A privacy computing method, device, equipment and medium

By determining the target security algorithm and standard interface, and configuring the security algorithm container to adapt to the calling capacity, the interoperability problem between heterogeneous privacy computing devices is solved, and seamless interoperability between secure and controllable standardized services and systems is achieved, thereby improving the flexibility and security of privacy computing.

CN116127511BActive Publication Date: 2025-09-19CHINA UNIONPAY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310079815.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-01-29
Publication Date
2025-09-19
Estimated Expiration
2043-01-29

AI Technical Summary

Technical Problem

Different privacy computing devices cannot exchange information, resulting in computing islands and a lack of safe and controllable standardized security algorithm services, making it difficult to achieve interconnection and interoperability of heterogeneous privacy computing systems.

Method used

By determining the target security algorithm and standard interface, obtaining parameter information and performing privacy calculations, configuring the security algorithm container to adapt to the calling capacity, implementing secure and controllable standardized services, and achieving interconnection and interoperability between heterogeneous systems.

Benefits of technology

It provides safe and controllable standardized security algorithm services to ensure the security and accuracy of privacy computing, and realizes seamless interconnection between heterogeneous privacy computing systems, improving the flexibility and security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116127511B_ABST
    Figure CN116127511B_ABST
Patent Text Reader

Abstract

The present application discloses a privacy computing method, apparatus, device, and medium for providing a secure, controllable, and standardized security algorithm service for privacy computing. The present application determines the target security algorithm to be called based on the correspondence between the target scenario algorithm to be called, the pre-saved scenario algorithm, and the security algorithm; determines the target security algorithm standard interface corresponding to the target security algorithm based on the correspondence between the pre-saved security algorithm and the security algorithm standard interface, obtains the preset standard semantic information corresponding to the target security algorithm standard interface, and determines the parameter information required for the target security algorithm based on the standard parameter information carried in the preset standard semantic information; obtains the corresponding parameter value stored in the privacy computing device based on the parameter information, and performs privacy computing based on the parameter value and the target security algorithm, thereby providing a secure, controllable, and standardized security algorithm service for privacy computing and facilitating the interconnection and interoperability between heterogeneous privacy computing systems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data security technology, and in particular to a privacy computing method, apparatus, device and medium. Background Art

[0002] Privacy computing (Privacy compute or Privacy computing) refers to a collection of technologies that implement data analysis and calculations while protecting the data itself from external leakage, so as to achieve the goal of "available but invisible" data, and realize the transformation and release of data value while fully protecting data and privacy security.

[0003] With growing industry awareness of data protection and tightening privacy regulations, privacy computing has garnered widespread attention due to its "available, invisible" nature. Numerous technology vendors have launched industry-specific privacy computing products. While this proliferation of products has enriched market choices, it has also introduced new challenges. For example, privacy computing products from different technology vendors are often designed and implemented based on different system platforms. When privacy computing products from different system platforms are stored on separate privacy computing devices, information exchange between these products is often impossible, transforming "data silos" into "computing silos." Furthermore, even if the same privacy computing product is released by the same technology vendor, when stored on different privacy computing devices, information exchange between these products is often impossible, similarly transforming "data silos" into "computing silos."

[0004] Therefore, interoperability between privacy-focused algorithm products stored in different privacy computing devices has become a significant pain point in the industry. Security algorithms (also known as security operators), as the core component of privacy computing, are crucial for interoperability between different privacy computing devices (also known as heterogeneous privacy computing systems). How each privacy computing device should provide secure, controllable, and standardized security algorithm services is a pressing technical challenge. Effectively achieving interoperability between heterogeneous privacy computing systems is crucial. Summary of the Invention

[0005] This application provides a privacy computing method, apparatus, device, and medium for providing secure, controllable, and standardized security algorithm services for privacy computing, and helps achieve interconnection and interoperability between heterogeneous privacy computing systems.

[0006] In a first aspect, the present application provides a privacy-preserving computing method, the method comprising:

[0007] Determine the target security algorithm to be called in the current privacy computing task based on the target scenario algorithm to be called in the current privacy computing task and the pre-saved correspondence between the scenario algorithm and the security algorithm;

[0008] Determine the target security algorithm standard interface corresponding to the target security algorithm according to the pre-stored correspondence between the security algorithm and the security algorithm standard interface;

[0009] Obtain the preset standard semantic information corresponding to the target security algorithm standard interface, and determine the parameter information required for the target security algorithm based on the standard parameter information carried in the preset standard semantic information; based on the parameter information, obtain the corresponding parameter value stored in the privacy computing device, and perform privacy computing based on the parameter value and the target security algorithm.

[0010] In one possible implementation, before performing privacy calculation based on the parameter value and the target security algorithm, the method further includes:

[0011] Obtaining, based on traffic information of a scenario algorithm container carrying the target scenario algorithm, a call capacity required by the target scenario algorithm when calling the target security algorithm;

[0012] If it is determined that the processing capacity of the current security algorithm container carrying the target security algorithm is less than the call capacity, at least one security algorithm container is added, and the total processing capacity of the added security algorithm containers is not less than the call capacity.

[0013] In one possible implementation, obtaining a corresponding parameter value stored in a privacy computing device based on the target parameter information includes:

[0014] According to the correspondence between the parameter information carried in the preset standard semantic information and the privacy computing device identifier, the privacy computing device identifier corresponding to the parameter information is determined, and the corresponding parameter value is obtained from the privacy computing device corresponding to the privacy computing device identifier.

[0015] In one possible implementation, obtaining corresponding parameter values ​​stored in the privacy computing device based on the parameter information includes:

[0016] If the target security algorithm is a stateful algorithm, obtaining the corresponding encrypted parameter value stored in the privacy computing device based on the encryption algorithm carried in the stateful algorithm;

[0017] The performing privacy calculation based on the parameter value and the target security algorithm includes:

[0018] Privacy calculation is performed based on the encrypted parameter value and the target security algorithm.

[0019] In one possible implementation, the method further includes:

[0020] Obtain output result format information carried in the preset standard semantic information, and output the privacy calculation result based on the output result format information.

[0021] In one possible implementation, the method further includes:

[0022] Obtain the task identifier of the current privacy computing task, save the correspondence between the task identifier and at least one of the target scenario algorithm, the target security algorithm, and the privacy computing result, and when it is determined that the privacy computing result needs to be sent to other privacy computing devices, send the privacy computing result and the task identifier together to the other privacy computing devices.

[0023] In one possible implementation, obtaining the task identifier of the current privacy-preserving computing task includes:

[0024] If it is the privacy computing device of the initiator of the current privacy computing task, then create the task identifier;

[0025] Otherwise, the task identifier received from the privacy computing device to which the initiator of the current privacy computing task belongs is used as the task identifier of the current privacy computing task.

[0026] In a second aspect, the present application further provides a privacy-preserving computing device, comprising:

[0027] A first determination module is configured to determine a target security algorithm to be called in the current privacy computing task based on the target scenario algorithm to be called included in the current privacy computing task and a pre-saved correspondence between the scenario algorithm and the security algorithm;

[0028] A second determining module is used to determine the target security algorithm corresponding to the target security algorithm according to the pre-stored correspondence between the security algorithm and the security algorithm standard interface;

[0029] A computing module is used to obtain preset standard semantic information corresponding to the standard interface of the target security algorithm, determine the parameter information required for the target security algorithm based on the standard parameter information carried in the preset standard semantic information; based on the parameter information, obtain the corresponding parameter value stored in the privacy computing device, and perform privacy computing based on the parameter value and the target security algorithm.

