AI Processor Mode Switching for Secure Mobile Inference

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile terminals, such as smartphones, lack sufficient security in their Rich Execution Environment (REE) to support AI applications like face recognition and payment security, as AI chips deployed in REE do not meet the security requirements of these applications.

Innovation Solution

An AI processing apparatus with a GPU as the AI processor that has multiple working modes, including a secure and non-secure mode, dynamically switches between these modes based on the AI processing request to meet security requirements, utilizing a TrustZone protection controller (TZPC) for mode switching and resource management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If AI chip is deployed in REE to provide AI services, then productivity and energy efficiency are improved, but security is worsened

Engineering Contradiction:
ImproveAI computing efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments the execution environment into two distinct modes: secure mode and normal mode. The AI processor can dynamically switch between these modes based on the security requirements of different AI applications. This segmentation allows high-security applications (e.g., face recognition, payment) to run in secure mode while other applications run in normal mode, thus resolving the contradiction between productivity and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The AI processor implements dynamic mode switching capability, transitioning between secure mode and normal mode based on the security level requirements of different AI processing requests. This dynamic adaptation allows the system to optimize both security and productivity by allocating appropriate execution environments in real-time rather than using a static configuration.

Inventive Principle:
Principle #15Dynamics

2Reliability

If AI processor uses multiple working modes with different security levels, then security is improved, but device complexity is worsened

Engineering Contradiction:
Improvesecurity levelVSAvoidprocessor mode management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The AI processor autonomously determines whether to switch to secure mode or normal mode based on the security level requirements of incoming AI processing requests. The processor self-manages the mode selection and switching without requiring complex external control logic, thus improving security while minimizing the increase in device complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the operational parameter (security mode) of the AI processor based on the security level of the AI application. By dynamically adjusting this parameter according to application requirements, the system achieves high security when needed while maintaining simplicity in the overall architecture.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP4290373B1Artificial intelligence (AI) processing method and ai processing device
Publication Date: 2026.03.11 HUAWEI TECH CO LTD
  • EP4290373B1 patent drawingFigure 1~2
  • EP4290373B1 patent drawingFigure 3~4
  • EP4290373B1 patent drawingFigure 5~6

AI summary

Embodiments of the present invention disclose an AI processing method and an AI processing apparatus. The method is applied to the AI processing apparatus. An AI processor has at least two working modes, and security of the at least two working modes is different. The method includes: processing, by the AI processor, an AI processing request in a target mode. The target mode is one of the at least two working modes, and the target mode is a working mode determined based on the AI processing request. The AI processor has at least two working modes with different security, and may switch between different working modes. This can meet security processing requirements of different AI processing requests, and improve security.