Private collaboration system and method with control plane and data plane separated

By implementing a privacy collaboration system that separates the control plane and the data plane in the blockchain network, the problem of insufficient expansion of privacy collaboration in the existing technology is solved, efficient and secure privacy collaboration is achieved, and a large number of member expansion is supported.

CN120046192APending Publication Date: 2025-05-27ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510125537.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-26
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

In the prior art, the privacy collaboration model has serious shortcomings in scalability, which leads to excessive time-consuming, low efficiency, and prone to misunderstandings or deviations.

Method used

By implementing a privacy collaboration system that separates the control plane and the data plane in the blockchain network, the decentralized characteristics of the blockchain network are used to support a large expansion of the number of members, and the control plane is realized on the chain through smart contract technology and the data plane is realized using off-chain resources.

Benefits of technology

It realizes efficient privacy collaboration, supports a large number of member expansion, avoids the problem of excessive load on the master node, and has strong scalability and high security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120046192A_ABST
    Figure CN120046192A_ABST
Patent Text Reader

Abstract

The invention provides a privacy collaboration system and method with a control plane and a data plane separated, which are used for realizing privacy collaboration among at least a part of members in a plurality of members, and a block chain node is deployed on a node device corresponding to each member. A block chain network to which the block chain node belongs contains a privacy cooperation smart contract for realizing privacy cooperation; the system comprises a control plane, and the control plane is used for calling the privacy collaboration smart contract according to a block chain transaction which is submitted to the block chain network and is used for privacy collaboration; and if an event which is generated after the privacy cooperation smart contract is called and is related to privacy cooperation between members is monitored, correspondingly generating a resource scheduling instruction aiming at the data plane, and the data plane is used for distributing off-chain resources on the node equipment corresponding to the members confirmed to participate in the privacy cooperation according to the resource scheduling instruction issued by the control plane so as to be used for a privacy cooperation process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of blockchain technology, and particularly to a privacy collaboration system and method with separated control plane and data plane. Background Art

[0002] Privacy collaboration refers to the cooperation among multiple participants to achieve common goals or complete specific tasks while ensuring that the sensitive information of each party is not disclosed. This cooperation can involve various forms such as data sharing, joint research, and collaborative work. Its core is to promote the effective utilization and value creation of data while protecting privacy. For example, secure multi-party computation (MPC) is a key technical means to achieve privacy collaboration, which allows participants to jointly execute calculations without revealing their respective input data.

[0003] In related technologies, it is often necessary for members to conduct intention negotiation through offline communication. After determining the intention, it is necessary for members to further establish network connections, allocate computing resources for privacy collaboration, etc. Since these processes need to rely on manual implementation, the time-consuming of privacy collaboration is too long, the efficiency is too low, and it is easy for members to have misunderstandings or deviations in offline communication.

[0004] In addition, privacy collaboration in related technologies often adopts modes such as peer-to-peer (P2P) and one-master-many-slaves. In the peer-to-peer (P2P) mode, since connections need to be established pairwise among members, its scalability is limited by the network topology and direct connections among members. As the number of members increases, it becomes more and more difficult to maintain the stability and efficiency of the network. In the one-master-many-slaves mode, it depends on one or a few members (master nodes, or servers) to manage and coordinate other members (slave nodes, or clients). As the number of slave nodes increases, the load on the master node will rise sharply, resulting in performance bottlenecks. In short, the privacy collaboration modes in related technologies have serious shortcomings in terms of scalability. Summary of the Invention

[0005] In view of this, this specification provides a privacy collaboration system and method with separated control plane and data plane to solve the deficiencies in related technologies.

[0006] Specifically, this specification is implemented through the following technical solutions:

[0007] According to the first aspect of the embodiments of the present specification, a privacy collaboration system with separated control plane and data plane is provided, which is used to implement privacy collaboration among at least some of multiple members. A blockchain node is deployed on the node device corresponding to each member, and the blockchain network to which the blockchain node belongs includes a privacy collaboration smart contract for implementing privacy collaboration; the system includes:

[0008] A control plane, which is used to: call the privacy collaboration smart contract according to the blockchain transaction for privacy collaboration submitted to the blockchain network; and, if an event related to the privacy collaboration among members is generated after the privacy collaboration smart contract is called, generate a resource scheduling instruction for the data plane accordingly;

[0009] A data plane, which is used to: allocate the off-chain resources on the node devices corresponding to the members confirmed to participate in the privacy collaboration according to the resource scheduling instruction issued by the control plane, for use in the privacy collaboration process.

[0010] According to the second aspect of the embodiments of the present specification, a privacy collaboration method with separated control plane and data plane is provided. A blockchain node is deployed on each node device corresponding to each member, and the blockchain network to which the blockchain node belongs includes a privacy collaboration smart contract for implementing privacy collaboration; the method is applied to the node device corresponding to any member, and the method includes:

[0011] In the control plane: call the privacy collaboration smart contract according to the blockchain transaction for privacy collaboration submitted to the blockchain network; and, if an event related to the privacy collaboration among members is generated after the privacy collaboration smart contract is called and the event is related to the any member, generate a resource scheduling instruction for the data plane accordingly;

[0012] In the data plane: allocate the off-chain resources on the local node device according to the resource scheduling instruction issued by the control plane, for use in the process of the any member participating in the privacy collaboration.

[0013] According to the third aspect of the embodiments of the present specification, an electronic device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the steps of the method described in the second aspect are implemented.

[0014] According to the fourth aspect of the embodiments of the present specification, a computer-readable storage medium is provided, on which a computer program is stored. When the program is executed by a processor, the steps of the method described in the second aspect are implemented.

[0015] According to a fifth aspect of the embodiments of this specification, a computer program product is provided, including a computer program / instructions, and when the computer program / instructions are executed by a processor, the steps of the method described in the second aspect are implemented.

[0016] In the technical solution provided in this specification, privacy collaboration is achieved through a blockchain network. The decentralized characteristics of the blockchain network can be utilized to support a large expansion of the number of members. Compared with the bilateral peer-to-peer mode, one-master-many-slaves mode, etc. in related technologies, it will not have a negative impact on existing members or the network in terms of stability, efficiency, etc., nor will there be a performance bottleneck on the master node, and it has extremely strong scalability. At the same time, by separating the control plane and the data plane, it is convenient to isolate and manage the control logic and data processing respectively, and it has extremely high security and flexibility. In particular, the control plane is implemented on the chain based on smart contract technology, the data plane is implemented using the off-chain resources of node devices, and the interaction between the on-chain and off-chain is achieved through an event mechanism, so that each control link implemented by the control plane can be archived on the blockchain, facilitating subsequent query and traceability when necessary. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 is a schematic diagram of the architecture of a privacy collaboration system with separated control plane and data plane shown in an exemplary embodiment of this specification;

[0018] Figure 2 is a schematic diagram of the architecture of a node device and its included privacy collaboration nodes shown in an exemplary embodiment of this specification;

[0019] Figure 3 is a schematic diagram of the architecture of a blockchain-based privacy collaboration system shown in an exemplary embodiment of this specification;

[0020] Figure 4 is a schematic diagram of a main network node of a blockchain-based system constructing a subnet node shown in an exemplary embodiment of this specification;

[0021] Figure 5 is a schematic diagram of the process flow of the negotiation stage in a privacy collaboration process shown in an exemplary embodiment of this specification;

[0022] Figure 6 is a schematic diagram of the process flow of the execution stage in a privacy collaboration process shown in an exemplary embodiment of this specification;

[0023] Figure 7 is a schematic diagram of the architecture of the control plane and data plane of a privacy collaboration system shown in an exemplary embodiment of this specification;

[0024] Figure 8It is a schematic flowchart of a privacy collaboration method with separation of the control plane and the data plane shown in an exemplary embodiment of this specification;

[0025] Figure 9 It is a schematic structural diagram of an electronic device shown in an exemplary embodiment of this specification;

[0026] Figure 10 It is a schematic structural diagram of a privacy collaboration device with separation of the control plane and the data plane shown in an exemplary embodiment of this specification. Detailed implementation manners

[0027] In the technical solution of this specification, privacy collaboration among members is realized based on blockchain technology. Each member has a corresponding node device, and the blockchain node corresponding to this member is deployed on this node device, and the blockchain network to which these blockchain nodes belong includes a privacy collaboration smart contract for realizing privacy collaboration.

