Artificial intelligence reverse osmosis global data security coupling protection system based on hardware timing constraints
Patent Information
- Application Number
- CN202611241996.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-08-17
- Publication Date
- 2026-09-29
AI Technical Summary
[0007]本发明的主要目的在于提供基于硬件时序约束的AI反渗透全域数据安全耦合防护系统,解决现有反AI渗透防护方案存储防护薄弱、分片报文识别漏判、密钥无硬件时空绑定、软硬件可拆分复刻、业务明文残留、跨库关联存在泄露风险等缺陷
1、多库物理隔离分项存储,底层阻断完整数据泄露风险:
Smart Images

Figure CN122839449A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the fields of network information security, FPGA embedded hardware security, and AI reverse penetration data protection technology, specifically involving an AI reverse penetration full-domain data security coupling protection system based on hardware timing constraints. Background Technology
[0002] Prior authorized invention patent CN120151098B discloses a data security protection system and method based on anti-AI penetration technology. It relies on AI model fingerprint whitelists, user digital ePASS-IDs, and four-dimensional permission control to achieve access-layer AI behavior management, enabling the interception of unregistered and unauthorized AI tools at the access entry point. However, this existing technology has several significant technical flaws and cannot form a complete closed-loop protection system. First, there is a lack of data integrity protection at the storage layer. Existing solutions store complete business data in a single database instance. Once an attacker bypasses identity verification, launches a database breach, or exports data from memory, the complete business data can be obtained in its entirety and directly used for offline training of AI models and reverse engineering of business logic. Even legitimate AI entities that pass whitelist verification can extract all data in batches within a session and cache and redistribute it, lacking isolation constraints at the data ontology level.
[0003] Second, the security capabilities of key binding are insufficient. Traditional keys rely solely on software random number generation and are not strongly bound to server hardware identifiers, access time and space information, operators, and AI entities. This makes them prone to issues such as credential replay, off-site theft, and unauthorized access to batch data. They also lack a four-dimensional binding key derivation constraint mechanism.
[0004] Third, fragmented AI theft detection capabilities are weak. Existing traffic identification relies on the timestamps of upper-layer operating system software to sort packets. These timestamps can be tampered with, leading to time sequence disorder under high-concurrency traffic. AI crawlers commonly use packet fragmentation to capture confidential data in segments. Existing solutions cannot correlate discrete fragmented packets, resulting in an extremely high false negative rate for malicious theft. Furthermore, the AI analysis algorithm is completely decoupled from the underlying hardware, allowing the protection logic to be completely replicated by replacing a general-purpose server, making the protection system easily disassembled and replicated.
[0005] Fourth, there is a lack of a layered reassembly and isolation mechanism. Existing technologies do not distinguish between two types of reassembly logic: network traffic fragmentation and reassembly, and cross-database splicing of business data. They rely on a single processing unit to process both traffic and business data simultaneously, resulting in chaotic logical coupling. There is no independent terminal data reassembly unit. The decrypted complete business plaintext can be persistently stored on disks, swap partitions, and kernel dump files. There is no forced memory overwrite and clearing mechanism at the end of the session, posing a significant risk of data leakage due to residual data.
[0006] Fifth, cross-database data association lacks a secure mapping mechanism. If a sharded storage architecture is adopted, traditional database foreign keys and cross-database JOIN queries will break the data link between isolated servers, bringing the risk of cross-database data leakage; without independent and irregular unified association identifiers, it is impossible to complete the pairing of structure and sensitive values without breaking the database channel. Summary of the Invention
[0007] The main objective of this invention is to provide a hardware-time-constrained AI anti-penetration full-domain data security coupling protection system, which solves the defects of existing anti-AI penetration protection solutions such as weak storage protection, missed detection of fragmented message identification, lack of hardware spatiotemporal binding of keys, split and replicable software and hardware, plaintext residue of business data, and leakage risk of cross-database association.
[0008] To achieve the above objectives, this invention provides an AI reverse penetration full-domain data security coupling protection system based on hardware timing constraints, comprising an encrypted service device, a traditional server, and several access terminals, wherein: The encrypted service device and the traditional server are physically isolated and deployed together to form a multi-database distributed storage architecture: the encrypted service device is used to store encrypted data of business sensitive elements after being encrypted by an algorithm, and the traditional server is used to store de-identified metadata without complete business semantics; The access terminal is configured with a data reassembly module and a secure memory destruction unit. When the access terminal initiates a data query request, it concurrently calls the encrypted data of the business-sensitive elements of the encrypted service device and the desensitized metadata of the traditional server. After all layers of verification by the full-domain AI penetration protection algorithm pass, the data reassembly module completes the encrypted decryption and multi-database data splicing in the local volatile memory to generate complete business data. When the session ends or times out, the secure memory destruction unit is triggered to perform a memory overwrite operation, clearing all plaintext data and temporary session keys in memory.
[0009] As a further preferred technical solution to the above technical solution, the encrypted service device and the traditional server are equipped with FPGAs of completely identical specifications. Each FPGA integrates a hardware counter, a BRAM buffer and a dual-threshold dynamic buffer scheduling module. The FPGA of the encrypted service device is also equipped with a clock phase fine-tuning module.
