Data transmission methods in intelligent agent systems, as well as intelligent agent systems, devices, and media.

By deploying the client, server, and large model in a trusted execution environment within the intelligent agent system and employing a full-link encryption algorithm, the problem of data transmission security in the intelligent agent system is solved, and secure and reliable data transmission is achieved.

CN121334271BActive Publication Date: 2026-07-17BEIJING ZITIAO NETWORK TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING ZITIAO NETWORK TECH CO LTD
Filing Date
2025-09-30
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

In intelligent agent systems, how to ensure data security during data transmission, especially how to implement end-to-end encryption in transmission links involving sensitive information to protect data security.

Method used

The first client, first server, and large model of the intelligent agent application are all deployed in a trusted execution environment. Encryption algorithms are used to encrypt user requests, inference results, and task execution results throughout the entire transmission process to ensure data security.

Benefits of technology

It achieves the security and reliability of data transmission in the intelligent agent system, ensuring the confidentiality and integrity of user data during transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121334271B_ABST
    Figure CN121334271B_ABST
Patent Text Reader

Abstract

One or more embodiments of this disclosure provide a data transmission method, intelligent agent system, device, and medium in an intelligent agent system. The intelligent agent system includes an intelligent agent application, a first client, a first server, and a large model. The first client, first server, and large model are deployed in a trusted execution environment. The method includes: in response to the intelligent agent application receiving a first user request, the first client encrypts the first user request and transmits first encrypted data to the large model; the first client receives second encrypted data transmitted by the large model; the first client obtains an inference result, encrypts at least one subtask, and transmits third encrypted data to the first server; the first client receives fourth encrypted data transmitted by the first server; the first client obtains a task execution result, and the intelligent agent application outputs the task execution result. Deploying the first client, first server, and large model in a trusted execution environment ensures secure and reliable data transmission within the intelligent agent system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One or more embodiments of this disclosure relate to a data transmission method in an intelligent agent system, an intelligent agent system, an electronic device, and a computer-readable storage medium. Background Technology

[0002] With the continuous development of artificial intelligence technology, agent systems have emerged. Developers of agent applications can deploy their applications within these systems, allowing them to run and provide services to users.

[0003] Ensuring data security during data transmission is of paramount importance in the operation of intelligent agent applications. Summary of the Invention

[0004] This summary section is provided to briefly introduce the concepts, which will be described in detail in the detailed description section below. This summary section is not intended to identify key or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.

[0005] At least one embodiment of this disclosure provides a data transmission method in an intelligent agent system. The intelligent agent system includes an intelligent agent application, a first client, a first server, and a large model. The first client is integrated into the intelligent agent application. The first client, the first server, and the large model are all deployed in a trusted execution environment. The method includes the following steps performed by the first client: in response to the intelligent agent application receiving a first user request, the first client encrypts the first user request to obtain first encrypted data and transmits the first encrypted data to the large model; the first client receives second encrypted data transmitted by the large model; the first client decrypts the second encrypted data to obtain a reasoning result of the large model based on the first user request, and determines at least one subtask based on the reasoning result, encrypts the at least one subtask to obtain third encrypted data, and transmits the third encrypted data to the first server; the first client receives fourth encrypted data transmitted by the first server; the first client decrypts the fourth encrypted data to obtain a task execution result obtained by the first server executing the at least one subtask, so that the intelligent agent application outputs the task execution result.

[0006] At least one embodiment of this disclosure provides an intelligent agent system, comprising an intelligent agent application, a first client, a first server, and a large model. The first client is integrated into the intelligent agent application. The first client, the first server, and the large model are all deployed in a trusted execution environment. The intelligent agent application is configured to: receive a first user request; the first client is configured to: encrypt the first user request and transmit first encrypted data to the large model; the large model is configured to: decrypt the first encrypted data, perform inference on the first user request to obtain an inference result, encrypt the inference result, and transmit second encrypted data to the first client. In this context, the inference result includes execution steps for processing the first user request; the first client is further configured to: decrypt the second encrypted data, determine at least one subtask based on the inference result, encrypt the at least one subtask, and transmit third encrypted data to the first server; the first server is configured to: decrypt the third encrypted data, execute the at least one subtask to obtain a task execution result, encrypt the task execution result, and transmit fourth encrypted data to the first client; the first client is further configured to: decrypt the fourth encrypted data to obtain the task execution result; and the intelligent agent application is further configured to: output the task execution result.

[0007] At least one embodiment of this disclosure provides an electronic device, including: a processing device; and a storage device including one or more computer program instructions; wherein the one or more computer program instructions are executed by the processing device to perform a data transmission method in an intelligent agent system provided in at least one embodiment of this disclosure.

[0008] At least one embodiment of this disclosure provides a computer-readable storage medium for non-transitory storage of computer-readable instructions, wherein the computer-readable instructions, when executed by a processor, implement the data transmission method in the intelligent agent system provided in at least one embodiment of this disclosure.

[0009] At least one embodiment of this disclosure provides a computer program product, including a computer program that, when executed by a processor, implements a data transmission method in an intelligent agent system provided in at least one embodiment of this disclosure. Attached Figure Description

[0010] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the originals and elements are not necessarily drawn to scale.

[0011] Figure 1This illustration schematically shows an architecture diagram of an intelligent agent system provided in at least one embodiment of the present disclosure;

[0012] Figure 2 This illustration schematically depicts an application scenario of an intelligent agent system provided by at least one embodiment of the present disclosure;

[0013] Figure 3 The illustration shows a flowchart of a data transmission method in an intelligent agent system according to at least one embodiment of the present disclosure;

[0014] Figure 4 The schematic diagram illustrates the structure of an intelligent agent system provided in at least one embodiment of this disclosure; and

[0015] Figure 5 A schematic diagram of the structure of an electronic device suitable for implementing embodiments of the present disclosure is shown. Detailed Implementation

[0016] One or more embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0017] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.

[0018] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below.

[0019] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.

[0020] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0021] The names of the messages or information exchanged between the various devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of these messages or information.

[0022] It is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition, use, storage or deletion of the data) shall comply with the requirements of relevant laws, regulations and related provisions.

[0023] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, relevant users should be informed of the type, scope of use, and usage scenarios of the information involved in this disclosure through appropriate means in accordance with relevant laws and regulations, and authorization should be obtained from the relevant users. Among them, relevant users may include any type of rights holder, such as individuals, enterprises, and groups.

[0024] For example, in response to receiving an active request from a user, a prompt message is sent to the relevant user to clearly indicate that the operation requested by the user will require obtaining and using the user's information. This allows the relevant user to choose whether to provide information to the software or hardware such as the electronic device, application, server, or storage medium that performs the operation of any embodiment of the present disclosure based on the prompt message.

[0025] As an optional but non-restrictive implementation, in response to a user's active request, a prompt message can be sent to the user, such as a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide information to the electronic device.

[0026] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.

[0027] First, the technical terms and application scenarios involved in one or more embodiments of this disclosure will be introduced.

[0028] A Trusted Execution Environment (TEE) is a hardware-based security technology that can be implemented on devices such as central processing units (CPUs) and graphics processing units (GPUs). TEE technology creates a secure environment isolated from the outside world by dividing it into secure and insecure parts, ensuring the confidentiality and integrity of data and code loaded within the secure environment. Because TEEs are isolated from ordinary environments, they offer a higher level of security.

[0029] Artificial intelligence confidential computing (AICC) can be understood as a privacy protection technology based on trusted execution environments, cryptographic applications, and information flow security. AICC services can be provided in the form of AICC platforms to achieve data flow security and application security in public cloud environments.

[0030] The Model Context Protocol (MCP) defines a way for applications and AI models to exchange contextual information. The MCP protocol allows AI models to access custom tools and services, enabling application developers to connect data sources, tools, and other components to AI models in a consistent manner.

