Key management method, method for protecting artificial intelligence model data, and related device

CN121441497BActive Publication Date: 2026-09-04BEIJING VOLCANO ENGINE TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511776450.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-11-28
Publication Date
2026-09-04
Estimated Expiration
2045-11-28

AI Technical Summary

Technical Problem

[0003]然而,上述业务场景中,密钥材料由密钥管理服务生成,用户缺乏对密钥材料的控制权,难以满足用户的合规性要求

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121441497B_ABST
    Figure CN121441497B_ABST
Patent Text Reader

Abstract

One or more embodiments of the present disclosure provide a key management method, a method for protecting artificial intelligence model data, and related devices. The key management method comprises: in response to receiving a first request for generating a data key, obtaining a first data key, encrypting the first data key using a first encryption key to obtain a first ciphertext data key; sending the first ciphertext data key to a key management system of a first user, and receiving a second ciphertext data key returned by the key management system of the first user, the second ciphertext data key being obtained by encrypting the first ciphertext data key using a second encryption key in the key management system of the first user; and returning the first data key and the second ciphertext data key to a requester of the first request. Through double encryption, the user can master the key material, meeting the user's compliance requirements for data security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One or more embodiments of this disclosure relate to a key management method, a method for protecting artificial intelligence model data, a key management device, an apparatus for protecting artificial intelligence model data, an electronic device, and a computer-readable storage medium. Background Technology

[0002] In some business scenarios, data security management is achieved by accessing key management services to meet data security requirements.

[0003] However, in the above business scenarios, the key materials are generated by the key management service, and users lack control over the key materials, making it difficult to meet users' compliance requirements. Summary of the Invention

[0004] This summary section is provided to briefly introduce the concepts, which will be described in detail in the subsequent detailed description section. This summary section is not intended to identify key or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.

[0005] At least one embodiment of this disclosure provides a key management method, comprising: in response to receiving a first request to generate a data key, obtaining a first data key, encrypting the first data key using a first encryption key to obtain a first ciphertext data key; sending the first ciphertext data key to a key management system of a first user, and receiving a second ciphertext data key returned by the key management system of the first user; wherein the second ciphertext data key is obtained by encrypting the first ciphertext data key using a second encryption key in the key management system of the first user; and returning the first data key and the second ciphertext data key to the requester of the first request.

[0006] At least one embodiment of this disclosure provides a method for protecting artificial intelligence model data, comprising: acquiring first model resource data associated with a first user; sending a first request to a key management service to generate a data key, and receiving a first data key and a second encrypted data key returned by the key management service; encrypting the first model resource data using the first data key to obtain encrypted resource data; deleting the first data key, and storing the second encrypted data key and the encrypted resource data; wherein the second encrypted data key is obtained by encrypting the first data key using a first encryption key generated by the key management service and a second encryption key generated by the key management system of the first user.

[0007] At least one embodiment of this disclosure provides a key management device, comprising: an encryption module configured to: in response to receiving a first request to generate a data key, obtain a first data key, and encrypt the first data key using a first encryption key to obtain a first ciphertext data key; a communication module configured to: send the first ciphertext data key to a key management system of a first user, and receive a second ciphertext data key returned by the key management system of the first user; wherein the second ciphertext data key is obtained by encrypting the first ciphertext data key using a second encryption key in the key management system of the first user; the communication module is further configured to: return the first data key and the second ciphertext data key to the requester of the first request.

[0008] At least one embodiment of this disclosure provides an apparatus for protecting artificial intelligence model data, comprising: an acquisition module configured to acquire first model resource data associated with a first user; a communication module configured to send a first request to a key management service to generate a data key, and receive a first data key and a second encrypted data key returned by the key management service; an encryption module configured to encrypt the first model resource data using the first data key to obtain encrypted resource data; and a storage module configured to delete the first data key and store the second encrypted data key and the encrypted resource data; wherein the second encrypted data key is obtained by encrypting the first data key using a first encryption key generated by the key management service and a second encryption key generated by the key management system of the first user.

[0009] At least one embodiment of this disclosure provides an electronic device, including: a processing device; and a storage device including one or more computer program instructions; wherein the one or more computer program instructions are executed by the processing device to perform a key management method or a method for protecting artificial intelligence model data provided in at least one embodiment of this disclosure.

[0010] At least one embodiment of this disclosure provides a computer-readable storage medium for non-transitory storage of computer-readable instructions, wherein, when executed by a processor, the computer-readable instructions implement the key management method or the method for protecting artificial intelligence model data provided in at least one embodiment of this disclosure.

[0011] At least one embodiment of this disclosure provides a computer program product, including a computer program that, when executed by a processor, implements a key management method or a method for protecting artificial intelligence model data provided in at least one embodiment of this disclosure. Attached Figure Description

[0012] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the originals and elements are not necessarily drawn to scale.

[0013] Figure 1 This illustration schematically depicts an application scenario of a key management service provided by at least one embodiment of the present disclosure;

[0014] Figure 2 The illustration shows a flowchart of a key management method provided in at least one embodiment of the present disclosure;

[0015] Figure 3 The illustration schematically shows a flowchart of an encryption process provided in at least one embodiment of the present disclosure;

[0016] Figure 4 The illustration shows a flowchart of a decryption process provided in at least one embodiment of the present disclosure;

[0017] Figure 5 This illustration schematically depicts an application scenario of a key management service provided by at least one embodiment of the present disclosure;

[0018] Figure 6 The illustration shows a flowchart of a method for protecting artificial intelligence model data provided in at least one embodiment of the present disclosure;

[0019] Figure 7 The schematic diagram illustrates the structure of a key management device provided in at least one embodiment of the present disclosure;

[0020] Figure 8 The schematic diagram illustrates a structural schematic of a device for protecting artificial intelligence model data provided in at least one embodiment of this disclosure; and

[0021] Figure 9 The schematic diagram illustrates a structure suitable for implementing at least one embodiment of the present disclosure of an electronic device. Detailed Implementation

[0022] One or more embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0023] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.

[0024] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below.

[0025] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.

[0026] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0027] The names of the messages or information exchanged between the various devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of these messages or information.

[0028] It is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition, use, storage or deletion of the data) shall comply with the requirements of relevant laws, regulations and related provisions.

[0029] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, relevant users should be informed of the type, scope of use, and usage scenarios of the information involved in this disclosure through appropriate means in accordance with relevant laws and regulations, and authorization should be obtained from the relevant users. Among them, relevant users may include any type of rights holder, such as individuals, enterprises, and groups.

[0030] For example, in response to receiving an active request from a user, a prompt message is sent to the relevant user to clearly indicate that the operation requested by the user will require obtaining and using the user's information. This allows the relevant user to choose whether to provide information to the software or hardware such as the electronic device, application, server, or storage medium that performs the operation of any embodiment of the present disclosure based on the prompt message.

[0031] As an optional but non-restrictive implementation, in response to a user's active request, a prompt message can be sent to the user, such as a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide information to the electronic device.

