Security verification method, medium, equipment and product of large model service running environment

By deploying virtual machines and remote proof services in a hardware trusted execution environment, and obtaining and generating remote proof reports, the security verification problem of large model services in machine learning platforms is solved, the trustworthiness verification of virtual machines and container stacks is realized, and user trust is improved.

CN120354404BActive Publication Date: 2026-02-24BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510830571.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-19
Publication Date
2026-02-24
Estimated Expiration
2045-06-19

AI Technical Summary

Technical Problem

How to ensure the security of large model services in machine learning platforms, especially the trustworthiness verification in virtual machine and container group environments, and prevent attacks on the IaaS layer.

Method used

By deploying virtual machines and remote proof services in a hardware trusted execution environment, environmental metrics are obtained, and remote proof reports are generated to verify the security of the runtime environment, including the trustworthiness verification of virtual machines and container stacks.

Benefits of technology

It increases users' trust in the service provider's services, shields against IaaS layer attacks, and ensures the security of the large-scale service's operating environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120354404B_ABST
    Figure CN120354404B_ABST
Patent Text Reader

Abstract

The present disclosure provides a security verification method, medium, device and product of a large model service running environment, relates to the technical field of computers, and deploys a large model service in a container group created in a virtual machine, and deploys the virtual machine in a hardware-based trusted execution environment, obtains an environment measurement corresponding to a running environment of the large model service through a remote attestation service deployed in the hardware-based trusted execution environment, and the environment measurement at least includes a first measurement corresponding to a trusted execution environment where the virtual machine is located and a container measurement in a container stack dimension corresponding to the container group, and the remote attestation service generates a remote attestation report according to the environment measurement, so that a user can verify the security of the running environment through the remote attestation report. Not only can attacks from the IaaS layer be shielded, but also the trustworthiness in the virtual machine dimension can be verified and the trustworthiness in the container stack dimension can be verified, thereby improving the trust degree of the user for the service provided by the service provider.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of computer technology, and more specifically, to a security verification method, medium, device, and product for a large-scale model service runtime environment. Background Technology

[0002] In related technologies, service providers can offer users machine learning platforms to deploy large model services. Generally, machine learning platforms provide PaaS (Platform as a Service) services, enabling users to deploy large model services through PaaS. In this scenario, users have very high requirements for the security of machine learning platforms, making the assurance of their security extremely important. Summary of the Invention

[0003] This summary section is provided to briefly introduce the concepts, which will be described in detail in the detailed description section below. This summary section is not intended to identify key or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.

[0004] Firstly, this disclosure provides a security verification method for a large model service runtime environment, including:

[0005] The remote proof service obtains the environment metrics corresponding to the runtime environment used to deploy the large model service; the large model service is deployed in a container group created in a virtual machine, the virtual machine is deployed in a hardware-based trusted execution environment, and the remote proof service is deployed in the hardware-based trusted execution environment; the environment metrics include at least a first metric corresponding to the trusted execution environment where the virtual machine is located and a container metric under the container stack dimension corresponding to the container group.

[0006] The remote verification service generates a remote verification report based on the environmental metrics. This report is used by users to perform security verification of the operating environment.

[0007] Secondly, this disclosure provides a security verification device for a large model service runtime environment, comprising:

[0008] The acquisition module is configured to acquire environment metrics corresponding to the runtime environment used to deploy the large model service via a remote proof service; the large model service is deployed in a container group created in a virtual machine, the virtual machine is deployed in a hardware-based trusted execution environment, and the remote proof service is deployed in a hardware-based trusted execution environment; the environment metrics include at least a first metric corresponding to the trusted execution environment where the virtual machine is located and a container metric under the container stack dimension corresponding to the container group;

[0009] The generation module is configured to generate a remote proof report based on the environmental metrics through the remote proof service. The remote proof report is used by users to perform security verification of the operating environment.

[0010] Thirdly, this disclosure provides a computer-readable medium having a computer program stored thereon, which, when executed by a processing device, implements the steps of the method described in the first aspect.

[0011] Fourthly, this disclosure provides an electronic device, comprising:

[0012] A storage device on which computer programs are stored;

[0013] A processing device for executing the computer program in the storage device to implement the steps of the method described in the first aspect.

[0014] Fifthly, this disclosure provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the method described in the first aspect.

