A multi-party computing control method, device and equipment providing privacy protection

By deploying cluster systems and streaming computing engine applications in multi-party secure computing systems, desensitization of private data is achieved, and insufficient privacy protection in the existing technology is solved, and efficient privacy protection and improvement of computing efficiency is achieved.

CN114817982BActive Publication Date: 2025-05-09ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210394942.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-04-15
Publication Date
2025-05-09
Estimated Expiration
2042-04-15

AI Technical Summary

Technical Problem

The existing multi-party security computing technology has shortcomings in privacy protection, and data owners find it difficult to control the privacy of data during the calculation process, and data may be leaked.

Method used

By deploying central nodes and work nodes in the cluster system, and using streaming computing engine applications and application monitoring services, desensitization of private data of customer participants is realized, ensuring that the data is processed locally and only desensitized data is returned.

Benefits of technology

It realizes privacy protection for multi-party computing, avoids the leakage of original data, reduces the risks of privacy leakage and supervision, and improves computing efficiency and system initiative.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114817982B_ABST
    Figure CN114817982B_ABST
Patent Text Reader

Abstract

The embodiments of this specification disclose a multi-party computing control method, device and equipment that provides privacy protection. The scheme includes: determining a service provider with a central node of a cluster system deployed, and a customer participant with a working node of the cluster system deployed; determining a streaming computing engine application and an application monitoring service deployed on the working node; initiating a cluster task at the central node according to a specified stream processing rule, sending instructions to the streaming computing engine application through the cluster task to instruct the streaming computing engine application to obtain the private data of the customer participant locally, and perform desensitization calculation on the private data according to the stream processing rule to obtain desensitized data; communicating with the application monitoring service at the central node to obtain computing status monitoring data and desensitized data of the streaming computing engine application; completing the multi-party secure computing of the customer participant according to the computing status monitoring data and the desensitized data, so that the service provider can provide services according to the computing results.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of Internet technology, and in particular to a multi-party computing control method, device and equipment that provides privacy protection. Background Art

[0002] With the development of computer and Internet technology, more and more data are appearing in various fields of the Internet. As a new energy source, data can generate higher value only when it flows. However, due to various reasons, data owners sometimes do not want to disclose the relevant data they own, resulting in the phenomenon of data islands.

[0003] To this end, the concept of secure multi-party computing (MPC) was proposed, which aims to realize the flow of data without exposing the privacy of each data owner. It allows multiple data owners to perform collaborative computing without mutual trust, output the computing results, and ensure that no party can obtain any information other than the computing results they deserve.

[0004] In traditional multi-party secure computing, the service provider that provides collaborative services is assumed to be secure, and each data owner needs to orchestrate and deploy relevant content locally. Once the content is modified, it needs to be redeployed. However, these deployment processes and subsequent computing processes are often passively controlled and managed by each data owner, affecting the efficiency of cooperation. Moreover, during the computing process, the data owned by the data owner may still be leaked through the service provider that provides collaborative services.

[0005] Based on this, a more efficient and practical multi-party computing control solution that can provide privacy protection is needed. Summary of the invention

[0006] One or more embodiments of the present specification provide a multi-party computing control method, apparatus, device, and storage medium that provide privacy protection, to solve the following technical problem: A more efficient and practical multi-party computing control solution that can provide privacy protection is needed.

[0007] To solve the above technical problems, one or more embodiments of this specification are implemented as follows:

[0008] One or more embodiments of this specification provide a multi-party computing control method for providing privacy protection, including:

[0009] Determine a service provider that deploys a central node of the cluster system and a customer participant that deploys a working node of the cluster system;

[0010] Determine the stream computing engine application and application monitoring service deployed on the working node;

[0011] Initiate a cluster task at the central node according to the specified stream processing rule, and send an instruction to the stream computing engine application through the cluster task to instruct the stream computing engine application to obtain the private data of the client participant locally, and perform desensitization calculation on the private data according to the stream processing rule to obtain desensitized data;

[0012] Communicate with the application monitoring service at the central node to obtain computing status monitoring data of the stream computing engine application and the desensitized data;

[0013] The multi-party secure computation of the client participants is completed based on the computation status monitoring data and the desensitized data, so that the service provider can provide services based on the results of the multi-party secure computation.

[0014] One or more embodiments of this specification provide a multi-party computing control device that provides privacy protection, including:

[0015] A first deployment module determines a service provider that deploys a central node of the cluster system and a client participant that deploys a working node of the cluster system;

[0016] A second deployment module determines the stream computing engine application and application monitoring service deployed on the working node;

[0017] A task initiation module, which initiates a cluster task at the central node according to a specified stream processing rule, and sends an instruction to the stream computing engine application through the cluster task to instruct the stream computing engine application to obtain the private data of the client participant locally, and perform desensitization calculation on the private data according to the stream processing rule to obtain desensitized data;

[0018] A data acquisition module communicates with the application monitoring service at the central node to obtain computing status monitoring data of the stream computing engine application and the desensitized data;

[0019] The service providing module completes the multi-party secure computing of the client participants according to the computing status monitoring data and the desensitized data, so that the service provider can provide services according to the results of the multi-party secure computing.

