Data processing system, method, device and equipment and storage medium
By using the intermediary as a hub, secure data collaboration across platforms and organizations is achieved, solving the problem of low efficiency in collaborative operations between the same organization and multiple different partner organizations, improving communication efficiency and reducing costs, and supporting large-scale data collaboration.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-23
- Publication Date
- 2026-04-10
AI Technical Summary
In privacy computing, it is difficult for a single organization to collaborate with multiple different partner organizations, resulting in low communication efficiency. Furthermore, cross-organizational collaboration is costly to deploy and has a long debugging cycle, making it difficult to achieve large-scale data cooperation.
By introducing a transfer party as an intermediary hub, and through standardized interfaces and data transfer between scenario application parties and data providers, cross-platform and cross-organizational data security collaboration can be achieved, avoiding redundant joint debugging between two organizations, and flexible data networking and cooperation can be carried out by adopting privacy computing data transfer methods.
It improves communication efficiency between organizations, reduces deployment costs and debugging cycles for cross-organizational collaboration, supports large-scale data cooperation between many organizations, enhances expansion flexibility and collaboration scalability, and ensures data security and compliance with regulatory requirements.
Smart Images

Figure CN121842260A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of communication technology, and in particular relates to a data processing system, method, apparatus, device and storage medium. Background Technology
[0002] Cross-agency privacy-preserving computation data collaboration is a method of achieving data value sharing and collaborative computation through technical means, under the premise that data does not leave the local area of each party and data privacy and security are guaranteed. Technologies such as multi-party secure computation, federated learning, and trusted execution environments can be used to achieve data flow and collaborative computation while ensuring data privacy and security, which is a key path to unlocking the value of data elements.
[0003] In privacy computing applications, when the same organization provides the same scenario services with different partner organizations, the differences in technical architecture, algorithm principles, security standards, and communication protocols among different privacy computing platforms mean that current privacy computing collaborations are mostly between two organizations. This makes it difficult for the same organization to directly collaborate with multiple different partner organizations, reducing the communication efficiency between organizations. Summary of the Invention
[0004] This application provides a data processing system, method, apparatus, device, and storage medium that can improve communication efficiency between an organization and multiple different collaborating organizations in privacy computing applications.
[0005] In a first aspect, embodiments of this application provide a data processing system, comprising: scenario application parties, data providers, and relay parties, wherein the relay parties communicate with N scenario application parties and M data providers, respectively, where N and M are positive integers; wherein... The application side uses it to send privacy computing requirement data to the transfer party; The relaying party is used to determine the privacy computing relay task based on the privacy computing requirement data sent by the scenario application party; send the privacy computing requirement data to the data provider according to the privacy computing relay task; and send the privacy computing result data fed back by the data provider to the scenario application party. The data provider performs corresponding operations on the privacy-computing request data, obtains the privacy-computing collaboration results, and sends the privacy-computing results data to the transfer party.
[0006] Secondly, embodiments of this application provide a data processing method applied to a relay in a data processing system as described in the first aspect. The relay communicates with N scenario application parties and M data providers, where N and M are positive integers. The data processing method may include: Receive privacy computing requirements data sent by the application users; Based on the privacy computing requirement data, determine the privacy computing transfer task; According to the privacy computing transfer task, send privacy computing requirement data to the data provider; Upon receiving privacy-computing results from the data provider, the privacy-computing results are sent to the application user.
[0007] Thirdly, embodiments of this application provide a data processing apparatus applied to a relay in a data processing system as described in the first aspect. The relay communicates with N scenario application parties and M data providers, where N and M are positive integers. The data processing apparatus may include: The receiving module is used to receive privacy computing requirement data sent by the application side in the scenario; The determination module is used to determine the privacy computing transfer task based on the privacy computing requirement data; The sending module is used to send privacy computing request data to the data provider in accordance with the privacy computing transfer task. The sending module is also used to send privacy computation result data to the application party when it receives privacy computation result data sent by the data provider.
[0008] Fourthly, embodiments of this application provide a computer device, which includes: a processor and a memory storing computer program instructions; When the processor executes computer program instructions, it implements the data processing method as shown in the second aspect.
[0009] Fifthly, embodiments of this application provide a computer storage medium storing computer program instructions, which, when executed by a processor, implement the data processing method as described in the second aspect.
[0010] In a sixth aspect, embodiments of this application provide a chip, which includes a processor and a communication interface. The communication interface and the processor are coupled, and the processor is used to run programs or instructions to implement the data processing method as shown in the second aspect.
[0011] In a seventh aspect, embodiments of this application provide a computer program product stored in a storage medium, which is executed by at least one processor to implement the data processing method as described in the second aspect.
[0012] The data processing system, method, apparatus, device, and storage medium of this application embodiment include a scenario application party, a data provider, and a relay party. The relay party communicates with N scenario application parties and M data providers, where N and M are positive integers. The scenario application party sends privacy computing request data to the relay party. The relay party determines a privacy computing relay task based on the received privacy computing request data from the scenario application party; sends privacy computing request data to the data providers according to the privacy computing relay task; and sends privacy computing result data fed back by the data providers to the scenario application party. The data provider performs corresponding operations on the privacy computing request data to obtain a privacy computing cooperation result and sends the privacy computing result data to the relay party. In this way, by using the intermediary as a unified hub, N scenario application parties and M data providers do not need to align interfaces, algorithm primitives, and security levels one by one, avoiding the N×M repetitive joint debugging required in the traditional model. They only need to complete a standardized connection with the intermediary to access the ecosystem. This breaks down heterogeneous barriers, enables large-scale cross-domain collaboration, solves the efficiency bottleneck of pairwise connections, significantly reduces the deployment cost and joint debugging cycle of cross-organizational collaboration, supports many-to-many large-scale data collaboration, and improves the communication efficiency between organizations. Moreover, relying on the standardized calling framework and reusable interfaces for privacy-preserving computation transfer tasks, new scenario application parties or data providers can quickly access the intermediary's ecosystem without modifying the existing platform architecture of each party, greatly improving the scalability and collaborative extensibility of cross-organizational privacy computation. Furthermore, the relaying party only serves as a hub for forwarding requests, coordinating tasks, and transmitting results. It does not access the original request data of the application scenario party, the original data of the data provider, or the intermediate calculation results. This avoids risks such as inadequate desensitization and data interception during cross-domain data transmission, complies with regulatory requirements for the protection of personal information and sensitive data, effectively resolves the trust barriers between application scenario parties and data providers, avoids issues such as unauthorized access and unauthorized use, and provides a safe and reliable environment for cross-organizational privacy computing cooperation. Attached Figure Description
[0013] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0014] Figure 1 This application provides a schematic diagram of the structure of a data processing system according to an embodiment of the present application. Figure 2 This application provides a schematic diagram of the structure of a data processing system according to an embodiment of the present application. Figure 3 A flowchart illustrating a data processing method based on a switching party, provided for an embodiment of this application; Figure 4 A schematic diagram of a data processing device based on a switching device is provided in an embodiment of this application; Figure 5 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation
[0015] The features and exemplary embodiments of various aspects of this application will be described in detail below. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain this application and not to limit it. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples.
[0016] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.
[0017] The acquisition, storage, use, and processing of data (including but not limited to features and information mentioned in this document) in the technical solution of this application all comply with the relevant provisions of national laws and regulations.
[0018] Privacy-preserving computation is gradually becoming a key technology for the circulation of data elements, and its usability without visibility is becoming the default configuration for data transactions. Industries such as finance, telecommunications, healthcare, and energy are leveraging privacy-preserving computation to build industry data spaces, driving the circulation of data elements. While privacy-preserving computation interoperability has enabled the connection and cooperation of heterogeneous privacy-preserving computation platforms, the interfaces, algorithm primitives, and security levels of various platforms differ significantly. Connections between different institutions have resulted in siloed "N×N" connections, leading to long debugging cycles, high maintenance costs, and severely hindering large-scale collaboration.
