Data processing method and device, nonvolatile storage medium and electronic equipment

By combining blockchain technology and privacy computing, the number of participating parties is determined based on data processing needs and data processing strategies is formulated, the problem of low data leakage risk and security in data sharing is solved, and higher data security and processing reliability are achieved.

CN120197213APending Publication Date: 2025-06-24CHINA TELECOM CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510294018.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The data processing method that implements data sharing function in the prior art has the risk of data leakage and has low data security.

Method used

By receiving the data processing requirements sent by the computing party associated with the blockchain, the number of participating computing parties is determined, and the data processing strategy, including different data encryption policies, is determined based on the quantity, and is sent to the participating computing party.

Benefits of technology

It realizes improving the confidentiality and reliability of data processing during data sharing, reducing the risk of data leakage, and improving data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120197213A_ABST
    Figure CN120197213A_ABST
Patent Text Reader

Abstract

The invention discloses a data processing method and device, a nonvolatile storage medium and electronic equipment. The method comprises the steps that a data processing demand sent by any computing party associated with the block chain is received, and the data processing demand is used for indicating a data processing method associated with the block chain; the number of participants matched with the data processing demand is determined from the block chain, and the participants are used for indicating nodes achieving the data processing demand in the distributed network; data processing strategies are determined according to the number of the calculation participants, and different data processing strategies comprise different data encryption strategies; and sending the data processing strategy to the calculation participating party. The technical problems of data leakage risk and low data security in a data processing method for realizing a data sharing function in related technologies are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of data processing, and in particular, to a method and device for data processing, a non-volatile storage medium, and an electronic device. Background Art

[0002] In the big data era, data has become the cornerstone of the development of the digital economy. By applying new-generation information technologies such as big data, blockchain, and the Internet of Things, various data services can be provided for all walks of life. In practical applications, individuals and enterprises, as well as enterprises and enterprises, also need to achieve data interconnection and interoperability through technologies such as data sharing. However, the data processing methods for data sharing in related data have the risk of data leakage of private data such as user information. Therefore, the data processing methods for implementing the data sharing function in related technologies have the problem of data security risks when applied.

[0003] In response to the above problems, no effective solution has been proposed yet. Summary of the Invention

[0004] Embodiments of this application provide a method and device for data processing, a non-volatile storage medium, and an electronic device, so as to at least solve the technical problems of data leakage risk and low data security in the data processing method for implementing the data sharing function in related technologies.

[0005] According to one aspect of the embodiments of this application, a method for data processing is provided, including: receiving a data processing requirement sent by any computing party associated with a blockchain, where the data processing requirement is used to indicate a data processing method related to the blockchain; determining the number of participating computing parties that match the data processing requirement from the blockchain, where the participating computing parties are used to indicate the nodes in the distributed network that implement the data processing requirement; determining a data processing strategy according to the number of participating computing parties, where different data processing strategies include different data encryption strategies; and sending the data processing strategy to the participating computing parties.

[0006] Optionally, determining the number of participating computing parties that match the data processing requirement includes: determining the type of the data processing requirement, where the type includes: single-task requirement and multi-task requirement. A single-task requirement is used to indicate a data processing requirement implemented by one participating computing party, and a multi-task requirement is used to indicate a data processing requirement implemented by multiple participating computing parties in cooperation; when the type of the data processing requirement is a single-task requirement, the number of participating computing parties that match the data processing requirement is one; when the type of the data processing requirement is a multi-task requirement, the number of participating computing parties that match the data processing requirement is multiple.

[0007] Optionally, determine a data processing strategy according to the number of participating computing parties, including: in the case of one party, execute a first type of data processing strategy, where the data encryption strategy in the first type of data processing strategy indicates encrypting sensitive data; in the case of multiple parties, execute a second type of data processing strategy, where the data encryption strategy included in the second type of data processing strategy indicates encrypting the target data corresponding to each participating computing party, and the target data is the data in the data to be processed that allows the participating computing party to process.

[0008] Optionally, after sending the data processing strategy to the participating computing parties, the method includes: determining the data usage rights of each participating computing party, where the data usage rights are used to indicate the data to be processed that allows the participating computing party to process; determining the target data corresponding to each participating computing party according to the data usage rights, where the target data is the data to be processed that allows the participating computing party to process; for each target data, determining the target computing resources for executing the data processing application on the target data, and providing the target computing resources for the participating computing party corresponding to the target data, where the participating computing party invokes the target computing resources to execute the data processing method indicated by the data processing requirements on the target data.

[0009] Optionally, in the case where the data processing requirement is a data intersection requirement indicating determining common data among multiple target data corresponding to multiple participating computing methods, by the participating computing parties invoking the corresponding target computing resources to execute the data processing method indicated by the data processing requirements on the target data, it includes: each participating computing party respectively invokes the target computing resources to encrypt multiple target data to obtain multiple encrypted target data; converting each encrypted target data into a corresponding identifier to obtain multiple identifiers, where the identifier is in the form of a numerical value; determining the data processing result corresponding to the data intersection requirement by the set composed of multiple encrypted target data corresponding to multiple identifiers with the same numerical value.

