Method, apparatus and computer program product for managing algorithm sandbox

By configuring sandbox keys for the algorithm sandbox and performing multi-level identity verification and permission auditing, the security risks and inefficiencies in data protection methods are solved, thereby improving the security and resource utilization efficiency during data transmission.

CN122133135APending Publication Date: 2026-06-02中电建新能源集团股份有限公司 +1

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
中电建新能源集团股份有限公司
Filing Date
2026-05-07
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Existing data protection methods have security risks, with lax access control and vulnerabilities in encryption mechanisms, leading to risks of data leakage and misuse. They are also inefficient and unable to cope with complex security threats and unreasonable resource utilization.

Method used

By configuring sandbox keys for the algorithm sandbox, multi-level identity verification and permission auditing are performed to ensure that the data source key is transmitted in an encrypted state and is only temporarily decrypted when needed by the application designer. The multi-level verification and hierarchical storage method avoids data abuse and leakage.

Benefits of technology

It enables encrypted storage of data at all levels and locations, ensuring data security during transmission, preventing data leakage, improving the security and efficiency of data use, and reducing resource waste and maintenance costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122133135A_ABST
    Figure CN122133135A_ABST
Patent Text Reader

Abstract

This disclosure relates to the field of data processing technology, and more specifically, to a management method, apparatus, device, and computer program product for an algorithm sandbox. The management method for the algorithm sandbox includes: determining an algorithm sandbox and configuring a sandbox key for the algorithm sandbox, the sandbox key being stored within the algorithm sandbox; receiving a usage request from an application designer through the algorithm sandbox and verifying the identity of the application designer; after the application designer's identity verification is successful, pushing the usage request from the application designer to a data provider; if the data provider approves the request, encrypting a data source key using the sandbox key, the data source key being the encryption key for the permission data provided by the data provider; sending the encrypted data source key to the algorithm sandbox, so that the algorithm sandbox can decrypt the requested permission data based on the data source key and provide it to the application designer for use.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of data processing technology, and in particular to a method, apparatus, device, and computer program product for managing an algorithm sandbox. Background Technology

[0002] Algorithm sandboxes can rely on secure container technology to build independent and isolated virtual environments.

[0003] However, the data protection methods of related technologies have security risks and are inefficient. They suffer from problems such as lax access control, vulnerabilities in encryption mechanisms, and insufficient data classification, which lead to risks of data leakage and misuse. Summary of the Invention

[0004] To overcome the problems existing in related technologies, this disclosure provides a management method, apparatus, equipment, and computer program product for an algorithm sandbox, which can solve the above-mentioned problems.

[0005] According to a first aspect of the present disclosure, a method for managing an algorithm sandbox is provided. The method includes: determining an algorithm sandbox and configuring a sandbox key for the algorithm sandbox, the sandbox key being stored within the algorithm sandbox; receiving a usage request from an application designer through the algorithm sandbox and verifying the identity of the application designer; after the identity verification of the application designer is successful, pushing the usage request from the application designer to a data provider; if the data provider approves the request, encrypting a data source key using the sandbox key, the data source key being an encryption key for permission data provided by the data provider; sending the encrypted data source key to the algorithm sandbox, so that the algorithm sandbox can decrypt the requested permission data based on the data source key and provide it to the application designer for use.

[0006] According to a second aspect of the present disclosure, an algorithm sandbox management apparatus is provided, the apparatus comprising: a configuration unit configured to determine an algorithm sandbox and configure a sandbox key for the algorithm sandbox, the sandbox key being stored within the algorithm sandbox; a verification unit configured to receive a usage request issued by an application designer through the algorithm sandbox and verify the identity of the application designer; after the identity verification of the application designer is passed, push the usage request issued by the application designer to a data provider; and a sending unit configured to, when the data provider approves the request, encrypt a data source key using the sandbox key, the data source key being an encryption key for permission data provided by the data provider; and send the encrypted data source key to the algorithm sandbox so that the algorithm sandbox can decrypt the requested permission data based on the data source key and provide it to the application designer for use.

[0007] According to a third aspect of the present disclosure, an electronic device is provided, comprising: a processor and a memory; the memory being used to store a computer program; and the processor being used to execute the algorithm sandbox management method as described in the first aspect by invoking the computer program.

[0008] According to a fourth aspect of the present disclosure, a computer program product is provided, including a computer program that, when executed by a processor, implements the method as described in the first aspect.

[0009] The technical solutions provided by the embodiments of this disclosure may include the following beneficial effects: After determining the algorithm sandbox, this disclosure allows configuring a sandbox key for it, which is stored within the sandbox. When an application designer submits a usage request to the algorithm sandbox, their identity is verified. Upon successful verification, the request is then pushed to the data provider for review. If approved, the data provider encrypts the data source key corresponding to the requested data using the sandbox key before sending it to the algorithm sandbox. Upon receiving the data, the algorithm sandbox decrypts it using the stored sandbox key and then decrypts the data using the decrypted data source key, ultimately providing it to the application designer.

[0010] In this way, the permission data provided by the data provider is stored encrypted at all levels and locations, and is only temporarily decrypted when the application designer needs to use it. This disclosure sets up multi-level verification to verify the identity and permissions of the application designer, and to decrypt only a portion of the data in the application designer's usage request to prevent data misuse; the keys are also stored hierarchically to ensure key security and to ensure that both data and keys are encrypted during transmission, preventing data leakage.