[0028] This specification realizes a privacy collaboration scheme with separation of the control plane and the data plane, which is used to realize privacy collaboration among at least some of multiple members. From the perspective of the system architecture, a privacy collaboration system is specifically realized. For example Figure 1 As shown, this privacy collaboration system may include a control plane 11 and a data plane 12, where:

[0029] The control plane 11 is used for: calling the privacy collaboration smart contract according to the blockchain transaction for privacy collaboration submitted to the blockchain network; and, if an event related to the privacy collaboration among members is generated after the privacy collaboration smart contract is called, generating a resource scheduling instruction for the data plane accordingly;

[0030] The data plane 12 is used for: allocating off-chain resources on the node devices corresponding to the members confirmed to participate in the privacy collaboration according to the resource scheduling instruction issued by the control plane, for use in the privacy collaboration process.

[0031] From Figure 1 It can be seen that in addition to the division between the control plane 11 and the data plane 12, the entire processing process can also be divided into on-chain and off-chain. The control plane 11 is involved in both on-chain and off-chain, while the data plane 12 is involved in off-chain. The process of the control plane 11 realized on-chain involves the calling of the privacy collaboration smart contract and the generation of events related to privacy collaboration. By listening to this event, a corresponding resource scheduling instruction can be generated off-chain. Furthermore, the data plane 12 can obtain and execute the resource scheduling instruction off-chain, thereby realizing the privacy collaboration process.

[0032] The above content is described from the perspective of the system. For the node device corresponding to each member, taking the node device 21 corresponding to the member P1 as an example, asFigure 2 As shown in the figure: from the perspective of on-chain and off-chain, the node device 21 may include a blockchain node 211 belonging to the on-chain and a privacy cooperation node 212 belonging to the off-chain; from the perspective of the control plane and the data plane, the scheduling module 212a in the blockchain node 211 and the privacy cooperation node 212 belongs to the control plane, and other modules such as the network module 212b and the computing module 212c included in the privacy cooperation node 212 belong to the data plane. Of course, in the specific implementation process, these functional modules necessarily need to rely on specific physical hardware, such as network cards, processors, memory, hard disks, etc., which will not be elaborated here.

[0033] Among them, the blockchain node 211 invokes a privacy cooperation smart contract according to the blockchain transaction for privacy cooperation submitted to the blockchain network, and generates an event related to the privacy cooperation between members. If the scheduling module 212a monitors an event related to the privacy cooperation between members generated after the privacy cooperation smart contract is invoked, it correspondingly generates a resource scheduling instruction for the data plane. The network module 212b, the computing module 212c, etc. allocate the corresponding off-chain resources according to the resource scheduling instruction, so as to implement processing such as network connection and privacy computing in the privacy cooperation process.

[0034] Back to the system perspective. As Figure 3 shown, taking members P1, P2, P3, and P4 as examples, a blockchain node 211 and a privacy cooperation node 212 are deployed on the node device 21 corresponding to member P1, a blockchain node 221 and a privacy cooperation node 222 are deployed on the node device 22 corresponding to member P2, a blockchain node 231 and a privacy cooperation node 232 are deployed on the node device 23 corresponding to member P3, and a blockchain node 241 and a privacy cooperation node 242 are deployed on the node device 24 corresponding to member P4.

[0035] Among them, the blockchain node 211, the blockchain node 221, the blockchain node 231, and the blockchain node 241 belong to the same blockchain network. If there are more members in the above privacy cooperation system, the blockchain network may also include more blockchain nodes. In other words, the blockchain nodes included in this blockchain network can all be deployed on the node devices corresponding to the above-mentioned members involved in the privacy cooperation system, which can ensure that the information in this blockchain network is restricted within these members, thereby helping to protect the privacy of this information and prevent it from being leaked to other irrelevant objects participating in this blockchain network. For example, this blockchain network can be constructed by these members based on the consortium chain mechanism, and these members are consortium chain members.

[0036] In some embodiments, the above blockchain network may also include other blockchain nodes, which may not belong to the above "members" and do not participate in the privacy collaboration among these members. For example, the blockchain network may be constructed based on the public chain mechanism, and the above members only correspond to some blockchain nodes in the blockchain network. For another example, the blockchain network may be constructed based on the consortium chain mechanism, and the above members are only some consortium chain members, only corresponding to some blockchain nodes in the blockchain network.

[0037] The above blockchain network may be an independently constructed blockchain network. Alternatively, the above blockchain network may be a blockchain subnet, which is constructed based on a blockchain main network, and the blockchain main network is another blockchain network different from the blockchain subnet. There are already various schemes for constructing blockchain subnets based on blockchain main networks in the related art, all of which can be applied in this specification. Taking member P1 as an example, as Figure 4 shown: Assume that member P1 has already joined the blockchain main network, and a blockchain node 210 belonging to the blockchain main network is deployed on its corresponding node device 21. By initiating a contract call transaction for creating a blockchain subnet in the blockchain main network, for example, the node device 21 can listen for the event indicating the creation of the blockchain subnet generated by the contract call transaction, so as to deploy a blockchain node 211 belonging to the new blockchain subnet on the node device 21. Relative to the blockchain main network, the blockchain subnet can separately maintain a blockchain database (or directly called a blockchain), separately conduct consensus, etc., maintain independence from the blockchain main network, achieve data isolation from each other and avoid mutual interference, and at the same time can conveniently manage the blockchain subnet through the blockchain main network.

[0038] For the blockchain nodes deployed on the node devices corresponding to each member, the description information of the data resources held by each member respectively is stored in the blockchain network to which these blockchain nodes belong. For example, each member can separately submit a registration information maintenance transaction to the blockchain network, and the registration information maintenance transaction can carry the description information of the data resources held by the corresponding member, so that each blockchain node in the blockchain network processes the registration information maintenance transaction to store the description information of the data resources held by the corresponding member.

[0039] There can also be multiple forms of the method for depositing the description information of data resources. For example, after the registration information maintenance transaction is necessarily packaged into a certain block and added to the blockchains respectively maintained by each blockchain node, it can be considered that the deposit of the registration information maintenance transaction is achieved at this time, which also means that the description information of the data resources included in the registration information maintenance transaction is also deposited in the blockchain network. For another example, the registration information maintenance transaction can call the privacy cooperation smart contract used to achieve privacy cooperation in the blockchain network, and the contract account of the privacy cooperation smart contract contains the contract state for recording member registration information. Then, when each blockchain node processes the registration information maintenance transaction, it can call and execute the privacy cooperation smart contract, so as to record the description information of the data resources included in the registration information maintenance transaction into the above contract state for recording member registration information as the content of the member registration information.

[0040] Depositing based on the contract state can facilitate subsequent operations such as adding, deleting, modifying, and querying the contract state by calling the privacy cooperation smart contract. Compared with directly querying the blockchain, it has relatively higher efficiency and convenience. For example, in the query scenario, each blockchain node respectively queries the transaction for the received registration information to query the contract state for recording member registration information; for another example, in the scenario of adding, deleting, and modifying, each blockchain node respectively processes the received registration information maintenance transaction, adds new member registration information to the contract state for recording member registration information, or modifies or deletes the existing member registration information in the contract state for recording member registration information. The privacy cooperation smart contract can support at least one of adding, deleting, modifying, and querying the above member registration information. Among them, the privacy cooperation smart contract can be a precompiled contract (PrecompiledContracts) pre-integrated in the blockchain client program, or an ordinary smart contract deployed through a blockchain transaction. This specification does not limit this.

