Patents Assigned to Nanhu Laboratory
  • Patent number: 12639442
    Abstract: Provided is a secure and trusted use method and system for a large model based on confidential computing. In the method, a desensitization service party starts a service in a confidential computing environment; the confidential computing environment establishes a secure connection with a user terminal and the large model separately; the service receives, in the confidential computing environment, original data uploaded by the user terminal, and desensitizes the original data to obtain desensitized data; and the service sends the desensitized data to the large model based on the secure connection between the confidential computing environment and the large model. In this scheme, a third party is used to desensitize the data before utilizing the large model, and a targeted solution is provided to address the issue of third-party data leakage. Confidential computing is applied to the usage scenario of the large model, with the third-party service performing desensitization.
    Type: Grant
    Filed: June 18, 2025
    Date of Patent: May 26, 2026
    Assignee: Nanhu Laboratory
    Inventor: Lei Zhang
  • Patent number: 12580730
    Abstract: Provided are a method and system for improving homomorphic encryption performance based on a trusted execution environment (TEE) which includes: acquiring a computing task; decomposing the computing task into a group of subtasks according to a computing function list in the computing task; decomposing the subtasks in turn according to a list of provided basic homomorphic encryption operators (LoHEO) to obtain a suboperation set; labeling a suboperation as a “linear operation” or a “nonlinear operation” according to whether the suboperation can be directly implemented using an element in the LoHEO; processing each suboperation in turn: for a suboperation labeled as the linear operation, determining a homomorphic computing scheme according to a suboperation task, acquiring and using encrypted computing data for homomorphic encryption computing; for a suboperation labeled as the nonlinear operation, completing plaintext computing in a TEE; and returning an encrypted computing result to a user side.
    Type: Grant
    Filed: December 26, 2024
    Date of Patent: March 17, 2026
    Assignee: Nanhu Laboratory
    Inventors: Lei Zhang, Jiachun Liao, Jinhao Yu, Zehao Li, Panpan Tang
  • Patent number: 12533900
    Abstract: A trademark anti-counterfeiting method based on cryptography is provided, where a trademark owner prints an anti-counterfeiting code associated with a trademark image through a specific method. A verifier executes following verification process: collecting a trademark image by using a photosensitive device; measuring K feature points of collected trademark image to obtain N groups of color values; calculating M_i? and a hash value MH_i? of M_i?; using the photosensitive device to read N MH_i values, MH and MH signature values of anti-counterfeiting code, and using a public key to verify validity of MH signature value; if the MH signature value is valid, performing fusion operation on N MH_i values, determining whether result of fusion operation is MH, if so, determining that N MH_i values are valid; comparing MH_i? with MH_i one by one, and if the comparison is successful, the verification is successful, otherwise the verification fails.
    Type: Grant
    Filed: June 24, 2024
    Date of Patent: January 27, 2026
    Assignee: Nanhu Laboratory
    Inventor: Lei Zhang
  • Patent number: 12530451
    Abstract: A security calculation method and system for side channel resistance based on data marking is used to defend against a microarchitectural side-channel attack (SCA), particularly a transient-execution attack. The method is data-centric, and based on data marking. Through the data marking (page table entry (PTE) marking and instruction marking), and a delayed update mechanism dependent on the data marking, the method ensures that any subsequent instructions dependent on a memory-sensitive instruction are not executed in speculative execution, thereby preventing confidential data from being leaked when a conditional branch outcome is unknown, effectively resisting the SCA, improving the security, and minimizing the impact on central processing unit (CPU) performance.
    Type: Grant
    Filed: April 16, 2025
    Date of Patent: January 20, 2026
    Assignee: Nanhu Laboratory
    Inventors: Lei Zhang, Zedong Wang
  • Patent number: 12504993
    Abstract: A high-throughput confidential computing method and system based on a RISC-V architecture are provided. The method includes: S1, acquiring a hardware device tree configuration file to classify each physical resource into a normal partition or a security partition; S2, loading a security manager; S3, mapping memory resources in the normal and security partitions to the normal and security domains, respectively; registering CPU resources in the normal and security partitions to the normal and security domains, respectively; and registering an interrupt handler function; S4, linking an image file of a security file system with a security kernel file to generate an operating system image of the security domain; S5, reading the operating system image, and loading the same to a memory address of the security domain; and S6, executing the initialization of the security domain according to an interrupt request from the normal domain.
