Data transmission method and device based on privacy calculation, equipment and storage medium
By embedding privacy-preserving computations into digital contracts during data transmission, the problem of insufficient data transmission security is solved, enabling privacy protection and compliance auditing of highly sensitive data, and ensuring that the data transmission process complies with the contract agreement.
Patent Information
- Application Number
- CN202511755708.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-26
- Publication Date
- 2026-01-13
AI Technical Summary
Existing technologies have insufficient data security during data transmission and cannot meet the privacy protection needs of highly sensitive data, especially in the medical and financial fields, where they are vulnerable to risks such as interface hijacking, unauthorized access, and data leakage.
A privacy-based computation-based data transmission method is adopted, which embeds privacy computation into digital contracts. The data space service platform ensures that the data transmission process complies with the contract agreement, thereby realizing the data transmission of privacy computation results.
It improves the security of data transmission, reduces the risk of original data being hijacked or recovered, meets the requirements of full-process traceability and compliance auditability of trusted data space, and ensures that the data usage process complies with the contract agreement.
Smart Images

Figure CN121333797A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to, and in particular to, a data transmission method, apparatus, device, and storage medium based on privacy computing. Background Technology
[0002] Currently, trusted data spaces primarily employ two delivery methods: API (Application Programming Interface) calls and direct data stream transmission. While these methods can meet basic data flow needs, they suffer from significant shortcomings in data transmission security, usage control, privacy compliance, and performance traceability. They are ill-suited for scenarios involving highly sensitive data such as medical and financial data. Specific problems include: API calls in the data transmission stage rely on network transmission interfaces, making them vulnerable to interface hijacking, unauthorized calls, or unauthorized access. Even with transport layer encryption such as HTTPS (Hypertext Transfer Protocol Secure), the returned semi-raw or lightly anonymized data can still be reverse engineered to reconstruct the original data. Direct data stream transmission, while supporting data encryption, exposes the original data completely to the user's local environment after decryption. Furthermore, the data stream is easily intercepted during transmission. This fails to meet the core requirements of trusted data spaces for data transmission security—"preventing leakage and tampering"—and also fails to meet the privacy protection requirement of "keeping the original data within the domain" for sensitive data.
[0003] It is evident that improving data transmission security and ensuring the orderly operation of data space services are problems that need to be addressed in this field. Summary of the Invention
[0004] In view of this, the purpose of this invention is to provide a data transmission method, apparatus, device, and storage medium based on privacy computing. This method embeds privacy computing into digital contracts, explicitly defining the specific process of data transmission, and simultaneously integrates with a data space service platform to ensure that the data transmission process complies with the contractual agreement. This improves data transmission security and reduces the risk of original data being hijacked or recovered. The specific solution is as follows:
[0005] Firstly, this application provides a data transmission method based on privacy computing, applied to a data provider, including:
[0006] The user uploads the data products corresponding to their original data to the data space service platform, so that the data user can create a data order for the data products on the data space service platform; the original data is medical-related data.
[0007] Obtain the data order and sign a digital contract with the data user; the digital contract contains a privacy computing strategy corresponding to the original data.
[0008] The data transmission of privacy calculation results corresponding to the original data is achieved based on the digital contract.
[0009] Optionally, uploading the data product corresponding to its own original data to the data space service platform includes:
[0010] Encapsulate your own raw data to obtain corresponding data products;
[0011] Upload the metadata information of the data product to the data space service platform.
[0012] Optionally, in a centralized privacy computing model, obtaining the data order and signing a digital contract with the data user includes:
[0013] Obtain the data order and sign a digital contract with the data user; the digital contract is a contract constructed by the data user.
[0014] Accordingly, the data transmission of the privacy computation results corresponding to the original data based on the digital contract includes:
[0015] The data product is encrypted and uploaded to the data space service platform, so that the data space service platform can perform privacy calculations on the original data corresponding to the encrypted data product based on the digital contract, and transmit the corresponding privacy calculation results to the data user.
[0016] Optionally, in the distributed privacy computing mode, obtaining the data order and signing a digital contract with the data user includes:
[0017] Obtain the data order and sign a digital contract with the data user; the digital contract is a contract constructed by the data user.
[0018] Accordingly, the data transmission of the privacy computation results corresponding to the original data based on the digital contract includes:
[0019] Based on the digital contract, privacy calculations are performed directly on the data product, and the corresponding privacy calculation results are transmitted to the data user.
[0020] Optionally, the method further includes:
[0021] Log information related to privacy-preserving computation of the original data will be synchronized to the data space service platform so that the data space service platform can store the log information using blockchain technology.
[0022] Secondly, this application provides a data transmission method based on privacy computing, applied to data users, including:
[0023] A data order for a data product is created in the data space service platform; the data product is the data product corresponding to the original data uploaded by the data provider to the data space service platform; the original data is medical-related data.
[0024] After the data provider obtains the data order, a digital contract is signed with the data provider; the digital contract contains a privacy computing strategy corresponding to the original data;
[0025] The data transmission of privacy calculation results corresponding to the original data is achieved based on the digital contract.
[0026] Thirdly, this application provides a data transmission device based on privacy computing, applied to a data provider, comprising:
[0027] The data product upload module is used to upload the data products corresponding to its own raw data to the data space service platform, so that the data user can create a data order for the data product in the data space service platform; the raw data is medical-related data.
[0028] The first contract signing module is used to obtain the data order and sign a digital contract with the data user; the digital contract contains a privacy computing strategy corresponding to the original data.
[0029] The first data transmission module is used to transmit the privacy calculation results corresponding to the original data based on the digital contract.