[0030] In a possible implementation, the calculation module is further configured to obtain, based on traffic information of a scenario algorithm container carrying the target scenario algorithm, a call capacity required by the target scenario algorithm when calling the target security algorithm;

[0031] If it is determined that the processing capacity of the current security algorithm container carrying the target security algorithm is less than the call capacity, at least one security algorithm container is added, and the total processing capacity of the added security algorithm containers is not less than the call capacity.

[0032] In one possible implementation, the calculation module is specifically configured to determine the privacy computing device identifier corresponding to the parameter information based on the correspondence between the parameter information carried in the preset standard semantic information and the privacy computing device identifier, and obtain the corresponding parameter value from the privacy computing device corresponding to the privacy computing device identifier.

[0033] In one possible implementation, the computing module is specifically configured to, if the target security algorithm is a stateful algorithm, obtain a corresponding encrypted parameter value stored in the privacy computing device based on an encryption algorithm carried in the stateful algorithm;

[0034] Privacy calculation is performed based on the encrypted parameter value and the target security algorithm.

[0035] In a possible implementation, the calculation module is further configured to obtain output result format information carried in the preset standard semantic information, and output the privacy calculation result based on the output result format information.

[0036] In one possible implementation, the computing module is further configured to obtain a task identifier for the current privacy computing task, save a correspondence between the task identifier and at least one of the target scenario algorithm, the target security algorithm, and the privacy computing result, and, when determining that the privacy computing result needs to be sent to other privacy computing devices, send the privacy computing result and the task identifier together to the other privacy computing devices.

[0037] In one possible implementation, the computing module is specifically configured to create the task identifier if the computing module is the privacy-preserving computing device of the initiator of the current privacy-preserving computing task;

[0038] Otherwise, the task identifier received from the privacy computing device to which the initiator of the current privacy computing task belongs is used as the task identifier of the current privacy computing task.

[0039] In a third aspect, the present application provides an electronic device comprising a processor and a memory, wherein the memory stores program code, and when the program code is executed by the processor, the processor executes the steps of any one of the above-mentioned privacy computing methods.

[0040] In a fourth aspect, the present application provides a computer-readable storage medium comprising a program code. When the storage medium is run on an electronic device, the program code is used to enable the electronic device to execute the steps of any of the above-mentioned privacy computing methods.

[0041] Since this application can determine the target security algorithm to be called in the current privacy computing task based on the target scenario algorithm to be called contained in the current privacy computing task, and the correspondence between the pre-saved scenario algorithm and the security algorithm; determine the target security algorithm standard interface corresponding to the target security algorithm according to the correspondence between the pre-saved security algorithm and the security algorithm standard interface, this application can pre-configure unified standard semantic information for the target security algorithm standard interface, obtain the preset standard semantic information corresponding to the target security algorithm standard interface, and determine the parameter information required for the target security algorithm based on the standard parameter information carried in the preset standard semantic information; based on the parameter information, obtain the corresponding parameter value saved in the privacy computing device, and perform privacy computing based on the parameter value and the target security algorithm. Based on this, it can provide a safe, controllable and standardized security algorithm service for privacy computing, perform privacy computing safely and accurately, and help to achieve interconnection and interoperability between heterogeneous privacy computing systems. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] In order to more clearly illustrate the implementation methods in the embodiments of the present application or related technologies, the following is a brief introduction to the drawings required for use in the embodiments or related technology descriptions. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.

[0043] Figure 1 A schematic diagram of a first privacy computing process provided by some embodiments is shown;

[0044] Figure 2 A schematic diagram of a second privacy computing process provided by some embodiments is shown;

[0045] Figure 3 A schematic diagram of a third privacy computing process provided by some embodiments is shown;

[0046] Figure 4 A fourth privacy computing process diagram provided by some embodiments is shown;

[0047] Figure 5A fifth privacy computing process diagram provided by some embodiments is shown;

[0048] Figure 6 A sixth privacy computing process diagram provided by some embodiments is shown;

[0049] Figure 7 A seventh privacy computing process diagram provided by some embodiments is shown;

[0050] Figure 8 A schematic diagram of a privacy computing device provided by some embodiments is shown;

[0051] Figure 9 A schematic structural diagram of an electronic device provided by some embodiments is shown. DETAILED DESCRIPTION

[0052] In order to provide safe, controllable and standardized security algorithm services and perform privacy computing safely and accurately, this application provides a privacy computing method, device, equipment and medium.

[0053] In order to make the purpose and implementation of this application clearer, the exemplary implementation of this application will be clearly and completely described below in conjunction with the drawings in the exemplary embodiments of this application. Obviously, the described exemplary embodiments are only part of the embodiments of this application, not all of the embodiments.

[0054] It should be noted that the brief descriptions of terms in this application are only for the purpose of facilitating the understanding of the embodiments described below, and are not intended to limit the embodiments of this application. Unless otherwise specified, these terms should be understood according to their ordinary and usual meanings.

[0055] In the specification and claims of this application and the accompanying drawings, the terms "first," "second," "third," etc. are used to distinguish similar or similar objects or entities, and are not necessarily intended to limit a particular order or sequence, unless otherwise noted. It should be understood that the terms used in this manner are interchangeable under appropriate circumstances.

[0056] The terms "comprise," "include," and "have," and any variations thereof, are intended to cover but not exclude inclusion; for example, a product or device comprising a list of components is not necessarily limited to all the components expressly listed but may include other components not expressly listed or inherent to such product or device.

[0057] The term "module" refers to any known or later developed hardware, software, firmware, artificial intelligence, fuzzy logic, or combination of hardware and / or software code that is capable of performing the functionality associated with that element.

[0058] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some or all of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present application.

[0059] Example 1:

[0060] Figure 1 A schematic diagram of a first privacy computing process provided by some embodiments is shown, and the process includes the following steps:

[0061] S101: Determine the target security algorithm to be called in the current privacy computing task based on the target scenario algorithm to be called contained in the current privacy computing task and the pre-saved correspondence between the scenario algorithm and the security algorithm.

[0062] The privacy computing method provided in the embodiments of the present application is applied to an electronic device, which may be a PC, a mobile terminal, or a server. In one possible implementation, the electronic device may be a privacy computing device that stores any privacy algorithm.

