Model training method and device based on trusted execution environment, electronic equipment, medium and program product

By using asymmetric encryption technology and algorithm containers in a trusted execution environment, the problem of target model data security and tenant isolation in cloud environments is solved, and an efficient and secure model training process is achieved.

CN120337272APending Publication Date: 2025-07-18中移信息技术有限公司 +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510317701.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-17
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

Existing model training methods fail to effectively protect the data security of the target model in the cloud environment, and do not consider the isolation between different tenants, resulting in the risk of data breach.

Method used

A model training method based on a trusted execution environment is adopted, and the task manager and data gateway is connected through an algorithm container, the target model is encrypted using asymmetric encryption technology, and model training is carried out in the TEE environment to ensure that the data is transmitted and processed in an isolated state.

Benefits of technology

The data security and privacy of the target model are achieved, external attacks and data leakage are prevented, data isolation between tenants is ensured, deployment and migration costs are reduced, and model training efficiency and accuracy are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337272A_ABST
    Figure CN120337272A_ABST
Patent Text Reader

Abstract

The invention discloses a model training method and device based on a trusted execution environment, electronic equipment, a medium and a program product, and relates to the technical field of data security. The model training method based on the trusted execution environment is applied to an algorithm container in the trusted execution environment and comprises the steps that a container starting request and a first public key sent by a task manager are received, and the first public key is generated by an initiator; sending a data acquisition request to a data gateway, and receiving a training data set sent by the data gateway; performing model training based on the training data set to obtain a target model; and encrypting the target model according to the first public key to obtain an encryption model, and sending the encryption model to a task manager, so that an initiator decrypts the encryption model according to a first private key corresponding to the first public key. According to the technical scheme, the problem that the data security of the target model obtained by training and the tenant performing model training in the environment cannot be guaranteed in the current model training method is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology, and particularly to a model training method, device, electronic device, computer-readable storage medium, and computer program product based on a trusted execution environment. Background Art

[0002] With the increasingly wide application of deep learning technology and neural network models, the data security and privacy protection of the data applied to model training and the model itself are becoming more and more important. At present, in order to protect the security of private data, when performing model training, the commonly adopted solution is to first perform pre-training of the model in the REE (Rich Execution Environment), and then decrypt the encrypted private data in the TEE (Trusted Execution Environment) for model tuning to obtain the target model. However, this solution only considers the privacy security of private data during the model training process, and the data security of the target model still cannot be protected. Moreover, in a cloud environment, the isolation between different tenants is not considered, bringing a security risk of data leakage.

[0003] The above content is only used to assist in understanding the technical solution of the present application, and does not represent an admission that the above content is prior art. Summary of the Invention

[0004] The main purpose of the present application is to provide a model training method, device, electronic device, computer-readable storage medium, and computer program product based on a trusted execution environment, aiming to solve the technical problem that the data security of the target model obtained by the current model training method and the tenants performing model training in the environment cannot be guaranteed.

[0005] To achieve the above purpose, the present application proposes a model training method based on a trusted execution environment, which is applied to an algorithm container in the trusted execution environment. The algorithm container is respectively connected to a task manager and a data gateway. The model training method based on the trusted execution environment includes:

[0006] Receiving a start container request and a first public key sent by the task manager, where the first public key is generated by the initiator;

[0007] Sending a data acquisition request to the data gateway and receiving the training data set sent by the data gateway;

[0008] Performing model training based on the training data set to obtain a target model;

[0009] Encrypt the target model according to the first public key to obtain an encrypted model, and send the encrypted model to the task manager for the initiator to decrypt the encrypted model according to the first private key corresponding to the first public key.

[0010] In one embodiment, the training data set includes an encrypted training data set and an encryption key. The method for model training based on a trusted execution environment further includes:

[0011] After receiving the start container request and the first public key sent by the task manager, generate a second public key and a second private key, and send the second public key to the task manager;

[0012] After sending a data acquisition request to the data gateway, receive the encrypted training data set and the encryption key sent by the data gateway. Among them, the encryption key is obtained by encrypting the symmetric key generated by the data gateway according to the second public key, and the encrypted training data set is obtained by encrypting the original training data set according to the symmetric key;

[0013] Decrypt the encryption key according to the second private key to obtain the symmetric key, and decrypt the encrypted training data set according to the symmetric key to obtain the original training data set;

[0014] Perform model training based on the original training data set to obtain a target model.

[0015] In one embodiment, the method for model training based on a trusted execution environment further includes:

[0016] After receiving the start container request and the first public key sent by the task manager, generate a trusted execution environment report;

[0017] Send the trusted execution environment report to the task manager for the task manager to verify the trusted execution environment where the algorithm container is located and determine whether to continue the model training process;

[0018] When sending a data acquisition request to the data gateway, send the trusted execution environment report to the data gateway for the data gateway to verify the trusted execution environment where the algorithm container is located.

[0019] In addition, the present application also proposes a method for model training based on a trusted execution environment, which is applied to a task manager. The task manager is respectively connected to an initiator, a data gateway, and an algorithm container in a trusted execution environment. The method for model training based on a trusted execution environment includes:

[0020] When receiving a training task request and a first public key sent by an initiator, send a start container request and the first public key to the algorithm container;

[0021] Send a data preparation request to the data gateway for the data gateway to prepare a training data set and send it to the algorithm container;

[0022] Receive the encrypted model sent by the algorithm container, and send the encrypted model to the initiator for the initiator to decrypt the encrypted model according to the first private key corresponding to the first public key to obtain the target model.

[0023] In one embodiment, the model training method based on a trusted execution environment further includes:

[0024] After sending a start container request and the first public key to the algorithm container, receive a second public key sent by the algorithm container, where the second public key is generated by the algorithm container and is used for the data gateway to encrypt the generated symmetric key, and the symmetric key is used to encrypt the original training data set;

[0025] After receiving the second public key sent by the algorithm container, send a data preparation request and the second public key to the data gateway.

[0026] In one embodiment, the model training method based on a trusted execution environment further includes:

[0027] After receiving the trusted execution environment report sent by the algorithm container, verify whether the algorithm container is running in the trusted execution environment based on the trusted execution environment report;

[0028] If so, execute the steps of the trusted execution environment report;

[0029] If not, terminate the model training task and close the algorithm container.

[0030] In addition, the present application further provides a model training method based on a trusted execution environment, which is applied to a data gateway. The data gateway is respectively connected to a task manager and an algorithm container in the trusted execution environment. The model training method based on the trusted execution environment includes:

[0031] When receiving a data preparation request sent by the task manager, obtain a training data set;

[0032] When receiving a data acquisition request sent by the algorithm container, send the training data set to the algorithm container for the algorithm container to train a target model based on the training data set and encrypt the target model according to the first public key generated by the initiator, and send the encrypted model to the task manager.

[0033] In one embodiment, the model training method based on a trusted execution environment further includes:

[0034] Receive the data preparation request and the second public key sent by the task manager, and generate a symmetric key;

[0035] Encrypt the original training data set according to the symmetric key to obtain an encrypted training data set;

[0036] Encrypt the symmetric key according to the second public key to obtain an encrypted key, where the second public key is generated by the algorithm container;

[0037] Send the encrypted training data set and the encrypted key to the algorithm container, so that the algorithm container decrypts the encrypted key based on the second private key corresponding to the second public key to obtain a symmetric key, and decrypts the encrypted training data set according to the symmetric key to obtain the original training data set, and the original training data set is used for the algorithm container to train the target model.