[0011] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description

[0012] The accompanying drawings, which are incorporated in and form part of this disclosure, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure.

[0013] Figure 1 This is a schematic flowchart illustrating an algorithm sandbox management method according to an exemplary embodiment of the present disclosure.

[0014] Figure 2 This disclosure is a schematic diagram of encryption and decryption interaction within a management platform of an algorithm sandbox, according to an exemplary embodiment.

[0015] Figure 3This disclosure illustrates an organizational structure diagram of an algorithm sandbox management platform according to an exemplary embodiment.

[0016] Figure 4 This disclosure is a block diagram illustrating an algorithm sandbox management device according to an exemplary embodiment.

[0017] Figure 5 This is a schematic diagram of the structure of a computer device according to an exemplary embodiment of the present disclosure. Detailed Implementation

[0018] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this disclosure as detailed in the appended claims.

[0019] The terminology used in this disclosure is for the purpose of describing particular embodiments only and is not intended to be limiting of the disclosure. The singular forms “a,” “the,” and “the” as used in this disclosure and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any and all possible combinations of one or more of the associated listed items.

[0020] It should be understood that although the terms first, second, third, etc., may be used in this disclosure to describe various information, such information should not be limited to these terms. These terms are used only to distinguish information of the same type from one another. For example, without departing from the scope of this disclosure, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."

[0021] Data holds value today. Data can be authorized for use by designated users within limited scope, and the need to ensure data security during its use, transmission, and storage is growing daily.

[0022] Traditional data protection methods pose security risks and are inefficient in data use, failing to address increasingly complex security threats and operational efficiency demands. During data transmission, testing, and sharing, factors such as lax access control, flawed encryption mechanisms, or data classification barriers can lead to risks of data leakage and misuse.

[0023] In related technologies, persistent data storage in the test environment can easily lead to mass data leakage; the equipment suffers from a shortage of computing power during peak testing periods, while its resource utilization is extremely low when idle, resulting in resource waste or excessively high maintenance costs; and the configuration differences between some test environments and actual production environments can also lead to inaccurate test results.

[0024] To address the aforementioned technical issues, this disclosure proposes a management method for algorithm sandboxes.

[0025] Figure 1 This is a schematic flowchart illustrating an algorithm sandbox management method according to an embodiment of the present disclosure.

[0026] like Figure 1 As shown, the management methods for the algorithm sandbox include: In step S101, an algorithm sandbox is determined and a sandbox key is configured for the algorithm sandbox. The sandbox key is stored in the algorithm sandbox. In step S102, the application designer's use request sent through the algorithm sandbox is received, and the identity of the application designer is verified. In step S103, after the application designer's identity verification is passed, the usage request issued by the application designer is pushed to the data provider; In step S104, if the data provider approves the application, the data source key is encrypted with a sandbox key. The data source key is the encryption key for the permission data provided by the data provider. In step S105, the encrypted data source key is sent to the algorithm sandbox so that the algorithm sandbox can decrypt the requested permission data based on the data source key and provide it to the application designer for use.

[0027] In some embodiments, the algorithm sandbox management method proposed in this disclosure can be executed by a management platform.

[0028] The management platform can store the acquired data in OSS (Object Storage Service) based on the data provider's data source. The management platform can manage the algorithm sandbox, and application designers can access the algorithm sandbox and conduct testing or development within the algorithm sandbox under the management platform.

[0029] It should be noted that the application designer is not limited to application developers using algorithm sandboxes. In the examples disclosed herein, any data user of any algorithm sandbox can be called an application designer, and may also include both data users and application users.

[0030] In some embodiments, an algorithm sandbox is determined and a sandbox key is configured for the algorithm sandbox, and the sandbox key is stored within the algorithm sandbox.

[0031] Determining an algorithm sandbox can involve identifying an existing algorithm sandbox and determining its configuration; or it can involve building a new algorithm sandbox based on requirements and configuration.

[0032] A sandbox key can be configured for the algorithm sandbox. Different algorithm sandboxes correspond to different sandbox keys. The algorithm sandbox and the management platform can store their respective sandbox keys separately. These sandbox keys can be used for information transmission between the algorithm sandbox and the management platform to ensure data security during the transmission process.

[0033] For example, the management platform can encrypt the data content that needs to be sent to the algorithm sandbox using the sandbox key corresponding to the algorithm sandbox, and then send it to the designated algorithm sandbox; after receiving the data content, the algorithm sandbox can decrypt it based on the stored sandbox key to obtain the data content.

[0034] In some embodiments, the system receives a usage request from the application designer through an algorithm sandbox and verifies the identity of the application designer.

[0035] It should be noted that application designers can enter the algorithm sandbox and then submit a usage application within the sandbox; alternatively, they can submit a usage application first, and then the management platform will assign the application designer to a suitable algorithm sandbox based on the usage application and the application designer's identity.

[0036] After receiving a usage request from the application designer, the management platform can verify the application designer's identity. This verification may include, but is not limited to, determining whether the application designer's identity is legitimate, determining the application designer's permission level, determining whether the usage request is compliant, and determining whether the requested data resources are used without authorization.

[0037] In some embodiments, after the application designer's identity verification is successful, the usage request issued by the application designer is pushed to the data provider.

[0038] The management platform verifies the identity of the application designer, and once the verification is successful, the legitimate identity of the application designer can be confirmed.

