AI large model security all-in-one machine and security channel establishment method and device

Through the secure processor and TEE memory encryption solution of AI big model security all-in-one, data security problems in localized deployment of AI big model are solved, hardware encryption and decryption and data isolation are realized, and data security and identity authentication isolation are improved.

CN120337205AActive Publication Date: 2025-07-18HUAKONG TSINGJIAO INFORMATION SCI BEIJING LTD

Patent Information

Application Number
CN202510787381.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-12
Publication Date
2025-07-18
Estimated Expiration
2045-06-12

AI Technical Summary

Technical Problem

In the localized deployment scenario of AI large model, data security is poor, and there is a security risk for model and training data, especially the security caused by unauthorized access by internal personnel cannot be effectively guaranteed.

Method used

It adopts an AI big model security all-in-one machine, including a secure processor and a physical memory module. TEE has different memory encryption and decryption keys. The AI big model application performs encrypted write and decrypted reading in an independent memory space, and establishes a secure channel with the client through a remote authentication module, and uses the public key generated by the hardware trusted root for identity authentication and session key generation.

Benefits of technology

It realizes hardware encryption and decryption of AI big model application data, isolates data in different TEEs, prevents access by host system and operation and maintenance management personnel, improves data security, and ensures data isolation through identity authentication and encrypted communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337205A_ABST
    Figure CN120337205A_ABST
Patent Text Reader

Abstract

The invention discloses an AI large model security all-in-one machine and a security channel establishment method and device, and relates to the technical field of multi-party security computing. The AI large model security all-in-one machine comprises a security processor and a physical memory module; the security all-in-one machine is provided with a plurality of trusted execution environments (TEE), different TEEs have different secret keys used for memory encryption and decryption and serve as memory secret keys, the memory secret keys of the TEEs are generated by a memory encryption module of a security processor based on a hardware trusted root of the security processor, and different memory spaces which are independently used are distributed to different TEEs on a physical memory module; an AI large model application is installed on each TEE, and data generated by the AI large model application is encrypted, written and decrypted and read in the memory space allocated for the TEE by the memory security module by using the memory key corresponding to the TEE. By adopting the scheme, the data security for localized deployment of the AI large model is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of multi-party secure computing technology, and in particular, to an AI large model security all-in-one machine, a secure channel establishment method, and a device. Background Art

[0002] Large language models (LLMs) and their applications in the field of artificial intelligence have become a global research hotspot. A large language model is a deep learning model trained based on massive text data. It can not only generate natural language text but also deeply understand the meaning of the text and process various natural language tasks, such as text summarization, question answering, translation, etc.

[0003] However, in the context of the rapid evolution of large model technology and its deep integration with the industry, data security protection has become the core challenge restricting the development of artificial intelligence, and enterprises face severe data security risks when applying large models. For example, there are security risks for models and training data in the scenario of local model deployment.

[0004] In a private deployment environment, when an enterprise uses its own data to optimize model applications, it faces the risk of potential unauthorized access to enterprise data by internal personnel, resulting in the security of training data, model parameters, and enterprise private knowledge bases not being effectively guaranteed. Summary of the Invention

[0005] Embodiments of this application provide an AI large model security all-in-one machine, a secure channel establishment method, and a device to solve the problem of poor data security for local deployment of AI large models in the prior art.

[0006] Embodiments of this application provide an AI large model security all-in-one machine, including: a security processor and a physical memory module; The security all-in-one machine has multiple trusted execution environments (TEEs). Different TEEs have different keys for memory encryption and decryption as memory keys. The memory keys of the TEEs are generated by the memory encryption module of the security processor based on the hardware trusted root of the security processor. Different TEEs are allocated independent and different memory spaces on the physical memory module; An AI large model application is installed on each TEE. The data generated by the AI large model application is encrypted and written and decrypted and read in the memory space allocated for the TEE by the memory security module using the memory key corresponding to the TEE.

[0007] Furthermore, it further includes: multiple AI acceleration cards; The AI acceleration cards are connected to the device direct access module of the security processor; Data is exchanged between the AI large model application of the TEE and the AI acceleration card through the device passthrough module.

[0008] Furthermore, the security processor has a remote authentication module; The remote authentication module realizes remote authentication of the authenticity of the TEE through message interaction with the client.

[0009] Furthermore, a database is established in each TEE for storing identity authentication information; During the process of establishing a secure channel between the AI large model application and the client, the identity of the client is authenticated based on the identity authentication information stored in the database of the TEE to which the AI large model application belongs.

