Model service verification method and model service system

By setting up an isolated execution environment in the model service device and utilizing an encrypted communication channel, the problems of the model service device being unable to securely deploy inference models and the client device being unable to verify reliability are solved, thereby realizing the security and trustworthiness verification of the model inference service and preventing user data leakage.

CN120832681BActive Publication Date: 2025-12-12LANGCHAO ELECTRONIC INFORMATION IND CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202511317413.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-16
Publication Date
2025-12-12
Estimated Expiration
2045-09-16

AI Technical Summary

Technical Problem

The model service device cannot securely deploy inference models, and the client device cannot verify the reliability of the model service device, resulting in the leakage of user data.

Method used

An isolated execution environment for the processor and acceleration device is set up in the model service device, and data is exchanged through an encrypted communication channel. The client device verifies the metric data of the isolated execution environment to ensure trustworthiness.

Benefits of technology

This enhances the security of model inference services, prevents user data leakage, and ensures the trustworthiness of model service devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120832681B_ABST
    Figure CN120832681B_ABST
Patent Text Reader

Abstract

The application discloses a model service verification method and a model service system, and relates to the technical field of computers.In the method, the processor and the acceleration device in the model service device are both provided with isolated execution environments, and the inference model is deployed in the isolated execution environment of the acceleration device, so that the security of the inference model deployment can be improved.In addition, before a client device issues an inference model task to the model service device, the model service device can be requested to provide environment measurement data of the isolated execution environments of the processor and the acceleration device, and the credibility of the model service device can be verified according to the environment measurement data, so that the inference model task is issued after it is determined that the model service device is credible, the verification of the model service device by the client device can be realized, the risk of user data leakage can be further reduced, and the security of the model inference service can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and in particular to a model service verification method and a model service system. Background Technology

[0002] With the continuous development of artificial intelligence technology, more and more users are starting to use model inference services. However, in related technologies, on the one hand, model service devices cannot securely deploy inference models, and on the other hand, client devices cannot verify the reliability of model service devices, which can easily lead to user data leakage. Summary of the Invention

[0003] This invention provides a model service verification method and a model service system, which can isolate and deploy inference models in model service devices and enable client devices to verify the model service devices and inference models, thereby improving the security of model inference services.

[0004] To address the aforementioned technical problems, this invention provides a model service verification method applied to a model service device. The model service device includes a processor and an acceleration device. The processor has a first isolated execution environment, and the acceleration device has a second isolated execution environment. An inference model runs in the acceleration device. The processor and the acceleration device establish an encrypted communication channel between the first and second isolated execution environments. The method includes:

[0005] When the processor receives a proof request from the client device, it generates first environment metric data for the first isolated execution environment and sends the environment metric request to the acceleration device through an encrypted communication channel.

[0006] When the acceleration device receives an environment measurement request, it generates second environment measurement data for the second isolated execution environment and inference model, and sends the second environment measurement data to the processor through an encrypted communication channel.

[0007] The processor integrates the first environmental metric data and the second environmental metric data into a proof report, and sends the proof report to the client device so that the client device can verify the proof report through the proof service device and send a model inference task to the model service device when it determines that the proof report has passed the verification.

[0008] This invention also provides a model service verification method, applied to a proof service device, comprising:

[0009] Receive the certification report sent by the client device, and extract the first environmental measurement data and the second environmental measurement data from the certification report;

[0010] The first environmental measurement data and the second environmental measurement data are verified separately, and it is determined whether both the first environmental measurement data and the second environmental measurement data pass the verification.

[0011] If both the first and second environmental measurement data are verified, a verification pass message is sent to the client device.

[0012] If it is determined that the first environmental measurement data or the second environmental measurement data has failed verification, a verification failure message is sent to the client device.

[0013] This invention also provides a model service verification method, applied to a client device, the method comprising:

[0014] Send a proof request to the model service device and receive a proof report returned by the model service device;

[0015] Send a verification report to the verification service device and determine whether the verification service device returns a verification success message;

[0016] When the verification service device returns a successful verification message, a model inference task is sent to the model service device.

[0017] The present invention also provides a model service system, including: a model service device, a client device, and a proof service device. The model service device includes a processor and an acceleration device. The processor has a first isolated execution environment, and the acceleration device has a second isolated execution environment. The second isolated execution environment contains a reasoning model.

[0018] A model service device is used to execute model service verification methods applied to the model service device.

[0019] The client device is used to execute the model service verification method applied to the client device.

[0020] A proof service device is used to execute model service verification methods applied to the proof service device.

[0021] The beneficial effects of this invention are as follows: The model service device may include a processor and an acceleration device. The processor has a first isolated execution environment, and the acceleration device has a second isolated execution environment. An inference model runs in the acceleration device, and the processor and acceleration device establish an encrypted communication channel between the first and second isolated execution environments. Since the isolated execution environment can effectively resist external attacks, the model service device can securely deploy the inference model. Furthermore, the processor can establish an encrypted communication channel between the first and second isolated execution environments, enabling encrypted communication. Subsequently, when the processor receives a proof request from a client device, it can generate first environment measurement data for the first isolated execution environment and send the environment measurement request to the acceleration device through the encrypted communication channel. When the acceleration device receives the environment measurement request, it generates second environment measurement data for the second isolated execution environment and the inference model, and sends the second environment measurement data to the processor through the encrypted communication channel. Finally, the processor integrates the first and second environment measurement data into a proof report and sends the proof report to the client device, allowing the client device to verify the proof report through the proof service device and, upon determining that the proof report has passed verification, send a model inference task to the model service device. As can be seen, the processor and acceleration device can exchange data through an encrypted communication channel, and both the processor and acceleration device can generate environmental metric data for their own isolated execution environment and return it to the client device for verification. Thus, this invention also enables the client device to verify the trustworthiness of the model service device, thereby preventing user data leakage and improving the security of using the model inference service.

[0022] The present invention also provides a model service system, which has the above-mentioned beneficial effects. Attached Figure Description

[0023] To more clearly illustrate the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0024] Figure 1 This is a structural block diagram of a model service system provided in an embodiment of the present invention;

[0025] Figure 2 A flowchart of the first model service verification method provided in this embodiment of the invention;

[0026] Figure 3 A flowchart of the second model service verification method provided in this embodiment of the invention;

[0027] Figure 4 A flowchart of the third model service verification method provided in this embodiment of the invention;

[0028] Figure 5 This is a flowchart illustrating a model service verification method provided in an embodiment of the present invention. Detailed Implementation

[0029] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the protection scope of the present invention.