[0020] One or more embodiments of this specification provide a multi-party computing control device that provides privacy protection, including:

[0021] at least one processor; and,

[0022] a memory communicatively connected to the at least one processor; wherein,

[0023] The memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to:

[0024] Determine a service provider that deploys a central node of the cluster system and a customer participant that deploys a working node of the cluster system;

[0025] Determine the stream computing engine application and application monitoring service deployed on the working node;

[0026] Initiate a cluster task at the central node according to the specified stream processing rule, and send an instruction to the stream computing engine application through the cluster task to instruct the stream computing engine application to obtain the private data of the client participant locally, and perform desensitization calculation on the private data according to the stream processing rule to obtain desensitized data;

[0027] Communicate with the application monitoring service at the central node to obtain computing status monitoring data of the stream computing engine application and the desensitized data;

[0028] The multi-party secure computation of the client participants is completed based on the computation status monitoring data and the desensitized data, so that the service provider can provide services based on the results of the multi-party secure computation.

[0029] One or more embodiments of this specification provide a non-volatile computer storage medium storing computer executable instructions, wherein the computer executable instructions are configured to:

[0030] Determine a service provider that deploys a central node of the cluster system and a customer participant that deploys a working node of the cluster system;

[0031] Determine the stream computing engine application and application monitoring service deployed on the working node;

[0032] Initiate a cluster task at the central node according to the specified stream processing rule, and send an instruction to the stream computing engine application through the cluster task to instruct the stream computing engine application to obtain the private data of the client participant locally, and perform desensitization calculation on the private data according to the stream processing rule to obtain desensitized data;

[0033] Communicate with the application monitoring service at the central node to obtain computing status monitoring data of the stream computing engine application and the desensitized data;

[0034] The multi-party secure computation of the client participants is completed based on the computation status monitoring data and the desensitized data, so that the service provider can provide services based on the results of the multi-party secure computation.

[0035] At least one of the above technical solutions adopted in one or more embodiments of this specification can achieve the following beneficial effects:

[0036] The cluster system is built by deploying central nodes and working nodes according to the service provider and customer participants. The streaming computing engine application and application monitoring service on the cluster system can quickly deploy and issue cluster tasks, and realize task monitoring upload, so that the system can quickly iterate statistical logic and universally serve various monitoring scenarios. And only through the instructions in the cluster task, the calculation rules of the streaming computing engine application can be modified without redeployment, which reduces the development and maintenance costs, improves computing efficiency, strengthens centralized control, and improves initiative. In addition, the system operation processing logic is completed on the customer participant side, and only the desensitized data and the calculation results after streaming computing are returned to the service provider, avoiding the privacy leakage and regulatory risks caused by the original private data leaving the domain, thereby ensuring the provision of privacy protection and realizing multi-party computing control. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] In order to more clearly illustrate the embodiments of this specification or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0038] Figure 1 A flowchart of a multi-party computing control method providing privacy protection provided in one or more embodiments of this specification;

[0039] Figure 2 A schematic diagram of a stream computing engine application in an application scenario provided for one or more embodiments of this specification;

[0040] Figure 3 A schematic diagram of a business execution process in an application scenario provided for one or more embodiments of this specification;

[0041] Figure 4 A schematic diagram of the structure of a multi-party computing control device providing privacy protection provided in one or more embodiments of this specification;

[0042] Figure 5 A schematic diagram of the structure of a multi-party computing control device providing privacy protection provided in one or more embodiments of this specification. DETAILED DESCRIPTION

[0043] The embodiments of this specification provide a multi-party computing control method, apparatus, device, and storage medium that provide privacy protection.

[0044] In order to enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the drawings in the embodiments of this specification. Obviously, the described embodiments are only part of the embodiments of this application, not all of them. Based on the embodiments of this specification, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of this application.

[0045] Figure 1 A flowchart of a multi-party computing control method for providing privacy protection is provided for one or more embodiments of this specification. The method can be applied to different business fields, such as Internet financial business field, e-commerce business field, instant messaging business field, game business field, official business field, etc. The process can be executed by a computing device in the corresponding field, and some input parameters or intermediate results in the process allow manual intervention and adjustment to help improve accuracy.

[0046] Figure 1 The process in may include the following steps:

[0047] S102: Determine a service provider on which a central node of a cluster system is deployed, and a client participant on which a working node of the cluster system is deployed.

[0048] A cluster refers to a group of nodes, which can be physical servers or virtual machines, and include at least a central node and a working node.

[0049] The working nodes belong to the client participants, who are the data owners. They own the relevant data for multi-party computing and can perform corresponding work on the data (for example, computing, transmitting, storing, etc.). The central nodes belong to the service providers, which are the parties that provide services to other nodes, such as providing management services and configuration services to working nodes, or providing business services to actual users (actual users refer to users who conduct business with client participants or service providers). Of course, the business service is usually related to the results obtained by multi-party computing.

