: Continuously monitor the model's weight version and gradient changes; specifically, record the weight updates and gradient values ​​after each model training; Get the CPU and GPU load of the current running environment in real time; specifically, regularly sample the CPU and GPU usage, temperature, and memory usage parameters; Capture the user's permission level, geographic location, and session state; specifically, log the user's IP address, device type, login time, and the user's role and permission level within the system; Analyze the collected context information to generate dynamic security policies, including: Determine the encryption algorithm based on the model state and user session information, specifically including selecting different encryption algorithms based on the data type; A dynamic permission token is generated by combining the user role and the model version. The dynamic permission token includes the user role, allowed operations, model version, and expiration time.

2. The AI ​​data security management method according to claim 1, characterized in that: According to the generated dynamic security policy, data encryption operations and access control are performed, including: Verify that the authorization token provided by the user complies with the current security policy; specifically, check whether the signature in the JWT is valid, whether the expiration time has passed, and whether the user role and allowed operations match the request; If the verification passes, the data is encrypted according to the encryption algorithm specified in the policy. This includes calling the encryption library to perform the encryption operation and storing or transmitting the encrypted data. All encryption, decryption, and access control operations are recorded and an operation log is generated; specifically, the operation time, user ID, operation type, data type, encryption algorithm, and operation results are recorded.

3. The AI ​​data security management method according to claim 1, characterized in that: The secure aggregation of model parameters among distributed nodes to generate a global model includes: Each node uploads the local gradient through the MCP protocol and adds differential privacy noise that meets the preset noise level to the gradient value; The SMPC protocol is used to perform collaborative calculations of encrypted gradients between multiple nodes to ensure that data is not leaked during the aggregation process; The aggregated gradients are applied to the parameter update of the global model, and the updated model parameters are broadcast to all nodes.

4. The AI ​​data security management method according to claim 1, characterized in that: The MCP protocol is used to synchronize the model version to all nodes, including: Send the updated model version information to all distributed nodes via the MCP protocol; the MCP protocol message contains the model version number, update timestamp, and hash value of the model parameters; Send an update instruction to each node, instructing the node to regenerate a dynamic permission token that matches the new model version and update the local access control policy.

5. An AI data security management system based on model context protocol, characterized in that: The system comprises: A context-aware module, configured to collect context information of the model in real time; wherein the context information includes at least model status, environmental parameters, and user session information; The MCP protocol engine is used to respond to security management requests initiated by the client, parse the collected context information and generate a dynamic security policy; wherein the dynamic security policy at least includes the selection of an encryption algorithm and the generation of a dynamic permission token; The security control module is used to perform data encryption operations and access control according to the generated dynamic security policy, and record operation logs; Federated learning coordinator, which is used to securely aggregate model parameters across distributed nodes to generate a global model, synchronize model version updates to all nodes through the MCP protocol, and notify all nodes of updated access rights; Collect model context information in real time, including: Continuously monitor the model's weight version and gradient changes; specifically, record the weight updates and gradient values ​​after each model training; Get the CPU and GPU load of the current running environment in real time; specifically, regularly sample the CPU and GPU usage, temperature, and memory usage parameters; Capture the user's permission level, geographic location, and session state; specifically, log the user's IP address, device type, login time, and the user's role and permission level within the system; Analyze the collected context information to generate dynamic security policies, including: Determine the encryption algorithm based on the model state and user session information, specifically including selecting different encryption algorithms based on the data type; A dynamic permission token is generated by combining the user role and the model version. The dynamic permission token includes the user role, allowed operations, model version, and expiration time.

6. An electronic device, characterized in that: It includes a memory and a processor, the memory stores a computer program, and when the computer program is executed by the processor, it implements the AI ​​data security management method according to any one of claims 1 to 4.

7. A computer-readable storage medium, characterized in that A computer program is stored thereon, and when the computer program is executed by a processor, the AI ​​data security management method as described in any one of claims 1 to 4 is implemented.

8. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instruction is executed by a processor, the AI ​​data security management method described in any one of claims 1 to 4 is implemented.

Citation Information

Patent Citations

  • Security management and retrieval method based on Internet of Vehicles data

    CN119150349A