[0030] Fourthly, this application provides a data transmission device based on privacy computing, applied to a data user, including:
[0031] The data order creation module is used to create data orders for data products in the data space service platform; the data product is the data product corresponding to the original data uploaded by the data provider to the data space service platform; the original data is medical-related data.
[0032] The second contract signing module is used to sign a digital contract with the data provider after the data provider obtains the data order; the digital contract contains a privacy computing strategy corresponding to the original data;
[0033] The second data transmission module is used to transmit the privacy calculation results corresponding to the original data based on the digital contract.
[0034] Fifthly, this application provides an electronic device, comprising:
[0035] Memory, used to store computer programs;
[0036] A processor for executing the computer program to implement the privacy-based computation-based data transmission method as described above.
[0037] Sixthly, this application provides a computer-readable storage medium for storing a computer program, which, when executed by a processor, implements the privacy-based computation-based data transmission method described above.
[0038] Therefore, in this application, the data provider can upload the data product corresponding to its original data to the data space service platform, so that the data user can create a data order for the data product on the data space service platform; the original data is medical-related data; then, the data order is obtained, and a digital contract is signed with the data user; the digital contract contains a privacy computing strategy corresponding to the original data; subsequently, the data transmission of the privacy computing results corresponding to the original data can be realized based on the digital contract. In this way, this application can embed privacy computing into the digital contract, clearly define the specific process of data transmission, and, combined with the data space service platform, ensure that the data transmission process complies with the contract agreement; this can improve the security of the data transmission process and reduce the risk of the original data being hijacked or restored. Attached Figure Description
[0039] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0040] Figure 1 This is a flowchart of a data transmission method based on privacy computing disclosed in this application;
[0041] Figure 2 This application discloses a specific data transmission method based on privacy computing.
[0042] Figure 3 This is a flowchart of another specific privacy-based computation-based data transmission method disclosed in this application;
[0043] Figure 4 This is a flowchart of another specific privacy-based computation-based data transmission method disclosed in this application;
[0044] Figure 5This is a flowchart of another specific privacy-based computation-based data transmission method disclosed in this application;
[0045] Figure 6 This is a schematic diagram of a data transmission device based on privacy computing disclosed in this application;
[0046] Figure 7 This is a schematic diagram of another data transmission device structure based on privacy computing disclosed in this application;
[0047] Figure 8 This is a structural diagram of an electronic device disclosed in this application. Detailed Implementation
[0048] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0049] See Figure 1 As shown, this embodiment of the invention discloses a data transmission method based on privacy computing, applied to a data provider, including:
[0050] Step S11: Upload the data product corresponding to your original data to the data space service platform so that the data user can create a data order for the data product in the data space service platform; the original data is medical related data.
[0051] It should be noted that the data transmission process involves data providers, data users, and a trusted data space service platform. Data providers and users can interact with the data space service platform through their own endpoint interfaces (access connectors). In this embodiment, the data provider can first upload the data products corresponding to its raw data to the data space service platform. Here, the data provider can initiate a product listing application to the data space service platform through its local access connector so that the platform can include it in the data catalog. Afterwards, the data user can query the data catalog and select a suitable data product to create a corresponding data order (specifying the relevant access connector for delivery). It is understood that the data order may involve information such as the data's encryption mode algorithm to facilitate data processing by the data provider. It is also understood that the raw data here can be medical data, or data from other scenarios such as finance.
[0052] In one specific embodiment, uploading the data product corresponding to one's own raw data to the data space service platform may include: encapsulating the raw data to obtain the corresponding data product; and uploading the metadata information of the data product to the data space service platform. Specifically, the data provider can encapsulate its own raw data to obtain the corresponding data product; and then upload the metadata of the data product to the data space service platform; in this way, the data space service platform can include the data product in the data catalog for easy management. In some embodiments, the service platform may also synchronize the data product to regional / industry functional nodes (which are core components of the data infrastructure, providing unified identity management, access connector management, catalog management, registration and filing, and operation monitoring and auditing services for trusted data spaces as business nodes) for registration, recording the data products being managed.
[0053] Step S12: Obtain the data order and sign a digital contract with the data user; the digital contract contains a privacy computing strategy corresponding to the original data.
[0054] In this embodiment, after the data provider uploads the data product to the data space service platform, the data user can create a data order for the data product. Then, the data provider can retrieve the order information and sign a digital contract with the corresponding data user. It should be noted that the digital contract is a contract built by the data user on the data space service platform corresponding to the corresponding data product, which includes information such as the privacy calculation strategy for the raw data of the data product and the format of the calculation result return.
[0055] In specific embodiments, privacy computation modes can include centralized and distributed models. Centralized models refer to data privacy computation being completed at the data space service center; distributed models refer to privacy computation being performed separately by data providers, data users, and other relevant participants. Specifically, centralized privacy computation means that the privacy computation engine of the service platform (centralized) acts as the core of the computation, receiving encrypted data and computation instructions uploaded by each participant through the access connector, completing centralized privacy computation, returning the results, and synchronizing the entire process log to the evidence storage and auditing service. Distributed privacy computation means that the local privacy computation engines of each participant transmit encrypted intermediate results through interaction between access connectors, the business nodes of the service platform are responsible for policy distribution and task coordination, and the evidence storage and auditing service aggregates the entire link log.
[0056] Step S13: Based on the digital contract, transmit the privacy calculation results corresponding to the original data.
[0057] In this embodiment, the above steps enable the data provider and data user to sign a digital contract. For the centralized privacy computing model, product data needs to be uploaded to the data space service platform, where the privacy computing engine performs privacy computing and sends the final calculation result to the data user, thus achieving data transmission. For the distributed privacy computing model, the data provider performs privacy computing using its local privacy computing engine, while the data space service platform plays a supervisory role. The data user can then interact with the data provider through a connector to exchange the calculation results, thus achieving data transmission.