[0031] An intelligent agent system can be understood as a platform that supports the development, deployment, and operation of intelligent agent applications. In other words, developers of intelligent agent applications can develop, deploy, and run their applications within the intelligent agent system. When running intelligent agent applications within the intelligent agent system, data transmission can be based on the MCP protocol.

[0032] Intelligent agent applications can be understood as applications centered around autonomous intelligent agents. The operation of intelligent agent applications follows the logic of "perception-reasoning-action-learning" to achieve complex AI tasks involving multiple steps and across systems.

[0033] Large models, also known as large AI models, can be understood as AI models with a large number of parameters built by artificial neural networks. Large models are pre-trained through supervised learning and further optimized through methods such as instruction fine-tuning and human alignment, enabling them to solve general tasks, follow instructions, and perform complex reasoning.

[0034] Figure 1 The illustration shows a schematic diagram of the architecture of an intelligent agent system provided in at least one embodiment of the present disclosure.

[0035] See Figure 1 As shown, the intelligent agent system 10 includes a host 101. Intelligent agent applications can run on the host 101. For example, intelligent agent applications 111, 121, ..., 1N1 can run on the host 101, where N is an integer greater than 0. The host 101 can be understood as the control center of the intelligent agent system 10, providing the user interface for the intelligent agent applications, receiving user requests from the intelligent agent applications, and providing the capabilities required for the intelligent agent applications to run, such as the language understanding capability of integrating artificial intelligence models and the ability to maintain the context of multi-turn dialogues. The host 101 can also provide an execution environment for AI tasks, enabling intelligent agent applications to run on the intelligent agent system 10 to provide corresponding services to users.

[0036] Intelligent agent applications can integrate clients. For example, intelligent agent application 111 can integrate client 112, intelligent agent application 121 can integrate client 122, and so on, and intelligent agent application 1N1 can integrate client 1N2. A client can be understood as a module within the intelligent agent application, used to communicate with the server. For example, client 112 can communicate with server 113, client 122 can communicate with server 123, and so on, and client 1N2 can communicate with server 1N3. The client can also manage requests, responses, and notifications related to the intelligent agent application.

[0037] The server can provide service 103. For example, service 103 may include tools for implementing different functions, resources for providing various types of information, etc.

[0038] The communication process between the client and the server can be implemented based on the MCP protocol, that is, the client and the server can use the MCP protocol to transmit data.

[0039] The intelligent agent system 10 may also include a large model 102, which may include at least one artificial intelligence model, such as a large language model, a large visual model, a multimodal large model, etc. The large model 102 can utilize the artificial intelligence capabilities of the artificial intelligence model to perform semantic understanding of user requests.

[0040] The following section uses specific examples to illustrate the operation process of intelligent agent applications.

[0041] In some examples, agent application 111 can provide weather query functionality. A user uses agent application 111 to send a user request, such as "Please check the weather at location A on September 1st". Then, the client 112 integrated into agent application 111 sends the user request to the big model 102. The big model 102 performs semantic understanding on the user request, understands that the user request indicates that they want to query the weather at location A on September 1st, and returns the inference result to the client 112, such as "location A and September 1st".

[0042] Based on the reasoning result, client 112 determines the sub-task to be executed, such as "checking the weather". Client 112 sends the sub-task to server 113. Server 113 calls service 103 based on the sub-task, such as "weather query service". Server 113 sends the task execution result returned by the weather query service (such as the weather being sunny at location A on September 1) to client 112, so that intelligent agent application 111 can return the task execution result to the user.

[0043] Based on the above analysis of the operation process of intelligent agent applications, it can be observed that the operation involves the transmission of data related to user requests across different roles within the intelligent agent system (including client, server, and large model). Since user requests may involve sensitive information, data security must be ensured throughout the entire transmission chain of the intelligent agent application.

[0044] To at least partially solve the aforementioned technical problems, at least one embodiment of this disclosure provides a data transmission method in an intelligent agent system. The intelligent agent system includes an intelligent agent application, a first client, a first server, and a large model. The first client is integrated into the intelligent agent application, and the first client, the first server, and the large model are all deployed in a trusted execution environment. The method includes the following steps performed by the first client: in response to the intelligent agent application receiving a first user request, the first client encrypts the first user request to obtain first encrypted data and transmits the first encrypted data to the large model; the first client receives second encrypted data transmitted by the large model; the first client decrypts the second encrypted data to obtain a reasoning result of the large model based on the first user request, and determines at least one subtask based on the reasoning result, encrypts at least one subtask to obtain third encrypted data, and transmits the third encrypted data to the first server; the first client receives fourth encrypted data transmitted by the first server; the first client decrypts the fourth encrypted data to obtain a task execution result obtained by the first server executing at least one subtask, so that the intelligent agent application outputs the task execution result.

[0045] In the data transmission method of the intelligent agent system provided in at least one embodiment of this disclosure, for the intelligent agent application deployed in the intelligent agent system, the first client, the first server and the large model of the intelligent agent application are all deployed in a trusted execution environment. During the operation of the intelligent agent application, the entire data transmission link is encrypted by an encryption algorithm to ensure the data security of the user during the use of the intelligent agent application, and to realize the security and trustworthiness of data transmission in the intelligent agent system.

[0046] Based on the data transmission method in the intelligent agent system provided in at least one embodiment of the present disclosure, at least one embodiment of the present disclosure also provides an intelligent agent system, an electronic device, a computer-readable storage medium, and a computer program product.

[0047] The present disclosure and some examples thereof will now be described in detail with reference to the accompanying drawings.

[0048] Figure 2 The illustration shows an application scenario diagram of an intelligent agent system provided by at least one embodiment of the present disclosure.

[0049] like Figure 2 As shown, the application scenario of this embodiment includes an intelligent agent system 21. The intelligent agent system 21 includes an intelligent agent application 211, a first client 212, a first server 213, and a large model 214 integrated in the intelligent agent application 211. The first client 212, the first server 213, and the large model 214 are deployed in a trusted execution environment. For example, the first client 212, the first server 213, and the large model 214 can be deployed in the AICC platform.

[0050] The application scenario of this embodiment also includes user 20. For example, user 20 can be a person using the intelligent agent application 211, and user 20 can send user requests to the intelligent agent application 211. User 20 can use a terminal device, which can be a mobile phone, tablet computer, portable computer, desktop computer, smart wearable device, smart home appliance, or smart vehicle terminal, etc. The terminal device can display the interactive interface of the intelligent agent application 211, and user 200 can send user requests to the intelligent agent application 211 in the interactive page.

[0051] During the operation of the intelligent agent application 211, data transmission is involved between the first client 212, the first server 213, and the large model 214. For example, after the intelligent agent application 211 receives a first user request, the first client 212 can obtain the first user request. Since the first client 212 is deployed in a trusted execution environment, the first client 212 can encrypt the first user request to obtain the first encrypted data.

[0052] The large model 214 can receive the first encrypted data, decrypt the first encrypted data to obtain the first user request, and perform inference on the first user request to obtain the inference result. Since the large model 214 is deployed in a trusted execution environment, the large model 214 can encrypt the inference result to obtain the second encrypted data.

[0053] The first client 212 can receive the second encrypted data, decrypt the second encrypted data to obtain the reasoning result, and determine at least one subtask based on the reasoning result, encrypt the at least one subtask, and obtain the third encrypted data.

[0054] The first server 213 can receive the third encrypted data, decrypt the third encrypted data, execute at least one subtask, and obtain the task execution result. Since the first server 213 is deployed in a trusted execution environment, the first server 213 can encrypt the task execution result and obtain the fourth encrypted data.

[0055] The first client 212 can receive the fourth encrypted data, decrypt the fourth encrypted data to obtain the task execution result, and send the task execution result to the intelligent agent application 211, so that the intelligent agent application 211 outputs the task execution result to the user 20.