    Type: Grant
    Filed: November 25, 2024
    Date of Patent: December 23, 2025
    Assignee: Nanhu Laboratory
    Inventors: Lei Zhang, Zedong Wang
  • Publication number: 20250384134
    Abstract: Provided is a secure and trusted use method and system for a large model based on confidential computing. In the method, a desensitization service party starts a service in a confidential computing environment; the confidential computing environment establishes a secure connection with a user terminal and the large model separately; the service receives, in the confidential computing environment, original data uploaded by the user terminal, and desensitizes the original data to obtain desensitized data; and the service sends the desensitized data to the large model based on the secure connection between the confidential computing environment and the large model. In this scheme, a third party is used to desensitize the data before utilizing the large model, and a targeted solution is provided to address the issue of third-party data leakage. Confidential computing is applied to the usage scenario of the large model, with the third-party service performing desensitization.
    Type: Application
    Filed: June 18, 2025
    Publication date: December 18, 2025
    Applicant: Nanhu Laboratory
    Inventor: Lei ZHANG
  • Publication number: 20250365147
    Abstract: A zero-trust remote attestation service deployment system based on a confidential virtual machine (CVM) includes a trusted execution environment (TEE), a key management component, and an application service virtual machine. Leveraging the TEE technology, both application execution and storage are protected in a zero-trust state. The key management component runs in the TEE, while a service application runs in the CVM. Encryption keys of the CVM are securely stored and efficiently accessed through the TEE technology and the proposed key management component, as well as operational methods. This system enables a zero-trust service and effectively mitigates the risk of sensitive data theft caused by malicious software through memory scraping or code operation logic tampering.
    Type: Application
    Filed: May 14, 2025
    Publication date: November 27, 2025
    Applicant: Nanhu Laboratory
    Inventors: Lei ZHANG, Zhichao YAN
  • Patent number: 12483393
    Abstract: Provided is a method of controlling remote data based on confidential computing and a system thereof. The method includes: sending, by a data provider, a public key P to a Proxy Module (PM) operating in a confidential computing environment of a data consumer; sharing, by the data provider, shared data D to the PM; creating, by the PM, a secret key K for data D, and carrying out trusted encryption sealing; using, by the data provider, a secret key S to generate a token T for a data control signal, and sending the token to the PM; parsing, by the PM, the data control signal contained in T; carrying out, by the PM, corresponding control on the corresponding data D; using, by the PM, a secret key S? to carry out trusted signature on an operation result and sending the operation result to the data provider; obtaining the operation result.
    Type: Grant
    Filed: December 29, 2024
    Date of Patent: November 25, 2025
    Assignee: Nanhu Laboratory
    Inventor: Lei Zhang
  • Publication number: 20250322067
    Abstract: A security calculation method and system for side channel resistance based on data marking is used to defend against a microarchitectural side-channel attack (SCA), particularly a transient-execution attack. The method is data-centric, and based on data marking. Through the data marking (page table entry (PTE) marking and instruction marking), and a delayed update mechanism dependent on the data marking, the method ensures that any subsequent instructions dependent on a memory-sensitive instruction are not executed in speculative execution, thereby preventing confidential data from being leaked when a conditional branch outcome is unknown, effectively resisting the SCA, improving the security, and minimizing the impact on central processing unit (CPU) performance.
    Type: Application
    Filed: April 16, 2025
    Publication date: October 16, 2025
    Applicant: Nanhu Laboratory
    Inventors: Lei ZHANG, Zedong WANG
  • Patent number: 12436796
    Abstract: Provided is a novel method of measuring a confidential computing application layer and a system thereof. The method includes: utilizing characteristic of static measurement of an existing underlying component of confidential computing at a virtual machine level to realize the trusted measurement of a trigger module TG_APP at an underlying measurement level; utilizing the TG_APP which is subjected to the trusted measurement to carry out the trusted measurement of a user-mode application; and utilizing the trusted TG_APP which is measured by a confidential computing chip layer to realize the trusted measurement of the application layer. The method not only avoids the problem of a huge amount of measurement of confidential computing, but also realizes the measurement of the accurate application of the application layer, which well solves the problem of measurement of the confidential computing application layer based on a virtual machine.