[0058] In a specific embodiment, under a centralized privacy computing mode, obtaining the data order and signing a digital contract with the data user may include: obtaining the data order and signing a digital contract with the data user; the digital contract is a contract constructed by the data user; correspondingly, transmitting the data of the privacy computing results corresponding to the original data based on the digital contract may include: encrypting the data product and uploading the encrypted data product to the data space service platform, so that the data space service platform can perform privacy computing on the original data corresponding to the encrypted data product based on the digital contract and transmit the corresponding privacy computing results to the data user. Specifically, the data provider first needs to sign a digital contract with the data user. The digital contract is a digital contract containing privacy computing strategies (privacy computing algorithm, computing boundaries, result return format, log storage requirements, etc.) constructed by the data user in the privacy computing module of the data space service platform; the data provider and the data user can sign the digital contract through an access connector, and the contract is also backed up on the data space service platform. The data provider reviews the content of the digital contract to ensure that the contract meets security requirements and will not leak the original data. Subsequently, the data provider can encrypt and upload its data product to the data space service platform. Specifically, it can encrypt the data in the metadata domain and upload the encrypted data product to the trusted data space service platform for privacy-preserving computation. This encryption process can be understood as being based on encryption parameters corresponding to a digital contract. Further, the data space service platform can initiate computation tasks on the encrypted digital product uploaded by the data provider based on the privacy-preserving computation strategy corresponding to the digital contract. The service platform completes the computation using its own privacy-preserving computation engine and then sends the corresponding computation results to the data user based on the digital contract, thus achieving data transmission.
[0059] In a specific embodiment, under the distributed privacy computing mode, obtaining the data order and signing a digital contract with the data user may include: obtaining the data order and signing a digital contract with the data user; the digital contract is a contract constructed by the data user; correspondingly, the data transmission of the privacy computing results corresponding to the original data based on the digital contract includes: directly performing privacy computing on the data product based on the digital contract and transmitting the corresponding privacy computing results to the data user. Specifically, under the distributed privacy computing mode, the data space service platform plays a supervisory role, and privacy computing is completed locally by each participating party; after the data provider and data user sign the digital contract, the data provider can synchronize the original data of the data product to the local privacy computing engine based on the digital contract to perform localized processing on the original data, while other data users and related participating parties can start their local privacy computing engines and exchange intermediate results (ciphertext form) through the interaction interface between the access connectors; after receiving the ciphertext form intermediate results transmitted by all participating parties, the data user can perform result aggregation based on the digital contract to obtain the final computing result.
[0060] Furthermore, in a specific embodiment, the method may further include: synchronizing log information related to privacy computation of the original data to the data space service platform, so that the data space service platform can store the log information using blockchain technology. Specifically, during the entire privacy computation data transmission process, the data provider can synchronize relevant log information to the data space service platform, and the service platform can use blockchain technology to store the log information for easy supervision, query, and traceability. It is understood that in both centralized and distributed privacy computation models, each participating party can synchronize relevant log information related to its processing to the data space service platform.
[0061] Therefore, this application can embed privacy-preserving computation into digital contracts, clearly defining the specific process of data transmission. Combined with the real-time monitoring of the data space service platform, it can solve the problem of "loss of control over behavior after data delivery" in traditional delivery, ensuring that data use complies with the contract agreement throughout the entire process. Raw data is not directly transmitted across entities (centralized encrypted storage on the platform, distributed storage locally), only encrypted intermediate results or computation results are transmitted, fundamentally reducing the risk of data hijacking, theft, and restoration, achieving "data usable but invisible." Furthermore, the full-process fine-grained logging combined with tamper-proof evidence storage allows for precise traceability of "how the data is used, who is using it, and where it is used." In the event of a contract breach (such as use beyond the scope), responsibility can be quickly determined, meeting the operational requirements of a trusted data space for "full-process traceability and compliant auditability."
[0062] like Figure 2As shown, this embodiment discloses a data transmission method based on privacy computing, applied to a data user, including:
[0063] Step S21: Create a data order for the data product in the data space service platform; the data product is the data product corresponding to the original data uploaded by the data provider to the data space service platform; the original data is medical-related data.
[0064] In this embodiment, the data user can access the data catalog of the query data space service platform through their own connector, that is, query the information of various data products. After selecting the target data product, the user can create the corresponding transaction contract, that is, create a data order for the data product.
[0065] In a specific embodiment, under the centralized privacy computing mode, the data user jumps to the privacy computing module of the trusted data space service platform through a connector, builds a digital contract management module, and generates a digital contract containing privacy computing strategies for the data product. The privacy computing strategy here may include: privacy computing algorithm (such as random forest), computing boundaries (such as model training epochs ≤ 100, feature dimension ≤ 50), result return format (such as model parameters, statistical indicators, excluding raw data), and log storage requirements (logs are synchronized to the storage and auditing module of the data space service platform).
[0066] Correspondingly, in the distributed privacy computing model, data users can use a local distributed privacy computing engine to construct digital contracts, which may include: a list of collaborative computing nodes (precisely specifying the participants, such as specific entities like Hospital A, Hospital B, and medical research institutions), sharding transmission protocols and algorithms (e.g., using the privacy-preserving set intersection (PSI) protocol specifically for privacy computing, for collaborative computing of intersection samples from multiple sources), result aggregation rules (clarifying the decryption algorithm and aggregation logic of the sharding results computed by multiple parties, such as "each sharding result is homomorphically encrypted and added before being decrypted to generate the final statistical value"), and local computing monitoring requirements (strictly restricting the export of sharded data and unauthorized computing behavior, such as "prohibiting any participant from copying or transmitting local sharded data to non-agreement nodes").
