Data processing method, system, device, medium and program product

By decrypting and sharing data within the server's trusted hardware execution environment, the problem of data isolation of different types of source is solved, and efficient data utilization and secure sharing are achieved.

CN120068125BActive Publication Date: 2025-08-22INSPUR (BEIJING) ELECTRONICS INFORMATION IND CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510549713.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-08-22
Estimated Expiration
2045-04-28

AI Technical Summary

Technical Problem

Different types of scene source data are isolated from each other, forming data islands, resulting in low data utilization.

Method used

By decrypting the requested ciphertext in the server's trusted hardware execution environment, obtaining the target task, and obtaining source data from other clients for task execution, the results are feedback in the form of ciphertext to ensure the temporary storage and trusted use of data, and blocking the connection between clients.

Benefits of technology

It realizes the sharing of data from different client sources, improves data utilization, and ensures data security and independence, simplifies communication complexity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068125B_ABST
    Figure CN120068125B_ABST
Patent Text Reader

Abstract

The present application discloses a data processing method, system, device, medium and program product, which relate to the field of computer technology. In the present application, the server can use the source data provided by one client to complete the target task submitted by another client, thereby realizing the sharing of source data of different clients; and the source data and tasks of each client are temporarily stored in the server in ciphertext and used in the server in a trusted manner; that is: the server only performs temporary storage and trusted use of source data and tasks, and cannot permanently store source data and tasks, thereby protecting the independence and security of the source data and tasks of each client. As the center of trust for each client, the server shields the connection between different clients and simplifies the complexity of communication. The data of each client is shared and guaranteed to be secure from being leaked.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a data processing method, system, device, medium and program product. Background Art

[0002] New digital technologies such as artificial intelligence (AI) urgently require massive, multi-source databases. This is particularly true for autonomous driving, which requires data from diverse road scenarios, including highways, cities, mountainous areas, and rural areas, to train autonomous driving models. However, currently, these data sources are isolated from each other, forming data silos. This prevents the full realization of their value and results in low data utilization.

[0003] Therefore, how to improve the utilization rate of different types of source data is a problem that those skilled in the art need to solve. Summary of the Invention

[0004] In view of this, the purpose of this application is to provide a data processing method, system, device, medium and program product to improve the utilization rate of different types of source data.

[0005] In a first aspect, the present application provides a data processing method, applied to a server, comprising:

[0006] Receive the request ciphertext sent by the target client; the request ciphertext is encrypted using the key negotiated between the target client and the server;

[0007] Decrypt the request ciphertext in the trusted hardware execution environment in the server to obtain the target task;

[0008] If the source data corresponding to the target task is not obtained from the target client, the source data is obtained from other clients connected to the server and stored in the trusted hardware execution environment;

[0009] In the trusted hardware execution environment, the target task is run based on the source data to obtain the target result;

[0010] The target result is fed back in encrypted form to the receiving end preset for the target result, and the target task, source data and target result in the trusted hardware execution environment are deleted.

[0011] In a second aspect, the present application provides a data processing system, comprising: a server and a plurality of clients connected to the server;

[0012] The server includes: a processor, an intelligent network card, and a computing device; the processor, the intelligent network card, and the computing device are all equipped with confidential hardware modules;

[0013] The server is used to receive the request ciphertext sent by the target client; the request ciphertext is encrypted using the key negotiated between the target client and the server; the request ciphertext is decrypted in the trusted hardware execution environment of the server to obtain the target task; if the source data corresponding to the target task is not obtained from the target client, the source data is obtained from other clients connected to the server, and the source data is stored in the trusted hardware execution environment; in the trusted hardware execution environment, the target task is run based on the source data to obtain the target result; the target result is fed back to the receiving end preset for the target result in the form of ciphertext, and the target task, source data and target result in the trusted hardware execution environment are deleted;

[0014] The target client is at least one of the multiple clients, and the trusted hardware execution environment is created based on a confidential hardware module in a processor, a smart network card, or a computing device.

[0015] In a third aspect, the present application provides an electronic device, comprising:

[0016] memory for storing computer programs;

[0017] A processor is used to execute the computer program to implement the aforementioned disclosed data processing method.

[0018] In a fourth aspect, the present application provides a computer-readable storage medium for storing a computer program, wherein the computer program implements the aforementioned disclosed data processing method when executed by a processor.

[0019] In a fifth aspect, the present application provides a computer program product, comprising a computer program / instruction, which implements the steps of the aforementioned disclosed data processing method when executed by a processor.

[0020] In this application, the server can use the source data provided by one client to complete the target task submitted by another client, thereby realizing the sharing of source data of different clients; and, the source data and tasks of each client are temporarily stored in the server in ciphertext and used in the server in a trusted manner; that is: the server only performs temporary storage and trusted use of source data and tasks, and cannot permanently store source data and tasks, thereby protecting the independence and security of the source data and tasks of each client. As the center of trust for each client, the server shields the connection between different clients and simplifies the complexity of communication. The data of each client is shared, improving the utilization rate of data of all parties and ensuring security from being leaked.

[0021] Correspondingly, the data processing system, device, medium and program product provided by this application also have the above-mentioned technical effects. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] In order to more clearly illustrate the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0023] Figure 1 A flow chart of a data processing method disclosed in this application;

[0024] Figure 2 A schematic diagram of a data processing system disclosed in this application;

[0025] Figure 3 A schematic diagram of a server structure disclosed in this application;

[0026] Figure 4 A schematic diagram of a trusted execution environment and a non-trusted execution environment in a server disclosed in this application;

[0027] Figure 5 A flow chart of another data processing method disclosed in this application;

[0028] Figure 6 Another server structure diagram provided for this application;

[0029] Figure 7 This is a terminal structure diagram provided for this application. DETAILED DESCRIPTION

[0030] The following will be combined with the accompanying drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0031] It should be noted that, in the description of this application, the terms "comprises," "includes," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. The terms "first," "second," etc., in this application are used to distinguish similar objects, and are not used to describe a particular order or sequence.

