A privacy computing method, apparatus, device and medium

By decoupling privacy algorithms from algorithm engines and platforms and running algorithm images in a containerized manner, the interoperability problem between different privacy computing platforms is solved, enabling flexible privacy computing interoperability.

CN117113441BActive Publication Date: 2026-03-17CHINA UNIONPAY
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-08-28
Publication Date
2026-03-17

AI Technical Summary

Technical Problem

Privacy algorithms designed for different privacy computing platforms cannot communicate with each other, leading to the problem of computing silos.

Method used

By separating privacy algorithms from algorithm engines and privacy computing platforms, and creating algorithm images for containerized operation, the pluggable and interoperable nature of privacy algorithms can be achieved.

Benefits of technology

It enables interoperability between privacy algorithms designed on different privacy computing platforms, improving the flexibility and compatibility of privacy computing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117113441B_ABST
    Figure CN117113441B_ABST
Patent Text Reader

Abstract

The application discloses a privacy calculation method, device, equipment and medium, which can use a privacy algorithm designed by other privacy calculation platforms to perform privacy calculation, so that privacy algorithms designed based on different privacy calculation platforms can interconnect and intercommunicate. Since the application can identify an algorithm identifier carried in a privacy calculation task running instruction when the privacy calculation task running instruction is received, if it is identified that the privacy algorithm corresponding to the algorithm identifier is a privacy algorithm designed based on other privacy calculation platforms, an algorithm image of the algorithm identifier is obtained from a pre-established image warehouse in a containerized manner, and corresponding privacy calculation is performed based on the privacy algorithm in the algorithm image, based on which, the purpose that privacy algorithms designed based on different privacy calculation platforms can interconnect and intercommunicate can be achieved by using a privacy algorithm designed by other privacy calculation platforms to perform privacy calculation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data security technology, and in particular to a privacy computing method, apparatus, device and medium. Background Technology

[0002] Privacy computing refers to a set of technologies that enable data analysis and computation while protecting the data itself from being disclosed to the outside world. This achieves the goal of making the data "usable but not visible," and realizes the transformation and release of data value while fully protecting data and privacy.

[0003] With increasing awareness of data protection and stricter privacy regulations, privacy computing has garnered widespread attention due to its "usable but invisible" characteristics. Numerous technology vendors have launched their own industry-specific privacy computing algorithms (referred to as privacy algorithms). While this abundance of algorithms has enriched market choices, it has also brought new challenges. For example, privacy algorithms from different vendors are typically designed and implemented on different privacy computing platforms. These algorithms often cannot exchange information, turning "data silos" into "computing silos."

[0004] Therefore, the interoperability between privacy algorithms designed on different privacy computing platforms has become a major pain point in the industry. How to use privacy algorithms designed on other privacy computing platforms for privacy computing, enabling interoperability between these algorithms, is a pressing technical problem that needs to be solved. Summary of the Invention

[0005] This application provides a privacy computing method, apparatus, device, and medium for performing privacy computing using privacy algorithms designed on other privacy computing platforms, enabling interconnection and interoperability between privacy algorithms designed on different privacy computing platforms.

[0006] In a first aspect, this application provides a privacy computing method, the method comprising:

[0007] Receive a privacy computing task execution instruction and identify the algorithm identifier carried in the privacy computing task execution instruction;

[0008] If the privacy algorithm corresponding to the algorithm identifier is identified as a privacy algorithm designed based on other privacy computing platforms, then the algorithm image with the algorithm identifier obtained from the pre-established image repository is run in a containerized manner, and corresponding privacy computing is performed based on the privacy algorithm in the algorithm image; wherein, the algorithm image is generated based on the privacy algorithm and the set algorithm image generation standard.

[0009] Secondly, this application provides a privacy computing device, the device comprising:

[0010] The receiving module is used to receive the privacy computing task execution instruction and identify the algorithm identifier carried in the privacy computing task execution instruction;

[0011] The running module is used to, if it is identified that the privacy algorithm corresponding to the algorithm identifier is a privacy algorithm designed based on other privacy computing platforms, run the algorithm image of the algorithm identifier obtained from the pre-established image repository in a containerized manner, and perform corresponding privacy computing based on the privacy algorithm in the algorithm image; wherein, the algorithm image is generated based on the privacy algorithm and the set algorithm image generation standard.

[0012] Thirdly, this application provides an electronic device that includes at least a processor and a memory, wherein the processor is configured to execute a computer program stored in the memory to implement the steps of any of the methods described above.

[0013] Fourthly, this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of any of the methods described above.

[0014] This application can identify the algorithm identifier carried in the privacy computing task execution instruction when it receives the instruction. If the privacy algorithm corresponding to the algorithm identifier is identified as a privacy algorithm designed based on other privacy computing platforms, the application can run the algorithm image with the algorithm identifier obtained from the pre-established image repository in a containerized manner, and perform corresponding privacy computing based on the privacy algorithm in the algorithm image. The algorithm image can be generated based on the privacy algorithm corresponding to the algorithm identifier and the set algorithm image generation standard. Based on this, it is possible to use privacy algorithms designed on other privacy computing platforms to perform privacy computing, so that privacy algorithms designed on different privacy computing platforms can be interconnected.

[0015] Furthermore, in related technologies, the privacy algorithms offered by various vendors all require specific algorithm engines to run. Privacy algorithms, algorithm engines, and privacy computing platforms are strongly bound together. Each privacy computing platform's algorithm engine service is designed internally, and the methods for submitting computing tasks, obtaining computing results, and passing algorithm parameters differ between these platforms. Therefore, an algorithm engine from one vendor cannot be deployed or used by other privacy computing platforms (also known as heterogeneous privacy computing platforms or heterogeneous platforms). Additionally, the use of algorithm engines also encounters security verification issues. The security authentication methods of algorithm engines on different heterogeneous platforms are also different, making it impossible to achieve a universal and unified approach. All of these factors prevent the use of privacy algorithms designed on other privacy computing platforms (heterogeneous privacy computing platforms) for privacy computing, making it impossible for privacy algorithms designed on different privacy computing platforms to interoperate. This application can separate the privacy algorithm from the algorithm engine and privacy computing platform, isolate the privacy algorithm part, and use an algorithm image that runs the privacy algorithm in a containerized manner to drive the execution of the privacy algorithm. This enables privacy computing using privacy algorithms designed on other privacy computing platforms, and achieves the goal of interconnection and interoperability between privacy algorithms designed on different privacy computing platforms.

[0016] In addition, this application can separate the privacy algorithm from the algorithm engine and privacy computing platform, making the privacy algorithm part independent and creating an algorithm image of the privacy algorithm. The privacy algorithm is driven by running the algorithm image of the privacy algorithm in a containerized manner. It can be regarded as making the privacy algorithm as a plug-in, which can be used by other heterogeneous privacy computing platforms in a pluggable manner. This can quickly and flexibly realize the interconnection between privacy algorithms designed by different privacy computing platforms. Attached Figure Description

[0017] To more clearly illustrate the implementation methods in the embodiments of this application or related technologies, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings.

[0018] Figure 1 A schematic diagram of a first privacy computation process provided by some embodiments is shown;

[0019] Figure 2 The diagram illustrates a second privacy computation process provided by some embodiments;

[0020] Figure 3 The diagram illustrates a third privacy computation process provided by some embodiments;

[0021] Figure 4 A schematic diagram of a fourth privacy computation process provided by some embodiments is shown;

[0022] Figure 5 A schematic diagram of a fifth privacy computation process provided in some embodiments is shown;

[0023] Figure 6 A schematic diagram of a sixth privacy computation process provided in some embodiments is shown;

[0024] Figure 7 A schematic diagram of a seventh privacy computation process provided in some embodiments is shown;

[0025] Figure 8 The diagram illustrates an eighth privacy computation process provided in some embodiments;

[0026] Figure 9 This diagram illustrates a component instance state according to some embodiments;

[0027] Figure 10 A schematic diagram of a ninth privacy computation process provided in some embodiments is shown;

[0028] Figure 11 A schematic diagram of a tenth privacy computation process provided in some embodiments is shown;

[0029] Figure 12 A schematic diagram of an eleventh privacy computation process provided in some embodiments is shown;

[0030] Figure 13 This diagram illustrates the relationship between a privacy computing task and a component instance, as provided in some embodiments.

