Task execution method and device based on trusted data space, equipment and medium

By analyzing the target computing code of the data user and generating data flow calculation diagrams, allocating the computing engine and issuing tasks, it solves the problem of difficulty in making full use of distributed computing resources in the existing technology, and realizes efficient and secure data computing and storage.

CN119938272APending Publication Date: 2025-05-06LINGSHU TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510008505.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-03
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

It is difficult for the prior art to make full use of distributed computing resources to achieve unified, secure, convenient and efficient data computing and data storage.

Method used

By code analysis of the target calculation code of the data user, a data flow calculation diagram is generated, and a calculation subtask and task execution plan is generated based on the diagram, the calculation engine is allocated, and the task is sent to the trusted data space node for execution.

Benefits of technology

The storage resources and computing resources of trusted data space nodes are fully utilized, ensuring the reliability and security of data processing, and improving data processing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119938272A_ABST
    Figure CN119938272A_ABST
Patent Text Reader

Abstract

The invention discloses a task execution method and device based on trusted data space, equipment and a medium. The method comprises the steps of performing code analysis on a target calculation code released by a data user, and generating a data stream calculation graph and at least one target data resource required to be called in a calculation process; according to each operation node and each node edge in the data flow calculation graph, generating at least one calculation subtask and a task execution plan based on each target data resource, and allocating a corresponding calculation engine to each calculation subtask; and according to the task execution plan, issuing each calculation sub-task to the trusted data space node to which the corresponding calculation engine belongs, so that the trusted data space node calls the own calculation engine to execute the calculation sub-task, and generates and feeds back a task execution result. According to the technical scheme of the embodiment of the invention, full utilization of storage resources and computing resources of trusted data space nodes is realized, and the data processing efficiency is improved while the data processing reliability and security are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of trusted space secure computing technology, and in particular to a task execution method, device, equipment and medium based on a trusted data space. Background Art

[0002] In the field of trusted space secure computing, the trusted data space can contain multiple nodes, each of which runs in TEE (Trusted Execution Environment). Data processing programs can be run on the nodes, and data security can be guaranteed through TEE isolation and memory encryption technology.

[0003] However, the data processing programs on the nodes are all run on a single machine, and the data is also stored on a single machine. The data provider needs to send the data to the data user and then perform data calculation on the data user's node, which does not fully utilize the data provider's node computing power. On the other hand, when the amount of data increases and a single machine cannot complete all data storage, the data needs to be stored on multiple machines. Therefore, how to make full use of distributed computing resources to achieve unified, secure, convenient and efficient data computing and data storage has become a problem that needs to be solved urgently. Summary of the invention

[0004] The present invention provides a task execution method, device, equipment and medium based on a trusted data space to fully utilize the storage resources and computing resources of the trusted data space nodes, ensure the reliability and security of data processing while improving data processing efficiency.

[0005] According to one aspect of the present invention, a task execution method based on a trusted data space is provided, which is applied to a blockchain node, and the method includes:

[0006] Obtain the target computing code published by the data user, and perform code parsing on the target computing code to generate a data flow computing graph and at least one target data resource required to be called in the computing process; the data flow computing graph includes at least one computing node with data logic operation as a node and at least one node edge with data flow as an edge;

[0007] According to each computing node and each node edge in the data flow computing graph, based on each of the target data resources, at least one computing subtask and a task execution plan are generated, and a corresponding computing engine is allocated to each of the computing subtasks;

[0008] According to the task execution plan, each computing subtask is sent to the trusted data space node to which the corresponding computing engine belongs, so that the trusted data space node can call its own computing engine to execute the computing subtask, generate and feedback the task execution result.

[0009] According to another aspect of the present invention, a task execution method based on a trusted data space is provided, which is applied to a trusted data space node, wherein the trusted data space node includes a computing engine and a data storage engine, and the method includes:

[0010] Obtain the computing subtask issued by the blockchain node, and execute the computing subtask through the computing engine;

[0011] In response to a call request from a computing engine of a participating data space node to a node data resource under its own node, a data storage engine under its own node performs a remote authentication report verification on the computing engine of the participating data space node; the participating data space node is a trusted data space node other than its own node that participates in task calculation;

[0012] If the report verification is passed, the node data resources under the node itself are encrypted to obtain encrypted resource data;

[0013] The encrypted resource data is fed back to the computing engines of the participating data space nodes.

[0014] According to another aspect of the present invention, a task execution device based on a trusted data space is provided, which is configured in a blockchain node, and the device includes:

[0015] A code acquisition module is used to acquire the target computing code published by the data user, and to perform code analysis on the target computing code to generate a data flow computing graph and at least one target data resource required to be called in the computing process; the data flow computing graph includes at least one computing node with a data logic operation as a node and at least one node edge with a data flow as an edge;

[0016] A plan generation module, configured to generate at least one computing subtask and a task execution plan based on each computing node and each node edge in the data flow computing graph and each target data resource, and to allocate a corresponding computing engine to each computing subtask;

[0017] The task sending module is used to send each computing subtask to the trusted data space node to which the corresponding computing engine belongs according to the task execution plan, so that the trusted data space node can call its own computing engine to execute the computing subtask, generate and feedback the task execution result.

[0018] According to another aspect of the present invention, a task execution device based on a trusted data space is provided, which is configured in a trusted data space node, wherein the trusted data space node includes a computing engine and a data storage engine, including:

[0019] A subtask acquisition module, used to acquire the computing subtasks issued by the blockchain node and execute the computing subtasks through the computing engine;

[0020] A call request response module is used to respond to the call request of the computing engine of the participating data space node to the node data resource under its own node, and the data storage engine under its own node performs remote authentication report verification on the computing engine of the participating data space node; the participating data space node is a trusted data space node other than its own node that participates in task calculation;

[0021] The data encryption module is used to encrypt the node data resources under its own node to obtain encrypted resource data if the report verification passes;

[0022] A data feedback module is used to feed back the encrypted resource data to the computing engines participating in the data space nodes.

[0023] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:

[0024] at least one processor; and

[0025] a memory communicatively connected to the at least one processor; wherein,

[0026] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the task execution method based on the trusted data space described in any embodiment of the present invention.

[0027] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the task execution method based on a trusted data space described in any embodiment of the present invention when executed.