[0039] However, projects executed within the algorithm sandbox may involve collaboration among multiple parties, and the management platform cannot grasp the scope of responsibilities of each application designer, making it impossible to decide whether to grant data access to that application designer. Therefore, the application designer's usage request can be pushed to the data provider for further review.

[0040] Data providers can determine whether to grant application designers access to the data they have applied for, based on the actual task allocation.

[0041] In some embodiments, a data provider may grant application designers access to data beyond their permission level based on a usage request.

[0042] In some application scenarios, special handling is required. If the application designer needs to use high-privilege data but their own permission level is not up to standard, relevant technologies can upgrade the application designer's permission level so that the application designer can use data with the corresponding permission level. However, if the application designer's permission level is not downgraded to the original level after the project ends or the task is completed, it may lead to data leakage or data security issues.

[0043] Based on this embodiment, application designers can request temporary, unauthorized access to data from the data provider based on a usage request. The application designer can request access to data exceeding their own permissions in the usage request, and if the data provider approves the request, they can temporarily use the data beyond their permissions. After this data usage is completed, because the application designer's permission level remains unchanged, they will be unable to use data that does not conform to their permission level subsequently, thus ensuring data security and preventing leakage. Furthermore, unlike related technologies, there is no need to repeatedly adjust permission levels, making the process and operation more convenient.

[0044] In some embodiments, upon application by the data provider, the data source key is encrypted using a sandbox key, where the data source key is the encryption key for the permission data provided by the data provider.

[0045] After obtaining the permission data provided by the data provider based on the data source, the management platform can assign a corresponding data source key to the data source and encrypt and save the data obtained from the data source using the data source key.

[0046] Since different data sources correspond to different keys, and the stored data is encrypted using the keys of the corresponding data sources, data security is ensured, and the leakage of a large amount of stored data due to the leakage of a single key is avoided.

[0047] Upon application by the data provider, the management platform can obtain the corresponding data source key and encrypt it using a sandbox key. This sandbox key represents the algorithm sandbox in which the application designer resides. After obtaining authorization, the application designer can use the authorized data within this algorithm sandbox.

[0048] In some embodiments, an encrypted data source key is sent to the algorithm sandbox so that the algorithm sandbox can decrypt the requested permission data based on the data source key and provide it to the application designer for use.

[0049] After encrypting the data source key using the sandbox key, the encrypted data source key can be sent to the algorithm sandbox. The algorithm sandbox can decrypt the data source key based on the locally stored sandbox key to obtain the data source key. The data source key obtained by the algorithm sandbox can then be used to decrypt permission data stored in OSS for application designers to use.

[0050] Since the sandbox key is configured during the initialization phase of the algorithm sandbox, encrypting the data source key during transmission prevents its interception and potential data leakage. Furthermore, different algorithm sandboxes possess different sandbox keys, meaning that even if an algorithm sandbox mistakenly receives encrypted information sent to another sandbox, it cannot decrypt the plaintext. Moreover, because the management platform and the algorithm sandboxes do not directly transmit permission data, this avoids both data leakage due to interception or cracking during transmission and the risk of abuse and leakage arising from the algorithm sandbox acquiring permission data locally.

[0051] Therefore, based on this embodiment, the security and reliability of the transmission process between the management platform and the algorithm sandbox can be ensured.

[0052] The algorithm sandbox management method proposed in this disclosure configures keys corresponding to the algorithm sandbox in both the management platform and the algorithm sandbox. After completing multiple rounds of verification and review of the usage application initiated by the application designer, the decryption key of the permission data is issued after encryption. This ensures data security during data use and transmission, avoids the risk of data leakage caused by hijacking of data transmission, and avoids the risk of abuse and leakage caused by data stored locally in the algorithm sandbox.

[0053] In some embodiments, determining an algorithm sandbox and configuring a sandbox key for the algorithm sandbox includes: determining a data source for receiving data uploaded by a data provider, obtaining the data uploaded by the data provider through the data source, and classifying the uploaded data into permission data based on permission levels; determining contract configuration parameters for the algorithm sandbox, including basic permission settings, industry-specific restrictions, and dynamic adjustment mechanisms; creating an algorithm sandbox based on the configured data source and contract configuration parameters, and configuring a sandbox key for the algorithm sandbox.

[0054] In some embodiments, a data source is determined for receiving data uploaded by a data provider.

[0055] Data providers can upload data through data sources. It should be noted that there can be multiple data sources, and these data sources can also be used to transmit streaming data.

[0056] The management platform can configure data sources corresponding to data providers, thereby enabling multi-source data fusion and access. It can access real-time data through gateways (such as cloud edge gateways), synchronize historical data through data synchronization tools, and access external collaborative data through API (Application Programming Interface) gateways. All of this data can be uploaded by the data providers, and the management platform can categorize this data according to dimensions such as permission levels and business scenarios to build a data resource catalog.

[0057] For example, in the field of wind power generation, real-time data can include real-time data from wind turbine sensors (such as second-level time-series data such as vibration, temperature, and speed), which, after being preprocessed by edge computing, can be encrypted and transmitted to the cloud data lake via the MQTT protocol; historical data, such as fault records, operation and maintenance logs, and power output data, can be imported in one go through data synchronization tools; external collaborative data can include grid connection parameters obtained from the grid dispatching platform API (under authorized conditions) and wind speed forecast data obtained from the meteorological service provider interface, which can be uniformly accessed through the cloud API gateway to avoid directly exposing the data source address.