[0010] Furthermore, the AI large model application has a public key for establishing a secure channel with the client; The public key of the AI large model application is generated by the security processor based on the hardware trusted root, and the public keys of the AI large model applications in different TEEs are different.

[0011] The embodiment of the present application also provides a method for establishing a secure channel, which is applied to the AI large model application in the TEE of any one of the above-mentioned AI large model security all-in-ones, and includes: The AI large model application confirms the establishment information for establishing a secure channel through message interaction with the client; Receive the identity certificate sent by the client, and the identity certificate carries the identity authentication information for identity authentication; Authenticate the identity of the client by comparing the identity authentication information carried in the identity certificate with the identity authentication information stored in the database of the TEE to which the AI large model application belongs; After the identity authentication of the client is passed, send a token to the client, and the token is used to carry in the data packet sent by the client to the AI large model application; Through message interaction with the client, based on the confirmed establishment information and the public key of the AI large model application, a session key is generated using a key exchange algorithm, and the session key is used for encrypted communication between the AI large model application and the client. The public key of the AI large model application is generated by the security processor based on the hardware trusted root, and the public keys of the AI large model applications in different TEEs are different.

[0012] The embodiment of the present application also provides a method for establishing a secure channel, which is applied to a client located outside any one of the above-mentioned AI large model security all-in-ones, and includes: Confirm the establishment information for establishing a secure channel through message interaction with the AI large model application in the TEE; Send an identity certificate to the AI large model application, where the identity certificate carries identity authentication information for identity authentication, so that the AI large model application authenticates the identity of the client by comparing the identity authentication information carried in the identity certificate with the identity authentication information stored in the database of the TEE to which the AI large model application belongs; Receive the token sent by the AI large model application to the client after the identity authentication of the client is passed, where the token is used to be carried in the data packet sent by the client to the AI large model application; Through message interaction with the AI large model application, generate a session key based on the confirmed establishment information and the public key of the AI large model application using a key exchange algorithm. The session key is used for encrypted communication between the AI large model application and the client. The public key of the AI large model application is generated by the secure processor based on the hardware trusted root, and the public keys of the AI large model applications in different TEEs are different.

[0013] An embodiment of the present application also provides a secure channel establishment device, which is applied to the AI large model application in the TEE of any of the above-mentioned AI large model security all-in-ones, and includes: The first establishment information confirmation module is used to confirm the establishment information for establishing a secure channel through message interaction with the client; The certificate receiving module is used to receive the identity certificate sent by the client, where the identity certificate carries identity authentication information for identity authentication; The identity authentication module is used to authenticate the identity of the client by comparing the identity authentication information carried in the identity certificate with the identity authentication information stored in the database of the TEE to which the AI large model application belongs; The token sending module is used to send a token to the client after the identity authentication of the client is passed, where the token is used to be carried in the data packet sent by the client to the AI large model application; The first session key generation module is used to generate a session key based on the confirmed establishment information and the public key of the AI large model application through message interaction with the client using a key exchange algorithm. The session key is used for encrypted communication between the AI large model application and the client. The public key of the AI large model application is generated by the secure processor based on the hardware trusted root, and the public keys of the AI large model applications in different TEEs are different.

[0014] The embodiment of the present application further provides a secure channel establishment device, which is applied to a client located outside any of the above-mentioned AI large model security all-in-one machines, and includes: A second establishment information confirmation module, configured to confirm the establishment information for establishing a secure channel through message interaction with the AI large model application in the TEE; A certificate sending module, configured to send an identity certificate to the AI large model application, where the identity certificate carries identity authentication information for identity authentication, so that the AI large model application authenticates the identity of the client by comparing the identity authentication information carried in the identity certificate with the identity authentication information stored in the database of the TEE to which the AI large model application belongs; A token receiving module, configured to receive a token sent by the AI large model application to the client after the identity authentication of the client is passed, and the token is used to be carried in the data packet sent by the client to the AI large model application; A second session key generation module, configured to generate a session key through message interaction with the AI large model application, based on the confirmed establishment information and the public key of the AI large model application, using a key exchange algorithm. The session key is used for encrypted communication between the AI large model application and the client. The public key of the AI large model application is generated by the secure processor based on the hardware trusted root, and the public keys of the AI large model applications in different TEEs are different.

[0015] The embodiment of the present application further provides an electronic device, including a processor and a machine-readable storage medium. The machine-readable storage medium stores machine-executable instructions that can be executed by the processor. The processor is prompted by the machine-executable instructions to implement any of the above-mentioned secure channel establishment methods applied to the AI large model application, or to implement any of the above-mentioned secure channel establishment methods applied to the client.

