Data element processing method, electronic equipment, computer storage medium and program product

By setting up a secure environment and virtual nodes in the PaaS platform and using coordinating nodes for privacy computing, the problem of users setting up their own secure nodes and computing power requirements in the data supply chain is solved, achieving low-cost and efficient data security.

CN121966897APending Publication Date: 2026-05-01DINGTALK (CHINA) INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
DINGTALK (CHINA) INFORMATION TECH CO LTD
Filing Date
2024-10-30
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

In the data supply chain, users need to set up additional security nodes and computing power to ensure the security of data element interaction, which leads to increased costs and system power consumption.

Method used

By setting up a secure environment and virtual nodes in the PaaS platform, and coordinating the nodes to call privacy computing services to perform privacy computing on data elements, users are spared the need to set up their own secure nodes and additional computing power.

Benefits of technology

It reduces the cost for users to maintain data security, alleviates the burden of computing power and system power consumption, and improves the security and efficiency of data interaction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121966897A_ABST
    Figure CN121966897A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a data element processing method, electronic equipment, a computer storage medium and a program product, and the method comprises the steps: receiving to-be-processed data elements of different users through different virtual nodes corresponding to different users in a PaaS platform; calling a privacy calculation service in the PaaS platform through a coordination node in the secure environment so as to perform privacy calculation on the data elements of the different users through the privacy calculation service; and feeding back a result of the privacy calculation to a target application so as to provide data processing based on the data elements through the target application. Through the embodiment of the invention, the cost of maintaining own data security by a user can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a data element processing method, electronic device, computer storage medium, and computer program product. Background Technology

[0002] As the digitalization process deepens across industries, more and more enterprises and organizations need to conduct their work based on data and information interaction. In response, the data supply chain has emerged. With data management departments at its core, the data supply chain establishes unified data standards, manages consistent data quality, and ensures data security throughout its entire lifecycle. It begins by collecting data from supplying departments, then moves to data storage, governance, sharing and exchange, data mining and computation, and finally, delivers the data to demanding departments for application, forming a holistic functional network structure.

[0003] In the data supply chain, parties typically interact through data elements. Data elements refer to data resources that exist electronically, participate in production and business activities through computation, and play a significant role. Currently, to ensure the security of data element interactions, owners of different data elements set up security nodes, such as data security servers, in their respective local area networks to securely process data element interactions, thereby guaranteeing the security of data element interactions and preventing the illegal theft of data elements.

[0004] However, in this approach, on the one hand, the data element owners need to set up additional security nodes, increasing the cost burden of data security; on the other hand, dedicated computing power is also required to handle the processing and calculation of data elements received from other parties, which further increases the cost burden of data security and also greatly consumes the computing power and system power consumption of the data element receivers. Summary of the Invention

[0005] In view of this, embodiments of this application provide a data element processing scheme to at least partially solve the above-mentioned problems.

[0006] According to a first aspect of the embodiments of this application, a data element processing method is provided, the method comprising: receiving data elements of different users to be processed through different virtual nodes corresponding to different users in a PaaS platform, wherein the different virtual nodes are all set in the security environment of the PaaS platform; invoking a privacy computing service in the PaaS platform through a coordination node in the security environment to perform privacy computing on the data elements of the different users through the privacy computing service; and feeding back the result of the privacy computing to a target application to provide data processing based on the data elements through the target application.

[0007] According to a second aspect of the present application, an electronic device is provided, including: a processor, a memory, a communication interface, and a communication bus, wherein the processor, the memory, and the communication interface communicate with each other through the communication bus; the memory is used to store at least one executable instruction, which causes the processor to perform an operation corresponding to the method described in the first aspect.

[0008] According to a third aspect of the embodiments of this application, a computer storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the method described in the first aspect.

[0009] According to a fourth aspect of the embodiments of this application, a computer program product is provided, including computer instructions that instruct a computing device to perform an operation corresponding to the method described in the first aspect.

[0010] According to the data element processing scheme provided in this application embodiment, to address the security needs of users in the data supply chain, a secure environment is set up in the PaaS (Platform as a Service) platform, and virtual nodes for users are set up in the secure environment. When users need to perform privacy computation, they can receive the data elements to be processed through the virtual nodes in the secure environment, and then call the relevant privacy computation services through the coordination node in the secure environment to perform privacy computation in the secure environment. Therefore, on the one hand, users no longer need to set up additional secure nodes for data security, reducing the cost for users to maintain their own data security; on the other hand, when privacy computation is needed, the corresponding privacy computation services in the PaaS platform can be called through the coordination node in the PaaS platform's secure environment, and the privacy computation operation is also performed in the PaaS platform's secure environment. Thus, while ensuring data security, users do not need to use additional equipment or processing to implement privacy computation, reducing the burden of computing power and system power consumption on the user side. It is evident that the scheme of this application embodiment can greatly reduce the system operation, maintenance, and management costs related to privacy computation on the user side. Attached Figure Description

[0011] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings.

