Scheduling system, information processing method and device based on secure multi-party computation

By introducing a scheduling system, the problem of existing secure multi-party computation schemes being incompatible with different computing resources and data sources is solved, enabling flexible data and task transmission in different environments and improving computing efficiency and data fusion capabilities.

CN115145701BActive Publication Date: 2026-07-21ALIBABA INNOVATION PRIVATE LIMITED

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ALIBABA INNOVATION PRIVATE LIMITED
Filing Date
2021-03-31
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing secure multi-party computation solutions are typically based on specific computing resources and are incompatible with any computing systems and data sources of the participating parties, leading to difficulties in data fusion.

Method used

It provides a scheduling system, including data source routing components, compute node routing components, configuration routing components, communication protocol routing components, and secure channel routing components. It supports multiple data sources, compute nodes, configuration nodes, communication protocols, and secure channels, enabling flexible routing and transmission of data and tasks.

Benefits of technology

It enables flexible loading and transmission of data and tasks in different computing environments, is compatible with any computing resources and data sources, and improves computing efficiency and data fusion capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115145701B_ABST
    Figure CN115145701B_ABST
Patent Text Reader

Abstract

Embodiments of the present specification provide a scheduling system, an information processing method and device based on secure multi-party computation. The scheduling system is used to assist a first participant node to participate in secure multi-party computation, and includes: a data source routing component supporting multiple data sources, and configured with first routing information corresponding to a first data source adopted by the first participant node, and used to, in response to a first loading instruction of the first participant node on first data related to a multi-party computation task, load the first data from the first data source to a first computing node of the first participant node according to the first routing information; and a computing node routing component supporting multiple computing nodes, and configured with second routing information corresponding to the first computing node, and used to, in response to an issuing instruction of the first participant node on the multi-party computation task, send the multi-party computation task to the first computing node according to the second routing information, so that the first computing node executes the multi-party computation task.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments in this specification relate to the field of computer technology, and more specifically, to scheduling systems, information processing methods and apparatus based on secure multi-party computation. Background Technology

[0002] The value of big data is constantly being explored, mined, and revealed, giving rise to numerous new business models. As big data increasingly integrates into various industries, the demand for data fusion across departments, companies, and industries is growing. However, due to various reasons, data fusion often fails, a problem known as the data silo problem. There are many reasons for the emergence of data silos, with data security being a crucial factor. To address this issue, secure multi-party computation has been introduced. As a data security computation method, secure multi-party computation can solve problems in data computation, fusion, and machine learning scenarios while ensuring data security.

[0003] Existing secure multi-party computation solutions are typically based on a specific type of computing resource or can only perform local computations. They cannot use any computing system that the participants are free to use, nor can they support various common data sources.

[0004] Therefore, there is an urgent need for a reasonable and reliable solution that can accommodate any environmental requirements of the participants, enabling them to use any computing resources and data sources when participating in secure multi-party computation. Summary of the Invention

[0005] This specification provides embodiments of a scheduling system, an information processing method and apparatus based on secure multi-party computation.

[0006] In a first aspect, embodiments of this specification provide a scheduling system for assisting a first participating node in participating in secure multi-party computation. The scheduling system includes: a data source routing component that supports multiple data sources and is configured with first routing information corresponding to the first data source adopted by the first participating node. In response to a first loading instruction from the first participating node for first data related to a multi-party computation task, the system loads the first data from the first data source to a first computing node of the first participating node according to the first routing information. The first data source belongs to the multiple data sources. A computing node routing component that supports multiple computing nodes and is configured with second routing information corresponding to the first computing node. In response to a issuing instruction from the first participating node for the multi-party computation task, the system sends the multi-party computation task to the first computing node according to the second routing information, causing the first computing node to execute the multi-party computation task. The first computing node belongs to the multiple computing nodes.

[0007] In some embodiments, the scheduling system further includes: a configuration routing component that supports multiple configuration nodes and configures third routing information corresponding to the first configuration node adopted by the first participating node, and is used to load the first configuration information from the first configuration node to a target location in response to a second loading instruction of the first participating node for the first configuration information of the first data, according to the third routing information, wherein the first configuration node belongs to the multiple configuration nodes and stores configuration information of the data in which the first participating node can participate in secure multi-party computation, and the target location is located locally on the first participating node and is related to the multi-party computation task.

[0008] In some embodiments, the scheduling system further includes: a communication protocol routing component that supports multiple communication protocols and is used to implement information transmission related to the multi-party computing task between the first participating node and other participating nodes using a specified communication protocol, wherein the specified communication protocol belongs to the multiple communication protocols.

[0009] In some embodiments, the scheduling system further includes: a secure channel routing component that supports multiple secure channels and is used to implement intermediate data exchange between the first computing node and other computing nodes related to the multi-party computing task through a specified secure channel, wherein the specified secure channel belongs to the multiple secure channels.

[0010] In some embodiments, the multiple data sources include a number of the following: data sources based on Relational Database Service (RDS), data sources based on Open Data Processing Service (ODPS), and MySQL; the multiple computing nodes include a number of the following: computing nodes based on ODPS service, computing nodes based on Hadoop, and computing nodes based on the local memory of participating nodes.

[0011] In some embodiments, the first loading instruction includes the storage path of the first data in the first data source; and the data source routing component is specifically configured to: obtain the first data from the first data source according to the storage path and the first routing information; and send the first data to the first computing node.

[0012] In some embodiments, the multiple configuration nodes include a number of the following: configuration nodes based on participant node local services, configuration nodes based on HSF services, and configuration nodes based on HTTP services.

[0013] In some embodiments, when the first configuration node is a configuration node based on the local service of the participant node, the third routing information includes the path information of the first configuration node in the first participant node; when the first configuration node is a configuration node based on HSF service, the third routing information includes the HSF interface provided by the first configuration node; when the first configuration node is a configuration node based on HTTP service, the third routing information includes the HTTP interface provided by the first configuration node.

[0014] In some embodiments, the multiple communication protocols include the HSF protocol and the HTTP protocol.

[0015] In some embodiments, the communication protocol routing component is configured with a first communication protocol for receiving messages for the first participating node, wherein the specified communication protocol includes the first communication protocol; and the communication protocol routing component is specifically used to: use the first communication protocol to receive messages related to the multi-party computing task sent by the other participating nodes, and send the messages to the first participating node.

[0016] In some embodiments, the communication protocol routing component is specifically used to: receive communication protocol information corresponding to the other participating nodes and messages related to the multi-party computing task from the first participating node, and send the messages to the other participating nodes using the second communication protocol indicated by the communication protocol information.

[0017] In some embodiments, the multiple secure channels include a number of the following: a transmission channel utilizing an intermediate node, a data transmission channel based on the object storage service OSS, and a data transmission channel based on a trusted encirclement.

[0018] In some embodiments, the secure channel routing component is configured with corresponding first secure channel information for the first computing node, the specified secure channel including the first secure channel indicated by the first secure channel information; and the secure channel routing component is specifically used to: obtain intermediate data required by the first computing node during task execution from the first secure channel, and send the intermediate data to the first computing node, wherein the intermediate data is sent to the first secure channel by the other computing nodes.

[0019] In some embodiments, the secure channel routing component is specifically used to: receive second secure channel information corresponding to the other computing nodes from the first computing node, as well as intermediate data generated by the first computing node during task execution, and send the intermediate data to the second secure channel indicated by the second secure channel information for the other computing nodes to obtain.

[0020] Secondly, embodiments of this specification provide an information processing method based on secure multi-party computation, applied to a scheduling system as described in the first aspect. The scheduling system assists a first participating node in participating in secure multi-party computation. The method includes: utilizing a data source routing component, in response to a first loading instruction from the first participating node for first data related to a multi-party computation task, loading the first data from the first data source to a first computing node of the first participating node according to first routing information corresponding to the first data source used by the first participating node; and utilizing a computing node routing component, in response to a issuing instruction from the first participating node for the multi-party computation task, sending the multi-party computation task to the first computing node according to second routing information corresponding to the first computing node, so that the first computing node executes the multi-party computation task.