[0019] In data element circulation scenarios, cross-domain data cooperation often involves personal information and sensitive data. Inadequate anonymization or interception of transmission links can easily trigger regulatory penalties and public opinion risks. The deep integration of privacy-preserving computation and data circulation is becoming a core direction for solving compliance issues in cross-domain data cooperation. Through privacy-preserving computation technology and standardized application programming interfaces (APIs) for interconnectivity, heterogeneous platforms can be mapped to a unified semantic layer, enabling data to remain within its domain and models to run across multiple domains. In terms of policy and industrial development, data exchanges in various regions have adopted privacy-preserving computation as the default configuration in promoting data transactions where data is usable but not visible. Institutions in finance, telecommunications, healthcare, and energy are relying on privacy-preserving computation to build industry data spaces, forming a secure, compliant, efficient, and inclusive data element space.
[0020] Currently, one of the key pathways for data circulation is to use privacy-preserving computation as a technological foundation and a unifying link to connect data providers and application scenarios, forming a secure, reliable, and efficient data cooperation network and unlocking the value of data from all parties. The interoperability standards and application scenarios for privacy-preserving computation in the financial industry are developing rapidly. Cross-institutional data analysis scenarios, such as precision marketing, credit risk control, and data sharing, typically involve cooperation between two institutions.
[0021] In related technologies, cross-institutional privacy-preserving collaborative computation can be achieved based on a homogeneous platform. In this scheme, participating parties choose the same privacy-preserving computation platform, such as the open-source FATE, and collaborate through a unified underlying architecture, algorithm library, and interface standards. Each party only needs to deploy the same platform components locally; data does not need to leave the local machine. Model parameters or intermediate computation results are exchanged only through encrypted channels, enabling joint modeling or secure computation. This provides support for multiple institutions to achieve joint model training and inference without sharing raw data, protecting data privacy and security.
[0022] Alternatively, heterogeneous privacy computing platforms can collaborate based on an interoperability framework. In this solution, application parties in different scenarios, according to the published interoperability standard framework, enable minimum necessary interoperability at the system architecture level through standardized communication protocols, API interfaces, and algorithm component interaction specifications. This allows for reasonable parsing of each layer of the privacy computing system and collaborative computation of key components at each layer. Regarding API standardization, while ensuring standardization, space is reserved for flexible implementation of modules at different levels outside the interface, balancing compatibility with diversity. Through the interoperability framework, privacy computing platforms from different institutions and with different technical approaches can achieve data and algorithm collaboration, reducing the cost of redundant deployment across multiple platforms, improving efficiency through resource integration and algorithm reuse, and expanding the application boundaries and collaborative space of privacy computing.
[0023] However, while cross-institutional privacy computing collaboration based on homogeneous platforms can achieve data collaboration to a certain extent, it also exposes a series of thorny problems. First, there is a significant siloing phenomenon, with each institution building its own platform based on its own service needs, resulting in a lack of effective collaboration between platforms in terms of data and algorithms. Second, when institutions have diverse collaboration needs and need to connect with partner institutions using different privacy computing technologies, they face high costs for hardware procurement, software licensing, and maintenance, which also increases the complexity of technical management. Coordination work regarding version iteration, data interaction, and security protection between platforms consumes a significant amount of human and time resources, severely restricting the efficiency and scale of privacy computing collaboration.
[0024] While heterogeneous privacy computing platforms based on interoperability frameworks have solved the silo problem of traditional privacy computing and broken down platform barriers, they still face the challenge of pairwise integration. Because different privacy computing platforms are developed by different technical teams, their technical architectures, algorithm protocols, and interface standards vary significantly. The integration process requires adapting core modules such as platform management and scheduling, computing engines, and network transmission one by one. In practice, each new collaboration requires substantial technical investment and repeated platform testing. The integration cycle is long and costly, and even minor differences between platforms can lead to integration failures. This makes it difficult for a single organization to directly collaborate with multiple different partner organizations, reducing inter-organizational communication efficiency.
[0025] To address the aforementioned pain points, this application proposes a data processing system, method, apparatus, device, and storage medium. Building upon existing interconnectivity between heterogeneous privacy computing platforms, the design of initiators, relayers, and participants allows data providers and application users to connect only with the relayer according to interconnectivity standards. Through the relayer's data transfer and routing, any application user can flexibly collaborate with relevant data providers on privacy computing data, forming a new data transfer and collaboration model. This privacy computing data transfer method enables flexible data networking and collaboration, avoiding the need for joint debugging and connection between different institutions, and improving communication efficiency between institutions.
[0026] The following will be combined with the appendix Figures 1 to 5 This application describes in detail the data processing methods, apparatus, computer equipment, and storage media of the embodiments. It should be noted that these embodiments are not intended to limit the scope of this application.
[0027] Combination Figure 1 This is a schematic diagram of the structure of a data processing system provided in an embodiment of this application.
[0028] like Figure 1As shown, the data processing system may include scenario application parties, data providers, and relay parties. The relay parties communicate with N scenario application parties and M data providers, where N and M are positive integers. Scenario application parties can be financial institutions, such as banks, and the N scenario application parties can be N different types of financial institutions. Data providers can be at least one of the following: e-commerce platforms, third-party payment applications, or merchant institutions.
[0029] It should be noted that, as Figure 1 The scenario application party, the transfer party, and the data provider shown can all act as the initiator of privacy-preserving computation data requests, so as to complete the joint computation task through privacy-preserving computation application algorithms. In the embodiments of this application, at least one scenario application party is the initiator, and the privacy-preserving computation application algorithm is cooperated by the transfer party and at least one data provider for detailed explanation.
[0030] Specifically, in this embodiment, the scenario application party is used to send privacy computing requirement data to the relay party. For example, the initiating party is responsible for initiating data requests, providing original data sources, or privacy computing requirement data such as application algorithm computing tasks.
[0031] The relaying party is responsible for determining privacy computing relay tasks based on the privacy computing requirement data received from the application party; sending privacy computing requirement data to the data provider according to the privacy computing relay tasks; and sending privacy computing result data fed back by the data provider to the application party. For example, the relaying party can determine privacy computing relay tasks such as protocol conversion, data routing, and secure evidence storage auditing based on the privacy computing requirement data, and send the privacy computing requirement data to the data provider.
[0032] The data provider performs corresponding operations on the privacy-computing request data, obtains the privacy-computing collaboration results, and sends the privacy-computing results data to the transfer party.
[0033] Therefore, this application provides a standardized calling framework, based on existing standard interface specifications for interoperability of pairwise privacy computing, that connects heterogeneous scenario application parties and data providers through a central coordinating party. This framework enables cross-platform and cross-organizational data security collaboration, i.e., data transfer. Through this data processing system, scenario application parties and data providers can quickly access the transfer party's ecosystem via standardized and reusable interfaces for privacy computing transfer tasks, without modifying the existing platform architecture of any party. This significantly improves the scalability and collaborative extensibility of cross-organizational privacy computing, enabling the completion of the entire lifecycle process of discovery, negotiation, execution, settlement, and auditing.
[0034] In some embodiments of this application, the scenario application party is configured with an initiator privacy computing platform, the data provider is configured with a participant privacy computing platform, and the transfer party is configured with a transfer party privacy computing platform; wherein, the transfer party privacy computing platform communicates with the initiator privacy computing platform and the participant privacy computing platform respectively in accordance with the interconnection standard specifications.
[0035] In this way, based on the privacy computing interoperability standard, the privacy computing platforms of scenario application parties, data providers, and transfer parties can be divided into management layer, scheduling layer, and application algorithm layer.
[0036] Based on this, in some embodiments of this application, such as Figure 2 As shown, the interoperability privacy computing platform is configured with an interoperability management layer, an interoperability scheduling layer, and an interoperability application algorithm layer, all corresponding to the interoperability standard specifications. Specifically, the interoperability management layer connects to both the initiator's privacy computing platform and the participant's privacy computing platform; the interoperability scheduling layer connects to both the initiator's privacy computing platform and the participant's privacy computing platform; and the interoperability application algorithm layer connects to both the initiator's privacy computing platform and the participant's privacy computing platform.
[0037] Based on this, the switching party's management layer is used to manage the institutional and permission information of the N scenario application parties and M data providers accessing the switching party, as well as the node information and permission information of the service nodes in each scenario application party and each data provider. The service nodes in the scenario application parties can be different service departments under a financial institution.