[0030] It should be noted that, in the description of this invention, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. The terms "first," "second," etc., used in this invention are used to distinguish similar objects and are not used to describe a specific order or sequence.

[0031] To enable those skilled in the art to better understand the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0032] With the continuous development of artificial intelligence technology, more and more users are starting to use model inference services. However, in related technologies, on the one hand, model service devices cannot securely deploy inference models. For example, when deploying inference models on acceleration devices, the security boundary cannot be extended to the acceleration devices, which can easily lead to the leakage of user data on the acceleration device side. On the other hand, client devices cannot verify the reliability of model service devices, which can also easily lead to the leakage of user data.

[0033] In view of this, regarding the technical issues of how to improve the security of model inference services, ensure that inference models can be securely deployed on model service devices, and ensure that user devices can verify model service devices, this invention provides a model service verification method. In this method, both the processor and acceleration device in the model service device are equipped with isolated execution environments, and the inference model is deployed within the isolated execution environment of the acceleration device, thereby improving the security of inference model deployment. Furthermore, before sending a model inference task to the model service device, the client device can request environmental measurement data of the isolated execution environments of both the processor and acceleration device. The trustworthiness of the model service device can be verified based on this environmental measurement data. Thus, the model inference task is only sent after the trustworthiness of the model service device is confirmed. This enables the client device to verify the model service device, further reducing the risk of user data leakage and thereby improving the security of the model inference service.

[0034] The model service system applicable to this embodiment is described below. Please refer to... Figure 1 , Figure 1 This is a structural block diagram of a model service system provided in an embodiment of the present invention. The system may include a model service device, a client device, and a verification service device. The client device establishes communication connections with both the model service device and the verification service device. The model service device, client device, and verification service device are described separately below.

[0035] The model service device may include a processor and acceleration devices, which can be connected via a bus, such as a PCIe bus (Peripheral Component Interconnect express, a high-speed serial computer expansion bus standard). Acceleration devices can be graphics cards, programmable logic devices (such as FPGAs, ASICs, Field-Programmable Gate Arrays, Application-Specific Integrated Circuits), or other dedicated devices for executing model tasks. Furthermore, multiple acceleration devices can be configured in the model service device to meet users' model inference needs. The processor has a first isolated execution environment, which can consist of independent computing cores, independent memory, and an independent software environment. A model service application can be configured in the first isolated execution environment to interact with client devices and acceleration devices. The acceleration device has a second isolated execution environment, which can also consist of independent computing cores, independent memory, and an independent software environment. The acceleration device can run inference models in the second isolated execution environment, which provide model inference services. These inference models can be various types of models, such as pre-trained language models or pre-trained image processing models.

[0036] Furthermore, to prevent the transmission of plaintext data between the processor and the acceleration device, which could lead to the interception and leakage of user data in the transmission link between the processor and the acceleration device, the processor and the acceleration device can establish an encrypted communication channel between a first isolated execution environment and a second isolated execution environment. This ensures that the two isolated execution environments interact with data through the encrypted communication channel. For example, the processor can set up a first secure communication module in the first isolated execution environment, and the acceleration device can set up a second secure communication module in the second isolated execution environment. The first secure communication module and the second secure communication module can negotiate the encrypted communication channel, such as negotiating the encryption key required for communication, thereby completing the construction of the encrypted communication channel. The establishment of the encrypted communication channel can occur when the first and second isolated execution environments complete initialization. In this way, the processor and the acceleration device can perform encrypted data transmission based on this encrypted communication channel. For example, during bus data transmission (such as when the processor and the acceleration device transmit data through the PCIe bus), encrypted data can be transmitted between the processor and the acceleration device. At this time, the processor has a first isolated execution environment, and the acceleration device has a second isolated execution environment. The first and second isolated execution environments can communicate encryptedly, which can improve the deployment security of the inference model and the transmission security of user data within the model service device.

[0037] Furthermore, both the processor and the acceleration device have the capability to perform environmental measurements on their own isolated execution environments and provide the environmental measurement data to external devices (such as client devices) for verification. Specifically, a first trusted measurement module can be set up in the first isolated execution environment of the processor to perform trusted measurements on the first isolated execution environment; a second trusted measurement module can be set up in the second isolated execution environment of the acceleration device to perform trusted measurements on the second isolated execution environment. The first trusted measurement module also has the function of sending environmental measurement requests to the acceleration device and collecting the environmental measurement data returned by the acceleration device. In this way, external devices (such as client devices) can comprehensively verify the trustworthiness of the model service device, thereby improving the security of the model inference service.

[0038] The client device is a terminal device used by the user, such as a personal computer or mobile device (e.g., a mobile phone, tablet, etc.). Unlike related technologies, in this embodiment, before issuing a model inference task to the model service device, the client device can first send a proof request to the latter. This triggers the latter to generate environmental measurement data in its internal isolated execution environment, generate a proof report using the environmental measurement data, and send the proof report to the client device. Subsequently, the client device can request the proof service device to verify the proof report. Upon receiving the verification result from the proof service device, if the client device determines that the verification is successful, it can issue a model inference task to the model service device. Conversely, if the verification result is unsuccessful, the client device can choose not to issue the model inference task, thereby preventing user data leakage.

[0039] The verification service device is used to verify the verification report of the model service device. The verification service device can pre-store benchmark data for verifying the verification report. Furthermore, the verification service device can interface with verification platforms provided by various device manufacturers, enabling verification of processors and accelerators from different manufacturers. Upon receiving a request from a client device, the verification service device can verify the verification report, and only determines that the verification report has passed verification if the environmental metric data of the processor and accelerator in the model service device have all passed verification. This allows for complete verification of the trustworthiness of the model service device, effectively ensuring the reliability of the model inference service.

[0040] Based on the above system structure description, the model service verification method provided by the embodiments of the present invention will be introduced below. First, the implementation method on the model service device side will be described. Please refer to... Figure 2 , Figure 2This is a flowchart of a first model service verification method provided in an embodiment of the present invention. The method is applied to a model service device, which includes a processor and an acceleration device. The processor has a first isolated execution environment, and the acceleration device has a second isolated execution environment. An inference model runs in the acceleration device. The processor and the acceleration device establish an encrypted communication channel between the first and second isolated execution environments. The method may include:

[0041] S101. When the processor receives the proof request sent by the client device, it generates first environment measurement data for the first isolated execution environment and sends the environment measurement request to the acceleration device through the encrypted communication channel.

[0042] In this embodiment, the processor can set up a model service application in the first isolated execution environment. By running this application, the processor can establish network communication with external client devices within the first isolated execution environment. As described above, to ensure security, the client device can first send a verification request after establishing a session with the model service device. When the processor receives this verification request, it will first perform an environment measurement operation on its own first isolated execution environment to obtain first environment measurement data.

