Method, device and storage medium for enhancing data security of large model application

CN120979705BActive Publication Date: 2026-09-22BEIJING ZITIAO NETWORK TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511061833.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-30
Publication Date
2026-09-22
Estimated Expiration
2045-07-30

AI Technical Summary

Benefits of technology

[0008]应当理解,本内容部分中所描述的内容并非旨在限定本公开的实施例的关键特征或重要特征,也不用于限制本公开的范围。本公开的其它特征将通过以下的描述而变得容易理解。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979705B_ABST
    Figure CN120979705B_ABST
Patent Text Reader

Abstract

According to an embodiment of the present disclosure, a method, device, equipment and storage medium for enhancing data security of a large model application are provided. The method comprises: a data management service receiving ciphertext user data from the large model application, the ciphertext user data comprising first data of a user; the data management service decrypting the ciphertext user data to obtain the first data, and storing encrypted first data into a database, the encrypted first data being encrypted based on a first key corresponding to the user maintained by a key management service; the data management service obtaining the encrypted first data from the database in response to receiving a request for obtaining the first data of the user, and sending the encrypted first data to the large model application, the large model application sending the encrypted first data to a task execution end; and the key management service communicating with the task execution end, so that the task execution end obtains the first data decrypted based on the first key and performs a task based on the first data, thereby improving security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The exemplary embodiments disclosed herein generally relate to the field of computers, and more particularly to methods, apparatus, devices, and computer-readable storage media for enhancing data security in large-scale model applications. Background Technology

[0002] With the development of artificial intelligence technology, large-scale model applications have emerged as an important development direction, demonstrating strong potential in areas such as dialogue interaction, knowledge reasoning, and content creation. Large-scale models can be machine learning models with a large number of parameters, such as Large Language Models (LLMs), visual large-scale models, speech large-scale models, or multimodal large-scale models. They can achieve a closed loop of "understanding-planning-execution" through large-scale models, not only generating text but also completing practical operations through tool calls, dynamic programming, and continuous learning. Summary of the Invention

[0003] In a first aspect of this disclosure, a method for enhancing data security in a large-scale model application is provided, comprising the following steps performed by a data management service deployed in a first trusted execution environment and a key management service deployed in a second trusted execution environment: the data management service receives encrypted user data from the large-scale model application, encrypted using a first encryption method, the encrypted user data including the user's first data; the data management service decrypts the encrypted user data using a decryption method corresponding to the first encryption method to obtain the first data; and the data management service stores the encrypted first data in a database, the encrypted first data being obtained by encrypting the decrypted first data using a first key corresponding to the user maintained by the key management service; in response to receiving a request from the large-scale model application to obtain the user's first data, the data management service retrieves the encrypted first data from the database and sends the encrypted first data to the large-scale model application; wherein the large-scale model application sends the encrypted first data to a task execution end; and the key management service communicates with the task execution end, enabling the task execution end to obtain the first data decrypted based on the first key, and then the task execution end executes a task based on the first data.

[0004] In a second aspect of this disclosure, an apparatus for enhancing data security in large-scale model applications is provided. The apparatus includes: a receiving module configured to receive encrypted user data encrypted using a first encryption method from a large-scale model application, the encrypted user data including first data of the user, wherein the data management service is deployed in a first trusted execution environment; a first processing module configured to decrypt the encrypted user data using a decryption method corresponding to the first encryption method to obtain the first data, and to store the encrypted first data in a database, wherein the encrypted first data is obtained by encrypting the decrypted first data using a first key corresponding to the user maintained by a key management service, the key management service being deployed in a second trusted execution environment; a second processing module configured to, in response to receiving a request from the large-scale model application to obtain the user's first data, retrieve the encrypted first data from the database and send the encrypted first data to the large-scale model application; wherein the large-scale model application sends the encrypted first data to a task execution end; and a communication module configured to communicate between the key management service and the task execution end, enabling the task execution end to obtain the first data decrypted based on the first key, and subsequently, the task execution end to perform a task based on the first data.

[0005] In a third aspect of this disclosure, an electronic device is provided. The device includes at least one processing unit; and at least one memory coupled to the at least one processing unit and storing instructions for execution by the at least one processing unit. When executed by the at least one processing unit, the instructions cause the device to perform the method of the first aspect.

[0006] In a fourth aspect of this disclosure, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program that can be executed by a processor to implement the method of the first aspect.

[0007] In a fifth aspect of this disclosure, a computer program product is provided. The computer program product includes computer-executable instructions that, when executed by a processor, implement the method according to a first aspect of this disclosure.

[0008] It should be understood that the content described in this content section is not intended to limit the key or essential features of the embodiments of this disclosure, nor is it intended to restrict the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0009] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. In the drawings, the same or similar reference numerals denote the same or similar elements, wherein: Figure 1A schematic diagram of an example environment in which embodiments of the present disclosure can be implemented is shown; Figure 2 A flowchart illustrating a process for enhancing data security in large model applications according to some embodiments of the present disclosure is shown; Figure 3 Example flowcharts of data encryption and data decryption processes according to some embodiments of the present disclosure are shown; Figure 4 A schematic diagram of an architecture for request processing of large models is shown according to some embodiments of the present disclosure; Figure 5 A schematic structural block diagram of an apparatus for enhancing data security in large model applications, according to certain embodiments of the present disclosure, is shown. Figure 6 A block diagram of an electronic device capable of implementing several embodiments of the present disclosure is shown. Detailed Implementation

[0010] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0011] It should be noted that the headings of any section / subsection provided herein are not limiting. Various embodiments are described throughout this document, and embodiments of any type may be included under any section / subsection. Furthermore, embodiments described in any section / subsection may be combined in any way with any other embodiments described in the same section / subsection and / or different sections / subsections.

[0012] In the description of embodiments of this disclosure, the term "comprising" and similar terms should be understood as open-ended inclusion, i.e., "including but not limited to". The term "based on" should be understood as "at least partially based on". The term "one embodiment" or "the embodiment" should be understood as "at least one embodiment". The term "some embodiments" should be understood as "at least some embodiments". Other explicit and implicit definitions may also be included below. The terms "first", "second", etc., may refer to different or the same objects. Other explicit and implicit definitions may also be included below.

