A large model security protection system, a large model security protection method and a medium

By deploying multiple trusted execution environments and security barriers within the large AI model, the problems of data leakage and model resource leakage under cloud-based collaborative deployment are solved, achieving dual hardware-level security protection and end-to-end security, ensuring the information security and compliance of the large model.

CN121711199BActive Publication Date: 2026-07-21SHENZHEN CONFIDENTIAL COMPUTING TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHENZHEN CONFIDENTIAL COMPUTING TECH CO LTD
Filing Date
2026-02-24
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

In existing technologies, when large AI models are deployed collaboratively in the cloud, attackers can bypass the trusted execution environment through complex means, leading to data leakage or model resource leakage, posing a serious challenge to the security defense system.

Method used

Deploy multiple trusted execution environments, including a first trusted execution environment and a second trusted execution environment. The first trusted execution environment has a security guard to protect the information security of the large model. The second trusted execution environment has a RAG knowledge base. The security guard detects the prompt words and output results of the large model and performs encrypted transmission and identity authentication under a trusted connection.

Benefits of technology

It achieves dual hardware-level security protection, effectively resisting complex attacks, preventing data and model resource leakage, ensuring end-to-end security, preventing prompt word injection attacks and improper output, and ensuring the security and compliance of data interaction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121711199B_ABST
    Figure CN121711199B_ABST
Patent Text Reader

Abstract

The application discloses a large model security protection system, a large model security protection method and a medium. The large model security protection system is deployed with multiple trusted execution environments including a first trusted execution environment and a second trusted execution environment. The first trusted execution environment and the second trusted execution environment can establish a first trusted connection. The first trusted execution environment is internally deployed with a security protection fence, and the second trusted execution environment is internally deployed with a large model. The security protection fence is used for information security protection of the large model. According to the embodiment of the application, the first trusted execution environment independent of the second trusted execution environment is used for security protection of the large model in the second trusted execution environment, so that dual hardware-level security of security protection and model protection is realized, complex attack means is effectively resisted, and the risk of simultaneous leakage of protection and model resources is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the interdisciplinary fields of artificial intelligence security and trusted computing, and in particular to a large-scale model security protection system, a large-scale model security protection method, and a medium. Background Technology

[0002] With the large-scale application of AI big data models in key areas such as finance, healthcare, and government affairs, attacks targeting these models have exploded, posing a serious challenge to security defense systems and exposing various industries to security risks such as data breaches and loss of control over content security.

[0003] Currently, large-scale AI models are generally deployed and applied using a cloud-based collaborative approach. This involves collaboration between the cloud and the edge to achieve cross-domain data sharing and AI computation between the "terminal and cloud." In this cloud-based collaborative deployment, to protect the privacy of cloud-based AI services, a Trusted Execution Environment (TEE) is deployed on the cloud side. The large-scale AI model is then deployed within the TEE, and the edge accesses the AI ​​model directly by accessing the TEE. While this approach provides a certain level of security for cloud-based AI service privacy, attackers may use sophisticated attack methods to bypass the TEE's protection, leading to the simultaneous leakage of both protection and model resources. For example, some advanced tooltip injection attacks may involve attackers constructing seemingly normal tooltips that actually conceal malicious instructions. When the large-scale model processes these tooltips, it could lead to data leakage or the execution of malicious operations.

[0004] Therefore, existing technologies still need to be improved and enhanced. Summary of the Invention

[0005] The technical problem to be solved by this application is to provide a large-scale model security protection system, a large-scale model security protection method and medium to address the shortcomings of the existing technology.

[0006] To address the aforementioned technical problems, the first aspect of this application provides a large-scale model security protection system, which deploys a multi-trusted execution environment including a first trusted execution environment and a second trusted execution environment. The first trusted execution environment and the second trusted execution environment can establish a first trusted connection. A security protection barrier is deployed within the first trusted execution environment, and a large model is deployed within the second trusted execution environment. The security protection barrier is used to provide information security protection for the large model.

[0007] In the large-scale model security protection system, the first trusted execution environment and the second trusted execution environment in the multi-trusted execution environment are independent of each other and are deployed on the same server or in the same server cluster.

[0008] The large model security protection system, wherein the RAG knowledge base is deployed in the second trusted execution environment, or the multi-trusted execution environment further includes a third trusted execution environment, the third trusted execution environment being connected to the first trusted execution environment and the second trusted execution environment, and a second trusted connection being established with the second trusted execution environment, wherein the RAG knowledge base is deployed in the third trusted execution environment.

[0009] The large model security protection system, wherein the security protection bar is used to perform large model prompt word security detection operations and / or large model output result compliance detection operations, wherein: The security detection operation for the large model prompt words includes: detecting the security and compliance of the encrypted large model prompts sent by the user terminal; The compliance detection operation for the large model output results includes: detecting the compliance of the encrypted large model output results sent by the second trusted execution environment.