[0032] In order to enable those skilled in the art to better understand the present application, the present application is further described in detail below with reference to the accompanying drawings and specific implementation methods.

[0033] See also Figure 1 As shown, the embodiment of the present application discloses a data processing method, which is applied to a server and includes:

[0034] S101. Receive a request ciphertext sent by a target client; encrypt the request ciphertext using a key negotiated between the target client and the server.

[0035] In this embodiment, the server is connected to multiple clients, and any client negotiates with the server: the key used to encrypt communication data, the parameters of the random number generation algorithm, the parameters of the data encryption and decryption algorithm, the parameters of the signature / verification algorithm, the parameters of the key agreement algorithm and / or the parameters of the authentication algorithm, so that any client and the server can communicate secretly to ensure communication security.

[0036] S102: Decrypt the request ciphertext in the trusted hardware execution environment of the server to obtain the target task.

[0037] It should be noted that the trusted hardware execution environment in the server is constructed based on the relevant confidential hardware modules in the server. Any confidential hardware module in the server includes: a secure memory, a secure transmitter, and a confidential calculator. In one embodiment, the server initializes the algorithm parameters required for communication with the target client; the algorithm parameters include: parameters of the random number generation algorithm, parameters of the data encryption and decryption algorithm, parameters of the signature / verification algorithm, parameters of the key agreement algorithm, and / or parameters of the authentication algorithm; initializes the confidential hardware module in the server; and creates a trusted hardware execution environment based on the initialized confidential hardware module. The server and the target client then mutually authenticate each other, allocating a trusted memory area to the authenticated client to store the data provided by the client and perform key negotiation. Specifically, the server receives a login authentication request from the target client; performs two-way authentication between the target client and the server based on the login authentication request; and allocates a trusted memory area for the target client within the trusted hardware execution environment. The server receives a key negotiation request from the target client; completes the key negotiation in the trusted memory area based on the key negotiation request; stores the negotiated key, and synchronizes the negotiated key to the target client.

[0038] S103: If the source data is not obtained from the target client, the source data corresponding to the target task is obtained from other clients connected to the server, and the source data is stored in the trusted hardware execution environment.

[0039] In this embodiment, when the source data corresponding to the target task cannot be obtained from the target client, the source data corresponding to the target task is obtained from other clients connected to the server.

[0040] S104: In the trusted hardware execution environment, run the target task based on the source data to obtain the target result.

[0041] Since the server allocates a trusted memory area to each authenticated client, the source data or task data provided by the corresponding client is stored in the trusted memory area allocated by the server for the client, and the relevant ciphertext is decrypted and temporarily stored in this trusted memory area, and the relevant task is executed in this trusted memory area. In one embodiment, decrypting the request ciphertext in the trusted hardware execution environment of the server to obtain the target task includes: decrypting the request ciphertext in the trusted memory area to obtain the target task; accordingly, storing the source data in the trusted hardware execution environment includes: storing the source data in the trusted memory area; accordingly, executing the target task based on the source data in the trusted hardware execution environment includes: executing the target task based on the source data in the trusted memory area.

[0042] It should be noted that the target client that submits the target task may also provide all or part of the source data of the target task. Therefore, in one embodiment, if the source data is obtained from the target client, the source data is stored in the trusted hardware execution environment; in the trusted hardware execution environment, the target task is run based on the source data to obtain the target result; the target result is fed back in ciphertext to the receiving end preset for the target result, and the target task, source data and target result in the trusted hardware execution environment are deleted. For example: the target task is a training task of an image recognition model, and the training data set of the image recognition model can be obtained from the target client. Therefore, after the training data set is obtained from the target client, the training data set is stored in the trusted hardware execution environment; in the trusted hardware execution environment, the image recognition model is trained based on the training data set to obtain a trained model; the trained model is fed back in ciphertext to the relevant receiving end, and the training data set, trained model and other related data in the trusted hardware execution environment are deleted to prevent data leakage.

[0043] In another embodiment, if part of the source data is obtained from the target client, the remaining part of the source data is obtained from other clients connected to the server. That is, the source data for running the target task is obtained first from the target client that submitted the target task. When the source data at the target client is insufficient to run the target task, the remaining source data required to run the target task is obtained from other clients. For example, the target task is a training task for an image recognition model, but only part of the training data for the image recognition model can be obtained from the target client. Therefore, after obtaining part of the training data from the target client, the remaining training data is obtained from at least one other client connected to the server, and then these training data are merged to form a training data set for the image recognition model. Obtaining data from at least one other client connected to the server includes: the server sends a request to obtain relevant data to at least one client. If the client that receives the request has the data that the server wants to obtain, then the client sends this data to the server. During this process, the server and the relevant clients communicate in encrypted form. Another example: the target task is to train an autonomous driving model, but only the urban road scene data can be obtained from the target client. Therefore, after obtaining the urban road scene data from the target client, the highway scene data, mountain road scene data, and / or rural road scene data are obtained from at least one other client connected to the server. These scene data are then merged as the training data set for the autonomous driving model, so that the trained autonomous driving model can be applied to scenes such as urban roads, highways, mountain roads, and / or rural roads. It can be seen that when the source data at the target client is insufficient to run the target task, the partial data provided by the target client can be a complete data set or a portion of a complete data set; accordingly, the other part of the data provided by other clients can also be a complete data set or a portion of a complete data set.