[0013] The embodiments of this disclosure may involve user data, data acquisition, and / or use. All of these aspects comply with applicable laws, regulations, and relevant provisions. In the embodiments of this disclosure, all data collection, acquisition, processing, manipulation, forwarding, and use are conducted with the user's knowledge and confirmation. Accordingly, in implementing the embodiments of this disclosure, the type, scope of use, and usage scenarios of any data or information that may be involved should be communicated to the user and their authorization obtained in accordance with relevant laws and regulations through appropriate means. The specific methods of notification and / or authorization may vary depending on the actual situation and application scenario, and the scope of this disclosure is not limited in this respect.

[0014] In this specification and the embodiments, any processing of personal information will be carried out only under the premise of legality (such as obtaining the consent of the personal information subject, or being necessary for the performance of a contract), and will only be carried out within the scope stipulated or agreed upon. A user's refusal to process personal information beyond what is necessary for basic functions will not affect the user's use of basic functions.

[0015] This disclosure proposes a scheme to enhance the data security of large-scale application models. According to this scheme, a data management service receives encrypted user data from a large-scale application model, encrypted using a first encryption method. The encrypted user data includes the user's first data. Further, the data management service decrypts the encrypted user data using a decryption method corresponding to the first encryption method to obtain the first data, and stores the encrypted first data in a database. The encrypted first data is obtained by encrypting the decrypted first data using a first key maintained by a key management service corresponding to the user. Further, in response to a request from the large-scale application model to retrieve the user's first data, the data management service retrieves the encrypted first data from the database and sends it to the large-scale application model; wherein the large-scale application model sends the encrypted first data to a task execution terminal. Further, the key management service communicates with the task execution terminal, enabling the task execution terminal to obtain the first data decrypted using the first key, and then the task execution terminal performs a task based on the first data.

[0016] Based on this approach, embodiments of this disclosure can effectively avoid the leakage of sensitive data such as keys and data transmitted via the data management service by deploying the data management service in a first trusted execution environment and running the key management unit in a second trusted execution environment, thereby significantly improving security. Furthermore, the large-scale application and the data management server encrypt the user's initial data using a pre-agreed encryption method, effectively ensuring the security of user data during transmission.

[0017] Example Environment Figure 1 A schematic diagram of an example environment 100 in which embodiments of the present disclosure can be implemented is shown. For example... Figure 1 As shown, example environment 100 may include data management service 110 and key management service 120.

[0018] In this example environment 100, the data management service 110 can be deployed in a first trusted execution environment. The key management service 120 can be deployed in a second trusted execution environment. The first and second trusted execution environments can be the same trusted execution environment (TEE) or different trusted execution environments. In some embodiments, the data management service 110 and the key management service 120 can reside on the server corresponding to the large model application 130.

[0019] Specifically, data management service 110 receives encrypted user data encrypted using a first encryption method from large model application 130. The encrypted user data includes the user's first data. Data management service 110 decrypts the encrypted user data using the decryption method corresponding to the first encryption method to obtain the first data. Data management service 110 or key management service 120 encrypts the decrypted first data using a first key maintained by key management service 120 corresponding to the user, and stores it in a database. In response to a request from large model application 130 to retrieve the user's first data, data management service 110 retrieves the encrypted first data from the database and sends it to large model application 130. Large model application 130 then sends the encrypted first data to task execution terminal 140. Key management service 120 communicates with task execution terminal 140, enabling task execution terminal 140 to obtain the first data decrypted using the first key, and then task execution terminal 140 executes the task based on the first data.

[0020] In some embodiments, the user's first data may be data input by the user based on the client of the large-scale application 130. This client may be any type of mobile terminal, fixed terminal, or portable terminal with a display device, including mobile phones, desktop computers, laptop computers, notebook computers, netbook computers, tablet computers, media computers, multimedia tablets, handheld computers, portable gaming terminals, VR / AR devices, personal communication system (PCS) devices, personal navigation devices, personal digital assistants (PDAs), audio / video players, digital cameras / camcorders, positioning devices, television receivers, radio receivers, e-book devices, gaming devices, or any combination thereof, including accessories and peripherals of these devices or any combination thereof. In some embodiments, the client of the large-scale application 130 may also support any type of interface for the target user (such as "wearable" circuitry).

[0021] The server-side of the large-scale application 130 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks, and big data and artificial intelligence platforms. The server-side of the large-scale application 130 can include, for example, computing systems / servers such as mainframes, edge computing nodes, and computing devices in cloud environments, etc.

[0022] The task execution terminal 140 can be any suitable software or hardware, such as cloud phones, terminal devices, etc., which will not be elaborated here.

[0023] It should be understood that the structure and function of the various elements in environment 100 are described for illustrative purposes only and do not imply any limitation on the scope of this disclosure.

[0024] The following description will continue with reference to the accompanying drawings, which will provide some exemplary embodiments of this disclosure.

[0025] Example process Figure 2 A flowchart of a process 200 for enhancing data security in large-scale application models according to some embodiments of the present disclosure is shown. Process 200 may be performed by a data management service 110 deployed in a first trusted execution environment and a key management service 120 deployed in a second trusted execution environment.

[0026] In some embodiments, the first trusted execution environment (TEX) or the second trusted execution environment (TEX) can be a secure area within the server-side computing system of the large model application 130, providing an isolated, protected space for processing sensitive data and performing critical security operations. The first TEX or the second TEX can run as a separate environment within the server-side of the large model application 130 and can run in parallel with the server-side operating system of the large model application 130. This environment is designed to withstand external attacks and internal threats, ensuring the security and integrity of the data processed and the operations performed within it, and is more secure than the operating system. In some embodiments, the first TEX and the second TEX can be the same trusted execution environment, or they can be different trusted execution environments.

[0027] The following is for reference. Figure 1 Description of process 200. In box 210, data management service 110 receives encrypted user data encrypted in a first encryption method from large model application 130, the encrypted user data including the user's first data.

