GB/T 45958-2025 in English
VALIDCybersecurity technology—Security framework for artificial intelligence computing platform
- Issued on:2025-08-01
- Implemented on:2026-02-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$262.00
| Standard No: | GB/T 45958-2025 |
| Document status: | VALID |
| Title in English: | Cybersecurity technology—Security framework for artificial intelligence computing platform |
| Title in Chinese: | 网络安全技术 人工智能计算平台安全框架 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 1~3 business days |
| Issued on: | 2025-08-01 |
| Implemented on: | 2026-02-01 |
| Chinese Classification: | L80-Data encryption |
| Professional Classification: | GB-National Standard |
| Related Keywords: | control security functions security
resource-layer security functions resource-layer security data security requirements provide security models data security interface security protection attack identification security framework |
| Related Topics: | cyber security
|
《GB/T 45958-2025网络安全技术 人工智能计算平台安全框架》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准委。
Introduction
Standard Overview and Development Background
GB/T 45958-2025, "Cybersecurity Technology - Security Framework for Artificial Intelligence Computing Platforms," is my country's first national standard specifically addressing the security of artificial intelligence computing platforms. Proposed and coordinated by the National Cybersecurity Standardization Technical Committee (SAC/TC260), it was jointly drafted by over 60 organizations, including Huawei Technologies Co., Ltd. and the China Electronics Standardization Institute. Published in 2025, the standard aims to address new security challenges arising from the widespread application of artificial intelligence technology across various fields.
With the rapid development of artificial intelligence technology and the large-scale deployment of specialized hardware devices such as artificial intelligence servers and artificial intelligence accelerators, traditional cybersecurity frameworks are no longer able to fully address the unique security requirements of AI computing platforms. This standard was developed against this backdrop to provide comprehensive security guidance for the design, construction, application, and operation and maintenance of AI computing platforms.
Analysis of the Core Security Framework
The standard establishes a three-dimensional security framework for artificial intelligence computing platforms, including three core components: security functions, security management, and role security responsibilities.
| Security Dimensions | Main Contents | Key Technical Requirements | Corresponding Risk Prevention and Control |
|---|---|---|---|
| Security Functions | Security of the Resource Layer, Scheduling Layer, and Application Support Layer | Integrity Verification, Security Isolation, and Password Protection | Technical Security Risks |
| Security Management | Seven Aspects, including Identity, Password, Log, Monitoring, and Auditing | Compliance Management, Process Traceability, and Risk Management | Management Security Risks |
| Roles and Responsibilities | Division of Security Responsibilities among Four Types of Participants | Clear responsibilities, collaborative mechanisms, and accountability traceability | Organizational security risks |
Detailed explanation of resource-layer security functions
Resource-layer security is the foundation of AI computing platform security, covering security requirements in four areas: computing resources, storage resources, network resources, and virtual resources.
Computing Resource Security
In view of the particularity of AI acceleration processors and AI servers, the standard proposes 7 specific security requirements:
- Firmware integrity and authenticity verification mechanism
- Version anti-rollback protection
- Integrity verification interface provision
- Management interface security protection
- Fault monitoring and disposal
- Resource security isolation
- Trusted execution environment construction
Storage Resource Security
In view of the large amount of checkpoint data and model parameters generated during model training and inference, the standard requires:
- Redundant storage to prevent data loss
- Distributed architecture to improve availability
- Multiple backup and anti-ransomware encryption
- Cryptographic technology to protect confidentiality and integrity
Implementation of Scheduling Layer Security Functions
Scheduling layer security ensures the reliability and security of resource allocation and task execution, including resource scheduling security and task scheduling security.
| Scheduling Type | Security Requirements | Technical Implementation | Typical Risks |
|---|---|---|---|
| Resource Scheduling Security | Unified Management Scheduling, Security Isolation, Anomaly Monitoring | Policy Engine, Isolation Technology, Monitoring and Alarm | Resource Hijacking, Malicious Occupation |
| Task Scheduling Security | Fault Recovery, Safe Migration | Checkpoint Technology, Hot Migration | Task Interruption, Data Loss |
Application Support Layer Security Practices
Application support layer security focuses on the security of three key links: data processing, model training, and model reasoning.
Data Processing Security
The standard innovatively proposes the concept of a dataset bill of materials, requiring:
- Generate a dataset bill of materials file and transfer it with the dataset
- Support integrity, authenticity, and version correctness verification
- Implement security defect tracing
- Protect the confidentiality and integrity of important data
Model Training Security
For the machine learning model training process, the following requirements apply:
- Generate a model bill of materials file
- Retain tamper-proof log records
- Support compliance auditing and problem tracing
Model Reasoning Security
For the model reasoning link, four core security measures are proposed:
- Model authorization control and encryption and decryption protection
- Verification of integrity, authenticity, and version correctness
- Security testing of reasoning requests
- Security testing of reasoning results
Construction of a security management system
The standard constructs a complete security management system from seven dimensions, which complements the security functions.
| Management Areas | Core Requirements | Implementation Points | Related Standards |
|---|---|---|---|
| Identity Management | Identity Authentication and Access Control | Multi-factor Authentication, Least Privilege | GB/T 22239-2019 |
| Password Management | Algorithm Security and Key Management | National Secret Algorithm, Full Lifecycle Management | GB/T 39786-2021 |
| Log Management | Full Process Logging | Immutable, transparent auditing | GB/T 22239-2019 |
| Security Monitoring | Continuous Security Monitoring | Real-time monitoring, abnormal alarm | GB/T 22239-2019 |
| Security Audit | Resource Usage Audit | Malicious occupation detection, container escape identification | GB/T 22239-2019 |
| Risk Management | Vulnerability Fixes and Updates | Timely Fixes, Patch Releases | GB/T 22239-2019 |
| Personal information protection | Compliance with regulations for processing personal information | Informed consent, minimum necessary | GB/T 35273-2020 |
Division of security responsibilities
The standard clarifies the security responsibilities of four types of participants and builds a collaborative protection system.
Responsibilities of the Platform Provider
As the infrastructure provider, assume the most comprehensive security responsibility:
- Provide technical support for security functions
- Implement a security management system
- Ensure compliance with password application
- Implement personal information protection
Responsibilities of the Data Provider
Focus on the security of the data supply link:
- Provide secure data sets
- Support verification and traceability
- Support transparent auditing
Responsibilities of the Model Provider
Responsible for model development and supply security:
- Comply with data security requirements
- Provide security models or interfaces
- Support model verification and auditing
Responsibilities of the Application Provider
Assume ultimate application security responsibility:
- Comply with general security requirements
- Protect model and data security
- Interface security protection
- Attack identification and blocking
- Logging and tracing
Implementation recommendations and best practices
Based on the standard requirements, the following implementation recommendations are proposed:
Technical implementation level
- Establish a firmware security management system for AI accelerated computing resources to implement integrity verification and version control
- Deploy a distributed storage architecture to ensure checkpoint data redundancy and availability
- Implement network partitioning and isolation to distinguish between data processing, model training, and inference networks
- Adopt trusted execution environment technology to protect in-memory model and data security
Management implementation level
- Develop a bill of materials management system to achieve full lifecycle traceability of data and models
- Establish a multi-role collaborative security mechanism to clarify responsibility boundaries and collaboration processes
- Implement hierarchical log management to meet audit requirements of different granularities
- Carry out regular security assessments to promptly discover and fix vulnerabilities
Compliance implementation level
- Follow the requirements of the Level Protection System and make adaptive adjustments based on AI characteristics
- Implement personal information protection regulations to ensure legal and compliant data processing
- Adopt national standard cryptographic algorithms to ensure encryption security strength
- Establish a compliance audit mechanism and conduct regular security compliance inspections
Standard evolution and future prospects
GB/T 45958-2025, as the first national standard in the field of artificial intelligence computing platform security, reflects my country's forward-looking thinking in AI security governance. With the rapid development of AI technology, future standards may need to:
- Adapt to the security requirements of new AI architectures such as large models
- Cover emerging technologies such as federated learning and privacy-preserving computing
- Strengthen coordination and mutual recognition with international standards
- Continuously update security requirements to respond to new threats
The implementation of this standard will effectively promote the healthy and orderly development of my country's artificial intelligence industry and lay a solid foundation for building a secure and trustworthy AI ecosystem.

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 47020-2026 in English
Cybersecurity technology—Data format of software bill of materials
2026-01-28 -

GB/T 46068-2025 in English
Data security technology—Security certification requirements for cross-border processing activity of personal information
2025-08-29 -

GB/T 29240-2024 in English
Cybersecurity technology—General security technical specification for terminal computer
2024-10-26 -

GB/T 46334-2025 in English
Security testing methods for critical network devices—Programmable logic controller(PLC)
2025-10-05