[0044] In one embodiment, the target task is used to train or infer a target model; accordingly, the source data is the training input data or inference input data of the target model; accordingly, in a trusted hardware execution environment, the target task is run based on the source data to obtain a target result, including: in the trusted hardware execution environment, using the training input data or inference input data to train or infer the target model, and using the trained model or inference result as the target result. In one embodiment, the target task is used to train an autonomous driving model; accordingly, the source data is at least one driving scenario data of the autonomous driving model; accordingly, in the trusted hardware execution environment, the target task is run based on the source data to obtain a target result, including: in the trusted hardware execution environment, using the at least one driving scenario data to train the autonomous driving model, and using the trained model as the target result.

[0045] S105: Feedback the target result in encrypted form to the receiving end preset for the target result, and delete the target task, source data and target result in the trusted hardware execution environment.

[0046] In this embodiment, the receiving ends preset for the target result include: the client, other clients connected to the server and / or third-party devices. The target client can specify the receiving end in the request ciphertext, or the server and the target client can negotiate to specify the receiving end.

[0047] In this embodiment, the server can use the source data provided by one client to complete the target task submitted by another client, thereby enabling the sharing of source data from different clients. Furthermore, each client's source data and tasks are temporarily stored in encrypted form on the server and used in a trusted manner. In other words, the server only temporarily stores and trusts source data and tasks and cannot permanently store them, thereby protecting the independence and security of each client's source data and tasks. As the center of trust for each client, the server shields connections between different clients and simplifies communication complexity. Data from each client is shared, improving the utilization rate of each party's data while ensuring security and preventing leakage.

[0048] See Figure 2 A data processing system includes a server and two users: User 1 and User 2; one user is a client. The server includes: a processor confidential computing module, a heterogeneous processor confidential computing module, a traditional processor module, and a traditional heterogeneous processor module. Among them, the core of the processor confidential computing module and the traditional processor module can be a CPU, and the heterogeneous processor confidential computing module and the traditional heterogeneous processor module can be heterogeneous accelerators such as GPU and FPGA. In one example, the server may also include components such as a power supply, a heat sink, and a network processor; network processors such as network cards, etc., please refer to the details. Figure 3 .like Figure 2 and Figure 4 As shown, the server can provide a trusted execution environment based on a heterogeneous accelerator, a central processing unit, or a network processor, and the server can provide a non-trusted execution environment based on a traditional processor module.

[0049] See Figure 5 The normal operation of the data processing system follows the following steps: system initialization, including key generation, device initialization, etc.; creation of a trusted execution environment; multi-party computing application authentication; shared negotiation key generation; secure storage of negotiation keys; shared data encryption / decryption / computation; and shared computing result encryption / decryption.

[0050] 1. Initialization system includes:

[0051] Algorithm initialization: The system creates and initializes relevant algorithms and system parameters based on application requirements. These include, but are not limited to, the random number generation algorithm RanGen, the data symmetric encryption and decryption algorithms Enc / Dec, the proxy (re)encryption and decryption algorithms ProEnc / ProDec, the digital signature / verification algorithms Sig / Veri, the key agreement algorithm KeyAgr between the client and the device, the authentication algorithm TeeAuth and the application authentication algorithm AppAuth required to establish a trusted execution environment for computing devices. Different clients can use different or the same algorithms. Communication between the server and different clients is encrypted, but the authentication algorithms, agreement algorithms, encryption and decryption algorithms used can vary.

[0052] Key initialization: The system initializes the corresponding keys based on the established algorithm, including but not limited to the system master key (MK), the key agreement algorithm key (KAK), and the trusted execution environment authentication algorithm-related keys (TAK) (including {STK (Secure Transformation Key), SSK (Secure Storage Key), EAK (Equipment Authentication Key), AAK (App Authentication Key), etc.}. The trusted execution environment authentication algorithm-related keys can be considered a key group, and different modules require different keys.

[0053] Device initialization: Initialize the device and initialize the keys of key modules according to the requirements for creating a trusted execution environment, including but not limited to the confidential computing module (used for confidential computing of data by the central processing unit or network processor), the heterogeneous confidential computing module (used for confidential computing of data accelerated by heterogeneous processors), the secure storage module (used for secure storage of data such as keys), and the secure transmission module (used for transmitting data).

[0054] 2. Create a Trusted Execution Environment (TEE): Leverage the software and hardware resources within the basic TEE to create a TEE, including but not limited to the central processing unit (CPU), heterogeneous processors, network processors, secure transmission modules, and secure storage modules. For example, Intel's SGX provides hardware resources to create a TEE, including the protected memory area EPC (Enclave Page Cache, a protected memory area within the TEE) and the CPU's internal memory encryption engine MEE (Memory Encryption Engine).

[0055] 3. Authenticating Multi-Party Computing Applications: Applications running in a trusted execution environment are securely authenticated through remote authentication and other methods to ensure their authenticity and reliability. A trusted memory (enclave) area is created for the application in the EPC for storing application code and data. Furthermore, the client can also use remote authentication to verify the authenticity and reliability of the server's trusted execution environment. This method forms a two-way authentication between the client and the server, enhancing system trustworthiness.

[0056] 4. Generate a shared negotiation key: The system and client application perform key negotiation using the initialized random number generation algorithm, key negotiation algorithm, and related keys. They generate a shared negotiation key (SK) that is used to establish a secure data transmission channel between the system and the client. If there are three or more clients, each client negotiates with the server separately.

[0057] 5. Secure storage of negotiated keys: The negotiated key SK is securely stored by both the client and the server. The server uses the secure transmission module to store the negotiated key SK.