[0056] Thus, by deploying the first client 212, the first server 213, and the large model 214 in a trusted execution environment, data transmission between the first client 212 and the first server 213, and between the first client 212 and the large model 214, are all conducted under the secure protection of the trusted execution environment. Encrypted links are formed between the first client 212 and the first server 213, and between the first client 212 and the large model 214, ensuring data security for users during the use of the intelligent agent application 211.

[0057] In some embodiments, the first client 212, the first server 213, and the large model 214 can also provide remote proof reports to the agent application 211, and the agent application 211 can display the remote proof reports to the user 20 to verify that the first client 212, the first server 213, and the large model 214 are all deployed in a trusted execution environment.

[0058] The following will combine Figure 3 A data transmission method in an intelligent agent system provided by at least one embodiment of the present disclosure will be described in detail.

[0059] Figure 3 The illustration shows a flowchart of a data transmission method in an intelligent agent system provided by at least one embodiment of the present disclosure.

[0060] like Figure 3As shown, the data transmission method in the intelligent agent system of this embodiment includes steps S301 to S305. In some embodiments, the data transmission method in the intelligent agent system is applied to an intelligent agent system, which includes an intelligent agent application, a first client, a first server, and a large model. The first client is integrated into the intelligent agent application, and the first client, the first server, and the large model are all deployed in a trusted execution environment.

[0061] In some embodiments, the method of deploying the first client, the first server, and the large model in a trusted execution environment described above can be provided as an option in the agent system. For example, in response to the developer of the agent application selecting a confidential computing deployment mode, the first client, the first server, and the large model are deployed in a trusted execution environment.

[0062] In other words, developers of intelligent agent applications can choose whether to deploy their applications in the intelligent agent system using confidential computing deployment mode. If the developers of intelligent agent applications actively enable confidential computing deployment mode, the entire process of the intelligent agent application will be encrypted to ensure the security of data transmission during the operation of the intelligent agent application.

[0063] The data transmission method in this intelligent agent system includes the following steps performed by the first client:

[0064] Step S301: In response to the intelligent agent application receiving the first user request, the first client encrypts the first user request, obtains the first encrypted data, and transmits the first encrypted data to the large model.

[0065] The first user request can be understood as information sent to the intelligent agent application by the user during the application's use. The first user request can represent the user's intention to use the intelligent agent application. The first user request can be text information in natural language, or it can carry other modalities of information, such as video, audio, image, or file information.

[0066] Since the first client is integrated into the agent application, it can obtain the first user request from the agent application in response to the first user request sent by the user to the agent application.

[0067] Unlike clients deployed in traditional cloud environments, in one or more embodiments of this disclosure, the first client is deployed in a trusted execution environment. Therefore, the first client's operating environment is secure, and the first client can encrypt the first user request to obtain first encrypted data, which is then transmitted when transmitting data to the large model.

[0068] For example, the first client can encrypt the first user request based on the first encryption algorithm to obtain the first encrypted data.

[0069] In one or more embodiments of this disclosure, the first encryption algorithm can be understood as the encryption algorithm used in the communication link between the first client and the large model. For example, the first encryption algorithm may be the encryption algorithm indicated in the communication protocol used during the communication process between the first client and the large model. One or more embodiments of this disclosure do not limit the first encryption algorithm; for example, the first encryption algorithm may include any symmetric encryption algorithm and asymmetric encryption algorithm.

[0070] By encrypting the first user request, the first client transmits encrypted first data to the large model, ensuring the security of the data transmission process.

[0071] Step S302: The first client receives the second encrypted data transmitted by the large model.

[0072] For example, the second encrypted data can be obtained through the following steps: the large model decrypts the first encrypted data, performs inference on the first user request to obtain the inference result, encrypts the inference result, and transmits the second encrypted data to the first client.

[0073] For example, when the first client encrypts the first user request using the first encryption algorithm, the large model can decrypt the first encrypted data based on the first decryption algorithm corresponding to the first encryption algorithm.

[0074] The first decryption algorithm can be understood as a decryption algorithm corresponding to the first encryption algorithm, capable of decrypting data encrypted by the first encryption algorithm. The large model decrypts the first encrypted data to obtain the first user request. Then, the large model infers from the first user request, identifies the user's intent, and obtains an inference result including the execution steps for processing the first user request.

[0075] For example, a large model can perform semantic understanding on the first user request, in which case the inference results can include the semantic understanding results.

[0076] In other words, the large model combines artificial intelligence capabilities to analyze the first user request, identify the usage requirements indicated by the first user request, and provide the various execution steps for processing the first user request, so that the intelligent agent application can process the first user request according to the execution steps indicated by the reasoning results.

[0077] Unlike large models deployed in traditional cloud environments, in one or more embodiments of this disclosure, large models are deployed in trusted execution environments. Therefore, the runtime environment of large models is secure, and large models can encrypt inference results to obtain second encrypted data, which is transmitted when transmitting data to the first client.

[0078] For example, considering that the bidirectional communication between the large model and the first client can be based on the same communication protocol, the large model can encrypt the inference result based on the first encryption algorithm to obtain the second encrypted data.

[0079] Based on the encrypted inference results, the large model transmits encrypted second-encrypted data to the first client, ensuring the security of the data transmission process.

[0080] Step S303: The first client decrypts the second encrypted data to obtain the reasoning result of the large model based on the first user's request, and determines at least one subtask based on the reasoning result, encrypts at least one subtask to obtain the third encrypted data, and transmits the third encrypted data to the first server.

[0081] The first client decrypts the second encrypted data to obtain the inference result. For example, when the large model uses the first encryption algorithm to encrypt the inference result, the first client can decrypt the second encrypted data based on the first decryption algorithm to obtain the inference result. The execution steps indicated by the inference result for processing the first user request are then broken down into multiple subtasks. In one or more embodiments of this disclosure, a subtask may correspond to an execution step, and a subtask may include the process of calling a service to obtain the task execution result.

[0082] When the first client transmits data to the first server, the first client transmits encrypted third encrypted data to the first server. For example, the first client may encrypt at least one subtask based on a second encryption algorithm.

[0083] In one or more embodiments of this disclosure, the second encryption algorithm can be understood as an encryption algorithm used in the communication link between the first client and the first server. For example, the second encryption algorithm may be an encryption algorithm indicated in the communication protocol used during the communication process between the first client and the first server. One or more embodiments of this disclosure do not limit the second encryption algorithm; for example, the second encryption algorithm may include any symmetric encryption algorithm and asymmetric encryption algorithm.

[0084] The first client encrypts at least one subtask to obtain third encrypted data. By encrypting at least one subtask, the first client transmits the encrypted third encrypted data to the first server, ensuring the security of data transmission.

[0085] Step S304: The first client receives the fourth encrypted data transmitted by the first server.

[0086] For example, the fourth encrypted data can be obtained as follows: the first server decrypts the third encrypted data, executes at least one subtask, obtains the task execution result, encrypts the task execution result, and transmits the fourth encrypted data to the first client.

[0087] For example, when the first client encrypts at least one subtask using the second encryption algorithm, the first server can decrypt the third encrypted data based on the second decryption algorithm corresponding to the second encryption algorithm to obtain at least one subtask.

[0088] The second decryption algorithm can be understood as a decryption algorithm that corresponds to the second encryption algorithm and can be used to decrypt data encrypted by the second encryption algorithm.

[0089] The task execution result can be understood as the result obtained after executing the subtask. In some embodiments, the first server can be associated with multiple services that provide different functions. For example, multiple services that provide different functions can be pre-registered on the first server for invocation by the first server. For each subtask in at least one subtask, the service corresponding to the subtask is determined, the service is invoked, and the task execution result of the subtask is obtained.