[0043] Specifically, to ensure secure communication between the client device and the processor, when the processor receives a session establishment request from the client device, it can establish an encrypted session between the client device and the first isolated execution environment. Subsequently, the client device can send an authentication request to the first isolated execution environment through this encrypted session to trigger the processor to perform environment measurement operations.

[0044] Based on this, the method may also include:

[0045] Step 11: When the processor receives a session establishment request from the client device, it establishes an encrypted session between the client device and the first isolated execution environment.

[0046] Accordingly, receiving a proof request sent by the client device may include:

[0047] Step 21: Receive the authentication request sent by the client device via an encrypted session.

[0048] In one specific implementation, generating first environment metric data for the first isolated execution environment may include:

[0049] Step 31: The processor extracts the first random number from the proof request and obtains the metadata of the first isolated execution environment, the processor's processor certificate, and security version information.

[0050] In this step, to achieve the verification effect, the client device can first set a first random number in the proof request. The processor needs to sign this first random number to prove the validity of this round of verification. Therefore, upon receiving a proof request, the processor needs to extract the first random number from the proof request.

[0051] In addition, the processor needs to obtain a processor certificate, which is an identity certificate built into the processor by the device manufacturer during the production stage. By generating a signature using the processor certificate's private key and providing the processor certificate to external devices for signature verification, the processor can provide external devices with a way to verify its identity.

[0052] In addition, the processor needs to obtain the metadata of the first isolated execution environment (IEX) and the processor's security version information. The metadata includes the information required to construct the IEX, indicating whether the IEX was constructed correctly. The security version information indicates the processor's security level.

[0053] Step 32: Perform hash processing on the executable code, data segment, and memory stack in the first isolated execution environment to obtain the first identification information of the first isolated execution environment.

[0054] In this step, to demonstrate that the program code within the first isolated execution environment has not been tampered with, and thus prove that the first isolated execution environment can effectively resist external attacks, the processor also needs to perform hash processing on the executable code, data segment, and memory stack in the first isolated execution environment to obtain the first identification information of the first isolated execution environment. When the first isolated execution environment is not damaged, this first identification information should be consistent with the pre-saved baseline data.

[0055] Step 33: Use the private key of the processor certificate to sign the first random number, the first identification information, the metadata, and the security version information to obtain the first signature value, and integrate the processor certificate and the first signature value into the first environment measurement data.

[0056] In this step, the processor can use the private key of the processor certificate to sign the first random number, the first identification information, the metadata, and the security version information to obtain the first signature value, and integrate the processor certificate and the first signature value into the first environmental measurement data so that external devices can use the processor certificate to verify the first signature value.

[0057] Furthermore, the processor can also send an environment measurement request to the acceleration device via an encrypted communication channel to trigger the acceleration device to perform an environment measurement operation on its own second isolated execution environment, and send the obtained second environment measurement data to the processor. Similarly, to achieve the verification effect, the client device can first set a second random number in the verification request. The acceleration device needs to sign this second random number to prove the validity of this round of verification. Therefore, when generating the environment measurement request, the processor must include this second random number in the environment measurement request.

[0058] In one implementation, sending an environmental measurement request to the acceleration device via an encrypted communication channel may include:

[0059] Step 41: The processor extracts a second random number from the proof request, uses the second random number to generate an environmental measurement request, and sends the environmental measurement request to the acceleration device through an encrypted communication channel.

[0060] Furthermore, since different types of acceleration devices and acceleration device manufacturers support different triggering methods for environmental measurement operations, the processor needs to call the corresponding acceleration device driver interface to send an environmental measurement request to the acceleration device according to the device type of the acceleration device.

[0061] In one implementation, sending an environmental metric request to the acceleration device via an encrypted communication channel includes:

[0062] Step 51: Based on the device type of the acceleration device, the processor calls the driver interface of the acceleration device to send an environmental metric request to the acceleration device through an encrypted communication channel.

[0063] S102. When the acceleration device receives an environment measurement request, it generates second environment measurement data for the second isolated execution environment and inference model, and sends the second environment measurement data to the processor through an encrypted communication channel.

[0064] In this embodiment, similar to the processor, when the acceleration device receives an environment measurement request, it also needs to perform environment measurement operations for its own second isolated execution environment to obtain second environment measurement data. However, unlike the processor, considering that the integrity and reliability of the inference model also affect the model's inference performance, the acceleration device also needs to consider the integrity and reliability of the inference model when performing environment measurement operations. It needs to generate second environment measurement data for both the second isolated execution environment and the inference model simultaneously, and then send the second environment measurement data to the processor through an encrypted communication channel.

[0065] In one specific implementation, generating second environment metric data for the second isolated execution environment and the inference model may include:

[0066] Step 61: The acceleration device extracts the second random number from the environmental metric request and obtains the acceleration device certificate.

[0067] In this step, the acceleration device needs to extract a second random number from the environmental metric request and sign the second random number to prove the validity of this round of verification.

[0068] In addition, the acceleration device needs to obtain an acceleration device certificate, which is an identity certificate built into the acceleration device by the device manufacturer during the production stage. By generating a signature using the private key of the acceleration device certificate and providing the acceleration device certificate to external devices for signature verification, the acceleration device can provide external devices with a way to verify the identity of the acceleration device.

[0069] Step 62: Hash the hardware and firmware information of the second isolated execution environment to obtain the second identifier information of the second isolated execution environment, and hash the model code of the inference model to obtain the model baseline information.

[0070] In this step, to demonstrate that the second isolated execution environment has not been compromised, the acceleration device can perform hash processing on the hardware information (such as hardware parameters, register states, and BIOS information) and firmware information of the second isolated execution environment to obtain a second identification information for the second isolated execution environment. When the second isolated execution environment is not compromised, this second identification information should be consistent with the pre-saved baseline data.

[0071] Furthermore, to verify the integrity of the inference model, the acceleration device can also perform hashing on the model code of the inference model to obtain model baseline information. Similarly, when the inference model has not been tampered with, the model baseline information should be consistent with the pre-saved baseline data.

[0072] Step 63: Use the private key of the acceleration device certificate to sign the second random number, the second identification information, and the model benchmark information to obtain the second signature value, and integrate the acceleration device certificate and the second signature value into the second environmental measurement data.

[0073] In this step, the acceleration device can use the certificate private key of the acceleration device certificate to sign the second random number, the second identification information, and the model benchmark information to obtain the second signature value, and integrate the acceleration device certificate and the second signature value into the second environmental metric data so that external devices can use the acceleration device certificate to verify the second signature value.