[0041] The above description information of the data resources can be various types of information used to describe the data resources, and this specification does not limit this. For example, the data resources can be a data set, and the corresponding description information can include the fields contained in each piece of data in the data set, that is, the schema of the data contained in the data set. For example, when a member is a bank, the data resources it holds can include the information table of the registered users in the bank, and the corresponding description information can include the fields of each piece of information in the information table, such as name, age, account number, remaining amount, etc. For another example, the description information can describe the corresponding data resources from other dimensions, such as the size of the data volume, the year of data entry, the data source, etc.

[0042] In addition to the description information of data resources, the member registration information may also include other information related to privacy collaboration, which is not restricted in this specification. For example, the member registration information may also include the type of privacy computing protocol supported by the corresponding member. In this way, if a member wishes to conduct privacy collaboration with other members, it can confirm the type of privacy computing protocol supported by other members based on the member registration information, and then select the type of privacy computing protocol supported by both parties to promote privacy collaboration. Regarding the type of privacy computing protocol, this specification does not impose any restrictions; for example, in the scenario of secure multi-party computing, the type of privacy computing protocol may include PSI (Private Set Intersection), GC (Garbled Circuit), LR (Logistic regression), etc.

[0043] Based on the above introduction, in an exemplary embodiment, the privacy collaboration smart contract of this specification may include the following content:

[0044] Res{

[0045] P1: Dset1; PSI

[0046] P2: Dset2; PSI; GC / LR

[0047] P3: Dset3; PSI; GC / LR

[0048] P4: Dset4; GC / LR

[0049] }

[0050] Interface{

[0051] Init(Px, Py, Proto)

[0052] Commit(Px, Py, Stat)

[0053] }

[0054] Res{} is used to record the member registration information corresponding to each member. For example, in the above embodiment, the member registration information corresponding to members P1 - P4 is specifically recorded. The member registration information corresponding to member P1 is "P1:Dset1; PSI", where: P1 is the member ID, Dset1 is the description information of the data resources held by this member P1, and PSI is the type of privacy computing protocol supported by this member P1. The member registration information corresponding to member P2 is "P2:Dset2; PSI; GC / LR", where: P2 is the member ID, Dset2 is the description information of the data resources held by this member P2, and PSI and GC / LR are the types of privacy computing protocols supported by this member P2. The situations of members P3 and P4 are similar and will not be elaborated here.

[0055] Two interfaces are defined in Interface{}. Among them: The Init() interface is used for a certain member to initiate a privacy collaboration request to other members, and the Commit() interface is used for other members to confirm and respond to the request initiated by this certain member.

[0056] From the perspective of different stages, the privacy collaboration process can be divided into a negotiation stage and an execution stage.

[0057] In the negotiation stage, the blockchain transaction received by the control plane for privacy collaboration is a collaboration request transaction, and the event related to the privacy collaboration between members generated by the privacy collaboration smart contract is a privacy collaboration request event. This privacy collaboration request event contains the information of the requesting member and the responding member participating in the privacy calculation indicated by the collaboration request transaction; correspondingly, the data plane is specifically used for: initiating a notification to the responding member based on the resource scheduling instruction, and submitting a collaboration confirmation transaction to the blockchain network in response to the confirmation operation of this responding member.

[0058] Cooperating with the structure of each node device as Figure 2-3 shown, the above negotiation stage can specifically include the following steps as Figure 5 shown:

[0059] Step 502, each blockchain node respectively calls the collaboration request logic in the privacy collaboration smart contract according to the collaboration request transaction submitted by the first member, and generates a privacy collaboration request event. This privacy collaboration request event contains the information of the requesting member and the responding member participating in the privacy calculation indicated by the collaboration request transaction.

[0060] The first member can be any one of the above members, that is, any member can, based on its own needs, request other members to conduct privacy collaboration with itself. For example, the first member can request the second member mentioned below to conduct privacy collaboration with itself.

[0061] As described above, in the blockchain network, there is description information of the data resources held by each member, enabling the first member to learn about the description information of the data resources held by other members based on this and select the members with whom it wishes to conduct privacy collaboration. Taking the aforementioned privacy collaboration smart contract as an example, assume that the first member is member P1, the data resource maintained by this member P1 is dataset Dataset1, and the fields of each data in this dataset Dataset1 include name, age, account number, remaining amount, etc. Member P1 hopes to perform a private intersection with another dataset containing the same fields. Then, member P1 can query the description information Dset2, Dset3, and Dset4 respectively published by members P2, P3, and P4 by submitting a registration information query transaction as described above to the blockchain network, which correspond to the dataset Dataset2 maintained by member P2, the dataset Dataset3 maintained by member P3, and the dataset Dataset4 maintained by member P4 respectively.

[0062] Assume that both Dset2 and Dset3 meet the requirements of member P1. If the privacy collaboration smart contract does not record the types of privacy computing protocols supported by each member, for example, each member defaults to supporting the same type of privacy computing protocol, then member P1 only needs to select any one or all of members P2 and P3 for privacy collaboration based on the matching situation between the description information of the data resources.

[0063] If the privacy collaboration smart contract records the types of privacy computing protocols supported by each member, then member P1 can further consider the types of privacy computing protocols supported by itself and members P2 and P3 respectively, and select other members whose supported privacy computing protocol types are the same as its own. In the aforementioned example, member P1 only supports the PSI algorithm, while both members P2 and P3 support this PSI algorithm. Therefore, both of them meet the requirements of member P1 in terms of the description information of the data resources and the supported privacy computing protocol types. However, if, for example, member P3 only supports the GC algorithm and does not support the PSI algorithm, then even if the description information of the data resources of member P3 meets the requirements of member P1, member P1 should not choose to conduct privacy collaboration with member P3.

[0064] Assume that member P1 chooses to conduct privacy collaboration with member P2. Then member P1 can submit a collaboration request transaction to the blockchain network, that is, a blockchain transaction used to request member P2 to conduct privacy collaboration with this member P1. This collaboration request transaction is executed separately by each blockchain node in the blockchain network. For example, in Figure 3In the illustrated embodiment, blockchain nodes 211, 221, 231, and 241 respectively obtain and execute the collaboration request transaction. The collaboration request transaction invokes the collaboration request logic in the privacy collaboration smart contract. The collaboration request logic refers to a processing logic defined in the privacy collaboration smart contract, and this processing logic is used to transfer from the chain to off-chain a request for the requesting member to hope that the responding member collaborates with it privately.

[0065] The requesting member and the responding member are respectively members in different roles in the private collaboration. For example, in the above example, member P1 hopes to collaborate privately with member P2. Then member P1 is the requesting member and member P2 is the responding member. Of course, member P1 can also request to collaborate privately with multiple members at the same time, and the present specification does not limit the quantity here. When the collaboration request transaction indicates the information of the responding member participating in the private computation, the information of the responding member can be carried in, for example, the Data field of the collaboration request transaction and can be provided as an input parameter to the above-mentioned collaboration request logic. When the collaboration request transaction indicates the information of the requesting member participating in the private computation, if the requesting member is the initiator of the collaboration request transaction, the information of the requesting member itself is recorded in, for example, the from field of the collaboration request transaction and can be provided as an input parameter to the above-mentioned collaboration request logic, without being additionally recorded in, for example, the above-mentioned Data field. Of course, since the from field usually records information such as the account address and wallet address of the transaction initiator, which can be different from the member ID of the requesting member, in order to avoid the collaboration request logic converting the account address or wallet address, etc. into the corresponding member ID, the information of the requesting member can also be carried in, for example, the Data field of the collaboration request transaction and can be provided as an input parameter to the above-mentioned collaboration request logic.

[0066] As described above, the blockchain network also stores the types of private computation protocols supported by each member respectively. Correspondingly, the collaboration request transaction can also include one type of private computation protocol or multiple alternative types of private computation protocols recommended by the requesting member and provided as input parameters to the above-mentioned collaboration request logic.

