Privacy computing method and apparatus, electronic device, and storage medium

By integrating privacy computing algorithms with blockchain smart contract technology, a privacy computing contract architecture is constructed, and the problems of algorithm opacity, high cost and difficulty in monitoring and auditing in the existing technology are solved, and the security, credibility and cost reduction of data and algorithms are achieved.

WO2025092476A1PCT designated stage expired Publication Date: 2025-05-08ZTE CORP

Patent Information

Application Number
PCT/CN2024/126053
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-10-30
Filing Date
2024-10-21
Publication Date
2025-05-08

AI Technical Summary

Technical Problem

In practice, existing privacy computing technologies have the opacity of algorithms to all participants, the high cost of trusted execution environment, and the inability to meet the monitoring and audit requirements of trusted computing in the entire process of data.

Method used

By integrating privacy computing algorithms with blockchain smart contract technology, a privacy computing contract architecture is constructed, pure soft design that does not rely on hardware, reduce costs, and store privacy computing encryption results on the blockchain to achieve monitoring and auditing.

Benefits of technology

It realizes the security and trustworthiness of data and algorithms, reduces hardware costs, simplifies algorithm upgrades, and supports privacy computing monitoring and auditing in the circulation of data elements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024126053_08052025_PF_FP_ABST
    Figure CN2024126053_08052025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of communications, and discloses a privacy computing method and system, an electronic device, and a storage medium. According to the present application, a privacy computing task request sent by a task initiator node is acquired, the privacy computing task request comprising an algorithm identifier and a plurality of data identifiers; a target privacy computing algorithm corresponding to the algorithm identifier is acquired from a blockchain, encrypted data corresponding to the data identifiers is acquired from task participant nodes, and privacy computing encryption results are obtained by means of computation; the privacy computing encryption results are stored on the blockchain; and a query request parameter carrying a target result identifier sent by the task initiator node is received, a privacy computing encryption result corresponding to the target result identifier is acquired from the blockchain, and a privacy computing result is obtained on the basis of the privacy computing encryption result.
Need to check novelty before this filing date? Find Prior Art

Description

Privacy computing method, device, electronic device and storage medium

[0001] Cross-references

[0002] This application claims priority to the Chinese patent application filed with the China Patent Office on October 30, 2023, with application number 202311435235.9 and invention name “Privacy computing method, device, electronic device and storage medium”. The entire contents of the application are incorporated by reference into this application. Technical Field

[0003] The present application relates to the field of communication technology, and in particular to privacy computing methods, devices, electronic devices and storage media. Background Art

[0004] Data has become a new factor of production. Accelerating the market-based allocation of data has become an essential path to promoting high-quality digital development. As a technological product, data, due to its virtuality, low-cost replicability, and diverse subject matter, carries the risk of easy copying and leakage during its circulation. The industry is still exploring how to ensure the orderly flow and secure application of data while ensuring its availability, manageability, integrity, accuracy, security, and reliability.

[0005] Currently, the industry primarily uses a solution that combines multi-party secure computing (MSPC) and a trusted execution environment (TEE) in privacy computing technology. This approach uses MPC technology to improve data security at the software level, achieving "available but invisible" data, while TEE provides a secure and complete independent processing environment at the hardware level, achieving trusted computing of data elements at both the software and hardware levels. However, this solution has the following problems in practice:

[0006] 1. Storing the privacy computing algorithm in a trusted execution environment can prevent the algorithm from being tampered with through memory isolation and restricted access. However, it cannot make the algorithm completely open and transparent to all participants, making it inconvenient to monitor and audit privacy computing in the circulation of data elements.

[0007] 2. The trusted execution environment relies on hardware implementation, which is relatively costly.

[0008] 3. Simple privacy computing cannot meet the requirements of in-process monitoring and post-audit required for trusted computing of the entire data process.

[0009] Summary of the Invention

[0010] The main purpose of this application is to provide a privacy computing method, device, electronic device and storage medium.

[0011] The present application provides a privacy computing method, including: obtaining a privacy computing task request sent by a task initiator node, the privacy computing task request including an algorithm identifier and multiple data identifiers, wherein one data identifier corresponds to the encrypted data required for a task participant node to participate in the privacy computing; obtaining a target privacy computing algorithm corresponding to the algorithm identifier from a blockchain, and obtaining the encrypted data corresponding to the data identifier from each of the task participant nodes, and calculating a privacy computing encryption result; storing the privacy computing encryption result in the blockchain, wherein each stored privacy computing encryption result corresponds to a unique result identifier; receiving a query request parameter carrying a target result identifier sent by the task initiator node, obtaining the privacy computing encryption result corresponding to the target result identifier from the blockchain, and obtaining a privacy computing result based on the privacy computing encryption result.

[0012] The present application also provides a privacy-preserving computing device, comprising: a first acquisition module, configured to acquire a privacy-preserving computing task request sent by a task initiator node, the privacy-preserving computing task request including an algorithm identifier and multiple data identifiers, wherein one data identifier corresponds to the encrypted data required for a task participant node to participate in the privacy-preserving computing; a second acquisition module, configured to acquire the target privacy-preserving computing algorithm corresponding to the algorithm identifier from a blockchain, and to acquire the encrypted data corresponding to the data identifier from each task participant node, and to calculate a privacy-preserving computing encryption result; a privacy-preserving computing module, configured to store the privacy-preserving computing encryption result in the blockchain, wherein each stored privacy-preserving computing encryption result corresponds to a unique result identifier; and a result query module, configured to receive a query request parameter carrying a target result identifier sent by the task initiator node, and to acquire the privacy-preserving computing encryption result corresponding to the target result identifier from the blockchain, so as to obtain a privacy-preserving computing result based on the privacy-preserving computing encryption result. The present application also provides an electronic device, comprising: a memory, a processor, and a privacy-preserving computing program stored in the memory and executable on the processor, wherein the privacy-preserving computing program implements the privacy-preserving computing method described above when executed by the processor.

[0013] The present application also provides a computer-readable storage medium, on which a privacy computing program is stored. When the privacy computing program is executed by a processor, the privacy computing method as described above is implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments recorded in the embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0015] Figure 1 is a heat dissipation group of an embodiment of the present application. In order to more clearly illustrate the embodiment of the present application or the technical solution in the prior art, the following will briefly introduce the drawings required for use in the embodiment or the prior art description. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the structures shown in these drawings without paying any creative work.

[0016] FIG1 is a flowchart of the first embodiment of the privacy computing method of the present application;

[0017] FIG2 is a schematic diagram of a trusted computing contract system framework in an embodiment of the present application;

[0018] FIG3 is a schematic diagram of a transaction scenario of the key storage module in FIG2 ;

[0019] FIG4 is a schematic diagram of a transaction scenario of the encrypted data evidence storage module in FIG2 ;

[0020] FIG5 is a schematic diagram of a transaction scenario of the result evidence storage module and the decryption module in FIG2 ;

[0021] FIG6 is a flowchart of generating a privacy-preserving computing contract in an embodiment of the present application;

[0022] FIG7 is a timing diagram of the privacy computing method in an embodiment of the present application;

[0023] FIG8 is a schematic diagram of the functional modules of a privacy-preserving computing device according to an embodiment of the present application;

[0024] FIG9 is a schematic diagram of the hardware structure of the electronic device involved in the embodiment of the present application.