[0028] In some embodiments, the large model application 130 can be various specific application scenarios and solutions developed using large machine learning models. The large machine learning model can be any suitable machine learning model with a large number of parameters, which can be configured to handle any suitable complex task. For example, in embodiments of this disclosure, the large machine learning model can be a large model. As an example, a large model can be an LLM, and can also be a speech large model, a vision large model, a multimodal large model, etc. In some embodiments, the large model application 130 can include, but is not limited to, agents, natural language processing, etc.

[0029] In some embodiments, an intelligent agent is a system or entity capable of perceiving its environment and making decisions, or making decisions and taking actions to achieve a specific goal or task. In some scenarios, an intelligent agent is also referred to as an Agent. In some embodiments, an intelligent agent may utilize one or more large models to drive its interaction with the user, and the interaction can be any appropriate interaction. Additionally, an intelligent agent may work in a human-like manner, using large models to "understand" the user's intentions, proactively "planning" to achieve goals, and utilizing various "tools" to complete tasks, ultimately "acting" to execute these tasks.

[0030] In some embodiments, the user's first data can be any suitable type of request, such as text, voice, image, etc. The user's first data can be input from a client based on the large model application 130, such as input from a conversation window between the user and the agent on the client. The first data can be any suitable data, such as the user's account, password, mobile phone number, etc.

[0031] To ensure the security of data transmission, in some embodiments, the client of the large model application 130 can encrypt the user's first data using a first encryption method to obtain encrypted user data. The first encryption method can be an encryption method agreed upon by the large model application 130 and the data management service 110, which can be a symmetric encryption method or an asymmetric encryption method, and will not be elaborated here.

[0032] Furthermore, the client of the large model application 130 can send encrypted user data to the data management service 110. As an example, the client of the large model application 130 can send encrypted user data to an intermediate service (such as an agent service, i.e., an agent server). The intermediate service can then send the encrypted user data to the data management service 110. The intermediate service can act as an intermediary for requests or data transmission, used to transfer data or requests between the large model application 130 and the data management service 110. For ease of description, the large model application 130 and the intermediate service can be collectively referred to as the end-side application.

[0033] In some embodiments, since there is data or request transmission between the endpoint application and the data management service 110, to ensure transmission security, the endpoint application may send a target security authentication request to the data management service 110 before transmitting data with the data management service 110. Further, the data management service 110 may provide the endpoint application with its security certificate. Further, the endpoint application may determine whether this security certificate meets preset security requirements. Further, in response to the security certificate meeting the security requirements, the endpoint application may determine that the data transmission between the endpoint application and the data management service 110 is secure. This security requirement can be any appropriate requirement that measures the identity and trustworthiness of the data management service 110, such as whether the security certificate is valid, whether the security certificate is within its validity period, etc. Specifically, in response to the security certificate meeting the security requirements, the endpoint application may establish a transmission channel between the data management service 110 and the endpoint application. This transmission channel is the foundation for supporting data transmission between the agent and the data management service 110.

[0034] In some embodiments, to improve efficiency, the electronic device can store the user data entered by the user in the historical process in an encrypted form in the database, so that the subsequent task execution terminal 140 can execute the corresponding task based on the plaintext obtained after decrypting the encrypted user data. In order to avoid repeated input of user data and improve interaction efficiency, in some embodiments, the user's first data can be the data prompted to be entered by the user after it is determined that the first data does not exist in the database.

[0035] Specifically, the data management service 110 can receive a second request from the large model application 130 to obtain the first data. The second request can be any appropriate request, such as "Help me buy a train ticket from program A," and the first data can be the mobile phone number required to buy the train ticket. Further, in response to the database not containing the first data, the data management service 110 provides the large model application 130 with a prompt for the second request. This prompt prompt is used to suggest inputting data associated with the second request. The prompt prompt can be any appropriate form of content, such as text, images, etc. The prompt prompt can be the text "You need a mobile phone number to buy a train ticket; please enter your mobile phone number." Taking the large model application 130 as an agent as an example, this prompt prompt can be presented on the user-agent conversation interface in the form of conversation content output by the agent.

[0036] Furthermore, the data management service 110 can receive encrypted user data from the large model application 130, which includes first data determined based on user input data. For example, this encrypted user data could be encrypted using the phone number entered by the user after viewing the prompt.

[0037] In box 220, data management service 110 decrypts the encrypted user data based on the decryption method corresponding to the first encryption method to obtain the first data, and data management service 110 stores the encrypted first data in the database. The encrypted first data is obtained by encrypting the decrypted first data based on the first key corresponding to the user maintained by key management service 120.

[0038] In some embodiments, the decryption method corresponding to the first encryption method is the decryption method agreed upon by the large model application 130 and the data management service 110. As an example, if the first encryption method is symmetric encryption of the first data using a certain key, then the decryption method can be decrypting the encrypted user data using that key. As another example, if the first encryption method is asymmetric encryption of the first data using a certain public key, then the decryption method can be decrypting the encrypted user data using the private key corresponding to that public key.

[0039] To facilitate the execution of other tasks based on the first data and to ensure the security of the first data, the key management service 120 can encrypt the decrypted first data based on the first key it maintains corresponding to the user and send it to the data management service 110, so that the data management service 110 can store the encrypted first data in the database.

[0040] As an example, data management service 110 can send the decrypted first data to key management service 120, so that key management service 120 can encrypt the received decrypted first data based on the user's first key that it maintains.

[0041] In some embodiments, to ensure the security of the decrypted first data during transmission, the data management service 110 can encrypt the decrypted first data based on a third encryption method to obtain the encrypted first data. The third encryption method can be an encryption method agreed upon by the key management service 120 and the data management service 110. The third encryption method can be a symmetric encryption method or an asymmetric encryption method, which will not be elaborated here. Further, the data management service 110 can send the encrypted first data to the key management service 120. At this time, the first data is sent to the key management service 120 in ciphertext form, which can effectively ensure the security of the first data during transmission. Further, the key management service 120 decrypts the encrypted first data based on the decryption method corresponding to the third encryption method. The decryption method corresponding to the third encryption method can be a decryption method agreed upon by the key management service 120 and the data management service 110. As an example, if the third encryption method is symmetric encryption of the first data using a certain key, then the decryption method can be decrypting the encrypted first data using that key. As another example, if the third encryption method is to perform asymmetric encryption on the first data using a certain public key, then the decryption method can be to decrypt the encrypted first data using the private key corresponding to this public key.

