Data processing methods, systems, devices, equipment, storage media, and program products

By combining the keys of the parent company and subsidiaries for decryption and distributed processing in the confidential environment of the parent company's computing nodes, the security problem of data sharing within the group was solved, and data security and processing efficiency were improved.

CN120834960BActive Publication Date: 2025-12-02INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511310673.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-15
Publication Date
2025-12-02
Estimated Expiration
2045-09-15

AI Technical Summary

Technical Problem

The data sharing and processing methods between subsidiaries and the parent company within the group are in plaintext transmission, posing a significant risk of data leakage and making it difficult to guarantee data security.

Method used

A confidential environment is set up on the parent company's computing nodes. A disk storage key is generated by combining the parent company's key with the subsidiary's key. The disk storage key is then used to decrypt the data stored on the subsidiary's nodes and perform distributed processing in the confidential environment to ensure data security.

Benefits of technology

By processing data in a confidential environment, data leakage is avoided, data protection requirements are met, processing efficiency is improved, and the problems of large data volume and high processing time requirements are solved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120834960B_ABST
    Figure CN120834960B_ABST
Patent Text Reader

Abstract

This application provides a data processing method, system, apparatus, device, storage medium, and program product, relating to the field of big data. Applied to any parent company computing node in a confidential environment cluster, the parent company computing node is configured with a confidential environment. The method includes: initiating a data usage request to a subsidiary node and receiving a subsidiary key sent by the subsidiary node; combining the parent company key and the subsidiary key to obtain a disk storage key; decrypting the disk storage data of the subsidiary node stored in the confidential environment using the disk storage key; performing distributed processing on the decrypted disk storage data in the confidential environment to obtain a processing result, and sending the processing result to the subsidiary node. This application's method reduces the risk of data leakage and meets data protection requirements; by distributing the processing tasks through the parent company computing node, it simultaneously solves the problems of large data volumes and high processing time requirements.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of big data, and in particular to a data processing method, system, apparatus, equipment, storage medium, and program product. Background Technology

[0002] As digital transformation deepens, the amount of data generated within the group and by its affiliates is growing exponentially. Data between different subsidiaries, departments, and partners within the group often involves sensitive personal information, trade secrets, or important data, requiring strict segregation and minimal use.

[0003] When faced with massive amounts of data that require joint processing by parent and subsidiary companies, the traditional method of data sharing and processing between subsidiaries and parent companies within a group is often plaintext transmission. Plaintext transmission poses a significant risk of data leakage, making it difficult to guarantee the security of data within the group.

[0004] Therefore, to ensure the security of data within the group, a data processing method for group data is needed. Summary of the Invention

[0005] This application provides a data processing method, system, apparatus, device, storage medium, and program product to solve the technical problem that data security is difficult to guarantee.

[0006] Firstly, this application provides a data processing method applied to any parent company computing node in a parent company confidential environment cluster, wherein the parent company computing node is configured with a confidential environment, including:

[0007] Initiate a data usage request to the subsidiary node and receive the subsidiary key sent by the subsidiary node;

[0008] Combine the parent company's key with the subsidiary's key to obtain the disk storage key;

[0009] Use the disk write key to decrypt the disk write data of subsidiary nodes stored in a confidential environment;

[0010] In a confidential environment, the decrypted data is processed in a distributed manner to obtain the processing results, which are then sent to the subsidiary node.

[0011] Secondly, this application provides a data processing method applied to subsidiary nodes, including:

[0012] In response to a data usage request sent by the parent company's computing node, the subsidiary's key is sent to the parent company's computing node, so that the parent company's computing node can combine the parent company's key with the subsidiary's key to obtain a disk storage key. The disk storage key is used to decrypt the disk storage data of the subsidiary node in the confidential environment. The decrypted disk storage data is then processed in a distributed manner in the confidential environment to obtain the processing result.

[0013] Obtain the processing result.

[0014] Thirdly, this application provides a data processing system, including: the system includes a parent company confidential environment cluster and several subsidiary nodes, the parent company confidential environment cluster includes several parent company computing nodes, and the parent company computing nodes are equipped with a confidential environment;

[0015] The parent company's computing node is used to initiate data usage requests to the subsidiary nodes and receive subsidiary keys sent by the subsidiary nodes.

[0016] The subsidiary node is used to send the subsidiary key to the parent computing node in response to a data usage request sent by the parent computing node;

[0017] The parent company's computing node is also used to combine the parent company's key with the subsidiary's key to obtain the disk storage key; the disk storage key is used to decrypt the disk storage data of the subsidiary corresponding to the data usage request, and the disk storage data is stored in a confidential environment; the disk storage data is processed in a distributed manner in the confidential environment to obtain the processing result, and the processing result is sent to the subsidiary node;

[0018] Subsidiary nodes are also used to obtain processing results.

[0019] Fourthly, this application provides a data processing apparatus, applied to any parent company computing node in a parent company confidential environment cluster, wherein the parent company computing node is configured with a confidential environment, including:

[0020] The key receiving module is used to initiate data usage requests to subsidiary nodes and receive subsidiary keys sent by subsidiary nodes.

[0021] The disk write key acquisition module is used to combine the parent company's key with the subsidiary's key to obtain the disk write key;

[0022] The disk data decryption module is used to decrypt the disk data of subsidiary nodes stored in a confidential environment using the disk key;

[0023] The distributed data processing module is used to perform distributed processing on the decrypted disk data in a confidential environment, obtain the processing results, and send the processing results to the subsidiary node.

