Method and device for enhancing data security of large model application, equipment and storage medium

By deploying trusted execution environment data management and key management services in large-scale model applications and using encryption and decryption methods to process user data, the security issues in data transmission and storage processes of large-scale model applications are solved, and secure data transmission and storage are achieved.

CN120979705APending Publication Date: 2025-11-18BEIJING ZITIAO NETWORK TECH CO LTD

Patent Information

Application Number
CN202511061833.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-30
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

In existing technologies, large-scale application data faces security risks during transmission and storage, especially during cross-environment data transmission and decryption, where keys and sensitive data are easily leaked, resulting in insufficient data security.

Method used

By deploying the data management service in the first trusted execution environment and the key management service in the second trusted execution environment, user data is processed using encryption and decryption methods to ensure data security during transmission and storage. Specific steps include the data management service receiving encrypted user data, decrypting and storing it, and then the key management service communicating with the task execution end to decrypt the data, ensuring secure data transmission between different environments.

Benefits of technology

It effectively avoids the leakage of keys and sensitive data, improves the security of data transmission and storage in large-scale model applications, and ensures the integrity and privacy of data during transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979705A_ABST
    Figure CN120979705A_ABST
Patent Text Reader

Abstract

According to the embodiment of the invention, the method, the device and the equipment for enhancing the data security of the large model application and the storage medium are provided. The method comprises the following steps: a data management service receives ciphertext user data from a large model application, wherein the ciphertext user data comprises first data of a user; the data management service decrypts the ciphertext user data to obtain first data, and stores the encrypted first data in a database, the encrypted first data being encrypted based on a first key corresponding to the user maintained by the key management service; the data management service responds to the received request for obtaining the first data of the user, obtains the encrypted first data from the database and sends the encrypted first data to the large model application, and the large model application sends the encrypted first data to the task execution end; the key management service communicates with the task execution end, so that the task execution end obtains the first data decrypted based on the first key and executes the task based on the first data, and the security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Example embodiments of the present disclosure generally relate to the field of computers, and in particular, to a method, apparatus, device and computer readable storage medium for enhancing data security of large model application. BACKGROUND

[0002] With the development of artificial intelligence technology, large model application based on large model has shown great potential in dialogue interaction, knowledge reasoning, content creation and other aspects as an important development direction, where the large model can be a machine learning model with a large number of parameters, such as a large language model (LLM), a visual large model, a speech large model or a multi-modal large model. They can realize the closed loop of "understanding-planning-execution" through large models, not only limited to generating text, but also can complete actual operation through tool calling, dynamic planning and continuous learning. SUMMARY

[0003] In a first aspect of the present disclosure, a method for enhancing data security of a large model application is provided, comprising the following steps performed by a data management service deployed in a first trusted execution environment and a key management service deployed in a second trusted execution environment: the data management service receives ciphertext user data in a first encryption manner from the large model application, the ciphertext user data comprising first data of a user; the data management service decrypts the ciphertext user data based on a decryption manner corresponding to the first encryption manner to obtain the first data, and the data management service stores the encrypted first data into a database, the encrypted first data being obtained by encrypting the decrypted first data based on a first key corresponding to the user maintained by the key management service; the data management service acquires the encrypted first data from the database and sends the encrypted first data to the large model application in response to receiving a request from the large model application for obtaining the first data of the user; wherein the large model application sends the encrypted first data to a task execution end; and the key management service communicates with the task execution end, so that the task execution end obtains the first data decrypted based on the first key, and then the task execution end executes a task based on the first data.

[0004] In a second aspect of the present disclosure, an apparatus for enhancing data security of a large model application is provided. The apparatus comprises: a receiving module configured to receive, by a data management service, ciphertext user data in a first encryption mode from a large model application, the ciphertext user data comprising first data of a user, wherein the data management service is deployed in a first trusted execution environment; a first processing module configured to decrypt, by the data management service, the ciphertext user data based on a decryption mode corresponding to the first encryption mode to obtain the first data, and store, by the data management service, encrypted first data into a database, the encrypted first data being obtained by encrypting the decrypted first data based on a first key corresponding to the user maintained by a key management service, the key management service being deployed in a second trusted execution environment; a second processing module configured to obtain, by the data management service, the encrypted first data from the database and send the encrypted first data to the large model application in response to receiving a request from the large model application for obtaining the first data of the user; wherein the large model application sends the encrypted first data to a task execution end; and a communication module configured to enable the key management service to communicate with the task execution end, so that the task execution end obtains the first data decrypted based on the first key, and then the task execution end performs a task based on the first data.

[0005] In a third aspect of the present disclosure, an electronic device is provided. The device comprises at least one processing unit; and at least one memory coupled to the at least one processing unit and storing instructions for execution by the at least one processing unit. The instructions, when executed by the at least one processing unit, cause the device to perform the method of the first aspect.

[0006] In a fourth aspect of the present disclosure, a computer-readable storage medium is provided. The computer-readable storage medium has stored thereon a computer program, the computer program being executable by a processor to implement the method of the first aspect.

[0007] In a fifth aspect of the present disclosure, a computer program product is provided. The computer program product comprises computer executable instructions that, when executed by a processor, implement the method according to the first aspect of the present disclosure.

[0008] It should be understood that the content described in this part of the content is not intended to limit the key features or important features of the embodiments of the present disclosure, nor is it intended to limit the scope of the present disclosure. Other features of the present disclosure will become apparent through the following description. BRIEF DESCRIPTION OF DRAWINGS

[0009] The above and other features, advantages, and aspects of embodiments of the present disclosure will become more apparent by describing in detail the following embodiments with reference to the attached drawings. In the drawings, the same or similar reference numerals refer to the same or similar elements, in which:

[0010] Figure 1 A schematic diagram showing an example environment in which embodiments of the present disclosure can be implemented is shown;

[0011] Figure 2 A flowchart showing a process of enhancing data security for large models application according to some embodiments of the present disclosure is shown;

[0012] Figure 3 An example flowchart showing data encryption and data decryption processes according to some embodiments of the present disclosure is shown;

[0013] Figure 4 An architectural schematic diagram showing request processing for large models according to some embodiments of the present disclosure is shown;

[0014] Figure 5 A schematic structural block diagram of an apparatus for enhancing data security for large models application according to certain embodiments of the present disclosure is shown;

[0015] Figure 6 A block diagram of an electronic device capable of implementing a number of embodiments of the present disclosure is shown. DETAILED DESCRIPTION

[0016] Embodiments of the present disclosure will be described more fully hereinafter with reference to the accompanying drawings. While certain embodiments of the present disclosure will be shown and described, it will be clear to those having ordinary skill in the art that the present disclosure can be embodied in various forms and should not be construed as limited to the embodiments set forth herein, but rather should be interpreted to cover all equivalent and alternative embodiments. It will also be clear to those having ordinary skill in the art that the drawings provided herein are not necessarily to scale, and that in some instances dimensions of certain features have been exaggerated for the sake of clarity.