[0010] The large model security protection system, wherein the large model prompt word security detection operation specifically includes: receiving a large model prompt in ciphertext form sent by the user terminal, decrypting the large model prompt in ciphertext form to obtain a large model prompt in plaintext form, and performing security detection on the large model prompt in plaintext form to detect the security of the large model prompt.

[0011] The large model security protection system, wherein the compliance detection operation of the large model output result includes: receiving the encrypted large model output result sent by the second trusted execution environment; decrypting the encrypted large model output result to obtain the plaintext large model output result; and performing compliance detection on the plaintext large model output result to detect the compliance of the large model output result.

[0012] The large-scale model security protection system, wherein the security protection barrier is used for encrypted transmission operations, wherein: The encrypted transmission operation includes: encrypting the plaintext output of the large model that has passed the compliance test to obtain the ciphertext output of the large model, and transmitting the ciphertext output of the large model to the user terminal; and / or: encrypting the plaintext prompt of the large model that has passed the security test to obtain the ciphertext prompt, and connecting the plaintext prompt to the second trusted execution environment via the first trusted connection.

[0013] The large-scale model security protection system further includes a security protection barrier used for user authentication and providing remote proof to the user so that the user can remotely verify the first trusted execution environment based on the remote proof, thereby ensuring end-to-end security.

[0014] In the large model security protection system, the second trusted execution environment is further used to perform source verification on the received large model prompt words to ensure that access to the large model is controlled.

[0015] The large model security protection system, wherein the second trusted execution environment is further used to perform large model inference operations, wherein: The large model reasoning operation includes: calling the RAG knowledge base through the large model to realize the reasoning process based on the large model prompts, and obtaining the output result of the large model.

[0016] The large-scale model security protection system, wherein the second trusted execution environment is further used to perform encryption and / or decryption operations, wherein: The decryption operation includes: receiving the encrypted large model prompt sent by the security guard, and decrypting the encrypted large model prompt to obtain the plaintext large model prompt; The encryption operation includes: encrypting the output result of the large model obtained by large model inference to obtain the large model output result in ciphertext form, and sending the large model output in ciphertext form to the security guardrail via the first trusted connection.

[0017] A second aspect of this application provides a method for protecting large models, wherein the method specifically includes: The system receives a large model prompt from the user terminal through the security guardrail in the first trusted execution environment, and then sends the large model prompt to the second trusted execution environment, wherein a trusted connection is established between the first trusted execution environment and the second trusted execution environment. The large model deployed in the second trusted execution environment calls the RAG knowledge base to realize the reasoning process based on the large model prompts to obtain the output result of the large model, and then transmits the output result of the large model to the security guardrail; The output results of the large model are transmitted to the user terminal through the security guard.

[0018] The large model security protection method, before receiving the large model prompt sent by the user terminal through the security protection bar in the first trusted execution environment, further includes: The system performs identity authentication on the user terminal and provides remote proof to the user terminal so that the user terminal can remotely verify the first trusted execution environment based on the remote proof, thereby ensuring end-to-end security.

[0019] The large model security protection method, wherein the large model prompt sent by the user terminal is in encrypted form, and the step of sending the large model prompt to the second trusted execution environment specifically includes: Decrypting the ciphertext of the large model hint yields the plaintext version of the large model hint; The security of large model prompts in plaintext form is detected, wherein the security includes at least one of prompt word injection security, DDoS attack security, and malicious file embedding security; When the security check passes, the plaintext large model hint is encrypted to obtain the ciphertext large model hint, and the ciphertext large model hint is sent to the second trusted execution environment.

[0020] The large model security protection method, wherein the large model output result transmitted in the second trusted execution environment is in encrypted form; the transmission of the large model output result to the user terminal through the security protection barrier specifically includes: Decrypting the ciphertext output of the large model yields the plaintext output. The compliance of the output results of a large model in plaintext format is checked, wherein the compliance includes at least one of the following: anonymization compliance, false information compliance, and illegal information compliance. When the compliance check is passed, the plaintext output of the large model is encrypted to obtain the ciphertext output of the large model, and the ciphertext output of the large model is sent to the user terminal.

[0021] The large model security protection method, wherein after the large model deployed in the second trusted execution environment calls the RAG knowledge base to implement the reasoning process based on the large model prompts to obtain the large model output result, the method further includes: The source of the large model hint is verified by a second trusted execution environment to ensure that the large model in the second trusted execution environment can only be accessed by the first trusted execution environment. Once the source verification is successful, the operation of calling the RAG knowledge base through the large model deployed in the second trusted execution environment to implement the reasoning process based on the large model prompts in order to obtain the output results of the large model is executed.

[0022] A third aspect of this application provides a computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to perform the large-scale security protection method described above.