[0010] Optionally, in the case where the data processing requirement is a data query requirement, by the participating computing parties invoking the corresponding target computing resources to execute the data processing method indicated by the data processing requirements on the target data, it includes: parsing the data query requirement to obtain a query condition; extracting the data that meets the query condition from the target data as a preliminary query result; encrypting the sensitive data in the preliminary query result to obtain an encrypted result; determining the encrypted result and other data in the preliminary query result as the final data processing result corresponding to the data query requirement.

[0011] Optionally, the data processing method further includes: obtaining the logs generated when the participating computing parties execute the data processing strategy on the data to be processed; deleting the data related to sensitive data in the logs, where the sensitive data is the data used to describe personal information.

[0012] According to another aspect of the embodiments of the present application, there is also provided a data processing method, including: receiving a data processing policy sent by a blockchain, where different data processing policies include different data encryption policies; performing the data processing policy on target data according to the target computing resources provided by the blockchain, where the target data is the data to be processed that allows the participating computing parties to process, the participating computing parties are used to indicate the nodes in the distributed network that implement the data processing requirements, the data processing requirements are sent by any one of the participating computing parties associated with the blockchain, and the data processing requirements are used to indicate the data processing method related to the blockchain.

[0013] According to another aspect of the embodiments of the present application, there is also provided a data processing device, including: a receiving module, configured to receive data processing requirements sent by any one of the computing parties associated with the blockchain, where the data processing requirements are used to indicate the data processing method related to the blockchain; a first determination module, configured to determine the number of participating computing parties that match the data processing requirements from the blockchain, where the participating computing parties are used to indicate the nodes in the distributed network that implement the data processing requirements; a second determination module, configured to determine a data processing policy according to the number of participating computing parties, where different data processing policies include different data encryption policies; and a processing module, configured to send the data processing policy to the participating computing parties.

[0014] According to another aspect of the embodiments of the present application, there is also provided a non-volatile storage medium, in which a computer program is stored, and when the device where the non-volatile storage medium is located runs the computer program, it executes the above data processing method.

[0015] According to another aspect of the embodiments of the present application, there is also provided an electronic device, including a memory and a processor, where a computer program is stored in the memory, and the processor is configured to execute the above data processing method through the computer program.

[0016] According to another aspect of the embodiments of the present application, there is also provided a computer program product, including computer instructions, and when the computer instructions are executed by a processor, the steps of the above data processing method are implemented.

[0017] In the embodiments of the present application, a data processing requirement sent by any computing party associated with the blockchain is received, where the data processing requirement is used to indicate a data processing method related to the blockchain; the number of participating computing parties that match the data processing requirement is determined from the blockchain, where the participating computing parties are used to indicate the nodes in the blockchain that implement the data processing requirement; a data processing strategy is determined according to the number of participating computing parties, where different data encryption strategies are included in different data processing strategies; the data processing strategy is sent to the participating computing parties. In this way, the secure sharing of multi-party data is realized through blockchain technology and data encryption strategies. The blockchain technology is used to provide corresponding trusted computing resources for different participating computing parties, and each participating party processes the data over which it has processing authority by using the trusted computing resources and data encryption strategies. While realizing the flexible sharing of multi-party data, data processing is completed without any party obtaining (nor decrypting or inferring) the original data of any other party, achieving the purpose of data privacy protection, thereby realizing the technical effects of improving the confidentiality and reliability of data processing, reducing the risk of data leakage, and improving data security, and further solving the technical problems of data leakage risk and low data security existing in the data processing methods for realizing the data sharing function in the related art. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:

[0019] Figure 1 is a hardware structure block diagram of a computer terminal for a method of implementing data processing according to an embodiment of the present application;

[0020] Figure 2 is a flowchart of the steps of a method of data processing according to an embodiment of the present application;

[0021] Figure 3 is a flowchart of the steps of another method of data processing according to an embodiment of the present application;

[0022] Figure 4 is a schematic structural diagram of a device for data processing according to an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0023] To enable those skilled in the art to better understand the solution of this application, the following will clearly and completely describe the technical solution in the embodiments of this application with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.

[0024] It should be noted that the terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of this application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0025] In the related art, a single data encryption strategy is usually adopted to protect data security. If the data is leaked, the encryption strategy of the leaked data is the same, resulting in the existing data encryption method being unable to protect data privacy security. Therefore, there are problems such as a high risk of data leakage and low data security when sharing data. To solve this problem, relevant solutions are provided in the embodiments of this application, which will be described in detail below.

[0026] According to the embodiments of this application, an embodiment of a method for data processing is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described here can be executed in a different order than here.