[0038] In one embodiment, the model training method based on a trusted execution environment further includes:

[0039] After receiving the data acquisition request sent by the algorithm container, verify whether the algorithm container is running in a trusted execution environment based on the received trusted execution environment report;

[0040] If so, execute the step of sending the training data set to the algorithm container.

[0041] In addition, to achieve the above object, the present application also proposes a model training device based on a trusted execution environment, which is applied to an algorithm container. The model training device based on a trusted execution environment includes:

[0042] An information receiving module, configured to receive a start container request and a first public key sent by the task manager, where the first public key is generated by the initiator;

[0043] A data request module, configured to send a data acquisition request to a data gateway and receive the training data set sent by the data gateway;

[0044] A model training module, configured to perform model training based on the training data set to obtain a target model;

[0045] A model encryption module, configured to encrypt the target model according to the first public key to obtain an encrypted model, and send the encrypted model to the task manager for the initiator to decrypt the encrypted model according to the first private key corresponding to the first public key.

[0046] In addition, to achieve the above object, the present application further provides a model training device based on a trusted execution environment, which is applied to a task manager. The model training device based on the trusted execution environment includes:

[0047] An information sending module, configured to send a start container request and the first public key to an algorithm container when receiving a training task request and a first public key sent by an initiator;

[0048] A data request module, configured to send a data preparation request to a data gateway for the data gateway to prepare a training data set and send it to the algorithm container;

[0049] A model forwarding module, configured to receive the encrypted model sent by the algorithm container and send the encrypted model to the initiator for the initiator to decrypt the encrypted model according to the first private key corresponding to the first public key to obtain a target model.

[0050] In addition, to achieve the above object, the present application further provides a model training device based on a trusted execution environment, which is applied to a data gateway. The model training device based on the trusted execution environment includes:

[0051] A data acquisition module, configured to acquire a training data set when receiving a data preparation request sent by a task manager;

[0052] A data sending module, configured to send the training data set to the algorithm container when receiving a data acquisition request sent by the algorithm container for the algorithm container to train a target model based on the training data set and encrypt the target model according to the first public key generated by the initiator and send the encrypted model to the task manager.

[0053] In addition, to achieve the above object, the present application further provides an electronic device, which includes: a memory, a processor, and a computer program stored on the memory and executable on the processor. The computer program is configured to implement the steps of the model training method based on a trusted execution environment as described above.

[0054] In addition, to achieve the above object, the present application further provides a storage medium, which is a computer-readable storage medium. A computer program is stored on the storage medium, and when the computer program is executed by a processor, it implements the steps of the model training method based on a trusted execution environment as described above.

[0055] In addition, to achieve the above object, the present application further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the steps of the model training method based on a trusted execution environment as described above.

[0056] The present application proposes a model training method based on a trusted execution environment, which is applied to an algorithm container in the trusted execution environment. The algorithm container is respectively connected to a task manager and a data gateway. The model training method based on the trusted execution environment includes: First, receive a container startup request and a first public key sent by the task manager. The first public key is generated by the initiator, and the first public key can be used by the algorithm container to encrypt the subsequently trained target model to protect the data security of the target model. Send a data acquisition request to the data gateway, receive the training data set sent by the data gateway, then perform model training based on the training data set to obtain a target model. Finally, encrypt the target model according to the first public key to obtain an encrypted model, and send the encrypted model to the task manager for the initiator to decrypt the encrypted model according to the first private key corresponding to the first public key. In the embodiments of the present application, the first public key and the first private key of asymmetric encryption are used to encrypt and decrypt the target model trained in the trusted execution environment respectively, ensuring the out-of-domain security and privacy of the model, and ensuring that the target model can only be obtained by the initiator. Moreover, the technical solution of the present application integrates the trusted execution environment and the algorithm container to construct a highly secure and tenant-isolated model training environment, so as to ensure that sensitive data and computing logic in the model training process are in a completely isolated and encrypted state, effectively preventing external attacks and data leakage, and protecting the data security of each tenant in the trusted execution environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] The accompanying drawings here are incorporated into the specification and form a part of this specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.

[0058] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0059] Figure 1 It is a schematic flowchart provided for the first embodiment of the model training method based on the trusted execution environment of the present application;

[0060] Figure 2 It is a schematic diagram of data transmission and communication among multiple parties such as the initiator, task manager, trusted execution environment, algorithm container, and data gateway in the embodiments of the present application;

[0061] Figure 3 It is a schematic diagram of the principle for the initiator to generate asymmetric keys based on a key generation tool in the embodiments of the present application;

[0062] Figure 4 It is a schematic diagram of the principle for the initiator in the embodiment of this application to decrypt the encryption model based on a decryption tool and a private key;

[0063] Figure 5 It is a schematic diagram of a feasible communication sequence diagram among multiple parties such as the initiator, task manager, trusted execution environment, algorithm container, and data gateway in the embodiment of this application;

[0064] Figure 6 It is a schematic diagram of the structural composition of a model training device based on a trusted execution environment applied to an algorithm container in the embodiment of this application;

[0065] Figure 7 It is a schematic diagram of the structural composition of a model training device based on a trusted execution environment applied to a task manager in the embodiment of this application;

[0066] Figure 8 It is a schematic diagram of the structural composition of a model training device based on a trusted execution environment applied to a data gateway in the embodiment of this application;

[0067] Figure 9 It is a schematic diagram of the device structure of the hardware operating environment involved in the model training method based on a trusted execution environment in the embodiment of this application.

[0068] The realization of the purpose, functional characteristics, and advantages of this application will be further described with reference to the embodiments and the accompanying drawings. Detailed implementation manners

[0069] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of this application and are not used to limit this application.

[0070] To better understand the technical solutions of this application, the following will be described in detail in combination with the accompanying drawings of the specification and specific implementation manners.

[0071] The execution subject of this embodiment can be a computing service device with data processing, network communication, and program running functions, such as a tablet computer, personal computer, mobile phone, server, etc., or an electronic device, control device, etc. that can implement the above functions. The following takes a server as the execution subject as an example to describe this embodiment and the following embodiments.

[0072] The general idea of model training in a trusted execution environment is as follows: First, pre-train the model in the REE environment to obtain the model. Then, in the TEE, decrypt the encrypted private data for model parameter tuning. However, this solution has the following defects: It only ensures the privacy security of training samples during model training and does not consider the privacy security of the new model. In addition, the data provider only uses the public key of the training party for data encryption and does not verify whether the environment of the training party is a trusted execution environment, which poses a security problem. Moreover, in the cloud environment, the isolation security problem between different tenants is not considered, and during the model training process, the resource isolation problem between different training tasks is not ensured. The trained model and program often involve migration and deployment, resulting in high deployment and migration costs.

[0073] To overcome the above technical defects, the embodiments of the present application integrate the trusted execution environment and algorithm container technology to construct a highly secure and isolated model training environment. Through the trusted execution environment provided by the TEE, it is ensured that sensitive data and computing logic during the model training process are in a completely isolated and encrypted state between tenants, effectively preventing external attacks and data leakage. Moreover, the technical solution of the embodiments of the present application uses the national cryptography algorithm for encryption in the case of data and results leaving the domain, enhancing the data protection mechanism and ensuring the data security of the target model obtained by training.