[0016] The embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, it implements any of the above-mentioned secure channel establishment methods applied to the AI large model application, or implements any of the above-mentioned secure channel establishment methods applied to the client.

[0017] The embodiment of the present application further provides a computer program product containing instructions. When it runs on a computer, it causes the computer to execute any of the above-mentioned secure channel establishment methods applied to the AI large model application, or to execute any of the above-mentioned secure channel establishment methods applied to the client.

[0018] The beneficial effects of the present application include: In the solution provided by the embodiments of the present application, the AI large model security all-in-one machine includes: a security processor and a physical memory module. The security all-in-one machine has multiple Trusted Execution Environments (TEEs), and different TEEs have different keys for memory encryption and decryption, which are used as memory keys. The memory keys of the TEEs are generated by the memory encryption module of the security processor based on the hardware trusted root of the security processor. Different TEEs are allocated different memory spaces for independent use on the physical memory module. Moreover, an AI large model application is installed on each TEE. The data generated by the AI large model application is encrypted and written and decrypted and read by the memory security module using the memory key corresponding to the TEE in the memory space allocated for the TEE. By adopting this solution, hardware encryption and decryption of the data generated by the AI large model application in the TEE are realized, so that application programs outside the host system and the trusted execution environment cannot access the data generated by the AI large model application, and thus the operation and maintenance management personnel of the host system cannot obtain the data generated by the AI large model application either. In addition, the memory keys of different TEEs are different, which further realizes the isolation of the data generated in different TEEs. Therefore, the data security for the local deployment of the AI large model is improved.

[0019] Other features and advantages of the present application will be described in the following specification, and some of them will become obvious from the specification or be understood by implementing the present application. The objectives and other advantages of the present application can be achieved and obtained through the structures specifically pointed out in the written specification, claims, and drawings. Brief Description of the Drawings

[0020] The drawings are used to provide further understanding of the present application and form a part of the specification. They are used together with the embodiments of the present application to explain the present application and do not constitute a limitation to the present application. In the drawings: Figure 1 It is a schematic structural diagram of the AI large model security all-in-one machine provided by the embodiments of the present application; Figure 2 It is a schematic structural diagram of the AI large model security all-in-one machine provided by another embodiment of the present application; Figure 3 It is a schematic structural diagram of the AI large model security all-in-one machine provided by another embodiment of the present application; Figure 4 It is a schematic diagram of the interaction between the client and the AI large model application on the AI large model security all-in-one machine in the embodiments of the present application; Figure 5 It is a flowchart of the security channel establishment method applied to the AI large model application provided by the embodiments of the present application; Figure 6 It is a flowchart of the security channel establishment method applied to the client provided by the embodiments of the present application; Figure 7 The flowchart of the secure channel establishment method provided by the embodiment of the present application; Figure 8 The schematic structural diagram of the secure channel establishment device applied to the AI large model application provided by the embodiment of the present application; Figure 9 The schematic structural diagram of the secure channel establishment device applied to the client provided by the embodiment of the present application; Figure 10 The schematic structural diagram of the electronic device provided by the embodiment of the present application. Detailed implementation manners

[0021] In order to provide an implementation solution for improving the data security of the local deployment of the AI large model, the embodiment of the present application provides an AI large model security all-in-one machine, a secure channel establishment method and device. The preferred embodiments of the present application are described below with reference to the accompanying drawings of the specification. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present application, and are not used to limit the present application. And without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other.

[0022] The embodiment of the present application provides an AI large model security all-in-one machine, as Figure 1 shown, including: a security processor and a physical memory module; This security all-in-one machine has multiple trusted execution environments (TEEs). Different TEEs have different keys for memory encryption and decryption. As memory keys, the memory keys of the TEEs are generated by the memory encryption module of the security processor based on the hardware trusted root of the security processor. Different TEEs are allocated independent and different memory spaces on the physical memory module; An AI large model application is installed on each TEE. The data generated by the AI large model application is encrypted and written and decrypted and read by the memory security module using the memory key corresponding to the TEE in the memory space allocated for the TEE.