[0067] Step S22: After the data provider obtains the data order, a digital contract is signed with the data provider; the digital contract contains a privacy computing strategy corresponding to the original data.
[0068] Furthermore, data providers can review the content of digital contracts to ensure that they meet security requirements and do not leak original data; each participating party (data provider, data user) can view and sign the digital contract through their own access connector, and the contract is filed on the data space service platform after signing.
[0069] In a specific embodiment, under the centralized privacy computing mode, the service platform can initiate privacy computing tasks based on digital contracts and complete privacy computing through the privacy computing engine in the platform; while under the distributed privacy computing mode, the service platform can issue contract policies and collaborative computing instructions to the access connectors of each participant to ensure that each node understands the computing rules and execution requirements.
[0070] Step S23: Based on the digital contract, transmit the privacy calculation results corresponding to the original data.
[0071] Furthermore, in the centralized privacy computing model, the service platform issues control policies from the digital contract to its own privacy computing engine to initiate the computing task: the privacy computing engine loads the encrypted data product from the data provider and verifies the integrity of the data and algorithm (through hash verification); then it receives computing instructions (such as model training parameters and statistical dimensions) uploaded by the data user through the access connector; then it executes privacy computing (such as "local training → model aggregation → global model generation"), monitoring in real time whether the computing process complies with the contract policies (such as prohibiting access to the plaintext of encrypted data and restricting the export of model parameters); and if abnormal behavior is detected (such as training beyond the specified number of rounds), the computing can be terminated immediately and an alarm can be triggered. Afterwards, the service platform can return the computing results to the data user through the connector based on the result format agreed upon in the digital contract, thus realizing data transmission.
[0072] Correspondingly, in the distributed privacy computing model, data providers (such as multiple hospitals) perform localized processing on the raw data through the privacy computing engine of the local access connector: using the secret sharing algorithm of Multi-Party Computation (MPC), the raw data is divided into N encrypted fragments (N = number of participants); and then data fragment identifiers (associated fragment ownership and encryption key) are generated. Each participating party's access connector privacy computing engine initiates local computation: The data provider's access connector's privacy computing engine loads local data fragments and performs local computations (such as basic operations like fragmented multiplication and addition under the MPC framework); it transmits encrypted intermediate results (such as ciphertext results after fragmented computation) through the interaction interface between access connectors. The interface can adopt a dual protection mechanism of "transport layer security protocol encryption + application layer signature" to ensure the security of intermediate result transmission; the service platform receives the computation progress reported by each access connector in real time and monitors computation behavior according to contract policies (such as verifying the legitimacy of node identities and blocking unauthorized nodes' access requests to intermediate results); the data user receives the encrypted intermediate results transmitted by all participating parties, performs result aggregation according to the rules agreed in the contract (such as completing the decryption of fragmented ciphertext and merging of results through the MPC protocol), and generates the final computation result, thus realizing data transmission.
[0073] Therefore, this application can embed privacy-preserving computation into digital contracts, clearly defining the specific process of data transmission. Combined with the real-time monitoring of the data space service platform, it can solve the problem of "loss of control over behavior after data delivery" in traditional delivery, ensuring that data use complies with the contract agreement throughout the entire process. Raw data is not directly transmitted across entities (centralized encrypted storage on the platform, distributed storage locally), only encrypted intermediate results or computation results are transmitted, fundamentally reducing the risk of data hijacking, theft, and restoration, achieving "data usable but invisible." Furthermore, the full-process fine-grained logging combined with tamper-proof evidence storage allows for precise traceability of "how the data is used, who is using it, and where it is used." In the event of a contract breach (such as use beyond the scope), responsibility can be quickly determined, meeting the operational requirements of a trusted data space for "full-process traceability and compliant auditability."
[0074] like Figure 3As shown in the diagram, this embodiment discloses a system architecture diagram corresponding to a data transmission method based on privacy computing, involving a trusted data space service platform and multiple participants (data providers and data users). Each participant includes an access connector, and in a distributed privacy computing mode, each participant also includes a local privacy computing engine. The data space service platform is the core hub for data delivery and privacy computing, integrating multiple key functions: 1. Regional / Industry Functional Nodes: Responsible for participant identity authentication (verifying the legitimacy of data providers, users, etc.), privacy computing data product metadata registration, directory management, and computing compliance supervision (checking whether tasks comply with agreed-upon strategies), laying a solid foundation for cross-domain and cross-industry data flow; 2. Business Nodes: Linking digital contract management (embedding privacy computing strategies into contracts, clarifying data usage scenarios, delivery methods, and participant rights and responsibilities), usage control (real-time monitoring of the privacy computing process to prevent out-of-scope operations), and privacy computing task scheduling (coordinating computing resources and task flows in a centralized mode), serving as the link between business rules and computing... 3. Privacy Computing Engine (Centralized): Deployed within the service platform, supporting centralized privacy computing such as confidential computing; In centralized mode, it is responsible for confidential computing environment verification, agreed algorithm content, algorithm consistency verification, data consistency verification, result encryption processing, multi-participant collaborative computing and result aggregation, and the original data is encrypted and stored on the platform, only outputting the computing results to avoid direct exposure of the original data; 4. Evidence Preservation and Auditing Service: Deeply integrated with the privacy computing engine (centralized / distributed) and business nodes, it records the entire privacy computing process log in fine granularity (such as participant identity, computing steps, intermediate result transmission, result destination, etc.), and relies on anti-tampering technology to achieve log evidence preservation, providing a basis for performance traceability and compliance auditing. Correspondingly, the access connector and distributed privacy computing engine are deployed locally on the data providers, users, and other participants, forming the core execution layer for "data not leaving the domain." Specifically: 1. Access Connector: As the terminal interface for interaction between participants and the Trusted Data Space Service Platform, it undertakes functions such as data product encapsulation and access (associating privacy computing algorithms and encryption rules), intermediate result transmission (transmitting encrypted fragments or intermediate computation results in distributed mode), and local log recording (synchronizing to the platform's evidence storage and auditing service); 2. Privacy Computing Engine (Distributed): Embedded in the access connectors of each participant, it supports distributed algorithms such as federated learning and MPC; it completes scene modeling, fragment encryption of raw data, and collaborative computing (such as local fragment operations of MPC) locally, only transmitting encrypted intermediate results externally, ensuring that raw data only remains in the local environment of the participants, meeting the privacy protection requirement of "data not leaving the domain" for highly sensitive data.