[0067] Taking the aforementioned privacy collaboration smart contract as an example, the collaboration request transaction can call the Init() interface defined in the privacy collaboration smart contract to achieve the call of the collaboration request logic. Specifically, the collaboration request transaction can define each parameter in the Init() interface. For example, it can define the requesting member Px = P1, the responding member Py = P2, and the type of private computation protocol Proto = PSI to indicate that member P1 is the requesting member, member P2 is the responding member, and the type of private computation protocol to be used is PSI.

[0068] Taking the collaboration request logic as an example, the ways in which each blockchain node executes the privacy collaboration smart contract may vary due to different types of privacy collaboration smart contracts. For example, when the privacy collaboration smart contract is a pre-compiled contract, the collaboration request logic is integrated into the client program of the blockchain node, and it is already compiled machine code. Therefore, each blockchain node can directly execute this collaboration request logic without temporarily interpreting the code. When the privacy collaboration smart contract is a general smart contract, the collaboration request logic is usually intermediate language such as bytecode compiled from high-level languages like C++. Therefore, each blockchain node needs to interpret and execute the code of the collaboration request logic in this intermediate language form. Of course, some general smart contracts may also have been pre-compiled into machine code by high-level languages like C++, enabling each blockchain node to directly execute the corresponding collaboration request logic. The execution of other smart contract logics such as the collaboration confirmation logic in this specification is similar and will not be elaborated further later.

[0069] After each blockchain node executes the collaboration request logic, it will generate corresponding privacy collaboration request events. Since both the blockchain node and the privacy collaboration node are deployed on each node device, the privacy collaboration node can screen out the above-mentioned privacy collaboration request events by listening to the contract events generated by the local blockchain node, thus realizing information transfer from the chain to off-chain. This mechanism of information transfer from the chain to off-chain through events can be called the event mechanism.

[0070] After the blockchain node executes a blockchain transaction to invoke and execute the privacy collaboration smart contract, it will generate a corresponding receipt, which will contain the above-mentioned events. Each event will specifically contain several fields, such as topic (theme) and data (data), etc. The privacy collaboration node can obtain the receipt generated by the blockchain node and read the topic of each event contained in the receipt. For example, the above-mentioned privacy collaboration request events, privacy collaboration confirmation events, etc., will all correspond to a unique specific topic. Therefore, based on the topic of each event, the privacy collaboration node can identify the types of each event generated by the blockchain node, thereby accurately determining whether it has monitored privacy collaboration request events, privacy collaboration confirmation events, or other events. Information such as the information of the requester member and the responder member can be recorded in the data field of the corresponding event.

[0071] It can be seen that by using the blockchain network to deposit and prove the member registration information of each member, each member can accurately and conveniently obtain the description information of the data resources held by other members, the types of privacy algorithm protocols supported, etc., avoiding problems such as misunderstandings, information asymmetry, and low efficiency that may be caused by offline communication. At the same time, by invoking the privacy collaboration smart contract through the collaboration request transaction, both the collaboration request transaction itself and the privacy collaboration request event generated based on the privacy collaboration smart contract can leave corresponding records on the blockchain, making each privacy collaboration traceable and facilitating subsequent tracing.

[0072] Step 504, after the privacy collaboration node corresponding to the second member monitors the privacy collaboration request event, if it confirms that the second member belongs to the responding member, it sends a notification to the second member, and in response to the confirmation operation of the second member, submits a collaboration confirmation transaction to the blockchain network.

[0073] As mentioned above, the privacy collaboration request event records the information of the requesting member and the responding member. Therefore, after each member's corresponding privacy collaboration node monitors the privacy collaboration request event, it can compare the information of the responding member in the privacy collaboration request event with its own corresponding member to determine whether its own corresponding member belongs to the responding member. For example, assume that the requesting member recorded in the privacy collaboration request event is member P1 and the responding member is member P2. Then: as Figure 3 shown, after the privacy collaboration node 212 monitors the privacy collaboration request event, it finds that its corresponding member P1 does not belong to the responding member, so it will not make further processing; after the privacy collaboration node 222 monitors the privacy collaboration request event, it finds that its corresponding member P2 belongs to the responding member, so it will send a notification to member P2, which can be in any form such as text messages, emails, instant messaging messages, client push messages, etc., and this specification does not limit this; after the privacy collaboration node 232 monitors the privacy collaboration request event, it finds that its corresponding member P3 does not belong to the responding member, so it will not make further processing; after the privacy collaboration node 242 monitors the privacy collaboration request event, it finds that its corresponding member P4 does not belong to the responding member, so it will not make further processing. Therefore, finally, only member P2, who is the responding member, will receive the notification, while other members will not be disturbed.

[0074] The notice for the second member may include information of the requesting member for the second member to confirm whether to accept this request. Of course, the notice may also include other information for the second member to view so as to comprehensively determine whether to accept this request. For example, in a privacy collaboration request event, it may include a type or multiple alternative types of privacy computing protocols recommended by the requesting member, and the information of the privacy computing protocol type can also be added to the above notice for the second member to view and, if necessary, for the second member to select from multiple alternative types of privacy computing protocols. Another example is that if there are multiple responder members at the same time, the notice may also indicate the information of all responder members.

[0075] Each member may simultaneously have multiple independent data resources and publish them on the blockchain. Then, the first member needs to indicate in the collaboration request transaction which data resource or resources held by each participant are required to participate in the privacy collaboration. Correspondingly, the privacy collaboration request event may include the description information of the data resources that the requesting member and the responder member respectively need to participate in the privacy collaboration. Then, the notice provided to the second member may include the description information of the data resources held by the second member and required to participate in the privacy collaboration, and may further include the description information of the data resources held by the first member and required to participate in the privacy collaboration for the second member to view so as to comprehensively determine whether to accept this request.

[0076] If it is confirmed to participate in the privacy collaboration, the second member may perform a confirmation operation, which can be any pre-defined operation capable of expressing the confirmation intention of the second member. Based on the confirmation operation of the second member, the privacy collaboration node may submit a collaboration confirmation transaction to the blockchain network, that is, a blockchain transaction indicating that the second member confirms to conduct privacy collaboration with the first member. Then, without the second member and the first member having offline interaction, and even without the two parties knowing each other's offline contact information, the two parties can achieve the negotiation process as described above based on blockchain technology, including the first member initiating a privacy collaboration request and the second member confirming to participate in the privacy collaboration, and the process is extremely simple and efficient.

[0077] In the execution stage, the blockchain transaction received by the control plane for privacy collaboration is a collaboration confirmation transaction, and the event related to the privacy collaboration between members generated by the privacy collaboration smart contract is a privacy collaboration confirmation event, which includes the information of the requesting member and the responder member; correspondingly, the data plane is specifically used for: based on the resource scheduling instruction, using the off-chain resources on the node devices corresponding to the requesting member and the responder member to establish a network connection and participate in privacy computing.

[0078] Cooperating with Figure 2-3 the structure of each node device as shown inFigure 6 The following steps shown below:

[0079] Step 602: Each blockchain node respectively calls the collaboration confirmation logic in the privacy collaboration smart contract according to the received collaboration confirmation transaction, and generates a privacy collaboration confirmation event, where the privacy collaboration confirmation event contains information of the requesting party member and the responding party member.