[0025] The realization of the objectives, functional features and advantages of this application will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION

[0026] It should be understood that the specific embodiments described herein are only used to explain the present application and are not intended to limit the present application.

[0027] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments of this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0028] It should be noted that all directional indications in the embodiments of the present application (such as up, down, left, right, front, back, etc.) are only used to explain the relative position relationship, movement status, etc. between the various components under a certain specific posture (as shown in the accompanying drawings). If the specific posture changes, the directional indication will also change accordingly.

[0029] In this application, unless otherwise specified or limited, the terms "connection" and "fixation" should be understood in a broad sense. For example, "fixation" can mean fixed connection, detachable connection, or integration; mechanical connection or electrical connection; direct connection or indirect connection through an intermediate medium; internal communication between two elements or interaction between two elements, unless otherwise specified. For those skilled in the art, the specific meanings of the above terms in this application can be understood according to specific circumstances.

[0030] In addition, the descriptions of "first", "second", etc. in this application are for descriptive purposes only and should not be understood as indicating or implying their relative importance or implicitly indicating the number of the technical features indicated. Therefore, the features defined as "first" or "second" may explicitly or implicitly include at least one of such features. In addition, the technical solutions between the various embodiments can be combined with each other, but this must be based on the fact that they can be implemented by ordinary technicians in this field. When the combination of technical solutions is contradictory or cannot be implemented, it should be deemed that such combination of technical solutions does not exist and is not within the scope of protection required by this application.

[0031] Currently, the industry primarily uses a solution that combines multi-party secure computing (MSPC) and a trusted execution environment (TEE) in privacy computing technology. This approach uses MPC technology to improve data security at the software level, achieving "available but invisible" data, while TEE provides a secure and complete independent processing environment at the hardware level, achieving trusted computing of data elements at both the software and hardware levels. However, this solution has the following problems in practice:

[0032] 1. Storing the privacy computing algorithm in a trusted execution environment can prevent the algorithm from being tampered with through memory isolation and restricted access. However, it cannot make the algorithm completely open and transparent to all participants, making it inconvenient to monitor and audit privacy computing in the circulation of data elements.

[0033] 2. The trusted execution environment relies on hardware implementation, which is relatively costly.

[0034] 3. Simple privacy computing cannot meet the requirements of in-process monitoring and post-audit required for trusted computing of the entire data process.

[0035] Based on this, an embodiment of the present application provides a privacy-preserving computing method. Referring to FIG1 , FIG1 is a flow chart of an embodiment of a privacy-preserving computing method of the present application. In this embodiment, the privacy-preserving computing method includes:

[0036] Step S10: Obtain a privacy computing task request sent by the task initiator node. The privacy computing task request includes an algorithm identifier and multiple data identifiers, where one data identifier corresponds to the encrypted data required for a task participant node to participate in privacy computing.

[0037] Those skilled in the art know that privacy computing refers to a series of information technologies that analyze and calculate data while ensuring that the data provider does not leak the original data, thereby ensuring that the data is "available but invisible" during the circulation and integration process.

[0038] The embodiments of the present application are mainly used in multi-party data privacy computing scenarios during the circulation of data elements. For example, in the federated learning scenario, federated learning aims to establish a federated learning model based on a distributed data set. It is a learning model that collaboratively completes machine learning tasks without the original data being stored. The participants in federated learning jointly train a network model. Each participant trains and calculates their own samples locally. They need to exchange their own training gradient data and jointly calculate a gradient value suitable for both parties based on the gradient data of both parties to perform the joint gradient descent process.

[0039] In this embodiment, one algorithm identifier corresponds to one privacy-preserving computing algorithm, wherein the first preset node in the blockchain may store multiple different algorithm identifiers and a first mapping relationship between each algorithm identifier and the privacy-preserving computing algorithm.

[0040] After step S10, step S20 is executed to obtain the target privacy computing algorithm corresponding to the algorithm identifier from the blockchain, and obtain the encrypted data corresponding to the data identifier from each task participant node, and calculate the privacy computing encryption result.

[0041] Among them, the target privacy computing algorithm is the privacy computing algorithm corresponding to the algorithm identifier sent by the task initiator node.

[0042] In this embodiment, the algorithm identifier sent by the task initiator node can be obtained, and the first mapping relationship can be queried from the first preset node of the blockchain to retrieve the corresponding privacy computing algorithm (the corresponding privacy computing algorithm is the target privacy computing algorithm), and the encrypted data corresponding to the data identifier can be obtained from each task participant node. Then, based on the encrypted data obtained from each task participant node and combined with the target privacy computing algorithm, the privacy computing encryption result is calculated.

[0043] It should be noted that this encrypted data is obtained by encrypting the original data required for the secure multi-party privacy computation by the task participant nodes. The algorithm used to encrypt this original data is asymmetric, meaning that the encryption key used to encrypt the original data is inconsistent with the decryption key corresponding to the encrypted data (to prevent unauthorized parties from stealing the encryption key and decrypting the encrypted data, thereby obtaining the original data involved in the secure multi-party privacy computation and leaking the privacy information of the participating nodes).

[0044] Among them, secure multi-party privacy computing means: in the absence of a trusted third party, multiple participants jointly calculate an objective function, and ensure that each party only obtains its own calculation results, and it is impossible to infer the input data of any other party through the interaction data during the calculation process.

[0045] The embodiment of the present application obtains the encrypted data from each task participant node instead of directly obtaining the original data of the task participant node participating in the secure multi-party privacy computing, thereby avoiding the leakage of private data, improving the security of the privacy computing process, and ensuring that the data is "available but invisible" during the circulation and integration process.

[0046] After step S20, step S30 is executed to store the privacy computing encryption result in the blockchain, wherein each stored privacy computing encryption result corresponds to a unique result identifier.

[0047] That is, the encrypted data is encrypted and the resulting privacy-preserving computation result is stored on-chain. It should be noted that the second preset node in the blockchain can store multiple different privacy-preserving computation encryption results, as well as a second mapping relationship between each privacy-preserving computation encryption result and a result identifier.

[0048] Step S40: Receive a query request parameter carrying a target result identifier sent by the task initiator node, obtain a privacy-preserving computing encryption result corresponding to the target result identifier from the blockchain, and obtain a privacy-preserving computing result based on the privacy-preserving computing encryption result.

[0049] In this embodiment, by receiving the query request parameter carrying the target result identifier sent by the task initiator node, the second mapping relationship can be queried from the second preset node of the blockchain to retrieve the corresponding privacy computing encryption result (that is, the privacy computing encryption result corresponding to the target result identifier is obtained from the chain), and based on the privacy computing encryption result obtained from the chain, the customer (the customer in this case refers to the task initiator node) can obtain the final required data information (that is, the privacy computing result).

[0050] As an example, the step of obtaining a privacy computing result based on the privacy computing encryption result includes: step A10, sending the privacy computing encryption result to the task initiator node, so that the task initiator node decrypts the privacy computing encryption result based on the decryption key corresponding to the encrypted data to obtain the privacy computing result.