[0031] Figure 14 A schematic diagram of a container loading process provided by some embodiments is shown;

[0032] Figure 15 The diagram illustrates a privacy computing device according to some embodiments;

[0033] Figure 16 A schematic diagram of an electronic device provided in some embodiments is shown. Detailed Implementation

[0034] In order to enable privacy computing using privacy algorithms designed on other privacy computing platforms and to allow interoperability between privacy algorithms designed on different privacy computing platforms, this application provides a privacy computing method, apparatus, device and medium.

[0035] To make the objectives and implementation methods of this application clearer, the exemplary implementation methods of this application will be clearly and completely described below with reference to the accompanying drawings of the exemplary embodiments of this application. Obviously, the exemplary embodiments described are only some embodiments of this application, and not all embodiments.

[0036] It should be noted that the brief descriptions of terms in this application are only for the convenience of understanding the embodiments described below, and are not intended to limit the embodiments of this application. Unless otherwise stated, these terms should be understood in their ordinary and common meaning.

[0037] The terms "first," "second," "third," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar or related objects or entities, and do not necessarily imply a specific order or sequence, unless otherwise specified. It should be understood that such terms are interchangeable where appropriate.

[0038] The terms “comprising” and “having”, and any variations thereof, are intended to cover but not exclude inclusion, for example, a product or device that includes a range of components is not necessarily limited to all of the components that are clearly listed, but may include other components that are not clearly listed or that are inherent to such product or device.

[0039] The term "module" refers to any known or subsequently developed hardware, software, firmware, artificial intelligence, fuzzy logic, or combination of hardware and / or software code that is capable of performing the functions associated with that element.

[0040] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.

[0041] All embodiments of this application comply with the relevant provisions of national laws and regulations regarding the acquisition, storage, use, and processing of data.

[0042] Example 1:

[0043] Figure 1 The diagram illustrates a first privacy computation process provided by some embodiments, such as Figure 1 As shown, the process includes the following steps:

[0044] S101: Receive the privacy computing task execution instruction and identify the algorithm identifier carried in the privacy computing task execution instruction.

[0045] The privacy computing method provided in this application is applied to an electronic device, which may be a PC, a mobile terminal, or a server. Optionally, the electronic device may be a privacy computing device that stores a privacy algorithm designed based on a privacy computing platform.

[0046] In one possible implementation, when privacy computing is required, the electronic device (privacy computing device) can identify the algorithm identifier carried in the privacy computing task execution instruction upon receiving it. This application does not specifically limit the triggering method of the privacy computing task execution instruction. For example, it could be triggered when a worker clicks a button such as "Start Calculation" displayed on the electronic device, thereby receiving the privacy computing task execution instruction. Alternatively, it could be triggered upon receiving a start request from another privacy computing device to initiate a privacy computing task, thereby receiving the privacy computing task execution instruction.

[0047] Optionally, the number of algorithm identifiers carried in the privacy computing task execution instruction can be one or more. This application does not impose a specific limit on the number of algorithm identifiers carried in the privacy computing task execution instruction. In addition, this application does not impose a specific limit on the specific content of the algorithm identifiers carried in the privacy computing task execution instruction. For example, the algorithm identifier may include the algorithm name, algorithm type, algorithm version, etc., and can be flexibly set according to needs.

[0048] S102: If the privacy algorithm corresponding to the algorithm identifier is identified as a privacy algorithm designed based on other privacy computing platforms, then the algorithm image of the algorithm identifier obtained from the pre-established image repository is run in a containerized manner, and corresponding privacy computing is performed based on the privacy algorithm in the algorithm image; wherein, the algorithm image is generated based on the privacy algorithm and the set algorithm image generation standard.

[0049] In one possible implementation, for any algorithm identifier carried in the privacy computing task execution instruction, if the privacy algorithm corresponding to the algorithm identifier is identified as a privacy algorithm designed based on another privacy computing platform, in order to enable privacy computing using privacy algorithms designed on other privacy computing platforms (for ease of description, the aforementioned electronic device can be referred to as the user, and the device containing the aforementioned other privacy computing platform can be referred to as the publisher), and to allow interoperability between privacy algorithms designed on different privacy computing platforms, the algorithm image of the algorithm identifier obtained from a pre-established image repository can be run in a containerized manner, and corresponding privacy computing can be performed based on the privacy algorithm in the algorithm image. The algorithm image of the aforementioned algorithm identifier can be an algorithm image generated by the publisher, etc., based on the privacy algorithm corresponding to the algorithm identifier and a set algorithm image generation standard. Optionally, the privacy algorithm corresponding to the aforementioned algorithm identifier can belong to the publisher, that is, the privacy algorithm corresponding to the aforementioned algorithm identifier can be a privacy algorithm launched by the publisher's technology vendor. The algorithm image generation standard can be flexibly set according to needs, and this application does not specifically limit it.

[0050] Optionally, when performing corresponding privacy computations based on the privacy algorithms in the aforementioned algorithm mirror, the privacy computation can be jointly performed using the privacy algorithms in the aforementioned algorithm mirror (privacy algorithms designed based on other privacy computing platforms) and the privacy algorithms stored in the aforementioned electronic device (privacy algorithms designed based on the user's own privacy computing platform). This application does not specifically limit the specific process of performing privacy computations. This application also does not specifically limit the number of privacy algorithms participating in the joint privacy computation process (such as the number of privacy algorithms designed based on other privacy computing platforms).

[0051] To facilitate understanding, the privacy computing process provided in this application will be explained and illustrated below through a specific embodiment. (See reference...) Figure 2 , Figure 2 The diagram illustrates a second privacy computation process provided by some embodiments, which includes the following steps:

[0052] S201: Each publisher generates its own privacy algorithm image based on its own privacy algorithm and the established algorithm image generation standard, and publishes its own algorithm image and corresponding algorithm identifier to the image repository (public storage environment).

[0053] S202: The user receives the privacy computing task execution instruction and identifies each algorithm identifier carried in the instruction. For each algorithm identifier, if the privacy algorithm corresponding to that identifier is identified as a privacy algorithm designed based on another privacy computing platform, then the algorithm image for that identifier, obtained from a pre-established image repository, is run in a containerized manner. Corresponding privacy computations are performed based on the privacy algorithms in each algorithm image.

[0054] This application can identify the algorithm identifier carried in the privacy computing task execution instruction when it receives the instruction. If the privacy algorithm corresponding to the algorithm identifier is identified as a privacy algorithm designed based on other privacy computing platforms, the application can run the algorithm image with the algorithm identifier obtained from the pre-established image repository in a containerized manner, and perform corresponding privacy computing based on the privacy algorithm in the algorithm image. The algorithm image can be generated based on the privacy algorithm corresponding to the algorithm identifier and the set algorithm image generation standard. Based on this, it is possible to use privacy algorithms designed on other privacy computing platforms to perform privacy computing, so that privacy algorithms designed on different privacy computing platforms can be interconnected.