[0074] S103, the processor integrates the first environmental metric data and the second environmental metric data into a proof report, and sends the proof report to the client device so that the client device can verify the proof report through the proof service device and send a model inference task to the model service device when it determines that the proof report has passed the verification.

[0075] In this embodiment, the processor can integrate the first environmental metric data and the second environmental metric data into a proof report and send the proof report to the client device. The client device can verify the proof report through the proof service device, and send a model inference task to the model service device when the proof report passes verification, thereby ensuring the security of the model inference service. Of course, before forwarding the proof report to the proof service device, the client device can also add other information to the proof report, such as a first random number, a second random number, and a timestamp.

[0076] It is worth noting that steps S102 to S104 can be periodically triggered by the client device, which can ensure the security of the model inference service in the long term.

[0077] The process of the model service device executing the model inference task sent by the client device is described below. In one embodiment, the method may further include:

[0078] Step 71: When the processor receives the model inference task sent by the client device, it sends the model inference task to the acceleration device through the encrypted communication channel.

[0079] Step 72: The acceleration device uses the inference model to execute the model inference task and sends the task execution result to the processor through an encrypted communication channel.

[0080] Step 73: The processor sends the task execution result to the client device.

[0081] In steps 71-73, the client device can send the model inference task to the processor's first isolated execution environment. Subsequently, the processor can issue the model inference task to the acceleration device via an encrypted communication channel. The acceleration device can then execute the model inference task using the inference model and send the task execution result to the processor via the encrypted communication channel. The processor, in turn, sends the task execution result to the client device through the model application, thus completing one round of model inference service.

[0082] Furthermore, the processor can send the proof report to the client device via a pre-built encrypted session.

[0083] Based on this, sending the proof report to the client device may include:

[0084] Step 81: Send a proof report to the client device via an encrypted session.

[0085] Furthermore, when a client device needs to deploy a model to the model service device, it can first verify the processor and acceleration device. Once the processor and acceleration device pass verification, the client device sends the model to be deployed to the processor. Upon receiving the model from the client device, the processor can deploy the model to the second isolated execution environment of the acceleration device via an encrypted communication channel. It is important to note that, for subsequent verification purposes, the client device must store the model baseline information of the model to be deployed on the verification service device before deploying the model.

[0086] In one embodiment, the method may further include:

[0087] Step 91: When the processor receives the model to be deployed from the client device, it deploys the model to be deployed to the second isolated execution environment of the acceleration device through an encrypted communication channel; when the client device determines that the proof report has passed verification, it sends the model to be deployed to the model service device, and the model baseline information of the model to be deployed is stored in the proof service device.

[0088] Based on the above embodiments, the model service device may include a processor and an acceleration device. The processor has a first isolated execution environment, and the acceleration device has a second isolated execution environment. An inference model runs in the acceleration device, and the processor and acceleration device establish an encrypted communication channel between the first and second isolated execution environments. Since the isolated execution environment can effectively resist external attacks, the model service device can securely deploy the inference model first. Furthermore, the processor can establish an encrypted communication channel between the first and second isolated execution environments, enabling encrypted communication. Subsequently, when the processor receives a proof request from the client device, it can generate first environment measurement data for the first isolated execution environment and send the environment measurement request to the acceleration device through the encrypted communication channel. When the acceleration device receives the environment measurement request, it generates second environment measurement data for the second isolated execution environment and the inference model, and sends the second environment measurement data to the processor through the encrypted communication channel. Finally, the processor integrates the first and second environment measurement data into a proof report and sends the proof report to the client device, allowing the client device to verify the proof report through the proof service device. If the client device determines that the proof report has passed verification, it sends a model inference task to the model service device. As can be seen, the processor and acceleration device can exchange data through an encrypted communication channel, and both the processor and acceleration device can generate environmental metric data for their own isolated execution environment and return it to the client device for verification. Thus, this invention also enables the client device to verify the trustworthiness of the model service device, thereby preventing user data leakage and improving the security of using the model inference service.

[0089] The following describes the implementation of this method on the proof service equipment side. Please refer to... Figure 3 , Figure 3 This is a flowchart of a second model service verification method provided in an embodiment of the present invention. This method is applied to a proof service device and may include:

[0090] S201. Receive the certification report sent by the client device, and extract the first environmental measurement data and the second environmental measurement data from the certification report.

[0091] As described above, the first environmental metric data is generated by the processor of the model service device, and the second environmental metric data is generated by the acceleration device of the model service device. By verifying the first and second environmental metric data, it is demonstrated that the service device can determine the trustworthiness of the processor and acceleration device of the model service device.

[0092] S202. Verify the first environmental measurement data and the second environmental measurement data respectively, and determine whether the first environmental measurement data and the second environmental measurement data both pass the verification.

[0093] In this embodiment, the verification service device needs to verify the first environmental measurement data and the second environmental measurement data separately, and determine whether both the first environmental measurement data and the second environmental measurement data have passed verification. The verification service device only sends verification success information to the client device when it determines that both the first environmental measurement data and the second environmental measurement data have passed verification; otherwise, it sends verification failure information to the client device.

[0094] In one specific implementation, validating the first environmental measurement data may include:

[0095] Step 1001: Extract the first random number from the proof report, and extract the processor certificate and the first signature value from the first environmental metric data.

[0096] In this step, the client device can add a first random number to the verification report, which verifies the authenticity of the first random number in the first environmental measurement data. Therefore, the verification service device can extract the first random number from the verification report.

[0097] In addition, the proof service device can extract the processor certificate and the first signature value from the first environmental measurement data, and use the processor certificate to verify the first signature value.

[0098] Step 1002: Determine if the processor certificate has been revoked.

[0099] As mentioned above, since processor certificates can be issued by processor manufacturers, and processor manufacturers can set up verification platforms to verify the validity of processor certificates, the verification service device can access the verification platform provided by the processor manufacturer and verify the validity of the processor certificate. If it is determined that the processor certificate has been revoked, the first environmental measurement data can be directly determined to be invalid; otherwise, the signature verification process can proceed.

[0100] Step 1003: If it is determined that the processor certificate has not been revoked, the processor certificate is used to decrypt the first signature value to obtain the first decrypted value, and the first decrypted value is verified using the first random number and the first preset benchmark value to determine whether the first decrypted value passes the verification.

[0101] In this step, if it is determined that the processor certificate has not been revoked, the first signature value can be decrypted using the processor certificate to obtain the first decrypted value. The first decrypted value is then verified using a first random number and a first preset benchmark value to determine whether it passes verification. The first preset benchmark value can be set based on the metadata of the first isolated execution environment in the processor, the first identification data, and the processor's security version information. Furthermore, the first random number, the first preset benchmark value, and the first decrypted value can be compared. If they match, the first decrypted value is determined to have passed verification; otherwise, it is determined to have failed verification.