[0023] Beneficial effects: 1. This application deploys two independent trusted execution environments, a first trusted execution environment and a second trusted execution environment, and uses the first trusted execution environment to protect the large model in the second trusted execution environment. This achieves dual hardware-level security for both security protection and model protection, effectively resisting complex attack methods and avoiding the risk of simultaneous leakage of protection and model resources.

[0024] 2. This application uses a security protection bar to perform security detection on large model prompt words, which can identify and block prompt words that hide malicious instructions, thereby reducing the possibility of prompt word injection attacks, DDoS attacks and malicious file attacks from the source.

[0025] 3. This application uses a security guard to perform compliance checks on the output results of large models, which can promptly detect non-compliant content in the output of large models, such as the leakage of sensitive information, expressions that violate laws, regulations or ethical guidelines, etc., effectively avoiding security problems caused to users by improper output of large models.

[0026] 4. This application uses dual protection of identity authentication and remote verification to determine the trustworthiness of the trusted execution environment. Combined with encrypted communication between the user terminal and the first trusted execution environment, as well as between the first trusted execution environment and the second trusted execution environment, it achieves end-to-end security, ensuring the security of data interaction between the terminal and the cloud, as well as the security of data interaction between the first trusted execution environment and the second trusted execution environment, and preventing data from being stolen or tampered with during transmission.

[0027] 5. This application verifies the source of the large model hints through a second trusted execution environment, ensuring that only the first trusted execution environment can access the large model and the RAG knowledge base. Combined with the trusted execution environment-level encrypted storage of the RAG knowledge base, this effectively prevents the leakage of knowledge resources. Attached Figure Description

[0028] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0029] Figure 1 A schematic diagram of the large-scale model security protection system provided in the embodiments of this application.

[0030] Figure 2 A flowchart illustrating the principle of a specific example of a large-scale model security protection system provided in this application embodiment.

[0031] Figure 3 A flowchart of a large-model security protection method provided in an embodiment of this application. Detailed Implementation

[0032] This application provides a large-scale model security protection system, a large-scale model security protection method, and a medium. To make the objectives, technical solutions, and effects of this application clearer and more explicit, the following detailed description is provided with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only for explaining this application and are not intended to limit this application.

[0033] Those skilled in the art will understand that, unless specifically stated otherwise, the singular forms “a,” “an,” “the,” and “the” used herein may also include the plural forms. It should be further understood that the term “comprising” as used in this application means the presence of the stated features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. It should be understood that when we say an element is “connected” or “coupled” to another element, it can be directly connected or coupled to the other element, or there may be intermediate elements. Furthermore, “connected” or “coupled” as used herein can include wireless connections or wireless coupling. The term “and / or” as used herein includes all or any units and all combinations of one or more associated listed items.

[0034] It will be understood by those skilled in the art that, unless otherwise defined, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains. It should also be understood that terms such as those defined in general dictionaries should be understood to have the same meaning as in the context of the prior art, and should not be interpreted in an idealized or overly formal sense unless specifically defined as herein.

[0035] It should be understood that the sequence number and size of each step in this embodiment do not imply the order of execution. The execution order of each process is determined by its function and internal logic, and should not constitute any limitation on the implementation process of this application embodiment.

[0036] Research has revealed that with the large-scale application of AI big data models in key sectors such as finance, healthcare, and government, attacks targeting these models are growing explosively, posing a serious challenge to security defense systems and exposing various industries to security risks such as data breaches and loss of control over content security.

[0037] Currently, large-scale AI models are generally deployed and applied using a cloud-based collaborative approach. This involves collaboration between the cloud and the edge to achieve cross-domain data sharing and AI computation between the "terminal and cloud." In this cloud-based collaborative deployment approach, to ensure privacy protection for cloud-based AI services, a Trusted Execution Environment (TEE) solution is employed on the cloud side to provide a certain level of security for cloud-based AI service privacy. For example, a secure execution domain (such as Intel SGX, AMDSEV, and ARM TrustZone) is constructed in the cloud, logically isolated from the general computing environment, to provide security protection for the large-scale AI model.

[0038] However, with the diversification of attack methods and approaches, simply building a secure execution domain in the cloud that is logically isolated from the general computing environment is insufficient to ensure the security of large AI models and the RAG knowledge base they use. For example, attackers might construct seemingly normal prompts that actually conceal malicious instructions. When the large model processes these prompts, it could lead to data leakage or the execution of malicious operations. Alternatively, attackers could attack the RAG knowledge base used by the large AI model to steal knowledge resources, or they could attack the secure execution domain that is logically isolated from the general computing environment to disrupt the trusted execution environment, causing the large AI model to run in an untrusted space.