[0055] Furthermore, in related technologies, the privacy algorithms offered by various vendors all require specific algorithm engines to run. Privacy algorithms, algorithm engines, and privacy computing platforms are strongly bound together. Each privacy computing platform's algorithm engine service is designed internally, and the methods for submitting computing tasks, obtaining computing results, and passing algorithm parameters differ between these platforms. Therefore, an algorithm engine from one vendor cannot be deployed or used by other privacy computing platforms (also known as heterogeneous privacy computing platforms or heterogeneous platforms). Additionally, the use of algorithm engines also encounters security verification issues. The security authentication methods of algorithm engines on different heterogeneous platforms are also different, making it impossible to achieve a universal and unified approach. All of these factors prevent the use of privacy algorithms designed on other privacy computing platforms (heterogeneous privacy computing platforms) for privacy computing, making it impossible for privacy algorithms designed on different privacy computing platforms to interoperate. This application can separate the privacy algorithm from the algorithm engine and privacy computing platform, isolate the privacy algorithm part, and use an algorithm image that runs the privacy algorithm in a containerized manner to drive the execution of the privacy algorithm. This enables privacy computing using privacy algorithms designed on other privacy computing platforms, and achieves the goal of interconnection and interoperability between privacy algorithms designed on different privacy computing platforms.

[0056] In addition, this application can separate the privacy algorithm from the algorithm engine and privacy computing platform, making the privacy algorithm part independent and creating an algorithm image of the privacy algorithm. The privacy algorithm is driven by running the algorithm image of the privacy algorithm in a containerized manner. It can be regarded as making the privacy algorithm as a plug-in, which can be used by other heterogeneous privacy computing platforms in a pluggable manner. This can quickly and flexibly realize the interconnection between privacy algorithms designed by different privacy computing platforms.

[0057] Example 2:

[0058] To enable quick and accurate privacy computing using privacy algorithms designed by other privacy computing platforms, based on the above embodiments, in this embodiment, the step of running the algorithm image corresponding to the algorithm identifier obtained from a pre-established image repository in a containerized manner includes:

[0059] Identify the algorithm image execution standard indicated by the algorithm image generation standard;

[0060] The algorithm image is run in a containerized manner according to the algorithm image running standard.

[0061] In one possible implementation, when running an algorithm image, the algorithm image running standard indicated in the corresponding algorithm image generation standard can be identified first, and the algorithm image can be run in a containerized manner according to the algorithm image running standard.

[0062] Optionally, when running an algorithm image in a containerized manner according to the algorithm image running standard, the runtime environment of the target container can be configured according to the container configuration information carried in the algorithm image running standard to start the target container, thereby achieving the containerized running of the corresponding algorithm image. This application does not specifically limit the container configuration information; it can be flexibly set according to requirements. For example, the container configuration information carried in the algorithm image running standard may include: image system configuration definition information of the algorithm component (algorithm), image task configuration definition information of the algorithm component, etc.

[0063] The image system configuration definition information for algorithm components refers to the basic system configurations that need to be configured when using the algorithm component container service created from the algorithm image on a heterogeneous platform (other privacy computing platforms). This configuration can be set using system ENV variables (environment variables), and the corresponding algorithm component can read the ENV to load the required system configurations at runtime. The image system configuration definition information is mainly divided into system interface self-description information and algorithm component configuration self-description information.

[0064] Referring to Table 1, which illustrates a system interface self-description information table provided in some embodiments, the system interface self-description information may include fields such as: storage layer service address, storage layer service address identifier name, scheduling layer callback address, scheduling layer callback address identifier name, transmission service address, and transmission service address identifier name. Optionally, considering that existing privacy computing platforms are often coupled with algorithm engines, to ensure compatibility with existing privacy computing platforms, the system interface self-description information may also include the computing engine service address and computing engine service address identifier name. This allows the privacy computing platform, based on an algorithm engine configured with a computing engine service address, to run algorithm images obtained from an image repository in a containerized manner. Optionally, when the privacy computing platform does not have an algorithm engine configured, the algorithm image obtained from an image repository can also be run in a containerized manner; this application does not specifically limit this. Optionally, the system interface self-description information may also include descriptive information or remarks for each field. For example, the descriptive information or remarks for the scheduling layer callback address (referred to as description / remarks in the table) may be: callback can be made via interface callback, or callback can be made via container running results or other means. This application does not impose specific limitations on the fields and their descriptions or remarks in the system interface self-description information; these can be flexibly set according to requirements. Furthermore, the system interface self-description information can also include optional requirements for each field, specifying whether it is mandatory or optional. For example, if a field is mandatory, it means that the content of this field must be set. For instance, if the storage layer service address is mandatory, it means that the storage layer service address must be set so that the container's runtime environment can be configured based on that address. If a field is optional, it means that the content of this field can be set or not. For instance, if the computing engine service address field is optional, it means that the computing engine service address can be set or not.

[0065] Table 1

[0066]

[0067] Referring to Table 2, which shows a schematic table of self-descriptive information for an algorithm component configuration provided in some embodiments, the self-descriptive information for the algorithm component configuration may include: the identifier (Identity document, ID) of the privacy computing task in which the algorithm component participates, the node ID of the current node, the organization ID to which the current node belongs, the session ID required by the transmission SDK, the link ID, the dataset authorization token, the log path (log address information), the number of parallel uploads and downloads of data by the storage SDK, the block size of uploads and downloads of data by the storage SDK, etc., which will not be elaborated here.

[0068] Table 2

[0069]

[0070] Optionally, the image task configuration definition information of the algorithm component refers to the algorithm-related configurations that need to be configured when the heterogeneous platform uses the algorithm component container service created using this algorithm image. The image task configuration definition information of the algorithm component may include fields such as the name of the algorithm component to be run, algorithm component parameters, algorithm inputs, and outputs. Referring to Tables 3-6, Table 3 shows a schematic table of algorithm component names provided in some embodiments, Table 4 shows a schematic table of algorithm component parameters provided in some embodiments, Table 5 shows a schematic table of algorithm component inputs provided in some embodiments, and Table 6 shows a schematic table of algorithm component outputs provided in some embodiments; these will not be elaborated upon further here.

[0071] Table 3

[0072] Identifier Name Optional Meaning of the logo Description / Remarks runtime.component.name Required Currently running component name

[0073] Table 4

[0074]

[0075] Table 5

[0076]

[0077] Table 6

[0078]

[0079] To facilitate understanding, the privacy computing process provided in this application will be explained and illustrated below through a specific embodiment. (See reference...) Figure 3 , Figure 3 The diagram illustrates a third privacy computation process provided by some embodiments, which includes the following steps:

[0080] First, the electronic device (privacy computing device, user) receives the privacy computing task execution instruction and identifies each algorithm identifier carried in the instruction. For each algorithm identifier, if the privacy algorithm corresponding to that identifier is identified as being based on another privacy computing platform, the scheduling layer of the electronic device can retrieve the algorithm image for that identifier from a pre-established image repository. It then identifies the algorithm image execution standard indicated by the algorithm image generation standard, and based on the container configuration information carried in the algorithm image execution standard, configures the necessary system configurations and algorithm parameters in the container's ENV, configuring the target container's runtime environment. Finally, it starts the target container (algorithm container) by calling an application container engine (Docker) or Kubernetes (k8s), running the corresponding algorithm image in a containerized manner.

[0081] After running the algorithm image for each algorithm identifier in a containerized manner (after the algorithm container starts), you can execute the default startup command to run the entry .py file (Python script file). Optionally, you can execute the entry .py files in the following order:

[0082] (1) Obtain system configuration (image system configuration definition information of algorithm components) from ENV, such as configuration information of transport service address, configuration information of storage layer service address, configuration information of computing engine service address, privacy computing task ID, node information of all participants in the current privacy computing task, etc.

[0083] (2) Based on the configuration information of the transmission service address, all participating nodes initialize the transmission session information. For example, they initialize the session ID and other information required by the transmission SDK.

[0084] (3) Initialize the storage session information according to the configuration information of the storage layer service address.

[0085] (4) Obtain algorithm parameters from ENV, such as: obtaining the running parameters of the algorithm components, the input information and output information of the algorithm, etc.

[0086] (5) Read data, such as reading the data or model input to the algorithm.