[0032] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.

[0033] In some business scenarios, data security is of paramount importance. By accessing a key management service and utilizing its key management and other data encryption protection services, data security can be enhanced.

[0034] Taking a large model service platform as an example, the large model service platform can provide users with services related to large models. For example, the large model service platform can provide basic large models, large model training services, large model inference services, large model fine-tuning services, and large model evaluation services. Users can use the computing resources of the large model service platform to develop artificial intelligence (AI) applications.

[0035] During the use of large model service platforms, the platforms need to ensure the data security of large model resource data. Therefore, some large model service platforms integrate with key management services provided by cloud service providers to provide encryption services for large model resource data.

[0036] However, key management services have at least the following drawbacks: First, users lack ownership and control over the keys, as key materials are usually hosted in the cloud by the key management service, making it difficult to meet data sovereignty and compliance requirements; second, some key management services offer a "bring your own key" (BYOK) option, allowing users to import keys, but the process of encrypting data using the user-imported key is still completed within the key management service, which still has access to the key materials, making it difficult for users to have full control over the keys; furthermore, in some high-compliance scenarios, users often have their own self-built key management systems, which they wish to use for data encryption.

[0037] To at least partially solve the above-mentioned technical problem, at least one embodiment of this disclosure provides a key management method, the method comprising: in response to receiving a first request to generate a data key, obtaining a first data key, encrypting the first data key using a first encryption key to obtain a first ciphertext data key, sending the first ciphertext data key to a key management system of a first user, and receiving a second ciphertext data key returned by the key management system of the first user, wherein the second ciphertext data key is obtained by encrypting the first ciphertext data key using a second encryption key in the key management system of the first user, and returning the first data key and the second ciphertext data key to the requester of the first request.

[0038] In a key management method provided in at least one embodiment of this disclosure, a key management service is connected to a user's own key management system. When generating a data key, after the first data key is encrypted once by the first encryption key of the key management service, it is then encrypted a second time by the second encryption key of the user's own key management system. On the one hand, this ensures that the second encrypted ciphertext data key meets the encryption standards provided by the key management service, thus guaranteeing encryption strength. On the other hand, the key management service and the user's own key management system transmit only ciphertext data keys, avoiding information leakage during transmission. Furthermore, the double encryption method allows the user to control the key materials, meeting the user's compliance requirements for data security.

[0039] At least one embodiment of this disclosure provides a method for protecting artificial intelligence model data. The method includes: acquiring first model resource data associated with a first user; sending a first request to a key management service to generate a data key; receiving a first data key and a second encrypted data key returned by the key management service; encrypting the first model resource data using the first data key to obtain encrypted resource data; deleting the first data key; and storing the second encrypted data key and the encrypted resource data. The second encrypted data key is obtained by encrypting the first data key using a first encryption key generated by the key management service and a second encryption key generated by the key management system of the first user.

[0040] In a method for protecting artificial intelligence model data provided in at least one embodiment of this disclosure, a key management service connected to a large model service platform accesses the user's own key management system. For scenarios where users need to encrypt model resource data during the use of the large model service platform, the first data key is encrypted twice using a first encryption key from the key management service and a second encryption key from the user's own key management system. This enables the large model service platform to support data security management based on the user's own key management system, and the key materials do not leave the security domain, thereby improving the security of users during the use of the large model service platform.

[0041] Based on the key management method and the method for protecting artificial intelligence model data provided in at least one embodiment of this disclosure, at least one embodiment of this disclosure also provides a key management device, a device for protecting artificial intelligence model data, an electronic device, a computer-readable storage medium, and a computer program product.

[0042] The following detailed description, with reference to the accompanying drawings, describes one or more embodiments of the present disclosure and some examples thereof.

[0043] Figure 1 The illustration shows an application scenario diagram of a key management service provided by at least one embodiment of the present disclosure.

[0044] like Figure 1 As shown, the application scenario provided in this embodiment can be a key management service (KMS), which can be understood as a key management and data encryption service platform.

[0045] In one or more embodiments of this disclosure, the key management service 11 is connected to the user's key management system 12, which can be understood as a user-built and owned key management system. For example, the user's key management system 12 can be a hardware security module (HSM).

[0046] In response to a first request to generate a data key, the key management service 11 can generate a first data key and a first encryption key, encrypt the first data key using the first encryption key to obtain a first ciphertext data key, and send the first ciphertext data key to the user's key management system 12, which generates a second encryption key, encrypts the first ciphertext data key again using the second encryption key to obtain a second ciphertext data key, and returns the second ciphertext data key to the key management service 11, which then returns the first data key and the second ciphertext data key to the requester of the first request.

[0047] In this way, the requester of the first request can use the first data key to encrypt the data, and then, by deleting the first data key and retaining the second ciphertext data key, ensure that the data key used for data encryption is encrypted by the user's own key management system, thus ensuring the security of the data key and that the user has control over the key material.

[0048] The following will combine Figures 2 to 4 A key management method provided by at least one embodiment of the present disclosure will be described in detail.

[0049] Figure 2The illustration shows a flowchart of a key management method provided in at least one embodiment of the present disclosure.

[0050] like Figure 2 As shown, the key management method of this embodiment includes steps S201 to S203. In some embodiments, the entity executing the key management method can be a key management service. The key management method includes:

[0051] Step S201: In response to receiving a first request to generate a data key, obtain the first data key, encrypt the first data key using the first encryption key, and obtain the first ciphertext data key.

[0052] The first request can be understood as a request to the key management service to generate a data key. For example, the key management service can connect to other systems and provide key-related services to them. Other systems connected to the key management service may have data encryption requirements. In this case, other systems connected to the key management service can send the first request to the key management service to request the key management service to generate a data key so that other systems connected to the key management service can use the data key to encrypt data.

[0053] The first data encryption key (DEK) can be understood as the key used for data encryption. The first data encryption key can be generated by the key management service.

[0054] In one or more embodiments of this disclosure, the first data key is double-encrypted, and the double-encryption encryption keys are generated by the key management service and the key management system of the first user, respectively.

[0055] The first encryption key generated by the key management service can be understood as the master encryption key (KEK). The key management service first uses the first encryption key to encrypt the first data key for the first time to obtain the first ciphertext data key. In this way, it ensures that the encryption standard of the encryption process for the first data key meets the encryption standard provided by the key management service, and avoids the situation that the encrypted first data key is not secure enough due to the low encryption strength of the user's key management system.

[0056] Step S202: Send the first ciphertext data key to the first user's key management system and receive the second ciphertext data key returned by the first user's key management system.

[0057] After encrypting the first data key once using the first encryption key generated by the key management service, the key management service can send the first ciphertext data key to the first user's key management system, which will then generate a second encryption key. The second encryption key will be used to encrypt the first ciphertext data key a second time to obtain the second ciphertext data key.