    Type: Grant
    Filed: January 7, 2025
    Date of Patent: October 7, 2025
    Assignee: Nanhu Laboratory
    Inventor: Lei Zhang
  • Patent number: 12425185
    Abstract: Provided is a confidential computing-based method for customizedly balancing between security and performance of homomorphic encryption, including the following steps: receiving a computing task, security and performance custom parameters, and encrypted computing data; when a user performs security customization, dividing the computing data into multiple security levels according to the security custom parameters, and according to the security levels of data involved in computing, executing partial corresponding computing task outside a trusted execution environment, and executing partial computing task in the trusted execution environment; when the user performs performance customization, dynamically allocating resources according to the performance custom parameters, executing partial computing task in the trusted execution environment, and executing partial computing task outside the trusted execution environment; and finally, returning a computing result to a request side.
    Type: Grant
    Filed: December 28, 2024
    Date of Patent: September 23, 2025
    Assignee: Nanhu Laboratory
    Inventors: Lei Zhang, Jinhao Yu, Jiachun Liao, Zehao Li, Panpan Tang
  • Patent number: 12394192
    Abstract: A small-size vehicle detection deep learning model based on feature fusion of multi-scale modules is provided, which solves the problem of small-size vehicle image detection. The model includes a Backbone network, a Neck layer and a Head network, wherein a C2f_DCNv3 module based on the combination of deformable convolution v3 (DCNv3) and a cross stage feature fusion (C2f) module and an SPPF_LSKA module based on the combination of a spatial pyramid pooling fast (SPPF) layer and a large separable kernel attention (LSKA) module are introduced into the Backbone network; a C2f_SCConv module based on the combination of spatial and channel reconstruction convolution (SCConv) and a C2f module is introduced into the Neck layer; and a multi-scale kernel detection (MSK_Detect) module is introduced into the Head network.
    Type: Grant
    Filed: December 30, 2024
    Date of Patent: August 19, 2025
    Assignee: Nanhu Laboratory
    Inventors: Yicheng Qiu, Feng Sha, Li Niu
  • Patent number: 12314419
    Abstract: A cross-domain sharing method and apparatus for zero-trust sensitive big data based on privacy computation is provided, so that a sensitive data provider can safely and fully import data into a database of a computing environment of a data user in a cross-domain manner for secondary use, and ensure that no malicious party can steal original sensitive data. The data user can develop and deploy an application as usual and faces no limitation on a deployment environment. With a zero-trust sharing environment, the sensitive data can be fully provided for a user area while the data provider only needs to examine the application of the user and approve the application to use the corresponding sensitive data if the application does not have a malicious leakage behavior. Further, the data provider can terminate data use by the application at any time by disabling an account.
    Type: Grant
    Filed: August 21, 2023
    Date of Patent: May 27, 2025
    Assignee: Nanhu Laboratory
    Inventors: Lei Zhang, Zhichao Yan
  • Patent number: 12316741
    Abstract: Provides is an adaptive homomorphic encryption method based on a trusted execution environment. The method can achieve adaptive configuration and switching of homomorphic encryption parameters and schemes in a chip-level security environment. While ensuring the security of private data and computing results, the efficiency of a homomorphic encryption algorithm is improved, and the usability of different homomorphic encryption algorithms is expanded, thus greatly improving the practicability of a homomorphic encryption method, and promoting the implementation of a privacy protection technology with innovative ideas of integrating different technical routes.
    Type: Grant
    Filed: November 13, 2024
    Date of Patent: May 27, 2025
    Assignee: Nanhu Laboratory
    Inventors: Lei Zhang, Zehao Li, Jiachun Liao, Jinhao Yu
  • Patent number: 12021849
    Abstract: A privacy computing-enabled migration method for large-scale persistent data across platforms is provided. By virtue of a sealing key management service SKMS, based on trusted sealing and trusted connection which are the basic functions of privacy computing, large-scale migration of privacy data with low deployment cost, high security and high efficiency can be realized by providing download links to platforms that meet requirements, thus greatly improving the flexibility of data deployment and use and the landing of trusted sealing technology.
    Type: Grant
    Filed: May 30, 2023
    Date of Patent: June 25, 2024
    Assignee: Nanhu laboratory
    Inventor: Lei Zhang
  • Patent number: 12010249
    Abstract: A method and device for zero-trust fusion computation of multi-party data is provided, which adopts a chip-level based trusted execution environment (TEE) technique, and by improving a development preparation phase of a fusion computation background and improving a calculation phase, enable fusion computation of multi-party data to be performed in a zero-trust secure running environment, guaranteeing that the data is in a secure state without trusting any party during an entire process of transmission, storage and fusion computation, and allowing for enhanced data privacy protection. The solution brings many advantages in terms of data storage security, data transmission security and data use security as well as universality and performance superiority.