[0028] The technical solution of the embodiment of the present invention parses the target computing code of the data user to generate a data flow computing graph and the target data resources required to be called in the computing process, generates at least one computing subtask and a task execution plan based on each operation node and each node edge in the data flow computing graph and each target data resource, and allocates a corresponding computing engine to each computing subtask. According to the task execution plan, each computing subtask is sent to the trusted data space node to which the corresponding computing engine belongs, thereby fully utilizing the storage resources and computing resources of the trusted data space node. On the premise of ensuring the safe circulation and use of data, the computing power of each distributed node is fully utilized to jointly complete the computing task and output the final result, thereby ensuring the reliability and security of data processing while improving the data processing efficiency.

[0029] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present invention, nor are they intended to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0031] Figure 1 is a flowchart of a task execution method based on a trusted data space provided according to Embodiment 1 of the present invention;

[0032] Figure 2 is a flowchart of a task execution method based on a trusted data space provided according to Embodiment 2 of the present invention;

[0033] Figure 3 is a schematic diagram of the execution process of a task execution method based on a trusted data space provided according to Embodiment 3 of the present invention;

[0034] Figure 4 is a structural diagram of a task execution device based on a trusted data space provided according to a fourth embodiment of the present invention;

[0035] Figure 5 is a structural diagram of a task execution device based on a trusted data space provided according to Embodiment 5 of the present invention;

[0036] Figure 6 It is a structural schematic diagram of an electronic device for implementing the task execution method based on a trusted data space according to an embodiment of the present invention. DETAILED DESCRIPTION

[0037] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.

[0038] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0039] Embodiment 1

[0040] Figure 1 This is a flowchart of a task execution method based on a trusted data space provided in the first embodiment of the present invention. This embodiment can be applied to the case of distributed task computing under a trusted data space. The method can be executed by a task execution device based on a trusted data space. The task execution device based on a trusted data space can be implemented in the form of hardware and / or software. The task execution device based on a trusted data space can be configured in an electronic device, such as a blockchain node. Figure 1 As shown, the method is applied to a blockchain node, specifically including:

[0041] S110. Obtain the target computing code published by the data user, and perform code parsing on the target computing code to generate a data flow computing graph and at least one target data resource required to be called during the computing process; the data flow computing graph includes at least one computing node with data logic operation as a node and at least one node edge with data flow as an edge.

[0042] S120. Generate at least one computing subtask and a task execution plan according to each computing node and each node edge in the data flow computing graph and based on each target data resource, and allocate a corresponding computing engine to each computing subtask.

[0043] S130. According to the task execution plan, each computing subtask is sent to the trusted data space node to which the corresponding computing engine belongs, so that the trusted data space node can call its own computing engine to execute the computing subtask, generate and feedback the task execution result.

[0044] Among them, the target computing code can be the computing code written by the data user using a code compiler combined with the selected target data resources; the target data resources can be the target data resources selected by the data user from multiple candidate data resources based on its own computing needs.

[0045] Among them, the data flow calculation graph is used to represent the data calculation process as well as the target data resources and calculation functions required in the calculation process.

[0046] Specifically, the blockchain node calls the computing task management smart contract to scan and parse the target computing code, generate a data flow computing graph, and at least one target data resource required to be called during the computing process. The data flow computing graph uses data logic operations as nodes and data flows as node edges. Data logic operations can include addition operations, summary operations, and other custom operation functions. The data flow can specifically be the specific process of data operations, that is, the data flow direction of the intermediate parameter data obtained through the operation.

[0047] The blockchain node can generate at least one computing subtask and task execution plan based on each computing node and each node edge in the data flow computing graph and each target data resource. Each computing subtask can call the computing engine to execute in parallel. Among them, the task execution plan can be the task execution order between each computing subtask, such as executing computing subtask B after computing subtask A is executed, or determining the computing subtasks that can be calculated at the same time and calling the corresponding computing engine to execute in parallel.

[0048] In an optional embodiment, according to each computing node and each node edge in the data flow computing graph, based on each target data resource, at least one computing subtask and a task execution plan are generated, and a corresponding computing engine is allocated to each computing subtask, including:

[0049] Step a1: Perform resource security compliance testing on each target data resource to obtain security compliance testing results.

[0050] Exemplarily, a resource security compliance check may be performed on the target data resource based on the compliant data computing operations corresponding to the target data resource; if all the data computing operations in which the target data resource participates are its corresponding compliant data computing operations, it may be determined that the security compliance check result of the target data resource has passed.

[0051] Step a2: If the security compliance test result passes, at least one computing subtask and task execution plan are generated according to each computing node and each node edge in the data flow computing graph.

[0052] Step a3: Obtain engine specification information corresponding to the computing engines under at least one trusted data space node, and allocate a corresponding computing engine to each computing subtask according to the engine specification information.

[0053] Trusted data space nodes can publish the engine specification information of their own computing engines in advance and store them on the chain, and the blockchain node's computing resource management smart contract will verify the information. The engine specification information may include unit computing price, CPU (Central Processing Unit) core number and network parameters.

[0054] At least one computing subtask and task execution plan are generated based on each computing node and each node edge in the data flow computing graph, and a corresponding computing engine is assigned to each computing subtask based on the specification information of each engine. When assigning computing engines, the principle of data proximity can be considered, that is, computing engines with similar distances are assigned to each computing subtask; at the same time, the unit computing price and computing time of the computing engine can also be considered, and the computing subtasks that can be operated at the same time are executed in parallel as much as possible.

[0055] Optionally, you can generate data proximity principle constraints, computing cost total price constraints, computing time consumption constraints and parallel execution constraints; with the calculation subtask allocation as the goal, combined with the above four constraints, solve the optimization function to obtain the optimal solution, and generate a task execution plan based on the optimal solution.

[0056] According to the task execution plan, each computing subtask is sent to the trusted data space node to which the corresponding computing engine belongs. The corresponding trusted data space node calls its own computing engine to execute the computing subtask, generate and feedback the task execution result. When the computing engine needs to call data resources, it can send a resource call request to the data storage engine where the data resource is located.

[0057] Furthermore, if the security compliance test result of the target data resource fails, the call to the target data resource is terminated, and the generation of the computing subtask and task execution plan is ended.