[0074] The embodiments of the present application provide a model training method based on a trusted execution environment for an algorithm container applied to a trusted execution environment. The algorithm container is respectively connected to a task manager and a data gateway. Refer to Figure 1 , Figure 1 which is a schematic flowchart of the first embodiment of the model training method based on a trusted execution environment of the present application. The model training method based on a trusted execution environment includes:

[0075] Step S10: Receive a start container request and a first public key sent by the task manager, where the first public key is generated by the initiator;

[0076] Among them, the trusted execution environment is a secure area isolated and protected on the main processor, with independent execution and data encryption capabilities to ensure the confidentiality and integrity of the programs and data loaded inside. The trusted execution environment in the embodiments of the present application can be a TEE environment provided by hygon csv (China Secure Virtualization, a hardware-level memory encryption solution). The algorithm container can be a kata container, which is a lightweight virtualization solution based on hardware virtualization for running programs in a container, aiming to provide higher security, isolation, and at the same time maintain compatibility with the container ecosystem.

[0077] Exemplarily, the kata container running a specific algorithm contains the framework code of the model running program implemented in Python (a programming language) 3.9.13. The framework includes capabilities such as data loading, trusted execution environment report generation, and national cryptography algorithm encryption, as well as the environmental dependencies required by the model. The overall framework is encapsulated as a service and provides interfaces. Among them, the task manager is used to communicate with the initiator, respond to the requests of the initiator, and thus is responsible for tasks such as initiating training tasks, starting and stopping the kata model container, monitoring the life cycle, and synchronizing data gateways.

[0078] When the initiator needs to initiate a model training task, a set of keys, including a first public key and a first private key, will be generated based on the asymmetric encryption algorithm through a preset key generation tool. Among them, the first public key will be sent to the algorithm container via the task manager for the algorithm container to encrypt the trained target model subsequently. After the initiator sends a training task request and the first public key to the task manager, the task manager will send a container start request and the first public key to the algorithm container.

[0079] Step S20: Send a data acquisition request to the data gateway and receive the training data set sent by the data gateway;

[0080] When the algorithm container executes the model training task, it needs to obtain the corresponding training data set from the data gateway. Among them, the data gateway is a data source that has established a communication connection with the data provider and is used to provide training data for the algorithm container in the trusted execution environment.

[0081] Exemplarily, the Kata algorithm container can send an interface request through the TLS (Transport Layer Security) protocol to call the data gateway to obtain data. The TLS protocol is used to provide confidentiality, data integrity, and authenticity between two communication applications. In addition, the TLS protocol can also be used for data communication between any two ends (initiator, task manager, algorithm container, data gateway, data source, etc.) in the model training method of the embodiments of the present application.

[0082] Step S30: Perform model training based on the training data set to obtain a target model;

[0083] After the algorithm container receives the training data set from the data gateway, it starts to perform model training based on the training data set. The process of model training is the process of training a deep learning neural network model or other types of models, which will not be elaborated here. It should be noted that during the process of running the Kata container in the TEE (Trusted Execution Environment) for model training, the hardware acceleration characteristics of the TEE and the lightweight advantages of the Kata container can be fully utilized to reduce system resource consumption and improve the execution efficiency of model training. In this step, resource and multi-tenant situations are isolated and managed through containerization. Moreover, by optimizing the resource scheduling and management strategies of the Kata container, the embodiments of the present application achieve efficient resource allocation in the TEE environment, enabling the model training to be completed faster. Even in a cloud environment, resource and multi-tenant situations can be isolated and managed, further improving resource utilization while reducing overall energy consumption.

[0084] Step S40: Encrypt the target model according to the first public key to obtain an encrypted model, and send the encrypted model to the task manager for the initiator to decrypt the encrypted model according to the first private key corresponding to the first public key.

[0085] After the algorithm model is trained to obtain the target model, the target model can be encrypted according to the received first public key to obtain an encrypted model, and then the encrypted model is sent to the task manager for the task manager to send the encrypted model back to the initiator. Since the first public key and the first private key are generated by the initiator, only the initiator can decrypt the encrypted model according to the first private key to obtain the target model, and no other party can view the target model in plaintext during the transmission process, thus protecting the privacy and security of the target model and avoiding the leakage of model data.

[0086] Exemplarily, the data transmission and communication structure among the initiator, the task manager, the trusted execution environment, the model container, the data gateway, etc. is as Figure 2 shown. The initiator is connected to the task manager, and the task manager is respectively connected to the data gateway and the algorithm container in the trusted execution environment (TEE). The algorithm container is connected to the task manager, the initiator, and the data gateway respectively. In addition to being connected to the task manager and the algorithm container, the data gateway is also connected to the data source. It should be noted that Figure 2 the connections and communications (including the TLS protocol) among the various parties are two-way connections, that is, they can be used to send data and also to receive data.

[0087] It should be noted that the training process of the entire algorithm container can be based on Python 3 to implement a self-developed model operation framework, integrating all model environment dependencies into the framework. At the same time, it includes capabilities such as key generation, data loading, national cipher SM2 (Elliptic Curve Public Key Cryptography Algorithm 2, an asymmetric encryption algorithm based on elliptic curves), national cipher SM4 (a block cipher algorithm), and obtaining a trusted execution environment report. The whole is encapsulated as an interface, and the user only needs to fill in the specific model logic, and trigger the model operation and result download by calling the interface, improving the efficiency of model deployment and migration.

[0088] In summary, the technical solution of the embodiment of the present application supports directly containerizing the existing model training program code and importing it into the Kata container in the trusted execution environment, realizing the flexibility and convenience of model training deployment. At the same time, due to the good compatibility of the Kata container, the model training program can be seamlessly migrated and deployed in different deployment environments. The technical solution of the embodiment of the present application also provides a standardized container interface and tool chain, reducing the user's usage threshold and migration cost, and promoting the popularization and application of model training technology. In addition, using plaintext data for model training in the trusted execution environment (TEE) constructed by hardware chips can effectively avoid the influence of external interference and noise on the training process, improving the accuracy and stability of model training. At the same time, the plaintext calculation method also ensures high performance of the calculation and high availability of the calculation results. In addition, combining advanced technologies such as deep learning and machine learning to optimize and adjust the model training process further improves the generalization ability and robustness of the obtained target model.

[0089] Further, in a feasible embodiment, the training data set includes an encrypted training data set and an encryption key, and the model training method based on the trusted execution environment may further include:

[0090] Step A10, after receiving the start container request and the first public key sent by the task manager, generate a second public key and a second private key, and send the second public key to the task manager;

[0091] It should be noted that step A10 and the following steps A20 to A40 in the embodiment of the present application are supplementary solutions to the foregoing steps S10 to S40, and can form a complete technical solution together with steps S10 to S40.

[0092] Specifically, after the algorithm container receives the start container request and the first public key, it automatically initializes and randomly generates a pair of asymmetric keys according to the national cipher algorithm, including a second public key and a second private key, and then sends the second public key among them to the task manager.

[0093] Exemplarily, the national cryptographic algorithm may be SM2 (an asymmetric encryption algorithm based on elliptic curves) or SM9 (Elliptic Curve Public Key Cryptography Algorithm 9, an identity-based asymmetric encryption algorithm).