[0050] S104: Determine the stream computing engine application (hereinafter referred to as engine application) and application monitoring service deployed on the working node.

[0051] Streaming data refers to a series of dynamic data sets that are infinite in time distribution and quantity. The value of data decreases over time, so real-time calculations must be performed to give a quick response. Streaming computing is a computing mode that performs real-time computing on streaming data, and engine applications are applications used to perform streaming computing.

[0052] The engine application is deployed on the working node, and it can perform streaming calculations on the data to be calculated on the working node. An application monitoring service is also deployed on the working node to monitor the working status of the engine application and the data processed. For example, it can determine whether the working status of the engine application is abnormal, obtain the calculation results of the data, etc. Here, the standard framework application can be packaged in binary form to obtain the engine application. On the working node that requires streaming calculation, the cluster system framework starts the engine application and the application monitoring service.

[0053] S106: According to the specified stream processing rules, a cluster task is initiated at the central node, and instructions are sent to the stream computing engine application through the cluster task to instruct the stream computing engine application to obtain the private data of the customer participant locally, and perform desensitizing calculation on the private data according to the stream processing rules to obtain desensitized data.

[0054] The cluster task is generated and initiated by the central node. The cluster task carries corresponding parameters, and its main function is to control multi-party computing. For example, according to the cluster task, instructions are sent to each engine application to control the opening and closing of the engine application, calculate the data, and return the calculation results to the central node.

[0055] Private data refers to data owned by client participants. Generally speaking, client participants want to use this data for multi-party computing, but it usually contains some privacy data (for example, the client participants' own business data, the user data of their corresponding actual users, etc.), and the client participants do not want to disclose this data for multi-party computing.

[0056] Based on this, after the engine application obtains the private data of the client participants locally on the working node, it performs desensitization calculations on the private data according to the stream processing rules, and processes the part of the data involving privacy so that others cannot obtain the privacy. For example, for image data, some areas can be blurred; for text data, some of the data can be invalidated (using symbols such as "*" to replace characters), converted to random values, and data encryption can be performed; for audio data, some of the content can be muted.

[0057] S108: Communicate with the application monitoring service at the central node to obtain computing status monitoring data of the stream computing engine application and the desensitized data.

[0058] Computing status monitoring data is usually persistent, and the central node needs to collect the computing status monitoring data in real time to ensure whether there are any abnormalities in the working status of the engine application. If an abnormality occurs, it can be responded to quickly. Desensitized data is usually not persistent, and it is obtained based on the needs of actual users. For example, the actual user initiates a business demand at the service provider. The service provider initiates a cluster task based on the business demand and sends instructions to the engine application in each working node. At this time, the engine application obtains private data, and after desensitizing calculation, it returns the desensitized data to the central node. Since business needs are not continuous, the acquisition of desensitized data is usually not continuous.

[0059] S110: completing the multi-party secure computing of the client participants according to the computing status monitoring data and the desensitized data, so that the service provider can provide services according to the results of the multi-party secure computing.

[0060] At this time, the central node helps each working node to complete multi-party secure computing, for example, it provides engine application deployment and monitoring services, obtains and organizes desensitized data, etc., which can be regarded as providing services for multi-party secure computing. Of course, in the subsequent business execution process, the service provider can also continue to provide relevant services to the actual users who execute the business based on the calculation results of multi-party secure computing.

[0061] The system's computing and processing logic is completed by the client, and only the desensitized data and the calculation results after streaming processing are returned to the service provider, avoiding privacy leakage and regulatory risks caused by the original private data leaving the domain.

[0062] based on Figure 1 This specification also provides some specific implementation plans and extension plans of the method, which will be described below.

[0063] In one or more embodiments of this specification, to ensure the efficiency of the engine application deployment process, the cluster can be an automated container operation platform, such as a kubernetes cluster (also known as a k8s cluster). The kubernetes cluster can deploy, replicate, and schedule nodes, and can also expand or shrink the container scale at any time, organize containers into groups, provide load balancing between containers, provide container elasticity, and perform node cluster expansion, which is very convenient for the deployment process.

[0064] Based on this, the command line CLI interface of the engine application is obtained, and according to the specified stream processing rules, a cluster task (kubernetes job) is initiated in the central node, and instructions are sent to the CLI interface through the kubernetes job. After receiving the instruction, the engine application is started and the streaming calculation of private data is started according to the streaming calculation task parameters carried in the instruction. Among them, the streaming calculation task parameters are mainly used to guide the engine application on how to perform data calculation, such as which data to sum, integrate, and modulus.