[0102] Step 1004: If the first decrypted value is found to pass the verification, then the first environmental measurement data is determined to have passed the verification.

[0103] Step 1005: If it is determined that the processor certificate has been revoked, or that the first decryption value has failed verification, then the first environmental measurement data is determined to have failed verification.

[0104] In steps 1004-1005, if it is determined that the processor certificate has not been revoked and the first decryption value passes verification, then the first environmental measurement data can be determined to have passed verification. Conversely, if it is determined that the processor certificate has been revoked or the first decryption value fails verification, then the first environmental measurement data can be determined to have failed verification, and consequently, the verification report can be determined to have failed verification.

[0105] In another specific implementation, validating the second environmental measurement data may include:

[0106] Step 1101: Extract the second random number from the proof report, and extract the acceleration device certificate and second signature value from the second environmental metric data.

[0107] In this step, the client device can add a second random number to the verification report, which verifies the authenticity of the second random number in the second environmental metric data. Therefore, the verification service device can extract the second random number from the verification report.

[0108] In addition, the verification service device can extract the acceleration device certificate and the second signature value from the second environmental measurement data, and use the acceleration device certificate to verify the second signature value.

[0109] Step 1102: Determine whether the accelerator equipment certificate has been revoked.

[0110] As mentioned above, since acceleration device certificates can be issued by acceleration device manufacturers, and these manufacturers can set up verification platforms to validate the certificates, the certificate service device can access the verification platform provided by the acceleration device manufacturer and verify the validity of the certificates. If the acceleration device certificate is determined to be revoked, the second environmental measurement data can be directly deemed invalid; otherwise, the signature verification process can proceed.

[0111] Step 1103: If it is determined that the acceleration device certificate has not been revoked, the second signature value is decrypted using the acceleration device certificate to obtain the second decrypted value, and the second decrypted value is verified using the second random number and the second preset benchmark value to determine whether the second decrypted value passes the verification; the second preset benchmark value contains model benchmark information.

[0112] In this step, if it is determined that the acceleration device certificate has not been revoked, the second signature value can be decrypted using the acceleration device certificate to obtain the second decrypted value. The second decrypted value is then verified using a second random number and a second preset benchmark value to determine if it passes verification. The second preset benchmark value can be set based on the second identifier data of the second isolated execution environment in the acceleration device. Furthermore, to verify the integrity of the model, the second preset benchmark value can also include model benchmark information. Subsequently, the second random number, the second preset benchmark value, and the second decrypted value can be compared. If they match, the second decrypted value is determined to have passed verification; otherwise, it is determined to have failed verification.

[0113] Step 1104: If the second decrypted value is found to pass the verification, then the second environmental measurement data is deemed to have passed the verification.

[0114] Step 1105: If it is determined that the acceleration device certificate has been revoked, or that the second decryption value has failed verification, then the second environmental measurement data has failed verification.

[0115] In steps 1104-1105, if it is determined that the acceleration device certificate has not been revoked and the second decryption value passes verification, then the second environmental measurement data can be determined to have passed verification. Conversely, if it is determined that the acceleration device certificate has been revoked, or the second decryption value fails verification, then the second environmental measurement data can be determined to have failed verification, and consequently, the verification report can be determined to have failed verification.

[0116] S203. If it is determined that both the first environmental measurement data and the second environmental measurement data have passed verification, then send verification pass information to the client device.

[0117] S204. If it is determined that the first environmental measurement data or the second environmental measurement data has failed verification, a verification failure message is sent to the client device.

[0118] Furthermore, when deploying a model, the client device can save the model baseline information of the model to be deployed to this proof service device in advance.

[0119] In one embodiment, the method may further include:

[0120] Step 1201: When the model baseline information of the model to be deployed is received from the client device, the model baseline information is saved.

[0121] The following describes the implementation of this method on the client device side. Please refer to... Figure 4 , Figure 4 This is a flowchart of a third model service verification method provided in an embodiment of the present invention. This method is applied to a client device and may include:

[0122] S301. Send a proof request to the model service device and receive a proof report returned by the model service device.

[0123] In this embodiment, unlike related technologies, the client device can send a proof request to the model service device before issuing the model inference task to the model service device. This triggers the latter to generate environmental measurement data for its internal isolated execution environment, generate a proof report using the environmental measurement data, and send the proof report to the client device.

[0124] Specifically, to ensure the validity of the device proof, the client device can generate a first random number corresponding to the processor and a second random number corresponding to the acceleration device, and add the first and second random numbers to the proof request. The processor needs to sign the first random number, and the acceleration device needs to sign the second random number to achieve the proof effect.

[0125] In one implementation, sending a proof request to the model service device may include:

[0126] Step 1301: Generate a first random number and a second random number, use the first random number and the second random number to generate a proof request, and send the proof request to the model service device.

[0127] S302. Send a verification report to the verification service device and determine whether the verification service device returns a verification success message.

[0128] In this embodiment, the client device can request the verification of the verification report from the verification service device. Subsequently, upon receiving the verification result returned by the verification service device, if the client device determines that the verification result is successful, it can issue a model inference task to the model service device. Conversely, if the verification result is determined to be a failure, the client device can choose not to issue a model inference task, thereby preventing user data leakage.

[0129] Specifically, the client device can add the aforementioned first and second random numbers to the proof report so that the proof service device can perform verification.

[0130] In one implementation, sending a certification report to the certification service device may include:

[0131] Step 1401: Add the first random number and the second random number to the proof report, and send the proof report to the proof service device.

[0132] S303. When the verification service device returns a successful verification message, send a model inference task to the model service device.

[0133] Furthermore, when a client device needs to deploy a model to the model service device, it can first verify the processor and acceleration device. Once the processor and acceleration device pass verification, the client device sends the model to be deployed to the processor. Upon receiving the model from the client device, the processor can deploy the model to the second isolated execution environment of the acceleration device via an encrypted communication channel. It is important to note that, for subsequent verification purposes, the client device must store the model baseline information of the model to be deployed on the verification service device before deploying the model.

[0134] In one embodiment, the method may further include:

[0135] Step 1501: Send the model baseline information of the model to be deployed to the proof service device so that the proof service device can save the model baseline information;

[0136] Accordingly, after confirming that the verification service device returns a successful verification message, it may also include:

[0137] Step 1501: Send the model to be deployed to the model service device.

