Processing method, device and system
By configuring a secure storage space in the storage device and using an encryption and decryption engine to interact with the AI model for secure interaction, the problem of data leakage during the processing of the AI model is solved, and the secure storage and processing of data is realized, improving the security and reliability of the model.
Patent Information
- Application Number
- CN202510397565.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-07-18
AI Technical Summary
How to ensure the security and reliability of data during the processing of AI model and prevent data breaches, especially when it involves personal privacy and secure data.
By configuring the controller of the storage device, the storage space of the target model is set as a secure storage space, and the processor's encryption and decryption engine is used to securely interact with the target model in the secure storage space to ensure encrypted transmission and processing of data.
Improve the processing security and reliability of AI models, preventing data leakage during transmission, storage and processing, especially when private data is involved, reducing the probability of data being stolen.
Smart Images

Figure CN120337249A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of processing technology, and relates to but is not limited to a processing method, device and system. Background Art
[0002] With the continuous development of Artificial Intelligence (AI) technology, AI models have been widely used in various fields.
[0003] A large amount of data is required during the processing of AI models, and data leakage may occur. How to perform AI model processing safely and reliably has become an urgent problem to be solved. Summary of the Invention
[0004] At least one processing method, device and system are provided in the embodiments of this application. The technical solution of this application is implemented as follows:
[0005] In a first aspect, this application provides a processing method, including:
[0006] The controller of the storage device configures the storage device to use the storage space for caching the target model as a secure storage space;
[0007] Load the target model into the secure storage space of the storage device;
[0008] The encryption and decryption engine of the processor performs secure interaction with the target model in the secure storage space.
[0009] In a second aspect, this application provides a processing device, and the device includes:
[0010] A configuration unit, configured to configure the storage device by the controller of the storage device to use the storage space for caching the target model as a secure storage space;
[0011] A loading unit, configured to load the target model into the secure storage space of the storage device;
[0012] An interaction unit, configured to perform secure interaction between the encryption and decryption engine of the processor and the target model in the secure storage space.
[0013] In a third aspect, this application provides an electronic device, and the electronic device includes: a storage unit, a controller of the storage unit, a processor, and an encryption and decryption engine of the processor; the memory includes a secure storage space and a non-secure storage space;
[0014] The controller of the storage unit is used to: configure the storage unit to use the storage space for caching the target model as a secure storage space;
[0015] The processor is used to: load the target model into the secure storage space of the storage device;
[0016] The encryption and decryption engine of the processor is used to: securely interact with the target model in the secure storage space.
[0017] In a fourth aspect, the present application provides a processing system, including a plurality of electronic devices;
[0018] Through secure interaction between the plurality of electronic devices, a target processing result is obtained; wherein, when the plurality of electronic devices perform secure interaction, the interaction data is encrypted by the encryption and decryption engine of the processor of the electronic device and then interacted. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 It is the first optional flowchart of the processing method provided by the embodiment of the present application;
[0020] Figure 2 It is the second optional flowchart of the processing method provided by the embodiment of the present application;
[0021] Figure 3 It is the third optional flowchart of the processing method provided by the embodiment of the present application;
[0022] Figure 4 It is the fourth optional flowchart of the processing method provided by the embodiment of the present application;
[0023] Figure 5 It is the fifth optional flowchart of the processing method provided by the embodiment of the present application;
[0024] Figure 6 It is the sixth optional flowchart of the processing method provided by the embodiment of the present application;
[0025] Figure 7 It is the seventh optional flowchart of the processing method provided by the embodiment of the present application;
[0026] Figure 8 It is the eighth optional flowchart of the processing method provided by the embodiment of the present application;
[0027] Figure 9 It is the ninth optional flowchart of the processing method provided by the embodiment of the present application;
[0028] Figure 10 It is an optional structural schematic diagram of the model deployment of the Internet of Things system provided by the embodiment of the present application;
[0029] Figure 11 It is an optional flowchart of the generation process of the encryption and decryption engine key provided by the embodiment of the present application;
[0030] Figure 12An optional structural diagram of the encryption and decryption process of the memory area provided by the embodiments of the present application;
[0031] Figure 13 An optional structural diagram of the processing process of the model provided by the embodiments of the present application;
[0032] Figure 14 An optional structural diagram of the processing system of the AI model provided by the embodiments of the present application;
[0033] Figure 15 Another optional structural diagram of the processing system of the AI model provided by the embodiments of the present application;
[0034] Figure 16 Yet another optional structural diagram of the processing system of the AI model provided by the embodiments of the present application;
[0035] Figure 17 An optional structural diagram of the processing device provided by the embodiments of the present application. Detailed implementation manners
[0036] To make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the following will further describe the specific technical solutions of the application in detail in combination with the accompanying drawings in the embodiments of the present application. The following embodiments are used to illustrate the present application but not to limit the scope of the present application.
[0037] In the following description, reference is made to "some embodiments", which describe a subset of all possible embodiments. However, it can be understood that "some embodiments" can be the same subset or different subsets of all possible embodiments, and can be combined with each other without conflict.
[0038] In the following description, the terms "first / second / third" are only used to distinguish different objects, and do not represent a specific order for the objects, and there is no limitation on the order. It can be understood that "first / second / third" can be interchanged with a specific order or sequence when allowed, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein.
[0039] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of the present application and are not intended to limit the present application.
[0040] Embodiments of the present application may provide a processing method, apparatus, device, system, storage medium, and computer program product. In practical applications, the processing method may be implemented by a processing device, and each functional entity in the processing device may be jointly implemented by hardware resources of an electronic device, such as computing resources of a processor, etc., and communication resources (such as various communication methods for supporting the implementation of optical cables, cellular networks, etc.).
[0041] The target model disclosed in the embodiments of the present application is a machine learning model that can identify natural language and / or other inputs (such as audio-visual, images, tables, etc.) input into the target model, and perform comprehensive language processing tasks such as semantic analysis and answering questions, and then generate an output related to the input and / or respond to the input.
[0042] The target model disclosed in the embodiments of the present application learns the characteristics and rules of natural language by training a large amount of diverse data, so as to be able to understand and generate natural language. It usually has model parameters in the hundreds of millions to hundreds of billions (model parameters are variables that control the behavior of the target model), and can capture complex relationships and patterns in natural language.
[0043] The target model disclosed in the embodiments of the present application may be a generative model, a generative language model (GLMs). For example, it may specifically include large language models (LLMs), GPT (Generative Pre-trained Transformer), or deepsick, etc. The target model involved in the embodiments of the present application may be a general large model, or an expert large model obtained by fine-tuning based on requirements. The embodiments of the present application do not make any limitations in this regard. Among them, when the target model disclosed in the embodiments of the present application runs in response to a call instruction and the input data being processed involves at least one of the following: data in a personal knowledge base, data in a personal long-term memory base, security data, or privacy data, it is processed according to the following method.