[0065] Furthermore, after the central node sends the instruction, the engine application starts to perform streaming computing. At this time, the application monitoring service is started synchronously to monitor the streaming computing process of the application, for example, to monitor whether the working status of the engine application is abnormal, whether the engine application is calculated according to the streaming computing task parameters carried in the instruction, etc. If an abnormality occurs, it can be reported to the central node for timely processing by the central node.

[0066] At this time, the central node receives the computing status monitoring data and desensitized data of the engine application reported by the application monitoring service through a gateway (such as gateway, which is a restful API gateway based on the http protocol and can be used as a unified API access layer), and then uploads it to the system framework API service for the framework API to control the engine application. Among them, the framework API service refers to the interface customized based on the corresponding framework.

[0067] In one or more embodiments of this specification, it has been mentioned above that the privacy of the data of the client participants is protected by performing desensitization calculations through the engine application. However, in fact, the protection here is limited to protecting the private data from being leaked due to multi-party computing. If the private data is leaked due to local security issues of the engine application, desensitization calculations are difficult to achieve the privacy protection effect.

[0068] Based on this, after receiving the desensitized data, the framework API service will not immediately perform multi-party secure computing through the desensitized data, but will generate simulated data for the client participants through the desensitized data. Simulated data means that after desensitizing calculations are performed on the simulated data, data similar to or even identical to the simulated data can be obtained. Similarity means that the degree of difference between the data and the desensitized data is lower than the preset threshold. For example, the original private data is the ID card number "123456789", and the desensitized data obtained after desensitizing calculations is "123***789". At this time, the generated simulated data is "123000789", and the data obtained after desensitizing calculations is "123***789", which is the same as the previous desensitized data. Of course, if the data is different from the desensitized data but similar, it can also have a certain effect. It should be noted that the data used as an example here is only for the convenience of explanation and does not mean that the actual ID number is really as shown above.

[0069] Among them, the simulation data can be obtained after a certain degree of transformation based on the private data that can be obtained. However, the client participants usually do not transmit the private data directly to the service provider. In this case, the simulation data can be obtained by reverse compiling the desensitized data. For example, taking the ID card number in the above text as an example, the service provider can only get the desensitized data "123***789". After reverse compiling it, multiple possibilities can be obtained. These multiple possibilities can all be used to obtain the desensitized data through desensitization calculation. At this time, one or more possibilities are selected as simulation data.

[0070] After obtaining the simulation data, when the computing status monitoring data meets the predetermined conditions, the simulation data is injected into the engine application, and the engine application processes the simulation data as part of the data in the input stream of private data. A part of the simulation data is mixed with the private data. Even if the private data is really leaked in the engine application, the existence of this part of the simulation data will make it difficult for the party who illegally obtains the data to conduct illegal activities based on the private data obtained. In addition, since the calculation result of the simulation data after desensitization calculation is similar to the desensitized data, it will not have much impact on the calculation result of the final multi-party secure calculation. Of course, in order to ensure the accuracy of the calculation results, the simulation data can have a certain usage period. For example, a simulation data can only be used for one day.

[0071] Among them, the predetermined situation is determined based on the calculation status monitoring data. The calculation status monitoring data is mainly used to monitor whether the calculation of the engine application is abnormal. If an abnormality occurs, simulation data can be generated. For example, when the engine application is attacked, some data may fluctuate to a certain extent (for example, some data is frequently accessed and obtained in a short period of time). At this time, the fluctuation can be used as a predetermined situation, and similar simulation data can be generated for the part of the data corresponding to the fluctuation. Of course, the current calculation state can also be evaluated based on the calculation status monitoring data. If the evaluation result shows that there is a risk of abnormality, it can also be used as a predetermined situation. For example, when a certain type of data in the private data is sparsely distributed and its samples are relatively scarce in the space where it is located, once it is attacked, the specified data in this type of data is easier to be directly obtained and easier to be quickly identified by the attacker based on the number of samples; or, if this type of data is in a state of being accessed for a long time, the probability of it being attacked will also increase accordingly.

[0072] Furthermore, after sending instructions to the engine application and adding simulated data, instructions can continue to be sent to the engine application. If the engine application verifies that simulated data corresponding to private data already exists locally, the private data is replaced with the simulated data. Compared with the doping method, directly replacing private data with simulated data can achieve better privacy leakage prevention effects, but it also results in a decrease in the accuracy of the calculation results. Therefore, data replacement is not required in every round of multi-party secure computing. For example, it can be determined whether data replacement is required based on the risk level of the current predetermined situation (for example, if an abnormality has occurred, it is the highest risk level, and if no abnormality has occurred, the risk level is divided according to the actual situation) to ensure the accuracy of the final calculation result as much as possible.

[0073] In one or more embodiments of the present specification, before deploying the engine application to the working node, it needs to be built first. As mentioned above, it can be built through kubernetes.