[0051] In this embodiment, the decryption key corresponding to the encrypted data is stored in the task initiator node. Those skilled in the art will know that the decryption key corresponding to the encrypted data is also the decryption key of the privacy computing encryption result.

[0052] This embodiment can send the privacy calculation encryption result to the task initiator node, so that the task initiator node can decrypt the privacy calculation encryption result based on the decryption key corresponding to the encrypted data to obtain the privacy calculation result, thereby enabling the task initiator to obtain the privacy calculation result calculated by participating in the secure multi-party privacy calculation. Since the privacy calculation result requires the task initiator's private decryption key to decrypt the privacy calculation encryption result, it effectively avoids the leakage of privacy data, thereby improving the security of the privacy calculation process and ensuring that the data is "available but invisible" during the circulation and integration process.

[0053] As another example, the step of obtaining a privacy-preserving computing result based on the privacy-preserving computing encryption result includes:

[0054] Step B10: decrypt the privacy computing encryption result based on the decryption key corresponding to the encrypted data to obtain a privacy computing result.

[0055] Step B20: Send the privacy calculation result to the task initiator node.

[0056] In this embodiment, the decryption key corresponding to the encrypted data is stored in the key storage module of the trusted computing contract platform (at this time, the client terminal corresponding to the trusted computing contract platform is the executor of the privacy computing method of the embodiment of this application), and is not stored on the chain (that is, the decryption key corresponding to the encrypted data is not stored on the blockchain).

[0057] Specifically, this embodiment integrates privacy-preserving computing algorithms with blockchain smart contract technology to construct a privacy-preserving computing contract architecture and proposes a trusted computing contract framework (including a trusted computing contract platform) to ensure the security and reliability of data and algorithms during privacy-preserving computing. This trusted computing contract platform implements a purely software-based design independent of hardware, achieving cost reductions, facilitating algorithm upgrades, and enabling monitoring and auditing of privacy-preserving computing during the circulation of data elements.

[0058] This embodiment can decrypt the privacy calculation encryption result based on the decryption key corresponding to the encrypted data to obtain the privacy calculation result, and send the privacy calculation result to the task initiator node, so that the task initiator can obtain the privacy calculation result calculated by participating in the secure multi-party privacy calculation. Since the privacy calculation result and the decryption key are not stored on the chain, illegal persons cannot obtain the original data information of the task initiator (that is, the original data participating in the secure multi-party privacy calculation) and the privacy calculation result through the privacy calculation encryption result, thereby effectively avoiding the leakage of privacy data. In one embodiment, the security of the privacy calculation process is improved, ensuring that the data is "available but invisible" during the circulation and integration process.

[0059] It is known to those skilled in the art that blockchain is a technology set composed of multiple technologies such as consensus algorithms, cryptography and distributed storage. It combines data in a sequential manner in chronological order into a chain data structure with the characteristics of decentralization, information immutability, information transparency and joint maintenance. The smart contract platform (the executor of the privacy computing method in this embodiment of the application) can automatically execute the contract on behalf of each signatory without relying on a central agency. Due to the decentralized nature of the blockchain, the results of the smart contract execution will be saved on all nodes, ensuring the credibility and immutability of the execution results. By combining privacy computing with blockchain technology, this embodiment can not only effectively protect sensitive information in the process of data circulation and sharing, but also realize data sharing that is recordable, verifiable, traceable, auditable, controllable and secure and reliable throughout the entire process.

[0060] It should be noted that in this embodiment, any task initiator node among the above-mentioned task participant nodes can be converted into a task initiator node, and the task initiator node can also be converted into a task participant node. After the role conversion, if the processing logic of the privacy computing method of the embodiment of this application is still executed, that is, even if the task participant node and / or the task initiator node undergoes a role conversion, if the processing logic of the task participant node and the task initiator node itself is essentially the same as the technical concept of the embodiment of this application, it is still within the scope of protection of this application.

[0061] The present application proposes a privacy computing method, device, electronic device and storage medium. In the privacy computing method, the technical solution of the embodiment of the present application is to obtain a privacy computing task request sent by the task initiator node, and the privacy computing task request includes an algorithm identifier and multiple data identifiers, wherein one data identifier corresponds to the encrypted data required for a task participant node to participate in the privacy computing; obtain the target privacy computing algorithm corresponding to the algorithm identifier from the blockchain, and obtain the encrypted data corresponding to the data identifier from each task participant node, calculate the privacy computing encryption result, and store the privacy computing encryption result in the blockchain, wherein each stored privacy computing encryption result corresponds to a unique Result identifier, and then receive the query request parameter carrying the target result identifier sent by the task initiator node, obtain the privacy computing encryption result corresponding to the target result identifier from the blockchain, and obtain the privacy computing result based on the privacy computing encryption result, so that the embodiment of this application integrates and innovates the privacy computing algorithm and blockchain smart contract technology, constructs a privacy computing contract architecture, and proposes a trusted computing contract framework to achieve data and algorithm security and reliability in the privacy computing process. The privacy computing contract architecture realizes a pure software design that does not rely on hardware, meets the requirements of reducing hardware costs, and more convenient algorithm upgrade operations, and can monitor and audit privacy computing in the circulation of data elements.

[0062] To help understand the technical concept of the embodiments of the present application, a specific embodiment 1 is listed below with reference to FIG2 . FIG2 is a schematic diagram of the trusted computing contract system framework in the embodiments of the present application. The terminal corresponding to the trusted computing contract platform is the executor of the privacy computing method in the embodiments of the present application, which includes:

[0063] The privacy computing task initiator is used to generate encryption and decryption key pairs and initiate privacy computing request tasks (i.e., privacy computing task requests).

[0064] Trusted computing contract platform, providing trusted privacy computing functions based on privacy computing contracts;

[0065] Privacy computing task participants are used to participate in privacy computing tasks.

[0066] In one embodiment, after the privacy computing task initiator generates an encryption and decryption key pair locally, it stores the encryption key (i.e., an asymmetric encryption key) in the key storage module in the trusted computing contract platform. Its local original data set is encrypted with the encryption key and becomes encrypted data stored in the local privacy data set. Before initiating the privacy computing task, the hash value of the required encrypted data is stored in the blockchain through the encrypted data notarization module; the task initiator sends a request to execute the privacy computing contract (i.e., a privacy computing task request), and after the privacy computing task is completed, it obtains the privacy computing contract execution result (i.e., the privacy computing encryption result) from the blockchain through the result notarization module.

[0067] In one embodiment, the trusted computing contract platform can be divided into three layers: a blockchain infrastructure layer, a privacy-preserving computing contract interface layer, and a privacy-preserving computing contract application layer. The blockchain infrastructure layer primarily includes the underlying blockchain engine, providing blockchain capabilities that are tamper-proof, decentralized, and fully traceable.

[0068] The privacy-preserving computing contract interface layer provides privacy-preserving computing contract applications with interfaces for reading and writing ledgers, as well as obtaining encrypted data:

[0069] Ledger reading interface (GetState): Communicates with the blockchain node through the grpc protocol to obtain the corresponding ledger data at the node. Among them, gRPC is a high-performance, open source, and universal RPC (Remote Procedure Call) framework.