[0012] Figure 1A This is a flowchart illustrating the steps of a data element processing method according to an embodiment of this application.

[0013] Figure 1BFor based on Figure 1A A schematic diagram of an exemplary data supply chain for the method shown;

[0014] Figure 2 This is a flowchart of another data element processing method according to an embodiment of this application;

[0015] Figure 3 This is a schematic diagram illustrating a scenario example according to an embodiment of this application;

[0016] Figure 4 This is a schematic diagram of the structure of an electronic device according to an embodiment of this application. Detailed Implementation

[0017] To enable those skilled in the art to better understand the technical solutions in the embodiments of this application, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art should fall within the protection scope of the embodiments of this application.

[0018] The specific implementation of the embodiments of this application will be further described below with reference to the accompanying drawings.

[0019] Reference Figure 1A The diagram illustrates a flowchart of the steps of a data element processing method according to an embodiment of the present invention.

[0020] The data element processing method in this embodiment includes the following steps:

[0021] Step S102: Receive the data elements of the different users to be processed through different virtual nodes corresponding to different users in the PaaS platform.

[0022] In this embodiment, PaaS (Platform as a Service) can be understood as a cloud computing service model that provides users with an online platform to support the development, running, and management of applications on a fully managed infrastructure. Correspondingly, a PaaS platform is a platform with PaaS deployed. The PaaS platform can have a built-in integrated development environment and a series of tools to achieve functions such as source code management, project building, testing, debugging, and deployment, providing developers with a one-stop development and deployment solution.

[0023] Unlike conventional PaaS platforms, this embodiment also deploys a secure environment on the PaaS platform. The secure environment aims to protect computer programs and their data during operation from unauthorized access, modification, damage, or disclosure. In one feasible approach, this secure environment can be implemented as a TEE (Trusted Execution Environment). A TEE is a specific area within a hardware processor, such as a CPU, designed specifically to protect sensitive data and code within the device housing the processor. It provides a secure space for data and code execution by offering isolation, high performance, secure communication, and secure key storage, ensuring data confidentiality and security. In this embodiment, implementing the PaaS platform's secure environment as a TEE not only ensures the security of data elements and the privacy computations performed on them, but also, due to the relatively mature and stable nature of TEE technology, further guarantees robust stability in data element processing and saves on implementation costs. However, this is not the only approach; other feasible secure environment implementation methods are also applicable to the solutions in this embodiment, including but not limited to Titan M and Intel SGX.

[0024] Based on this, different virtual nodes corresponding to different users are set up in this secure environment. It should be noted that, in this embodiment, a virtual node can be understood as a virtual computing node in the PaaS platform, a virtual server used to execute application code and store related data elements. These nodes provide developers with an isolated, scalable, and efficient environment to support the construction, operation, and management of their applications. Different users (such as enterprises, merchants, organizations, etc.) can apply to the PaaS platform to create their virtual nodes according to their actual needs. Virtualization technologies (such as KVM, Xen, Hyper-V, etc.) can be used to create and manage computing nodes in the PaaS platform. Virtualization technology allows multiple virtual computing nodes to run on a single physical device, such as a physical server. Furthermore, in this embodiment, these virtual computing nodes are all set up in the secure environment of the PaaS platform. Each user's virtual node, once created, is only used to process the data elements of that user; other users cannot access it without authorization. When privacy-preserving computations are required on data elements from different users, each user can receive the necessary data elements through their own virtual node and temporarily store them there. Subsequently, after user confirmation and authorization, the virtual node can provide the data required for privacy computations, ensuring the legality and security of the processing of these data elements.

[0025] Step S104: Through the coordination node in the secure environment, call the privacy computing service in the PaaS platform to perform privacy computing on the data elements of different users.

[0026] In this embodiment, the coordinating node is also located in a secure environment. The coordinating node can manage and schedule resources and services within the PaaS platform, ensuring the efficient and stable operation of related services. Furthermore, the coordinating node can support security mechanisms such as Role-Based Access Control (RBAC) to ensure that only authorized users can access the corresponding resources and services within the PaaS platform. Optionally, the coordinating node can also employ encryption technology to protect the confidentiality and integrity of data elements during transmission and storage. In addition, in this embodiment, because different users store data elements in different forms or formats, the coordinating node also performs the function of aligning data elements between different users undergoing privacy computation.

[0027] For example, different users might use different field names for data elements with the same meaning. The coordinating node can align them based on semantic parsing or pre-defined mapping relationships (e.g., determining they are fields with the same meaning or projecting them to the same data space). Similarly, if different users use different data types for fields with the same meaning, the coordinating node can align them to the same data type, and so on. This alignment process by the coordinating node makes subsequent privacy-preserving computations smoother and more efficient.