[0044] In a first aspect, embodiments of the present application provide a processing method.
[0045] Reference Figure 1 As shown in the content, the processing method of Embodiment 1 may include but is not limited to Figure 1 S101 to S103 shown in
[0046] S101. The controller of the storage device configures the storage device to cache the storage space of the target model as a secure storage space.
[0047] The embodiments of this application do not limit the type of the target model, which can be configured according to actual requirements. The target model here can be any AI model. For example, the target model can be a large language model, a neural network model, etc.
[0048] The storage space here can be the memory of the processor. The secure storage space can be an encrypted memory space. The controller of the storage device can be a memory controller.
[0049] The embodiments of this application do not limit the size of the secure storage space used to cache the target model. It can be configured according to actual requirements.
[0050] In a possible implementation, the secure storage space can also be divided into multiple secure sub-spaces. For example, the secure storage space can be divided into one or more of the following: code sub-space, data sub-space, input sub-space, temporary sub-space, etc. The code sub-space is used to store the code algorithm library of the target model; the data sub-space is used to store the weight parameters of the target model; the input sub-space is used to store the input data of the target model; the temporary sub-space is used to store some data temporarily generated by the target model. Of course, other sub-spaces can also be included, such as the output sub-space, etc., which will not be listed one by one here.
[0051] Of course, the inside of the secure storage space can also not be divided, and it is specifically configured according to actual requirements.
[0052] In a possible implementation, S101 can be implemented as: the controller of the storage device first determines the size of the storage space of the target model, then applies for a secure space in the encrypted secure storage space that meets the size of the storage space of the target model, and binds the secure space to the target model, so as to determine that the secure space is the space for caching the target model.
[0053] In another possible implementation, S101 can be implemented as: the controller of the storage device first determines the size of the storage space of the target model, then applies for a space in the storage space that meets the size of the storage space of the target model, then encrypts the space to obtain a secure storage space, and binds the secure space to the target model, so as to determine that the secure space is the space for caching the target model.
[0054] For example, the controller of the storage device can configure the secure storage space by means of a memory page table.
[0055] S102. Load the target model into the secure storage space of the storage device.
[0056] S102 can be implemented as: The processor loads the target model into the secure storage space of the storage device. For example, the processor accesses the memory page table, reads the address of the secure storage space for storing the target model in the memory page table, and then stores the relevant data of the target model into the storage space pointed to by this address.
[0057] S103. The encryption / decryption engine of the processor performs secure interaction with the target model in the secure storage space.
[0058] The processor here may include, but is not limited to: Central Processing Unit (CPU), Graphics Processing Unit (GPU), Neural Network Processing Unit (NPU).
[0059] The encryption / decryption engine is integrated in the processor. The encryption / decryption engine can be a circuit or a chip for performing encryption and decryption. The present application embodiment does not limit the processing logic of the encryption / decryption engine, and it can be configured according to actual requirements.
[0060] In a possible implementation manner, the encryption / decryption engine here can be a chip integrated with symmetric encryption and decryption algorithms. In another possible manner, the encryption / decryption engine here can be a chip integrated with asymmetric encryption and decryption algorithms. Of course, the encryption / decryption engine can also integrate symmetric encryption and decryption algorithms and asymmetric encryption and decryption algorithms at the same time.
[0061] S103 can be implemented as: The encryption / decryption engine of the processor performs secure interaction with the target model in the secure storage space.
[0062] The encryption / decryption engine of the processor decrypts the data in the secure storage space, reads the calculation instructions required by the target processing, then performs various calculations based on the calculation instructions, decrypts the calculation results through the encryption / decryption engine and stores them in the secure storage space, and realizes the secure interaction between the encryption / decryption engine and the target model through such a cycle.
[0063] The present application embodiment does not limit the execution timing of S103, and it can be configured according to actual requirements. For example, based on the running instruction of the target model for the electronic device, the encryption / decryption engine of the processor can be executed to perform secure interaction with the target model in the secure storage space, so as to realize the relevant processing of the target model. For example, after receiving the ciphertext input, since the processing process of the ciphertext requires implementing relevant data protection, S103 can be directly triggered to start.
[0064] A processing method provided by an embodiment of the present application at least includes: the controller of the storage device configures the storage space of the storage device for caching the target model as a secure storage space; loads the target model into the secure storage space of the storage device; and the encryption and decryption engine of the processor performs secure interaction with the target model in the secure storage space.
[0065] It can be seen that the storage space for storing the target model is a secure storage space, and the operation of the target model is realized based on the interaction between the encryption and decryption engine and the target model in the secure storage space. The interaction process is secure, so the operation and processing process of the target model is secure, thereby realizing the secure storage and operation of the target model, and improving the reliability and security of the target model processing.
[0066] The processing method provided by an embodiment of the present application may further include the configuration process of the secure storage space. Next, this processing process will be described in combination with the configuration process of the secure storage space. In one possible embodiment, referring to Figure 2 the content shown, the process of Embodiment 2 may include but is not limited to the following S201 to S203.
[0067] S201: Write an identification value in the target storage space of the storage device.
[0068] The identification value is used to indicate that the storage space required by the target model is a secure storage space.
[0069] The embodiment of the present application does not limit the position of the identification value. For example, a two-digit numerical space can be customized in the memory page table for writing the flag value. The embodiment of the present application does not limit the specific value of the identification value, which can be configured according to actual needs. For example, the identification value here can be 0x01.
[0070] In this way, when the processor loads the target model, detecting this identification value can sense that the target model needs to be written into the secure storage space.
[0071] S202: Load the target model into the secure storage space of the storage device.
[0072] When the processor detects this identification value in the target storage space, it loads the target model into the secure storage space of the storage device.
[0073] If the processor does not detect this identification value, it loads the target model into the non-secure storage space as an ordinary model.
[0074] S203: The processor reads the identification value and performs secure interaction with the target model based on the encryption and decryption engine of the processor.
[0075] The processor reads this identification value and performs secure interaction with the target model based on the encryption and decryption engine of the processor.
[0076] If the processor does not detect the identification value, the target model is directly interacted with the processor as an ordinary model.
[0077] In this embodiment, the secure storage and secure interaction of the target model are realized by writing the identification value in the target storage space, and the security is relatively high. And this embodiment can perform ordinary storage and interaction on the target model without the identification value. In this way, the usage requirements of two scenarios can be met, that is, for the target model that needs to be encrypted, the identification value is configured to realize secure storage and secure interaction, and for the ordinary target model, normal storage and interaction can also be realized. The usage scenario is wide, and the problem of resource waste caused by using secure storage and secure interaction for all models is avoided.