[0039] To address this, this application provides a large-model security protection system. This system deploys multiple trusted execution environments, including a first trusted execution environment and a second trusted execution environment. The first trusted execution environment and the second trusted execution environment can establish a first trusted connection. A security protection barrier is deployed within the first trusted execution environment, and a large model is deployed within the second trusted execution environment. The security protection barrier is used to provide information security protection for the large model. This application achieves dual hardware-level security—both security protection and model protection—by using a first trusted execution environment independent of the second trusted execution environment to protect the large model in the second trusted execution environment. This effectively resists complex attack methods and avoids the risk of simultaneous leakage of both protection and model resources.

[0040] The application content will be further explained below with reference to the accompanying drawings and the description of the embodiments.

[0041] This embodiment provides a large-scale model security protection system, such as Figure 1As shown, the large-scale model security protection system is deployed with multiple trusted execution environments, including a first trusted execution environment and a second trusted execution environment, forming at least a dual-trusted execution environment isolation architecture. The first trusted execution environment deploys a security guardrail, while the second trusted execution environment deploys the large model. The first trusted execution environment provides TEE-level protection for the security guardrail, and the second trusted execution environment provides TEE-level protection for the large model. The security guardrail is used for information security protection of the large model. Thus, through the first and second trusted execution environments, dual hardware-level protection of the large model—both information protection and model protection—is achieved, effectively resisting complex attack methods and improving the security of the large model.

[0042] Specifically, the first trusted execution environment (TEX) protects the security guardrail, while the security guardrail and the second trusted execution environment protect the large model. The first TEX serves as the first level of hardware-level protection, providing hardware protection for the security guardrail. The security guardrail, as the first line of defense, protects the large model prompts (i.e., access requests) and outputs from the user, effectively preventing malicious users or external attacks from attempting to bypass the security mechanism and directly access the second TEX. This ensures the security of the data and system within the second TEX. The second TEX serves as the second level of hardware-level protection, providing hardware protection for the large model. Thus, by combining the first TEX, second TEX, and security guardrail, not only is dual hardware-level protection achieved, but also security protection is provided for large model prompts and outputs, comprehensively ensuring the safe and stable operation of the large model.

[0043] The aforementioned first and second trusted execution environments can have various deployment relationships. In one embodiment, the first and second trusted execution environments can be independent of each other. For example, two independent first and second trusted execution environments can be built in the cloud using hardware trusted roots such as SPU / Intel TDX / AMD SEV. In another embodiment, the second trusted execution environment is deployed within the first trusted execution environment. For example, the first trusted execution environment is first built in the cloud using hardware trusted roots such as SPU / Intel TDX / AMD SEV, and then the second trusted execution environment is built within the first trusted execution environment using hardware trusted roots such as SPU / Intel TDX / AMD SEV. That is, a security barrier and the second trusted execution environment are deployed within the first trusted execution environment.

[0044] When the first trusted execution environment and the second trusted execution environment are independent of each other, they can be deployed on the same server or in the same service cluster. When the second trusted execution environment is deployed within the first trusted execution environment, both can be deployed on the same server. For example, ... Figure 2 As shown, the cloud deploys a multi-trusted execution environment, including a first trusted execution environment and a second trusted execution environment, and the first trusted execution environment and the second trusted execution environment are independent of each other.

[0045] Furthermore, to achieve secure communication between the first trusted execution environment (TEX) and the second trusted execution environment (TEX), a first trusted connection is established between them. The process for establishing this first trusted connection can be as follows: First, a remote verification server is started to remotely verify both the first and second TEXs. After both TEXs pass remote verification, they are started, and a first trusted connection is established between them through a hardware-encrypted channel, ensuring secure and reliable data interaction between them. The remote verification can be used to verify the environmental integrity, component legitimacy, and configuration correctness of both TEXs, ensuring that both are in a trusted state and guaranteeing the security of data interaction from the source.

[0046] Furthermore, during the reasoning process using the large model, the large model utilizes the RAG knowledge base, which stores a large amount of knowledge related to the large model's reasoning, assisting the large model in generating more accurate and comprehensive answers. To ensure the security of the RAG knowledge base, this application embodiment implements TEE-level protection for the RAG knowledge base used by the large model, enabling the RAG knowledge base to be isolated from untrusted execution environments and preventing attackers from directly attacking it or stealing its knowledge resources.

[0047] TEE-level protection for the RAG knowledge base can be achieved in several ways. For example, the RAG knowledge base can be deployed within a second trusted execution environment (TEX). Deploying it within the second TEX allows direct access to the RAG knowledge base within that environment, thus providing TEE-level protection for both the large model and the RAG knowledge base used by it. Another example is deploying a third trusted execution environment within a multi-TEX environment. The RAG knowledge base can be deployed in the third TEX, and a second trusted connection can be established between the second and third TEXs. The large model deployed in the second TEX can then access the RAG knowledge base deployed in the third TEX through this second trusted connection. This achieves both independent TEE-level protection for the RAG knowledge base and ensures secure transmission of the RAG knowledge base. Furthermore, the process for establishing the second trusted connection is the same as that for the first trusted connection, and will not be elaborated upon here.

