A data processing method, apparatus and electronic device

By coordinating nodes to receive privacy computing task instructions, determining the target instruction set, and configuring the protocol plugin set, the performance limitations of the privacy computing model are resolved, enabling more efficient and flexible execution of privacy computing tasks.

CN114239063BActive Publication Date: 2026-05-26LENOVO (BEIJING) LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
LENOVO (BEIJING) LTD
Filing Date
2021-12-17
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

The performance of current privacy computing models still needs to be optimized, especially in the coordination and execution of privacy computing tasks, where they lack flexibility and efficiency.

Method used

A data processing method is provided, which receives privacy computing task creation instructions through a coordination node, determines the target instruction set and configures the protocol plugin set, and sends it to a computing node group for computation, ensuring that the protocol plugins of each target instruction can be configured independently, thereby improving the flexibility and performance of target instruction set configuration.

Benefits of technology

It improves the flexibility and performance of privacy-preserving computation tasks, reduces configuration complexity, and ensures that compute node groups can efficiently execute privacy-preserving computation tasks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114239063B_ABST
    Figure CN114239063B_ABST
Patent Text Reader

Abstract

This application provides a data processing method, apparatus, and electronic device. The method includes: receiving a privacy computing task creation instruction sent by a data providing node; determining a target instruction set from a pre-stored privacy algorithm instruction set, wherein the target instruction set matches the privacy computing task creation instruction; configuring a protocol plugin set for the target instruction set according to pre-stored protocol configuration information; and sending the target instruction set and the protocol plugin set to at least one computing node group.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data processing technology, and in particular to a data processing method, apparatus and electronic device. Background Technology

[0002] Privacy computing is a set of technologies that enable data computation and analysis while protecting the data itself from external disclosure. However, the performance of current privacy computing models still needs optimization. Summary of the Invention

[0003] This application provides the following technical solution:

[0004] This application provides a data processing method applied to a coordination node, the method comprising:

[0005] Receive privacy computing task creation instructions sent by the data provider node;

[0006] A target instruction set is determined from a pre-stored set of privacy algorithm instructions, and the target instruction set is matched with the privacy computing task creation instructions;

[0007] Configure a protocol plugin set for the target instruction set according to the pre-stored protocol configuration information;

[0008] The target instruction set and the protocol plugin set are sent to at least one computing node group.

[0009] The method further includes:

[0010] Determine data distribution instructions based on the target instruction set;

[0011] The data distribution instruction is sent to the data providing node, so that the data providing node sends the data to be computed to the at least one computing node group according to the data distribution instruction.

[0012] The privacy algorithm instruction set and the protocol configuration information are pre-stored in the following manner:

[0013] Receive the privacy algorithm instruction set and the protocol configuration information of the privacy algorithm instruction set from the algorithm providing node;

[0014] The privacy algorithm instruction set and the protocol configuration information are stored.

[0015] The protocol configuration information records the privacy computing protocol corresponding to each privacy algorithm instruction in the privacy algorithm instruction set;

[0016] Alternatively, the privacy algorithm instruction set may have multiple sub-instruction sets, and the protocol configuration information may record the privacy computing protocol corresponding to each sub-instruction set.

[0017] The step of determining the target instruction set from the pre-stored privacy algorithm instruction set includes:

[0018] The target instruction set is determined based on the selection instruction sent by the data providing node;

[0019] Alternatively, the target instruction set may be determined from the pre-stored privacy algorithm instruction set based on the query instruction sent by the data providing node;

[0020] Alternatively, the target instruction set can be matched from the pre-stored privacy algorithm instruction set based on the task description information sent by the data providing node.

[0021] The privacy algorithm instructions sent to the same computing node group from the target instruction set have the same privacy computing protocol.

[0022] Sending the target instruction set and the protocol plugin set to at least one computing node group includes:

[0023] The target instruction set is encrypted using a target public key, which is the public key of each computing node in the at least one computing node group;

[0024] The encrypted target instruction set and the protocol plugin set are sent to the at least one computing node group.

[0025] After determining the target instruction set matching the privacy computing task creation instruction from the pre-stored privacy algorithm instruction set, the method further includes:

[0026] Determine the target privacy transport protocol that matches the target instruction set;

[0027] The target privacy transmission protocol is sent to the at least one computing node group to configure the privacy data transmission relationship between the computing nodes in the at least one computing node group.

[0028] Another aspect of this application provides a data processing apparatus for use in a coordination node, the apparatus comprising:

[0029] The receiving module is used to receive privacy computing task creation instructions sent by the data providing node;

[0030] A determination module is used to determine a target instruction set from a pre-stored privacy algorithm instruction set, the target instruction set being matched with the privacy computing task creation instruction;

[0031] The configuration module is used to configure a protocol plugin set for the target instruction set according to the pre-stored protocol configuration information;

[0032] The sending module is used to send the target instruction set and the protocol plugin set to at least one computing node group.

[0033] A third aspect of this application provides an electronic device, comprising: a memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the computer instructions to perform the data processing method described in any of the preceding claims.

[0034] In this application, a privacy-preserving computation task creation instruction sent by a data providing node is received. A target instruction set is determined from a pre-stored privacy algorithm instruction set. This target instruction set may include at least one target instruction matching the privacy-preserving computation task creation instruction. A protocol plugin set is configured for the target instruction set according to pre-stored protocol configuration information. This allows for the independent configuration of protocol plugins for each target instruction within the target instruction set, ensuring that the protocol plugins for each target instruction can be configured independently. This improves the flexibility and reduces the complexity of target instruction set configuration, thereby optimizing the performance of the target instruction set matching the privacy-preserving computation task. Furthermore, the target instruction set and protocol plugin set are sent to at least one computation node group. Different computation node groups can perform computations by loading different target instructions and protocol plugins, enhancing the flexibility and performance of privacy-preserving computation. Attached Figure Description

[0035] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0036] Figure 1 This is a flowchart illustrating a data processing method provided in Embodiment 1 of this application;

[0037] Figure 2 This is a schematic diagram of a data processing scenario under a data processing architecture provided in this application;

[0038] Figure 3 This is a schematic diagram of a data processing scenario under another data processing architecture provided in this application;

[0039] Figure 4 This is a schematic diagram of another data processing scenario under another data processing architecture provided in this application;

[0040] Figure 5 This is a flowchart illustrating a data processing method provided in Embodiment 2 of this application;

[0041] Figure 6This is a schematic diagram of a data processing method provided in this application.