[0017] It should be noted that the headings provided herein are not limitations of the various embodiments described herein. The various embodiments described herein can be included under any heading and any type of embodiment can be included under any heading. Furthermore, embodiments described in any heading can be combined with any other embodiment described in the same heading and / or a different heading in any manner.

[0018] In the description of embodiments of the present disclosure, the term “includes” and its hornologs are to be read as open-ended terms that mean “includes, but is not limited to.” The term “based on” is to be read as “based, at least in part, on.” The term “one embodiment” or “an embodiment” is to be read as “at least one embodiment.” The term “some embodiments” is to be read as “at least some embodiments.” Other explicit and implicit definitions can also be included below. The terms “first,” “second,” etc. can refer to different or same objects. Other explicit and implicit definitions can also be included below.

[0019] The data of the user, the acquisition and / or use of the data, etc. can be involved in the embodiments of the present disclosure. These aspects comply with the corresponding laws and regulations and relevant provisions. In the embodiments of the present disclosure, the collection, acquisition, processing, processing, forwarding, use, etc. of all data are performed on the premise that the user is aware of and confirms. Accordingly, when implementing the embodiments of the present disclosure, the type of data or information that can be involved, the use range, the use scenario, etc. should be notified to the user and the authorization of the user should be obtained through appropriate means according to the relevant laws and regulations. The specific notification and / or authorization manner can vary according to the actual situation and application scenario, and the scope of the present disclosure is not limited in this aspect.

[0020] In the present specification and embodiments, if personal information processing is involved, it will be processed on the premise of legality (for example, obtaining the consent of the subject of personal information, or being necessary for the performance of a contract, etc.), and only within the prescribed or agreed range. The user refuses to process personal information other than the necessary information required for the basic function, which does not affect the user's use of the basic function.

[0021] Embodiments of the present disclosure provide a scheme for enhancing data security of a large model application. According to the scheme, a data management service receives ciphertext user data encrypted in a first encryption manner from a large model application, the ciphertext user data including first data of a user. Further, the data management service decrypts the ciphertext user data based on a decryption manner corresponding to the first encryption manner to obtain the first data, and the data management service stores encrypted first data into a database, the encrypted first data being obtained by encrypting the decrypted first data based on a first key corresponding to the user maintained by a key management service. Further, the data management service, in response to receiving a request from the large model application for obtaining the first data of the user, obtains the encrypted first data from the database and sends the encrypted first data to the large model application; wherein the large model application sends the encrypted first data to a task execution end. Further, the key management service communicates with the task execution end, so that the task execution end obtains the first data decrypted based on the first key, and then the task execution end executes a task based on the first data.

[0022] Based on such a manner, the embodiments of the present disclosure can effectively avoid the problem of leakage of sensitive data such as keys and data transmitted via the data management service by deploying the data management service in the first trusted execution environment and running the key management unit in the second trusted execution environment, effectively improving the security. In addition, the large model application and the data management server encrypt the first data of the user based on the agreed encryption manner, effectively ensuring the security of the user data in the transmission process.

[0023] Example Environment

[0024] Figure 1 A schematic diagram of an example environment 100 in which embodiments of the present disclosure can be implemented is shown. As shown, the example environment 100 can include a data management service 110 and a key management service 120. Figure 1

[0025] In this example environment 100, the data management service 110 can be deployed in a first trusted execution environment. The key management service 120 can be deployed in a second trusted execution environment. The first trusted execution environment and the second trusted execution environment can be the same trusted execution environment (TEE), or can be different trusted execution environments. In some embodiments, the data management service 110 and the key management service 120 can be located on a server corresponding to the large model application 130.

[0026] Specifically, the data management service 110 receives ciphertext user data encrypted in a first encryption manner from the large model application 130, the ciphertext user data including first data of a user. The data management service 110 decrypts the ciphertext user data based on a decryption manner corresponding to the first encryption manner to obtain the first data, and the data management service 110 or the key management service 120 encrypts the decrypted first data based on a first key corresponding to the user maintained by the key management service 120, and stores the encrypted first data into a database. The data management service 110 obtains the encrypted first data from the database in response to receiving a request from the large model application 130 to obtain the first data of the user, and sends the encrypted first data to the large model application 130; wherein the large model application 130 sends the encrypted first data to the task execution end 140. The key management service 120 communicates with the task execution end 140, so that the task execution end 140 obtains the first data decrypted based on the first key, and then the task execution end 140 executes a task based on the first data.

[0027] ​In some embodiments, the first data of the user can be data input by a client of the large model application 130 based on the user, which can be a device with a display device of any type of mobile terminal, fixed terminal, or portable terminal including a mobile phone, a desktop computer, a laptop computer, a notebook computer, a netbook computer, a tablet computer, a media computer, a multimedia tablet, a palmtop computer, a portable game terminal, a VR / AR device, a personal communication system (PCS) device, a personal navigation device, a personal digital assistant (PDA), an audio / video player, a digital camera / camcorder, a positioning device, a television receiver, a radio broadcast receiver, an electronic book device, a game device, or any combination of the foregoing, including accessories and peripherals of these devices or any combination thereof. In some embodiments, the client of the large model application 130 can also support any type of interface for the target user (such as a “wearable” circuit, etc.).

[0028] The server of the large model application 130 can also be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content distribution networks, and basic cloud computing services such as big data and artificial intelligence platforms. The server of the large model application 130 may, for example, include a computing system / server such as a mainframe, an edge computing node, a computing device in a cloud environment, etc.

[0029] The task execution end 140 can be any appropriate software or hardware, such as a cloud phone, a terminal device, etc., which will not be described here.

[0030] It should be understood that the structure and function of the various elements in the environment 100 are described for illustrative purposes only, without implying any limitation on the scope of the present disclosure.

[0031] Some example embodiments of the present disclosure will be described below with continued reference to the accompanying drawings.