[0058] 6. Encrypted Shared Data: The client uses SK to symmetrically encrypt the data to be shared and transmits it to the server via a communication channel. The server receives the encrypted data and forwards it to the secure storage device of the heterogeneous processor. The server receives and forwards the encrypted data through, but is not limited to, the processor and network interface card.

[0059] 7. Decrypt shared data: The server heterogeneous processor reads the negotiated key SK stored in the secure transmission module to decrypt the customer encrypted data stored in the secure storage module, and writes the decrypted data back to the secure storage module to support data sharing and computing.

[0060] 8. Compute shared data: Heterogeneous processors read decrypted data from multiple clients in the secure storage module in a trusted execution environment, perform confidential computations on the data as required by the application, obtain computation results, and feed the results back to the secure transmission module, central processing unit, or network processor.

[0061] 9. Encrypted shared calculation results: The calculation results are encrypted by the secure transmission module, central processing unit or network processor, and the encrypted results are fed back to the client through a public channel.

[0062] 10. Decrypt and share the calculation results: The client uses SK to decrypt the encrypted calculation results to obtain the final calculation results.

[0063] The system provided in this embodiment can be used for financial lending services. For example, multiple banks share data, allowing a server to calculate a customer's loan limit or credit score, and then analyze and infer the customer's repayment ability and risk. It can also be used for medical diagnosis services. For example, multiple hospitals share data, allowing a server to calculate a patient's imaging and laboratory data, and then infer the patient's diagnosis and treatment plan. It can also be used for road traffic prediction services. For example, multiple departments such as the Highway Administration, Meteorological Bureau, and Traffic Management Bureau share data, allowing a server to calculate and analyze the road capacity of a specific road at a specific time and provide travel guidance to users. It can also be used for autonomous driving tasks. For example, multiple users provide autonomous driving data for different scenarios, allowing a server to update autonomous driving model parameters.

[0064] The following describes data sharing and utilization for autonomous driving scenarios, using the example of two parties. Assume that the two parties wish to jointly train the same autonomous driving model using their own unique scenario databases. The server is independently operated by a trusted third party, two-way authentication is used for multi-party applications, and the negotiated key is stored in a secure transmission module. The relevant process is described as follows:

[0065] 1. Initialize the system: The system creates and initializes relevant algorithms and system parameters according to the requirements of the autonomous driving scenario library:

[0066] Step 1.1: Initialize the random number generation algorithm RanGen and its parameters.

[0067] Step 1.2: Initialize the data symmetric encryption / decryption algorithm Enc / Dec and parameters.

[0068] Step 1.3: Initialize the data asymmetric encryption and decryption algorithm PubEnc / PubDec and parameters.

[0069] Step 1.4: Initialize the digital signature / verification algorithm Sign / Veri and its parameters.

[0070] Step 1.5: Initialize the key agreement algorithm KeyAgr and parameters between the client and the device.

[0071] Step 1.6: Initialize the authentication algorithm TeeAuth and parameters required to create the trusted execution environment of the computing device.

[0072] Step 1.7: Initialize the two-way authentication algorithm MultAuth and parameters between the client application and the server environment.

[0073] The system initializes the corresponding key according to the initialization algorithm:

[0074] Step 1.8: Initialize the system master key (MK) according to steps 1.1-1.7. Generate the client's asymmetric public key (PubKey_Client) and private key (PriKey_Client) and the server's asymmetric public key (PubKey_Server) and private key (PriKey_Server) from the system master key. For simplicity, the public and private keys are functionally considered to be shared by the public key encryption / decryption algorithm and the digital signature / verification algorithm. In practice, they can be used separately.

[0075] Step 1.9: Initialize each module of the confidential computing server, such as CPU, GPU, NPU, etc., according to the functional requirements of the system and computing device. During the creation of the trusted execution environment, the key set consisting of the public / private key required for device authentication is TAK_i={STK_i, SSK_i, EAK_i, AAK_i}, where i represents CPU, GPU, NPU, etc., and the system determines the key set components based on the trusted execution environment hardware and software infrastructure with different functions.

[0076] The system initializes the device modules with key protection functions according to the initialized keys:

[0077] Step 1.10: Write STK_CPU, SSK_CPU, EAK_CPU, and AAK_CPU into the secure transmission module, secure storage module, and confidential computing module of the CPU, respectively. Similarly, write STK_GPU, SSK_GPU, EAK_GPU, and AAK_GPU into the secure transmission module, secure storage module, and confidential computing module of the GPU, respectively. In addition, the server asymmetric public key PubKey_Server / private key PriKey_Server is written into the secure storage module of the CPU (or GPU, in this embodiment, writing into the CPU is used as an example) as needed.

[0078] 2. Create a trusted execution environment:

[0079] Step 2.1: Based on the device modules initialized in step 1.10, perform trusted authentication of each device module using a digital signature algorithm in an online or offline manner. For example, the processor confidential computing module verifies the following signature:

[0080] If the equation holds, the processor confidential computing module trusts the heterogeneous processor confidential computing module, where Public_EAK_GPU and Secret_EAK_GPU are the heterogeneous confidential computing module authentication public key and private key, respectively, and Random_CPU and Random_CPU are the random numbers generated by each confidential computing module. If the equation does not hold, the trusted execution environment creation fails. Similarly, similar steps are performed between other modules required for the trusted execution environment, such as the processor confidential computing module and its secure storage module and secure transmission module, to complete the establishment of trust relationships between the various modules of the device.