[0021] Thirdly, embodiments of this specification provide an information processing method based on secure multi-party computation, applied to a first participating node, the first participating node corresponding to the scheduling system described in the first aspect. The method includes: generating a multi-party computation task based on acquired task information, the task information including the computation protocol used in this secure multi-party computation and first description information of first data participating in the computation, the first data belonging to the first participating node; sending a first loading instruction for the first data to a data source routing component in the scheduling system, causing the data source routing component to respond to the first loading instruction and load the first data from the first data source to a first computing node of the first participating node according to first routing information corresponding to the first data source used by the first participating node; sending a dispatch instruction for the multi-party computation task to a computing node routing component in the scheduling system, causing the computing node routing component to respond to the dispatch instruction and send the multi-party computation task to the first computing node according to second routing information corresponding to the first computing node, causing the first computing node to execute the multi-party computation task.

[0022] In some embodiments, the first description information includes the data source type of the first data source; and before sending the first load instruction for the first data to the data source routing component in the scheduling system, the method further includes: determining whether the data source type and the node type of the first computing node are the same; sending the first load instruction for the first data to the data source routing component in the scheduling system includes: in response to determining that the data source type and the node type are not the same, sending the first load instruction for the first data to the data source routing component in the scheduling system.

[0023] In some embodiments, the first description information includes a data identifier of the first data; and before sending a first load instruction for the first data to a data source routing component in the scheduling system, the method further includes: obtaining the storage path of the first data in the first data source based on the data identifier; and the first load instruction includes the storage path.

[0024] In some embodiments, the scheduling system further includes a configuration routing component that supports multiple configuration nodes and configures third routing information corresponding to the first configuration node adopted by the first participating node. The first configuration node belongs to the multiple configuration nodes and stores configuration information of data that the first participating node can participate in secure multi-party computation. The step of obtaining the storage path of the first data in the first data source based on the data identifier includes: sending a second loading instruction including the data identifier to the configuration routing component, causing the configuration routing component to respond to the second loading instruction and load the first configuration information of the first data from the first configuration node to a target location on the local machine of the first participating node according to the third routing information; and obtaining the storage path from the first configuration information in the target location.

[0025] In some embodiments, the scheduling system further includes a communication protocol routing component that supports multiple communication protocols; and the method further includes: during task execution, transmitting information related to the multi-party computing task between the first participating node and other participating nodes via the communication protocol routing component using a specified communication protocol, wherein the specified communication protocol belongs to the multiple communication protocols.

[0026] In some embodiments, the communication protocol routing component configures a first communication protocol for message reception for the first participating node, the specified communication protocol including the first communication protocol; and the transmission of information related to the multi-party computing task between the first participating node and other participating nodes via the communication protocol routing component using the specified communication protocol includes: receiving messages related to the multi-party computing task sent by the other participating nodes via the communication protocol routing component using the first communication protocol.

[0027] In some embodiments, the task information further includes communication protocol information corresponding to the other participating nodes, wherein the specified communication protocol includes a second communication protocol indicated by the communication protocol information; and the transmission of information related to the multi-party computing task between the first participating node and other participating nodes via the communication protocol routing component and using the specified communication protocol includes: sending messages related to the multi-party computing task to the other participating nodes via the communication protocol routing component and using the second communication protocol.

[0028] Fourthly, embodiments of this specification provide an information processing method based on secure multi-party computation, applied to a first computing node, the first computing node corresponding to a first participating node, and a scheduling system as described in the first aspect. The method includes: receiving a multi-party computation task sent by a computing node routing component in the scheduling system, the multi-party computation task being generated and sent to the computing node routing component by the first participating node based on acquired task information, the task information including the computation protocol used in this secure multi-party computation and first description information of first data participating in the computation, the first data belonging to the first participating node; receiving the first data sent by a data source routing component in the scheduling system, the first data being obtained by the data source routing component from a first data source adopted by the first participating node; and executing the multi-party computation task.

[0029] In some embodiments, the scheduling system further includes a secure channel routing component that supports multiple secure channels; and the execution of the multi-party computation task includes: during task execution, via the secure channel routing component, through a specified secure channel, performing intermediate data exchange between the first computing node and other computing nodes related to the multi-party computation task, wherein the specified secure channel belongs to the multiple secure channels.

[0030] In some embodiments, the secure channel routing component configures corresponding first secure channel information for the first computing node, the specified secure channel including the first secure channel indicated by the first secure channel information; and the intermediate data exchange between the first computing node and other computing nodes related to the multi-party computing task via the secure channel routing component and the specified secure channel includes: obtaining intermediate data required during task execution from the first secure channel via the secure channel routing component, wherein the intermediate data is sent by the other computing nodes to the first secure channel.

[0031] In some embodiments, the task information further includes second security channel information corresponding to the other computing nodes, wherein the specified security channel includes the second security channel indicated by the second security channel information; and the intermediate data exchange between the first computing node and other computing nodes related to the multi-party computing task via the specified security channel through the security channel routing component includes: sending intermediate data generated during task execution to the second security channel via the security channel routing component for the other computing nodes to obtain.

[0032] In some embodiments, obtaining intermediate data required during task execution from the first secure channel via the secure channel routing component includes: if the number of received multi-party computation tasks is 1, then obtaining all intermediate data from the first secure channel via the secure channel routing component.

[0033] In some embodiments, when the other computing nodes execute multiple multi-party computation tasks for this secure multi-party computation, obtaining the intermediate data required during task execution from the first secure channel via the secure channel routing component includes: if the number of received multi-party computation tasks is multiple, determining the source of the intermediate data required for any received multi-party computation task; if the source is the multiple multi-party computation tasks, obtaining all intermediate data from the first secure channel via the secure channel routing component; if the source is some of the multiple multi-party computation tasks, determining the task identifier of the some multi-party computation tasks, and obtaining the intermediate data corresponding to the task identifier from the first secure channel via the secure channel routing component.

[0034] In some embodiments, sending intermediate data generated during task execution to the second secure channel indicated by the second secure channel information via the secure channel routing component includes: if the number of received multi-party computation tasks is 1, then after the computation is completed, sending all the intermediate data generated to the second secure channel via the secure channel routing component.

[0035] In some embodiments, sending intermediate data generated during task execution to the second secure channel indicated by the second secure channel information via the secure channel routing component includes: if the number of received multi-party computation tasks is multiple, then for any received multi-party computation task, after computation is completed, sending the task identifier of the multi-party computation task and the intermediate data generated during the execution of the multi-party computation task to the second secure channel via the secure channel routing component.

[0036] In some embodiments, the method further includes: if the data source type of the first data source and the node type of the first computing node are different, then the intermediate data and / or result data generated during task execution are written into the first data source.

[0037] Fifthly, embodiments of this specification provide an information processing apparatus based on secure multi-party computation, applied to a first participating node, the first participating node corresponding to the scheduling system described in the first aspect. The apparatus includes: a generation unit configured to generate a multi-party computation task based on acquired task information, the task information including the computation protocol used in this secure multi-party computation and first description information of first data participating in the computation, the first data belonging to the first participating node; a first sending unit configured to send a first loading instruction for the first data to a data source routing component in the scheduling system, causing the data source routing component to respond to the first loading instruction and load the first data from the first data source to a first computing node of the first participating node according to first routing information corresponding to the first data source used by the first participating node; and a second sending unit configured to send a distribution instruction for the multi-party computation task to a computing node routing component in the scheduling system, causing the computing node routing component to respond to the distribution instruction and send the multi-party computation task to the first computing node according to second routing information corresponding to the first computing node, causing the first computing node to execute the multi-party computation task.

[0038] Sixthly, embodiments of this specification provide an information processing apparatus based on secure multi-party computation, applied to a first computing node, the first computing node corresponding to a first participating node, and a scheduling system as described in the first aspect. The apparatus includes: a first receiving unit configured to receive a multi-party computation task sent by a computing node routing component in the scheduling system, the multi-party computation task being generated by the first participating node based on acquired task information and sent to the computing node routing component, the task information including the computation protocol used in this secure multi-party computation and first description information of first data participating in the computation, the first data belonging to the first participating node; a second receiving unit configured to receive the first data sent by a data source routing component in the scheduling system, the first data being obtained by the data source routing component from a first data source used by the first participating node; and a task execution unit configured to execute the multi-party computation task.

[0039] In a seventh aspect, embodiments of this specification provide a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed in a computer, it causes the computer to perform the method described in any of the implementations of the third and fourth aspects.

[0040] Eighthly, embodiments of this specification provide a computing device including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, it implements the method described in any of the implementations of the third and fourth aspects.

[0041] Ninthly, embodiments of this specification provide a computer program, wherein when the computer program is executed in a computer, it causes the computer to perform the method described in any of the implementations of the third and fourth aspects.