[0138] Based on the above embodiments, the model service verification method described above will be fully described below with reference to specific schematic diagrams. Please refer to... Figure 5 , Figure 5 This is a flowchart illustrating a model service verification method provided in an embodiment of the present invention. This method is applied to a model service system, which includes the following modules:

[0139] 1) Client application: The end user accesses the language model service, which is responsible for initiating the session, verifying the trustworthiness of the remote model service environment, and communicating securely with the backend model application.

[0140] 2) Remote verification service: Its main function is to verify the security status of the model application service environment, including the trustworthiness of the processor-side confidential computing environment (such as SGX confidential computing environment, Software Guard Extensions, and protection extension technology), the confidential computing environment on the acceleration device side, and the integrity of the services and code deployed and running in the confidential computing environment.

[0141] 3) Model Application: Running in a processor-side confidential computing environment, its main function is to provide model services to client applications, including artificial intelligence training and inference tasks. Running in a processor-side confidential computing environment, it receives user model service requests through a RESTful API. At the same time, it offloads certain computing functions to the acceleration device side, and performs remote calls to the acceleration device and accesses the acceleration device's memory data, etc.

[0142] 4) Model computation: Running in the confidential computing environment on the acceleration device side, its main functions are to respond to processor requests, perform computationally intensive model training and inference computations within the acceleration device, respond to processor remote calls and acceleration device memory access, and interact with the processor to write the processing results to the processor memory.

[0143] 5) Trusted Measurement Module: Trusted measurement modules exist on both the processor side and the acceleration device side. Their main functions are to perform integrity measurements on the confidential computing environment on the processor side and the confidential computing environment on the acceleration device side to ensure that they are not tampered with; to receive measurement values ​​reported by other modules; and to verify the received confidential computing environment integrity measurement values.

[0144] 6) Secure communication module: Both the confidential computing environment on the processor side and the confidential computing environment on the acceleration device side have a secure communication module. Its main functions are key secure negotiation and storage, encryption / decryption and integrity verification of communication data. The cryptographic algorithms and integrity verification mechanisms adopted comply with relevant national and industry standards for cryptography.

[0145] The specific processing procedure is as follows:

[0146] 1) The processor's confidential computing environment and the acceleration device's confidential computing environment are initialized. The processor's secure communication module (which can be understood as part of the acceleration device driver) establishes an encrypted channel with the acceleration device's secure communication module (generally part of the acceleration device firmware). After key negotiation, subsequent data transmission between the processor and the acceleration device is only in encrypted form via PCIe, ensuring the confidentiality of the data transmission link between the processor and the acceleration device. Key generation can be achieved through key negotiation protocols such as TLS (Transport Layer Security) and IKE (Internet Key Exchange), or through out-of-band or manual specification.

[0147] 2) The client application initiates a new session request to the model application.

[0148] 3) The model application and the client application establish a new session, and all subsequent communication between the two will take place in this session.

[0149] 4) The client application requests a proof of the trustworthiness of the model's runtime environment from the model application. This proof can be used to verify the trustworthiness of the remote service environment, including the confidential computing environment of the processor, the trusted computing environment of the acceleration device, and the trustworthiness of the code and data running in the confidential computing environment. The trustworthiness proof request contains two random numbers of no less than 64 bits, the first and the second.

[0150] 5) The model application requests the Trusted Measurement Module in the processor to perform an integrity measurement on the processor's operating environment. The measurement request transmits the first and second random numbers extracted from the client request.

[0151] 6) The processor's trusted measurement module performs integrity measurement on the processor's confidential computing environment. The measurement data includes unique identifiers, certificates (chains), Enclave metadata, processor security version, etc. Finally, the above information and the first random number of the challenge in the measurement request are signed with the certificate private key, where the unique identifier = hash(code segment||data segment||stack).

[0152] 7) The processor's trusted measurement module requests the trusted measurement module of the acceleration device to perform an integrity measurement of the acceleration device's operating environment. This process is encrypted by the secure communication modules of both parties (not shown in the figure for simplification). The measurement request transmits a second random number extracted from the client request.

[0153] 8) The trusted measurement module of the acceleration device performs integrity measurement on the confidential computing environment of the acceleration device. The measurement data includes hardware information, firmware information, BIOS and hardware status of the acceleration device. Finally, the above information and the second random number in the measurement request are signed with the private key of the acceleration device certificate.

[0154] 9) The trusted measurement module of the acceleration device sends the above-mentioned measurement results of the confidential computing environment of the acceleration device, along with the acceleration device certificate signature data and the acceleration device certificate (chain), to the trusted measurement module of the processor. This process is encrypted by the secure communication modules of both parties (not shown in the figure for the sake of simplifying the process).

[0155] 10) The processor's trusted measurement module sends the trusted execution environment measurement results generated in step 6), together with the certificate signature data, certificate (chain), and the accelerated device confidential computing environment measurement results received from the accelerated device trusted measurement module in step 9), along with the accelerated device certificate signature data, accelerated device certificate (chain), the first random number and the second random number in the user request, to the model application to form a remote proof report.

[0156] 11) The model application sends the remote proof report received in step 9), including the trusted execution environment measurement results and the accelerated device confidential computing environment measurement results, along with the added timestamps and other information, to the remote proof service.

[0157] 12) Upon receiving a remote proof report verification request, the remote proof service decrypts and verifies the trusted execution environment measurement results and the accelerated device confidential computing environment measurement results, respectively:

[0158] The certificate (chain) is used to verify the unique identifier, Enclave metadata, processor security version, code hash value, data hash value, user first random number and other key information in the measurement report. If the calculation result is consistent with the signature value, the confidential computing environment has not been tampered with.

[0159] The acceleration device certificate (chain) is used to verify the key information in the acceleration device metric report, such as acceleration device hardware information, firmware information, BIOS and hardware status, and user second random number. The verification is performed by decrypting and signing. If the calculation result is consistent with the signature value, the acceleration device computing environment has not been tampered with.

[0160] If the certificate and acceleration device certificate are pre-installed by the chip manufacturer, in addition to verifying the certificate signature, purpose, validity period, and other information, it is also necessary to verify the validity of the certificate with the chip manufacturer, whether it has been revoked, etc. If the certificate is invalid, the remote verification will fail.

[0161] 13) The remote verification service returns the results to the client application, including the verification results of the confidential computing environment and the confidential computing environment of the accelerated device. If any verification of the confidential computing environment or the confidential computing environment of the accelerated device fails, the remote verification result is deemed to have failed.

[0162] If remote verification fails, the client application can either abort subsequent service requests or continue providing service after receiving a security risk warning. If remote verification succeeds, the client application can trust the remote model service.

