Intelligent calculation center network data management method and system
Through language description and threshold secret sharing technology, the network data of the intelligent computing center is divided into multiple shadow fragments, which solves the single point failure and data leakage problems of traditional intelligent computing centers, achieves higher security and flexibility, and improves the stability and reliability of data management.
Patent Information
- Application Number
- CN202510722048.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-30
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2045-05-30
AI Technical Summary
Traditional intelligent computing center network data management has single point failure risks and data leakage hazards, and lacks flexible, sophisticated and secure management mechanisms, especially in the process of sharing and storing sensitive information.
Using language description and threshold secret sharing technology, sensitive data is divided into multiple shadow fragments through a formal description structure and distributed to protocol participants in a multi-level structure. The original data can only be reconstructed when the minimum number of shadow fragments is reached.
It improves the security and flexibility of data management, reduces the risk of data leakage, enhances fault tolerance, reduces the risk of single point failure, and improves the stability and continuity of data services.
Smart Images

Figure CN120639280A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network data management, and in particular to a network data management method and system for an intelligent computing center. Background Art
[0002] With the rapid development of technologies such as artificial intelligence, big data, and cloud computing, intelligent computing centers have become crucial infrastructure for digital transformation across various industries. By aggregating and managing massive amounts of network data, intelligent computing centers support large-scale computing tasks and intelligent applications. However, with the rapid expansion of network data, the complexity and security of data management are becoming increasingly prominent.
[0003] Traditional intelligent computing center network data management often utilizes a centralized data storage and management model, which presents security risks such as single points of failure and vulnerability to cyberattacks. Furthermore, when it comes to network data containing sensitive or confidential information, traditional data management solutions typically rely solely on basic encryption methods, lacking more flexible, sophisticated, and secure management mechanisms. This exposes data to the risk of leakage during sharing and storage.
[0004] To solve the above problems, there is an urgent need to propose a more secure and flexible data management method to enable the intelligent computing center to have higher security, flexibility and fault tolerance in the management and sharing of network data. Summary of the Invention
[0005] In view of the above technical problems, the present invention provides a network data management method and system for an intelligent computing center. By combining language description and threshold secret sharing technology, it realizes refined management and security protection of network data, thereby effectively addressing security risks and management bottlenecks in the network data management of the intelligent computing center.
[0006] Other features and advantages of the present disclosure will become apparent from the following detailed description, or may be learned in part by practice of the present disclosure.
[0007] According to one aspect of the present invention, a method for managing network data in an intelligent computing center is proposed, the method comprising:
[0008] Obtaining an original data set containing original information as input, wherein the original data set contains secret data to be concealed;
[0009] evaluating the original data set, determining secret data that needs to be concealed from the original data set, and obtaining a secret data set;
[0010] Performing a language description on the secret data set, extracting key features of the secret data, and generating a corresponding formal description structure;
[0011] Based on the formal description structure and key characteristics of the secret data, select parameters of the threshold secret sharing scheme, determine the total number of protocol participants n and the minimum number of shadow fragments m required for secret data reconstruction, and select a distribution method for the secret data: equal distribution or privileged distribution;
[0012] Executing the threshold secret sharing scheme, dividing the secret data set into n shadow segments according to the formal description structure, and distributing the n shadow segments to n protocol participants respectively;
[0013] When the secret data needs to be recovered, no less than m shadow fragments are collected, and at least m shadow fragments are combined according to the formal description to reconstruct the original secret data.
[0014] Furthermore, when evaluating the original data set, the following steps are also included:
[0015] Extracting secret data that needs to be concealed from the original information data set; and removing irrelevant data or inserting the irrelevant data as noise data to interfere with the true meaning of the secret data.
[0016] Furthermore, when the secret data set contains multiple secret data, if the multiple secret data have similar meanings, a unified language description is used for them; if the meanings of the multiple secret data are different, each of the secret data is described independently in an independent language; the language description is implemented using a formal grammar, and the formal grammar is selected from one of a sequential grammar, a tree grammar or a graphical grammar.
[0017] Furthermore, under the equal distribution method, each of the protocol participants obtains an equal secret shadow fragment; under the privileged distribution method, at least one protocol participant is designated as a privileged participant and is assigned a privileged shadow fragment, so that the privileged participant is indispensable in the reconstruction process of the secret data.
