一种基于可信执行环境的智能体安全防护装置、方法及终端

By using an intelligent agent security protection device based on a trusted execution environment, hardware-level isolation and full lifecycle management of agents are achieved, solving the problems of insufficient hardware-level isolation and easy tampering of management rules in existing technologies. It is suitable for multiple industry scenarios and has high security and low deployment cost.

CN122113125BActive Publication Date: 2026-07-17SHENZHEN CONFIDENTIAL COMPUTING TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHENZHEN CONFIDENTIAL COMPUTING TECH CO LTD
Filing Date
2026-04-28
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing agent security protection solutions lack hardware-level isolation capabilities, their control rules are easily tampered with, they cannot achieve trusted protection throughout the entire lifecycle, and their adaptability and security are insufficient, making it difficult to resist advanced attacks and unauthorized access.

Method used

An intelligent agent security protection device based on a trusted execution environment is adopted, including a general-purpose chip module, a security protection module, and a remote verification server module. An independent trusted execution environment is built through hardware-level isolation, and the entire process is controlled by security chips and computing chips. This achieves hardware-level isolation and behavior control of the intelligent agent, and full-link verification is performed by combining a remote verification mechanism.

Benefits of technology

It achieves hardware-level isolation and behavior control throughout the entire lifecycle of the Agent, prevents tampering with the control logic, adapts to the needs of multiple industry scenarios, resists advanced attacks and unauthorized access, ensures security and business availability, and reduces deployment costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122113125B_ABST
    Figure CN122113125B_ABST
Patent Text Reader

Abstract

本发明公开了一种基于可信执行环境的智能体安全防护装置、方法及终端,所述装置包括:通用芯片模块、安全防护模块以及远程验证服务器模块。通用芯片模块用于对接用户侧宿主业务系统。安全防护模块通过硬件级隔离技术构建可信执行环境,安全防护模块包括安全芯片与计算芯片。远程验证服务器模块与安全芯片通过国密加密算法建立加密可信通信链路,并仅对用户发起的验证请求做出响应。本发明通过计算芯片内置管控执行、安全芯片硬件级度量防篡改的协同机制,实现智能体运行环境的硬件级隔离、操作行为的精细化管控、全流程的可信验证,全面抵御智能体越权操作、环境篡改、非法访问、行为失控等全场景安全风险。
Need to check novelty before this filing date? Find Prior Art