Method and system for enhancing security and improving performance associated with artificial intelligence operations

By introducing hardware security module (HSM) uninstall password operation in AI/ML systems, the problems of degradation and security are solved, and efficient AI/ML operation and enhanced security are achieved.

CN120263398APending Publication Date: 2025-07-04MARVELL ASIA PTE LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510017633.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-06-17
Filing Date
2025-01-06
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

In the prior art, when performing password operations using a processor not specifically designed for AI/ML operations, performance degradation occurs, and when performing AI/ML and password operations using the same processor, the system security is fragile.

Method used

Using the hardware security module (HSM) to uninstall password operations of AI-related operations, HSM is specially designed to perform password operations efficiently and send the results to a processor specially designed for AI/ML operations to achieve the separation of password operations and AI/ML operations.

Benefits of technology

Improves the performance and security of the system, and operates to the HSM through uninstalling passwords, reduces the burden on the AI processor, improves resource utilization, and reduces security vulnerabilities through environmental isolation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263398A_ABST
    Figure CN120263398A_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to methods and systems for enhancing security and improving performance associated with artificial intelligence operations. A system includes a hardware security module (HSM) configured to receive an artificial intelligence (AI) request sent by an application. The AI request is a request to perform one or more AI-related operations. The HSM is configured to perform one or more cryptographic operations associated with the one or more AI-related operations. The HSM is configured to send results of the one or more cryptographic operations associated with the one or more AI-related operations to the AI processor. The system also includes an AI processor configured to receive results of the one or more cryptographic operations associated with the one or more AI-related operations from the HSM. The AI processor is configured to perform one or more AI-related operations.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Related Applications

[0002] This application claims the benefit and priority of U.S. Provisional Patent Application No. 63 / 617,509, filed on January 4, 2024, and U.S. Non - Provisional Patent Application No. 18 / 745,384, filed on June 17, 2024, the entire contents of which are incorporated herein by reference. BACKGROUND OF THE INVENTION

[0003] In recent years, artificial intelligence (AI) and machine learning (ML) have become prevalent and are applied in a wide range of fields, including autonomous vehicles, ChatGPT, etc. Considering the high data density and complex operations (such as mathematical operations) in AI / ML - related applications, hardware architectures (such as accelerators) have been specifically designed to efficiently execute ML / AI - related operations. In some traditional systems, processors that are not specifically designed to execute one or more AI operations may be used.

[0004] AI / ML - related operations may involve sensitive data. Therefore, before an application sends data to an accelerator for processing, one or more cryptographic operations may be performed on the data to protect the sensitive data. An accelerator that may have been specifically designed to efficiently execute AI / ML - related operations may now be tasked with first performing cryptographic operations that are not designed for efficient execution before it can perform one or more AI / ML - related operations on the data, resulting in performance degradation.

[0005] In traditional situations where processors that are not specifically designed to execute AI / ML - related operations are used to perform AI / ML - related operations, they may similarly be tasked with performing one or more cryptographic operations. Since traditional processors are not specifically designed to efficiently execute cryptographic operations, performing cryptographic operations before they execute AI / ML operations results in performance degradation.

[0006] Furthermore, using the same accelerator or the same processor to perform not only AI / ML operations but also one or more cryptographic operations makes the system more vulnerable to security attacks. For example, since the same accelerator or the same processor is used to perform cryptographic operations and AI / ML operations, the system operates in the same environment (e.g., there is no isolation between key management and processing environments), thereby increasing the vulnerability of system security.