[0070] Ledger write interface (PutState): Communicates with blockchain nodes through the grpc protocol, sends data to the node, and writes the data to the node ledger after reaching consensus on the corresponding transaction.

[0071] Encrypted data acquisition interface (GetEncryptedData): obtains the corresponding encrypted data stored in each participant's private data set based on the privacy computing participant's address information and the participant's data identifier (dataId).

[0072] This embodiment proposes a trusted computing contract framework, solves the adaptation problem between privacy computing and smart contracts based on this framework, constructs a privacy computing contract architecture, and realizes the adaptation and transformation of privacy computing algorithms and processes.

[0073] Among related technologies, privacy computing improves the security of data circulation at the technical level and can achieve "available but invisible" data. However, in practice, the following problems still exist: (1) The trustworthiness of data and algorithms in the privacy computing process: how to make the algorithms completely transparent to users so as to review their security; (2) The trusted execution environment relies on hardware implementation, which is costly and has the problem that algorithms cannot be updated or are difficult to update; (3) Simple privacy computing cannot meet the requirements of pre-authorization, in-process monitoring, and post-audit required for trusted computing of the entire data process.

[0074] To address these issues, this embodiment integrates privacy-preserving computing algorithms with blockchain smart contract technology, proposing a trusted computing contract framework. Through smart contracts, this framework ensures the security and reliability of data and algorithms during privacy-preserving computing. This framework utilizes a hardware-independent, purely software-based design, reducing costs and facilitating algorithm upgrades. It also enables monitoring and auditing of privacy-preserving computing during the circulation of data elements.

[0075] It should be noted that although the above-mentioned specific embodiment 1 shows many details, it is only used to help understand the technical concept or technical principle of the embodiment of this application, and does not constitute a limitation of this application. More simple transformations based on this technical concept should all be within the scope of protection of this application.

[0076] In order to help understand the application scenario or technical concept of the embodiment of the present application in one embodiment, the following specific embodiment 2 is listed:

[0077] This embodiment is mainly used in multi-party data privacy computing scenarios during the circulation of data elements, such as federated learning scenarios. Combined with the homomorphic encryption algorithm, it can achieve the invisible availability of gradient data in the federated learning process, avoiding the inference of private information such as training data, labels, and models from the gradient data of several iterations. The specific implementation content of the homomorphic encryption privacy computing contract constructed based on the trusted computing contract framework of the embodiment of this application is as follows:

[0078] 1. Implement the encryption key storage module, construct a key storage transaction, store the homomorphic encryption key in the blockchain, and provide a key retrieval method to obtain the stored homomorphic encryption key.

[0079] 2. Implement the encrypted data notarization module, construct the encrypted data hash notarization transaction, and store the hash value of the encrypted training data of the federated learning participants in the blockchain.

[0080] 3. Implement the result notarization and decryption module, construct the result notarization transaction and store the homomorphic encryption result on the chain, and provide a decryption method to obtain the plaintext calculation result based on the homomorphic encryption result and decryption key.

[0081] 4. Implement the privacy computing module, where the homomorphic encryption algorithm is implemented as follows:

[0082] 1) Implementing homomorphic "addition" and homomorphic "multiplication" of encrypted data, wherein the "addition" operation includes the plaintext polynomial "adding" the ciphertext polynomial, and the ciphertext polynomial "adding" the ciphertext polynomial operation; and the "multiplication" operation includes the plaintext polynomial "multiplying" the ciphertext polynomial, and the ciphertext polynomial "multiplying" the ciphertext polynomial operation.

[0083] 2) Implement data encryption and decryption of federated learning training data based on the above-mentioned key storage module and decryption module.

[0084] 3) Use the encrypted data acquisition interface in the privacy computing contract layer to obtain the encrypted data of the federated learning participants required for the privacy computing task.

[0085] 4) Based on the above-mentioned result storage module, the calculation results of the federated learning data through homomorphic "addition" or homomorphic "multiplication" are stored on the blockchain, making the calculation results traceable.

[0086] In the above homomorphic encryption privacy computing contract, homomorphic encryption data storage, homomorphic encryption algorithm execution, homomorphic encryption result storage and decryption are carried out during the federated learning process, which can ensure the security and reliability of the data and algorithm of the homomorphic encryption process.

[0087] It should be noted that Specific Example 2 is only used to help understand the application scenarios or technical concepts of the embodiments of the present application, and does not constitute a limitation on the embodiments of the present application. More simple transformations based on the technical concept should all be within the scope of protection of this application.

[0088] In one possible implementation, the privacy-preserving computing task request further includes a target key identifier, and before obtaining the privacy-preserving computing task request sent by the task initiator node, further includes:

[0089] Step C10: Obtain the asymmetric encryption key sent by the task initiator node, and store the encryption key in the blockchain, wherein each stored encryption key corresponds to a unique key identifier, and the encryption key is the encryption key corresponding to the encrypted data.

[0090] In this embodiment, one key identifier corresponds to one encryption key, and the third preset node in the blockchain may store multiple different key identifiers, as well as a third mapping relationship between each key identifier and the encryption key.

[0091] Step C20, the step of calculating and obtaining the privacy calculation encryption result includes:

[0092] Step C30: Obtain the target encryption key corresponding to the target key identifier from the blockchain.

[0093] The target encryption key is the encryption key corresponding to the target key identifier.

[0094] In this embodiment, by obtaining the target key identifier sent by the task initiator node, the third mapping relationship can be queried from the third preset node of the blockchain to retrieve the corresponding encryption key (the corresponding encryption key is the target encryption key).

[0095] In step C40, the target encryption key and the encrypted data obtained from each of the task participant nodes are used as input parameters of the target privacy computing algorithm to calculate and obtain a privacy computing encryption result.

[0096] This embodiment obtains the target encryption key corresponding to the target key identifier from the blockchain, and uses the target encryption key and the encrypted data obtained from each task participant node as input parameters of the target privacy computing algorithm for calculation, so as to accurately calculate the privacy computing encryption result and accurately obtain the encrypted privacy computing result. After the task initiator obtains the privacy computing encryption result from the blockchain, it can decrypt the privacy computing encryption result through the private decryption key, so that the customer (the customer at this time can refer to the task initiator node) can obtain the final required data information.

[0097] In a possible implementation, the privacy-preserving computing task request further includes an information identifier corresponding to the encrypted information required by the task initiator node to participate in the privacy-preserving computing.

[0098] The step of using the target encryption key and the encrypted data obtained from each of the task participant nodes as input parameters of the target privacy computing algorithm to calculate the privacy computing encryption result further includes:

[0099] Step D10: Obtain the encrypted information corresponding to the information identifier from the task initiator node.

[0100] The embodiment of the present application obtains the encrypted information from the task initiator node instead of directly obtaining the original data of the task initiator node participating in the secure multi-party privacy computing, thereby avoiding the leakage of private data, improving the security of the privacy computing process, and ensuring that the data is "available but invisible" during the circulation and integration process.

[0101] Step D20: Use the target encryption key, the encrypted information obtained from the task initiator node, and the encrypted data obtained from each of the task participant nodes as input parameters of the target privacy computing algorithm to calculate the privacy computing encryption result.