[0010] As a further preferred technical solution to the above technical solution, the hardware counter operates independently on the FPGA. The FPGA extracts message features from the preset message byte range in the message header, and the hardware counter generates a native timing mark of a specified number of bits. The timing mark is divided into two parts: a high-order segment and a low-order segment. The high-order segment records the hardware counter value in real time and is used to distinguish the timing sequence of message acquisition. The low-order segment stores the unique hardware ID verification code of the device and is used to verify the device to which the timing mark belongs and to prevent forgery and tampering. Each message's sampling features are bound to a unique timing marker, which serves as the sole sorting and association basis for the hardware timing constraint reassembly unit to reassemble fragmented message segments. The timing marker is synchronously fixed to the server's read-only security log. If the log is tampered with, the hardware ID checksum verification will fail, serving as evidence for tracing and obtaining evidence of AI theft.
[0011] As a further preferred technical solution of the above technical solution, the BRAM buffer is an independent high-speed storage unit within the FPGA, which independently connects to the message hardware sampling channel and isolates the hardware sampling link from the upper-level application on the server. The BRAM buffer caches the message sampling characteristics and timing marks output by the hardware counter in real time, collects its own buffer occupancy value in real time, and continuously outputs it to the dual-threshold dynamic buffer scheduling module.
[0012] As a further preferred technical solution to the above technical solution, for the clock phase fine-tuning module, the system clock of the traditional server is used as the global master clock source. The clock phase fine-tuning module of the encrypted service device periodically sends phase calibration commands to the traditional server and then reads the system clock of the traditional server to dynamically correct the sampling phase of the local FPGA crystal oscillator of the encrypted server, correct the cumulative time deviation caused by the long-term operation of the crystal oscillator, and unify the message sampling time reference of the encrypted service device and the traditional server. The FPGA of the encrypted service device and the FPGA of the traditional server are uniformly limited to the message sampling interval of the first preset byte of the message header, and the reference sampling offset is fixed to the second preset byte, ensuring that the message feature interception position and sampling rules of the two servers are completely from the same source, and the fragmented messages captured across servers are continuously reassembled according to the time sequence mark.
[0013] As a further preferred technical solution to the above technical solution, the dual-threshold dynamic buffer scheduling module receives the occupancy rate data reported by the BRAM buffer in real time. Prioritizing the continuous and orderly output of timing markers, it dynamically adjusts the frame interval for message feature output. The hierarchical scheduling rules are as follows: when the buffer load is below the first threshold, a set of message features bound to timing markers is output every first frame; when the buffer load is between the first and second thresholds, a set of message features bound to timing markers is output every second frame; when the buffer load is above the second threshold, message features bound to timing markers are output frame by frame in real time. The dual-threshold dynamic buffer scheduling module outputs scheduling control signals to synchronously regulate the FPGA message output rhythm.
[0014] As a further preferred technical solution to the above technical solution, the encrypted service device, the traditional server, and each access terminal are all synchronously deployed with a full-domain AI penetration protection algorithm. The full-domain AI penetration protection includes an AI risk assessment kernel and a fragmented packet hardware timing constraint reassembly unit, wherein: The fragmented message hardware timing constraint reassembly unit and the AI risk assessment kernel form a linkage and coupling relationship. The fragmented message hardware timing constraint reassembly unit only receives the message features output by FPGA and bound with timing tags. It uses only the hardware count value in the native timing tag with a specified number of bits as the sole basis for serial sorting and reassembling the fragmented access message features scattered in multiple independent data packets into continuous and complete samples. The reassembled continuous samples are unidirectionally input into the AI risk assessment kernel. The AI risk assessment kernel receives continuous samples from the hardware timing constraint reassembly unit, which reconstructs fragmented messages. It then combines these samples with pre-stored user behavior baselines and a confidential asset fingerprint database to distinguish between normal segmented file transfer behavior and malicious segmented theft behavior by AI tools. When suspicious access behavior is detected, a preset observation window is set. During this window, the kernel continuously receives time-marked traffic characteristics synchronously output by the FPGA. Once the presence of AI penetration and theft risk is confirmed, a blocking command is issued through the corresponding server driver to directly cut off the hardware message forwarding channel.
[0015] As a further preferred technical solution to the above technical solution, the de-identified structure metadata stored on the traditional server includes form field names, field types, form layout parameters, interface style encoding, and hierarchical alignment encoding identifiers; the encrypted data of business sensitive elements stored on the encrypted service device includes business values, process technology parameters, and financial confidential fields.
[0016] As a further preferred technical solution to the above technical solution, the access terminal is further provided with a multi-dimensional policy key derivation module. The multi-dimensional strategy key derivation module integrates all binding factors through the key derivation function to generate two independent session keys adapted to the encrypted service device and the traditional server. Only when the four-dimensional verification of device hardware identifier, access spatiotemporal information, AI entity fingerprint, and biometric hash all match, the access terminal obtains the two session keys and provides them to the data joint reconstruction module for data decryption. If any binding factor verification fails, the key derivation process is terminated and data access is rejected.