[0090] In other words, a subtask can indicate the services that the subtask needs to call. The first server executes the subtask by calling the services indicated by the subtask and obtains the task execution result of the subtask.

[0091] Unlike servers deployed in traditional cloud environments, in one or more embodiments of this disclosure, the first server is deployed in a trusted execution environment. Therefore, the first server's operating environment is secure, and the first server can encrypt the task execution results and transmit fourth encrypted data when transmitting data to the first client.

[0092] For example, considering that the bidirectional communication between the first server and the first client can be based on the same communication protocol, the first server can encrypt the task execution result based on the second encryption algorithm to obtain the fourth encrypted data.

[0093] Based on the encrypted task execution result, the first server transmits encrypted fourth-order encrypted data to the first client, ensuring the security of the data transmission process.

[0094] Step S305: The first client decrypts the fourth encrypted data to obtain the task execution result obtained by the first server executing at least one subtask, so that the intelligent agent application outputs the task execution result.

[0095] The first client decrypts the fourth encrypted data to obtain the task execution result. For example, when the first server uses the second encryption algorithm to encrypt the task execution result, the first client can decrypt the fourth encrypted data based on the second decryption algorithm to obtain the task execution result and return the task execution result to the intelligent agent application. The intelligent agent application can output the task execution result to complete the processing of the first user's request.

[0096] In this way, by deploying the first client, the first server, and the large model in a trusted execution environment, encrypted and secure transmission is achieved in each data transmission link during the operation of the intelligent agent application, thus ensuring the data security of user data.

[0097] The data transmission process in the intelligent agent system is illustrated below with a specific example. In some embodiments, the first user request is "Please order food C for me on food delivery platform A or food delivery platform B". The intelligent agent application receives the first user request, the first client obtains the first user request from the intelligent agent application, encrypts the first user request based on the first encryption algorithm to obtain the first encrypted data, and transmits the first encrypted data to the large model.

[0098] The large model receives the first encrypted data, decrypts it based on the first decryption algorithm, obtains the first user request, and performs inference on the first user request to obtain the inference result. For example, the inference result can be "obtain the price of food C on food delivery platform A, obtain the price of food C on food delivery platform B, compare the price of food C on food delivery platform A and the price of food C on food delivery platform B, and order food C on the food delivery platform with the lower price". The large model encrypts the inference result based on the first encryption algorithm to obtain the second encrypted data, and transmits the second encrypted data to the first client.

[0099] The first client receives the second encrypted data, decrypts the second encrypted data based on the first decryption algorithm, obtains the reasoning result, and determines multiple sub-tasks based on the reasoning result. For example, the sub-tasks may include "calling service A to obtain the price of food C on food delivery platform A", "calling service A to obtain the price of food C on food delivery platform B", "calling service B to compare the price of food C on food delivery platform A and the price of food C on food delivery platform B", and "calling service A to order food C on the food delivery platform with the lower price". The first client encrypts the multiple sub-tasks based on the second encryption algorithm to obtain the third encrypted data, and transmits the third encrypted data to the first server.

[0100] The first server receives the third encrypted data, decrypts the third encrypted data based on the second decryption algorithm, obtains multiple subtasks, executes each subtask, obtains the task processing results, encrypts the task execution results based on the second encryption algorithm, obtains the fourth encrypted data, and transmits the fourth encrypted data to the first client.

[0101] The first client receives the fourth encrypted data, decrypts the fourth encrypted data based on the second decryption algorithm, obtains the task execution result, and the intelligent agent application outputs the task execution result, thus completing the processing of the first user's request.

[0102] Furthermore, the first client, the first server, and the large model deployed in the trusted execution environment can also provide remote proof reports. For example, the agent application can receive at least one of the following: a first remote proof report sent by the large model, a second remote proof report sent by the first server, and a third remote proof report sent by the first client. The first remote proof report can be used to prove that the large model is running in the trusted execution environment, the second remote proof report can be used to prove that the first server is running in the trusted execution environment, and the third remote proof report can be used to prove that the first client is running in the trusted execution environment.

[0103] In other words, by providing remote proof reports to the agent application, the agent application can verify that the first client, the first server, and the large model are all deployed in a trusted execution environment, that the operating environment of the first client, the first server, and the large model is secure, and that the data transmission process is secure.

[0104] For example, the first client, the first server, and the large model can send the aforementioned remote proof report to the agent application before the agent application begins processing the first user request (i.e., before the agent application sends the first user request to the first client). In this way, processing of the first user request only begins after the agent application ensures that it is processing the request within a trusted execution environment.

[0105] In some possible implementations, the first remote proof report may include at least a portion of the key in the first encryption algorithm, and the second remote proof report may include at least a portion of the key in the second encryption algorithm.

[0106] In other words, a portion of the key used in confidential computation is provided to the agent application as a field in the remote proof report, and simultaneously provided to the first client. This serves two purposes: firstly, it enables key transmission for subsequent encrypted computation; secondly, it uses the remote proof report as an intermediate carrier to transmit the key, ensuring its security.

[0107] In some embodiments, the first remote proof report may include a first public key in a first encryption algorithm and a first private key corresponding to the first public key. In this case, the data transmission process between the first client and the large model may be as follows:

[0108] The first client obtains the first public key based on the first remote proof report, and calls the first trusted encryption component to obtain the first data key. It then uses the first data key to encrypt the first user request to obtain the first ciphertext data, and uses the first public key to encrypt the first data key to obtain the first ciphertext key. Finally, it sends the first encrypted data, including the first ciphertext data and the first ciphertext key, to the large model.

[0109] The first trusted encryption component can be understood as a component that provides confidential computing services. For example, the trusted encryption component may provide the first data key in the form of a software development kit (SDK).

[0110] The first trusted encryption component can be a trusted encryption component deployed in the first client. The first client calls the first trusted encryption component deployed in the first client to obtain the first data key. The first data key can be understood as the data key used in the bidirectional communication process between the first client and the large model.

[0111] By carrying the first public key and the first private key in the first remote proof report, the large model can inform the first client of part of the key in the first encryption algorithm, so that the first client first uses the first data key to encrypt the data of the first user request to obtain the first ciphertext data, and then uses the first public key to encrypt the first data key to obtain the first ciphertext key, thus forming the first encrypted data including the first ciphertext data and the first ciphertext key.

[0112] The large model obtains the first private key based on the first remote proof report, decrypts the first ciphertext key using the first private key to obtain the first data key, and decrypts the first ciphertext data using the first data key to obtain the first user request.

[0113] Since the first remote proof report is sent by the large model, the large model can obtain the first private key. The large model first uses the first private key to decrypt the first ciphertext key to obtain the first data key in plaintext, and then uses the first data key in plaintext to decrypt the first ciphertext data to obtain the first user request in plaintext.

[0114] After the large model performs inference on the first user's request and obtains the inference result, it can also encrypt the inference result using the first data key to obtain second encrypted data, which is then sent to the first client. The first client can also decrypt the second encrypted data using the first data key to obtain the inference result, thus completing the data transmission between the client and the large model.

[0115] In some embodiments, the second remote proof report may include a second public key in the second encryption algorithm and a second private key corresponding to the second public key. In this case, the data transmission process between the first client and the first server may be as follows:

[0116] The first client obtains the second public key based on the second remote proof report, and calls the second trusted encryption component to obtain the second data key. It then uses the second data key to encrypt at least one subtask to obtain second ciphertext data, and uses the second public key to encrypt the second data key to obtain the second ciphertext key. Finally, it sends the third encrypted data, including the second ciphertext data and the second ciphertext key, to the first server.