[0023] By using the above-mentioned AI large model security all-in-one machine provided by the embodiment of the present application, the hardware encryption and decryption of the data generated by the AI large model application in the TEE are realized, so that application programs outside the host system and the trusted execution environment cannot access the data generated by the AI large model application, and thus the operation and maintenance management personnel of the host system cannot obtain the data generated by the AI large model application. Moreover, the memory keys of different TEEs are different, further realizing the isolation of the data generated in different TEEs. Therefore, the data security of the local deployment of the AI large model is improved.

[0024] In one embodiment of the present application, the TEE can exist in the AI large model security all-in-one machine in the form of a confidential virtual machine or a confidential container. The TEE has an independent system kernel and is completely isolated from the host system. Therefore, the IT administrator / operation and maintenance personnel of the AI large model security all-in-one machine do not have access rights to the data or code in the TEE, thereby preventing access to and theft of business system data.

[0025] Different TEEs have different keys for memory encryption and decryption. As memory keys, they are generated by the memory encryption module of the security processor based on the hardware trusted root. For example, for a TEE, based on the hardware trusted root and the attribute information of the TEE, a memory key is generated using a preset algorithm and stored, and the generated memory key will not be exposed to the host system or the virtual machine monitor (Hypervisor).

[0026] In the embodiment of the present application, for different TEEs, different memory spaces are allocated for them on the physical memory module. For a TEE, the allocated memory space is only for the independent use of the TEE. The memory encryption module encrypts and writes and decrypts and reads the data generated by the AI large model application in the TEE in the allocated memory space. Applications in the untrusted execution environment on the host cannot maliciously access and steal data from this memory space.

[0027] In one embodiment of the present application, as Figure 2 shown, the AI large model security all-in-one machine may further include: a plurality of AI acceleration cards; The AI acceleration card is connected to the device passthrough module of the security processor; Data is exchanged between the AI large model application of the TEE and the AI acceleration card through the device passthrough module.

[0028] In one embodiment of the present application, the device passthrough module can be a PCIe device passthrough module. Its function is to unbind the AI acceleration card with a PCIe interface from the host on the device driver layer and directly pass it into the trusted execution environment TEE for direct connection with the AI large model application in the TEE. After passing through, the host system will not have permission to access the data in the AI acceleration card, thereby improving the security of the data in the AI acceleration card directly connected to the TEE, and further improving the security of the data of the AI large model application in the TEE.

[0029] In one embodiment of the present application, as Figure 3 shown, the security processor of the AI large model security all-in-one machine may further have a remote authentication module; The remote authentication module realizes remote authentication of the authenticity of the TEE through message interaction with the client.

[0030] In one embodiment of the present application, remote authentication can be initiated by a client located outside the AI large model security all-in-one machine. Through message interaction with the remote authentication module, the authenticity of the TEE of the AI large model security all-in-one machine is authenticated. After successful authentication, a secure channel can be established between the client and the AI large model application in the TEE, and a data transmission operation can be initiated.

[0031] Furthermore, in one embodiment of the present application, a database can be established in each TEE on the AI large model security all-in-one machine for storing identity authentication information; During the process of establishing a secure channel between the AI large model application and the client, the identity of the client can be authenticated based on the identity authentication information stored in the database of the TEE to which it belongs.

[0032] The identity authentication information used can be traditional username and password data, or biometric identity data information such as fingerprint, face, etc.

[0033] After successfully authenticating the identity of the client, a secure channel is established with the client, and data is transmitted through the established secure channel. For example, operations such as receiving a query request initiated by the client, returning a query result to the client, and receiving data for model training sent by the client are performed.

[0034] Through the above-mentioned identity authentication mechanism for the client, after the AI large model security all-in-one machine is locally deployed, different TEEs on the AI large model security all-in-one machine can only be accessed by clients with specific identities. For example, the AI large model application in a TEE can only be accessed by specific organizations or specific department personnel of the company, thereby achieving the isolation of data between different organizations or departments during AI large model services, and further enhancing data security.

[0035] In practical applications, as Figure 4 shown, within a group, there are Department A and Department B (one is the Finance Department and the other is the Marketing Department), two different departments. Both have the need to perform large model-related inference services on the company's AI large model security all-in-one machine. For example, Department A uses the 32B model in TEE-1 on the AI large model security all-in-one machine, and Department B uses the 70B model in TEE-2 on the AI large model security all-in-one machine. At the same time, Department A and Department B need to isolate and protect their respective data requests. Then, by using the above-mentioned AI large model security all-in-one machine provided in the embodiments of the present application, data isolation can be achieved, and data security can be further enhanced.

[0036] In the embodiments of the present application, the AI large model application has a public key for establishing a secure channel with the client; The public key of the AI large model application is generated by the secure processor based on the hardware trusted root, and the public keys of the AI large model applications in different TEEs are different.