[0078] The processing method provided by the embodiment of the present application may further include a process in which the processor reads the identification value and performs secure interaction with the target model based on the encryption and decryption engine of the processor.
[0079] In some embodiments, referring to Figure 3 the content shown, Embodiment 3 may include but is not limited to the following S301 to S304.
[0080] S301. Write an identification value in the target storage space of the storage device.
[0081] The implementation of S301 may refer to the detailed description of writing the identification value in the target storage space of the storage device in S201, and will not be elaborated here one by one.
[0082] S302. Load the target model into the secure storage space of the storage device.
[0083] The implementation of S302 may refer to the detailed description of loading the target model into the secure storage space of the storage device in S202, and will not be elaborated here one by one.
[0084] S303. The processor reads the identification value, and the computing unit of the processor obtains the computing instruction of the target model in response to the encryption and decryption engine.
[0085] The computing instruction here is various instructions required during the operation of the model.
[0086] When the processor reads the identification value, it calls the encryption and decryption engine, and the computing unit of the processor obtains the computer instruction of the target model from the secure storage space through the encryption and decryption engine.
[0087] Further, after the computing unit of the processor obtains the computing instruction of the target model, it performs relevant calculations to complete the processing of the target model, thereby obtaining a calculation result.
[0088] S304. The processor reads the identification value, and the processor writes the calculation result into the secure storage space of the target model through the encryption and decryption engine.
[0089] The calculation result is the processing result of the target model obtained based on the instruction calculation.
[0090] When the processor reads the identification value, it calls the encryption and decryption engine to encrypt the calculation result and write it into the secure storage space of the target model.
[0091] In this embodiment, during the interaction between the encryption and decryption engine and the target model, the process of obtaining computer instructions is implemented through the encryption and decryption engine, which ensures the security of instruction acquisition. The writing of the calculation result is also implemented through the encryption and decryption engine, thereby ensuring that the execution process of each instruction during the operation of the target model is secure and reliable. In this embodiment, the encryption and decryption engine is integrated into the processor, which can further improve the security of the interaction process.
[0092] The processing process provided by the embodiment of the present application may further include the process in which the calculation unit of the processor responds to the encryption and decryption engine to obtain the calculation instruction of the target model. In some embodiments, referring to Figure 4 the content shown, Embodiment 4 may include but is not limited to the following S401 to S405.
[0093] S401. Write the identification value into the target storage space of the storage device.
[0094] The implementation of S401 can refer to the detailed description of writing the identification value into the target storage space of the storage device in S201, and will not be elaborated here one by one.
[0095] S402. Load the target model into the secure storage space of the storage device.
[0096] The implementation of S402 can refer to the detailed description of loading the target model into the secure storage space of the storage device in S202, and will not be elaborated here one by one.
[0097] S403. The processor reads the identification value and decrypts the secure storage space through the encryption and decryption engine.
[0098] When the processor reads the identification value, it can determine that the target model is stored in the secure storage space, so it will first call the encryption and decryption engine to decrypt the secure storage space.
[0099] In the embodiment of the present application, the encryption and decryption logic and algorithms in the encryption and decryption engine are not limited and can be configured according to actual needs.
[0100] The embodiments of the present application do not limit the encryption and decryption keys in the encryption and decryption engine, and can be configured according to actual requirements. For example, the encryption and decryption keys here can be public keys. For example, encryption can be performed with a key and decryption can be performed with a public key, or encryption can be performed with a public key and decryption can be performed with a private key.
[0101] S404. The computing unit of the processor reads the computing instructions of the target model from the secure storage space.
[0102] After decryption, the computing unit of the processor can read the instructions in the secure storage space, so as to obtain the computing instructions of the target model.
[0103] Further, after the computing unit of the processor obtains the computing instructions of the target model, relevant calculations are performed to complete the processing of the target model, thereby obtaining a calculation result.
[0104] S405. The processor reads the identification value, and the processor writes the calculation result into the secure storage space of the target model through the encryption and decryption engine.
[0105] For the implementation of S405, reference can be made to the detailed description in S304 where the processor reads the identification value and the processor writes the calculation result into the secure storage space of the target model through the encryption and decryption engine, and details are not described herein one by one.
[0106] In this embodiment, when obtaining the computer instructions of the target model, first decrypt through the encryption and decryption engine, and then read the computer instructions of the target model. It can be seen that the instructions of the target model cannot be read casually and need to be decrypted by the encryption and decryption engine. The encryption and decryption engine performs encryption through hardware and cannot be cracked by software programs, reducing the probability of the target model instructions being stolen and improving the security of the target model.
[0107] The processing process provided by the embodiments of the present application may further include the process of the processor writing the calculation result into the secure storage space of the target model through the encryption and decryption engine. In some embodiments, referring to Figure 5 the content shown, Embodiment 5 may include but is not limited to the following S501 to S506.
[0108] S501. Write an identification value into the target storage space of the storage device.
[0109] For the implementation of S501, reference can be made to the detailed description in S201 of writing an identification value into the target storage space of the storage device, and details are not described herein one by one.
[0110] S502. Load the target model into the secure storage space of the storage device.
[0111] For the implementation of S502, reference can be made to the detailed description in S202 of loading the target model into the secure storage space of the storage device, and details are not described herein one by one.
[0112] S503. The processor reads the identification value, and the computing unit of the processor responds to the encryption and decryption engine to obtain the computing instruction of the target model.
[0113] For the implementation of S503, reference can be made to the detailed description of S303 or (S403 and S404), which will not be elaborated here one by one.
[0114] S504. The processor sends the unencrypted computing result to the encryption and decryption engine.
[0115] The processor sends the computing result to the encryption and decryption engine through the hardware connection relationship between the computing unit and the encryption and decryption engine.
[0116] S505. The encryption and decryption engine encrypts the unencrypted computing result to obtain the encrypted computing result.
[0117] The encryption and decryption engine encrypts the unencrypted computing result with a key to obtain the encrypted computing result.
[0118] In the embodiments of the present application, the encryption key of the encryption and decryption engine is not limited and can be configured according to actual needs.
[0119] S506. Write the encrypted computing result into the secure storage space of the target model.
[0120] The processor writes the encrypted computing result into the secure storage space of the target model.
[0121] In this embodiment, when writing the computing result, it is first encrypted by the encryption and decryption engine, and then the encrypted computing result is written into the secure storage space. It can be seen that the write instruction of the target model cannot be read casually, the written computing result is encrypted by the encryption and decryption engine, and the encryption and decryption engine encrypts through hardware and cannot be cracked by a software program, reducing the probability of the written result of the target model being stolen and improving the security of the target model.