[0024] Fifthly, this application provides a data processing apparatus for use in a subsidiary node, comprising:

[0025] The key sending module is used to respond to the data usage request sent by the parent company's computing node and send the subsidiary key to the parent company's computing node, so that the parent company's computing node can combine the parent company key and the subsidiary key to obtain the disk key. The disk key is used to decrypt the disk data of the subsidiary node stored in the confidential environment, and the disk data is processed in a distributed manner in the confidential environment to obtain the processing result.

[0026] The processing result acquisition module is used to obtain the processing results.

[0027] Sixthly, this application provides an electronic device, including: a processor and a memory communicatively connected to the processor;

[0028] The memory stores the instructions that the computer executes;

[0029] The processor executes computer-executable instructions stored in memory to implement the method of either the first aspect or the method of either the second aspect.

[0030] In a seventh aspect, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the method of any one of the first aspects or the method of any one of the second aspects.

[0031] Eighthly, this application provides a computer program product, including a computer program that, when executed by a processor, implements the method of any one of the first aspects or the method of any one of the second aspects.

[0032] The data processing method, system, apparatus, equipment, storage medium, and program products provided in this application ensure the security of subsidiary data and prevent its leakage by setting up a confidential environment on the parent company's computing node and storing the subsidiary's disk-based data for joint processing in the confidential environment. When joint processing is required, the subsidiary's key is obtained and combined with the parent company's key in the confidential environment to decrypt the subsidiary's disk-based data stored in the confidential environment. The disk-based data is then processed in the parent company's confidential environment, reducing the risk of data leakage and meeting data protection requirements. The distributed processing tasks on the parent company's computing node also solve the problems of large data volume and high processing time requirements. Attached Figure Description

[0033] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0034] Figure 1 A diagram illustrating data transmission between the parent company and its various subsidiaries within a group;

[0035] Figure 2 A flowchart illustrating a data processing method provided in this application embodiment. Figure 1 ;

[0036] Figure 3 This application provides a structural framework diagram for efficient group data processing based on a distributed confidential environment.

[0037] Figure 4 A flowchart illustrating a data processing method provided in this application embodiment. Figure 2 ;

[0038] Figure 5 This is an interactive schematic diagram of a data processing system provided in an embodiment of this application;

[0039] Figure 6 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application;

[0040] Figure 7 This is a schematic diagram of another data processing apparatus provided in an embodiment of this application;

[0041] Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.

[0042] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0043] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application.

[0044] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of the relevant data all comply with relevant laws, regulations, and standards, and necessary measures have been taken to ensure that they do not violate public order and good morals. Corresponding operation portals are provided for users to choose to authorize or refuse.

[0045] Furthermore, the technical solution involved in this application, which involves big data analysis of user information (including but not limited to personal biometrics, identity data, consumption data, asset data, electronic terminal operation data, etc.) and the use of artificial intelligence technology for automated decision-making, and makes decisions with significant impact based on the results of automated decision-making, provides users with corresponding operation entry points for users to choose to agree to or reject the results of automated decision-making; if the user chooses to reject, the process will proceed to the expert decision-making process.

[0046] First, let me explain the terms used in this application:

[0047] SM2, a national standard cryptographic algorithm, is an asymmetric encryption algorithm based on elliptic curve cryptography. It is primarily used for data encryption, decryption, digital signatures, and authentication. It is suitable for information security assurance in critical information systems.

[0048] SM3, a Chinese national cryptographic standard, is a hash algorithm primarily used for digital signatures and message integrity verification.

[0049] RSA: Rivest Shamir Adleman algorithm, is an asymmetric encryption algorithm.

[0050] It should be noted that the data processing methods, systems, devices, equipment, storage media, and program products provided in this application can be used in the field of big data, or in any field other than big data. The application fields of the data processing methods, systems, devices, equipment, storage media, and program products in this application are not limited.

[0051] Groups typically consist of a parent company and several subsidiaries. With the deepening of digital transformation, the amount of data generated within the group and by related parties is growing exponentially. Data between different subsidiaries, departments, and partners within the group often involves sensitive personal information, trade secrets, or important data, requiring strict segregation and minimal usage.

[0052] The specific application scenario of this application is the joint data processing scenario between the parent company and different subsidiaries in an existing group when facing massive amounts of data that require joint processing by the parent company and subsidiaries. Figure 1 This is a diagram illustrating data transfer between the parent company and its various subsidiaries within a group, such as... Figure 1 As shown, the existing data sharing and processing methods between subsidiaries and parent companies within a group are often based on plaintext transmission. When data is transmitted between subsidiaries and parent companies, plaintext data is transmitted directly. However, plaintext transmission poses a huge risk of data leakage, and the security of data within the group is difficult to guarantee.

[0053] The data processing method, system, apparatus, equipment, storage medium, and program products provided in this application aim to solve the above-mentioned technical problems of the prior art by storing subsidiary data in the confidential environment of the parent company and performing distributed computing in the confidential environment of the parent company, thereby preventing data leakage during joint processing.

[0054] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0055] Figure 2 A flowchart illustrating a data processing method provided in this application embodiment. Figure 1 This is applicable to any parent company compute node in a confidential environment cluster, where the parent company compute node is configured with a confidential environment, such as... Figure 2 As shown, the method includes:

[0056] S201. Initiate a data usage request to the subsidiary node and receive the subsidiary key sent by the subsidiary node.