[0038] Here, the management layer of the transfer party can be understood as the management of resource information and permission information, such as the management of institutions, nodes, datasets, projects, processes, jobs, models, and application algorithm components. It does not involve specific computation and data transmission. It is used to manage the objects participating in privacy computation, what resources they can use, and what permissions they have. It can realize the isolation of permissions for different application parties in different scenarios as well as the service departments of application parties in the same scenario, avoid unauthorized access, and manage sessions to ensure communication security and provide a data compliance foundation for subsequent collaboration.
[0039] The relay scheduling layer is located between the relay management layer and the relay application algorithm layer. It is used to determine privacy computing relay tasks based on privacy computing requirement data and information in the relay management layer. Privacy computing relay tasks include tasks for transmitting data related to privacy computing requirement data between the scenario application party and the data provider.
[0040] Here, the relay scheduling layer can be understood as task and collaboration management. It is a bridge connecting the relay management layer and the relay application algorithm layer. It can be used to transform privacy computing requirement data and information in the relay management layer into privacy computing relay tasks. Then, based on the privacy computing relay tasks, it executes the first task of calling the participant scheduling interface corresponding to the data provider to transmit data to the data provider, and the second task of calling the initiator scheduling interface corresponding to the scenario application to transmit data to the scenario application.
[0041] The relay application algorithm layer is used to perform operations for processing data with privacy computing requirements, and to transmit data related to privacy computing requirements between the application party and the data provider.
[0042] Here, the application algorithm layer of the switching party can run privacy-preserving computation primitives, including secure intersection such as PSI and ECDH-PSI, and joint modeling such as SecureBoost and SecureLR. Additionally, refer to... Figure 2 The application algorithm layer interactions between the application application provider, the relay provider, and the data provider can be communicated and invoked through the transmission module, including data sending, receiving, acquiring data, and session release. The transmission module provides a unified secure communication channel for the operation of application algorithms and forwards and manages the traffic of application algorithms.
[0043] Therefore, the transferor can achieve flexible calls between scenario application parties and data providers through API data transfer requests for institutions, nodes, data, projects, components, processes, tasks, models, application algorithms, and transmissions. This breaks down cross-institutional data collaboration between scenario application parties and data providers into multiple controllable, manageable, and auditable steps, such as establishing connections, discovering resources, requesting authorization, collaborative computing, and releasing resources. Ultimately, this achieves the goal of privacy-preserving, secure, and compliant collaboration between scenario application parties and data providers, where data is available but not visible, controllable, and measurable, thus forming a data circulation network.
[0044] In some embodiments of this application, the switching party management layer can interface with the initiating party management layer and the participating party management layer, enabling scenario application parties and data providers to access the switching party. Based on this, the switching party is further configured to: receive a first network access request sent by the scenario application party and a second network access request sent by the data provider; wherein the first network access request includes the initiating organization information of the scenario application party, the node information of the service nodes in the scenario application, and data usage intent data; the second network access request includes the participating party organization information of the data provider and the node information of the service nodes in the data provider; verify the identities of the scenario application party and the data provider respectively based on the first and second network access requests; and verify the compliance of the data usage based on the data usage intent data; and generate organization network access information if the identity and data usage compliance verification of the scenario application party and the data provider are passed, including authentication and session initialization information, which is used to verify communication between the initiating party interface of the scenario application party and the participating party interface of the data provider. The authentication and session initialization information includes at least one of the following: Token, Session, and Session parameters.
[0045] In this application embodiment, the organization information may include an organization identifier and organization identity credentials, wherein the organization identity credentials may include a digital certificate and an API key. Node information includes a node identifier and a node Uniform Resource Locator (URL) address.
[0046] In this application embodiment, the switching party can be used to verify the identity of the scenario application party and the data provider respectively through Certificate Authority (CA) certificate chain verification based on the first network access request and the second network access request, and to verify the compliance of the data usage based on the data usage intent data through CA certificate chain verification.
[0047] In some embodiments of this application, the scenario application party is used to send a first request to the transfer party through the initiator interface. The first request is used to query the list of data providers accessing the transfer party. If the list of data providers sent by the transfer party is received, the target data provider to be cooperated with is determined from the list of data providers. The second request is sent to the transfer party. The second request is a request to sign a contract with the target data provider. The relayer is used to send a second request to the target data provider; The target data provider is used to determine, based on the second request, whether to allow signing a contract with the scenario application provider; if it determines that signing a contract with the scenario application provider is allowed, it sends a first contract result to the transferor; if it determines that signing a contract with the scenario application provider is not allowed, it sends a second contract result to the transferor. The relaying party is also configured to, upon receiving a first signing result sent by the relaying party, send a first signing result to the scenario application party, wherein the first signing result is a result allowing the signing of a contract with the scenario application party; and, based on the first signing result, configure network information for transmitting data between the scenario application party and the data provider in the relaying party's application algorithm layer, and send a third request to the scenario application party and the data provider respectively, wherein the third request is configured to request the scenario application party to configure network information for transmitting data related to the data provider with the relaying party in the initiating party's application algorithm layer, and the third request is configured to request the data provider to configure network information for transmitting data related to the scenario application party with the relaying party in the participating party's application algorithm layer.
[0048] In addition, the relaying party is also used to send a second signing result to the scenario application party when it receives the second signing result sent by the relaying party. The second signing result is a result that does not allow signing a contract with the scenario application party.
[0049] It should be noted that the signing in this embodiment is an authorization step in the cross-domain privacy computing data transfer process to establish a legitimate collaborative relationship between the scenario application party and the data provider. In essence, it is a confirmation of collaborative intention and permission binding based on standardized interfaces and identity verification. It can be understood as a standardized and auditable technical process that enables the scenario application party and the data provider to establish a legitimate and mutually trusting collaborative relationship, providing a foundation for subsequent cross-domain privacy computing collaboration with legitimate identity, clear permissions, and controllable communication.
[0050] It should be noted that the docking in this embodiment refers to the architecture and interface adaptation process between platforms based on interoperability standards, which only occurs during the institution's network access phase. The connection in this embodiment refers to the encrypted communication link established based on authorization after docking is completed, used for data and instruction interaction in subsequent parameter negotiation, joint calculation, and other stages.
[0051] In this embodiment, the privacy-preserving computation-based data transfer collaboration achieves parameter negotiation and management between the application scenario provider and the data provider through various stages, including node request forwarding, dataset request forwarding, project request forwarding, and process and job management request forwarding. This enables the application scenario provider and the data provider to collaborate and complete the same privacy-preserving computation algorithm task through the transferor. Here, the privacy-preserving computation data transfer collaboration is implemented through an API interface provided by the transferor. No network connection needs to be established between the application scenario provider and the data provider. Both send data to the transferor. After receiving the requests from the application scenario provider and the data provider, the transferor first verifies the legitimacy of the API interface initiator's identity based on the organization's network access information. Secondly, it performs permission verification based on the application scenario provider and the data provider's information in the message. After successful verification, the API interface request is forwarded.
[0052] Based on this, the following section provides a detailed explanation of the negotiation of management layer parameters for the aforementioned node request forwarding, dataset request forwarding, project request forwarding, process and job management request forwarding, and other related processes. Here, "management layer" refers to the initiating party management layer, the relaying party management layer, and the participating party management layer.
[0053] In some embodiments of this application, the node request forwarding process is addressed.
[0054] The data provider is used to determine the data usage rights of the scenario application party based on the first contract result; and to store the association relationship between the data provider and the data meta information corresponding to the data usage rights of the scenario application party. The data meta information is not the original data itself, and the original data is the data corresponding to the data usage rights.
[0055] The scenario application party is used to send a fourth request to the forwarding party through the initiator's interface. The fourth request is used to query the data metadata information in the scenario application party that corresponds to the data usage permissions of the scenario application party.
[0056] The relaying party is used to send a fourth request to the scenario application party upon receiving the fourth request; and to send feedback data to the scenario application party upon receiving feedback data corresponding to the fourth request, wherein the feedback data includes data metadata.