[0027] The method embodiment provided by the embodiments of this application can be executed in a mobile terminal, a computer terminal, or a similar computing device. Figure 1 A hardware structure block diagram of a computer terminal for implementing the method for data processing is shown. As Figure 1As shown, the computer terminal 10 may include one or more processors 102 (shown as 102a, 102b, ……, 102n in the figure) (the processor 102 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply, and / or a camera. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only schematic and does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 may further include more or fewer components than Figure 1 shown in, or have a different configuration from Figure 1 that shown.

[0028] It should be noted that the above one or more processors 102 and / or other data processing circuits may generally be referred to as "data processing circuits" herein. The data processing circuit may be embodied in software, hardware, firmware, or any combination thereof, in whole or in part. In addition, the data processing circuit may be a single independent processing module, or be incorporated in whole or in part into any one of other elements in the computer terminal 10. As involved in the embodiments of the present application, the data processing circuit is a kind of processor control (such as the selection of a variable resistor terminal path connected to an interface).

[0029] The memory 104 may be used to store software programs and modules of application software, such as program instructions / data storage devices corresponding to the data processing method in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implements the above-mentioned data processing method. The memory 104 may include a high-speed random access memory, and may further include a non-volatile memory, such as one or more magnetic storage devices, a flash memory, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely located relative to the processor 102, and these remote memories may be connected to the computer terminal 10 through a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0030] The transmission device 106 is used to receive or send data via a network. Specific examples of the above-mentioned network may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a Radio Frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0031] The display can be, for example, a touch-screen liquid crystal display (LCD), which enables the user to interact with the user interface of the computer terminal 10.

[0032] The embodiment of the present application provides a data processing method that can run in the above operating environment. Figure 2 It is a step flowchart of the data processing method provided by the embodiment of the present application, as Figure 2 shown. The method includes the following steps:

[0033] Step S202, receiving a data processing requirement sent by any computing party associated with the blockchain, where the data processing requirement is used to indicate a data processing method related to the blockchain.

[0034] The method provided by the embodiments of this application combines blockchain technology with privacy computing technology, and proposes a multi-party data processing method based on blockchain technology and privacy computing, aiming to improve the security of data processing on the basis of realizing the secure sharing of multi-party data. The method provided by the embodiments of this application can be flexibly applied to the blockchain platform. In step S202, when the blockchain platform receives a data processing requirement, it triggers the execution of the data processing method provided by the embodiments of this application. Among them, the data processing requirement is sent by any device or software (i.e., the computing party) associated with the blockchain (i.e., the blockchain platform). The data processing requirement contains a data processing method related to the blockchain, indicating how to call the resources on the blockchain to process the data to be processed. In this embodiment, all devices / software participating in the data processing process are called participating computing parties, among which the one sending the data processing requirement is the initiating computing party. The data processing method provided by the embodiments of this application is applicable to various types of data processing. Then the data processing requirement can be any one of the following: data analysis requirement, federated learning requirement, data query requirement, data audit requirement, or can also contain multiple of the above different types of data processing requirements at the same time; when the data processing requirement is a data analysis requirement, the data processing method it indicates is to perform statistical analysis, pattern recognition, trend prediction, etc. on the data without directly exposing the original data (i.e., the data to be processed). When the data processing requirement is a federated learning requirement, the data processing method it indicates is to enable multiple parties to jointly utilize a specific data set (i.e., the data to be processed) to improve the performance of the model to be trained while protecting their respective data privacy through encrypted communication and distributed computing protocols; when realizing the federated learning requirement, it also allows different devices or servers to jointly train the model without sharing the original data. When the data processing requirement is a data query requirement, the data processing method it indicates is to retrieve specific data from a specific data set (i.e., the data to be processed). When the data processing requirement is a data audit requirement, the data processing method it indicates is to review and verify the processing process and results of the data to be processed.

[0035] Step S204, determine the number of participating computing parties that match the data processing requirement from the blockchain, where the participating computing parties are used to indicate the nodes in the distributed network that implement the data processing requirement.

[0036] After receiving the data processing requirement in step S202, by analyzing the data processing requirement, in step S204, according to the data processing requirement, the participating computing parties that match the data processing requirement are determined from all the computing parties associated with the blockchain platform, that is, each computing party that needs to be applied in the process of implementing the data processing requirement is matched. Among them, the participating computing party refers to each node in the distributed network that uses blockchain technology, and each of these nodes represents a resource in the distributed network. For example, hardware devices, software running on the devices, services providing computing or storage resources, etc.; the computing parties associated with the blockchain platform (i.e., the participating computing parties) are the nodes in the distributed network used to implement the data processing requirement received in step S202.

[0037] Optionally, determining the number of participating computing parties that match the data processing requirement includes: determining the type of the data processing requirement, where the type includes: single-task requirement and multi-task requirement. The single-task requirement is used to indicate a data processing requirement implemented by one participating computing party, and the multi-task requirement is used to indicate a data processing requirement implemented through the collaboration of multiple participating computing parties; when the type of the data processing requirement is a single-task requirement, the number of participating computing parties that match the data processing requirement is one; when the type of the data processing requirement is a multi-task requirement, the number of participating computing parties that match the data processing requirement is multiple.