[0074] Specifically, Figure 2Provided for one or more embodiments of this specification, a schematic diagram of a streaming computing engine application in an application scenario. Obtain an SQL parser and a computing rule parser to build an instruction parsing layer (SQL / Rule Parser) of a central node. Among them, the SQL parser is used to determine which data needs to be obtained from which customer participants, and the computing rule parser is used to determine how to calculate and process these data. Obtain an SQL processor (SQL processor) to build an execution plan generation layer. Obtain a streaming runtime (Streaming runtime) and an SQL runtime (SQL runtime) to build a plan execution layer. At this time, through the containerized application deployment capability of the kubernetes cluster, the instruction parsing layer, the execution plan generation layer, and the plan execution layer are packaged on the working node to obtain the engine application. Of course, the engine application can also include a data storage layer (storage), a data source layer (sources), a data sinking layer (sinks), etc. Among them, the data source of the data source layer can obtain data through message queues MQ and message queues MQTT, and the data of the data sinking layer can sink data through message queues MQTT, HTTP, File, etc. Provide a complete permission review and evidence storage solution to effectively prevent security risks.

[0075] Based on this, in the process of sending instructions, a SQL query instruction is sent to the CLI interface through the kubernetes job, indicating to start the streaming calculation of the private data obtained by the SQL query instruction query. Among them, if the SQL query instruction does not contain the streaming calculation task parameters, a description file is generated, which contains the streaming calculation task parameters, and the description file is sent to the CLI interface. If the subsequent streaming calculation task parameters change, with the help of a kubernetes-like system framework, by initiating a kubernetes job (it should be noted that the kubernetes job can be the same as the kubernetes job that sends the SQL query instruction in this embodiment, or it can be newly generated) to modify the description file, the streaming calculation task parameters can be changed, and the rapid deployment of iterative processing logic can be achieved, the system is decoupled, and the system robustness is enhanced while reducing deployment costs.

[0076] Figure 3 A schematic diagram of a business execution process in an application scenario is provided for one or more embodiments of this specification. The solution in this article is explained for a common business scenario. In this business scenario, the private data of the customer participant is the business data of the actual user served by the customer participant, and the desensitized data is used to determine the credit status of the actual user. For example, the customer participant is a bank and the service provider is a credit inquiry platform.

[0077] The actual user wants to check his own credit status and initiates a business demand on the credit query platform, triggering the framework API service. The framework API service generates and sends SQL query instructions to the engine application. After receiving the instruction, the engine application parses the instruction through the instruction parsing layer, and performs desensitized calculations and streaming calculations based on the private data obtained from the log file (for example, obtaining streaming data from the log file through the data stream module fluent module), and uploads the calculation results to the gateway of the central node. During the calculation process, the running status is reported to the gateway of the central node through the application monitoring service. While the gateway reports its own running status to the framework API service, it also reports the obtained data for statistical reporting and subsequent processing to obtain the credit status for the actual user and display it to the actual user.

[0078] In this business scenario, the user's credit score usually does not change drastically in a short period of time, and it has a certain lag (for example, the user's credit score does not change immediately after he owes money, but only after the debt has not been repaid for a certain period of time). Therefore, this business scenario is particularly suitable for the method described above, which generates simulated data and mixes or replaces it with private data to further protect privacy.

[0079] Based on the same idea, one or more embodiments of this specification also provide devices and apparatuses corresponding to the above methods, such as Figure 4 , Figure 5 shown.

[0080] Figure 4 A schematic diagram of a multi-party computing control device for providing privacy protection is provided for one or more embodiments of this specification, and the device includes:

[0081] The first deployment module 402 determines a service provider that deploys a central node of the cluster system and a client participant that deploys a working node of the cluster system;

[0082] The second deployment module 404 determines the stream computing engine application and application monitoring service deployed on the working node;

[0083] The task initiation module 406 initiates a cluster task at the central node according to the specified stream processing rule, and sends an instruction to the stream computing engine application through the cluster task to instruct the stream computing engine application to obtain the private data of the client participant locally, and perform desensitization calculation on the private data according to the stream processing rule to obtain desensitized data;

[0084] The data acquisition module 408 communicates with the application monitoring service at the central node to obtain the computing status monitoring data of the stream computing engine application and the desensitized data;

[0085] The service providing module 410 completes the multi-party secure computing of the client participants according to the computing status monitoring data and the desensitized data, so that the service provider can provide services according to the results of the multi-party secure computing.

[0086] Optionally, the cluster is a kubernetes cluster;

[0087] The task initiating module 406 obtains the command line CLI interface of the stream computing engine application;

[0088] According to the specified stream processing rules, a kubernetes job is initiated at the central node, and an instruction to start streaming computing and streaming computing task parameters are sent to the CLI interface through the kubernetes job, so that the streaming computing engine application starts streaming computing for the private data according to the streaming computing task parameters.

[0089] Optionally, a synchronous monitoring module 412 is further included, which synchronously starts the application monitoring service when the instruction to start the streaming computing is sent, so that the application monitoring service monitors the process of the streaming computing;

[0090] The data acquisition module 408 receives the computing status monitoring data of the stream computing engine application and the desensitized data reported by the application monitoring service through the gateway of the central node;

[0091] The computing status monitoring data reported by the gateway is received through the framework API service of the central node, so that the framework API service controls the streaming computing engine application.