[0117] By carrying the second public key and the second private key in the second remote proof report, the first server can inform the first client of part of the key in the second encryption algorithm, so that the first client first uses the second data key to encrypt the data of at least one subtask to obtain the second ciphertext data, and then uses the second public key to encrypt the second data key to obtain the second ciphertext key, forming the third encrypted data including the second ciphertext data and the second ciphertext key.

[0118] The second trusted encryption component can be a trusted encryption component deployed in the first client. The first client calls the second trusted encryption component deployed in the first client to obtain the second data key. The second data key can be understood as the data key used in the bidirectional communication process between the first client and the first server.

[0119] One or more embodiments of this disclosure do not limit the first data key and the second data key. For example, the first trusted encryption component and the second trusted encryption component can be the same trusted encryption component, and the first data key and the second data key can be the same data key in the same round of dialogue; or, for another example, the first trusted encryption component and the second trusted encryption component can be different trusted encryption components, and the first data key and the second data key can be different data keys in the same round of dialogue.

[0120] The first server obtains the second private key based on the second remote proof report, decrypts the second ciphertext key using the second private key to obtain the second data key, and decrypts the second ciphertext data using the second data key to obtain at least one subtask.

[0121] Since the second remote proof report is sent by the first server, the first server can obtain the second private key. The first server first uses the second private key to decrypt the second ciphertext key to obtain the second data key of the plaintext, and then uses the second data key of the plaintext to decrypt the second ciphertext data to obtain at least one subtask of the plaintext.

[0122] After executing at least one subtask on the first server and obtaining the execution results of each subtask, the first server can further encrypt the execution results using a second data key to obtain fourth encrypted data, which is then sent to the first client. The first client can also decrypt the fourth encrypted data using the second data key to obtain the execution results, thus completing the data transmission between the first client and the first server.

[0123] In some embodiments, the first data key may correspond to the session in which the first user request is made, and different sessions may have different first data keys; the second data key may correspond to the session in which the first user request is made, and different sessions may have different second data keys.

[0124] In other words, in a single round of dialogue in an intelligent agent application, the trusted encryption component provides the same data key, ensuring that the communication links between the first client and the large model, as well as between the first client and the first server, use the same data key for data encryption and decryption. In different dialogues, the data key used for the communication links between the first client and the large model, and between the first client and the first server, changes, ensuring the security and trustworthiness of the entire link in a single round of dialogue. At the same time, the data key is updated in a timely manner, further enhancing the security of the intelligent agent system.

[0125] Based on the data transmission method in the intelligent agent system provided in at least one embodiment of this disclosure, at least one embodiment of this disclosure also provides an intelligent agent system. The following will be combined with... Figure 4 The intelligent agent system is described in detail.

[0126] Figure 4 The schematic diagram illustrates the structure of an intelligent agent system provided in at least one embodiment of the present disclosure.

[0127] like Figure 4 As shown, the intelligent agent system 400 of this embodiment includes an intelligent agent application 401, a first client 402, a large model 403, and a first server 404. The first client 402 is integrated into the intelligent agent application 401. The first client 402, the first server 404, and the large model 403 are all deployed in a trusted execution environment. For example, these units or modules can be implemented by hardware (e.g., circuit) modules or software modules, etc. The following embodiments are the same and will not be repeated. For example, these units or modules can be implemented by a central processing unit (CPU), a general-purpose graphics processor (GPGPU), a graphics processing unit (GPU), a tensor processor (TPU), a field-programmable gate array (FPGA), or other forms of processing units with data processing capabilities and / or instruction execution capabilities, as well as corresponding computer instructions.

[0128] The intelligent agent application 401 is configured to receive a first user request. For example, the intelligent agent application 401 can be configured to execute step S301 described above. The specific implementation principle can be found in the relevant description of step S301, and will not be repeated here.

[0129] The first client 402 is configured to encrypt the first user request and transmit the first encrypted data to the large model 403. For example, the first client 402 can be configured to execute step S301 described above; the specific implementation principle can be found in the relevant description of step S301, and will not be repeated here.

[0130] The large model 403 is configured to: decrypt the first encrypted data, perform inference on the first user request to obtain an inference result, encrypt the inference result, and transmit the second encrypted data to the first client 402, wherein the inference result includes execution steps for processing the first user request. For example, the large model 403 can be configured to execute step S302 described above; its specific implementation principle can be found in the relevant description of step S302, and will not be repeated here.

[0131] The first client 402 is further configured to: decrypt the second encrypted data, determine at least one subtask based on the inference result, encrypt the at least one subtask, and transmit the third encrypted data to the first server 404. For example, the first client 402 can be configured to execute step S303 as described above; its specific implementation principle can be found in the relevant description of step S303, and will not be repeated here.

[0132] The first server 404 is configured to: decrypt the third encrypted data, execute the at least one subtask, obtain the task execution result, encrypt the task execution result, and transmit the fourth encrypted data to the first client 402. For example, the first server 404 can be configured to execute step S304 as described above; its specific implementation principle can be found in the relevant description of step S304, and will not be repeated here.

[0133] The first client 402 is also configured to: decrypt the fourth encrypted data to obtain the task execution result. For example, the first client 402 can be configured to execute step S305 as described above; the specific implementation principle can be found in the relevant description of step S305, and will not be repeated here.

[0134] The intelligent agent application 401 is also configured to output the task execution result. For example, the intelligent agent application 401 can be configured to execute step S305 described above. The specific implementation principle can be found in the relevant description of step S305, and will not be repeated here.

[0135] In at least one embodiment of this disclosure, the first client 402 is further configured to: encrypt the first user request based on a first encryption algorithm and transmit the first encrypted data to the large model; the large model 403 is further configured to: decrypt the first encrypted data based on a first decryption algorithm corresponding to the first encryption algorithm; encrypt the inference result based on the first encryption algorithm and transmit the second encrypted data to the first client 402; the first client 402 is further configured to: decrypt the second encrypted data based on the first decryption algorithm.

[0136] In at least one embodiment of this disclosure, the first client 402 is further configured to: encrypt the at least one subtask based on a second encryption algorithm, and transmit third encrypted data to the first server; the first server 404 is further configured to: decrypt the third encrypted data based on a second decryption algorithm corresponding to the second encryption algorithm; encrypt the task execution result based on the second encryption algorithm, and transmit fourth encrypted data to the first client 402; the first client 402 is further configured to: decrypt the fourth encrypted data based on the second decryption algorithm to obtain the task execution result.

[0137] In at least one embodiment of this disclosure, the agent system 400 further includes a deployment module configured to deploy the first client 402, the first server 403, and the large model in a trusted execution environment in response to the developer of the agent application 401 selecting a confidential computing deployment mode.

[0138] In at least one embodiment of this disclosure, the agent application 401 is further configured to receive at least one of the following: a first remote proof report sent by the large model 403, a second remote proof report sent by the first server 404, and a third remote proof report sent by the first client 402; wherein the first remote proof report is used to prove that the large model 403 is running in the trusted execution environment, the second remote proof report is used to prove that the first server 404 is running in the trusted execution environment, and the third remote proof report is used to prove that the first client 402 is running in the trusted execution environment.

[0139] In at least one embodiment of this disclosure, the first remote proof report includes a first public key in the first encryption algorithm and a first private key corresponding to the first public key. The first client 402 is further configured to: obtain the first public key based on the first remote proof report, and call a first trusted encryption component to obtain a first data key; encrypt the first user request using the first data key to obtain first ciphertext data, and encrypt the first data key using the first public key to obtain a first ciphertext key; and send the first encrypted data including the first ciphertext data and the first ciphertext key to the large model 403.

[0140] In at least one embodiment of this disclosure, the large model 403 is further configured to: obtain the first private key based on the first remote proof report; decrypt the first ciphertext key using the first private key to obtain the first data key; and decrypt the first ciphertext data using the first data key to obtain the first user request.