[0163] 14) The client application submits an AI training or inference task request to the model application.

[0164] 15) When the model is used for artificial intelligence training or inference tasks, it sends calculation instructions or memory access instructions to the model operation module of the acceleration device. This process is encrypted by the secure communication module of both parties (not shown in the figure for the sake of simplifying the process).

[0165] 16) The acceleration device model calculation module calculates according to the processor instructions and then returns the calculation results to the model application module. This process is encrypted by the secure communication module of both parties (not shown in the figure for the sake of simplifying the process).

[0166] 17) The model application module returns the results of the artificial intelligence training or inference tasks to the user application.

[0167] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method.

[0168] Embodiments of the present invention also provide a computer-readable storage medium storing a computer program configured to execute the steps in any of the above-described model service verification method embodiments at runtime.

[0169] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard disk, magnetic disk, or optical disk.

[0170] Embodiments of the present invention also provide a computer program product, which includes a computer program that, when executed by a processor, implements the steps in any of the above-described model service verification method embodiments.

[0171] Embodiments of the present invention also provide another computer program product, including a non-volatile computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps in any of the above-described model service verification method embodiments.

[0172] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0173] The above provides a detailed description of the model service verification method and model service system provided by this invention. Specific examples have been used to illustrate the principles and implementation methods of this invention. The descriptions of the embodiments above are merely for the purpose of helping to understand the method and core ideas of this invention. It should be noted that those skilled in the art can make various improvements and modifications to this invention without departing from its principles, and these improvements and modifications also fall within the protection scope of this invention.

Claims

1. A model service verification method, characterized by, The method is applied to a model service device, the model service device comprising a processor and an acceleration device, the processor having a first isolated execution environment, the acceleration device having a second isolated execution environment, an inference model running in the acceleration device, the processor establishing an encrypted communication channel between the first isolated execution environment and the second isolated execution environment with the acceleration device, the method comprising: The processor generates first environment measurement data for the first isolated execution environment upon receiving a proof request sent by a client device, and sends an environment measurement request to the acceleration device through the encrypted communication channel; The acceleration device generates second environment measurement data for the second isolated execution environment and the inference model upon receiving the environment measurement request, and sends the second environment measurement data to the processor through the encrypted communication channel; The processor integrates the first environment measurement data and the second environment measurement data into a proof report, and sends the proof report to the client device, so that the client device verifies the proof report through a proof service device and sends a model inference task to the model service device upon determining that the proof report passes the verification; Generating first environment measurement data for the first isolated execution environment comprises: The processor extracts a first random number from the proof request, and obtains metadata of the first isolated execution environment, a processor certificate of the processor, and security version information; wherein the first random number is used to be signed by the processor to prove the validity of this round of verification; Hash processing executable code, data segments, and memory stacks in the first isolated execution environment to obtain first identification information of the first isolated execution environment; Using a certificate private key of the processor certificate to sign the first random number, the first identification information, the metadata, and the security version information as a whole to obtain a first signature value, and integrating the processor certificate and the first signature value into the first environment measurement data; Sending an environment measurement request to the acceleration device through the encrypted communication channel comprises: The processor extracts a second random number from the proof request, generates the environment measurement request using the second random number, and sends the environment measurement request to the acceleration device through the encrypted communication channel; wherein the second random number is used to be signed by the acceleration device to prove the validity of this round of verification; Generating second environment measurement data for the second isolated execution environment and the inference model comprises: The acceleration device extracts the second random number from the environment measurement request, and obtains an acceleration device certificate of the acceleration device; Hash processing hardware information and firmware information of the second isolated execution environment to obtain second identification information of the second isolated execution environment, and hash processing model code of the inference model to obtain model benchmark information; The second signature value is obtained by signing the second random number, the second identification information and the model reference information using a certificate private key of the acceleration device certificate, and the second environment measurement data is obtained by integrating the acceleration device certificate and the second signature value.

2. The model service verification method of claim 1, wherein, An environment measurement request is sent to the acceleration device through the encrypted communication channel, including: The processor calls a driver interface of the acceleration device to send the environment measurement request to the acceleration device through the encrypted communication channel according to the device type of the acceleration device.

3. The model service verification method of claim 1, wherein, Further comprising: The processor deploys the to-be-deployed model to the second isolated execution environment of the acceleration device through the encrypted communication channel when receiving the to-be-deployed model sent by the client device; The client device sends the to-be-deployed model to the model service device when determining that the attestation report passes the verification, and model reference information of the to-be-deployed model is saved in the attestation service device.

4. The model service verification method of claim 1, wherein, Further comprising: The processor establishes an encrypted session between the client device and the first isolated execution environment when receiving a session establishment request sent by the client device; An attestation request sent by a client device is received, including: The attestation request sent by the client device is received through the encrypted session; The attestation report is sent to the client device, including: The attestation report is sent to the client device through the encrypted session.

5. The model service verification method of claim 1, wherein, Further comprising: The processor sends the model inference task to the acceleration device through the encrypted communication channel when receiving the model inference task sent by the client device; The acceleration device executes the model inference task using the inference model and sends the task execution result to the processor through the encrypted communication channel; The processor sends the task execution result to the client device.