[0042] Figure 7 This is a flowchart illustrating a data processing method provided in Embodiment 1 of this application;

[0043] Figure 8 This is a flowchart illustrating a data processing method provided in Embodiment 1 of this application;

[0044] Figure 9 This is a schematic diagram illustrating a scenario of privacy transmission provided in this application;

[0045] Figure 10 This is a schematic diagram of a numerical partitioning allocation scenario provided in this application;

[0046] Figure 11 This is a schematic diagram illustrating another privacy transmission scenario provided in this application;

[0047] Figure 12 This is a schematic diagram of the structure of a data processing device provided in this application;

[0048] Figure 13 This is a schematic diagram of the structure of an electronic device provided in this application. Detailed Implementation

[0049] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0050] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0051] Reference Figure 1 This is a flowchart illustrating a data processing method provided in Embodiment 1 of this application. This method can be applied to coordinating nodes, such as... Figure 1 As shown, the method may include, but is not limited to, the following steps:

[0052] Step S101: Receive the privacy computing task creation instruction sent by the data providing node.

[0053] Data provider nodes can be used to provide the data needed for privacy-preserving computations.

[0054] The data provider node can generate a privacy computing task creation instruction and send it to the coordinating node, provided that the data it provides meets the set usage requirements.

[0055] Of course, data provider nodes can also respond to creation instruction generation requests and generate privacy computing task creation instructions. These creation instruction generation requests can be input by the user into the data provider node.

[0056] In this embodiment, the privacy computing task creation instruction is used to trigger the coordinating node to create one or more privacy computing tasks. A privacy computing task can be understood as a privacy computation or privacy operation that needs to be performed.

[0057] Privacy-preserving computation tasks may include, but are not limited to, secure multi-party computation (MPC) tasks.

[0058] Step S102: Determine the target instruction set from the pre-stored privacy algorithm instruction set. The target instruction set matches the privacy computing task creation instruction.

[0059] The pre-stored privacy algorithm instruction set may include at least one privacy algorithm instruction or at least one sub-instruction set, and each sub-instruction set contains at least one sub-privacy algorithm instruction.

[0060] Each privacy algorithm instruction may contain at least one operator. Operators can be used to manipulate the data involved in privacy computation, such as performing addition or multiplication operations. The inclusion of at least one operator in each privacy algorithm instruction ensures that it can be used to complete a subtask, which is one of the subtasks obtained by decomposing the privacy computation task. The subtasks performed by different privacy algorithm instructions differ from one another.

[0061] Each sub-instruction set can contain one operator for each sub-privacy algorithm instruction, and the operators contained in each sub-privacy algorithm instruction within a sub-instruction set are different from each other. The fact that each sub-privacy algorithm instruction within a sub-instruction set contains one operator ensures that the sub-instruction set can be used to complete subtasks, and the subtasks completed by different sub-instruction sets are different from each other. For an understanding of subtasks, please refer to the subtasks described above; they will not be repeated here.

[0062] In this embodiment, determining the target instruction set from a pre-stored privacy algorithm instruction set may include:

[0063] S1021. Determine the target instruction set based on the selection instruction sent by the data providing node.

[0064] In this embodiment, the coordinating node can provide privacy algorithm instruction selection options to the data providing node. The data providing node can determine the selection instruction based on the privacy algorithm instruction selection options and send the selection instruction to the coordinating node. The coordinating node selects the corresponding privacy algorithm instruction or sub-instruction set from the pre-stored privacy algorithm instruction set as the target instruction set according to the selection instruction.

[0065] Alternatively, determining the target instruction set from a pre-stored privacy algorithm instruction set may also include:

[0066] S1022. Determine the target instruction set from the pre-stored privacy algorithm instruction set based on the query instruction sent by the data providing node.

[0067] In this embodiment, key information can be obtained from the query instructions sent by the data providing node, and a privacy algorithm instruction or sub-instruction set that matches the key information can be queried in the pre-stored privacy algorithm instruction set. The queried privacy algorithm instruction or sub-instruction set is then determined as the target instruction set.

[0068] The key information can be understood as: index information that helps data providing nodes search for the desired privacy algorithm instruction or sub-instruction set in the pre-stored privacy algorithm instruction set.

[0069] This embodiment also provides another implementation method for determining the target instruction set from a pre-stored privacy algorithm instruction set, which may specifically include:

[0070] S1023. Match the target instruction set from the pre-stored privacy algorithm instruction set based on the task description information sent by the data providing node.

[0071] In this embodiment, the data providing node can obtain task description information based on the privacy computing task. The task description information may include, but is not limited to: description information related to the privacy computing task; or, description information of each subtask included in the privacy computing task.

[0072] The corresponding task description information includes the implementation method of the description information related to the privacy computing task. The coordination node can parse the task description information, determine each subtask included in the privacy computing task, and match the target instructions or sub-instruction sets that can complete each subtask included in the privacy computing task from the pre-stored privacy algorithm instruction set. The matched target instructions or sub-instruction sets are determined as the target instruction set.

[0073] The corresponding task description information includes the implementation methods of the description information of each subtask contained in the privacy computing task. The coordination node matches the target instruction or sub-instruction set corresponding to the description information of each subtask from the pre-stored privacy algorithm instruction set, and determines the matched target instruction or sub-instruction set as the target instruction set.