[0094] Step A20: After sending a data acquisition request to the data gateway, receive the encrypted training data set and the encrypted key sent by the data gateway. The encrypted key is obtained by encrypting the symmetric key generated by the data gateway according to the second public key, and the encrypted training data set is obtained by encrypting the original training data set according to the symmetric key.

[0095] In addition, after the algorithm container sends a data acquisition request to the data gateway, it receives the encrypted training data set and the encrypted key sent by the data gateway, which is to protect the data security of the training data set during transmission between the data gateway and the algorithm container. The encrypted key is obtained by encrypting the symmetric key generated by the data gateway according to the second public key. It can be understood that after the second public key is sent to the task manager, the task manager also sends the second public key to the data gateway when sending a data device request to the data gateway, so that the data gateway can encrypt the symmetric key generated by itself according to the second public key to obtain the encrypted key. Moreover, the symmetric key generated by the data gateway is used to encrypt the obtained original training data set.

[0096] Step A30: Decrypt the encrypted key according to the second private key to obtain the symmetric key, and decrypt the encrypted training data set according to the symmetric key to obtain the original training data set.

[0097] Step A40: Perform model training based on the original training data set to obtain the target model.

[0098] Before model training, the algorithm container can decrypt the received encrypted key according to the second private key in the asymmetric key generated by itself to obtain the symmetric key in plaintext form, and then decrypt the encrypted training data set that has gone through the symmetric key encryption process according to the symmetric key, so as to obtain the original training data set in plaintext form. Finally, model training is performed based on the original training data set in plaintext form to obtain the target model.

[0099] In summary, in the embodiment of the present application, double encryption is adopted during the transmission of training data between the data gateway and the algorithm container. That is, the original training data set is encrypted by the symmetric key, and the symmetric key is encrypted by the second public key, further ensuring the security of the original training data.

[0100] In a feasible embodiment, the model training method based on a trusted execution environment may further include:

[0101] Step B10: After receiving the start container request and the first public key sent by the task manager, generate a trusted execution environment report;

[0102] It should be noted that Step B10 and the following Steps B20 to B30 in the embodiments of the present application are supplementary solutions to the foregoing Steps S10 to S40, and can form a complete technical solution together with Steps S10 to S40, or can also form a complete technical solution together with Steps S10 to S40 and Steps A10 to A40.

[0103] To further ensure the security of the trusted execution environment where the algorithm container is located, after receiving the start container request and the first public key, start the algorithm container and generate a corresponding trusted execution environment report, which is used to characterize that the algorithm container is running in a trusted execution environment.

[0104] Step B20: Send the trusted execution environment report to the task manager for the task manager to verify the trusted execution environment where the algorithm container is located and determine whether to continue the model training process;

[0105] Sending the trusted execution environment report to the task manager allows the task manager to verify the environment where the algorithm container is located, further ensuring the security of the trusted execution environment where the algorithm container is located. On the other hand, the trusted execution environment report also supports the initiator to download it for verification by itself.

[0106] It can be understood that after the task manager or the initiator receives the trusted execution environment report, verification can be performed. If the report shows that the security of the trusted execution environment where the algorithm container is located does not meet the expectation, terminate the current model training task and close the algorithm container; if the verification passes, the task manager continues the model training process and executes the step of sending a data preparation request to the data gateway.

[0107] Step B20: While sending a data acquisition request to the data gateway, send the trusted execution environment report to the data gateway for the data gateway to verify the trusted execution environment where the algorithm container is located.

[0108] On the other hand, while the algorithm container sends a data acquisition request to the data gateway, it also provides the trusted execution environment report to the data gateway for the data gateway to verify the security of the trusted execution environment where the algorithm container is located. In this way, multiple verifications are performed to further ensure the security of the trusted execution environment.

[0109] In summary, in the technical solution of the embodiment of the present application, the model training data in the preset algorithm container is comprehensively encrypted by the national secret algorithm in the TEE environment to ensure the security of the data during transmission, storage, and processing. At the same time, the isolation feature of the TEE is used to encrypt the memory to prevent the risk of data leakage and unauthorized access. Moreover, the data gateway first verifies the trusted execution environment report in the algorithm container to ensure that the algorithm container is running in the trusted execution environment. After passing the verification, the data set encrypted by the national secret algorithm is transmitted to the algorithm container through the TLS protocol, ensuring the privacy and security of the out-of-domain data set. Subsequently, the trained target model is asymmetrically encrypted by the national secret algorithm in the algorithm container in the trusted execution environment using the first public key transmitted by the initiator, and then transmitted to the initiator through the TLS protocol via the task management. The initiator can decrypt the encrypted model using the decryption tool and the first private key to obtain the target model in plaintext form. This process ensures the out-of-domain security and privacy of the trained target model, ensuring that the target model can only be obtained by the initiator.

[0110] The embodiment of the present application also provides a trusted execution environment-based model training method applied to a task manager. The task manager is respectively connected to an initiator, a data gateway, and an algorithm container in the trusted execution environment. The trusted execution environment-based model training method includes:

[0111] Step C10, when receiving a training task request and a first public key sent by the initiator, send a start container request and the first public key to the algorithm container;

[0112] The embodiment of the present application provides a control method applied to a task manager. Specifically, when receiving a training task request and a first public key sent by the initiator, confirm the model training task, send an interface request to the algorithm container in the trusted execution environment to start the algorithm container, and at the same time send the first public key provided by the initiator.

[0113] Exemplarily, the task manager can send a start container request to the kata algorithm container in the trusted execution environment through K8s (Kubernetes, a container orchestration engine).

[0114] Step C20, send a data preparation request to the data gateway for the data gateway to prepare a training data set and send it to the algorithm container;

[0115] The task manager can also send a data preparation request to the data gateway through the TLS protocol, causing the data gateway to start obtaining the training data set from the data source in order to provide the training data required for training the model to the algorithm container.

[0116] Step C30: Receive the encrypted model sent by the algorithm container, and send the encrypted model to the initiator for the initiator to decrypt the encrypted model according to the first private key corresponding to the first public key to obtain the target model.

[0117] After the algorithm container trains the target model based on the training data set provided by the data gateway and encrypts the target model according to the first public key, it will send the encrypted model to the task manager. The task manager then sends the encrypted model back to the initiator, and the initiator can decrypt the encrypted model according to the first private key corresponding to the pre-generated first public key to obtain the target model in plaintext form.

[0118] Exemplarily, before step C10, the initiator can generate an asymmetric key pair, including the first public key and the first private key, through a key generation tool and a national cryptography algorithm (SM2 or SM9). This step is to ensure that the first private key only exists on the initiator side and does not exist on other sides. In this way, only the initiator can decrypt the encrypted model. As Figure 3 shown, the initiator can generate a pair of SM2-based public and private key pairs by running the key generation tool and store them locally. After the algorithm container trains the target model and sends the encrypted model according to the first public key to the initiator via the task manager, referring to Figure 4 , the initiator runs the decryption tool and uses the local private key to decrypt the downloaded result (referring to the encrypted model) to obtain the original text of the result (referring to the target model in plaintext form).