[0018] Furthermore, the threshold secret sharing scheme is executed in a hierarchical multi-level structure environment, and the protocol participants are distributed at multiple levels including the organizational layer, fog computing layer and cloud layer. The protocol participants at each level respectively obtain the secret shadow fragments of the corresponding level, thereby realizing the distribution and management of the secret data in the multi-level structure.
[0019] Furthermore, when the formal description structure is a tree structure, the secret data set is divided into multiple hierarchical sub-secret nodes, each sub-secret node corresponds to a part of the secret data set, the connection relationship between the sub-secret nodes represents the combination order of each part of the secret data, and the sub-secrets of different levels are assigned to the protocol participants of the corresponding levels; when the formal description structure is a graph structure, the secret data set is divided into several secret parts and mapped to nodes of the graph structure, each node corresponds to a part of the secret data set, and the nodes are connected by undirected edges to represent the association relationship between the secret parts, and the secret part corresponding to each node is assigned as a shadow fragment to different protocol participants.
[0020] Furthermore, when the secret data is image data, a graphic threshold secret sharing scheme based on language description is executed, including:
[0021] generating a formalized graph structure based on key features of the image data, dividing the image data into a plurality of shadow segments, each shadow segment corresponding to a node in the graph structure;
[0022] The minimum number of shadow fragment combinations required to reconstruct the image data is determined through the association relationship between nodes in the graph structure, and the shadow fragments are distributed to different protocol participants, so that the original image data can be restored only when no less than the minimum number of shadow fragment combinations are collected.
[0023] According to a second aspect of the present disclosure, there is provided an intelligent computing center network data management system, the system comprising:
[0024] an acquisition module, configured to acquire as input an original data set containing original information, wherein the original data set contains secret data to be concealed;
[0025] An evaluation module, configured to evaluate the original data set, determine secret data that needs to be concealed from the original data set, and obtain a secret data set;
[0026] A language description module is used to describe the secret data set in language, extract key features of the secret data, and generate a corresponding formal description structure;
[0027] a scheme selection module for selecting parameters of a threshold secret sharing scheme based on the formal description structure and key features of the secret data, determining the total number of protocol participants n and the minimum number of shadow fragments m required for secret data reconstruction, and selecting a distribution method for the secret data: equal distribution or privileged distribution;
[0028] a sharing execution module, configured to execute the threshold secret sharing scheme, divide the secret data set into n shadow segments according to the formal description structure, and distribute the n shadow segments to n protocol participants respectively;
[0029] A data recovery module is used to collect no less than m shadow fragments when the secret data needs to be recovered, and combine at least m shadow fragments according to the formal description to reconstruct the original secret data.
[0030] The technical solution disclosed in this disclosure has the following beneficial effects:
[0031] The security of network data management is improved. Through threshold secret sharing technology, sensitive information is divided into multiple shadow fragments. Data can be reconstructed only when a predetermined number of shadow fragments is reached, which greatly reduces the risk of data leakage. The flexibility and refinement of data management are enhanced. The use of language description methods can clearly define and distinguish the key features of different data, making data sharing and management more accurate. The fault tolerance of the system is improved. Even if some shadow fragments are lost or damaged, data reconstruction can still be completed through other shadow fragments, which significantly improves the reliability of data recovery. The risk of single point failure brought by centralized storage of data is reduced. Through distributed shadow management strategies, the stability and continuity of data services in the intelligent computing center are significantly improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 This is a flow chart of a method for managing network data in an intelligent computing center according to an embodiment of this specification;
[0033] Figure 2 This is a structural block diagram of an intelligent computing center network data management system in an embodiment of this specification;
[0034] Figure 3 It is a terminal device for implementing the network data management method of the intelligent computing center in the embodiment of this specification;
[0035] Figure 4 It is a computer-readable storage medium storing a method for managing network data of an intelligent computing center in an embodiment of this specification. DETAILED DESCRIPTION
[0036] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in a variety of forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that the present disclosure will be more comprehensive and complete and will fully convey the concepts of the example embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments. In the following description, many specific details are provided to provide a full understanding of the embodiments of the present disclosure. However, those skilled in the art will appreciate that the technical solutions of the present disclosure may be practiced while omitting one or more of the specific details, or that other methods, components, devices, steps, etc. may be employed. In other cases, well-known technical solutions are not shown or described in detail to avoid obscuring various aspects of the present disclosure.