[0007] The above examples of the related art and their related limitations are intended to be illustrative rather than exclusive. After reading the specification and studying the drawings, other limitations of the related art will become apparent. SUMMARY OF THE INVENTION

[0008] In one or more embodiments, a system is disclosed that includes: a Hardware Security Module (HSM); an interface configured to receive an Artificial Intelligence (AI) request from an application, where the AI request is a request to perform one or more AI-related operations; and an AI processor, where the interface is configured to offload one or more cryptographic operations associated with the one or more AI-related operations to the HSM, and where the HSM is configured to perform the one or more cryptographic operations associated with the one or more AI-related operations, and where the HSM is configured to send the results of the one or more cryptographic operations associated with the one or more AI-related operations to the AI processor, and where the AI processor is configured to receive the results of the one or more cryptographic operations associated with the one or more AI-related operations from the HSM, and where the AI processor is configured to perform the one or more AI-related operations.

[0009] In one or more embodiments, a method is disclosed that includes: receiving an Artificial Intelligence (AI) request from an application, where the AI request is a request to perform one or more AI-related operations; offloading one or more cryptographic operations associated with the one or more AI-related operations to a Hardware Security Module (HSM); performing, by the HSM, the one or more cryptographic operations associated with the one or more AI-related operations; sending the results of the one or more cryptographic operations associated with the one or more AI-related operations to the AI processor; and performing, by the AI processor, the one or more AI-related operations.

[0010] In one or more embodiments, a system is disclosed that includes: a Hardware Security Module (HSM) configured to receive an Artificial Intelligence (AI) request sent by an application, where the AI request is a request to perform one or more AI-related operations, where the HSM is configured to perform the one or more cryptographic operations associated with the one or more AI-related operations, and where the HSM is configured to send the results of the one or more cryptographic operations associated with the one or more AI-related operations to the AI processor; and an AI processor configured to receive the results of the one or more cryptographic operations associated with the one or more AI-related operations from the HSM, and where the AI processor is configured to perform the one or more AI-related operations.

[0011] In one or more embodiments, a system is disclosed that includes: components for receiving artificial intelligence (AI) requests from an application, where the AI requests are requests to perform one or more AI-related operations; components for offloading one or more cryptographic operations associated with the one or more AI-related operations to a hardware security module (HSM); components for the HSM to perform the one or more cryptographic operations associated with the one or more AI-related operations; components for sending the results of the one or more cryptographic operations associated with the one or more AI-related operations to an AI processor; and components for the AI processor to perform the one or more AI-related operations. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] Aspects of the present disclosure are best understood from the following detailed description when read in conjunction with the accompanying drawings. It should be noted that, in accordance with industry standard practice, various features are not drawn to scale. In fact, for clarity of discussion, the dimensions of various features may be arbitrarily increased or decreased.

[0013] Figure 1 FIG. illustrates an example schematic diagram of a system for enhancing security associated with AI / ML operations and improving performance, according to one aspect of the present embodiment.

[0014] Figure 2 FIG. illustrates an example schematic diagram of a hardware security module (HSM), according to one aspect of the present embodiment.

[0015] Figures 3A - 3D FIG. illustrates an example of an AI / ML request processed by the system, according to one aspect of the present embodiment.

[0016] Figure 4 FIG. illustrates a flowchart of an example process for executing an AI / ML operation request, according to one aspect of the present embodiment. DETAILED DESCRIPTION

[0017] The following disclosure provides many different embodiments or examples for implementing different features of the present subject matter. Specific examples of components and arrangements are described below to simplify the present disclosure. Of course, these are merely examples and are not intended to be limiting. Additionally, the present disclosure may repeat reference numerals and / or letters in various examples. This repetition is for simplicity and clarity and does not in itself determine the relationship between the various embodiments and / or configurations discussed.

[0018] Before describing various embodiments in more detail, it should be understood that these embodiments are not restrictive, as elements in such embodiments can vary. It should also be understood that the specific embodiments described and / or illustrated herein have elements that can be readily separated from a particular embodiment and can optionally be combined with any one of several other embodiments or replace elements in any one of several other embodiments described herein. It should further be understood that the terms used herein are for the purpose of describing certain concepts and the terms are not intended to be restrictive. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood in the field to which the embodiments belong.