[0057] In one example, the parent company's confidential environment cluster may include several parent company compute nodes, and these parent company compute nodes may include parent company confidential compute nodes. Figure 3 This application provides a structural framework diagram for efficient group data processing based on a distributed confidential environment, as shown in the embodiments of this application. Figure 3 As shown, the parent company's confidential computing nodes are numbered from 0 to n-1, totaling n nodes. Each parent company confidential computing node may include: an interaction and monitoring module 104, a confidential environment module 105, and a disk module 106. Subsidiary nodes may include: an interaction module 101 and a data processing module 102. To ensure the confidential environment is not compromised, the parent company nodes may also include: a parent company control node. The parent company control node includes: an interaction and computing power management module 103, used to interact with other nodes besides the parent company control node, and also used to monitor the status of the parent company computing nodes and schedule computing tasks.

[0058] For example, either a subsidiary or a parent company can initiate a joint data processing task, and this application does not restrict the initiator of such a task. If a parent company's computing node needs to use data from a subsidiary, it sends a data usage request to the subsidiary node through the parent company's control node.

[0059] After receiving the data usage request, the subsidiary node's interaction module 101 directly sends the subsidiary node's own key component K2 to the confidential environment of all parent company computing nodes.

[0060] Optionally, the confidential environment includes a trusted application; before initiating a data usage request to the subsidiary node, the method further includes: building a trusted application in the parent company's computing node based on trusted execution environment technology, the trusted application being used for distributed processing of disk-written data in the confidential environment.

[0061] In one example, the confidential environment has clustering capabilities and can include both hardware and software components, implemented based on a Trusted Execution Environment (TEE). The hardware component may include a disk pre-configured with the confidential environment, which is activated when needed. The software component includes trusted applications that can implement core confidential computing services such as private set intersection, hidden queries, joint statistics, joint modeling, and prediction. Confidential computing tasks are performed within the trusted environment, and plaintext data used for data processing cannot be accessed by the administrator or any participating party. The confidential environment is equipped with a random number generator to generate random numbers as key components; it has encryption and decryption capabilities according to national cryptographic standards (SM2 / SM3, etc.) and international standards (RSA, etc.), and can also be used to encrypt and decrypt data written to disk.

[0062] By building trusted applications on the parent company's computing nodes based on trusted execution environment technology, and processing the data written to disk within the trusted applications, the plaintext of the data written to disk by the subsidiary is prevented from being obtained by the administrator or any participating party because the data is processed in a confidential environment.

[0063] Optionally, before initiating a data usage request to the subsidiary, the method further includes: obtaining the subsidiary's key; combining the parent company's key with the subsidiary's key to obtain a disk storage key and storing the disk storage key in a confidential environment; while the confidential environment is intact, sending the number and ID of the parent company's computing nodes to the subsidiary nodes, so that the subsidiary nodes can perform binning processing on the data of the subsidiary nodes based on the number and ID of the parent company's computing nodes, and sending the binned data to the corresponding parent company computing nodes; encrypting the binned data based on the disk storage key, and storing the encrypted binned data as disk storage in the confidential environment.

[0064] In one example, before initiating a data usage request to the subsidiary, there is also a data preparation stage, which includes: Step 1: The interaction and computing power management module 103 of the parent company control node provides the number of parent company computing nodes n and node numbers 0 to n-1 to the subsidiary node.

[0065] Step 2: The subsidiary node's interaction module 101 sends the subsidiary node's own key component K2 to the confidential environment of all parent company computing nodes.

[0066] Step 3: All confidential environments of the parent company's confidential nodes share their respective key components and synthesize them to obtain the parent company key K1. The parent company key can be obtained by XORing the key components of each parent company's confidential node or by performing an AND operation. This application does not restrict the method of obtaining the parent company key. The parent company key K1 is combined with the subsidiary key K2 of the subsidiary node to form the disk storage key K. The disk storage key K is stored in a confidential environment and cannot be accessed by outsiders or maintenance personnel. The disk storage key K can be obtained by XORing the parent company key K1 and the subsidiary key K2 or by performing an AND operation. This application does not restrict the method of obtaining the disk storage key.

[0067] Step 4: Subsidiary nodes remotely authenticate the confidentiality of each parent company's computing nodes.

[0068] Step 5: The data processing module 102 of the subsidiary node performs binning on its own data based on the number of parent company computing nodes n and node numbers 0 to n-1, resulting in binned data. Specifically, the rules for binning the subsidiary node's own data are as follows: each data entry is assigned a unique numerical code, and then the numerical code is modulo the number of parent company computing nodes n. The data is then binned according to the remainder from 0 to n-1, with the bin number corresponding to the parent company computing node number, ensuring a uniform data distribution.

[0069] Step 6: The subsidiary's interaction module sends the binned data to the confidential environment of the corresponding parent company computing node according to the bin number.

[0070] Step 7: The confidential environment of all parent company computing nodes uses the disk key K generated in step 4 to encrypt the data sent by the subsidiary line by line and store it on disk module 106.

[0071] Optionally, the method also includes: deleting subsidiary keys and disk keys stored in a confidential environment.

[0072] In one example, the confidential environment of all parent company compute nodes deletes the generated disk key K and subsidiary key K2 to ensure that subsidiary data is not used beyond its scope.