[0037] The accompanying drawings are merely schematic illustrations of the present disclosure. Identical reference numerals in the drawings denote identical or similar components, and thus their repeated description will be omitted. Some of the blocks shown in the accompanying drawings represent functional entities that do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.
[0038] The present invention provides a product intelligent computing center network data management method. Figure 1 The figure shows a flow chart of a method for managing network data in an intelligent computing center according to an embodiment of the present invention. The method can be applied to electronic devices such as personal computers and servers. The method can be performed by a device, which can be implemented by software and / or hardware. The method can specifically include the following steps S101 to S106:
[0039] In step S101 , an original data set containing original information is obtained as input, wherein the original data set contains secret data to be concealed.
[0040] This step is used to collect data sets to be processed from external data sources. These data include important sensitive information, such as personal privacy data, corporate confidential data, or strategic information.
[0041] In step S102, the original data set is evaluated, and secret data that needs to be concealed is determined from the original data set to obtain a secret data set.
[0042] When evaluating the original data set, the process also includes extracting secret data that needs to be concealed from the original information data set; and removing irrelevant data or inserting the irrelevant data as noise data to interfere with the true meaning of the secret data.
[0043] Specifically, in step S102, a comprehensive assessment is performed on the acquired raw data set. The main purpose is to identify confidential data that is of great value to protect from the vast amount of data, thereby forming a confidential data set and laying the foundation for subsequent security processing. Secret data extraction can be achieved by automatically or semi-automatically filtering out sensitive information from the raw data set through preset rules, keyword matching, pattern recognition, machine learning algorithms, or manual labeling. This sensitive information includes user personal privacy, business secrets, strategic plans, financial data, and other content that requires strict protection. The extracted confidential data will be summarized as a confidential data set. To improve data management efficiency and protection effectiveness, data that is not related to confidential data or has a lower security risk is eliminated to reduce the burden of subsequent processing.
[0044] In step S103, the secret data set is described in language, key features of the secret data are extracted, and a corresponding formal description structure is generated.
[0045] Among them, when the secret data set contains multiple secret data, if the multiple secret data have similar meanings, a unified language description is used for them; if the meanings of the multiple secret data are different, each of the secret data is described in an independent language; the language description is implemented using a formal grammar, and the formal grammar is selected from one of a sequential grammar, a tree grammar or a graphical grammar.
[0046] Step S103 describes the identified secret data set in a linguistic manner, aiming to accurately capture the core features and structural information of the secret data through formal language tools, thereby providing a logical basis for subsequent data segmentation and secure sharing. This linguistic description abstracts complex secret data into an easily manageable formal structure, clarifies the relationships, hierarchies, and importance of each secret data point, and facilitates the more precise design of secret sharing schemes. Representative features are extracted from the secret data set, such as the data's semantic content, data categories, and inter-data correlations and dependencies. These key features form the foundational information for the linguistic description. When multiple secret data points within a secret data set share similar meanings or functions, they are grouped into the same linguistic description model to reduce redundancy, improve processing efficiency, and enhance description consistency. When the meanings of secret data differ significantly, independent linguistic descriptions are established for each secret data point to ensure accurate descriptions and fine-grained control, facilitating targeted protection and management.
[0047] Combining the extracted key features with the selected formal grammar, the method automatically generates formal description structures for secret data. These structures not only reflect the semantics and relationships of the data, but also provide specific rules and process basis for the subsequent segmentation, distribution, and recovery of secret data.
[0048] In step S104, based on the formal description structure and the key characteristics of the secret data, the parameters of the threshold secret sharing scheme are selected, the total number of protocol participants n and the minimum number of shadow fragments m required for secret data reconstruction are determined, and the distribution method of the secret data is selected as equal distribution or privileged distribution.
[0049] Among them, under the equal distribution method, each of the protocol participants obtains an equal secret shadow fragment; under the privileged distribution method, at least one protocol participant is designated as a privileged participant and is allocated a privileged shadow fragment, so that the privileged participant is indispensable in the reconstruction process of the secret data.
[0050] When the formal description structure is a tree structure, the secret data set is divided into multiple hierarchical sub-secret nodes, each sub-secret node corresponds to a part of the secret data set, the connection relationship between the sub-secret nodes represents the combination order of each part of the secret data, and the sub-secrets of different levels are assigned to the protocol participants of the corresponding levels; when the formal description structure is a graph structure, the secret data set is divided into several secret parts and mapped to nodes of the graph structure, each node corresponds to a part of the secret data set, and the nodes are connected by undirected edges to represent the association relationship between the secret parts, and the secret part corresponding to each node is assigned as a shadow fragment to different protocol participants.