[0087] (6) Initialize the algorithm, pass in the parameters and input data required by the algorithm, start running the algorithm mirrors of the privacy algorithms of each participant, and perform interconnected privacy computing.

[0088] The privacy algorithm can be an algorithm of the Intersection, Hetero_Logistic_Regression, etc., and this application does not make specific limitations on it.

[0089] (7) After any privacy algorithm has completed its execution, the results (data, model, report results, etc.) can be persisted to a storage service. For example, the results can be stored in an S3 database (storage SDK). Optionally, the results (including sub-results during algorithm execution) can be transferred to an external service (transfer server) (transfer SDK) to enable interconnection and interoperability of privacy algorithms with other privacy computing platforms.

[0090] To facilitate understanding, the privacy computing process provided in this application will be explained below through a specific embodiment. (See also...) Figure 4 , Figure 4 The diagram illustrates a fourth privacy computation process provided by some embodiments, which includes the following steps:

[0091] S401: Receive the privacy computing task execution instruction and identify the algorithm identifier carried in the privacy computing task execution instruction.

[0092] S402: If the privacy algorithm corresponding to the above algorithm identifier is identified as a privacy algorithm designed based on other privacy computing platforms, then identify the algorithm image running standard indicated by the algorithm image generation standard; configure the running environment of the target container according to the container configuration information carried in the algorithm image running standard, start the target container, and run the algorithm image with the algorithm identifier obtained from the pre-established image repository in a containerized manner, and perform corresponding privacy computing based on the privacy algorithm in the algorithm image.

[0093] Compared to the situation where different privacy computing platforms generate algorithm images of their privacy algorithms based on different benchmarks (such as different platform design methods), resulting in a lack of interoperability between privacy algorithms on different privacy computing platforms, this embodiment allows each privacy computing platform to adopt a unified algorithm image generation standard to quickly create algorithm images of their respective privacy algorithms and publish them to a unified image repository. This unified algorithm image publishing and discovery method makes them available to heterogeneous privacy computing platforms. When using privacy algorithms from other heterogeneous privacy computing platforms, each privacy computing platform can also use a unified algorithm image execution standard to run the algorithm images in a containerized manner. For example, it supports configuring various parameters into the container's runtime environment using system ENVs, and automatically running the container's configured startup files to run the algorithm task process when the container starts. This enables the use of privacy algorithms from other heterogeneous privacy computing platforms, achieving interoperability between privacy algorithms on different privacy computing platforms.

[0094] Example 3:

[0095] To facilitate rapid privacy computation, based on the above embodiments, in this embodiment, after identifying the algorithm identifier carried in the privacy computation task execution instruction and before configuring the target container's runtime environment according to the container configuration information carried in the algorithm image execution standard, the method further includes:

[0096] Identify the container communication method carried in the tag information of the algorithm image, and obtain the target container based on the container communication method.

[0097] In one possible implementation, to standardize algorithm image generation standards and facilitate interoperability between privacy algorithms designed on different privacy computing platforms, the algorithm image definition and algorithm component definition in the algorithm image generation standard can be standardized. Specifically, when standardizing the algorithm image definition, the naming of the algorithm image, image tags, directory structure information of log addresses, container communication methods, and security protection measures used to ensure the algorithm image are uniformly standardized. The following sections will describe the standardized aspects of the algorithm image definition.

[0098] (a) Naming standardization of algorithm images

[0099] Optionally, the naming of algorithm images can uniformly adopt the following format:

[0100] / <developer> / <image-name> : <tag>.

[0101] Here, `developer` represents the developer's identifier for the algorithm component, which can be a company name or organization name, etc. Standardization of identifiers for various technology vendors (developers) can be achieved through alliances or similar organizations, which will not be elaborated upon here. `image-name` represents important information such as the function and classification of the algorithm component to be represented, such as: longitudinal logistic regression (hetero-lr), PSI based on DH key negotiation (dh-psi), FATE algorithm package (fate-collection), etc. `tag` represents the algorithm's version number, which follows the naming convention `major.minor.patch[-state]`, such as version numbers like 1.0.0, 1.0.1-beta, etc. `major` in the version number indicates the major version number of the algorithm, and its change usually signifies a significant change in the algorithm. `minor` indicates the minor version number of the algorithm, which usually only reflects some major changes. `patch` usually indicates a patch version. `state` represents the algorithm's state, which is optional. The algorithm's state can be a set of data describing the current state of the system; this application does not specifically limit this. Normally, once an algorithm image is published to an image repository, its name and other information cannot be changed.

[0102] (b) Normalization of image tags for algorithm images

[0103] Optionally, the image tags for the algorithm image can be uniformly added using key-value pairs such as LABEL k1=v1, k2=v2, thereby providing more information for the algorithm image. The specific meaning of the image tags can be clearly explained in the external documentation.

[0104] (c) Standardization of the directory structure information of the algorithm image's log address

[0105] Optionally, the directory structure information of the algorithm image's log address can be specified in the image tag, etc., using the Dockerfile WORKDIR method. Refer to Table 7, which shows a schematic table of image tag information provided in some embodiments. The directory for the log address (log file address) can be specified in the image tag information as / home / admin / app / logs, etc., which will not be elaborated further here.

[0106] Table 7

[0107] LABEL key Description / Remarks log_dir Log file directory, such as / home / admin / app / logs

[0108] Optionally, the electronic device can identify the log address information carried in the algorithm image (such as in the image tag information of the algorithm image); and store the running log generated by running the algorithm image according to the log address information.

[0109] To facilitate understanding, the privacy computing process provided in this application will be explained and illustrated below through a specific embodiment. (See reference...) Figure 5 , Figure 5 The diagram illustrates a fifth privacy computation process provided by some embodiments, which includes the following steps:

[0110] S501: Receives a privacy computing task execution instruction, identifies the algorithm identifier carried in the instruction, and if the identified privacy algorithm is based on another privacy computing platform, runs the algorithm image with that identifier obtained from a pre-established image repository in a containerized manner. Performs corresponding privacy computing based on the privacy algorithm in the image.

[0111] S502: Identify the log address information carried by the above algorithm image; store the running log generated by running the algorithm image according to the log address information.

[0112] (d) Standardization of container communication methods for algorithm images

[0113] Optionally, to make the container externally accessible, methods such as Transmission Control Protocol / Internet Protocol (TCP / IP) sockets can be used to expose internal services by listening on a port. The container port number can be specified in the image tag information of the algorithm image, thus making the container externally accessible. Referring to Table 8, which shows a schematic table of image tag information provided in some embodiments, the container port number can be specified in the image tag information. Subsequent users can identify the container port number (container communication method) carried in the algorithm image tag information, obtain the target container based on this container port number, and configure the target container's runtime environment according to the configuration information required by the algorithm image's runtime standard, thereby starting the target container and running the corresponding algorithm image. These steps will not be elaborated further here.

[0114] Table 8

[0115] LABEL key Description / Remarks port Port number, such as 80

[0116] Optionally, to address potential port number (container port number) conflicts, the capabilities of infrastructure (such as Kubernetes) can be leveraged to resolve these conflicts. Existing technologies can be used to resolve port number conflicts, which will not be elaborated upon here.

[0117] Alternatively, internal services can be exposed by utilizing Unix Domain Socket technology, such as listening to local socket files. External services can also be accessed via socket files. This method (Unix file) can shield the details of the network architecture, but requires algorithm components to support traffic forwarding and can flexibly and accurately start the target container. Refer to Table 9, which shows a schematic table of image labels provided in some embodiments. The algorithm component support services will be described in subsequent embodiments and will not be elaborated here.

[0118] Table 9

[0119]

[0120] To facilitate understanding, the privacy computing process provided in this application will be explained and illustrated below through a specific embodiment. (See reference...) Figure 6 , Figure 6 The diagram illustrates a sixth privacy computation process provided by some embodiments, which includes the following steps:

[0121] S601: Receive the privacy computing task execution instruction and identify the algorithm identifier carried in the privacy computing task execution instruction.