[0058] In this way, by encrypting the data first by the key management service and then by the first user's key management system, the data security during the communication process from the key management service to the first user's key management system is protected, and the leakage of the first data key that may occur if the first data key is directly transmitted from the key management service to the first user's key management system is avoided.

[0059] Step S203: Return the first data key and the second ciphertext data key to the requester of the first request.

[0060] After the first user's key management system performs secondary encryption on the first data key, the key management service can send the plaintext first data key and the double-encrypted second ciphertext data key to the requester of the first request. The requester of the first request can use the plaintext first data key to encrypt the data. After the data encryption is completed, the requester of the first request can delete the plaintext first data key and only keep the double-encrypted second ciphertext data key.

[0061] Thus, since the second encrypted data key is additionally encrypted by the first user's key management system, the retained key materials are in the control of the first user, satisfying the first user's compliance requirements during key generation and data encryption.

[0062] The following explains the process of decrypting the data key.

[0063] In some embodiments, the key management service receives a second request to decrypt a data key, the second request including a second ciphertext data key, sends the second ciphertext data key to the key management system of the first user, receives a first ciphertext data key returned by the key management system of the first user, decrypts the first ciphertext data key to obtain the first data key in plaintext, and returns the first data key in plaintext to the requester of the second request.

[0064] Because the key generation process involves first encrypting the data using a first encryption key generated by the key management service, and then encrypting it a second time using a second encryption key generated by the first user's key management system, the key management service first sends the second ciphertext data key to the first user's key management system during key decryption and data decryption. The first user's key management system then performs the first decryption, for example, by using the second decryption key corresponding to the second encryption key to decrypt the second ciphertext data key, obtaining the first ciphertext data key. Next, the key management service performs the second decryption, for example, by using the first decryption key corresponding to the first encryption key to decrypt the first ciphertext data key, obtaining the first data key. Finally, the key management service returns the first data key to the requester of the second request, completing the double decryption process. This ensures that the first data key can only be obtained and data decryption can only be performed after the data has been decrypted by the first user's key management system.

[0065] In some possible implementations, a key system proxy is configured between the key management service and the first user's key management system to facilitate data transfer between the key management service and the first user's key management system.

[0066] For example, the first encrypted data key is sent to the first user's key management system through a key system agent; or, for another example, a second request is sent to the first user's key management system through a key system agent.

[0067] A key system agent can be used to adapt communication between different key management systems for different users. In other words, a key system agent can connect to key management systems from different vendors and of different types. For example, a key system agent can be a lightweight agent program.

[0068] By configuring a key system agent, the key management service can connect to the key management systems of different users, adapt to different users' key management systems, and enrich the applicable scenarios of the key management service.

[0069] In some embodiments, a key system agent can be used to perform communication protocol conversion so that the converted communication protocol is consistent with the communication protocol used by the receiver.

[0070] In other words, since different users can use different key management systems, and different key management systems can correspond to different transmission protocols, by creating a key system proxy, the differences in transmission protocols between different types of key management systems can be masked, and protocol conversion can be performed between the key management service and the user's key management system to enable communication between the user's key management system and the key management service.

[0071] Figure 3 The illustration shows a flowchart of an encryption process provided by at least one embodiment of the present disclosure.

[0072] like Figure 3 In the aforementioned encryption process, the interaction between the requester of the first request, the key management service, the key system agent, and the key management system of the first user is as follows: The requester of the first request sends a first request to the key management service. The key management service generates a first data key and a first encryption key, encrypts the first data key using the first encryption key to obtain a first ciphertext data key, and sends the first ciphertext data key to the key system agent. The key system agent performs protocol conversion on the first key transmission request to obtain a second key transmission request that matches the transmission protocol applicable to the key management system of the first user, and sends the second key transmission request to the key management system of the first user. The key management system of the first user generates a second encryption key, encrypts the first ciphertext data key using the second encryption key to obtain a second ciphertext data key, and sends the second ciphertext data key to the key management service. The key management service sends the first data key and the second ciphertext data key together to the requester of the first request.

[0073] Figure 4 The illustration shows a flowchart of a decryption process provided in at least one embodiment of the present disclosure.

[0074] like Figure 4 In the aforementioned decryption process, the interaction between the requester of the second request, the key management service, the key system agent, and the key management system of the first user is as follows: The key management system of the first user sends a second request to the key management service; the key management service sends a third key transmission request to the key system agent; the key system agent performs protocol conversion on the third key transmission request to obtain a fourth key transmission request that matches the transmission protocol used by the key management system of the first user, and sends the fourth key transmission request to the key management system of the first user; the key management system of the first user uses the second decryption key to decrypt the second ciphertext data key to obtain the first ciphertext data key, and sends the first ciphertext data key to the key management service; the key management service uses the first decryption key to decrypt the first ciphertext data key to obtain the first data key, and sends the first data key to the requester of the second request.

[0075] Furthermore, since the key management service is connected to the first user's key management system, the key management service can also generate audit logs and present them to the first user. The audit logs may include at least one of the following: the process of generating data keys and the process of decrypting data keys.

[0076] In this way, the key management service provides users with a unified audit log mechanism, which presents the interaction process between the key management service and the user's key management system, as well as the key processing process of the key management service itself, to the user in a complete and clear manner, ensuring that the first user can view every key operation and key status, thereby improving security transparency.

[0077] The key management service provided by one or more embodiments of this disclosure can be applied in the scenario of a large model service platform. The key management process in the scenario of a large model service platform is described below.

[0078] Figure 5 The illustration shows an application scenario diagram of a key management service provided by at least one embodiment of the present disclosure.

[0079] like Figure 5 As shown, the application scenario provided in this embodiment may include a key management service 11, which communicates with a large model service platform 13. The large model service platform 13 can provide users (e.g., enterprises, organizations, or individuals) with rich model services. At the same time, the large model service platform 11 can also provide users with end-to-end functions such as model data, fine-tuning, inference, and evaluation.

[0080] Key management service 11 helps large model service platform 13 manage keys and protect the security of model resource data on the cloud by providing an encryption interface.

[0081] Furthermore, the key management service 11 can also communicate with the key management system 12 of the first user through the key system agent 14. The first user can be a user using the large model service platform 13.

[0082] For example, when the first user uses the large model service platform 13, the first user can trigger the creation operation of the key system agent in the large model service platform 13. The large model service platform 13 can use its own network resources and computing resources to create a key system agent 14 pointing to the key management system 12 of the first user. Furthermore, based on the key system agent 14, a managed key is created in the large model service platform 13, so that during the operation of the large model service platform 13, the encryption and decryption processes are all transferred to the key system agent 14 and completed by the key management system 12 of the first user.

[0083] In some embodiments, the large model service platform 13, the key management service 11, the key system agent 14, and the first user's key management system 12 all communicate through a secure channel. For example, the communication between the large model service platform 13, the key management service 11, the key system agent 14, and the first user's key management system 12 is doubly encrypted at both the network layer and the application layer. For example, mTLS encryption or HTTPS encryption is performed at the network layer, and data encryption is performed at the application layer, thereby ensuring the confidentiality, integrity, and authenticity of the data during the transmission of requests between the large model service platform 13, the key management service 11, the key system agent 14, and the first user's key management system 12.