[0051] For clarification, in determining the threshold parameters, the total number of protocol participants, n, is determined based on the number of nodes in the system that actually participate in secret sharing and reconstruction, including all trusted management entities or devices. The minimum number of shadow fragments, m, is the minimum number of shadow fragments required to successfully reconstruct the secret data, satisfying m ≤ n. The size of m affects data security and fault tolerance: a larger m indicates higher security, but also increases the recovery threshold. Equal distribution means that all protocol participants receive equal secret shadow fragments, with no special privilege differences. This is suitable for participants with equal rights and the same responsibilities. Privileged distribution means that in actual applications, some participants, due to the importance of their responsibilities or special privileges, need to have additional secret shadow fragments to ensure that they are irreplaceable during the reconstruction of secret data, thereby achieving hierarchical management, privilege control, and security policy customization.
[0052] When applying a tree structure, the secret data set is divided into multi-level sub-secret nodes. Each node corresponds to a part of the secret data, and the connection between nodes reflects the combination and inheritance order of the secret data. Sub-secret nodes at different levels are assigned to protocol participants at the corresponding level to achieve hierarchical management and enhance the refinement of security policies. This hierarchical division facilitates the management of complex secret data and its access rights, and is suitable for scenarios with a rigorous organizational structure.
[0053] In the application of graph structure, secret data is divided into multiple secret parts and mapped to the nodes of the graph. The nodes are connected by undirected edges, which represent the association and dependency between the secret parts. The shadow fragments are allocated to different protocol participants based on the graph structure, supporting multi-path and multi-role data recovery methods.
[0054] In step S105, the threshold secret sharing scheme is executed to divide the secret data set into n shadow segments according to the formal description structure, and the n shadow segments are respectively distributed to n protocol participants.
[0055] In which, the threshold secret sharing scheme is executed in a hierarchical multi-level structure environment, and the protocol participants are distributed on multiple levels including the organizational layer, fog computing layer and cloud layer. The protocol participants at each level respectively obtain the secret shadow fragments of the corresponding level, thereby realizing the distribution and management of the secret data in the multi-level structure.
[0056] Exemplarily, when the secret data is image data, a graphical threshold secret sharing scheme based on language description is executed, including: generating a formalized graph structure according to the key features of the image data, dividing the image data into a number of shadow fragments, each shadow fragment corresponding to a node in the graph structure; determining the minimum number of shadow fragment combinations required to reconstruct the image data through the association relationship between the nodes in the graph structure, and distributing the shadow fragments to different protocol participants, so that the original image data can be restored only when no less than the minimum number of shadow fragment combinations are collected.
[0057] In step S106, when the secret data needs to be recovered, no less than m shadow fragments are collected, and at least m shadow fragments are combined according to the formal description to reconstruct the original secret data.
[0058] For example, assuming the secret data is divided into nine shadow fragments and the minimum reconstruction threshold m is set to 3, during the data recovery phase, at least three different shadow fragments must be collected (e.g., shadow fragments numbered 2, 5, and 9). Based on the previously described structure, these three shadow fragments are mathematically operated and logically combined, and a threshold secret sharing algorithm (such as the Shamir algorithm) is used to recover the complete secret data. For example, for image data, the image portions corresponding to the three shadow fragments are fused to reconstruct the original complete image. Only when the number of collected shadow fragments reaches or exceeds m can the recovered data be guaranteed to be correct, ensuring secure and reliable data reconstruction.
[0059] Based on the same idea, Figure 2FIG. 1 is a block diagram of a network data management system for an intelligent computing center according to an embodiment of the present invention. The system includes: an acquisition module 201 for acquiring, as input, an original data set containing original information, wherein the original data set contains secret data to be concealed; an evaluation module 202 for evaluating the original data set, determining the secret data to be concealed from the original data set, and obtaining a secret data set; a language description module 203 for performing a language description on the secret data set, extracting key features of the secret data, and generating a corresponding formal description structure; a scheme selection module 204 for selecting parameters of a threshold secret sharing scheme based on the formal description structure and the key features of the secret data, determining the total number of protocol participants n and the minimum number of shadow fragments m required for secret data reconstruction, and selecting a distribution method for the secret data, such as equal distribution or privileged distribution; a sharing execution module 205 for executing the threshold secret sharing scheme, dividing the secret data set into n shadow fragments according to the formal description structure, and distributing the n shadow fragments to the n protocol participants; and a data recovery module 206 for collecting at least m shadow fragments when the secret data needs to be recovered, and combining at least m shadow fragments according to the formal description to reconstruct the original secret data.