[0122] S602: If the privacy algorithm corresponding to the above algorithm identifier is identified as a privacy algorithm designed based on other privacy computing platforms, then the container communication method carried in the tag information of the algorithm image is identified. Based on the container communication method, the target container is obtained, and the algorithm image running standard indicated by the algorithm image generation standard is identified. According to the container configuration information carried in the algorithm image running standard, the running environment of the target container is configured, and the target container is started. The algorithm image with the algorithm identifier obtained from the pre-established image repository is run in a containerized manner. Corresponding privacy computation is performed based on the privacy algorithm in the algorithm image.

[0123] (e) Standardize the protection measures to ensure the security of algorithm images

[0124] Optionally, to prevent the privacy algorithms in the algorithm image from being tampered with and to ensure the security of privacy computing, the publisher (other privacy computing platform) may provide benchmark verification data corresponding to the algorithm image when publishing it. For example, the benchmark verification data may be the SHA256 digest value of the algorithm image, the image signature, etc., and this application does not specifically limit this.

[0125] Optionally, after recognizing that the privacy algorithm corresponding to the algorithm identifier carried in the privacy computing task execution instruction is a privacy algorithm designed based on other privacy computing platforms, the user (the aforementioned electronic device) can obtain the verification data carried by the algorithm image in a containerized manner before running the algorithm image corresponding to the algorithm identifier obtained from the image repository. This verification data can then be compared with the benchmark verification data provided by other privacy computing platforms for the algorithm image. For example, the SHA256 digest value, image signature, etc., carried by the algorithm image can be compared with the benchmark verification data (benchmark SHA256 digest value, benchmark image signature, etc.) provided by other privacy computing platforms for the algorithm image. If the comparison result shows that the verification data is consistent with the benchmark verification data, it can be considered that the privacy algorithm in the algorithm image has not been tampered with and is secure. The subsequent step of running the algorithm image corresponding to the algorithm identifier obtained from the image repository in a containerized manner can then proceed. Conversely, if the data to be verified is inconsistent with the baseline verification data, it can be considered that the privacy algorithms in the algorithm image have been tampered with. In this case, the step of obtaining the algorithm image corresponding to the algorithm identifier from the image repository in a containerized manner can be omitted. Optionally, a set security warning message can be output, but this application does not specifically limit this. Optionally, the process of the publisher adding image signature information and the user verifying image signature information can be implemented based on notary services, etc., which will not be elaborated here.

[0126] In one possible implementation, to ensure the security of privacy computing, after the user (the aforementioned electronic device) identifies that the privacy algorithm corresponding to the algorithm identifier carried in the privacy computing task execution instruction is a privacy algorithm designed based on other privacy computing platforms, before running the algorithm image corresponding to the corresponding algorithm identifier obtained from the image repository in a containerized manner, it can also perform a common vulnerability and exposure (CVE) vulnerability scan on the algorithm image using open-source or self-developed tools, depending on its own infrastructure. Optionally, if the scan result shows no vulnerabilities with a set security threat level, the algorithm image can be considered to have no security threat, and the subsequent step of running the algorithm image with the corresponding algorithm identifier obtained from the image repository in a containerized manner can be performed. Conversely, if the scan result shows vulnerabilities with a set security threat level, the algorithm image can be considered to have a security threat and security issues, and the subsequent step of running the algorithm image with the corresponding algorithm identifier obtained from the image repository in a containerized manner can be omitted. For example, a set security warning message can be output, etc., which is not specifically limited in this application.

[0127] The security threat level can be flexibly set according to needs, and this application does not impose specific limitations on it. For example, when the security threat level is set to medium, high, severe, and high risk, if the scan results show no vulnerabilities at the medium, high, severe, or high risk levels, the algorithm image can be considered to have no security threats. If the scan results show vulnerabilities at the medium, high, severe, or high risk levels, the algorithm image can be considered to have security threats.

[0128] For ease of understanding, the privacy computing process provided in this application will be explained and illustrated below through a specific embodiment. (See attached document for details.) Figure 7 , Figure 7 The diagram illustrates a seventh privacy computation process provided by some embodiments, which includes the following steps:

[0129] S701: Receives instructions to run a privacy computing task and identifies the algorithm identifier carried in the instructions.

[0130] S702: Obtain the algorithm image corresponding to the above algorithm identifier from the image repository. If the privacy algorithm corresponding to the algorithm identifier is identified as a privacy algorithm designed based on other privacy computing platforms, obtain the verification data carried by the algorithm image, and compare the verification data with the benchmark verification data for the algorithm image provided by other privacy computing platforms. If the comparison result is consistent, run the algorithm image in a containerized manner and perform corresponding privacy computing based on the privacy algorithm in the algorithm image. The algorithm image is generated based on the privacy algorithm and the set algorithm image generation standard.

[0131] For ease of understanding, the privacy computing process provided in this application will be explained and illustrated below through a specific embodiment. (See attached document for details.) Figure 8 , Figure 8 The diagram illustrates an eighth privacy computation process provided by some embodiments, which includes the following steps:

[0132] S801: Receives the privacy computing task execution instruction and identifies the algorithm identifier carried in the privacy computing task execution instruction.

[0133] S802: Obtain the algorithm image corresponding to the above algorithm identifier from the image repository. If the privacy algorithm corresponding to the algorithm identifier is identified as a privacy algorithm designed based on other privacy computing platforms, perform a vulnerability scan on the algorithm image. If the scan result is a vulnerability without a set security threat level, run the algorithm image in a containerized manner and perform corresponding privacy computing based on the privacy algorithm in the algorithm image. The algorithm image is generated based on the privacy algorithm and the set algorithm image generation standard.

[0134] Regarding the security of algorithm images (container images) in this application, it can be stipulated that the publisher needs to carry verification information such as the image's signature when publishing the algorithm image to prevent the algorithm image from being tampered with during the publishing and storage process. Furthermore, when users pull and deploy algorithm images on heterogeneous platforms, they can perform verification information verification (checking) and vulnerability scanning on the algorithm image to ensure the security and availability of the algorithm image.

[0135] Example 4:

[0136] In order to provide users with information about the algorithm parameters of the privacy algorithm used for privacy computing, based on the above embodiments, the method in this application embodiment further includes:

[0137] Identify and display the algorithm parameter information carried by the algorithm image.

[0138] In one possible implementation, to standardize algorithm image generation, in addition to standardizing algorithm image definitions, the definition of algorithm component names can also be standardized. For example, the standardization of algorithm component name definitions may include naming conventions for component (algorithm component) names and component instance state conventions.

[0139] Among them, (a) the naming conventions for component names can be as follows:

[0140] Optionally, the component name can be a unique identifier string for the component, and the component name can be named in the format <prefix>.<version>.<type>.<name>. For example, the component name can be: intercom.v1.algorithm.hetero_lr, etc. Here, the <prefix> in the component name can be a prefix specified in the interoperability standard, such as intercom, etc., and can be flexibly set according to needs; this application does not impose specific limitations on it. The <version> in the component name can be the corresponding interface version, such as v1, etc. The <type> in the component name can be the component type (algorithm type), such as algorithm type, etc., and this application does not impose specific limitations on it. The <name> in the component name can be the name identifier of an algorithm component (corresponding interface) such as Linear Regression (LR), such as hetero_lr, etc.