[0042] The scheduling system, information processing method, and apparatus based on secure multi-party computation provided in the above embodiments of this specification, by setting multiple routing components in the scheduling system, such as a data source routing component supporting multiple data sources and a computing node routing component supporting multiple computing nodes, enable the participants to which the first participating node belongs in the scheduling system to configure routing in the data source routing component and the computing node routing component according to actual environmental requirements. This allows the data source routing component to connect to any data source of the participant (such as the first data source mentioned above), and the computing node routing component to connect to any computing resource of the participant (such as the first computing node mentioned above). Therefore, in the specific secure multi-party computation process, the first participating node and its first computing node can use the routing components in the scheduling system for information loading, transmission, etc. Thus, the solution provided in the above embodiments of this specification is compatible with any environmental requirements of the participants, enabling the participants to use any computing resources and data sources when participating in secure multi-party computation. Attached Figure Description

[0043] To more clearly illustrate the technical solutions of the various embodiments disclosed in this specification, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only a few embodiments disclosed in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0044] Figure 1 This is a schematic diagram of the scheduling system according to this specification;

[0045] Figure 2 This is an exemplary system architecture diagram to which some embodiments of this specification can be applied;

[0046] Figure 3 This is a schematic diagram of an embodiment of the information processing method based on secure multi-party computation according to this specification;

[0047] Figure 4 This is a schematic diagram of the interaction process between the first participating node and other participating nodes;

[0048] Figure 5 This is a schematic diagram of the data exchange process between the first computing node and other computing nodes;

[0049] Figure 6 This is a schematic diagram of an embodiment of the information processing method based on secure multi-party computation according to this specification;

[0050] Figure 7 This is a schematic diagram of an information processing device based on secure multi-party computation according to this specification;

[0051] Figure 8 This is a schematic diagram of an information processing device based on secure multi-party computation according to this specification. Detailed Implementation

[0052] The present specification will now be described in further detail with reference to the accompanying drawings and embodiments. It is to be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. The described embodiments are only a part of the embodiments described in this specification, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments in this specification without inventive effort are within the scope of protection of this application.

[0053] It should be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings. Unless otherwise specified, the embodiments and features described herein can be combined with each other. Furthermore, the terms "first," "second," and "third" in this specification are used only for informational purposes and do not constitute any limitation.

[0054] As mentioned earlier, existing secure multi-party computation schemes are usually based on a specific computing resource or can only perform local computations. They cannot use any computing system that the participants are free to use, nor can they support various common data sources.

[0055] Based on this, some embodiments of this specification provide a scheduling system. By applying this scheduling system to a secure multi-party computation scheme, the secure multi-party computation scheme can be made compatible with any environmental requirements of the participants, enabling the participants to use any computing resources and data sources when participating in secure multi-party computation.

[0056] See Figure 1 This is a structural diagram of a scheduling system. The scheduling system assists the first participating node in participating in secure multi-party computation. For example... Figure 1 As shown, the scheduling system may include a data source routing component and a compute node routing component.

[0057] The data source routing component supports multiple data sources and is configured with first routing information corresponding to the first data source adopted by the first participating node. It is used to respond to the first loading instruction of the first participating node for the first data related to the multi-party computing task. According to the first routing information, the first data is loaded from the first data source to the first computing node of the first participating node. The first data source belongs to the multiple data sources.

[0058] The computing node routing component supports multiple computing nodes and is configured with second routing information corresponding to the first participating node. It is used to respond to the instructions issued by the first participating node for multi-party computing tasks, and send the multi-party computing tasks to the first computing node according to the second routing information, so that the first computing node can execute the multi-party computing tasks. The first computing node belongs to the multiple computing nodes.

[0059] The aforementioned data sources may include, but are not limited to, several of the following: data sources based on Relational Database Service (RDS), data sources based on Open Data Processing Service (ODPS), and MySQL. The first data source stores the data that the first participating node can use for secure multi-party computation. For an explanation of the secure multi-party computation task, please refer to the relevant descriptions below.

[0060] The aforementioned computing nodes may include, but are not limited to, several of the following: computing nodes based on ODPS services, computing nodes based on Hadoop, and computing nodes based on the local memory of participating nodes.

[0061] In practice, before performing secure multi-party computation, the first participating party (e.g., an individual or organization) to which the first participating node belongs can configure routing in the data source routing component and the compute node routing component according to actual environmental requirements. For example, in the data source routing component, the first participating node can be configured with the first routing information corresponding to the first data source it uses. The first routing information may include, for example, the communication address of the first data source. Optionally, the first routing information may also include the data source identifier of the first data source, and / or the communication address of the first compute node, etc.

[0062] Additionally, the first participant can configure second routing information for its computing node within the computing node routing component. This second routing information may include the communication address of the first computing node. Optionally, the second routing information may also include the node identifier of the first computing node, etc.

[0063] It should be noted that some participants seeking secure multi-party computation possess their own distributed computing systems, while others are limited to local computation. Considering the varying technical capabilities of these participants, a computation node routing component can be configured within the scheduling system for each participant's nodes to access. This allows participants to fully utilize their computing resources. For example, participants with distributed computing systems can utilize them, while those limited to local computation can perform local computations. This improves computational efficiency and helps participants aiming for secure multi-party computation achieve their computational goals.

[0064] In some embodiments, the first loading instruction may include the storage path of the first data in the first data source, and the data source routing component may be specifically used to: obtain the first data from the first data source according to the storage path and the first routing information, and send the first data to the first computing node.

[0065] In some embodiments, the first loading instruction may include a data identifier for the first data, and the data source routing component may be specifically used to: obtain the first data from the first data source according to the data identifier and the first routing information, and send the first data to the first computing node.

[0066] Optionally, in addition to including the storage path or data identifier of the first data, the first load instruction may also include the communication address of the first computing node. For example, if the first routing information does not include the communication address of the first computing node, the first load instruction may include the communication address of the first computing node.

[0067] Typically, both the first data source and the first computing node are located on the first participant's side, and the data source routing component and the first computing node can communicate directly. Therefore, after obtaining the first data from the first data source, the data source routing component can directly send the first data to the first computing node.

[0068] Optionally, if there is a situation where the data source routing component and the first computing node cannot communicate directly, the data source routing component can call the first computing node routing component after obtaining the first data from the first data source, so that the component sends the first data to the first computing node.

[0069] In some embodiments, to enable participants to customize local configurations, the scheduling system may further include a configuration routing component. The configuration routing component supports multiple configuration nodes and configures a third routing information corresponding to the first configuration node used by the first participant node. In response to a second loading instruction from the first participant node for the first configuration information of the first data, the component loads the first configuration information from the first configuration node to a target location according to the third routing information. The first configuration node belongs to one of the multiple configuration nodes and stores configuration information of the data that the first participant node can participate in secure multi-party computation. The target location is located locally on the first participant node and is related to the multi-party computation task.

[0070] The aforementioned configuration nodes may include, but are not limited to, several of the following: configuration nodes based on the local services of participating nodes, configuration nodes based on HSF (High-Speed ​​Service Framework) services, and configuration nodes based on HTTP (Hypertext Transfer Protocol) services.

[0071] The aforementioned target location can be a location used to temporarily store the configuration information involved in each secure multi-party computation. This target location can be the hard disk area or memory area of ​​the first participating node, etc., without specific limitations.

[0072] The first configuration information corresponding to the first data may include the storage path of the first data in the first data source, the IP (Internet Protocol) address of the first data source, the port number, the username, the password, etc.

[0073] In practice, before performing secure multi-party computation, the first participating party can configure routing in the routing configuration component according to actual environmental requirements. For example, in the routing configuration component, the first participating party node can be configured with the third routing information of the first configuration node it adopts.

[0074] Specifically, when the first configuration node is a configuration node based on the local services of the participating node, the third routing information may include the path information of the first configuration node within the first participating node. When the first configuration node is a configuration node based on HSF services, the third routing information may include the HSF interface provided by the first configuration node. When the first configuration node is a configuration node based on HTTP services, the third routing information may include the HTTP interface provided by the first configuration node.

[0075] Based on the above description of the configuration routing component, in practical applications, the second loading instruction may include the data identifier of the first data. When the first configuration node is a configuration node based on the local service of the participating node, the configuration routing component can obtain the first configuration information from the first configuration node based on the data identifier and the path information in the third routing information. When the first configuration node is a configuration node based on the HSF service, the configuration routing component can call the HSF interface in the third routing information, so that the interface obtains the first configuration information from the first configuration node based on the data identifier and returns the first configuration information. When the first configuration node is a configuration node based on the HTTP service, the configuration routing component can call the HTTP interface in the third routing information, so that the interface obtains the first configuration information from the first configuration node based on the data identifier and returns the first configuration information.