[0032] Example Process

[0033] Figure 2 A flowchart of a process 200 of enhancing data security of a large model application is shown according to some embodiments of the present disclosure. The process 200 can be performed by the data management service 110 deployed in a first trusted execution environment and the key management service 120 deployed in a second trusted execution environment.

[0034] In some embodiments, the first trusted execution environment or the second trusted execution environment can be a secure enclave in a computing system of a server of the large model application 130, which can provide an isolated, protected space for processing sensitive data and performing critical security operations. The first trusted execution environment or the second trusted execution environment can run in a separate environment in the server of the large model application 130 and can run in parallel with an operating system of the server of the large model application 130. This environment is designed to be able to resist external attacks and internal threats, ensuring the security and integrity of the data processed and the operations performed therein, which is more secure than the operating system. In some embodiments, the first trusted execution environment and the second trusted execution environment can be the same trusted execution environment, and can also not be the same trusted execution environment.

[0035] The following description refers to the accompanying drawings. Figure 1 The process 200 is described. At block 210, the data management service 110 receives ciphertext user data encrypted in a first encryption scheme from the large model application 130, the ciphertext user data including first data of a user.

[0036] In some embodiments, the large model application 130 can be various specific application scenarios and solutions developed by using large machine learning models. The large machine learning model can be any appropriate machine learning model with a large number of parameters, which can be configured to process any appropriate complex task. For example, in the embodiments of the present disclosure, the large machine learning model can be a large model. As an example, the large model can be an LLM, and can also be a speech large model, a visual large model, a multi-modal large model, etc. In some embodiments, the large model application 130 can include, but is not limited to, an intelligent agent, natural language processing, etc.

[0037] In some embodiments, an intelligent agent is a system or entity that can perceive an environment and make decisions or make decisions and take actions to achieve a specific goal or task. In some scenarios, the intelligent agent is also called an Agent. In some embodiments, the intelligent agent can use one or more large models to drive its interaction with the user, which can be any appropriate interaction. In addition, the intelligent agent can work in a manner similar to a human being, use a large model to "understand" the user's intention, actively "plan" to achieve the goal, and can use various "tools" to complete the task, and finally "act" to perform these tasks.

[0038] In some embodiments, the first data of the user can be any appropriate type of request, such as text, voice, image, etc. The first data of the user can be input based on the client of the large model application 130, such as input based on a conversation window of the user with the intelligent agent on the client. The first data can be any appropriate data, for example, the user's account, password, mobile phone number, etc.

[0039] To ensure the security of the data transmission process, in some embodiments, the client of the large model application 130 can encrypt the first data of the user in a first encryption manner to obtain ciphertext user data. The first encryption manner can be an encryption manner agreed by the large model application 130 and the data management service 110, which can be a symmetric encryption manner, and can also be an asymmetric encryption manner, which will not be described here.

[0040] Further, the client of the large model application 130 can send the ciphertext user data to the data management service 110. As an example, the client of the large model application 130 can send the ciphertext user data to an intermediate service (such as an agent service, i.e., Agent Server). Further, the intermediate service can send the ciphertext user data to the data management service 110. The intermediate service can be an intermediary for requests or data transmission, used to transmit data or requests between the large model application 130 and the data management service 110. For ease of description, the large model application 130 and the intermediate service can be collectively referred to as an end-side application.

[0041] In some embodiments, due to the transmission of data or requests between the end-side application and the data management service 110, in order to ensure the security of the transmission, the end-side application can send a target security authentication request to the data management service 110 before the data transmission between the end-side application and the data management service 110. Further, the data management service 110 can provide the end-side application with a security certificate of the data management service 110. Further, the end-side application can determine whether the security certificate meets the preset security requirements. Further, the end-side application can determine that the data transmission between the end-side application and the data management service 110 is secure in response to the security certificate meeting the security requirements. The security requirement can be any appropriate requirement that can measure the identity and credibility of the data management service 110, such as whether the security certificate is valid, whether the security certificate is within the valid period, and the like. Specifically, the end-side application can establish a transmission channel between the data management service 110 and the end-side application in response to the security certificate meeting the security requirements. The transmission channel is the basis for supporting the data transmission between the agent and the data management service 110.

[0042] In some embodiments, in order to improve efficiency, the electronic device can store the user data input by the user in the historical process in the database in an encrypted form, so that the subsequent task execution end 140 can perform the corresponding task based on the plaintext obtained by decrypting the encrypted user data. In order to avoid repeated input of user data and improve interaction efficiency, in some embodiments, the first data of the user can be the first data prompted to be input by the user after it is determined that the first data does not exist in the database.

[0043] Specifically, the data management service 110 can receive a second request for obtaining first data from the large model application 130. The second request can be any appropriate request, such as “Help me buy a train ticket from A program”, and the first data can be a mobile phone number required to buy a train ticket. Further, the data management service 110 provides prompt content for the second request to the large model application 130 in response to the database not including the first data, the prompt content being used to prompt input of data associated with the second request. The prompt content can be any appropriate form of content, such as text, images, and the like. The prompt content can be a text of “Buying a train ticket requires a mobile phone number. Please enter your mobile phone number”. Taking the large model application 130 as an agent for example, the prompt content can be in the form of conversation content output by the agent and presented on a conversation interface between the user and the agent.

[0044] Further, the data management service 110 can receive ciphertext user data from the large model application 130, the ciphertext user data including the first data determined based on the user input data. For example, the ciphertext user data can be ciphertext obtained by encrypting the mobile phone number input by the user after viewing the prompt content.

[0045] In block 220, the data management service 110 decrypts the ciphertext user data based on a decryption method corresponding to the first encryption method to obtain the first data, and the data management service 110 stores the encrypted first data in the database, the encrypted first data being obtained by encrypting the decrypted first data based on the first key corresponding to the user maintained by the key management service 120.

[0046] In some embodiments, the decryption method corresponding to the first encryption method is a decryption method agreed upon by the large model application 130 and the data management service 110. As an example, if the first encryption method is symmetric encryption of the first data with a certain key, then the decryption method can be decryption of the ciphertext user data with the key. As another example, if the first encryption method is asymmetric encryption of the first data with a certain public key, then the decryption method can be decryption of the ciphertext user data with a private key corresponding to the public key.

[0047] In order to facilitate subsequent execution of other tasks based on the first data, and in order to ensure the security of the first data, the key management service 120 can encrypt the decrypted first data based on the first key corresponding to the user maintained thereby and send the encrypted first data to the data management service 110, so that the data management service 110 can store the encrypted first data in the database.