[0028] In one feasible approach, the alignment process described above can be implemented as follows: Metadata information of the data elements to be subjected to privacy computation is obtained through a coordinating node in a secure environment; based on the metadata information, alignment processing is performed on the data elements of different users. Then, the privacy computation service in the PaaS platform can be further invoked to perform privacy computation on the aligned data elements of different users. Metadata is information about the organization, data domains, and relationships of data elements, describing their attributes, characteristics, relationships, management methods, etc. By utilizing the metadata of data elements, the similarities and differences and relationships between data elements can be determined more quickly, improving the efficiency of the alignment process.

[0029] However, this is not the only option. In practical applications, the users involved in privacy computation can first align the data elements and then use a coordinating node to call the privacy computation service to perform privacy computation.

[0030] Privacy-preserving computation services in a PaaS platform can be deployed within a secure environment to further enhance security. Alternatively, they can be deployed outside of a secure environment to conserve space and provide more security resources for users. When deployed outside a secure environment, the coordinating node can also perform access authentication and security filtering for the privacy-preserving computation services to be invoked, ensuring the security of these services.

[0031] Privacy-preserving computation services are a general term for code that provides privacy-preserving computation. These services can perform secure computation and analysis on data without sharing sensitive data (such as data elements in the embodiments of this application), thereby ensuring the privacy and security of the data during processing. In one feasible approach, a privacy-preserving computation service may include at least one of the following: a service for instructing privacy-preserving intersection computation on data elements; a service for instructing joint analysis of data elements; and a service for instructing joint modeling of data elements.

[0032] Privacy intersection computation is a technique for secure multi-party computation. Specifically, in the embodiments of this application, it allows multiple users participating in privacy computation to jointly calculate the intersection of their data elements without disclosing their own data elements to each other, and without revealing any information other than the intersection to any of the participating users. In specific implementations, those skilled in the art can use any appropriate privacy intersection algorithm to implement the privacy intersection computation service according to actual needs. For example, algorithms based on public-key encryption such as RSA blind signatures, or algorithms based on homomorphic encryption, or algorithms based on the Unintentional Transmission (OT) protocol, or algorithms based on the Unintentional Pseudo-Random Function (OPRF) protocol, etc., can be used to implement the privacy intersection computation service.

[0033] Joint analysis refers to a process in which multiple data holders (such as multiple users to be subjected to privacy-preserving computations in this embodiment) jointly participate in data analysis and computation, while protecting data privacy. It can complete joint data analysis and computation tasks without disclosing the original data. In specific implementations, those skilled in the art can employ any appropriate joint analysis algorithm to implement joint analysis services according to actual needs. For example, the weighted matrix method, pairwise comparison method, and full profile method can be used to implement joint analysis services.

[0034] Joint modeling is a data analysis method that integrates and analyzes data from multiple parties (such as the data elements of multiple users to be used for privacy computation in this embodiment) to arrive at more comprehensive and accurate conclusions while protecting the data privacy of such data. In practical implementation, those skilled in the art can adopt any appropriate joint modeling method to implement the joint modeling service according to actual needs. For example, secure multi-party computation, federated learning, and other methods can be used to implement the joint modeling service. Taking federated learning as an example, federated learning allows multiple users to train models locally on their own sides and then upload the encrypted model parameters to a PaaS platform for aggregation, thereby obtaining a global model without sharing the original data. Subsequently, federated computation among these multiple users can be performed based on this global model.

[0035] Based on the aforementioned privacy-preserving computation services, in one feasible approach, the user can choose which privacy-preserving computation service to invoke. In this case, the user's device provides a human-computer interaction interface (HCI) through which the user inputs or selects the privacy-preserving computation service to use. The PaaS platform then invokes the privacy-preserving computation service input or selected by the user. If multiple users participating in privacy computation simultaneously make selections and choose different privacy-preserving computation services, feedback can be provided to all users to ensure that they select the same privacy-preserving computation service. In another feasible approach, the PaaS platform can select a less loaded privacy-preserving computation service based on its current load. In yet another feasible approach, the PaaS platform can analyze the privacy-preserving computation request input by the user (including but not limited to one or more of semantic analysis, intent analysis, and best-match algorithm analysis) to select the privacy-preserving computation service that best matches the analysis results from among multiple privacy-preserving computation services.

[0036] Furthermore, the PaaS platform can invoke selected or determined privacy-preserving computation services through coordinating nodes. These services then perform privacy-preserving computations based on data elements stored in the virtual nodes of multiple users. Examples include the aforementioned privacy-preserving intersection computation, joint analysis computation, and joint modeling computation. Finally, the results of the privacy-preserving computations are obtained.

[0037] Step S106: Feed back the results of privacy computation to the target application so that the target application can provide data processing based on data elements.