[0081] Step 2.2: Complete mutual authentication between the modules of the device according to step 2.1. The device establishes a trusted execution environment by verifying the following authentication algorithm:

[0082] If the equation holds, a trusted execution environment (TEE) is established; otherwise, the creation of the TEE fails. TeeAuth is a truth function, meaning that if all elements in the function are 1, the result is 1; otherwise, the result is 0.

[0083] 3. Authentication multi-party computing applications:

[0084] Step 3.1: After the device trusted execution environment is established in step 2.2, any module on the device and the multi-party computing application perform mutual authentication to establish a trust relationship, thereby completing the mutual authentication between the device and the application (assuming all trust relationships are transitive). The trust relationship between the processor confidential computing module and the multi-party computing application must meet the following conditions:

[0085] If the equation holds, the mutual authentication between the processor confidential computing module (device) and the multi-party computing application (application) is complete; otherwise, the authentication fails.

[0086] Step 3.2: After completing the two-way authentication in step 2.2, a trusted memory area is created for the application to store the application code and data (shared negotiation key).

[0087] 4. Generate a shared negotiation key:

[0088] Step 4.1: The shared negotiation key generation process is as follows:

[0089] ,in, Hash is the hash function, g is the generator of the cyclic group, and ID represents the client or server identity information. Here, steps 3.1 and 4.2 can be combined into a two-way authentication and key agreement process.

[0090] 5. Securely store the negotiated key:

[0091] Step 5.1: The negotiated key SK is securely stored by the client and server, respectively. The server's key is stored by the secure transmission module.

[0092] 6. Encrypt shared data:

[0093] Step 6.1: M clients use the negotiated key SKi with the server to symmetrically encrypt the shared database data of different scenarios, which can be expressed as The generated ciphertext is transmitted to the server via a public channel, where i is the client number. After receiving the client's encrypted data, the server forwards it to the secure storage device of the heterogeneous processor.

[0094] 7. Decrypt shared data:

[0095] Step 7.1: The server heterogeneous processor reads the negotiated key SKi stored in the secure transmission module to decrypt the client encrypted data, which can be expressed as . And write the decrypted data back to the secure storage module.

[0096] 8. Calculate shared data:

[0097] Step 8.1: The heterogeneous processor reads the multi-party decrypted data in the secure storage module under the trusted execution environment i , perform confidential calculations on the data according to the application requirements and obtain the calculation results Result,

[0098] . And feed back the calculation results to the secure transmission module.

[0099] 9. Encrypted shared calculation results:

[0100] Step 9.1: The secure transmission module encrypts the calculation result, which is expressed as , and the encrypted result Feedback to the client.

[0101] 10. Decrypt the shared calculation results:

[0102] Step 10.1: The client uses SK to decrypt the encrypted calculation result, which is expressed as , to obtain the final calculation results.

[0103] Referring to the above process, assume that there are three participants who provide scene A, scene B and scene C respectively. Scene A is the rural road scene library data, scene B is the highway scene library data, and scene C is the urban road scene library data. If the autonomous driving model is trained with only one scene library data, then the decision-making of the model will not be sensitive and perfect when used in other scenes. Then, if a shared database is established using the data from these three parties, an autonomous driving model that can adapt to rural roads, highways and urban roads at the same time can be calculated (trained). Based on this, the function in step 8.1 can be regarded as the training model for autonomous driving, Data i For different scenario library data, the data of scenario A, scenario B and scenario C are encrypted and sent to the server. The server decrypts and calculates in a heterogeneous and secure environment to achieve efficient and private data sharing and circulation, and train an autonomous driving model that can adapt to rural roads, highways and urban roads at the same time.

[0104] In this embodiment, in a trusted execution environment, the server uses a trusted application to negotiate with the user to generate a negotiation key, and securely stores the negotiation key in a dedicated negotiation key storage module under a heterogeneous architecture. In the trusted execution environment, the server uses the trusted application to call the negotiation key securely stored in the negotiation key storage module to decrypt the data, and feeds the decrypted plaintext data back to the confidential computing module to perform multi-source data calculations. Finally, the calculation results are encrypted using the negotiation key and securely fed back to the user.

[0105] This solution solves the problem of sharing and using scenario library data in different scenarios, improving data computing efficiency while ensuring data privacy and security. This solution integrates three technologies: heterogeneous computing, confidential computing, and key agreement, providing a secure and efficient method for data sharing and use.

[0106] A data processing device provided in an embodiment of the present application is introduced below. The data processing device described below can be referenced with other embodiments described herein.

[0107] The present application discloses a data processing method, which is applied to a server and includes:

[0108] The receiving module is used to receive the request ciphertext sent by the target client; the request ciphertext is encrypted using the key negotiated between the target client and the server;

[0109] A decryption module is used to decrypt the request ciphertext in the trusted hardware execution environment of the server to obtain the target task;

[0110] An acquisition module is used to acquire the source data from other clients connected to the server if the source data corresponding to the target task is not acquired from the target client, and store the source data in the trusted hardware execution environment;

[0111] The running module is used to run the target task based on the source data in the trusted hardware execution environment to obtain the target result;

[0112] The feedback module is used to feed back the target result in encrypted form to the receiving end preset for the target result, and delete the target task, source data and target result in the trusted hardware execution environment.

[0113] In one embodiment, an initialization module is further included for initializing the algorithm parameters required for communicating with the target client; the algorithm parameters include: parameters of the random number generation algorithm, parameters of the data encryption and decryption algorithm, parameters of the signature / signature verification algorithm, parameters of the key agreement algorithm and / or parameters of the authentication algorithm; the confidential hardware module in the server is initialized; and a trusted hardware execution environment is created based on the initialized confidential hardware module.