[0084] The large model service platform 13 can run a security sandbox 131. Each security sandbox 131 can correspond to a task; that is, a task runs in an isolated security sandbox 131, and different tasks run in different security sandboxes 131. Different security sandboxes 131 cannot communicate directly with each other, and each security sandbox 131 has only minimal permissions and access capabilities. Within the security sandbox 131, model resource data is stored in encrypted form. It is only decrypted when the model resource data enters the memory of the security sandbox 131 (i.e., when a task needs to be executed). Through the security sandbox 131, the model resource data and the key materials used to encrypt the model resource data are kept within the security domain.

[0085] Because each task runs in a different security sandbox 131, each task is transformed into an independent security container. Through network isolation, task isolation, and security sandboxes, cross-tenant data interaction and lateral penetration are prevented. Even within the same virtual private cloud (VPC), there are network isolation policies between different tasks and different tenants. Dynamic network policies are used, such as security groups, access control lists (ACLs), and private network channel isolation, to prevent cross-task data channels and probes.

[0086] In some embodiments, the security sandbox 131 mounts a first file system 132, which can be a transparent encrypted file system. The first file system 132 can be used to store decrypted model resource data. In this way, when a task is executed in the security sandbox 131, the model resource data is obtained through the first file system 132 to prevent the leakage of model resource data.

[0087] In some embodiments, the security sandbox 131 can communicate with the key management service 11. For example, the security sandbox 131 can transmit operation and maintenance data of the large model service platform 13 to the key management service 11. In this case, the large model service platform 13 can also run a trusted proxy 133. The security sandbox 131 and the key management service 11 communicate through the trusted proxy 133 to prevent the key management service 11 from directly operating on the security sandbox 131 and to prevent the key management service 11 from directly accessing the data stored in the security sandbox 131.

[0088] In this way, by adjusting the architecture of the large model service platform, the security requirement that model resource data and key materials not leave the security domain can be achieved when users use the large model service platform to provide services related to large models.

[0089] The following will combine Figure 6 A method for protecting artificial intelligence model data, provided by at least one embodiment of this disclosure, will be described in detail.

[0090] Figure 6 The illustration shows a flowchart of a method for protecting artificial intelligence model data provided in at least one embodiment of the present disclosure.

[0091] like Figure 6 As shown, the method for protecting artificial intelligence model data in this embodiment includes steps S601 to S604. In some embodiments, the entity executing the method for protecting artificial intelligence model data can be a large model service platform, which communicates with a key management service. For example, the key management service can communicate with the key management system of the first user through a key system proxy. The method for protecting artificial intelligence model data includes:

[0092] Step S601: Obtain the first model resource data associated with the first user.

[0093] In one or more embodiments of this disclosure, the first user can be understood as any user using the large model service platform, for example, the first user can be a tenant using the large model service platform.

[0094] Model resource data can be understood as data related to the large model service provided by the large model service platform. The first model resource data associated with the first user can be understood as model resource data related to the large model service triggered by the first user.

[0095] In some embodiments, the first model resource data may include at least one of the following: training data for training a large model, input data for inference of a large model, model weights of a large model, model parameters of a large model, and intermediate state data of a large model.

[0096] For example, the training data used for training large models, the input data used for inference of large models, and the model weights of large models can be model resource data uploaded by the first user to the large model service platform. The model parameters and intermediate state data of large models (such as training cache during the training process of large models) can be model resource data generated by the large model service platform after executing the first user's task.

[0097] In other words, in one or more embodiments of this disclosure, the model resource data involved in each process of the first user using the large model service platform can be encrypted and decrypted based on the first user's key management system, thereby achieving comprehensive protection of the first user's model resource data and ensuring the data security of the first user.

[0098] Step S602: Send a first request to the key management service to generate a data key, and receive the first data key and the second ciphertext data key returned by the key management service.

[0099] In one or more embodiments of this disclosure, the large model service platform communicates with the key management service, and the key management service is used to encrypt the model resource data in the large model service platform. Furthermore, by creating a key system proxy, a secure channel is established to securely connect the key management service with the key management system of the first user. This ensures that the data key for encrypting the first model resource data is managed by the first user's own key management system and encrypted by the first user's own key management system, thereby achieving the "hold your own key" (HYOK) characteristic and realizing the goal of keeping the key materials within the security domain and having complete control over them by the user.

[0100] In some possible implementations, the large model service platform can call a key management service to generate a first data key and a first encryption key. The first encryption key is used to encrypt the first data key to obtain a first ciphertext data key. Based on a key system proxy, the first ciphertext data key is sent to the first user's key management system through the key system proxy. The platform receives a second ciphertext data key returned by the first user's key management system, which is obtained by encrypting the first ciphertext data key using a second encryption key generated by the first user's key management system. The platform then sends the first data key and the second ciphertext data key to the large model service platform. In this way, the large model service platform can receive the first data key and the second ciphertext data key returned by the key management service.

[0101] Compared with the traditional encryption process of "generating a first data key and a first encryption key by a key management service, and returning the first data key and the ciphertext data key encrypted with the first encryption key to the large model service platform", in one or more embodiments of this disclosure, the first data key is further encrypted by a second encryption key generated by the key management system of the first user, so that the key material of the finally generated second ciphertext data key is controlled by the first user, thus meeting the compliance requirements of the first user.

[0102] Step S603: Encrypt the first model resource data using the first data key to obtain encrypted resource data.

[0103] In one or more embodiments of this disclosure, envelope encryption is used to ensure the data security of model resource data. Envelope encryption is completed by encrypting the first model resource data using a first data key, and then encrypting the first data key using a first encryption key generated by a key management service and a second encryption key generated by the key management system of the first user. This ensures the data security of model resource data within the large model service platform.

[0104] Step S604: Delete the first data key, and store the second ciphertext data key and encrypted resource data.

[0105] After encrypting the first model resource data, the first data key is deleted, so that the large model service platform only stores the second ciphertext data key and the encrypted resource data, ensuring the data security of the model resource data during the operation of the large model service platform.

[0106] The first type of resource data is associated with the first task. The task can be understood as a task related to the large model that is executed using the computing resources provided by the large model service platform. For example, the task can be a model training task, a model fine-tuning task, a model inference task, etc. The first model resource data can be model resource data related to the first task, such as model resource data required to execute the first task, or model resource data generated after executing the first task.

[0107] In some embodiments, different tasks in the large model service platform can correspond to different security sandboxes. A security sandbox, also known as a security sandbox, can be understood as an isolated environment provided for tasks in the large model service platform. By using a security sandbox, the execution security of tasks is ensured, and at the same time, the tasks are isolated from each other to avoid mutual interference.

