An artificial intelligence secure running system and method based on a hardware one-way data channel and a network-free kernel
By using a hardware-based unidirectional data channel and a network-free kernel architecture, the risk of data leakage in artificial intelligence systems is resolved, achieving unidirectional and secure data transmission and improving the deployability of high-security application scenarios.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- 吴英杰
- Filing Date
- 2026-03-16
- Publication Date
- 2026-06-02
AI Technical Summary
Existing artificial intelligence systems are at risk of data leakage when transmitting data via network interfaces. Current security isolation technologies rely on the operating system's network protocol stack, which is vulnerable to malicious exploitation.
It adopts an architecture with a hardware unidirectional data channel and no network kernel. The hardware unidirectional data channel ensures the unidirectionality of the data input direction, and the general network communication protocol stack is stripped from the isolated artificial intelligence computing unit to limit the external communication capability.
By restricting network communication at the system architecture level, the one-way transmission of data is ensured, the risk of data leakage is reduced, and the deployability in high-security application scenarios is improved.
Smart Images

Figure CN122137654A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of artificial intelligence security technology, and in particular to an artificial intelligence security operation system and method based on a hardware unidirectional data channel and a network-free kernel. Background Technology
[0002] With the widespread application of artificial intelligence (AI) technology in finance, government affairs, healthcare, and critical infrastructure, a large amount of sensitive data needs to be processed within AI systems. However, existing AI operating environments typically rely on operating systems with full network communication capabilities. During system operation, AI models or related processes may transmit data through network interfaces, posing a potential risk of data leakage. Existing security isolation technologies typically restrict systems through software sandboxes, virtualization containers, or network access control policies, but these technologies still rely on the operating system's own network protocol stack. If the system is improperly configured or maliciously exploited, there is still a risk of data leakage through network channels. Therefore, a secure AI operating system is needed that can restrict the network communication capabilities of the AI operating environment at the system architecture level while ensuring the security of data input. Summary of the Invention
[0003] To address the issue of existing artificial intelligence (AI) systems potentially transmitting data externally via network interfaces, this invention proposes a secure AI operation system and method based on a hardware unidirectional data channel and a network-free kernel. This invention establishes a data access unit, a hardware unidirectional data channel, and an isolated AI computing unit within the system architecture. This ensures that input data can only enter the isolated AI computing unit through the hardware unidirectional data channel, thereby guaranteeing unidirectional data transmission at the physical level. Simultaneously, an operating system kernel stripped of the general network communication protocol stack runs within the isolated AI computing unit, preventing processes running in this environment from actively establishing network connections, thus restricting external communication capabilities at the system kernel level.
[0004] Based on the above structure, this invention also includes a security management terminal for controlling the operation, managing tasks, and acquiring results of the isolated AI computing unit. Control through the management terminal enables unified management and security auditing of AI computing tasks. In a further embodiment, the data access unit can preprocess the input data, including data format conversion, desensitization, or encryption, to improve data security. In a further embodiment, the isolated AI computing unit can construct an independent AI model operating environment, allowing the AI model to perform inference or data processing tasks in an environment without network communication capabilities, thereby avoiding external network access during model operation. In a further embodiment, the isolated AI computing unit can also collaborate with remote computing nodes through a controlled encrypted communication channel to expand the computing power of the AI system while ensuring local security isolation. Through the above technical solutions, this invention can implement network communication restrictions on the AI operating environment at the system architecture level and ensure the unidirectionality of data input through a hardware unidirectional data channel, thereby constructing a secure and reliable AI operating environment, reducing the risk of data leakage, and improving the deployability of the AI system in high-security application scenarios. Attached Figure Description Figure 1 This is a schematic diagram of the overall structure of an artificial intelligence secure operation system based on a hardware unidirectional data channel and a network-free kernel, according to the present invention. Figure 2 This is a schematic diagram illustrating the process of data transmission to the isolated artificial intelligence computing unit via a hardware unidirectional data channel in this invention. Figure 3 This is a schematic diagram illustrating the process by which the security management terminal controls the operation of the isolated artificial intelligence computing unit and acquires the results in this invention.
Claims
1. An artificial intelligence secure operation system, characterized in that, include: The data access unit is used to collect or receive user input data. An isolated artificial intelligence computing unit is used to perform artificial intelligence model calculations; A hardware unidirectional data channel is used to enable unidirectional data transmission from the data access unit to the isolated artificial intelligence computing unit at the physical layer; A security management terminal is used to control the operation of the isolated artificial intelligence computing unit and acquire the results. The isolated artificial intelligence computing unit runs an operating system kernel stripped of the general network communication protocol stack, which prevents processes running in the computing unit from actively establishing external network connections.
2. The artificial intelligence secure operation system according to claim 1, characterized in that: The hardware unidirectional data channel is a unidirectional data transmission device based on an optically isolated structure or a data diode structure.
3. The artificial intelligence secure operation system according to claim 1, characterized in that: The data access unit is used to preprocess the input data, including data format conversion, desensitization, or encryption.
4. The artificial intelligence secure operation system according to claim 1, characterized in that: The security management terminal is used to manage the task initiation, operation status monitoring, and result extraction of the isolated artificial intelligence computing unit.
5. The artificial intelligence safe operation system according to claim 1, characterized in that: The isolated artificial intelligence computing unit is used to construct an isolated artificial intelligence model operating environment, enabling the artificial intelligence model to perform data processing or inference operations in an operating environment without network communication capabilities.
6. The artificial intelligence secure operation system according to claim 1, characterized in that: The isolated artificial intelligence computing unit performs collaborative computing with remote computing nodes through a controlled encrypted communication channel.
7. The artificial intelligence secure operation system according to claim 1, characterized in that: The system also includes a security audit module, which records the execution logs of artificial intelligence computing tasks, data access records, and system operating status information.
8. A method for ensuring the safe operation of artificial intelligence, characterized in that, The system applied to the artificial intelligence safe operation system according to any one of claims 1 to 7 includes the following steps: Collect or receive user input data through the data access unit; The input data is transmitted unidirectionally to the isolated artificial intelligence computing unit via a hardware unidirectional data channel; An artificial intelligence model is run in an isolated artificial intelligence computing unit to process or perform inference operations on the data. The computing unit runs an operating system kernel stripped of the general network communication protocol stack, so that the running process cannot actively establish external network connections. The AI computing tasks are controlled and the computing results are obtained through a security management terminal.
9. The method for secure operation of artificial intelligence according to claim 8, characterized in that: The data is preprocessed by the data access unit before entering the isolated artificial intelligence computing unit.
10. The method for secure operation of artificial intelligence according to claim 8, characterized in that: The isolated artificial intelligence computing unit performs collaborative computing with remote computing nodes through a controlled encrypted communication channel when executing artificial intelligence computing tasks.