[0060] The specific details of the above system have been described in detail in the implementation method part. For undisclosed details, please refer to the implementation method part, and thus will not be repeated here.
[0061] This system improves the security of network data management. Through threshold secret sharing technology, sensitive information is divided into multiple shadow fragments. Data can only be reconstructed when a predetermined number of shadow fragments is reached, greatly reducing the risk of data leakage; it enhances the flexibility and refinement of data management. The use of language description methods can clearly define and distinguish the key features of different data, making data sharing and management more accurate; it improves the fault tolerance of the system. Even if some shadow fragments are lost or damaged, data reconstruction can still be completed through other shadow fragments, significantly improving the reliability of data recovery; it reduces the risk of single point failure brought by centralized storage of data, and significantly improves the stability and continuity of data services in the intelligent computing center through distributed shadow management strategies.
[0062] Based on the same idea, the embodiment of this specification also provides a network data management device for an intelligent computing center, such as Figure 4 shown.
[0063] The network data management device of the intelligent computing center can be the terminal device or server provided in the above embodiment.
[0064] The intelligent computing center network data management device can vary significantly due to different configurations or performance. It can include one or more processors 301, memory 302, and a bus. The memory 302 can store one or more storage applications or data. The memory 302 can include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) and / or a cache storage unit, such as a plug-in mobile hard drive, a smart memory card (SmartMediaCard, SMC), a secure digital (SD) card, a flash memory card (FlashCard), etc. equipped on an electronic device, and can further include a read-only storage unit. The application stored in the memory 302 can include one or more program modules (not shown in the figure). Such program modules include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each of these examples or some combination may include the implementation of a network environment. Furthermore, the processor 301 can be configured to communicate with the memory 302 to execute a series of computer-executable instructions in the memory 302 on the intelligent computing center network data management device. The intelligent computing center network data management device may also include one or more power supplies 303, one or more wired or wireless network interfaces 304, one or more I / O interfaces (input and output interfaces) 305, and one or more external devices 306 (e.g., a keyboard). It may also communicate with one or more devices that enable a user to interact with the device, and / or with any device that enables the device to communicate with one or more other computing devices (e.g., a router, a network switch, etc.). Such communication may be performed through the I / O interface 305. In addition, the device may also communicate with one or more networks (e.g., a local area network (LAN)) through the wired or wireless interface 304.
[0065] In some embodiments, the processor 301 may be composed of an integrated circuit, for example, a single packaged integrated circuit, or a plurality of packaged integrated circuits with the same or different functions, including one or more central processing units (CPUs), microprocessors, digital processing chips, graphics processors, and a combination of various control chips. The processor 301 is the control core (Control Unit) of the electronic device, connecting the various components of the entire electronic device using various interfaces and lines, and executing or executing programs or modules stored in the memory 11 (such as the product intelligent computing center network data management program, etc.), as well as calling data stored in the memory, to perform various functions of the processing device and process data.
[0066] The bus may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc. The bus is configured to enable connection and communication between the memory 302 and at least one processor 301, etc.
[0067] The power supply can be logically connected to the at least one processor 301 via a power management device, thereby implementing functions such as charging management, discharging management, and power consumption management through the power management device. The power supply can also include one or more DC or AC power supplies, a recharging device, a power failure detection circuit, a power converter or inverter, a power status indicator, and other arbitrary components. The electronic device 1 can also include various sensors, Bluetooth modules, Wi-Fi modules, etc., which are not further described here.
[0068] Optionally, the processing device may further include a user interface, which may be a display. Optionally, the user interface may also be a standard wired interface or a wireless interface. Optionally, in some embodiments, the display may be an LED display, a liquid crystal display, a touch-sensitive liquid crystal display, or an OLED display.
[0069] (Organic Light-Emitting Diode, organic light-emitting diode) touch screen, etc. Among them, the display can also be appropriately called a display screen or a display unit, which is used to display information processed in the electronic device 1 and to display a visual user interface.