[0058] Data providers can categorize the data they upload through data sources by classifying, classifying, and tagging it to support rapid retrieval and permission matching.

[0059] Taking wind power generation as an example, core wind turbine parameters can be classified as high-privilege data, historical power generation and routine maintenance records as general-privilege data, and regional meteorological data as low-privilege data. Each data resource can be tagged, with tag parameters including metadata such as data source (e.g., a tag like "Wind Turbine ID-102#" to indicate data generated by wind turbine number 102), collection time, format, permission level, and authorized scope.

[0060] In some embodiments, contract configuration parameters for the algorithm sandbox are determined.

[0061] It can configure a role-based permission system and specify data request contracts as needed; it can support dynamic adjustment of contracts via API (change records are synchronized to the audit log), and has built-in industry compliance clauses. Based on the built-in industry compliance clauses, it can verify the compliance of data usage and intervene in violations.

[0062] For example, in the field of wind power generation, access roles (application designers) can be limited and permission levels for each access role can be configured; data request contracts can be set according to data requirements; contracts can be modified in real time via API and adjusted records can be automatically synchronized to audit logs to meet the needs of emergency scenarios (e.g., typhoon season); relevant compliance clauses of the wind power industry can be built into the contract to verify whether data usage behavior complies with regulatory requirements, and to refuse operation and prompt the reason for violation when violations occur.

[0063] In some embodiments, an algorithm sandbox is created based on the configured data source and contract configuration parameters, and a sandbox key is configured for the algorithm sandbox.

[0064] Creating and initializing a cloud elastic algorithm sandbox can include the following steps: Customize the base image for business adaptation (stored in a private repository after review), configure container permissions via K8s (Kubernetes) (prohibit host mounting and restrict system calls) to prevent escape; create independent namespaces according to test scenarios and block communication; Differentiated resource strategies are implemented for tasks such as historical training and large-scale model inference. For medium-intensity computing scenarios such as historical data training, the system automatically allocates optimized cloud instances and binds them with horizontal scaling strategies. The horizontal scaling strategy dynamically adjusts the number of instances based on CPU / memory utilization. For heavy computing scenarios such as large-scale model inference, GPU instances are automatically scheduled and a vertical scaling mechanism is configured, optimizing the resource configuration of a single instance based on historical load. Resource limits are controlled, idle resources are automatically released to optimize costs, and resource allocation is dynamically adjusted based on usage reports. During the initialization of the algorithm sandbox, a cloud key system can also be built, covering the generation, distribution, periodic rotation, and access control mechanisms of sandbox keys, thereby ensuring data encryption protection.

[0065] For example, a container environment can be customized based on Kubernetes cloud-native technology, pre-installing the wind power algorithm runtime environment and security components through a customized base image. Namespaces are used to isolate different test scenarios, and network layer isolation is achieved through NetworkPolicy rules. In terms of resource management, elastic computing instances are allocated based on historical training tasks, and HPA (Horizontal Pod Autoscaler) policies are configured. For large model inference tasks, GPU instances are allocated, and resource limits are set to manage resource costs.

[0066] The following example is taken in the field of wind power generation: For example, a minimal Alpine Linux system can be pre-installed with a dedicated wind power algorithm environment, including Python 3.9, TensorFlow 2.13, PyTorch 2.0, and a wind power SCADA data parsing library, and lightweight security tools can be integrated and uploaded to a private repository. Independent namespaces can be created for different test scenarios (e.g., "fault prediction model test"), and these namespaces can block communication through NetworkPolicy to ensure that test tasks do not interfere with each other.

[0067] Resource adaptation strategies can be designed based on test scenarios. Historical data training can be divided into medium-intensity test scenarios, allocating cloud ESC instances and binding HPA elastic scaling rules. The system monitors the average CPU utilization of all Pods for this task (the target threshold is usually set at 70%). When monitoring data indicates that the load is consistently higher than this threshold, the HPA controller will automatically increase the number of Pod replicas to distribute the load. When the utilization drops significantly and persists for a period of time, the system will automatically reduce the number of replicas to release resources. Large model inference is divided into heavy-intensity test scenarios, enabling strategies such as GPU instances. The Pod definition explicitly requests nxxxxxxa.com / gpu resources, and the Kubernetes scheduler schedules the Pod precisely to nodes with available GPU nodes. At the same time, the system binds Vertical Pod Autoscaler (VPA) to this type of task, intelligently suggesting or automatically adjusting the CPU and memory request and limit values ​​of individual Pods based on historical load, avoiding GPU idleness or memory overflow (OOM) issues caused by improper specification settings. It supports setting resource usage limits and automatically releasing idle resources, among other resource cost management strategies. Specifically, the system enforces resource quotas at the namespace level, setting total usage limits for computing resources (CPU, memory, GPU) and storage resources for each test project or team. The system continuously monitors the workload of each Pod. For services that are not long-running, the system deploys an additional "idle detector," which automatically releases resources once an idle state is detected, effectively managing resource costs.

[0068] Based on HPA elastic scaling rules, the system's resource consumption can be monitored. When resource consumption is too high, the number of instances (replicas) can be increased to alleviate the performance pressure on the algorithm sandbox; when resources are abundant, resources can be released to reduce the number of instances, thereby reducing costs.

