Acceleration equipment, computing systems and acceleration methods

By using an acceleration device in the homomorphic encryption algorithm to calculate the bucketing results, the problem of large computational load in data joint processing is solved, achieving higher processing efficiency and performance.

CN115801220BActive Publication Date: 2026-05-26ALIBABA CLOUD COMPUTING CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ALIBABA CLOUD COMPUTING CO LTD
Filing Date
2022-10-11
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

In homomorphic encryption algorithms, the data joint processing requires bucketing and computation of ciphertext data from multiple objects for each feature, resulting in a large amount of computation and affecting processing efficiency.

Method used

An acceleration device is adopted, which includes a storage component and multiple acceleration components. The device is connected to the host processing component via a bus. The storage component is used to store the binning results. The control unit and computing unit of the acceleration component perform calculations, reducing the computational load of the host processing component and realizing parallel computing.

Benefits of technology

This improved processing efficiency, reduced the computational load on the host processing components, decreased I/O overhead, and ensured the acceleration performance of the acceleration device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115801220B_ABST
    Figure CN115801220B_ABST
Patent Text Reader

Abstract

This application provides an acceleration device, computing system, and acceleration method. The acceleration device includes a first storage component and at least one first acceleration component; the first acceleration component includes a first control unit and multiple first processing units; the first storage component is connected to a first host processing component via a bus; the first storage component stores multiple bucketing results; the multiple bucketing results are obtained by bucketing multiple ciphertext data corresponding to multiple objects according to different characteristics; the first control unit obtains at least one bucketing result from the first storage component and assigns at least one bucketing result to at least one first processing unit; the first processing unit performs calculations on the multiple ciphertext data in the bucketing results to obtain ciphertext processing results; the first control unit is used to store the ciphertext processing result corresponding to any bucketing result in the first storage component. The technical solution provided by this application improves processing efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to an acceleration device, computing system and acceleration method. Background Technology

[0002] With the development of science and technology, the value of data is receiving increasing attention. Different data providers often have a need for data fusion, but due to privacy concerns, data cannot be shared between them, creating data silos. To address this problem, privacy-preserving computation based on homomorphic encryption has emerged. It aims to break down data silos and utilize multi-party data for computation, modeling, and other tasks without compromising data privacy.

[0003] Homomorphic encryption is a type of encryption algorithm with special natural properties. Processing homomorphically encrypted data to obtain an output data, and then decrypting this output data, yields the same output as processing the unencrypted original data in the same way. In other words, computation before decryption is equivalent to decryption before computation. This characteristic is of great significance for protecting data security.

[0004] In a practical application, when multiple data providers possess the same object but have different characteristics, the following data joint processing requirement arises: The data initiator calculates the target data based on the characteristic values ​​of each object, performs homomorphic encryption to obtain ciphertext data, and then provides the ciphertext data corresponding to each of the multiple objects to the data receiver. The data receiver, for each characteristic it possesses, buckets the ciphertext data corresponding to the multiple objects according to the different characteristic values; it then performs calculations on the ciphertext data in each bucket to obtain the ciphertext processing result, and then returns the ciphertext processing results of each bucket corresponding to each characteristic to the data initiator. The data initiator can then decrypt to obtain the plaintext processing results of each bucket. Based on the plaintext processing results of each bucket, subsequent processing operations can be performed, thereby achieving the goal of the data initiator using the characteristics of the data receiver for data processing, while protecting the data security of both parties.

[0005] As described above, because it is necessary to bucket the ciphertext data corresponding to multiple objects for each feature and perform calculations on the ciphertext data, the amount of computation is very large, which affects the processing efficiency. Summary of the Invention

[0006] This application provides an acceleration device, a computing system, and an acceleration method to solve technical problems affecting processing efficiency in the prior art.

[0007] In a first aspect, this application provides an acceleration device, including a first storage component and at least one first acceleration component; the first acceleration component includes a first control unit and a plurality of first computing units; the first storage component is connected to a first host processing component via a bus.

[0008] The first storage component is used to store multiple bucketing results; the multiple bucketing results are obtained by bucketing multiple ciphertext data corresponding to multiple objects according to different features;

[0009] The first control unit is configured to obtain at least one bucketing result from the first storage component; and to assign the at least one bucketing result to at least one first processing unit;

[0010] The first computing unit is used to perform calculations on multiple ciphertext data in any bucketing result assigned to it, according to the target calculation and processing mode, to obtain the ciphertext processing result.

[0011] The first control unit is used to store the encrypted processing result corresponding to any bucketing result into the first storage component;

[0012] The first storage component is used to provide the encrypted processing results corresponding to the multiple bucketing results to the first host processing component.

[0013] Secondly, this application provides an acceleration device, including a storage component and at least one acceleration component, wherein the acceleration component includes a control unit and multiple computing units; the storage component is connected to a host processing component via a bus.

[0014] The storage component is used to store multiple sets of data to be processed, each set of data to be processed including at least one set of operation data;

[0015] The control unit is configured to acquire at least one set of operation data from the first storage component and assign it to at least one computing unit.

[0016] The computing unit is used to perform calculation processing on at least one operation data in a set of data to be processed assigned to it, according to a target calculation processing mode, to obtain a calculation processing result.

[0017] The control unit is used to store the calculation results corresponding to any set of data to be processed into the storage component; the calculation results are used to provide to the host processing component.

[0018] Thirdly, this application provides a computing system, including a first computing device and a second computing device; the first computing device includes a first host processing component and a first acceleration device as described in the first aspect above.

[0019] The second computing device includes a second host processing unit and a second acceleration device; the second acceleration device includes a second storage unit and at least one third acceleration unit; the second storage unit is connected to the second host processing unit via a bus;

[0020] The second storage component is used to store multiple data to be processed sent by the second host processing component; the data to be processed is target data to be encrypted or ciphertext processing result to be decrypted;

[0021] The third acceleration component is used to obtain at least one piece of data to be processed from the second storage component; for any piece of data to be processed, the data to be processed is encrypted or decrypted to obtain a calculation result, and the calculation result is stored in the second storage component;

[0022] The second host processing component is used to obtain the calculation result corresponding to any data to be processed from the second storage component.

[0023] Fourthly, embodiments of this application provide a computing device, including a host processing component, a host storage component, and an acceleration device as described in the first aspect above or as described in the second aspect above.

[0024] Fifthly, embodiments of this application provide an acceleration method applied to an acceleration device, the acceleration device including a first storage component and at least one first acceleration component; the first acceleration component includes a first control unit and a plurality of first computing units; the first storage component is connected to a first host processing component via a bus; the method includes:

[0025] At least one bucketing result is obtained from multiple bucketing results; the multiple bucketing results are obtained by bucketing multiple encrypted data provided by the first host processing component.

[0026] The at least one bucketing result is assigned to at least one first processing unit; the first processing unit is used to perform calculation processing on multiple ciphertext data in the bucketing result for any bucketing result assigned to it to obtain a ciphertext processing result;

[0027] Obtain the encrypted processing result corresponding to any bucketing result generated by the first processing unit;

[0028] The encrypted processing result is stored in the first storage component.