[0092] Optionally, the data acquisition module 408, the framework API service generates simulation data for the client participant according to the desensitized data, so that the simulation data can obtain data similar to the desensitized data through the desensitization calculation;

[0093] When the computing status monitoring data meets a predetermined condition, the simulation data is injected into the streaming computing engine application so that the streaming computing engine application processes the simulation data as part of the data in an input stream, wherein the input stream contains private data of the corresponding customer participant.

[0094] Optionally, it further includes a simulation data replacement module 414, which sends an instruction to the stream computing engine application through the cluster task to instruct the stream computing engine application to check whether simulation data corresponding to the private data already exists locally;

[0095] If so, the private data is replaced by the simulated data to generate desensitized data for the actual user corresponding to the private data.

[0096] Optionally, a cluster building module 416 is further included to obtain an SQL parser and a calculation rule parser for building a central node instruction parsing layer;

[0097] Get the SQL processor to build the execution plan generation layer;

[0098] Get the stream runtime and SQL runtime to build the plan execution layer;

[0099] Through the containerized application deployment capability of the Kubernetes cluster, the instruction parsing layer, the execution plan generation layer, and the plan execution layer are packaged on the working node to obtain the streaming computing engine application.

[0100] Optionally, the cluster building module 416 sends a SQL query instruction to the CLI interface through the kubernetes job to instruct to start streaming computing of the private data obtained by querying the SQL query instruction;

[0101] If the SQL query instruction does not contain the streaming computing task parameters corresponding to the streaming computing, a description file containing the streaming computing task parameters is generated and sent to the CLI interface. When the streaming computing task parameters change, the description file is modified through the kubernetes job.

[0102] Optionally, the private data of the client participant is business data of an actual user served by the client participant, and the desensitized data is used to determine the credit status of the actual user.

[0103] Figure 5 A schematic diagram of a multi-party computing control device providing privacy protection is provided for one or more embodiments of this specification, and the device includes:

[0104] at least one processor; and,

[0105] a memory communicatively connected to the at least one processor; wherein,

[0106] The memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to:

[0107] Determine a service provider that deploys a central node of the cluster system and a customer participant that deploys a working node of the cluster system;

[0108] Determine the stream computing engine application and application monitoring service deployed on the working node;

[0109] Initiate a cluster task at the central node according to the specified stream processing rule, and send an instruction to the stream computing engine application through the cluster task to instruct the stream computing engine application to obtain the private data of the client participant locally, and perform desensitization calculation on the private data according to the stream processing rule to obtain desensitized data;

[0110] Communicate with the application monitoring service at the central node to obtain computing status monitoring data of the stream computing engine application and the desensitized data;

[0111] The multi-party secure computation of the client participants is completed based on the computation status monitoring data and the desensitized data, so that the service provider can provide services based on the results of the multi-party secure computation.

[0112] Based on the same idea, one or more embodiments of this specification also provide a non-volatile computer storage medium corresponding to the above method, storing computer executable instructions, wherein the computer executable instructions are configured as follows:

[0113] Determine a service provider that deploys a central node of the cluster system and a customer participant that deploys a working node of the cluster system;

[0114] Determine the stream computing engine application and application monitoring service deployed on the working node;

[0115] Initiate a cluster task at the central node according to the specified stream processing rule, and send an instruction to the stream computing engine application through the cluster task to instruct the stream computing engine application to obtain the private data of the client participant locally, and perform desensitization calculation on the private data according to the stream processing rule to obtain desensitized data;

[0116] Communicate with the application monitoring service at the central node to obtain computing status monitoring data of the stream computing engine application and the desensitized data;

[0117] The multi-party secure computation of the client participants is completed based on the computation status monitoring data and the desensitized data, so that the service provider can provide services based on the results of the multi-party secure computation.

[0118] In the 1990s, improvements to a technology could be clearly distinguished as hardware improvements (for example, improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the method flow). However, with the development of technology, many improvements to the method flow today can be regarded as direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that an improvement in a method flow cannot be implemented using a hardware entity module. For example, a programmable logic device (PLD) (such as a field programmable gate array (FPGA)) is such an integrated circuit whose logical function is determined by the user's programming of the device. Designers can "integrate" a digital system on a PLD by programming it themselves, without having to ask a chip manufacturer to design and produce a dedicated integrated circuit chip. Moreover, nowadays, instead of manually making integrated circuit chips, this kind of programming is mostly implemented by "logic compiler" software, which is similar to the software compiler used when developing and writing programs, and the original code before compilation must also be written in a specific programming language, which is called hardware description language (HDL). There is not only one HDL, but many kinds, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones are VHDL (Very-High-Speed ​​Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also know that it is only necessary to program the method flow slightly in the above-mentioned hardware description languages ​​and program it into the integrated circuit, and then it is easy to obtain the hardware circuit that implements the logic method flow.