[0058] The above technical solution ensures the call security and compliance of the target data resources by performing resource security compliance detection on the target data resources. The engine specification information of the computing engine of each trusted data space node is considered when performing computing subtasks, thus achieving the reliability and accuracy of the allocation of computing subtasks.

[0059] In order to further improve the accuracy of resource compliance detection of target data resources, in an optional embodiment, resource security compliance detection is performed on each target data resource to obtain security compliance detection results, including:

[0060] Step b1: According to the data flow calculation diagram, determine the data logic operations that each target data resource needs to participate in.

[0061] Specifically, taking any data resource in the data flow calculation graph as the starting point, traverse all the operation nodes that can be reached from the starting point, and use the data logic operation corresponding to each traversed operation node as the data logic operation that the target data resource needs to participate in.

[0062] Step b2: for any target data resource, determine a set of executable operations for the target data resource.

[0063] It should be noted that the data logic operations that the computing engine and specific encoders can support are limited. The security and compliance detection of data resources can be formulated using a blacklist and whitelist mechanism, or executed using rule matching templates.

[0064] Specifically, executable operation sets corresponding to different data resources are predetermined, and the executable operation sets include data logic operations that can be executed by the data resources.

[0065] Step b3: determine whether the data logic operation that the target data resource needs to participate in is in the executable operation set, and obtain a determination result.

[0066] Exemplarily, assume that the execution operation set of the target data resource C is {operation 1, operation 2, operation 3}. If the data logic operations that the target data resource needs to participate in are operation 1 and operation 2, it can be determined that the data logic operations that the target data resource needs to participate in are in its corresponding executable operation set, and the security compliance test of the target data resource has passed; if the data logic operations that the target data resource needs to participate in are operation 5 and operation 6, it can be determined that the data logic operations that the target data resource needs to participate in are not in its corresponding executable operation set, and the security compliance test of the target data resource has not passed.

[0067] Step b4: Determine the security compliance test result of the target data resource based on the judgment result.

[0068] Furthermore, the resource security compliance check of the target data resource can also be to determine whether a predetermined necessary operation, such as data desensitization or data encryption, is performed before or after a certain data logic operation of the target data resource is performed. If the necessary operation is not performed, it can be considered that the security compliance check of the target data resource has failed; if the necessary operation is performed, it can be considered that the security compliance check of the target data resource has passed.

[0069] The above technical solution achieves accurate detection of the security and compliance of the target data resources by traversing to determine the data logic operations that the target data resources need to participate in, and judging whether the required data logic operations exist in their corresponding executable operation set, thereby improving the reliability and accuracy of the security and compliance detection results of the target data resources.

[0070] It should be noted that the target computing code published by the data user on the blockchain is generated by the data user based on the data resource network diagram published on the chain. The data resource network diagram records different types of callable data resources and resource relationships between different data resources. Therefore, this embodiment also provides a method for generating a data resource network diagram, including the following steps:

[0071] Step c1: Obtain the metadata and its corresponding digital signature published on the chain by at least one data provider, and form data resources with the metadata and its corresponding digital signature corresponding to each data provider.

[0072] Specifically, the data provider can use the data storage engine under the trusted data space node to store the original data in the trusted data space node. The trusted data space node uses the trusted execution environment to encrypt and store the stored original data. The encryption key is securely stored in the trusted execution environment and cannot be obtained by the outside world to ensure data security.

[0073] The data storage engine uses metadata intelligent recognition technology to automatically extract metadata related to the original data. The metadata related to the original data can include:

[0074] a. Transaction-related metadata: owner, price, access address and protocol, and computing node security requirements.

[0075] b. Descriptive metadata: describes the basic information of the data, such as content, subject, date, etc.

[0076] c. Structural metadata: describes the structure, format, fields, relationships, etc. of the data.

[0077] d. Administrative metadata: information related to data storage, management, access control, etc.

[0078] e. Technical metadata: technical details such as data storage technology, encoding, processing flow, etc.

[0079] f. Compliance metadata: involves data privacy protection, compliance requirements, etc.

[0080] g. Business metadata: describes the meaning of data in the business, business rules and objectives, etc.

[0081] The data provider digitally signs the metadata, and the data storage engine also signs the metadata using the private key of the trusted data space node, and sends the metadata and its corresponding digital signature to the blockchain to form data resources.

[0082] Step c2: Determine the semantic relationship between the data resources based on the resource characteristics of the data resources.

[0083] The semantic relationship between data resources may be a data association relationship between data resources. For example, if the data resources are of the same type, the corresponding semantic relationship may be resources of the same type. If the data resources are in a containment relationship, such as vehicle data and vehicle speed, the semantic relationship may be a data containment relationship.

[0084] Step c3: Generate a data resource network diagram with data resources as nodes and semantic relationships as edges, and store the data resource network diagram on-chain so that data users can call the data resource network diagram to generate target computing code.

[0085] Blockchain nodes can call data resource management smart contracts to generate a data resource network diagram with data resources as nodes and semantic relationships as edges, and store the data resource network diagram on the chain. Data users can call the data resource network diagram and select the corresponding data resources based on their actual computing needs, and then generate the target computing code.

[0086] Optionally, when there is a need to add, reduce or update data resources, the data resource management smart contract can automatically update the data resource network diagram.

[0087] The above technical solution forms data resources through the metadata uploaded to the chain by the data provider and its corresponding digital signature, and generates a data resource network diagram based on the semantic relationship between data resources and in combination with each data resource, thereby realizing the precise construction of the data resource network diagram, thereby facilitating subsequent data users to retrieve data resources based on the data resource network diagram, providing convenience for data users and improving the retrieval efficiency of data resources.

[0088] This embodiment also provides a method for a data user to select data resources based on a data resource network diagram and generate target computing code, which can be specifically performed by a specific code editor. The specific steps are as follows:

[0089] Step d1: Based on the candidate data resources for task execution selected by the data user through the data resource network diagram, an initial code is generated.

[0090] Data users can use the data resource network diagram to retrieve candidate data resources that they need to process and calculate for task execution based on their own needs. Using the relevant code framework, they can write the initial code that can run on the computing engine in a specific code editor.

[0091] Step d2: execute the initial code and determine similar data resources based on the data resource network diagram.