[0029] The acceleration device provided in this application includes a first storage component and at least one first acceleration component. The first acceleration component includes a first control unit and multiple first processing units. The first storage component is connected to a first host processing component via a bus. The first storage component stores multiple bucketing results. The first control unit and the first storage component acquire at least one bucketing result and assign the at least one bucketing result to at least one first processing unit. The first processing unit is used to perform calculation processing on multiple encrypted data in the bucketing result according to a target calculation processing mode for any bucketing result assigned to it to obtain an encrypted processing result. The first control unit then stores the encrypted processing result corresponding to any bucketing result in the first storage component. The first storage component provides the encrypted processing results corresponding to the multiple bucketing results to the first host processing component. This application embodiment utilizes the acceleration device to realize the calculation processing of bucketing results, offloading the calculation processing operation from the host processing component to the acceleration device, thereby reducing the computational load of the host processing component, thus improving processing efficiency and performance. Furthermore, through the storage component and multiple processing units in the acceleration device, parallel calculation processing of multiple bucketing results can be realized, further improving processing efficiency.

[0030] These or other aspects of this application will become more apparent in the following description of the embodiments. Attached Figure Description

[0031] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0032] Figure 1 A schematic diagram of one embodiment of the acceleration device provided in this application is shown;

[0033] Figure 2 A schematic diagram of another embodiment of the acceleration device provided in this application is shown;

[0034] Figure 3 A schematic diagram of the structure of one embodiment of the first computing unit provided in this application is shown;

[0035] Figure 4 This illustration shows a schematic diagram of the operational structure of the first operational unit in a practical application according to an embodiment of this application;

[0036] Figure 5a A schematic diagram of the structure of one embodiment of the computing system provided in this application is shown;

[0037] Figure 5b This illustration shows an interactive scenario of the computing system provided in this application in a practical application;

[0038] Figure 6 A schematic diagram of one embodiment of the second acceleration device provided in this application is shown;

[0039] Figure 7 A schematic diagram of the structure of one embodiment of the third acceleration component provided in this application is shown;

[0040] Figure 8 A schematic diagram of the structure of one embodiment of the acceleration method provided in this application is shown;

[0041] Figure 9 A schematic diagram of the structure of one embodiment of the computing device provided in this application is shown. Detailed Implementation

[0042] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings.

[0043] In some of the processes described in the specification, claims, and accompanying drawings of this application, multiple operations appearing in a specific order are included. However, it should be clearly understood that these operations may not be executed in the order they appear herein, or may be executed in parallel. The operation numbers, such as 101, 102, etc., are merely used to distinguish different operations and do not themselves represent any execution order. Furthermore, these processes may include more or fewer operations, and these operations may be executed sequentially or in parallel. It should be noted that the descriptions such as "first," "second," etc., in this document are used to distinguish different messages, devices, modules, etc., and do not represent a chronological order, nor do they limit "first" and "second" to different types.

[0044] Computational processing operations using homomorphic encryption algorithms often involve encryption, decryption, or processing of encrypted data. Data providers typically use the host processing components in their own computing devices to perform these computational processes, resulting in poor performance.

[0045] The technical solutions of this application embodiment can be applied to application scenarios that use homomorphic encryption algorithms for computational processing, such as the data joint processing scenario mentioned in the background technology, which may be a multi-party joint modeling scenario, etc.

[0046] As described in the background section, a current data joint processing requirement is as follows: The data initiator calculates the target data based on the feature values ​​of each object, performs homomorphic encryption to obtain ciphertext data, and then provides the ciphertext data corresponding to multiple objects to the data receiver. The data receiver, for each feature it possesses, buckets the ciphertext data corresponding to multiple objects according to different feature values; it then processes the ciphertext data in each bucket result to obtain the ciphertext processing result, and returns the ciphertext processing result of each bucket result corresponding to each feature to the data initiator. The data initiator can then decrypt to obtain the plaintext processing result of each bucket result, and perform subsequent processing operations based on the plaintext processing result of each bucket result.

[0047] The aforementioned data joint processing requirements can exist in practical applications, for example, in multi-party joint modeling scenarios using federated learning. Taking multi-party joint modeling as an example, federated learning is a distributed machine learning approach that enables joint modeling using data from multiple parties while protecting data privacy. Vertical federated learning is a commonly used federated learning method, referring to multi-party joint modeling where the feature data and label information of sample objects are distributed among different data providers. Multiple data providers possess the same sample objects but different feature data. For example, data provider A and data provider B possess the same user C, but data provider A possesses user C's education level data, while data provider B possesses user C's age data. Here, education level data and age data are the feature data. During joint modeling, typically only one party possesses the label data of the sample objects. The data provider with the label data is called the data initiator (active party), while the data provider without the label data is called the data receiver (passive party). Through vertical federated learning, the active party can leverage the feature data of the passive party to improve the capabilities of the machine learning model while protecting the data privacy of all participating parties.

[0048] In the vertical federated learning approach, the decision tree model is a commonly used machine learning model. The most important aspect of training a decision tree model is finding the optimal split point. The split point refers to the specific value of a certain feature data. For example, if the label data is user C and the target group is the target group, the split point might be age less than 20 years old or age less than 30 years old, etc.

[0049] When training a decision tree model, the typical approach is as follows: First, the active party determines the gradient information corresponding to the model based on the feature values ​​and label data of the sample objects it possesses. Then, it encrypts this gradient information using homomorphic encryption, transmitting it as ciphertext gradient information to the passive party. The passive party calculates the cumulative ciphertext gradient value for each feature's corresponding split space based on the ciphertext gradient information and sends this cumulative ciphertext gradient value back to the active party. The active party decrypts this to obtain the cumulative gradient value, and based on the cumulative gradient values ​​of multiple features, it can ultimately determine the optimal split point. It is evident that the passive party needs to perform ciphertext accumulation on the homomorphically encrypted ciphertext gradient information. To improve training efficiency, a bucketing approach can be used. For each feature data point, the passive party can bucket the ciphertext gradient information corresponding to different sample objects according to the feature value, accumulate the ciphertext gradient information within each bucket, and then send the cumulative ciphertext gradient value corresponding to each bucket result to the active party. The active party then determines the optimal split point based on the cumulative ciphertext gradient values ​​of each bucket result.

[0050] As described above, the data receiver needs to perform bucketing for each feature and corresponding calculations on the ciphertext gradient information within each bucket. Since these calculations are usually performed using the processing components in their respective computing devices, the host processing component also needs to perform other tasks, which results in a large amount of computation for the processing component, thus affecting processing performance and reducing processing efficiency.

[0051] To improve processing performance and efficiency, the inventors discovered that processing ciphertext data encrypted using homomorphic encryption algorithms essentially requires multiplying and adding large integers, consuming significant processing power. Therefore, they considered using dedicated acceleration devices for ciphertext data processing to achieve better performance. However, designing such devices to effectively guarantee acceleration performance became a challenge. Based on this, the inventors conducted further research and proposed the technical solution of this application. This application provides an acceleration device including a storage component and at least one acceleration component. Each acceleration component includes a control unit and multiple computing units. The storage component is connected to the host processing component via a bus. Through the acceleration device provided in this application, computational processing operations are offloaded from the host processing component to the acceleration device, thereby reducing the computational load on the host processing component. Using a dedicated acceleration device to perform computational processing operations improves processing efficiency and performance. Furthermore, the storage component and multiple computing units in the acceleration device enable parallel computational processing, further improving efficiency. The host processing component only needs to perform one data transfer to perform computational processing operations under homomorphic encryption, reducing I / O overhead and ensuring the acceleration performance of the device.

[0052] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0053] Figure 1 This application provides a schematic diagram of the structure of an acceleration device according to one embodiment. The acceleration device may include a storage component 11 and at least one acceleration component 12, each acceleration component 12 ( Figure 1 (Taking the first acceleration component as an example) may include a control unit 101 and multiple processing units 102; the storage component 11 is connected to the host processing component 13 via a bus; the bus type may be, for example, PCIE (peripheral component interconnect express, high-speed serial computer expansion bus standard), and of course, other high-speed bus interconnects such as Ethernet may also be used, which is not limited in this application.