[0069] In some embodiments, a key management system can be built during the initialization of the algorithm sandbox to manage data keys.

[0070] Furthermore, in some embodiments, the method further includes updating the sandbox key and / or the data source key according to a rotation cycle.

[0071] For example, a key management system can include key generation and distribution mechanisms, periodic key rotation mechanisms, and key access control mechanisms. The management platform can create a unique data key (sandbox key or data source key) for each algorithm sandbox or access data, and distribute it to the memory of authorized algorithm sandboxes via a secure channel. A periodic key rotation policy can be enforced, setting the rotation cycle based on data access levels. After the key usage period reaches the rotation cycle, a new version key is automatically generated and the data is re-encrypted. Old version keys are archived or destroyed according to a policy. Furthermore, key and user identity can be controlled through access levels, restricting access to users or services matching the corresponding access levels to use keys of that level, ensuring various confidentiality requirements.

[0072] In some embodiments, permission levels for services and / or items can be determined, and permission data matching the permission levels can be provided to the services and / or items.

[0073] Once data permissions are granted to a service and / or project, all application designers involved in that service and / or project can use the accessed data.

[0074] Furthermore, in some embodiments, permission data can be further divided according to tasks in services and / or projects, and users under each task can use all the permission data divided for that task.

[0075] In some embodiments, receiving a usage request from an application designer through an algorithm sandbox and verifying the identity of the application designer includes: determining the permission level of the application designer and determining that the permission level of the application designer matches the permission level of the data requested in the usage request.

[0076] Application designers can submit data usage applications according to the application process. The application should include, but is not limited to, the test scenario, data requirements, and usage period. The management platform can verify the application designer's identity, preset role permissions, and whether the role permissions match the data permission level using the identity authentication system. Then, it will push the verified usage application to the data provider for approval.

[0077] In some embodiments, after the application designer's identity verification is passed, the usage request issued by the application designer is pushed to the data provider so that the data provider can review the compliance of the usage request.

[0078] Compliance audits can include verifying the identity of the application designer, such as whether the application designer needs or should access the data requested in the usage application. In some projects, there is a division of tasks among multiple parties. Due to the confidentiality requirements of these tasks, based on this embodiment, the data provider can consider rejecting requests initiated by the application designer in another task with the corresponding permission level, thereby avoiding confusion in the division of tasks.

[0079] Compliance reviews can also include temporary access to data exceeding authorized levels. For example, if an application designer's access level does not meet the requirements for the requested data, but the application designer needs to use this data in the assigned task, the data provider may grant special permission for the application designer to use this data after review.

[0080] In some embodiments, the management platform can verify the identity of the application designer in multiple dimensions. The verification results of the primary dimensions can determine whether the identity of the application designer is legitimate, while the verification results of the secondary dimensions can prompt the data provider whether the review has been approved.

[0081] For example, the primary dimension could be whether the application designer's identity is legitimate. If the primary dimension determines that the application designer's identity is illegitimate, the application can be rejected directly without being sent to the data provider for review. If the primary dimension determines that the identity is legitimate, then the secondary dimension is used to check whether the application designer has the permission to obtain the data in the application. The application is then sent to the data provider, and the permission levels of the application designer and the requested data are indicated to help the data provider make a quick judgment.

[0082] In some embodiments, the validation of the secondary dimension includes determining the difference between the permission level of the application designer and the permission level of the requested data; if the difference in permission levels is not greater than the temporary unauthorized use threshold, the use request is pushed to the data provider; if the difference in permission levels is greater than the temporary unauthorized use threshold, the validation of the use request fails.

[0083] For example, the temporary unauthorized access threshold can be set to level 1. If an application designer requests data with a permission level exceeding their own level 1 permission, the request can be approved by the management platform and pushed to the data provider. The management platform can then notify the data provider that the application designer has requested temporary unauthorized access to data, allowing the data provider to make a judgment.

[0084] When an application designer requests data with a permission level matching their own permission level, the management platform approves the request and pushes it to the data provider. The management platform can then notify the data provider that the application designer meets the request requirements and recommend authorization.

[0085] If an application designer requests data with a permission level exceeding their own permission level and exceeding level 1, the management platform will reject the request. Furthermore, the platform can return the reason for the rejection to the application designer, informing them that they can then try to obtain further authorization through other means before resubmitting the request.

[0086] In some embodiments, the authorized data may also be preprocessed upon request by the data provider.

[0087] For example, after the data provider completes the approval process, they can call the cloud data anonymization service to perform differentiated processing on sensitive fields within the authorized data. For instance, wind turbine coordinates can be replaced with "region + number" to ensure that the anonymized data is "usable but not recognizable".

[0088] A cloud SSL VPN encrypted tunnel can be established, using an algorithm sandbox asymmetric public key to encrypt data before transmission, and implementing secondary encryption protection through the VPN channel during transmission, effectively defending against man-in-the-middle attacks.

[0089] In some embodiments, the method further includes: when the data provider provides streaming permission data, encrypting the streaming permission data in blocks, and pushing the encrypted streaming permission data to a message queue for storage.

[0090] For real-time streaming data (such as real-time streaming data generated by wind turbine sensors), a "encrypt-while-transmit" mode can be adopted. After encrypting in blocks, the data is continuously pushed to the cloud message queue via a long connection. Finally, the encrypted data is stored in the cloud object storage OSS. The system automatically configures an access control list, authorizing only the service account of the target algorithm sandbox to have read permissions, and sets lifecycle rules to achieve automatic data archiving and cleanup.