[0075] Furthermore, in the centralized privacy computing model, the service platform's privacy computing engine (centralized) serves as the computing core, receiving encrypted data and computing instructions uploaded by each participant through the access connector, completing centralized computing, returning results, and synchronizing the entire process log to the evidence storage and auditing service. Correspondingly, in the distributed privacy computing model, each participant's local privacy computing engine (distributed) transmits encrypted intermediate results through interaction between access connectors. The service platform's business nodes are responsible for policy distribution and task coordination, while the evidence storage and auditing service aggregates the entire link log. Regional / industry functional nodes provide identity, directory, and compliance protection capabilities from the upper layer.
[0076] As can be seen, based on the above system architecture, this application is adaptable to both centralized and distributed privacy computing models. The centralized model deploys the privacy computing engine on the trusted data space service platform, enabling "encrypted aggregation, unified platform computation, and result output" of data from multiple providers. The distributed model embeds the engine into the access connectors of each participant, achieving "raw data not leaving the domain locally, only transmitting encrypted intermediate results, and multi-entity collaborative computation," covering different security levels and scenario requirements. The privacy computing engine is deeply integrated with the existing core modules of the trusted data space (digital contract management, usage control, and evidence auditing), while simultaneously expanding the access connectors' capabilities in "data product encapsulation, local privacy computing execution, and intermediate result transmission," forming a secure flow architecture of "platform-connector" collaboration. Privacy computing-specific strategies (including algorithm type, computation boundaries, result format, and log evidence requirements) are embedded in digital contracts, and the computation process is monitored in real time by the usage control module (e.g., prohibiting computation beyond the scope and restricting result export), achieving precise boundary control of data usage. By using the evidence storage and auditing module to record the entire privacy computing process log in a fine-grained manner (participant identity, calculation steps, intermediate result transmission, result destination, etc.), and combining it with tamper-proof technologies such as blockchain for evidence storage, it can support performance traceability and compliance auditing.
[0077] like Figure 4 The diagram shows a data transmission method flowchart under a centralized privacy computing model disclosed in this embodiment. It can be understood that the privacy computing engine is deployed on a trusted data space service platform. Data providers upload encrypted data products to the privacy computing engine of the service platform. Data users initiate computing requests through an access connector. The computing process is uniformly executed on the service platform; the original data does not leave the platform, only the computing results are returned. This model is suitable for scenarios where "multiple data providers are willing to aggregate data to a trusted third-party platform and unified computing resources are required" (such as cross-enterprise supply chain data joint analysis and regional government data collaborative statistics). Specific methods include:
[0078] First, the data provider encapsulates and lists the data products. Specifically, the data provider can use a local access connector to encapsulate data product metadata based on the raw data, such as selecting the privacy computing delivery mode and use case (e.g., centralized privacy computing delivery - large model online inference, centralized privacy computing - image processing). Then, through the local access connector, the data provider can initiate a data product listing application to the catalog management module of the data space service platform, submitting data product metadata (including privacy computing algorithm identifier and data security level). After the service platform approves the application, it will be included in the data catalog and synchronized to the regional / industry functional nodes to complete the registration.
[0079] Then, business transactions and digital contract signing take place. Specifically, data users can query the data catalog at the business node of the data space service platform, select the target data product, place an order, and create a transaction contract and order (specifying the relevant access connector for delivery, denoted as the delivery connector, indicating the connector used by each participant in this privacy computation for data delivery). Then, the data provider can retrieve order information through the delivery connector, configure data encryption parameters (such as encryption mode, algorithm, etc.), encrypt the data in the metadata domain, and upload the encrypted data product to the privacy computation engine (centralized) of the trusted data space service platform. It should be noted that data users can jump to the privacy computation module of the trusted data space service platform through the delivery connector, and build a digital contract management module to generate a digital contract containing a privacy computation strategy. The strategy may specifically include: privacy computation algorithm (such as random forest), computation boundaries (such as model training epochs ≤ 100, feature dimensions ≤ 50), result return format (such as model parameters, statistical indicators, excluding raw data), and log storage requirements (such as each round of training logs related to privacy computation needing to be synchronized to the storage and auditing module). The data provider and user sign the contract through the access connector, and the contract is filed with the service platform. Furthermore, the data provider reviews the contract content to ensure that the contract meets security requirements and will not leak the original data.
[0080] Afterwards, privacy-preserving computation tasks can be executed. The service platform can issue control policies from the digital contract to its own privacy-preserving computation engine to initiate the computation task: The privacy-preserving computation engine loads the encrypted data products from the data provider and verifies the integrity of the data and algorithms (through hash verification); it receives computation instructions (such as model training parameters and statistical dimensions) uploaded by the data user's access connector; it executes privacy-preserving computations (such as "local training → model aggregation → global model generation"), and monitors in real time whether the computation process complies with the contract policy (such as prohibiting access to the plaintext of encrypted data and restricting the export of model parameters); if abnormal behavior is detected (such as training beyond the specified number of rounds), the computation is immediately terminated and an alarm is triggered.