[0141] In at least one embodiment of this disclosure, the large model 403 is further configured to: encrypt the inference result using the first data key to obtain second encrypted data; send the second encrypted data to the first client 402; the first client 402 is further configured to: decrypt the second encrypted data using the first data key to obtain the inference result.

[0142] In at least one embodiment of this disclosure, the second remote proof report includes a second public key in the second encryption algorithm and a second private key corresponding to the second public key. The first client 402 is further configured to: obtain the second public key based on the second remote proof report, and call the second trusted encryption component to obtain a second data key; encrypt the at least one subtask using the second data key to obtain second ciphertext data, and encrypt the second data key using the second public key to obtain a second ciphertext key; and send the third encrypted data including the second ciphertext data and the second ciphertext key to the first server 404.

[0143] In at least one embodiment of this disclosure, the first server 404 is further configured to: obtain the second private key based on the second remote proof report; decrypt the second ciphertext key using the second private key to obtain the second data key; and decrypt the second ciphertext data using the second data key to obtain the at least one subtask.

[0144] In at least one embodiment of this disclosure, the first server 404 is further configured to: encrypt the task execution result using the second data key to obtain fourth encrypted data; and send the fourth encrypted data to the first client 402; the first client 402 is further configured to: decrypt the fourth encrypted data using the second data key to obtain the task execution result.

[0145] In at least one embodiment of this disclosure, the first data key corresponds to the session in which the first user request is made, and different sessions correspond to different first data keys.

[0146] In at least one embodiment of this disclosure, the second data key corresponds to the session in which the first user request is made, and different sessions correspond to different second data keys.

[0147] In at least one embodiment of this disclosure, the first server 404 is further configured to: for each of the at least one subtask, determine the service corresponding to the subtask, invoke the service, and obtain the task execution result of the subtask.

[0148] It should be noted that, for clarity and brevity, this disclosure does not provide all the constituent units of the intelligent agent system 400. To achieve the necessary functions of the intelligent agent system 400, those skilled in the art can provide and configure other constituent units (not shown) according to specific needs, and one or more embodiments of this disclosure do not limit this.

[0149] At least one embodiment of this disclosure also provides an electronic device, including a processing device and a storage device, the storage device including one or more computer program modules; wherein the one or more computer program modules are stored in the storage device and configured to be executed by the processing device, the one or more computer program modules being used to implement the data transmission method in the intelligent agent system provided in any embodiment of this disclosure.

[0150] For example, the processing device may be a processor, such as a central processing unit (CPU), digital signal processor (DSP), image processor (GPU), general-purpose graphics processor (GPGPU), or other form of processing unit with data processing capabilities and / or instruction execution capabilities. It may be a general-purpose processor or a dedicated processor and may control other components in the electronic device to perform the desired functions.

[0151] For example, the storage device may be a memory, which may include one or more computer program products. These computer program products may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may, for example, include random access memory (RAM) and / or cache memory. The non-volatile memory may, for example, include read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, and a processing device may execute these program instructions to implement the functions (implemented by the processing device) in the embodiments of this disclosure and / or other desired functions. Various application programs and various data may also be stored in the computer-readable storage medium, which is not limited by the embodiments of this disclosure.

[0152] The following is for reference. Figure 5 The diagram illustrates a structural schematic of an electronic device (e.g., a terminal device or a server) 500 suitable for implementing embodiments of the present disclosure. The terminal device in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 5 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.

[0153] like Figure 5 As shown, the electronic device 500 may include a processing unit (e.g., a central processing unit, a graphics processor, etc.) 501, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 502 or a program loaded from a storage device 508 into a random access memory (RAM) 503. The RAM 503 also stores various programs and data required for the operation of the electronic device 500. The processing unit 501, ROM 502, and RAM 503 are interconnected via a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.

[0154] Typically, the following devices can be connected to I / O interface 505: input devices 506 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 507 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 508 including, for example, magnetic tapes, hard disks, etc.; and communication devices 509. Communication device 509 allows electronic device 500 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 5An electronic device 500 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively.

[0155] In particular, according to one or more embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, one or more embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 509, or installed from a storage device 508, or installed from a ROM 502. When the computer program is executed by the processing device 501, it performs the functions defined above in the methods of the embodiments of this disclosure.

[0156] It should be noted that the computer-readable medium described in this disclosure can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this disclosure, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in connection with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.

[0157] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol) and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.

[0158] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.

[0159] The aforementioned computer-readable medium carries one or more programs. When the electronic device executes the aforementioned one or more programs, the electronic device causes the following: receiving a first user request, encrypting the first user request, and transmitting first encrypted data; decrypting the first encrypted data, performing reasoning on the first user request to obtain a reasoning result, encrypting the reasoning result, and transmitting second encrypted data; decrypting the second encrypted data, determining at least one subtask based on the reasoning result, encrypting the at least one subtask, and transmitting third encrypted data; decrypting the third encrypted data, executing the at least one subtask to obtain a task execution result, encrypting the task execution result, and transmitting fourth encrypted data; decrypting the fourth encrypted data to obtain the task execution result, and outputting the task execution result.

[0160] Computer program code for performing the operations of this disclosure can be written in one or more programming languages ​​or a combination thereof, including but not limited to object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0161] One or more embodiments of this disclosure also provide a computer program product comprising one or more computer instructions. When the computer instructions are loaded and executed on a computing device, all or part of the processes or functions described in any embodiment of this disclosure are generated.

[0162] The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, or data center to another website, computer, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means.

[0163] When the computer program product is executed by a computer, the computer performs any of the aforementioned methods. The computer program product can be a software installation package; when any of the aforementioned methods is required, the computer program product can be downloaded and executed on the computer.

[0164] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0165] The units or modules described in the embodiments of this disclosure can be implemented in software or hardware. The names of the units or modules do not necessarily constitute a limitation on the unit or module itself.

[0166] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), and so on.

[0167] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0168] According to one or more embodiments of this disclosure, Example 1 provides a data transmission method in an intelligent agent system. The intelligent agent system includes an intelligent agent application, a first client, a first server, and a large model. The first client is integrated into the intelligent agent application. The first client, the first server, and the large model are all deployed in a trusted execution environment. The method includes the following steps performed by the first client:

[0169] In response to the intelligent agent application receiving a first user request, the first client encrypts the first user request to obtain first encrypted data and transmits the first encrypted data to the large model;

[0170] The first client receives the second encrypted data transmitted by the large model; the first client decrypts the second encrypted data to obtain the reasoning result of the large model based on the first user request, and determines at least one sub-task based on the reasoning result, encrypts the at least one sub-task to obtain the third encrypted data, and transmits the third encrypted data to the first server.

[0171] The first client receives the fourth encrypted data transmitted by the first server;

[0172] The first client decrypts the fourth encrypted data to obtain the task execution result obtained by the first server executing the at least one sub-task, so that the intelligent agent application outputs the task execution result.

[0173] According to one or more embodiments of this disclosure, Example 2 provides a first client from Example 1 encrypting the first user request to obtain first encrypted data, and transmitting the first encrypted data to the large model, including:

[0174] The first client encrypts the first user request based on the first encryption algorithm to obtain the first encrypted data, and then transmits the first encrypted data to the large model.

[0175] The first client decrypts the second encrypted data, including:

[0176] The first client decrypts the second encrypted data based on a first decryption algorithm corresponding to the first encryption algorithm;

[0177] The second encrypted data is obtained by the large model decrypting the first encrypted data based on the first decryption algorithm to obtain the first user request, reasoning about the first user request to obtain the reasoning result, and encrypting the reasoning result based on the first encryption algorithm.

[0178] According to one or more embodiments of this disclosure, Example 3 provides a first client from Example 1 encrypting the at least one subtask to obtain third encrypted data, and transmitting the third encrypted data to the first server, including:

[0179] The first client encrypts the at least one subtask based on the second encryption algorithm to obtain third encrypted data, and then transmits the third encrypted data to the first server.