[0122] It should be noted that if the encryption and decryption engine adopts the Advanced Encryption Standard (AES). Since AES is a symmetric encryption and decryption algorithm. It can directly operate on the ciphertext. In this way, the processor can directly obtain the encrypted computer instruction in the secure storage space, and then operate on the encrypted computing instruction to obtain the encrypted result, and write the encrypted result into the secure storage space. In the case of needing to read the content, the encryption and decryption engine is called to decrypt the computing result. In this way, the entire processing process is encrypted and is hardware encryption and cannot be cracked by software, thus realizing the full encryption operation of the target model and having high security.
[0123] The processing method provided by the embodiments of this application can be applied to the privacy data scenario. Refer to Figure 6 the content shown in
[0124] S601. If the calculation of the target model involves privacy data, configure the storage space of the storage device used to cache the target model as a secure storage space.
[0125] Privacy data refers to data that is not desired to be obtained by other users or devices. The embodiments of this application do not limit the type of privacy data, which can be configured according to actual needs.
[0126] For example, privacy data can include but is not limited to: user personal information, transaction information, health information, medical information, device address information, location behavior information, education and work information, etc.
[0127] The controller of the storage device first determines whether the calculation of the target model involves privacy data. If the calculation of the target model involves privacy data, configure the storage space of the storage device used to cache the target model as a secure storage space.
[0128] The configuration process can refer to the description in S101 and will not be elaborated here one by one.
[0129] If it is determined that the calculation of the target model does not involve privacy data, the target model can be stored in a general storage space.
[0130] The situation where the calculation of the target model involves privacy data here can include: the input of the target model includes privacy data and / or the processing process of the target model requires privacy data, etc.
[0131] S602. Load the target model into the secure storage space of the storage device.
[0132] The implementation of S602 can refer to the detailed description of loading the target model into the secure storage space of the storage device in S102 and will not be elaborated here one by one.
[0133] S603. The encryption and decryption engine of the processor performs secure interaction with the target model in the secure storage space.
[0134] The implementation of S603 can refer to the detailed description of the encryption and decryption engine of the processor performing secure interaction with the target model in the secure storage space in S103 and will not be elaborated here one by one.
[0135] In this implementation, only when the calculation of the target model involves privacy data, the secure storage space is configured. For the target model that does not involve privacy data, it can still be implemented through a non-secure storage space. On the basis of protecting the user's privacy data, resources can be reasonably configured and utilized to prevent resource waste.
[0136] The processing method provided by the embodiment of the present application can also receive the input from the client, and refer to Figure 7 the content shown. This process may include but is not limited to the following S701 to S705.
[0137] S701. Receive the first input data sent by the client device.
[0138] The sending here can be wired sending or wireless sending.
[0139] The above-mentioned electronic device is used for model processing and is equivalent to a model-side device. The client device can be a device that sends input data and requests the model-side to perform model processing. The client device here can be a smart wearable device (such as a smart watch, smart glasses, etc.), a mobile device (such as a mobile phone, tablet, etc.).
[0140] The model-side device can include but is not limited to: mobile phones, computers, servers, etc.
[0141] The first input data is the data that needs to be input into the target model for processing. The embodiment of the present application does not limit the content of the first input data, which can be configured according to actual needs.
[0142] The electronic device receives the first input data sent by the client device through the connection relationship with the client device.
[0143] S702. If the first input data is the ciphertext input of the target model, store the ciphertext input in the secure storage space.
[0144] After receiving the first input data, the electronic device first determines whether the first input data is ciphertext. If it is determined that the first input data is ciphertext, store the ciphertext in the secure storage space. If the first input data is not ciphertext, store the first input data in the non-secure storage space.
[0145] The secure storage space here is used to store the relevant data of the target model. In the case where the subspaces of the secure storage space are divided, the first input data can be stored in the subspace of the secure storage space for storing input data.
[0146] S703. The controller of the storage device configures the storage device to use the storage space for caching the target model as the secure storage space.
[0147] The implementation of S703 can refer to the detailed description of loading the target model into the secure storage space of the storage device in S102, which will not be elaborated here one by one.
[0148] S704. Load the target model into the secure storage space of the storage device.
[0149] The implementation of S704 can refer to the detailed description of the secure interaction between the encryption / decryption engine of the processor and the target model in the secure storage space in S103, which will not be elaborated here one by one.
[0150] In S705, the encryption / decryption engine of the processor performs secure interaction with the target model in the secure storage space and the first input data.
[0151] The encryption / decryption engine of the processor first performs secure interaction with the first input data to obtain the unencrypted input data, and then interacts with the instructions of the target model to obtain the unencrypted model calculation instructions, so that the processor calculates the input data according to the calculation instructions of the target model to obtain the calculation result; and encrypts the calculation result through the encryption / decryption engine to obtain the target calculation result, and stores the target calculation result in the secure storage space.
[0152] In this implementation, not only the security of the processing process of the target model is realized. Since the input data is ciphertext, the possibility of data leakage during data transmission is reduced. Storing the ciphertext in the secure storage space reduces the possibility of data leakage during storage. The processing process of the input data is realized through the encryption / decryption engine, reducing the possibility of data leakage during processing. Processing from all aspects of data transmission, data storage, and data processing improves the security of target model processing.
[0153] The processing method provided by the embodiments of the present application can also perform output at the user end. Refer to Figure 8 the content shown. This process may include but is not limited to the following S801 to S805.
[0154] In S801, the controller of the storage device configures the storage space of the storage device for caching the target model as a secure storage space.
[0155] The implementation of S801 can refer to the detailed description of the controller of the storage device in S101 configuring the storage space of the storage device for caching the target model as a secure storage space, which will not be elaborated here one by one.
[0156] In S802, the target model is loaded into the secure storage space of the storage device.
[0157] The implementation of S802 can refer to the detailed description of loading the target model into the secure storage space of the storage device in S102, which will not be elaborated here one by one.
[0158] In S803, the encryption / decryption engine of the processor performs secure interaction with the target model in the secure storage space.
[0159] The implementation of S803 can refer to the detailed description of the secure interaction between the encryption / decryption engine of the processor and the target model in the secure storage space in S103, which will not be elaborated here one by one.
[0160] S804. Determine the processing result of the target model based on the secure interaction between the encryption / decryption engine of the processor and the target model.
[0161] The processor can obtain the processing result of the target model through the secure interaction between the computing unit and the encryption / decryption engine.
[0162] The processing result here can be the final processing result of the target model or the intermediate processing result of the target model.
[0163] If it is the final processing result, it is output to the user device; if it is the intermediate processing result, it is sent to other electronic devices for further processing until the final processing result is obtained and then sent to the user device.
[0164] S805. In the case where the processing result of the target model includes private data, encrypt the processing result through the encryption / decryption engine and output it to the user device.
[0165] The processor first determines whether the processing result includes private data. If it is determined that the processing result includes private data, the processing result is encrypted through the encryption / decryption engine and output to the user device; if the processing result does not include private data, the processing result is directly sent to the user device.