[0042] Furthermore, the key management service 120 can encrypt the first data based on the user's corresponding first key and then send it to the data management service 110. Furthermore, the data management service 110 can store the first data encrypted with the first key into a database.

[0043] As another example, the data management service 110 can obtain the user's first key maintained by the key management service 120, and encrypt the decrypted first data based on the first key.

[0044] To ensure the security of the first key during transmission, in some embodiments, the key management service 120 can encrypt the user's corresponding first key based on a fourth encryption method to obtain the encrypted first key. The fourth encryption method can be an encryption method agreed upon by the key management service 120 and the data management service 110. The fourth encryption method can be a symmetric encryption method or an asymmetric encryption method, which will not be elaborated here. Further, the data management service 110 can obtain the encrypted first key from the key management service 120. Further, the data management service 110 decrypts the encrypted first key based on the decryption method corresponding to the fourth encryption method. The decryption method corresponding to the fourth encryption method can be a decryption method agreed upon by the key management service 120 and the data management service 110. As an example, if the fourth encryption method is symmetric encryption of the first key using a certain key, then the decryption method can be decrypting the first key using that key. As another example, if the fourth encryption method is asymmetric encryption of the first key using a certain public key, then the decryption method can be decrypting the first key using the private key corresponding to that public key.

[0045] Furthermore, the data management service 110 uses the first key to encrypt the decrypted first data and then stores it in the database.

[0046] Since data management service 110 and key management service 120 involve data transmission, in order to ensure the security of data transmission between the two services, a security verification can be performed before the first data, which is decrypted based on the first key pair corresponding to the user maintained by key management service 120, is encrypted and stored in the database.

[0047] In some embodiments, the data management service 110 may send a first security authentication request to the key management service 120. This first security authentication request may include information to be authenticated, such as information associated with the key management service 120. Further, the data management service 110 may authenticate whether a first security certificate obtained from the key management service 120 meets security conditions. These security conditions may be any appropriate auxiliary conditions that can measure the identity and trustworthiness of the key management service 120, such as whether the security certificate is valid, whether the security certificate is within its validity period, etc.

[0048] It should be noted that, generally, before sending data to the receiver, the sender needs to verify whether the receiver meets the security requirements. Therefore, the verification based on the first security certificate mentioned above can be the first data obtained by sending the decrypted first data to the key management service 120 or by encrypting the decrypted data based on the third encryption method, and the verification required by the key management service 120 before encrypting the first data based on the first key.

[0049] In other embodiments, the key management service 120 may send a second security authentication request to the data management service 110. This second security authentication request may include information to be authenticated, such as information associated with the data management service 110. The key management service 120 may authenticate whether a second security certificate obtained from the data management service 110 meets security conditions. These security conditions may be any appropriate auxiliary conditions that can measure the identity and trustworthiness of the data management service 110, such as whether the security certificate is valid, whether the security certificate is within its validity period, etc.

[0050] It should be noted that, generally, before sending data to the receiver, the sender needs to verify whether the receiver meets the security requirements. Therefore, the verification based on the second security certificate mentioned above can be the first key obtained by the key management service 120 sending the first key to the data management service 110 or encrypting the first key based on the fourth encryption method, and the verification required in the data management service 110 before encrypting the first data based on the first key.

[0051] Furthermore, in response to the first security certificate or the second security certificate meeting the security conditions, the data management service 110 or the key management service 120 may perform the operation of encrypting the decrypted first data based on the first key pair corresponding to the user maintained by the key management service 120 and storing it in the database.

[0052] In box 230, in response to receiving a request from the large model application 130 to obtain the user's first data, the data management service 110 retrieves the encrypted first data from the database and sends the encrypted first data to the large model application 130; wherein, the large model application 130 sends the encrypted first data to the task execution terminal 140.

[0053] As an example, this request (the first request) could be a request provided by the user to the large model application 130. In some embodiments, this request could be any suitable type of request, such as text, voice, image, etc. For example, this request could be a text request from the user based on a conversation window between the user and the agent, such as "Please buy me a plane ticket from application A".

[0054] In some embodiments, the task execution terminal 140 can be any suitable software, hardware, etc., such as a cloud phone or an electronic device. This electronic device can be the same device as the client corresponding to the large model application 130, or it can be a different device. A cloud phone is a virtual mobile phone service provided through a remote server. Users can access these services via the internet and perform operations on the cloud server that would normally be performed on a local client. The main function of a cloud phone is to transfer the client's computing and storage resources to the cloud, thereby enabling cross-device access and operation.

[0055] In box 240, the key management service 120 communicates with the task execution terminal 140, enabling the task execution terminal 140 to obtain the first data decrypted based on the first key, and then the task execution terminal 140 executes the task based on the first data.

[0056] In order to transform the encrypted first data into decipherable data or data that can be directly used by the task execution terminal 140, the key management service 120 can send the first key to the task execution terminal 140 so that the task execution terminal 140 can decrypt the encrypted first data based on the first key.

[0057] To ensure the security of the first key during data transmission, the key management service 120, upon receiving a key acquisition request from the corresponding user of the task execution terminal 140, can encrypt the first key using a second encryption method and send it to the task execution terminal 140. The second encryption method can be an encryption method agreed upon by the key management service 120 and the task execution terminal 140; it can be symmetric or asymmetric encryption, which will not be elaborated here. Furthermore, the task execution terminal 140 can decrypt the first key using the decryption method corresponding to the second encryption method, and then use the first key to decrypt the encrypted first data. The decryption method corresponding to the second encryption method can be a decryption method agreed upon by the key management service 120 and the task execution terminal 140. As an example, if the second encryption method is symmetric encryption of the first key using a certain key, then the decryption method can be decrypting the encrypted first key using that key. As another example, if the second encryption method is asymmetric encryption of the first key using a certain public key, then the decryption method can be decrypting the encrypted first key using the private key corresponding to that public key.

[0058] To further ensure decryption security, in some embodiments, a third trusted execution environment may be deployed in the task execution terminal 140, and the decryption process of the encrypted first key and the encrypted first data is performed in the third trusted execution environment. Specifically, the task execution terminal 140 decrypts the encrypted first key in the third trusted execution environment. Further, the task execution terminal 140 uses the first key to decrypt the encrypted first data in the third trusted execution environment.