[0073] By deleting the subsidiary key and the data storage key after the data is written to disk, the security of the subsidiary data is further improved, ensuring that the subsidiary data is not used beyond its scope.

[0074] The disk-writing key is obtained by combining the subsidiary key and the parent key. The number and number of the parent company's computing nodes are sent to the subsidiary nodes so that the subsidiaries can bin the data. The disk-writing key is used to encrypt the binned data of the subsidiary nodes, which ensures the security of the subsidiary node data. At the same time, it facilitates distributed computing and improves the efficiency of joint processing of disk-writing data.

[0075] Optionally, it also includes: in response to a remote authentication request from a subsidiary node, obtaining a metric value of a remote authentication report for the confidential environment; comparing the metric value with a pre-stored baseline value of the confidential environment; determining that the confidential environment has not been compromised when the metric value and the baseline value are the same; and determining that the confidential environment has been compromised when the metric value and the baseline value are different.

[0076] In one example, such as Figure 3 As shown, it also includes an independent remote authentication service node, which comprises: a unified interface encapsulation 107, a certificate verification 108, and a measurement baseline and verification 109. The independent remote authentication service node uses the unified interface encapsulation 107 to shield the interface differences of remote authentication for various confidential computing technologies. The independent remote authentication service node can request certificate verification from the certification authority (CA) level by level. The independent remote authentication service node pre-stores a baseline value A for measuring the confidential environment of the parent company's computing nodes. By obtaining the measurement value B from the remote authentication report of the confidential environment of the parent company's computing nodes, it compares the baseline value A and the measurement value B to ensure whether the confidential computing environment has been compromised: if the baseline value A and the measurement value B are the same, it is determined that the confidential environment has not been compromised; if the baseline value A and the measurement value B are different, it is determined that the confidential environment has been compromised.

[0077] By comparing the metric values ​​of the confidential environment with pre-stored baseline values, inconsistencies are identified as evidence of a compromised confidential environment, while consistency indicates that the confidential environment has not been compromised. This enables monitoring of whether the confidential environment has been compromised, facilitating timely action when compromise is detected, ensuring the security of the confidential environment, and further improving the security of jointly processed data.

[0078] S202. Combine the parent company's key with the subsidiary's key to obtain the disk storage key.

[0079] In one example, the disk-based key K can be obtained through the following steps: The confidential environments of the parent company's confidential nodes share their respective key components and synthesize them to obtain the parent company key K1. The parent company key can be obtained by XORing the key components of each parent company's confidential node or by performing an AND operation. This application does not restrict the method of obtaining the parent company key. The parent company key K1 is then combined with the subsidiary key K2 of the subsidiary node to form the disk-based key K. The disk-based key K is stored in a confidential environment and cannot be accessed by external parties or maintenance personnel. The disk-based key K can be obtained by XORing the parent company key K1 and the subsidiary key K2 or by performing an AND operation. This application does not restrict the method of obtaining the disk-based key.

[0080] S203. Use the disk write key to decrypt the disk write data of the subsidiary node stored in the confidential environment.

[0081] In one example, the disk data of a subsidiary can be decrypted in a confidential environment using the disk key K.

[0082] S204. In a confidential environment, perform distributed processing on the decrypted disk data to obtain the processing results, and send the processing results to the subsidiary node.

[0083] In one example, the processing result can be sent to a subsidiary node or other nodes of the parent company. This application does not restrict the recipient of the processing result.

[0084] like Figure 3 As shown, distributed processing can be achieved through the parent company's control node. Specifically, the interaction and computing power management module 103 of the parent company's control node monitors the operation of each parent company computing node in the parent company's confidential environment cluster in real time, and can dynamically add or delete parent company computing nodes to reclaim resources. The interaction and computing power management module 103 of the parent company's control node can also dynamically allocate tasks. By monitoring the resource load of each parent company confidential node, specifically, it calculates and outputs a resource load value based on the CPU, memory, etc., of the parent company confidential node. This application does not restrict the calculation method of the resource load of the parent company confidential node. Computational tasks are distributed to multiple parent company computing nodes for concurrent execution to achieve distributed processing and improve computing efficiency. This application does not restrict the allocation method.

[0085] Optionally, the method also includes: when the parent company's computing node fails the availability monitoring, updating the number and number of other computing nodes in the parent company's confidential environment cluster besides the parent company's computing node to obtain the updated number and number of nodes; based on the updated number and number of nodes, transferring the data written to disk of the parent company's computing node to the corresponding node.

[0086] In one example, the fault handling steps for the parent company's compute node may include the following steps:

[0087] Step 4.1: The parent company's control node initiates availability monitoring to the parent company's computing node in real time. If the parent company's computing node fails the availability monitoring, the number and number of other computing nodes in the parent company's confidential environment cluster, excluding the parent company's computing node, are readjusted.

[0088] Step 4.2: Other compute nodes in the parent company's confidential environment cluster, besides the parent company's compute node, take over the disk-written data from the failed parent company compute node. Specifically, this may include: the parent company's control node assigns a unique digital code to the encrypted disk-written data of the failed parent company compute node; performing a remainder operation (n-1) on the digital code; and binning the disk-written data of the failed parent company compute node according to the remainders from 0 to n-2. The bin numbers correspond to the updated numbers on other compute nodes, and the data is transferred to the corresponding other compute nodes for takeover according to the bin numbers. Since the disk-written data managed by each compute node in the parent company's confidential environment cluster uses the same parent company key, the new takeover node can handle the data from the failed node.