[0038] The target application can be any appropriate application that provides data processing based on data elements, based on the results of privacy-preserving computation. Since privacy-preserving computation is performed on data elements, the results also reflect the processing results of the data elements to a certain extent. Therefore, in one feasible approach, the target application can directly display the results of the privacy-preserving computation. However, this is not limited to this; in another feasible approach, the target application can further process the results of the privacy-preserving computation and then display the reprocessed results. This reprocessing can be: filling a preset data display template based on the results of the privacy-preserving computation and displaying the filled data display template; or recalculating the results of the privacy-preserving computation as needed and displaying the recalculated results, etc. This application embodiment does not limit the reprocessing based on the results of privacy-preserving computation.

[0039] In one feasible approach, the target application of this application embodiment can be implemented as an AI (artificial intelligence) application based on a PaaS platform. For example, this AI application can be implemented based on an AI application platform. The AI ​​application platform can provide capabilities such as model training, model scheduling, and plugin development to enable rapid development of AI applications. Based on this, in this step, the results of privacy-preserving computation can be fed back to the AI ​​application for processing based on the privacy-preserving computation results.

[0040] In one feasible approach, the privacy computation of this embodiment can also be initiated by an AI application. That is, based on the request instruction from the AI ​​application, the data elements of different users to be used are determined; and the data elements of different users are obtained as the data elements of different users to be processed through different virtual nodes corresponding to different users in the PaaS platform. Correspondingly, feeding back the privacy computation result to the target application to provide data processing based on data elements can be achieved by feeding back the privacy computation result to the AI ​​application to process the result based on the privacy computation and obtain response data in response to the request instruction. The request instruction from the AI ​​application can be any appropriate request or instruction that requests or instructs the use of different users' data elements for privacy computation. However, it is not limited to AI applications; any other appropriate type of application can also be applied to the solution of this embodiment, such as low-code applications, cool applications, etc.

[0041] Furthermore, as a link in the data supply chain, the target application, such as an AI application, in this embodiment can assume the responsibility of data delivery in the data supply chain (responsible for delivering data elements to the data element market in the form of applications for use by data consumers), while the PaaS platform can assume the responsibility of data flow and processing in the data supply chain (responsible for providing data element circulation methods, providing the circulation of data elements from the data supply end to the data consumption end in a form similar to logistics). Before the PaaS platform, the data supply chain also has a data warehouse storing data elements from different users. This data warehouse, together with the PaaS platform and the target application, forms the data supply chain.

[0042] Based on this, in one feasible solution, before receiving the data elements of different users to be processed through different virtual nodes corresponding to different users in the PaaS platform in step S102, the data element processing method of this application embodiment may further include: storing the data elements of multiple different users through multiple data warehouses at different levels in the data warehouse. The multiple data warehouses at different levels include at least one of the following: a user's enterprise-level data warehouse, a user's industry-level data warehouse, and a user's application-level data warehouse associated with the PaaS platform. Correspondingly, receiving the data elements of the different users to be processed through different virtual nodes corresponding to different users in the PaaS platform can be implemented as: receiving the data elements of the different users to be processed transmitted from the data warehouse through different virtual nodes corresponding to different users in the PaaS platform.

[0043] The data warehouse is responsible for managing and processing data elements at the application, enterprise, and industry levels associated with the PaaS platform. It manages internal and external data elements in a unified manner using virtualized data. Through capabilities such as data asset registration, management, measurement, and billing, it ultimately provides services in the form of a data element product catalog.

[0044] in:

[0045] Application-level data warehouse for users associated with the PaaS platform: This helps users manage the organizational and application data of users stored on the preset application platform and process it into data elements for uploading to the application-level data warehouse.

[0046] User's industry-level data warehouse: Used to introduce secure and compliant industry data from the user's industry through data trading platforms in various regions, enrich the user's external data resources, and put them on the industry-level data warehouse;

[0047] User's enterprise-level data warehouse: The data element capabilities provided by the user's self-built service system are put into the user's own enterprise-level data warehouse.

[0048] Compared to traditional data supply chains, which require users to deploy each link of the data supply chain and the data tools for each link, resulting in high development and deployment costs and data security risks, the solution in this application is not limited to the internal flow of data elements within the user. Instead, it connects the user's internal services with external data suppliers and data service providers through a PaaS platform, linking the entire data supply chain, including both data supply and demand sides, within a single solution. Specifically, a "data warehouse" centrally manages internal and external data element assets based on data element information such as data element product catalogs; "data flow" enables privacy-preserving computation of data elements and the flow of results based on these computations through the PaaS platform, ensuring low-cost, high-efficiency operation of data elements while providing privacy-preserving computation capabilities that are available but not visible; and "data delivery" connects the final link in the data element supply chain, enabling the construction of data element-based services into scenario-based applications for use.

[0049] An example of the aforementioned data supply chain is as follows: Figure 1B As shown, by Figure 1B It is evident that this data supply chain comprises three stages: "data warehouse", "data flow", and "data delivery".