[0054] The acceleration device can be implemented using an application-specific integrated circuit (ASIC) or a field-programmable gate array (FPGA). Of course, it can also be implemented using a digital signal processor (DSP), a digital signal processing device (DSPD), a programmable logic device (PLD), a controller, a microcontroller, a microprocessor, or other forms of integrated circuits (ICs). This application does not limit the implementation of such devices.

[0055] The acceleration device can be deployed in a computing device, which can be referred to as the host device of the acceleration device. The host processing component can be, for example, the central processing unit (CPU) in the computing device, which is responsible for the traditional processing tasks in the computing device.

[0056] Among them, storage component 11 is used to store multiple sets of data to be processed, each set of data to be processed including at least one set of operation data;

[0057] Control unit 101 is used to obtain at least one set of operation data from storage component 11 and assign it to at least one computing unit;

[0058] The arithmetic unit 102 is used to perform calculation processing on at least one operation data in a set of data to be processed assigned to it, according to a target calculation processing mode, to obtain the calculation processing result.

[0059] The control unit 101 is used to store the calculation results corresponding to any set of data to be processed to the storage component 11; the calculation results are used to provide to the host processing component 13.

[0060] Among them, the storage component can be implemented using external memory with high bandwidth, etc.

[0061] In this embodiment, the computational processing operations are offloaded from the host processing component to the acceleration device, thereby reducing the computational load of the host processing component and improving processing efficiency and performance. In addition, through the storage component and multiple computing units in the acceleration device, parallel computation processing of multiple sets of data to be processed can be realized, further improving processing efficiency. The host processing component only needs to perform one data transmission to realize the computational processing operation under the homomorphic encryption algorithm, which can reduce I / O overhead and ensure the acceleration performance of the acceleration device.

[0062] The target computation mode may include, for example, encryption, decryption, or ciphertext accumulation.

[0063] In one implementation scenario, the data to be processed may include target data to be encrypted; that is, each set of data to be processed includes one operation data, which is the target data. The target data can be calculated based on the feature values ​​of any object. The computation unit 102 performs computation processing on at least one operation data according to the target computation processing mode, and the computation processing result can be the encryption of the target data to obtain ciphertext data. In this implementation scenario, the acceleration device can be configured in the computing device corresponding to the data initiator.

[0064] In another implementation scenario, the data to be processed may include the ciphertext processing result to be decrypted, that is, each set of data to be processed includes an operation data, which is the ciphertext processing result; then the computing unit 102 performs calculation processing on at least one operation data according to the target calculation processing mode, and the calculation processing result may be: decrypting the ciphertext processing result to obtain the plaintext processing result; in this implementation scenario, the acceleration device may be configured in the computing device corresponding to the data initiator.

[0065] In another implementation scenario, each set of data to be processed is a bucketed result, including multiple ciphertext data. That is, each set of data to be processed includes multiple operation data, which are the ciphertext data. The computing unit 102 performs calculations on at least one operation data according to the target calculation processing mode. The calculation processing result can be obtained by accumulating multiple ciphertext data to obtain a ciphertext processing result. In this implementation scenario, the acceleration device can be configured in the computing device corresponding to the data initiator.

[0066] The technical solution of this application will be introduced below for different implementation scenarios. As can be seen from the above description, in the scenario of joint data processing, the data receiver needs to bucket the encrypted data corresponding to multiple objects for each feature and process the encrypted data in each bucket. The amount of computation is very large, which affects the processing performance.

[0067] In collaborative data processing scenarios, a set of data to be processed corresponds to a bucketed result, and each bucketed result includes multiple encrypted data. To address the issue of high computational load in collaborative data processing scenarios, which impacts message processing, such as... Figure 2 The diagram shown is a structural schematic of another embodiment of an acceleration device provided in this application. The acceleration device may include: a first storage component 21 and at least one first acceleration component 22; the first storage component 21 is connected to the first host processing component 23 via a bus.

[0068] It should be noted that, Figure 2 The acceleration device shown is Figure 1 The acceleration device shown is implemented in a specific scenario. Figure 2 The "first" in the first storage component 21, first acceleration component 22, first host processing component 23, etc. involved in the acceleration device shown is only a name used to facilitate the distinction between different implementation scenarios.

[0069] The acceleration device can be implemented using an application-specific integrated circuit (ASIC) or a field-programmable gate array (FPGA). Of course, it can also be implemented using a digital signal processor (DSP), a digital signal processing device (DSPD), a programmable logic device (PLD), a controller, a microcontroller, a microprocessor, or other forms of integrated circuits (ICs). This application does not limit the implementation of such devices.

[0070] The acceleration device can be deployed in a first computing device, which is a host device relative to the acceleration device. The first host processing component can be, for example, a central processing unit (CPU) in the first computing device, which is responsible for traditional processing tasks in the first computing device.

[0071] Among them, each first acceleration component 22 ( Figure 2 (Taking a first acceleration component as an example) may include a first control unit 201 and multiple first processing units 202.

[0072] The first storage component 21 is used to store multiple bucketing results, wherein the multiple bucketing results are obtained by bucketing multiple ciphertext data corresponding to multiple objects according to different features.

[0073] The first control unit 201 is used to obtain at least one bucketing result from the first storage component 21 and to assign the at least one bucketing result to at least one first processing unit.

[0074] The first arithmetic unit 202 is used to perform calculations on multiple ciphertext data in any assigned bucket result according to the target calculation and processing mode to obtain the ciphertext processing result.

[0075] The first control unit 201 is used to store the encrypted processing result corresponding to any bucketing result into the first storage component 21.

[0076] The first storage component 21 is used to provide the encrypted processing results corresponding to the multiple bucketing results to the first host processing component 23.

[0077] Each object can correspond to one piece of ciphertext data, thus multiple objects can correspond to multiple pieces of ciphertext data. The ciphertext data can be obtained by encrypting the target data using a homomorphic encryption algorithm. In a practical application, such as a multi-party collaborative modeling scenario, this ciphertext data can refer to ciphertext gradient information, obtained by the data initiator by encrypting the gradient data using a homomorphic encryption algorithm.

[0078] As an alternative approach, multiple bucketing results can be obtained by the first host processing component performing bucketing processing on multiple encrypted data corresponding to multiple objects based on different characteristics.

[0079] In addition, as an alternative approach, to further improve message processing and acceleration performance, the acceleration device may also include a second acceleration component connected to the first storage component 21. The second acceleration component retrieves multiple encrypted data from the first storage component 21 and, for any given feature, performs bucketing processing on the multiple encrypted data to obtain multiple bucketing results; the multiple bucketing results are then stored in the first storage component 21. The first host processing component 23 can transmit multiple encrypted data corresponding to multiple objects sent by the data sender to the first storage component 21 in the acceleration device for storage. Thus, by having the bucketing operation and computational processing operations performed by the acceleration device, the host processing component only needs to transmit encrypted data once, which can be shared by multiple features for bucketing operations. This reduces the computational load on the host processing component, improves processing efficiency by utilizing a dedicated acceleration device to perform the corresponding operations, and reduces the I / O overhead of the acceleration device, ensuring its acceleration performance.