[0048] As an example, the data management service 110 can send the decrypted first data to the key management service 120, so that the key management service 120 encrypts the received decrypted first data based on the first key of the user maintained by the key management service 120.

[0049] In some embodiments, in order to ensure the security of the decrypted first data in the transmission process, the data management service 110 can encrypt the decrypted first data based on a third encryption manner to obtain encrypted first data. The third encryption manner can be an encryption manner agreed by the key management service 120 and the data management service 110. The third encryption manner can be a symmetric encryption manner or an asymmetric encryption manner, which will not be described here. Further, the data management service 110 can send the encrypted first data to the key management service 120, at this time, the first data is sent to the key management service 120 in the form of ciphertext, which can effectively ensure the security of the first data in the transmission process. Further, the key management service 120 decrypts the encrypted first data based on the decryption manner corresponding to the third encryption manner. The decryption manner corresponding to the third encryption manner can be a decryption manner agreed by the key management service 120 and the data management service 110. As an example, if the third encryption manner is to symmetrically encrypt the first data with a certain key, then the decryption manner can be to decrypt the encrypted first data with the key. As another example, if the third encryption manner is to asymmetrically encrypt the first data with a certain public key, then the decryption manner can be to decrypt the encrypted first data with the private key corresponding to the public key.

[0050] Further, the key management service 120 can send the first data encrypted based on the first key of the user to the data management service 110. Further, the data management service 110 can store the first data encrypted by the first key into the database.

[0051] As another example, the data management service 110 can obtain the first key of the user maintained by the key management service 120 to encrypt the decrypted first data based on the first key.

[0052] To ensure the security of the first key during transmission, in some embodiments, the key management service 120 can encrypt the first key corresponding to the user based on a fourth encryption manner to obtain an encrypted first key. The fourth encryption manner can be an encryption manner agreed by the key management service 120 and the data management service 110. The fourth encryption manner can be a symmetric encryption manner or an asymmetric encryption manner, which is not described herein. Further, the data management service 110 can obtain the encrypted first key from the key management service 120. Further, the data management service 110 decrypts the encrypted first key based on a decryption manner corresponding to the fourth encryption manner. The decryption manner corresponding to the fourth encryption manner can be a decryption manner agreed by the key management service 120 and the data management service 110. As an example, if the fourth encryption manner is to symmetrically encrypt the first key with a certain key, the decryption manner can be to decrypt the first key with the key. As another example, if the fourth encryption manner is to asymmetrically encrypt the first key with a certain public key, the decryption manner can be to decrypt the first key with a private key corresponding to the public key.

[0053] Further, the data management service 110 stores the encrypted first data in the database.

[0054] Since the data management service 110 and the key management service 120 involve data transmission, in order to ensure the security of the two services during data transmission, before the data management service 110 or the key management service 120 encrypts the decrypted first data based on the first key corresponding to the user maintained by the key management service 120 and stores it in the database, security verification can be performed first.

[0055] In some embodiments, the data management service 110 can send a first security authentication request to the key management service 120. The first security authentication request can include information to be authenticated, such as information associated with the key management service 120 to be authenticated. Further, the data management service 110 can authenticate whether the first security certificate satisfies a security condition based on the first security certificate obtained from the key management service 120. The security condition can be any appropriate auxiliary condition that can measure the identity and credibility of the key management service 120, such as whether the security certificate is valid, whether the security certificate is within the valid period, and the like.

[0056] It should be noted that, generally, before a sender sends data to a receiver, the sender needs to verify whether the receiver meets the security requirements, and therefore the above-mentioned verification of whether the security condition is met based on the first security certificate can be verification required by the data management service 110 before sending the decrypted first data or the encrypted first data obtained by encrypting the decrypted data based on the third encryption method to the key management service 120, and encrypting the first data based on the first key in the key management service 120.

[0057] In some embodiments, the key management service 120 can send a second security authentication request to the data management service 110. The second security authentication request can include information to be authenticated, such as information associated with the data management service 110 to be authenticated. The key management service 120 can authenticate whether the second security certificate meets the security condition based on the second security certificate obtained from the data management service 110. The security condition can be any appropriate auxiliary condition that can measure the identity and credibility of the data management service 110, such as whether the security certificate is valid, whether the security certificate is within the valid period, and the like.

[0058] It should be noted that, generally, before a sender sends data to a receiver, the sender needs to verify whether the receiver meets the security requirements, and therefore the above-mentioned verification of whether the security condition is met based on the second security certificate can be verification required by the key management service 120 before sending the first key or the encrypted first key obtained by encrypting the first key based on the fourth encryption method to the data management service 110, and encrypting the first data based on the first key in the data management service 110.

[0059] Further, the data management service 110 or the key management service 120 can perform subsequent operations of storing the encrypted first data to the database after the data management service 110 or the key management service 120 encrypts the decrypted first data based on the first key corresponding to the user maintained by the key management service 120 in response to the first security certificate or the second security certificate meeting the security condition.

[0060] At block 230, the data management service 110 obtains encrypted first data from the database and sends the encrypted first data to the large model application 130 in response to receiving the request for obtaining the first data of the user from the large model application 130; wherein the large model application 130 sends the encrypted first data to the task execution end 140.

[0061] As an example, this request (first request) can be a request that the user provides to the large model application 130. In some embodiments, this request can be any suitable type of request, such as can be text, voice, image, and so on. For example, this request can be a text request that the user inputs based on a conversation window between the user and the agent, such as “Please help me buy a ticket from application A.”

[0062] In some embodiments, the task execution end 140 can be any suitable software, hardware, and so on, such as the task execution end 140 can be a cloud phone, and can also be an electronic device, which can be the same device as the client corresponding to the large model application 130, or can be a different device. The cloud phone is a virtual mobile phone service provided through a remote server, and users can access these services through the Internet and perform operations on the cloud server that are usually performed on a local client. The cloud phone mainly transfers the computing and storage resources of the client to the cloud, thereby realizing cross-device access and operation.

[0063] At block 240, the key management service 120 communicates with the task execution end 140, so that the task execution end 140 obtains the first data decrypted based on the first key, and then the task execution end 140 performs the task based on the first data.

[0064] In order to change the encrypted first data into readable data or data that can be directly used by the task execution end 140, the key management service 120 can send the first key to the task execution end 140, so that the task execution end 140 can decrypt the encrypted first data based on the first key.