[0015] Based on the above technical solution, the large model service is deployed in a container group created within a virtual machine, and this virtual machine is deployed in a hardware-based trusted execution environment. Then, a remote verification service deployed within the hardware-based trusted execution environment obtains the environment metrics corresponding to the large model service's runtime environment. These environment metrics include at least a first metric corresponding to the trusted execution environment where the virtual machine resides and container metrics at the container stack level of the container group. Next, the remote verification service generates a remote verification report based on the environment metrics, allowing users to verify the security of the runtime environment through the remote verification report. Since the container group runs in a hardware-based trusted execution environment-hardened virtual machine, attacks from the IaaS (Infrastructure as a Service) layer can be shielded. Furthermore, through the first metric and container metrics, trust verification at the virtual machine level and the container stack level can be provided, thereby increasing user trust in the services provided by the service provider.

[0016] Other features and advantages of this disclosure will be described in detail in the following detailed description section. Attached Figure Description

[0017] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the originals and elements are not necessarily drawn to scale. In the drawings:

[0018] Figure 1 This is a flowchart illustrating a security verification method for a large model service runtime environment according to an exemplary embodiment.

[0019] Figure 2 This is a schematic diagram of a security verification system for a large model service runtime environment, according to an exemplary embodiment.

[0020] Figure 3 This is a schematic diagram of the structure of a security verification device for a large model service runtime environment, according to an exemplary embodiment.

[0021] Figure 4 This is a schematic diagram of the structure of an electronic device according to an exemplary embodiment. Detailed Implementation

[0022] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0023] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.

[0024] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below.

[0025] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.

[0026] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0027] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.

[0028] Figure 1 This is a flowchart illustrating a security verification method for a large-scale model service runtime environment according to an exemplary embodiment. For example... Figure 1 As shown, this disclosure provides a security verification method for a large model service runtime environment. Specifically, this method can be executed by a security verification device for a large model service runtime environment, which can be implemented in software and / or hardware. Figure 1 As shown, the method may include the following steps.

[0029] In step 110, the environment metrics corresponding to the runtime environment used to deploy the large model service are obtained; the large model service is deployed in a container group created in a virtual machine, the virtual machine is deployed in a hardware-based trusted execution environment, and the remote proof service is deployed in a hardware-based trusted execution environment; the environment metrics include at least the first metric corresponding to the trusted execution environment where the virtual machine is located and the container metric under the container stack dimension corresponding to the container group.

[0030] Here, "large model service" can refer to a large language model service. For example, a large model service could refer to a training task or inference service for a large language model deployed by a user. Large model services are deployed in container groups (Pods) created within virtual machines. For machine learning platforms, this actually means that users purchase corresponding IaaS resources (such as file systems, networks, ECS (Elastic Compute Service, cloud servers), etc.), and what users see during actual use is the created Pod.

[0031] In this embodiment of the disclosure, a hardware-based Trusted Execution Environment (TEE) is used to harden virtual machines used to deploy large model services. Exemplarily, the hardware-based Trusted Execution Environment can be a CPU (Central Processing Unit) TEE. A CPU TEE is an isolated region that runs on a CPU.

[0032] It should be understood that because the container groups used to deploy large model services are created in virtual machines hardened through a hardware-based trusted execution environment, service providers cannot dump the virtual machine's memory using VMM (Virtual Machine Monitor, also known as Hypervisor). Therefore, the method provided in this disclosure can shield against attacks from the IaaS layer, ensuring the security of the large model service's runtime environment.

[0033] Remote verification service is a security mechanism used to verify the trustworthiness and code integrity of a platform. In this embodiment of the disclosure, the remote verification service is deployed in a hardware-based trusted execution environment (TEE). That is, the remote verification service can be hardened using a hardware-based TEE to ensure its trustworthiness. For example, the hardware-based TEE used to deploy the remote verification service can be a CPU TEE.

[0034] Metrics refers to the integrity verification and security check of various components of a runtime environment. In this embodiment of the disclosure, environment metrics are values ​​obtained by measuring the runtime environment used to deploy large model services. Exemplarily, environment metrics can be presented in the form of hash values ​​or digital signatures to prove that the runtime environment has not been tampered with and is trustworthy. For example, hash calculations can be performed on software, configuration files, etc., in the runtime environment to generate corresponding hash values, which are used to verify whether the corresponding software or configuration files have been tampered with.