[0019] Encryption operations associated with AI / ML-related requests need to be performed to enhance data security while also improving performance, such as speed, etc. In a non-limiting example, requests or data associated with AI / ML operations are sent by an application and received by a system. The system can utilize a Hardware Security Module (HSM) to perform one or more cryptographic operations associated with the request or data in an efficient manner. An HSM is a physical computing device that protects and manages the secrets and confidential information (such as digital keys and data) of its users who use the HSM. The HSM typically has certain security protection measures in place to prevent tampering from network attacks and plays a crucial role in providing a secure environment for various cryptographic operations, such as encryption and decryption, digital signatures, strong authentication, and other cryptographic functions. The HSM is mainly used for generating, exporting, storing, and managing encryption keys, performing secure computations via encryption and decryption, and protecting users' sensitive data from unauthorized access and attacks.

[0020] The result of the cryptographic operation can be sent to an AI processor, such as an accelerator, CPU, GPU, etc., for performing AI / ML operations. In other words, the cryptographic operations that enhance the security of data or requests associated with AI / ML operations are offloaded to the HSM, which is designed to efficiently perform cryptographic operations, thereby enhancing security while improving performance. The result of the cryptographic operation, such as plaintext data, etc., can be sent to the AI processor to perform AI / ML operations. In a non-limiting example, the AI processor can be an accelerator designed to efficiently perform AI / ML operations. Thus, the AI processor is used to efficiently perform AI / ML operations and will not bear the burden of performing cryptographic operations that are not designed to run efficiently, thereby improving performance. Additionally, the physically separate HSM and AI processor are used, thus enhancing security and reducing the security vulnerabilities of the system by separating the encryption environment from the processing environment (such as AI / ML operations).

[0021] Figure 1FIG. shows an example schematic diagram of a system for enhancing security associated with AI / ML operations and improving performance according to an aspect of the present embodiment. Although these figures depict the components as functionally independent, such a description is for illustrative purposes only. It is obvious that the components depicted in the figure can be arbitrarily combined or divided into separate software, firmware, and / or hardware components. Additionally, it is apparent that regardless of how these components are combined or divided, they can be executed on the same host or multiple hosts, and multiple hosts can be connected via one or more networks.

[0022] In Figure 1 the example of, system 100 includes application 110 running on a host. Application 110 generates one or more requests for performing AI / ML operations and can send data associated with the request. In a non-limiting example, application 110 can be an application running on hardware for autonomous vehicles, for image recognition, for natural language processing, etc. In a non-limiting example, application 110 can be, but is not limited to, a cloud-based user application, such as an application hosted by a network service such as Amazon Web Services (AWS). Interface 120 can receive a request to perform one or more ML operations and / or data associated with the request from application 110. In a non-limiting example, application 110 can communicate with interface 120 via a network (not shown) that follows certain communication protocols, such as the TCP / IP protocol. Such a network can be, but is not limited to, the Internet, an intranet, a wide area network (WAN), a local area network (LAN), a wireless network, Bluetooth, WiFi, a mobile communication network, or any other network type. In a non-limiting example, the request and / or data received from application 110 can include sensitive data / information (e.g., bias values for an AI / ML model) and can be protected by application 110, such as encryption.

[0023] In some embodiments, interface 120 may send requests / data received from application 110 and associated with AI / ML operations to HSM 130 via bus 122 to perform one or more cryptographic operations. In a non-limiting example, HSM 130 may include a multi-chip embedded hardware / firmware cryptographic module that has software, firmware, hardware, or another component used for the purpose. In some embodiments, one or more processors include a multi-core processor and a security processor, where the security processor is configured to perform cryptographic operations using a hardware accelerator with embedded software implementing security algorithms. In some embodiments, HSM 130 is approved according to Federal Information Processing Standards (FIPS) levels 2 and 3 for performing secure key management cryptographic operations. In some embodiments, HSM 130 is pre-configured with default networks and authentication certificates so that HSM 130 can comply with FIPS / Common Criteria / PCI standards for key management and cryptographic operations. In some embodiments, the FIPS-approved HSM 130 includes one or more processors and a storage unit (not shown). In a non-limiting example, cryptographic operations may include one or more of key management, encryption / decryption, digital signature and verification, authentication, auditing, secure code execution, etc. HSM 130 is designed to efficiently perform cryptographic operations, thereby improving performance compared to other hardware components (such as CPUs, GPUs, inference engines, etc.) that are not specifically designed to perform cryptographic operations. The result of the cryptographic operation, such as plaintext data, may be sent by HSM 130 to AI processor 140 via bus 122 for execution.

