Private computing platform deployment method and device, equipment, storage medium and program product
By signing and encrypting the component applications and basic service images of the privacy computing platform, and verifying the decompression using an authorization code, security issues in the container deployment process are resolved, achieving higher data security and privacy protection.
Patent Information
- Application Number
- CN202511029939.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-24
- Publication Date
- 2025-11-07
AI Technical Summary
In existing technologies, containers pose security risks during the deployment of privacy computing platforms, leading to reduced security of privacy computing data.
By signing and encrypting the component applications and basic service images of the privacy computing platform, an encrypted image file is generated, and an authorization code is used to verify the decompression of the component installation files, thereby improving the security of the deployment platform.
This enhances the deployment security of the privacy computing platform, ensuring data privacy and security.
Smart Images

Figure CN120910904A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of privacy computing, and particularly relates to a privacy computing platform deployment method and device, equipment, a storage medium and a program product. BACKGROUND
[0002] Privacy computing technology is a technology for realizing data analysis and sharing under the premise of ensuring data privacy and data security. With the increasing demand for data fusion, the requirement for data protection is gradually increasing. By deploying a privacy computing platform in multiple participants, the multiple participants jointly execute a privacy computing task by using the deployed privacy computing platform, thereby improving the security of data.
[0003] In the prior art, in order to adapt to the environment differences of different participants, a container technology is used to deploy a privacy computing platform.
[0004] However, in the prior art, there are security problems in the process of deploying the privacy computing platform by using the container, which reduces the security of privacy computing data. SUMMARY
[0005] The present application provides a privacy computing platform deployment method, device, equipment, storage medium and program product, to solve the problem of reduced security of privacy computing data in the prior art.
[0006] In a first aspect, the present application provides a privacy computing platform deployment method, comprising:
[0007] obtaining a component application and a component application base image of a privacy computing platform;
[0008] obtaining a base service image for running the component application;
[0009] signing and encrypting the component application base image and the base service image to generate an encrypted image file;
[0010] creating a component installation file according to the encrypted image file and the component application;
[0011] sending the component installation file to a platform to be deployed, so that the platform to be deployed decompresses the component installation file according to a pre-generated authorization code and runs the encrypted image file in the component installation file, to complete the deployment of the privacy computing platform.
[0012] In a second aspect, the present application provides a privacy computing platform deployment device, comprising:
[0013] a first obtaining module configured to obtain a component application and a component application base image of a privacy computing platform;
[0014] The second obtaining module is configured to obtain a basic service image running the component application;
[0015] The encryption module is configured to sign and encrypt the component application basic image and the basic service image to generate an encrypted image file;
[0016] The first creating module is configured to create a component installation file according to the encrypted image file and the component application;
[0017] The first sending module is configured to send the component installation file to a to-be-deployed platform, so that the to-be-deployed platform decompresses the component installation file according to a pre-generated authorization code and runs the encrypted image file in the component installation file, to complete deployment of the privacy computing platform.
[0018] In a third aspect, an embodiment of the present application provides an electronic device, including a memory and a processor.
[0019] The memory stores computer execution instructions.
[0020] The processor executes the computer execution instructions stored in the memory, so that the processor executes the first aspect and / or various possible implementation manners of the first aspect.
[0021] In a fourth aspect, an embodiment of the present application provides a computer readable storage medium, the computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by a processor to implement the first aspect and / or various possible implementation manners of the first aspect.
[0022] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, and the computer program is executed by a processor to implement the first aspect and / or various possible implementation manners of the first aspect.
[0023] The privacy computing platform deployment method, device, equipment, storage medium and program product provided by the present application can sign and encrypt the basic image and the basic service image of the component application of the privacy computing platform, and when the encrypted image file and the component installation file created by the component application are decompressed in the to-be-deployed platform, the authorization code is used for verification and decompression, thereby improving the security of deploying the privacy computing platform. BRIEF DESCRIPTION OF DRAWINGS
[0024] The accompanying drawings, which are incorporated into and form part of the specification, illustrate embodiments consistent with the present application and, together with the specification, serve to explain the principles of the application.
[0025] Figure 1 The application scenario diagram of the privacy computing platform deployment method provided by the embodiment of the present application is shown in the following figure.