[0166] In this embodiment, not only the security of the processing process of the target model is realized, but also in the case where the processing result includes private data, the processing result is encrypted through the encryption / decryption engine, reducing the possibility of the processing result being leaked, and processing from all aspects of the output transmission of the processing result and the processing of the model, thereby improving the security of the target model processing.
[0167] The processing method provided by the embodiment of the present application may further include the generation process of the key of the encryption / decryption engine. Refer to Figure 9 the content shown, and this process may include but is not limited to the following S901 to S907.
[0168] S901. The controller of the storage device configures the storage device to cache the storage space of the target model as a secure storage space.
[0169] The implementation of S901 can refer to the detailed description of the controller of the storage device in S101 configuring the storage device to cache the storage space of the target model as a secure storage space, which will not be elaborated here one by one.
[0170] S902. Load the target model into the secure storage space of the storage device.
[0171] The implementation of S902 can refer to the detailed description of loading the target model into the secure storage space of the storage device in S102, which will not be elaborated here one by one.
[0172] S903: Receive the first encrypted random number sent by the client device.
[0173] The first random number is obtained by the client device based on a random algorithm.
[0174] The electronic device receives the first encrypted random number sent by the client device through the connection relationship with the client device.
[0175] In this way, the security during the transmission of the random number can be improved.
[0176] S904: Perform ciphertext processing on the first encrypted random number with the key of the client device to obtain the first random number.
[0177] Previously, the client device will send its own key to other electronic devices.
[0178] For example, each device can establish a key pool for storing keys (such as public keys) of other devices, as well as other keys, etc.
[0179] In the embodiments of the present application, the storage location of the key pool is not limited and can be configured according to actual needs. In a possible implementation manner, the key pool can be stored in a special register, and the content of the special register cannot be randomly called by software. Therefore, the security of the key is improved.
[0180] The electronic device obtains the key of the client device and performs ciphertext processing on the first encrypted random number with this key to obtain the first random number.
[0181] S905: Determine the session identifier of the first session.
[0182] The first session is a session sent by the client device for triggering the secure interaction between the encryption / decryption engine and the target model.
[0183] Generally, a session will have a unique session identifier.
[0184] The first session here is the request session of the client device.
[0185] For example, if the client device needs to predict the weather tomorrow, it will send a date and a location to the electronic device to establish a session, and at the same time generate a session identifier. The electronic device will trigger the secure interaction between the encryption / decryption engine and the target model based on this date and location to determine the weather tomorrow. Then the electronic device can read the identifier of this session.
[0186] S906. Process the session identifier and the first random number through a key generation algorithm to obtain the key of the encryption and decryption engine.
[0187] The embodiments of this application do not uniquely define the key generation algorithm, which can be configured according to actual requirements.
[0188] For example, the key generation algorithm here can be a Key Derivation Function (KDF).
[0189] Since the key of the encryption and decryption engine is generated based on the session identifier and the first random number, when the session ends, the key will become invalid. The key is only valid during the session device, reducing the possibility of the key being stolen, and the random number method reduces the possibility of the key being cracked.
[0190] S907. The encryption and decryption engine of the processor performs secure interaction with the target model in the secure storage space.
[0191] For the implementation of S907, reference can be made to the detailed description of the secure interaction between the encryption and decryption engine of the processor and the target model in the secure storage space in S103, which will not be elaborated here one by one.
[0192] In this embodiment, the key of the encryption and decryption engine is generated through the random number of the session. When the session ends, the key will become invalid, reducing the possibility of the key being stolen, and the key is generated through the random number, reducing the possibility of being cracked; thus improving the reliability of the encryption and decryption process of the encryption and decryption engine and enhancing the security of the model.
[0193] Next, taking the model processing of the Internet of Things (IoT) system as an example, this processing process will be described.
[0194] When and most of the AI systems supported by mobile terminals in the industry (including traditional deep learning and current generative AI) can be summarized into the following three models: large cloud models, considering the computing power bottleneck and the model operation / prediction requirements, deploy the AI model on the remote cloud service platform (especially the public cloud); large edge models, place the available computing units (including large AI models) on the mobile edge side; hybrid, the mobile phone runs some models with simple computing power requirements, and the cloud runs large models and processes user data.
[0195] In the above scenarios, the process of extracting and parsing user data faces the risk of being leaked.
[0196] In the IoT device interconnection scenario, it is mainly based on: interacting with the mobile phone side, after the IoT device collects data, it uniformly hands it over to the mobile phone to complete the model operation and data processing; the mobile phone side even schedules the data to the large cloud model.
[0197] In this way, users are unaware of the transfer and use of data, which may lead to a great deal of user privacy or leakage of sensitive device data; the mobile device cannot complete model operations, resulting in the forced migration of IoT sensitive data to the remote end, bringing about data being cached, stolen, or even used for subsequent training by the model provider; the mobile device cannot securely callback the AI algorithms or models of IoT devices (such as smartwatches, fitness trackers, smart glasses, etc.). If there are vulnerabilities in the peripheral interfaces of IoT devices for privilege escalation, the data of mobile device users can also be misused.
[0198] The model deployment structure of the IoT system can refer to Figure 10 the content shown in the figure, including: the cloud 1001, the mobile device 1002, and the IoT device 1003. The IoT device 1003 can include: the smartwatch 1003A, the fitness tracker 1003B, the smart glasses 1003C, and so on.
[0199] The mobile device 1002 can include: the first security client 10021, the first AI model 10022, the first encrypted memory 10023, and the first key pool 10024.
[0200] The smartwatch 1003A, the fitness tracker 1003B, and the smart glasses 1003C included in the IoT device 1003 can all include: the second security client 10031, the second AI model 10032, the second encrypted memory 10033, and the second key pool 10034.
[0201] Among them, encrypted transmission occurs between the cloud 1001 and the mobile device 1002, so sensitive user inputs or sensitive outputs of the model cannot be parsed from the cloud.
[0202] Encrypted transmission occurs between the mobile device 1002 and the IoT device 1003. Encrypted transmission also occurs between the smartwatch 1003A, the fitness tracker 1003B, and the smart glasses 1003C, thus building a secure IoT system.
[0203] First, establish a trusted channel and set the session key for the encryption and decryption engine. This process can include but is not limited to the following steps A1 to A4.
[0204] Step A1: Adopt the Pretty Good Privacy (PGP) protocol. Each IoT device and the mobile device share the keys of each other through the security client. These keys are all generated when the user first creates the distributed AI system; when a new IoT device needs to be added to the distributed system, the key of the new IoT device needs to be added by the user to any other device in the system; in this way, each device builds a PGP key pool.