[0080] Assume that the first member is member P1 and the second member is member P2. Member P2 can submit a collaboration confirmation transaction to the blockchain network through the privacy collaboration node 222 shown below to confirm participation in the privacy collaboration proposed by member P1. This collaboration confirmation transaction calls the collaboration confirmation logic in the privacy collaboration smart contract, and this collaboration confirmation logic refers to a processing logic defined in this privacy collaboration smart contract, and this processing logic is used to transfer from on-chain to off-chain the confirmation of the responding party member's participation in the privacy collaboration requested by the requesting party member. Figure 3 Similar to the privacy collaboration request event, the privacy collaboration confirmation event can contain information of the requesting party member and the responding party member, so as to form a difference between different privacy collaboration confirmation events. Specifically, the collaboration confirmation transaction can carry the information of the requesting party member in the Data field. The information of the responding party member can also be carried in the Data field of the collaboration confirmation transaction; or, it can also be characterized by the information in the From field, and subsequently the collaboration confirmation logic converts it into the member ID of the responding party member. In short, it is similar to the foregoing collaboration request transaction here.

[0081] Similar to the privacy collaboration request event, the privacy collaboration confirmation event can contain information of the requesting party member and the responding party member, so as to form a difference between different privacy collaboration confirmation events. Specifically, the collaboration confirmation transaction can carry the information of the requesting party member in the Data field. The information of the responding party member can also be carried in the Data field of the collaboration confirmation transaction; or, it can also be characterized by the information in the From field, and subsequently the collaboration confirmation logic converts it into the member ID of the responding party member. In short, it is similar to the foregoing collaboration request transaction here.

[0082] The privacy collaboration confirmation event may also include: a type of privacy computing protocol adopted by the second member for confirmation. The privacy collaboration request event may include a type of privacy computing protocol recommended by the requesting member. If the second member confirms the adoption, it may carry the information of this privacy computing protocol type in, for example, the Data field in the collaboration confirmation transaction, so as to be passed as an input parameter to the collaboration confirmation logic and then transmitted to the privacy collaboration confirmation event. Alternatively, the privacy collaboration request event may include multiple alternative privacy computing protocol types recommended by the requesting member, and the second member may select one of them and carry it in the collaboration confirmation transaction, and finally transmit it to the privacy collaboration confirmation event based on the aforementioned method. The privacy collaboration request event may also not include any privacy computing protocol type recommended by the requesting member, but the second member actively determines a type of privacy computing protocol and carries it in the collaboration confirmation transaction, and finally transmits it to the privacy collaboration confirmation event based on the aforementioned method. Of course, if a unique and default privacy computing protocol type is uniformly configured on each privacy collaboration node, or a selection rule for the privacy computing protocol type is uniformly configured, then the privacy collaboration request event and the privacy collaboration confirmation event may not include the information of the privacy computing protocol type, and each privacy collaboration node can automatically select the correct privacy computing protocol type for privacy collaboration.

[0083] Taking the aforementioned privacy collaboration smart contract as an example, the collaboration confirmation transaction can call the Commit() interface defined in the privacy collaboration smart contract to implement the call to the collaboration confirmation logic. Specifically, the collaboration confirmation transaction can define each parameter in the Commit() interface. For example, it can define the requesting member Px = P1, the responding member Py = P2, and the response result Stat = true, to indicate that member P1 is the requesting member, member P2 is the responding member, and member P2 agrees to participate in the privacy collaboration.

[0084] Step 604, after any privacy collaboration node corresponding to a member monitors the privacy collaboration confirmation event, if it confirms that the any member belongs to the requesting member or the responding member, it allocates the network resources in the node device where it is located to establish a network connection with other members participating in the privacy computing, and participates in the privacy computing by using the network connection and the computing resources in the node device where it is located.

[0085] Similar to the privacy collaboration request event, since the blockchain node and the privacy collaboration node are simultaneously deployed on the node devices corresponding to each member, the privacy collaboration node can filter out the above-mentioned privacy collaboration confirmation event from the contract events generated by the local blockchain node based on the event mechanism, thus realizing the information transfer from the chain to off-chain.

[0086] As described above, the information of the requester member and the responder member is recorded in the privacy collaboration confirmation event. Therefore, after each privacy collaboration node corresponding to a member monitors the privacy collaboration confirmation event, it can compare the information of the responder member in the privacy collaboration confirmation event with the member corresponding to itself, so as to determine whether the member corresponding to itself belongs to the requester member or the responder member. For example, assuming that the requester member recorded in the privacy collaboration confirmation event is member P1 and the responder member is member P2, then: As Figure 3 shown, after the privacy collaboration node 212 monitors the privacy collaboration request event, it is found that the member P1 corresponding to itself belongs to the requester member; after the privacy collaboration node 222 monitors the privacy collaboration request event, it is found that the member P2 corresponding to itself belongs to the responder member; after the privacy collaboration node 232 monitors the privacy collaboration request event, it is found that the member P3 corresponding to itself does not belong to the requester member and the responder member, so no further processing will be performed; after the privacy collaboration node 242 monitors the privacy collaboration request event, it is found that the member P4 corresponding to itself does not belong to the requester member and the responder member, so no further processing will be performed. Therefore, the privacy collaboration node 212 will allocate the resources on the node device 21, and the privacy collaboration node 222 will allocate the resources on the node device 22, so as to establish a network connection between the privacy collaboration node 212 and the privacy collaboration node 222, and participate in privacy computing by using this network connection and the computing resources in the node devices 21-12.

[0087] As described above, the off-chain resources on the node device may include: a network module and a computing module. Correspondingly, the data plane is specifically used for: when the scheduling target of the resource scheduling instruction includes network resources, scheduling the network module to allocate network resources for network communication during the privacy collaboration process; when the scheduling target of the resource scheduling instruction includes computing resources, scheduling the computing module to allocate computing resources and invoking the privacy collaboration algorithm library according to the type of privacy computing protocol indicated in the resource scheduling instruction for privacy computing during the privacy collaboration process. If taking Figure 2 the node device 21 shown as an example, the off-chain resources on the node device 21 may include a network module 212b and a computing module 212c, and the privacy collaboration algorithm library is configured in the computing module 212c. Then, the network module 212b is used to allocate network resources according to the resource scheduling instruction for network communication during the privacy collaboration process, such as establishing a network connection and performing data transmission based on this network connection, etc. The computing module 212c is used to allocate computing resources according to the resource scheduling instruction and invoke the privacy collaboration algorithm library according to the type of privacy computing protocol indicated in the resource scheduling instruction to implement privacy computing.

[0088] Further, in combination with the scheduling module 212a, the cooperation process among the scheduling module 212a, the network module 212b, and the computing module 212c is described in detail. Generally, the scheduling module 212a listens for contract events generated by the blockchain node 211, and accordingly schedules the network module 212b and the computing module 212c to utilize the network resources of the network module 212b and the computing resources of the computing module 212c respectively, and apply them to the process related to privacy cooperation.

[0089] Specifically, if the scheduling module 212a monitors a privacy cooperation request event, it can initiate a notification when member P1 belongs to the responding member. As mentioned above, if member P1 is the requesting member, or is neither the requesting member nor the responding member, then the scheduling module 212a does not need to process it.

[0090] If the scheduling module 212a monitors a privacy cooperation confirmation event, it can issue a network resource scheduling instruction to the network module 212b and a computing resource scheduling instruction to the computing module 212c when member P1 belongs to the requesting member or the responding member. Correspondingly, the network module 212b is used to allocate the network resources in the node device 11 to establish a network connection with other members participating in privacy computing according to the above network resource scheduling instruction. For example, when member P1 is the requesting member and member P2 is the responding member, the allocated network resources are used to establish a network connection between the privacy cooperation node 212 and the privacy cooperation node 222. The computing module 212c is used to participate in privacy computing by using the network connection established by the network module 212b and the computing resources in the node device 11 according to the above computing resource scheduling instruction.

[0091] It can be seen that the privacy cooperation node can automatically implement the scheduling of network resources and computing resources based on the privacy cooperation confirmation event, so as to automatically establish a network connection and execute privacy computing. That is to say, in addition to being able to achieve convenient and fast communication and negotiation, the technical solution of this specification can also enable the privacy cooperation smart contract to automatically schedule the off-chain resources of the node device based on the privacy cooperation confirmation event on the chain, and then automatically complete privacy cooperation among multiple members. The whole process is efficient and convenient.