[0057] For example, the scenario application party and the data provider sign an agreement. The scenario application party queries the relay party for information on scenario applications already connected to the interconnected ecosystem through the node information query API. After determining the required data provider, the scenario application party sends a cooperation agreement application to the scenario application party via the relay party through the initiator interface. The relay party determines the data provider information based on information such as organization ID and node ID, and sends the agreement application to the scenario application party. After receiving the application, the data provider can confirm the application information. After the data provider confirms, it will update the cooperation intention feedback to the relay party. The relay party then synchronizes the establishment of the cooperation relationship status to the scenario application party, thereby completing the agreement. Furthermore, after the agreement is completed, network management can be performed, that is, the scenario application party, the relay party, and the data provider need to configure the network information of their respective transmission module components to ensure the correct transmission of communication messages during application algorithm interaction.
[0058] In some embodiments of this application, the process of requesting and forwarding a dataset is addressed.
[0059] The data provider is also used to, upon receiving feedback data sent by the relaying party, determine the first data that the scenario application party is expected to use based on the data element information in the feedback data, where the data element information does not include the data element information corresponding to the first data; and send a fifth request to the relaying party, the fifth request being used to request the data provider to grant the scenario application party the data usage permission to use the first data; The relaying party is used to send a fifth request to the data provider upon receiving a fifth request; The data provider is used to determine, based on the fifth request, whether to grant the scenario application party data usage rights to use the first data.
[0060] For example, in data collaboration, each data provider needs to confirm available data resources and manage access permissions. That is, the data provider manages its own data resources and specifies which data providers can use the resources through institution IDs, node IDs, etc. For dataset list queries, after each data provider opens its own data resources to designated institution nodes, the application provider can query the data resource list from the data provider through the privacy computing platform via the public dataset list query API interface. The application provider returns data metadata, such as data name, field meaning, statistical characteristics, and data volume, but not the raw data itself, strictly adhering to the principle of data privacy. For dataset usage applications and approvals, after determining the required data resources, the application provider initiates a data usage application through the privacy computing platform via the dataset authorization API interface. Upon receiving the application, the application provider is granted access to the specific data resources, achieving minimal authorization.
[0061] In some embodiments of this application, the process of forwarding project requests is addressed.
[0062] The application side is used to send a sixth request to the transfer party. The sixth request includes the data usage intent of the project, the scope of use of the project data, the processing algorithm of the project data, and the expected processing result of the project data. The relaying party is also used to, based on privacy computing requirement data, determine the target scenario application party, the service node in the target scenario application party, the target data provider, and the service node in the target data provider for the joint processing project, and send a project joining application request to the target data provider. The project joining application request carries the content of the sixth request, which is used to request the target data provider and the service node in the target data provider to jointly process the project; and, upon receiving the joint result from the target data provider, send the joint result to the scenario application party. The target data provider receives project plus application requests sent by the transferor, determines whether joint processing of projects is allowed based on the project plus application requests, and sends the joint result to the transferor through the participant interface of the target data provider. The joint result includes a first joint result or a second joint result. The first joint result indicates that joint processing of projects is allowed, and the second joint result indicates that joint processing of projects is not allowed.
[0063] For example, the application provider can create a collaborative project and submit project information, such as data usage intent, scope, algorithm, expected output, and data provider, to the transferor through the project review application API interface. The transferor's privacy computing platform parses the initiator organization ID and node ID information, as well as the participant organization ID and node ID information, in the message and sends the application to invite participants to join the project to the application provider. After receiving the application, the data provider will forward the authorization result to the application provider through the transferor via the project approval confirmation API interface.
[0064] In some embodiments of this application, the process and job management request forwarding are addressed.
[0065] The scenario application party is used to create a collaborative process and operation parameters corresponding to the project upon receiving the first joint result from the target data provider. Through the initiator interface of the scenario application party, a seventh request is sent to the transfer party. The seventh request carries the collaborative process and operation parameters. The seventh request is used to request the target data provider to verify the collaborative process and operation parameters based on the content of the sixth request, and to determine the authorization and review result if the verification is successful. The relaying party is used to send the seventh request to the target data provider upon receiving the seventh request; and to send the authorization review result to the scenario application party upon receiving the authorization review result sent by the target data provider. The target data provider is used to verify the cooperation process and operational parameters based on the content in the sixth request; if the verification is successful, the authorization review result is determined and sent to the transferor.
[0066] For example, regarding the application and approval of collaborative processes and job management, after project approval, the scenario application party selects information such as data, data provider, and interoperability algorithm to create collaborative processes and job parameter configurations. It then forwards the process / job execution application to the scenario application party through a relayer via API interfaces such as process approval and job approval. The data provider verifies the scenario application party's identity, the data and algorithms used, and the process / job configuration. Once confirmed, the data provider forwards the authorization review result to the scenario application party through the relayer.
[0067] In the embodiments of this application, the scheduling layer algorithm and job configuration can be configured.
[0068] In some embodiments of this application, the focus is on the job creation phase.
[0069] Privacy computing requirement data includes job creation requirement data; privacy computing transfer tasks include the first task of calling the participant scheduling interface corresponding to the data provider to transmit data to the data provider, and the second task of calling the initiator scheduling interface corresponding to the scenario application to transmit data to the scenario application. The application side is used to generate a job identifier upon receiving a job creation instruction; and to send job creation requirement data, including the job identifier, to the transfer party. The relaying party is used to determine the first task based on the job creation requirement data sent by the scenario application party; and to send the job creation requirement data to the data provider through the participant scheduling interface; and to determine the second task based on the permission to create a job sent by the data provider, and to send the permission to create a job to the scenario application party through the initiator scheduling interface. The data provider is responsible for verifying the job creation requirement data sent by the transferor, creating the job file if the verification is successful, and sending the result of permission to create the job to the transferor.
[0070] For example, after the process and job management review is completed, the scenario application party creates the job and generates a job ID. The scenario application party can send a job creation request, carrying the job ID, to all data providers in the process and job through a transfer channel. Each scenario application party verifies the job creation request, and creates the job based on the job ID after confirming that it is correct.
[0071] In some embodiments of this application, the focus is on the startup phase.
[0072] Privacy-preserving computing requirements data also includes job startup requirements data; The application side is used to send job creation request data to the transferor after receiving the permission to create a job from the transferor. The relay is used to send the job start request data to the data provider through the participant scheduling interface when it receives the job start request data sent by the scenario application party; and to send the job start permission result to the scenario application party through the initiator scheduling interface when it receives the job start permission result sent by the data provider. The data provider is responsible for verifying the job start request data sent by the transferor, starting the job file if the verification is successful, and sending the result of allowing the job to start to the transferor.
[0073] For example, after each data provider completes the job creation, the initiator sends a job start request to each data provider via a relay. Each application scenario party reviews the job start request and returns the review result to the application scenario party via the relay.
[0074] In some embodiments of this application, the focus is on the operation phase.
[0075] Privacy-preserving computing requirements also include job execution requirements data; The scenario application party is used to send job execution requirement data to the relay party after receiving the result of permission to start the job from the relay party; and to load the algorithm image for processing job parameters through the interconnection algorithm image of the scenario application party, start the privacy computing joint operation algorithm; and process the job parameters of the job through the privacy computing joint operation algorithm. The relay is used to send job execution requirement data to the data provider through the participant scheduling interface after receiving job execution requirement data sent by the scenario application party. The data provider is responsible for verifying the job execution requirement data sent by the transferor. If the verification is successful, the data provider loads the algorithm image for processing job parameters through the interconnection algorithm image, starts the privacy computing joint operation algorithm, and runs the job file through the privacy computing joint operation algorithm.
[0076] For example, after each data provider's job application is approved, the scenario application party initiates a job execution instruction, which is then sent to each data provider via a relay. If the process is asynchronous, each data provider will only request the instruction once. The scenario application party and each data provider will parse the process and job parameter configuration, load the algorithm image based on the relay's proprietary interoperability algorithm image, and start their own privacy computing joint operation algorithm.
[0077] In some embodiments of this application, the focus is on the query job execution phase.