[0080] The first host processing component 23 can send corresponding instruction information to the first storage component 21, the first acceleration component 22, and the second acceleration component to start or trigger each component to perform corresponding operations. For example, after the first host processing component 23 stores multiple encrypted data in the first storage component 21, it can send corresponding instruction information to the second acceleration component. The second acceleration component can then retrieve the multiple encrypted data from the first storage component 21 based on this instruction information. Alternatively, the first host processing component 23 can also notify the first storage component 21, the first acceleration component 22, and the second acceleration component to start after receiving multiple encrypted data sent by the data initiator. The first storage component 21, the first acceleration component 22, and the second acceleration component can then trigger and execute their respective operations in real time or periodically.

[0081] The second acceleration component is responsible for the bucketing operations corresponding to each feature possessed by the data receiver. It can bucket multiple encrypted data for each feature, obtaining multiple bucketing results for each feature. The bucketing results corresponding to different features can then be stored in the first storage component 21. The second acceleration component can also send a bucketing end notification to the first host processing component 23. After receiving the bucketing end notification, the first host processing component 23 can instruct the first acceleration component 22 to retrieve the multiple bucketing results and perform calculations, etc.

[0082] Optionally, to improve processing efficiency, the second acceleration component can adopt a parallel approach, simultaneously performing bucketing processing on multiple encrypted data for multiple features. These multiple features can be obtained by notification from the first host processing component 23, etc. The first host processing component 23 can divide the features to be processed into multiple groups, each group including multiple features. After the bucketing operation corresponding to multiple features in any group is completed, multiple features of another group are then distributed.

[0083] After obtaining multiple bucket results from the first storage component 21, the first acceleration component 22 can perform calculations on the ciphertext data in the same bucket result to obtain the ciphertext processing result, and store the ciphertext processing results corresponding to the multiple bucket results in the first storage component; Optionally, the first acceleration component 22 can specifically perform calculations on the ciphertext data in the same bucket result according to the target calculation processing mode. The corresponding operation method can be determined according to the target calculation processing mode, and the calculation processing is performed according to the operation method corresponding to the target calculation processing mode.

[0084] The target computation processing mode or the operation method can be notified to the first acceleration component 22 by the first host processing component 23.

[0085] The target computation processing mode may include, for example, ciphertext accumulation, as well as ciphertext multiplication, ciphertext subtraction, etc. In the scenario of multi-party joint modeling, the target computation processing mode can specifically refer to ciphertext accumulation.

[0086] The ciphertext accumulation operation can be a point addition operation, such as in ECC (Elliptic Curve Cryptography), where ciphertext accumulation is converted into a point addition operation between two points on an elliptic curve. In homomorphic encryption algorithms based on elliptic curves, the point addition operation is actually converted into modular addition, modular multiplication, and other arithmetic operations.

[0087] After the first storage component 21 stores the encrypted processing results corresponding to the multiple bucket results, it can notify the first host processing component 23, so that the first host processing component 23 can obtain the encrypted processing results corresponding to the multiple bucket results from the first storage component 21.

[0088] The first host processing component 23 can send the encrypted processing results corresponding to the multiple bucketing results to the data initiator, so that the data initiator can perform subsequent operations. For example, the data initiator can first decrypt to obtain the plaintext processing results corresponding to the multiple bucketing results for each feature, and then perform calculation processing on the plaintext processing results according to the target calculation processing mode; or it can first perform calculation processing on the encrypted processing results corresponding to the multiple bucketing results for each feature according to the target calculation processing mode, and then decrypt the processing results, etc.

[0089] In some embodiments, such as Figure 2 As described above, the acceleration device may further include a bus interface 24 for connecting to a first host device, so as to connect at least one first acceleration component 22 and a first storage component 21 to the first host processing component 23. The bus interface 24 allows the acceleration device to be pluggably installed in the first computing device.

[0090] In some embodiments, such as Figure 2 As described above, the acceleration device may also include a substrate 25, a first storage component 21, and at least one first acceleration component 22, which can be soldered onto the substrate 26 to achieve an electrical connection between at least one first acceleration component 22 and the first storage component 21.

[0091] By binning multiple encrypted data, multiple encrypted data can be divided into multiple data intervals. Each data interval is similar to a bucket, and the encrypted data contained in each data interval constitutes a binning result.

[0092] As an optional approach, the second acceleration component may perform bucketing on multiple encrypted data for any given feature to obtain multiple bucketing results. This may include: performing bucketing on multiple encrypted data according to at least one feature value corresponding to the feature for any given feature to obtain multiple bucketing results.

[0093] Specifically, the bucketing operation can first divide multiple objects according to at least one feature value, and then divide the encrypted data corresponding to the multiple objects according to the division results, so that the encrypted data corresponding to objects located in the same feature value range are divided into the same bucket result.

[0094] For example, if the object is a user and the feature is age, with feature values ​​including 10, 20, and 30 years old, then the age can be divided into four age ranges: 0-10, 10-20, 20-30, and 30-∞ (infinity). Based on these four age ranges, multiple users can be divided into different age ranges. The encrypted data corresponding to users in the same age range will then be grouped into the same bucket, resulting in multiple bucketing results.

[0095] In this configuration, at least one feature value corresponding to each feature can be stored by the first host processing component 23 in the first storage component 21, and retrieved by the second acceleration component from the first storage component 21. Alternatively, due to the small data volume, the first host processing component 23 can directly send at least one feature value corresponding to each feature to the second acceleration component.

[0096] In addition, as another option, the first storage component 21 is also used to store bucket information of multiple objects sent by the first host processing component 23, each corresponding to different characteristics;

[0097] The second acceleration component performs bucketing on multiple encrypted data for any given feature to obtain multiple bucketing results. This includes: determining the bucketing information corresponding to the feature for each of the multiple objects; and dividing the encrypted data corresponding to at least one object with the same bucketing information into the same bucket to obtain multiple buckets.

[0098] The bucketing information can refer to a bucket identifier, which is used to uniquely identify a bucket. It can be implemented using any combination of one or more characters (such as a combination of numbers, letters, etc.), and this application does not limit this. The bucketing information corresponding to multiple objects with different characteristics can be determined by the first host processing component 23.

[0099] After obtaining the encrypted data corresponding to each object, the first host processing component 23 can combine multiple features possessed by the data receiver. For each feature, based on at least one corresponding feature value, multiple objects can be divided, thus determining the feature value range of each object. Objects within the same feature value range are assigned the same bucket information, while different feature value ranges correspond to different bucket information. The first host processing component 23 can store the bucket information for each feature of each object in the first storage component 21. The second acceleration component can then retrieve the bucket information for each feature of multiple objects from the first storage component 21. Alternatively, since the bucket information data volume is relatively small, the first host processing component 23 can also send the bucket information for different features of multiple objects to the second acceleration component.

[0100] In some embodiments, the second acceleration component may include a data loading unit, multiple bucket units, and a data storage unit.

[0101] The data loading unit is used to obtain multiple encrypted data from the first storage component 21, provide the multiple encrypted data to multiple bucket units respectively, allocate features to be processed to the multiple bucket units respectively, and control the multiple bucket units to perform parallel processing.

[0102] The bucketing unit is used to divide multiple encrypted data into buckets based on the features assigned to it, obtain multiple bucketing results, and send the multiple bucketing results to the storage unit.

[0103] The data storage unit is used to store the multiple bucketing results sent by each bucketing unit into the first storage component.

[0104] Parallel processing of multiple features can be achieved through multiple bucket units. Each bucket unit can be allocated at least one feature, which can be processed in a linear fashion. The data storage unit can be implemented using RAM (Random Access Memory), etc.