[0089] By automatically transferring data to other parent company computing nodes when a parent company computing node fails, potential security issues during data transfer are avoided. Furthermore, no manual data transfer is required; by automatically transferring data from the failed node to a secure parent company computing node, data processing efficiency is further improved.

[0090] Optionally, the method further includes: when expanding the parent company's confidential environment cluster, updating the number and number of the parent company's computing nodes to obtain the updated number and number of the parent company's computing nodes; updating the disk key based on the updated number and number of the parent company's computing nodes, and sending the updated number and number of the parent company's computing nodes to the subsidiary nodes.

[0091] In one example, the process of scaling up a confidential computing node may include the following steps:

[0092] Step 5.1: The parent company's control node is readjusted by updating the number and number of the parent company's computing nodes to obtain the updated number of parent company computing nodes n and the updated parent company computing node numbers 0 to n-1, which are then sent to the subsidiary nodes.

[0093] Step 5.2: The subsidiary node's interaction module 101 sends the subsidiary node's own key component K2 to the confidential environment of all parent company computing nodes.

[0094] Step 5.3: All confidential environments of the parent company's confidential nodes share their respective key components and synthesize them to obtain the parent company key K1. The parent company key can be obtained by XORing the key components of each parent company's confidential node or by performing an AND operation. This application does not restrict the method of obtaining the parent company key. The parent company key K1 is combined with the subsidiary key K2 of the subsidiary node to form the disk storage key K. The disk storage key K is stored in a confidential environment and cannot be accessed by external parties or maintenance personnel. The disk storage key K can be obtained by XORing the parent company key K1 and the subsidiary key K2 or by performing an AND operation. This application does not restrict the method of obtaining the disk storage key.

[0095] Step 5.4: Subsidiary nodes remotely authenticate the confidentiality of each parent company's computing nodes.

[0096] Step 5.5: The data processing module 102 of the subsidiary node performs binning on its own data based on the number of parent company computing nodes n and node numbers 0 to n-1, resulting in binned data. Specifically, the rules for binning the subsidiary node's own data are as follows: each data entry is assigned a unique numerical code; then, the numerical code is modulo the number of parent company computing nodes n, and the data is binned according to the remainder from 0 to n-1. The bin number corresponds to the parent company computing node number, ensuring a uniform data distribution.

[0097] Step 5.6: The subsidiary's interaction module sends the binned data to the confidential environment of the corresponding parent company computing node according to the bin number.

[0098] Step 5.7: The confidential environment of all parent company computing nodes uses the disk key K generated in step 4 to encrypt the data sent by the subsidiary one by one and store it on the disk module 106.

[0099] Step 5.8: The parent company's computing node deletes the subsidiary's key and disk-based key stored in the confidential environment.

[0100] By updating the number and number of parent company computing nodes and updating the disk key when expanding the parent company's confidential environment cluster, automatic expansion of the confidential environment cluster is achieved without the need for manual renumbering of the parent company's computing nodes in the confidential environment cluster, further improving data processing efficiency.

[0101] The data processing method provided in this embodiment sets up a confidential environment on the parent company's computing node, storing the subsidiary's data for joint processing in the confidential environment, thus ensuring the security of the subsidiary's data and preventing data leakage. When joint processing is required, the subsidiary's key is obtained and combined with the parent company's key in the confidential environment to jointly decrypt the subsidiary's data stored in the confidential environment. The data is then processed in the parent company's confidential environment, reducing the risk of data leakage and meeting data protection requirements. By using the distributed processing tasks on the parent company's computing node, the problems of large data volume and high processing time requirements are also solved.

[0102] Figure 4 A flowchart illustrating a data processing method provided in this application embodiment. Figure 2 This is applicable to any parent company compute node in a confidential environment cluster, where the parent company compute node is configured with a confidential environment, such as... Figure 4 As shown, the method includes:

[0103] S401. In response to the data usage request sent by the parent company's computing node, the subsidiary key is sent to the parent company's computing node so that the parent company's computing node can combine the parent company's key with the subsidiary key to obtain the disk storage key. The disk storage key is used to decrypt the disk storage data of the subsidiary node stored in the confidential environment. The decrypted disk storage data is then processed in a distributed manner in the confidential environment to obtain the processing result.

[0104] Optionally, before responding to a data usage request sent by a parent company computing node, the method further includes: sending a subsidiary key to the parent company computing node, so that the parent company computing node combines the parent company key with the subsidiary key to obtain a disk storage key and stores the disk storage key in a confidential environment; obtaining the number and number of parent company computing nodes while the confidential environment is not compromised; performing binning processing on the data of the subsidiary nodes based on the number and number of parent company computing nodes to obtain binned data and bin numbers; sending the binned data to the corresponding parent company computing node based on the parent company computing node number and bin number, so that the parent company computing node encrypts the binned data based on the disk storage key and stores the encrypted binned data as disk storage in the confidential environment.

[0105] In one example, the rules for binning the data of a subsidiary node may include: assigning a unique numerical code to each data entry, then performing a remainder operation on the numerical code divided by the number of parent company computing nodes (n), and binning the data according to the remainder from 0 to n-1. The bin number corresponds to the parent company computing node number, ensuring a uniform data distribution. Alternatively, the data of a subsidiary node can be divided equally into n parts equal to the number of parent company computing nodes. This application does not restrict the method by which subsidiary nodes bin their own data.