[0026] Figure 2 Flowchart of the privacy computing platform deployment method provided in the present application Figure 1 ;
[0027] Figure 3 Flowchart of the privacy computing platform deployment method provided in the present application Figure 2 ;
[0028] Figure 4 Structural diagram of the privacy computing platform deployment device provided in the present application
[0029] Figure 5 Structural diagram of the electronic device provided in the present application
[0030] The specific embodiments of the present application have been shown in the above-described drawings, and will be described in more detail hereinafter. These drawings and the written description are not intended to restrict the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION
[0031] The exemplary embodiments will be described in detail herein with reference to the accompanying drawings. In the following description, the same numbers refer to the same or similar elements unless otherwise represented. The embodiments described in the following exemplary embodiments do not represent all the embodiments consistent with the present application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of the present application, as detailed in the appended claims.
[0032] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with the relevant laws, regulations and standards of the relevant countries and regions, take necessary security measures, do not violate public order and good customs, and provide corresponding operation portals for the user to choose authorization or refusal.
[0033] And the present application involves big data analysis of user information (including but not limited to personal biological characteristics, identity data, consumption data, asset data, electronic terminal operation data, etc.), and uses artificial intelligence technology for automatic decision-making, and provides corresponding operation portals for the user to choose to agree or refuse the automatic decision-making result based on the automatic decision-making result to make a technical solution that has a significant impact on personal rights and interests; if the user chooses to refuse, the expert decision-making process is entered.
[0034] It should be noted that the privacy computing platform deployment method, device, equipment, storage medium and program product provided by the present application can be used in the field of privacy computing, and can also be used in any field other than privacy computing. The application field of the privacy computing platform deployment method, device, equipment, storage medium and program product in the present application is not limited.
[0035] The privacy computing technology is a technology for realizing data analysis and sharing under the premise of ensuring data privacy and data security. With the increasing demand for data fusion, the requirement for data protection is gradually increasing. By deploying a privacy computing platform in multiple participants, the multiple participants jointly execute privacy computing tasks using the deployed privacy computing platform to improve the security of data. In the prior art, in order to adapt to the environment differences of different participants, a container technology is used to deploy the privacy computing platform. However, in the prior art, there are security problems in the process of deploying the privacy computing platform by the container, which reduces the security of the privacy computing data.
[0036] To solve the above technical problems, the present application embodiment proposes the following technical idea: the inventors consider signing and encrypting the base image and base service image applied to the privacy computing platform component, and when decompressing the encrypted image file and the component installation file created by the component application of the to-be-deployed platform, using the authorization code to verify the decompression, which improves the security of deploying the privacy computing platform.
[0037] The technical solutions of the present application and how the technical solutions of the present application solve the above technical problems will be described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes can not be described again in some embodiments. The embodiments of the present application will be described below with reference to the drawings.
[0038] Figure 1 The application scenario of the privacy computing platform deployment method provided by the present application is shown in the figure. Figure 1 As shown in the figure, the application scenario includes a deployment platform 101 and a to-be-deployed platform 102.
[0039] Specifically, the deployment platform 101 obtains the component application of the privacy computing platform, the base service image of the component application and the component application base image, signs and encrypts the component application base image and the base service image, generates an encrypted image file, creates a component installation file according to the encrypted image file and the component application, sends the component installation file to the to-be-deployed platform 102, and the to-be-deployed platform 102 decompresses the component installation file according to the pre-generated authorization code, obtains and runs the encrypted image file in the component installation file to complete the deployment of the privacy computing platform.
[0040] Figure 2 The flowchart of the privacy computing platform deployment method provided by the present applicationFigure 1 The execution subject of the embodiment can be a deployment platform in the embodiment shown in the figure, which is not particularly limited here. As shown in the figure, the method comprises the following steps. Figure 2 The deployment platform in the embodiment shown in the figure, which is not particularly limited here. As shown in the figure, the method comprises the following steps. Figure 3 The method comprises the following steps.
[0041] S201: Obtain the component application and the component application base image of the privacy computing platform.
[0042] In the embodiment, the component application of the privacy computing platform includes but is not limited to a privacy computing engine, a data management tool and a blockchain component.
[0043] S202: Obtain the base service image running the component application.
[0044] In the embodiment, the base service image includes but is not limited to a database image, a middleware image and a gateway image.
[0045] S203: Sign and encrypt the component application base image and the base service image to generate an encrypted image file.
[0046] In the embodiment, the signing and encryption method is asymmetric encryption.