[0108] After obtaining the first model resource data associated with the first user, a first security sandbox corresponding to the first model resource data can be created in the large model service platform. The first security sandbox can be used to perform at least one of the following: encrypting the first model resource data, decrypting the encrypted resource data, and storing the second ciphertext data key and the encrypted resource data. For example, in the first security sandbox, the first model resource data is encrypted using the first data key to obtain the encrypted resource data; the first data key is deleted from the first security sandbox; and the second ciphertext data key and the encrypted resource data are stored in the first security sandbox.

[0109] In other words, data is stored in encrypted form in the first security sandbox. For example, the second ciphertext data key and encrypted resource data are persistently stored on the disk or object storage of the first security sandbox to ensure the storage security of model resource data during the use of the large model service platform.

[0110] Furthermore, a second request to decrypt the data key is sent to the key management service, and the first data key in plaintext is received from the key management service. The second request includes a second ciphertext data key. The encrypted resource data is decrypted using the first data key in plaintext to obtain the first model resource data. The first model resource data is then used to execute the first task.

[0111] The above data decryption process can be executed when the first task associated with the first large model resource data is triggered. Triggering the first task associated with the first large model resource data can be understood as starting the first task or starting to execute the first task. Since the first model resource data in plaintext form is required when executing the first task, the key management service is called based on the second encrypted data key to obtain the first data key. Then, the encrypted data is decrypted using the first data key to obtain the first model resource data in order to execute the first task.

[0112] In some possible implementations, the large model service platform can call the key management service, which, based on the key system proxy, sends the second ciphertext data key to the first user's key management system through the key system proxy. The platform then receives the first ciphertext data key returned by the first user's key management system, decrypts the second ciphertext data key using the second decryption key generated by the first user's key management system, and decrypts the first ciphertext data key using the first decryption key generated by the key management service to obtain the first data key. In this way, the large model service platform can receive the first data key returned by the key management service.

[0113] Furthermore, in the large model service platform, a first security sandbox corresponding to the first model resource data is created. When the first security sandbox stores the second encrypted data key and the encrypted resource data, the first security sandbox can also mount a first file system. In the first security sandbox, the first model resource data mounted on the first file system is used to execute the first task, that is, to decrypt the encrypted resource data using the first data key, mount the obtained first model resource data to the first file system, and use the first model resource data mounted on the first file system to execute the first task.

[0114] In other words, when executing the first task within the first security sandbox, the first security sandbox needs to obtain plaintext first model resource data. For example, the memory of the first security sandbox needs to read plaintext first model resource data. In order to prevent the plaintext first model resource data from being written to the disk of the first security sandbox, the first model resource data is mounted on the first file system (for example, a transparent encrypted file system). The memory of the first security sandbox can access the first model resource data from the first file system to execute the first task. For the task, the above process of reading the first model resource data is completely transparent.

[0115] In this way, the data stored in the first security sandbox is all in encrypted form (the second encrypted data key and encrypted resource data). By mounting the first file system, the encrypted data is decrypted, so that the memory of the first security sandbox can read the plaintext data (the first model resource data). Under the premise of ensuring that the plaintext data only exists in the memory of the first security sandbox and is not persistently stored, the normal execution of the first task is not affected, and the large model service platform is guaranteed to provide large model services normally.

[0116] The following describes the method for protecting artificial intelligence model data provided by one or more embodiments of this disclosure, in conjunction with the specific usage process of the large model service platform.

[0117] The first user uploads training data for large-scale model training to the large-scale model service platform. The large-scale model service platform, acting as the first user, calls the key management service. The key management service generates a first data key and a first encryption key. It then encrypts the first data key once using the first encryption key and forwards the first encrypted data key to the first user's key management system through a key system proxy. The first user's key management system generates a second encryption key and encrypts the first encrypted data key a second time using the second encryption key to obtain the second encrypted data key. The second encrypted data key is then sent to the key management service. The key management service sends the first data key and the second encrypted data key to the first security sandbox of the large-scale model service platform. In the first security sandbox, the first data key is used to encrypt the training data to obtain encrypted resource data. The first data key is then destroyed, and the second encrypted data key and the encrypted resource data are stored in the first security sandbox.

[0118] In response to triggering a task associated with the training data, a first file system is mounted in the first secure sandbox. During the mounting process, the large model service platform calls the key management service. The key management service forwards the second encrypted data key to the first user's key management system through the key system proxy. The first user's key management system decrypts the second encrypted data key once using the second decryption key to obtain the first encrypted data key, and sends the first encrypted data key to the key management service. The key management service decrypts the first encrypted data key a second time using the first decryption key to obtain the first data key, and sends the first data key to the first secure sandbox of the large model service platform. In the first secure sandbox, the encrypted resource data is decrypted using the first data key to obtain the training data. The training data is then mounted in the first file system, enabling the memory of the first secure sandbox to access the training data and execute tasks associated with the training data, such as model training tasks, within the first secure sandbox.

[0119] After completing the task of associating with the training data, the obtained large model parameters (such as weight files) are encrypted using the aforementioned double encryption process and stored in the first security sandbox. Users can also upload inference data used for large model inference to the large model service platform, encrypt it using the aforementioned double encryption process, and store it in the first security sandbox.

[0120] In response to a task triggered by the inference data, the encrypted large model parameters and inference data are decrypted through the aforementioned dual decryption process, and model inference is performed in the first secure sandbox. Thus, data security and transmission security can be ensured throughout the entire service process related to the large model.

[0121] Furthermore, the large-scale model service platform writes all operational data related to the key management service (such as generating and decrypting data keys) to the audit log. Simultaneously, access and operations between the key management service and the key system agent are also recorded in the audit log for the primary user to query and verify. If abnormal behavior is detected in the audit log, such as frequent decryption, key borrowing, unauthorized access, or abnormal secure channel connections, an alarm mechanism can be triggered to promptly notify the primary user and stop the abnormal behavior.

[0122] Based on the key management method provided in at least one embodiment of this disclosure, at least one embodiment of this disclosure also provides a key management device. The following will be combined with... Figure 7 The key management device is described in detail.

[0123] Figure 7 The schematic diagram illustrates the structure of a key management device provided in at least one embodiment of the present disclosure.

[0124] like Figure 7 As shown, the key management device 700 of this embodiment includes an encryption module 701 and a communication module 702. For example, the encryption module 701 and the communication module 702 can be implemented using hardware (e.g., circuit) modules or software modules. The following embodiments are similar and will not be described again. For example, the encryption module 701 and the communication module 702 can be implemented using a central processing unit (CPU), a general-purpose graphics processing unit (GPGPU), a graphics processing unit (GPU), a tensor processor (TPU), a field-programmable gate array (FPGA), or other processing units with data processing capabilities and / or instruction execution capabilities, along with corresponding computer instructions.

[0125] The encryption module 701 is configured to: in response to receiving a first request to generate a data key, obtain a first data key, and encrypt the first data key using the first encryption key to obtain a first ciphertext data key. For example, the encryption module 701 can be configured to execute step S201 described above; its specific implementation principle can be found in the relevant description of step S201, and will not be repeated here.