[0017] As a further preferred technical solution to the above technical solution, the system's workflow is as follows: Step S1: Data partitioning and persistent storage steps: Business data is split into de-identified structure metadata and business-sensitive element encrypted data. The de-identified structure metadata is stored in a traditional server, and the business-sensitive element encrypted data is encrypted and stored in an encrypted service device. Cross-database field mapping is established by aligning encoding identifiers. The encrypted service device and the FPGA of the traditional server synchronously start the message sampling process. The hardware counter independently generates a preset bit native timing mark bound to the server hardware ID. The BRAM buffer caches message features and timing marks and continuously reports the buffer occupancy rate. The clock phase fine-tuning module periodically synchronizes the timing reference. The dual-threshold dynamic buffer scheduling module outputs message features with timing marks in an orderly manner according to the BRAM load. Step S2: Hardware-driven message reassembly and full-domain AI verification: The hardware-driven message reassembly unit relies solely on time-series markers to concatenate segmented message features, generating continuous samples that are then fed into the AI risk assessment kernel. The AI risk assessment kernel, combined with user behavior baselines and a confidential asset fingerprint database, identifies AI-segmented theft behavior and simultaneously completes four-dimensional verification of AI fingerprints, biometrics, access time windows, and device MAC / IP. If any verification fails or a penetration risk is identified, the hardware layer directly blocks access traffic. Step S3: Parallel Data Retrieval Step: After all four-dimensional verifications pass, the access terminal synchronously sends data reading commands to the encrypted service device and the traditional server; the clock phase fine-tuning module of the traditional server and the encrypted service device maintains timing consistency, the dual-threshold dynamic buffer scheduling module stably outputs traffic characteristics, and returns de-identified structure metadata and business sensitive element encrypted data to the terminal in parallel. Step S4: Instant memory decryption and reconstruction step: The access terminal calls the multi-dimensional policy key derivation module to generate multi-library independent session keys, decrypts the ciphertext data only in the terminal's volatile memory, and splices the desensitized structure metadata and the decrypted ciphertext data according to the alignment encoding identifier to generate complete business data for authorized AI or operators to use; Step S5: Session Destruction and Key Rollover Steps: After a session times out or is actively exited, the secure memory destruction unit performs a memory overwrite operation to clear all plaintext in memory and temporary session keys; after the system reaches the preset usage threshold, it re-executes the key derivation process to generate a new key, rolls and updates the session key, and completely destroys the old key to achieve forward security.
[0018] The beneficial effects of this invention are as follows: 1. Multi-database physical isolation and separate storage, fundamentally preventing the risk of complete data leakage: Business data is split into an anonymized structure, and encrypted sensitive elements are stored on two physically isolated servers. If either server is compromised, the complete business semantics cannot be restored. Logical mapping is achieved by using aligned encoded identifiers, without opening up cross-database channels, thus eliminating the risk of leakage during cross-database queries.
[0019] 2. FPGA hardware timing constraints across the entire chain significantly improve the accuracy of AI theft detection: The hardware counter generates an immutable timing mark with a unique device identifier of a specified number of bits. Combined with clock phase synchronization and dynamic buffer scheduling, the timing mark is guaranteed to be continuous and stable. The fragmented message hardware timing constraint reassembly unit reassembles fragmented traffic solely based on the hardware timing mark, solving the problem of missed judgment caused by the tampering of software timestamps and high-concurrency timing disorder, and realizing source tracing and evidence collection of traffic across the intranet and cloud.
[0020] 3. Two independent reorganization mechanisms provide layered protection with clear logical boundaries and no functional coupling: It is equipped with a server-side traffic sharding and reassembly unit and a terminal business data splicing and reassembly module, which respectively realizes pre-event risk interception and post-event legitimate data restoration; the deployment location, processing object, and matching index are completely isolated, forming a two-layer protection logic of pre-emptive traffic risk control interception and instant memory restoration of data reassembly, so that there will be no functional confusion or security logic vulnerabilities.
[0021] 4. The terminal has a built-in multi-dimensional policy key derivation module to achieve four-dimensional strong key binding: The key derivation module is deployed on the access terminal, integrating four factors—server hardware ID, access time and space information, AI fingerprint, and operator biometric hash—to generate an independent session key. The key is naturally bound to the hardware device, access scenario, user, and AI tool; any failure to verify any bound factor directly rejects decryption access, effectively resisting credential theft, off-site replay, and unauthorized batch extraction; the accompanying key rolling update mechanism provides forward security.
[0022] 5. Complete business data exists only momentarily in memory, with no persistent data residue: All business plaintext is temporarily generated by the data reassembly module only in the volatile memory of the access terminal. When the session ends, the plaintext, key, and intermediate mapping cache are forcibly overwritten and cleared. Complete business data is not left on the disk or swap partition, eliminating the risk of memory dump and temporary file leakage.
[0023] 6. Deeply coupled hardware and software, making the protection system difficult to disassemble and replicate. The AI fragmented traffic reassembly logic heavily relies on FPGA hardware timing markers. Without the FPGA hardware unit that comes with this invention, the fragmented message hardware timing constraint reassembly unit cannot work properly, and the AI segmented theft identification function will directly fail, thus preventing the protection algorithm from being separately ported and replicated. Attached Figure Description
[0024] Figure 1 This is a schematic diagram of the system structure of the present invention.
[0025] Figure 2 This is a system flowchart of the present invention. Detailed Implementation
[0026] The following description is intended to disclose the present invention and enable those skilled in the art to implement it. The preferred embodiments described below are merely examples, and other obvious variations will occur to those skilled in the art. The basic principles of the invention defined in the following description can be applied to other embodiments, modifications, improvements, equivalents, and other technical solutions that do not depart from the spirit and scope of the invention.