[0047] For example, the encryption method includes but is not limited to RSA encryption algorithm, elliptic curve cryptography algorithm and ElGamal encryption algorithm.
[0048] S204: Create a component installation file according to the encrypted image file and the component application.
[0049] Specifically, obtain the backend code source file of the component application, compile the code source file to obtain a compiled file, minimize the compiled file to filter the necessary content of the component application, obtain a target file, compress the target file and the encrypted image file to obtain the component installation file.
[0050] S205: Send the component installation file to the to-be-deployed platform to make the to-be-deployed platform decompress the component installation file according to the pre-generated authorization code and run the encrypted image file in the component installation file to complete the deployment of the privacy computing platform.
[0051] Specifically, the to-be-deployed platform decompresses the component installation file according to the authorization code within the validity period, decrypts the image file, starts the container according to the execution order of the container, runs the image file and deploys the privacy computing platform.
[0052] In addition, it needs to be explained that the deployment platform creates a code branch adapted to the to-be-deployed platform, the deployment platform is decoupled from the system for managing the to-be-deployed platform, the log messages uploaded by the system for managing the to-be-deployed platform are displayed on the detection system of the deployment platform, the front-end page of the deployment platform is redrawn, and the deployment platform is adapted to each to-be-deployed platform.
[0053] From the above embodiment, it can be known that by signing and encrypting the base image and the base service image applied to the component application of the privacy computing platform component, when the to-be-deployed platform decompresses the encrypted image file and the component installation file created by the component application, the authorization code is used to verify the decompression, and the security of the deployment of the privacy computing platform is improved.
[0054] In an embodiment of the present application, step S204 comprises:
[0055] S2041: Obtain the backend code source file of the component application.
[0056] In the embodiment, the backend code source file of the component application is obtained from the code repository.
[0057] S2042: Compile the backend code source file to obtain a compiled file of the component application.
[0058] Specifically, the backend code file is compiled by a compiler to obtain an executable file.
[0059] In the embodiment, the compiled file of the component application is an executable file.
[0060] The executable file is a binary executable file.
[0061] S2043: Minimize the compiled file of the component application to obtain a target file of the component application.
[0062] Specifically, the contents in the compiled file are filtered by a minimized image file to obtain the target file of the component application.
[0063] In the embodiment, the target file records the necessary contents for running the component application.
[0064] For example, the necessary contents include but are not limited to program code, runtime, and configuration file.
[0065] S2044: Compress the target file of the component application and the encrypted image file to generate a component installation file.
[0066] In the embodiment, the compression formats of the target file and the image file include but are not limited to 7z compression, zip compression, and iso compression.
[0067] From the above embodiment, by acquiring the code source file, compiling the code source file, performing the minimization operation to obtain the target file, and compressing the target file and the encrypted mirror file to generate the component installation file, the occupation of the installation file is reduced.
[0068] In an embodiment of the present application, before step S203, further comprising:
[0069] S401: respectively generating an encryption key pair of the component application base image and the base service image.
[0070] In the embodiment, the encryption key pair of the component application base image and the base service image is generated by the hardware security module.
[0071] In the embodiment, the encryption key pair includes an encryption private key and an encryption public key.
[0072] In the embodiment, the encryption key pair is an asymmetric key pair.
[0073] S402: sending the private key of the component application base image and the private key of the base service image to the cloud.
[0074] In the embodiment, when the encrypted component application base image and the base service image are decrypted by the to-be-deployed platform, the private keys are obtained from the cloud.
[0075] S403: storing the public key of the component application base image and the public key of the base service image to a signature encryption file.
[0076] Specifically, the component application base image and the base service image are signature encrypted by the public key of the component application base image and the public key of the base service image.
[0077] From the above embodiment, by respectively generating the encryption key pair of the component application base image and the base service image, uploading the private key in the key pair to the cloud, and storing the public key to the signature encryption file, the to-be-deployed platform uses the private key to decrypt the image file, and the security of the image is improved.
[0078] In an embodiment of the present application, before step S205, further comprising:
[0079] S501: obtaining a network address of the to-be-deployed platform.
[0080] In the embodiment, the network address of the to-be-deployed platform is the network address of the to-be-deployed platform server.
[0081] S502: generating a validity period of the component installation file according to the network address of the to-be-deployed platform.
[0082] In the embodiment, the effective period of the component installation file is set by the developer.