[0126] The communication module 702 is configured to: send the first ciphertext data key to the key management system of the first user, and receive the second ciphertext data key returned by the key management system of the first user; wherein the second ciphertext data key is obtained by encrypting the first ciphertext data key using the second encryption key in the key management system of the first user. For example, the communication module 702 can be configured to execute step S202 described above; its specific implementation principle can be found in the relevant description of step S202, and will not be repeated here.

[0127] The communication module 702 is also configured to return the first data key and the second ciphertext data key to the requester of the first request. For example, the communication module 702 can be configured to perform step S203 as described above; its specific implementation principle can be found in the relevant description of step S203, and will not be repeated here.

[0128] In at least one embodiment of this disclosure, the communication module 702 is further configured to: send the first ciphertext data key to the key management system of the first user through a key system agent; wherein the key system agent is used to adapt to communication between different key management systems of different users.

[0129] In at least one embodiment of this disclosure, the key management device 700 further includes a decryption module, and the communication module 702 is further configured to: receive a second request to decrypt a data key, wherein the second request includes the second ciphertext data key; send the second ciphertext data key to the key management system of the first user; and receive the first ciphertext data key returned by the key management system of the first user; the decryption module is configured to: decrypt the first ciphertext data key to obtain the first data key in plaintext; and the communication module 702 is further configured to: return the first data key in plaintext to the requester of the second request.

[0130] In at least one embodiment of this disclosure, the communication module 702 is further configured to send the second request to the key management system of the first user through a key system agent, wherein the key system agent is used to adapt to communication between different key management systems of different users.

[0131] In at least one embodiment of this disclosure, the key system agent is used to perform communication protocol conversion so that the converted communication protocol is consistent with the communication protocol used by the receiver.

[0132] In at least one embodiment of this disclosure, the key management device 700 further includes an audit module configured to: generate an audit log, wherein the audit log includes at least one of the following: a process for generating a data key and a process for decrypting a data key; and present the audit log to the first user.

[0133] It should be noted that, for clarity and brevity, at least one embodiment of this disclosure does not show all the constituent units of the key management device 700. To achieve the necessary functions of the key management device 700, those skilled in the art can provide and set other constituent units (not shown) according to specific needs, and one or more embodiments of this disclosure do not limit this.

[0134] Based on the method for protecting artificial intelligence model data provided in at least one embodiment of this disclosure, at least one embodiment of this disclosure also provides an apparatus for protecting artificial intelligence model data. The following will be combined with... Figure 8 The device for protecting artificial intelligence model data is described in detail.

[0135] Figure 8 The illustration shows a schematic diagram of the structure of a device for protecting artificial intelligence model data provided in at least one embodiment of the present disclosure.

[0136] like Figure 8 As shown, the device 800 for protecting artificial intelligence model data in this embodiment includes an acquisition module 801, a communication module 802, an encryption module 803, and a storage module 804. For example, the acquisition module 801, communication module 802, encryption module 803, and storage module 804 can be implemented using hardware (e.g., circuit) modules or software modules. The following embodiments are similar and will not be described again. For example, the acquisition module 801, communication module 802, encryption module 803, and storage module 804 can be implemented using a central processing unit (CPU), a general-purpose graphics processor (GPGPU), a graphics processing unit (GPU), a tensor processor (TPU), a field-programmable gate array (FPGA), or other processing units with data processing capabilities and / or instruction execution capabilities, along with corresponding computer instructions.

[0137] The acquisition module 801 is configured to acquire the first model resource data associated with the first user. For example, the acquisition module 801 can be configured to execute step S601 described above. The specific implementation principle can be found in the relevant description of step S601, and will not be repeated here.

[0138] The communication module 802 is configured to: send a first request to the key management service to generate a data key, and receive a first data key and a second ciphertext data key returned by the key management service; wherein the second ciphertext data key is obtained by encrypting the first data key using a first encryption key generated by the key management service and a second encryption key generated by the key management system of the first user. For example, the communication module 802 can be configured to execute step S602 described above; its specific implementation principle can be found in the relevant description of step S602, and will not be repeated here.

[0139] The encryption module 803 is configured to encrypt the first model resource data using the first data key to obtain encrypted resource data. For example, the encryption module 803 can be configured to execute step S603 as described above; its specific implementation principle can be found in the relevant description of step S603, and will not be repeated here.

[0140] Storage module 804 is configured to: delete the first data key and store the second ciphertext data key and the encrypted resource data. For example, storage module 804 can be configured to execute step S604 described above; its specific implementation principle can be found in the relevant description of step S604, and will not be repeated here.

[0141] In at least one embodiment of this disclosure, the apparatus 800 for protecting artificial intelligence model data further includes an execution module configured to: send a second request to the key management service to decrypt a data key, and receive the first data key in plaintext returned by the key management service, wherein the second request includes the second ciphertext data key; decrypt the encrypted resource data using the first data key in plaintext to obtain the first model resource data; and perform a first task using the first model resource data; wherein the first data key in plaintext is obtained by decrypting the second ciphertext data key through the key management system of the first user and the key management service.

[0142] In at least one embodiment of this disclosure, the apparatus 800 for protecting artificial intelligence model data further includes a creation module configured to: create a first security sandbox corresponding to the first model resource data; wherein the first security sandbox is used to perform at least one of the following: encrypting the first model resource data, decrypting the encrypted resource data, and storing the second ciphertext data key and the encrypted resource data.

[0143] In at least one embodiment of this disclosure, the first security sandbox is mounted with a first file system, and the execution module is further configured to: execute the first task in the first security sandbox using the first model resource data mounted with the first file system.

[0144] It should be noted that, for clarity and brevity, at least one embodiment of this disclosure does not show all the constituent units of the device 800 for protecting artificial intelligence model data. To achieve the necessary functions of the device 800 for protecting artificial intelligence model data, those skilled in the art can provide or set other constituent units (not shown) according to specific needs, and one or more embodiments of this disclosure do not limit this.

[0145] At least one embodiment of this disclosure also provides an electronic device, including a processing device and a storage device, the storage device including one or more computer program modules; wherein the one or more computer program modules are stored in the storage device and configured to be executed by the processing device, the one or more computer program modules being used to implement the key management method or the method for protecting artificial intelligence model data provided in any embodiment of this disclosure.

[0146] For example, the processing device may be a processor, such as a central processing unit (CPU), digital signal processor (DSP), image processor (GPU), general-purpose graphics processor (GPGPU), or other form of processing unit with data processing capabilities and / or instruction execution capabilities. It may be a general-purpose processor or a dedicated processor and may control other components in the electronic device to perform the desired functions.