[0119] The controller can be implemented in any appropriate manner, for example, the controller can take the form of a microprocessor or processor and a computer-readable medium storing a computer-readable program code (such as software or firmware) that can be executed by the (micro)processor, a logic gate, a switch, an application-specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of controllers include, but are not limited to, the following microcontrollers: ARC625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that in addition to implementing the controller in a purely computer-readable program code manner, the controller can be implemented in the form of a logic gate, a switch, an application-specific integrated circuit, a programmable logic controller, and an embedded microcontroller by logically programming the method steps. Therefore, this controller can be considered as a hardware component, and the devices included therein for implementing various functions can also be regarded as structures within the hardware component. Or even, the devices for implementing various functions can be regarded as both software modules for implementing the method and structures within the hardware component.

[0120] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0121] For the convenience of description, the above device is described by dividing it into various units according to its functions. Of course, when implementing this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0122] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Therefore, the embodiments of this specification may be in the form of complete hardware embodiments, complete software embodiments, or embodiments in combination with software and hardware. Moreover, the embodiments of this specification may be in the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0123] This specification is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of this specification. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0124] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0125] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable device. Figure 1 A process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0126] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0127] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0128] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0129] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0130] This specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.

[0131] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the device, equipment, and non-volatile computer storage medium embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0132] The above is a description of a specific embodiment of the specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0133] The above description is only one or more embodiments of this specification and is not intended to limit this specification. For those skilled in the art, one or more embodiments of this specification may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of one or more embodiments of this specification shall be included in the scope of the claims of this specification.

Claims

1. A multi-party computing control method providing privacy protection, comprising: Determine a service provider that deploys a central node of the cluster system and a customer participant that deploys a working node of the cluster system; Determine the stream computing engine application and application monitoring service deployed on the working node; Initiate a cluster task at the central node according to the specified stream processing rule, and send an instruction to the stream computing engine application through the cluster task to instruct the stream computing engine application to obtain the private data of the client participant locally, and perform desensitization calculation on the private data according to the stream processing rule to obtain desensitized data; Communicate with the application monitoring service at the central node to obtain computing status monitoring data of the stream computing engine application and the desensitized data; The multi-party secure computation of the client participants is completed based on the computation status monitoring data and the desensitized data, so that the service provider can provide services based on the results of the multi-party secure computation.

2. The method according to claim 1, wherein the cluster is a Kubernetes cluster; The initiating a cluster task at the central node according to the specified stream processing rule, and sending instructions to the stream computing engine application through the cluster task specifically includes: Obtain the command line CLI interface of the stream computing engine application; According to the specified stream processing rules, a kubernetes job is initiated at the central node, and an instruction to start stream computing and stream computing task parameters are sent to the CLI interface through the kubernetes job, so that the stream computing engine application starts the stream computing of the private data according to the stream computing task parameters.

3. The method of claim 2, further comprising: When the instruction to start the streaming computing is sent, the application monitoring service is started synchronously, so that the application monitoring service monitors the process of the streaming computing; The communication between the central node and the application monitoring service to obtain the computing status monitoring data of the stream computing engine application and the desensitized data specifically includes: Receiving, through the gateway of the central node, the computing status monitoring data of the streaming computing engine application and the desensitized data reported by the application monitoring service; The computing status monitoring data reported by the gateway is received through the framework API service of the central node, so that the framework API service controls the streaming computing engine application.

4. The method according to claim 3, wherein the framework API service controls the stream computing engine application, specifically comprising: The framework API service generates simulation data for the client participant based on the desensitized data, so that the simulation data can obtain data similar to the desensitized data through the desensitization calculation; When the computing status monitoring data meets a predetermined condition, the simulation data is injected into the streaming computing engine application so that the streaming computing engine application processes the simulation data as part of the data in an input stream, wherein the input stream contains private data of the corresponding customer participant.

5. The method according to claim 4, wherein after the central node initiates the cluster task, the method further comprises: Sending an instruction to the stream computing engine application through the cluster task to instruct the stream computing engine application to check whether simulation data corresponding to the private data already exists locally; If so, the private data is replaced with the simulated data to generate desensitized data for the actual user corresponding to the private data.

6. The method according to claim 2, before determining the stream computing engine application deployed on the working node, the method further comprises: Obtain SQL parser and calculation rule parser to build the central node instruction parsing layer; Get the SQL processor to build the execution plan generation layer; Get the stream runtime and SQL runtime to build the plan execution layer; Through the containerized application deployment capability of the Kubernetes cluster, the instruction parsing layer, the execution plan generation layer, and the plan execution layer are packaged on the working node to obtain the streaming computing engine application.