[0048] Furthermore, to further enhance the security of the RAG knowledge base, it can be stored in encrypted form (such as ciphertext vectors, symmetric encryption, etc.). For example, the RAG knowledge base can be stored in encrypted form in a second trusted execution environment. When a large model needs to access knowledge resources from the RAG knowledge base, the encrypted RAG knowledge base is stored in the second trusted execution environment, allowing the large model to retrieve knowledge resources in plaintext. Alternatively, the RAG knowledge base can be stored in encrypted form in a third trusted execution environment. When a large model needs to access knowledge resources from the RAG knowledge base, it first reads the encrypted RAG knowledge base through a second trusted connection, and then stores the encrypted RAG knowledge base in the second trusted execution environment, allowing the large model to retrieve knowledge resources in plaintext. Moreover, after the large model finishes its access, the plaintext knowledge resources are automatically deleted to prevent residual leakage. In other words, the RAG knowledge base is only decrypted and presented in plaintext form in the second trusted execution environment, and the plaintext knowledge resources in the RAG knowledge base are cleaned up after the large model finishes its access.

[0049] In one embodiment, the security protection bar protects the large model by performing security checks on the large model prompts and / or compliance checks on the large model output results. In other words, the security protection bar is used to perform security checks on the large model prompts and / or compliance checks on the large model output results.

[0050] The large model prompt word security detection operation is used to check the security and compliance of large model prompts sent by the user. To this end, the large model prompt word security detection operation includes checking the security and compliance of the large model prompts sent by the user, where security includes at least one of prompt word injection security, DDoS attack security, and malicious file embedding security. Specifically, prompt word injection security detection checks whether there are maliciously constructed prompt words in the large model prompts that attempt to bypass security mechanisms to perform unexpected operations. For example, an attacker might embed specific code in the prompt words to exploit the processing logic of the large model and obtain sensitive information from the database. DDoS attack security detection determines whether the large model prompt is part of a denial-of-service (DDoS) attack. For example, a large number of similar prompts from the same IP address within a short period of time may be an indication of a DDoS attack. Malicious file embedding security detection checks whether the large model prompt contains malicious files. For example, for prompts containing compressed files, the compressed files will be decompressed and security checked first.

[0051] Compliance includes at least one of the following: anonymization compliance, misinformation compliance, and violation compliance. Specifically, anonymization compliance checks whether the large model prompts contain sensitive information (such as personal privacy, trade secrets, etc.). If the large model prompts contain sensitive user data, it may lead to serious legal consequences and a crisis of trust. For example, in a medical consultation scenario, large model prompts may contain sensitive content such as the patient's specific personal information and diagnosis results. Misinformation compliance checks the accuracy and logic of the large model prompts. For example, in mathematical calculation problems, the problems in the large model prompts are verified to ensure their correctness. Violation compliance checks whether the large model prompts comply with ethical and moral standards. For example, large model prompts may contain biased or discriminatory statements.

[0052] This application embodiment performs these security checks on large model prompts using a security guard bar, effectively blocking malicious requests, preventing large models from being subjected to potential security threats, and ensuring system stability and data security. Furthermore, to further enhance security, the security guard bar will regularly update its detection rules and algorithms to cope with constantly evolving attack methods.

[0053] The large model output compliance check operation is used to check the compliance of the large model output results. This operation includes checking the compliance of the encrypted large model output results sent by the second trusted execution environment, where the compliance is the same as the compliance indicated by the large model. This embodiment of the application uses a security guard to perform compliance checks on the large model output results, ensuring the quality of information provided by the large model, protecting the legitimate rights and interests of users, avoiding various risks and problems caused by improper output, and enabling the large model to operate within a safe and reliable framework.

[0054] Furthermore, secure communication between the user terminal and the cloud is crucial when protecting large-scale models. To ensure the security of data interaction between the user terminal and the cloud, user terminal authentication and remote verification of the cloud can be performed before communication between the user terminal and the cloud to ensure end-to-end security. Therefore, the security protection barrier is also used to authenticate the user terminal and provide remote proof to the user terminal so that the user terminal can remotely verify the first trusted execution environment based on the remote proof. Authentication is used to confirm the legitimacy of the user terminal's identity, preventing unauthorized users from accessing the system. For example, authentication can be performed using usernames, passwords, digital certificates, etc. Only authenticated users can communicate with the cloud. Remote verification is used to verify the trustworthiness of the first trusted execution environment, ensuring it is operating securely and compliantly.

[0055] Specifically, when a user initiates a communication request with the cloud, the security barrier requires the user to provide identity information and verifies this information. If the identity authentication is successful, the security barrier generates a remote certificate containing relevant information about the first trusted execution environment, such as hardware configuration, software version, and running status. After receiving the remote certificate, the user verifies the first trusted execution environment remotely through a remote verification server, and establishes a secure communication channel with the cloud after successful remote verification.