[0024] In some embodiments, AI processor 140 may be specifically designed to perform AI / ML operations in an efficient manner. AI processor 140 may be ML hardware specifically designed to perform AI / ML operations in an effective manner, or it may be a CPU or a GPU. In a non-limiting example, the AI / ML operations may be associated with an ML model and may be computationally intensive. However, since AI processor 140 can be specifically designed to effectively perform AI / ML operations, the performance of the system can be improved.

[0025] It should be understood that since interface 120 sends cryptographic operations to be executed by HSM 130, the performance and security of the system are improved. In addition, since the cryptographic operations are executed by HSM 130, the resources of AI processor 140 are not burdened with operations for which they are not designed. In other words, the cryptographic operations are offloaded to be executed by HSM 130, which is designed to perform cryptographic operations, rather than by a processor designed to perform AI / ML operations or a general-purpose processor, thereby improving the efficiency, speed, and resource utilization of the system. It should also be understood that security is improved by physically separating the cryptographic environment from the processing environment. In a non-limiting example, once AI processor 140 has executed its AI / ML operations, the results can be sent to HSM 130 for performing cryptographic operations before the results are output and sent back to application 110 via interface 120.

[0026] It should be understood that one HSM is shown for illustrative purposes and should not be construed as limiting the embodiments. For example, multiple HSMs can be used.

[0027] Figure 2 A schematic example of HSM 130 according to one aspect of the present embodiment is depicted. In a non-limiting example, HSM 130 can include one or more of a plurality of modules, including interface 210 (in this non-limiting example, interface 210 is different from interface 120), processor 220, secure memory / key repository 230, tamper protection controller 240, random number generator 250, and firmware 260.

[0028] According to one example, interface 210 may receive requests, such as requests and / or data associated with one or more cryptographic operations. In this example, the cryptographic operations may be associated with AI / ML operation requests and may include data associated with AI / ML operations. Interface 210 may be configured to parse each of the multiple service requests and identify the type of service requested by a particular application. Various types of service requests may be any cryptographic operation, including but not limited to key management (e.g., key generation, key export, key deletion, secure key and data storage), cryptographic (e.g., encryption and decryption) operations on keys and data, digital signature and verification (e.g., generating digital signatures and verification), authentication (to ensure that only authorized users and systems can access certain data (e.g., sensitive data and / or services, such as biases / weights associated with AI / ML models)), auditing (for forensic analysis and compliance), secure code execution (to execute custom code within a secure boundary), etc. Then, interface 210 invokes the corresponding processors / components of the key management and cryptographic operation modules to process the particular type of service requested by the application and the data embedded in or pointed to by the service request. Once the key management and cryptographic operation modules have processed the service request, interface 210 may compose a response including the processing result and send the response back to the application that sent the service request.