[0070] Figure 3 Only the network data management device of the intelligent computing center with components is shown. It can be understood by those skilled in the art that Figure 3 The structure shown does not constitute a limitation on the network data management device of the intelligent computing center, and may include fewer or more components than shown in the figure, or a combination of certain components, or a different arrangement of components.
[0071] Specifically in this embodiment, the intelligent computing center network data management device includes a memory and one or more programs, wherein the one or more programs are stored in the memory, and the one or more programs may include one or more modules, and each module may include a series of computer-executable instructions in the intelligent computing center network data management device, and the one or more programs are configured to be executed by one or more processors, including computer-executable instructions for performing the following:
[0072] Obtaining an original data set containing original information as input, wherein the original data set contains secret data to be concealed;
[0073] evaluating the original data set, determining secret data that needs to be concealed from the original data set, and obtaining a secret data set;
[0074] Performing a language description on the secret data set, extracting key features of the secret data, and generating a corresponding formal description structure;
[0075] Based on the formal description structure and key characteristics of the secret data, select parameters of the threshold secret sharing scheme, determine the total number of protocol participants n and the minimum number of shadow fragments m required for secret data reconstruction, and select a distribution method for the secret data: equal distribution or privileged distribution;
[0076] Executing the threshold secret sharing scheme, dividing the secret data set into n shadow segments according to the formal description structure, and distributing the n shadow segments to n protocol participants respectively;
[0077] When the secret data needs to be recovered, no less than m shadow fragments are collected, and at least m shadow fragments are combined according to the formal description to reconstruct the original secret data.
[0078] Based on the same idea, the exemplary embodiments of the present invention further provide a computer-readable storage medium storing a program product capable of implementing the methods described above. In some possible implementations, various aspects of the present disclosure may also be implemented in the form of a program product comprising program code. When the program product is executed on a terminal device, the program code is configured to cause the terminal device to execute the steps described in the "Exemplary Methods" section above according to various exemplary embodiments of the present disclosure.
[0079] refer to Figure 4 As shown, a program 400 for implementing the above method according to an exemplary embodiment of the present disclosure is described. The program 400 may be a portable compact disc read-only memory (CD-ROM) and include program code, and may be run on a terminal device, such as a personal computer. However, the program product of the present disclosure is not limited thereto. In this document, a readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0080] The program product may employ any combination of one or more readable media. The readable medium may be a readable signal medium or a readable storage medium. The readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or component, or any combination thereof. More specific examples (a non-exhaustive list) of readable storage media include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof.
[0081] A computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries readable program code. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium that can transmit, propagate, or transfer a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0082] Program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, CSS, HTML, and the like, as well as conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, as a standalone software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device may be connected to the user computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0083] Through the description of the above embodiments, it is easy for those skilled in the art to understand that the example embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solution according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the exemplary embodiment of the present disclosure.
[0084] Furthermore, the figures above are merely illustrative of the processes included in the methods according to exemplary embodiments of the present disclosure and are not intended to be limiting. It is readily understood that the processes illustrated in the figures above do not indicate or limit the temporal order of these processes. Furthermore, it is readily understood that these processes may be executed synchronously or asynchronously, for example, in multiple modules.
[0085] It should be noted that although several modules or units of the device for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the exemplary embodiments of the present disclosure, the features and functions of two or more modules or units described above can be concretized in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided into multiple modules or units to be concretized.
[0086] Other embodiments of the present disclosure will readily occur to those skilled in the art after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and embodiments are to be considered as exemplary only, with the true scope and spirit of the present disclosure being indicated by the claims.
[0087] It should be understood that the present disclosure is not limited to the exact structures that have been described above and shown in the drawings, and that various modifications and changes can be made without departing from the scope thereof. The scope of the present disclosure is limited only by the appended claims.
Claims
1. A method for managing network data in an intelligent computing center, characterized in that: The method comprises: Obtaining an original data set containing original information as input, wherein the original data set contains secret data to be concealed; evaluating the original data set, determining secret data that needs to be concealed from the original data set, and obtaining a secret data set; Performing a language description on the secret data set, extracting key features of the secret data, and generating a corresponding formal description structure; Based on the formal description structure and key characteristics of the secret data, select parameters of the threshold secret sharing scheme, determine the total number of protocol participants n and the minimum number of shadow fragments m required for secret data reconstruction, and select a distribution method for the secret data: equal distribution or privileged distribution; Executing the threshold secret sharing scheme, dividing the secret data set into n shadow segments according to the formal description structure, and distributing the n shadow segments to n protocol participants respectively; When the secret data needs to be recovered, no less than m shadow fragments are collected, and at least m shadow fragments are combined according to the formal description to reconstruct the original secret data.