[0038] When determining the number of participating computing parties that match the data processing requirements in step S204, the method provided in this embodiment can be adopted; in the embodiments of the present application, according to the number of participating computing parties that match the data processing requirements, the data processing requirements are classified into single-task requirements and multi-task requirements; specifically, when the number of participating computing parties that match the data processing requirements is one, the data processing requirements are classified as single-task requirements, which means that the data processing requirements are executed by the participating computing party that initiates the data requirements (i.e., the initiating computing party). For example, when the data processing requirements are data analysis requirements based on the local data of the initiating computing party, the data processing requirements are single-task requirements. When the number of participating computing parties that match the data processing requirements exceeds one, the data processing requirements are classified as multi-task requirements, which means that the data processing requirements are jointly executed by the participating computing party that initiates the data requirements (i.e., the initiating computing party) and other computing parties associated with the blockchain platform. For example, when the data processing requirements are federated learning requirements, the type of data processing requirements is multi-task processing requirements. Therefore, in this embodiment, the number of participating computing parties can be determined by identifying the type of data processing requirements: when it is identified that the data processing requirements are single-task requirements (such as data analysis requirements based on local data, data audit requirements based on local data, data query requirements based on local data), it is determined that the number of participating computing methods that match the data processing requirements is one; when it is identified that the data processing requirements are multi-task requirements (such as federated learning requirements, data analysis requirements based on multi-party data, data audit requirements based on multi-party data, data query requirements based on multi-party data), it is determined that the number of participating computing methods that match the data processing requirements is multiple.

[0039] Step S206, determine a data processing strategy according to the number of participating computing parties, wherein different data processing strategies include different data encryption strategies.

[0040] After determining the participating computing parties that match the data processing requirements received in step S202Z and determining the number of participating computing parties in step S204, in step S206, according to the number of participating computing parties, determine the data processing strategy to be executed next. Since the method provided in the embodiments of the present application aims to improve the data security in the process of data sharing, there is a correlation between the number of participating computing parties for realizing the data processing requirements and the execution of the data processing strategy. Specifically, the data encryption strategies included in different data processing strategies determined according to the number of participating computing parties are different.

[0041] Optionally, determine a data processing strategy according to the number of parties participating in the calculation, including: in the case where the number is one, execute a first type of data processing strategy, wherein the data encryption strategy in the first type of data processing strategy indicates encrypting sensitive data; in the case where the number is multiple, execute a second type of data processing strategy, wherein the data encryption strategy included in the second type of data processing strategy indicates encrypting the target data corresponding to each party participating in the calculation, and the target data is the data in the data to be processed that allows the parties participating in the calculation to process.

[0042] In the embodiments of the present application, different data processing strategies are set for single-task requirements and multi-task requirements respectively. The type of data processing requirement is determined by the number of participating computing parties that match the data processing requirement. Therefore, in this embodiment, the subsequent data processing strategy to be executed can be determined according to the number of participating computing parties that match the data processing requirement. Specifically, when the number of participating computing parties is one, it indicates that the data processing requirement is a single-task requirement. At this time, the data processing strategy corresponding to the single-task requirement (i.e., the first type of data processing strategy) is executed. Since the single-task requirement is executed by the initiating computing party and processes the local data of the initiating computing party, when executing the first type of data strategy, if you want to protect the privacy and security of the data, you only need to encrypt the sensitive data in the local data, that is, the encryption strategy included in the first type of data processing strategy instructs to encrypt the sensitive data. The above-mentioned sensitive data can be data containing sensitive information such as personal identity information and health data. When encrypting the sensitive data, advanced encryption standard (AES) encryption algorithm, public key encryption algorithm (RSA) or other encryption methods can be used to ensure that the data is not accessed by unauthorized parties during the processing. When the number of participating computing parties is multiple, it indicates that the data processing requirement is a multi-task requirement. At this time, the data processing strategy corresponding to the multi-task requirement (i.e., the second type of data processing strategy) is executed. The multi-task requirement needs to be jointly implemented by multiple participating computing parties. Therefore, when executing the multi-task requirement, in order to ensure data security, each participating computing party encrypts the data to be processed (i.e., the target data) that it has the processing authority for locally. Then, these multiple participating computing parties share their respective encrypted target data, and on this basis, multiple task requirements are realized. That is, the encryption strategy in the second type of data processing strategy instructs each participating computing party to encrypt its corresponding target data, that is, each computing party can only process the data within its own dataset. Based on this, both data sharing and data security are achieved. For example, in the federated learning scenario, the target data corresponding to each participating computing party is encrypted locally at the participating computing party to ensure that during the model training process, each participating computing party cannot directly obtain or infer the original data (i.e., the target data) of other participating computing parties. The encrypted target data is then jointly processed in a secure environment, such as through multi-party computation (MPC), homomorphic encryption and other technologies, so that multiple participating computing parties can jointly train the model without leaking the data.

[0043] Step S208, send the data processing strategy to the participating computing parties.