[0076] In some embodiments, to enable participants to customize communication protocols, the scheduling system may further include a communication protocol routing component. The communication protocol routing component supports multiple communication protocols and is used to implement information transmission related to multi-party computation tasks between the first participant node and other participant nodes using a specified communication protocol, wherein the specified communication protocol belongs to one of the multiple communication protocols.

[0077] The aforementioned communication protocols may include, but are not limited to, HSF and HTTP protocols.

[0078] In practice, before performing secure multi-party computation, the first participating party can configure a first communication protocol for message reception in the communication protocol routing component, based on actual environmental requirements. Therefore, the aforementioned specified communication protocol may include, but is not limited to, the first communication protocol.

[0079] As one implementation, the communication protocol specified above includes a first communication protocol. The communication protocol routing component can be specifically used to: use the first communication protocol to receive messages related to the multi-party computing task sent by other participating nodes, and send the messages to the first participating node.

[0080] As another implementation, the communication protocol routing component can be specifically used to: receive communication protocol information corresponding to other participating nodes and messages related to the multi-party computation task from the first participating node, and send the messages to other participating nodes using the second communication protocol indicated by the communication protocol information. The second communication protocol belongs to the communication protocol specified above.

[0081] It should be noted that messages related to multi-party computation tasks may include, for example, the task identifier of the multi-party computation task generated by the participating node sending the message for the current secure multi-party computation, the number of multi-party computation tasks, the parameter names of the intermediate data produced by the multi-party computation task during task execution, and so on.

[0082] In some embodiments, to enable participants to customize secure channels for intermediate data exchange, the scheduling system may also include a secure channel routing component. The secure channel routing component supports multiple secure channels and is used to facilitate intermediate data exchange between a first computing node and other computing nodes related to multi-party computing tasks through a specified secure channel, where the specified secure channel belongs to one of the multiple secure channels.

[0083] The aforementioned secure channels may include, but are not limited to, several of the following: transmission channels utilizing intermediate nodes, data transmission channels based on Object Storage Service (OSS), and data transmission channels based on trusted encirclements.

[0084] In practice, before performing secure multi-party computation, the first participating party can configure its corresponding first secure channel information for the first computing node in the secure channel routing component, based on actual environmental requirements. Therefore, the specified secure channel may include, but is not limited to, the first secure channel indicated by the first secure channel information.

[0085] As one implementation, the aforementioned secure channel includes a first secure channel. The secure channel routing component can specifically be used to: obtain intermediate data required by the first computing node during task execution from the first secure channel, and send the intermediate data to the first computing node, wherein the intermediate data is sent to the first secure channel by other computing nodes.

[0086] As another implementation, the secure channel routing component can be specifically used to: receive second secure channel information corresponding to other computing nodes from the first computing node, as well as intermediate data generated by the first computing node during task execution, and send the intermediate data to the second secure channel indicated by the second secure channel information for other computing nodes to access. The second secure channel belongs to the aforementioned specified secure channel.

[0087] The above describes a scheduling system used to assist first-party nodes in participating in secure multi-party computation. It should be noted that the routing component in the scheduling system can be added or removed according to actual needs. Understandably, the scheduling system possesses characteristics such as versatility, ease of use, and easy scalability, and can effectively support secure multi-party computation.

[0088] Next, we will introduce the application of the scheduling system in the secure multi-party computation scheme.

[0089] See Figure 2 This is an exemplary system architecture diagram of an information processing method based on secure multi-party computation provided in some embodiments applicable to this specification.

[0090] like Figure 2 As shown, it illustrates a first participating node, a first data source used by the first participating node, a first computing node of the first participating node, and a scheduling system for assisting the first participating node in participating in secure multi-party computation. The scheduling system includes, but is not limited to, the data source routing component and computing node routing component as described above.

[0091] In practice, the first participating node can obtain task information, including the computation protocol used in this secure multi-party computation and the first description information of the first data involved in the computation. The first data belongs to the first participating node, which is one of the multiple participating nodes involved in this secure multi-party computation. Then, the first participating node can generate a multi-party computation task based on the obtained task information. Additionally, the first participating node can send a first load instruction for the first data to the data source routing component, causing the data source routing component to respond to the first load instruction and load the first data from the first data source to the first computing node according to the first routing information corresponding to the first data source. Furthermore, after generating the multi-party computation task, the first participating node can send a dispatch instruction for the multi-party computation task to the computing node routing component, causing the computing node routing component to respond to the dispatch instruction and send the multi-party computation task to the first computing node according to the second routing information corresponding to the first computing node, enabling the first computing node to execute the multi-party computation task.

[0092] The specific implementation steps of the above method are described below with reference to specific embodiments.

[0093] See Figure 3 This is a schematic diagram of an embodiment of an information processing method based on secure multi-party computation. The method includes the following steps:

[0094] Step 302: The first participating node generates a multi-party computation task based on the acquired task information;

[0095] Step 304: The first participating node sends a first loading instruction for the first data to the data source routing component in the scheduling system;

[0096] Step 306: In response to the first loading instruction, the data source routing component loads the first data from the first data source to the first computing node of the first participant node according to the first routing information corresponding to the first data source used by the first participant node.

[0097] Step 308: The first participating node sends a command to the computing node routing component in the scheduling system to issue a multi-party computing task.

[0098] Step 310: The computing node routing component responds to the issued instruction and sends the multi-party computing task to the first computing node according to the second routing information corresponding to the first computing node.

[0099] Step 312: The first computing node performs a multi-party computation task.

[0100] The steps above will be explained in further detail below.

[0101] In step 302, the task information may be obtained by the first participating node from the control node. The task information may include the computation protocol used in this secure multi-party computation, and the first description information of the first data participating in the computation. The first data belongs to the first participating node, which is one of the multiple participating nodes involved in this secure multi-party computation.

[0102] In practice, control nodes can be used to schedule secure multi-party computation services. Specifically, control nodes can coordinate the computation protocols and data used by multiple participating nodes for secure multi-party computation, thereby resolving the pre-negotiation issues related to secure multi-party computation. Furthermore, control nodes can also control the starting and stopping of secure multi-party computation services by multiple participating nodes.

[0103] Furthermore, the task information obtained by the first participating node may be generated by the control node in response to receiving a computation request. This computation request may include the computation protocol used in this secure multi-party computation, as well as descriptive information about multiple data items involved in the computation. It should be understood that these multiple data items correspond to the multiple participating nodes involved in this secure multi-party computation, and the first data item is at least one of these multiple data items.

[0104] It should be noted that the sender of the computation request can be any of the participating nodes among the multiple participating nodes, or the client corresponding to that participating node; no specific limitation is made here.

[0105] In this embodiment, the computation protocol in the task information may include a secure multi-party summation protocol, a secure multi-party product protocol, or a privacy-preserving intersection protocol, etc. The first description information of the first data may include metadata information and data identifiers of the first data. This metadata information may, for example, be used to describe some attributes of the first data, such as data source type, data table name, field names, etc.

[0106] The multi-party computation task generated by the first participating node may include a computation protocol, a data identifier for the first data, etc.

[0107] In practice, the first participating node can store the data partitioning strategy associated with the first data. This data partitioning strategy can be used by the first participating node to slice the first data and generate corresponding multi-party computation tasks for each data slice. Based on this, the first participating node can generate at least one multi-party computation task according to the data partitioning strategy and the task information.

[0108] In step 304, the first participating node may send a first load instruction for the first data to the data source routing component in the scheduling system. Then, the data source routing component may execute step 306, responding to the first load instruction and loading the first data from the first data source to the first computing node of the first participating node according to the first routing information corresponding to the first data source. Specifically, the data source routing component may obtain the first data from the first data source according to the first routing information and send the first data to the first computing node.

[0109] In one implementation, the first loading instruction may include a data identifier for the first data. Further, the data source routing component can retrieve the first data from the first data source based on the data identifier and the first routing information, and send the first data to the first computing node.

[0110] It should be noted that steps 302 and 304 can be executed in parallel or sequentially, without any specific limitation.