[0063] See Figure 2 , Figure 2 A second privacy computing process diagram provided by some embodiments is shown. In one possible implementation, a sub-algorithm of any privacy algorithm is stored in the privacy computing device. Figure 2 As shown, it is assumed that the privacy algorithm involved in this privacy computing task is The privacy computing task requires the first privacy computing device of the privacy computing initiator P0 and the privacy computing participant P i The second privacy computing device to which it belongs jointly completes the calculation. For example, assuming that the sub-algorithm included in the first privacy computing device is The sub-algorithm included in the second privacy computing device is Among them, variables with dots, such as Indicates private data that needs to be kept confidential by other privacy computing devices, and represents a logically usable but invisible data; variables without dots, such as x and y, represent usable and visible data held by the privacy computing device itself. For example, The sub-algorithm indicates that the data of parameter x is the available and visible data held by the first privacy computing device to which the privacy computing initiator P0 belongs. The parameter data requires other privacy computing devices (privacy computing participants P iThe data is provided by the second privacy computing device to which the first privacy computing device belongs, and the data is usable but invisible to the first privacy computing device. The sub-algorithm represents the data of the y parameter as the privacy computing participant P i The available and visible data held by the second privacy computing device itself, The parameter data is data that needs to be provided by other privacy computing devices (the first privacy computing device to which the privacy computing initiator P0 belongs). This data is data that can be used but not visible by the second privacy computing device. There is no specific limitation on the sub-algorithms included, and they can be flexibly set according to needs. For example, It can describe the privacy algorithms involved in privacy computing tasks such as federated longitudinal logistic regression or hidden statistics.

[0064] In a possible implementation, the first privacy computing device to which the privacy computing initiator P0 belongs and the privacy computing participant P i The number of the second privacy computing devices can be one or more. Regardless of whether the number of the first privacy computing device and the second privacy computing device is one or more, each privacy computing device can use the privacy computing process provided in the embodiment of the present application to perform privacy computing, which will not be repeated here.

[0065] In one possible implementation, in order to increase the flexibility and accuracy of privacy computing, the sub-algorithms in the privacy algorithm can be decoupled into scenarios and security algorithms. If the privacy algorithm does not include a security algorithm but only includes a scenario algorithm, it can be considered that the data to be processed is being calculated in plain text without secure encryption protection; if the privacy algorithm includes a scenario algorithm and a security algorithm, it can be considered that the data to be processed is being calculated in privacy under the condition of building secure encryption protection under a cryptographic multi-party secure computing protocol. The scenario algorithm can be the horizontal and vertical LR, XGBoost algorithm, etc. in federated learning, and the security algorithm can refer to cryptographic algorithm operations, or multi-party secure computing, etc., which perform some kind of secret primitive operations on data. The scenario algorithm and security algorithm included in the privacy algorithm (sub-algorithm) can be flexibly selected according to needs, and this application does not make specific restrictions on this.

[0066] In one possible implementation, for a current privacy computing task, the privacy computing device may obtain the target scenario algorithm to be called corresponding to the current privacy computing task. The privacy computing device may determine the target security algorithm to be called in the current privacy computing task based on the target scenario algorithm and the pre-saved correspondence between the scenario algorithm and the security algorithm. Figure 2For example, assuming that for the current privacy computing task, the target scenario algorithm corresponding to the current privacy computing task in the first privacy computing device is According to the pre-saved correspondence between scenario algorithms and security algorithms, the first privacy computing device can determine the target security algorithm corresponding to the current privacy computing task as Assume that for the current privacy computing task, the target scenario algorithm corresponding to the current privacy computing task in the second privacy computing device is According to the pre-saved correspondence between the scenario algorithm and the security algorithm, the second privacy computing device can determine the target security algorithm corresponding to the current privacy computing task as against Figure 2 The specific application of the task identifier will be introduced in detail later, so I will not go into details here.

[0067] S102: Determine the target security algorithm standard interface corresponding to the target security algorithm according to the pre-stored correspondence between the security algorithm and the security algorithm standard interface.

[0068] In one possible implementation, to provide secure, controllable, and standardized security algorithm services and enable safe and accurate privacy computing, a dedicated security algorithm standard interface can be preconfigured for each security algorithm, allowing the corresponding security algorithm to be safely and accurately invoked based on the corresponding security algorithm standard interface. Specifically, after the privacy computing device determines the target security algorithm to be invoked, it can determine the target security algorithm standard interface corresponding to the target security algorithm based on the pre-stored correspondence between security algorithms and security algorithm standard interfaces.

[0069] S103: Obtain the preset standard semantic information corresponding to the target security algorithm standard interface, and determine the parameter information required for the target security algorithm based on the standard parameter information carried in the preset standard semantic information; based on the parameter information, obtain the corresponding parameter value stored in the privacy computing device, and perform privacy computing based on the parameter value and the target security algorithm.

[0070] In one possible implementation, to provide secure, controllable, and standardized security algorithm services and enable secure and accurate privacy-preserving computing, each security algorithm standard interface is pre-configured with standard semantic information. This standard semantic information may at least carry standard input parameter information configured for the security algorithm (referred to as standard parameter information for ease of description). Optionally, the pre-set standard semantic information may also carry a correspondence between each parameter information and a privacy-preserving computing device identifier. Based on this correspondence, the privacy-preserving computing device may be determined from which specific privacy-preserving computing device the corresponding parameter value should be obtained for each parameter information. For example, after obtaining the pre-set standard semantic information corresponding to the target security algorithm standard interface, the privacy-preserving computing device may determine the parameter information required for the target security algorithm based on the standard parameter information carried in the pre-set standard semantic information. Furthermore, based on the correspondence between the parameter information carried in the pre-set standard semantic information and the privacy-preserving computing device identifier, the privacy-preserving computing device identifier corresponding to the parameter information may be determined. The corresponding parameter value may then be obtained from the privacy-preserving computing device corresponding to the privacy-preserving computing device identifier, and privacy-preserving computing may be performed based on the parameter value and the target security algorithm. For ease of understanding, please refer to Table 1, which shows a schematic table of standard semantic information for a frequently used security algorithm provided in some embodiments.

[0071] Table 1

[0072]

[0073] Taking the expression of the target security algorithm corresponding to the privacy computing device as vds(x,y) as an example, when the target security algorithm is vds(x,y), the standard parameter information carried in the preset standard semantic information corresponding to the target security algorithm standard interface can be x parameters and y parameters. The correspondence between the parameter information carried in the preset standard semantic information and the privacy computing device identifier can be known based on this correspondence: the parameter value x vector of the input parameter x is obtained from the privacy computing device belonging to the privacy computing initiator P0, and the parameter value y vector of the input parameter y is obtained from the privacy computing device belonging to the privacy computing participant Pi, such as P1.

[0074] Optionally, the pre-set standard semantic information corresponding to the security algorithm standard interface may carry, in addition to standard parameter information, a description of the security algorithm's specific calculation process and output result format. For example, when the target security algorithm is vds(x, y), the security algorithm's specific calculation process may be to sum the corresponding dot products of the x and y vectors, returning a scalar; the output result format may be a plaintext scalar. After the privacy computing device obtains a result based on the specific calculation process in the target security algorithm, it may output the corresponding privacy calculation result in a different output format, using the plaintext scalar format.

[0075] Taking the expression of the target security algorithm corresponding to the privacy computing device as mvm(x,Y) as an example, when the target security algorithm is mvm(x,Y), the standard parameter information carried in the preset standard semantic information corresponding to the target security algorithm standard interface can be x parameters and Y parameters. The correspondence between the parameter information carried in the preset standard semantic information and the privacy computing device identifier can be known based on this correspondence: the parameter value x vector of the input parameter x is obtained from the privacy computing device belonging to the privacy computing initiator P0, and the parameter value Y matrix of the input parameter Y is obtained from the privacy computing device belonging to the privacy computing participant Pi, such as P1. Optionally, in addition to carrying the standard parameter information, the preset standard semantic information corresponding to the security algorithm standard interface can also carry a description of the specific calculation process of the security algorithm and output result format information. For example, when the target security algorithm is mvm(x,Y), the specific calculation process of the security algorithm can be x vector multiplied by Y matrix to return a matrix; the output result format can be a plaintext matrix. After obtaining a result based on the specific computational process of the target security algorithm, the privacy computing device can output the corresponding privacy calculation result in a different format based on the plaintext scalar. Standard semantic information for other security algorithms can be found in Table 1 and will not be detailed here.