[0059] In some embodiments, the third trusted execution environment (TEX) can be a secure area within the computing system of the task execution terminal 140, providing an isolated, protected space for processing sensitive data and performing critical security operations. The TEX can run as a separate environment within the task execution terminal 140 and can run in parallel with the operating system of the task execution terminal 140. This environment is designed to withstand external attacks and internal threats, ensuring the security and integrity of the data processed and the operations performed within it, making it more secure than the operating system. Furthermore, trusted applications running in the TEX can access the full functionality of the device's main processor and memory, while hardware isolation protects these components from applications running on the main operating system.

[0060] In order to transform the encrypted first data into decipherable data or data that can be directly used by the task execution terminal 140, the task execution terminal 140 can send the encrypted first data to the key management service 120, so that the key management service 120 can decrypt the encrypted first data based on the first key, and thus obtain the decrypted first data sent by the key management service 120.

[0061] In some embodiments, in response to receiving a decryption request for the corresponding encrypted first data from the task execution terminal 140, the key management service 120 decrypts the encrypted first data based on the first key. Further, the key management service 120 encrypts the first data using a second encryption method and sends it to the task execution terminal 140. The second encryption method can be an encryption method agreed upon by the key management service 120 and the task execution terminal 140; it can be symmetric encryption or asymmetric encryption, which will not be elaborated here. Further, the task execution terminal 140 can decrypt the encrypted first data based on the decryption method corresponding to the second encryption method. As an example, if the second encryption method is symmetric encryption of the first data using a certain key, then the decryption method can be decrypting the encrypted first data using that key. As another example, if the second encryption method is asymmetric encryption of the first data using a certain public key, then the decryption method can be decrypting the encrypted first data using the private key corresponding to that public key.

[0062] Furthermore, the task execution terminal 140 can execute tasks based on the first data. The task can be any suitable task, such as interacting with a target application based on the first data to execute a task, or triggering a task on a hardware device on the task execution terminal 140. The target application can be any suitable application. For example, if the request to obtain the user's first data is "Please help me buy a train ticket from application A," then the target application can be application A on the cloud phone. The task executed by interacting with the target application can be any suitable task, such as logging into the target application or performing functional operations based on the application (such as buying tickets, watching videos, etc.). The hardware device can be any suitable device, such as a camera, sensor, etc. For example, if the first request is "Please help me log into application A," then this task can be a task to log into application A based on the account and password (first data).

[0063] Figure 3 Example flowcharts of data encryption and data decryption processes according to some embodiments of this disclosure are shown, now for... Figure 3 Please provide an explanation.

[0064] like Figure 3 As shown, the user can input a user request on the user-side 301 (the client of the large model application 130), so that the user-side 301 can receive this user request (a request to obtain the user's first data). This user request can be any appropriate request, such as a text request or an image request. As an example, this user request could be "Help me buy a plane ticket from application A". Furthermore, the user-side 301 can determine whether the database 305 stores the first encrypted data associated with this user request (such as an encrypted user identifier, which is the user data needed to buy the plane ticket).

[0065] As an example, the user-side 301, upon determining that encrypted first data is stored in database 305, can send this user request to the agent service 302. Further, the agent service 302 can send this user request to the data management service 110 in a first trusted execution environment. This first trusted execution environment can be a secure area within the central processing unit (CPU) of the server side of the large model application 130. Further, the data management service can retrieve the encrypted first data from database 305. Further, the data management service can send the encrypted first data to the task execution end 140, specifically via the agent service 302. Further, the key management service 120 can encrypt the first key using an encryption method agreed upon by the key management service 120 and the task execution end 140. Further, the task execution end 140 can also retrieve the encrypted first key from the key management service 120, which can be a second trusted execution environment running in the CPU of the server side of the large model application 130. Furthermore, the task execution terminal 140 can decrypt the encrypted first key using the decryption method agreed upon by the key management service 120 and the task execution terminal 140 to obtain the decrypted first key. Furthermore, the task execution terminal 140 can decrypt the encrypted first data based on the first key to obtain the first data (e.g., obtaining a decipherable user identifier needed for purchasing a plane ticket based on the encrypted user identifier). Furthermore, the task execution terminal 140 can interact with the target application based on the first data to execute the task. For example, the task execution terminal 140 can interact with application A based on this user identifier to purchase a plane ticket for the user.

[0066] As another example, the user-side 301 can respond to determining that the database 305 does not contain the encrypted first data by outputting a prompt, which can be used to instruct the user to enter the user identifier required for ticket purchase. Further, the user-side 301 can receive user input data. Further, the user-side 301 can encrypt this user input data to obtain ciphertext user data. Further, the user-side 301 can send the ciphertext user data to the agent service 302. Further, the agent service 302 can send this ciphertext user data to the data management service 110. Further, the data management service 110 can decrypt the ciphertext user data to obtain the decrypted first data. Further, the data management service 110 or the key management service 120 can encrypt the decrypted first data based on the first key maintained by the key management service 120 corresponding to the user, and store it in the database, so that when a subsequent request to obtain the first data is received, the task can be executed based on this encrypted first data; the specific process is not described in detail here. Figure 4 The diagram illustrates an architecture for request processing of large models according to some embodiments of this disclosure, and is now intended for... Figure 4 Please provide an explanation.

[0067] like Figure 4 As shown, the edge application 401 may include a communication encryption / decryption module. The task execution terminal 140 may include a Rich Execution Environment (REE) 401 and a Third Trusted Execution Environment (TEE) 402, where the REE is a general execution environment that can be configured to run a predefined operating system 403, and the REE can support any suitable application to run, which can be an application supported by the predefined operating system 403 (such as application A, application B). The edge application 401 may include a large model application 130 and agent services.

[0068] The task execution terminal 140 may also include a mobile operating system 404 and hardware 405. The mobile operating system may include system services, a kernel, and a TEE driver, where system services and the kernel are configured to be responsible for the basic functions of the operating system, and the TEE driver is responsible for communication and data transmission with the TEE. Hardware 405 is configured to provide low-level physical support, such as a processor, storage, etc.