[0114] In one embodiment, it also includes an authentication module for receiving a login authentication request sent by a target client; performing two-way authentication between the target client and the server according to the login authentication request; and dividing a trusted memory area for the target client in a trusted hardware execution environment.

[0115] In one embodiment, the decryption module is used to: decrypt the request ciphertext in the trusted memory area to obtain the target task;

[0116] Accordingly, the acquisition module is used to: store the source data into the trusted memory area;

[0117] Accordingly, the running module is used to run the target task based on the source data in the trusted memory area.

[0118] In one embodiment, a negotiation module is further included, which is used to receive a key negotiation request sent by a target client; complete key negotiation in a trusted memory area according to the key negotiation request; store the negotiated key, and synchronize the negotiated key to the target client.

[0119] In one embodiment, the acquisition module is further configured to: if part of the source data is acquired from the target client, acquire the remaining part of the source data from other clients connected to the server.

[0120] In one embodiment, if the source data is obtained from the target client, the source data is stored in a trusted hardware execution environment; in the trusted hardware execution environment, the target task is run based on the source data to obtain the target result; the target result is fed back in encrypted form to the receiving end preset for the target result, and the target task, source data and target result in the trusted hardware execution environment are deleted.

[0121] In one embodiment, the receiving end includes: a client, other clients connected to the server, and / or third-party devices.

[0122] In one embodiment, the target task is used to train or infer the target model; accordingly, the source data is the training input data or inference input data of the target model; accordingly, the running module is used to: in a trusted hardware execution environment, use the training input data or inference input data to train or infer the target model, and use the trained model or inference result as the target result.

[0123] In one embodiment, the target task is used to train the autonomous driving model; accordingly, the source data is at least one driving scene data of the autonomous driving model; accordingly, the running module is used to: train the autonomous driving model using at least one driving scene data in a trusted hardware execution environment, and use the trained model as the target result.

[0124] Among them, for more specific working processes of each module and unit in this embodiment, reference can be made to the corresponding contents disclosed in the aforementioned embodiments, which will not be repeated here.

[0125] As can be seen, in this embodiment, the server only provides temporary and trusted storage for source data and tasks, and cannot permanently store them. This protects the independence and security of each client's source data and tasks. As the trusted center for each client, the server shields connections between different clients and simplifies communication complexity. This allows for data sharing across clients, improving data utilization and ensuring data security.

[0126] The following introduces a data processing system provided in an embodiment of the present application. The data processing system described below can be referenced with other embodiments described in this document.

[0127] The present application discloses a data processing system comprising a server and multiple clients connected to the server. The server comprises a processor, a smart network card (SmartNIC), and a computing device. The processor, SmartNIC, and computing device are each equipped with a confidential hardware module. The computing device includes an accelerator such as a GPU or FPGA.

[0128] The server is used to receive a request ciphertext sent by a target client; the request ciphertext is encrypted using a key negotiated between the target client and the server; the request ciphertext is decrypted in a trusted hardware execution environment in the server to obtain a target task; if the source data corresponding to the target task is not obtained from the target client, the source data is obtained from other clients connected to the server, and the source data is stored in the trusted hardware execution environment; in the trusted hardware execution environment, the target task is run based on the source data to obtain a target result; the target result is fed back in ciphertext to a receiving end preset for the target result, and the target task, source data and target result in the trusted hardware execution environment are deleted; the target client is at least one of a plurality of clients, and the trusted hardware execution environment is created based on a confidential hardware module in a processor, smart network card or computing device.

[0129] In one embodiment, the confidential hardware module includes: a secure memory, a secure transmitter, and a confidential calculator.

[0130] In this embodiment, the server only provides temporary and trusted storage for source data and tasks, and cannot permanently store them. This protects the independence and security of each client's source data and tasks. As a trusted center for each client, the server shields connections between different clients and simplifies communication complexity. This allows for data sharing across clients, improving data utilization and ensuring data security.

[0131] An electronic device provided in an embodiment of the present application is introduced below. The electronic device described below can be referenced with other embodiments described herein.

[0132] The present application discloses an electronic device, including:

[0133] Memory, used to store computer programs;

[0134] A processor is configured to execute the computer program to implement the method disclosed in any of the above embodiments.

[0135] In this embodiment, when the processor executes the computer program stored in the memory, it can specifically implement the following steps: receiving a request ciphertext sent by the target client; encrypting the request ciphertext using the key obtained by negotiation between the target client and the server; decrypting the request ciphertext in the trusted hardware execution environment in the server to obtain the target task; if the source data corresponding to the target task is not obtained from the target client, obtaining the source data from other clients connected to the server, and storing the source data in the trusted hardware execution environment; running the target task based on the source data in the trusted hardware execution environment to obtain the target result; feeding back the target result in ciphertext form to the receiving end preset for the target result, and deleting the target task, source data and target result in the trusted hardware execution environment.

[0136] In this embodiment, when the processor executes the computer program stored in the memory, it can specifically implement the following steps: initialize the algorithm parameters required for communication with the target client; the algorithm parameters include: parameters of the random number generation algorithm, parameters of the data encryption and decryption algorithm, parameters of the signature / signature verification algorithm, parameters of the key agreement algorithm and / or parameters of the authentication algorithm; initialize the confidential hardware module in the server; and create a trusted hardware execution environment based on the initialized confidential hardware module.

[0137] In this embodiment, when the processor executes the computer program stored in the memory, it can specifically implement the following steps: receiving a login authentication request sent by the target client; performing two-way authentication between the target client and the server based on the login authentication request; and dividing a trusted memory area for the target client in a trusted hardware execution environment.

[0138] In this embodiment, when the processor executes the computer program stored in the memory, it can specifically implement the following steps: receive a key negotiation request sent by the target client; complete key negotiation in the trusted memory area according to the key negotiation request; store the negotiated key, and synchronize the negotiated key to the target client.