[0111] After executing step 302, the first participating node can then execute step 308, sending a command to the computing node routing component to distribute the multi-party computing task. This command may include, but is not limited to, the multi-party computing task. Next, the computing node routing component can execute step 310, responding to the command and sending the multi-party computing task to the first computing node according to the second routing information. Then, the first computing node can execute the multi-party computing task upon receiving the first data and the multi-party computing task.

[0112] In practice, during task execution, the first computing node can exchange intermediate data with other computing nodes related to multi-party computing tasks. For example, direct communication can be used for intermediate data exchange.

[0113] Additionally, the first computing node can be locally configured with a protocol computation toolkit corresponding to the computation protocol used in this secure multi-party computation. The first computing node can use this toolkit to perform protocol computation. It should be understood that this toolkit can include any tools involved in the computation protocol, such as encryption / decryption tools, random number generation tools, etc., without specific limitations.

[0114] Figure 3The corresponding embodiment provides an information processing method based on secure multi-party computation. By introducing a scheduling system to assist the first participating node in participating in secure multi-party computation, it can be compatible with any environmental requirements of the participants, enabling the participants to use any computing resources when participating in secure multi-party computation.

[0115] In some embodiments, the first description information includes the data source type of the first data source. Further, the metadata information in the first description information includes the data source type. Before performing step 304, the first participating node may determine whether the data source type and the node type of the first computing node are the same. Based on this, step 304 may further include: in response to determining that the data source type and the node type are not the same, sending a first loading instruction for the first data to the data source routing component.

[0116] It should be noted that if the data source type of the first data source is the same as the node type of the first compute node, it indicates that the first data source and the first compute node are the same, and the data loading step can be skipped. If the data source type of the first data source is different from the node type of the first compute node, it indicates that the first data source and the first compute node are different, and in this case, the data loading step needs to be performed to load the first data into the first compute node.

[0117] In some embodiments, the first description information includes a data identifier for the first data. Before executing step 304, the first participating node can obtain the storage path of the first data in the first data source based on the data identifier. Based on this, the first loading instruction can include the storage path, and step 306 can further include: obtaining the first data from the first data source according to the storage path and the first routing information, and sending the first data to the first computing node.

[0118] The first participating node can use various methods to obtain the storage path of the first data in the first data source.

[0119] For example, the data identifier and storage path of the first data can be pre-stored locally on the local machine of the first participating node. The first participating node can then retrieve the storage path from its local machine based on the data identifier.

[0120] For example, the scheduling system may also include a configuration routing component as described above. The first participating node may send a second load instruction, including a data identifier of the first data, to the configuration routing component. In response to the second load instruction, the configuration routing component loads the first configuration information of the first data from the first configuration node to the target location on the first participating node's local machine, based on third routing information. Afterward, the first participating node can obtain the storage path of the first data from the first configuration information at the target location.

[0121] In some embodiments, the scheduling system may further include a communication protocol routing component as described above. During task execution, the first participating node may use the communication protocol routing component to transmit information related to the multi-party computation task between the first participating node and other participating nodes via a specified communication protocol.

[0122] Furthermore, the communication protocol routing component configures a first communication protocol for message reception for the first participating node. The task information obtained by the first participating node also includes communication protocol information corresponding to other participating nodes. Both the first communication protocol and the second communication protocol indicated by the communication protocol information belong to the aforementioned specified communication protocols.

[0123] See Figure 4 This diagram illustrates the interaction process between the first participating node and other participating nodes. Typically, during task execution, the first participating node can receive messages related to the multi-party computation task sent by other participating nodes via a communication protocol routing component using a first communication protocol; and / or send messages related to the multi-party computation task to other participating nodes via a communication protocol routing component using a second communication protocol. For an explanation of these messages, please refer to the relevant descriptions above; they will not be repeated here.

[0124] By providing a communication protocol routing component, the participants to which the first participant node and other participant nodes belong can customize their own communication protocols, which can meet the different environmental needs of the participants.

[0125] In some embodiments, the scheduling system may further include a secure channel routing component as described above. In step 312, during task execution, the first computing node may exchange intermediate data related to the multi-party computing task with other computing nodes via the secure channel routing component and a designated secure channel.

[0126] Typically, the secure channel routing component configures corresponding first secure channel information for the first computing node. The task information received by the first participating node may also include second secure channel information corresponding to other computing nodes. In addition, the multi-party computing tasks generated by the first participating node may also include this second secure channel information. Both the first secure channel indicated by the first secure channel information and the second secure channel indicated by the second secure channel information belong to the aforementioned specified secure channels.

[0127] See Figure 5This is a schematic diagram illustrating the data exchange process between the first computing node and other computing nodes. Typically, during task execution, the first computing node can obtain intermediate data required during task execution from the first secure channel via the secure channel routing component, wherein this intermediate data is sent to the first secure channel by other computing nodes; and / or send intermediate data generated during task execution to the second secure channel via the secure channel routing component for other computing nodes to obtain.

[0128] By providing a secure channel routing component, the first participant node and other participants can customize their own secure channels to meet the different environmental needs of the participants.

[0129] In some embodiments, step 312 may specifically include: if the number of received multi-party computation tasks is 1, the first computing node may obtain all intermediate data from the first secure channel via the secure channel routing component; and / or after the computation is completed, send all the generated intermediate data to the second secure channel via the secure channel routing component.

[0130] In some embodiments, when other computing nodes execute multiple multi-party computation tasks for this secure multi-party computation, the above-mentioned acquisition of intermediate data required during task execution from the first secure channel via the secure channel routing component specifically includes: if the number of received multi-party computation tasks is multiple, then for any received multi-party computation task, determining the source of the intermediate data required by the multi-party task; if the source is the multiple multi-party computation tasks, then acquiring all intermediate data from the first secure channel via the secure channel routing component; if the source is some of the multiple multi-party computation tasks, then determining the task identifier of the partial multi-party computation tasks, and acquiring the intermediate data corresponding to the task identifier from the first secure channel via the secure channel routing component.

[0131] The source of intermediate data required for any of the aforementioned multi-party computation tasks, as well as the task identifiers of some of the aforementioned multi-party computation tasks, can be determined based on messages related to the multi-party computation tasks sent by the participating nodes corresponding to other computing nodes to the first participating node.

[0132] In some embodiments, the above-mentioned sending of intermediate data generated during task execution to the second secure channel indicated by the second secure channel information via the secure channel routing component specifically includes: if there are multiple multi-party computation tasks received, then for any received multi-party computation task, after the computation is completed, the task identifier of the multi-party computation task and the intermediate data generated during the execution of the multi-party computation task are sent to the second secure channel via the secure channel routing component.

[0133] In some embodiments, if the data source type of the first data source is different from the node type of the first computing node, the first computing node can write the intermediate data and / or result data generated during task execution into the first data source. For example, an output data table can be created in the first data source, and the intermediate data and / or result data generated during task execution can be written into that data table.

[0134] Further reference Figure 6 This is a schematic diagram of an embodiment of an information processing method based on secure multi-party computation. The method is applied to, for example... Figure 1 The corresponding embodiment describes a scheduling system for assisting a first participating node in secure multi-party computation. The method includes the following steps:

[0135] Step 604: Using the data source routing component, in response to the first loading instruction of the first participating node for the first data related to the multi-party computing task, the first data is loaded from the first data source to the first computing node of the first participating node according to the first routing information corresponding to the first data source adopted by the first participating node.

[0136] Step 606: Using the computing node routing component, in response to the instruction issued by the first participating node for the multi-party computing task, the multi-party computing task is sent to the first computing node according to the second routing information corresponding to the first computing node, so that the first computing node executes the multi-party computing task.

[0137] In some embodiments, the scheduling system may further include the configuration node routing component as described above. Based on this, the above method may further include: step 602, using the configuration node routing component, in response to a second loading instruction from the first participating node for first configuration information of first data related to the multi-party computation task, loading the first configuration information from the first configuration node to the target location locally of the first participating node according to the third routing information corresponding to the first configuration node adopted by the first participating node.

[0138] In some embodiments, the scheduling system may further include a communication protocol routing component as described above. Based on this, the method may further include: step 608, utilizing the communication protocol routing component and employing a specified communication protocol to achieve information transmission related to the multi-party computation task between the first participating node and other participating nodes.

[0139] In some embodiments, the scheduling system may further include the secure channel routing component as described above. Based on this, the method may further include: step 610, using the secure channel routing component to implement intermediate data exchange between the first computing node and other computing nodes related to multi-party computing tasks through a specified secure channel.

