IP Library › Granted Patent US 12,455,956
Granted Patent B2
US 12,455,956 · App. 18/400,166 · Granted Oct 28, 2025

Model running methods and apparatuses

Inventors: Wanyu Gu (Hangzhou, CN); Xianyi Zheng (Hangzhou, CN); Zhi Xin (Hangzhou, CN); Li Guo (Hangzhou, CN); Xiaofei Wan (Hangzhou, CN)
Assignee: Alipay (Hangzhou) Information Technology Co., Ltd.
G06F21/53
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,455,956
App. No.
18/400,166
Filed
Dec 29, 2023
Granted
Oct 28, 2025
Kind
B2
Art Unit
2435
USPC
726/2
Abstract

This specification discloses model running methods, apparatuses, computer-readable storage media and systems. In an example method, an original model is split to obtain a basic model and a trusted execution environment (TEE) model; and data of the basic model and data of the TEE model are delivered to a terminal device, so that a rich execution environment (REE) in the terminal device runs the data of the basic model, and a TEE in the terminal device runs the data of the TEE model.

Claims (74)

1. A computer-implemented method, comprising:

splitting an original model to obtain a basic model and a trusted execution environment (TEE) model; and

delivering data of the basic model and data of the TEE model to a terminal device to enable a rich execution environment (REE) in the terminal device runs the data of the basic model, and a TEE in the terminal device runs the data of the TEE model;

wherein:

after obtaining the TEE model and before delivering the data of the TEE model to the terminal device, the computer-implemented method further comprises: encrypting the TEE model based on a pre-obtained encryption key to obtain an encrypted model; and

the data of the TEE model comprises the encrypted model;

wherein the delivering data of the basic model and data of the TEE model to a terminal device comprises:

encapsulating the encrypted model into a TEE operator;

generating a reconstructed model based on the basic model and the TEE operator; and

delivering the reconstructed model to the REE in the terminal device.

2. The computer-implemented method according to claim 1 , wherein the splitting an original model comprises at least one of:

splitting the original model based on a predetermined split ratio;

splitting a neural network used by the original model, and using the first M layers as the basic model and the last N layers as the TEE model, wherein a total quantity of layers of the neural network is M+N; or

splitting the original model based on a size of a running space of the TEE in the terminal device.

3. The computer-implemented method according to claim 1 , wherein the delivering data of the basic model and data of the TEE model to a terminal device comprises:

delivering the data of the basic model to the REE in the terminal device; and

delivering the data of the TEE model to the TEE in the terminal device by using a TEE dedicated channel.

4. A computer-implemented method, comprising:

receiving data of a basic model and data of a trusted execution environment (TEE) model, wherein the data of the basic model and the data of the TEE model are obtained after an original model is split into the basic model and the TEE model;

running the basic model by using a rich execution environment (REE); and

running the TEE model by using a TEE;

wherein:

the receiving data of a basic model and data of a TEE model comprises: receiving, by the REE, a reconstructed model, wherein the reconstructed model is generated based on the basic model and a TEE operator obtained by encapsulating an encrypted model;

the running the basic model by using an REE comprises: running, by the REE, the basic model in the reconstructed model; and

the running the TEE model by using a TEE comprises:

receiving, by the TEE, the TEE operator to from the REE;

decapsulating, by the TEE, the TEE operator to obtain the encrypted model;

decrypting, by the TEE, the encrypted model by using a pre-obtained decryption key to obtain the TEE model; and

running, by the TEE, the TEE model.

5. The computer-implemented method according to claim 4 , wherein the receiving data of a basic model and data of a TEE model comprises:

receiving, by the REE, the data of the basic model; and

receiving, by the TEE, the data of the TEE model by using a TEE dedicated channel.

6. The computer-implemented method according to claim 4 , wherein the data of the TEE model comprises the encrypted model generated after the TEE model is encrypted.

7. The computer-implemented method according to claim 4 , wherein the TEE operator is received from the REE in response to that the REE is not able to recognize the TEE operator when the REE runs to the TEE operator in the reconstructed model.

8. The computer-implemented method according to claim 4 , wherein after the running the TEE model by using a TEE, the computer-implemented method further comprises:

outputting, by the TEE to the outside of the TEE, a feature vector obtained after running the TEE model.

9. The computer-implemented method according to claim 4 , wherein after the running the TEE model by using a TEE, the computer-implemented method further comprises: obtaining, by the TEE, an identification result based on a feature vector obtained after running the TEE model, and outputting the identification result to the outside of the TEE.

10. A computer-implemented system comprising a terminal device that comprises:

one or more processors; and

one or more memory devices interoperably coupled with the one or more processors and having tangible, non-transitory, computer-readable storage media storing one or more instructions that, when executed by the one or more processors, perform operations comprising:

receiving data of a basic model and data of a trusted execution environment (TEE) model, wherein the data of the basic model and the data of the TEE model are obtained after an original model is split into the basic model and the TEE model;

running the basic model by using a rich execution environment (REE); and

running the TEE model by using a TEE;

wherein:

the receiving data of a basic model and data of a TEE model comprises: receiving, by the REE, a reconstructed model, wherein the reconstructed model is generated based on the basic model and a TEE operator obtained by encapsulating an encrypted model;

the running the basic model by using an REE comprises: running, by the REE, the basic model in the reconstructed model; and

the running the TEE model by using a TEE comprises:

receiving, by the TEE, the TEE operator to from the REE;

decapsulating, by the TEE, the TEE operator to obtain the encrypted model;

decrypting, by the TEE, the encrypted model by using a pre-obtained decryption key to obtain the TEE model; and

running, by the TEE, the TEE model.