[0083] In the embodiment, the effective period of the component installation file set for different to-be-deployed platforms is different.
[0084] S503: Create an authorization code of the to-be-deployed platform according to the effective period of the component installation file.
[0085] Specifically, the authorization code module generates an authorization code according to the server IP and the use period of the external to-be-deployed platform.
[0086] As can be seen from the above embodiment, by setting the effective period of the component installation file for the to-be-deployed platform, an authorization code is generated, and the to-be-deployed platform decompresses the component installation file according to the authorization code, thereby improving the security of the component installation file.
[0087] Figure 2 Flowchart of the privacy computing platform deployment method provided in the present application Figure 1 The execution subject of the present embodiment can be Figure 3 The to-be-deployed platform in the embodiment shown in the figure is not particularly limited herein. As shown in the figure, Figure 4 The method comprises the following steps:
[0088] S301: Receive the component installation file sent by the deployment platform, wherein the component installation file is created by the deployment platform according to the encrypted image file and the component application; the encrypted image file is obtained by the deployment platform by acquiring the component application, the component application base image, and the base service image of the component application of the privacy computing platform, and then signing and encrypting the component application base image and the base service image.
[0089] Specifically, the deployment platform constructs a pipeline configuration file, and encrypts and packages different component applications and base images of the privacy computing platform into a component installation file. S302: Decompress the component installation file according to the pre-generated authorization code and run the encrypted image file in the component installation file to complete the deployment of the privacy computing platform.
[0090] Specifically, the to-be-deployed platform inputs the pre-generated authorization code, verifies whether the component installation file is valid, and if the component installation file is valid, generates a configuration file of the privacy computing container, imports the configuration file into the privacy computing container, and runs the encrypted image file through the privacy computing container to complete the deployment of the privacy computing platform.
[0091] As can be seen from the above embodiment, by signing and encrypting the base image and the base service image of the component application of the privacy computing platform by the deployment platform, when the to-be-deployed platform decompresses the encrypted image file and the component installation file created by the component application, the authorization code is used to verify the decompression, thereby improving the security of the deployment of the privacy computing platform.
[0092] In one embodiment of the present application, step S302 comprises:
[0093] S3021: decompress the component installation file according to the pre-generated authorization code to obtain the encrypted image file.
[0094] Specifically, the to-be-deployed platform inputs the pre-generated authorization code, verifies whether the component installation file is valid, and if the component installation file is valid, decompresses the component installation file to obtain the encrypted image file.
[0095] S3022: generate a configuration file of the privacy computing container according to the network address and data path of the to-be-deployed platform.
[0096] In this embodiment, the container running environment is pre-installed in the network environment of each to-be-deployed platform, and the encrypted image file is imported into the container running environment.
[0097] In this embodiment, the configuration file of the privacy computing container is modified according to the network address and data storage path of the server of the to-be-deployed platform, and after the modification of the configuration file is completed, a container startup command is executed.
[0098] S3033: import the configuration file of the privacy computing container into the privacy computing container, and run the encrypted image file through the privacy computing container to complete the deployment of the privacy computing platform.
[0099] Specifically, according to the startup sequence of the container, the container is started in sequence, the configuration file is imported into the container, and the running state of the container is checked for abnormality. If no abnormality is verified, the image file is run to complete the deployment of the privacy computing platform.
[0100] From the above embodiments, it can be seen that by using the pre-generated authorization code to decompress the component installation file, the network address and data path of the to-be-deployed platform are configured as the configuration file of the privacy computing container, and the image file in the component installation file is run through the privacy computing container, thereby improving the deployment efficiency of the privacy computing platform.
[0101] Figure 4 The structure diagram of the privacy computing platform deployment device provided by the present application is shown in Figure 5 As shown, the privacy computing platform deployment device 40 provided by the present embodiment comprises a first acquisition module 401, a second acquisition module 402, an encryption module 403, a first creation module 404, and a first sending module 405.
[0102] The first acquisition module 401 is configured to acquire the component application and the component application base image of the privacy computing platform.
[0103] The second obtaining module 402 is configured to obtain a base service image of the running component application.
[0104] The encryption module 403 is configured to sign and encrypt the component application base image and the base service image to generate an encrypted image file.
[0105] The first creating module 404 is configured to create a component installation file according to the encrypted image file and the component application.