[0027] In the preferred embodiments of the present invention, those skilled in the art should note that the national secret codes and other related technologies involved in the present invention can be regarded as prior art.
[0028] Preferred embodiment.
[0029] like Figure 1 As shown, this invention discloses an AI reverse penetration full-domain data security coupling protection system based on hardware timing constraints, including a ciphertext service device, at least one traditional server (for data isolation), and several access terminals, wherein: It is worth mentioning that the encrypted service device is configured as a full-domain encryption server and a cloud SaaS security gateway server for different application scenarios. The full-domain encryption server is deployed in the enterprise's intranet data center for storing sensitive encrypted data of private business within the intranet and collecting hardware time-series data of intranet traffic. The cloud SaaS security gateway server is deployed at the external network egress point for collecting de-identified traffic of cloud SaaS business and conducting pre-access risk control for external networks.
[0030] The encrypted service device and the traditional server are physically isolated and deployed together to form a multi-database, itemized storage architecture: the encrypted service device stores encrypted data of sensitive business elements encrypted using, for example, the national cryptographic algorithm SM4; the traditional server (which has a business service system installed and is used to deploy commonly used service systems) stores de-identified metadata without complete business semantics; the de-identified metadata stored on the traditional server includes form field names, field types, form layout parameters, interface style encoding, and hierarchical alignment encoding identifiers; the encrypted data of sensitive business elements stored on the encrypted service device includes commercial values, process technology parameters, and financially confidential fields; the encrypted service device and the traditional server establish a cross-database data mapping relationship through alignment encoding identifiers, and data stored on a single server cannot be pieced together to restore complete business data. The alignment encoding identifier adopts a four-layer fixed structure of AC-[form type encoding]-[record sequence number]-[field sequence number], which is globally unique. When the same original business field is split and stored in the database, an identical alignment code identifier is generated and written to the data tables of the two servers respectively. The two servers do not establish database foreign keys or cross-database query channels. They only rely on the alignment code identifier in the memory of the access terminal to complete the matching of the structure and the ciphertext field.
[0031] The access terminal is configured with a data reassembly module and a secure memory destruction unit. When the access terminal initiates a data query request, it concurrently calls the encrypted data of the business-sensitive elements of the encrypted service device and the de-identified metadata of the traditional server. After all multi-layer verifications by the full-domain AI penetration protection algorithm pass, the data reassembly module completes the encrypted decryption and multi-database data splicing only in local volatile memory to generate complete business data. When the session ends or times out, the secure memory destruction unit is triggered to perform a memory overwrite operation, clearing all plaintext data in memory and temporary session keys, and leaving no complete business plaintext on non-volatile storage media such as disks, swap partitions, and kernel dump files. Preferably, the access terminal with the full-domain AI penetration protection algorithm monitors all network behaviors, dynamically analyzes the AI whitelist identity, and issues a message warning if the verification fails.
[0032] It is worth mentioning that the data reassembly module is independent of the server-side fragmented message hardware timing constraint reassembly unit and has no functional overlap. When the terminal initiates a query request, it calls the encrypted sensitive element ciphertext of the encrypted service device and the desensitized structure metadata of the traditional server in parallel. After verifying that all requests are allowed, the data reassembly module retrieves the independent session key generated by the multi-dimensional policy key derivation module. It performs SM4 ciphertext decryption only in local volatile memory, and then completes the field pairing and splicing of the desensitized structure metadata and the decrypted sensitive values according to the alignment encoding identifier to generate complete and readable business data. The processing objects of this unit are the encrypted business fields and structural information. The matching index is the alignment encoding identifier. It is only for legitimate authorized access scenarios and does not participate in traffic risk identification.
[0033] For the secure memory destruction unit: it is automatically triggered when the session ends or times out, and calls the secure memory overwrite function to clear all plaintext business data, temporary session keys, aligned encoding temporary mapping hash dictionary, and decryption intermediate cache generated by the data reassembly module in memory. The complete business plaintext is not left on non-volatile media such as disks, swap partitions, and kernel dump files throughout the process.
[0034] The encrypted message service device and the traditional server are each equipped with an FPGA of identical specifications. Each FPGA integrates a hardware counter, a BRAM buffer (the BRAM (Block Random Access Memory) buffer is integrated into the FPGA's internal hardware logic and is a dedicated storage hardware resource within the FPGA chip, not external memory), and a dual-threshold dynamic buffer scheduling module. The FPGA of the encrypted message service device also has a clock phase fine-tuning module, wherein: The hardware counter runs independently on the FPGA without going through the operating system or CPU. The upper-layer software has no permission to read, modify, or reset the hardware counter. The FPGA extracts message features from the preset message byte range in the message header, and the hardware counter generates a native timing mark of a specified number of bits (preferably 64 bits). The timing mark is divided into two parts: a high-order segment (preferably the high 32 bits) and a low-order segment (preferably the low 32 bits). The high-order segment records the hardware counter value in real time and is used to distinguish the timing of message collection. The low-order segment stores the unique hardware ID verification code of the device and is used to verify the device to which the timing mark belongs and to prevent forgery and tampering. Each message's sampling features are bound to a unique timing marker, which serves as the sole sorting and association basis for the hardware timing constraint reassembly unit to reassemble fragmented message segments. The timing marker is synchronously fixed to the server's read-only security log. If the log is tampered with, the hardware ID checksum verification will fail, serving as evidence for tracing and obtaining evidence of AI theft.