[0139] In this embodiment, when the processor executes the computer program stored in the memory, the following steps may be specifically implemented: if part of the source data is obtained from the target client, the remaining part of the source data is obtained from other clients connected to the server.

[0140] In this embodiment, when the processor executes the computer program stored in the memory, it can specifically implement the following steps: if the source data is obtained from the target client, the source data is stored in the trusted hardware execution environment; in the trusted hardware execution environment, the target task is run based on the source data to obtain the target result; the target result is fed back in encrypted form to the receiving end preset for the target result, and the target task, source data and target result in the trusted hardware execution environment are deleted.

[0141] Furthermore, the embodiment of the present application also provides an electronic device. The electronic device can be Figure 6 The server shown can also be Figure 7 Terminal shown. Figure 6 and Figure 7 Each of the diagrams is a structural diagram of an electronic device according to an exemplary embodiment, and the contents in the diagrams cannot be considered as any limitation on the scope of use of the present application.

[0142] Figure 6 This is a schematic diagram of the structure of a server provided in an embodiment of the present application. The server may specifically include: at least one processor, at least one memory, a power supply, a communication interface, an input / output interface, and a communication bus. The memory is used to store a computer program, which is loaded and executed by the processor to implement the relevant steps of the data processing disclosed in any of the aforementioned embodiments.

[0143] In this embodiment, the power supply is used to provide operating voltage for each hardware device on the server; the communication interface can create a data transmission channel between the server and external devices. The communication protocol it follows is any communication protocol that can be applied to the technical solution of this application and is not specifically limited here; the input and output interface is used to obtain external input data or output data to the outside world. The specific interface type can be selected according to specific application needs and is not specifically limited here.

[0144] In addition, the memory as a carrier for resource storage can be a read-only memory, random access memory, disk or CD, etc. The resources stored thereon include operating system, computer programs and data, etc. The storage method can be temporary storage or permanent storage.

[0145] The operating system is used to manage and control the hardware devices and computer programs on the server, enabling the processor to operate and process data in the memory. It can be Windows Server, NetWare, Unix, Linux, etc. In addition to computer programs capable of performing the data processing methods disclosed in any of the aforementioned embodiments, computer programs can also include computer programs capable of performing other specific tasks. Data can include data such as application update information and other data such as application developer information.

[0146] Figure 7 This is a schematic diagram of the structure of a terminal provided in an embodiment of the present application. The terminal may specifically include but is not limited to a smartphone, tablet computer, laptop computer or desktop computer.

[0147] Generally, the terminal in this embodiment includes: a processor and a memory.

[0148] The processor may include one or more processing cores, such as a quad-core processor or an octa-core processor. The processor may be implemented in at least one of the following hardware forms: a DSP (Digital Signal Processing), an FPGA (Field-Programmable Gate Array), or a PLA (Programmable Logic Array). The processor may also include a main processor and a coprocessor. The main processor is used to process data in the awake state, also known as a CPU (Central Processing Unit); the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, the processor may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing content required to be displayed on the display. In some embodiments, the processor may also include an AI (Artificial Intelligence) processor, which is used to handle computational operations related to machine learning.

[0149] The memory may include one or more computer non-volatile storage media, which may be non-transitory. The memory may also include high-speed random access memory, and non-volatile memory, such as one or more disk storage devices, flash memory storage devices. In this embodiment, the memory is used to store at least the following computer program, wherein, after the computer program is loaded and executed by the processor, it can implement the relevant steps in the data processing method performed by the terminal side disclosed in any of the aforementioned embodiments. In addition, the resources stored in the memory may also include an operating system and data, etc., and the storage method may be temporary storage or permanent storage. Among them, the operating system may include Windows, Unix, Linux, etc. The data may include but is not limited to update information of the application.

[0150] In some embodiments, the terminal may further include a display screen, an input and output interface, a communication interface, a sensor, a power supply, and a communication bus.

[0151] Those skilled in the art will understand that Figure 7 The structure shown in the figure does not constitute a limitation to the terminal, and may include more or fewer components than shown in the figure.

[0152] The following introduces a computer-readable storage medium provided in an embodiment of the present application. The computer-readable storage medium described below can be referenced with other embodiments described in this document.

[0153] A computer-readable storage medium is used to store a computer program, wherein the computer program implements the data processing method disclosed in the above embodiment when executed by a processor.

[0154] The non-volatile storage medium is a computer-readable non-volatile storage medium that serves as a resource storage medium and can be a read-only memory, random access memory, magnetic disk, or optical disk. The resources stored thereon include operating systems, computer programs, and data, and the storage method can be either transient or permanent. In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, a USB flash drive, read-only memory (ROM), random access memory (RAM), a removable hard disk, a magnetic disk, or an optical disk, among other media capable of storing computer programs.

[0155] A computer program product provided in an embodiment of the present application is introduced below. The computer program product described below can be referenced with other embodiments described herein.

[0156] A computer program product comprises a computer program / instruction, which implements the steps of the aforementioned data processing method when executed by a processor.

[0157] An embodiment of the present application further provides another computer program product, including a non-volatile computer-readable storage medium, wherein the non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, any of the above-mentioned data processing methods is implemented.

[0158] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.

[0159] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, a hard disk, a removable disk, a CD-ROM, or any other form of non-volatile storage medium known in the art.

[0160] This document uses specific examples to illustrate the principles and implementation methods of this application. The description of the above embodiments is only used to help understand the method and core ideas of this application. At the same time, for those skilled in the art, based on the ideas of this application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as limiting this application.