[0029] In a non - limiting example, processor 220 may be used to execute one or more types of service requests. For example, processor 220 may be configured to perform key management (by using secure memory / key repository 230) or cryptographic operations / services (e.g., Advanced Encryption Standard (AES) operations, Data Encryption Standard (DES) operations, etc.) according to the type of service requested. For non - limiting examples, key management or encryption operations may be but are not limited to generating new keys, storing keys into key repository 230, exporting keys back to application 110 or AI processor 140, deleting existing keys from key repository 230, encrypting or decrypting data using keys, and storing the encrypted or decrypted data in key repository 230. Key repository 230 may be a secure memory component used for key management. Processor 220 may use secure memory / key repository 230 for key management and cryptographic operations and further provide the processing result (e.g., the generated key) back to the requesting application 110 or AI processor 140 via interface 210, bus 122, and / or interface 120. In some embodiments, key management and encryption operations may be configured to stop or abort key management or encryption operations if an alert of a potential security threat is issued for a particular operation and / or the application requesting the service.

[0030] In a non - limiting example, the secure memory / key store 230 is configured to maintain various types of information / data associated with multiple applications in a secure environment. Such information includes, but is not limited to, keys, encrypted data, decrypted data, and any other confidential or proprietary information of each of the multiple applications. In some embodiments, the secure memory / key store 230 includes multiple types of storage devices, including but not limited to dynamic random access memory (DRAM) and flash memory for key and data storage, ferroelectric RAM (FRAM) for storing critical logs, and eFuse for one - time key writing that cannot be erased, etc.

[0031] According to a non - limiting example, the tamper - protection controller 240 can be used to ensure that data and / or requests are not tampered with, and if the tamper - protection controller 140 detects tampering, then the request and / or operation can be aborted. In a non - limiting example, the random number generator 250 can be used to generate random numbers that can be used for encryption / decryption. In a non - limiting example, the HSM 130 can include firmware 260. According to a non - limiting example, the results (e.g., plaintext data) associated with AI / ML operations and / or data can be output from the HSM 130 to the AI processor 140 for the AI processor 140 to perform one or more AI / ML operations. In an example, the AI / ML operations can include complex mathematical operations associated with an ML model.

[0032] Figures 3A - 3D An example of an AI / ML request processed by the system according to one aspect of the present embodiment is depicted. Now refer to Figure 3A , data 302, such as requests and / or data associated with ML / AI operations, is sent from the application 110 via the interface 120 to the HSM 130 for performing one or more cryptographic operations, as described above Figure 1 and Figure 2As described. The data 302 can be received as encrypted data to enhance security. For example, the data 302 can include biases or weights associated with a particular ML model or operation. It should be understood that the HSM 130 is designed to efficiently perform one or more cryptographic operations. The HSM 130 can utilize the processor 220 (which can be an accelerator) for efficiently performing cryptographic operations, such as high resource utilization and reduced latency. Thus, cryptographic operations associated with AI / ML requests and / or data are offloaded to the HSM 130 instead of having the AI processor 140 perform the cryptographic operations. Since the AI processor 140 is designed to achieve high performance for AI / ML operations, it may not be able to achieve similar performance for cryptographic operations. Thus, using the HSM 130 can improve efficiency and resource utilization. Additionally, creating a separation between the cryptographic environment and the AI processing environment can enhance the security of the system compared to a single environment where both cryptographic operations and AI processing are performed.

[0033] Now refer to Figure 3B , the result of the cryptographic operation can be sent to the AI processor 140 so that the AI processor 140 can efficiently perform AI / ML operations. In this non-limiting example, the result can be the data 304 that is sent from the HSM 130 to the AI processor 140 via the interface 120 and / or the bus 122. The data 304 can be plaintext data (e.g., unencrypted). The data 304 can be the result of a cryptographic operation as described above with respect to Figure 1 and Figure 2 described, such as authentication, signature verification, encryption / decryption, etc. It should be understood that since the AI processor 140 can be designed to efficiently perform one or more AI / ML operations, the performance of the system is enhanced. It should be understood that even if the AI processor 140 is not specifically designed to perform AI / ML operations, such as a CPU, GPU, etc., the performance of the system can still be enhanced because the cryptographic operations are still performed by components (such as the HSM 130) that are designed to efficiently perform cryptographic operations. The AI processor 140 generates the data 306 as the result of its AI / ML processing, as shown in Figure 3C . When the data 306 is sent from the AI processor 140 to the HSM 130 via the bus 122 and / or the interface 120, the data 306 can be in an unencrypted form. According to a non-limiting example, the data 306 is sent from the AI processor 140 to the HSM 130 to perform one or more cryptographic operations as described above in Figure 1 and Figure 2 described, thereby generating a result, such as in encrypted form. Thus, the data 308 (e.g., encrypted data) generated by the HSM 130 can now be sent back via the bus 122 and / or the interface 120 to the application 110 of the requested AI / ML operation, as shown in Figure 3Das shown.