[0078] Privacy-preserving computing requirements also include query job execution requirements; The application side uses the initiator's interface to send query job execution requirement data to the transferor; The relay is used to send query job execution requirement data to the data provider through the participant scheduling interface when it receives query job execution requirement data sent by the scenario application party; and to send job status information to the scenario application party through the initiator scheduling interface when it receives job status information of the running job file sent by the data provider. The data provider, upon receiving query job execution request data, sends job status information of the job execution file to the transferor through the participant interface.
[0079] For example, after the interconnection algorithm between the scenario application parties and each scenario application party is started, the scenario application party queries the status of the job task and other callback information through the query interface and the relay party through the relay party. The relay party's scheduling layer plays the role of synchronizing and coordinating the task status in this process, without touching any plaintext data or intermediate calculation results.
[0080] In some embodiments of this application, the scenario application party is used to send, in sequence, a job release request, a project release request, a permission information release request, and a data unbinding request between the scenario application party and the data provider when it is determined that the job has been completed. The relaying party is used to unbind the data relationship between the scenario application party and the data provider when it receives a request from the data provider to unbind a job, a project, a permission information, or a request to unbind data exchanged between the scenario application party and the data provider; and to forward the request to the data provider in sequence to the data provider. The data provider is responsible for performing unbinding operations when it receives requests from the transferor to unbind jobs, projects, permission information, or data exchanged between the scenario application and the data provider.
[0081] For example, regarding resource release and project termination, after the interoperability algorithm task is completed, the results need to be managed and resources released. The scenario application party, scenario application party, or transfer party can release authorization and terminate binding relationships step by step through APIs such as project approval termination, data permission termination, and process approval termination.
[0082] In some embodiments of this application, the switching party privacy computing platform further includes an audit layer for recording the switching party's operational behavior as an intermediary in transmitting and / or processing data exchanged between the application party and the data provider, and generating audit logs.
[0083] This enables real-time auditing, ensuring that collaborations are auditable and traceable.
[0084] Based on this, the data processing system provided in this application embodiment can be applied to the following technical scenarios: Firstly, in algorithm data transfer scenarios. Specifically, after the application party and various data providers interconnect and run the algorithm, they call the transmission module through the transmission API interface. Based on node signing and network configuration information, data transmission communication is forwarded through the transferor's transmission module. The transferor's transmission module performs load balancing based on data traffic and bandwidth to ensure that data transfer cooperation between different institutions does not affect each other. Secondly, in model and result processing. Specifically, trained models can be managed through model interoperability APIs, such as applying for model export, model review applications, and querying model attributes. All of these are transferred through the transferor, and the review results are returned.
[0085] This breaks down heterogeneous barriers, enabling large-scale cross-domain collaboration and resolving efficiency bottlenecks in pairwise connections. By using the intermediary as a unified hub, N application scenarios and M data providers no longer need to align interfaces, algorithm primitives, and security levels individually, avoiding the N×M repetitive integration tests required in traditional models. They only need to complete a standardized connection with the intermediary to access the ecosystem, significantly reducing deployment costs and integration cycles for cross-institutional collaboration and supporting large-scale many-to-many data cooperation. Furthermore, relying on a standardized calling framework and reusable API interfaces, new application scenarios, such as adding banking institutions, or data providers, such as adding e-commerce platforms, can quickly access the intermediary's ecosystem without modifying the existing platform architecture of each party, greatly enhancing the scalability and collaborative extensibility of the data element market.
[0086] Furthermore, the transferor only serves as a hub for forwarding requests, coordinating tasks, and transmitting results. It does not access the original request data of the application scenario party, the original data of the data provider, or the intermediate calculation results. This avoids risks such as inadequate anonymization and data interception during cross-domain data transmission, complies with regulatory requirements for the protection of personal information and sensitive data, avoids privacy risks, adheres to the principle of data usability without visibility, and can also achieve full lifecycle compliance and traceability, namely a closed-loop process of discovery-negotiation-execution-settlement-audit. The transferor can fully record the operational behavior of the three parties, such as request submission, task allocation, data processing, and result feedback, forming a traceable audit link to ensure that every link of cross-organizational collaboration is controllable and traceable, reducing regulatory penalties and public opinion risks.
[0087] Furthermore, application users do not need to communicate and negotiate with multiple data providers individually; they only need to submit a privacy computation request once to the transferor, which can then handle task matching, data coordination, and result aggregation, significantly reducing cross-institutional communication costs and operational complexity. Simultaneously, standardized interfaces and processes avoid compatibility conflicts between heterogeneous platforms, reducing the failure rate and troubleshooting costs. It should be noted that the data processing system provided in this application embodiment is applicable to cross-domain data collaboration scenarios in multiple industries such as finance, telecommunications, and healthcare. Through an efficient and secure privacy computation transfer mechanism, it enables data resources scattered across different institutions to achieve value complementarity under compliant conditions.
[0088] Furthermore, as an intermediary coordinator, the transferor can conduct dual verification of the legality of the application party's needs and the compliance of the data provider's operations, ensuring that the data usage intent complies with laws and regulations and the agreements between the parties. At the same time, based on process records, it can achieve measurement and statistics on dimensions such as data usage and computing resource consumption, providing a basis for subsequent steps such as settlement and revenue sharing, protecting the rights and interests of all parties, effectively solving the trust barrier between the application party and the data provider, avoiding problems such as unauthorized access and unauthorized use, and providing a safe and reliable environment for cross-institutional privacy computing cooperation.
[0089] Next, combined Figure 1 and Figure 2 The data processing system in this application provides a detailed description of a data processing method based on a switching party, as provided in the embodiments of this application.
[0090] Figure 3 This is a flowchart illustrating a data processing method provided in an embodiment of this application.
[0091] like Figure 3 As shown, applied to, for example Figure 1 and Figure 2 The data processing system shown has a relay that communicates with N scenario application parties and M data providers, where N and M are positive integers. Based on this, the data processing method can specifically include the following steps: Step 310: Receive privacy computing requirement data sent by the scenario application party; Step 320: Determine the privacy computing transfer task based on the privacy computing requirement data; Step 330: Send the privacy computing requirement data to the data provider according to the privacy computing transfer task; Step 340: If the privacy computing result data sent by the data provider is received, send the privacy computing result data to the scenario application party.
[0092] Therefore, to address the issue of low efficiency in interconnecting and collaborating heterogeneous privacy-preserving computing platforms among various institutions, this proposal suggests a data transfer method based on privacy-preserving computing interconnection. By connecting each participating party to the privacy-preserving computing platform, and enabling institutions to join the network via the platform, data routing and forwarding are achieved through management layer parameter configuration, scheduling layer algorithm and job configuration, and application algorithm layer communication transmission. This allows the initiator and participating parties to conduct secure intersection and joint modeling collaborations in privacy-preserving computing without establishing a network connection. Through the flexible configuration of the privacy-preserving computing platform, identity verification and privacy-preserving computing collaboration among participating parties are achieved, enabling scenario-based application providers such as banks to collaborate with multiple data provider platforms, and data providers to flexibly connect with multiple scenario-based application providers, providing a fundamental solution for the construction of a privacy-preserving computing data network.
[0093] The steps described above are explained in detail below.
[0094] In some embodiments of this application, the switching party is configured with a switching party privacy computing platform; the scenario application party is configured with an initiating party privacy computing platform, and the data provider is configured with a participating party privacy computing platform. The switching party privacy computing platform communicates with the initiating party privacy computing platform and the participating party privacy computing platform respectively in accordance with the interconnection standard specifications.
[0095] In some embodiments of this application, the switching party privacy computing platform is configured with a switching party management layer, a switching party scheduling layer, and a switching party application algorithm layer that correspond to the interoperability standard specifications. Specifically, the transfer party management layer is connected to the initiator management layer in the initiator privacy computing platform and the participant management layer in the participant privacy computing platform, respectively; the transfer party scheduling layer is connected to the initiator scheduling layer in the initiator privacy computing platform and the participant scheduling layer in the participant privacy computing platform, respectively; and the transfer party application algorithm layer is connected to the initiator application algorithm layer in the initiator privacy computing platform and the participant application algorithm layer in the participant privacy computing platform, respectively. The transfer management layer is used to manage the organizational and permission information of N scenario application parties and M data providers accessing the transfer layer, as well as the node and permission information of service nodes in each scenario application party and service nodes in each data provider. The relay scheduling layer is set between the relay management layer and the relay application algorithm layer. It is used to determine the privacy computing relay task based on the privacy computing requirement data and the information in the relay management layer. The privacy computing relay task includes the task of transmitting data related to the privacy computing requirement data between the scenario application party and the data provider. The relay application algorithm layer is used to perform operations for processing data with privacy computing requirements, and to transmit data related to privacy computing requirements between the application party and the data provider.