[0140] For a detailed explanation of each of the above steps, please refer to the relevant instructions above, which will not be repeated here.

[0141] Further reference Figure 7 This specification provides an embodiment of an information processing apparatus based on secure multi-party computation, which can be applied to, for example... Figure 2 The first participant node is shown. The first participant node corresponds to... Figure 1 The scheduling system described in the corresponding embodiment.

[0142] like Figure 7 As shown, the information processing device 700 based on secure multi-party computation in this embodiment includes: a generation unit 701, a first sending unit 702, and a second sending unit 703. The generation unit 701 is configured to generate a multi-party computation task based on acquired task information. The task information includes the computation protocol used in this secure multi-party computation and first description information of first data participating in the computation, wherein the first data belongs to a first participating node. The first sending unit 702 is configured to send a first loading instruction for the first data to a data source routing component in the scheduling system, causing the data source routing component to respond to the first loading instruction and load the first data from the first data source to the first computing node of the first participating node according to the first routing information corresponding to the first data source used by the first participating node. The second sending unit 703 is configured to send a distributing instruction for the multi-party computation task to a computing node routing component in the scheduling system, causing the computing node routing component to respond to the distributing instruction and send the multi-party computation task to the first computing node according to the second routing information corresponding to the first computing node, so that the first computing node executes the multi-party computation task.

[0143] In some embodiments, the first description information includes the data source type of the first data source; and the above-described apparatus 700 may further include: a determining unit (not shown in the figure), configured to determine whether the data source type and the node type of the first computing node are the same before the first sending unit 702 sends the first loading instruction to the data source routing component; the first sending unit 702 may be further configured to: send the first loading instruction to the data source routing component in response to the determining unit determining that the data source type and the node type are not the same.

[0144] In some embodiments, the first description information includes a data identifier of the first data; and the aforementioned apparatus 700 may further include: an acquisition unit (not shown in the figure), configured to acquire, based on the data identifier, the storage path of the first data in the first data source before the first sending unit 702 sends a first loading instruction to the data source routing component. Based on this, the first loading instruction includes the storage path.

[0145] In some embodiments, the scheduling system further includes a configuration routing component that supports multiple configuration nodes and configures third routing information corresponding to the first configuration node adopted by the first participating node. The first configuration node belongs to the multiple configuration nodes and stores configuration information of the data that the first participating node can participate in secure multi-party computation. The acquisition unit can be further configured to: send a second loading instruction including a data identifier to the configuration routing component, causing the configuration routing component to respond to the second loading instruction and, according to the third routing information, load the first configuration information of the first data from the first configuration node to the target location of the first participating node; and obtain the storage path from the first configuration information in the target location.

[0146] In some embodiments, the scheduling system further includes a communication protocol routing component that supports multiple communication protocols; and the above-mentioned apparatus 700 may further include: a communication unit (not shown in the figure) configured to, during task execution, transmit information related to the multi-party computing task between the first participating node and other participating nodes via the communication protocol routing component using a specified communication protocol, wherein the specified communication protocol belongs to the multiple communication protocols.

[0147] In some embodiments, the communication protocol routing component configures a first communication protocol for message reception for the first participating node, the specified communication protocol including the first communication protocol; and the communication unit may be further configured to: receive messages related to multi-party computing tasks sent by other participating nodes via the communication protocol routing component and using the first communication protocol.

[0148] In some embodiments, the task information may further include communication protocol information corresponding to other participating nodes, wherein the specified communication protocol includes a second communication protocol indicated by the communication protocol information; and the communication unit may be further configured to send messages related to the multi-party computing task to other participating nodes via a communication protocol routing component and using the second communication protocol.

[0149] Further reference Figure 8 This specification provides an embodiment of an information processing apparatus based on secure multi-party computation, which can be applied to, for example... Figure 2 The first computing node is shown. The first computing node corresponds to the first participating node, and as shown below. Figure 1 The corresponding implementation describes the scheduling system.

[0150] like Figure 8As shown, the information processing device 800 based on secure multi-party computation in this embodiment includes: a first receiving unit 801, a second receiving unit 802, and a task execution unit 803. The first receiving unit 801 is configured to receive a multi-party computation task sent by a computing node routing component in a scheduling system. The multi-party computation task is generated by a first participating node based on acquired task information and sent to the computing node routing component. The task information includes the computation protocol used in this secure multi-party computation and first description information of first data participating in the computation, the first data belonging to the first participating node. The second receiving unit 802 is configured to receive first data sent by a data source routing component in the scheduling system. The first data is obtained by the data source routing component from a first data source used by the first participating node. The task execution unit 803 is configured to execute the multi-party computation task.

[0151] In some embodiments, the scheduling system further includes a secure channel routing component that supports multiple secure channels; and the task execution unit 803 may be further configured to: during task execution, via the secure channel routing component, exchange intermediate data related to multi-party computing tasks between the first computing node and other computing nodes through a specified secure channel, wherein the specified secure channel belongs to the multiple secure channels.

[0152] In some embodiments, the secure channel routing component is configured with corresponding first secure channel information for the first computing node, the specified secure channel including the first secure channel indicated by the first secure channel information; and the task execution unit 803 may be further configured to: obtain intermediate data required during task execution from the first secure channel via the secure channel routing component, wherein the intermediate data is sent to the first secure channel by other computing nodes.

[0153] In some embodiments, the task information may further include second security channel information corresponding to other computing nodes, wherein the specified security channel includes the second security channel indicated by the second security channel information; and the task execution unit 803 may be further configured to send intermediate data generated during task execution to the second security channel via a security channel routing component for other computing nodes to obtain.

[0154] In some embodiments, the task execution unit 803 may be further configured to: if the number of received multi-party computation tasks is 1, then obtain all intermediate data from the first secure channel via the secure channel routing component, and / or after the computation is completed, send all the generated intermediate data to the second secure channel via the secure channel routing component.

[0155] In some embodiments, when the other computing nodes execute multiple multi-party computation tasks for this secure multi-party computation, the task execution unit 803 may be further configured to: if the number of received multi-party computation tasks is multiple, determine the source of the intermediate data required by any received multi-party computation task; if the source is the multiple multi-party computation tasks, obtain all intermediate data from the first secure channel via the secure channel routing component; if the source is some of the multiple multi-party computation tasks, determine the task identifier of the partial multi-party computation tasks, and obtain the intermediate data corresponding to the task identifier from the first secure channel via the secure channel routing component.

[0156] In some embodiments, the task execution unit 803 may be further configured to: if the number of received multi-party computation tasks is multiple, then for any received multi-party computation task, after the computation is completed, send the task identifier of the multi-party computation task and the intermediate data generated during the execution of the multi-party computation task to the second secure channel via the secure channel routing component.

[0157] In some embodiments, the above-described apparatus 800 may further include: a data write-back unit (not shown in the figure), configured to write intermediate data and / or result data generated during task execution to the first data source if the data source type of the first data source and the node type of the first computing node are different.

[0158] exist Figure 7 and Figure 8 In the corresponding device embodiments, the specific processing of each unit and the resulting technical effects can be found in the relevant descriptions above, and will not be repeated here.

[0159] This specification also provides a computer-readable storage medium storing a computer program thereon, wherein when the computer program is executed in a computer, it causes the computer to perform the information processing method based on secure multi-party computation as shown in the above method embodiments.

[0160] This specification also provides a computing device, including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, it implements the information processing method based on secure multi-party computation shown in the above method embodiments.

[0161] This specification also provides a computer program in its embodiments, wherein when the computer program is executed in a computer, it causes the computer to perform the information processing methods based on secure multi-party computation shown in the above method embodiments.

[0162] Those skilled in the art will recognize that the functions described in the various embodiments disclosed in this specification in one or more of the examples above can be implemented using hardware, software, firmware, or any combination thereof. When implemented in software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium.

[0163] In some cases, the actions or steps described in the claims can be performed in a different order than that shown in the embodiments and still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0164] The specific embodiments described above further illustrate the purpose, technical solutions, and beneficial effects of the multiple embodiments disclosed in this specification. It should be understood that the above descriptions are merely specific implementations of the multiple embodiments disclosed in this specification and are not intended to limit the protection scope of the multiple embodiments disclosed in this specification. Any modifications, equivalent substitutions, improvements, etc., made based on the technical solutions of the multiple embodiments disclosed in this specification should be included within the protection scope of the multiple embodiments disclosed in this specification.