[0147] For example, the storage device may be a memory, which may include one or more computer program products. These computer program products may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may, for example, include random access memory (RAM) and / or cache memory. The non-volatile memory may, for example, include read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, and a processing device may execute these program instructions to implement the functions (implemented by the processing device) in at least one embodiment of this disclosure and / or other desired functions. Various application programs and various data may also be stored in the computer-readable storage medium, which is not limited by one or more embodiments of this disclosure.

[0148] The following is for reference. Figure 9 The diagram illustrates a structural schematic of an electronic device (e.g., a terminal device or a server) 900 suitable for implementing at least one embodiment of the present disclosure. The terminal device in at least one embodiment of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 9 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of use of at least one embodiment of this disclosure.

[0149] like Figure 9 As shown, electronic device 900 may include a processing device (e.g., a central processing unit, a graphics processor, etc.) 901, which can perform various appropriate actions and processes according to a program stored in read-only memory (ROM) 902 or a program loaded from storage device 908 into random access memory (RAM) 903. RAM 903 also stores various programs and data required for the operation of electronic device 900. Processing device 901, ROM 902, and RAM 903 are interconnected via bus 904. Input / output (I / O) interface 905 is also connected to bus 904.

[0150] Typically, the following devices can be connected to I / O interface 905: input devices 906 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 907 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 908 including, for example, magnetic tapes, hard disks, etc.; and communication devices 909. Communication device 909 allows electronic device 900 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 9 An electronic device 900 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively.

[0151] In particular, according to one or more embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, one or more embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 909, or installed from a storage device 908, or installed from a ROM 902. When the computer program is executed by a processing device 901, it performs the functions defined in the methods of at least one embodiment of this disclosure.

[0152] It should be noted that the computer-readable medium described in this disclosure can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this disclosure, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.

[0153] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol) and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any currently known or future-developed networks.

[0154] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.

[0155] The aforementioned computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to perform the aforementioned key management method or the method for protecting artificial intelligence model data.

[0156] Computer program code for performing the operations of this disclosure can be written in one or more programming languages ​​or a combination thereof, including but not limited to object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0157] One or more embodiments of this disclosure also provide a computer program product comprising one or more computer instructions. When the computer instructions are loaded and executed on a computing device, all or part of the processes or functions described in any embodiment of this disclosure are generated.

[0158] The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, or data center to another website, computer, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means.

[0159] When the computer program product is executed by a computer, the computer performs either the aforementioned key management method or the method for protecting artificial intelligence model data. The computer program product can be a software installation package; when either of the aforementioned key management method or the method for protecting artificial intelligence model data needs to be used, the computer program product can be downloaded and executed on the computer.

[0160] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0161] The units or modules described in at least one embodiment of this disclosure can be implemented in software or hardware. The names of the units or modules do not necessarily limit the specific unit or module itself.

[0162] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), and so on.

[0163] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0164] According to one or more embodiments of this disclosure, Example 1 provides a key management method, including:

[0165] In response to receiving a first request to generate a data key, the system obtains a first data key, encrypts the first data key using a first encryption key, and obtains a first ciphertext data key.

[0166] The first ciphertext data key is sent to the key management system of the first user, and the second ciphertext data key returned by the key management system of the first user is received; wherein the second ciphertext data key is obtained by encrypting the first ciphertext data key using the second encryption key in the key management system of the first user.

[0167] The first data key and the second ciphertext data key are returned to the requester of the first request.

[0168] According to one or more embodiments of this disclosure, Example 2 provides a key management system for sending the first ciphertext data key to a first user, as described in Example 1, including:

[0169] The first ciphertext data key is sent to the key management system of the first user through a key system agent; wherein, the key system agent is used to adapt to communication between different key management systems of different users.

[0170] According to one or more embodiments of this disclosure, Example 3 provides the method of Example 1, further comprising:

[0171] Receive a second request to decrypt the data key, wherein the second request includes the second ciphertext data key;

[0172] Send the second ciphertext data key to the first user's key management system, and receive the first ciphertext data key returned by the first user's key management system;

[0173] Decrypt the first ciphertext data key to obtain the first data key in plaintext;

[0174] The first data key in plaintext is returned to the requester of the second request.

[0175] According to one or more embodiments of this disclosure, Example 4 provides the sending of the second request to the key management system of the first user as in Example 3, including:

[0176] The second request is sent to the first user's key management system through a key system agent, wherein the key system agent is used to adapt to communication between different key management systems of different users.

[0177] According to one or more embodiments of this disclosure, Example 5 provides a key system agent as in Example 2 or Example 4 for performing communication protocol conversion, such that the converted communication protocol is consistent with the communication protocol used by the receiver.

[0178] According to one or more embodiments of this disclosure, Example Six provides the method of Example One, further comprising:

[0179] Generate an audit log, wherein the audit log includes at least one of the following: the process of generating a data key and the process of decrypting a data key;

[0180] The audit logs are presented to the first user.

[0181] According to one or more embodiments of this disclosure, Example 7 provides a method for protecting artificial intelligence model data, including:

[0182] Obtain the first model resource data associated with the first user;

[0183] Send a first request to the key management service to generate a data key, and receive the first data key and the second ciphertext data key returned by the key management service;

[0184] The first model resource data is encrypted using the first data key to obtain encrypted resource data;

[0185] Delete the first data key and store the second ciphertext data key and the encrypted resource data;

[0186] The second encrypted data key is obtained by encrypting the first data key using a first encryption key generated by the key management service and a second encryption key generated by the key management system of the first user.

[0187] According to one or more embodiments of this disclosure, Example 8 provides the method of Example 7, further comprising:

[0188] Send a second request to the key management service to decrypt the data key, and receive the first data key in plaintext returned by the key management service, wherein the second request includes the second ciphertext data key;

[0189] The encrypted resource data is decrypted using the first data key in plaintext to obtain the first model resource data;

[0190] Using the resource data from the first model, execute the first task;

[0191] The first data key in plaintext is obtained by decrypting the second ciphertext data key through the first user's key management system and the key management service.

[0192] According to one or more embodiments of this disclosure, Example 9 provides the method of Example 7, further comprising:

[0193] Create a first security sandbox corresponding to the first model resource data;

[0194] The first security sandbox is used to perform at least one of the following: encrypting the first model resource data, decrypting the encrypted resource data, and storing the second ciphertext data key and the encrypted resource data.

[0195] According to one or more embodiments of this disclosure, Example 10 provides a first security sandbox as in Example 9 mounted with a first file system, wherein the first task is performed using the first model resource data, including:

[0196] Within the first security sandbox, the first task is executed using the first model resource data mounted on the first file system.

[0197] According to one or more embodiments of this disclosure, Example 11 provides a key management apparatus, including:

[0198] The encryption module is configured to: in response to receiving a first request to generate a data key, obtain a first data key, encrypt the first data key using a first encryption key, and obtain a first ciphertext data key;

[0199] The communication module is configured to: send the first ciphertext data key to the key management system of the first user, and receive the second ciphertext data key returned by the key management system of the first user; wherein the second ciphertext data key is obtained by encrypting the first ciphertext data key using the second encryption key in the key management system of the first user;

[0200] The communication module is further configured to return the first data key and the second ciphertext data key to the requester of the first request.