[0102] In this embodiment, the encrypted information is the encrypted data corresponding to the task initiator node. That is, the encrypted information is obtained by the task initiator node encrypting the original data required to participate in the secure multi-party privacy computation. The encrypted data obtained from the task participant node is obtained by the task participant node encrypting the original data required to participate in the secure multi-party privacy computation.

[0103] This embodiment obtains the encrypted information corresponding to the information identifier from the task initiator node, and uses the target encryption key, the encrypted information obtained from the task initiator node, and the encrypted data obtained from each task participant node as input parameters of the target privacy calculation algorithm. In this way, on the basis of multiple task participant nodes inputting their respective data information to participate in secure multi-party privacy calculation, it also adds a scenario in which the task initiator node itself can also input its own data information to participate in secure multi-party privacy calculation, enriching the scenario application requirements of secure multi-party privacy computing, and thereby improving the robustness of the privacy calculation method of the embodiment of this application.

[0104] In one possible implementation, the privacy-preserving computing task request further includes a target hash data identifier, and before obtaining the target privacy-preserving computing algorithm corresponding to the algorithm identifier from the blockchain, further includes:

[0105] Step E10: Obtain the hash value corresponding to the encrypted information and the hash value of the encrypted data corresponding to each of the task participant nodes, and store the obtained hash values ​​in the blockchain, wherein each stored hash value corresponds to a unique hash value identifier.

[0106] In one embodiment, after obtaining the encrypted information corresponding to the information identifier from the task initiator node, the method further includes:

[0107] Step F10, performing hash calculation on the encrypted information obtained from the task initiator node to obtain the first actual hash value corresponding to the task initiator node, and performing hash calculation on the encrypted data obtained from each of the task participant nodes to obtain the second actual hash value corresponding to each of the task participant nodes.

[0108] Step F20, based on the first hash value identifier sent by the task initiator node, obtain the first target hash value of the encrypted information sent by the task initiator node from the blockchain, and based on the second hash value identifier sent by each task participant node, obtain the second target hash value of the encrypted data sent by each task participant node from the blockchain.

[0109] Step F30 : performing a security check on the encrypted information sent by the task initiator node according to the first actual hash value and the first target hash value to obtain a first security check result.

[0110] In an exemplary embodiment, in step F30, the step of performing security verification on the encrypted information sent by the task initiator node according to the first actual hash value and the first target hash value to obtain a first security verification result includes:

[0111] Step G10: When the first actual hash value and the first target hash value are inconsistent, determining that the first security verification result is a verification failure.

[0112] Step G20: When the first actual hash value is consistent with the first target hash value, determine that the first security verification result is successful.

[0113] This embodiment performs security verification on the encrypted information sent by the task initiator node by comparing whether the first actual hash value and the first target hash value are consistent, thereby preventing illegal persons from maliciously tampering with the encrypted information sent by the task initiator node, and preventing errors in the data uploaded by the task initiator node, which affects the security and credibility of the privacy calculation process in the circulation of data elements.

[0114] After step F30, step F40 is executed to perform security verification on the encrypted data sent by each task participant node based on the second actual hash value and the second target hash value to obtain a second security verification result corresponding to each task participant node.

[0115] In an exemplary embodiment, in step F40, the step of performing security verification on the encrypted data sent by each of the task participant nodes based on the second actual hash value and the second target hash value to obtain a second security verification result corresponding to each of the task participant nodes includes:

[0116] Step H10: respectively compare the second actual hash value and the second target hash value corresponding to the same task participant node to obtain a comparison result corresponding to each task participant node.

[0117] In step H20, when all the comparison results are consistent, it is determined that the second security verification results corresponding to all the task participant nodes are successful.

[0118] This embodiment performs security verification on the encrypted data sent by the task participant node by comparing the second actual hash value and the second target hash value corresponding to the same task participant node to see if they are consistent, thereby preventing illegal persons from maliciously tampering with the encrypted data sent by the task participant node, and preventing errors in the data uploaded by the task participant node itself, which affects the security and credibility of the privacy calculation process in the circulation of data elements.

[0119] After step F40, execute step F50. When the first security verification result and each of the second security verification results are successful, execute the step of using the target encryption key, the encrypted information obtained from the task initiator node, and the encrypted data obtained from each of the task participant nodes as input parameters of the target privacy calculation algorithm.

[0120] In this embodiment, when the first security verification result and each second security verification result are successful, it means that the data provided by all nodes participating in the secure multi-party privacy computing (including the task initiator node and each task participant node) are safe and reliable. Through comprehensive security verification, the data participating in the multi-party security computing is prevented from being illegally tampered with, or the node itself uploads data incorrectly, resulting in unreliable calculation results. This realizes secure and reliable computing of data flow and solves the problems of malicious algorithms and data tampering in privacy computing.

[0121] It is worth mentioning that the embodiment of this application proposes a privacy data storage and encryption and decryption mechanism based on the trusted computing contract framework to avoid the leakage of privacy data caused by the open and transparent nature of the privacy computing contract and achieve full-process privacy data security.

[0122] To help understand the technical principles of the embodiments of this application, the following specific embodiment is listed, in which the privacy computing contract application layer includes:

[0123] 1. The key storage module is used to store the encryption keys used to encrypt the original datasets of each participant in the privacy-focused computing process, preventing the leakage of private data by directly passing the plaintext dataset to the privacy-focused computing contract. Based on the PutState interface in the smart contract interface layer, it implements a key storage method to construct a key storage transaction using the key-value pair information of the encryption key generated by the task initiator and stores it on the blockchain. Based on the GetState interface, it implements a key retrieval method to retrieve the stored encryption key. The key is constructed from the task initiator's ID, and the value is the encryption key (publicKey). Task participants can obtain the corresponding encryption key from the blockchain through the key storage module, as shown in Figure 3.

[0124] 2. The encrypted data evidence module is used to store the hash values ​​of the encrypted data belonging to each privacy computing participant on the blockchain, thus preventing the encrypted data of each participant from being tampered with. It implements the encrypted data hash value evidence method through the PutState interface in the smart contract interface layer. It uses the encrypted data hash value key-value pairs uploaded by each privacy computing party to construct an encrypted data hash evidence transaction and store it on the blockchain. When executing a privacy computing task, the privacy computing contract can obtain the corresponding encrypted data from each privacy computing task participant based on the encrypted data identifier (dataId). It can also query the hash value of the corresponding encrypted data through the encrypted data hash query method implemented based on the GetState interface in the encrypted data evidence module, and determine whether the encrypted data has been tampered with by comparison, as shown in Figure 4.

[0125] 3. The result storage module and decryption module are used to store and upload privacy-preserving computing results to the blockchain, as well as for the task initiator to decrypt the results. The result storage module implements the privacy-preserving computing result storage method through the PutState interface in the smart contract interface layer, constructs the corresponding result storage transaction, and writes it to the blockchain. Accordingly, the task initiator can obtain the corresponding privacy-preserving computing result from the result storage module based on the result identifier (resId). The decryption module is used to decrypt the encrypted privacy-preserving computing result. Its input is the encrypted privacy-preserving computing result and the decryption key, and its output is the plaintext privacy-preserving computing result, as shown in Figure 5.