[0096] In some embodiments of this application, the switching party privacy computing platform further includes an audit layer for recording the switching party's operational behavior as an intermediary in transmitting and / or processing data exchanged between the application party and the data provider, and generating audit logs.
[0097] In some embodiments of this application, the data processing method may further include: The system receives a first network access request from the application scenario provider and a second network access request from the data provider. The first network access request includes the initiating organization information of the application scenario provider, the node information of the service nodes in the application scenario, and the data usage intent data. The second network access request includes the participating organization information of the data provider and the node information of the service nodes in the data provider. Based on the first and second network access requests, verify the identities of the scenario application party and the data provider respectively; and based on the data usage intent data, verify the compliance of the data usage. Once the compliance verification of the identity and data usage of the scenario application party and the data provider is passed, the organization access information is generated. The organization access information includes authentication and session initialization information. The organization access information is used to verify the communication between the initiator interface of the scenario application party and the participant interface of the data provider.
[0098] In some embodiments of this application, the data processing method may further include: The system receives the first request sent by the application side of the scenario. The first request is used to query the list of data providers of the access transfer party. Send a list of data providers to the application users in the scenario; Upon receiving a second request from the application provider, the second request is a request to sign a contract with the target data provider; Send a second request to the target data provider; Receive the first signing result sent by the relay party; Send the first signing result to the scenario application party. The first signing result is the result that allows signing a contract with the scenario application party. In addition, based on the first signing result, network information for transmitting data between the application party and the data provider is configured in the algorithm layer of the transfer party's application. A third request is sent to both the scenario application party and the data provider. The third request is used to request the scenario application party to configure network information for transmitting data related to the data provider to the relay party in the application algorithm layer of the initiating party. The third request is also used to request the data provider to configure network information for transmitting data related to the scenario application party to the relay party in the application algorithm layer of the participating party.
[0099] In some embodiments of this application, the data processing method may further include: Receive the fourth request sent by the scenario application party; the fourth request is used to request the query of data metadata corresponding to the data usage permissions of the scenario application party. Send a fourth request to the application provider; and, upon receiving feedback data corresponding to the fourth request, send feedback data to the application provider, the feedback data including data metadata.
[0100] In some embodiments of this application, the data processing method may further include: Receive a fifth request sent by the data provider. The fifth request is used to request the data provider to grant the scenario application party the data usage permission to use the first data. Send a fifth request to the data provider.
[0101] In some embodiments of this application, the data processing method may further include: Receive the seventh request sent by the scenario application party. The seventh request is used to request the target data provider to verify the cooperation process and operation parameters based on the content of the sixth request, and determine the authorization review result if the verification is successful. Send a seventh request to the target data provider; Upon receiving the authorization review result from the target data provider, the authorization review result is sent to the application user.
[0102] In some embodiments of this application, privacy computing requirement data includes job creation requirement data; privacy computing transfer tasks include a first task of calling the participant scheduling interface corresponding to the data provider to transmit data to the data provider and a second task of calling the initiator scheduling interface corresponding to the scenario application to transmit data to the scenario application. Step 320: Based on the privacy computing requirement data, determine that the privacy computing transfer task may specifically include: Based on the job creation requirement data sent by the scenario application party, determine the first task; Step 330: According to the privacy computing transfer task, send the privacy computing requirement data to the data provider, including: The task creation requirement data is sent to the data provider through the participant scheduling interface; Step 340: Upon receiving the privacy computation result data from the data provider, send the privacy computation result data to the application provider, including: Upon receiving permission from the data provider to create a job, determine the second task; The initiator sends the result allowing job creation to the application side via the scheduling interface.
[0103] In some embodiments of this application, the privacy computing requirement data also includes job startup requirement data; Step 330: According to the privacy computing transfer task, send the privacy computing requirement data to the data provider, including: Based on the startup job requirement data sent by the scenario application party, the startup job requirement data is sent to the data provider through the participant scheduling interface; Step 340: Upon receiving the privacy computation result data from the data provider, send the privacy computation result data to the application provider, including: Upon receiving the permission to start the job from the data provider, the system sends the permission to start the job to the application user through the initiator's scheduling interface.
[0104] In some embodiments of this application, the privacy computing requirement data also includes job execution requirement data; Step 330: According to the privacy computing transfer task, send the privacy computing requirement data to the data provider, including: Upon receiving job execution requirement data from the application scenario provider, the system sends the job execution requirement data to the data provider through the participant scheduling interface.
[0105] In some embodiments of this application, the privacy computing requirement data also includes query job execution requirement data; Step 330: According to the privacy computing transfer task, send the privacy computing requirement data to the data provider, including: Upon receiving query job execution requirement data from the scenario application party, the query job execution requirement data is sent to the data provider through the participant scheduling interface; Step 340: Upon receiving the privacy computation result data from the data provider, send the privacy computation result data to the application provider, including: Upon receiving the job status information of the running job file sent by the data provider, the job status information is sent to the application user through the initiator's scheduling interface.
[0106] In some embodiments of this application, the data processing method may further include: Upon receiving requests from the data provider to unbind tasks, projects, permission information, or data exchanged between the scenario application provider and the data provider, the relationship between the data exchanged between the scenario application provider and the data provider shall be unbound. The system forwards requests to the data provider in sequence to release the job, the project, the permission information, and the data unbinding requests between the application scenario provider and the data provider.
[0107] This breaks down heterogeneous barriers, enabling large-scale cross-domain collaboration and resolving efficiency bottlenecks in pairwise connections. By using the intermediary as a unified hub, N application scenarios and M data providers no longer need to align interfaces, algorithm primitives, and security levels individually, avoiding the N×M repetitive integration tests required in traditional models. They only need to complete a standardized connection with the intermediary to access the ecosystem, significantly reducing deployment costs and integration cycles for cross-institutional collaboration and supporting large-scale many-to-many data cooperation. Furthermore, relying on a standardized calling framework and reusable API interfaces, new application scenarios, such as adding banking institutions, or data providers, such as adding e-commerce platforms, can quickly access the intermediary's ecosystem without modifying the existing platform architecture of each party, greatly enhancing the scalability and collaborative extensibility of the data element market.
[0108] Furthermore, the transferor only serves as a hub for forwarding requests, coordinating tasks, and transmitting results. It does not access the original request data of the application scenario party, the original data of the data provider, or the intermediate calculation results. This avoids risks such as inadequate anonymization and data interception during cross-domain data transmission, complies with regulatory requirements for the protection of personal information and sensitive data, avoids privacy risks, adheres to the principle of data usability without visibility, and can also achieve full lifecycle compliance and traceability, namely a closed-loop process of discovery-negotiation-execution-settlement-audit. The transferor can fully record the operational behavior of the three parties, such as request submission, task allocation, data processing, and result feedback, forming a traceable audit link to ensure that every link of cross-organizational collaboration is controllable and traceable, reducing regulatory penalties and public opinion risks.
[0109] Furthermore, application users do not need to communicate and negotiate with multiple data providers individually; they only need to submit a privacy computation request once to the transferor, which can then handle task matching, data coordination, and result aggregation, significantly reducing cross-institutional communication costs and operational complexity. Simultaneously, standardized interfaces and processes avoid compatibility conflicts between heterogeneous platforms, reducing the failure rate and troubleshooting costs. It should be noted that the data processing system provided in this application embodiment is applicable to cross-domain data collaboration scenarios in multiple industries such as finance, telecommunications, and healthcare. Through an efficient and secure privacy computation transfer mechanism, it enables data resources scattered across different institutions to achieve value complementarity under compliant conditions.