[0050] The "data warehouse" includes a user's enterprise-level data warehouse X, a user's industry-level data warehouse Y, and a user's application-level data warehouse Z (represented as "Application P Data Warehouse Z" in this example), which is associated with the PaaS platform. Data warehouse X corresponds to each user and can be built by the user to store their own data elements. Data warehouse Y corresponds to the user's industry and stores data elements within that industry. These data elements can be obtained by collecting, processing, operating, and uploading data elements from multiple users within that industry to a data trading platform. Data warehouse Z is the data warehouse corresponding to application P, and the data elements stored therein can be obtained by processing the data elements collected from application P.

[0051] Furthermore, based on the data elements stored in data warehouses X, Y, and Z, corresponding measurement and registration processes can be performed to obtain a product catalog of data elements, which facilitates the management and maintenance of data elements in each data warehouse.

[0052] When privacy computation is required between different users (such as when privacy computation is triggered at preset time intervals, or when a request instruction for privacy computation is received from the target application, or when an instruction for privacy computation is received from the PaaS platform, etc.), in this example, users A and B will retrieve the data elements to be performed on privacy computation from at least one of data warehouses X, Y, and Z, and temporarily store them in their respective virtual nodes in the PaaS platform's secure environment, which are represented as "virtual node A" and "virtual node B" in this example.

[0053] The PaaS platform implements the "data flow" link in the data supply chain. When it determines that users A and B need to perform privacy computation, it reads the data elements to be computed from "virtual node A" and "virtual node B" through a coordinating node deployed in the same secure environment. Optionally, the data elements of these two virtual nodes can be aligned if necessary. Furthermore, for example, based on the current load or usage of each privacy computation service, a service can be selected from privacy intersection computation service, federated analysis service, and federated modeling service. In this example, privacy intersection computation service is shown. That is, the coordinating node calls the privacy intersection computation service to perform privacy intersection computation on the data elements retrieved from virtual nodes A and B, and after obtaining the computation result, sends it to the AI ​​application in the AI ​​platform (AIPaaS).

[0054] At this point, the data supply chain has moved to the "data delivery" stage. In this stage, after obtaining the results of the privacy intersection calculation between users A and B, the AI ​​application can perform post-processing based on these results to meet actual needs, and then present the final processed result through the AI ​​application.

[0055] As can be seen, the solution of this application addresses the security needs of users in the data supply chain by setting up a secure environment within the PaaS (Platform as a Service) platform and establishing virtual nodes for users within this secure environment. When users need to perform privacy-preserving computations, they can receive the data elements to be processed through these virtual nodes and then invoke relevant privacy-preserving computation services through a coordinating node within the secure environment to perform the computations. Therefore, on the one hand, users no longer need to set up additional secure nodes for data security, reducing the cost of maintaining their own data security; on the other hand, when privacy-preserving computations are needed, the corresponding privacy-preserving computation services within the PaaS platform can be invoked through the coordinating node in the PaaS platform's secure environment, and the privacy-preserving computation operation is also performed within the PaaS platform's secure environment. This ensures data security while eliminating the need for users to use additional equipment or processing to perform privacy-preserving computations, reducing the burden on user-side computing power and system power consumption. Therefore, the solution of this application can significantly reduce the system operation, maintenance, and management costs related to privacy-preserving computations on the user side.

[0056] Based on the above embodiments, referring to Figure 2 The flowchart illustrates the steps of another data element processing method according to an embodiment of this application.

[0057] This embodiment optimizes some processes from the previous embodiment to further improve the confidentiality and security of privacy-preserving computations on data elements. The data element processing method in this embodiment includes the following steps:

[0058] Step S202: Receive multiple different data element components from different users in the PaaS platform through multiple virtual nodes corresponding to different users, and store them in the corresponding virtual nodes respectively.

[0059] In this embodiment, at least one of the multiple users corresponds to multiple virtual nodes, and the virtual nodes corresponding to different users are all different. That is, among the multiple users, there are some users, and for each of these users, there are multiple virtual nodes, and the multiple virtual nodes corresponding to different users are all different. For example, user A corresponds to virtual nodes A1 and A2, and user B corresponds to virtual nodes B1 and B2, and A1, A2, B1, and B2 are all different. Or, user A corresponds to virtual nodes A1 and A2, and user B corresponds to virtual nodes B1, B2, and B3, and A1, A2, B1, B2, and B3 are all different. Or, user A corresponds to virtual nodes A1 and A2, and user B corresponds to virtual node B, and A1, A2, and B are all different. It should be noted that the above examples are for illustration only and are not intended to limit. In actual applications, the number of virtual nodes corresponding to each user can be determined according to the resource situation of each user and the PaaS platform. This embodiment of the application does not impose any restrictions on this. This approach provides users with more flexible virtual node resources within a secure environment, enhancing their flexibility in resource utilization.