[0037] Based on the above-mentioned AI large model security all-in-one machine provided by the embodiments of the present application, the embodiments of the present application also provide a secure channel establishment method, which is applied to the AI large model application in the TEE of the above-mentioned AI large model security all-in-one machine, such as Figure 5 shown, including: Step 51, the AI large model application confirms the establishment information for establishing a secure channel through message interaction with the client; Step 52, receive the identity certificate sent by the client, and the identity certificate carries the identity authentication information for identity authentication; Step 53, authenticate the identity of the client by comparing the identity authentication information carried in the identity certificate with the identity authentication information stored in the database of the TEE to which the AI large model application belongs; Step 54, after the identity authentication of the client is passed, send a token to the client, and the token is used to carry in the data packet sent by the client to the AI large model application; Step 55, through message interaction with the client, based on the confirmed establishment information and the public key of the AI large model application, generate a session key using a key exchange algorithm, and the session key is used for encrypted communication between the AI large model application and the client. The public key of the AI large model application is generated by the secure processor based on the hardware trusted root, and the public keys of the AI large model applications in different TEEs are different.

[0038] Correspondingly, the embodiments of the present application also provide a secure channel establishment method, which is applied to the client outside the above-mentioned AI large model security all-in-one machine, such as Figure 6 shown, including: Step 61, confirm the establishment information for establishing a secure channel through message interaction with the AI large model application in the TEE; Step 62, send an identity certificate to the AI large model application, and the identity certificate carries the identity authentication information for identity authentication, so that the AI large model application authenticates the identity of the client by comparing the identity authentication information carried in the identity certificate with the identity authentication information stored in the database of the TEE to which the AI large model application belongs; Step 63, receive the token sent by the AI large model application to the client after the identity authentication of the client is passed, and the token is used to carry in the data packet sent by the client to the AI large model application; Step 64: Through message interaction with the AI large model application, based on the confirmed establishment information and the public key of the AI large model application, a session key is generated using a key exchange algorithm. The session key is used for encrypted communication between the AI large model application and the client. The public key of the AI large model application is generated by the secure processor based on the hardware trusted root, and the public keys of the AI large model applications in different TEEs are different.

[0039] When using the above-mentioned secure channel establishment method provided by the embodiments of the present application, for a client located outside the AI large model security all-in-one machine, when it is necessary to establish a secure channel with the AI large model application in the TEE of the AI large model security all-in-one machine, the AI large model application will authenticate the client, and only after the authentication passes will a secure channel be established. Moreover, the public key used to generate the session key between the AI large model application and the client is generated by the secure processor based on the hardware trusted root, and the public keys of the AI large model applications in different TEEs are different. Thus, it can be achieved that the AI large model applications in different TEEs are only accessible to clients with specific identities, thereby realizing the isolation of data between clients with different identities during the AI large model service, and further enhancing data security.

[0040] The above-mentioned secure channel establishment method provided by the embodiments of the present application will be described in detail below. Based on the above AI large model security all-in-one machine, as Figure 7 shown, it includes: Step 71: Through message interaction between the AI large model application and the client, the establishment information for establishing a secure channel is confirmed.

[0041] In this step, the establishment of the secure channel can be initiated by the client. First, the client generates a random number C, and generates a secure channel establishment request containing the random number C, the client TLS version number, the password suite list, and the compression algorithm list, and sends it to the AI large model application.

[0042] Then, after receiving the secure channel establishment request, the AI large model application generates a random number S, and based on the client TLS version number, the password suite list, and the compression algorithm list carried in the secure channel establishment request, generates a secure channel establishment response containing the random number S, the confirmed TLS version number, the selected password suite, and the compression algorithm, and returns it to the client.

[0043] In this step, the random number C, the random number S, the confirmed TLS version number, the selected password suite, and the compression algorithm belong to the establishment information confirmed between the server and the client for establishing a secure channel.

[0044] Step 72: The client sends an identity certificate to the AI large model application, and the identity certificate carries the identity authentication information for identity authentication.

[0045] Step 73. After receiving the identity certificate sent by the client, the AI large model application authenticates the identity of the client by comparing the identity authentication information carried in the identity certificate with the identity authentication information stored in the database of the TEE to which the AI large model application belongs.

[0046] Step 74. After successfully authenticating the identity of the client, the AI large model application sends a token to the client, which is used to be carried in the data packets sent by the client to the AI large model application subsequently.