[0091] In some embodiments, the processing details of encrypted data in the cloud environment include multi-dimensional verification of data integrity and source reliability.

[0092] Data integrity and source reliability are verified through multi-dimensional checks to ensure data legitimacy. Data can be decrypted according to the application designer's permissions, preventing unauthorized access. Furthermore, decrypted data is valid only within the current task, and temporary storage is cleared from memory after the task ends, preventing misuse or leakage of data for that task.

[0093] Furthermore, multi-layered audit controls can be set up when exporting data or applying it to prevent data leakage. End-to-end auditing is implemented during the processing of encrypted data to retain logs, facilitating access by regulators.

[0094] In some embodiments, the application environment is deployed within a sandbox and a native audit mechanism is configured.

[0095] In some embodiments, a dual-path deployment integration can be adopted, which involves development and deployment within the sandbox and / or external application upload and deployment.

[0096] Taking the wind power sector as an example, models such as wind turbine fault prediction models, power output prediction models, and oil temperature early warning models for new energy wind power scenarios are completed in the sandbox. These models are then automatically packaged into container images using cloud continuous integration and continuous deployment (Cloud CI / CD) tools and pushed to the cloud container image repository. After the images are reviewed and approved by the security team, they are marked as "deployable". Models developed by external development teams need to be uploaded to the sandbox through a dedicated interface, which automatically triggers static code scanning and dynamic behavior testing (to detect whether there is data theft logic). After the scan is passed, the model enters the pre-release review stage.

[0097] In some embodiments, the gateway generates a unique access token for approved models, which is bound to contract parameters. When calling the model, the token must be included in the request header, and access to the model interface is only allowed after the gateway verifies the token.

[0098] For example, once a model passes the review, a unique access token is generated by the cloud API gateway, bound to contract parameters such as "Fault Prediction Model Token Validity Period = 30 days". The token uses JWT format (including model ID, permission scope, and validity period), is tamper-proofed by cloud KMS signature, and must be included in the request header when making calls. Access to the model interface is only allowed after the gateway verifies the token.

[0099] In some embodiments, core monitoring indicators can be established, cost accounting can be implemented, and the usage of the model can be verified in real time through a compliance audit system to support cost and compliance management.

[0100] In some embodiments, the application can be invoked and monitored.

[0101] For example, data users can submit application call requests through a sandbox. The system automatically verifies whether the requested role permissions match the application permissions. If the verification is successful, the application call request is pushed to the application designer and data provider for approval. If the approval is successful, the system can automatically update the token permissions and synchronize the adjustment record to the audit log, thereby ensuring that permission changes are traceable.

[0102] For example, the system records the entire application call chain, identifies latency bottlenecks, and immediately freezes the token and sends an alert to the security team upon detecting anomalies (such as the number of calls in a single day exceeding the contract's upper limit threshold, or calls from IP addresses not belonging to the operations and maintenance platform). After the security team verifies and confirms that the risk has been eliminated, the token is regenerated and the calling privileges are restored.

[0103] Based on the embodiments of this disclosure, the algorithm sandbox can be monitored throughout the entire process and isolation protection can be achieved.

[0104] Figure 2 This is a schematic diagram illustrating encryption and decryption interactions within a management platform for an algorithm sandbox, according to an embodiment of this disclosure.

[0105] The following is combined Figure 2 This paper will further explain the solution through a specific example.

[0106] like Figure 2 As shown, in some embodiments, the management platform may include the following functional modules: OSS, key system, algorithm sandbox, and memory corresponding to the algorithm sandbox.

[0107] Data providers can upload access control data to OSS through configured data sources. After or during the upload process, OSS can request encryption from the key system. The key system can generate a data source key (Data Encryption Key, DEK) for the data and use the generated DEK to encrypt the data. It's important to note that multiple data sources or data uploaded from multiple data sources can have multiple DEKs, thus preventing the leakage of a single DEK from leading to the leakage of all data stored in OSS.

[0108] After data is encrypted using the DEK, the key system can internally encrypt the DEK using the master key (Key Encryption Key, or KEK) to protect it. The mapping between the DEK and the encrypted access data can be maintained, for example, through an identifier or mapping table. This allows the corresponding DEK to be determined based on the data, and then decrypted using the KEK.

[0109] Encrypted data can be stored in OSS.

[0110] During the initialization phase of the sandbox, the management platform can create algorithm sandboxes and initialize them based on elastic algorithms and contracts.

[0111] During initialization, the key system can generate a sandbox key (Session Encryption Key, SEK) for the algorithm sandbox and distribute the SEK to the corresponding algorithm sandbox so that the algorithm sandbox can store the SEK.

[0112] In some embodiments, the key system may also use KEK to encrypt SEK.

[0113] In some embodiments, the DEK and / or SEK can be updated according to a rotation cycle.

[0114] The KEK does not interact with other keys, is stored in the key system, and is used internally within the key system, so it does not need to be updated.

[0115] In some embodiments, encrypting the data source key with a sandbox key includes: determining the data source key corresponding to the data provider; wherein the data source key is a key assigned to the data provider; in the case of verifying the permissions of the algorithm sandbox, determining the data source key that has been encrypted and stored with the master key, and decrypting it to obtain the data source key; determining the sandbox key corresponding to the algorithm sandbox, and encrypting the data source key with the sandbox key.