[0060] As a link in the data supply chain, in this embodiment, the PaaS platform can receive data elements from the data warehouse that are to be processed, transmitted from different users, through different virtual nodes corresponding to different users within the PaaS platform. Further optionally, multiple different data element components from different users, transmitted from the data warehouse and to be processed, can be received from the data warehouse through multiple different virtual nodes corresponding to different users within the PaaS platform, and stored separately in the corresponding user's multiple virtual nodes. In this approach, on the one hand, a single user can store their data elements through multiple virtual nodes to increase the amount of data available for privacy computation, eliminating the need for back-and-forth data element access and improving the efficiency of data element access and privacy computation; on the other hand, in one feasible approach, a single user can divide their data elements to be privacy-computed into multiple components and store them separately in their corresponding multiple virtual nodes, thereby further ensuring the security of the data elements while improving the efficiency of subsequent privacy computation.

[0061] Optionally, all of the aforementioned different data element components are encrypted data element components to further ensure the confidentiality and security of the data elements during transmission and subsequent use in privacy-preserving computations. That is, before the data elements are transmitted to the PaaS platform, they are split and encrypted on the user's side and then stored in virtual nodes within the secure environment of the PaaS platform for subsequent privacy-preserving computations. This further enhances the security of the data elements.

[0062] Step S204: Through the coordination node in the secure environment of the PaaS platform, call the privacy computing service in the PaaS platform to perform parallel privacy computing on multiple different data element components of different users.

[0063] For the same user, the data elements stored in multiple virtual nodes are usually non-overlapping. Based on this, parallel privacy computation can be performed on the data element components in multiple virtual nodes to improve the efficiency of privacy computation.

[0064] For example, virtual nodes A1 and A2 corresponding to user A store two parts of data elements to be computed in privacy, denoted as data elements A1 and A2, respectively; virtual node B corresponding to user B stores data element B to be computed in privacy. Assuming the coordinating node invokes a privacy intersection computation service, this service can perform privacy intersection computations on data elements A1 and B, and on data elements A2 and B, in parallel. Then, after obtaining the results of the two privacy intersection computations, these two results are merged to obtain the final privacy intersection computation result.

[0065] It should be noted that the operations such as the coordination node calling the corresponding privacy computing service in this step can be implemented with reference to the description of the relevant parts in the foregoing embodiments, and will not be repeated here.

[0066] Step S206: Feed back the results of privacy computation to the target application so that the target application can provide data processing based on data elements.

[0067] The implementation of this step can be referred to the relevant description of step S106 in the foregoing embodiments, and will not be repeated here.

[0068] In this embodiment, the user first breaks down the data element to be subjected to privacy computation into multiple data element components and encrypts them. This ensures that only a portion of the encrypted data element components are present in the multiple virtual nodes corresponding to a single user. Furthermore, because these multiple virtual nodes and the coordinating node are located in a secure environment, unauthorized access is impossible. This significantly enhances the security and confidentiality of the data element and the privacy computation and processing based on it. Moreover, this method enables parallel privacy computation of data elements, greatly improving the speed and efficiency of privacy computation.

[0069] The following example uses a specific scenario. Figure 3 The above-described data element processing method of the embodiments of this application will be described by way of example.

[0070] In this example, the privacy computing service in the PaaS platform is provided by a dedicated privacy computing service provider. Figure 3The diagram simply illustrates vendors A and B. Privacy computing service providers can offer a variety of privacy computing services, including but not limited to privacy intersection computing services, joint analysis services, joint modeling services, and so on. Optionally, privacy computing service providers can also provide secure environments such as TEEs. Having privacy computing services provided by privacy computing service providers can reduce the implementation cost of privacy computing services on PaaS platforms, and also allows for more flexible invocation of different privacy computing services, while enriching the variety of privacy computing services available.

[0071] In this situation, on the one hand, privacy computing service providers can offer privacy computing services to different users. For example, Figure 3 In this context, multiple users are represented by companies H, J, K, L, M, and N. Assume that companies H, J, and N have all subscribed to privacy computing services from vendor A, while companies K, L, and M have all subscribed to privacy computing services from vendor B. Then, regardless of whether a user's data is stored on a public cloud, a private cloud, or a local server, companies subscribed to the same vendor's privacy computing services can all access those services for privacy computing purposes.

[0072] On the other hand, privacy computing service providers can deploy their privacy computing services on a PaaS platform via mirroring to achieve resource sharing. In this case, the PaaS platform can use the privacy computing services provided by the privacy computing service provider as local resources of the PaaS platform.

[0073] To integrate data resources, form a complete data supply chain, and save users the cost of securely implementing data elements, this approach also includes a data asset platform and a data storage service platform. The data asset platform acts as a "data warehouse" within the data supply chain, deploying enterprise-level data warehouses, industry-level data warehouses, and application-level data warehouses associated with the PaaS platform. Based on this, in Figure 3 In the example shown, the customer issues a privacy computing request (such as...). Figure 3 After the "Application Service" step (as specified in the code), if the PaaS platform determines that privacy computation is required, it can obtain data elements of different users from the data warehouse of the data asset platform. In this example, these are data elements of different enterprises. For example, data elements of different enterprises can be obtained from the data asset platform through the data resource service in the PaaS platform.