[0035] The BRAM buffer is an independent high-speed storage unit within the FPGA, independently connected to the message hardware sampling channel, isolating the hardware sampling link from the upper-level application on the server. The BRAM buffer caches message sampling features and timing markers output by the hardware counter in real time, and continuously outputs its own buffer occupancy value to the dual-threshold dynamic buffer scheduling module in real time. The BRAM buffer caches instantaneous high-concurrency traffic, avoiding the loss or gap of message features and hardware timing markers, and preventing malicious programs from tampering with the traffic features and timing markers to be analyzed.
[0036] For the clock phase fine-tuning module, the system clock of the traditional server is used as the global master clock source. The clock phase fine-tuning module of the encrypted service device periodically sends phase calibration commands to the traditional server and then reads the system clock of the traditional server to dynamically correct the sampling phase of the local FPGA crystal oscillator of the encrypted server, correcting the cumulative time deviation caused by the long-term operation of the crystal oscillator, and unifying the message sampling time reference of the encrypted service device and the traditional server. As a supplementary explanation, for example, the time code of the file number generated in Bangladesh is 9 o'clock, and the time generated in Beijing time is 12 o'clock. Then, the file is finally decrypted by combining the Bangladesh time and Beijing time to form a barcode key, which serves as the basis for decrypting the corresponding file.
[0037] The FPGA of the encrypted service device and the FPGA of the traditional server are uniformly limited to the first preset byte of the message header (preferably 24-40), and the reference sampling offset is fixed to the second preset byte (preferably 32). This ensures that the message feature interception position and sampling rules of the two servers are completely from the same source, and the fragmented messages captured across servers are continuously reassembled according to the time sequence mark.
[0038] The dual-threshold dynamic buffer scheduling module receives real-time occupancy data from the BRAM buffer. Prioritizing continuous and orderly output of timing markers, it dynamically adjusts the frame interval for message feature output. The hierarchical scheduling rules are as follows: when the buffer load is below the first threshold (70%), a set of message features bound to timing markers is output every first frame (preferably 8 frames); when the buffer load is between the first and second thresholds (70%-85%), a set of message features bound to timing markers is output every second frame (preferably 6 frames); when the buffer load is above the second threshold (85%), message features bound to timing markers are output frame by frame in real-time. The dual-threshold dynamic buffer scheduling module outputs scheduling control signals to synchronously regulate the FPGA message output rhythm, avoiding hardware timing marker interval errors and order reversals under high concurrency traffic. The dual-threshold dynamic buffer scheduling module on the encrypted service device side synchronously links with the server kernel driver, temporarily increasing the hardware encryption channel interrupt priority in high-risk encrypted traffic scenarios to shorten the sensitive encrypted text transmission window.
[0039] It is worth mentioning that the encrypted service device, traditional server, and each access terminal are all synchronously deployed with a full-domain AI penetration protection algorithm. This full-domain AI penetration protection includes an AI risk assessment kernel and a fragmented packet hardware timing constraint reassembly unit, wherein: The fragmented message hardware timing constraint reassembly unit and the AI risk assessment kernel form a linked coupling relationship. The fragmented message hardware timing constraint reassembly unit only receives the message features output by FPGA and bound with timing marks. It uses only the hardware count value in the native timing mark of a specified number of bits as the sole basis for serial sorting to reassemble the fragmented access message features scattered in multiple independent data packets into continuous and complete samples. The reassembled continuous samples are unidirectionally input into the AI risk assessment kernel. The fragmented message hardware timing constraint reassembly unit cannot complete message reassembly without the hardware timing mark generated by the FPGA hardware counter. If only the operating system software timestamp exists, the reassembly logic will completely fail. The AI risk assessment kernel reuses the anti-AI penetration identification algorithm kernel of prior patent CN120151098B. The AI risk assessment kernel receives continuous samples output by the hardware timing constraint reassembly unit of fragmented messages, and combines them with the pre-stored user behavior baseline and the fingerprint database of classified assets to distinguish between normal segmented file transmission behavior and malicious segmented theft behavior of AI tools. When suspicious access behavior is identified, a preset time (preferably 30 seconds) is set for continuous observation. During the window period, the kernel continuously receives the time-marked traffic features synchronously output by the FPGA. After confirming the existence of AI penetration and theft risk, the kernel issues a blocking command through the corresponding server driver to directly cut off the hardware message forwarding channel (for encrypted service devices, power can be directly cut off). The AI risk assessment kernel simultaneously completes four-dimensional identity spatiotemporal verification: AI entity model fingerprint whitelist verification, operator biometric hash matching verification, access time window validity verification, and request end MAC / IP address authorization verification. If any verification fails, the data reading process is directly terminated without triggering subsequent key derivation and multi-database data retrieval operations.
[0040] Preferably, the access terminal is further provided with a multi-dimensional policy key derivation module; The multi-dimensional strategy key derivation module is configured to receive multiple types of binding factors to participate in key operations. The binding factors include device hardware identifier, access spatiotemporal information, AI entity fingerprint, and operator biometric hash. The device hardware identifier is derived from the server's unique hardware ID verification code within the 64-bit native hardware timing mark generated by the FPGA hardware counter, and is used to bind the encrypted service device and the traditional server hardware identity; the access spatiotemporal information includes the time window parameters corresponding to the access request, the MAC address and IP address of the requesting terminal; The multi-dimensional strategy key derivation module integrates all binding factors through the HKDF-SM3 key derivation function to generate two independent session keys adapted to the encrypted service device and the traditional server. Only when the four-dimensional verification of device hardware identifier, access spatiotemporal information, AI entity fingerprint, and biometric hash all match, the access terminal obtains the two session keys and provides them to the data joint reconstruction module for data decryption. If any binding factor verification fails, the key derivation process is terminated and data access is rejected.