[0076] Since this application can determine the target security algorithm to be called in the current privacy computing task based on the target scenario algorithm to be called contained in the current privacy computing task, and the correspondence between the pre-saved scenario algorithm and the security algorithm; determine the target security algorithm standard interface corresponding to the target security algorithm according to the correspondence between the pre-saved security algorithm and the security algorithm standard interface, this application can pre-configure unified standard semantic information for the target security algorithm standard interface, obtain the preset standard semantic information corresponding to the target security algorithm standard interface, and determine the parameter information required for the target security algorithm based on the standard parameter information carried in the preset standard semantic information; based on the parameter information, obtain the corresponding parameter value saved in the privacy computing device, and perform privacy computing based on the parameter value and the target security algorithm. Based on this, it can provide a safe, controllable and standardized security algorithm service for privacy computing, perform privacy computing safely and accurately, and help to achieve interconnection and interoperability between heterogeneous privacy computing systems.

[0077] In addition, compared with the highly strongly coupled relationship between the scenario algorithm and the security algorithm, since the scenario algorithm and the security algorithm of this application are loosely coupled, it is possible to freely select a trusted security algorithm for the scenario algorithm, thereby improving the flexibility and security of privacy computing.

[0078] In one possible implementation, in addition to configuring an exclusive security algorithm standard interface for each security algorithm that has preset standard semantic information, several derived security algorithm interfaces can also be reserved to reserve interface space for new security algorithms. If new security algorithms are introduced later, the corresponding security algorithm standard interface can be quickly configured for the introduced new security algorithms.

[0079] In one possible implementation, the target security algorithm can provide two service forms. When the target security algorithm is a stateful algorithm, a stateful algorithm service can be provided; when the target security algorithm is a stateless algorithm, a stateless algorithm service can be provided. The target security algorithm can be a stateful algorithm or a stateless algorithm, and this application does not make any specific restrictions on this. When the target security algorithm is a stateful algorithm, the security algorithm can access the ciphertext and the key, and can perform some additional encryption processing and expansion on the ciphertext data, such as adding noise. When a stateless algorithm is used, for all parties, the security algorithm does not access the ciphertext, and the ciphertext operations are also encapsulated inside the operator. The input and output of the operator are all plaintext. This structure makes it impossible to reversely calculate the other party's private data from the output result. The use of a stateless algorithm can ensure data security at the operator service level.

[0080] In one possible implementation, taking the target security algorithm as a stateful algorithm as an example, when performing privacy computing based on the target security algorithm, the computing process mainly includes three stages: the first stage is the data preparation stage. In the first stage, the privacy computing device can determine the privacy computing device identifier corresponding to the parameter information based on the correspondence between the parameter information carried in the preset standard semantic information corresponding to the target security algorithm standard interface and the privacy computing device identifier, and obtain the corresponding encrypted parameter value from the privacy computing device corresponding to the privacy computing device identifier. The second stage is the privacy computing stage. In the second stage, the privacy computing device can perform privacy computing based on the parameter value and the target security algorithm. The third stage is the calculation result output stage. In the third stage, the privacy computing device can obtain the final privacy computing result and output the corresponding calculation result according to the output result format information carried in the preset standard semantic information corresponding to the target security algorithm standard interface.

[0081] If the target security algorithm is a stateful algorithm, the encryption algorithm carried by the stateful algorithm can be used to obtain the corresponding encrypted parameter values ​​stored in the privacy computing device. Privacy computing can then be performed based on these encrypted parameter values ​​and the target security algorithm. The following uses secret sharing and homomorphic encryption in stateful algorithms as examples to illustrate the three stages of the privacy computing process.

[0082] When the target security algorithm is homomorphic encryption, in the first phase, the privacy computing device can first generate the corresponding key, determine the privacy computing device identifier corresponding to the parameter information based on the correspondence between the parameter information carried in the preset standard semantic information corresponding to the target security algorithm standard interface and the privacy computing device identifier, and obtain the corresponding parameter value encrypted based on the key from the privacy computing device corresponding to the privacy computing device identifier. In the second phase, the privacy computing phase, the privacy computing device can perform privacy computing based on the parameter value and the target security algorithm in a ciphertext state. In the third phase, the calculation result output phase, the privacy computing device can use the key generated in the first phase to decrypt the calculation result obtained in the second phase, and output the corresponding calculation result according to the output result format information carried in the preset standard semantic information corresponding to the target security algorithm standard interface.

[0083] When the target security algorithm is secret sharing, in the first phase, the privacy computing device can determine the privacy computing device identifier corresponding to the parameter information based on the correspondence between the parameter information carried in the preset standard semantic information corresponding to the target security algorithm standard interface and the privacy computing device identifier, and obtain the corresponding parameter value encrypted based on the key from the privacy computing device corresponding to the privacy computing device identifier in a secret sharing manner. In the second phase, the privacy computing stage, the privacy computing device can perform privacy computing based on the parameter value and the target security algorithm in the secret sharing state. In the third phase, the calculation result output stage, the privacy computing device can merge and restore the calculation results obtained in the second phase based on the secret sharing method corresponding to the first phase to obtain the final calculation result, and output the corresponding calculation result according to the output result format information carried in the preset standard semantic information corresponding to the target security algorithm standard interface.

[0084] The execution order of the first, second, and third phases of the stateful algorithm described above is merely illustrative. In actual computations, the various phases can be combined and executed based on the actual computational requirements of the security algorithm. For example, the first and second phases can be combined, or the second and third phases can be combined, or the first phase can be called multiple times, with the second phase utilizing multiple first-phase processing results. This flexible combination and execution makes stateful algorithm services more flexible than stateless algorithm services. However, it also results in the security algorithm protocol being intruded by the scenario algorithm protocol, making it impossible to ensure security of the security algorithm solely at the service level. Instead, security must be ensured in conjunction with the scenario algorithm protocol. With stateless algorithms, the security algorithm does not access ciphertext, and ciphertext operations are encapsulated within the operator, ensuring data security at the operator service level.

[0085] Based on the above embodiments, in one possible implementation, in order to flexibly and accurately provide secure, controllable, and standardized security algorithm services, before performing privacy calculations based on parameter values ​​and the target security algorithm, the call capacity required by the target scenario algorithm when calling the target security algorithm can also be obtained based on the traffic information of the scenario algorithm container that carries the target scenario algorithm. For example, see Figure 3 , Figure 3 A third privacy computing process diagram provided by some embodiments is shown, such as Figure 3 As shown, the traffic information of the scenario algorithm container can be obtained based on the sidecar container embedded in the scenario algorithm container LR, and the call capacity required by the target scenario algorithm when calling the target security algorithm can be obtained. At the same time, the traffic information of the security algorithm container can also be obtained based on the sidecar container embedded in the security algorithm container HE that carries the target security algorithm, and the processing capacity of the security algorithm container can be obtained.