[0106] The first sending module 405 is configured to send the component installation file to a to-be-deployed platform, so that the to-be-deployed platform decompresses the component installation file and runs the encrypted image file in the component installation file according to a pre-generated authorization code, to complete deployment of the privacy computing platform.
[0107] In an embodiment of the present application, the first creating module 404 includes:
[0108] The obtaining unit is configured to obtain a backend code source file of the component application.
[0109] The compiling unit is configured to compile the backend code source file to obtain a compiled file of the component application.
[0110] The minimizing unit is configured to minimize the compiled file of the component application to obtain a target file of the component application.
[0111] The compressing unit is configured to compress the target file of the component application and the encrypted image file to generate the component installation file.
[0112] In an embodiment of the present application, the privacy computing platform deployment apparatus 40 further includes:
[0113] The first generating module is configured to generate an encryption key pair of the component application base image and the base service image, respectively.
[0114] The second sending module is configured to send a private key of the component application base image and a private key of the base service image to the cloud.
[0115] The storage module is configured to store a public key of the component application base image and a public key of the base service image to a signature encryption file.
[0116] In an embodiment of the present application, the privacy computing platform deployment apparatus 40 further includes:
[0117] The third obtaining module is configured to obtain a network address of the to-be-deployed platform.
[0118] The second generating module is configured to generate a validity period of the component installation file according to the network address of the to-be-deployed platform.
[0119] The second creating module is configured to create an authorization code of the to-be-deployed platform according to the validity period of the component installation file.
[0120] The privacy computing platform deployment apparatus provided in the embodiment can execute the method provided in the method embodiment, and has similar implementation principles and technical effects, which will not be described here again.
[0121] Figure 5 A structural schematic diagram of an electronic device provided in the present application is shown in FIG. 1. As shown in FIG. 1, the electronic device 50 provided in the embodiment includes at least one processor 501 and a memory 502. Optionally, the electronic device 50 further includes a communication component 503. The processor 501, the memory 502 and the communication component 503 are connected through a bus.
[0122] In the specific implementation process, the at least one processor 501 executes the computer execution instructions stored in the memory 502, so that the at least one processor 501 executes the above-mentioned privacy computing platform deployment method.
[0123] The specific implementation process of the processor 501 can refer to the method embodiment, which has similar implementation principles and technical effects, and will not be described here again.
[0124] In the above-mentioned embodiments, it should be understood that the processor can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC) and the like. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor and the like. The steps of the method disclosed in the present application can be directly embodied as execution completed by a hardware processor, or executed by a combination of hardware and software modules in the processor.
[0125] The memory can include a random access memory (RAM), and can also include a non-volatile memory (NVM), for example, at least one disk memory.
[0126] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the bus in the drawings of the present application does not limit to only one bus or one type of bus.
[0127] The present application also provides a computer program product comprising a computer program which, when executed by a processor, implements the above-mentioned privacy computing platform deployment method.
[0128] The present application also provides a computer readable storage medium having stored therein computer-executable instructions that, when executed by a processor, implement the above-mentioned privacy computing platform deployment method.
[0129] The above-mentioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk or optical disk. The readable storage medium can be any available medium that can be accessed by a general or special purpose computer.
[0130] An exemplary readable storage medium is coupled to the processor, so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be an integral part of the processor. The processor and the readable storage medium can be located in an Application Specific Integrated Circuit (ASIC). Of course, the processor and the readable storage medium can also exist as discrete components in the device.
[0131] The division of units is only a logical functional division, and in actual implementation, there can be another division manner, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0132] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, i.e., may be located in one place, or may be distributed to multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment of the present application.
[0133] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit.
[0134] If the function is realized in the form of a software function unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the part of the prior art or the part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method of each embodiment of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various program code storage media.
[0135] Those skilled in the art can understand that all or part of the steps of the above-mentioned method embodiments can be completed by program instruction related hardware. The aforementioned program can be stored in a computer readable storage medium. The program executes the steps including the above-mentioned method embodiments when executed; and the aforementioned storage medium includes: ROM, RAM, magnetic disk or optical disk, and various program code storage media.
[0136] It should be noted that for the above-mentioned method embodiments, in order to simply describe, they are all expressed as a combination of a series of actions, but those skilled in the art should know that the application is not limited by the order of the described actions, because according to the application, certain steps can be performed in other order or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily necessary for the present application.