[0141] Among them, (b) the component instance state specification can be as follows:

[0142] Table 10 shows a schematic table of a component instance state specification provided in some embodiments. Figure 9 A schematic diagram of a component instance state provided by some embodiments is shown, referring to Table 10 and Figure 9 When a component image is not loaded into the system, the initial state of its component instance can be "unloaded". Details regarding the creation of component instances for component images will be described in subsequent embodiments and will not be repeated here. Once the component image has been downloaded and verified and loaded into the system, the component instance's state can be "loaded", at which point the component image can be started or unloaded. When the component image is running, the component instance's state can be "running" (or "started"). When the component image stops running, the component instance's state can be "stopped", at which point the component image can be restarted or unloaded. If a failure occurs after the component image starts, the component instance's state can be "failed".

[0143] Table 10

[0144]

[0145]

[0146] In one possible implementation, before running the algorithm image in a containerized manner, a component instance of the algorithm image can be created and the component instance can be registered as a service, so that the algorithm services provided by the algorithm image can be discovered and invoked, and then the subsequent steps of running the algorithm image corresponding to the algorithm identifier obtained from the pre-established image repository in a containerized manner can be performed.

[0147] To facilitate understanding, the privacy computing process provided in this application will be explained and illustrated below through a specific embodiment. (See reference...) Figure 10 , Figure 10 The diagram illustrates a ninth privacy computation process provided by some embodiments, which includes the following steps:

[0148] S1001: The container manager in the electronic device queries the algorithm image information from the image repository and obtains several algorithm images.

[0149] S1002: When the scheduling service in the electronic device receives a privacy computing task execution instruction, it identifies the algorithm identifier carried in the privacy computing task execution instruction and can submit the privacy computing task execution instruction to the container manager.

[0150] S1003: The container manager identifies the algorithm identifier carried in the privacy computing task execution instruction. If it identifies that the privacy algorithm corresponding to the algorithm identifier is a privacy algorithm designed based on other privacy computing platforms, it can send an instance creation request to the algorithm instance service to create a component instance (also known as an algorithm instance) of the privacy algorithm corresponding to the algorithm identifier.

[0151] S1004: The component instance service creates a component instance of the privacy algorithm corresponding to the above algorithm identifier, and initializes and loads the component instance into the system.

[0152] S1005: The component instance service submits an application to the component register and discovery service in the electronic device to register the aforementioned component instance for service.

[0153] S1006: The component registration and discovery service registers component instances for services, enabling the algorithm services provided by the corresponding algorithm images to be discovered and invoked.

[0154] S1007: The container manager can periodically send instructions to the component instance service to perform instance health checks.

[0155] S1008: The component instance service can perform health checks on component instances and can report the health check results back to the container manager.

[0156] S1009: If the health check result is passed, the component instance service will report the status information that the privacy computing task can start running to the scheduling service.

[0157] Among them, health checks on component instances can include comparing the signature pending verification information of the algorithm image with the benchmark verification data, performing vulnerability scans, etc. If the comparison result shows that the pending verification information and the benchmark verification data are consistent, and the vulnerability scan result shows that there are no vulnerabilities with a set security threat level, then the health check result can be considered as passing; otherwise, the health check result can be considered as failing.

[0158] S1010: The scheduling service runs the algorithm image identified by the above algorithm in a containerized manner, and performs corresponding privacy calculations based on the privacy algorithm in the algorithm image. The scheduling service then feeds back the privacy calculation results to the container manager.

[0159] S1011: Once the privacy computing task is complete, the container manager can send an instance destruction command to the component instance service.

[0160] S1012: The component instance service can clean up the above component instances and send a request to the component registration and discovery service to deregister the above component instances.

[0161] S1013: The component registration and discovery service deregisters the above component instances and reports the deregistered service information to the component instance service.

[0162] In one possible implementation, the self-description information of the algorithm image can be standardized. This self-description information mainly refers to the basic information of the algorithm image defined in image tag information (LABELS) when creating the container image (algorithm image). This allows heterogeneous privacy computing platforms to identify (dynamically generate) the algorithm information carried in the tag information of the algorithm image through preloading and other means when using the algorithm image for privacy computing, and to display this algorithm information.

[0163] Optionally, the algorithm's self-description information can mainly include four types of algorithm information: algorithm function self-description information, algorithm parameter self-description information, algorithm input self-description information, and algorithm output self-description information. Referring to Table 11, which shows a schematic table of algorithm function self-description information provided in some embodiments, the algorithm function self-description information can include the version number followed by the privacy algorithm, the name of the algorithm component, the description of the algorithm component, the version of the algorithm component, the version of the nth sub-algorithm in the algorithm component, the name of the nth sub-algorithm in the algorithm component, the description information of the nth sub-algorithm in the algorithm component, and a list of roles implemented by the algorithm component (sub-algorithm) in privacy computation. The list of roles implemented in privacy computation can include guest, host, arbiter, etc., where guest represents the data user and host represents the data provider. In vertical algorithms, guest is often the party with label y. Arbiter can be used to assist multiple parties in completing joint modeling; its main function is to aggregate gradients or models, which will not be elaborated further here.

[0164] Table 11

[0165]

[0166]

[0167] Referring to Table 12, which illustrates a self-descriptive information table of algorithm parameters provided in some embodiments. Optionally, the self-descriptive information of the algorithm parameters may include: the name of the nth parameter, the description of the nth parameter, the type of the nth parameter, etc. The type of the parameter may include integer, string, float (floating-point), boolean, etc.

[0168] Table 12

[0169]

[0170] Referring to Table 13, which illustrates a self-descriptive information table for algorithm inputs provided in some embodiments, the self-descriptive information for algorithm inputs may optionally include: the name of the nth input, the description of the nth input, the type of the nth input, etc. The type of input may include a model, dataset, training set, testing set, report, etc.

[0171] Table 13

[0172]

[0173]

[0174] Referring to Table 14, which illustrates a self-descriptive information table of algorithm output provided in some embodiments. Optionally, the self-descriptive information of the algorithm output may include: the name of the nth output, the description of the nth output, the type of the nth output, etc. The type of output may include model, dataset, training set, testing set, report, etc., which will not be elaborated further here.

[0175] Table 14

[0176]

[0177] For ease of understanding, the privacy computing process provided in this application will be explained and illustrated below through a specific embodiment. (See attached document for details.) Figure 11 , Figure 11 The diagram illustrates a tenth privacy computation process provided by some embodiments, which includes the following steps:

[0178] S1101: Receive the privacy computing task execution instruction and identify the algorithm identifier carried in the privacy computing task execution instruction.

[0179] S1102: Obtain the algorithm image corresponding to the above algorithm identifier from the image repository. If the privacy algorithm corresponding to the algorithm identifier is identified as a privacy algorithm designed based on other privacy computing platforms, perform a vulnerability scan on the algorithm image. If the scan result is a vulnerability without a set security threat level, run the algorithm image in a containerized manner and perform corresponding privacy computing based on the privacy algorithm in the algorithm image. The algorithm image is generated based on the privacy algorithm and the set algorithm image generation standard.

[0180] S1103: Identify the algorithm information carried by the above algorithm image and display the corresponding algorithm information.

[0181] To facilitate understanding, the privacy computing process provided in this application will be explained below through a specific embodiment. (See also...) Figure 12 , Figure 12 The diagram illustrates an eleventh privacy computation process provided by some embodiments, which includes the following steps:

[0182] The container manager in the electronic device queries algorithm image information from the image repository and pulls several algorithm images to the local electronic device. When the schedule service in the electronic device receives a privacy computing task execution command, it identifies the algorithm identifier carried in the privacy computing task execution command and can submit the privacy computing task execution command to the container manager. The container manager identifies the algorithm identifier carried in the privacy computing task execution command. If it identifies that the privacy algorithm corresponding to the algorithm identifier is a privacy algorithm designed based on other privacy computing platforms, it can create a component instance (algorithm instance) of the privacy algorithm corresponding to the algorithm identifier through the application programming interface service (API server). Optionally, the container manager can perform full lifecycle management of the component instance creation and deregistration process through the API server, etc., which will not be elaborated here.