[0180] The first client decrypts the fourth encrypted data, including:

[0181] The first client decrypts the fourth encrypted data based on the second decryption algorithm corresponding to the second encryption algorithm;

[0182] The fourth encrypted data is obtained by the first server decrypting the third encrypted data based on the second decryption algorithm to obtain the at least one subtask, executing the at least one subtask to obtain the task execution result, and encrypting the task execution result based on the second encryption algorithm.

[0183] According to one or more embodiments of this disclosure, Example 4 provides that the first client, the first server, and the large model in Example 1 are all deployed in a trusted execution environment, including:

[0184] In response to the developer of the intelligent agent application selecting the confidential computing deployment mode, the first client, the first server, and the large model are deployed in a trusted execution environment.

[0185] According to one or more embodiments of this disclosure, Example 5 provides the method of Example 1, further comprising:

[0186] The intelligent agent application receives at least one of the following: a first remote proof report sent by the large model, a second remote proof report sent by the first server, and a third remote proof report sent by the first client;

[0187] The first remote proof report is used to prove that the large model is running in the trusted execution environment, the second remote proof report is used to prove that the first server is running in the trusted execution environment, and the third remote proof report is used to prove that the first client is running in the trusted execution environment.

[0188] According to one or more embodiments of this disclosure, Example Six provides that the agent application in Example Two receives a first remote proof report sent by the large model, the first remote proof report including a first public key in the first encryption algorithm and a first private key corresponding to the first public key.

[0189] The first client encrypts the first user request based on the first encryption algorithm to obtain first encrypted data, and transmits the first encrypted data to the large model, including:

[0190] The first client obtains the first public key based on the first remote proof report, and invokes the first trusted encryption component to obtain the first data key;

[0191] The first client uses the first data key to encrypt the first user request to obtain the first ciphertext data, and uses the first public key to encrypt the first data key to obtain the first ciphertext key;

[0192] The first client sends the first encrypted data, including the first ciphertext data and the first ciphertext key, to the large model.

[0193] According to one or more embodiments of this disclosure, Example 7 provides the method of decrypting the first encrypted data based on the first decryption algorithm as in Example 6, including:

[0194] Based on the first remote proof report, obtain the first private key;

[0195] The first ciphertext key is decrypted using the first private key to obtain the first data key;

[0196] The first encrypted data is decrypted using the first data key to obtain the first user request.

[0197] According to one or more embodiments of this disclosure, Example 8 provides the encryption of the inference result based on the first encryption algorithm as in Example 6, including:

[0198] The reasoning result is encrypted using the first data key to obtain the second encrypted data;

[0199] The first client decrypts the second encrypted data based on a first decryption algorithm corresponding to the first encryption algorithm, including:

[0200] The first client uses the first data key to decrypt the second encrypted data and obtains the reasoning result.

[0201] According to one or more embodiments of this disclosure, Example 9 provides that the intelligent agent application in Example 3 receives a second remote proof report sent by the first server, wherein the second remote proof report includes a second public key in the second encryption algorithm and a second private key corresponding to the second public key.

[0202] The first client encrypts the at least one subtask based on the second encryption algorithm to obtain third encrypted data, and transmits the third encrypted data to the first server, including:

[0203] The first client obtains the second public key based on the second remote proof report, and invokes the second trusted encryption component to obtain the second data key;

[0204] The first client uses the second data key to encrypt the at least one subtask to obtain second ciphertext data, and uses the second public key to encrypt the second data key to obtain a second ciphertext key;

[0205] The first client sends the third encrypted data, which includes the second ciphertext data and the second ciphertext key, to the first server.

[0206] According to one or more embodiments of this disclosure, Example 10 provides the method of decrypting the third encrypted data based on the second decryption algorithm as in Example 9, including:

[0207] Obtain the second private key based on the second remote proof report;

[0208] The second private key is used to decrypt the second ciphertext key to obtain the second data key;

[0209] The second ciphertext data is decrypted using the second data key to obtain the at least one subtask.

[0210] According to one or more embodiments of this disclosure, Example 11 provides the encryption of the task execution result based on the second encryption algorithm as in Example 9, including:

[0211] The task execution result is encrypted using the second data key to obtain the fourth encrypted data;

[0212] The first client decrypts the fourth encrypted data based on the second decryption algorithm corresponding to the second encryption algorithm, including:

[0213] The first client uses the second data key to decrypt the fourth encrypted data to obtain the task execution result.

[0214] According to one or more embodiments of this disclosure, Example Twelve provides a first data key corresponding to the session in any of Examples Six to Eight, with different first data keys corresponding to different sessions.

[0215] According to one or more embodiments of this disclosure, Example Thirteen provides a second data key corresponding to the session in any of Examples Nine to Eleven, with different second data keys corresponding to different sessions.

[0216] According to one or more embodiments of this disclosure, Example Fourteen provides the execution of the at least one subtask in Example Three to obtain a task execution result, including:

[0217] For each of the at least one subtask, determine the service corresponding to the subtask, call the service, and obtain the task execution result of the subtask.

[0218] According to one or more embodiments of this disclosure, Example Fifteen provides an intelligent agent system, the intelligent agent system including an intelligent agent application, a first client, a first server, and a large model, wherein the first client is integrated into the intelligent agent application, and the first client, the first server, and the large model are all deployed in a trusted execution environment.

[0219] The intelligent agent application is configured to: receive a first user request;

[0220] The first client is configured to: encrypt the first user request and transmit the first encrypted data to the large model;

[0221] The large model is configured to: decrypt the first encrypted data, perform inference on the first user request to obtain an inference result, encrypt the inference result, and transmit the second encrypted data to the first client, wherein the inference result includes execution steps for processing the first user request;

[0222] The first client is further configured to: decrypt the second encrypted data, determine at least one subtask based on the reasoning result, encrypt the at least one subtask, and transmit the third encrypted data to the first server;

[0223] The first server is configured to: decrypt the third encrypted data, execute the at least one subtask, obtain the task execution result, encrypt the task execution result, and transmit the fourth encrypted data to the first client;

[0224] The first client is also configured to: decrypt the fourth encrypted data to obtain the task execution result;

[0225] The intelligent agent application is also configured to output the task execution result.

[0226] According to one or more embodiments of this disclosure, Example Sixteen provides an electronic device comprising:

[0227] Processing device; and

[0228] Storage device, including one or more computer program instructions;

[0229] The one or more computer program instructions are executed by a processing device to perform the data transmission method in the intelligent agent system provided in at least one embodiment of the present disclosure.

[0230] According to one or more embodiments of the present disclosure, Example Seventeen provides a computer-readable storage medium for non-transitory storage of computer-readable instructions, wherein the computer-readable instructions, when executed by a processor, implement a data transmission method in an intelligent agent system provided in at least one embodiment of the present disclosure.

[0231] The above description is merely a preferred embodiment of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features disclosed in this disclosure that have similar functions.

[0232] Furthermore, while the operations are described in a specific order, this should not be construed as requiring these operations to be performed in the specific order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.

[0233] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative examples of implementing the claims.