[0092] Moreover, similar to the privacy cooperation request event, by invoking the privacy cooperation smart contract through the cooperation confirmation transaction, both the cooperation confirmation transaction itself and the privacy cooperation confirmation event generated based on the privacy cooperation smart contract can leave corresponding records on the blockchain, making each privacy cooperation traceable for subsequent tracing.

[0093] For network resources, when establishing a network connection between the network resources on the node device 21 and other members participating in privacy computing, multiple methods can be used to achieve this.

[0094] For example, it is possible to query from the local blockchain node 211: the IP addresses of each blockchain node in the blockchain network, that is, the IP addresses of the node devices where these blockchain nodes are located, and then establish a network connection based on this.

[0095] For another example, since each blockchain node will establish a network connection after joining the blockchain network, it is possible to leverage the connections already established among the blockchain nodes in the blockchain network: If any member belongs to the requesting member or the responding member, then for this any member, it is possible to determine the connections already established in the blockchain network between the blockchain node on the node device where the privacy cooperation node corresponding to this any member is located and the blockchain nodes corresponding to other members participating in privacy computing, and allocate a new port number for privacy computing to the determined established connection.

[0096] Taking member P1 and member P2 as an example. Assume that there is a P2P connection established between the blockchain node 211 corresponding to member P1 and the blockchain node 221 corresponding to member P2. This P2P connection is specifically established based on the IP address A1 of node device 11 and the IP address A2 of node device 12, and the port number allocated specifically for the blockchain instance is D1. Then, when node device 11 receives a communication message with the IP address A1 and port number D1, it can hand over this communication message to blockchain node 211 for processing; similarly, when node device 12 receives a communication message with the IP address A2 and port number D1, it can hand over this communication message to blockchain node 221 for processing. On this basis, node device 11 can allocate a new port number D2 to privacy cooperation node 212; among them, if combined Figure 4 , it can also be considered that the new port number D2 is allocated to network module 212b. Similarly, node device 12 can allocate a new port number D2 to privacy cooperation node 222. Then, when node device 11 receives a communication message with the IP address A1 and port number D2, it can hand over this communication message to privacy cooperation node 212 for processing; similarly, when node device 12 receives a communication message with the IP address A2 and port number D2, it can hand over this communication message to privacy cooperation node 222 for processing.

[0097] Of course, in addition to directly establishing P2P connections between blockchain nodes, in some embodiments, other methods can also be used to establish connections. For example, blockchain nodes can be respectively connected to the BTN (Blockchain Transmission Network) network, and the BTN network can assist in realizing communication between blockchain nodes. The BTN network is a dedicated data transmission network, which is composed of some nodes with high computing power, high reliability and high stability, and is specially used for blockchain data transmission to ensure the security and integrity of the data transmission process. On this basis, the network connection established between blockchain nodes with the help of the BTN network can be used to realize network transmission between privacy cooperation nodes, so as to improve the efficiency and security of privacy cooperation by virtue of the high speed, reliability and stability of the BTN network.

[0098] For computing resources, the privacy cooperation algorithm library configured thereon can be a full-scale privacy cooperation algorithm library, which corresponds to all privacy cooperation algorithms, or it can be a lightweight privacy cooperation algorithm library, which corresponds to the privacy cooperation algorithms selected by the corresponding members. In fact, for all members of the entire system, the node devices corresponding to at least one member or at most all members can be configured with a full-scale privacy cooperation algorithm library; or, the node devices corresponding to at least one member or at most all members can be configured with a lightweight privacy cooperation algorithm library; or, the node devices corresponding to a part of the members can be configured with a full-scale privacy cooperation algorithm library, and the node devices corresponding to another part of the members can be configured with a lightweight privacy cooperation algorithm library. Among them, the lightweight privacy cooperation algorithm library can only retain the privacy cooperation algorithms required by the corresponding members without configuring other privacy cooperation algorithms, making the privacy cooperation algorithm libraries configured on the node devices of these members relatively more lightweight, realizing the on-demand assembly / configuration of the privacy cooperation algorithm library, and thus minimizing its dependence on the corresponding resources.

[0099] See, for example Figure 7 the schematic diagram of the architecture of the control plane and the data plane shown in

[0100] In the control plane on the left side of the dotted line:

[0101] The contract event management module is used to register various events, such as the aforementioned privacy cooperation request event and privacy cooperation confirmation event, etc. By obtaining information such as the topic of these events, it is convenient to accurately monitor these events, so as to realize the functions similar to the aforementioned scheduling module.

[0102] The algorithm management module is used to manage the aforementioned privacy collaboration algorithm library. In this way, after the privacy collaboration algorithm library has been configured on each node device, the privacy collaboration system can still manage it dynamically. For example, the control plane (such as this algorithm management module) can be used to: call the privacy collaboration smart contract according to the algorithm update transaction submitted to the blockchain network; and, if an algorithm update event generated after the privacy collaboration smart contract is called is monitored, then generate an algorithm update instruction for the data plane accordingly; correspondingly, the data plane is also used to: update the privacy collaboration algorithms included in the privacy collaboration algorithm library according to the algorithm update instruction issued by the control plane, so as to add new privacy collaboration algorithms and / or delete the original privacy collaboration algorithms.

[0103] The member management module can be used to manage the aforementioned member registration information. For example, relevant management is achieved through the registration information maintenance transaction described above.

[0104] The input / output management module is used to define the standard interface data format to achieve the interaction between the control plane and the data plane. Specifically, it can be implemented in the form of a message queue to ensure that data can be interacted asynchronously and reliably.

[0105] The network management module can be used to manage relevant resources in the network. For example, by generating resource scheduling instructions related to network resources, allocate relevant resources in the network to establish a blockchain P2P network in the blockchain scenario and a data interconnection network in the privacy collaboration scenario, etc.

[0106] In the data plane on the right side of the dashed line:

[0107] The privacy collaboration algorithm library is used to implement specific privacy calculations. Specifically, this privacy collaboration algorithm library can be docked with the control plane through a pre-configured interface, so as to receive the resource scheduling instructions related to computing resources issued by the control plane, and then realize the allocation of computing resources, and realize privacy calculations based on the allocated computing resources. For the relevant description of this privacy collaboration algorithm library, reference can also be made to the content described above.

[0108] The data interconnection network can be a network established under the management of the network management module for use in the privacy collaboration process. As described above, in some embodiments, this data interconnection network can be completely independent of the blockchain P2P network, and in other embodiments, this data interconnection network can be constructed on the basis of the blockchain P2P network.

[0109] The interaction scheduler can decouple the computing and the network. To Figure 2For example, the interactive scheduler can be used to implement the interaction between the network module 212b and the computing module 212c, and thus can be called an interaction module. The interaction module is used to: create a send message queue for the communication requests generated by the computing module 212c, so that the network module 212b can asynchronously forward the communication requests in the send message queue; and, create a feedback message queue for the response messages sent back by the network module 212b, so that the computing module 212c can asynchronously process the response messages in the feedback message queue. In short, through this asynchronous interaction scheduling, the network configuration information can be shielded from the computing module 212c to ensure the stable operation of its privacy computing tasks.

[0110] Consistent with the above privacy collaboration system with separated control plane and data plane, this specification also proposes a privacy collaboration method with separated control plane and data plane. Blockchain nodes are deployed on the node devices corresponding to each member, and the blockchain network to which the blockchain nodes belong includes privacy collaboration smart contracts for implementing privacy collaboration. Please refer to Figure 8 , the method is applied to the node device corresponding to any member, and the method includes:

[0111] Step 802, in the control plane: call the privacy collaboration smart contract according to the blockchain transaction for privacy collaboration submitted to the blockchain network; and, if an event related to the privacy collaboration between members is generated after the privacy collaboration smart contract is called and the event is related to the any member, then correspondingly generate a resource scheduling instruction for the data plane;

[0112] Step 804, in the data plane: allocate the off-chain resources on the node device according to the resource scheduling instruction issued by the control plane for the process of any member participating in privacy collaboration.