[0041] The workflow for the multi-dimensional policy key derivation module is as follows: (1) Acquisition of device hardware identifier: When the access terminal pulls data in parallel from the two servers, it synchronously extracts the lower 32 bits of the hardware ID verification code in the 64-bit hardware timing mark output by the FPGA hardware counter of the two servers, which serves as the unique binding credential of the server hardware. (2) Access spatiotemporal information collection: The access terminal collects the effective time window parameters, local MAC physical address and local IP address of this access in real time, as spatiotemporal constraint factors; (3) Multi-factor fusion derivation: The HKDF-SM3 key derivation function is used to serialize and mix the four types of binding factors to generate independent session keys for the corresponding ciphertext service device and traditional server respectively; (4) Output docking: The two sets of session keys generated are stored only in the terminal's volatile memory and are directly provided to the data reconstruction module to complete the decryption of sensitive elements; (5) Key rolling update: When the system reaches the key usage count or data lifecycle threshold, the multi-dimensional strategy key derivation module re-collects the full set of binding factors in real time to generate a new session key, and the old key is immediately destroyed to achieve forward security.
[0042] like Figure 2 As shown, the system's workflow is as follows: Step S1: Data partitioning and persistent storage steps: Business data is split into de-identified structure metadata and business-sensitive element encrypted data. The de-identified structure metadata is stored in a traditional server, and the business-sensitive element encrypted data is encrypted with SM4 and stored in the encrypted service device. Cross-database field mapping is established through alignment encoding identifiers; the FPGA of the encrypted service device starts the message sampling process; the hardware counter independently generates a preset bit (64-bit) native timing mark bound to the server hardware ID; the BRAM buffer caches message features and timing marks and continuously reports the buffer occupancy rate; the clock phase fine-tuning module periodically synchronizes the timing reference; the dual-threshold dynamic buffer scheduling module outputs message features with timing marks in an orderly manner according to the BRAM load hierarchy; Step S2: Hardware-driven message reassembly and full-domain AI verification: The hardware-driven message reassembly unit relies solely on time-series markers to concatenate segmented message features, generating continuous samples that are then fed into the AI risk assessment kernel. The AI risk assessment kernel, combined with user behavior baselines and a confidential asset fingerprint database, identifies AI-segmented theft behavior and simultaneously completes four-dimensional verification of AI fingerprints, biometrics, access time windows, and device MAC / IP. If any verification fails or a penetration risk is identified, the hardware layer directly blocks access traffic. Step S3: Parallel Data Retrieval Step: After all four-dimensional verifications pass, the access terminal synchronously sends data reading commands to the encrypted service device and the traditional server; the clock phase fine-tuning module of the traditional server and the encrypted service device maintains timing consistency, the dual-threshold dynamic buffer scheduling module stably outputs traffic characteristics, and returns de-identified structure metadata and business sensitive element encrypted data to the terminal in parallel. Step S4: Instant memory decryption and reconstruction step: The access terminal calls the multi-dimensional policy key derivation module to generate multi-library independent session keys, decrypts the ciphertext data only in the terminal's volatile memory, and splices the desensitized structure metadata and the decrypted ciphertext data according to the alignment encoding identifier to generate complete business data for authorized AI or operators to use; Step S5: Session Destruction and Key Rollover Steps: After a session times out or is actively exited, the secure memory destruction unit performs a memory overwrite operation to clear all plaintext in memory and temporary session keys; after the system reaches the preset usage threshold, it re-executes the key derivation process to generate a new key, rolls and updates the session key, and completely destroys the old key to achieve forward security.
[0043] As another example, this relates to the protection of financial statements in government ERP systems.
[0044] Government agencies physically isolate encrypted service devices and traditional servers, and store financial statements separately: desensitized metadata such as form names, row and column layouts, and cell styles are stored on traditional servers; confidential values such as revenue, budgets, and fiscal costs are encrypted using SM4 and stored on encrypted service devices; the two server FPGAs use a unified 32-byte message sampling offset, and the clock phase fine-tuning module completes timing calibration every 30 minutes.
[0045] Finance staff can access monthly financial statements through a dedicated access terminal. Access traffic flows through dual-server FPGAs. Hardware counters generate timing markers with device IDs, BRAM buffers cache traffic characteristics, and a dual-threshold dynamic buffer scheduling module dynamically adjusts the output frame interval based on business concurrency. The fragmented message hardware timing constraint reassembly unit reassembles fragmented access messages based on hardware timing markers and sends them to the AI risk assessment kernel to complete four-dimensional verification using audit AI tools fingerprints, facial biometric hashes, office intranet MAC addresses, and valid working day time windows.