6. A model service verification method characterized by, Applied to an attestation service device, the method comprises: An attestation report sent by a client device is received, and first environment measurement data and second environment measurement data are extracted from the attestation report; wherein the client device sends an attestation request to a model service device, and receives an attestation report returned by the model service device, the attestation request contains first and second random numbers generated by the client device, and the attestation report contains the first and second random numbers added by the client device; The first environment measurement data and the second environment measurement data are verified respectively, and it is determined whether the first environment measurement data and the second environment measurement data both pass the verification; If it is determined that the first environment measurement data and the second environment measurement data both pass the verification, verification pass information is sent to the client device; If it is determined that the first environment measurement data or the second environment measurement data does not pass the verification, verification failure information is sent to the client device; The first environment measurement data is verified, including: The first random number is extracted from the attestation report, and a processor certificate and a first signature value are extracted from the first environment measurement data; It is determined whether the processor certificate is revoked; If it is determined that the processor certificate is not revoked, the first signature value is decrypted using the processor certificate to obtain a first decrypted value, and the first decrypted value is verified using the first random number and a first preset reference value to determine whether the first decrypted value passes the verification; If it is determined that the first decrypted value passes the verification, it is determined that the first environmental measurement data passes the verification; If it is determined that the processor certificate is revoked, or it is determined that the first decrypted value does not pass the verification, it is determined that the first environmental measurement data does not pass the verification; Verifying the second environmental measurement data includes: extracting a second random number from the attestation report and extracting an acceleration device certificate and a second signature value from the second environmental measurement data; determining whether the acceleration device certificate is revoked; If it is determined that the acceleration device certificate is not revoked, the second signature value is decrypted using the acceleration device certificate to obtain a second decrypted value, and the second decrypted value is verified using the second random number and a second preset reference value to determine whether the second decrypted value passes the verification; the second preset reference value includes model reference information; If it is determined that the second decrypted value passes the verification, it is determined that the second environmental measurement data passes the verification; If it is determined that the acceleration device certificate is revoked, or it is determined that the second decrypted value does not pass the verification, it is determined that the second environmental measurement data does not pass the verification; The model service device includes a processor and an acceleration device, the processor has a first isolated execution environment, the acceleration device has a second isolated execution environment, the acceleration device runs an inference model, and the processor and the acceleration device establish an encrypted communication channel between the first isolated execution environment and the second isolated execution environment; When the processor receives an attestation request sent by a client device, the processor generates first environmental measurement data for the first isolated execution environment and sends an environmental measurement request to the acceleration device through the encrypted communication channel; When the acceleration device receives the environmental measurement request, the acceleration device generates second environmental measurement data for the second isolated execution environment and the inference model, and sends the second environmental measurement data to the processor through the encrypted communication channel; The processor integrates the first environmental measurement data and the second environmental measurement data into an attestation report and sends the attestation report to the client device; Generating first environmental measurement data for the first isolated execution environment includes: The processor extracts a first random number from the attestation request and obtains metadata of the first isolated execution environment, a processor certificate of the processor, and security version information; wherein the first random number is used to be signed by the processor to prove the validity of this round of verification; Hash processing executable code, data segments, and memory stacks in the first isolated execution environment to obtain first identification information of the first isolated execution environment; The processor certificate private key is used to sign the first random number, the first identification information, the metadata and the security version information as a whole to obtain a first signature value, and the processor certificate and the first signature value are integrated into the first environment measurement data; An environment measurement request is sent to the acceleration device through the encrypted communication channel, including: The processor extracts a second random number from the attestation request, generates the environment measurement request using the second random number, and sends the environment measurement request to the acceleration device through the encrypted communication channel; wherein the second random number is used to be signed by the acceleration device to prove the validity of the current verification; Second environment measurement data is generated for the second isolated execution environment and the inference model, including: The acceleration device extracts the second random number from the environment measurement request and obtains an acceleration device certificate of the acceleration device; The hardware information and the firmware information of the second isolated execution environment are hashed to obtain second identification information of the second isolated execution environment, and the model code of the inference model is hashed to obtain model benchmark information; The second random number, the second identification information and the model benchmark information are signed as a whole by a certificate private key of the acceleration device certificate to obtain a second signature value, and the acceleration device certificate and the second signature value are integrated into the second environment measurement data.

7. The model service verification method of claim 6, wherein, Further comprising: When receiving the model benchmark information of the to-be-deployed model sent by the client device, the model benchmark information is saved.

8. A model service verification method characterized by, Applied to a client device, the method comprises: An attestation request is sent to a model service device, and an attestation report returned by the model service device is received; The attestation report is sent to an attestation service device, and it is determined whether the attestation service device returns verification success information; When it is determined that the attestation service device returns the verification success information, a model inference task is sent to the model service device; An attestation request is sent to a model service device, including: First and second random numbers are generated, the attestation request is generated using the first and second random numbers, and the attestation request is sent to the model service device; The attestation report is sent to an attestation service device, including: The first and second random numbers are added to the attestation report, and the attestation report is sent to the attestation service device; The model service device comprises a processor and an acceleration device, the processor has a first isolated execution environment, the acceleration device has a second isolated execution environment, an inference model runs in the acceleration device, and the processor and the acceleration device establish an encrypted communication channel between the first isolated execution environment and the second isolated execution environment; The processor generates first environment measurement data for the first isolated execution environment when receiving an attestation request sent by a client device, and sends an environment measurement request to the acceleration device through the encrypted communication channel; The acceleration device generates second environment measurement data for the second isolated execution environment and the inference model upon receiving the environment measurement request, and sends the second environment measurement data to the processor through the encrypted communication channel; The processor integrates the first environment measurement data and the second environment measurement data into a proof report, and sends the proof report to the client device; Generating first environment measurement data for the first isolated execution environment includes: The processor extracts a first random number from the proof request, and obtains metadata of the first isolated execution environment, a processor certificate of the processor, and security version information; wherein the first random number is used to be signed by the processor to prove the validity of this round of verification; Hash processing executable code, data segment, and memory stack in the first isolated execution environment to obtain first identification information of the first isolated execution environment; Using a certificate private key of the processor certificate to sign the first random number, the first identification information, the metadata, and the security version information to obtain a first signature value, and integrating the processor certificate and the first signature value into the first environment measurement data; Sending an environment measurement request to the acceleration device through the encrypted communication channel includes: The processor extracts a second random number from the proof request, generates the environment measurement request using the second random number, and sends the environment measurement request to the acceleration device through the encrypted communication channel; wherein the second random number is used to be signed by the acceleration device to prove the validity of this round of verification; Generating second environment measurement data for the second isolated execution environment and the inference model includes: The acceleration device extracts the second random number from the environment measurement request, and obtains an acceleration device certificate of the acceleration device; Hash processing hardware information and firmware information of the second isolated execution environment to obtain second identification information of the second isolated execution environment, and hash processing model code of the inference model to obtain model benchmark information; Using a certificate private key of the acceleration device certificate to sign the second random number, the second identification information, and the model benchmark information to obtain a second signature value, and integrating the acceleration device certificate and the second signature value into the second environment measurement data.

9. The model service verification method of claim 8, wherein, Further comprising: Sending model benchmark information of a to-be-deployed model to the proof service device, so that the proof service device saves the model benchmark information; After determining that the proof service device returns the verification success information, further comprising: Sending the to-be-deployed model to the model service device.

10. A model service system, characterized by, Comprising: A model service device, a client device, and a proof service device, the model service device comprising a processor and an acceleration device, the processor having a first isolated execution environment, the acceleration device having a second isolated execution environment, an inference model running in the acceleration device, and the processor and the acceleration device establishing an encrypted communication channel between the first isolated execution environment and the second isolated execution environment; The model service device is configured to perform the model service verification method according to any one of claims 1 to 5. The client device is configured to perform the model service verification method according to any one of claims 8 to 9. The attestation service device is configured to perform the model service verification method according to any one of claims 6 to 7.

Citation Information

Patent Citations

  • Security verification method for large model service operation environment, medium, equipment and product

    CN120354404A