[0105] Optionally, each bucketing unit can be assigned a feature. The first host processing component 23 can determine the number of features to be processed in parallel at one time based on the number of units in the multiple bucketing units. This number of features can be less than or equal to the number of units. The first host processing component 23 can select at least one feature based on the number of features, and provide the bucketing information of multiple objects corresponding to the at least one feature to the acceleration device. The data loading unit then allocates the bucketing information of the at least one feature to the at least one bucketing unit. Each bucketing unit can obtain the bucketing information of one feature, and then, for the feature assigned to it, divides the ciphertext data corresponding to at least one object with the same bucketing information into the same bucketing result. Alternatively, the first host processing component 23 can also select at least one feature based on the number of features, and provide the at least one feature value corresponding to the at least one feature to the acceleration device. The data loading unit then allocates the at least one feature value corresponding to the at least one feature to the at least one bucketing unit. Each bucketing unit can obtain the at least one feature value of one feature, and then, for the feature assigned to it, bucket the multiple ciphertext data according to its corresponding at least one feature value.

[0106] Some embodiments, such as Figure 2 As shown, each first acceleration component 22 may further include a first storage unit 203; the first processing unit 202 may also be used to save the ciphertext processing result corresponding to any bucketing result to the first storage unit 203;

[0107] The first control unit 201 may store the encrypted processing result corresponding to any bucket result to the first storage component 21 by storing the encrypted processing result corresponding to any bucket result stored in the first storage unit 203 to the first storage component 21.

[0108] In some embodiments, such as Figure 2 As shown in the figure, each first acceleration component 22 may also include a first loading unit 204.

[0109] Specifically, the first control unit 201 may obtain at least one bucket result from the first storage component 21 by controlling the first loading unit 204 to obtain at least one bucket result from the first storage component 21.

[0110] Optionally, the first control unit 201 may perform corresponding operations according to the instructions of the first host processing component 23. Therefore, in some embodiments, the first control unit 201 may also be used to receive first control information sent by the first host processing component 23 and control the operation of multiple first arithmetic units 202 and first storage units 203 according to the first control information.

[0111] The first control information may include a first total amount of data for at least one bucketing result to be acquired by the first acceleration component 22, and a second total amount of data corresponding to the at least one bucketing result after calculation and processing. Additionally, it may include a first storage address corresponding to the at least one bucketing result to be acquired, and a second storage address corresponding to at least one encrypted processing result obtained after calculation and processing of the at least one bucketing result. Therefore, the first control unit 201 can specifically acquire at least one bucketing result from the first storage component 21 according to the first total amount of data and the first storage address; and can control the first storage unit 203 to store at least one encrypted processing result in the first storage component 21 according to the second total amount of data and the second storage address. Specifically, the first control unit 201 can specifically control the first loading unit 204 to acquire at least one bucketing result from the first storage component 21 according to the first total amount of data and the first storage address.

[0112] In addition, the first control information may also include the target calculation processing mode or the calculation method corresponding to the target calculation processing mode, and the first control unit 201 may specifically notify the first calculation unit 202 of the corresponding calculation method according to the first control information.

[0113] The first operation unit 202 performs calculations and processing on multiple ciphertext data in any assigned bucket result to obtain a ciphertext processing result, including: for any assigned bucket result, processing multiple ciphertext data in the bucket result according to the operation method to obtain a ciphertext processing result.

[0114] In one or more of the above embodiments, the operation method corresponding to each target calculation mode can be pre-configured with one or more corresponding operation instructions. By executing one or more operation instructions, the multiple encrypted data in each bucket result can be calculated and processed.

[0115] In practical applications, each first arithmetic unit 202 can be implemented using a programmable processor (PC), which can store corresponding instructions to execute corresponding operations. In some embodiments, such as Figure 3 As shown, the first arithmetic unit 202 may include a first storage subunit 301, a first parsing subunit 302, a first calculation subunit 304, and a first control subunit 303.

[0116] The first storage subunit 301 is used to store one or more instructions corresponding to the target computing and processing mode;

[0117] The first parsing subunit 302 is used to parse one or more instructions;

[0118] The first control subunit 303 is used to send calculation instruction information to the first calculation subunit based on the parsing result of the first parsing subunit;

[0119] The first calculation subunit 304 is used to perform calculation processing on multiple ciphertext data based on calculation instruction information to obtain ciphertext processing results.

[0120] The one or more operation instructions, after being parsed, can be converted into corresponding calculation instruction information to control the operation of the first calculation subunit.

[0121] The first storage sub-unit can be implemented using RAM, etc.

[0122] In practical applications, Figure 2 The target computation processing mode applicable to the illustrated embodiment can be ciphertext accumulation, corresponding to point addition. For example, the ciphertext data can be encrypted using an elliptic curve-based homomorphic encryption algorithm, such as the EC-ELGamal semi-homomorphic acceleration algorithm. EC-ELGamal is a type of ECC, which is an implementation of ElGamal based on elliptic curves. Its main computations include elliptic curve point addition, point subtraction, point multiplication, modular inverse, and discrete logarithms. ElGamal, on the other hand, is an asymmetric encryption algorithm based on Diffie-Hellman key exchange.

[0123] Using the EC-ELGamal semi-homomorphic encryption algorithm, its encryption formula is:

[0124]

[0125] Where P represents the public key, which is a point on the elliptic curve; G is the base point of the elliptic curve; k is a random number; m is the plaintext data to be encrypted, i.e., the target data; and Enc(P, m) represents the ciphertext obtained by encryption, which consists of point pairs C1 and C2.

[0126] The formula for adding ciphertext is:

[0127]

[0128] The decryption formula is:

[0129]

[0130] Where M represents the decryption result, s represents the private key, and the private key multiplied by the base point is the public key. Therefore, sC1 = s*kG = kP, and thus C2 - sC1 = mG.

[0131] As can be seen, encryption essentially requires dot product on an elliptic curve and the addition of the results of dot products on two elliptic curves (dot addition). Ciphertext addition is essentially dot addition on an elliptic curve, while decryption requires dot product on an elliptic curve. Dot product operation is essentially composed of scalars and dots. For example, the dot product operation kP includes the scalar k and the dot P; the dot product operation mG includes the scalar m and the dot G.

[0132] Ciphertext accumulation means adding multiple ciphertext data together. In some embodiments, the first calculation subunit 304, based on calculation instruction information, performs calculations on multiple ciphertext data to obtain a ciphertext processing result. This can be done by: sequentially obtaining one ciphertext data from the multiple ciphertext data, performing a dot-plus operation with the previous dot-plus result, determining whether the current accumulation count meets the preset number, and if so, outputting the last dot-plus result as the ciphertext processing result; otherwise, saving the dot-plus result to the first storage subunit 301. The first control unit can provide the multiple ciphertext data to the first calculation subunit in the form of an input data stream.

[0133] In one implementation, the first storage subunit 301 may include a first instruction storage subunit, a first data storage subunit, and a first data storage subunit.

[0134] The first instruction storage subunit is used to store one or more operation instructions, the first data storage subunit is used to store intermediate results in the calculation process, such as the previous addition result, and the first number storage unit is used to store the preset number of times, etc.

[0135] In addition, for target computation processing modes involving dot multiplication, the first storage subunit may also include a first scalar storage subunit for storing scalar data.