[0092] The initial code references the required data resource by referencing the resource identifier of the candidate data resource. The resource identifier is automatically generated based on the hash value of the data resource when the data resource is on-chain.

[0093] The specific code editor analyzes the resource prices of the referenced candidate data resources and displays the total price of the data resources required for the current initial code execution in real time. Through the data resource network diagram, similar data resources similar to the candidate data resources can be found. If there are similar data resources with lower prices, similar data resources are determined and recommended to data users in real time.

[0094] Step d3: In response to the data user's request for selecting similar data resources, based on the similar data resources, the initial code is updated to obtain the target calculation code.

[0095] The data user can select similar data resources based on the similar data resources recommended by the code editor. In response to the data user's request to select similar data resources, the code editor replaces the corresponding candidate data resources with similar data resources, and updates the initial code based on the similar data resources to obtain the target computing code.

[0096] The above technical solution generates an initial code that meets the computing needs of the data user, and recommends similar resource codes in real time based on the candidate resource codes selected by the data user, thereby ensuring that the total price of resources consumed by the target computing code is low, thereby improving the user experience of the data user.

[0097] It is understandable that when the computing engine of each trusted data space node completes the computing subtask, the blockchain node can pay the corresponding computing fees to each trusted data space node based on the task completion status.

[0098] In an optional embodiment, after each computing subtask is sent to the trusted data space node to which the corresponding computing engine belongs according to the task execution plan, so that the trusted data space node calls its own computing engine to execute the computing subtask, generates and feeds back the task execution result, it also includes:

[0099] Step e1, obtaining the task execution results fed back by each trusted data space node; the task execution results include the calculated measurement value and the task calculation status.

[0100] The calculation measurement value may be the number of calculations consumed by the calculation engine to execute the calculation subtask; the task calculation status may include not executed, calculating, and calculation completed.

[0101] The computing engine of each trusted data space uploads the computing measurement value and task computing status under its own node during the execution of computing subtasks.

[0102] Step e2: Determine whether the computing subtasks of each trusted data space node have been completed based on the computing status of each task.

[0103] If the task computing status uploaded by each computing engine is all completed, it can be determined that the computing subtask of the trusted data space node has been completed.

[0104] Step e3: If yes, determine the to-be-settled value attributes corresponding to each trusted data space node according to each calculated measurement value, and settle the corresponding to-be-settled value attributes to each trusted data space node.

[0105] According to the calculation measurement values ​​uploaded by each computing engine and the calculation unit price agreed in the computing engine specifications, the blockchain node uses the Token smart contract to automatically calculate the corresponding settlement value attributes of each trusted data space node, that is, the price to be paid, and pays the fees to each trusted data space node.

[0106] The above technical solution determines the to-be-settled value attributes corresponding to each trusted data space node based on the calculated measurement values ​​and task calculation status of each trusted data space node, thereby realizing fee settlement for each trusted data space node, ensuring that the computing engine of each trusted data space node completes the execution of its own task, and avoiding the occurrence of erroneous payment of fees caused by incomplete task execution.

[0107] The technical solution of the embodiment of the present invention parses the target computing code of the data user to generate a data flow computing graph and the target data resources required to be called in the computing process, generates at least one computing subtask and a task execution plan based on each operation node and each node edge in the data flow computing graph and each target data resource, and allocates a corresponding computing engine to each computing subtask. According to the task execution plan, each computing subtask is sent to the trusted data space node to which the corresponding computing engine belongs, thereby fully utilizing the storage resources and computing resources of the trusted data space node. On the premise of ensuring the safe circulation and use of data, the computing power of each distributed node is fully utilized to jointly complete the computing task and output the final result, thereby ensuring the reliability and security of data processing while improving the data processing efficiency.

[0108] Embodiment 2

[0109] Figure 2The flowchart of a task execution method based on a trusted data space provided in the second embodiment of the present invention is applicable to the case of distributed task computing under a trusted data space. The method can be executed by a task execution device based on a trusted data space. The task execution device based on a trusted data space can be implemented in the form of hardware and / or software. The task execution device based on a trusted data space can be configured in an electronic device, such as a trusted data space node. Figure 2 As shown, the method is applied to a trusted data space node, wherein the trusted data space node includes a computing engine and a data storage engine, and the specific method steps include:

[0110] S210. Obtain the computing subtask issued by the blockchain node, and execute the computing subtask through the computing engine.

[0111] S220. In response to the call request of the computing engine of the participating data space node to the node data resource under its own node, the data storage engine under its own node performs remote authentication report verification on the computing engine of the participating data space node; the participating data space node is the trusted data space node other than its own node that participates in the task calculation.

[0112] S230: If the report verification is passed, the node data resources under the own node are encrypted to obtain encrypted resource data.

[0113] S240. Feedback the encrypted resource data to the computing engines participating in the data space nodes.

[0114] Specifically, the computing engine of the trusted data space node executes the computing subtasks issued by the blockchain node. It should be noted that in the process of the computing engine executing the computing subtasks, there may be a need to call data resources stored in other trusted data space nodes, and there may be resource call requests for data resources sent by other trusted data space nodes.

[0115] In response to the call request of the computing engine of the participating data space node to the node data resource under its own node, the data storage engine under its own node performs remote authentication report verification on the computing engine of the participating data space node. Among them, the participating data space node is the trusted data space node other than its own node that participates in the task calculation.

[0116] The data storage engine of its own node verifies the remote authentication report of the computing engine of the participating data space node, confirms its identity, and verifies whether the TEE environment in which it is located meets the security requirements. If both the report verification and the TEE environment verification are passed, the node data resources under its own node are encrypted to obtain encrypted resource data to ensure the security of resource data.

[0117] In an optional embodiment, data encryption is performed on the node data resources under the own node to obtain encrypted resource data, including:

[0118] Step f1, obtain the first public key of the computing engine of the participating data space node, and obtain the second public key of the computing engine of the own node.

[0119] Step f2: Generate an encryption key based on the first public key and the second public key.

[0120] Specifically, an encryption key is generated according to the first public key and the second public key based on a preset key negotiation algorithm. For example, the key negotiation algorithm may be DH (Diffie-Hellman Key Exchange Algorithm).

[0121] Step f3: Use the encryption key to encrypt the node data resources under the own node to obtain encrypted resource data.