[0119] In a feasible embodiment, the model training method based on the trusted execution environment may further include:

[0120] Step D10: After sending the start container request and the first public key to the algorithm container, receive the second public key sent by the algorithm container, where the second public key is generated by the algorithm container and is used for the data gateway to encrypt the generated symmetric key, and the symmetric key is used to encrypt the original training data set;

[0121] It should be noted that step D10 and the following step D20 in the embodiments of the present application are supplementary solutions to the foregoing steps C10 to C40, and can form a complete technical solution together with steps C10 to C40.

[0122] Specifically, after the algorithm container receives the start container request and the first public key, it automatically initializes and randomly generates a pair of asymmetric keys according to the national cryptography algorithm, including the second public key and the second private key, and then sends the second public key among them to the task manager.

[0123] Among them, the second public key is used for the data gateway to encrypt the generated symmetric key, and the symmetric key is used to encrypt the original training data set, so as to realize double encryption of the original training data set and protect the data security during the data transmission between the data gateway and the algorithm container.

[0124] Exemplarily, the national cryptography algorithm used by the algorithm container to generate the key can be SM2 or SM9.

[0125] Step D20: After receiving the second public key sent by the algorithm container, send a data preparation request and the second public key to the data gateway.

[0126] In addition, after the task manager receives the second public key sent by the algorithm container, it can further send a data preparation request to the data gateway to enable the data gateway to prepare to obtain the training data set, and send the second public key generated by the algorithm container to the data gateway for the data gateway to encrypt the symmetric key generated by itself according to the second public key, so as to realize double encryption.

[0127] In a feasible embodiment, the model training method based on the trusted execution environment further includes:

[0128] Step E10: After receiving the trusted execution environment report sent by the algorithm container, verify whether the algorithm container runs in the trusted execution environment based on the trusted execution environment report;

[0129] Step E20: If so, execute the steps of the trusted execution environment report;

[0130] Step E30: If not, terminate the model training task and close the algorithm container.

[0131] It should be noted that steps E10 to E30 in the embodiments of the present application are supplementary solutions to the foregoing steps C10 to C30, and can form a complete technical solution together with steps C10 to C30, or can also form a complete technical solution together with steps C10 to C30 and steps D10 to D20.

[0132] In the embodiments of the present application, in order to strengthen the verification of the trusted execution environment where the algorithm container is located, after the algorithm container receives the start container request and the first public key, the algorithm container is started, and a corresponding trusted execution environment report is generated, which is used to characterize that the algorithm container is running in the trusted execution environment. After the task manager receives the trusted environment report, it determines whether the algorithm container is running in the trusted execution environment according to the information recorded in the trusted environment report. If the trusted environment report shows that the security of the trusted execution environment where the algorithm container is located does not meet the expected requirements, the current model training task is terminated and the algorithm container is closed; if the verification passes, the model training process continues, and the step of sending a data preparation request to the data gateway is executed.

[0133] The model training method based on the trusted execution environment applied to the task manager provided by the embodiments of the present application can solve the technical problem that the data security of the target model obtained by training and the tenant who performs model training in the environment cannot be guaranteed in the current model training method. Compared with the prior art, the beneficial effects of the model training method based on the trusted execution environment provided by the present application are the same as those of the model training method based on the trusted execution environment applied to the algorithm container provided by the above embodiments, and other technical features in the model training method based on the trusted execution environment are the same as the features disclosed in the method of the previous embodiment, which will not be elaborated here.

[0134] The embodiments of the present application also provide a model training method based on the trusted execution environment applied to the data gateway. The data gateway is respectively connected to the task manager and the algorithm container in the trusted execution environment. The model training method based on the trusted execution environment includes:

[0135] Step F10: When receiving the data preparation request sent by the task manager, obtain the training data set;

[0136] Step F20: When receiving the data acquisition request sent by the algorithm container, send the training data set to the algorithm container for the algorithm container to train the target model based on the training data set, encrypt the target model according to the first public key generated by the initiator, and send the encrypted model to the task manager.

[0137] The embodiments of the present application provide a control method applied to the data gateway. When the data gateway receives the data preparation request sent by the task manager, it first obtains the corresponding training data set from the data source. It should be noted that before step F10, the task manager first receives the training task request from the initiator, and then the task manager sends a start container request to the algorithm container. In addition, the training data set can be transmitted between the data gateway and the data source through the TLS protocol.

[0138] When the data gateway receives a data acquisition request sent by the algorithm container, it can send the training data set it has obtained to the algorithm container, so that the algorithm container can train a target model based on the training data set. The algorithm container encrypts the target model according to the first public key generated by the initiator received, and then sends the encrypted model to the task manager, so that the task manager can send the encrypted model back to the initiator, enabling the initiator to decrypt the encrypted model according to the first private key stored by itself to obtain the target model in plaintext form.

[0139] In a feasible embodiment, the model training method based on the trusted execution environment may further include:

[0140] Step G10, receiving a data preparation request and a second public key sent by the task manager, and generating a symmetric key;

[0141] It should be noted that step G10 and the following steps G20 to G40 in the embodiments of the present application are supplements to the foregoing steps F10 to F40, and can form a complete technical solution together with steps F10 to F40.

[0142] Specifically, after the data gateway receives the data preparation request and the second public key sent by the task manager, for this data preparation request, a symmetric key is randomly generated according to the national cryptographic algorithm for encrypting the original training data set obtained from the data source.

[0143] Exemplarily, the national cryptographic algorithm can be either SM4 or SM1.

[0144] Step G20, encrypting the original training data set according to the symmetric key to obtain an encrypted training data set;

[0145] Step G30, encrypting the symmetric key according to the second public key to obtain an encrypted key, where the second public key is generated by the algorithm container;

[0146] The data gateway can encrypt the original training data set with the symmetric key it generates to obtain encrypted training data. In addition, the symmetric key can be encrypted with the second public key generated by the algorithm container to obtain an encrypted key, and the obtained encrypted key is stored in the encrypted training data set. It should be noted that only the party with the second private key corresponding to the second public key can successfully obtain the original training data set in plaintext form. The purpose of this step is to ensure that the original training data set corresponding to the encrypted training data set can only be decrypted and used by the algorithm container, ensuring data security.

[0147] Step G40: Send the encrypted training dataset and the encryption key to the algorithm container, so that the algorithm container decrypts the encryption key based on the second private key corresponding to the second public key to obtain a symmetric key, and decrypts the encrypted training dataset according to the symmetric key to obtain the original training dataset, which is used for the algorithm container to train the target model.

[0148] Finally, send the encrypted training dataset and the encryption key to the algorithm container. The algorithm container can decrypt the encryption key according to the second private key stored in itself to obtain the symmetric key for decrypting the encrypted dataset, so as to decrypt and obtain the original training dataset in plaintext form. The algorithm container can perform model training according to the original training dataset to obtain the target model.

[0149] In a feasible embodiment, the model training method based on the trusted execution environment may further include:

[0150] Step H10: After receiving the data acquisition request sent by the algorithm container, verify whether the algorithm container is running in the trusted execution environment based on the received trusted execution environment report;

[0151] Step H20: If so, execute the step of sending the training dataset to the algorithm container.

[0152] It should be noted that steps H10 to H20 in the embodiments of the present application are supplementary solutions to the foregoing steps F10 to F40, and can form a complete technical solution together with steps F10 to F40, or can form a complete technical solution together with steps F10 to F40 and steps G10 to G20.

