Edge AI Model Protection With Hardware-Bound Secure Elements

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing AI models deployed on edge devices are vulnerable to manipulation and counterfeiting, lacking effective protection mechanisms.

Innovation Solution

Implementing a secure element or trusted execution environment on edge devices to store and manage a salt, which is used to modify and encrypt data before running AI models, ensuring only authorized devices can utilize the models effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If AI models are deployed directly on edge devices without protection mechanisms, then device complexity is reduced and ease of operation is improved, but security and reliability deteriorate due to vulnerability against manipulation and counterfeiting

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A trusted execution environment (TEE) or secure element is introduced as an intermediary between the AI model and the edge device processor. This intermediary component handles cryptographic operations and protects the AI model parameters, allowing the model to be bound to specific hardware while maintaining ease of operation through automated security mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional software-based protection mechanisms with hardware-based trusted execution environments or secure elements. This substitution provides stronger security guarantees by leveraging hardware security features, effectively protecting against manipulation and counterfeiting while maintaining operational simplicity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If AI models are protected through binding to specific hardware using trusted execution environments, then security and reliability are improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted execution environment or secure element serves multiple functions: it protects AI model parameters, enables hardware binding, performs cryptographic operations, and provides authentication. By consolidating these functions into a single component, the patent improves security without proportionally increasing overall device complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The trusted execution environment operates autonomously to protect AI models, automatically handling cryptographic operations and hardware binding without requiring complex user intervention or additional software layers. This self-service approach simplifies the overall system architecture while maintaining strong security

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250298910A1Protection of ai models
Publication Date: 2025.09.25 INFINEON TECHNOLOGIES AG
  • US20250298910A1 patent drawing
  • US20250298910A1 patent drawing
  • US20250298910A1 patent drawing

AI summary

An edge device is proposed that comprises a first memory configured to receive and store an artificial intelligence model (AI model) and a pre-processor configured to pre-process sensor data. The edge device further comprises a protected memory for storing modifying data, and a classification stage for running the AI model on the pre-processed data that is modified based on the modifying data. The classification stage outputs output data generated by running the AI model on the modified pre-processed data.