[0086] In one possible implementation, after obtaining the calling capacity required by the target scenario algorithm when calling the target security algorithm, the privacy computing device can determine whether the processing capacity of the security algorithm container HE currently carrying the target security algorithm is not less than the calling capacity. If the processing capacity of the security algorithm container HE currently carrying the target security algorithm is not less than the calling capacity, the target security algorithm can be directly run based on the security algorithm container currently carrying the target security algorithm, and the above-mentioned steps of performing privacy calculation based on parameter values ​​and the target security algorithm can be performed.

[0087] In one possible implementation, see again Figure 3 If the processing capacity of the security algorithm container HE currently carrying the target security algorithm is less than the calling capacity, the information that the processing capacity is less than the calling capacity can be sent to the microservice management platform in the privacy computing device, etc., and the security algorithm container can be scheduled based on the microservice management platform. For the target security algorithm, at least one security algorithm container can be added so that the total processing capacity of each added security algorithm container is not less than the calling capacity. The target security algorithm can be run based on each added security algorithm container, thereby performing the above-mentioned steps of privacy calculation based on parameter values ​​and target security algorithm.

[0088] In one possible implementation, when the total processing capacity of the security algorithm containers currently carrying the target security algorithm is greater than the calling capacity, it is also possible to try to see whether several security algorithm containers can be reduced based on the microservice management platform, and determine whether the total processing container of the remaining security algorithm containers is not less than the calling capacity after reducing several security algorithm containers. If the total processing container of the remaining security algorithm containers is not less than the calling capacity, then several security algorithm containers can be reduced.

[0089] Since this application can flexibly and diversely configure the security algorithm container based on the relationship between the calling capacity and the processing capacity, it improves the horizontal elastic scaling capability of the security algorithm container and improves the high availability of the security algorithm container.

[0090] In addition, the embodiment of the present application provides a process for flexibly and diversely configuring security algorithm containers based on the size relationship between the calling capacity and the processing capacity. This process can be used when the target security algorithm is a stateful algorithm or when the target security algorithm is a stateless algorithm. This application does not make specific limitations on this.

[0091] In one possible implementation, when the sidecar container embedded in a security algorithm container identifies that the corresponding security algorithm container has a security defect, the security defect information can be reported to the microservice management platform, and a flow control policy can be issued based on the microservice management platform. The flow control policy can carry the identification information of the security algorithm container with the security defect, and the use of the security algorithm container can be temporarily prohibited; after the sidecar container embedded in the security algorithm container identifies that the defect of the security algorithm container has been successfully eliminated and repaired, the information of the successful repair can be reported to the microservice management platform, and the microservice management platform can issue a lifting information, allowing the use of the security algorithm container again, allowing the security algorithm container to participate in privacy computing, etc.

[0092] In one possible implementation, when multiple privacy computing devices are interconnected to perform privacy computing, each privacy computing device can obtain a task ID for the current privacy computing task, store the corresponding relationship between the task ID and the target scenario algorithm, target security algorithm, privacy computing result, etc., and, when determining that the privacy computing result needs to be sent to other privacy computing devices, send the privacy computing result and the task ID to the other privacy computing devices. After receiving the task ID and privacy computing result, the other privacy computing devices can further perform calculations based on the privacy computing result to generate their own privacy computing results. The other privacy computing devices can also store the corresponding relationship between the task ID and their privacy computing results, target scenario algorithm, and target security algorithm. Because the same task ID can be used to label the target scenario algorithm, target security algorithm, privacy computing result, etc. involved in the privacy computing task on different privacy computing devices, different privacy computing tasks can be distinguished based on the task ID, allowing each privacy computing task to be completed quickly and accurately.

[0093] Compared with the privacy algorithm that contains highly coupled scenario algorithms and security algorithms, since this application can decouple the privacy algorithm into scenario algorithms and security algorithms, it allows the free selection of trusted security algorithms for the privacy algorithm, thereby improving the flexibility and security of the privacy algorithm.

[0094] In one possible implementation, the task identifier for the current privacy-preserving computing task may be created by the privacy-preserving computing device of the initiator of the current privacy-preserving computing task. After creating the task identifier, the initiator can send it to the privacy-preserving computing devices of the participating parties through an algorithmic call. The privacy-preserving computing devices of the participating parties can use the task identifier received from the privacy-preserving computing device of the initiator as the task identifier for the current privacy-preserving computing task. For ease of understanding, the privacy-preserving computing process provided in this application is described below using a specific example.

[0095] Please refer again Figure 2 , the privacy computing device to which the initiator P0 belongs starts the algorithm every time Specifically, for the current privacy computing task, the privacy computing device to which the initiator P0 belongs starts (calls) the scenario algorithm. When creating a unique task ID corresponding to the current privacy computing task, the privacy computing device to which the initiator P0 belongs (for the convenience of description, referred to as the first privacy computing device) can save the task ID and the scenario algorithm. Security Algorithm In addition, after the first privacy computing device obtains the privacy computing result (for the convenience of description, referred to as the first computing data) after performing the corresponding calculation on the data to be processed, the first privacy computing device can also save the corresponding relationship between the task identifier and the first computing data. If it is determined that the first computing data needs to be recalculated based on the sub-algorithm stored in the privacy computing device (second privacy computing device) to which the participant Pi belongs, the first privacy computing device can send the task identifier together with the first computing data to the second privacy computing device. The second privacy computing device can receive the task identifier and save the task identifier and the scenario algorithm. Security Algorithm In addition, the second privacy computing device can recalculate the first computing data to obtain a privacy computing result (for the convenience of description, referred to as the second computing data). After obtaining the second computing data, the second privacy computing device can also save the correspondence between the task identifier and the second computing data.

[0096] For ease of understanding, the privacy computing process provided by this application is described below through a specific embodiment. Figure 4 , Figure 4A fourth privacy computing process diagram provided by some embodiments is shown, which includes the following steps:

[0097] S401: Determine the target security algorithm to be called in the current privacy computing task based on the target scenario algorithm to be called contained in the current privacy computing task and the pre-saved correspondence between the scenario algorithm and the security algorithm.

[0098] S402: Determine a target security algorithm standard interface corresponding to a target security algorithm according to a pre-stored correspondence between security algorithms and security algorithm standard interfaces.

[0099] S403: Obtaining the preset standard semantic information corresponding to the target security algorithm standard interface, and determining the parameter information required for the target security algorithm based on the standard parameter information contained in the preset standard semantic information; based on this parameter information, obtaining the corresponding parameter values ​​stored in the privacy computing device. Simultaneously, based on the traffic information of the scenario algorithm container carrying the target scenario algorithm, obtaining the call capacity required by the target scenario algorithm when calling the target security algorithm; if it is determined that the processing capacity of the current security algorithm container carrying the target security algorithm is less than the call capacity, then adding at least one security algorithm container, such that the total processing capacity of each of the added security algorithm containers is not less than the call capacity.

[0100] S404: Perform privacy calculation based on parameter values ​​and target security algorithm.