[0136] In a practical application, the schematic diagram of the operational structure of the first operational unit 202 can be as follows: Figure 4 As shown, Figure 4 The first instruction storage unit, first parsing subunit, first control subunit, first data storage subunit, first calculation subunit, first scalar storage subunit, and first scalar storage subunit described above have been described in detail previously and will not be repeated here. Combined with... Figure 4As shown, the first computational subunit may have basic computational logic, which may include a first input A, a second input B, a third input C, and a fourth input D. The first input A may come from the input data stream or the first data storage subunit, and the second input B, the third input C, and the fourth input D may come from the first data storage subunit. Of course, each input can be empty. Taking the dot-matrix addition operation corresponding to ciphertext accumulation as an example: the ciphertext data obtained from the input data stream can enter the first input A, the previous dot-matrix addition result is used as the second input B, and the third input C and the fourth input D can be empty. The first computational subunit performs the dot-matrix addition operation, adding the first input A and the second input B to obtain the dot-matrix addition result. This dot-matrix addition result will be stored in the first data storage subunit or output as the ciphertext processing result.

[0137] In a practical application, the technical solution of this application embodiment can be a computing device corresponding to a data receiver responsible for processing multiple encrypted data. The data initiator corresponds to a second computing device, used to transmit encrypted data corresponding to multiple objects to the first computing device.

[0138] like Figure 5a As shown in the illustration, this application embodiment also provides a computing system, which may include a first computing device 51 and a second computing device 52.

[0139] The first computing device 51 may include a first host processing component 511 and a first acceleration device 512. The specific structure of the first acceleration device 512 can be found in [details omitted]. Figures 1-4 The acceleration device described in any of the embodiments shown;

[0140] The second computing device 52 may include a second host processing component 521 and a second acceleration device 522. The second acceleration device 522 is used to accelerate encryption or decryption operations, etc. Therefore, the second acceleration device 522 can be used to acquire multiple data to be processed, encrypt or decrypt any data to be processed, and obtain the computing result.

[0141] The data to be processed can be target data to be encrypted or ciphertext processing results to be decrypted; correspondingly, the calculation processing results can be ciphertext data or plaintext processing results.

[0142] For encrypted data, the second host processing component 521 can obtain encrypted data corresponding to multiple objects from the second acceleration device 522 and send it to the first computing device 51.

[0143] For the plaintext processing result, the second host processing component 521 can obtain the plaintext processing result from the second acceleration device 522 and perform subsequent processing operations.

[0144] For example, in a practical application, the technical solution of this application embodiment can be applied to a scenario where multi-party joint modeling is performed using a vertical federated learning approach.

[0145] like Figure 5b In the interactive diagram shown, the second acceleration device 522 in the second computing device 52 of the data initiator first encrypts the gradient information corresponding to different sample objects to obtain the encrypted gradient information of multiple sample objects. The gradient information is calculated using a decision tree model based on the feature values ​​and label data of the sample objects provided by the data initiator.

[0146] Subsequently, the second acceleration device 522 sends the encrypted gradient information of multiple sample objects to the second host processing component 521, which then sends the encrypted gradient information of the multiple sample objects to the first computing device 51 corresponding to the data receiver.

[0147] After receiving the encrypted gradient information of multiple sample objects, the first host processing component 511 in the first computing device 51 can send the encrypted gradient information of multiple sample objects to the first acceleration device 512. The first acceleration device 512 can first perform bucketing processing on the encrypted gradient information of multiple sample objects according to different features to obtain multiple bucketing results for each feature. Then, using the technical solution of this application, the encrypted gradient accumulation value corresponding to the multiple bucketing results of each feature can be calculated and then sent to the first host processing component 511. The first host processing component 511 then sends the encrypted gradient accumulation value corresponding to the multiple bucketing results of each feature to the second computing device 52 of the data initiator.

[0148] The second host processing component 521 in the second computing device 52 receives the ciphertext gradient accumulation value corresponding to the multiple bucket results of each feature, and can send it to the second acceleration device 522.

[0149] The second acceleration device 522 can decrypt the gradient accumulation values ​​corresponding to the multiple bucketing results of each feature to obtain the gradient accumulation value corresponding to that feature. Alternatively, it can first accumulate the ciphertext gradient accumulation values ​​corresponding to the multiple bucketing results to obtain the ciphertext gradient accumulation value corresponding to that feature, and then decrypt the ciphertext gradient accumulation value corresponding to that feature to obtain the gradient accumulation value corresponding to that feature.

[0150] The second acceleration device 522 can send the gradient accumulation values ​​corresponding to multiple features to the second host processing component 521.

[0151] The second host processing component 521 can specifically determine the optimal split point of the decision tree model based on the accumulated gradient values ​​corresponding to multiple features. The decision tree model can then be constructed based on the optimal split point.

[0152] The decision tree model can be XGBoost (eXtreme Gradient Boosting), or other types of decision tree models, such as GBDT (Gradient Boosting Decision Tree) or GBM (Gradient Boosting Machine).

[0153] Gradient information can include the first-order gradient and second-order gradient corresponding to each sample object. It is obtained by taking the derivative of the loss function of the decision tree model. By inputting the feature values ​​of the sample object into the decision tree model, the prediction data can be obtained. The degree of inconsistency between the prediction data and the label data can be estimated by using the loss function. The first-order gradient and second-order gradient can be obtained by taking the derivative of the loss function.

[0154] As can be seen from the above description, for the second computing device, when the data to be processed is target data to be encrypted, the target data can be the gradient information corresponding to the decision tree model calculated based on the feature values ​​and label data of the sample object provided by the data initiator.

[0155] When the data to be processed is the ciphertext processing result to be decrypted, the data to be processed can be the ciphertext processing result to be decrypted calculated based on any feature provided by the data receiver. The ciphertext processing result to be decrypted can be the ciphertext gradient accumulation value, which can be the ciphertext gradient accumulation value corresponding to each feature or the ciphertext gradient accumulation value corresponding to each bucket result. The corresponding calculation and processing result obtained by decrypting it is the gradient accumulation value.

[0156] A connection is established between the first computing device 51 and the second computing device 52 via a network. The network provides a communication link medium between the first computing device 51 and the second computing device 52. The network can include various connection types, such as wired, wireless, or fiber optic cable, etc. Optionally, the wireless connection can be implemented through a mobile network, and correspondingly, the mobile network standard can be any one of 2G (GSM), 2.5G (GPRS), 3G (WCDMA, TD-SCDMA, CDMA2000, UTMS), 4G (LTE), 4G+ (LTE+), 5G, WiMax, etc. Optionally, a communication connection can also be established via Bluetooth, WiFi, infrared, etc.

[0157] The first computing device 51 and the second computing device 52 may also include other components, such as input / output interfaces, display components, communication components that realize the above-mentioned communication connections, and host storage components that store computer instructions for the host processing components to call and execute to achieve corresponding operations, etc. This application will not elaborate on these.

[0158] In some embodiments, such as Figure 6 As shown, the second acceleration device 522 may include a second storage component 601 and at least one third acceleration component 602; the second storage component 601 is connected to the second host processing component 521 via a bus.

[0159] The second storage component 601 is used to store multiple data to be processed sent by the second host processing component 521; the data to be processed is target data to be encrypted or ciphertext processing result to be decrypted;

[0160] The third acceleration component 602 is used to obtain at least one piece of data to be processed from the second storage component 601; for any piece of data to be processed, the data to be processed is encrypted or decrypted to obtain the calculation result, and the calculation result is stored in the second storage component 601.

[0161] The second host processing component 521 is used to obtain the calculation result corresponding to any data to be processed from the second storage component 601.

[0162] Optionally, the second acceleration device 522 may be equipped with multiple third acceleration components 602, thereby improving parallel processing capabilities, processing efficiency, and acceleration performance.