[0069] like Figure 4As shown, the endpoint application 401 can send a security authentication request to the remote authentication module 412 in the first trusted execution environment, so that the remote authentication module 412 can send a security certificate of the data management service to the endpoint application 401. Further, the endpoint application 401 can authenticate whether this security certificate meets predetermined security requirements. Further, in response to determining that the security certificate meets the predetermined security requirements, the endpoint application 401 can establish a transmission channel between the endpoint application 401 and the data management service.

[0070] As an example, the client application 401 can respond to a data encryption request received from a user (such as the user inputting a user identifier associated with application A on task execution terminal 140, the user's registered account on application A, password, etc.), and this data encryption request can carry data to be encrypted. Further, the client application 401 can encrypt this data to be encrypted (first data) using a first encryption method based on its communication encryption / decryption module. Further, the client application 401 can send this encrypted first data to the data management service 110 in the trusted execution environment 442. Further, the data management service 110 can decrypt the encrypted first data using its communication encryption / decryption module. Further, the data management service can encrypt the decrypted first data using a third encryption method. Further, the data management service can send the encrypted first data (obtained by encryption using the third encryption method) to the key management service 120 in the trusted execution environment 442. Furthermore, the key management service 120 can decrypt the encrypted first data based on the decryption method corresponding to the third encryption method to obtain the decrypted first data. Furthermore, the key management service 120 can create an encryption key corresponding to the data to be encrypted, such as a first key corresponding to a user. Furthermore, the key management service 120 can encrypt the decrypted first data based on the first key to obtain the encrypted first data. Furthermore, the key management service 120 can send the encrypted first data to the data management service 110. Furthermore, the data management service 110 can store the encrypted first data in the database 305.

[0071] In some embodiments, the client-side application 401 may, in response to receiving a user input request (e.g., "Please help me log in to application A"), send this user request to the data management service 110, wherein this user request is a request to obtain the user's first data. Further, the data management service 110 may obtain encrypted first data (e.g., encrypted account and encrypted password) from the database 305. Further, the data management service 110 may provide this encrypted first data to the operating system 403 of the task execution terminal 140.

[0072] In some embodiments, the task execution terminal 140 can use the operating system 403 to send the encrypted first data to the key management service 120. Further, the task execution terminal 140 can use the key management service 120 to determine the first key corresponding to the encrypted first data. Further, the key management service 120 can decrypt the encrypted first data based on the first key to obtain the decrypted first data. Further, the key management service 120 can encrypt the decrypted first data based on a second encryption method to obtain the encrypted first data. Further, the task execution terminal 140 can receive the encrypted first data sent by the key management service. Further, the task execution terminal 140 can decrypt the encrypted first data based on the decryption method corresponding to the second encryption method to interact with application A based on the first data and log in to application A.

[0073] In other embodiments, the key management service 120 can encrypt the first key based on the second encryption method to obtain the encrypted first key. Further, the key management service 120 can send this encrypted first key to the communication encryption / decryption module in the TEE 402, so that the encrypted first key can be decrypted in the third trusted execution environment based on the decryption method corresponding to the second encryption method. Further, the task execution terminal 140 can decrypt the encrypted first data based on the decrypted first key to obtain the decrypted first data. Further, the task execution terminal 140 can interact with application A based on the first data to log in to application A.

[0074] It should be noted that the terminal application 401, data management service 110, and key management service 120 are all configured with communication encryption and decryption modules, which can support the functions of encrypting and decrypting data. Specifically, when any two units of the terminal application 401, data management service 110, and key management service 120 transmit any appropriate data, the data can be encrypted based on the encryption and decryption module in the unit sending the data, and the received encrypted data can be decrypted based on the encryption and decryption module in the unit receiving the data. Further details will not be elaborated here.

[0075] Based on this approach, embodiments of this disclosure can effectively avoid the leakage of sensitive data such as keys and data transmitted via the data management service by deploying the data management service in a first trusted execution environment and running the key management unit in a second trusted execution environment, thereby significantly improving security. Furthermore, the large-scale application and the data management server encrypt the user's initial data using a pre-agreed encryption method, effectively ensuring the security of user data during transmission.

[0076] Example devices and equipment Embodiments of this disclosure also provide corresponding apparatus for implementing the above methods or processes. Figure 5 A schematic structural block diagram of an apparatus 500 for enhancing data security in large-scale application according to certain embodiments of the present disclosure is shown. Apparatus 500 may be implemented as or included in the data management service 110 discussed above. The various modules / components in apparatus 500 may be implemented by hardware, software, firmware, or any combination thereof.

[0077] like Figure 5 As shown, the device 500 includes a receiving module 510, configured for a data management service to receive encrypted user data encrypted using a first encryption method from a large model application, the encrypted user data including the user's first data, wherein the data management service is deployed in a first trusted execution environment; a first processing module 520, configured for the data management service to decrypt the encrypted user data using a decryption method corresponding to the first encryption method to obtain the first data, and for the data management service to store the encrypted first data in a database, wherein the encrypted first data is obtained by encrypting the decrypted first data using a first key corresponding to the user maintained by a key management service, the key management service being deployed in a second trusted execution environment; a second processing module 530, configured for the data management service to, in response to a request from the large model application to obtain the user's first data, retrieve the encrypted first data from the database and send the encrypted first data to the large model application; wherein the large model application sends the encrypted first data to a task execution end; and a communication module 540, configured for the key management service to communicate with the task execution end, enabling the task execution end to obtain the first data decrypted based on the first key, and then the task execution end to execute a task based on the first data.

[0078] In some embodiments, the communication module 540 is further configured to: in response to receiving a key acquisition request from the corresponding user of the task execution terminal, the key management service encrypts the first key using the second encryption method and sends it to the task execution terminal; the task execution terminal decrypts the first key based on the decryption method corresponding to the second encryption method and then uses the first key to decrypt the encrypted first data.

[0079] In some embodiments, a third trusted execution environment is deployed in the task execution terminal, and the task execution terminal decrypts the encrypted first data based on the following process: the task execution terminal decrypts the encrypted first key in the third trusted execution environment; and the task execution terminal decrypts the encrypted first data using the first key in the third trusted execution environment.