[0074] The pre-stored privacy algorithm instruction set includes at least one implementation of a privacy algorithm instruction. The target instruction set may include at least one target instruction, and each target instruction may include one or more privacy algorithm instructions. Each target instruction can be used to complete a part of the privacy computation task, thereby collectively completing the privacy computation task.

[0075] The pre-stored privacy algorithm instruction set includes at least one sub-instruction set implementation. The target instruction set may include at least one target sub-instruction set, and each target sub-instruction set includes at least one sub-instruction. Each target sub-instruction set is used to complete a part of the privacy computation task, collectively completing the privacy computation task.

[0076] In this embodiment, the privacy algorithm instruction set can be pre-stored in the following way:

[0077] S1024. Receive privacy algorithm instruction set from the algorithm provider node.

[0078] In this embodiment, the algorithm provides nodes to obtain privacy computing algorithms, decomposes the privacy computing algorithms to obtain at least one privacy algorithm instruction or at least one sub-instruction set, at least one privacy algorithm instruction constitutes a privacy algorithm instruction set, or at least one sub-instruction set constitutes a privacy algorithm instruction set.

[0079] In this embodiment, there are no restrictions on the specific method by which the algorithm providing node obtains the privacy computing algorithm. For example, the algorithm providing node can obtain a privacy computing algorithm from external input, or it can write the privacy computing algorithm using a higher-level language.

[0080] Privacy-preserving computation algorithms can be understood as algorithms used for privacy-preserving computation tasks. Privacy-preserving algorithm instructions or sub-instruction sets can be understood as algorithmic instructions used to complete sub-tasks. The understanding of sub-tasks can be found in the section on sub-tasks described above, and will not be repeated here.

[0081] In this embodiment, the privacy algorithm instruction or the sub-privacy algorithm instruction in the sub-instruction set can be an instruction that can be directly executed by the computing node.

[0082] S1025. Store the privacy algorithm instruction set.

[0083] In this embodiment, the coordinating node can simplify its operation and improve its execution efficiency by receiving and storing the privacy algorithm instruction set from the algorithm providing node.

[0084] Of course, the coordinating node can also obtain the privacy computing algorithm, break it down into a privacy algorithm instruction set, and store it.

[0085] Step S103: Configure the protocol plugin set for the target instruction set according to the pre-stored protocol configuration information.

[0086] Pre-stored protocol configuration information can include relevant information needed when processing privacy computing tasks.

[0087] Specifically, the pre-stored privacy algorithm instruction set includes at least one implementation method of a privacy algorithm instruction, and the protocol configuration information records the privacy computing protocol corresponding to each privacy algorithm instruction in the privacy algorithm instruction set.

[0088] The corresponding target instruction set includes at least one implementation of a privacy algorithm instruction. Configuring a protocol plugin set for the target instruction set based on pre-stored protocol configuration information may include:

[0089] S1031. Obtain the privacy computing protocol corresponding to each privacy algorithm instruction in the target instruction set from the privacy computing protocol corresponding to each privacy algorithm instruction recorded in the pre-stored protocol configuration information.

[0090] S1032. Configure a protocol plugin for the privacy algorithm instruction using the privacy computation protocol corresponding to the privacy algorithm instruction.

[0091] In this embodiment, the privacy computation protocol corresponding to the privacy algorithm instruction is used to configure a protocol plugin for the privacy algorithm instruction, which may include:

[0092] S10321. Obtain the first parameter of the privacy computing protocol corresponding to the privacy algorithm instruction, wherein the first parameter at least characterizes the execution efficiency of executing the privacy algorithm instruction according to the privacy computing protocol;

[0093] S10322. Based on the first parameter of the privacy computing protocol corresponding to the privacy algorithm instruction, select a privacy computing protocol that meets the set execution efficiency threshold from the privacy computing protocols corresponding to the privacy algorithm instruction, and use it as the target privacy computing protocol. Configure the protocol plugin containing the target privacy computing protocol to the privacy algorithm instruction.

[0094] It is understandable that the set of protocol plugins that configure each privacy algorithm instruction in the target instruction set is called the protocol plugin set.

[0095] The pre-stored privacy algorithm instruction set includes implementation methods for at least one sub-instruction set, and the protocol configuration information records the privacy computation protocol corresponding to each sub-instruction set. It is understood that the privacy computation protocols corresponding to the sub-instructions within the sub-instruction set are consistent.

[0096] The implementation method for a target instruction set including at least one target sub-instruction set, which configures a protocol plugin set for the target instruction set according to pre-stored protocol configuration information, may include:

[0097] S1033. Obtain the privacy computing protocol corresponding to each target sub-instruction set in the target instruction set from the privacy computing protocol corresponding to each sub-instruction set recorded in the pre-stored protocol configuration information.

[0098] S1034. Configure a protocol plugin for the target subinstruction set using the privacy computing protocol corresponding to the target subinstruction set.

[0099] Configuring a protocol plugin for the target subinstruction set using the privacy-preserving computation protocol corresponding to the target subinstruction set can include:

[0100] S10341. Obtain the second parameter of the privacy computing protocol corresponding to the target sub-instruction set. The second parameter at least characterizes the execution efficiency of executing the target sub-instruction set according to the privacy computing protocol.

[0101] S10342. Based on the second parameter of the privacy computing protocol corresponding to the target sub-instruction set, select the privacy computing protocol that meets the set execution efficiency threshold from the privacy computing protocols corresponding to the target sub-instruction set, and use it as the target privacy computing protocol. Configure the protocol plugin containing the target privacy computing protocol to the target sub-instruction set.

[0102] It is understandable that the collection containing the protocol plugins configured for each target sub-instruction set in the target instruction set is called the protocol plugin set.

[0103] In this embodiment, the protocol configuration information can be received simultaneously with the privacy algorithm instruction set from the algorithm providing node, and the protocol configuration information corresponding to the privacy algorithm instruction set can be stored to complete the pre-storage of the protocol configuration information.