[0163] In some embodiments, such as Figure 7 As shown, each third acceleration component 602 may include a second control unit 701 and a plurality of second computing units 702;

[0164] The second control unit 701 is used to acquire at least one piece of data to be processed from the second storage component; and to assign the at least one piece of data to be processed to at least one second processing unit;

[0165] The second processing unit 702 is used to encrypt or decrypt any data to be processed assigned to it, and obtain the calculation result.

[0166] The second control unit 701 is used to store the calculation result corresponding to any data to be processed into the second storage component 601.

[0167] In some embodiments, each third acceleration component 602 may further include a second storage unit 703; the second processing unit 702 is further configured to save the calculation result corresponding to any data to be processed to the second storage unit 703;

[0168] The second control unit 701 stores the calculation result corresponding to any data to be processed to the second storage component 601, including: storing the calculation result corresponding to any data to be processed stored in the second storage unit 703 to the second storage component 601.

[0169] In some embodiments, such as Figure 7 As shown, each third acceleration component 602 may further include a second loading unit 704. The second control unit 701 may specifically control the second loading unit 704 to acquire at least one piece of data to be processed from the second storage component 601.

[0170] In some embodiments, the second control unit 701 is further configured to receive second control information sent by the second host processing component 521, and control the operation of multiple second arithmetic units 702 and second storage units 703 according to the second control information;

[0171] The second control unit 701 is also used to notify the second arithmetic unit 702 of the corresponding arithmetic method according to the second control information; wherein, the arithmetic method corresponding to encryption is dot addition and dot multiplication, and the arithmetic method corresponding to decryption is dot multiplication.

[0172] The second control information may include a first total amount of at least one piece of data to be processed required by the third acceleration component, and a second total amount of data corresponding to the at least one piece of data to be processed after computation. Furthermore, it may include a first storage address corresponding to the at least one piece of data to be processed, and a second storage address corresponding to the at least one computation result obtained after computation of the at least one piece of data to be processed. Therefore, the second control unit 701 can specifically obtain at least one piece of data to be processed from the second storage component 601 according to the first total amount of data and the first storage address; and can control the second storage unit 703 to store at least one computation result in the second storage component 601 according to the second total amount of data and the second storage address. Specifically, the second control unit 701 can specifically control the second loading unit 704 to obtain at least one piece of data to be processed from the second storage component 601 according to the first total amount of data and the first storage address.

[0173] In addition, the second control information may also include the corresponding operation method for encryption or decryption, and the second control unit 701 may specifically notify the second operation unit 702 of the corresponding operation method according to the second control information.

[0174] The second operation unit 702 performs calculations on any assigned data to obtain a calculation result, including: processing the assigned data according to the operation method to obtain a calculation result.

[0175] The encryption or decryption operation can be pre-configured with one or more operation instructions. Executing one or more operation instructions enables the computational processing of each piece of data to be processed. In some embodiments, the second operation unit 702 can be implemented using a programmable processor (PC) in practical applications. This PC can store corresponding instructions to execute corresponding operations. The second operation unit 702 may include a second storage subunit, a second parsing subunit, a second calculation subunit, and a second control subunit.

[0176] The second storage subunit is used to store one or more operation instructions corresponding to encryption or decryption;

[0177] The second parsing subunit is used to parse one or more operation instructions;

[0178] The second control subunit is used to send calculation instruction information to the second calculation subunit based on the parsing result of the second parsing subunit;

[0179] The second calculation subunit is used to perform calculations on the data to be processed based on the calculation instruction information to obtain the calculation results.

[0180] The one or more operation instructions, after being parsed, can be converted into corresponding calculation instruction information to control the operation of the first calculation subunit.

[0181] The second storage sub-unit can be implemented using RAM, etc.

[0182] In one implementation, the second storage subunit may include a second instruction storage subunit, a second data storage subunit, and a second data storage subunit.

[0183] The second instruction storage unit is used to store one or more operation instructions, the second data storage subunit is used to store intermediate results during the calculation process, and the second number storage unit is used to store preset number of times, etc.

[0184] In addition, since the encryption operation involves dot multiplication, the second storage subunit may also include a first scalar storage subunit for storing scalar data.

[0185] It should be noted that the specific structure of the second arithmetic unit can be the same as that of the first arithmetic unit 202 described in the corresponding embodiments above. Therefore, the specific implementation can be found in the explanation of the first arithmetic unit above, and will not be repeated here.

[0186] The technical solutions of this application embodiment can improve the processing efficiency of encryption or decryption operations in the second computing device and the processing efficiency of ciphertext accumulation operations in the first computing device, reduce the computational load of the host processing component, improve processing performance, improve acceleration performance, and realize efficient and high-performance data joint processing.

[0187] The first computing device and the second computing device can be physical machines, such as physical machines that provide cloud computing capabilities.

[0188] Furthermore, embodiments of this application also provide an acceleration method, which can be applied to, for example... Figure 2 The acceleration device shown includes a first storage component and at least one first acceleration component; the first acceleration component includes a first control unit and multiple first processing units; the first storage component is connected to the first host processing component via a bus; the specific structural implementation of this acceleration device can be found in the corresponding embodiments, and will not be repeated here. The method can be specifically executed by the first acceleration component in the acceleration device, such as... Figure 8 As described herein, the method may include the following steps:

[0189] 801: Retrieve at least one bucket result from multiple bucket results.

[0190] Multiple bucketing results are obtained by bucketing multiple ciphertext data corresponding to multiple objects according to different features.

[0191] 802: Distribute at least one bucket result to at least one first arithmetic unit.

[0192] The first processing unit is used to perform calculations on multiple ciphertext data in any assigned bucket result to obtain a ciphertext processing result.

[0193] 803: Obtain the ciphertext processing result corresponding to any bucket result generated by the first processing unit.

[0194] 804: Store the ciphertext processing result to the first storage component.

[0195] The first storage component is used to provide the encrypted processing results corresponding to the multiple bucket results to the first host processing component.

[0196] It should be noted that, Figure 8 The specific operation of each step in the acceleration method described in the illustrated embodiment has been described in detail in the relevant device embodiments, and will not be elaborated here.

[0197] Furthermore, embodiments of this application also provide a computing device, such as... Figure 9As shown, the computing device may include a host processing component 901, a host storage component 902, and an acceleration device 903, wherein the acceleration device 903 may employ, for example... Figure 1 Figure 5, or Figure 6 The structures described in any of the embodiments shown are not repeated here.

[0198] The host storage component 902 can store one or more computer instructions for the host processing component 1001 to call and execute in order to perform the corresponding operation.

[0199] Of course, computing devices may also include other components, such as input / output interfaces, display components, communication components, etc.

[0200] Input / output interfaces provide interfaces between processing components and peripheral interface modules, which can be output devices, input devices, etc. Communication components are configured to facilitate wired or wireless communication between computing devices and other devices.

[0201] The host processing component may include one or more processors to execute computer instructions to complete all or part of the steps in the above-described method. Alternatively, the host processing component may be implemented as one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the above-described method.

[0202] Host storage components are configured to store various types of data to support operation on computing devices. Host storage components can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.

[0203] Acceleration devices can be implemented using application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components. They can be connected to the host processing components via a bus and deployed in computing devices using a hot-swappable method.

[0204] This application also provides a computer-readable storage medium storing a computer program, which, when executed by a computer, can perform the above-described functions. Figure 8The acceleration method of the illustrated embodiment. The computer-readable medium may be included in the computing device described in the above embodiments; or it may exist independently and not assembled into the electronic device.