[0065] In order to ensure the security of the first key in the data transmission process, the key management service 120 can encrypt the first key in a second encryption manner and send it to the task execution end 140 in response to receiving the key acquisition request of the corresponding user from the task execution end 140. The second encryption manner can be an encryption manner agreed upon by the key management service 120 and the task execution end 140, which can be symmetric encryption or asymmetric encryption, which will not be described here. Further, the task execution end 140 can decrypt the first key based on the decryption manner corresponding to the second encryption manner, and then decrypt the encrypted first data using the first key. The decryption manner corresponding to the second encryption manner can be a decryption manner agreed upon by the key management service 120 and the task execution end 140. As an example, if the second encryption manner is to symmetrically encrypt the first key with a certain key, then the decryption manner can be to decrypt the encrypted first key with this key. As another example, if the second encryption manner is to asymmetrically encrypt the first key with a certain public key, then the decryption manner can be to decrypt the encrypted first key with the private key corresponding to the public key.

[0066] To further ensure the security of the decryption, in some embodiments, a third trusted execution environment can be deployed in the task execution end 140, and the process of decrypting the encrypted first key and the encrypted first data is performed in the third trusted execution environment. Specifically, the task execution end 140 decrypts the encrypted first key in the third trusted execution environment. Further, the task execution end 140 decrypts the encrypted first data using the first key in the third trusted execution environment.

[0067] In some embodiments, the third trusted execution environment can be a secure enclave in the computing system of the task execution end 140, which can provide an isolated, protected space for processing sensitive data and performing critical security operations. The third trusted execution environment can run in a separate environment in the task execution end 140 and can run in parallel with the operating system of the task execution end 140. This environment is designed to be able to resist external attacks and internal threats, ensuring the security and integrity of the data processed and the operations performed therein, which is more secure than the operating system. In addition, the trusted application running in the third trusted execution environment can access all the functions of the device main processor and memory, and the hardware isolation protects these components from applications running in the main operating system and the like.

[0068] To change the encrypted first data into readable data or data that can be directly used by the task execution end 140, the task execution end 140 can send the encrypted first data to the key management service 120, so that the key management service 120 can decrypt the encrypted first data based on the first key, and then obtain the decrypted first data sent by the key management service 120.

[0069] In some embodiments, the key management service 120 decrypts the encrypted first data based on the first key in response to receiving a decryption request of the corresponding encrypted first data from the task execution end 140. Further, the key management service 120 encrypts the first data in a second encryption manner and sends it to the task execution end 140. The second encryption manner can be an encryption manner agreed by the key management service 120 and the task execution end 140, which can be symmetric encryption or asymmetric encryption, which is not described here. Further, the task execution end 140 can decrypt the encrypted first data based on the decryption manner corresponding to the second encryption manner. As an example, if the second encryption manner is to symmetrically encrypt the first data with a certain key, then the decryption manner can be to decrypt the encrypted first data with this key. As another example, if the second encryption manner is to asymmetrically encrypt the first data with a certain public key, then the decryption manner can be to decrypt the encrypted first data with the private key corresponding to the public key.

[0070] Further, the task execution end 140 can execute the task based on the first data, the task can be any appropriate task, such as can be interacting with a target application based on the first data to execute the task, can also be a task of triggering a hardware device on the task execution end 140. The target application can be any appropriate application, such as if the request of obtaining the first data of the user is “please help me buy a train ticket from application A”, then this target application can be the application A on the cloud phone. The task of interacting with the target application to execute can be any appropriate task, such as logging in to the target application, executing a functional operation based on the application program (such as buying a ticket, watching a video, etc.). The hardware device can be any appropriate device, for example, a camera, a sensor, etc. For example, if the first request is “please help me log in to application A”, then this task can be a task of logging in to application A based on the account and password (first data).

[0071] Figure 3 An example flowchart of a data encryption and data decryption process according to some embodiments of the present disclosure is shown, which will now be described with reference to Figure 3 .

[0072] As Figure 3 shown, the user can input a user request at the user end side 301 (the client of the large model application 130) so that the user end side 301 can receive this user request (the request of obtaining the first data of the user). This user request can be any appropriate request, such as can be a text request, an image request. As an example, this user request can be “help me buy a ticket from application A”. Further, the user end side 301 can determine whether the first encrypted data (such as an encrypted user identifier, which is the user data required to buy a ticket) associated with this user request is saved in the database 305.

[0073] As an example, the user side 301 can send the user request to the agent service 302 in response to determining that the encrypted first data is stored in the database 305. Further, the agent service 302 can send the user request to the data management service 110 in the first trusted execution environment. The first trusted execution environment can be a secure enclave in a central processing unit (CPU) in the server side of the large model application 130. Further, the data management service can obtain the encrypted first data from the database 305. Further, the data management service can send the encrypted first data to the task execution side 140, specifically via the agent service 302. Further, the key management service 120 can encrypt the first key in an encryption method agreed between the key management service 120 and the task execution side 140. Further, the task execution side 140 can also obtain the encrypted first key from the key management service 120, which can be running in a second trusted execution environment in the CPU in the server side of the large model application 130. Further, the task execution side 140 can decrypt the encrypted first key in a decryption method agreed between the key management service 120 and the task execution side 140 to obtain the decrypted first key. Further, the task execution side 140 can decrypt the encrypted first data based on the first key to obtain the first data (e.g., the user identifier based on the encryption, which is needed to buy a ticket and is readable). Further, the task execution side 140 can interact with the target application based on the first data to perform the task. For example, the task execution side 140 can interact with the A application based on the user identifier to buy a ticket for the user.

[0074] As another example, the user-side 301 can output a prompt content in response to determining that the encrypted first data is not included in the database 305, which can be used to indicate the user to input the user identification required for buying the ticket. Further, the user-side 301 can receive the user input data. Further, the user-side 301 can encrypt the user input data to obtain the ciphertext user data. Further, the user-side 301 can send the ciphertext user data to the agent service 302. Further, the agent service 302 can send the ciphertext user data to the data management service 110. Further, the data management service 110 can decrypt the ciphertext user data to obtain the decrypted first data. Further, the data management service 110 or the key management service 120 encrypts the decrypted first data based on the first key corresponding to the user maintained by the key management service 120 and stores it in the database for subsequent execution of the task based on the encrypted first data when receiving the request for obtaining the first data, and the specific process is not described herein.

[0075] Figure 4 An architecture diagram for request processing of a large model is shown according to some embodiments of the present disclosure, which will be described in detail below. Figure 4

[0076] As shown in Figure 4 , the end-side application 401 can include a communication encryption and decryption module. The task execution end 140 can include a rich execution environment (REE) 401 and a TEE 402 (third trusted execution environment), wherein the REE is a normal execution environment, which can be configured to run a predetermined operating system 403, and the REE can support that any appropriate application can be run, which can be an application (such as A application, B application) supported by the predetermined operating system 403. The end-side application 401 can include a large model application 130 and an agent service.