[0110] Furthermore, as an intermediary coordinator, the transferor can conduct dual verification of the legality of the application party's needs and the compliance of the data provider's operations, ensuring that the data usage intent complies with laws and regulations and the agreements between the parties. At the same time, based on process records, it can achieve measurement and statistics on dimensions such as data usage and computing resource consumption, providing a basis for subsequent steps such as settlement and revenue sharing, protecting the rights and interests of all parties, effectively solving the trust barrier between the application party and the data provider, avoiding problems such as unauthorized access and unauthorized use, and providing a safe and reliable environment for cross-institutional privacy computing cooperation.
[0111] Based on the same inventive concept, this application also provides a data processing device. (Specifically combined with...) Figure 4 Please provide a detailed explanation.
[0112] Figure 4 This is a schematic diagram of a data processing device based on a switching device, provided as an embodiment of this application.
[0113] like Figure 4 As shown, the data processing device 40 may specifically include: The receiving module is used to receive privacy computing requirement data sent by the application side in the scenario; The determination module is used to determine the privacy computing transfer task based on the privacy computing requirement data; The sending module is used to send privacy computing request data to the data provider in accordance with the privacy computing transfer task. The sending module is also used to send privacy computation result data to the application party when it receives privacy computation result data sent by the data provider.
[0114] Thus, the data processing device in this embodiment of the application, using the transferor as a unified hub, eliminates the need for N scenario application parties and M data providers to align interfaces, algorithm primitives, and security levels one by one, avoiding the N×M repetitive joint debugging required in the traditional model. They only need to complete a standardized connection with the transferor once to access the ecosystem, breaking down heterogeneous barriers and enabling large-scale cross-domain collaboration. This solves the efficiency bottleneck of pairwise connections, significantly reduces the deployment cost and joint debugging cycle of cross-organizational collaboration, supports many-to-many large-scale data cooperation, and improves communication efficiency between organizations. Furthermore, relying on the standardized calling framework and reusable interfaces for privacy-preserving computation transfer tasks, new scenario application parties or data providers can quickly access the transferor's ecosystem without modifying the existing platform architecture of each party, greatly enhancing the scalability and collaborative extensibility of cross-organizational privacy computation. Furthermore, the relaying party only serves as a hub for forwarding requests, coordinating tasks, and transmitting results. It does not access the original request data of the application scenario party, the original data of the data provider, or the intermediate calculation results. This avoids risks such as inadequate desensitization and data interception during cross-domain data transmission, complies with regulatory requirements for the protection of personal information and sensitive data, effectively resolves the trust barriers between application scenario parties and data providers, avoids issues such as unauthorized access and unauthorized use, and provides a safe and reliable environment for cross-organizational privacy computing cooperation.
[0115] Based on the same inventive concept, this application also provides a computer device. (Specifically combined with...) Figure 5 Please provide a detailed explanation.
[0116] Figure 5 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application.
[0117] like Figure 5 As shown, the computer device may include at least one of the following as described in the embodiments of this application: a client computer device and a server computer device. The computer device may include a processor 501 and a memory 502 storing computer program instructions.
[0118] Specifically, the processor 501 may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.
[0119] Memory 502 may include a large-capacity memory for data or instructions. For example, and not limitingly, memory 502 may include a hard disk drive (HDD), a floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or a Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 502 may include removable or non-removable (or fixed) media. Where appropriate, memory 502 may be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, memory 502 is non-volatile solid-state memory. In a particular embodiment, memory 502 includes solid-state storage (ROM). Where appropriate, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically rewritable ROM (EAROM), or flash memory, or a combination of two or more of these.
[0120] The processor 501 implements any of the data processing methods described in the above embodiments by reading and executing computer program instructions stored in the memory 502.
[0121] In one example, the computer device may also include a communication interface 503 and a bus 510. Wherein, as... Figure 5 As shown, the processor 501, memory 502, and communication interface 503 are connected through bus 510 and complete communication with each other.
[0122] The communication interface 503 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.
[0123] Bus 510 includes hardware, software, or both, that couples components of a flow control device together. For example, and not limitingly, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 510 may include one or more buses. Although specific buses are described and illustrated in embodiments of this application, any suitable bus or interconnect is contemplated herein.
[0124] The computer device can execute the data processing method described in the embodiments of this application, thereby achieving the combination Figures 1 to 5 The data processing methods and apparatus described.
[0125] Furthermore, in conjunction with the data processing methods in the above embodiments, this application embodiment can provide a computer-readable storage medium for implementation. This computer-readable storage medium stores computer program instructions; when these computer program instructions are executed by a processor, they implement any of the data processing methods in the above embodiments.
[0126] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.
[0127] The functional blocks shown in the above block diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.
[0128] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.
[0129] The above are merely specific embodiments of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.
Claims
1. A data processing system, characterized in that, include: The system comprises scenario application providers, data providers, and relay providers, with the relay provider communicating with N scenario application providers and M data providers, where N and M are positive integers; where... The application party in the scenario is used to send privacy computing requirement data to the transfer party; The transferor is configured to determine a privacy computing transfer task based on the privacy computing requirement data sent by the scenario application party; send the privacy computing requirement data to the data provider according to the privacy computing transfer task; and send the privacy computing result data fed back by the data provider to the scenario application party. The data provider is used to perform corresponding operations on the privacy computing requirement data, obtain the privacy computing cooperation result, and send the privacy computing result data to the transfer party.
2. The system according to claim 1, characterized in that, The application party in the scenario is configured with an initiator privacy computing platform, the data provider is configured with a participant privacy computing platform, and the transfer party is configured with a transfer party privacy computing platform; The privacy computing platform of the relaying party communicates with the privacy computing platform of the initiating party and the privacy computing platform of the participating party in accordance with the interoperability standard specifications.
3. The system according to claim 2, characterized in that, The switching party privacy computing platform is configured with a switching party management layer, a switching party scheduling layer, and a switching party application algorithm layer corresponding to the interoperability standard specification; Specifically, the switching party management layer is connected to both the initiator management layer in the initiator privacy computing platform and the participant management layer in the participant privacy computing platform; the switching party scheduling layer is connected to both the initiator scheduling layer in the initiator privacy computing platform and the participant scheduling layer in the participant privacy computing platform; and the switching party application algorithm layer is connected to both the initiator application algorithm layer in the initiator privacy computing platform and the participant application algorithm layer in the participant privacy computing platform. The switching management layer is used to manage the organizational information and permission information of N scenario application parties and M data providers accessing the switching layer, and to manage the node information and permission information of service nodes in each scenario application party and service nodes in each data provider. The switching party scheduling layer is located between the switching party management layer and the switching party application algorithm layer. It is used to determine the privacy computing switching task based on the privacy computing requirement data and the information in the switching party management layer. The privacy computing switching task includes a task for transmitting data related to the privacy computing requirement data between the scenario application party and the data provider. The switching party's application algorithm layer is used to perform operations to process the privacy computing requirement data, and to transmit data related to the privacy computing requirement data between the scenario application party and the data provider.
4. The system according to claim 2 or 3, characterized in that, The privacy computing platform of the switching party also includes an audit layer, which is used to record the operation behavior of the switching party as an intermediary in transmitting and / or processing the data exchanged between the scenario application party and the data provider, and generate audit logs.
5. The system according to claim 1, characterized in that, The switching party is further configured to receive a first network access request sent by the scenario application party and a second network access request sent by the data provider; wherein, the first network access request includes the initiating organization information of the scenario application party, the node information of the service nodes in the scenario application, and data usage intent data; the second network access request includes the participating organization information of the data provider and the node information of the service nodes in the data provider. Based on the first network access request and the second network access request, verify the identities of the scenario application party and the data provider respectively; and, based on the data usage intent data, verify the compliance of the data usage. Once the identity verification of the scenario application party and the data provider and the compliance verification of the data usage are passed, the organization access information is generated. The organization access information includes authentication and session initialization information. The organization access information is used to verify the communication between the initiator interface of the scenario application party and the participant interface of the data provider.