[0035] In this embodiment of the disclosure, the environment metric includes at least a first metric corresponding to the trusted execution environment where the virtual machine resides and a container metric under the container stack dimension corresponding to the container group.

[0036] The first metric refers to the metric value obtained by measuring the hardware-based trusted execution environment in which the virtual machine resides. For example, the first metric may include metric values ​​for the bootloader, metric values ​​for the firmware, and metric values ​​for the kernel.

[0037] It should be noted that the first metric is actually performed at the level of the trusted execution environment in which the virtual machine resides, in order to verify the trustworthiness of that trusted execution environment.

[0038] Container metrics within the container stack dimension of a container group refer to metric values ​​obtained by measuring the container stack dimension. For example, container metrics include second metrics related to the components of the container orchestration platform corresponding to the container group, and third metrics related to the images of the large model service.

[0039] The container orchestration platform corresponding to the container group can be Kubernetes (an open-source platform for managing containers). A Pod is the smallest deployable unit in Kubernetes; a Pod contains at least one application container, storage resources, a unique network address, and options that determine how the container should run. The container orchestration platform may include components such as kubelet (a component for managing containers and Pods on nodes), containerd (a container runtime for managing the lifecycle of containers), runc (a reference implementation for creating and running containers), and docker (an application container engine for developing, running, and deploying applications). Accordingly, the second metric includes metrics for kubelet, containerd, runc, and docker.

[0040] It is important to note that by measuring the trustworthiness of the components included in a container orchestration platform, the trustworthiness of the components used in the container orchestration platform can be verified.

[0041] Images related to the large model service refer to files associated with the large model service. Within a Pod, user-provided images of the large model service are instantiated as containers, packaging them into standardized units for deployment. Measuring these images allows verification that the large model service has not been tampered with.

[0042] It is important to note that by using the first metric and container metrics, trustworthiness can be measured not only at the level of the trusted execution environment but also at the level of the container stack, which greatly ensures the trustworthiness of the runtime environment in which the large model service resides.

[0043] Of course, when a virtual machine is equipped with a trusted acceleration device, the environment metric also includes a fourth metric corresponding to the trusted execution environment of the trusted acceleration device.

[0044] A trusted acceleration device is a hardware device used to accelerate computational tasks and provide a trusted execution environment. For example, a trusted acceleration device can be a GPU (Graphics Processing Unit) and / or an MPU (Microprocessor Unit) with a trusted execution environment. Accordingly, the fourth metric corresponding to the trusted execution environment of the trusted acceleration device can refer to the metric value of the GPU TEE and / or the metric value of the MPU TEE.

[0045] Therefore, the environmental metrics provided in this disclosure embodiment may include a first metric corresponding to the trusted execution environment where the virtual machine resides, a container metric under the container stack dimension, and a fourth metric of the trusted acceleration device.

[0046] It is worth noting that the security verification method for the runtime environment of large model services provided in this disclosure can not only provide security verification at the virtual machine level, but also provide security verification at the trusted acceleration device level and at the container stack level, thereby providing full-dimensional security verification for the runtime environment of large model services in the scenario of large model services.

[0047] In this embodiment of the disclosure, the remote proof service can proactively pull the corresponding environment metrics from the device deploying the large model service. Alternatively, the device deploying the large model service can also proactively send the corresponding environment metrics to the remote proof service.

[0048] In step 120, a remote verification report is generated based on environmental metrics through the remote verification service. The remote verification report is used by users to perform security verification of the operating environment.

[0049] Here, after receiving the environment metrics corresponding to the runtime environment used to deploy the large model service, the remote proof service generates a remote proof report for that runtime environment based on the environment metrics. The remote proof report may include the trusted status of the runtime environment (such as trusted or untrusted, whether the trusted execution environment is complete and has not been tampered with), the values ​​of the environment metrics, and a measurement log for recording detailed operations during the proof process.

[0050] The remote proof report provided by the remote proof service allows users to verify the trustworthiness of the large model service's runtime environment based on the information they possess. For example, since users own their own image, the remote proof report allows them to check whether the deployed image has been tampered with. Another example is that the remote proof service can provide the source code or corresponding baseline hash values ​​of each component in the runtime environment; users can verify whether the runtime environment has been tampered with by comparing the source code or baseline hash values. It's important to note that if the runtime environment has been tampered with, the corresponding environment metrics will inevitably change. Consequently, the environment metrics will be inconsistent with the baseline hash value provided by the remote proof service, indicating that the runtime environment has been tampered with and is in an untrusted state.