[0056] Furthermore, to enhance the security of communication between the client and the cloud, a secure communication channel is established between the cloud and the first trusted execution environment. This channel can be established using encryption technologies, such as SSL / TLS protocols to encrypt data transmission, preventing data from being stolen or tampered with during transmission. Simultaneously, the first trusted connection between the first and second trusted execution environments can also employ encrypted transmission, for example, using SSL / TLS protocols to encrypt data transmission.

[0057] Therefore, when the user client sends a large model hint to the first trusted execution environment, it first encrypts the large model hint and then sends the ciphertext version of the large model hint to the first trusted execution environment. Upon receiving the ciphertext version of the large model hint, the first trusted execution environment decrypts it to obtain the plaintext version of the large model hint, and then performs a security check on the plaintext version of the large model hint. Specifically, the large model hint security check operation includes: receiving the ciphertext version of the large model hint sent by the user client, decrypting the ciphertext version of the large model hint to obtain the plaintext version of the large model hint, and performing a security check on the plaintext version of the large model hint to verify its security.

[0058] Similarly, after the large model completes inference and generates its output in the second trusted execution environment, the second trusted execution environment encrypts the output to form a ciphertext output and sends this ciphertext output to the first trusted execution environment. Upon receiving the ciphertext output, the first trusted execution environment decrypts it to obtain the plaintext output, and then performs a compliance check on the plaintext output. Therefore, the compliance check operation specifically includes: receiving the ciphertext output from the second trusted execution environment; decrypting the ciphertext output to obtain the plaintext output; and performing a compliance check on the plaintext output to verify its compliance.

[0059] Furthermore, since encrypted transmission is used between the user terminal and the first trusted execution environment, and between the first trusted execution environment and the second trusted execution environment, the security guard bar, after performing a security check on the plaintext large model prompt, encrypts the plaintext large model prompt that passes the check. Simultaneously, after performing a compliance check on the plaintext large model output result, it also encrypts the plaintext large model output result that passes the compliance check. Therefore, the security guard bar is used for encrypted transmission operations, wherein the encrypted transmission operations include encrypting the plaintext large model output result that passes the compliance check to obtain an ciphertext large model output result, and transmitting the ciphertext large model output result to the user terminal; and / or; encrypting the plaintext large model prompt that passes the security check to obtain an ciphertext large model prompt, and connecting the plaintext large model prompt to the second trusted execution environment.

[0060] Furthermore, to further enhance the security of the large model and RAG knowledge base, the second trusted execution environment (TEX), upon receiving a large model hint, verifies the data source of the hint to ensure that only the first trusted execution environment (TEX) can access the large model and RAG knowledge base within the TEX. To this end, the second TEX also performs source verification on the received large model hint words to ensure controlled access to the large model. Specifically, when the second TEX receives an access request carrying a large model hint, it checks whether the requester is the first trusted execution environment. If the requester is the first trusted execution environment, access to the large model and RAG knowledge base is allowed; otherwise, the access request is rejected. This source verification mechanism effectively prevents unauthorized access, further ensuring the security of the large model and RAG knowledge base.

[0061] Meanwhile, to address potential anomalies, the second trusted execution environment can be configured with an emergency handling mechanism. When the second trusted execution environment detects an abnormal access request during source verification or encounters an error while processing large model prompts, it immediately triggers the emergency handling mechanism for handling. For example, the large model security protection system records detailed information about the abnormal event, including the requester's identity, request time, and anomaly type, and promptly sends an alert to the system administrator, notifying them to take appropriate measures, such as temporarily closing relevant interfaces or conducting a comprehensive check of the large model security protection system.

[0062] Of course, in practical applications, the number of trusted execution environments can be expanded according to actual needs. For example, a list of trusted access requesters can be pre-configured in the second trusted execution environment. This list can be configured with multiple trusted execution environments, each used to handle different types of tasks or store different levels of sensitive information. Then, upon receiving an access request, the requester is verified based on this list of trusted access requesters to perform source verification on the received large model hints.

[0063] In summary, this embodiment provides a large-model security protection system. This system deploys multiple trusted execution environments, including a first trusted execution environment and a second trusted execution environment. The first trusted execution environment and the second trusted execution environment can establish a first trusted connection. A security protection barrier is deployed within the first trusted execution environment, and a large model is deployed within the second trusted execution environment. The security protection barrier is used to provide information security protection for the large model. This embodiment achieves dual hardware-level security—both security protection and model protection—by using a first trusted execution environment independent of the second trusted execution environment to protect the large model within the second trusted execution environment. This effectively resists complex attack methods and avoids the risk of simultaneous leakage of both protection and model resources.