[0104] The corresponding privacy algorithm instruction set is obtained by the coordinating node from the decomposition of the privacy computation algorithm. The protocol configuration information can also be determined by the coordinating node based on the privacy algorithm instruction set, and the protocol configuration information is stored to complete the pre-storage of the protocol configuration information.

[0105] By receiving and storing the protocol configuration information of the privacy algorithm instruction set from the algorithm providing node, the coordinating node can further simplify its operation and improve its execution efficiency.

[0106] Step S104: Send the target instruction set and protocol plugin set to at least one computing node group.

[0107] In this embodiment, at least one computing node group can execute the target instruction set based on the protocol plugin set.

[0108] A compute node group may include at least two compute nodes, and each compute node may include at least one virtual machine.

[0109] If the target instruction set includes a target instruction or a target sub-instruction set, and the protocol plugin set includes a corresponding protocol plugin, then the target instruction set and the protocol plugin set can be sent to a compute node group. For example... Figure 2 As shown, the coordinating node receives a privacy algorithm instruction set from the algorithm providing node, pre-stores the privacy algorithm instruction set, determines the target instruction set from the pre-stored privacy algorithm instruction set, the target instruction set matches the privacy computing task creation instruction, configures a protocol plugin set for the target instruction set according to the pre-stored protocol configuration information, and sends the target instruction set and protocol plugin set to a computing node group. This computing node group can process the data to be computed provided by the data providing node based on the target instruction set and protocol plugin set.

[0110] When the target instruction set includes multiple target instructions or multiple target sub-instruction sets, and the protocol plugin set includes multiple corresponding protocol plugins, the target instruction set and the protocol plugin set can be sent to multiple compute node groups. Sending the target instruction set and the protocol plugin set to multiple compute node groups can include:

[0111] The target instruction set and protocol plugin set are sent to each compute node group respectively.

[0112] It is understandable that although different compute node groups receive the same target instruction set and protocol plugin set, each compute node group can use one target instruction or target sub-instruction set from the target instruction set and one corresponding protocol plugin from the protocol plugin set. Therefore, the target instructions or target sub-instruction sets and corresponding protocol plugins used by each compute node group differ from one another. For example... Figure 3 As shown, the coordinating node receives a privacy algorithm instruction set from the algorithm providing node, pre-stores the privacy algorithm instruction set, determines the target instruction set from the pre-stored privacy algorithm instruction set, and matches the target instruction set with the privacy computing task creation instruction. Based on the pre-stored protocol configuration information, it configures a protocol plugin set for the target instruction set, and then sends the target instruction set and the protocol plugin set to n computing node groups, where n is an integer greater than 1. The data providing node can provide the same data to be computed to each computing node group. Each computing node group can process a portion of the received data to be computed, and the data processed by each computing node group is different from the others.

[0113] Sending the target instruction set and protocol plugin set to multiple compute node groups can also include:

[0114] Multiple target instructions or multiple target sub-instruction sets from the target instruction set, and multiple protocol plugins from the protocol plugin set, are sent to different compute node groups. Each compute node group executes its own received target instructions or target sub-instruction sets based on the protocol plugins it receives. For example... Figure 4 As shown, the coordinating node receives a privacy algorithm instruction set from the algorithm providing node, pre-stores the privacy algorithm instruction set, determines the target instruction set from the pre-stored privacy algorithm instruction set, and matches the target instruction set with the privacy computing task creation instruction. Based on the pre-stored protocol configuration information, it configures a protocol plugin set for the target instruction set, and sends target instruction 1 or target sub-instruction set 1, and protocol plugin 1 from the target instruction set to computing node group 1, ..., and sends target instruction n or target sub-instruction set n from the target instruction set to computing node group n, where n is an integer greater than 1. The data providing node can provide the same data to be computed to each computing node group, and each computing node group can process a portion of the received data to be computed. The data processed by each computing node group is different from the others.

[0115] The coordinating node can determine the execution order of multiple target instructions or multiple target sub-instruction sets in the target instruction set, so that multiple computing node groups can use the target instructions or target sub-instruction sets and the corresponding protocol plugins in the execution order.

[0116] It should be noted that a computing node group may include at least two computing nodes. Privacy algorithm instructions or sub-instruction sets sent to the same computing node group from the target instruction set have the same privacy computing protocol. That is, the privacy algorithm instructions or sub-instruction sets received by at least two computing nodes in the same computing node group from the target instruction set have the same privacy computing protocol.

[0117] In this embodiment, a privacy computing task creation instruction sent by a data providing node is received; a target instruction set is determined from a pre-stored privacy algorithm instruction set. The target instruction set may include at least one target instruction that matches the privacy computing task creation instruction; and a protocol plugin set is configured for the target instruction set according to pre-stored protocol configuration information. This allows for the configuration of a protocol plugin for each target instruction in the target instruction set, ensuring that the protocol plugin for each target instruction can be configured independently. This improves the flexibility of the target instruction set configuration, reduces the complexity of the target instruction set configuration, and optimizes the performance of the target instruction set that matches the privacy computing task.

[0118] Furthermore, the target instruction set and protocol plugin set are sent to at least one computing node group. Different computing node groups can perform calculations by loading different target instructions and protocol plugins, thereby improving the flexibility and performance of privacy computing.

[0119] As another optional embodiment of this application, refer to Figure 5 This is a flowchart illustrating a data processing method embodiment 2 provided by this application. This embodiment is mainly an extension of the data processing method described in embodiment 1 above. The method may include, but is not limited to, the following steps:

[0120] Step S201: Receive the privacy computing task creation instruction sent by the data providing node.

[0121] Step S202: Determine the target instruction set from the pre-stored privacy algorithm instruction set. The target instruction set matches the privacy computing task creation instruction.

[0122] Step S203: Configure the protocol plugin set for the target instruction set according to the pre-stored protocol configuration information.

[0123] Step S204: Send the target instruction set and protocol plugin set to at least one computing node group.

[0124] For a detailed description of steps S201-S204, please refer to the relevant description of steps S101-S104 in Example 1, which will not be repeated here.