[0106] Data is binned by the number and ID of the parent company's computing nodes, ensuring even data distribution. The parent company's computing nodes then encrypt the binned data at the subsidiary nodes using the disk-writing key, guaranteeing the security of the subsidiary node data and facilitating distributed computing, thus improving the efficiency of collaborative data processing. After data is written to disk, the subsidiary key and the disk-writing key are deleted, ensuring that subsidiary data is not used beyond its intended scope and further enhancing its security.

[0107] S402, Obtain the processing result.

[0108] The data processing method provided in this embodiment ensures the security of subsidiary data and prevents data leakage by setting up a confidential environment on the parent company's computing node and storing the subsidiary's disk data for joint processing in the confidential environment. When joint processing is required, the subsidiary's key is obtained and combined with the parent company's key in the confidential environment to decrypt the subsidiary's disk data stored in the confidential environment. The disk data is then processed in the parent company's confidential environment, reducing the risk of data leakage and meeting data protection requirements. The distributed processing task on the parent company's computing node also solves the problems of large data volume and high processing time requirements.

[0109] Figure 5 This is an interactive schematic diagram of a data processing system provided in an embodiment of this application, such as... Figure 5 As shown, the system includes: a parent company confidential environment cluster and several subsidiary nodes. The parent company confidential environment cluster includes several parent company computing nodes, each configured with a confidential environment. The parent company computing nodes are used to perform the following steps:

[0110] S201, Initiate a data usage request to the subsidiary node.

[0111] S202. Combine the parent company's key with the subsidiary's key to obtain the disk storage key.

[0112] S203. Use the disk storage key to decrypt the disk storage data of the subsidiary corresponding to the data usage request.

[0113] S204. Perform distributed processing on the disk-written data in a confidential environment, obtain the processing results, and send the processing results to the subsidiary node.

[0114] Subsidiary nodes are used to perform the following steps:

[0115] S401. In response to the data usage request sent by the parent company's computing node, send the subsidiary key to the parent company's computing node.

[0116] S402, Obtain the processing result.

[0117] In an implementation scenario, such as Figure 3 As shown, the system may include: an interaction module 101 and a data processing module 102 for subsidiary nodes; an interaction and computing power management module 103 for parent company control nodes; an interaction and monitoring module 104, a confidential computing environment module 105, and a disk module 106 for parent company computing nodes (numbered 0 to n-1, a total of n nodes); and a unified interface encapsulation module 107, a certificate verification module 108, and a measurement baseline and verification module 109 for independent remote authentication service nodes.

[0118] The subsidiary node's interaction module 101 is used to interact with other nodes, mainly including obtaining all the numbers of the parent company's confidential computing nodes from the parent company's control node, communicating with the parent company's confidential computing nodes, sending data and key components, and obtaining calculation results; the data processing module 102 is used to format the subsidiary node's own data.

[0119] The parent company's control node interaction and computing power management module 103 is used to interact with other nodes, monitor the status of the parent company's confidential computing nodes, and schedule computing tasks.

[0120] The parent company's confidential computing node interaction and monitoring module 104 is used to interact with other nodes and send the monitoring status of its own node to the parent company's control node; the confidential computing environment module 105 is implemented based on a trusted execution environment and is used to perform joint computation on disk data, generate disk key, encrypt and write data to disk, decrypt disk data, etc.; the disk module 106 is used to store encrypted data.

[0121] The data processing system provided in this embodiment sets up a confidential environment on the parent company's computing node, storing the subsidiary's data for joint processing in the confidential environment, ensuring the security of the subsidiary's data and preventing data leakage. When joint processing is required, the subsidiary's key is obtained and combined with the parent company's key in the confidential environment to decrypt the subsidiary's data stored in the confidential environment. The data is then processed in the parent company's confidential environment, reducing the risk of data leakage and meeting data protection requirements. By distributing processing tasks on the parent company's computing node, the system simultaneously solves the problems of large data volume and high processing time requirements.

[0122] Figure 6 This is a schematic diagram of the structure of a data processing device provided in an embodiment of this application, as shown below. Figure 6 As shown, the data processing device 60 provided in this embodiment is applied to any parent company computing node in a parent company confidential environment cluster. The parent company computing node is equipped with a confidential environment, including:

[0123] The key receiving module 601 is used to initiate a data usage request to the subsidiary node and receive the subsidiary key sent by the subsidiary node;

[0124] The disk storage key acquisition module 602 is used to combine the parent company key and the subsidiary key to obtain the disk storage key;

[0125] The disk data decryption module 603 is used to decrypt the disk data of subsidiary nodes stored in a confidential environment using the disk key;

[0126] The distributed data processing module 604 is used to perform distributed processing on the decrypted disk data in a confidential environment, obtain the processing results, and send the processing results to the subsidiary node.

[0127] In one possible implementation, the confidential environment includes a trusted application; the data processing device 60 is also specifically used to: build a trusted application in a parent company computing node based on trusted execution environment technology, the trusted application being used for distributed processing of disk-written data in the confidential environment.

[0128] In one possible implementation, the data processing device 60 is further specifically used to: obtain the subsidiary key, combine the parent company key with the subsidiary key to obtain a disk storage key, and store the disk storage key in a confidential environment; when the confidential environment is not compromised, send the number and number of the parent company's computing nodes to the subsidiary nodes, so that the subsidiary nodes can perform binning processing on the data of the subsidiary nodes based on the number and number of the parent company's computing nodes, and send the binned data to the corresponding parent company computing nodes; encrypt the binned data based on the disk storage key, and store the encrypted binned data as disk storage in the confidential environment.