[0046] After all verifications pass, the terminal pulls data from multiple databases in parallel. The terminal's built-in multi-dimensional policy key derivation module extracts the hardware IDs of the two servers, the local MAC / IP, the current time window, face hash, and AI fingerprint to generate two sets of session keys. The data joint reconstruction module decrypts the ciphertext in memory, matches the form fields with the financial values based on the alignment code identifier, and concatenates them to generate a complete financial report. After the staff closes the report page, the secure memory destruction unit immediately overwrites and clears all financial plaintext, session keys, and alignment code mapping dictionaries in memory. Every 100 decryption operations completed, the system automatically triggers a key rolling update. The multi-dimensional policy key derivation module re-collects the complete set of binding factors to generate a new key, and the old key is completely destroyed.
[0047] If an attacker steals a traditional server database alone, they can only obtain a blank report frame; if they steal a ciphertext service device alone, they can only obtain unordered ciphertext and semantically unaligned encoding; when an AI crawler captures report data in segments and batches, the server-side fragmented message hardware timing constraint reassembly unit can connect the fragmented traffic in series, and the AI judgment kernel sets a 30-second observation window. After confirming the batch extraction behavior, it directly blocks the external network traffic.
[0048] It is worth mentioning that the technical features such as national secret codes involved in this patent application should be regarded as prior art. The specific structure, working principle, and possible control methods and spatial arrangement of these technical features can be adopted using conventional choices in the field, and should not be regarded as the inventive point of this patent. This patent will not be further elaborated in detail.
[0049] For those skilled in the art, modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this invention should be included within the protection scope of this invention.
Claims
1. A hardware-time-constrained AI reverse penetration full-domain data security coupling protection system, characterized in that, It includes a encrypted service device, a traditional server, and several access terminals, among which: The encrypted service device and the traditional server are physically isolated and deployed together to form a multi-database distributed storage architecture: the encrypted service device is used to store encrypted data of business sensitive elements after being encrypted by an algorithm, and the traditional server is used to store de-identified metadata without complete business semantics; The access terminal is configured with a data reassembly module and a secure memory destruction unit. When the access terminal initiates a data query request, it concurrently calls the encrypted data of the business-sensitive elements of the encrypted service device and the desensitized metadata of the traditional server. After all layers of verification by the full-domain AI penetration protection algorithm pass, the data reassembly module completes the encrypted decryption and multi-database data splicing in the local volatile memory to generate complete business data. When the session ends or times out, the secure memory destruction unit is triggered to perform a memory overwrite operation, clearing all plaintext data and temporary session keys in memory.
2. The AI reverse penetration full-domain data security coupling protection system based on hardware timing constraints according to claim 1, characterized in that, The encrypted service device and the traditional server are each equipped with an FPGA of the same specifications. Each FPGA integrates a hardware counter, a BRAM buffer and a dual-threshold dynamic buffer scheduling module. The FPGA of the encrypted service device is also equipped with a clock phase fine-tuning module.
3. The AI reverse penetration full-domain data security coupling protection system based on hardware timing constraints according to claim 2, characterized in that, The hardware counter operates independently on the FPGA. The FPGA extracts message features from the preset message byte range in the message header, and the hardware counter generates a native timing mark of a specified number of bits. The timing mark is divided into two parts: a high-order segment and a low-order segment. The high-order segment records the hardware counter value in real time and is used to distinguish the timing sequence of message acquisition. The low-order segment stores the unique hardware ID verification code of the device and is used to verify the device to which the timing mark belongs and to prevent forgery and tampering. Each message's sampling features are bound to a unique timing marker, which serves as the sole sorting and association basis for the hardware timing constraint reassembly unit to reassemble fragmented message segments. The timing marker is synchronously fixed to the server's read-only security log. If the log is tampered with, the hardware ID checksum verification will fail, serving as evidence for tracing and obtaining evidence of AI theft.
4. The AI reverse penetration full-domain data security coupling protection system based on hardware timing constraints according to claim 3, characterized in that, The BRAM buffer is an independent high-speed storage unit within the FPGA, independently connected to the message hardware sampling channel, isolating the hardware sampling link from the upper-level application on the server; the BRAM buffer caches message sampling characteristics and timing markers output by the hardware counter in real time, and continuously collects its own buffer occupancy value and outputs it to the dual-threshold dynamic buffer scheduling module in real time.
5. The AI reverse penetration full-domain data security coupling protection system based on hardware timing constraints according to claim 4, characterized in that, For the clock phase fine-tuning module, the system clock of the traditional server is used as the global master clock source. The clock phase fine-tuning module of the encrypted service device periodically sends phase calibration commands to the traditional server and then reads the system clock of the traditional server to dynamically correct the sampling phase of the local FPGA crystal oscillator of the encrypted server, correct the cumulative time deviation caused by the long-term operation of the crystal oscillator, and unify the message sampling time reference of the encrypted service device and the traditional server. The FPGA of the encrypted service device and the FPGA of the traditional server are uniformly limited to the first preset byte of the message header, and the reference sampling offset is fixed to the second preset byte, ensuring that the message feature interception position and sampling rules of the two servers are completely from the same source. The fragmented messages captured across servers are continuously reassembled according to the timing mark.
6. The AI reverse penetration full-domain data security coupling protection system based on hardware timing constraints according to claim 5, characterized in that, The dual-threshold dynamic buffer scheduling module receives real-time occupancy data from the BRAM buffer. Prioritizing the continuous and orderly output of timing markers, it dynamically adjusts the frame interval for message feature output. The hierarchical scheduling rule is as follows: when the buffer load is below the first threshold, a set of message features bound to timing markers is output every first frame; when the buffer load is between the first and second thresholds, a set of message features bound to timing markers is output every second frame. When the buffer load exceeds the second threshold, the message characteristics bound to the timing mark are output frame by frame in real time; the dual-threshold dynamic buffer scheduling module outputs scheduling control signals to synchronously regulate the FPGA message output rhythm.