[0116] After the sandbox initialization is completed, when the application designer initiates a data usage request through the algorithm sandbox, the management platform can perform multi-level verification of the application designer's identity and usage request. This multi-round verification can be performed by the key system or by other functional modules.

[0117] Once verification is successful and the data can be shared with the application designer, the data requested by the application designer can be identified from the OSS, and the DEK used for encryption of that data can be determined. The DEK is then provided to the key system. The key system can use the KEK to decrypt the data and obtain the DEK.

[0118] The decrypted DEK is then re-encrypted using the corresponding SEK from the algorithm sandbox, and the encrypted packet is sent to the algorithm sandbox. The algorithm sandbox can decrypt the encrypted packet using the SEK stored in memory to determine the data's DEK. The decrypted DEK is then used to retrieve the data from OSS.

[0119] Figure 3 This is an organizational chart of an algorithm sandbox management platform according to an embodiment of the present disclosure.

[0120] like Figure 3 As shown, the management platform for the algorithm sandbox can include the algorithm sandbox and the cloud platform, integrating functions such as data storage, image management, application management, identity authentication, key management, data transmission, application deployment, application auditing, application release, and resource allocation, to achieve monitoring and response effects.

[0121] The users of this management platform and the functions corresponding to their identities may include, but are not limited to: data owners (data providers) can review applications and encrypt and upload data; application designers can submit usage applications to the management platform and then use the data.

[0122] In some embodiments, the application designers may include application developers, data users, and application users.

[0123] Application developers can submit a usage request when they need data during the application development phase and use the authorized data for application development. After the application development is completed, they can verify the identity of other users who want to use the application they developed. Once the verification is approved, other users can use the application developed by the application developer.

[0124] Data users who need to use data can submit a usage application and can use the data if the conditions are met.

[0125] Application users who need to use applications that have been developed or deployed in the algorithm sandbox can send a usage application to the application's developer or deployer. If the application is approved, the application in the algorithm sandbox can be invoked.

[0126] Corresponding to the embodiments of the algorithm sandbox management method of this disclosure, this disclosure also provides embodiments of the corresponding algorithm sandbox management device.

[0127] Please see Figure 4 , Figure 4 This is a block diagram of an algorithm sandbox management device in one embodiment of this disclosure. Figure 4 As shown, the management device for the algorithm sandbox includes: Configuration unit 410 is configured to determine the algorithm sandbox and configure the sandbox key for the algorithm sandbox, and the sandbox key is stored in the algorithm sandbox; The verification unit 420 is configured to receive the application design request sent by the application designer through the algorithm sandbox, verify the identity of the application designer, and push the application design request sent by the application designer to the data provider after the identity verification of the application designer is successful. Sending unit 430 is configured to encrypt the data source key with a sandbox key when the data provider approves the request. The data source key is the encryption key for the permission data provided by the data provider. The encrypted data source key is sent to the algorithm sandbox so that the algorithm sandbox can decrypt the requested permission data based on the data source key and provide it to the application designer for use.

[0128] In some embodiments, determining an algorithm sandbox and configuring a sandbox key for the algorithm sandbox includes: determining a data source for receiving data uploaded by a data provider, obtaining the data uploaded by the data provider through the data source, and classifying the uploaded data into permission data based on permission levels; determining contract configuration parameters for the algorithm sandbox, including basic permission settings, industry-specific restrictions, and dynamic adjustment mechanisms; creating an algorithm sandbox based on the configured data source and contract configuration parameters, and configuring a sandbox key for the algorithm sandbox.

[0129] In some embodiments, receiving a usage request from an application designer through an algorithm sandbox and verifying the identity of the application designer includes: determining the permission level of the application designer and determining that the permission level of the application designer matches the permission level of the data requested in the usage request.

[0130] In some embodiments, after the application designer's identity verification is passed, the usage request issued by the application designer is pushed to the data provider so that the data provider can review the compliance of the usage request.

[0131] In some embodiments, encrypting the data source key with a sandbox key includes: determining the data source key corresponding to the data provider; wherein the data source key is a key assigned to the data provider; in the case of verifying the permissions of the algorithm sandbox, determining the data source key that has been encrypted and stored with the master key, and decrypting it to obtain the data source key; determining the sandbox key corresponding to the algorithm sandbox, and encrypting the data source key with the sandbox key.

[0132] In some embodiments, the apparatus is also configured to update the sandbox key and / or data source key according to a rotation cycle.

[0133] In some embodiments, the apparatus is further configured to: when a data provider provides streaming permission data, to encrypt the streaming permission data in blocks and push the encrypted streaming permission data to a message queue for storage.

[0134] The specific implementation process of the functions and roles of each unit in the above device can be found in the implementation process of the corresponding steps in the above method, and will not be repeated here.

[0135] Embodiments of this disclosure also provide an electronic device, including: a processor and a memory; the memory for storing a computer program; and the processor for executing the algorithm sandbox management method as described in any of the above embodiments by invoking the computer program.

[0136] Embodiments of this disclosure also propose a computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the algorithm sandbox management method as described in any of the above embodiments.

[0137] Embodiments of this disclosure also provide a computer program product, including a computer program that, when executed by a processor, implements the method as described in any of the foregoing embodiments.