[0122] It should be noted that in order to ensure the security of data storage, the data resources stored under the trusted data space node are stored in encrypted form. Therefore, the data storage engine of the trusted data space node needs to first use the node private key to decrypt the node data resources under its own node to obtain the decrypted resource data, and then use the encryption key to encrypt the decrypted resource data to obtain encrypted resource data.

[0123] Feedback the encrypted resource data to the computing engine of the participating data space node. The computing engine of the participating data space node decrypts the encrypted resource data and continues to calculate according to the computing subtask.

[0124] It should be noted that because the two computing engines need to exchange the calculation results of the computing subtasks (that is, the intermediate results of the computing subtasks) with each other for data merging operations, their trusted data exchange method is consistent with the authentication and encryption transmission process used for data exchange between the computing engine and the data storage engine, which will not be elaborated in this embodiment.

[0125] This embodiment also provides a method for a data provider to upload data resources. Specifically, it includes the following steps:

[0126] Step g1, in response to the data provider's storage request for original data through the data storage engine, encrypt the original data to obtain node data resources, and store the node data resources in the data storage engine under its own node.

[0127] Step g2: The data storage engine uses the private key of the trusted data space node to sign the metadata of the original data to obtain the engine digital signature.

[0128] Step g3: Feedback the engine digital signature to the data provider, so that the data provider can store the metadata and its corresponding digital signature on the chain based on its own digital signature on the metadata and the digital signature of the engine.

[0129] Specifically, the data provider can use the data storage engine under the trusted data space node to store the original data in the trusted data space node. The trusted data space node uses the trusted execution environment to encrypt and store the stored original data. The encryption key is securely stored in the trusted execution environment and cannot be obtained by the outside world to ensure data security.

[0130] The data storage engine uses metadata intelligent recognition technology to automatically extract metadata related to the original data. The metadata related to the original data can include:

[0131] a. Transaction-related metadata: owner, price, access address and protocol, and computing node security requirements.

[0132] b. Descriptive metadata: describes the basic information of the data, such as content, subject, date, etc.

[0133] c. Structural metadata: describes the structure, format, fields, relationships, etc. of the data.

[0134] d. Administrative metadata: information related to data storage, management, access control, etc.

[0135] e. Technical metadata: technical details such as data storage technology, encoding, processing flow, etc.

[0136] f. Compliance metadata: involves data privacy protection, compliance requirements, etc.

[0137] g. Business metadata: describes the meaning of data in the business, business rules and objectives, etc.

[0138] The data provider digitally signs the metadata, and the data storage engine also signs the metadata using the private key of the trusted data space node, and sends the metadata and its corresponding digital signature to the blockchain to form data resources.

[0139] The technical solution of the embodiment of the present invention executes computing subtasks through a computing engine, and responds to the call request of the computing engine of the participating data space node to the node data resources under its own node. The data storage engine under its own node performs remote authentication report verification on the computing engine of the participating data space node, and encrypts the node data resources under its own node after the verification is passed to obtain encrypted resource data, and feeds back the encrypted resource data to the computing engine of the participating data space node, thereby realizing full utilization of the storage resources and computing resources of the trusted data space node. On the premise of ensuring the safe circulation and use of data, the computing power of each distributed node is fully utilized to jointly complete the computing task and output the final result, thereby ensuring the reliability and security of data processing while improving the data processing efficiency.

[0140] Embodiment 3

[0141] Figure 3 The following is a schematic diagram of the execution process of a task execution method based on a trusted data space provided in Embodiment 3 of the present invention. The present invention further provides a preferred embodiment based on the above embodiments.

[0142] like Figure 3 As shown, the specific execution process is as follows:

[0143] Each data provider uses the data storage engine of the trusted data space node in the TEE environment to store the original data in the trusted data space node. The trusted data space node uses the TEE environment to encrypt and store the stored original data. The encryption key is securely stored in the TEE environment and cannot be obtained by the outside world.

[0144] The data storage engine uses metadata intelligent recognition technology to automatically extract relevant metadata of the original data:

[0145] a. Transaction-related metadata: owner, price, access address and protocol, and computing node security requirements.

[0146] b. Descriptive metadata: describes the basic information of the data, such as content, subject, date, etc.

[0147] c. Structural metadata: describes the structure, format, fields, relationships, etc. of the data.

[0148] d. Administrative metadata: information related to data storage, management, access control, etc.

[0149] e. Technical metadata: technical details such as data storage technology, encoding, processing flow, etc.

[0150] f. Compliance metadata: involves data privacy protection, compliance requirements, etc.

[0151] g. Business metadata: describes the meaning of data in the business, business rules and objectives, etc.

[0152] The data provider digitally signs the metadata, and the data storage engine uses the private key of the trusted data space node to digitally sign the metadata. The metadata and digital signature are then sent to the blockchain to form data resources.

[0153] Blockchain nodes use the data resource management smart contract to build a data resource network diagram using the data resources in the data resource pool. Specifically, the data resource network diagram is built with data resources as nodes and the semantic relationships between data resources as edges; when there are new, reduced, or updated data resources, the data resource management smart contract automatically updates the data resource network diagram.

[0154] Data users retrieve the data they want to process and calculate through the data resource network diagram, and use the relevant code framework to write calculation codes that can run on the calculation engine in a specific code editor. The calculation code references the required data by referencing the identifier of the data resource (automatically generated by the hash value of the data resource when the data resource is uploaded to the blockchain); the specific code editor analyzes the price of the referenced data resource and displays the total price of the data resource currently spent on the execution of the calculation code in real time. It can also find similar data resources through the data resource network diagram. If there are data resources with lower prices, the specific code editor recommends lower-priced data resources in real time.

[0155] The data user publishes the written calculation code to the blockchain. The calculation task management smart contract scans the calculation code and generates a data flow calculation graph, which uses data operations (such as data addition, data aggregation, other custom functions, etc.) as nodes and data flows as edges.