[0205] Step A2: When the AI session is established, the device operated by the user first distributes a random number (Random Number Generator, RNG), encrypts it using the PGP key of the device, and then broadcasts it to any other connected devices.
[0206] Step A3: Based on step 2, other devices select a matching key from the PGP key pool for decryption to obtain the session random number at this time.
[0207] Step A4: After that, each device obtains the same random number, and combines it with the session identifier (session, ID) at this time, and uses the KDF algorithm to derive the same memory encryption and decryption engine key.
[0208] The generation process of the encryption and decryption engine key can refer to Figure 11 the content shown, including but not limited to the following S1101 to S1107.
[0209] S1101: Device A generates a PGP key.
[0210] S1102: Device A shares the PGP key.
[0211] S1103: Device B adds the PGP key to the key pool.
[0212] S1104: Device A generates a random number.
[0213] S1105: Device A encrypts the random number with the PGP key and sends it to Device B.
[0214] S1106: Device B decrypts with the PGP key to obtain the RNG.
[0215] S1107: Device A and Device B each use KDF to obtain the same memory encryption engine key K.
[0216] Secondly, configure the encrypted memory of each device in the system.
[0217] Use the temporary key to encrypt and decrypt the specified physical memory area (N blocks) in a transparent manner. The so-called "temporary" means that each time a random number (RNG) dispatched by the user is superimposed with the user session to generate a key, and finally managed by the memory encryption and decryption engine. When reading and writing data in the memory storage area of the specified memory controller, the data in this memory area will be encrypted / decrypted.
[0218] The encryption and decryption process of the memory area can refer to Figure 12The content shown includes: a memory (memory) encryption and decryption engine 1201, a memory controller 1202, a processor 1203, and an encrypted memory 1204. Among them, the encrypted memory 1204 includes memory blocks 12041, 12042, and so on.
[0219] The data in the encrypted memory 1204 can also be output to peripheral devices.
[0220] When the processor 1203 has a write requirement, the memory encryption and decryption engine 1201 obtains the key, then performs an encryption operation, transfers the encrypted data to the memory controller 1202, and the memory controller 1202 encrypts the data writing process and stores it in the encrypted memory 1204.
[0221] When the processor 1203 has a read requirement, the memory controller 1202 reads data from the encrypted memory, then calls the memory encryption engine 1201, and the memory controller 1202 decrypts the data with the key, so that the processor 1203 can read the data.
[0222] The input received by the large model on the mobile phone side is the data encrypted by the memory encryption and decryption engine of the sending - end IoT device. When the mobile phone parses and uses it, processors such as the GPU can only trigger the memory encryption and decryption engine to first perform decryption and finally encrypt the model output again and write it into the corresponding memory, and finally the encrypted output is returned to the IoT device, and vice versa. Then, the AI large model uses the encrypted memory and obtains the final output.
[0223] The processing process of the model can refer to Figure 13 The content shown includes device A1301 and device B1302. Device A1301 may include: a memory encryption engine 13011, a memory controller 13012, a processor 13013, and an encrypted memory 13014. Device B1302 may include: a memory encryption engine 13021, a memory controller 13022, a processor 13023, and an encrypted memory 13024.
[0224] The data processing process may include: in the case where device A1301 needs to transfer data to device B1302, after the processor 13013 of device A1301 obtains the output transfer instruction, it instructs the memory encryption engine 13011 of device A to obtain the key, encrypts the data with the key and then transfers the data to the memory controller 13012, and the memory controller 13012 encrypts the data writing process and stores it in the encrypted memory 13014; the processor 13013 transfers the output to the encrypted memory 13024 of device B.
[0225] The processor 13023 of Device B instructs the memory controller 13022 to read the encrypted data of Device A from the encrypted memory 13024. The memory encryption engine 13021 decrypts the encrypted data based on the key. The processor 13023 processes the data to obtain the processed data. Then, the memory encryption engine 13021 encrypts the processed data based on the key. The memory controller 13022 writes the encrypted processed data into the encrypted memory 13024. The processor transfers the processed data in the encrypted memory 13024 to the encrypted memory 13014.
[0226] The processor 13013 of Device A1301 instructs the memory controller 13012 to read the processed encrypted data from the encrypted memory 13014. Then, the memory encryption engine 13011 decrypts it based on the key to obtain the processed data.
[0227] Among them, the encryption and decryption modes inside the memory encryption engine can be implemented based on AES.
[0228] Next, the principle of the AI model running in the hardware encrypted memory space will be described.
[0229] The encrypted memory space is transparent and isolated from any external SW components. The physical area corresponding to the memory space during the actual operation of the model has been configured for hardware encryption (for example, using the AES algorithm of this solution); any data parsing and inference operation processing processes of the model are controlled by the bits of the physical memory page table (Page Table Entry, PTE) of the memory encryption and decryption engine controller. Once it is activated and set to 0x01, the data processed by any operation of the processor on the memory is encrypted (written to the memory) or decrypted (read from the memory).
[0230] The processor does not need to participate in the AES encryption and decryption operations, that is, there is no need to process the encryption and decryption program instructions at the software level. All memory reads and writes are completed by the hardware, and this process is transparent to the processor.
[0231] The processor registers and the operating mode are in a secure encryption state, and any other working thread / process cannot (has no permission) access or steal the current working thread information. It is equivalent to the processor context (the processor is bound) being bound to the secure encryption configuration (pte bit = 1) for the operation of this model at this time.
[0232] The structure of the processing system of the AI model can refer to Figure 14The content shown includes: encrypted memory 1401, AES engine 1402, memory page table 1403, and processor 1404. The encrypted memory 1401 includes a model code segment 14011, a model data segment 14012, a model heap space 14013, and a model stack space 14014. The model code segment 14011 is used to store the model algorithm library, the model data segment 14012 is used to store the model weight parameters, the model heap space 14013 is used to store user input data, and the model stack space 14014 is used to store data temporarily generated by the model.
[0233] When the model is running, if the PTE is detected to be 1, the AES engine 1402 is called to decrypt the encrypted memory 1401, and the PTE is continuously set to 1. The AES engine 1402 decrypts the calculation instructions of the model and then transmits them to the processor 1404.
[0234] The processor 1401 performs operations based on the calculation instructions to obtain a processing result. When it is determined that the PTE is 1, the AES engine 1402 is called to encrypt the processing result, and the PTE is continuously set to 1. The AES engine 1402 stores the encrypted processing data in the encrypted memory 1401.
[0235] Next, the process of the AI model parsing and processing the ciphertext input from the client user will be described.
