The invention provides an end-side
large model parameter protection method and
system based on a trusted execution environment, and the method comprises the steps: enabling a
large model client application program to receive the input of a user, and transmitting the input of the user to a
trusted application, namely, a
large model security application; the REE
OS kernel forwards the request of the user mode to the
trusted application, proxy I / O and NPU of the
trusted application and continuous memory allocation requests are achieved, and trusted application
thread scheduling is achieved; the security monitor is used for forwarding a request of the REE
OS kernel to the TEE
OS kernel; the TEE OS kernel is responsible for carrying out security configuration related to the TrustZone with high privilege and realizing
address space isolation between security applications; and the large model security application realizes pipeline
recovery accelerated reasoning, dynamic memory capacity expansion and NPU device calling by an NPU driver to perform calculation acceleration. According to the method, the
hardware acceleration capability of the reasoning task is guaranteed, meanwhile, the scale of a TEE
trusted computing base (TCB) is controlled, and the overall safety and the performance expandability of the
system are improved.