[0047] Step 75. The AI large model application generates a private key and a public key, and sends the generated public key to the client.

[0048] For the sake of easy distinction, they can be called the server private key and the server public key.

[0049] In this step, the server private key and the server public key of the AI large model application are generated by the security processor of the AI large model security all-in-one machine based on the hardware trusted root, and the server public keys of the AI large model applications in different TEEs are different.

[0050] Specifically, it can be based on the confusion of the hardware trusted root and the ID of the TEE, and the derived key is used as the server public key of the AI large model application of this TEE.

[0051] Step 76. The client generates a private key and a public key, and sends the generated public key to the AI large model application.

[0052] For the sake of easy distinction, they can be called the client private key and the client public key.

[0053] Step 77. The client generates a session key using a key exchange algorithm.

[0054] In this step, the client can generate a session key using a key exchange algorithm based on the random number C, the random number S, the client private key, the client public key, and the received server public key.

[0055] Step 78. After receiving the client public key sent by the client, the AI large model application generates a session key using a key exchange algorithm.

[0056] In this step, the AI large model application can generate a session key using a key exchange algorithm based on the random number C, the random number S, the server private key, the server public key, and the received client public key.

[0057] In the embodiments of the present application, various feasible key exchange algorithms can be used, which will not be described in detail here.

[0058] After the client and the AI large model application each generate a session key, the generated session key is used for encrypted communication between the AI large model application and the client. Moreover, the session key is only valid for this connection and is confidential to third parties other than the two communicating parties.

[0059] By adopting the above-mentioned AI large model security all-in-one machine provided by the embodiments of the present application and the corresponding security channel establishment method, in response to the need for data security in the local deployment of the AI large model, an integrated solution based on software and hardware cooperation is realized, and end-to-end security protection for large model training, inference, and deployment is achieved.

[0060] Based on the same inventive concept, according to the security channel establishment method for the AI large model application provided by the above embodiments of the present application, correspondingly, another embodiment of the present application further provides a security channel establishment device, which is applied to the AI large model application in the TEE of any of the above-mentioned AI large model security all-in-one machines, and its structural schematic diagram is as Figure 8 shown, and specifically includes: The first establishment information confirmation module 81 is used to confirm the establishment information for establishing a security channel through message interaction with the client; The certificate receiving module 82 is used to receive the identity certificate sent by the client, and the identity certificate carries identity authentication information for identity authentication; The identity authentication module 83 is used to authenticate the identity of the client by comparing the identity authentication information carried in the identity certificate with the identity authentication information stored in the database of the TEE to which the AI large model application belongs; The token sending module 84 is used to send a token to the client after the identity authentication of the client is passed, and the token is used to be carried in the data packet sent by the client to the AI large model application; The first session key generation module 85 is used to generate a session key through message interaction with the client based on the confirmed establishment information and the public key of the AI large model application, and the session key is used for encrypted communication between the AI large model application and the client. The public key of the AI large model application is generated by the security processor based on the hardware trusted root, and the public keys of the AI large model applications in different TEEs are different.

[0061] Based on the same inventive concept, according to the security channel establishment method for the client provided by the above embodiments of the present application, correspondingly, another embodiment of the present application further provides a security channel establishment device, which is applied to a client located outside any of the above-mentioned AI large model security all-in-one machines, and its structural schematic diagram is as Figure 9 shown, and specifically includes: The second establishment information confirmation module 91 is used to confirm the establishment information for establishing a secure channel through message interaction with the AI large model application in the TEE; The certificate sending module 92 is used to send an identity certificate to the AI large model application. The identity certificate carries identity authentication information for identity authentication, so that the AI large model application authenticates the identity of the client by comparing the identity authentication information carried in the identity certificate with the identity authentication information stored in the database of the TEE to which the AI large model application belongs; The token receiving module 93 is used to receive the token sent by the AI large model application to the client after the identity authentication of the client is passed. The token is used to be carried in the data packet sent by the client to the AI large model application; The second session key generation module 94 is used to generate a session key through message interaction with the AI large model application, based on the confirmed establishment information and the public key of the AI large model application, using a key exchange algorithm. The session key is used for encrypted communication between the AI large model application and the client. The public key of the AI large model application is generated by the secure processor based on the hardware trusted root, and the public keys of the AI large model applications in different TEEs are different.

[0062] The functions of the above modules can correspond to Figures 1 to 7 the corresponding processing steps in the shown process, which will not be elaborated here.