[0051] It is worth noting that the remote authentication service can generate remote authentication reports through chained authentication. Chained authentication ensures the trustworthiness of each component and link in the system through a series of cryptographic verification steps. This mechanism starts from a trusted root and progressively verifies each component and module in the system, forming a complete chain of trust. In the embodiments disclosed in this disclosure, the trustworthiness of the firmware and bootloader is verified first, then the trustworthiness of the kernel, followed by the trustworthiness of the components included in the container orchestration platform, and finally the trustworthiness of the large model service image, thereby forming a trusted chained authentication.

[0052] Therefore, by deploying the large model service within a container group created in a virtual machine, and this virtual machine being deployed in a hardware-based trusted execution environment (HPE), and then obtaining the environment metrics corresponding to the runtime environment of the large model service through a remote verification service deployed in the HPE, the environment metrics include at least a first metric corresponding to the HPE where the virtual machine resides and a container metric at the container stack dimension of the container group. Then, the remote verification service generates a remote verification report based on the environment metrics, allowing users to verify the security of the runtime environment through the remote verification report. Since the container group runs in a hardware-based HPE-hardened virtual machine, attacks from the IaaS layer can be shielded. Furthermore, through the first metric and container metrics, trustworthiness verification at the virtual machine dimension and the container stack dimension can be provided, thereby increasing user trust in the services provided by the service provider.

[0053] In some feasible implementations, in step 110, in response to deploying a large model service in a container group, environmental metrics can be collected by creating an initialization container in the container group, and then the environmental metrics can be uploaded to a remote proof service by the initialization container.

[0054] Here, the initialization container is a special type of container used to run initialization tasks before the application container starts. Deploying a large model service in a container group can be understood as launching the large model service within the container group. Launching the large model service in a container group can be understood as creating the corresponding container for the large model service within the container group based on the image associated with the large model service. When deploying a large model service in a container group, the initialization container created within the container group can collect environmental metrics corresponding to the runtime environment. Then, the initialization container sends the collected environmental metrics to the remote proof service.

[0055] It is worth noting that after deploying the large model service, the initialization container will be recycled, so the collected environment metrics are static environment metrics of the runtime environment.

[0056] It should be noted that in this embodiment of the disclosure, if the environmental metric characterization of the operating environment is tampered with, the large model service can be terminated.

[0057] Therefore, through the above implementation method, when deploying large model services, environmental metrics of the operating environment can be collected to measure the security of the operating environment where the container group is located.

[0058] In some feasible implementations, in step 110, in response to initializing the virtual machine, the second metric and the first metric corresponding to the component can be sent to the remote verification service. Accordingly, in step 120, a first remote verification report can be generated by the remote verification service based on the second metric and the first metric, and then the first remote verification report can be used by the remote verification service for users to verify the trustworthiness of the virtual machine.

[0059] For detailed explanations of the first and second metrics, please refer to the relevant descriptions in the above implementation methods; they will not be repeated here. During virtual machine initialization, the second and first metrics can be sent to the remote proof service.

[0060] Users can purchase corresponding virtual machine instances from the service provider. During the IaaS service initialization process, they can perform operations to initialize the virtual machine instance and send the first metric to the remote proof service. During the PaaS service initialization process, they can perform operations to join the Kubernetes cluster, install Kubernetes-related components on the virtual machine instance, and send the second metric to the remote proof service.

[0061] Of course, following the above implementation method, if the virtual machine instance is equipped with a trusted acceleration device, the operation of sending the fourth metric corresponding to the trusted acceleration device to the remote proof service can also be performed during the IaaS service initialization process.

[0062] When the remote verification service receives the second and first metrics, it generates a first remote verification report based on these metrics. It should be noted that during virtual machine initialization, since the large model service has not yet been started, the first remote verification report does not contain the third metric for the image related to the large model service. Because the first remote verification report carries both the first and second metrics, it can be used by users to verify the security of the virtual machine used to deploy the large model service.

[0063] When a user specifies that a large model service can be deployed via a virtual machine, the user can request a remote proof service to provide a first remote proof report, which includes a first metric and a second metric. The user can then use the first remote proof report to determine whether the virtual machine is suitable for deploying the large model service.

[0064] For example, the remote certification service may output a first remote certification report in response to a query request sent by a user.