[0138] Please see Figure 5 , Figure 5 This is a schematic diagram of the structure of a computer device provided in an optional embodiment of the present invention, such as... Figure 5 As shown, the computer device includes one or more processors 10, memory 20, and interfaces for connecting the components, including high-speed interfaces and low-speed interfaces. The components communicate with each other via different buses and can be mounted on a common motherboard or otherwise installed as needed. The processors can process instructions executed within the computer device, including instructions stored in or on memory to display graphical information of a GUI on external input / output devices (such as display devices coupled to the interfaces). In some alternative implementations, multiple processors and / or multiple buses can be used with multiple memories and multiple memory modules, if desired. Similarly, multiple computer devices can be connected, each providing some of the necessary operations (e.g., as a server array, a group of blade servers, or a multiprocessor system).

[0139] Processor 10 may be a central processing unit, a network processor, or a combination thereof. Processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The programmable logic device may be a complex programmable logic device (CAMP), a field-programmable gate array (FPGA), a general-purpose array logic (GDA), or any combination thereof.

[0140] The memory 20 stores instructions executable by at least one processor 10 to cause at least one processor 10 to perform the method shown in the above embodiments.

[0141] The memory 20 may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function; the data storage area may store data created based on the use of the computer device as shown by a landing page for an app. Furthermore, the memory 20 may include high-speed random access memory and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some alternative embodiments, the memory 20 may optionally include memory remotely located relative to the processor 10, which can be connected to the computer device via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0142] The memory 20 may include volatile memory, such as random access memory; the memory may also include non-volatile memory, such as flash memory, hard disk or solid-state drive; the memory 20 may also include a combination of the above types of memory.

[0143] The computer device also includes a communication interface 30 for communicating with other devices or communication networks.

[0144] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the disclosure herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the following claims.

[0145] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.

[0146] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. The terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0147] The methods and apparatus provided in the embodiments of this disclosure have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this disclosure. The descriptions of the embodiments above are only for the purpose of helping to understand the methods and core ideas of this disclosure. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this disclosure. Therefore, the content of this specification should not be construed as a limitation of this disclosure.

Claims

1. A method for managing an algorithm sandbox, characterized in that, The method includes: An algorithm sandbox is determined and a sandbox key is configured for the algorithm sandbox, and the sandbox key is stored in the algorithm sandbox; Receive a usage request from the application designer through the algorithm sandbox and verify the identity of the application designer; After the application designer's identity is verified, the usage request issued by the application designer will be pushed to the data provider; If the data provider approves the application, the data source key is encrypted using the sandbox key, where the data source key is the encryption key for the permission data provided by the data provider. The encrypted data source key is sent to the algorithm sandbox, so that the algorithm sandbox can decrypt the requested permission data based on the data source key and provide it to the application designer for use.

2. The method according to claim 1, characterized in that, The process of determining the algorithm sandbox and configuring the sandbox key for the algorithm sandbox includes: Determine a data source for receiving data uploaded by the data provider, obtain the data uploaded by the data provider through the data source, and classify the uploaded data into permission data based on permission levels; The contract configuration parameters of the algorithm sandbox are determined, including basic permission settings, industry-specific restrictions, and dynamic adjustment mechanisms. The algorithm sandbox is created based on the configured data source and the contract configuration parameters, and a sandbox key is configured for the algorithm sandbox.

3. The method according to claim 1, characterized in that, The process of verifying the identity of the application designer by receiving the usage request sent through the algorithm sandbox includes: Determine the permission level of the application designer, and determine whether the permission level of the application designer matches the permission level of the data requested in the usage application.

4. The method according to claim 1, characterized in that, After the identity verification of the application designer is passed, the usage application issued by the application designer is pushed to the data provider so that the data provider can review the compliance of the usage application.

5. The method according to claim 1, characterized in that, The step of encrypting the data source key using the sandbox key includes: Determine the data source key corresponding to the data provider; wherein, the data source key is a key assigned to the data provider; If the permissions of the algorithm sandbox are verified, the data source key, which is encrypted and stored with the master key, is determined and decrypted to obtain the data source key; Determine the sandbox key corresponding to the algorithm sandbox, and encrypt the data source key using the sandbox key.

6. The method according to claim 1, characterized in that, The method further includes: The sandbox key and / or the data source key are updated according to the rotation cycle.

7. The method according to claim 1, characterized in that, The method further includes: When the data provider provides streaming permission data, the streaming permission data is encrypted in blocks, and the encrypted streaming permission data is pushed to a message queue for storage.

8. A management device for an algorithm sandbox, characterized in that, The device includes: The configuration unit is configured to determine an algorithm sandbox and configure a sandbox key for the algorithm sandbox, the sandbox key being stored within the algorithm sandbox; The verification unit is configured to receive a usage request sent by the application designer through the algorithm sandbox, verify the identity of the application designer, and push the usage request sent by the application designer to the data provider after the identity verification of the application designer is successful. The sending unit is configured to, upon the data provider's approval of the application, encrypt the data source key using the sandbox key, wherein the data source key is the encryption key for the permission data provided by the data provider; send the encrypted data source key to the algorithm sandbox so that the algorithm sandbox can decrypt the applied permission data based on the data source key and provide it to the application designer for use.

9. An electronic device, characterized in that, include: Processor, memory; The memory is used to store computer programs; The processor is configured to execute the algorithm sandbox management method as described in any one of claims 1-7 by invoking the computer program.

10. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the method for managing an algorithmic sandbox as described in any one of claims 1 to 7.