[0080] In some embodiments, the communication module 540 is further configured to: the key management service, in response to receiving a decryption request for the corresponding encrypted first data from the task execution end, decrypt the encrypted first data based on the first key; the key management service encrypts the first data using a second encryption method and sends it to the task execution end; and the task execution end decrypts the encrypted first data based on the decryption method corresponding to the second encryption method.

[0081] In some embodiments, the first processing module 520 is further configured to: encrypt the decrypted first data using a third encryption method to obtain encrypted first data; send the encrypted first data to a key management service; decrypt the encrypted first data using the decryption method corresponding to the third encryption method; encrypt the first data using a first key corresponding to the user and send it to the data management service; and store the first data encrypted with the first key in a database.

[0082] In some embodiments, the first processing module 520 is further configured to: encrypt the first key corresponding to the user based on the fourth encryption method to obtain the encrypted first key; obtain the encrypted first key from the key management service; decrypt the encrypted first key based on the decryption method corresponding to the fourth encryption method; and encrypt the decrypted first data using the first key and store it in the database.

[0083] In some embodiments, the apparatus 500 further includes a third processing module, which is further configured to: send a first security authentication request to a key management service, and the data management service authenticates whether the first security certificate meets the security conditions based on the first security certificate obtained from the key management service; or a fourth processing module, which is configured to: send a second security authentication request to a data management service, and the key management service authenticates whether the second security certificate meets the security conditions based on the second security certificate obtained from the data management service.

[0084] In some embodiments, the task execution terminal performs a task based on the first data, including: the task execution terminal interacts with the target application based on the first data to perform the task.

[0085] In some embodiments, the request is a first request, and the receiving module 510 is further configured to: the data management service receive a second request from the large model application to obtain first data; in response to the database not including the first data, the data management service provides the large model application with prompt content for the second request, the prompt content being used to prompt input of data associated with the second request; and the data management service receives encrypted user data from the large model application, the encrypted user data including the first data determined based on user input data.

[0086] The units included in device 500 can be implemented in various ways, including software, hardware, firmware, or any combination thereof. In some embodiments, one or more units may be implemented using software and / or firmware, such as machine-executable instructions stored on a storage medium. In addition to or as an alternative to machine-executable instructions, some or all of the units in device 500 may be implemented at least partially by one or more hardware logic components. By way of example and not limitation, exemplary types of hardware logic components that may be used include field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-chips (SoCs), complex programmable logic devices (CPLDs), and so on.

[0087] Figure 6 A block diagram of an electronic device 600 in which one or more embodiments of the present disclosure may be implemented is shown. It should be understood that... Figure 6 The electronic device 600 shown is merely exemplary and should not be construed as limiting the functionality and scope of the embodiments described herein. Figure 6 The electronic device 600 shown can be used to achieve Figure 1 The data management service 110 is shown.

[0088] like Figure 6 As shown, electronic device 600 is in the form of a general-purpose electronic device. Components of electronic device 600 may include, but are not limited to, one or more processors or processing units 610, memory 620, storage device 630, one or more communication units 640, one or more input devices 650, and one or more output devices 660. Processing unit 610 may be a physical or virtual processor and is capable of performing various processes according to programs stored in memory 620. In a multiprocessor system, multiple processing units execute computer-executable instructions in parallel to improve the parallel processing capability of electronic device 600.

[0089] Electronic device 600 typically includes multiple computer storage media. Such media can be any accessible media that is accessible to electronic device 600, including but not limited to volatile and non-volatile media, removable and non-removable media. Memory 620 can be volatile memory (e.g., registers, cache, random access memory (RAM)), non-volatile memory (e.g., read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory), or some combination thereof. Storage device 630 can be a removable or non-removable medium and can include machine-readable media, such as flash drives, disks, or any other media that can be used to store information and / or data (e.g., training data for training) and can be accessed within electronic device 600.

[0090] Electronic device 600 may further include additional removable / non-removable, volatile / non-volatile storage media. Although not explicitly stated... Figure 6 As shown, disk drives for reading from or writing to removable, non-volatile disks (e.g., "floppy disks") and optical disk drives for reading from or writing to removable, non-volatile optical disks can be provided. In these cases, each drive can be connected to a bus (not shown) via one or more data media interfaces. Memory 620 may include computer program product 625 having one or more program modules configured to perform various methods or actions of various embodiments of this disclosure.

[0091] The communication unit 640 enables communication with other electronic devices via a communication medium. Additionally, the functionality of the components of the electronic device 600 can be implemented using a single computing cluster or multiple computing machines capable of communicating via communication connections. Therefore, the electronic device 600 can operate in a networked environment using logical connections to one or more other servers, networked personal computers (PCs), or another network node.

[0092] Input device 650 can be one or more input devices, such as a mouse, keyboard, trackball, etc. Output device 660 can be one or more output devices, such as a monitor, speaker, printer, etc. Electronic device 600 can also communicate with one or more external devices (not shown) via communication unit 640 as needed. These external devices include storage devices, display devices, etc., and can communicate with one or more devices that enable user interaction with electronic device 600, or with any device that enables electronic device 600 to communicate with one or more other electronic devices (e.g., network card, modem, etc.). Such communication can be performed via input / output (I / O) interfaces (not shown).

[0093] According to an exemplary implementation of this disclosure, a computer-readable storage medium is provided that stores computer-executable instructions thereon, wherein the computer-executable instructions are executed by a processor to implement the methods described above. According to an exemplary implementation of this disclosure, a computer program product is also provided, which is tangibly stored on a non-transitory computer-readable medium and includes computer-executable instructions, which are executed by a processor to implement the methods described above.

[0094] Various aspects of this disclosure are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatuses, devices, and computer program products implemented according to this disclosure. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0095] These computer-readable program instructions can be provided to a processing unit of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that, when executed by the processing unit of the computer or other programmable data processing apparatus, they create means for implementing the functions / actions specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium that causes a computer, programmable data processing apparatus, and / or other device to operate in a particular manner. Thus, the computer-readable medium storing the instructions comprises an article of manufacture that includes instructions for implementing aspects of the functions / actions specified in one or more blocks of the flowchart and / or block diagram.