[0113] Optionally, the off-chain resources on the node device include: a network module and a computing module, and a privacy collaboration algorithm library is configured in the computing module;

[0114] The allocating the off-chain resources on the node device according to the resource scheduling instruction issued by the control plane includes:

[0115] In the case where the scheduling target of the resource scheduling instruction includes network resources, schedule the network module to allocate network resources for realizing network communication in the process of privacy collaboration;

[0116] In the case where the scheduling target of the resource scheduling instruction includes computing resources, schedule the computing module to allocate computing resources and call the privacy collaboration algorithm library according to the type of privacy computing protocol indicated in the resource scheduling instruction for realizing privacy computing in the process of privacy collaboration.

[0117] Optionally,

[0118] The privacy cooperation algorithm library is a full-scale privacy cooperation algorithm library, corresponding to the full-scale privacy cooperation algorithm;

[0119] Or,

[0120] The privacy cooperation algorithm library is a lightweight privacy cooperation algorithm library, corresponding to the privacy cooperation algorithm selected by any of the members.

[0121] Optionally, the data plane further includes: an interaction module;

[0122] The allocation of off-chain resources on the node device according to the resource scheduling instruction sent by the control plane includes:

[0123] Creating a sending message queue for the communication requests generated by the computing module through the interaction module, so that the network module asynchronously forwards the communication requests in the sending message queue;

[0124] Creating a return message queue for the response messages returned by the network module through the interaction module, so that the computing module asynchronously processes the response messages in the return message queue.

[0125] Optionally,

[0126] When the blockchain transaction for privacy cooperation is a cooperation request transaction, the event related to privacy cooperation between members is a privacy cooperation request event, and the privacy cooperation request event contains information about the requesting member and the responding member participating in the privacy calculation indicated by the cooperation request transaction; the allocation of off-chain resources on the node device according to the resource scheduling instruction sent by the control plane includes: initiating a notification to any of the members as the responding member based on the resource scheduling instruction, and submitting a cooperation confirmation transaction to the blockchain network in response to the confirmation operation of any of the members;

[0127] When the blockchain transaction for privacy cooperation is a cooperation confirmation transaction, the event related to privacy cooperation between members is a privacy cooperation confirmation event, and the privacy cooperation confirmation event contains information about the requesting member and the responding member; the allocation of off-chain resources on the node device according to the resource scheduling instruction sent by the control plane includes: based on the resource scheduling instruction, when any of the members belongs to the requesting member or the responding member, establishing a network connection and participating in privacy calculation using the off-chain resources on the node device.

[0128] It should be noted that: The method embodiments describe the interaction between the control plane and the data plane, as well as their respective execution logics, all of which are Figure 1-7 consistent with the embodiments shown in Figure 1-7 terms of the technical solutions, and reference can be made to the description of the embodiments shown in the foregoing regarding

[0129] To sum up, in the technical solutions provided in this specification, privacy collaboration is achieved through a blockchain network. The decentralized characteristics of the blockchain network can be utilized to support a large expansion of the number of members. Compared with the bilateral peer-to-peer mode, the one-master-many-slave mode, etc. in the related technologies, it will not have a negative impact on the existing members or the network in terms of stability, efficiency, etc., nor will there be a performance bottleneck on the master node, and it has extremely strong scalability. At the same time, by separating the control plane and the data plane, it is convenient to isolate and manage the control logic and data processing respectively, and it has extremely high security and flexibility. In particular, the control plane is implemented on the chain based on smart contract technology, the data plane is implemented using the off-chain resources of the node devices, and the interaction between the on-chain and off-chain is achieved through an event mechanism, so that each control link implemented by the control plane can be archived on the blockchain, facilitating query and traceability when necessary later.

[0130] Figure 9 is a schematic structural diagram of an electronic device in an exemplary embodiment. Please refer to Figure 9 , at the hardware level, the electronic device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory. Of course, there may also be other required hardware. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it, forming a device for hiding the recipient address or a device for verifying the transaction attribution at the logical level. Of course, in addition to the software implementation method, this specification does not exclude other implementation methods, such as logical devices or a combination of software and hardware, etc. That is to say, the execution subject of the following processing flow is not limited to each logical unit, and can also be hardware or a logical device.

[0131] Corresponding to the embodiments of the privacy collaboration method with the separation of the control plane and the data plane described above, this specification also provides embodiments of a privacy collaboration device with the separation of the control plane and the data plane.

[0132] Please refer to Figure 10 , blockchain nodes are deployed on each node device corresponding to each member, and the blockchain network to which the blockchain nodes belong includes a privacy collaboration smart contract for implementing privacy collaboration; the device is applied to a node device corresponding to any member, and the device may include:

[0133] A resource scheduling unit 1001 is configured to enable the control plane to: call the privacy collaboration smart contract according to a blockchain transaction for privacy collaboration submitted to the blockchain network; and, if an event related to privacy collaboration among members is generated after the privacy collaboration smart contract is called and the event is related to any one of the members, generate a resource scheduling instruction for the data plane accordingly.

[0134] A response processing unit 1002 is configured to enable the data plane to: allocate off-chain resources on the node device according to the resource scheduling instruction issued by the control plane for any one of the members to participate in the privacy collaboration process.

[0135] Optionally, the off-chain resources on the node device include: a network module and a computing module, and a privacy collaboration algorithm library is configured in the computing module;

[0136] The response processing unit 1002 is specifically configured to:

[0137] In the case where the scheduling target of the resource scheduling instruction includes network resources, schedule the network module to allocate network resources for network communication during the privacy collaboration process;

[0138] In the case where the scheduling target of the resource scheduling instruction includes computing resources, schedule the computing module to allocate computing resources and call the privacy collaboration algorithm library according to the type of privacy computing protocol indicated in the resource scheduling instruction for privacy computing during the privacy collaboration process.

[0139] Optionally,

[0140] The privacy collaboration algorithm library is a full-scale privacy collaboration algorithm library corresponding to full-scale privacy collaboration algorithms;

[0141] Or,

[0142] The privacy collaboration algorithm library is a lightweight privacy collaboration algorithm library corresponding to the privacy collaboration algorithm selected by any one of the members.

[0143] Optionally, the data plane further includes: an interaction module;

[0144] The response processing unit 1002 is specifically configured to:

[0145] Create a sending message queue for communication requests generated by the interaction module for the computing module, so that the network module asynchronously forwards the communication requests in the sending message queue;

[0146] Create a return message queue for response messages returned by the interaction module for the network module, so that the computing module asynchronously processes the response messages in the return message queue.

[0147] Optionally,

[0148] When the blockchain transaction for privacy collaboration is a collaboration request transaction, the event related to the privacy collaboration between members is a privacy collaboration request event, and the privacy collaboration request event includes information of the requesting member and the responding member participating in privacy computing indicated by the collaboration request transaction; specifically, the response processing unit 1002 is configured to: initiate a notification to any one of the members serving as the responding member based on the resource scheduling instruction, and submit a collaboration confirmation transaction to the blockchain network in response to the confirmation operation of any one of the members;

[0149] When the blockchain transaction for privacy collaboration is a collaboration confirmation transaction, the event related to the privacy collaboration between members is a privacy collaboration confirmation event, and the privacy collaboration confirmation event includes information of the requesting member and the responding member; specifically, the response processing unit 1002 is configured to: based on the resource scheduling instruction, when any one of the members belongs to the requesting member or the responding member, establish a network connection and participate in privacy computing by using off-chain resources on the node device where it is located.

[0150] For the specific implementation processes of the functions and effects of each unit in the above device, please refer to the implementation processes of the corresponding steps in the above method for details, which will not be elaborated here.