    Type: Grant
    Filed: September 18, 2023
    Date of Patent: June 11, 2024
    Assignee: NANHU LABORATORY
    Inventors: Lei Zhang, Zhichao Yan
  • Patent number: 11914609
    Abstract: The present disclosure provides a method for interconnecting a data lake and a relational database, including the following steps: S1: adding a data source class of a relational database to a data lake; S2: matching and using, by the data lake, a data source class of the relational database; and S3: determining and loading a corresponding driver according to the data source class, so as to connect the corresponding relational database. By cascading a data source registering configuration file, a relational database configuration file and a driver package catalog in a parameter passing method, when the data lake is started, a specific database to be used is designated unnecessarily, but a corresponding database is used directly. The configuration file is also traversed unnecessarily, but the user acquires configuration information as required in the parameter passing method.
    Type: Grant
    Filed: December 21, 2022
    Date of Patent: February 27, 2024
    Assignees: NANHU LABORATORY, BEIJING BIG DATA ADVANCED TECHNOLOGY RESEARCH INSTITUTE
    Inventors: Hao Liu, Tao Zhang, Lei Zhang, Peng Wang, Zhefeng Liu, Zhiling Chen, Qiuye Wang, Wei Chen, Yinlong Liu, Chenxi Yu
  • Patent number: 11886554
    Abstract: The present invention discloses a method for protecting a deep learning model based on confidential computing. In this solution, a use process of a deep learning model is divided into two stages: Data preprocessing and inference. At the data preprocessing stage, a data preprocessing model is mainly used to process inference data of an authorized user. The data preprocessing model is a lightweight processing module, which occupies less computing resources, and the data preprocessing model is deployed in a confidential computing environment. At the inference stage, an inference model is used to perform inference on preprocessed data, and the inference model is deployed in a common computing environment. In the entire process, copyright attestation of the deep learning model can be implemented without affecting inference accuracy of the model, and the infringement of the model copyright can be effectively resisted through model forgery, transfer learning, knowledge distillation, and the like.
    Type: Grant
    Filed: February 28, 2023
    Date of Patent: January 30, 2024
    Assignee: Nanhu Laboratory
    Inventors: Lei Zhang, Wensheng Tian
  • Patent number: 11870904
    Abstract: A method for encrypting and decrypting data across domains based on privacy computing is provided. A data provider deploys a base key for a data user in advance, and when the data user needs to use the data at a later stage, the data provider generates a data token about a data key based on the base key, and then transmits encrypted data and the data token to the data user. The user obtains the data key based on its own base key in a privacy environment according to the data token, and uses the data key in the privacy environment to realize use of the encrypted data. A transmission process does not involve transmission of the key; therefore, even if a transmission channel is not secure, security of the data can still be ensured, and even if private data is used, the data itself cannot be obtained.
    Type: Grant
    Filed: January 20, 2023
    Date of Patent: January 9, 2024
    Assignee: NANHU LABORATORY
    Inventors: Lei Zhang, Ruiyan Xia
  • Patent number: 11789899
    Abstract: The present disclosure provides a high-performance data lake system and a data storage method. The data storage method includes the following steps: S1: converting a file into a file stream; S2: converting the file stream into an array in which multiple subarrays are nested; and S3: converting the array into a resilient distributed dataset (RDD), and storing the RDD to a storage layer of a data lake. The present disclosure provides a nested field structure, which lays the foundation for parallel processing in reading, and effectively improves read performance. Furthermore, the present disclosure flexibly generates a number of nested subarrays according to hardware cores, such that the data lake achieves better extension performance, and can keep optimal writing efficiency for different users.
    Type: Grant
    Filed: November 17, 2022
    Date of Patent: October 17, 2023
    Assignees: Nanhu Laboratory, Advanced Institute of Big Data, Beijing
    Inventors: Hao Liu, Zhiling Chen, Tao Zhang, Peng Wang, Qiuye Wang, Chenxi Yu, Wei Chen, Yinlong Liu, Zhefeng Liu, Yonggang Tu