用可信执行环境+零信任,让医疗生成AI处理数据时全程加密
Securing Generative AI in Healthcare: A Zero-Trust Architecture Powered by Confidential Computing on Google Cloud
- 结合零信任与硬件级加密,实现数据使用中全程保护
- 通过远程认证确保计算过程可验证,解决合规难题
- 适合需严守患者隐私和模型安全的医疗AI团队
生成式人工智能在医疗领域的应用受制于传统安全框架无法解决的数据在用阶段风险,即敏感患者数据与专有模型在运行中暴露。本文提出可信零信任框架(CZF),融合零信任架构的细粒度访问控制与可信执行环境(TEE)的硬件强制数据隔离。在Google Cloud上构建了多层架构方案,并分析其对真实威胁的防御能力。CZF通过硬件级加密确保数据在使用中始终受保护,远程认证提供工作负载完整性的密码学证明,将合规从流程性任务转化为可验证的技术事实,支持此前因安全与知识产权顾虑而受阻的多方协作。该框架通过弥合数据在用缺口并落实零信任原则,为医疗领域负责任地采用变革性AI技术建立了可信赖的基础。
原文摘要 · Abstract (English)
The integration of Generative Artificial Intelligence (GenAI) in healthcare is impeded by significant security challenges unaddressed by traditional frameworks, precisely the data-in-use gap where sensitive patient data and proprietary AI models are exposed during active processing. To address this, the paper proposes the Confidential Zero-Trust Framework (CZF), a novel security paradigm that synergistically combines Zero-Trust Architecture for granular access control with the hardware-enforced data isolation of Confidential Computing. We detailed a multi-tiered architectural blueprint for implementing the CZF on Google Cloud and analyzed its efficacy against real-world threats. The CZF provides a defense-in-depth architecture where data remains encrypted while in-use within a hardware-based Trusted Execution Environment (TEE). The framework's use of remote attestation offers cryptographic proof of workload integrity, transforming compliance from a procedural exercise into a verifiable technical fact and enabling secure, multi-party collaborations previously blocked by security and intellectual property concerns. By closing the data-in-use gap and enforcing Zero-Trust principles, the CZF provides a robust and verifiable framework that establishes the necessary foundation of trust to enable the responsible adoption of transformative AI technologies in healthcare.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。