[0125] Step S205: Determine the data distribution instruction based on the target instruction set.

[0126] In this embodiment, the data required for the privacy computing task can be determined according to the target instruction set, and a data distribution instruction can be generated. The data distribution instruction is used to trigger the data providing node to send the data required for the privacy computing task.

[0127] Step S206: Send the data distribution instruction to the data provider node so that the data provider node sends the data to be computed to at least one group of computing nodes according to the data distribution instruction.

[0128] In this embodiment, at least one computing node group can execute privacy algorithm instructions or target sub-instruction sets according to the execution order of multiple privacy algorithm instructions or multiple target sub-instruction sets in the target instruction set determined by the coordinating node, based on the protocol plugin to be executed, to process the obtained data to be computed.

[0129] The implementation method corresponding to the privacy-preserving computation task as a secure multi-party computation task involves at least one group of computing nodes executing privacy algorithm instructions or target sub-instruction sets according to the execution order of multiple privacy algorithm instructions or multiple target sub-instruction sets in the target instruction set determined by the coordinating node, based on the protocol plugins to be executed, to process the obtained data to be computed. Specifically, this process may include:

[0130] S2061. At least two computing nodes in the first computing node group obtain the data to be calculated, which is determined based on at least two numerical partitions, and the at least two numerical partitions are different from each other.

[0131] S2062. Each computing node in the first computing node group obtains the first target instruction sent by the coordinating node and the protocol plugin configured for the first target instruction. The first target instruction is one of the privacy algorithm instructions or target sub-instruction sets executed according to the above execution order determined by the coordinating node.

[0132] S2063. Each computing node in the first computing node group executes the first target instruction based on the protocol plugin configured for the first target instruction, processes the data to be computed obtained by the computing node, and obtains the first processing result.

[0133] S2064. Each computing node in the first computing node group obtains computing node information of at least two target computing nodes for executing the second target instruction, as determined by the coordinating node based on the above execution order, and broadcasts the first processing result to the second computing node group based on the computing node information.

[0134] In the second computing node group, the target computing node can execute the second target instruction based on the protocol plugin configured by the coordinating node for the second target instruction, and process the obtained first processing result.

[0135] The second target instruction is a privacy algorithm instruction or a set of target sub-instructions that executes after the first target instruction and whose execution order is adjacent to that of the first target instruction. For example, such as Figure 6 As shown, the three computing nodes in the first computing node group respectively obtain the data to be computed, input1, input2, and input3. Each computing node in the first computing node group obtains the first target instruction sent by the coordinating node and the protocol plugin configured for the first target instruction. The first target instruction includes Add (i.e., addition operator), Open (i.e., operator to recover plaintext from ciphertext), and Mul (i.e., multiplication operator). The first processing results x1, x2, and x3 of each computing node in the first computing node group are broadcast to the second computing node group. The second computing node group can execute the second target instruction based on the protocol plugin configured for the second target instruction determined by the coordinating node to process the first processing results. The second target instruction includes two Cmp (i.e., operators for comparing sizes) and one Equal (i.e., operators for comparing whether they are equal).

[0136] In this embodiment, the data distribution instruction is determined according to the target instruction set and sent to the data provider node. This allows the data provider node to send the data to be calculated to at least one computing node group according to the data distribution instruction. This avoids the data provider node blindly sending data to the computing node group, ensuring the efficiency of the computing node group in obtaining the data to be calculated, and thus ensuring the efficiency of calculation based on the data to be calculated.

[0137] As another optional embodiment of this application, refer to Figure 7 This is a flowchart illustrating a data processing method embodiment 3 provided in this application. This embodiment is mainly a refinement of the data processing method described in embodiment 1 above. The method may include, but is not limited to, the following steps:

[0138] Step S301: Receive the privacy computing task creation instruction sent by the data providing node.

[0139] Step S302: Determine the target instruction set from the pre-stored privacy algorithm instruction set. The target instruction set matches the privacy computing task creation instruction.

[0140] Step S303: Configure the protocol plugin set for the target instruction set according to the pre-stored protocol configuration information.

[0141] For a detailed description of steps S301-S303, please refer to the relevant description of steps S101-S103 in Example 1, which will not be repeated here.

[0142] Step S304: Encrypt the target instruction set according to the target public key, where the target public key is the public key of each computing node in at least one computing node group.

[0143] In this embodiment, the public keys of each computing node in the computing node group are different from each other.

[0144] Specifically, encrypting the target instruction set based on the target public key can include:

[0145] The target instruction set is encrypted using the public key of each computing node in the computing node group.

[0146] Step S305: Send the encrypted target instruction set and protocol plugin set to at least one computing node group.

[0147] After receiving the encrypted target instruction set, each computing node in the computing node group decrypts the encrypted target instruction set using its private key corresponding to its public key, thus obtaining the target instruction set.

[0148] Steps S304-S305 are a specific implementation of step S104 in Example 1.

[0149] In this embodiment, the public keys of each computing node in the computing node group are different from each other, and the target instruction set is encrypted using the target public key. The encrypted target instruction set is then sent to at least one computing node group. This can ensure the security of the target instruction set transmission and the privacy of the target instruction set obtained by each computing node in the computing node group, preventing the target instruction set obtained by the computing node from being leaked.

[0150] As another optional embodiment of this application, refer to Figure 8 This is a flowchart illustrating an embodiment 4 of a data processing method provided in this application. This embodiment is mainly an extension of the data processing method described in embodiment 1 above. The method may include, but is not limited to, the following steps:

[0151] Step S401: Receive the privacy computing task creation instruction sent by the data providing node.

[0152] Step S402: Determine the target instruction set from the pre-stored privacy algorithm instruction set. The target instruction set matches the privacy computing task creation instruction.

[0153] Step S403: Configure the protocol plugin set for the target instruction set according to the pre-stored protocol configuration information.