[0081] Finally, results are delivered and logs are stored. Specifically, after the privacy computing engine completes the calculation, it returns the results to the data user through the access connector according to the contractually agreed result format (such as trained model parameters and statistical reports). The data user logs in to the delivery connector to obtain the calculation results. At the same time, the privacy computing engine can synchronize the entire process log (including data loading time, calculation steps, parameter adjustment, and result output time) to the service platform's evidence storage and auditing module. The log content includes: participant identification (identity authentication results of associated regional / industry functional nodes); privacy computing algorithm execution details (such as the loss value of each training round); and data usage behavior records (such as result download time). The evidence storage and auditing module can use blockchain technology to prevent log tampering and support query and traceability by data providers, users, and regulators.
[0082] In specific embodiments, the entire process of centralized privacy computing can be subject to compliance supervision; regional / industry functional nodes can obtain the operation information of privacy computing tasks (such as computing compliance and log integrity) through the monitoring interface of the service platform, and conduct regular compliance audits to ensure that the computing process complies with data security conditions and trusted data space rules.
[0083] Therefore, in this application, the centralized privacy computing model deploys the privacy computing engine on the Trusted Data Space service platform, achieving "encrypted aggregation, unified platform computing, and result output" of data from multiple providers. Furthermore, it deeply integrates the privacy computing engine with the existing core modules of the Trusted Data Space (digital contract management, usage control, and evidence storage auditing), while expanding the access connector's capabilities in "data product encapsulation, local privacy computing execution, and intermediate result transmission," forming a secure flow architecture of "platform-connector" collaboration. Privacy computing-specific strategies (including algorithm type, computing boundaries, result format, and log storage requirements) are embedded in digital contracts. The usage control module monitors the computing process in real time (e.g., prohibiting out-of-scope computing and restricting result export), achieving precise boundary control of data usage. The evidence storage auditing module records the entire privacy computing process log in a fine-grained manner (participant identities, computing steps, intermediate result transmission, result destination, etc.), and combines this with tamper-proof technologies such as blockchain for evidence storage, supporting performance traceability and compliance auditing.
[0084] like Figure 5The diagram shown is a flowchart of a data transmission method under a centralized privacy computing model disclosed in this embodiment. It can be understood that the privacy computing engine is deployed in the access connectors of each participating party (data provider, data user). The trusted data space service platform is only responsible for "policy distribution, task coordination, and log aggregation," and does not store the original data. The original data of the data provider is processed in the privacy computing engine of the local access connector (e.g., sharding and encryption), and the encrypted intermediate results are transmitted only through the interaction interface between the access connectors to collaboratively complete the computation; the original data does not leave the local machine. This model is suitable for scenarios where "highly sensitive data (such as medical data, personal biological data) does not want to leave the domain and requires multi-party collaborative computation" (e.g., multi-hospital joint research, cross-bank risk control model training). Specific methods include:
[0085] First, data product metadata registration is performed. Specifically, data providers can choose privacy computing delivery modes and use cases (such as distributed privacy computing delivery and distributed privacy computing). The data provider access connector only uploads the data product metadata (privacy computing algorithm type and data security level) to the directory management module of the Trusted Data Space Service Platform to complete the registration and listing. The service platform synchronizes the metadata to the regional / industry functional node registration, and the original data is only stored locally on the provider's premises.
[0086] Then, business transactions and digital contract signing take place. Specifically, data users (such as medical research institutions) access the connector query service platform's data catalog, filter out data products that meet the requirement of "multi-entity collaborative computing of highly sensitive data," and initiate a joint computing application (e.g., specifying the specific scenario and objective of "training a tumor prediction model based on multi-hospital data"). Contracts and orders are created, and the delivery connector is specified. Data providers can log in to the delivery connector, obtain order information, and synchronize the data product data to the local distributed privacy computing engine. Data users log in to the delivery connector to obtain order information. Using a local distributed privacy computing engine, they construct a digital contract. The strategy can include: a list of collaborative computing nodes (precisely specifying participants, such as Hospital A, Hospital B, medical research institutions, etc.); sharding transmission protocols and algorithms (e.g., using the Privacy Set Intersection (PSI) protocol specifically for privacy computing, used for collaborative computation of intersection samples from multi-source data); result aggregation rules (clearly defining the decryption algorithm and aggregation logic for MPC sharding results, such as "each sharding result is homomorphically encrypted and added before decryption to generate the final statistical value"); and local computing monitoring requirements (strictly restricting sharding data export and unauthorized computation, such as "prohibiting any participant from copying or transmitting local sharding data to non-agreement nodes"). Each participant (data provider, data user) views and signs the contract through their own access connector. After signing, the contract is filed on the service platform. Subsequently, the service platform issues the contract strategy and collaborative computing instructions to each participant's access connector, ensuring that each node understands the computation rules and execution requirements.