[0065] Therefore, through the above implementation method, a first remote verification report can be provided to the user when initializing the virtual machine and before deploying the large model service, so that the user can verify the trustworthiness of the virtual machine through the first remote verification report, and thus determine whether to deploy the large model service in the virtual machine.

[0066] In some feasible implementations, in step 110, in response to deploying a large model service in the container group, a first metric, a second metric, and a third metric may be sent to the remote verification service. Accordingly, in step 120, a second remote verification report may be generated by the remote verification service based on the first metric, the second metric, and the third metric. The second remote verification report is used by the user to verify the trustworthiness of the runtime environment.

[0067] Here, when deploying a large model service in a container group, a first metric, a second metric, and a third metric are sent to the remote proof service. Detailed explanations of the first, second, and third metric can be found in the relevant descriptions of the above implementation methods, and will not be repeated here.

[0068] Following the above approach, the first, second, and third metrics can be collected through container initialization. Alternatively, if the virtual machine instance is equipped with a trusted acceleration device, the fourth metric corresponding to the trusted acceleration device can also be sent to the remote verification service during IaaS service initialization. In other words, when deploying a large model service in a container group, the first, second, third, and fourth metrics can be collected through container initialization, and then sent to the remote verification service through the container initialization to verify the trustworthiness of the entire runtime environment of the large model service.

[0069] Following the above implementation method, during virtual machine initialization, the trustworthiness of the virtual machine can be verified using a first remote verification report generated based on the first and second metrics. When deploying the container corresponding to the large model service in the container group, the trustworthiness of the runtime environment where the container group resides is measured again. Users can obtain a second remote verification report from the remote verification service and then use the second remote verification report to verify the trustworthiness of the runtime environment of the large model service. When the runtime environment of the large model service changes, the deployment of the large model service can be terminated.

[0070] It's worth noting that the second remote proof report essentially adds a third metric for credibility verification to the first remote proof report. By generating the second remote proof report using the first, second, and third metrics, users can verify not only the trustworthiness of the virtual machine when deploying large model services, but also the trustworthiness of the container stack, significantly increasing user confidence in the machine learning platform. The remote proof service can output both the first and second remote proof reports simultaneously, allowing users to verify whether the virtual machine's runtime environment has changed after deploying large model services.

[0071] Therefore, through the above implementation method, when deploying large model services, a second remote proof report can be provided to users, including a first metric of the trusted execution environment dimension, a second metric of the container stack dimension, and a third metric. This allows users to verify the trustworthiness of the virtual machine and container stack through the second remote proof report, which can greatly improve users' trust in the machine learning platform.

[0072] In some feasible implementations, the virtual machine has an access interface for accessing the virtual machine. Accordingly, access operations can also be recorded in the access control system in response to access operations targeting the access interface.

[0073] Here, an access control system is a tool or service used to record access operations. For example, an access control system can be a security audit platform. The access control system is deployed in a hardware-based trusted execution environment. That is, the access control system can be hardened using a hardware-based trusted execution environment to ensure its trustworthiness. For example, a hardware-based trusted execution environment can be a CPU TEE.

[0074] In this embodiment of the disclosure, the access control system is used to display recorded access operations to the user. For example, the access control system may, in response to a user's query request, display recorded access operations for a virtual machine to the user.

[0075] For PaaS layer operations personnel, the virtual machine provides an access interface through which they can access and maintain the runtime environment of a user's Pod. During this process, all access operations performed through this interface are recorded in the access control system and ultimately displayed to the user. Therefore, all access operations targeting the virtual machine are visible and transparent to the user.

[0076] It is worth noting that access operations to virtual machines can be recorded in the access control system in the form of screen recording and / or logs.

[0077] Therefore, by recording access operations to virtual machines in the access control system, all access operations can be recorded and transparently transmitted to the user, thus ensuring the security of the large model service's operating environment.

[0078] In some feasible implementations, the environmental metrics can also be synchronized to the access control system via the remote authentication service. The access control system is used to generate an operation log of the operating environment based on the environmental metrics. The operation log is used by the user to perform security verification of the operating environment.

[0079] Here, the remote authentication service can synchronize the environmental metrics corresponding to the operating environment to the access control system. Since the access control system runs in a hardware-based trusted execution environment, the trustworthiness of the access control system can be guaranteed. Therefore, the environmental metrics stored in the access control system are also trustworthy.