7. The AI reverse penetration full-domain data security coupling protection system based on hardware timing constraints according to claim 6, characterized in that, The encrypted service device, traditional server, and each access terminal are all synchronously deployed with a full-domain AI penetration protection algorithm. This full-domain AI penetration protection includes an AI risk assessment kernel and a fragmented packet hardware timing constraint reassembly unit, wherein: The fragmented message hardware timing constraint reassembly unit and the AI risk assessment kernel form a linkage and coupling relationship. The fragmented message hardware timing constraint reassembly unit only receives the message features output by FPGA and bound with timing tags. It uses only the hardware count value in the native timing tag with a specified number of bits as the sole basis for serial sorting and reassembling the fragmented access message features scattered in multiple independent data packets into continuous and complete samples. The reassembled continuous samples are unidirectionally input into the AI risk assessment kernel. The AI risk assessment kernel receives continuous samples from the hardware timing constraint reassembly unit, which reconstructs fragmented messages. It then combines these samples with pre-stored user behavior baselines and a confidential asset fingerprint database to distinguish between normal segmented file transfer behavior and malicious segmented theft behavior by AI tools. When suspicious access behavior is detected, a preset observation window is set. During this window, the kernel continuously receives time-marked traffic characteristics synchronously output by the FPGA. Once the presence of AI penetration and theft risk is confirmed, a blocking command is issued through the corresponding server driver to directly cut off the hardware message forwarding channel.
8. The AI reverse penetration full-domain data security coupling protection system based on hardware timing constraints according to claim 7, characterized in that, The de-identified metadata stored on the traditional server includes form field names, field types, form layout parameters, interface style encoding, and hierarchy alignment encoding identifiers; the encrypted data of business-sensitive elements stored on the encrypted service device includes business values, process technology parameters, and financial confidential fields.
9. The AI reverse penetration full-domain data security coupling protection system based on hardware timing constraints according to claim 8, characterized in that, The access terminal is also equipped with a multi-dimensional policy key derivation module. The multi-dimensional strategy key derivation module integrates all binding factors through the key derivation function to generate two independent session keys adapted to the encrypted service device and the traditional server. Only when the four-dimensional verification of device hardware identifier, access spatiotemporal information, AI entity fingerprint, and biometric hash all match, the access terminal obtains the two session keys and provides them to the data joint reconstruction module for data decryption. If any binding factor fails the verification, the key derivation process is terminated and data access is rejected.
10. The AI reverse penetration full-domain data security coupling protection system based on hardware timing constraints according to claim 9, characterized in that, The system's workflow is as follows: Step S1: Data partitioning and persistent storage steps: split business data into de-identified structured metadata and business-sensitive element encrypted data. Store the de-identified structured metadata in a traditional server, and store the business-sensitive element encrypted data in an encrypted service device after encryption. Establish cross-database field mapping by aligning encoding identifiers. The encrypted service device and the FPGA of the traditional server synchronously start the message sampling process; the hardware counter independently generates a preset bit native timing mark bound to the server hardware ID; the BRAM buffer caches message features and timing marks and continuously reports the buffer occupancy rate; the clock phase fine-tuning module periodically synchronizes the timing reference; the dual-threshold dynamic buffer scheduling module outputs message features with timing marks in an orderly manner according to the BRAM load. Step S2: Hardware timing-driven message reassembly and full-domain AI verification steps: The hardware timing-constrained reassembly unit of fragmented messages relies solely on timing markers to connect segmented message features and generate continuous samples, which are then sent to the AI risk assessment kernel. The AI risk assessment kernel combines user behavior baselines and the fingerprint database of confidential assets to identify AI segmented theft behavior and simultaneously completes four-dimensional verification of AI fingerprint, biometrics, access time window, and device MAC / IP. If any verification fails or a penetration risk is identified, the hardware layer directly blocks access traffic. Step S3: Parallel Data Retrieval Step: After all four-dimensional verifications pass, the access terminal synchronously sends data reading commands to the encrypted service device and the traditional server; the clock phase fine-tuning module of the traditional server and the encrypted service device maintains timing consistency, the dual-threshold dynamic buffer scheduling module stably outputs traffic characteristics, and returns de-identified structure metadata and business sensitive element encrypted data to the terminal in parallel. Step S4: Instant memory decryption and reconstruction step: The access terminal calls the multi-dimensional policy key derivation module to generate multi-library independent session keys, decrypts the ciphertext data only in the terminal's volatile memory, and splices the desensitized structure metadata and the decrypted ciphertext data according to the alignment encoding identifier to generate complete business data for authorized AI or operators to use; Step S5: Session Destruction and Key Rollover Step: After the session times out or the user actively exits, the secure memory destruction unit performs a memory overwrite operation to clear all plaintext in memory and temporary session keys; Once the system reaches the preset usage threshold, it re-executes the key derivation process to generate a new key, continuously updates the session key, and completely destroys the old key to achieve forward security.
Citation Information
Patent Citations
Data security protection system and method based on anti-ai penetration technology
CN120151098B