[0077] The task execution end 140 can further include a mobile operating system (mobile OS) 404, hardware 405. The mobile operating system can include a system service, a kernel and a TEE driver, wherein the system service and the kernel are configured to be responsible for the basic functions of the operating system, and the TEE driver is responsible for communication and data transmission with the TEE. The hardware 405 is configured to provide underlying physical support, such as including processors, storage, etc.

[0078] As shown in Figure 4 ​As shown, the endpoint application 401 can send a security authentication request to the remote authentication module 412 in the first trusted execution environment, so that the remote authentication module 412 can send a security certificate of the data management service to the endpoint application 401. Further, the endpoint application 401 can authenticate whether this security certificate meets predetermined security requirements. Further, in response to determining that the security certificate meets the predetermined security requirements, the endpoint application 401 can establish a transmission channel between the endpoint application 401 and the data management service.

[0079] As an example, the client application 401 can respond to a data encryption request received from a user (e.g., the user inputs a user identifier associated with application A on task execution terminal 140, the user's registered account on application A, password, etc.), and this data encryption request can carry data to be encrypted. Further, the client application 401 can encrypt this data to be encrypted (first data) using a first encryption method based on its communication encryption / decryption module. Further, the client application 401 can send this encrypted first data to the data management service 110 in the trusted execution environment 442. Further, the data management service 110 can decrypt the encrypted first data using its communication encryption / decryption module. Further, the data management service can encrypt the decrypted first data using a third encryption method. Further, the data management service can send the encrypted first data (obtained by encryption using the third encryption method) to the key management service 120 in the trusted execution environment 442. Furthermore, the key management service 120 can decrypt the encrypted first data based on the decryption method corresponding to the third encryption method to obtain the decrypted first data. Furthermore, the key management service 120 can create an encryption key corresponding to the data to be encrypted, such as a first key corresponding to a user. Furthermore, the key management service 120 can encrypt the decrypted first data based on the first key to obtain the encrypted first data. Furthermore, the key management service 120 can send the encrypted first data to the data management service 110. Furthermore, the data management service 110 can store the encrypted first data in the database 305.

[0080] In some embodiments, the client-side application 401 may, in response to receiving a user input request (e.g., "Please help me log in to application A"), send this user request to the data management service 110, wherein the user request is a request to obtain the user's first data. Further, the data management service 110 may obtain encrypted first data (e.g., encrypted account and encrypted password) from the database 305. Further, the data management service 110 may provide this encrypted first data to the operating system 403 of the task execution terminal 140.

[0081] In some embodiments, the task execution terminal 140 can use the operating system 403 to send the encrypted first data to the key management service 120. Further, the task execution terminal 140 can use the key management service 120 to determine the first key corresponding to the encrypted first data. Further, the key management service 120 can decrypt the encrypted first data based on the first key to obtain the decrypted first data. Further, the key management service 120 can encrypt the decrypted first data based on a second encryption method to obtain the encrypted first data. Further, the task execution terminal 140 can receive the encrypted first data sent by the key management service. Further, the task execution terminal 140 can decrypt the encrypted first data based on the decryption method corresponding to the second encryption method to interact with application A based on the first data and log in to application A.

[0082] In other embodiments, the key management service 120 can encrypt the first key based on the second encryption method to obtain the encrypted first key. Further, the key management service 120 can send this encrypted first key to the communication encryption / decryption module in the TEE 402, so that the encrypted first key can be decrypted in the third trusted execution environment based on the decryption method corresponding to the second encryption method. Further, the task execution terminal 140 can decrypt the encrypted first data based on the decrypted first key to obtain the decrypted first data. Further, the task execution terminal 140 can interact with application A based on the first data to log in to application A.

[0083] It should be noted that the terminal application 401, data management service 110, and key management service 120 are all configured with communication encryption and decryption modules, which can support the functions of encrypting and decrypting data. Specifically, when any two units of the terminal application 401, data management service 110, and key management service 120 transmit any appropriate data, the data can be encrypted based on the encryption and decryption module in the unit sending the data, and the received encrypted data can be decrypted based on the encryption and decryption module in the unit receiving the data. Further details will not be elaborated here.

[0084] Based on this approach, embodiments of this disclosure can effectively avoid the leakage of sensitive data such as keys and data transmitted via the data management service by deploying the data management service in a first trusted execution environment and running the key management unit in a second trusted execution environment, thereby significantly improving security. Furthermore, the large-scale application and the data management server encrypt the user's initial data using a pre-agreed encryption method, effectively ensuring the security of user data during transmission.

[0085] Example Apparatus and Device

[0086] Embodiments of this disclosure also provide corresponding apparatus for implementing the above methods or processes. Figure 5 A schematic structural block diagram of an apparatus 500 for enhancing data security in large-scale application according to certain embodiments of the present disclosure is shown. The apparatus 500 may be implemented as or included in the terminal device 110 discussed above. The various modules / components in the apparatus 500 may be implemented by hardware, software, firmware, or any combination thereof.

[0087] like Figure 5 As shown, the device 500 includes a receiving module 510, configured for a data management service to receive encrypted user data encrypted using a first encryption method from a large model application, the encrypted user data including the user's first data, wherein the data management service is deployed in a first trusted execution environment; a first processing module 520, configured for the data management service to decrypt the encrypted user data using a decryption method corresponding to the first encryption method to obtain the first data, and for the data management service to store the encrypted first data in a database, wherein the encrypted first data is obtained by encrypting the decrypted first data using a first key corresponding to the user maintained by a key management service, the key management service being deployed in a second trusted execution environment; a second processing module 530, configured for the data management service to, in response to a request from the large model application to obtain the user's first data, retrieve the encrypted first data from the database and send the encrypted first data to the large model application; wherein the large model application sends the encrypted first data to a task execution end; and a communication module 540, configured for the key management service to communicate with the task execution end, enabling the task execution end to obtain the first data decrypted based on the first key, and then the task execution end to execute a task based on the first data.

[0088] In some embodiments, the communication module 540 is further configured to: in response to receiving a key acquisition request from the corresponding user of the task execution terminal, the key management service encrypts the first key using the second encryption method and sends it to the task execution terminal; the task execution terminal decrypts the first key based on the decryption method corresponding to the second encryption method and then uses the first key to decrypt the encrypted first data.