[0101] For ease of understanding, the privacy computing process provided by this application is described below through a specific embodiment. Figure 5 , Figure 5 A fifth privacy computing process diagram provided by some embodiments is shown, which includes the following steps:

[0102] S501: Determine the target security algorithm to be called in the current privacy computing task based on the target scenario algorithm to be called contained in the current privacy computing task and the pre-saved correspondence between the scenario algorithm and the security algorithm.

[0103] S502: Determine the target security algorithm standard interface corresponding to the target security algorithm according to the pre-stored correspondence between the security algorithm and the security algorithm standard interface.

[0104] S503: Obtain the preset standard semantic information corresponding to the target security algorithm standard interface, and determine the parameter information required for the target security algorithm based on the standard parameter information carried in the preset standard semantic information; determine the privacy computing device identifier corresponding to the parameter information based on the correspondence between the parameter information carried in the preset standard semantic information and the privacy computing device identifier, and obtain the corresponding parameter value from the privacy computing device corresponding to the privacy computing device identifier. Based on the parameter information, obtain the corresponding parameter value stored in the privacy computing device. At the same time, based on the traffic information of the scenario algorithm container carrying the target scenario algorithm, obtain the call capacity required by the target scenario algorithm when calling the target security algorithm; if it is determined that the processing capacity of the current security algorithm container carrying the target security algorithm is less than the call capacity, add at least one security algorithm container, and the total processing capacity of each added security algorithm container is not less than the call capacity.

[0105] S504: Perform privacy calculation based on parameter values ​​and target security algorithm.

[0106] S505: Obtain output result format information carried in the preset standard semantic information, and output the privacy calculation result based on the output result format information.

[0107] For ease of understanding, the privacy computing process provided by this application is described below through a specific embodiment. Figure 6 , Figure 6 A sixth privacy computing process diagram provided by some embodiments is shown, which includes the following steps:

[0108] S601: Determine the target security algorithm to be called in the current privacy computing task based on the target scenario algorithm to be called contained in the current privacy computing task and the pre-saved correspondence between the scenario algorithm and the security algorithm.

[0109] S602: Determine a target security algorithm standard interface corresponding to a target security algorithm according to a pre-stored correspondence between security algorithms and security algorithm standard interfaces.

[0110] S603: Obtain the preset standard semantic information corresponding to the target security algorithm standard interface, and determine the parameter information required for the target security algorithm based on the standard parameter information carried in the preset standard semantic information; determine the privacy computing device identifier corresponding to the parameter information based on the correspondence between the parameter information carried in the preset standard semantic information and the privacy computing device identifier; if the target security algorithm is a stateful algorithm, obtain the corresponding encrypted parameter value from the privacy computing device corresponding to the privacy computing device identifier based on the encryption algorithm carried in the stateful algorithm; and obtain the corresponding parameter value stored in the privacy computing device based on the parameter information. At the same time, based on the traffic information of the scenario algorithm container carrying the target scenario algorithm, obtain the call capacity required by the target scenario algorithm when calling the target security algorithm; if it is determined that the processing capacity of the current security algorithm container carrying the target security algorithm is less than the call capacity, add at least one security algorithm container, and the total processing capacity of each added security algorithm container is not less than the call capacity.

[0111] S604: Perform privacy calculation based on parameter values ​​and target security algorithm.

[0112] S605: Obtain output result format information carried in the preset standard semantic information, and output the privacy calculation result based on the output result format information.

[0113] For ease of understanding, the privacy computing process provided by this application is described below through a specific embodiment. Figure 7 , Figure 7 A seventh privacy computing process diagram provided by some embodiments is shown, which includes the following steps:

[0114] S701: Determine the target security algorithm to be called in the current privacy computing task based on the target scenario algorithm to be called contained in the current privacy computing task and the pre-saved correspondence between the scenario algorithm and the security algorithm.

[0115] S702: Determine the target security algorithm corresponding to the target security algorithm according to the pre-stored correspondence between the security algorithm and the security algorithm standard interface.

[0116] S703: Obtain the preset standard semantic information corresponding to the target security algorithm standard interface, and determine the parameter information required for the target security algorithm based on the standard parameter information carried in the preset standard semantic information; determine the privacy computing device identifier corresponding to the parameter information based on the correspondence between the parameter information carried in the preset standard semantic information and the privacy computing device identifier, and obtain the corresponding parameter value from the privacy computing device corresponding to the privacy computing device identifier. Based on the parameter information, obtain the corresponding parameter value stored in the privacy computing device. At the same time, based on the traffic information of the scenario algorithm container carrying the target scenario algorithm, obtain the call capacity required by the target scenario algorithm when calling the target security algorithm; if it is determined that the processing capacity of the current security algorithm container carrying the target security algorithm is less than the call capacity, add at least one security algorithm container, and the total processing capacity of each added security algorithm container is not less than the call capacity.

[0117] S704: Perform privacy calculation based on parameter values ​​and target security algorithm.

[0118] S705: Obtain output result format information carried in the preset standard semantic information, and output the privacy calculation result based on the output result format information.

[0119] S706: Obtain the task identifier of the current privacy computing task, save the correspondence between the task identifier and at least one of the target scenario algorithm, the target security algorithm, and the privacy computing result, and when it is determined that the privacy computing result needs to be sent to other privacy computing devices, send the privacy computing result and the task identifier to the other privacy computing devices together.

[0120] Example 2:

[0121] Based on the same technical concept, this application also provides a privacy computing device, see Figure 8 , Figure 8 A schematic diagram of a privacy-preserving computing device provided by some embodiments is shown, the device comprising:

[0122] A first determination module 81 is configured to determine a target security algorithm to be called in the current privacy computing task based on the target scenario algorithm to be called in the current privacy computing task and a pre-stored correspondence between scenario algorithms and security algorithms;

[0123] A second determining module 82 is configured to determine a target security algorithm standard interface corresponding to the target security algorithm based on a pre-stored correspondence between security algorithms and security algorithm standard interfaces;

[0124] The calculation module 83 is used to obtain the preset standard semantic information corresponding to the standard interface of the target security algorithm, and determine the parameter information required for the target security algorithm based on the standard parameter information carried in the preset standard semantic information; based on the parameter information, obtain the corresponding parameter value stored in the privacy computing device, and perform privacy computing based on the parameter value and the target security algorithm.

[0125] In a possible implementation, the calculation module 83 is further configured to obtain, based on traffic information of the scenario algorithm container carrying the target scenario algorithm, the call capacity required by the target scenario algorithm when calling the target security algorithm;

[0126] If it is determined that the processing capacity of the current security algorithm container carrying the target security algorithm is less than the call capacity, at least one security algorithm container is added, and the total processing capacity of the added security algorithm containers is not less than the call capacity.

[0127] In one possible implementation, the calculation module 83 is specifically configured to determine the privacy computing device identifier corresponding to the parameter information based on the correspondence between the parameter information carried in the preset standard semantic information and the privacy computing device identifier, and obtain the corresponding parameter value from the privacy computing device corresponding to the privacy computing device identifier.

[0128] In one possible implementation, the calculation module 83 is specifically configured to, if the target security algorithm is a stateful algorithm, obtain a corresponding encrypted parameter value stored in the privacy computing device based on the encryption algorithm carried in the stateful algorithm;

[0129] Privacy calculation is performed based on the encrypted parameter value and the target security algorithm.