[0201] According to one or more embodiments of this disclosure, Example Twelve provides an apparatus for protecting artificial intelligence model data, comprising:

[0202] The acquisition module is configured to: acquire the first model resource data associated with the first user;

[0203] The communication module is configured to: send a first request to the key management service to generate a data key, and receive a first data key and a second ciphertext data key returned by the key management service;

[0204] The encryption module is configured to: encrypt the first model resource data using the first data key to obtain encrypted resource data;

[0205] The storage module is configured to: delete the first data key and store the second ciphertext data key and the encrypted resource data;

[0206] The second encrypted data key is obtained by encrypting the first data key using a first encryption key generated by the key management service and a second encryption key generated by the key management system of the first user.

[0207] According to one or more embodiments of this disclosure, Example Thirteen provides an electronic device, including:

[0208] Processing device; and

[0209] Storage device, including one or more computer program instructions;

[0210] The one or more computer program instructions are executed by the processing device to perform the key management method or the method for protecting artificial intelligence model data provided in at least one embodiment of the present disclosure.

[0211] According to one or more embodiments of the present disclosure, Example Fourteen provides a computer-readable storage medium that non-transitory stores computer-readable instructions, wherein when the computer-readable instructions are executed by a processor, they implement the key management method or the method for protecting artificial intelligence model data provided in at least one embodiment of the present disclosure.

[0212] The above description is merely a preferred embodiment of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features disclosed in this disclosure that have similar functions.

[0213] Furthermore, while the operations are described in a specific order, this should not be construed as requiring these operations to be performed in the specific order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.

[0214] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative examples of implementing the claims.

Claims

1. A key management method, comprising: In response to receiving a first request to generate a data key, the system obtains a first data key, encrypts the first data key using a first encryption key, and obtains a first ciphertext data key, wherein the first encryption key is generated by a key management service. The first ciphertext data key is sent to the key management system of the first user, and the second ciphertext data key returned by the key management system of the first user is received; wherein the second ciphertext data key is obtained by encrypting the first ciphertext data key using the second encryption key in the key management system of the first user. The first data key and the second ciphertext data key are returned to the requester of the first request, wherein the requester of the first request is used to delete the first data key and retain the second ciphertext data key after encrypting the data using the first data key.

2. The method according to claim 1, wherein, The step of sending the first ciphertext data key to the key management system of the first user includes: The first ciphertext data key is sent to the key management system of the first user through a key system agent; wherein, the key system agent is used to adapt to communication between different key management systems of different users.

3. The method according to claim 1, further comprising: Receive a second request to decrypt the data key, wherein the second request includes the second ciphertext data key; Send the second ciphertext data key to the first user's key management system, and receive the first ciphertext data key returned by the first user's key management system; Decrypt the first ciphertext data key to obtain the first data key in plaintext; The first data key in plaintext is returned to the requester of the second request.

4. The method according to claim 3, wherein, Sending the second request to the key management system of the first user includes: The second request is sent to the first user's key management system through a key system agent, wherein the key system agent is used to adapt to communication between different key management systems of different users.

5. The method according to claim 2 or 4, wherein, The key system agent is used to perform communication protocol conversion, so that the converted communication protocol is consistent with the communication protocol used by the receiver.

6. The method according to claim 1, further comprising: Generate an audit log, wherein the audit log includes at least one of the following: the process of generating a data key and the process of decrypting a data key; The audit logs are presented to the first user.

7. A method for protecting artificial intelligence model data, comprising: Obtain the first model resource data associated with the first user; Send a first request to the key management service to generate a data key, and receive the first data key and the second ciphertext data key returned by the key management service; The first model resource data is encrypted using the first data key to obtain encrypted resource data; Delete the first data key and store the second ciphertext data key and the encrypted resource data; The second ciphertext data key is obtained by first encrypting the first data key with the first encryption key generated by the key management service to obtain the first ciphertext data key, and then encrypting the first ciphertext data key with the second encryption key generated by the key management system of the first user.

8. The method according to claim 7, further comprising: Send a second request to the key management service to decrypt the data key, and receive the first data key in plaintext returned by the key management service, wherein the second request includes the second ciphertext data key; The encrypted resource data is decrypted using the first data key in plaintext to obtain the first model resource data; Utilize the resource data of the first model to execute the first task; The first data key in plaintext is obtained by decrypting the second ciphertext data key through the first user's key management system and the key management service.

9. The method according to claim 7, further comprising: Create a first security sandbox corresponding to the first model resource data; The first security sandbox is used to perform at least one of the following: encrypting the first model resource data, decrypting the encrypted resource data, and storing the second ciphertext data key and the encrypted resource data.

10. The method according to claim 9, wherein, The first security sandbox is mounted with a first file system. The step of using the first model resource data to execute the first task includes: Within the first security sandbox, the first task is executed using the first model resource data mounted on the first file system.

11. A key management device, comprising: The encryption module is configured to: in response to receiving a first request to generate a data key, obtain a first data key, encrypt the first data key using a first encryption key, and obtain a first ciphertext data key, wherein the first encryption key is generated by a key management service; The communication module is configured to: send the first ciphertext data key to the key management system of the first user, and receive the second ciphertext data key returned by the key management system of the first user; wherein the second ciphertext data key is obtained by encrypting the first ciphertext data key using the second encryption key in the key management system of the first user; The communication module is further configured to return the first data key and the second ciphertext data key to the requester of the first request, wherein the requester of the first request is configured to delete the first data key and retain the second ciphertext data key after encrypting the data using the first data key.

12. A device for protecting artificial intelligence model data, comprising: The acquisition module is configured to: acquire the first model resource data associated with the first user; The communication module is configured to: send a first request to the key management service to generate a data key, and receive a first data key and a second ciphertext data key returned by the key management service; The encryption module is configured to: encrypt the first model resource data using the first data key to obtain encrypted resource data; The storage module is configured to: delete the first data key and store the second ciphertext data key and the encrypted resource data; The second ciphertext data key is obtained by first encrypting the first data key with the first encryption key generated by the key management service to obtain the first ciphertext data key, and then encrypting the first ciphertext data key with the second encryption key generated by the key management system of the first user.

13. An electronic device, comprising: Processing device; as well as Storage device, including one or more computer program instructions; Wherein, the one or more computer program instructions are executed by the processing device to perform the method according to any one of claims 1 to 6 or any one of claims 7 to 10.

14. A computer-readable storage medium for non-transitory storage of computer-readable instructions, wherein, When the computer-readable instructions are executed by a processor, the method of any one of claims 1 to 6 or any one of claims 7 to 10 is implemented.

Citation Information

Patent Citations

  • Blockchain-based data cloud storage encryption method and system

    CN109120639A

  • Data processing method and device, readable medium and electronic equipment

    CN117061105A