Claims

1. A data processing method, characterized in that: Applicable to servers, including: Receiving a request ciphertext sent by a target client; encrypting the request ciphertext using a key negotiated between the target client and the server; Decrypting the request ciphertext in a trusted hardware execution environment in the server to obtain a target task; If the source data corresponding to the target task is not obtained from the target client, obtaining the source data from other clients connected to the server, and storing the source data in the trusted hardware execution environment; In the trusted hardware execution environment, executing the target task based on the source data to obtain a target result; Feedback the target result in encrypted form to a receiving end preset for the target result, and delete the target task, the source data, and the target result in the trusted hardware execution environment; Initializing algorithm parameters required for communication with the target client; the algorithm parameters include: parameters of a random number generation algorithm, parameters of a data encryption and decryption algorithm, parameters of a signature / signature verification algorithm, parameters of a key agreement algorithm, and / or parameters of an authentication algorithm; initializing a confidential hardware module in the server; creating the trusted hardware execution environment based on the initialized confidential hardware module; the confidential hardware module includes: a secure memory, a secure transmitter, and a confidential calculator; the confidential hardware module is disposed in a heterogeneous accelerator; wherein, receiving a login authentication request sent by the target client; performing a two-way authentication between the target client and the server according to the login authentication request; and allocating a trusted memory area for the target client in the trusted hardware execution environment; The communications between the server and different clients are all encrypted, and the authentication algorithms, negotiation algorithms, and encryption and decryption algorithms used are different.

2. The method according to claim 1, characterized in that Decrypting the request ciphertext in a trusted hardware execution environment in the server to obtain a target task includes: Decrypting the request ciphertext in the trusted memory area to obtain the target task; Accordingly, storing the source data in the trusted hardware execution environment includes: storing the source data in the trusted memory area; Accordingly, within the trusted hardware execution environment, running the target task based on the source data includes: The target task is executed in the trusted memory area based on the source data.

3. The method according to claim 1, characterized in that receiving a key negotiation request sent by the target client; completing key negotiation in the trusted memory area according to the key negotiation request; The negotiated key is stored and synchronized to the target client.

4. The method according to claim 1, wherein Also includes: If part of the source data is obtained from the target client, the remaining part of the source data is obtained from other clients connected to the server.

5. The method according to claim 1, wherein Also includes: If the source data is obtained from the target client, storing the source data in the trusted hardware execution environment; In the trusted hardware execution environment, executing the target task based on the source data to obtain a target result; Feedback the target result in encrypted form to a receiving end preset for the target result, and delete the target task, the source data and the target result in the trusted hardware execution environment.

6. The method according to claim 1, characterized in that The receiving end includes: the target client, other clients connected to the server and / or third-party devices.

7. The method according to any one of claims 1 to 6, characterized in that The target task is used to train or reason about the target model; Accordingly, the source data is the training input data or inference input data of the target model; Accordingly, within the trusted hardware execution environment, executing the target task based on the source data to obtain a target result includes: In the trusted hardware execution environment, the target model is trained or inferred using the training input data or the inference input data, and the trained model or the inference result is used as the target result.

8. The method according to any one of claims 1 to 6, characterized in that The target task is used to train the autonomous driving model; Accordingly, the source data is at least one driving scene data of the autonomous driving model; Accordingly, within the trusted hardware execution environment, executing the target task based on the source data to obtain a target result includes: In the trusted hardware execution environment, the autonomous driving model is trained using the at least one driving scenario data, and the trained model is used as the target result.

9. A data processing system, characterized in that: include: A server and a plurality of clients connected to the server; The server includes: a processor, an intelligent network card, and a computing device; the processor, the intelligent network card, and the computing device are all equipped with a confidential hardware module; The server is used to receive a request ciphertext sent by a target client; the request ciphertext is encrypted using a key obtained by negotiation between the target client and the server; the request ciphertext is decrypted in a trusted hardware execution environment in the server to obtain a target task; if the source data corresponding to the target task is not obtained from the target client, the source data is obtained from other clients connected to the server, and the source data is stored in the trusted hardware execution environment; in the trusted hardware execution environment, the target task is run based on the source data to obtain a target result; the target result is fed back to a receiving end preset for the target result in a ciphertext form, and the trusted hardware execution environment is deleted. The target task, the source data and the target result; wherein, the algorithm parameters required for communication with the target client are initialized; the algorithm parameters include: parameters of the random number generation algorithm, parameters of the data encryption and decryption algorithm, parameters of the signature / signature verification algorithm, parameters of the key agreement algorithm and / or parameters of the authentication algorithm; the confidential hardware module in the server is initialized; the trusted hardware execution environment is created based on the initialized confidential hardware module; wherein, a login authentication request sent by the target client is received; two-way authentication is performed between the target client and the server according to the login authentication request; a trusted memory area is divided for the target client in the trusted hardware execution environment; The target client is at least one of the multiple clients, and the trusted hardware execution environment is created based on the confidential hardware module in the processor, the smart network card or the computing device; the confidential hardware module includes: a secure memory, a secure transmitter and a confidential calculator; the confidential hardware module is arranged in a heterogeneous accelerator; the communication between the server and different clients is encrypted, and the authentication algorithm, negotiation algorithm, encryption and decryption algorithm used are different.

10. An electronic device, characterized in that: include: memory for storing computer programs; A processor, configured to execute the computer program to implement the method according to any one of claims 1 to 8.

11. A computer-readable storage medium, characterized in that Used to store a computer program, wherein when the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.

12. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the method according to any one of claims 1 to 8 is implemented.

Citation Information

Patent Citations

  • Service processing method and device based on trusted execution environment

    CN111181720A