[0080] It is worth noting that by synchronizing the environmental metrics corresponding to the operating environment to the access control system, users can not only verify the security of the operating environment through remote authentication services, but also obtain environmental metrics from the access control system to verify the security of the operating environment through these environmental metrics.

[0081] After receiving environmental metrics, the access control system can generate runtime logs based on those metrics. These runtime logs can include the environmental metrics. Through these logs, users can verify the trustworthiness of the large model service's runtime environment using the information they possess. For example, users can use the runtime logs to verify whether a deployed image has been tampered with.

[0082] Therefore, by using the access control system, users can verify the credibility of the runtime environment used to deploy large model services, thereby increasing users' trust in the machine learning platform provided by the service provider.

[0083] Figure 2 This is a schematic diagram of a security verification system for a large-scale model service runtime environment, according to an exemplary embodiment. For example... Figure 2As shown, the container group is deployed within a virtual machine, which runs on a CPU TEE. This means that the bootloader, firmware, kernel, virtual machine, container group, kubelet, containerd, and runc are all hardened using the CPU TEE. When the target container corresponding to the large model service is deployed within the container group, environmental metrics corresponding to the runtime environment are collected by the initialization container created within the container group. These environmental metrics include the first metric of the CPU TEE, the second metric corresponding to the components included in the container orchestration platform, the third metric of the large model service, and the fourth metric of the trusted acceleration device (which may include a graphics processor and / or other trusted acceleration devices). The collected environmental metrics are then sent to the remote verification service via the initialization container. The remote verification service generates a remote verification report based on the environmental metrics. Users can access the remote verification service to obtain the corresponding remote verification report and use it to perform security verification of the large model service's runtime environment. Furthermore, the remote verification service can synchronize the environmental metrics to the access control system. The access control system can generate runtime logs based on the environmental metrics. Users can then use the runtime logs exposed by the access control system to perform security verification of the large model service's runtime environment. Of course, virtual machines have access interfaces. When PaaS layer operations personnel access the virtual machine through these interfaces, the access operations are recorded in the access control system. Users can access the access control system to view the access operations recorded by the access control system and / or the generated runtime logs, in order to perform security verification of the large model service's runtime environment.

[0084] In addition, since container groups run in hardened virtual machines within a hardware-based trusted execution environment, IaaS layer operations personnel cannot access the virtual machines without the virtual machine password, thus shielding against attacks from the IaaS layer.

[0085] Figure 3 This is a schematic diagram illustrating the structure of a security verification device for a large-scale model service runtime environment, according to an exemplary embodiment. For example... Figure 3 As shown, this disclosure provides a security verification device 300 for a large model service runtime environment, which includes:

[0086] The acquisition module 301 is configured to acquire environment metrics corresponding to the runtime environment used to deploy the large model service through the remote proof service; the large model service is deployed in a container group created in a virtual machine, the virtual machine is deployed in a hardware-based trusted execution environment, and the remote proof service is deployed in the hardware-based trusted execution environment; the environment metrics include at least a first metric corresponding to the trusted execution environment where the virtual machine is located and a container metric under the container stack dimension corresponding to the container group.

[0087] The generation module 302 is configured to generate a remote verification report based on the environmental metrics through the remote verification service. The remote verification report is used by users to perform security verification of the operating environment.

[0088] Optionally, the acquisition module 301 is specifically configured as follows:

[0089] In response to deploying the large model service in the container group, the environmental metrics are collected through an initialization container created in the container group;

[0090] The environmental metrics are uploaded to the remote proof service via the initialization container.

[0091] Optionally, the container metric includes a second metric corresponding to the components included in the container orchestration platform used to deploy the container group;

[0092] The acquisition module 301 is specifically configured as follows:

[0093] In response to initializing the virtual machine, the second metric and the first metric corresponding to the component are sent to the remote proof service;

[0094] The generation module 302 is specifically configured as follows:

[0095] The remote proof service generates a first remote proof report based on the second metric and the first metric. The first remote proof report is used by the user to perform security verification on the virtual machine.

[0096] Optionally, the container metrics include a second metric corresponding to the components of the container orchestration platform corresponding to the container group and a third metric related to the image of the large model service;

[0097] The acquisition module 301 is specifically configured as follows:

[0098] In response to deploying the large model service in the container group, the first metric, the second metric, and the third metric are sent to the remote proof service;

[0099] The generation module 302 is specifically configured as follows:

[0100] The remote verification service generates a second remote verification report based on the first metric, the second metric, and the third metric. The second remote verification report is used by the user to perform security verification on the operating environment.