[0087] Then, distributed collaborative privacy computation is performed; specifically, the data provider (such as multiple hospitals) performs localized processing on the raw data through the privacy computation engine of the local access connector: using the secret sharing algorithm of multi-party secure computation (MPC), the raw data is divided into N encrypted fragments (N is the number of participants); and data fragment identifiers (associated with fragment ownership and encryption key) are generated. Correspondingly, the privacy computing engines of each participating party's access connector initiate local computation: the privacy computing engine of the data provider's access connector loads local data fragments and performs local computations (such as basic operations like fragmented multiplication and addition under the MPC framework); it transmits encrypted intermediate results (such as ciphertext results after fragmented computation) through the interaction interface between access connectors. The interface adopts a dual protection mechanism of "transport layer encryption (such as TLS) + application layer signature" to ensure the security of intermediate result transmission; the service platform receives the computation progress reported by each access connector in real time and monitors the computation behavior according to the contract policy (such as verifying the legitimacy of node identities and blocking unauthorized nodes' access requests to intermediate results); the privacy computing engine of the data user's access connector receives the encrypted intermediate results transmitted by all participating parties, performs result aggregation according to the aggregation rules agreed in the contract (such as completing the decryption of fragmented ciphertext and merging of results through the MPC protocol), and generates the final computation result.
[0088] Finally, results are delivered and end-to-end evidence is stored. Specifically, data users can feed back the final computation results to their local application systems (such as research analysis platforms in medical research institutions) through the access connector. At the same time, the privacy computing engines of each participating party's access connector synchronize local computation logs (covering shard loading time, intermediate result transmission records, local computation time, key operation parameters, etc.) to the evidence storage and auditing module of the Trusted Data Space Service Platform. The service platform summarizes the multi-source logs and generates a "Distributed Computing End-to-End Evidence Storage Report". Regional / industry functional nodes can query this evidence storage report through the service platform to audit the compliance of the computation process (such as whether it follows data security rules and complies with contractual agreements).
[0089] Therefore, in this application, the distributed privacy computing model embeds the engine into the access connectors of each participating party, achieving "raw data not leaving the domain locally, only transmitting encrypted intermediate results, and multi-party collaborative computing," which can cover different security levels and scenario requirements. Furthermore, it deeply integrates the privacy computing engine with the existing core modules of the trusted data space (digital contract management, usage control, and evidence storage auditing), while expanding the access connectors' capabilities in "data product encapsulation, local privacy computing execution, and intermediate result transmission," forming a secure flow architecture of "platform-connector" collaboration. Privacy computing-specific policies (including algorithm type, computation boundaries, result format, log storage requirements, etc.) are embedded in digital contracts, and the usage control module monitors the computation process in real time (e.g., prohibiting out-of-scope computation and restricting result export), achieving precise boundary control of data usage. The evidence storage auditing module records the entire privacy computing process log (participant identity, computation steps, intermediate result transmission, result destination, etc.) in a fine-grained manner, combined with tamper-proof technologies such as blockchain for evidence storage, supporting performance traceability and compliance auditing.
[0090] like Figure 6 As shown, this embodiment discloses a data transmission device based on privacy computing, applied to a data provider, including:
[0091] The data product upload module 11 is used to upload the data product corresponding to its own original data to the data space service platform, so that the data user can create a data order for the data product in the data space service platform; the original data is medical-related data.
[0092] The first contract signing module 12 is used to obtain the data order and sign a digital contract with the data user; the digital contract contains a privacy computing strategy corresponding to the original data.
[0093] The first data transmission module 13 is used to transmit the privacy calculation results corresponding to the original data based on the digital contract.
[0094] Therefore, the data provider of this application can upload data products to the data space service platform and sign a digital contract with the data user, embed privacy computing into the digital contract, clearly stipulate the specific process of data transmission, and at the same time, combine the data space service platform to ensure data security, which can improve the security of the data transmission process and reduce the risk of the original data being hijacked or restored.
[0095] In one specific embodiment, the data product upload module 11 may include:
[0096] The data encapsulation unit is used to encapsulate its own raw data to obtain corresponding data products;
[0097] The information uploading unit is used to upload the metadata information of the data product to the data space service platform.
[0098] In one specific embodiment, the first contract signing module 12 may include:
[0099] The first contract signing unit is used to obtain the data order and sign a digital contract with the data user; the digital contract is a contract constructed by the data user.
[0100] Accordingly, the first data transmission module 13 may include:
[0101] The data product uploading unit is used to encrypt the data product and upload the encrypted data product to the data space service platform, so that the data space service platform can perform privacy calculations on the original data corresponding to the encrypted data product based on the digital contract and transmit the corresponding privacy calculation results to the data user.
[0102] In another specific embodiment, the data product upload module 11 may include:
[0103] The second contract signing unit is used to obtain the data order and sign a digital contract with the data user; the digital contract is a contract constructed by the data user.
[0104] Accordingly, the first data transmission module 13 may include:
[0105] A privacy computing unit is used to perform privacy calculations directly on the data product based on the digital contract and transmit the corresponding privacy calculation results to the data user.
[0106] In one specific embodiment, the device may further include:
[0107] The log synchronization module is used to synchronize log information related to privacy computing of the original data to the data space service platform, so that the data space service platform can use blockchain technology to store the log information.
[0108] like Figure 7 As shown, this embodiment discloses a data transmission device based on privacy computing, applied to a data user, including:
[0109] The data order creation module 21 is used to create data orders for data products in the data space service platform; the data product is the data product corresponding to the original data uploaded by the data provider to the data space service platform; the original data is medical-related data.
[0110] The second contract signing module 22 is used to sign a digital contract with the data provider after the data provider obtains the data order; the digital contract contains a privacy computing strategy corresponding to the original data;
[0111] The second data transmission module 23 is used to transmit the privacy calculation results corresponding to the original data based on the digital contract.
[0112] Therefore, it is evident that users of the data in this application can query data products on the data space service platform to create data orders and sign digital contracts with data providers. By embedding privacy computing into the digital contracts and clearly defining the specific process of data transmission, and by combining this with the data space service platform to ensure data security, the security of the data transmission process can be improved, and the risk of the original data being hijacked or restored can be reduced.