[0044] In step S208, the data processing strategy determined in step S206 according to the number of participating computing parties is sent to each participating computing party that matches the data processing requirements received in step S202. These data processing strategies simultaneously guide the encryption processing and other processing of data. The participating computing parties execute the obtained data processing strategies to process the data to be processed over which they have processing authority.

[0045] According to some optional embodiments of the present application, after sending the data processing strategy to the participating computing parties, the method includes: determining the data usage authority of each participating computing party, where the data usage authority is used to indicate the data to be processed that allows the participating computing party to perform processing; determining the target data corresponding to each participating computing party according to the data usage authority, where the target data is the data to be processed that allows the participating computing party to perform processing; for each target data, determining the target computing resources for executing the data processing application on the target data, and providing the target computing resources for the participating computing party corresponding to the target data, where the participating computing party invokes the target computing resources to execute the data processing method indicated by the data processing requirements on the target data.

[0046] After the data processing strategy is sent to each participating computing party in step S208, each participating computing party executes the received data processing strategy. In order to enable each participating computing party to execute the data processing strategy, a distributed network using blockchain technology will allocate trusted computing resources to each participating computing party; specifically, the distributed network using blockchain technology determines the trusted computing resources allocated to each participating computing party through the method provided in this embodiment. When allocating the corresponding trusted computing resources to each participating computing party, first determine the data processing authority of each participating computing party. The data processing authority is used to indicate the data that allows the participating computing party to perform processing. Therefore, after determining the data usage authority of the participating computing party, a part of the data (i.e., the target data) that allows the participating computing party to perform data processing operations can be determined from the data to be processed corresponding to the data processing requirements; further, the distributed network determines the computing resources (i.e., the target computing resources) distributed to the participating computing party according to the target data for which the participating computing party is to perform data processing operations and the data processing strategy issued to the participating computing party. The target computing resources are used to support the participating computing party to execute the data processing strategy on the target data. Finally, multiple participating computing parties respectively invoke the (target) computing resources allocated to them by the distributed network to jointly implement the data processing method indicated by the data processing requirements. The above-mentioned computing resources can be encryption computing units, distributed computing networks, etc., which are specifically determined according to the actual data processing strategy and target data.

[0047] According to some other alternative embodiments of the present application, in the case where the data processing requirement is a data intersection requirement indicating to determine common data among multiple target data corresponding to multiple participating computing methods, the participating computing parties call the corresponding target computing resources to execute the data processing method indicated by the data processing requirement on the target data, including: each participating computing party respectively calls the target computing resources to encrypt the multiple target data to obtain multiple encrypted target data; converts each encrypted target data into a corresponding identifier to obtain multiple identifiers, where the identifier is in the form of a numerical value; determines the data processing result corresponding to the data intersection requirement by the set composed of multiple encrypted target data corresponding to multiple identifiers with the same numerical value.

[0048] In this embodiment, the data processing requirement may also be a data intersection requirement indicating to perform an intersection operation on two or more data sets. In some embodiments, when the data processing requirement is the above data intersection requirement, the data processing requirement belongs to the type of multi-task requirements. Therefore, multiple participating computing parties need to jointly participate to implement the data intersection requirement. In this embodiment, in order to ensure the security of data during the data sharing process, when each participating computing party uses the target computing resource allocated by the distributed network to perform data processing on its corresponding target data, it first encrypts its corresponding target data. Each participating computing party shares its encrypted target data (i.e., the target encrypted data). Based on the target encrypted data shared by each participating computing party, an intersection calculation is performed to obtain an encrypted intersection result (i.e., the processing result corresponding to the data intersection requirement). The final output of executing the data intersection requirement is the encrypted intersection, that is, the output result only contains encrypted data and does not include any data other than the intersection of the multi-party target encrypted data. During the process of executing the data intersection requirement, each participating computing party executes an encryption algorithm to encrypt its corresponding target data. The encryption result of the target data is an identifier in the form of a numerical value. The principle followed by the encryption algorithm is that different data generates different ciphertexts after encryption, and the converted identifiers are different numerical values; but the same original data should generate the same numerical identifier after encryption and identifier conversion. This conversion process can be implemented using a hash function (such as SHA-256). After each participating computing party shares the encrypted target data, by comparing all the identifiers, a set of identifiers with the same numerical value is found, and the obtained set is the data processing result corresponding to the data intersection requirement. In this process, secure multi-party computing technologies such as oblivious transfer (OT) or secure comparison protocol are used to ensure that each participating computing party cannot infer the original data (i.e., the target data) of other participating computing parties from the identifiers.

[0049] According to some other optional embodiments of the present application, in the case where the data processing requirement is a data query requirement, the corresponding target computing resources are called by the participating computing parties to perform the data processing method indicated by the data processing requirement on the target data, including: parsing the data query requirement to obtain query conditions; extracting the data that meets the query conditions from the target data as the preliminary query result; encrypting the sensitive data in the preliminary query result to obtain an encryption result; and determining the encryption result and other data in the preliminary query result as the final data processing result corresponding to the data query requirement.