[0101] Optionally, in response to the virtual machine being mounted with a trusted acceleration device, the environment metric further includes a fourth metric corresponding to the trusted execution environment of the trusted acceleration device.

[0102] Optionally, the virtual machine has an access interface for accessing the virtual machine; the security verification device 300 for the large model service runtime environment further includes:

[0103] A recording module is configured to record an access operation in response to an access operation on the access interface in an access control system deployed in a hardware-based trusted execution environment, the access control system being used to display the recorded access operation to a user.

[0104] Optionally, the security verification device 300 for the large model service runtime environment further includes:

[0105] The synchronization module is configured to synchronize the environmental metrics to the access control system via the remote authentication service. The access control system is used to generate an operation log of the operating environment based on the environmental metrics. The operation log is used by the user to perform security verification of the operating environment.

[0106] Regarding the security verification device 300 for the large model service runtime environment in the above embodiments, the method logic executed by each functional module has been described in detail in the section on methods, and will not be repeated here.

[0107] Figure 4 This is a schematic diagram of the structure of an electronic device according to an exemplary embodiment. Reference is made below. Figure 4 The diagram illustrates a structural schematic of an electronic device (e.g., a terminal device or a server) 400 suitable for implementing embodiments of the present disclosure. The terminal device in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 4 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.

[0108] like Figure 4As shown, electronic device 400 may include a processing device (e.g., a central processing unit, a graphics processor, etc.) 401, which can perform various appropriate actions and processes according to a program stored in read-only memory (ROM) 402 or a program loaded from storage device 408 into random access memory (RAM) 403. RAM 403 also stores various programs and data required for the operation of electronic device 400. Processing device 401, ROM 402, and RAM 403 are interconnected via bus 404. Input / output (I / O) interface 405 is also connected to bus 404.

[0109] Typically, the following devices can be connected to I / O interface 405: input devices 406 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 407 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 408 including, for example, magnetic tapes, hard disks, etc.; and communication devices 409. Communication device 409 allows electronic device 400 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 4 An electronic device 400 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively.

[0110] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication device 409, or installed from storage device 408, or installed from ROM 402. When the computer program is executed by processing device 401, it performs the functions defined in the methods of embodiments of this disclosure.

[0111] It should be noted that the computer-readable medium described in this disclosure can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this disclosure, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.

[0112] In some implementations, communication can be conducted using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol), and can be interconnected with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.

[0113] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.

[0114] The aforementioned computer-readable medium carries one or more programs. When these programs are executed by the electronic device, the electronic device causes the following: It obtains an environment metric corresponding to the runtime environment used to deploy a large model service via a remote verification service. The large model service is deployed in a container group created in a virtual machine, the virtual machine is deployed in a hardware-based trusted execution environment, and the remote verification service is deployed in the hardware-based trusted execution environment. The environment metric includes at least a first metric corresponding to the trusted execution environment where the virtual machine resides and a container metric at the container stack dimension corresponding to the container group. The remote verification service generates a remote verification report based on the environment metric, and the remote verification report is used by a user to perform security verification of the runtime environment.

[0115] Computer program code for performing the operations of this disclosure can be written in one or more programming languages ​​or a combination thereof, including but not limited to object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0116] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0117] The modules described in the embodiments of this disclosure can be implemented in software or hardware. The names of the modules are not, in some cases, intended to limit the functionality of the module itself.

[0118] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), and so on.

[0119] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0120] The above description is merely a preferred embodiment of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features disclosed in this disclosure that have similar functions.

[0121] Furthermore, while the operations are described in a specific order, this should not be construed as requiring these operations to be performed in the specific order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.

[0122] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative forms of implementing the claims. Regarding the apparatus in the above embodiments, the specific manner in which the various modules perform their operations has been described in detail in the embodiments relating to the method, and will not be elaborated upon here.