[0074] Furthermore, the data resource service can store the acquired data elements into virtual nodes corresponding to each enterprise within the PaaS platform's own secure environment; or, it can store them in a secure environment image within the PaaS platform provided by the privacy computing service provider subscribed to by each enterprise. It should be noted that this secure environment image can also reside within the PaaS platform's actual secure environment.

[0075] Furthermore, the coordinating node in the PaaS platform can invoke the corresponding privacy computing service through the privacy computing service mirror of the privacy computing service provider within the PaaS platform to perform privacy computing on the data elements in the virtual node. The results of the privacy computing are then fed back to the customer (e.g., ...). Figure 3 (See the "Return Result" shown). Meanwhile, if the user... Figure 3 The companies in the platform have also applied for data storage services. The PaaS platform will then store the data elements and / or privacy calculation results uploaded to the virtual nodes through the "custom storage service" in the PaaS platform, based on the data storage service platform, according to the storage rules set by the users, such as storage time, storage content, and storage address.

[0076] The data storage service platform can connect with various storage spaces to provide services such as internal enterprise storage, application platform storage for pre-defined applications, or cloud storage. "Customized storage service" stores the required data and data elements into the appropriate storage space through the data storage service platform according to the storage rules set by the user.

[0077] Because privacy computing service providers offer their services to PaaS platforms via mirroring, PaaS platforms also provide a "service mirror management" function to manage and maintain these service images. However, providing privacy computing services via mirroring is only one example. As mentioned earlier, PaaS platforms themselves can also offer corresponding privacy computing services for users. Therefore, when providing privacy computing services, PaaS platforms can offer their own privacy computing services, privacy computing services provided by privacy computing service providers, or both, allowing users to choose.

[0078] As can be seen, this example provides a more flexible and richer feasible approach to privacy computing services. It not only realizes the entire data supply chain, but also ensures the security and confidentiality of users' data elements, provides more flexible and diverse ways to implement privacy computing services, and effectively reduces the cost and burden of data security implementation for users.

[0079] Reference Figure 4 This document illustrates a schematic diagram of an electronic device according to an embodiment of this application. The specific embodiments of this application do not limit the specific implementation of the electronic device.

[0080] like Figure 4 As shown, the electronic device may include: a processor 402, a communications interface 404, a memory 406, and a communications bus 408.

[0081] in:

[0082] The processor 402, communication interface 404, and memory 406 communicate with each other via communication bus 408.

[0083] Communication interface 404 is used to communicate with other electronic devices or servers.

[0084] The processor 402 is used to execute program 410, specifically to perform the relevant steps in the above-described data element processing method embodiment.

[0085] Specifically, program 410 may include program code that includes computer operation instructions.

[0086] Processor 402 may be a CPU, a GPU (Graphics Processing Unit), an Application Specific Integrated Circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of this application. The one or more processors included in the smart device may be processors of the same type, such as one or more CPUs; or they may be processors of different types, such as one or more CPUs and one or more ASICs.

[0087] Memory 406 is used to store program 410. Memory 406 may include high-speed RAM memory, and may also include non-volatile memory, such as at least one disk storage device.

[0088] Program 410 may include multiple computer instructions. Specifically, program 410 may use multiple computer instructions to cause processor 402 to perform the operation corresponding to the data element processing method described in any of the foregoing multiple method embodiments.

[0089] The specific implementation of each step in procedure 410 can be found in the corresponding descriptions of the steps and units in the above method embodiments, and has corresponding beneficial effects, which will not be repeated here. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the devices and modules described above can be referred to the corresponding process descriptions in the foregoing method embodiments, and will not be repeated here.

[0090] This application also provides a computer storage medium storing a computer program thereon, which, when executed by a processor, implements the method described in any of the foregoing method embodiments. The computer storage medium includes, but is not limited to, compact disc read-only memory (CD-ROM), random access memory (RAM), floppy disk, hard disk, or magneto-optical disk.

[0091] This application also provides a computer program product, including computer instructions that instruct a computing device to perform an operation corresponding to any of the data element processing methods in the above-described multiple method embodiments.

[0092] Furthermore, it should be noted that the user-related information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to sample data used for training the model, data used for analysis, stored data, displayed data, etc.) involved in the embodiments of this application are all information and data authorized by the user or fully authorized by all parties. Moreover, the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse.

[0093] It should be noted that, depending on the implementation needs, the various components / steps described in the embodiments of this application can be broken down into more components / steps, or two or more components / steps or parts of the operation of components / steps can be combined into new components / steps to achieve the purpose of the embodiments of this application.