7. The method according to claim 6, wherein the step of sending the instruction to start streaming computing and the streaming computing task parameters to the CLI interface through the kubernetes job specifically comprises: Sending a SQL query instruction to the CLI interface through the kubernetes job to instruct to start streaming computing of the private data obtained through the SQL query instruction; If the SQL query instruction does not contain the streaming computing task parameters corresponding to the streaming computing, a description file containing the streaming computing task parameters is generated and sent to the CLI interface. When the streaming computing task parameters change, the description file is modified through the kubernetes job.

8. According to the method described in any one of claims 1 to 7, the private data of the customer participant is the business data of the actual user served by the customer participant, and the desensitized data is used to determine the credit status of the actual user.

9. A multi-party computing control device providing privacy protection, comprising: A first deployment module determines a service provider that deploys a central node of the cluster system and a client participant that deploys a working node of the cluster system; A second deployment module determines the stream computing engine application and application monitoring service deployed on the working node; A task initiation module, which initiates a cluster task at the central node according to a specified stream processing rule, and sends an instruction to the stream computing engine application through the cluster task to instruct the stream computing engine application to obtain the private data of the client participant locally, and perform desensitization calculation on the private data according to the stream processing rule to obtain desensitized data; A data acquisition module communicates with the application monitoring service at the central node to obtain computing status monitoring data of the stream computing engine application and the desensitized data; The service providing module completes the multi-party secure computing of the client participants according to the computing status monitoring data and the desensitized data, so that the service provider can provide services according to the results of the multi-party secure computing.

10. The device according to claim 9, wherein the cluster is a kubernetes cluster; The task initiation module obtains the command line CLI interface of the stream computing engine application; According to the specified stream processing rules, a kubernetes job is initiated at the central node, and an instruction to start stream computing and stream computing task parameters are sent to the CLI interface through the kubernetes job, so that the stream computing engine application starts the stream computing of the private data according to the stream computing task parameters.

11. The device according to claim 10, further comprising a synchronous monitoring module, which synchronously starts the application monitoring service when the instruction to start the streaming computing is sent, so that the application monitoring service monitors the process of the streaming computing; The data acquisition module receives the computing status monitoring data of the streaming computing engine application and the desensitized data reported by the application monitoring service through the gateway of the central node; The computing status monitoring data reported by the gateway is received through the framework API service of the central node, so that the framework API service controls the streaming computing engine application.

12. The device according to claim 11, wherein the data acquisition module and the framework API service generate simulation data for the client participant according to the desensitized data, so that the simulation data can obtain data similar to the desensitized data through the desensitization calculation; When the computing status monitoring data meets a predetermined condition, the simulation data is injected into the streaming computing engine application so that the streaming computing engine application processes the simulation data as part of the data in an input stream, wherein the input stream contains private data of the corresponding customer participant.

13. The apparatus according to claim 12, further comprising a simulation data replacement module, which sends an instruction to the stream computing engine application through the cluster task to instruct the stream computing engine application to check whether simulation data corresponding to the private data already exists locally; If so, the private data is replaced with the simulated data to generate desensitized data for the actual user corresponding to the private data.

14. The device according to claim 10, further comprising a cluster construction module, which obtains a SQL parser and a calculation rule parser to construct a central node instruction parsing layer; Get the SQL processor to build the execution plan generation layer; Get the stream runtime and SQL runtime to build the plan execution layer; Through the containerized application deployment capability of the Kubernetes cluster, the instruction parsing layer, the execution plan generation layer, and the plan execution layer are packaged on the working node to obtain the streaming computing engine application.

15. The device according to claim 14, wherein the cluster construction module sends a SQL query instruction to the CLI interface through the kubernetes job to instruct to start the streaming calculation of the private data obtained by querying the SQL query instruction; If the SQL query instruction does not contain the streaming computing task parameters corresponding to the streaming computing, a description file containing the streaming computing task parameters is generated and sent to the CLI interface. When the streaming computing task parameters change, the description file is modified through the kubernetes job.

16. The device according to any one of claims 9 to 15, wherein the private data of the client participant is business data of an actual user served by the client participant, and the desensitized data is used to determine the credit status of the actual user.

17. A multi-party computing control device providing privacy protection, comprising: at least one processor; as well as, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to: Determine a service provider that deploys a central node of the cluster system and a customer participant that deploys a working node of the cluster system; Determine the stream computing engine application and application monitoring service deployed on the working node; Initiate a cluster task at the central node according to the specified stream processing rule, and send an instruction to the stream computing engine application through the cluster task to instruct the stream computing engine application to obtain the private data of the client participant locally, and perform desensitization calculation on the private data according to the stream processing rule to obtain desensitized data; Communicate with the application monitoring service at the central node to obtain computing status monitoring data of the stream computing engine application and the desensitized data; The multi-party secure computation of the client participants is completed based on the computation status monitoring data and the desensitized data, so that the service provider can provide services based on the results of the multi-party secure computation.

Citation Information

Patent Citations

  • Distributed Top-k query method based on privacy maintenance

    CN102394784A

  • Data encryption / decryption and desensitization operation engine and working method thereof

    CN108509805A