Claims

1. A security verification method for a large model service runtime environment, characterized in that, include: The remote proof service obtains the environment metrics corresponding to the runtime environment used to deploy the large model service; the large model service is deployed in a container group created in a virtual machine, the virtual machine is deployed in a hardware-based trusted execution environment, and the remote proof service is deployed in the hardware-based trusted execution environment; the environment metrics include at least a first metric corresponding to the trusted execution environment where the virtual machine is located and a container metric under the container stack dimension corresponding to the container group. The remote verification service generates a remote verification report based on the environmental metrics. The remote verification report is used by users to perform security verification of the operating environment. The step of obtaining environmental metrics corresponding to the runtime environment used to deploy large model services through remote proof services includes: In response to deploying the large model service in the container group, the environment metrics are collected through an initialization container created in the container group. The container metrics include a second metric corresponding to the components of the container orchestration platform corresponding to the container group and a third metric of the image related to the large model service. In response to the virtual machine being mounted with a trusted acceleration device, the environment metrics also include a fourth metric corresponding to the trusted execution environment of the trusted acceleration device. The first metric, the second metric, the third metric, and the fourth metric are collected through the initialization container. The initialization container is a container used to run initialization tasks before the application container starts. The environmental metrics are uploaded to the remote proof service via the initialization container. The virtual machine has an access interface for accessing the virtual machine; the method further includes: In response to an access operation for the access interface, the access operation is recorded in the access control system, which is deployed in a hardware-based trusted execution environment. The access control system is used to display the recorded access operation to the user and is a security audit platform.

2. The method according to claim 1, characterized in that, The step of obtaining environmental metrics corresponding to the runtime environment used to deploy large model services through remote proof services includes: In response to initializing the virtual machine, the second metric and the first metric corresponding to the component are sent to the remote proof service; The process of generating a remote proof report based on the environmental metrics through the remote proof service includes: The remote proof service generates a first remote proof report based on the second metric and the first metric. The first remote proof report is used by the user to perform security verification on the virtual machine.

3. The method according to claim 1, characterized in that, The step of obtaining environmental metrics corresponding to the runtime environment used to deploy large model services through remote proof services includes: In response to deploying the large model service in the container group, the first metric, the second metric, and the third metric are sent to the remote proof service; The process of generating a remote proof report based on the environmental metrics through the remote proof service includes: The remote verification service generates a second remote verification report based on the first metric, the second metric, and the third metric. The second remote verification report is used by the user to perform security verification on the operating environment.

4. The method according to claim 1, characterized in that, The method further includes: The remote authentication service synchronizes the environmental metrics to the access control system. The access control system generates an operation log for the operating environment based on the environmental metrics. The operation log is used by users to perform security verification on the operating environment.

5. A security verification device for a large model service runtime environment, characterized in that, include: The acquisition module is configured to acquire environment metrics corresponding to the runtime environment used to deploy the large model service via a remote proof service; the large model service is deployed in a container group created in a virtual machine, the virtual machine is deployed in a hardware-based trusted execution environment, and the remote proof service is deployed in a hardware-based trusted execution environment; the environment metrics include at least a first metric corresponding to the trusted execution environment where the virtual machine is located and a container metric under the container stack dimension corresponding to the container group; The generation module is configured to generate a remote proof report based on the environment metrics through the remote proof service. The remote proof report is used by users to perform security verification of the operating environment. The acquisition module is specifically configured as follows: In response to deploying the large model service in the container group, the environment metrics are collected through an initialization container created in the container group. The container metrics include a second metric corresponding to the components of the container orchestration platform corresponding to the container group and a third metric of the image related to the large model service. In response to the virtual machine being mounted with a trusted acceleration device, the environment metrics also include a fourth metric corresponding to the trusted execution environment of the trusted acceleration device. The first metric, the second metric, the third metric, and the fourth metric are collected through the initialization container. The initialization container is a container used to run initialization tasks before the application container starts. The environmental metrics are uploaded to the remote proof service via the initialization container. The virtual machine has an access interface for accessing the virtual machine; The security verification device for the large model service runtime environment also includes: A recording module is configured to record an access operation in response to an access operation on the access interface in an access control system deployed in a hardware-based trusted execution environment. The access control system is used to display the recorded access operation to the user and is a security audit platform.

6. A computer-readable medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processing device, it implements the steps of the method according to any one of claims 1-4.

7. An electronic device, characterized in that, include: A storage device on which computer programs are stored; A processing device for executing the computer program in the storage device to implement the steps of the method according to any one of claims 1-4.

8. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1-4.

Citation Information

Patent Citations

  • Method and device for verifying credibility, electronic equipment and medium

    CN117574384A

  • Zero-trust remote authentication service deployment system based on confidential virtual machine

    CN118171257A