[0063] The secure channel establishment device provided by the embodiments of the present application can be implemented through a computer program. Those skilled in the art should be able to understand that the above module division method is only one of many module division methods. If divided into other modules or not divided into modules, as long as the secure channel establishment device has the above functions, it should be within the protection scope of the present application.

[0064] The embodiments of the present application also provide an electronic device, as Figure 10 shown, including a processor 101 and a machine-readable storage medium 102. The machine-readable storage medium 102 stores machine-executable instructions that can be executed by the processor 101. The processor 101 is urged by the machine-executable instructions to: implement any of the above secure channel establishment methods applied to the AI large model application, or implement any of the above secure channel establishment methods applied to the client.

[0065] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, it implements any of the above-mentioned secure channel establishment methods applied to the AI large model application, or implements any of the above-mentioned secure channel establishment methods applied to the client.

[0066] An embodiment of the present application further provides a computer program product containing instructions. When it runs on a computer, it causes the computer to execute any of the above-mentioned secure channel establishment methods applied to the AI large model application, or execute any of the above-mentioned secure channel establishment methods applied to the client.

[0067] The machine-readable storage medium in the above-mentioned electronic device may include a random access memory (Random Access Memory, RAM), and may also include a non-volatile memory (Non-Volatile Memory, NVM), such as at least one disk memory. Optionally, the memory may also be at least one storage device located far from the aforementioned processor.

[0068] The above-mentioned processor may be a general-purpose processor, including a central processing unit (Central Processing Unit, CPU), a network processor (Network Processor, NP), etc.; it may also be a digital signal processor (Digital Signal Processing, DSP), an application specific integrated circuit (Application Specific Integrated Circuit, ASIC), a field programmable gate array (Field-Programmable Gate Array, FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0069] Each embodiment in this specification is described in a related manner. The same or similar parts between the embodiments can be referred to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for the embodiments of the device, electronic device, computer-readable storage medium, and computer program product, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiments.

[0070] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprising", "including" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.

[0071] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and combinations of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing device to produce a machine, such that the instructions executed by the processor of the computer or other programmable data processing device generate means for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks.

[0072] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufacture including instruction means for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks.

[0073] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks.

[0074] Obviously, those skilled in the art can make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalent technologies, this application is also intended to include these modifications and variations.

Claims

1. An AI large model security all-in-one machine, characterized in that, Comprising: A security processor and a physical memory module; The security all-in-one machine has multiple trusted execution environments (TEEs). Different TEEs have different keys for memory encryption and decryption, which are used as memory keys. The memory key of the TEE is generated by the memory encryption module of the security processor based on the hardware trusted root of the security processor. Different TEEs are allocated different independent memory spaces on the physical memory module; An AI large model application is installed on each TEE. The data generated by the AI large model application is encrypted and written and decrypted and read by the memory security module using the memory key corresponding to the TEE in the memory space allocated for the TEE.

2. The AI large model security all-in-one machine according to claim 1, wherein It further comprises: Multiple AI acceleration cards; The AI acceleration cards are connected to the device passthrough module of the security processor; Between the AI large model application of the TEE and the AI acceleration cards, data is exchanged through the device passthrough module.

3. The AI large model security all-in-one machine according to claim 1, characterized in that, The security processor has a remote authentication module; The remote authentication module realizes the remote authentication of the authenticity of the TEE through message interaction with the client.

4. The AI large model security all-in-one machine according to claim 1, characterized in that, A database is established in each TEE for storing identity authentication information; During the process of establishing a secure channel between the AI large model application and the client, the identity of the client is authenticated based on the identity authentication information stored in the database of the TEE to which the AI large model application belongs.

5. The AI large model security all-in-one machine according to claim 4, characterized in that, The AI large model application has a public key for establishing a secure channel with the client; The public key of the AI large model application is generated by the security processor based on the hardware trusted root, and the public keys of the AI large model applications in different TEEs are different.

6. A method for establishing a secure channel, characterized in that, The AI large model application in the TEE of the AI large model security all-in-one machine according to any one of claims 1-5 comprises: The AI large model application confirms the establishment information for establishing a secure channel through message interaction with the client; Receives the identity certificate sent by the client, and the identity certificate carries the identity authentication information for identity authentication; Authenticates the identity of the client by comparing the identity authentication information carried in the identity certificate with the identity authentication information stored in the database of the TEE to which the AI large model application belongs; After the identity authentication of the client is passed, a token is sent to the client, and the token is used to be carried in the data packet sent by the client to the AI large model application; Through message interaction with the client, based on the confirmed establishment information and the public key of the AI large model application, a session key is generated using a key exchange algorithm. The session key is used for encrypted communication between the AI large model application and the client. The public key of the AI large model application is generated by the security processor based on the hardware trusted root, and the public keys of the AI large model applications in different TEEs are different.