[0236] When the encrypted memory is configured and activated, the client and the server negotiate and hold the same security key. Therefore, the server security memory engine can parse the ciphertext input information from the client. The protection (encryption and decryption) operation of the security memory engine is determined by the actual behavior of the AI model. For example, if the user inputs ciphertext, the model working mode sets its page table attribute to 1. Finally, the ciphertext input information of the user is imported into the running memory space of the server AI model (and stored as ciphertext) after being parsed by the processor, so as to indicate the relevant task operations of the model subsequently.
[0237] Reference Figure 15 As shown in the reference, the encrypted memory 1401 includes a first area 1401A for user input ciphertext and a second area 1401B for storing the model.
[0238] After receiving the input ciphertext, the user ciphertext is stored in the first area 1401A. When the model is running, if the PTE is detected to be 1, the AES engine 1402 is called to decrypt the data and the calculation instructions of the model, and the PTE is continuously set to 1. The AES engine 1402 decrypts the user ciphertext and the calculation instructions of the model and then transmits them to the processor 1404.
[0239] The processor 1401 performs operations on the input data based on the computing instructions to obtain a processing result. When it is determined that the PTE is 1, it calls the AES engine 1402 to encrypt the processing result, and at the same time continues to set the PTE to 1. The AES engine 1402 stores the encrypted processing data in the second area 1401B.
[0240] Next, the encryption memory configuration is bound to the processor operation and reasoning process.
[0241] Two threads / processes / tasks on any processor are isolated from each other and cannot manipulate and access each other's processor context information (such as register data); the implementation model is isolated from other processes.
[0242] When the processor detects that the PTE of the AI model running instruction is set to 1, the processor occupied by the AI model working thread will be set to the safe mode, and it can only manipulate the safe memory space and cannot export data to any other non-safe memory space; the encrypted memory is bound to the model and the processor. The result of any final read / write operation instruction of the processor to the memory is determined by whether the attribute (pte = 1) of the AI model running space is set. If pte is set to 1, the data from the memory will be automatically processed (decrypted) by the AES engine in advance, and vice versa, when writing to the memory, it is encrypted by the AES engine first.
[0243] Reference Figure 16 As shown in the content, the memory may further include a non-safe memory space 1405.
[0244] There is isolation between the processor context one 1406 and the processor context two 1407.
[0245] In a second aspect, to implement the above processing method, a processing device according to an embodiment of the present application is deployed in an electronic device. Next, in conjunction with Figure 17 , the structural schematic diagram of the processing device 170 will be described.
[0246] As Figure 17 shown, the processing device 170 includes: a configuration unit 1701, a loading unit 1702, and an interaction unit 1703.
[0247] Among them:
[0248] The configuration unit 1701 is used to: store the controller configuration of the device, and configure the storage space for caching the target model as a safe storage space.
[0249] The loading unit 1702 is used to: load the target model into the safe storage space of the storage device.
[0250] The interaction unit 1703 is used to: perform secure interaction between the encryption / decryption engine of the processor and the target model in the safe storage space.
[0251] In some embodiments, the configuration unit 1701 is further configured to: write an identification value into a target storage space of a storage device, where the identification value is used to indicate that the storage space required by the target model is a secure storage space;
[0252] The interaction unit 1703 is further configured to: when the processor reads the identification value, perform secure interaction with the target model based on the encryption and decryption engine of the processor.
[0253] In some embodiments, the interaction unit 1703 is further configured to: the computing unit of the processor obtains a computing instruction of the target model in response to the encryption and decryption engine; the processor writes the computing result into the secure storage space of the target model through the encryption and decryption engine; the computing result is a processing result of the target model obtained by computing based on the instruction.
[0254] In some embodiments, the interaction unit 1703 is further configured to: decrypt the secure storage space through the encryption and decryption engine; the computing unit of the processor reads the computing instruction of the target model from the secure storage space.
[0255] In some embodiments, the interaction unit 1703 is further configured to: the processor sends the unencrypted computing result to the encryption and decryption engine; the encryption and decryption engine encrypts the unencrypted computing result to obtain an encrypted computing result; and writes the encrypted computing result into the secure storage space of the target model.
[0256] In some embodiments, the configuration unit 1701 is further configured to: if the calculation of the target model involves privacy data, configure the storage space of the storage device for caching the target model as a secure storage space.
[0257] In some embodiments, the processing device 170 may further include an input processing unit.
[0258] The input processing unit is configured to: receive first input data sent by a client device; if the first input data is a ciphertext input of the target model, store the ciphertext input in the secure storage space;
[0259] The interaction unit 1703 is further configured to: the encryption and decryption engine of the processor performs secure interaction with the target model and the first input data in the secure storage space.
[0260] In some embodiments, the processing device 170 may further include an output processing unit.
[0261] The output processing unit is configured to: determine a processing result of the target model based on secure interaction between the encryption and decryption engine of the processor and the target model; and when the processing result of the target model includes privacy data, encrypt the processing result through the encryption and decryption engine and output it to the client device.
[0262] In some embodiments, the processing device 170 may further include a key processing unit.
[0263] The key processing unit is configured to: receive a first encrypted random number sent by the client device; decrypt the first encrypted random number with the key of the client device to obtain a first random number; determine the session identifier of a first session, where the first session is a session sent by the client device for triggering the secure interaction between the encryption / decryption engine and the target model; and process the session identifier and the first random number through a key generation algorithm to obtain the key of the encryption / decryption engine.
[0264] It should be noted that the processing device provided in the embodiments of the present application, including each unit included therein, can be implemented by a processor in an electronic device; of course, it can also be implemented by specific logic circuits; during implementation, the processor can be a central processing unit (CPU, Central Processing Unit), a microprocessor (MPU, Micro Processor Unit), a digital signal processor (DSP, Digital Signal Processor), or a field programmable gate array (FPGA, Field-Programmable Gate Array), etc.
[0265] The description of the above device embodiments is similar to that of the above method embodiments and has similar beneficial effects to the method embodiments. For the technical details not disclosed in the device embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.
[0266] It should be noted that in the embodiments of the present application, if the above processing method is implemented in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of the present application, in essence, or the part that contributes to the related technology, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the processing methods of the various embodiments of the present application. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM, Read Only Memory), a magnetic disk, or an optical disc that can store program codes. In this way, the embodiments of the present application are not limited to any specific combination of hardware and software.
[0267] In a third aspect, to implement the above processing method, an electronic device is provided in the embodiments of the present application.
[0268] The electronic device includes: a storage unit, a controller of the storage unit, a processor, and an encryption / decryption engine of the processor; the memory includes a secure storage space and a non-secure storage space;
[0269] The controller of the storage unit is configured to: configure the storage space of the storage unit for caching the target model as the secure storage space;
[0270] The processor is configured to: load the target model into the secure storage space of the storage device;
[0271] The encryption / decryption engine of the processor is configured to: perform secure interaction with the target model in the secure storage space.
[0272] This electronic device can implement any of the processing methods provided in the first aspect above.