[0154] Step S404: Send the target instruction set and protocol plugin set to at least one computing node group.

[0155] For detailed procedures of steps S401-S404, please refer to the relevant description of steps S101-S104 in Example 1, which will not be repeated here.

[0156] Step S405: Determine the target privacy transmission protocol that matches the target instruction set.

[0157] Determining the target privacy transport protocol that matches the target instruction set may include:

[0158] S4051. Based on the target instruction set, determine the data type of the processing result that can be obtained by executing the privacy algorithm instruction or sub-instruction set in the target instruction set.

[0159] S4052. If the data type is plaintext, then the consistency verification transmission protocol is determined to be the target privacy transmission protocol that matches the target instruction set.

[0160] S4053. If the data type is ciphertext, then the blinding transmission protocol is determined to be the target privacy transmission protocol that matches the target instruction set.

[0161] Step S406: Send the target privacy transmission protocol to at least one computing node group to configure the privacy data transmission relationship between each computing node in at least one computing node group.

[0162] In an implementation where the consistency verification transport protocol is determined as the target privacy transport protocol, configuring the privacy data transmission relationship between each compute node in the compute node group may include:

[0163] S4061. Configure the data transmission mode of at least two first computing nodes in the computing node group used to execute the first target instruction to be plaintext transmission.

[0164] The first target instruction is one of the privacy algorithm instructions or target sub-instruction sets executed in the execution order of multiple privacy algorithm instructions or multiple target sub-instruction sets in the target instruction set determined by the coordination node.

[0165] S4062. The data processing method for at least two second computing nodes in the configuration computing node group used to execute the second target instruction is to perform consistency verification on the data received from at least two first computing nodes, and after the consistency verification is passed, the data received from at least two first computing nodes is determined as the data to be used.

[0166] The second target instruction is a privacy algorithm instruction or a set of target sub-instructions that is executed after the first target instruction and whose execution order is adjacent to that of the first target instruction.

[0167] It is understandable that the first computing node and the second computing node can be the same computing node.

[0168] In an implementation where the consistency verification transport protocol is determined as the target privacy transport protocol, configuring the privacy data transmission relationship between each compute node in the compute node group may also include:

[0169] S4063. Configure the data transmission mode of at least two computing nodes in the first computing node group used to execute the first target instruction to be plaintext transmission.

[0170] The first target instruction in this step can be found in the relevant description in step S4061, and will not be repeated here.

[0171] S4064. The data processing method for at least two computing nodes in the second computing node group used to execute the second target instruction is to perform a consistency check on the data received from at least two computing nodes in the first computing node group. After the consistency check is passed, the data received from at least two computing nodes in the first computing node group is determined as the data to be used.

[0172] The second target instruction in this step can be found in the relevant description in step S4062, and will not be repeated here.

[0173] In this embodiment, the first computing node group and the second computing node group are different computing node groups.

[0174] After completing the configuration in steps S4063-S4064, each computing node in at least one computing node group can transmit data according to privacy data transmission relationships to ensure data security. For example, Figure 9 As shown, the first computing node group includes three computing nodes, namely Peer1, Peer2, and Peer3. Peer1, Peer2, and Peer3 execute the same privacy algorithm instruction or target sub-instruction set based on the same protocol plugin to obtain the processing result x2. If it is determined that the processing result x2 is of plaintext type, Peer1, Peer2, and Peer3 broadcast the processing result x2 to Peer4 and Peer5 in the second computing node group. Peer4 performs a consistency check on the processing result x2 from Peer1, Peer2, and Peer3. If the consistency check passes, the processing result x2 is determined as data to be used. Peer5 performs a consistency check on the processing result x2 from Peer1, Peer2, and Peer3. If the consistency check passes, the processing result x2 is determined as data to be used. This can prevent the processing result x2 from being tampered with during transmission, which would cause the second computing node group to process incorrect data.

[0175] Corresponding to the implementation method of determining the blinding transmission protocol as the target privacy transmission protocol that matches the target instruction set, configuring the privacy data transmission relationship between each computing node in the computing node group may include:

[0176] S4065. Configure the data transmission mode of at least two computing nodes in the first computing node group used to execute the first target instruction to be encrypted transmission.

[0177] In the case of a privacy-preserving computation task that is a multi-party secure computation task, if the ciphertext type is specifically a numerical fragment type, then the ciphertext transmission may include:

[0178] S40651. A first numerical partition is determined based on a first random number, and different computing nodes in the first computing node group obtain different first numerical partitions.

[0179] The first numerical slice is determined based on the first random number, including:

[0180] Based on the first random number, a first numerical partition is used to determine the number of targets, and the number of targets is the same as the number of at least two computing nodes in the first computing node group.

[0181] S40652. Based on the first numerical slice obtained therefrom, the first processing result obtained by executing the first target instruction is hidden to obtain a blinded numerical value.

[0182] S40653. Based on the computing node information obtained in step S2064, broadcast its blinded value to at least two computing nodes in the second computing node group.

[0183] S4066. Configure the data processing method of at least two computing nodes in the second computing node group used to execute the second target instruction to be based on blinded values ​​and the third value fragment obtained by the computing nodes in the second computing node group, and determine the second value fragment.

[0184] In this embodiment, the first numerical partition of each computing node in the first computing node group can be determined in the following way:

[0185] S406511. Based on the first random number, determine the first numerical slice with the number of targets, wherein the number of targets is the same as the number of at least two computing nodes in the first computing node group;

[0186] S406512. Select one of the first numerical fragments of the target number as the first numerical fragment to be used, and send the first numerical fragments other than the first numerical fragment to be used to other computing nodes in the first computing node group.

[0187] S406513, Receive the first numerical fragment from other computing nodes in the first computing node group;

[0188] S406514. Determine the first target numerical fragment based on the first numerical fragment to be used and the first numerical fragments from other computing nodes in the first computing node group.