[0130] In a possible implementation, the calculation module 83 is further configured to obtain output result format information carried in the preset standard semantic information, and output the privacy calculation result based on the output result format information.

[0131] In one possible implementation, the computing module 83 is further configured to obtain a task identifier for the current privacy computing task, save a correspondence between the task identifier and at least one of the target scenario algorithm, the target security algorithm, and the privacy computing result, and, when determining that the privacy computing result needs to be sent to other privacy computing devices, send the privacy computing result and the task identifier together to the other privacy computing devices.

[0132] In one possible implementation, the computing module 83 is specifically configured to create the task identifier if the computing module is the privacy-preserving computing device of the initiator of the current privacy-preserving computing task;

[0133] Otherwise, the task identifier received from the privacy computing device to which the initiator of the current privacy computing task belongs is used as the task identifier of the current privacy computing task.

[0134] Example 3:

[0135] Based on the same technical concept, the present application also provides an electronic device, Figure 9 A schematic diagram of the structure of an electronic device provided by some embodiments is shown. Figure 9 As shown, it includes: a processor 91, a communication interface 92, a memory 93 and a communication bus 94, wherein the processor 91, the communication interface 92, and the memory 93 communicate with each other through the communication bus 94;

[0136] The memory 93 stores a computer program. When the program is executed by the processor 91, the processor 91 performs the following steps:

[0137] Determine the target security algorithm to be called in the current privacy computing task based on the target scenario algorithm to be called in the current privacy computing task and the pre-saved correspondence between the scenario algorithm and the security algorithm;

[0138] Determine the target security algorithm standard interface corresponding to the target security algorithm according to the pre-stored correspondence between the security algorithm and the security algorithm standard interface;

[0139] Obtain the preset standard semantic information corresponding to the target security algorithm standard interface, and determine the parameter information required for the target security algorithm based on the standard parameter information carried in the preset standard semantic information; based on the parameter information, obtain the corresponding parameter value stored in the privacy computing device, and perform privacy computing based on the parameter value and the target security algorithm.

[0140] In a possible implementation, the processor 91 is further configured to obtain, based on traffic information of a scenario algorithm container carrying the target scenario algorithm, a call capacity required by the target scenario algorithm when calling the target security algorithm;

[0141] If it is determined that the processing capacity of the current security algorithm container carrying the target security algorithm is less than the call capacity, at least one security algorithm container is added, and the total processing capacity of the added security algorithm containers is not less than the call capacity.

[0142] In one possible implementation, the processor 91 is specifically configured to determine the privacy computing device identifier corresponding to the parameter information based on the correspondence between the parameter information carried in the preset standard semantic information and the privacy computing device identifier, and obtain a corresponding parameter value from the privacy computing device corresponding to the privacy computing device identifier.

[0143] In one possible implementation, the processor 91 is specifically configured to, if the target security algorithm is a stateful algorithm, obtain, based on the encryption algorithm carried in the stateful algorithm, a corresponding encrypted parameter value stored in the privacy computing device;

[0144] Privacy calculation is performed based on the encrypted parameter value and the target security algorithm.

[0145] In a possible implementation, the processor 91 is further configured to obtain output result format information carried in the preset standard semantic information, and output the privacy calculation result based on the output result format information.

[0146] In one possible implementation, the processor 91 is further configured to obtain a task identifier for the current privacy computing task, save a correspondence between the task identifier and at least one of the target scenario algorithm, the target security algorithm, and the privacy computing result, and, when determining that the privacy computing result needs to be sent to other privacy computing devices, send the privacy computing result and the task identifier together to the other privacy computing devices.

[0147] In one possible implementation, the processor 91 is specifically configured to create the task identifier if the processor 91 is the privacy-preserving computing device of the initiator of the current privacy-preserving computing task;

[0148] Otherwise, the task identifier received from the privacy computing device to which the initiator of the current privacy computing task belongs is used as the task identifier of the current privacy computing task.

[0149] Since the principle of solving the problem by the above-mentioned electronic device is similar to that of the privacy computing method, the implementation of the above-mentioned electronic device can refer to the implementation of the method, and the repeated parts will not be repeated.

[0150] The communication bus mentioned in the electronic device mentioned above may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, only one thick line is used in the figure, but this does not mean that there is only one bus or only one type of bus.

[0151] The communication interface 92 is used for communication between the electronic device and other devices.

[0152] The memory may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk memory. Alternatively, the memory may be at least one storage device located away from the processor.

[0153] The above-mentioned processor can be a general-purpose processor, including a central processing unit, a network processor (NP), etc.; it can also be a digital signal processing processor (DSP), an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, etc.

[0154] Example 4:

[0155] Based on the same technical concept, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program executable by an electronic device. When the program is executed on the electronic device, the electronic device implements the following steps:

[0156] Determine the target security algorithm to be called in the current privacy computing task based on the target scenario algorithm to be called in the current privacy computing task and the pre-saved correspondence between the scenario algorithm and the security algorithm;

[0157] Determine the target security algorithm standard interface corresponding to the target security algorithm according to the pre-stored correspondence between the security algorithm and the security algorithm standard interface;

[0158] Obtain the preset standard semantic information corresponding to the target security algorithm standard interface, and determine the parameter information required for the target security algorithm based on the standard parameter information carried in the preset standard semantic information; based on the parameter information, obtain the corresponding parameter value stored in the privacy computing device, and perform privacy computing based on the parameter value and the target security algorithm.

[0159] In one possible implementation, before performing privacy calculation based on the parameter value and the target security algorithm, the method further includes:

[0160] Obtaining, based on traffic information of a scenario algorithm container carrying the target scenario algorithm, a call capacity required by the target scenario algorithm when calling the target security algorithm;

[0161] If it is determined that the processing capacity of the current security algorithm container carrying the target security algorithm is less than the call capacity, at least one security algorithm container is added, and the total processing capacity of the added security algorithm containers is not less than the call capacity.

[0162] In one possible implementation, obtaining a corresponding parameter value stored in a privacy computing device based on the target parameter information includes:

[0163] According to the correspondence between the parameter information carried in the preset standard semantic information and the privacy computing device identifier, the privacy computing device identifier corresponding to the parameter information is determined, and the corresponding parameter value is obtained from the privacy computing device corresponding to the privacy computing device identifier.

[0164] In one possible implementation, obtaining corresponding parameter values ​​stored in the privacy computing device based on the parameter information includes:

[0165] If the target security algorithm is a stateful algorithm, obtaining the corresponding encrypted parameter value stored in the privacy computing device based on the encryption algorithm carried in the stateful algorithm;

[0166] The performing privacy calculation based on the parameter value and the target security algorithm includes:

[0167] Privacy calculation is performed based on the encrypted parameter value and the target security algorithm.

[0168] In one possible implementation, the method further includes:

[0169] Obtain output result format information carried in the preset standard semantic information, and output the privacy calculation result based on the output result format information.

[0170] In one possible implementation, the method further includes:

[0171] Obtain the task identifier of the current privacy computing task, save the correspondence between the task identifier and at least one of the target scenario algorithm, the target security algorithm, and the privacy computing result, and when it is determined that the privacy computing result needs to be sent to other privacy computing devices, send the privacy computing result and the task identifier together to the other privacy computing devices.