[0273] In a fourth aspect, an embodiment of the present application provides a processing system, including the electronic device. This electronic device is the electronic device in the third aspect.
[0274] Through secure interaction between multiple electronic devices, a target processing result is obtained; wherein, when multiple electronic devices perform secure interaction, the interaction data is encrypted by the encryption / decryption engine of the processor of the electronic device and then interacted.
[0275] The interaction here may include the following scenarios:
[0276] Multiple target models of multiple electronic devices are processed in parallel to obtain multiple processing results, and then the multiple processing results are encrypted and sent to the management device for processing to obtain the final target processing result.
[0277] Among multiple electronic devices, after one electronic device finishes processing, the result is used as the input of another electronic device, and the model of the other device processes it again, and so on, and the last electronic device outputs the target processing result.
[0278] In a fifth aspect, an embodiment of the present application provides a storage medium, that is, a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements any of the processing methods provided in the first aspect in the above embodiments.
[0279] In a sixth aspect, an embodiment of the present application provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, it implements any of the processing methods provided in the first aspect in the above embodiments.
[0280] It should be noted here that the descriptions of the above storage medium and device embodiments are similar to those of the above method embodiments and have similar beneficial effects to the method embodiments. For the technical details not disclosed in the storage medium and device embodiments of the present application, please refer to the descriptions of the method embodiments of the present application for understanding.
[0281] It should be understood that the "one embodiment" or "an embodiment" mentioned throughout the specification means that the specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, the appearances of "in one embodiment" or "in some embodiments" throughout the specification do not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner. It should be understood that in various embodiments of the present application, the sequence numbers of the above processes do not mean the order of execution is prior or subsequent. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application. The sequence numbers of the embodiments of the present application are only for description and do not represent the advantages or disadvantages of the embodiments.
[0282] It should be noted that in this article, the term "comprising", "including" or any other variant thereof is intended to cover a non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, the element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the element.
[0283] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are only illustrative. For example, the division of the processing unit is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined, or can be integrated into another system, or some features can be ignored, or not executed. In addition, the couplings, direct couplings, or communication connections between the components shown or discussed with each other can be through some interfaces. The indirect couplings or communication connections of devices or units can be electrical, mechanical or other forms.
[0284] The units described above as separate components may or may not be physically separated, and the components shown as units may or may not be physical units; they can be located in one place or distributed to multiple network units; some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0285] In addition, each functional unit in the embodiments of the present application may all be integrated into one processing unit, or each unit may be separately regarded as one unit, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware, or in the form of a combination of hardware and software functional units.
[0286] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps including the above method embodiments. The aforementioned storage medium includes various media that can store program codes, such as removable storage devices, read-only memory (ROM), magnetic disks, or optical discs.
[0287] Alternatively, if the above-mentioned integrated unit of the present application is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the embodiments of the present application, in essence, or the part that contributes to the related technology, may be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the processing methods of the various embodiments of the present application. The aforementioned storage medium includes various media that can store program codes, such as removable storage devices, ROM, magnetic disks, or optical discs.
[0288] The above processing is only the implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A processing method, comprising: The controller of a storage device configures the storage space of the storage device for caching a target model as a secure storage space; Loading the target model into the secure storage space of the storage device; The encryption and decryption engine of a processor performs secure interaction with the target model in the secure storage space.
2. The method according to claim 1, wherein configuring the storage space of the storage device for caching a target model as a secure storage space comprises: Writing an identification value into a target storage space of the storage device, the identification value being used to indicate that the storage space required by the target model is a secure storage space; The secure interaction between the encryption and decryption engine of the processor and the target model in the secure storage space comprises: The processor reads the identification value and performs secure interaction with the target model based on the encryption and decryption engine of the processor.
3. The method according to claim 2, wherein performing secure interaction between the encryption and decryption engine of the processor and the target model comprises: The calculation unit of the processor responds to the encryption and decryption engine to obtain a calculation instruction of the target model; The processor writes the calculation result into the secure storage space of the target model through the encryption and decryption engine; The calculation result is a processing result of the target model calculated based on the instruction.
4. The method according to claim 3, wherein the calculation unit of the processor responds to the encryption and decryption engine to obtain a calculation instruction of the target model, comprising: Decrypting the secure storage space through the encryption and decryption engine; The calculation unit of the processor reads the calculation instruction of the target model in the secure storage space.
5. The method according to claim 3, wherein the processor writes the calculation result into the secure storage space of the target model through the encryption and decryption engine, comprising: The processor sends the unencrypted calculation result to the encryption and decryption engine; The encryption and decryption engine encrypts the unencrypted calculation result to obtain an encrypted calculation result; Writing the encrypted calculation result into the secure storage space of the target model.
6. The method according to any one of claims 1 to 5, wherein configuring the storage space of the storage device for caching a target model as a secure storage space comprises: If the calculation of the target model involves private data, configuring the storage space of the storage device for caching the target model as a secure storage space.
7. The method according to any one of claims 1 to 5, the method further comprising: Receiving first input data sent by a client device; If the first input data is a ciphertext input of the target model, storing the ciphertext input in the secure storage space; The secure interaction between the encryption and decryption engine of the processor and the target model in the secure storage space comprises: The encryption and decryption engine of the processor performs secure interaction with the target model and the first input data in the secure storage space.
8. The method according to any one of claims 1 to 5, the method further comprising: Determine the processing result of the target model based on the secure interaction between the encryption / decryption engine of the processor and the target model; When the processing result of the target model includes private data, encrypt the processing result through the encryption / decryption engine and output it to the client device.
9. The method according to any one of claims 1 to 5, before performing the secure interaction between the encryption / decryption engine of the processor and the target model in the secure storage space, the method includes: Receive a first encrypted random number sent by the client device; Decrypt the first encrypted random number with the key of the client device to obtain a first random number; Determine the session identifier of the first session; The first session is the session sent by the client device for triggering the secure interaction between the encryption / decryption engine and the target model; Process the session identifier and the first random number through a key generation algorithm to obtain the key of the encryption / decryption engine.
10. An electronic device, the electronic device comprising: A storage unit, a controller of the storage unit, a processor, and an encryption / decryption engine of the processor; The memory includes a secure storage space and a non-secure storage space; The controller of the storage unit is configured to: configure the storage space of the storage unit for caching the target model as a secure storage space; The processor is configured to: load the target model into the secure storage space of the storage device; The encryption / decryption engine of the processor is configured to: perform secure interaction with the target model in the secure storage space.
11. A processing system includes multiple electronic devices according to claim 10; Obtain a target processing result through secure interaction between the multiple electronic devices; wherein, When the multiple electronic devices perform secure interaction, the interaction data is encrypted through the encryption / decryption engine of the processor of the electronic device and then interacted.