[0034] Figure 4 FIG. depicts a flowchart of an example process for performing an AI / ML operation request according to an aspect of the present embodiment. At step 410, an AI request (e.g., data or operation request) can be received from an application. The AI request can be a request to perform one or more AI-related operations, such as a Sigmoid operation, a Softmax operation, etc. At step 420, one or more cryptographic operations associated with one or more AI-related operations are offloaded to the HSM, as described above Figures 1 - 3D above. At step 430, one or more cryptographic operations associated with one or more AI-related operations are performed by the HSM, as described above Figures 1 - 3D above. At step 440, the results of one or more cryptographic operations associated with one or more AI-related operations are sent to the AI processor, e.g., as described above in Figures 1 - 3D above. At step 450, one or more AI-related operations are performed by the AI processor, as described above. In a non-limiting example, the results of the AI operations of the AI processor can be sent to the HSM to perform one or more cryptographic operations on them before sending the results of the AI operations back to the application that requested the AI operations.

[0035] Thus, the cryptographic operations are offloaded from the AI processor to be performed by the HSM, which is more suitable for handling cryptographic operations. Thus, by separating the cryptographic operation environment from the AI processing environment, both performance and security are improved. Therefore, the AI processor does not need to perform cryptographic operations and can perform AI operations (processing) on the data received from the HSM. Thus, not only security and performance are improved, but also efficiency and resource utilization are improved.

[0036] For purposes of illustration and description, the above description of various embodiments of the claimed subject matter is provided. It is not intended to be exhaustive or to limit the claimed subject matter to the precise forms disclosed. Many modifications and variations are obvious to those of ordinary skill in the art. The embodiments were chosen and described in order to best describe the principles of the invention and its practical applications, thereby enabling others skilled in the relevant art to understand the claimed subject matter, the various embodiments, and the various modifications suitable for the particular uses contemplated.

Claims

1. A system, comprising: A hardware security module HSM; An interface configured to receive an artificial intelligence AI request from an application, where the AI request is a request to perform one or more AI-related operations; and An AI processor, where the interface is configured to offload one or more cryptographic operations associated with the one or more AI-related operations to the HSM, and where the HSM is configured to perform one or more cryptographic operations associated with the one or more AI-related operations, and where the HSM is configured to send the results of the one or more cryptographic operations associated with the one or more AI-related operations to the AI processor, and where the AI processor is configured to receive the results of the one or more cryptographic operations associated with the one or more AI-related operations from the HSM, and where the AI processor is configured to perform the one or more AI-related operations.

2. The system according to claim 1, where the HSM is a hardware component separate from the AI processor.

3. The system according to claim 1, where the AI processor is a central processing unit CPU or a graphics pipeline unit GPU.

4. The system according to claim 1, where the one or more cryptographic operations are at least one or more of encryption / decryption, digital signature and verification, authentication, auditing, secure code execution, key management, and tamper protection.

5. The system according to claim 1, where the interface receives data associated with the AI request in an encrypted format.

6. The system according to claim 5, where the interface is configured to send data to the HSM in an encrypted format, and where the HSM is configured to decrypt the data to form plaintext data, and where the HSM is further configured to send the plaintext data to the AI processor, where the plaintext data is used by the AI processor to process the one or more AI-related operations.