[0153] In the embodiments of the present application, in order to strengthen the verification of the trusted execution environment where the algorithm container is located, in addition to sending a data acquisition request to the data gateway, the algorithm container also needs to send a trusted execution environment report to the data gateway, and this trusted execution environment report is used to represent that the algorithm container is running in the trusted execution environment. After the data gateway receives the trusted environment report, it judges whether the algorithm container is running in the trusted execution environment according to the information recorded in the trusted environment report. If the trusted environment report shows that the security of the trusted execution environment where the algorithm container is located does not meet the expected requirements, terminate the current model training task, close the algorithm container, and refuse to send the training dataset (or encrypted training dataset) to the algorithm container; if the verification passes, continue the model training process and execute the step of sending the training dataset (or encrypted training dataset) to the algorithm container. The purpose of this step is to ensure that the training dataset provided by the data provider is given to the trainer within the TEE environment, ensure that the algorithm execution environment is within the trusted execution environment, prevent data leakage, and ensure data security.

[0154] Combining the content of the foregoing application embodiments, when the algorithm container is a kata algorithm container, a feasible communication sequence diagram among multiple parties such as the initiator, task manager, trusted execution environment, model container, and data gateway is as follows Figure 5 described. The steps include: 1. The initiator initiates a training task and uploads the public key to the task manager (i.e., the task management in Figure 5 ); 2. The task manager starts the kata algorithm container; 3. The task manager verifies the tee report (i.e., the trusted execution environment report) of the algorithm container and receives the SM2 public key generated by the algorithm container; 4. The task manager passes the SM2 public key to the gateway (i.e., the data gateway) and notifies the gateway to prepare the data; 5. The gateway randomly generates an SM4 key, encrypts the data set, and places the SM4 key encrypted with the SM2 public key of the container in the encrypted data; 6. The kata algorithm container obtains the encrypted data from the data gateway, decrypts the key using the SM2 private key, and then decrypts the data using the SM4 key to complete the model training process; 7. The kata algorithm container encrypts and outputs the trained model using the public key in step 1; 8. The initiator user obtains the result (i.e., the encrypted model).

[0155] In the data input link of the application embodiment of the present application, national secret algorithms and TLS protocols are used for data transmission; in the execution link, a TEE environment and virtualization container isolation technology are used to achieve secure computing environments; and in the output link, an asymmetric national secret algorithm is used to ensure the data security of the target model. The above full-link security guarantee improves the privacy and security of the data used for training and the target model.

[0156] The model training method based on a trusted execution environment provided by the application embodiment of the present application can solve the technical problem that the data security of the target model obtained by training and the tenant who performs model training in the environment cannot be guaranteed in the current model training methods. Compared with the prior art, the beneficial effects of the model training method based on a trusted execution environment provided by the present application are the same as those of the model training methods based on a trusted execution environment applied to algorithm containers and task managers provided in the above embodiments, and other technical features in the model training method based on a trusted execution environment are the same as the features disclosed in the previous embodiment method, which will not be elaborated here.

[0157] It should be noted that the above examples are only for understanding the present application and do not constitute a limitation on the model training method based on a trusted execution environment of the present application. Based on this technical concept, more forms of simple transformations are within the protection scope of the present application.

[0158] The present application also provides a model training device based on a trusted execution environment applied to an algorithm container. Referring to Figure 6 , the model training device based on a trusted execution environment includes:

[0159] An information receiving module 11, configured to receive a start container request and a first public key sent by a task manager, wherein the first public key is generated by an initiator;

[0160] A data request module 12, configured to send a data acquisition request to a data gateway and receive a training data set sent by the data gateway;

[0161] A model training module 13, configured to perform model training based on the training data set to obtain a target model;

[0162] A model encryption module 14, configured to encrypt the target model according to the first public key to obtain an encrypted model, and send the encrypted model to the task manager for the initiator to decrypt the encrypted model according to a first private key corresponding to the first public key.

[0163] In an embodiment, the model training device further includes a key generation module, and the key generation module is configured to:

[0164] After receiving the start container request and the first public key sent by the task manager, generate a second public key and a second private key, and send the second public key to the task manager.

[0165] The information receiving module 11 is further configured to:

[0166] After sending the data acquisition request to the data gateway, receive an encrypted training data set and an encrypted key sent by the data gateway, wherein the encrypted key is obtained by encrypting a symmetric key generated by the data gateway according to the second public key, and the encrypted training data set is obtained by encrypting an original training data set according to the symmetric key;

[0167] The model training device further includes a decryption module, and the decryption module is configured to:

[0168] Decrypt the encrypted key according to the second private key to obtain a symmetric key, and decrypt the encrypted training data set according to the symmetric key to obtain an original training data set;

[0169] The model training module 13 is further configured to:

[0170] Perform model training based on the original training data set to obtain a target model.

[0171] In an embodiment, the model training device further includes a report generation module, and the report generation module is configured to:

[0172] After receiving the start container request and the first public key sent by the task manager, generate a trusted execution environment report;

[0173] Send the trusted execution environment report to the task manager for the task manager to verify the trusted execution environment where the algorithm container is located and determine whether to continue the model training process;

[0174] When sending a data acquisition request to the data gateway, send the trusted execution environment report to the data gateway for the data gateway to verify the trusted execution environment where the algorithm container is located.

[0175] The model training device based on the trusted execution environment provided by this application adopts the model training method based on the trusted execution environment in the above embodiment, and can solve the technical problem that the data security of the target model obtained by training and the tenant who conducts model training in the environment cannot be guaranteed in the current model training method. Compared with the prior art, the beneficial effects of the model training device based on the trusted execution environment provided by this application are the same as those of the model training method based on the trusted execution environment provided by the above embodiment, and other technical features in the model training device based on the trusted execution environment are the same as the features disclosed in the method of the previous embodiment, which will not be elaborated here.

[0176] This application also provides a model training device based on the trusted execution environment applied to a task manager. Refer to Figure 7 and the model training device based on the trusted execution environment includes:

[0177] An information sending module 21, configured to send a container start request and the first public key to the algorithm container when receiving a training task request and the first public key sent by the initiator;

[0178] A data request module 22, configured to send a data preparation request to the data gateway for the data gateway to prepare a training data set and send it to the algorithm container;

[0179] A model forwarding module 23, configured to receive the encrypted model sent by the algorithm container and send the encrypted model to the initiator for the initiator to decrypt the encrypted model according to the first private key corresponding to the first public key to obtain the target model.

[0180] In an embodiment, the model training device further includes an information receiving module, and the information receiving module is configured to:

[0181] After sending the container start request and the first public key to the algorithm container, receive the second public key sent by the algorithm container, where the second public key is generated by the algorithm container and is used for the data gateway to encrypt the generated symmetric key, and the symmetric key is used to encrypt the original training data set;

[0182] The information sending module 21 is configured to:

[0183] After receiving the second public key sent by the algorithm container, send a data preparation request and the second public key to the data gateway.

[0184] In one embodiment, the model training device further includes an environment verification module, and the environment verification module is used for:

[0185] After receiving the trusted execution environment report sent by the algorithm container, verify whether the algorithm container is running in the trusted execution environment based on the trusted execution environment report;

[0186] If so, execute the steps of the trusted execution environment report;

[0187] If not, terminate the model training task and close the algorithm container.