[0129] In one possible implementation, the data processing device 60 is also specifically used to: delete subsidiary keys and disk-based keys stored in a confidential environment.

[0130] In one possible implementation, the data processing device 60 is further specifically configured to: in response to a remote authentication request from a subsidiary node, obtain a metric value of a remote authentication report of the confidential environment; compare the metric value with a pre-stored baseline value of the confidential environment; if the metric value and the baseline value are the same, determine that the confidential environment has not been compromised; if the metric value and the baseline value are different, determine that the confidential environment has been compromised.

[0131] In one possible implementation, the data processing device 60 is further specifically used to: update the number and number of other computing nodes in the parent company's confidential environment cluster besides the parent company's computing node when the parent company's computing node fails the availability monitoring, to obtain the updated number of nodes and node numbers; and transfer the disk-written data of the parent company's computing node to the corresponding node based on the updated number of nodes and node numbers.

[0132] In one possible implementation, the data processing device 60 is further specifically used to: update the number and number of parent company computing nodes when expanding the parent company confidential environment cluster, to obtain the updated number of parent company computing nodes and the updated parent company computing node number; update the disk key based on the updated number of parent company computing nodes and the updated parent company computing node number, and send the updated number of parent company computing nodes and the updated parent company computing node number to the subsidiary node.

[0133] Figure 7 This is a schematic diagram of another data processing apparatus provided in an embodiment of this application, as shown below. Figure 7 As shown, the data processing device 70 provided in this embodiment is applied to a subsidiary node and includes:

[0134] The key sending module 701 is used to respond to the data usage request sent by the parent company's computing node, send the subsidiary key to the parent company's computing node, so that the parent company's computing node can combine the parent company key and the subsidiary key to obtain the disk key, use the disk key to decrypt the disk data of the subsidiary node stored in the confidential environment, and perform distributed processing on the disk data in the confidential environment to obtain the processing result.

[0135] The processing result acquisition module 702 is used to obtain the processing result.

[0136] In one possible implementation, the data processing device 70 is further configured to: send the subsidiary key to the parent company's computing node, so that the parent company's computing node combines the parent company key with the subsidiary key to obtain a disk storage key and stores the disk storage key in a confidential environment; while the confidential environment is not compromised, obtain the number and number of the parent company's computing nodes; based on the number and number of the parent company's computing nodes, perform binning processing on the data of the subsidiary nodes to obtain the binned data and bin number; based on the number and bin number of the parent company's computing nodes, send the binned data to the corresponding parent company's computing node, so that the parent company's computing node encrypts the binned data based on the disk storage key and stores the encrypted binned data as disk storage in the confidential environment.

[0137] The data processing device provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.

[0138] Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 8As shown, the electronic device 800 may include a memory 801 and a processor 802. Optionally, the electronic device may also include a transceiver 803, wherein the memory 801 and the processor 802 communicate with each other; for example, the memory 801, the processor 802 and the transceiver 803 may communicate via a communication bus 804, the memory 801 is used to store a computer program, and the processor 802 executes the computer program to implement the method of the above embodiments.

[0139] Optionally, the aforementioned processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps in the method embodiments disclosed in this application can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.

[0140] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the methods in any of the above method embodiments.

[0141] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the methods in any of the above method embodiments.

[0142] All or part of the steps in the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a readable memory. When the program is executed, it performs the steps of the above method embodiments; and the aforementioned memory (storage medium) includes: read-only memory (ROM), RAM, flash memory, hard disk, solid-state drive, magnetic tape, floppy disk, optical disk, and any combination thereof.

[0143] This application describes embodiments with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processing unit of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processing unit of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0144] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0145] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0146] Obviously, those skilled in the art can make various modifications and variations to the embodiments of this application without departing from the spirit and scope of this application. Therefore, if these modifications and variations to the embodiments of this application fall within the scope of this application and its equivalents, this application also intends to include these modifications and variations.

[0147] In this application, the term "comprising" and its variations can refer to non-limiting inclusion; the term "or" and its variations can refer to "and / or". The terms "first", "second", etc., in this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. In this application, "multiple" refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. The character " / " generally indicates that the preceding and following related objects have an "or" relationship.

[0148] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.

[0149] In the above embodiments, the descriptions of each embodiment have their own emphasis. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as the combination of these technical features does not contradict each other, it should be considered within the scope of this specification.

[0150] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.

[0151] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.

Claims

1. A data processing method, characterized in that, The method, applicable to any parent company compute node in a parent company confidential environment cluster, wherein the parent company compute node is configured with a confidential environment, includes: Initiate a data usage request to the subsidiary node and receive the subsidiary key sent by the subsidiary node; Combine the parent company's key with the subsidiary's key to obtain the disk storage key; The disk-written data of the subsidiary node stored in the confidential environment is decrypted using the disk-written key; The decrypted disk data is processed in a distributed manner in the confidential environment to obtain the processing result, and the processing result is sent to the subsidiary node.

2. The method according to claim 1, characterized in that, The confidential environment includes trusted applications; prior to initiating a data usage request to the subsidiary node, the method further includes: Based on Trusted Execution Environment (TEE) technology, the trusted application is built on the parent company's computing node. The trusted application is used to perform distributed processing of the disk-written data in the confidential environment.