Claims

1. A data transmission method in an intelligent agent system, wherein, The intelligent agent system includes an intelligent agent application, a first client, a first server, and a large model. The first client is integrated into the intelligent agent application. The first client, the first server, and the large model are all deployed in a trusted execution environment. The method includes the following steps executed by the first client: In response to the intelligent agent application receiving a first user request, the first client encrypts the first user request to obtain first encrypted data and transmits the first encrypted data to the large model; The first client receives the second encrypted data transmitted by the large model, wherein the first encrypted data and the second encrypted data are encrypted based on a first encryption algorithm; The first client decrypts the second encrypted data to obtain the reasoning result of the large model based on the first user request, and determines at least one subtask based on the reasoning result, encrypts the at least one subtask to obtain the third encrypted data, and transmits the third encrypted data to the first server. The first client receives the fourth encrypted data transmitted by the first server, wherein the third encrypted data and the fourth encrypted data are encrypted based on the second encryption algorithm; The first client decrypts the fourth encrypted data to obtain the task execution result obtained by the first server executing the at least one sub-task, so that the intelligent agent application outputs the task execution result; The method further includes: the agent application receiving at least one of the following: a first remote proof report sent by the large model, a second remote proof report sent by the first server, or a third remote proof report sent by the first client, wherein the first remote proof report is used to prove that the large model is running in the trusted execution environment, the first remote proof report includes at least a portion of the key in the first encryption algorithm, the second remote proof report is used to prove that the first server is running in the trusted execution environment, the second remote proof report includes at least a portion of the key in the second encryption algorithm, and the third remote proof report is used to prove that the first client is running in the trusted execution environment.

2. The method according to claim 1, wherein, The first client encrypts the first user request to obtain first encrypted data, and transmits the first encrypted data to the large model, including: The first client encrypts the first user request based on the first encryption algorithm to obtain the first encrypted data, and then transmits the first encrypted data to the large model. The first client decrypts the second encrypted data, including: The first client decrypts the second encrypted data based on a first decryption algorithm corresponding to the first encryption algorithm; The second encrypted data is obtained by the large model decrypting the first encrypted data based on the first decryption algorithm to obtain the first user request, reasoning about the first user request to obtain the reasoning result, and encrypting the reasoning result based on the first encryption algorithm.

3. The method according to claim 1, wherein, The first client encrypts the at least one subtask to obtain third encrypted data, and transmits the third encrypted data to the first server, including: The first client encrypts the at least one subtask based on the second encryption algorithm to obtain third encrypted data, and then transmits the third encrypted data to the first server. The first client decrypts the fourth encrypted data, including: The first client decrypts the fourth encrypted data based on the second decryption algorithm corresponding to the second encryption algorithm; The fourth encrypted data is obtained by the first server decrypting the third encrypted data based on the second decryption algorithm to obtain the at least one subtask, executing the at least one subtask to obtain the task execution result, and encrypting the task execution result based on the second encryption algorithm.

4. The method according to claim 1, wherein, The first client, the first server, and the large model are all deployed in a trusted execution environment, including: In response to the developer of the intelligent agent application selecting the confidential computing deployment mode, the first client, the first server, and the large model are deployed in a trusted execution environment.

5. The method according to claim 2, wherein, The intelligent agent application receives a first remote proof report sent by the large model. The first remote proof report includes a first public key in the first encryption algorithm and a first private key corresponding to the first public key. The first client encrypts the first user request based on the first encryption algorithm to obtain first encrypted data, and transmits the first encrypted data to the large model, including: The first client obtains the first public key based on the first remote proof report, and invokes the first trusted encryption component to obtain the first data key; The first client uses the first data key to encrypt the first user request to obtain the first ciphertext data, and uses the first public key to encrypt the first data key to obtain the first ciphertext key; The first client sends the first encrypted data, including the first ciphertext data and the first ciphertext key, to the large model.

6. The method according to claim 5, wherein, The step of decrypting the first encrypted data based on the first decryption algorithm includes: Based on the first remote proof report, obtain the first private key; The first ciphertext key is decrypted using the first private key to obtain the first data key; The first encrypted data is decrypted using the first data key to obtain the first user request.

7. The method according to claim 5, wherein, The encryption of the reasoning result based on the first encryption algorithm includes: The reasoning result is encrypted using the first data key to obtain the second encrypted data; The first client decrypts the second encrypted data based on a first decryption algorithm corresponding to the first encryption algorithm, including: The first client uses the first data key to decrypt the second encrypted data and obtains the reasoning result.

8. The method according to claim 3, wherein, The intelligent agent application receives a second remote proof report sent by the first server. The second remote proof report includes a second public key in the second encryption algorithm and a second private key corresponding to the second public key. The first client encrypts the at least one subtask based on the second encryption algorithm to obtain third encrypted data, and transmits the third encrypted data to the first server, including: The first client obtains the second public key based on the second remote proof report, and invokes the second trusted encryption component to obtain the second data key; The first client uses the second data key to encrypt the at least one subtask to obtain second ciphertext data, and uses the second public key to encrypt the second data key to obtain a second ciphertext key; The first client sends the third encrypted data, which includes the second ciphertext data and the second ciphertext key, to the first server.

9. The method according to claim 8, wherein, The process of decrypting the third encrypted data based on the second decryption algorithm includes: Obtain the second private key based on the second remote proof report; The second private key is used to decrypt the second ciphertext key to obtain the second data key; The second ciphertext data is decrypted using the second data key to obtain the at least one subtask.

10. The method according to claim 8, wherein, The step of encrypting the task execution result based on the second encryption algorithm includes: The task execution result is encrypted using the second data key to obtain the fourth encrypted data; The first client decrypts the fourth encrypted data based on the second decryption algorithm corresponding to the second encryption algorithm, including: The first client uses the second data key to decrypt the fourth encrypted data to obtain the task execution result.

11. The method according to any one of claims 5 to 7, wherein, The first data key corresponds to the session in which the first user request is made, and different sessions correspond to different first data keys.

12. The method according to any one of claims 8 to 10, wherein, The second data key corresponds to the session in which the first user request is made, and different sessions correspond to different second data keys.

13. The method according to claim 3, wherein, The execution of the at least one subtask to obtain the task execution result includes: For each of the at least one subtask, determine the service corresponding to the subtask, call the service, and obtain the task execution result of the subtask.

14. An intelligent agent system, wherein, The intelligent agent system includes an intelligent agent application, a first client, a first server, and a large model. The first client is integrated into the intelligent agent application. The first client, the first server, and the large model are all deployed in a trusted execution environment. The intelligent agent application is configured to: receive a first user request; The first client is configured to: encrypt the first user request and transmit the first encrypted data to the large model; The large model is configured to: decrypt the first encrypted data, perform inference on the first user request to obtain an inference result, encrypt the inference result, and transmit the second encrypted data to the first client, wherein the inference result includes execution steps for processing the first user request, and the first encrypted data and the second encrypted data are encrypted based on a first encryption algorithm; The first client is further configured to: decrypt the second encrypted data, determine at least one subtask based on the reasoning result, encrypt the at least one subtask, and transmit the third encrypted data to the first server; The first server is configured to: decrypt the third encrypted data, execute the at least one subtask, obtain the task execution result, encrypt the task execution result, and transmit the fourth encrypted data to the first client, wherein the third encrypted data and the fourth encrypted data are obtained by encrypting based on the second encryption algorithm; The first client is also configured to: decrypt the fourth encrypted data to obtain the task execution result; The intelligent agent application is also configured to output the task execution result; The intelligent agent application is further configured to receive at least one of the following: a first remote proof report sent by the large model, a second remote proof report sent by the first server, or a third remote proof report sent by the first client, wherein the first remote proof report is used to prove that the large model is running in the trusted execution environment, the first remote proof report includes at least a portion of the key in the first encryption algorithm, the second remote proof report is used to prove that the first server is running in the trusted execution environment, the second remote proof report includes at least a portion of the key in the second encryption algorithm, and the third remote proof report is used to prove that the first client is running in the trusted execution environment.

15. An electronic device comprising: Processing device; as well as Storage device, including one or more computer program instructions; The one or more computer program instructions are executed by the processing device to perform the method according to any one of claims 1 to 13.

16. A computer-readable storage medium for non-transitory storage of computer-readable instructions, wherein, The method of any one of claims 1 to 13 is implemented when the computer-readable instructions are executed by a processor.