[0189] Accordingly, the third numerical partition of each computing node in the second computing node group can be determined in the following way:

[0190] S406515. Each computing node in the first computing node group determines a third numerical partition of the number of second targets based on a second random number. The number of second targets is the same as the number of at least two computing nodes in the second computing node group, and the second random number is equal to the first random number.

[0191] S406516. Each computing node in the first computing node group sends the third numerical fragment of the obtained second target number to each computing node in the second computing node group, so that each computing node in the second computing node group processes the received third numerical fragment to obtain the third numerical fragment of the computing node in the second computing node group.

[0192] For example, such as Figure 10 As shown, the first computing node group includes three computing nodes, namely Peer1, Peer2, and Peer3. Peer1 determines three first numerical partitions based on the first random number u1, namely u 11 u12 u 13 Peer2 determines three first numerical partitions based on the first random number u2, namely u 21 u 22 u 23 Peer3 determines three first numerical partitions based on the first random number u3, namely u 31 u 32 u 33 , Peer1 will u 11 As the first numerical slice to be used, u 12 Send to Peer2, with u 13 Send to Peer3, Peer2 will send u 21 As the first numerical slice to be used, u 22 Send to Peer2, with u 23 Send it to Peer3, Peer3 will send u 31 As the first numerical slice to be used, u 32 Send to Peer2, with u 33 Send to Peer3, Peer1 based on u 11 u 21 and u 31 The first target numerical slice [r] = u is obtained. 11 +u 21 +u 31 Peer2 is based on u 12 u 22 and u 32 The first target numerical slice [r] = u is obtained. 12 +u 22 +u 32 Peer3 is based on u 13 u 23 and u 33 The first target numerical slice [r] = u is obtained. 13 +u 23 +u 33 Peer1 determines two third numerical partitions based on the second random number u′1, namely u′ 14 、u′ 15 Peer2 determines two third-valued partitions based on the second random number u'2, namely u' 24 、u' 25 Peer3 determines two first value partitions based on the second random number u'3, namely u' 34 、u' 35 , Peer1 will u′ 14 Send it to Peer4 in the second compute node group, Peer1 will send u′ 15Send it to Peer5 in the second compute node group, Peer2 will send u' 24 Send it to Peer4 in the second compute node group, Peer2 will send u' 25 Send it to Peer5 in the second compute node group, Peer3 will send u' 34 Send it to Peer4 in the second compute node group, Peer3 will send u' 35 Send to Peer5 and Peer4 in the second compute node group for u′ 14 、u' 24 and u' 34 After processing, the third numerical fragment of Peer4, [r'] = u', is obtained. 14 +u' 24 +u' 34 Peer2 on u′ 15 、u' 25 and u' 35 After processing, the third numerical fragment of Peer5, [r'] = u', is obtained. 15 +u' 25 +u' 35 .

[0193] After completing the configuration in steps S4065-S4066, each computing node in at least one computing node group can transmit data according to privacy data transmission relationships to ensure data privacy and prevent data leakage. For example, Figure 11As shown, the first computing node group includes three computing nodes, namely Peer1, Peer2, and Peer3. Peer1, Peer2, and Peer3 execute the same privacy algorithm instruction or target sub-instruction set based on the same protocol plugin to obtain the processing result [x1]. The processing result [x1] is a data fragment. Peer1, Peer2, and Peer3 determine the first numerical fragment [r] based on the first random number r, and the first numerical fragment [r] obtained by different computing nodes in the first computing node group is different. Peer1, Peer2, and Peer3 perform a hiding process on the processing result [x1] based on their obtained first numerical fragment [r] to obtain a blinded value x1+r. Peer1, Peer2, and Peer3 broadcast the blinded value x1+r to Peer4 and Peer5 in the second computing node group. Since r is a random number, x1+r will not expose x1, ensuring the privacy of x1 transmission. Peer4 and Peer5 can obtain the third numerical fragment [r'] based on the second random number r', and execute [x′1] = x1 + r - [r'] to obtain the second numerical fragment [x′1]. It can be understood that the data recovery party can recover x1 based on the second numerical fragment [x′1] and the following method: x′1 = open([x′1]) = open(x1 + r - [r']) = x1 + rr = x1.

[0194] The following section describes a data processing apparatus provided in this application. The data processing apparatus described below can be referred to in correspondence with the data processing method described above.

[0195] Please see Figure 12 The data processing device is applied to the collaborative node and includes: a receiving module 100, a determining module 200, a configuration module 300, and a sending module 400.

[0196] The receiving module 100 is used to receive the privacy computing task creation instruction sent by the data providing node;

[0197] The determination module 200 is used to determine the target instruction set from the pre-stored privacy algorithm instruction set, and the target instruction set matches the privacy computing task creation instruction;

[0198] Configuration module 300 is used to configure a protocol plugin set for the target instruction set according to the pre-stored protocol configuration information;

[0199] The sending module 400 is used to send the target instruction set and protocol plugin set to at least one computing node group.

[0200] In this embodiment, the data processing device may further include:

[0201] The data distribution module is used for:

[0202] Determine the data distribution instructions based on the target instruction set;

[0203] A data distribution instruction is sent to the data provider node, so that the data provider node sends the data to be computed to at least one group of computing nodes according to the data distribution instruction.

[0204] In this embodiment, the data processing device may further include:

[0205] Pre-store module, used for:

[0206] Receive the privacy algorithm instruction set and its protocol configuration information from the algorithm provider node;

[0207] The privacy algorithm instruction set and protocol configuration information are stored.

[0208] In this embodiment, the protocol configuration information records the privacy computing protocol corresponding to each privacy algorithm instruction in the privacy algorithm instruction set;

[0209] Alternatively, the privacy algorithm instruction set may contain multiple sub-instruction sets, and the protocol configuration information records the privacy computing protocol corresponding to each sub-instruction set.