[0183] The algorithm instance service can submit a registration query to the component register and discovery service in the electronic device to register the aforementioned component instances. The component register and discovery service registers the component instances, enabling the algorithm services provided by the corresponding algorithm images to be discovered and invoked. The algorithm instance service reports the status information that the privacy computation task is ready to start to the schedule service. The schedule service runs the algorithm image identified by the algorithm identifier in a containerized manner, performing corresponding privacy computations based on the privacy algorithms in the algorithm image. The schedule service submits the privacy computation results to the container manager.

[0184] Optionally, after the privacy computing task is completed, the container manager can send an instance destruction command to the component instance service (not shown in the figure). The component instance service can then deregister and clean up the aforementioned component instances and send an unregister query to the component registration and discovery service to deregister the aforementioned component instances. The component registration and discovery service then deregisters the aforementioned component instances.

[0185] The component registration and discovery service manages component instances, providing registration and lookup services for algorithm components. The scheduling service schedules privacy algorithm jobs and privacy computing tasks. The container manager encapsulates the orchestration capabilities of underlying containers (such as Kubernetes infrastructure containers) and receives information from the scheduling service. The container manager can shield information about specific container engines, such as whether the container engine is Docker or Podman. It can also shield information about container orchestration, such as whether it's Kubernetes (k8s) or OpenShift. Furthermore, the container manager can shield information about specific image repositories, such as whether the image repository connecting to electronic devices is public or private. Note that the component registration and discovery service, scheduling service, container manager, and component instance service are merely logical abstractions and do not correspond to specific services, nor are their physical forms specifically limited.

[0186] To facilitate understanding, the privacy computing process provided in this application will be explained and illustrated below through a specific embodiment. (See reference...) Figure 13 , Figure 13 The diagram illustrates the relationship between a privacy computing task and a component instance as provided in some embodiments.

[0187] An algorithm component image can be loaded into a component instance through a loading mechanism, and this component instance can be registered with a registration and discovery service for use by multiple privacy computing tasks. Optionally, the relationship between privacy computing tasks and component instances can be many-to-one or one-to-one, etc. For example, multiple privacy computing tasks can correspond to one component instance, such as privacy computing task 1, privacy computing task 2, privacy computing task 3, etc., all of which can use the same component instance. Alternatively, one privacy computing task can correspond to one component instance; this application does not specifically limit this.

[0188] Optionally, privacy-preserving computing platforms can leverage their own infrastructure to implement container loading capabilities through a container manager. Taking Kubernetes as an example, after the container manager has configured the Deployment, it can call the API server's REST interface or the command-line tool (kubectl) to create a pod, or component instance, that encapsulates the container. Here, a component image (algorithm image) can refer to a packaged container image file representing an algorithm component. A component instance can refer to a process or service that provides component functionality after the component instance is loaded and started. Component instances can run in a persistent or one-time manner.

[0189] Optionally, running in a persistent mode means that after the algorithm component is loaded, the resulting component instance will persist in the system for use by one or more tasks (privacy computing tasks). The algorithm component can be started when it is first used, or it can be launched during system startup. The algorithm component can be stopped when the system stops, or based on system idle time, etc. Running in a one-time mode means that the algorithm component starts when the task begins execution and stops when the task completes. Optionally, regardless of the running mode, the workflow and steps of the algorithm component are the same.

[0190] The standard algorithm component loading management mechanism is further described below. This mechanism consists of two parts: a component management service and a component support service. The entire lifecycle of a standard algorithm component can be managed through a container manager. For ease of understanding, a specific embodiment is provided below to illustrate the privacy computing process provided in this application. (See also...) Figure 14 , Figure 14 A schematic diagram of a container loading process provided by some embodiments is shown.

[0191] Optionally, the Component Management Service can be based on component registration and discovery services, network services, data services, computing services, scheduling services, etc., to manage algorithm components and component instances, and is responsible for managing the containers running the algorithm components. For example, it can interface with container platforms (such as Docker, Swarm, and Kubernetes) to complete container orchestration and management.

[0192] The Component Support Service provides basic operational capabilities to algorithm components. It offers standard service interfaces, such as registration and discovery interfaces, for the functions used within the component container. It maps basic interface functions into the container using Unix files or sockets, receives and responds to requests from algorithm components, and can run the corresponding algorithm image in a containerized manner by loading and starting the component container (target container) to implement the logic process of the privacy algorithm component and perform privacy computation based on the privacy algorithm.

[0193] This application innovatively designs a component container (algorithm component container), an algorithm image loading process, and specifies the definitions of image names and corresponding algorithm component names. This ensures the uniqueness of algorithm images during the release process, avoiding problems such as algorithm image conflicts and difficulty in differentiation when releasing algorithm images on different heterogeneous platforms. Furthermore, this application specifies the methods and formats for submitting computation tasks and passing algorithm parameters through the algorithm component container, enabling privacy computing platforms to use privacy algorithms (heterogeneous algorithm components) from other privacy computing platforms and to interact normally with heterogeneous privacy algorithm components.

[0194] Furthermore, this application provides a general and standardized technical solution for containerizing, submitting, managing, and obtaining the computation results of privacy-preserving computation tasks using algorithm components. Any privacy-preserving computation platform can use algorithm component containers (algorithm images) contributed by other heterogeneous platforms normally by modifying and adapting them according to this solution. This allows them to apply algorithm component containers contributed by other heterogeneous platforms to their own platform (privacy computation), increasing the diversity of privacy algorithms and achieving interoperability between privacy algorithms.

[0195] Example 5:

[0196] Based on the same technical concept, this application provides a privacy computing device, see reference. Figure 15 . Figure 15 The diagram illustrates a privacy computing device according to some embodiments, the device comprising:

[0197] The receiving module 1501 is used to receive the privacy computing task execution instruction and identify the algorithm identifier carried in the privacy computing task execution instruction;

[0198] The running module 1502 is used to, if it is identified that the privacy algorithm corresponding to the algorithm identifier is a privacy algorithm designed based on other privacy computing platforms, run the algorithm image of the algorithm identifier obtained from the pre-established image repository in a containerized manner, and perform corresponding privacy computing based on the privacy algorithm in the algorithm image; wherein, the algorithm image is generated based on the privacy algorithm and the set algorithm image generation standard.

[0199] In one possible implementation, the operating module 1502 is specifically used for:

[0200] Identify the algorithm image execution standard indicated by the algorithm image generation standard; run the algorithm image in a containerized manner according to the algorithm image execution standard.

[0201] In one possible implementation, the operating module 1502 is specifically used for:

[0202] Based on the container configuration information carried in the algorithm image running standard, the target container's running environment is configured, the target container is started, and the algorithm image is run.

[0203] In one possible implementation, the operation module 1502 is further configured to:

[0204] Identify the container communication method carried in the tag information of the algorithm image, and obtain the target container based on the container communication method.

[0205] In one possible implementation, the operation module 1502 is further configured to:

[0206] Identify the log address information carried by the algorithm image; store the running logs generated by running the algorithm image according to the log address information.

[0207] In one possible implementation, the operation module 1502 is further configured to:

[0208] Identify and display the algorithm information carried by the algorithm image.

[0209] In one possible implementation, the operation module 1502 is further configured to:

[0210] The data to be verified carried by the algorithm image is obtained, and the data to be verified is compared with the benchmark verification data for the algorithm image provided by the other privacy computing platform. If the comparison result is consistent, the subsequent step of running the algorithm image corresponding to the algorithm identifier obtained from the pre-established image repository in a containerized manner is performed.

[0211] In one possible implementation, the operation module 1502 is further configured to:

[0212] The algorithm image is subjected to a vulnerability scan. If the scan result shows no vulnerabilities with a set security threat level, the subsequent step is to run the algorithm image corresponding to the algorithm identifier obtained from the pre-established image repository in a containerized manner.