[0113] Furthermore, embodiments of this application also disclose an electronic device, Figure 8 This is a structural diagram of an electronic device 30 according to an exemplary embodiment. The content of the diagram should not be construed as limiting the scope of this application.
[0114] Figure 8 This is a schematic diagram of the structure of an electronic device 30 provided in an embodiment of this application. Specifically, the electronic device 30 may include: at least one processor 31, at least one memory 32, a power supply 33, a communication interface 34, an input / output interface 35, and a communication bus 36. The memory 32 stores a computer program, which is loaded and executed by the processor 31 to implement the relevant steps in the privacy-based computation-based data transmission method disclosed in any of the foregoing embodiments. Alternatively, the electronic device 30 in this embodiment may specifically be an electronic computer.
[0115] In this embodiment, the power supply 33 is used to provide operating voltage for each hardware device on the electronic device 30; the communication interface 34 can create a data transmission channel between the electronic device 30 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 35 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.
[0116] In addition, the memory 32, as a carrier for resource storage, can be a read-only memory, random access memory, disk or optical disk, etc. The resources stored thereon can include operating system 321, computer program 322, etc., and the storage method can be temporary storage or permanent storage.
[0117] The operating system 321 is used to manage and control the various hardware devices on the electronic device 30 and the computer program 322, which may be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program capable of performing the privacy-based computation data transmission method executed by the electronic device 30 as disclosed in any of the foregoing embodiments, the computer program 322 may further include a computer program capable of performing other specific tasks.
[0118] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the aforementioned privacy-based computation-based data transmission method. Specific steps of this method can be found in the corresponding content disclosed in the foregoing embodiments, and will not be repeated here.
[0119] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.
[0120] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0121] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.
[0122] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0123] The technical solutions provided in this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only intended to help understand the methods and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.
Claims
1. A data transmission method based on privacy computing, characterized in that, Applied to data providers, including: The user uploads the data products corresponding to their original data to the data space service platform, so that the data user can create a data order for the data products on the data space service platform; the original data is medical-related data. Obtain the data order and sign a digital contract with the data user; the digital contract contains a privacy computing strategy corresponding to the original data. The data transmission of privacy calculation results corresponding to the original data is achieved based on the digital contract.
2. The data transmission method based on privacy computing according to claim 1, characterized in that, Uploading the data product corresponding to its own original data to the data space service platform includes: Encapsulate your own raw data to obtain corresponding data products; Upload the metadata information of the data product to the data space service platform.
3. The data transmission method based on privacy computing according to claim 2, characterized in that, In a centralized privacy computing model, obtaining the data order and signing a digital contract with the data user includes: Obtain the data order and sign a digital contract with the data user; the digital contract is a contract constructed by the data user. Accordingly, the data transmission of the privacy computation results corresponding to the original data based on the digital contract includes: The data product is encrypted and uploaded to the data space service platform, so that the data space service platform can perform privacy calculations on the original data corresponding to the encrypted data product based on the digital contract, and transmit the corresponding privacy calculation results to the data user.
4. The data transmission method based on privacy computing according to claim 2, characterized in that, In a distributed privacy computing model, obtaining the data order and signing a digital contract with the data user includes: Obtain the data order and sign a digital contract with the data user; the digital contract is a contract constructed by the data user. Accordingly, the data transmission of the privacy computation results corresponding to the original data based on the digital contract includes: Based on the digital contract, privacy calculations are performed directly on the data product, and the corresponding privacy calculation results are transmitted to the data user.
5. The data transmission method based on privacy computing according to any one of claims 1 to 4, characterized in that, Also includes: Log information related to privacy-preserving computation of the original data will be synchronized to the data space service platform so that the data space service platform can store the log information using blockchain technology.
6. A data transmission method based on privacy computing, characterized in that, Applied to data users, including: A data order for a data product is created in the data space service platform; the data product is the data product corresponding to the original data uploaded by the data provider to the data space service platform; the original data is medical-related data. After the data provider obtains the data order, a digital contract is signed with the data provider; the digital contract contains a privacy computing strategy corresponding to the original data; The data transmission of privacy calculation results corresponding to the original data is achieved based on the digital contract.
7. A data transmission device based on privacy computing, characterized in that, Applied to data providers, including: The data product upload module is used to upload the data products corresponding to its own raw data to the data space service platform, so that the data user can create a data order for the data product in the data space service platform; the raw data is medical-related data. The first contract signing module is used to obtain the data order and sign a digital contract with the data user; the digital contract contains a privacy computing strategy corresponding to the original data. The first data transmission module is used to transmit the privacy calculation results corresponding to the original data based on the digital contract.
8. A data transmission device based on privacy computing, characterized in that, Applied to data users, including: The data order creation module is used to create data orders for data products in the data space service platform; the data product is the data product corresponding to the original data uploaded by the data provider to the data space service platform; the original data is medical-related data. The second contract signing module is used to sign a digital contract with the data provider after the data provider obtains the data order; the digital contract contains a privacy computing strategy corresponding to the original data; The second data transmission module is used to transmit the privacy calculation results corresponding to the original data based on the digital contract.
9. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor for executing the computer program to implement the privacy-based computation-based data transmission method as described in any one of claims 1 to 6.
10. A computer-readable storage medium, characterized in that, Used to store a computer program, which, when executed by a processor, implements the privacy-based computation-based data transmission method as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Intelligent medical data gateway system
CN115396260A
Data trusted transaction method and system based on block chain and privacy calculation
CN118364492A
Cross-subject power data security sharing and collaborative analysis method fusing block chain and privacy calculation
CN120856411A
Privacy computing method and apparatus, electronic device, and storage medium
WO2025092476A1