[0156] The blockchain node analyzes the data flow calculation graph to identify data operations that violate the data resource security and compliance requirements. If they exist, the computing task application will be rejected. If not, a new computing task will be created. The specific analysis method is as follows:

[0157] Starting from any data resource, traverse all accessible data operation nodes at the starting point, and analyze whether each data operation meets the security and compliance requirements of the data resource. The specific method of whether the data operation meets the security and compliance requirements of the data resource is: the data operations that the computing engine and the specific code editor can support are limited, assuming that the set C = {operation 1, operation 2...}; the security and compliance requirements of data resources can be formulated using a blacklist and whitelist mechanism, or using a rule template, such as: specifying that only operations 3 and 4 can be performed for data resource A, or operations 5 and 6 cannot be used. Perform the above analysis on all data resources.

[0158] After the data flow calculation graph meets the security requirements through analysis, the calculation task management smart contract generates a calculation plan for the calculation task. The trusted data space node publishes the specifications of its own calculation engine to the blockchain in advance and verifies it through the calculation resource management smart contract. The specifications mainly include: unit calculation price, number of CPU cores, network conditions, etc. The calculation subtasks are generated according to the data flow calculation graph, and the calculation engine is assigned to each calculation subtask. When assigning, the following considerations are considered: 1. The principle of data proximity; 2. Low total price of calculation cost; 3. Short calculation time; 4. Try to be parallel. According to the above goals and constraints, an optimization function is generated, and the optimization function is solved to obtain the optimal solution. A complete calculation plan is generated based on the optimal solution.

[0159] According to the computing plan, the computing subtasks are distributed to various computing engines for execution. When the computing engine needs data resources, it sends a request to the data storage engine where the data resources are located.

[0160] After the trusted data space node receives the request, the data storage engine first verifies the remote authentication report of the computing engine, confirms its identity, and that the TEE it is in meets the security requirements. Then, it uses the computing engine's public key and its own public key to negotiate the data encryption key DEK using the DH key negotiation algorithm. After the data storage engine decrypts the data stored on the disk, it uses the DEK to encrypt the data and transmits it to the computing engine. After the computing engine decrypts the data, it continues to calculate according to the computing subtask.

[0161] During the calculation process, the calculation engine sends the calculation status to the blockchain to form a calculation process, which is convenient for the overall scheduling of the calculation task. At the same time, the calculation quantity is also uploaded to the blockchain to form the measurement of the calculation task. After the calculation of each party is completed, the result is returned to the initiator of the calculation task (data user). According to the value of the calculation measurement and the unit price agreed in the calculation engine specification, the blockchain uses the Token smart contract to automatically realize the payment of the fee, and the calculation task is completed.

[0162] Embodiment 4

[0163] Figure 4 A structural diagram of a task execution device based on a trusted data space provided in the fourth embodiment of the present invention. A task execution device based on a trusted data space provided in the embodiment of the present invention can be applied to the case of distributed task computing under a trusted data space. The task execution device based on a trusted data space can be implemented in the form of hardware and / or software. The device can be configured in a blockchain node, such as Figure 4 As shown, the device specifically includes: a code acquisition module 401, a plan generation module 402 and a task delivery module 403.

[0164] The code acquisition module 401 is used to acquire the target computing code published by the data user, and perform code analysis on the target computing code to generate a data flow computing graph and at least one target data resource required to be called in the computing process; the data flow computing graph includes at least one computing node with a data logic operation as a node and at least one node edge with a data flow as an edge;

[0165] A plan generation module 402 is used to generate at least one computing subtask and a task execution plan based on each computing node and each node edge in the data flow computing graph and each target data resource, and to allocate a corresponding computing engine to each computing subtask;

[0166] The task issuing module 403 is used to issue each computing subtask to the trusted data space node to which the corresponding computing engine belongs according to the task execution plan, so that the trusted data space node can call its own computing engine to execute the computing subtask, generate and feedback the task execution result.

[0167] The technical solution of the embodiment of the present invention parses the target computing code of the data user to generate a data flow computing graph and the target data resources required to be called in the computing process, generates at least one computing subtask and a task execution plan based on each operation node and each node edge in the data flow computing graph and each target data resource, and allocates a corresponding computing engine to each computing subtask. According to the task execution plan, each computing subtask is sent to the trusted data space node to which the corresponding computing engine belongs, thereby fully utilizing the storage resources and computing resources of the trusted data space node. On the premise of ensuring the safe circulation and use of data, the computing power of each distributed node is fully utilized to jointly complete the computing task and output the final result, thereby ensuring the reliability and security of data processing while improving the data processing efficiency.

[0168] Optionally, the plan generation module 402 includes:

[0169] A security compliance detection unit, used to perform resource security compliance detection on each of the target data resources to obtain a security compliance detection result;

[0170] A plan generation unit, configured to generate at least one computing subtask and a task execution plan according to each computing node and each node edge in the data flow computing graph if the security compliance detection result passes;

[0171] The specification information acquisition unit is used to acquire engine specification information corresponding to the computing engines under at least one trusted data space node, and allocate a corresponding computing engine to each computing subtask according to the engine specification information.

[0172] Optional safety compliance monitoring unit, specifically used for:

[0173] According to the data flow calculation diagram, determine the data logic operations that each of the target data resources needs to participate in respectively;

[0174] For any target data resource, determine a set of executable operations for the target data resource;

[0175] Determine whether the data logic operation required for the target data resource to participate is in the executable operation set, and obtain a determination result;

[0176] Based on the judgment result, a security compliance detection result of the target data resource is determined.

[0177] Optionally, the device further comprises:

[0178] A digital signature acquisition module is used to acquire metadata and its corresponding digital signature published on the chain by at least one data provider, and form data resources with the metadata and its corresponding digital signature corresponding to each of the data providers;

[0179] A semantic relationship determination module, used to determine the semantic relationship between the data resources according to the resource characteristics of the data resources;

[0180] The resource network diagram generation module is used to generate a data resource network diagram with data resources as nodes and the semantic relationship as edges, and store the data resource network diagram on-chain so that the data user can call the data resource network diagram to generate the target computing code.

[0181] Optionally, the target calculation code is generated as follows:

[0182] Based on the candidate data resources for task execution selected by the data user through the data resource network diagram, an initial code is generated;

[0183] Executing the initial code and determining similar data resources based on the data resource network diagram;

[0184] In response to a data user's request for selecting the similar data resource, the initial code is updated based on the similar data resource to obtain a target calculation code.