[0213] Based on the same technical concept, this application also provides an electronic device, see reference. Figure 16 , Figure 16 The diagram illustrates an electronic device according to some embodiments. The electronic device includes a processor 1601, a communication interface 1602, a memory 1603, and a communication bus 1604, wherein the processor 1601, the communication interface 1602, and the memory 1603 communicate with each other through the communication bus 1604.

[0214] The memory 1603 stores a computer program. When the program is executed by the processor 1601, the processor 1601 performs the steps described in any of the above methods, which will not be repeated here.

[0215] The communication bus mentioned in the above electronic devices can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not mean that there is only one bus or one type of bus.

[0216] Communication interface 1602 is used for communication between the above-mentioned electronic device and other devices.

[0217] The memory may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.

[0218] The processors mentioned above can be general-purpose processors, including central processing units, network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits, field-programmable gate arrays or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.

[0219] Based on the same technical concept, embodiments of this application provide a computer-readable storage medium storing a computer program executable by an electronic device. When the program is run on the electronic device, it causes the electronic device to perform the steps of any of the above methods, which will not be described in detail here.

[0220] The aforementioned computer-readable storage medium can be any available medium or data storage device that can be accessed by the processor in an electronic device, including but not limited to magnetic storage such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), optical storage such as CDs, DVDs, BDs, HVDs, etc., and semiconductor storage such as ROMs, EPROMs, EEPROMs, non-volatile memory (NAND flash), solid-state drives (SSDs), etc.

[0221] Based on the same technical concept, this application provides a computer program product, which includes: computer program code, which, when run on a computer, causes the computer to implement the method described in any of the above-described method embodiments applied to electronic devices.

[0222] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof, or in whole or in part, as a computer program product. The computer program product includes one or more computer instructions, which, when loaded and executed on a computer, generate, in whole or in part, the processes or functions described in the embodiments of this application.

[0223] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0224] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0225] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0226] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0227] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.< / tag> < / image-name> < / developer>

Claims

1. A method of privacy computation, the method comprising: The method comprises: receiving a privacy computing task running instruction, and identifying an algorithm identifier carried in the privacy computing task running instruction; if it is identified that a privacy algorithm corresponding to the algorithm identifier is a privacy algorithm designed based on another privacy computing platform, creating a component instance of the privacy algorithm corresponding to the algorithm identifier, and performing service registration on the component instance; shielding an algorithm engine corresponding to the other privacy computing platform to which the privacy algorithm belongs, running an algorithm image of the algorithm identifier obtained from a pre-connected image repository in a containerized manner, and jointly performing corresponding privacy computing based on a privacy algorithm in the algorithm image and a self-privacy algorithm; wherein the algorithm image is generated by a device where the other privacy computing platform is located based on the privacy algorithm and a set algorithm image generation standard, the privacy algorithm belongs to the device where the other privacy computing platform is located; and the privacy algorithm is decoupled from the other privacy computing platform and the algorithm engine corresponding to the other privacy computing platform.

2. The method of claim 1, wherein, The running of the algorithm image of the algorithm identifier obtained from the pre-connected image repository in a containerized manner comprises: identifying an algorithm image running standard indicated by the algorithm image generation standard; running the algorithm image in a containerized manner according to the algorithm image running standard.

3. The method of claim 2, wherein, The running of the algorithm image in a containerized manner according to the algorithm image running standard comprises: configuring a running environment of a target container according to container required configuration information carried in the algorithm image running standard, starting the target container, and running the algorithm image.

4. The method of claim 3, wherein, After the identification of the algorithm identifier carried in the privacy computing task running instruction and before the configuration of the running environment of the target container according to the container required configuration information carried in the algorithm image running standard, the method further comprises: identifying a container communication mode carried in tag information of the algorithm image, and obtaining the target container based on the container communication mode.

5. The method according to any one of claims 1 to 4, characterized in that, The method further comprises: identifying log address information carried in the algorithm image; and storing a running log generated by the running of the algorithm image according to the log address information.

6. The method according to any one of claims 1 to 4, characterized in that, The method further comprises: identifying algorithm information carried in the algorithm image, and displaying the algorithm information.

7. The method according to any one of claims 1 to 4, characterized in that, After the identification that the privacy algorithm corresponding to the algorithm identifier is a privacy algorithm designed based on another privacy computing platform and before the running of the algorithm image of the algorithm identifier obtained from the pre-connected image repository in a containerized manner, the method further comprises: obtaining to-be-verified data carried in the algorithm image, comparing the to-be-verified data with benchmark verification data provided by the other privacy computing platform for the algorithm image, and if the comparison result is that both are consistent, performing a subsequent step of running the algorithm image of the algorithm identifier obtained from the pre-connected image repository in a containerized manner.

8. The method according to any one of claims 1 to 4, characterized in that, Before the running, in a containerized manner, of the algorithm image corresponding to the algorithm identifier obtained from the pre-connected image repository, the method further comprises: Performing a vulnerability scan on the algorithm image, and if the scan result is no vulnerability of a set security threat level, then performing the subsequent step of running, in a containerized manner, of the algorithm image corresponding to the algorithm identifier obtained from the pre-connected image repository.

9. A privacy computing device, comprising: The apparatus comprises: A receiving module configured to receive a privacy computing task running instruction and identify an algorithm identifier carried in the privacy computing task running instruction; The running module is configured to, if it is identified that the privacy algorithm corresponding to the algorithm identifier is a privacy algorithm designed based on other privacy computing platforms, create a component instance of the privacy algorithm corresponding to the algorithm identifier, and perform service registration on the component instance; mask the corresponding algorithm engine of the other privacy computing platform to which the privacy algorithm belongs, run, in a containerized manner, the algorithm image of the algorithm identifier obtained from the pre-connected image repository, and jointly perform corresponding privacy computing based on the privacy algorithm in the algorithm image and the self-privacy algorithm; wherein the algorithm image is generated by the device where the other privacy computing platform is located based on the privacy algorithm and a set algorithm image generation standard, the privacy algorithm belongs to the device where the other privacy computing platform is located; the privacy algorithm is decoupled from the other privacy computing platform and the corresponding algorithm engine of the other privacy computing platform.

10. The apparatus of claim 9, wherein, The running module is specifically configured to identify an algorithm image running standard indicated by the algorithm image generation standard, and run the algorithm image in a containerized manner according to the algorithm image running standard.

11. The apparatus of claim 10, wherein, The running module is specifically configured to configure a running environment of a target container according to configuration information required by a container carried in the algorithm image running standard, start the target container, and run the algorithm image.

12. The device of any one of claims 9-11, wherein, The running module is further configured to obtain to-be-verified data carried by the algorithm image, compare the to-be-verified data with reference verification data provided by the other privacy computing platform for the algorithm image, and if the comparison result is that both are consistent, then perform the subsequent step of running, in a containerized manner, of the algorithm image corresponding to the algorithm identifier obtained from the pre-connected image repository.

13. The apparatus of any one of claims 9-11, wherein, The running module is further configured to perform a vulnerability scan on the algorithm image, and if the scan result is no vulnerability of a set security threat level, then perform the subsequent step of running, in a containerized manner, of the algorithm image corresponding to the algorithm identifier obtained from the pre-connected image repository.

14. An electronic device, comprising: It comprises a processor and a memory, wherein the memory stores program code, and when the program code is executed by the processor, the processor executes the steps of the privacy computing method in any one of claims 1-8. It comprises a processor and a memory, wherein the memory stores program code, and when the program code is executed by the processor, the processor executes the steps of the privacy computing method in any one of claims 1-8.

15. A computer-readable storage medium, characterized in that, It comprises program codes for making the electronic device perform the steps of the privacy computation method according to any one of claims 1-8 when the storage medium is run on the electronic device.

Citation Information

Patent Citations

  • Development method of DevOps of AI algorithm service

    CN116301876A

  • Privacy computing device and privacy computing method

    CN116366227A