[0137] It should be further noted that although the steps in the flowchart are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowchart may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0138] It should be understood that the above-described device embodiments are merely illustrative, and the device of this application can also be implemented in other ways. For example, the division of units / modules in the above embodiments is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units, modules, or components may be combined, or integrated into another system, or some features may be ignored or not executed.
[0139] Furthermore, unless otherwise specified, the functional units / modules in the various embodiments of this application can be integrated into one unit / module, or each unit / module can exist physically separately, or two or more units / modules can be integrated together. The integrated units / modules described above can be implemented in hardware or as software program modules.
[0140] When integrated units / modules are implemented in hardware, the hardware can be digital circuits, analog circuits, etc. The physical implementation of the hardware structure includes, but is not limited to, transistors, memristors, etc. Unless otherwise specified, the processor can be any suitable hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC, etc. Unless otherwise specified, the storage unit can be any suitable magnetic or magneto-optical storage medium, such as Resistive Random Access Memory (RRAM), Dynamic Random Access Memory (DRAM), Static Random Access Memory (SRAM), Enhanced Dynamic Random Access Memory (EDRAM), High-Bandwidth Memory (HBM), Hybrid Memory Cube (HMC), etc.
[0141] If the integrated units / modules are implemented in the form of software program modules and sold or used as independent products, they can be stored in a computer readable memory. Based on such understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a memory and includes a number of instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the embodiments of the method of the present application. The aforementioned memory includes: a U disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.
[0142] In the above embodiments, the description of each embodiment has its own focus, and the parts not described in detail in a certain embodiment can be referred to the related description of other embodiments. The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described, however, as long as the combinations of the technical features do not exist contradictory, they should be considered as the scope of the present application.
[0143] Other embodiments of the application will be apparent to those skilled in the art from consideration of the specification and practice of the application disclosed herein. The application is intended to cover any variations, uses or adaptations of the application following, in general, the principles of the application and including such departures from the present disclosure as come within known or customary practice in the art to which the application pertains or can relate. The specification and examples are to be regarded as exemplary only, and the true scope and spirit of the application are indicated by the following claims.
[0144] It should be understood that the application is not limited to the precise construction that has been described and illustrated herein and that various modifications and changes can be made therein without departing from the scope thereof. The scope of the application is indicated by the appended claims.
Claims
1. A method for deploying a privacy computing platform, characterized in that, Applied to a deployment platform, comprising: obtaining a component application and a component application base image of a privacy computing platform; obtaining a base service image running the component application; signing and encrypting the component application base image and the base service image to generate an encrypted image file; creating a component installation file according to the encrypted image file and the component application; sending the component installation file to a platform to be deployed, so that the platform to be deployed decompresses the component installation file according to a pre-generated authorization code and runs the encrypted image file in the component installation file to complete the deployment of the privacy computing platform.
2. The method of claim 1, wherein, The component installation file is created according to the encrypted image file and the component application, comprising: obtaining a backend code source file of the component application; compiling the backend code source file to obtain a compiled file of the component application; minimizing the compiled file of the component application to obtain a target file of the component application; compressing the target file of the component application and the encrypted image file to generate a component installation file.
3. The method of claim 1, wherein, Before the signing and encryption of the component application base image and the base service image to generate the encrypted image file, further comprising: generating an encryption key pair for the component application base image and the base service image, respectively; sending the private key of the component application base image and the private key of the base service image to the cloud; storing the public key of the component application base image and the public key of the base service image to the signature encryption file.
4. The method of claim 1, wherein, Before sending the component installation file to the platform to be deployed, further comprising: obtaining the network address of the platform to be deployed; generating the validity period of the component installation file according to the network address of the platform to be deployed; creating an authorization code for the platform to be deployed according to the validity period of the component installation file.
5. A method for deploying a privacy computing platform, the method comprising: Applied to a platform to be deployed, comprising: receiving a component installation file sent by a deployment platform, wherein the component installation file is created by the deployment platform according to an encrypted image file and a component application; the encrypted image file is obtained by the deployment platform from a component application, a component application base image and a base service image of the component application of a privacy computing platform, and signing and encrypting the component application base image and the base service image; decompressing the component installation file according to a pre-generated authorization code and running the encrypted image file in the component installation file to complete the deployment of the privacy computing platform.