[0050] The data processing requirement received in step S202 may also be a data query requirement for indicating retrieving specific data from a specific data set (i.e., the data to be processed). In this embodiment, a single-task requirement in which the data query requirement is a data query requirement based on local data (i.e., the data query requirement indicates that each participating computing party queries specific data in its local data) is taken as an example to illustrate the process of implementing the single-task requirement. After the blockchain receives a data query requirement initiated by any participating computing party associated with the blockchain platform, it forwards the data query requirement to the corresponding participating computing party. Among them, the initiating computing party may also initiate a data query requirement to itself. After parsing the received data query requirement, the participating computing party obtains the specific query conditions included therein, such as query keywords, date ranges, or other relevant parameters. The participating computing party first extracts the data that meets the above query conditions from the local data (i.e., the target data) as the preliminary query result. Further, in order to ensure data security, the participating computing party checks whether the preliminary query result contains sensitive data. If it contains sensitive data, the sensitive data is encrypted and then merged with the remaining non-sensitive data in the preliminary query result as the final data processing result corresponding to the data query requirement. If the preliminary query result does not contain sensitive data, the preliminary query result is used as the final data processing result corresponding to the data query requirement.

[0051] According to some optional embodiments of the present application, the data processing method further includes: obtaining the logs generated when the participating computing parties execute the data processing policy on the data to be processed; and deleting the data related to sensitive data in the logs, where the sensitive data is data used to describe personal information.

[0052] In the method provided in the embodiment of the present application, in order to ensure data security to the greatest extent, in this embodiment, the blockchain platform also obtains the log records generated when all participating computing parties execute the data processing policy to identify and remove sensitive data and other data related to sensitive data in the logs. Among them, the sensitive data includes data used to describe personal information, and the data related to sensitive data includes: process data for encrypting or otherwise processing sensitive data.

[0053] Through the above steps, by jointly using blockchain technology and privacy computing technology, while realizing flexible multi-party data sharing, each participating party can complete data processing without obtaining (nor decrypting or inferring) the original data of any other party, thus achieving data privacy protection, improving the confidentiality and reliability of data processing, reducing the risk of data leakage, and achieving the technical effect of improving data security; at the same time, it can achieve the technical effect of meeting diverse data processing requirements and improve the flexibility of data processing.

[0054] Figure 3 It is a flowchart of the steps of another data processing method provided by an embodiment of the present application. As Figure 3 shown, the method includes the following steps:

[0055] Step S302: Receive the data processing strategy sent by the blockchain. Among them, the data encryption strategies included in different data processing strategies are different.

[0056] After the blockchain platform receives the data processing requirements, determines the number of participating computing parties according to the data processing requirements, determines the data processing strategy according to the number of participating computing parties, and sends the data processing strategy to each participating computing party, each participating computing party determined by the blockchain platform to implement the data processing requirements executes the following solution. First, in step S302, the participating computing party (node) receives the data processing strategy sent by the blockchain platform (i.e., the distributed network). The data processing method recorded in the data processing strategy must include a data encryption strategy; the blockchain platform can process various types of data to be processed and data processing requirements, and the data encryption strategies included in different data processing strategies are different to meet different security and privacy protection requirements.

[0057] Step S304, execute the data processing strategy on the target data according to the target computing resources provided by the blockchain. Among them, the target data is the data to be processed that allows the participating computing party to process. The participating computing party is used to indicate the node in the distributed network that realizes the data processing requirements. The data processing requirements are sent by any one of the participating computing parties associated with the blockchain, and the data processing requirements are used to indicate the data processing method related to the blockchain.

[0058] After determining multiple participating computing parties that match the data processing requirements, the blockchain platform obtains the data usage permissions of each participating computing party to determine, based on the data usage permissions, the part of the data to be processed (i.e., the target data) that allows the participating computing parties to perform data processing operations in all the data to be processed; the blockchain platform allocates corresponding computing resources (i.e., target computing resources) to each participating computing party according to the target data corresponding to each participating computing party and the data processing policy issued for it. In step S304, the participating computing party invokes the (target) computing resources allocated by the blockchain platform for it to execute the data processing policy on its corresponding target data. The embodiment of the present application is applied to a distributed network (i.e., the blockchain platform) that adopts blockchain technology. Each participating computing party is a node in the distributed network used to implement the received data processing requirements. Each node represents a resource in the distributed network. For example, a hardware device, software running on the device, a service providing computing or storage resources, etc.; the data processing requirements trigger the blockchain platform to execute the data processing method provided by the embodiment of the present application, which is sent by any device or software associated with the blockchain. The data processing requirements include a data processing method related to the blockchain, indicating how to invoke the resources on the blockchain to process the data to be processed.