11. The computer-implemented system according to claim 10 , wherein the receiving data of a basic model and data of a TEE model comprises:

receiving, by the REE, the data of the basic model; and

receiving, by the TEE, the data of the TEE model by using a TEE dedicated channel.

12. The computer-implemented system according to claim 10 , wherein the data of the TEE model comprises the encrypted model generated after the TEE model is encrypted.

13. The computer-implemented system according to claim 10 , further comprising a server that comprises:

one or more second processors; and

one or more second memory devices interoperably coupled with the one or more second processors and having second tangible, non-transitory, computer-readable storage media storing one or more second instructions that, when executed by the one or more second processors, perform second operations comprising:

splitting the original model to obtain the basic model and the TEE model; and

delivering data of the basic model and data of the TEE model to the terminal device to enable the REE in the terminal device runs the data of the basic model, and the TEE in the terminal device runs the data of the TEE model.

14. The computer-implemented system according to claim 13 , wherein the splitting an original model comprises at least one of:

splitting the original model based on a predetermined split ratio;

splitting a neural network used by the original model, and using the first M layers as the basic model and the last N layers as the TEE model, wherein a total quantity of layers of the neural network is M+N; or

splitting the original model based on a size of a running space of the TEE in the terminal device.

15. The computer-implemented system according to claim 13 , wherein the delivering data of the basic model and data of the TEE model to a terminal device comprises:

delivering the data of the basic model to the REE in the terminal device; and

delivering the data of the TEE model to the TEE in the terminal device by using a TEE dedicated channel.

16. The computer-implemented system according to claim 13 , wherein:

after obtaining the TEE model and before delivering the data of the TEE model to the terminal device, the second operations further comprise encrypting the TEE model based on a pre-obtained encryption key to obtain the encrypted model,

the data of the TEE model comprises the encrypted model; and

the delivering data of the basic model and data of the TEE model to a terminal device comprises:

encapsulating the encrypted model into the TEE operator;

generating the reconstructed model based on the basic model and the TEE operator; and

delivering the reconstructed model to the REE in the terminal device.

Assignments (3)
OWNERSHIP STATEMENT Recorded Jan 13, 2026
From: XIN, ZHI
To: ALIPAY (HANGZHOU) INFORMATION TECHNOLOGY CO., LTD.
Reel/Frame 075096/0221 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 2, 2025
From: GU, WANYU; GUO, LI; WAN, XIAOFEI
To: ALIPAY (HANGZHOU) INFORMATION TECHNOLOGY CO., LTD.
Reel/Frame 072133/0661 →
EMPLOYMENT AGREEMENT Recorded Sep 2, 2025
From: ZHENG, XIANYI
To: ALIPAY (HANGZHOU) INFORMATION TECHNOLOGY CO., LTD.
Reel/Frame 072793/0665 →
Priority Claims (1)
CN 202111309418.7 · Nov 6, 2021 · national
Continuity (3)
Continuation PCTCN2022128036 · Oct 27, 2022
Related Publication 20240134965A1 · Apr 25, 2024
Related Publication 20240232331A9 · Jul 11, 2024
References Cited (18)
US 11436343B2 · Maor · 2022 [cited by examiner]
US 20200082279A1 · Arora · 2020 [cited by examiner]
US 20210165883A1 · Zhang · 2021 [cited by applicant]
US 20210200882A1 · Maor et al. · 2021 [cited by applicant]
US 20210232916A1 · Veneroso · 2021 [cited by examiner]
US 20240273220A1 · Nakai · 2024 [cited by examiner]
CN 102624870 · 2012 [cited by applicant]
CN 111275202 · 2020 [cited by applicant]
CN 111786955 · 2020 [cited by applicant]
CN 112947935 · 2021 [cited by applicant]
CN 113553204 · 2021 [cited by applicant]
CN 113569265 · 2021 [cited by applicant]
CN 114091653 · 2022 [cited by applicant]
WO WO2018092071 · 2018 [cited by applicant]
WO WO2019242423 · 2019 [cited by applicant]
International Preliminary Report on Patentability in International Appln. No. PCT/CN2022/128036, mailed on May 16, 2024, 14 pages (with English translation). [cited by applicant]
International Search Report and Written Opinion in International Appln. No. PCT/CN2022/128036, mailed on Jan. 18, 2023, 17 pages (with English translation). [cited by applicant]
Liu et al., “Research on the construction of virtualized package model and its technical methods in knowledge ecosystem of library,” information science, Feb. 2015, p. 121-131 (with English Abstract). [cited by applicant]