[0151] Based on the same concept as the above method, this specification also provides an electronic device, including: a processor; a memory for storing processor-executable instructions; wherein, the processor realizes the steps of the method as described in any one of the above embodiments by running the executable instructions.

[0152] Based on the same concept as the above method, this specification also provides a computer-readable storage medium, on which computer instructions are stored, and when the instructions are executed by a processor, the steps of the method as described in any one of the above embodiments are realized.

[0153] Based on the same concept as the above method, this specification also provides a computer program product, including computer programs / instructions, and when the computer programs / instructions are executed by a processor, the steps of the method as described in any one of the above embodiments are realized.

Claims

1. A privacy collaboration system with a separated control plane and a separated data plane, for realizing privacy collaboration among at least a part of a plurality of members, wherein a blockchain node is deployed on a node device corresponding to each member, and a blockchain network to which the blockchain node belongs contains a privacy collaboration smart contract for realizing privacy collaboration; the system comprises: A control plane, the control plane being used to: call the privacy collaboration smart contract according to a blockchain transaction for privacy collaboration submitted to the blockchain network; And, if an event related to privacy collaboration between members is monitored after the privacy collaboration smart contract is called, a resource scheduling instruction for the data plane is generated accordingly; The data plane is used to allocate off-chain resources on node devices corresponding to members confirmed to participate in privacy collaboration according to the resource scheduling instructions issued by the control plane for use in the privacy collaboration process.

2. According to the system of claim 1, the off-chain resources on the node device include: A network module and a computing module, wherein the computing module is configured with a privacy collaboration algorithm library; The data plane is specifically used for: In a case where the scheduling target of the resource scheduling instruction includes network resources, scheduling the network module to allocate network resources for realizing network communication in the privacy collaboration process; When the scheduling target of the resource scheduling instruction includes computing resources, the computing module is scheduled to allocate computing resources, and the privacy collaboration algorithm library is called according to the privacy computing protocol type indicated in the resource scheduling instruction to implement privacy computing in the privacy collaboration process.

3. The system according to claim 2, A node device corresponding to at least one member is configured with a full privacy collaboration algorithm library, and the full privacy collaboration algorithm library corresponds to a full privacy collaboration algorithm; and / or, The node device corresponding to at least one member is configured with a lightweight privacy collaboration algorithm library, and the lightweight privacy collaboration algorithm library corresponds to the privacy collaboration algorithm selected by the corresponding member.

4. The system according to claim 2, The control plane is further configured to: call the privacy collaboration smart contract according to the algorithm update transaction submitted to the blockchain network; and generate an algorithm update instruction for the data plane accordingly if an algorithm update event generated after the privacy collaboration smart contract is called is monitored; The data plane is also used to update the privacy collaboration algorithms contained in the privacy collaboration algorithm library according to the algorithm update instruction issued by the control plane, so as to add new privacy collaboration algorithms and / or delete original privacy collaboration algorithms.

5. The system according to claim 2, wherein the data plane further comprises: Interaction module; The interaction module is used to: create a sending message queue for the communication request generated by the computing module, so that the network module can asynchronously forward the communication requests in the sending message queue; and create a return message queue for the response message returned by the network module, so that the computing module can asynchronously process the response message in the return message queue.

6. The system according to claim 1, In the case where the blockchain transaction for privacy collaboration is a collaboration request transaction, the event related to privacy collaboration between members is a privacy collaboration request event, and the privacy collaboration request event includes information of the requesting member and the responding member participating in the privacy computing indicated by the collaboration request transaction; the data plane is specifically used to: initiate a notification to the responding member based on the resource scheduling instruction, and, in response to the confirmation operation of the responding member, submit a collaboration confirmation transaction to the blockchain network; In the case where the blockchain transaction used for privacy collaboration is a collaboration confirmation transaction, the event related to the privacy collaboration between members is a privacy collaboration confirmation event, and the privacy collaboration confirmation event includes information of the requesting member and the responding member; the data plane is specifically used to: based on the resource scheduling instructions, use the off-chain resources on the node devices corresponding to the requesting member and the responding member to establish a network connection and participate in privacy computing.

7. According to the system of claim 1, the contract account of the privacy collaboration smart contract contains a contract status for recording member registration information, wherein the member registration information contains description information of the data resources held by the corresponding member and information of the type of privacy collaboration protocol supported by the corresponding member; the control plane is also used to: According to the received registration information query transaction, query the member registration information recorded in the contract account of the privacy collaboration smart contract by any member; and / or, According to the received registration information maintenance transaction, new member registration information is added to the contract state for recording member registration information, or the existing member registration information in the contract state for recording member registration information is modified or deleted.

8. A privacy collaboration method with a separated control plane and a separated data plane, wherein a blockchain node is deployed on each node device corresponding to each member, and the blockchain network to which the blockchain node belongs contains a privacy collaboration smart contract for implementing privacy collaboration; the method is applied to a node device corresponding to any member, and the method comprises: On the control plane: calling the privacy collaboration smart contract according to the blockchain transaction for privacy collaboration submitted to the blockchain network; And, if an event related to privacy collaboration between members is monitored after the privacy collaboration smart contract is called, and the event is related to any of the members, a resource scheduling instruction for the data plane is generated accordingly; On the data plane: according to the resource scheduling instructions issued by the control plane, off-chain resources on the node device are allocated for any member to participate in the privacy collaboration process.

9. According to the method of claim 8, the off-chain resources on the node device include: A network module and a computing module, wherein the computing module is configured with a privacy collaboration algorithm library; Allocating off-chain resources on the node device according to the resource scheduling instruction issued by the control plane includes: In a case where the scheduling target of the resource scheduling instruction includes network resources, scheduling the network module to allocate network resources for realizing network communication in the privacy collaboration process; When the scheduling target of the resource scheduling instruction includes computing resources, the computing module is scheduled to allocate computing resources, and the privacy collaboration algorithm library is called according to the privacy computing protocol type indicated in the resource scheduling instruction to implement privacy computing in the privacy collaboration process.

10. The method according to claim 9, The privacy collaboration algorithm library is a full privacy collaboration algorithm library, corresponding to a full range of privacy collaboration algorithms; or, The privacy collaboration algorithm library is a lightweight privacy collaboration algorithm library, corresponding to the privacy collaboration algorithm selected by any member.

11. The method according to claim 9, wherein the data plane further comprises: Interaction module; Allocating off-chain resources on the node device according to the resource scheduling instruction issued by the control plane includes: Creating a sending message queue for the communication request generated by the computing module through the interaction module, so that the network module asynchronously forwards the communication request in the sending message queue; A return message queue is created for the response message returned by the network module through the interaction module, so that the computing module can asynchronously process the response message in the return message queue.

12. The method according to claim 8, In the case where the blockchain transaction for privacy collaboration is a collaboration request transaction, the event related to privacy collaboration between members is a privacy collaboration request event, and the privacy collaboration request event includes information of requesting members and responding members participating in privacy computing indicated by the collaboration request transaction; The allocating off-chain resources on the node device according to the resource scheduling instruction issued by the control plane includes: initiating a notification to any member as a responder member based on the resource scheduling instruction, and submitting a collaborative confirmation transaction to the blockchain network in response to a confirmation operation of any member; In the case where the blockchain transaction for privacy collaboration is a collaboration confirmation transaction, the event related to the privacy collaboration between members is a privacy collaboration confirmation event, and the privacy collaboration confirmation event includes information of the requesting member and the responding member; the off-chain resources on the node device are allocated according to the resource scheduling instruction issued by the control plane, including: based on the resource scheduling instruction, when any of the members belongs to the requesting member or the responding member, the off-chain resources on the node device are used to establish a network connection and participate in privacy computing.

13. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of any one of the methods of claims 8 to 12 when executing the program.

14. A computer-readable storage medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the steps of the method according to any one of claims 8 to 12.

15. A computer program product, comprising a computer program / instruction, which, when executed by a processor, implements the steps of the method according to any one of claims 8 to 12.