[0096] Computer-readable program instructions can be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions that execute on the computer, other programmable data processing apparatus, or other device to perform the functions / actions specified in one or more boxes of a flowchart and / or block diagram.

[0097] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of an instruction, which contains one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0098] Various implementations of this disclosure have been described above. These descriptions are exemplary and not exhaustive, nor are they limited to the disclosed implementations. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described implementations. The terminology used herein is chosen to best explain the principles, practical applications, or improvements to technology in the market, or to enable others skilled in the art to understand the various implementations disclosed herein.

Claims

1. A method for enhancing data security in large-scale model applications, comprising the following steps performed by a data management service deployed in a first trusted execution environment and a key management service deployed in a second trusted execution environment: The data management service receives encrypted user data from a large model application, which is encrypted using a first encryption method. The encrypted user data includes the user's first data. The data management service decrypts the encrypted user data based on the decryption method corresponding to the first encryption method to obtain the first data, and the data management service stores the encrypted first data in the database. The encrypted first data is obtained by encrypting the decrypted first data based on the first key corresponding to the user maintained by the key management service. The decrypted first data or the first key is transmitted between the data management service and the key management service in an encrypted form. In response to receiving a request from the large model application to obtain the user's first data, the data management service retrieves the encrypted first data from the database and sends the encrypted first data to the large model application; wherein, the large model application sends the encrypted first data to the task execution terminal; Furthermore, the key management service communicates with the task execution terminal, enabling the task execution terminal to obtain the first data decrypted based on the first key, and then the task execution terminal executes the task based on the first data.

2. The method according to claim 1, wherein, The key management service communicates with the task execution terminal, enabling the task execution terminal to obtain the first data decrypted based on the first key, including: In response to receiving a key acquisition request from the task execution terminal corresponding to the user, the key management service encrypts the first key using a second encryption method and sends it to the task execution terminal; the task execution terminal decrypts the first key based on the decryption method corresponding to the second encryption method, and then uses the first key to decrypt the encrypted first data.

3. The method according to claim 2, wherein, The task execution terminal is equipped with a third trusted execution environment, and the task execution terminal decrypts the encrypted first data based on the following process: The task execution terminal decrypts the encrypted first key in the third trusted execution environment; and The task execution terminal decrypts the encrypted first data using the first key in the third trusted execution environment.

4. The method according to claim 1, wherein, The key management service communicates with the task execution terminal, enabling the task execution terminal to obtain the first data decrypted based on the first key, including: In response to receiving a decryption request for the encrypted first data from the task execution end, the key management service decrypts the encrypted first data based on the first key; the key management service encrypts the first data using a second encryption method and sends it to the task execution end; and the task execution end decrypts the encrypted first data based on the decryption method corresponding to the second encryption method.

5. The method of claim 1, wherein the data management service stores the encrypted first data in the database, comprising: The data management service encrypts the decrypted first data using a third encryption method to obtain the encrypted first data. The data management service sends the encrypted first data to the key management service; The key management service decrypts the encrypted first data based on the decryption method corresponding to the third encryption method; as well as The key management service encrypts the first data based on the first key corresponding to the user and then sends it to the data management service; The data management service stores the first data, encrypted with the first key, into the database.

6. The method of claim 1, wherein the data management service stores the encrypted first data in the database comprising: The key management service encrypts the first key corresponding to the user based on the fourth encryption method to obtain the encrypted first key; The data management service obtains the encrypted first key from the key management service; The data management service decrypts the encrypted first key based on the decryption method corresponding to the fourth encryption method; as well as The data management service uses the first key to encrypt the decrypted first data and then stores it in the database.

7. The method of claim 1, wherein before the data management service stores the encrypted first data in the database, the method further comprises: The data management service sends a first security authentication request to the key management service, and the data management service authenticates whether the first security certificate meets the security conditions based on the first security certificate obtained from the key management service. or The key management service sends a second security authentication request to the data management service, and the key management service authenticates whether the second security certificate meets the security conditions based on the second security certificate obtained from the data management service.

8. The method according to claim 1, wherein the task execution terminal executes the task based on the first data, comprising: The task execution terminal interacts with the target application based on the first data to execute the task.

9. The method of claim 1, wherein the request is a first request, and the data management service receiving encrypted user data encrypted in a first encryption method from a large model application comprises: The data management service receives a second request from the large model application to obtain the first data; In response to the fact that the database does not contain the first data, the data management service provides the large model application with prompts for the second request, the prompts being used to suggest inputting data associated with the second request; as well as The data management service receives the encrypted user data from the large model application, the encrypted user data including the first data determined based on user input data.

10. An apparatus for enhancing data security in large model applications, comprising: The receiving module is configured to receive encrypted user data encrypted in a first encryption method from a large model application, wherein the encrypted user data includes the user's first data, and wherein the data management service is deployed in a first trusted execution environment; The first processing module is configured to have the data management service decrypt the ciphertext user data based on the decryption method corresponding to the first encryption method to obtain first data, and the data management service store the encrypted first data in a database. The encrypted first data is obtained by encrypting the decrypted first data based on the first key corresponding to the user maintained by the key management service. The key management service is deployed in a second trusted execution environment, and the decrypted first data or the first key is transmitted between the data management service and the key management service in an encrypted form. The second processing module is configured such that, in response to a request from the large model application to obtain the user's first data, the data management service retrieves the encrypted first data from the database and sends the encrypted first data to the large model application; wherein the large model application sends the encrypted first data to the task execution terminal. The communication module is configured to communicate between the key management service and the task execution end, so that the task execution end obtains the first data decrypted based on the first key, and then the task execution end executes the task based on the first data.

11. An electronic device, comprising: At least one processing unit; as well as At least one memory, coupled to the at least one processing unit and storing instructions for execution by the at least one processing unit, which, when executed by the at least one processing unit, cause the electronic device to perform the method according to any one of claims 1 to 9.

12. A computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method according to any one of claims 1 to 9.

13. A computer program product comprising computer-executable instructions, wherein the computer-executable instructions, when executed by a processor, implement the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Encrypted database system and method and device for realizing encrypted database system

    CN112699399A

  • Secret-related information maintenance method and device, equipment and storage medium

    CN116244750A