[0064] Based on the aforementioned large model security protection system, this embodiment provides a large model security protection method, such as... Figure 3 As shown, the large-scale model security protection method specifically includes: S10. Receive a large model prompt sent by the user terminal through the security guard bar in the first trusted execution environment, and send the large model prompt to the second trusted execution environment, wherein a trusted connection is established between the first trusted execution environment and the second trusted execution environment; S20. The large model deployed in the second trusted execution environment calls the RAG knowledge base to realize the reasoning process based on the large model prompts to obtain the output result of the large model, and transmits the output result of the large model to the security guardrail. S30. The output result of the large model is transmitted to the user terminal through the security guardrail.

[0065] The large model security protection method, before receiving the large model prompt sent by the user terminal through the security protection bar in the first trusted execution environment, further includes: The system performs identity authentication on the user terminal and provides remote proof to the user terminal so that the user terminal can remotely verify the first trusted execution environment based on the remote proof, thereby ensuring end-to-end security.

[0066] The large model security protection method, wherein the large model prompt sent by the user terminal is in encrypted form, and the step of sending the large model prompt to the second trusted execution environment specifically includes: Decrypting the ciphertext of the large model hint yields the plaintext version of the large model hint; The security of large model prompts in plaintext form is detected, wherein the security includes at least one of prompt word injection security, DDoS attack security, and malicious file embedding security; When the security check passes, the plaintext large model hint is encrypted to obtain the ciphertext large model hint, and the ciphertext large model hint is sent to the second trusted execution environment.

[0067] The large model security protection method, wherein the large model output result transmitted in the second trusted execution environment is in encrypted form; the transmission of the large model output result to the user terminal through the security protection barrier specifically includes: Decrypting the ciphertext output of the large model yields the plaintext output. The compliance of the output results of a large model in plaintext format is checked, wherein the compliance includes at least one of the following: anonymization compliance, false information compliance, and illegal information compliance. When the compliance check is passed, the plaintext output of the large model is encrypted to obtain the ciphertext output of the large model, and the ciphertext output of the large model is sent to the user terminal.

[0068] The large model security protection method, wherein after the large model deployed in the second trusted execution environment calls the RAG knowledge base to implement the reasoning process based on the large model prompts to obtain the large model output result, the method further includes: The source of the large model hint is verified by a second trusted execution environment to ensure that the large model in the second trusted execution environment can only be accessed by the first trusted execution environment. Once the source verification is successful, the operation of calling the RAG knowledge base through the large model deployed in the second trusted execution environment to implement the reasoning process based on the large model prompts in order to obtain the output results of the large model is executed.

[0069] This embodiment provides a computer-readable storage medium storing one or more programs that can be executed by one or more processors to implement the steps in the large model security protection method described in the above embodiment.

[0070] This application also provides a server on which the above-mentioned large-scale model security protection system is deployed.

[0071] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A large-scale model security protection system, characterized in that, The system deploys a multi-trusted execution environment, including a first trusted execution environment and a second trusted execution environment. The first trusted execution environment establishes a first trusted connection with the second trusted execution environment and uses encrypted transmission. The first trusted execution environment has a security guardrail deployed within it, while the second trusted execution environment has a large model deployed within it. The security guardrail is used to protect the information security of the large model. The first trusted execution environment and the second trusted execution environment within the multi-trusted execution environment are independent of each other and deployed on the same server or in the same server cluster. The second trusted execution environment is used to verify the source of received large model prompts to ensure that access to the large model is controlled so that only the first trusted execution environment can access the large model deployed in the second trusted execution environment, and to perform encryption and / or decryption operations. The decryption operation includes: receiving the encrypted large model prompt sent by the security guard, and decrypting the encrypted large model prompt to obtain the plaintext large model prompt; The encryption operation includes: encrypting the output result of the large model obtained by large model inference to obtain the large model output result in ciphertext form, and sending the large model output result in ciphertext form to the security guardrail via the first trusted connection.

2. The large-scale model security protection system according to claim 1, characterized in that, The second trusted execution environment has a RAG knowledge base deployed within it. Alternatively, the multi-trusted execution environment may further include a third trusted execution environment, which establishes a second trusted connection with the second trusted execution environment, and the third trusted execution environment has a RAG knowledge base deployed within it.

3. The large-scale model security protection system according to claim 1, characterized in that, The safety guardrail is used to perform large model prompt safety detection operations and / or large model output result compliance detection operations, wherein: The large model prompt security detection operation includes: detecting the security and compliance of the encrypted large model prompt sent by the user terminal; The compliance detection operation for the large model output results includes: detecting the compliance of the encrypted large model output results sent by the second trusted execution environment.

4. The large model security protection system according to claim 3, characterized in that, The security detection operation of the large model hint specifically includes: receiving a large model hint in ciphertext form sent by the user terminal, decrypting the large model hint in ciphertext form to obtain a large model hint in plaintext form, and performing a security detection on the large model hint in plaintext form to detect the security of the large model hint.