Claims

1. A scheduling system for assisting a first participating node in participating in secure multi-party computation, the scheduling system comprising: The data source routing component supports multiple data sources and is configured with first routing information corresponding to the first data source adopted by the first participating node. It is used to respond to the first loading instruction of the first participating node for the first data related to the multi-party computing task, and load the first data from the first data source to the first computing node of the first participating node according to the first routing information. The first data source belongs to the multiple data sources. A computing node routing component supports multiple computing nodes and is configured with second routing information corresponding to the first participating node. It is used to respond to the instruction issued by the first participating node to the multi-party computing task, and send the multi-party computing task to the first computing node according to the second routing information, so that the first computing node executes the multi-party computing task. The first computing node belongs to the multiple computing nodes. The scheduling system further includes: A routing component is configured to support multiple configuration nodes, and a third routing information corresponding to the first configuration node adopted by the first participating node is configured for it. It is used to respond to the second loading instruction of the first participating node for the first configuration information of the first data, and load the first configuration information from the first configuration node to the target location according to the third routing information. The first configuration node belongs to the multiple configuration nodes and stores the configuration information of the data that the first participating node can participate in secure multi-party computation. The target location is located locally on the first participating node and is related to the multi-party computation task. The first routing information further includes the data source identifier of the first data source and / or the communication address of the first computing node, and the target location is the location used to temporarily store the configuration information involved in the current computation each time a secure multi-party computation is performed.

2. The scheduling system according to claim 1, wherein, The scheduling system also includes: The communication protocol routing component supports multiple communication protocols and is used to implement information transmission related to the multi-party computing task between the first participating node and other participating nodes using a specified communication protocol, wherein the specified communication protocol belongs to the multiple communication protocols.

3. The scheduling system according to claim 1 or 2, wherein, The scheduling system also includes: The secure channel routing component supports multiple secure channels and is used to exchange intermediate data related to the multi-party computing task between the first computing node and other computing nodes through a specified secure channel, wherein the specified secure channel belongs to the multiple secure channels.

4. The scheduling system according to claim 1, wherein, The various data sources include multiples of the following: data sources based on Relational Database Service (RDS), data sources based on Open Data Processing Service (ODPS), and MySQL; The various computing nodes include several of the following: computing nodes based on ODPS services, computing nodes based on Hadoop, and computing nodes based on the local memory of participating nodes.

5. The scheduling system according to claim 1, wherein, The first loading instruction includes the storage path of the first data in the first data source; and The data source routing component is specifically used for: Based on the storage path and the first routing information, obtain the first data from the first data source; The first data is sent to the first computing node.

6. The scheduling system according to claim 1, wherein, The various configuration nodes include several of the following: configuration nodes based on the local services of the participating node, configuration nodes based on HSF services, and configuration nodes based on HTTP services.

7. The scheduling system according to claim 6, wherein, When the first configuration node is a configuration node based on the local service of the participating node, the third routing information includes the path information of the first configuration node in the first participating node; When the first configuration node is a configuration node based on HSF service, the third routing information includes the HSF interface provided by the first configuration node; When the first configuration node is an HTTP-based configuration node, the third routing information includes the HTTP interface provided by the first configuration node.

8. The scheduling system according to claim 2, wherein, The various communication protocols include HSF and HTTP protocols.

9. The scheduling system according to claim 2, wherein, The communication protocol routing component is configured with a first communication protocol for message reception for the first participating node, and the specified communication protocol includes the first communication protocol; and The communication protocol routing component is specifically used for: Using the first communication protocol, the system receives messages related to the multi-party computing task sent by the other participating nodes and sends the messages to the first participating node.

10. The scheduling system according to claim 2 or 9, wherein, The communication protocol routing component is specifically used for: The first participating node receives communication protocol information corresponding to the other participating nodes, as well as messages related to the multi-party computing task, and sends the messages to the other participating nodes using the second communication protocol indicated by the communication protocol information.

11. The scheduling system according to claim 3, wherein, The various secure channels include several of the following: a transmission channel utilizing intermediate nodes, a data transmission channel based on the object storage service OSS, and a data transmission channel based on a trusted encirclement.

12. The scheduling system according to claim 3, wherein, The secure channel routing component is configured with corresponding first secure channel information for the first computing node, and the specified secure channel includes the first secure channel indicated by the first secure channel information. as well as The secure channel routing component is specifically used for: The intermediate data required by the first computing node during task execution is obtained from the first secure channel and sent to the first computing node, wherein the intermediate data is sent to the first secure channel by the other computing nodes.

13. The scheduling system according to claim 3 or 12, wherein, The secure channel routing component is specifically used for: The first computing node receives the second security channel information corresponding to the other computing nodes, as well as the intermediate data generated by the first computing node during task execution, and sends the intermediate data to the second security channel indicated by the second security channel information for the other computing nodes to obtain.

14. An information processing method based on secure multi-party computation, applied to the scheduling system as described in claim 1, wherein the scheduling system is used to assist a first participating node in participating in secure multi-party computation, the method comprising: Using a data source routing component, in response to the first loading instruction of the first participating node for the first data related to the multi-party computing task, the first data is loaded from the first data source to the first computing node of the first participating node according to the first routing information corresponding to the first data source adopted by the first participating node. Using a computing node routing component, in response to the instruction issued by the first participating node to the multi-party computing task, the multi-party computing task is sent to the first computing node according to the second routing information corresponding to the first computing node, so that the first computing node executes the multi-party computing task. Using a configuration routing component, in response to a second loading instruction from the first participating node for the first configuration information of the first data, the first configuration information is loaded from the first configuration node to the target location according to the third routing information. The first configuration node belongs to the multiple configuration nodes and stores configuration information of the data that the first participating node can participate in secure multi-party computation. The target location is located locally on the first participating node and is related to the multi-party computation task. The first routing information also includes the data source identifier of the first data source and / or the communication address of the first computing node, and the target location is the location used to temporarily store the configuration information involved in the current computation each time a secure multi-party computation is performed.

15. An information processing method based on secure multi-party computation, applied to a first participating node, the first participating node corresponding to the scheduling system as described in claim 1, the method comprising: Based on the acquired task information, a multi-party computation task is generated. The task information includes the computation protocol used in this secure multi-party computation and the first description information of the first data participating in the computation, wherein the first data belongs to the first participating party node. A first loading instruction for the first data is sent to the data source routing component in the scheduling system, so that the data source routing component responds to the first loading instruction and loads the first data from the first data source to the first computing node of the first participant node according to the first routing information corresponding to the first data source adopted by the first participant node. Send a command to the computing node routing component in the scheduling system to issue the multi-party computing task, so that the computing node routing component responds to the command and sends the multi-party computing task to the first computing node according to the second routing information corresponding to the first computing node, so that the first computing node executes the multi-party computing task. The scheduling system further includes a configuration routing component, which supports multiple configuration nodes and configures a third routing information corresponding to the first configuration node adopted by the first participating node. The first configuration node belongs to the multiple configuration nodes and stores configuration information of the data that the first participating node can participate in secure multi-party computation. The first routing information further includes the data source identifier of the first data source and / or the communication address of the first computing node, and the target location is the location used to temporarily store the configuration information involved in the current computation each time a secure multi-party computation is performed.

16. The method according to claim 15, wherein, The first description information includes the data source type of the first data source; as well as Before sending the first load instruction for the first data to the data source routing component in the scheduling system, the method further includes: Determine whether the data source type and the node type of the first computing node are the same; Sending a first load instruction for the first data to the data source routing component in the scheduling system includes: In response to determining that the data source type and the node type are different, a first loading instruction for the first data is sent to the data source routing component in the scheduling system.

17. The method according to claim 15 or 16, wherein, The first description information includes the data identifier of the first data; as well as Before sending the first load instruction for the first data to the data source routing component in the scheduling system, the method further includes: Based on the data identifier, obtain the storage path of the first data in the first data source; as well as The first load instruction includes the storage path.

18. The method according to claim 17, wherein obtaining the storage path of the first data in the first data source based on the data identifier comprises: Send a second loading instruction including the data identifier to the configuration routing component, so that the configuration routing component responds to the second loading instruction and loads the first configuration information of the first data from the first configuration node to the target location of the first participant node according to the third routing information; The storage path is obtained from the first configuration information in the target location.

19. The method according to claim 15, wherein, The scheduling system also includes a communication protocol routing component, which supports multiple communication protocols; as well as The method further includes: During task execution, information related to the multi-party computing task is transmitted between the first participating node and other participating nodes via the communication protocol routing component using a specified communication protocol. The specified communication protocol belongs to the multiple communication protocols.