[0210] In this embodiment, the determining module 200 can be specifically used for:

[0211] The target instruction set is determined based on the selection instructions sent by the data providing node;

[0212] Alternatively, the target instruction set can be determined from a pre-stored privacy algorithm instruction set based on the query instruction sent by the data providing node;

[0213] Alternatively, the target instruction set can be matched from the pre-stored privacy algorithm instruction set based on the task description information sent by the data providing node.

[0214] In this embodiment, the privacy algorithm instructions sent to the same computing node group in the target instruction set have the same privacy computing protocol.

[0215] In this embodiment, the sending module 400 can be specifically used for:

[0216] The target instruction set is encrypted using the target public key, which is the public key of each computing node in the at least one computing node group.

[0217] Send the encrypted target instruction set and protocol plugin set to at least one computing node group.

[0218] In this embodiment, the data processing device may further include:

[0219] The privacy transmission protocol determination module is used to determine the target privacy transmission protocol that matches the target instruction set;

[0220] The privacy transmission protocol sending module is used to send the target privacy transmission protocol to at least one computing node group to configure the privacy data transmission relationship between each computing node in the at least one computing node group.

[0221] Corresponding to the above-described embodiment of a data processing method provided in this application, this application also provides an embodiment of an electronic device that applies the data processing method.

[0222] like Figure 13 The diagram shown is a structural schematic of an electronic device according to embodiment 1 of this application. The electronic device may include the following structure:

[0223] Memory 10 and processor 20.

[0224] Memory 10 is used to store at least one set of instructions;

[0225] Processor 20 is configured to call and execute the instruction set in memory 10, and execute the data processing method described in any one of the above method embodiments 1-4 by executing the instruction set.

[0226] Corresponding to the above-described embodiment of a data processing method provided in this application, this application also provides an embodiment of a storage medium.

[0227] In this embodiment, the storage medium stores a computer program that implements the data processing method described in any one of the embodiments 1-4. The computer program is executed by a processor to implement the data processing method described in any one of the embodiments 1-4.

[0228] It should be noted that each embodiment focuses on describing the differences from other embodiments, and the same or similar parts between the embodiments can be referred to accordingly. For the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiments.

[0229] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0230] For ease of description, the above devices are described in terms of function, divided into various modules. Of course, in implementing this application, the functions of each module can be implemented in one or more software and / or hardware.

[0231] As can be seen from the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary general-purpose hardware platforms. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments or some parts of the embodiments of this application.

[0232] The above provides a detailed description of a data processing method, apparatus, and electronic device provided in this application. Specific examples have been used to illustrate the principles and implementation methods of this application. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A data processing method applied to a coordinating node, the method comprising: Receive privacy computing task creation instructions sent by the data provider node; A target instruction set is determined from a pre-stored privacy algorithm instruction set, which matches the privacy computing task creation instruction; the pre-stored privacy algorithm instruction set includes at least one privacy algorithm instruction or at least one sub-instruction set, and each sub-instruction set contains at least one sub-privacy algorithm instruction. Configure a protocol plugin set for the target instruction set according to the pre-stored protocol configuration information; wherein, the protocol configuration information records the privacy computing protocol corresponding to each privacy algorithm instruction in the privacy algorithm instruction set; or, the privacy algorithm instruction set has multiple sub-instruction sets, and the protocol configuration information records the privacy computing protocol corresponding to each sub-instruction set; The target instruction set is encrypted using the public key of each computing node in the computing node group. The encrypted target instruction set and the protocol plugin set are sent to at least one computing node group.

2. The method according to claim 1, further comprising: Determine data distribution instructions based on the target instruction set; The data distribution instruction is sent to the data providing node, so that the data providing node sends the data to be computed to the at least one computing node group according to the data distribution instruction.

3. The method according to claim 1, wherein the privacy algorithm instruction set and the protocol configuration information are pre-stored in the following manner: Receive the privacy algorithm instruction set and the protocol configuration information of the privacy algorithm instruction set from the algorithm providing node; The privacy algorithm instruction set and the protocol configuration information are stored.

4. The method according to claim 1, wherein determining the target instruction set from the pre-stored privacy algorithm instruction set includes: The target instruction set is determined based on the selection instruction sent by the data providing node; Alternatively, the target instruction set may be determined from the pre-stored privacy algorithm instruction set based on the query instruction sent by the data providing node; Alternatively, the target instruction set can be matched from the pre-stored privacy algorithm instruction set based on the task description information sent by the data providing node.

5. The method according to claim 1, wherein the privacy algorithm instructions sent to the same computing node group in the target instruction set have the same privacy computing protocol.

6. The method according to claim 1, after determining the target instruction set matching the privacy computing task creation instruction from the pre-stored privacy algorithm instruction set, the method further includes: Determine the target privacy transport protocol that matches the target instruction set; The target privacy transmission protocol is sent to the at least one computing node group to configure the privacy data transmission relationship between the computing nodes in the at least one computing node group.

7. A data processing apparatus applied to a coordination node, the apparatus comprising: The receiving module is used to receive privacy computing task creation instructions sent by the data providing node; A determination module is used to determine a target instruction set from a pre-stored privacy algorithm instruction set, the target instruction set being matched with the privacy computing task creation instruction; the pre-stored privacy algorithm instruction set includes at least one privacy algorithm instruction or at least one sub-instruction set, each sub-instruction set containing at least one sub-privacy algorithm instruction; A configuration module is used to configure a protocol plugin set for the target instruction set according to pre-stored protocol configuration information; wherein, the protocol configuration information records the privacy computing protocol corresponding to each privacy algorithm instruction in the privacy algorithm instruction set; or, the privacy algorithm instruction set has multiple sub-instruction sets, and the protocol configuration information records the privacy computing protocol corresponding to each sub-instruction set; The sending module is used to encrypt the target instruction set according to the public key of each computing node in the computing node group, and send the encrypted target instruction set and the protocol plugin set to at least one computing node group.

8. An electronic device, comprising: A memory and a processor are communicatively connected, the memory stores computer instructions, and the processor executes the computer instructions to perform the data processing method according to any one of claims 1-6.