Model Sub-Model Segmentation for Trusted Execution Environment Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The security protection for models in artificial intelligence technologies is inadequate, leading to potential leaks or tampering of model parameters and structures during data processing.

Innovation Solution

A method and apparatus for model protection that involves obtaining identification information and attribute parameters of a target model, determining a sub-model suitable for a trusted execution environment (TEE) of a terminal device, and sending this sub-model to the device for secure storage and processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the complete model is deployed to terminal devices for local processing, then data processing efficiency and user privacy protection are improved, but the model security is worsened due to potential leaks or tampering of model parameters and structures

Engineering Contradiction:
Improvedata processing efficiencyVSAvoidmodel security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent divides the complete model into multiple sub-models and selectively deploys only necessary sub-models to terminal devices. This segmentation approach allows the system to maintain model security by keeping sensitive parts of the model on secure servers while still enabling local processing of specific tasks, thus resolving the contradiction between processing efficiency and model security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different quality levels to different parts of the model by identifying and selecting specific sub-models with appropriate security attributes for local deployment. Critical model components remain on secure servers while less sensitive sub-models are deployed to terminals, creating a differentiated security architecture that balances efficiency and security.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If model sub-setting is performed based on attribute parameters of trusted execution environment, then model security and adaptability are improved, but device complexity increases due to parameter matching and sub-model selection processes

Engineering Contradiction:
Improvemodel adaptabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary model sub-setting and attribute parameter analysis before actual deployment. By pre-processing the model into sub-models with defined attribute parameters and pre-establishing the correspondence between sub-models and terminal device capabilities, the system reduces runtime complexity while maintaining high adaptability to different devices.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent utilizes attribute parameters (such as security levels, computational requirements, memory constraints) to dynamically select and configure appropriate sub-models for different terminal devices. This parameter-based selection mechanism enables flexible adaptation to diverse devices without requiring complex manual configuration, as the system automatically matches device capabilities with suitable sub-model parameters.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12314382B2Model protection method and apparatus, data processing method and apparatus, and device and medium
Publication Date: 2025.05.27 CHINA UNIONPAY
  • US12314382B2 patent drawing
  • US12314382B2 patent drawing
  • US12314382B2 patent drawing

AI summary

Disclosed in the present application are a model protection method and apparatus, a data processing method and apparatus, and a device and a medium, which are used for improving the security protection of a model. In the present application, a cloud device can determine, from a target model, a first sub-model which is stored in a trusted execution environment (TEE) of a terminal device, and send the first sub-model to the terminal device; the terminal device can store the first sub-model in the TEE of the terminal device; and the TEE can ensure that data processing, etc., are performed in a trusted environment.