2. The intelligent computing center network data management method according to claim 1, characterized in that: When evaluating the original dataset, the following are also included: Extracting secret data that needs to be concealed from the original information data set; and removing irrelevant data or inserting the irrelevant data as noise data to interfere with the true meaning of the secret data.
3. The intelligent computing center network data management method according to claim 1, characterized in that: When the secret data set contains multiple secret data, if the multiple secret data have similar meanings, a unified language description is used for them; if the meanings of the multiple secret data are different, each of the secret data is described independently in a separate language; the language description is implemented using a formal grammar, and the formal grammar is selected from one of a sequential grammar, a tree grammar, or a graphical grammar.
4. The intelligent computing center network data management method according to claim 1, characterized in that: Under the equal distribution method, each of the protocol participants obtains an equal secret shadow fragment; under the privileged distribution method, at least one protocol participant is designated as a privileged participant and is allocated a privileged shadow fragment, so that the privileged participant is indispensable in the reconstruction process of the secret data.
5. The intelligent computing center network data management method according to claim 1, characterized in that: The threshold secret sharing scheme is executed in a hierarchical multi-level structure environment. The protocol participants are distributed at multiple levels including the organizational layer, fog computing layer and cloud layer. The protocol participants at each level respectively obtain the secret shadow fragments of the corresponding level, thereby realizing the distribution and management of the secret data in the multi-level structure.
6. The method for managing network data of an intelligent computing center according to claim 1, characterized in that: When the formal description structure is a tree structure, the secret data set is divided into multiple hierarchical sub-secret nodes, each sub-secret node corresponds to a part of the secret data set, the connection relationship between the sub-secret nodes represents the combination order of each part of the secret data, and the sub-secrets of different levels are assigned to the protocol participants of the corresponding levels; when the formal description structure is a graph structure, the secret data set is divided into several secret parts and mapped to nodes of the graph structure, each node corresponds to a part of the secret data set, and the nodes are connected by undirected edges to represent the association relationship between the secret parts, and the secret part corresponding to each node is assigned as a shadow fragment to different protocol participants.
7. The method for managing network data of an intelligent computing center according to claim 1, characterized in that: When the secret data is image data, a language-based graphical threshold secret sharing scheme is implemented, including: generating a formalized graph structure based on key features of the image data, dividing the image data into a plurality of shadow segments, each shadow segment corresponding to a node in the graph structure; The minimum number of shadow fragment combinations required to reconstruct the image data is determined through the association relationship between nodes in the graph structure, and the shadow fragments are distributed to different protocol participants, so that the original image data can be restored only when no less than the minimum number of shadow fragment combinations are collected.
8. An intelligent computing center network data management system, the system comprising: an acquisition module, configured to acquire as input an original data set containing original information, wherein the original data set contains secret data to be concealed; An evaluation module, configured to evaluate the original data set, determine secret data that needs to be concealed from the original data set, and obtain a secret data set; A language description module is used to describe the secret data set in language, extract key features of the secret data, and generate a corresponding formal description structure; a scheme selection module for selecting parameters of a threshold secret sharing scheme based on the formal description structure and key features of the secret data, determining the total number of protocol participants n and the minimum number of shadow fragments m required for secret data reconstruction, and selecting a distribution method for the secret data: equal distribution or privileged distribution; a sharing execution module, configured to execute the threshold secret sharing scheme, divide the secret data set into n shadow segments according to the formal description structure, and distribute the n shadow segments to n protocol participants respectively; A data recovery module is used to collect no less than m shadow fragments when the secret data needs to be recovered, and combine at least m shadow fragments according to the formal description to reconstruct the original secret data.
Citation Information
Patent Citations
System or method for implementing forgotten rights on metadata-driven blockchains using secret sharing and consensus of reads
CN114365133A
Data distributed storage method and system based on secret sharing technology
CN119172077A
Non-interactive multiplication privacy protection method based on summer secret sharing
CN119583044A
Secure multiparty computation on spreadsheets
US20180276417A1