3. The method according to claim 1, characterized in that, Prior to initiating the data usage request to the subsidiary, the method further includes: Obtain the subsidiary key, combine the parent company key with the subsidiary key to obtain the disk storage key, and store the disk storage key in the confidential environment; When the confidential environment is not compromised, the number and number of the parent company's computing nodes are sent to the subsidiary nodes, so that the subsidiary nodes can perform binning processing on the data of the subsidiary nodes based on the number and number of the parent company's computing nodes, and send the binned data to the corresponding parent company computing nodes. Based on the disk storage key, the binned data is encrypted, and the encrypted binned data is stored as disk storage in the confidential environment.

4. The method according to claim 3, characterized in that, The method further includes: Delete the subsidiary key and the disk key stored in the confidential environment.

5. The method according to claim 3, characterized in that, The method further includes: In response to the remote authentication request from the subsidiary node, obtain the measurement value of the remote authentication report for the confidential environment; The metric value is compared with the pre-stored baseline value of the confidential environment. If the metric value and the baseline value are the same, it is determined that the confidential environment has not been compromised. When the metric value and the baseline value are not the same, it is determined that the confidential environment has been compromised.

6. The method according to any one of claims 1-5, characterized in that, The method further includes: When the parent company's computing node fails the availability monitoring, the number and number of other computing nodes in the parent company's confidential environment cluster, excluding the parent company's computing node, are updated to obtain the updated number and number of nodes. Based on the updated number of nodes and node numbers, the disk data of the parent company's computing nodes is transferred to the corresponding nodes.

7. The method according to claim 3, characterized in that, The method further includes: When expanding the parent company's confidential environment cluster, the number and number of the parent company's computing nodes are updated to obtain the updated number and number of the parent company's computing nodes. Based on the updated number of parent company computing nodes and the updated parent company computing node number, the disk key is updated, and the updated number of parent company computing nodes and the updated parent company computing node number are sent to the subsidiary node.

8. A data processing method, characterized in that, Applied to subsidiary nodes, the method includes: In response to a data usage request sent by the parent company's computing node, the subsidiary key is sent to the parent company's computing node, so that the parent company's computing node combines the parent company key with the subsidiary key to obtain a disk storage key. The disk storage key is used to decrypt the disk storage data of the subsidiary node stored in the confidential environment. The decrypted disk storage data is then processed in a distributed manner in the confidential environment to obtain the processing result. The processing result is obtained.

9. The method according to claim 8, characterized in that, Prior to responding to a data usage request sent by the parent company's computing node, the method further includes: The subsidiary key is sent to the parent company's computing node, so that the parent company's computing node combines the parent company key with the subsidiary key to obtain the disk key and stores the disk key in the confidential environment; While the confidential environment remains intact, obtain the number and serial number of the parent company's computing nodes; Based on the number and number of the parent company's computing nodes, the data of the subsidiary's nodes is binned to obtain the binned data and bin number; Based on the parent company's computing node number and the bin number, the binned data is sent to the corresponding parent company's computing node, so that the parent company's computing node can encrypt the binned data based on the disk storage key, and store the encrypted binned data as disk storage in the confidential environment.

10. A data processing system, characterized in that, The system includes a parent company confidential environment cluster and several subsidiary nodes. The parent company confidential environment cluster includes several parent company computing nodes, and the parent company computing nodes are equipped with a confidential environment. The parent company's computing node is used to initiate data usage requests to the subsidiary node and receive the subsidiary key sent by the subsidiary node; The subsidiary node is used to send the subsidiary key to the parent company's computing node in response to a data usage request sent by the parent company's computing node; The parent company's computing node is also used to combine the parent company's key with the subsidiary's key to obtain a disk storage key; use the disk storage key to decrypt the disk storage data of the subsidiary corresponding to the data usage request, and store the disk storage data in the confidential environment; perform distributed processing on the disk storage data in the confidential environment to obtain the processing result, and send the processing result to the subsidiary node; The subsidiary node is also used to obtain the processing result.

11. A data processing apparatus, characterized in that, The device is applicable to any parent company computing node in a parent company confidential environment cluster, wherein the parent company computing node is configured with a confidential environment, and the device includes: The key receiving module is used to initiate a data usage request to the subsidiary node and receive the subsidiary key sent by the subsidiary node; The disk storage key acquisition module is used to combine the parent company key with the subsidiary key to obtain the disk storage key; The disk data decryption module is used to decrypt the disk data of the subsidiary node stored in the confidential environment using the disk key; The data distributed processing module is used to perform distributed processing on the decrypted disk data in the confidential environment, obtain the processing result, and send the processing result to the subsidiary node.

12. A data processing apparatus, characterized in that, Applied to subsidiary nodes, the device includes: The key sending module is used to send the subsidiary key to the parent company computing node in response to the data usage request sent by the parent company computing node, so that the parent company computing node can combine the parent company key with the subsidiary key to obtain the disk key, use the disk key to decrypt the disk data of the subsidiary node stored in the confidential environment, and perform distributed processing on the disk data in the confidential environment to obtain the processing result. The processing result acquisition module is used to obtain the processing result.

13. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1 to 9.

14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1 to 9.

15. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1 to 9.

Citation Information

Patent Citations

  • Key processing method and device

    CN112688781A

  • Key distribution method and device, computer equipment and storage medium

    CN117155549A