[0188] The model training device based on the trusted execution environment provided by this application adopts the model training method based on the trusted execution environment in the above embodiment, and can solve the technical problem that the data security of the target model obtained by training and the tenant who performs model training in the environment cannot be guaranteed in the current model training method. Compared with the prior art, the beneficial effects of the model training device based on the trusted execution environment provided by this application are the same as those of the model training method based on the trusted execution environment provided by the above embodiment, and other technical features in the model training device based on the trusted execution environment are the same as the features disclosed in the method of the previous embodiment, and will not be elaborated here.

[0189] This application also provides a model training device based on the trusted execution environment applied to a data gateway. Refer to Figure 8 , the model training device based on the trusted execution environment includes:

[0190] A data acquisition module 31, configured to acquire a training data set when receiving a data preparation request sent by a task manager;

[0191] A data sending module 32, configured to send the training data set to the algorithm container when receiving a data acquisition request sent by the algorithm container, so that the algorithm container trains a target model based on the training data set, encrypts the target model according to the first public key generated by the initiator, and sends the encrypted model to the task manager.

[0192] In one embodiment, the model training device further includes a key generation module and an encryption module. The key generation module is used for:

[0193] Receive the data preparation request and the second public key sent by the task manager, and generate a symmetric key;

[0194] The encryption module is used for:

[0195] Encrypt the original training data set according to the symmetric key to obtain an encrypted training data set;

[0196] Encrypt the symmetric key according to the second public key to obtain an encrypted key, where the second public key is generated by the algorithm container;

[0197] The data sending module 32 is further configured to:

[0198] Send the encrypted training data set and the encrypted key to the algorithm container, so that the algorithm container decrypts the encrypted key based on the second private key corresponding to the second public key to obtain the symmetric key, and decrypts the encrypted training data set according to the symmetric key to obtain the original training data set, and the original training data set is used for the algorithm container to train the target model.

[0199] In an embodiment, the model training device further includes an environment verification module, and the environment verification module is configured to:

[0200] After receiving a data acquisition request sent by the algorithm container, verify whether the algorithm container is running in a trusted execution environment based on the received trusted execution environment report;

[0201] If so, execute the step of sending the training data set to the algorithm container.

[0202] The model training device based on a trusted execution environment provided by the present application adopts the model training method based on a trusted execution environment in the above embodiment, and can solve the technical problem that the data security of the target model obtained by training and the tenant performing model training in the environment cannot be guaranteed in the current model training method. Compared with the prior art, the beneficial effects of the model training device based on a trusted execution environment provided by the present application are the same as those of the model training method based on a trusted execution environment provided by the above embodiment, and other technical features in the model training device based on a trusted execution environment are the same as those disclosed in the method of the previous embodiment, and will not be elaborated here.

[0203] The present application provides an electronic device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the model training method based on a trusted execution environment in the above embodiment.

[0204] Next, refer to Figure 9, which shows a schematic structural diagram of an electronic device suitable for implementing the embodiments of the present application. The electronic devices in the embodiments of the present application may include, but are not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions: tablet computers), PMPs (Portable Media Players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 9 The electronic device shown is merely an example and should not impose any limitation on the functions and scope of use of the embodiments of the present application.

[0205] As Figure 9 shown, the electronic device may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which may perform various appropriate actions and processes according to the program stored in the read-only memory (ROM: Read Only Memory) 1002 or the program loaded from the storage device 1003 into the random access memory (RAM: Random Access Memory) 1004. In the RAM 1004, various programs and data required for the operation of the electronic device are also stored. The processing device 1001, the ROM 1002, and the RAM 1004 are connected to each other through a bus 1005. The input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems may be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 may allow the electronic device to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows an electronic device with various systems, it should be understood that it is not required to implement or have all the systems shown. More or fewer systems may be implemented or had alternatively.

[0206] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by a processing device 1001, the above functions defined in the methods of the embodiments disclosed in the present application are executed.

[0207] The electronic device provided by the present application adopts the model training method based on a trusted execution environment in the above embodiments, and can solve the technical problem that the data security of the target model obtained by training and the tenant who performs model training in the environment cannot be guaranteed in the current model training method. Compared with the prior art, the beneficial effects of the electronic device provided by the present application are the same as those of the model training method based on a trusted execution environment provided in the above embodiments, and other technical features in the electronic device are the same as the features disclosed in the method of the previous embodiment, which will not be elaborated here.

[0208] It should be understood that each part disclosed in the present application can be implemented by hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in a suitable manner in any one or more embodiments or examples.

[0209] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in the present application, and all of them should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

[0210] The present application provides a computer-readable storage medium, on which there are computer-readable program instructions (i.e., computer programs), and the computer-readable program instructions are used to execute the model training method based on a trusted execution environment in the above embodiments.

[0211] The computer-readable storage medium provided by the present application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or flash memory, optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this embodiment, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, device, or component. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0212] The above computer-readable storage medium may be included in an electronic device; or it may exist separately without being assembled into the electronic device.

[0213] The above computer-readable storage medium carries one or more programs. When the one or more programs are executed by an electronic device, the electronic device is caused to: receive a start container request and a first public key sent by a task manager, where the first public key is generated by an initiator; send a data acquisition request to a data gateway and receive a training data set sent by the data gateway; perform model training based on the training data set to obtain a target model; encrypt the target model according to the first public key to obtain an encrypted model, and send the encrypted model to the task manager for the initiator to decrypt the encrypted model according to the first private key corresponding to the first public key.

[0214] Alternatively, the electronic device is caused to execute: when receiving a training task request and a first public key sent by an initiator, send a start container request and the first public key to an algorithm container; send a data preparation request to the data gateway for the data gateway to prepare a training data set and send it to the algorithm container; receive the encrypted model sent by the algorithm container and send the encrypted model to the initiator for the initiator to decrypt the encrypted model according to the first private key corresponding to the first public key to obtain a target model.

[0215] Alternatively, the electronic device is caused to perform: when receiving a data preparation request sent by the task manager, obtaining a training data set; when receiving a data acquisition request sent by the algorithm container, sending the training data set to the algorithm container, so that the algorithm container trains a target model based on the training data set, encrypting the target model according to a first public key generated by the initiator, and sending the encrypted model to the task manager.

[0216] Computer program code for performing the operations of the present application may be written in one or more programming languages or combinations thereof. The above-mentioned programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).

[0217] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.

[0218] The modules involved in the embodiments described in the present application may be implemented in software or in hardware. Wherein, the name of the module does not constitute a limitation to the unit itself in some cases.

[0219] The readable storage medium provided by this application is a computer-readable storage medium. The computer-readable storage medium stores computer-readable program instructions (i.e., computer programs) for executing the above model training method based on a trusted execution environment, and can solve the technical problem that the data security of the target model obtained by training and the tenant who performs model training in the environment cannot be guaranteed in the current model training method. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by this application are the same as those of the model training method based on a trusted execution environment provided by the above embodiments, and will not be elaborated here.

[0220] This application also provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the steps of the model training method based on a trusted execution environment as described above.

[0221] The computer program product provided by this application can solve the technical problem that the data security of the target model obtained by training and the tenant who performs model training in the environment cannot be guaranteed in the current model training method. Compared with the prior art, the beneficial effects of the computer program product provided by this application are the same as those of the model training method based on a trusted execution environment provided by the above embodiments, and will not be elaborated here.

