基于受控执行环境的AI agent数据保护方法和装置
By combining TEE and eBPF technologies, a controlled execution environment is constructed, which solves the problems of behavior monitoring and data protection during the operation of AI agents, realizes privacy protection and compliance throughout the entire lifecycle, and ensures data security and compliance.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- NANKAI UNIV
- Filing Date
- 2025-07-30
- Publication Date
- 2026-07-17
AI Technical Summary
Existing technologies struggle to provide observable, interventionist, and verifiable data protection for AI agent behavior during runtime, especially in complex multi-round inference and tool call chains. Traditional methods cannot meet the compliance requirements of regulations such as GDPR.
By combining Trusted Execution Environment (TEE) and Extended Berkeley Packet Filter (eBPF) technology, a controlled execution environment is constructed. Through a security decision monitoring module, network traffic is intercepted and verified at the kernel level, enabling full lifecycle behavior monitoring and data protection for the AI agent.
It achieves a trusted, observable, and revocable privacy sandbox throughout the entire lifecycle of the AI agent, ensuring data confidentiality and compliance, and preventing privacy data leakage and unauthorized access.
Smart Images

Figure CN120915513B_ABST