6. The system according to claim 5, characterized in that, The application party in the scenario is used to send a first request to the transfer party through the initiator interface. The first request is used to query the list of data providers that can access the transfer party. Upon receiving the list of data providers sent by the transfer party, the application party determines the target data provider to be cooperated with from the list of data providers. Send a second request to the transferor, the second request being a request to sign a contract with the target data provider; The relaying party is used to send the second request to the target data provider; Upon receiving the first signing result sent by the transferor, the first signing result is sent to the scenario application party, wherein the first signing result is a result that allows signing with the scenario application party; Furthermore, the switching party is also configured, based on the first signing result, to configure network information in the switching party's application algorithm layer for transmitting data between the scenario application party and the data provider, and to send a third request to the scenario application party and the data provider respectively. The third request is used to request the scenario application party to configure network information in the initiating party's application algorithm layer for transmitting data related to the data provider with the switching party, and the third request is used to request the data provider to configure network information in the participating party's application algorithm layer for transmitting data related to the scenario application party with the switching party.
7. The system according to claim 6, characterized in that, The data provider is used to determine the data usage rights of the scenario application party based on the first signing result; and to store the association relationship between the data provider and the data metadata corresponding to the data usage rights of the scenario application party, wherein the data metadata is not the original data itself, and the original data is the data corresponding to the data usage rights; The scenario application party is used to send a fourth request to the forwarding party through the initiator interface. The fourth request is used to request to query the data meta information in the scenario application party that corresponds to the data usage permission of the scenario application party. The relaying party is configured to send the fourth request to the scenario application party upon receiving the fourth request; and to send the feedback data to the scenario application party upon receiving feedback data corresponding to the fourth request, wherein the feedback data includes the data metadata.
8. The system according to claim 7, characterized in that, The data provider is also used to determine the first data that the scenario application party is expected to use based on the data element information in the feedback data when receiving feedback data sent by the transfer party, wherein the data element information does not include the data element information corresponding to the first data; A fifth request is sent to the transfer party, the fifth request being used to request the data provider to grant the scenario application party data usage rights to use the first data; The relaying party is used to send the fifth request to the data provider upon receiving the fifth request; The data provider is used to determine, based on the fifth request, whether to grant the scenario application party data usage permission to use the first data.
9. The system according to claim 3, characterized in that, The scenario application party is used to send a sixth request to the transfer party. The sixth request includes data usage intent data of the project, the scope of use of the project data, the processing algorithm of the project data, and the expected processing result of the project data. The transfer party is further configured to, based on the privacy computing requirement data, determine the target scenario application party, the service node in the target scenario application party, the target data provider, and the service node in the target data provider for jointly processing the project, and send a project joining application request to the target data provider, the project joining application request carrying the content of the sixth request, for requesting the target data provider and the service node in the target data provider to jointly process the project; and, upon receiving the joint result fed back by the target data provider, send the joint result to the scenario application party; The target data provider is configured to receive a project plus application request sent by the transferor, determine whether joint processing of the project is allowed based on the project plus application request, and send the joint result to the transferor through the participant interface of the target data provider. The joint result includes a first joint result or a second joint result, wherein the first joint result indicates that joint processing of the project is allowed, and the second joint result indicates that joint processing of the project is not allowed.
10. The system according to claim 9, characterized in that, The scenario application party is used to create a collaborative process and operation parameters corresponding to the project upon receiving the first joint result sent by the target data provider. Through the initiator interface of the application scenario, a seventh request is sent to the transferor. The seventh request carries the cooperation process and operation parameters. The seventh request is used to request the target data provider to verify the cooperation process and operation parameters based on the content of the sixth request, and determine the authorization review result if the verification is successful. The relaying party is configured to send the seventh request to the target data provider upon receiving the seventh request; And, upon receiving the authorization review result from the target data provider, send the authorization review result to the scenario application party; The target data provider is used to verify the cooperation process and operation parameters based on the content of the sixth request; if the verification is successful, the authorization review result is determined and sent to the transfer party.
11. The system according to claim 3, characterized in that, The privacy computing requirement data includes job creation requirement data; the privacy computing transfer task includes a first task of calling the participant scheduling interface corresponding to the data provider to transmit data to the data provider, and a second task of calling the initiator scheduling interface corresponding to the scenario application party to transmit data to the scenario application party; The application party in the scenario is used to generate a job identifier for the job upon receiving a job creation instruction; Send job creation request data, including the job identifier, to the receiving party; The relaying party is used to determine the first task based on the job creation requirement data sent by the scenario application party. And through the participant scheduling interface, send the job creation requirement data to the data provider; upon receiving the permission to create a job sent by the data provider, determine the second task, and send the permission to create a job to the scenario application party through the initiator scheduling interface; The data provider is used to verify the job creation requirement data sent by the transfer party upon receiving the job creation requirement data, and to create the job file if the verification is successful. And send the result allowing the creation of the job to the transfer party.
12. The system according to claim 11, characterized in that, The privacy computing requirements data also include job startup requirements data; The application party in the scenario is used to send the job creation requirement data to the transfer party when it receives the job creation permission result sent by the transfer party; The relaying party is configured to, upon receiving the job startup requirement data sent by the scenario application party, send the job startup requirement data to the data provider through the participant scheduling interface; and upon receiving the job startup permission result sent by the data provider, send the job startup permission result to the scenario application party through the initiator scheduling interface. The data provider is configured to verify the job start request data upon receiving it from the transfer party, and to start the job file if the verification is successful. And send the permission to start the job to the transfer party.
13. The system according to claim 12, characterized in that, The privacy computing requirements data also include job execution requirements data; The scenario application party is configured to send the job execution requirement data to the transfer party upon receiving the job start permission result sent by the transfer party; and to load the algorithm image for processing the job parameters through the interconnection algorithm image of the scenario application party, start the privacy computing joint operation algorithm; and process the job parameters of the job through the privacy computing joint operation algorithm. The relaying party is used to send the job operation requirement data to the data provider through the participant scheduling interface when it receives the job operation requirement data sent by the scenario application party. The data provider is configured to verify the job execution requirement data upon receiving it from the transfer party, and if the verification is successful, load the algorithm image for processing the job parameters through the data provider's interconnection algorithm image, start the privacy computing joint operation algorithm, and run the job file through the privacy computing joint operation algorithm.
14. The system according to claim 13, characterized in that, The privacy computing requirements data also include query job execution requirements data; The application party in the scenario is used to send the query job execution requirement data to the transfer party through the initiator interface; The relaying party is configured to, upon receiving the query job execution requirement data sent by the scenario application party, send the query job execution requirement data to the data provider through the participant scheduling interface; and, upon receiving the job status information of running the job file sent by the data provider, send the job status information to the scenario application party through the initiator scheduling interface. The data provider, upon receiving the query job execution requirement data, sends the job status information of running the job file to the transfer party through the participant interface.
15. The system according to claim 13 or 14, characterized in that, The scenario application party is used to send, in sequence, a request to release the job, a request to release the project, a request to release the permission information, and a request to unbind the data exchanged between the scenario application party and the data provider when it is determined that the job has been completed. The transfer party is used to unbind the relationship between the data exchanged between the scenario application party and the data provider when it receives the job release request, the project release request, the permission information release request, and the data unbinding request between the scenario application party and the data provider. And forward to the data provider the job release request, the project release request, the permission information release request, and the data unbinding request between the scenario application party and the data provider in sequence; The data provider is configured to perform an unbinding operation upon receiving a request from the transferor to unbind the job, the project, the permission information, or the data exchanged between the scenario application and the data provider.
16. A data processing method, characterized in that, A relaying unit applied to the data processing system as described in any one of claims 1-15, wherein the relaying unit communicates with N scenario application parties and M data providers respectively, where N and M are positive integers, the method comprising: Receive privacy computing requirement data sent by the application party in the scenario; Based on the privacy computing requirement data, determine the privacy computing transfer task; According to the privacy computing transfer task, send the privacy computing requirement data to the data provider; Upon receiving the privacy calculation result data sent by the data provider, the privacy calculation result data is sent to the application party in the scenario.
17. A computer device, characterized in that, The computer device includes: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, it implements the data processing method as described in claim 16.
18. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions that, when executed by a processor, implement the data processing method as described in claim 16.