[0185] Optionally, the device further comprises:

[0186] A computing status acquisition module is used to obtain the task execution results fed back by each of the trusted data space nodes after sending each of the computing subtasks to the trusted data space node to which the corresponding computing engine belongs according to the task execution plan, so that the trusted data space node can call its own computing engine to execute the computing subtask, generate and feed back the task execution results; the task execution results include the calculation measurement value and the task calculation status;

[0187] A task execution judgment module is used to determine whether the computing subtasks of each of the trusted data space nodes have been completed according to the computing status of each of the tasks;

[0188] The value attribute determination module is used to determine the value attributes to be settled corresponding to each of the trusted data space nodes according to each of the calculated measurement values ​​if it is determined that the calculation subtasks of each of the trusted data space nodes have been completed, and settle the corresponding value attributes to be settled to each of the trusted data space nodes.

[0189] The task execution device based on the trusted data space provided in the embodiment of the present invention can execute the task execution method based on the trusted data space provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0190] Embodiment 5

[0191] Figure 5 The structure diagram of a task execution device based on a trusted data space provided in the fifth embodiment of the present invention. The task execution device based on a trusted data space provided in the embodiment of the present invention can be applied to the case of distributed task computing in a trusted data space. The task execution device based on a trusted data space can be implemented in the form of hardware and / or software. The device can be configured in a trusted data space node, such as Figure 5 As shown, the device specifically includes: a subtask acquisition module 501, a call request response module 502, a data encryption module 503 and a data feedback module 504. Among them,

[0192] The subtask acquisition module 501 is used to acquire the computing subtask issued by the blockchain node and execute the computing subtask through the computing engine;

[0193] The call request response module 502 is used to respond to the call request of the computing engine of the participating data space node to the node data resource under its own node, and the data storage engine under its own node performs remote authentication report verification on the computing engine of the participating data space node; the participating data space node is a trusted data space node other than its own node that participates in task calculation;

[0194] The data encryption module 503 is used to encrypt the node data resources under the node itself to obtain encrypted resource data if the report verification passes;

[0195] The data feedback module 504 is used to feed back the encrypted resource data to the computing engines participating in the data space nodes.

[0196] The technical solution of the embodiment of the present invention executes computing subtasks through a computing engine, and responds to the call request of the computing engine of the participating data space node to the node data resources under its own node. The data storage engine under its own node performs remote authentication report verification on the computing engine of the participating data space node, and encrypts the node data resources under its own node after the verification is passed to obtain encrypted resource data, and feeds back the encrypted resource data to the computing engine of the participating data space node, thereby realizing full utilization of the storage resources and computing resources of the trusted data space node. On the premise of ensuring the safe circulation and use of data, the computing power of each distributed node is fully utilized to jointly complete the computing task and output the final result, thereby ensuring the reliability and security of data processing while improving the data processing efficiency.

[0197] Optionally, the data encryption module 503 is specifically used for:

[0198] Obtaining the first public key of the computing engine of the participating data space node, and obtaining the second public key of the computing engine of the own node;

[0199] Generate an encryption key according to the first public key and the second public key;

[0200] The encryption key is used to encrypt the node data resources under the own node to obtain encrypted resource data.

[0201] Optionally, the device further comprises:

[0202] A storage request response module is used to respond to a storage request for original data by a data provider through a data storage engine, encrypt the original data, obtain a node data resource, and store the node data resource in the data storage engine under its own node;

[0203] A metadata signature module, used to sign the metadata of the original data using the private key of the trusted data space node through the data storage engine to obtain an engine digital signature;

[0204] The digital signature feedback module is used to feed back the engine digital signature to the data provider, so that the data provider can store the metadata and its corresponding digital signature on the chain based on its own digital signature on the metadata and the digital signature obtained by the engine digital signature.

[0205] The task execution device based on the trusted data space provided in the embodiment of the present invention can execute the task execution method based on the trusted data space provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0206] Embodiment 6

[0207] Figure 6 A schematic diagram of the structure of an electronic device 60 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or required herein.

[0208] like Figure 6 As shown, the electronic device 60 includes at least one processor 61, and a memory connected to the at least one processor 61, such as a read-only memory (ROM) 62, a random access memory (RAM) 63, etc., wherein the memory stores a computer program that can be executed by at least one processor, and the processor 61 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 62 or the computer program loaded from the storage unit 68 to the random access memory (RAM) 63. In the RAM 63, various programs and data required for the operation of the electronic device 60 can also be stored. The processor 61, the ROM 62, and the RAM 63 are connected to each other via a bus 64. An input / output (I / O) interface 65 is also connected to the bus 64.

[0209] A number of components in the electronic device 60 are connected to the I / O interface 65, including: an input unit 66, such as a keyboard, a mouse, etc.; an output unit 67, such as various types of displays, speakers, etc.; a storage unit 68, such as a disk, an optical disk, etc.; and a communication unit 69, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 69 allows the electronic device 60 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0210] The processor 61 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the processor 61 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 61 executes the various methods and processes described above, such as a task execution method based on a trusted data space.

[0211] In some embodiments, the task execution method based on the trusted data space can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 68. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 60 via the ROM 62 and / or the communication unit 69. When the computer program is loaded into the RAM 63 and executed by the processor 61, one or more steps of the task execution method based on the trusted data space described above can be performed. Alternatively, in other embodiments, the processor 61 can be configured to execute the task execution method based on the trusted data space by any other appropriate means (for example, by means of firmware).

[0212] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), load programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0213] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when the computer program is executed by the processor, the functions / operations specified in the flow chart and / or block diagram are implemented. The computer program may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.

[0214] In the context of the present invention, a computer-readable storage medium may be a tangible medium that may contain or store a computer program for use by or in combination with an instruction execution system, device or equipment. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0215] To provide interaction with a user, the systems and techniques described herein may be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, voice input, or tactile input).

[0216] The systems and techniques described herein may be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0217] A computing system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The client and server relationship is generated by computer programs running on the corresponding computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system to solve the defects of difficult management and weak business scalability in traditional physical hosts and VPS services.

[0218] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and this document does not limit this.