[0126] 4. Privacy Computing Module, used to receive privacy computing task requests and implement privacy computing of the private data of all parties involved in the privacy computing. The privacy computing module includes a privacy computing algorithm adapted and modified according to the privacy computing contract framework (hereinafter referred to as the privacy computing contract algorithm). It uses the privacy computing contract framework to implement the privacy data encryption and decryption, encrypted data acquisition, and privacy computing algorithm result storage processes in the original privacy computing algorithm. The specific adaptation and modification methods are as follows:

[0127] (1) The privacy computing contract algorithm implements privacy data encryption and decryption based on the key storage module and decryption module of the privacy computing contract application layer. The privacy data is encrypted by obtaining the encryption key from the key storage module and decrypted by the decryption module.

[0128] (2) The privacy computing contract algorithm uses the GetEncryptedData interface in the privacy computing contract layer to obtain the encrypted data of the participants required for the privacy computing task.

[0129] (3) The privacy-preserving computing contract algorithm stores its calculation results on the blockchain based on the result evidence module of the privacy-preserving computing contract application layer, making the calculation results traceable. The calculation results may include the privacy-preserving computing intermediate results and the final calculation results.

[0130] In one embodiment, after the privacy computing task participants obtain the encryption key from the key storage module of the trusted computing contract platform, they encrypt the original data set to which they belong and store the encrypted data in the privacy data set. Before the task initiator initiates the privacy computing task, the task participants need to upload the hash value of the required encrypted data to the encrypted data storage module of the trusted computing contract platform for subsequent tamper-proof verification of the encrypted data.

[0131] It should be noted that Specific Example 3 is only used to help understand the technical concept of the embodiments of the present application, and does not constitute a limitation on the embodiments of the present application. More simple transformations based on the technical concept should all be within the scope of protection of this application.

[0132] In addition, to help understand the technical concept or technical principle of the embodiments of this application in one embodiment, a specific embodiment 4 is listed. This embodiment includes two parts: generating a privacy computing contract, and processing the confidentiality of data of each participant and trusted privacy computing, among which:

[0133] 1. Privacy Computing Contract Generation

[0134] As shown in Figure 6, the generation of a privacy computing contract includes the following steps:

[0135] 1. Privacy Computing Contract Editing: Any participant in the privacy computing task constructs a privacy computing contract template, which includes the specific implementation of the privacy computing module, key storage module, encrypted data notarization module, result notarization, and decryption module included in the above-mentioned contract application layer.

[0136] 2. Privacy Computing Contract Signature: Each participant reviews the privacy computing contract template and signs the privacy computing smart contract template after approval. The content of the privacy computing contract is completely transparent to all participants, and each participant can review the specific implementation logic of the privacy computing contract.

[0137] 3. Privacy Computing Contract Installation: After obtaining signatures from all participating parties, the privacy computing contract is uploaded to the blockchain and runs on the blockchain node, becoming an executable privacy computing contract. The blockchain network and the privacy computing contract together constitute the trusted computing contract platform.

[0138] 2. Confidential Data Processing and Trusted Privacy Computing for All Participants

[0139] As shown in Figure 7, the confidentiality processing and trusted privacy computing of data of each participant includes the following steps:

[0140] 1. Key generation: The task initiator generates the encryption and decryption key pair locally.

[0141] 2. Encryption key storage: The task initiator generates an encryption key storage transaction (transaction 1) through the key storage module of the trusted computing contract platform and sends the transaction to the blockchain node. The blockchain node stores the encryption key in the blockchain ledger.

[0142] 3. Key acquisition: Participants in the privacy computing task obtain the encryption key through the key storage module of the trusted computing contract platform.

[0143] 4. Data encryption: The privacy computing task initiator and each privacy computing participant use the encryption key locally to encrypt the original data set to obtain encrypted data.

[0144] 5. Encrypted Data Hash Storage: Each privacy computing participant hashes the encrypted data, where H represents the hash function, d identifies the encrypted data, and V represents the calculated hash value. The encrypted data hash storage module of the trusted computing contract platform generates an encrypted data hash value storage transaction (Transaction 2) and sends it to the blockchain node, which then stores the encrypted data in the blockchain ledger.

[0145] 6. Sending a Computation Request: The task initiator sends a private computing task request to the privacy-preserving computing module of the trusted computing contract platform and generates a private computing request transaction (Transaction 3). This transaction is sent to the blockchain node and written to the blockchain ledger. The request includes the IDs of each participant, the privacy-preserving computing algorithm identifier, the encrypted data dataId of each participant, the encryption key keyId, and the task initiator's encrypted data.

[0146] 7. Algorithm selection and encrypted data acquisition: The privacy computing contract obtains the corresponding encryption key from the chain through the key storage module based on the encryption key keyId in the privacy computing request parameter, obtains the specified encrypted data from the privacy data set of the privacy computing participant based on the encrypted data dataId of each participant in the request parameter, and selects the corresponding privacy computing algorithm based on the privacy computing algorithm identifier.

[0147] Each participant's encrypted data undergoes tamper-proof verification. This is done by hashing the encrypted data to obtain a hash value, which is then compared with the corresponding encrypted data hash value stored on the chain. If the hash values ​​are equal, it indicates that the encrypted data has not been tampered with; if they are not equal, it indicates that the encrypted data has been tampered with. Only when the encryption passes the tamper-proof verification can the privacy computing task proceed.

[0148] 8. Privacy computing execution and result storage: Use the encrypted data of all parties to execute the corresponding privacy computing algorithm logic through the privacy computing module of the trusted computing contract platform to obtain the privacy computing result, and generate the result evidence transaction (transaction four) through the result evidence module and send the transaction to the blockchain node. The blockchain node stores the encrypted result of the privacy computing in the blockchain ledger.

[0149] 9. Result Decryption and Return: The task initiator initiates a privacy-preserving computation result query request, with the decryption key and result identifier (resId) as parameters. The decryption module decrypts the encrypted privacy-preserving computation result using the decryption key provided by the task initiator and the privacy-preserving computation result obtained from the result storage module based on the resId, and returns the decrypted result to the task initiator.

[0150] To summarize the above process, this embodiment is based on the trusted computing contract framework and uses privacy computing contracts to ensure the security and reliability of data and algorithms in the privacy computing process. It also achieves traceability of privacy computing results by storing them on-chain, thereby achieving trustworthy data, algorithms, and results in the privacy computing process.

[0151] It should be noted that what is disclosed above are only a few specific implementation scenarios of the privacy computing method in the embodiments of this application. Of course, this cannot be used to limit the scope of protection of this application. Ordinary technicians in this field can understand that the implementation of all or part of the processes of the above embodiments and the equivalent changes made in accordance with the claims of this application still fall within the scope covered by this application.

[0152] That is to say, the above-mentioned specific embodiment 4 is only used to help understand the technical concept or technical principle of the embodiment of this application, and does not constitute a limitation of this application. More simple transformations based on this technical concept should all be within the scope of protection of this application.

[0153] In addition, an embodiment of the present application also proposes a privacy computing device, referring to Figure 8, which is a schematic diagram of the functional modules of the privacy computing device in an embodiment of the present application.