6. The method of claim 5, wherein, The component installation file is created according to the encrypted image file and the component application, comprising: obtaining a backend code source file of the component application; compiling the backend code source file to obtain a compiled file of the component application; minimizing the compiled file of the component application to obtain a target file of the component application; 7. A privacy computing platform deployment apparatus, characterized by, compressing the target file of the component application and the encrypted image file to generate a component installation file. Before the signing and encryption of the component application base image and the base service image to generate the encrypted image file, further comprising: generating an encryption key pair for the component application base image and the base service image, respectively; sending the private key of the component application base image and the private key of the base service image to the cloud; storing the public key of the component application base image and the public key of the base service image to the signature encryption file. Before sending the component installation file to the platform to be deployed, further comprising: obtaining the network address of the platform to be deployed; generating the validity period of the component installation file according to the network address of the platform to be deployed; creating an authorization code for the platform to be deployed according to the validity period of the component installation file. Applied to a platform to be deployed, comprising: receiving a component installation file sent by a deployment platform, wherein the component installation file is created by the deployment platform according to an encrypted image file and a component application; the encrypted image file is obtained by the deployment platform from a component application, a component application base image and a base service image of the component application of a privacy computing platform, and signing and encrypting the component application base image and the base service image; decompressing the component installation file according to a pre-generated authorization code and running the encrypted image file in the component installation file to complete the deployment of the privacy computing platform. The component installation file is created according to the encrypted image file and the component application, comprising: obtaining a backend code source file of the component application; compiling the backend code source file to obtain a compiled file of the component application; minimizing the compiled file of the component application to obtain a target file of the component application; compressing the target file of the component application and the encrypted image file to generate a component installation file. Before the signing and encryption of the component application base image and the base service image to generate the encrypted image file, further comprising: generating an encryption key pair for the component application base image and the base service image, respectively; sending the private key of the component application base image and the private key of the base service image to the cloud; storing the public key of the component application base image and the public key of the base service image to the signature encryption file. Before sending the component installation file to the platform to be deployed, further comprising: obtaining the network address of the platform to be deployed; generating the validity period of the component installation file according to the network address of the platform to be deployed; creating an authorization code for the platform to be deployed according to the validity period of the component installation file. Applied to a platform to be deployed, comprising: receiving a component installation file sent by a deployment platform, wherein the component installation file is created by the deployment platform according to an encrypted image file and a component application; the encrypted image file is obtained by the deployment platform from a component application, a component application base image and a base service image of the component application of a privacy computing platform, and signing and encrypting the component application base image and the base service image; decompressing the component installation file according to a pre-generated authorization code and running the encrypted image file in the component installation file to complete the deployment of the privacy computing platform. The component installation file is created according to the encrypted image file and the component application, comprising: obtaining a backend code source file of the component application; compiling the backend code source file to obtain a compiled file of the component application; minimizing the compiled file of the component application to obtain a target file of the component application; compressing the target file of the component application and the encrypted image file to generate a component installation file. Before the signing and encryption of the component application base image and the base service image to generate the encrypted image file, further comprising: generating an encryption key pair for the component application base image and the base service image, respectively; sending the private key of the component application base image and the private key of the base service image to the cloud; storing the public key of the component application base image and the public key of the base service image to the signature encryption file. Before sending the component installation file to the platform to be deployed, further comprising: obtaining the network address of the platform to be deployed; generating the validity period of the component installation file according to the network address of the platform to be deployed; creating an authorization code for the platform to be deployed according to the validity period of the component installation file. A second obtaining module is configured to obtain a basic service image running the component application; An encryption module is configured to sign and encrypt the component application basic image and the basic service image to generate an encrypted image file; A first creating module is configured to create a component installation file according to the encrypted image file and the component application; A first sending module is configured to send the component installation file to a to-be-deployed platform, so that the to-be-deployed platform decompresses the component installation file according to a pre-generated authorization code and runs the encrypted image file in the component installation file to complete deployment of the privacy computing platform.
8. An electronic device, comprising: Comprise: A processor, and a memory connected with the processor in communication; The memory stores computer execution instructions; The processor executes the computer execution instructions stored in the memory to implement the privacy computing platform deployment method according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by the processor to implement the privacy computing platform deployment method according to any one of claims 1 to 6.
10. A computer program product, characterised in that, A computer program is included, and the computer program is executed by the processor to implement the privacy computing platform deployment method according to any one of claims 1 to 6.