[0172] In one possible implementation, obtaining the task identifier of the current privacy-preserving computing task includes:

[0173] If it is the privacy computing device of the initiator of the current privacy computing task, then create the task identifier;

[0174] Otherwise, the task identifier received from the privacy computing device to which the initiator of the current privacy computing task belongs is used as the task identifier of the current privacy computing task.

[0175] Since the principle of solving the problem by the above-mentioned computer-readable storage medium is similar to that of the privacy computing method, the implementation of the above-mentioned computer-readable storage medium can refer to the implementation of the method, and the repeated parts will not be repeated.

[0176] The above-mentioned computer-readable storage medium can be any available medium or data storage device that can be accessed by the processor in the electronic device, including but not limited to magnetic storage such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), etc., optical storage such as CDs, DVDs, BDs, HVDs, etc., and semiconductor storage such as ROMs, EPROMs, EEPROMs, non-volatile memories (NANDFLASH), solid-state drives (SSDs), etc.

[0177] Based on the same technical concept, on the basis of the above embodiments, the present application provides a computer program product, which includes: computer program code, when the computer program code is run on a computer, it enables the computer to execute the steps of any of the privacy computing methods described above.

[0178] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0179] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0180] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0181] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.

[0182] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.

Claims

1. A privacy computing method, characterized in that: The method comprises: Determine the target security algorithm to be called in the current privacy computing task based on the target scenario algorithm to be called in the current privacy computing task and the pre-saved correspondence between the scenario algorithm and the security algorithm; Determine the target security algorithm standard interface corresponding to the target security algorithm according to the pre-stored correspondence between the security algorithm and the security algorithm standard interface; Obtain the preset standard semantic information corresponding to the target security algorithm standard interface, and determine the parameter information required for the target security algorithm based on the standard parameter information carried in the preset standard semantic information; based on the parameter information, obtain the corresponding parameter value stored in the privacy computing device, and perform privacy computing based on the parameter value and the target security algorithm.

2. The method according to claim 1, characterized in that Before performing privacy calculation based on the parameter value and the target security algorithm, the method further includes: Obtaining, based on traffic information of a scenario algorithm container carrying the target scenario algorithm, a call capacity required by the target scenario algorithm when calling the target security algorithm; If it is determined that the processing capacity of the current security algorithm container carrying the target security algorithm is less than the call capacity, at least one security algorithm container is added, and the total processing capacity of the added security algorithm containers is not less than the call capacity.

3. The method according to claim 1, characterized in that The obtaining, based on the parameter information, corresponding parameter values ​​stored in the privacy computing device includes: According to the correspondence between the parameter information carried in the preset standard semantic information and the privacy computing device identifier, the privacy computing device identifier corresponding to the parameter information is determined, and the corresponding parameter value is obtained from the privacy computing device corresponding to the privacy computing device identifier.

4. The method according to claim 1, wherein The obtaining, based on the parameter information, corresponding parameter values ​​stored in the privacy computing device includes: If the target security algorithm is a stateful algorithm, obtaining the corresponding encrypted parameter value stored in the privacy computing device based on the encryption algorithm carried in the stateful algorithm; The performing privacy calculation based on the parameter value and the target security algorithm includes: Privacy calculation is performed based on the encrypted parameter value and the target security algorithm.

5. The method according to any one of claims 1 to 4, characterized in that: The method further comprises: Obtain output result format information carried in the preset standard semantic information, and output the privacy calculation result based on the output result format information.

6. The method according to claim 5, characterized in that The method further comprises: Obtain the task identifier of the current privacy computing task, save the correspondence between the task identifier and at least one of the target scenario algorithm, the target security algorithm, and the privacy computing result, and when it is determined that the privacy computing result needs to be sent to other privacy computing devices, send the privacy computing result and the task identifier together to the other privacy computing devices.

7. The method according to claim 6, characterized in that Obtaining the task identifier of the current privacy computing task includes: If it is the privacy computing device of the initiator of the current privacy computing task, then create the task identifier; Otherwise, the task identifier received from the privacy computing device to which the initiator of the current privacy computing task belongs is used as the task identifier of the current privacy computing task.

8. A privacy computing device, characterized in that: The device comprises: A first determination module is configured to determine a target security algorithm to be called in the current privacy computing task based on the target scenario algorithm to be called included in the current privacy computing task and a pre-saved correspondence between the scenario algorithm and the security algorithm; A second determining module is used to determine the target security algorithm corresponding to the target security algorithm according to the pre-stored correspondence between the security algorithm and the security algorithm standard interface; A computing module is used to obtain preset standard semantic information corresponding to the standard interface of the target security algorithm, determine the parameter information required for the target security algorithm based on the standard parameter information carried in the preset standard semantic information; based on the parameter information, obtain the corresponding parameter value stored in the privacy computing device, and perform privacy computing based on the parameter value and the target security algorithm.

9. The device according to claim 8, characterized in that The calculation module is further configured to obtain, based on traffic information of the scenario algorithm container carrying the target scenario algorithm, the call capacity required by the target scenario algorithm when calling the target security algorithm; If it is determined that the processing capacity of the current security algorithm container carrying the target security algorithm is less than the call capacity, at least one security algorithm container is added, and the total processing capacity of the added security algorithm containers is not less than the call capacity.

10. The device according to claim 8, characterized in that The calculation module is specifically configured to determine the privacy computing device identifier corresponding to the parameter information based on the correspondence between the parameter information carried in the preset standard semantic information and the privacy computing device identifier, and obtain the corresponding parameter value from the privacy computing device corresponding to the privacy computing device identifier.

11. The device according to claim 8, characterized in that The computing module is specifically configured to obtain, if the target security algorithm is a stateful algorithm, a corresponding encrypted parameter value stored in the privacy computing device based on the encryption algorithm carried in the stateful algorithm; Privacy calculation is performed based on the encrypted parameter value and the target security algorithm.

12. The device according to any one of claims 8 to 11, characterized in that: The calculation module is further used to obtain the output result format information carried in the preset standard semantic information, and output the privacy calculation result based on the output result format information.

13. The device according to claim 12, characterized in that The computing module is further configured to obtain the task identifier of the current privacy computing task, save the correspondence between the task identifier and at least one of the target scenario algorithm, the target security algorithm, and the privacy computing result, and, when determining that the privacy computing result needs to be sent to other privacy computing devices, send the privacy computing result and the task identifier together to the other privacy computing devices.

14. The device according to claim 13, characterized in that The computing module is specifically configured to create the task identifier if the computing module is the privacy-preserving computing device of the initiator of the current privacy-preserving computing task; Otherwise, the task identifier received from the privacy computing device to which the initiator of the current privacy computing task belongs is used as the task identifier of the current privacy computing task.

15. An electronic device, characterized in that: It includes a processor and a memory, wherein the memory stores program code, and when the program code is executed by the processor, the processor executes the steps of the privacy computing method described in any one of claims 1-7.

16. A computer-readable storage medium, characterized in that It includes program code, and when the storage medium runs on an electronic device, the program code is used to enable the electronic device to execute the steps of the privacy computing method described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Privacy calculation method and device and electronic equipment

    CN113326523A

  • Private data processing method, device and system based on block chain

    CN113722753A