[0094] The methods described in the embodiments of this application can be implemented in hardware, firmware, or as software or computer code that can be stored in a recording medium (such as a CD-ROM, RAM, floppy disk, hard disk, or magneto-optical disk), or as computer code downloaded over a network that is originally stored in a remote recording medium or a non-transitory machine-readable medium and will be stored in a local recording medium. Thus, the methods described herein can be stored on a recording medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware (such as an Application Specific Integrated Circuit (ASIC) or a Field Programmable Gate Array (FPGA)). It is understood that the computer, processor, microprocessor controller, or programmable hardware includes storage components (e.g., Random Access Memory (RAM), Read-Only Memory (ROM), Flash Memory, etc.) capable of storing or receiving software or computer code, which, when accessed and executed by the computer, processor, or hardware, implements the methods described herein. Furthermore, when a general-purpose computer accesses code used to implement the methods shown herein, the execution of the code transforms the general-purpose computer into a dedicated computer for executing the methods shown herein.

[0095] Those skilled in the art will recognize that the units and method steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for specific applications, but such implementations should not be considered beyond the scope of the embodiments of this application.

[0096] The above embodiments are only used to illustrate the embodiments of this application, and are not intended to limit the embodiments of this application. Those skilled in the art can make various changes and modifications without departing from the spirit and scope of the embodiments of this application. Therefore, all equivalent technical solutions also fall within the scope of the embodiments of this application, and the patent protection scope of the embodiments of this application should be defined by the claims.

Claims

1. A data feature processing method, comprising: The PaaS platform receives data elements from different users through different virtual nodes corresponding to different users, wherein the different virtual nodes are all set up in the secure environment of the PaaS platform. Through the coordination node in the secure environment, the privacy computing service in the PaaS platform is invoked to perform privacy computing on the data elements of different users. The results of the privacy computation are fed back to the target application so that the target application can provide data processing based on the data elements.

2. The method according to claim 1, wherein, Before receiving the data elements of the different users to be processed through different virtual nodes corresponding to different users in the PaaS platform, the method further includes: storing the data elements of the different users through multiple data warehouses of different levels in the data warehouse, wherein the multiple data warehouses of different levels include at least one of the following: the user's enterprise-level data warehouse, the user's industry-level data warehouse, and the user's application-level data warehouse associated with the PaaS platform; The step of receiving data elements of different users to be processed through different virtual nodes corresponding to different users in the PaaS platform includes: receiving data elements of different users to be processed from the data warehouse through different virtual nodes corresponding to different users in the PaaS platform.

3. The method according to claim 2, wherein, At least one of the multiple users corresponds to multiple virtual nodes, and the virtual nodes corresponding to different users are different from each other; The process of receiving data elements from the data warehouse, which are to be processed by different users, through different virtual nodes corresponding to different users in the PaaS platform, includes: Through multiple virtual nodes corresponding to different users in the PaaS platform, multiple different data element components of the different users to be processed are received from the data warehouse and stored in the corresponding user's multiple virtual nodes respectively; wherein, the data element components are encrypted data element components.

4. The method according to claim 3, wherein, The aforementioned includes: Through the coordination node in the secure environment, the privacy computing service in the PaaS platform is invoked to perform parallel privacy computing on multiple different data element components of different users.

5. The method according to any one of claims 1-4, wherein, The security environment is the Trusted Execution Environment (TEE) in the PaaS platform.

6. The method according to any one of claims 1-4, wherein, The privacy computing service includes at least one of the following: a service for instructing privacy intersection computation on data elements, a service for instructing joint analysis on data elements, and a service for instructing joint modeling of data elements.

7. The method according to any one of claims 1-4, wherein, The step of invoking the privacy computing service in the PaaS platform through a coordination node in the secure environment to perform privacy computing on the data elements of different users includes: The metadata information of the data elements is obtained through the coordination node in the security environment; Based on the information in the metadata, the data elements of different users are aligned. The privacy computing service in the PaaS platform is invoked to perform privacy computing on the data elements of the different users after the alignment process.

8. The method according to any one of claims 1-4, wherein, The target application includes at least artificial intelligence (AI) applications based on the PaaS platform; The step of receiving data elements of different users to be processed through different virtual nodes corresponding to different users in the PaaS platform includes: determining the data elements of different users to be used according to the request instructions of the AI ​​application; and obtaining the data elements of different users as the data elements of different users to be processed through different virtual nodes corresponding to different users in the PaaS platform. The step of feeding back the result of the privacy calculation to the target application so as to provide data processing based on the data elements through the target application includes: feeding back the result of the privacy calculation to the AI ​​application so as to process the result of the privacy calculation through the AI ​​application and obtain response data in response to the request instruction.

9. A computer storage medium having a computer program stored thereon, which, when executed by a processor, implements the method as described in any one of claims 1-8.

10. A computer program product comprising computer instructions that instruct a computing device to perform an operation corresponding to any one of the methods described in claims 1-8.