[0059] Figure 4 It is a schematic structural diagram of a data processing device provided according to an embodiment of the present application, as Figure 4 shown, the data processing device includes: a receiving module 40, configured to receive data processing requirements sent by any one of the computing parties associated with the blockchain, where the data processing requirements are used to indicate a data processing method related to the blockchain; a first determination module 42, configured to determine the number of participating computing parties that match the data processing requirements from the blockchain, where the participating computing parties are used to indicate nodes in the distributed network that implement the data processing requirements; a second determination module 44, configured to determine a data processing policy according to the number of participating computing parties, where different data processing policies include different data encryption policies; a processing module 46, configured to send the data processing policy to the participating computing parties.

[0060] When the above data processing device implements the data processing method provided in the embodiments of the present application, the receiving module 40 receives a data processing requirement. The data processing requirement is sent by any computing party associated with a blockchain platform (i.e., a distributed network). The above computing party is a node in a distributed network (i.e., a blockchain platform) that adopts blockchain technology, and each node represents any device or software in the distributed network. The data processing requirement includes a data processing method related to the blockchain, indicating how to call resources on the blockchain to process the data to be processed. Further, the receiving module 40 transmits the received data processing requirement to the first determination module 42. The first determination module 42 matches multiple computing parties (i.e., participating computing parties) that implement the data processing method indicated by the data processing requirement in the distributed network and determines the number of the matched participating computing parties. The participating computing party refers to each node in a distributed network that adopts blockchain technology, and each of these nodes represents a resource in the distributed network, such as a hardware device, software running on the device, a service providing computing or storage resources, etc. The first determination module 42 informs the second determination module 44 of the determined number of participating computing parties. The second determination module 44 determines a specific data processing strategy according to the number of participating computing parties. Specifically, after determining the type of the data processing requirement according to the number of participating computing parties, the data processing strategy corresponding to the type of the data processing requirement is determined as the data processing strategy adopted this time. Among them, to ensure data security, the data processing strategy in the embodiments of the present application includes a data encryption strategy, but the data encryption strategies included in the data processing strategies corresponding to different types of data processing requirements are different. Finally, the processing module 46 distributes the determined data processing strategy to each participating computing party that matches the data processing requirement, and each participating computing party executes the received data processing strategy to finally complete the data processing.

[0061] It should be noted that Figure 4 For the preferred implementation manners of the illustrated embodiments, reference may be made to Figure 2 the relevant descriptions of the illustrated embodiments, which will not be elaborated herein.

[0062] The embodiments of the present application further provide a non-volatile storage medium. A computer program is stored in the non-volatile storage medium. When the device where the non-volatile storage medium is located runs the computer program, the above data processing method is executed.

[0063] The above non-volatile storage medium is used to store a program that performs the following functions: receiving a data processing requirement sent by any computing party associated with the blockchain, where the data processing requirement is used to indicate a data processing method related to the blockchain; determining, from the blockchain, the number of participating computing parties that match the data processing requirement, where the participating computing parties are used to indicate the nodes in the distributed network that implement the data processing requirement; determining a data processing strategy according to the number of participating computing parties, where different data processing strategies include different data encryption strategies; and sending the data processing strategy to the participating computing parties.

[0064] An embodiment of the present application further provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to execute the above data processing method through the computer program.

[0065] The processor in the above electronic device is used to run a program that performs the following functions: receiving a data processing requirement sent by any computing party associated with the blockchain, where the data processing requirement is used to indicate a data processing method related to the blockchain; determining, from the blockchain, the number of participating computing parties that match the data processing requirement, where the participating computing parties are used to indicate the nodes in the distributed network that implement the data processing requirement; determining a data processing strategy according to the number of participating computing parties, where different data processing strategies include different data encryption strategies; and sending the data processing strategy to the participating computing parties.

[0066] An embodiment of the present application further provides a computer program product, including computer instructions, and when the computer instructions are executed by a processor, the steps of the above data processing method are implemented.

[0067] It should be noted that each module in the above data processing device may be a program module (for example, a set of program instructions that implement a specific function), or a hardware module. For the latter, it may be presented in the following forms, but not limited to: the manifestation form of each of the above modules is a processor, or the functions of each of the above modules are implemented by a processor.

[0068] The serial numbers of the above embodiments of the present application are only for description and do not represent the advantages and disadvantages of the embodiments.

[0069] In the above embodiments of the present application, the descriptions of each embodiment have their own emphases. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0070] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of the units can be a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections between each other can be through some interfaces. The indirect couplings or communication connections of units or modules can be in electrical or other forms.

[0071] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0072] In addition, in each embodiment of the present application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.

[0073] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the related technology, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The foregoing storage medium includes: various media such as USB flash drives, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), mobile hard disks, magnetic disks or optical discs that can store program codes.

[0074] The above is only the preferred embodiment of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.

Claims

1. A method for data processing, characterized in that: include: Receiving a data processing requirement sent by any computing party associated with the blockchain, wherein the data processing requirement is used to indicate a data processing method related to the blockchain; Determining the number of participating computing parties matching the data processing requirement from the blockchain, wherein the participating computing parties are used to indicate nodes in a distributed network that implement the data processing requirement; Determining a data processing strategy according to the number of the participating computing parties, wherein different data processing strategies contain different data encryption strategies; The data processing strategy is sent to the participating computing parties.