[0089] In some embodiments, a third trusted execution environment is deployed in the task execution terminal, and the task execution terminal decrypts the encrypted first data based on the following process: the task execution terminal decrypts the encrypted first key in the third trusted execution environment; and the task execution terminal decrypts the encrypted first data using the first key in the third trusted execution environment.

[0090] In some embodiments, the communication module 540 is further configured to: the key management service, in response to receiving a decryption request for the corresponding encrypted first data from the task execution end, decrypt the encrypted first data based on the first key; the key management service encrypts the first data using a second encryption method and sends it to the task execution end; and the task execution end decrypts the encrypted first data based on the decryption method corresponding to the second encryption method.

[0091] In some embodiments, the first processing module 520 is further configured to: encrypt the decrypted first data using a third encryption method to obtain encrypted first data; send the encrypted first data to a key management service; decrypt the encrypted first data using the decryption method corresponding to the third encryption method; encrypt the first data using a first key corresponding to the user and send it to the data management service; and store the first data encrypted with the first key in a database.

[0092] In some embodiments, the first processing module 520 is further configured to: encrypt the first key corresponding to the user based on the fourth encryption method to obtain the encrypted first key; obtain the encrypted first key from the key management service; decrypt the encrypted first key based on the decryption method corresponding to the fourth encryption method; and encrypt the decrypted first data using the first key and store it in the database.

[0093] In some embodiments, the apparatus 500 further includes a third processing module, which is further configured to: send a first security authentication request to a key management service, and the data management service authenticates whether the first security certificate meets the security conditions based on the first security certificate obtained from the key management service; or a fourth processing module, which is configured to: send a second security authentication request to a data management service, and the key management service authenticates whether the second security certificate meets the security conditions based on the second security certificate obtained from the data management service.

[0094] In some embodiments, the task execution terminal performs a task based on the first data, including: the task execution terminal interacts with the target application based on the first data to perform the task.

[0095] In some embodiments, the request is a first request, and the receiving module 510 is further configured to: the data management service receive a second request from the large model application to obtain first data; in response to the database not including the first data, the data management service provides the large model application with prompt content for the second request, the prompt content being used to prompt input of data associated with the second request; and the data management service receives encrypted user data from the large model application, the encrypted user data including the first data determined based on user input data.

[0096] The units included in device 500 can be implemented in various ways, including software, hardware, firmware, or any combination thereof. In some embodiments, one or more units may be implemented using software and / or firmware, such as machine-executable instructions stored on a storage medium. In addition to or as an alternative to machine-executable instructions, some or all of the units in device 500 may be implemented at least partially by one or more hardware logic components. By way of example and not limitation, exemplary types of hardware logic components that may be used include field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-chips (SoCs), complex programmable logic devices (CPLDs), and so on.

[0097] Figure 6 A block diagram of an electronic device 600 in which one or more embodiments of the present disclosure may be implemented is shown. It should be understood that... Figure 6 The electronic device 600 shown is merely exemplary and should not be construed as limiting the functionality and scope of the embodiments described herein. Figure 6 The electronic device 600 shown can be used to achieve Figure 1 The terminal device 110 shown.

[0098] like Figure 6 As shown, electronic device 600 is in the form of a general-purpose electronic device. Components of electronic device 600 may include, but are not limited to, one or more processors or processing units 610, memory 620, storage device 630, one or more communication units 640, one or more input devices 650, and one or more output devices 660. Processing unit 610 may be a physical or virtual processor and is capable of performing various processes according to programs stored in memory 620. In a multiprocessor system, multiple processing units execute computer-executable instructions in parallel to improve the parallel processing capability of electronic device 600.

[0099] Electronic device 600 typically includes multiple computer storage media. Such media can be any accessible media that is accessible to electronic device 600, including but not limited to volatile and non-volatile media, removable and non-removable media. Memory 620 can be volatile memory (e.g., registers, cache, random access memory (RAM)), non-volatile memory (e.g., read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory), or some combination thereof. Storage device 630 can be a removable or non-removable medium and can include machine-readable media, such as flash drives, disks, or any other media that can be used to store information and / or data (e.g., training data for training) and can be accessed within electronic device 600.

[0100] Electronic device 600 may further include additional removable / non-removable, volatile / non-volatile storage media. Although not explicitly stated... Figure 6 As shown, disk drives for reading from or writing to removable, non-volatile disks (e.g., "floppy disks") and optical disk drives for reading from or writing to removable, non-volatile optical disks can be provided. In these cases, each drive can be connected to a bus (not shown) via one or more data media interfaces. Memory 620 may include computer program product 625 having one or more program modules configured to perform various methods or actions of various embodiments of this disclosure.

[0101] The communication unit 640 enables communication with other electronic devices via a communication medium. Additionally, the functionality of the components of the electronic device 600 can be implemented using a single computing cluster or multiple computing machines capable of communicating via communication connections. Therefore, the electronic device 600 can operate in a networked environment using logical connections to one or more other servers, network personal computers (PCs), or another network node.

[0102] Input device 650 can be one or more input devices, such as a mouse, keyboard, trackball, etc. Output device 660 can be one or more output devices, such as a monitor, speaker, printer, etc. Electronic device 600 can also communicate with one or more external devices (not shown) via communication unit 640 as needed. These external devices include storage devices, display devices, etc., and can communicate with one or more devices that enable user interaction with electronic device 600, or with any device that enables electronic device 600 to communicate with one or more other electronic devices (e.g., network card, modem, etc.). Such communication can be performed via input / output (I / O) interface (not shown).

[0103] According to an exemplary implementation of this disclosure, a computer-readable storage medium is provided that stores computer-executable instructions thereon, wherein the computer-executable instructions are executed by a processor to implement the methods described above. According to an exemplary implementation of this disclosure, a computer program product is also provided, which is tangibly stored on a non-transitory computer-readable medium and includes computer-executable instructions, which are executed by a processor to implement the methods described above.

[0104] Various aspects of this disclosure are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatuses, devices, and computer program products implemented according to this disclosure. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0105] These computer-readable program instructions can be provided to a processing unit of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that, when executed by the processing unit of the computer or other programmable data processing apparatus, they create means for implementing the functions / actions specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium that causes a computer, programmable data processing apparatus, and / or other device to operate in a particular manner. Thus, the computer-readable medium storing the instructions comprises an article of manufacture that includes instructions for implementing aspects of the functions / actions specified in one or more blocks of the flowchart and / or block diagram.