[0205] This application also provides a computer program product, which includes a computer program carried on a computer-readable storage medium. When the computer program is executed by a computer, it can perform the functions described above. Figure 8 The acceleration method of the illustrated embodiment. In such an embodiment, the computer program may be downloaded and installed from a network, and / or installed from a removable medium. When the computer program is executed by a processor, it performs the various functions defined in the system of this application.

[0206] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0207] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0208] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0209] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. An acceleration device, characterized in that, It includes a first storage component and at least one first acceleration component; the first acceleration component includes a first control unit and a plurality of first processing units; the first storage component is connected to a first host processing component via a bus; The first storage component is used to store multiple bucketing results; the multiple bucketing results are obtained by bucketing multiple ciphertext data corresponding to multiple objects according to different features; The first control unit is configured to obtain at least one bucketing result from the first storage component; and assign the at least one bucketing result to at least one first processing unit; The first computing unit is used to perform calculations on multiple ciphertext data in any bucketing result assigned to it, according to the target calculation and processing mode, to obtain the ciphertext processing result. The first control unit is used to store the encrypted processing result corresponding to any bucketing result into the first storage component; The first storage component is used to provide the encrypted processing results corresponding to the multiple bucketing results to the first host processing component.

2. The device according to claim 1, characterized in that, The first acceleration component further includes a first storage unit; the first processing unit is also configured to save the ciphertext processing result corresponding to any bucketing result to the first storage unit; The first control unit stores the encrypted processing result corresponding to any bucket result into the first storage component by storing the encrypted processing result corresponding to any bucket result stored in the first storage unit into the first storage component.

3. The device according to claim 2, characterized in that, The first control unit is further configured to receive first control information sent by the first host processing component, and control the operation of the plurality of first arithmetic units and the first storage unit according to the first control information; The first control unit is further configured to notify the first arithmetic unit of the arithmetic method corresponding to the target calculation processing mode according to the first control information; The first processing unit performs calculations and processing on multiple ciphertext data in any assigned bucket result to obtain a ciphertext processing result, including: for any assigned bucket result, processing multiple ciphertext data in the bucket result according to the aforementioned calculation method to obtain a ciphertext processing result.

4. The device according to claim 1, characterized in that, The first arithmetic unit includes an instruction first storage subunit, a first parsing subunit, a first calculation subunit, and a first control subunit; The first storage subunit is used to store one or more instructions corresponding to the target computing and processing mode; The first parsing subunit is used to parse the one or more instructions; The first control subunit is used to send calculation instruction information to the first calculation subunit based on the parsing result of the first parsing subunit; The first calculation subunit is used to perform calculation processing on the plurality of ciphertext data based on the calculation instruction information to obtain the ciphertext processing result.

5. The device according to claim 4, characterized in that, The target calculation and processing mode is ciphertext accumulation, and the ciphertext accumulation operation method is dot addition operation; The first calculation subunit performs calculations on the multiple ciphertext data based on the calculation instruction information to obtain the ciphertext processing result, including: sequentially obtaining one ciphertext data from the multiple ciphertext data, performing a dot-add operation with the previous dot-add result, determining whether the current cumulative number of additions meets the preset number, and if so, outputting the last dot-add result as the ciphertext processing result; otherwise, saving the dot-add result to the first storage subunit.

6. The device according to claim 1, characterized in that, It also includes a bus interface for accessing a first host device to enable the connection of the at least one first acceleration component and the first storage component with the first host processing component in the first host device.

7. The device according to claim 1, characterized in that, It also includes a substrate, on which the first storage component and the at least one first acceleration component are soldered.

8. An acceleration device, characterized in that, It includes a storage component and at least one acceleration component, the acceleration component including a control unit and multiple computing units; the storage component is connected to the host processing component via a bus. The storage component is used to store multiple sets of data to be processed, each set of data to be processed including at least one set of operation data; The control unit is configured to acquire at least one set of operation data from the storage component and assign it to at least one computing unit. The computing unit is used to perform calculation processing on at least one operation data in a set of data to be processed assigned to it, according to a target calculation processing mode, to obtain a calculation processing result. The control unit is used to store the calculation results corresponding to any set of data to be processed into the storage component; The calculation results are used to provide the host processing component.

9. The device according to claim 8, characterized in that, The data to be processed includes target data to be encrypted; the target data is calculated based on the feature value of any object; the computing unit performs calculation processing on the at least one operation data according to the target calculation processing mode, and the calculation processing result includes: encrypting the target data to obtain ciphertext data; Alternatively, the data to be processed includes the ciphertext processing result to be decrypted; the computing unit performs calculation processing on the at least one operation data according to the target calculation processing mode to obtain the calculation processing result, including: decrypting the ciphertext processing result to obtain the plaintext processing result; Alternatively, a set of data to be processed corresponds to a bucket result, including multiple ciphertext data; the computing unit performs calculation processing on the at least one operation data according to the target calculation processing mode, and the calculation processing result includes: performing cumulative processing on the multiple ciphertext data to obtain the ciphertext processing result.

10. A computing system, characterized in that, It includes a first computing device and a second computing device; the first computing device includes a first host processing component and an acceleration device as described in any one of claims 1 to 7; The second computing device includes a second host processing unit and a second acceleration device; the second acceleration device includes a second storage unit and at least one third acceleration unit; The second storage component is connected to the second host processing component via a bus; The second storage component is used to store multiple data items to be processed sent by the second host processing component; The data to be processed is either the target data to be encrypted or the ciphertext processing result to be decrypted; The third acceleration component is used to obtain at least one piece of data to be processed from the second storage component; for any piece of data to be processed, the data to be processed is encrypted or decrypted to obtain a calculation result, and the calculation result is stored in the second storage component; The second host processing component is used to obtain the calculation result corresponding to any data to be processed from the second storage component.

11. The computing system according to claim 10, characterized in that, The third acceleration component includes a second control unit and multiple second computing units; The second control unit is used to acquire at least one piece of data to be processed from the second storage component; and to assign the at least one piece of data to be processed to at least one second processing unit; The second processing unit is used to perform calculations, encryption, or decryption on any data to be processed assigned to it, and obtain the calculation result. The second control unit is used to store the calculation result corresponding to any result to be processed into the second storage component.

12. The computing system according to claim 10, characterized in that, When the data to be processed is target data to be encrypted, the target data is the gradient information corresponding to the decision tree model calculated based on the feature values ​​and label data of the sample object provided by the data initiator. or, When the data to be processed is the ciphertext processing result to be decrypted, the data to be processed is specifically the ciphertext processing result to be decrypted obtained by calculating any feature provided by the data receiver, and the calculation result obtained by decrypting the ciphertext processing result is the gradient accumulation value; then the second host processing component is also used to determine the optimal split point of the decision tree model based on the gradient accumulation values ​​corresponding to multiple features.

13. A computing device, characterized in that, It includes a host processing component, a host storage component, and an acceleration device as described in any one of claims 1 to 7 or as described in claim 8 or 9.

14. An acceleration method, characterized in that, The device is applied to an acceleration device, which includes a first storage component and at least one first acceleration component; the first acceleration component includes a first control unit and a plurality of first computing units. The first storage component and the first host processing component are connected via a bus; the method includes: At least one bucketing result is obtained from multiple bucketing results; the multiple bucketing results are obtained by bucketing multiple encrypted data provided by the first host processing component. The at least one bucketing result is assigned to at least one first processing unit; the first processing unit is used to perform calculation processing on multiple ciphertext data in the bucketing result for any bucketing result assigned to it to obtain a ciphertext processing result; Obtain the encrypted processing result corresponding to any bucketing result generated by the first processing unit; The encrypted processing result is stored in the first storage component.