5. The large model security protection system according to claim 3, characterized in that, The compliance detection operation of the large model output result includes: receiving the encrypted large model output result sent by the second trusted execution environment; decrypting the encrypted large model output result to obtain the plaintext large model output result; and performing compliance detection on the plaintext large model output result to detect the compliance of the large model output result.

6. The large model security protection system according to any one of claims 3-5, characterized in that, The security guard is used to encrypt transmission operations, wherein: The encrypted transmission operation includes: encrypting the plaintext output of the large model that has passed the compliance test to obtain the ciphertext output of the large model, and transmitting the ciphertext output of the large model to the user terminal; and / or: encrypting the plaintext prompt of the large model that has passed the security test to obtain the ciphertext prompt of the large model, and sending the ciphertext prompt of the large model to the second trusted execution environment via the first trusted connection.

7. The large-scale model security protection system according to claim 1, characterized in that, The security barrier is also used to authenticate the user terminal and provide remote proof to the user terminal so that the user terminal can remotely verify the first trusted execution environment based on the remote proof, thereby ensuring end-to-end security.

8. The large-scale model security protection system according to claim 1, characterized in that, The second trusted execution environment is also used to perform large model inference operations, wherein: The large model reasoning operation includes: calling the RAG knowledge base through the large model to realize the reasoning process based on the large model prompts, and obtaining the output result of the large model.

9. A method for protecting the security of large models, characterized in that, The large-model security protection method specifically includes: The system receives a large model prompt from the user terminal through the security guard bar in the first trusted execution environment, and then sends the large model prompt to the second trusted execution environment. The first trusted execution environment and the second trusted execution environment establish a first trusted connection and use encrypted transmission. The first trusted execution environment and the second trusted execution environment are independent of each other and are deployed on the same server or in the same server cluster. The large model deployed in the second trusted execution environment calls the RAG knowledge base to realize the reasoning process based on the large model prompts to obtain the output result of the large model, and then transmits the output result of the large model to the security guardrail; The output results of the large model are transmitted to the user terminal through the security guardrail. The second trusted execution environment is used to perform source verification on the received large model prompt to ensure that access to the large model is controlled so that only the first trusted execution environment can access the large model deployed within the second trusted execution environment, and to perform encryption and / or decryption operations, wherein: The decryption operation includes: receiving the encrypted large model prompt sent by the security guard, and decrypting the encrypted large model prompt to obtain the plaintext large model prompt; The encryption operation includes: encrypting the output result of the large model obtained by large model inference to obtain the large model output result in ciphertext form, and sending the large model output result in ciphertext form to the security guardrail via the first trusted connection.

10. The large-scale model security protection method according to claim 9, characterized in that, Before receiving the large model prompt sent by the user client through the security guardrail in the first trusted execution environment, the method further includes: The system performs identity authentication on the user terminal and provides remote proof to the user terminal so that the user terminal can remotely verify the first trusted execution environment based on the remote proof, thereby ensuring end-to-end security.

11. The large-scale model security protection method according to claim 10, characterized in that, The step of sending the large model hint from the user terminal in encrypted form, specifically including: Decrypting the ciphertext of the large model hint yields the plaintext version of the large model hint; The security of large model prompts in plaintext form is detected, wherein the security includes at least one of prompt word injection security, DDoS attack security, and malicious file embedding security; When the security check passes, the plaintext large model hint is encrypted to obtain the ciphertext large model hint, and the ciphertext large model hint is sent to the second trusted execution environment.

12. The large-scale model security protection method according to claim 9, characterized in that, The output of the large model transmitted in the second trusted execution environment is in encrypted form; the transmission of the large model output to the user terminal through the security barrier specifically includes: Decrypting the ciphertext output of the large model yields the plaintext output. The compliance of the output results of a large model in plaintext format is checked, wherein the compliance includes at least one of the following: anonymization compliance, false information compliance, and illegal information compliance. When the compliance check is passed, the plaintext output of the large model is encrypted to obtain the ciphertext output of the large model, and the ciphertext output of the large model is sent to the user terminal.

13. The large model security protection method according to claim 9, characterized in that, After the method describes implementing a large model-based reasoning process using the RAG knowledge base deployed in the second trusted execution environment to obtain the large model output, the method further includes: The source of the large model hint is verified by a second trusted execution environment to ensure that the large model in the second trusted execution environment can only be accessed by the first trusted execution environment. Once the source verification is successful, the operation of calling the RAG knowledge base through the large model deployed in the second trusted execution environment to implement the reasoning process based on the large model prompts in order to obtain the output results of the large model is executed.

14. A computer-readable storage medium, characterized in that, It stores a computer program, which, when executed in a computer, implements the large model security protection method as described in any one of claims 9-13.

Citation Information

Patent Citations

  • Large model data protection method and device based on trusted environment, equipment and medium

    CN120850332A

  • Large model gateway security protection system and security protection method

    CN120951390A

  • End-cloud collaborative large model secret state operation method and system

    CN121077669A