[0154] In this embodiment, the privacy computing device includes: a first acquisition module 10, configured to obtain a privacy computing task request sent by a task initiator node, wherein the privacy computing task request includes an algorithm identifier and multiple data identifiers, wherein one data identifier corresponds to the encrypted data required for a task participant node to participate in the privacy computing; a second acquisition module 20, configured to obtain the target privacy computing algorithm corresponding to the algorithm identifier from the blockchain, and obtain the encrypted data corresponding to the data identifier from each task participant node, and calculate the privacy computing encryption result; a privacy computing module 30, configured to store the privacy computing encryption result in the blockchain, wherein each stored privacy computing encryption result corresponds to a unique result identifier; a result query module 40, configured to receive a query request parameter carrying a target result identifier sent by the task initiator node, and obtain the privacy computing encryption result corresponding to the target result identifier from the blockchain, so as to obtain the privacy computing result based on the privacy computing encryption result.

[0155] In some embodiments, the result query module 40 is further configured to: send the privacy computing encryption result to the task initiator node, so that the task initiator node decrypts the privacy computing encryption result based on the decryption key corresponding to the encrypted data to obtain the privacy computing result.

[0156] In some embodiments, the result query module 40 is further configured to: decrypt the privacy computing encryption result based on the decryption key corresponding to the encrypted data to obtain a privacy computing result; and send the privacy computing result to the task initiator node.

[0157] In some embodiments, the privacy computing task request also includes a target key identifier. The first acquisition module 10 is further configured to: obtain the asymmetric encryption key sent by the task initiator node, and store the encryption key in the blockchain, wherein each stored encryption key corresponds to a unique key identifier, and the encryption key is the encryption key corresponding to the encrypted data; the second acquisition module 20 is further configured to: obtain the target encryption key corresponding to the target key identifier from the blockchain; use the target encryption key and the encrypted data obtained from each of the task participant nodes as input parameters of the target privacy computing algorithm to calculate the privacy computing encryption result.

[0158] In some embodiments, the privacy computing task request also includes an information identifier, which corresponds to the encryption information required for the task initiator node to participate in the privacy computing. The second acquisition module 20 is also configured to: obtain the encryption information corresponding to the information identifier from the task initiator node; use the target encryption key, the encryption information obtained from the task initiator node, and the encrypted data obtained from each of the task participant nodes as input parameters of the target privacy computing algorithm to calculate the privacy computing encryption result.

[0159] In some embodiments, the privacy computing task request also includes a target hash data identifier, and the second acquisition module 20 is further configured to: obtain the hash value corresponding to the encrypted information, and the hash value of the encrypted data corresponding to each task participant node, and store the obtained hash values ​​in the blockchain, wherein each stored hash value corresponds to a unique hash value identifier.

[0160] In some embodiments, the second acquisition module 20 is further configured to: perform hash calculation on the encrypted information obtained from the task initiator node to obtain a first actual hash value corresponding to the task initiator node, and perform hash calculation on the encrypted data obtained from each of the task participant nodes to obtain a second actual hash value corresponding to each of the task participant nodes; based on the first hash value identifier sent by the task initiator node, obtain the first target hash value of the encrypted information sent by the task initiator node from the blockchain, and based on the second hash value identifier sent by each of the task participant nodes, obtain the second target hash value of the encrypted data sent by each of the task participant nodes from the blockchain. ; According to the first actual hash value and the first target hash value, the encrypted information sent by the task initiator node is security verified to obtain a first security verification result; according to the second actual hash value and the second target hash value, the encrypted data sent by each task participant node is security verified to obtain a second security verification result corresponding to each task participant node; when the first security verification result and each second security verification result are both successful, the step of using the target encryption key, the encrypted information obtained from the task initiator node, and the encrypted data obtained from each task participant node as input parameters of the target privacy calculation algorithm is executed.

[0161] In some embodiments, the second acquisition module 20 is further configured to: when the first actual hash value and the first target hash value are inconsistent, determine that the first security verification result is a verification failure; when the first actual hash value and the first target hash value are consistent, determine that the first security verification result is a verification success.

[0162] In some embodiments, the second acquisition module 20 is further configured to: respectively compare the second actual hash value and the second target hash value corresponding to the same task participant node to obtain the comparison results corresponding to each task participant node; when the comparison results are consistent, it is determined that the second security verification results corresponding to each task participant node are all verified successfully.

[0163] The privacy computing device provided in this embodiment and the privacy computing method provided in the above embodiment belong to the same inventive concept. For technical details not fully described in this embodiment, please refer to the embodiments of the above-mentioned privacy computing method. This embodiment has the same beneficial effects as the embodiments of the privacy computing method, and will not be repeated here.

[0164] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, i.e., they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of this embodiment.

[0165] In addition, an embodiment of the present application further provides an electronic device, with reference to FIG9 , which is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application. As shown in FIG9 , the electronic device may include: a processor 1001, a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. Among them, the processor 1001 may be a central processing unit (CPU). The communication bus 1002 is used to implement connection and communication between these components. The user interface 1003 may include a display screen (Display), an input unit such as a keyboard (Keyboard). In one embodiment, the user interface 1003 may also include a standard wired interface and a wireless interface. In one embodiment, the network interface 1004 may include a standard wired interface and a wireless interface (such as a wireless fidelity (WIreless-FIdelity, WI-FI) interface). The memory 1005 may be a high-speed random access memory (Random Access Memory, RAM) or a stable non-volatile memory (Non-Volatile Memory, NVM), such as a disk storage. In one embodiment, the memory 1005 may also be a storage device independent of the aforementioned processor 1001 .

[0166] Those skilled in the art will appreciate that the structure shown in FIG9 does not limit the electronic device and may include more or fewer components than shown, or combinations of certain components, or different component arrangements. As shown in FIG9 , memory 1005 , a computer-readable storage medium, may include an operating system, a data storage module, a network communication module, a user interface module, and a privacy computing program.

[0167] In the electronic device shown in Figure 9, the network interface 1004 is mainly used for data communication with other devices; the user interface 1003 is mainly used for data interaction with the user; the processor 1001 and the memory 1005 in this embodiment can be set in the electronic device, and the electronic device calls the privacy computing program stored in the memory 1005 through the processor 1001, and executes the privacy computing method provided in any of the above embodiments.

[0168] The device proposed in this embodiment and the privacy computing method proposed in the above embodiment belong to the same inventive concept. Technical details not fully described in this embodiment can be referred to any of the above embodiments, and this embodiment has the same beneficial effects as executing the privacy computing method.

[0169] In addition, an embodiment of the present application also proposes a computer-readable storage medium, which may be a non-volatile computer-readable storage medium. A privacy computing program is stored on the computer-readable storage medium, and when the privacy computing program is executed by a processor, the privacy computing method of the present application as described above is implemented.

[0170] The various embodiments of the electronic device and computer-readable storage medium of this application can refer to the various embodiments of the privacy computing method of this application, and will not be repeated here.

[0171] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or system comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or system. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or system comprising the element.

[0172] The serial numbers of the above embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0173] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course, by hardware, but in many cases the former is a better embodiment. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes a number of instructions for enabling an electronic device to execute the methods described in each embodiment of the present application.

[0174] The above are only preferred embodiments of the present application and do not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made using the contents of the present application specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present application.