7. The system according to claim 6, where the AI processor is configured to send the results of processing the one or more AI-related operations to the HSM in an unencrypted format, and where the HSM is configured to encrypt the results of processing the one or more AI-related operations and then send the encrypted results of processing the one or more AI-related operations to the interface.

8. The system according to claim 7, where the interface is configured to send the encrypted results of processing the one or more AI-related operations to the application.

9. The system according to claim 1, where the one or more AI-related operations are related to an AI model.

10. A method, comprising: Receiving an artificial intelligence AI request from an application, where the AI request is a request to perform one or more AI-related operations; Offloading one or more cryptographic operations associated with the one or more AI-related operations to a hardware security module HSM; The HSM performs one or more cryptographic operations associated with one or more AI-related operations; send the results of the one or more cryptographic operations associated with the one or more AI-related operations to the AI processor; and execute the one or more AI-related operations by the AI processor.

11. The method according to claim 10, wherein the HSM is separate from the AI processor.

12. The method according to claim 10, wherein the one or more cryptographic operations are at least one or more of encryption / decryption, digital signature and verification, authentication, auditing, secure code execution, key management, and tamper protection.

13. The method according to claim 10, further comprising receiving data associated with the AI request from the application in an encrypted format.

14. The method according to claim 13, wherein the data is received by the HSM, and wherein the method further comprises: decrypting the data to form plaintext data; sending the plaintext data to the AI processor; and executing the one or more AI-related operations by the AI processor based on the plaintext data.

15. The method according to claim 14, further comprising: sending the results of processing the one or more AI-related operations from the AI processor to the HSM in an unencrypted format; using the HSM to encrypt the results of processing the one or more AI-related operations in an unencrypted format; and sending the encrypted results of processing the one or more AI-related operations to the application.

16. The method according to claim 10, wherein the one or more AI-related operations are related to an AI model.

17. A system, comprising: A hardware security module HSM, the HSM is configured to receive an artificial intelligence AI request sent by an application, wherein the AI request is a request to perform one or more AI-related operations, wherein the HSM is configured to perform one or more cryptographic operations associated with the one or more AI-related operations, and wherein the HSM is configured to send the results of the one or more cryptographic operations associated with the one or more AI-related operations to an AI processor; and The AI processor is configured to receive the results of the one or more cryptographic operations associated with the one or more AI-related operations from the HSM, and wherein the AI processor is configured to perform the one or more AI-related operations.

18. The system according to claim 17, wherein the HSM is a hardware component separate from the AI processor.

19. The system according to claim 17, wherein the AI processor is a central processing unit CPU or a graphics pipeline unit GPU.

20. The system according to claim 17, wherein the one or more cryptographic operations are at least one or more of encryption / decryption, digital signature and verification, authentication, auditing, secure code execution, key management, and tamper protection.

21. The system according to claim 17, wherein the HSM receives data associated with the AI request in an encrypted format.

22. The system according to claim 21, wherein the HSM is configured to decrypt the data to form plaintext data, and wherein the HSS is configured to send the plaintext data to the AI processor, and wherein the plaintext information is used by the AI processor to process the one or more AI-related operations.

23. The system according to claim 22, wherein the AI processor is configured to send the result of processing the one or more AI-related operations to the HSM in an unencrypted format, and wherein the HSM is configured to encrypt the result of processing the one or more AI-related operations, and then send the encrypted result of processing the one or more AI-related operations to the application.

24. The system according to claim 17, wherein the one or more AI-related operations are related to an AI model.

25. A system, comprising: means for receiving an artificial intelligence (AI) request from an application, wherein the AI request is a request to perform one or more AI-related operations; means for offloading one or more cryptographic operations associated with the one or more AI-related operations to a hardware security module (HSM); means for performing, by the HSM, one or more cryptographic operations associated with the one or more AI-related operations; means for sending the result of the one or more cryptographic operations associated with the one or more AI-related operations to an AI processor; and means for performing, by the AI processor, the one or more AI-related operations.