20. The method according to claim 19, wherein, The communication protocol routing component is configured with a first communication protocol for message reception for the first participating node, and the specified communication protocol includes the first communication protocol. as well as The transmission of information related to the multi-party computing task between the first participating node and other participating nodes via the communication protocol routing component, using a specified communication protocol, includes: The system receives messages related to the multi-party computing task sent by the other participating nodes via the communication protocol routing component and using the first communication protocol.

21. The method according to claim 19 or 20, wherein, The task information also includes communication protocol information corresponding to the other participating nodes, and the specified communication protocol includes the second communication protocol indicated by the communication protocol information; as well as The transmission of information related to the multi-party computing task between the first participating node and other participating nodes via the communication protocol routing component, using a specified communication protocol, includes: The communication protocol routing component, using the second communication protocol, sends messages related to the multi-party computing task to the other participating nodes.

22. An information processing method based on secure multi-party computation, applied to a first computing node, the first computing node corresponding to a first participating node, and a scheduling system as described in claim 1, the method comprising: The system receives a multi-party computation task sent by the computing node routing component in the scheduling system. The multi-party computation task is generated by the first participating node based on the acquired task information and sent to the computing node routing component. The task information includes the computation protocol used in this secure multi-party computation and the first description information of the first data participating in the computation. The first data belongs to the first participating node. The system receives the first data sent by the data source routing component in the scheduling system. The first data is obtained by the data source routing component from the first data source used by the first participating node according to the first routing information. Perform the multi-party computation task; The scheduling system further includes: A routing component is configured to support multiple configuration nodes, and a third routing information corresponding to the first configuration node adopted by the first participating node is configured for it. It is used to respond to the second loading instruction of the first participating node for the first configuration information of the first data, and load the first configuration information from the first configuration node to the target location according to the third routing information. The first configuration node belongs to the multiple configuration nodes and stores the configuration information of the data that the first participating node can participate in secure multi-party computation. The target location is located locally on the first participating node and is related to the multi-party computation task. The first routing information further includes the data source identifier of the first data source and / or the communication address of the first computing node, and the target location is the location used to temporarily store the configuration information involved in the current computation each time a secure multi-party computation is performed.

23. The method according to claim 22, wherein, The scheduling system also includes a secure channel routing component, which supports multiple secure channels; as well as The execution of the multi-party computation task includes: During task execution, intermediate data related to the multi-party computing task is exchanged between the first computing node and other computing nodes through the designated secure channel via the secure channel routing component. The designated secure channel belongs to the multiple secure channels.

24. The method according to claim 23, wherein, The secure channel routing component is configured with corresponding first secure channel information for the first computing node, and the specified secure channel includes the first secure channel indicated by the first secure channel information. as well as The intermediate data exchange related to the multi-party computing task between the first computing node and other computing nodes via the secure channel routing component and a designated secure channel includes: The intermediate data required during task execution is obtained from the first secure channel via the secure channel routing component, wherein the intermediate data is sent to the first secure channel by the other computing nodes.

25. The method according to claim 23 or 24, wherein, The task information also includes second security channel information corresponding to the other computing nodes, and the specified security channel includes the second security channel indicated by the second security channel information. as well as The intermediate data exchange related to the multi-party computing task between the first computing node and other computing nodes via the secure channel routing component and a designated secure channel includes: Intermediate data generated during task execution is sent to the second secure channel via the secure channel routing component for other computing nodes to access.

26. The method according to claim 24, wherein, The step of obtaining intermediate data required during task execution from the first secure channel via the secure channel routing component includes: If the number of received multi-party computation tasks is 1, then all intermediate data is obtained from the first secure channel via the secure channel routing component.

27. The method according to claim 24, wherein, When the other computing nodes execute multiple multi-party computation tasks for this secure multi-party computation, the step of obtaining intermediate data required during task execution from the first secure channel via the secure channel routing component includes: If there are multiple multi-party computation tasks received, then for any received multi-party computation task, determine the source of the intermediate data required by that multi-party task. If the source is one of the multiple multi-party computation tasks, then all intermediate data is obtained from the first secure channel via the secure channel routing component; If the source is a partial multi-party computation task among the plurality of multi-party computation tasks, then the task identifier of the partial multi-party computation task is determined, and intermediate data corresponding to the task identifier is obtained from the first secure channel via the secure channel routing component.

28. The method according to claim 25, wherein, The step of sending intermediate data generated during task execution to the second secure channel indicated by the second secure channel information via the secure channel routing component includes: If the number of received multi-party computation tasks is 1, then after the computation is completed, all the intermediate data produced will be sent to the second secure channel via the secure channel routing component.

29. The method according to claim 25, wherein, The step of sending intermediate data generated during task execution to the second secure channel indicated by the second secure channel information via the secure channel routing component includes: If there are multiple multi-party computation tasks received, then for any received multi-party computation task, after the computation is completed, the task identifier of the multi-party computation task and the intermediate data generated during the execution of the multi-party computation task are sent to the second secure channel via the secure channel routing component.

30. The method according to claim 22, wherein, The method further includes: If the data source type of the first data source is different from the node type of the first computing node, then the intermediate data and / or result data generated during the task execution process will be written into the first data source.

31. An information processing device based on secure multi-party computation, applied to a first participating node, the first participating node corresponding to the scheduling system as described in claim 1, the device comprising: The generation unit is configured to generate a multi-party computation task based on the acquired task information. The task information includes the computation protocol used in this secure multi-party computation and the first description information of the first data participating in the computation, wherein the first data belongs to the first participating party node. The first sending unit is configured to send a first loading instruction for the first data to the data source routing component in the scheduling system, so that the data source routing component responds to the first loading instruction and loads the first data from the first data source to the first computing node of the first participant node according to the first routing information corresponding to the first data source adopted by the first participant node. The second sending unit is configured to send a distribution instruction for the multi-party computing task to the computing node routing component in the scheduling system, so that the computing node routing component responds to the distribution instruction and sends the multi-party computing task to the first computing node according to the second routing information corresponding to the first computing node, so that the first computing node executes the multi-party computing task. The scheduling system further includes a configuration routing component, which supports multiple configuration nodes and configures third routing information corresponding to the first configuration node adopted by the first participating node. The first configuration node belongs to the multiple configuration nodes and stores configuration information of the data that the first participating node can participate in secure multi-party computation. The first routing information further includes the data source identifier of the first data source and / or the communication address of the first computing node, and the target location is the location used to temporarily store the configuration information involved in the current computation each time a secure multi-party computation is performed.

32. An information processing apparatus based on secure multi-party computation, applied to a first computing node, the first computing node corresponding to a first participating node, and a scheduling system as described in claim 1, the apparatus comprising: The first receiving unit is configured to receive a multi-party computation task sent by the computing node routing component in the scheduling system. The multi-party computation task is generated by the first participating node based on the acquired task information and sent to the computing node routing component. The task information includes the computation protocol used in this secure multi-party computation and the first description information of the first data participating in the computation, wherein the first data belongs to the first participating node. The second receiving unit is configured to receive the first data sent by the data source routing component in the scheduling system, wherein the first data is obtained by the data source routing component from the first data source used by the first participating node according to the first routing information; The task execution unit is configured to execute the multi-party computation task; The scheduling system further includes: A routing component is configured to support multiple configuration nodes, and a third routing information corresponding to the first configuration node adopted by the first participating node is configured for it. It is used to respond to the second loading instruction of the first participating node for the first configuration information of the first data, and load the first configuration information from the first configuration node to the target location according to the third routing information. The first configuration node belongs to the multiple configuration nodes and stores the configuration information of the data that the first participating node can participate in secure multi-party computation. The target location is located locally on the first participating node and is related to the multi-party computation task. The first routing information further includes the data source identifier of the first data source and / or the communication address of the first computing node, and the target location is the location used to temporarily store the configuration information involved in the current computation each time a secure multi-party computation is performed.

33. A computer-readable storage medium having a computer program stored thereon, wherein, When the computer program is executed in the computer, it causes the computer to perform the method of any one of claims 14-30.

34. A computing device comprising a memory and a processor, wherein, The memory stores executable code, and when the processor executes the executable code, it implements the method of any one of claims 14-30.

35. A computer program, wherein, When the computer program is executed in the computer, it causes the computer to perform the method of any one of claims 14-30.