2. The method according to claim 1, characterized in that Determining the number of participating computing parties that match the data processing requirements includes: Determine the type of the data processing requirement, wherein the type includes: a single-task requirement and a multi-task requirement, wherein the single-task requirement is used to indicate the data processing requirement implemented by one of the participating computing parties, and the multi-task requirement is used to indicate the data processing requirement implemented by multiple participating computing parties in collaboration; In the case where the type of the data processing requirement is the single-task requirement, the number of participating computing parties matching the data processing requirement is one; In the case where the type of the data processing requirement is the multi-task requirement, the number of participating computing parties matching the data processing requirement is multiple.

3. The method according to claim 1, characterized in that Determining a data processing strategy according to the number of computing parties involved includes: In the case where the number is one, executing a first type of data processing policy, wherein a data encryption policy in the first type of data processing policy indicates that sensitive data is to be encrypted; In the case where the number is multiple, a second type of data processing strategy is executed, wherein the data encryption strategy included in the second type of data processing strategy indicates that the target data corresponding to each participating computing party is encrypted, and the target data is the data in the data to be processed that the participating computing party is allowed to process.

4. The method according to claim 1, characterized in that After sending the data processing strategy to the participating computing party, the method includes: Determining the data usage rights of each of the computing participants, wherein the data usage rights are used to indicate the data to be processed that the computing participants are allowed to process; Determine the target data corresponding to each of the computing participants according to the data use authority, wherein the target data is the data to be processed that the computing participants are allowed to process; For each of the target data, determine the target computing resource for executing the data processing application on the target data, and provide the target computing resource to the participating computing party corresponding to the target data, wherein the participating computing party calls the target computing resource to execute the data processing method indicated by the data processing requirement on the target data.

5. The method according to claim 4, characterized in that In the case where the data processing requirement is a data intersection requirement indicating that common data is determined among a plurality of target data corresponding to a plurality of the participating computing methods, the participating computing party calls a corresponding target computing resource to execute the data processing method indicated by the data processing requirement on the target data, including: Each of the computing participants respectively calls the target computing resource to encrypt the plurality of target data to obtain a plurality of encrypted target data; Convert each of the encrypted target data into a corresponding identifier to obtain a plurality of the identifiers, wherein the identifiers are in the form of numerical values; A data processing result corresponding to the data intersection requirement is determined by a set consisting of a plurality of the encrypted target data corresponding to a plurality of the identifiers with the same numerical value.

6. The method according to claim 4, characterized in that In the case where the data processing requirement is a data query requirement, the data processing method indicated by the data processing requirement is executed on the target data by the participating computing party calling the corresponding target computing resource, including: Analyze the data query requirements to obtain query conditions; Extracting data that meets the query condition from the target data as preliminary query results; Encrypting the sensitive data in the preliminary query result to obtain an encrypted result; The encryption result and other data in the preliminary query result are determined as final data processing results corresponding to the data query requirement.

7. The method according to claim 1, characterized in that The method also includes: obtaining a log generated when the participating computing party executes the data processing strategy on the data to be processed; and deleting data related to sensitive data in the log, wherein the sensitive data is data used to describe personal information.

8. A method of data processing, characterized in that: include: Receiving a data processing strategy sent by a blockchain, wherein different data processing strategies contain different data encryption strategies; The data processing strategy is executed on the target data according to the target computing resources provided by the blockchain, wherein the target data is the data to be processed that the participating computing parties are allowed to process, and the participating computing parties are used to indicate the nodes in the distributed network that implement the data processing requirements, and the data processing requirements are sent by any one of the participating computing parties associated with the blockchain, and the data processing requirements are used to indicate the data processing method related to the blockchain.

9. A data processing device, characterized in that: include: A receiving module, used to receive a data processing requirement sent by any computing party associated with the blockchain, wherein the data processing requirement is used to indicate a data processing method related to the blockchain; A first determination module is used to determine the number of participating computing parties that match the data processing requirement from the blockchain, wherein the participating computing parties are used to indicate nodes in a distributed network that implement the data processing requirement; A second determination module is used to determine a data processing strategy according to the number of the participating computing parties, wherein different data processing strategies contain different data encryption strategies; A processing module is used to send the data processing strategy to the participating computing party.

10. A non-volatile storage medium, characterized in that: The non-volatile storage medium stores a computer program, wherein the data processing method according to any one of claims 1 to 7 is executed by running the computer program on the device where the non-volatile storage medium is located.

11. An electronic device comprising a memory and a processor, characterized in that: The memory stores a computer program, and the processor is configured to execute the data processing method according to any one of claims 1 to 7 through the computer program.

12. A computer program product comprising computer instructions, characterized in that: When the computer instructions are executed by a processor, the steps of the data processing method described in any one of claims 1 to 7 are implemented.