[0106] Computer-readable program instructions can be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions that execute on the computer, other programmable data processing apparatus, or other device to perform the functions / actions specified in one or more boxes of a flowchart and / or block diagram.

[0107] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of an instruction, which contains one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0108] Various implementations of this disclosure have been described above. These descriptions are exemplary and not exhaustive, nor are they limited to the disclosed implementations. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described implementations. The terminology used herein is chosen to best explain the principles, practical applications, or improvements to technology in the market, or to enable others skilled in the art to understand the various implementations disclosed herein.

Claims

1. A method for enhancing data security in large-scale model applications, comprising the following steps performed by a data management service deployed in a first trusted execution environment and a key management service deployed in a second trusted execution environment: The data management service receives encrypted user data from a large model application, which is encrypted using a first encryption method. The encrypted user data includes the user's first data. The data management service decrypts the ciphertext user data based on the decryption method corresponding to the first encryption method to obtain the first data, and the data management service stores the encrypted first data in the database. The encrypted first data is obtained by encrypting the decrypted first data based on the first key corresponding to the user maintained by the key management service. In response to receiving a request from the large model application to obtain the user's first data, the data management service retrieves the encrypted first data from the database and sends the encrypted first data to the large model application; wherein, the large model application sends the encrypted first data to the task execution terminal; Furthermore, the key management service communicates with the task execution terminal, enabling the task execution terminal to obtain the first data decrypted based on the first key, and then the task execution terminal executes the task based on the first data.

2. The method according to claim 1, wherein, The key management service communicates with the task execution terminal, enabling the task execution terminal to obtain the first data decrypted based on the first key, including: In response to receiving a key acquisition request from the task execution terminal corresponding to the user, the key management service encrypts the first key using a second encryption method and sends it to the task execution terminal; the task execution terminal decrypts the first key based on the decryption method corresponding to the second encryption method, and then uses the first key to decrypt the encrypted first data.

3. The method according to claim 2, wherein, The task execution terminal is equipped with a third trusted execution environment, and the task execution terminal decrypts the encrypted first data based on the following process: The task execution terminal decrypts the encrypted first key in the third trusted execution environment; and The task execution terminal decrypts the encrypted first data using the first key in the third trusted execution environment.

4. The method according to claim 1, wherein, The key management service communicates with the task execution terminal, enabling the task execution terminal to obtain the first data decrypted based on the first key, including: In response to receiving a decryption request for the encrypted first data from the task execution end, the key management service decrypts the encrypted first data based on the first key; the key management service encrypts the first data using a second encryption method and sends it to the task execution end; and the task execution end decrypts the encrypted first data based on the decryption method corresponding to the second encryption method.

5. The method of claim 1, wherein the data management service stores the encrypted first data in the database, comprising: The data management service encrypts the decrypted first data using a third encryption method to obtain the encrypted first data. The data management service sends the encrypted first data to the key management service; The key management service decrypts the encrypted first data based on the decryption method corresponding to the third encryption method; as well as The key management service encrypts the first data based on the first key corresponding to the user and then sends it to the data management service; The data management service stores the first data, encrypted with the first key, into the database.

6. The method of claim 1, wherein the data management service stores the encrypted first data in the database comprising: The key management service encrypts the first key corresponding to the user based on the fourth encryption method to obtain the encrypted first key; The data management service obtains the encrypted first key from the key management service; The data management service decrypts the encrypted first key based on the decryption method corresponding to the fourth encryption method; as well as The data management service uses the first key to encrypt the decrypted first data and then stores it in the database.

7. The method of claim 1, wherein before the data management service stores the encrypted first data in the database, the method further comprises: The data management service sends a first security authentication request to the key management service, and the data management service authenticates whether the first security certificate meets the security conditions based on the first security certificate obtained from the key management service. or The key management service sends a second security authentication request to the data management service, and the key management service authenticates whether the second security certificate meets the security conditions based on the second security certificate obtained from the data management service.

8. The method according to claim 1, wherein the task execution terminal executes the task based on the first data, comprising: The task execution terminal interacts with the target application based on the first data to execute the task.

9. The method of claim 1, wherein the request is a first request, and the data management service receiving encrypted user data encrypted in a first encryption method from a large model application comprises: The data management service receives a second request from the large model application to obtain the first data; In response to the fact that the database does not contain the first data, the data management service provides the large model application with prompts for the second request, the prompts being used to suggest inputting data associated with the second request; as well as The data management service receives the encrypted user data from the large model application, the encrypted user data including the first data determined based on user input data.

10. An apparatus for enhancing data security in large model applications, comprising: The receiving module is configured to receive encrypted user data encrypted in a first encryption method from a large model application, wherein the encrypted user data includes the user's first data, and wherein the data management service is deployed in a first trusted execution environment; The first processing module is configured to have the data management service decrypt the ciphertext user data based on the decryption method corresponding to the first encryption method to obtain the first data, and the data management service store the encrypted first data in the database. The encrypted first data is obtained by encrypting the decrypted first data based on the first key corresponding to the user maintained by the key management service. The key management service is deployed in the second trusted execution environment. The second processing module is configured such that, in response to a request from the large model application to obtain the user's first data, the data management service retrieves the encrypted first data from the database and sends the encrypted first data to the large model application; wherein the large model application sends the encrypted first data to the task execution terminal. The communication module is configured to communicate between the key management service and the task execution end, so that the task execution end obtains the first data decrypted based on the first key, and then the task execution end executes the task based on the first data.

11. An electronic device, comprising: At least one processing unit; as well as At least one memory, coupled to the at least one processing unit and storing instructions for execution by the at least one processing unit, which, when executed by the at least one processing unit, cause the electronic device to perform the method according to any one of claims 1 to 9.

12. A computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method according to any one of claims 1 to 9.

13. A computer program product comprising computer-executable instructions, wherein the computer-executable instructions, when executed by a processor, implement the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Encrypted database system and method and device for realizing encrypted database system

    CN112699399A

  • Data management method, device and system and storage medium

    CN114417362A

  • Secret-related information maintenance method and device, equipment and storage medium

    CN116244750A

  • Service processing method and device based on artificial intelligence, computer equipment and medium

    CN119203223A

  • Data processing method and device, equipment and storage medium

    CN119622760A

Cited By

  • Large model service safe operation method and device, medium, equipment and program product

    CN121256818A

  • Key management method and device for large model service, medium, equipment and product

    CN121309226A