[0219] The above specific implementations do not constitute a limitation on the protection scope of the present invention. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

Claims

1. A task execution method based on a trusted data space, characterized in that: Applied to blockchain nodes, including: Obtain the target computing code published by the data user, and perform code parsing on the target computing code to generate a data flow computing graph and at least one target data resource required to be called in the computing process; the data flow computing graph includes at least one computing node with data logic operation as a node and at least one node edge with data flow as an edge; According to each computing node and each node edge in the data flow computing graph, based on each of the target data resources, at least one computing subtask and a task execution plan are generated, and a corresponding computing engine is allocated to each of the computing subtasks; According to the task execution plan, each computing subtask is sent to the trusted data space node to which the corresponding computing engine belongs, so that the trusted data space node can call its own computing engine to execute the computing subtask, generate and feedback the task execution result.

2. The method according to claim 1, characterized in that The step of generating at least one computing subtask and a task execution plan based on each computing node and each node edge in the data flow computing graph and each target data resource, and allocating a corresponding computing engine to each computing subtask includes: Performing resource security compliance testing on each of the target data resources to obtain security compliance testing results; If the security compliance test result passes, at least one computing subtask and a task execution plan are generated according to each computing node and each node edge in the data flow computing graph; The engine specification information corresponding to the computing engines under at least one trusted data space node is obtained, and a corresponding computing engine is allocated to each computing subtask according to the engine specification information.

3. The method according to claim 2, characterized in that The performing of resource security compliance detection on each of the target data resources to obtain security compliance detection results includes: According to the data flow calculation diagram, determine the data logic operations that each of the target data resources needs to participate in respectively; For any target data resource, determine a set of executable operations for the target data resource; Determine whether the data logic operation required for the target data resource to participate is in the executable operation set, and obtain a determination result; Based on the judgment result, a security compliance detection result of the target data resource is determined.

4. The method according to claim 1, characterized in that The method further comprises: Obtain metadata and its corresponding digital signature published on the chain by at least one data provider, and form data resources with the metadata and their corresponding digital signatures corresponding to each of the data providers; Determining semantic relationships between the data resources according to resource characteristics of the data resources; Generate a data resource network diagram with data resources as nodes and the semantic relationships as edges, and store the data resource network diagram on-chain so that the data user can call the data resource network diagram to generate target computing code.

5. The method according to claim 4, characterized in that The target calculation code is generated as follows: Based on the candidate data resources for task execution selected by the data user through the data resource network diagram, an initial code is generated; Executing the initial code and determining similar data resources based on the data resource network diagram; In response to a data user's request for selecting the similar data resource, the initial code is updated based on the similar data resource to obtain a target calculation code.

6. The method according to claim 1, characterized in that After sending each of the computing subtasks to the trusted data space node to which the corresponding computing engine belongs according to the task execution plan, so that the trusted data space node can call its own computing engine to execute the computing subtask and generate and feedback the task execution result, the method further includes: Obtaining the task execution results fed back by each of the trusted data space nodes; the task execution results include calculation measurement values ​​and task calculation status; Determining whether the computing subtasks of each of the trusted data space nodes have been completed according to the computing status of each of the tasks; If so, then the to-be-settled value attributes corresponding to each of the trusted data space nodes are determined according to each of the calculated measurement values, and the corresponding to-be-settled value attributes are settled to each of the trusted data space nodes.

7. A task execution method based on a trusted data space, characterized in that: Applied to a trusted data space node, the trusted data space node includes a computing engine and a data storage engine, including: Obtain the computing subtask issued by the blockchain node, and execute the computing subtask through the computing engine; In response to a call request from a computing engine of a participating data space node to a node data resource under its own node, a data storage engine under its own node performs a remote authentication report verification on the computing engine of the participating data space node; the participating data space node is a trusted data space node other than its own node that participates in task calculation; If the report verification is passed, the node data resources under the node itself are encrypted to obtain encrypted resource data; The encrypted resource data is fed back to the computing engines of the participating data space nodes.

8. The method according to claim 7, characterized in that The step of encrypting the node data resources under the own node to obtain encrypted resource data includes: Obtaining the first public key of the computing engine of the participating data space node, and obtaining the second public key of the computing engine of the own node; Generate an encryption key according to the first public key and the second public key; The encryption key is used to encrypt the node data resources under the own node to obtain encrypted resource data.

9. The method according to claim 7, characterized in that: The method further comprises: In response to a data provider's request for storage of original data through a data storage engine, encrypt the original data to obtain a node data resource, and store the node data resource in a data storage engine under its own node; The data storage engine uses the private key of the trusted data space node to sign the metadata of the original data to obtain an engine digital signature; The engine digital signature is fed back to the data provider, so that the data provider can store the metadata and its corresponding digital signature on the chain based on its own digital signature on the metadata and the digital signature obtained by the engine digital signature.

10. A task execution device based on a trusted data space, characterized in that: Configured on the blockchain node, including: A code acquisition module is used to acquire the target computing code published by the data user, and to perform code analysis on the target computing code to generate a data flow computing graph and at least one target data resource required to be called in the computing process; the data flow computing graph includes at least one computing node with a data logic operation as a node and at least one node edge with a data flow as an edge; A plan generation module, configured to generate at least one computing subtask and a task execution plan based on each computing node and each node edge in the data flow computing graph and each target data resource, and to allocate a corresponding computing engine to each computing subtask; The task sending module is used to send each computing subtask to the trusted data space node to which the corresponding computing engine belongs according to the task execution plan, so that the trusted data space node can call its own computing engine to execute the computing subtask, generate and feedback the task execution result.

11. A task execution device based on a trusted data space, characterized in that: Configured in a trusted data space node, the trusted data space node includes a computing engine and a data storage engine, including: A subtask acquisition module, used to acquire the computing subtasks issued by the blockchain node and execute the computing subtasks through the computing engine; A call request response module is used to respond to the call request of the computing engine of the participating data space node to the node data resource under its own node, and the data storage engine under its own node performs remote authentication report verification on the computing engine of the participating data space node; the participating data space node is a trusted data space node other than its own node that participates in task calculation; The data encryption module is used to encrypt the node data resources under its own node to obtain encrypted resource data if the report verification passes; A data feedback module is used to feed back the encrypted resource data to the computing engines participating in the data space nodes.

12. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the task execution method based on the trusted data space as described in any one of claims 1-6 and / or 7-9.

13. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the task execution method based on a trusted data space as described in any one of claims 1-6 and / or 7-9 when executed.