7. A method for establishing a secure channel, characterized in that, Applied to a client located outside the AI large model security all-in-one machine according to any one of claims 1-5, it comprises: Confirms the establishment information for establishing a secure channel through message interaction with the AI large model application in the TEE; Send an identity certificate to the AI large model application. The identity authentication information for identity authentication is carried in the identity certificate, so that the AI large model application authenticates the identity of the client by comparing the identity authentication information carried in the identity certificate with the identity authentication information stored in the database of the TEE to which the AI large model application belongs; Receive the token sent by the AI large model application to the client after the identity authentication of the client is passed. The token is used to be carried in the data packet sent by the client to the AI large model application; Through message interaction with the AI large model application, based on the confirmed establishment information and the public key of the AI large model application, generate a session key using a key exchange algorithm. The session key is used for encrypted communication between the AI large model application and the client. The public key of the AI large model application is generated by the secure processor based on the hardware trusted root, and the public keys of AI large model applications in different TEEs are different.

8. A secure channel establishment device, characterized in that, The AI large model application in the TEE of the AI large model security all-in-one machine according to any one of claims 1-5 includes: The first establishment information confirmation module is used to confirm the establishment information for establishing a secure channel through message interaction with the client; The certificate receiving module is used to receive the identity certificate sent by the client. The identity authentication information for identity authentication is carried in the identity certificate; The identity authentication module is used to authenticate the identity of the client by comparing the identity authentication information carried in the identity certificate with the identity authentication information stored in the database of the TEE to which the AI large model application belongs; The token sending module is used to send a token to the client after the identity authentication of the client is passed. The token is used to be carried in the data packet sent by the client to the AI large model application; The first session key generation module is used to generate a session key using a key exchange algorithm through message interaction with the client, based on the confirmed establishment information and the public key of the AI large model application. The session key is used for encrypted communication between the AI large model application and the client. The public key of the AI large model application is generated by the secure processor based on the hardware trusted root, and the public keys of AI large model applications in different TEEs are different.

9. A secure channel establishment device, characterized in that, The client located outside the AI large model security all-in-one machine according to any one of claims 1-5 includes: The second establishment information confirmation module is used to confirm the establishment information for establishing a secure channel through message interaction with the AI large model application in the TEE; The certificate sending module is used to send an identity certificate to the AI large model application. The identity authentication information for identity authentication is carried in the identity certificate, so that the AI large model application authenticates the identity of the client by comparing the identity authentication information carried in the identity certificate with the identity authentication information stored in the database of the TEE to which the AI large model application belongs; A token receiving module, configured to receive a token sent by the AI large model application to the client after the authentication of the client is passed, where the token is used to be carried in the data packet sent by the client to the AI large model application; A second session key generation module, configured to generate a session key through message interaction with the AI large model application, based on the confirmed establishment information and the public key of the AI large model application, using a key exchange algorithm. The session key is used for encrypted communication between the AI large model application and the client. The public key of the AI large model application is generated by the security processor based on the hardware trusted root, and the public keys of the AI large model applications in different TEEs are different.

10. An electronic device, characterized in that, It includes a processor and a machine-readable storage medium. The machine-readable storage medium stores machine-executable instructions that can be executed by the processor. The processor is urged by the machine-executable instructions to implement the method recited in claim 6, or to implement the method recited in claim 7.

11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the method recited in claim 6, or implements the method recited in claim 7.

Citation Information

Patent Citations

  • Data processing accelerator having security unit to provide root trust services

    CN112262547A

  • Application release method, application use method, AI model release method and AI model release device

    CN113849777A

  • Method and terminal for protecting model in computing rod

    CN114168981A

  • Data trusted execution method and device based on central computing platform

    CN115600190A

  • Artificial intelligence model operation security trusted execution environment architecture and method

    CN117786694A

Cited By

  • Large model service security verification method and device, medium, equipment and product

    CN121309223A

  • Security verification method and device of large model service, medium, equipment and product

    CN121309223B

  • Industrial large model deployment method, operation method, device and all-in-one machine equipment

    CN121727741A

  • A method, operation method, device, and integrated equipment for deploying large-scale industry models

    CN121727741B