Claims

1. A privacy computing method, wherein: include: Obtaining a privacy computing task request sent by a task initiator node, wherein the privacy computing task request includes an algorithm identifier and multiple data identifiers, wherein one data identifier corresponds to encrypted data required for a task participant node to participate in privacy computing; Obtaining the target privacy computing algorithm corresponding to the algorithm identifier from the blockchain, and obtaining the encrypted data corresponding to the data identifier from each of the task participant nodes, and calculating to obtain the privacy computing encryption result; Storing the privacy-preserving computing encryption result in the blockchain, wherein each stored privacy-preserving computing encryption result corresponds to a unique result identifier; Receive a query request parameter carrying a target result identifier sent by the task initiator node, obtain a privacy computing encryption result corresponding to the target result identifier from the blockchain, and obtain a privacy computing result based on the privacy computing encryption result.

2. The privacy computing method according to claim 1, wherein: The step of obtaining a privacy computing result based on the privacy computing encryption result comprises: The privacy computing encryption result is sent to the task initiator node, so that the task initiator node decrypts the privacy computing encryption result based on the decryption key corresponding to the encrypted data to obtain the privacy computing result.

3. The privacy computing method according to claim 1, wherein: The step of obtaining a privacy computing result based on the privacy computing encryption result comprises: Decrypting the privacy computing encryption result based on the decryption key corresponding to the encrypted data to obtain a privacy computing result; The privacy calculation result is sent to the task initiator node.

4. The privacy computing method according to claim 1, wherein: The privacy-preserving computing task request also includes a target key identifier, and before obtaining the privacy-preserving computing task request sent by the task initiator node, further includes: Obtain an asymmetric encryption key sent by the task initiator node, and store the encryption key in the blockchain, wherein each stored encryption key corresponds to a unique key identifier, and the encryption key is the encryption key corresponding to the encrypted data; The step of calculating and obtaining the privacy calculation encryption result includes: Obtain a target encryption key corresponding to the target key identifier from the blockchain; The target encryption key and the encrypted data obtained from each of the task participant nodes are used as input parameters of the target privacy computing algorithm to calculate the privacy computing encryption result.

5. The privacy computing method according to claim 4, wherein: The privacy computing task request also includes an information identifier, which corresponds to the encrypted information required by the task initiator node to participate in the privacy computing. The step of using the target encryption key and the encrypted data obtained from each of the task participant nodes as input parameters of the target privacy computing algorithm to calculate the privacy computing encryption result also includes: Acquire the encrypted information corresponding to the information identifier from the task initiator node; The target encryption key, the encrypted information obtained from the task initiator node, and the encrypted data obtained from each of the task participant nodes are used as input parameters of the target privacy computing algorithm to calculate the privacy computing encryption result.

6. The privacy computing method according to claim 5, wherein: The privacy-preserving computing task request also includes a target hash data identifier, and before obtaining the target privacy-preserving computing algorithm corresponding to the algorithm identifier from the blockchain, further includes: Obtain a hash value corresponding to the encrypted information and a hash value of the encrypted data corresponding to each of the task participant nodes, and store the obtained hash values ​​in the blockchain, wherein each stored hash value corresponds to a unique hash value identifier.

7. The privacy computing method according to claim 6, wherein: After obtaining the encrypted information corresponding to the information identifier from the task initiator node, the method further includes: Performing hash calculation on the encrypted information obtained from the task initiator node to obtain a first actual hash value corresponding to the task initiator node, and performing hash calculation on the encrypted data obtained from each of the task participant nodes to obtain a second actual hash value corresponding to each of the task participant nodes; Based on the first hash value identifier sent by the task initiator node, a first target hash value of the encrypted information sent by the task initiator node is obtained from the blockchain, and based on the second hash value identifier sent by each task participant node, a second target hash value of the encrypted data sent by each task participant node is obtained from the blockchain; Performing a security check on the encrypted information sent by the task initiator node according to the first actual hash value and the first target hash value to obtain a first security check result; According to the second actual hash value and the second target hash value, security verification is performed on the encrypted data sent by each of the task participant nodes to obtain a second security verification result corresponding to each of the task participant nodes; When the first security verification result and each of the second security verification results are successful, execute the step of using the target encryption key, the encrypted information obtained from the task initiator node, and the encrypted data obtained from each of the task participant nodes as input parameters of the target privacy calculation algorithm.

8. The privacy computing method according to claim 7, wherein: The step of performing security verification on the encrypted information sent by the task initiator node according to the first actual hash value and the first target hash value to obtain a first security verification result includes: When the first actual hash value and the first target hash value are inconsistent, determining that the first security verification result is a verification failure; When the first actual hash value is consistent with the first target hash value, the first security verification result is determined to be a successful verification.

9. The privacy computing method according to claim 7, wherein: The step of performing security verification on the encrypted data sent by each of the task participant nodes according to the second actual hash value and the second target hash value to obtain a second security verification result corresponding to each of the task participant nodes includes: Compare the second actual hash value and the second target hash value corresponding to the same task participant node respectively. Xi value, and obtain the comparison result corresponding to each of the task participant nodes; When all the comparison results are consistent, it is determined that the second security verification results corresponding to all the task participant nodes are successful.

10. A privacy computing device, wherein: include: A first acquisition module is configured to acquire a privacy computing task request sent by a task initiator node, wherein the privacy computing task request includes an algorithm identifier and multiple data identifiers, wherein one data identifier corresponds to encrypted data required for a task participant node to participate in privacy computing; The second acquisition module is configured to obtain the target privacy computing algorithm corresponding to the algorithm identifier from the blockchain, and obtain the encrypted data corresponding to the data identifier from each of the task participant nodes, and calculate the privacy computing encryption result; A privacy-preserving computing module, configured to store the privacy-preserving computing encryption result in the blockchain, wherein each stored privacy-preserving computing encryption result corresponds to a unique result identifier; The result query module is configured to receive a query request parameter carrying a target result identifier sent by the task initiator node, obtain a privacy-preserving computing encryption result corresponding to the target result identifier from the blockchain, and obtain a privacy-preserving computing result based on the privacy-preserving computing encryption result.

11. An electronic device, wherein: include: A memory, a processor, and a privacy computing program stored in the memory and executable on the processor, wherein the privacy computing program, when executed by the processor, implements the privacy computing method as described in any one of claims 1 to 9.

12. A computer-readable storage medium, wherein: The computer-readable storage medium stores a privacy computing program, which, when executed by a processor, implements the privacy computing method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Shared data processing method based on security multi-party privacy protection in block chain

    CN113449336A

  • Secret-related information processing method and system based on block chain and multi-party security computing

    CN115495768A

  • System and method to protect data privacy of lightweight devices using blockchain and multi-party computation

    US20200034550A1

  • Ensuring information fairness and input privacy using a blockchain in a competitive scenario governed by a smart contract

    US20200082399A1

Cited By

  • Energy storage terminal remote security upgrading method and system based on end-to-end encryption

    CN120342744A

  • Data trusted processing method and system fusing trusted computing and block chain

    CN121144418A

  • Longitudinal federal data privacy calculation method and system based on artificial intelligence

    CN121261970A

  • Data transmission method and device based on privacy calculation, equipment and storage medium

    CN121333797A

  • Audit data processing method, device and product based on block chain and privacy calculation

    CN122222759A