[0222] The above are only some embodiments of this application, and thus do not limit the patent scope of this application. Any equivalent structural transformation made by using the content of the specification and drawings of this application under the technical concept of this application, or any direct / indirect application in other related technical fields, is included in the patent protection scope of this application.

Claims

1. A model training method based on a trusted execution environment, characterized in that An algorithm container applied to a trusted execution environment, the algorithm container being respectively connected to a task manager and a data gateway. The model training method based on the trusted execution environment includes: Receiving a start container request and a first public key sent by the task manager, where the first public key is generated by the initiator; Sending a data acquisition request to the data gateway and receiving the training data set sent by the data gateway; Performing model training based on the training data set to obtain a target model; Encrypting the target model according to the first public key to obtain an encrypted model, and sending the encrypted model to the task manager for the initiator to decrypt the encrypted model according to the first private key corresponding to the first public key.

2. The model training method based on a trusted execution environment according to claim 1, wherein The training data set includes an encrypted training data set and an encryption key. The model training method based on the trusted execution environment further includes: After receiving the start container request and the first public key sent by the task manager, generating a second public key and a second private key, and sending the second public key to the task manager; After sending the data acquisition request to the data gateway, receiving the encrypted training data set and the encryption key sent by the data gateway, where the encryption key is obtained by encrypting the symmetric key generated by the data gateway according to the second public key, and the encrypted training data set is obtained by encrypting the original training data set according to the symmetric key; Decrypting the encryption key according to the second private key to obtain the symmetric key, and decrypting the encrypted training data set according to the symmetric key to obtain the original training data set; Performing model training based on the original training data set to obtain a target model.

3. The model training method based on a trusted execution environment according to claim 1, wherein The model training method based on the trusted execution environment further includes: After receiving the start container request and the first public key sent by the task manager, generating a trusted execution environment report; Sending the trusted execution environment report to the task manager for the task manager to verify the trusted execution environment where the algorithm container is located and determine whether to continue the model training process; While sending the data acquisition request to the data gateway, sending the trusted execution environment report to the data gateway for the data gateway to verify the trusted execution environment where the algorithm container is located.

4. A model training method based on a trusted execution environment, characterized in that, Applied to a task manager, the task manager being respectively connected to the initiator, the data gateway, and the algorithm container in the trusted execution environment. The model training method based on the trusted execution environment includes: When receiving a training task request and a first public key sent by the initiator, sending a start container request and the first public key to the algorithm container; Sending a data preparation request to the data gateway for the data gateway to prepare the training data set and send it to the algorithm container; Receiving the encrypted model sent by the algorithm container and sending the encrypted model to the initiator for the initiator to decrypt the encrypted model according to the first private key corresponding to the first public key to obtain the target model.

5. The model training method based on a trusted execution environment according to claim 4, wherein, The model training method based on the trusted execution environment further includes: After sending a start container request and the first public key to the algorithm container, receive the second public key sent by the algorithm container, where the second public key is generated by the algorithm container and is used for the data gateway to encrypt the generated symmetric key, and the symmetric key is used to encrypt the original training dataset; After receiving the second public key sent by the algorithm container, send a data preparation request and the second public key to the data gateway.

6. The model training method based on a trusted execution environment according to claim 4, wherein The model training method based on a trusted execution environment further includes: After receiving the trusted execution environment report sent by the algorithm container, verify whether the algorithm container is running in a trusted execution environment based on the trusted execution environment report; If so, execute the steps of the trusted execution environment report; If not, terminate the model training task and close the algorithm container.

7. A model training method based on a trusted execution environment, characterized in that, Applied to a data gateway, the data gateway is respectively connected to a task manager and an algorithm container in a trusted execution environment, and the model training method based on the trusted execution environment includes: When receiving a data preparation request sent by the task manager, obtain a training dataset; When receiving a data acquisition request sent by the algorithm container, send the training dataset to the algorithm container for the algorithm container to train a target model based on the training dataset, and encrypt the target model according to the first public key generated by the initiator, and send the encrypted model to the task manager.

8. The model training method based on a trusted execution environment according to claim 7, wherein The model training method based on a trusted execution environment further includes: Receive the data preparation request and the second public key sent by the task manager, and generate a symmetric key; Encrypt the original training dataset according to the symmetric key to obtain an encrypted training dataset; Encrypt the symmetric key according to the second public key to obtain an encrypted key, where the second public key is generated by the algorithm container; Send the encrypted training dataset and the encrypted key to the algorithm container for the algorithm container to decrypt the encrypted key to obtain the symmetric key based on the second private key corresponding to the second public key, and decrypt the encrypted training dataset according to the symmetric key to obtain the original training dataset, and the original training dataset is used for the algorithm container to train a target model.

9. The method for model training based on a trusted execution environment according to claim 7, wherein The model training method based on a trusted execution environment further includes: After receiving a data acquisition request sent by the algorithm container, verify whether the algorithm container is running in a trusted execution environment based on the received trusted execution environment report; If so, execute the step of sending the training dataset to the algorithm container.

10. A model training device based on a trusted execution environment, characterized in that, Applied to an algorithm container, the model training device based on a trusted execution environment includes: An information receiving module, configured to receive a start container request and a first public key sent by a task manager, where the first public key is generated by an initiator; A data request module, configured to send a data acquisition request to the data gateway and receive the training dataset sent by the data gateway; A model training module, configured to perform model training based on the training dataset to obtain a target model; A model encryption module, which is used to encrypt the target model according to the first public key to obtain an encrypted model, and send the encrypted model to the task manager for the initiator to decrypt the encrypted model according to the first private key corresponding to the first public key.

11. A model training device based on a trusted execution environment, characterized in that, Applied to the task manager, the model training device based on the trusted execution environment includes: An information sending module, which is used to send a start container request and the first public key to the algorithm container when receiving a training task request and the first public key sent by the initiator; A data request module, which is used to send a data preparation request to the data gateway for the data gateway to prepare a training data set and send it to the algorithm container; A model forwarding module, which is used to receive the encrypted model sent by the algorithm container and send the encrypted model to the initiator for the initiator to decrypt the encrypted model according to the first private key corresponding to the first public key to obtain the target model.

12. A model training device based on a trusted execution environment, characterized in that, Applied to the data gateway, the model training device based on the trusted execution environment includes: A data acquisition module, which is used to acquire a training data set when receiving a data preparation request sent by the task manager; A data sending module, which is used to send the training data set to the algorithm container when receiving a data acquisition request sent by the algorithm container for the algorithm container to train the target model based on the training data set, encrypt the target model according to the first public key generated by the initiator, and send the encrypted model to the task manager.

13. An electronic device, characterized in that, The device includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, and the computer program is configured to implement the steps of the model training method based on the trusted execution environment according to any one of claims 1 to 3, 4 to 6, or 7 to 9.

14. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium, and when the computer program is executed by the processor, it implements the steps of the model training method based on the trusted execution environment according to any one of claims 1 to 3, 4 to 6, or 7 to 9.

15. A computer program product, characterized in that, The computer program product includes a computer program, and when the computer program is executed by the processor, it implements the steps of the model training method based on the trusted execution environment according to any one of claims 1 to 3, 4 to 6, or 7 to 9.