Communication method and communication apparatus
By coordinating and scheduling resources through the privacy computing management node, the execution requirements of multiple privacy computing tasks in the wireless network are addressed, enabling flexible management of task processes and enhanced encryption security.
Patent Information
- Application Number
- PCT/CN2025/106063
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-26
- Filing Date
- 2025-06-30
- Publication Date
- 2026-01-29
AI Technical Summary
Existing technologies have not yet effectively solved the problem of how to support the execution of multiple privacy computing tasks in wireless networks.
A communication method and apparatus are provided, which coordinate and schedule the resources of privacy computing units, allocate task processes and keys, and support the collaborative execution of multiple privacy computing tasks through a privacy computing management node.
It enables the effective management and execution of multiple privacy computing tasks in wireless networks, enhancing the security of ciphertext and the flexibility of task execution.
Smart Images

Figure CN2025106063_29012026_PF_FP_ABST
Abstract
Description
Communication method and communication apparatus
[0001] This application claims priority to the Chinese Patent Application No. 202411020272.8, filed on July 26, 2024, entitled “Communication method and communication apparatus”, the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0002] The present application relates to the field of communication technology, and more particularly, to a communication method and a communication apparatus. BACKGROUND
[0003] Privacy computing refers to a class of information technology that realizes data analysis and calculation while protecting data itself from being leaked, which contains data science, cryptography, artificial intelligence (AI), and many other technical systems.
[0004] In a scenario involving privacy computing, an encryption party can use an encryption key to encrypt sensitive data generated by it to obtain corresponding ciphertext, and send the ciphertext to a privacy computing party. The privacy computing party can use a privacy computing key to perform privacy computation on the ciphertext, and send the ciphertext processed by privacy computation to a decryption party. The decryption party can use a decryption key to decrypt the ciphertext processed by privacy computation to obtain the sensitive data.
[0005] Currently, there may be multiple privacy computing task execution requirements in a wireless network. Therefore, how to support the execution of privacy computing tasks in a wireless network is a technical problem to be solved at present. SUMMARY
[0006] The present application provides a communication method and a communication apparatus, which can support privacy computing tasks in a wireless network.
[0007] In a first aspect, a communication method is provided, comprising: obtaining privacy computing resource information of at least one privacy computing unit, the privacy computing resource information comprising at least one of privacy computing algorithm information, privacy computing function information, and an identifier of a network node to which the privacy computing unit belongs; receiving first request information, the first request information requesting execution of a first privacy computing task; and sending at least one configuration information according to the privacy computing resource information of the at least one privacy computing unit and the first request information, the at least one configuration information corresponding one-to-one to the at least one privacy computing unit, the configuration information being used for execution of the first privacy computing task.
[0008] The solution of the first aspect can be performed by a device at a privacy computing management node side. The device at the privacy computing management node side can be the privacy computing management node, or a component or module (such as a logic circuit, a chip, a chip system, etc.) in the privacy computing management node, or a logic node, a logic module, or software, etc. that can realize all or part of the functions of the privacy computing management node. For ease of description, the following describes the privacy computing management node.
[0009] In the solution, the privacy computing management node can determine the privacy computing resources indicated by the privacy computing resource information of the at least one privacy computing unit, and configure corresponding configuration information for each of the at least one privacy computing unit in combination with the first request information, so as to support the at least one privacy computing unit to cooperatively perform the privacy computing task.
[0010] Based on the above framework, when there are multiple privacy computing task execution requirements in the wireless network, the privacy computing management node can coordinate or schedule or manage the privacy computing resources of each privacy computing unit to execute each privacy computing task, so as to support the execution of the privacy computing task in the wireless network. For example, the privacy computing management node can reasonably allocate the privacy computing resources of each privacy computing unit, or in other words, can support the privacy computing unit to reasonably allocate its own privacy computing resources according to the received configuration information, so as to support the privacy computing unit to execute multiple privacy computing tasks in the wireless network.
[0011] In the first aspect, the configuration information includes at least one of the following: a task flow description, a subtask index, a security cryptographic algorithm identifier, a privacy computing task type, or a privacy computing task identifier.
[0012] Based on the one or more parameters, this can support the privacy computing unit to reasonably schedule or use its own privacy computing resources, so as to support the execution of multiple privacy computing tasks in the wireless network.
[0013] In the first aspect, the at least one privacy computing unit includes a first privacy computing unit, and the first privacy computing task includes a first subtask. The sending of the at least one configuration information includes: sending second request information to the first privacy computing unit, the second request information requesting to execute the first subtask; receiving response information from the first privacy computing unit, the response information indicating an agreement to execute the first subtask; and sending the first configuration information to the first privacy computing unit according to the response information, the at least one configuration information including the first configuration information.
[0014] Based on the above information interaction, the privacy computing management node can decompose one privacy computing task into multiple subtasks, and execute corresponding subtasks by corresponding privacy computing units, and issue configuration information corresponding to the subtask to be executed to the corresponding privacy computing unit.
[0015] In the first aspect, the method further includes: sending third request information to the first privacy computing unit, the third request information requesting to switch a state of the first subtask, the state of the first subtask including: starting, pausing, or stopping.
[0016] In this way, this can support the privacy computing management node to control the state of each subtask.
[0017] In the first aspect, the method further includes: determining the first key according to the privacy computing resource information of the at least one privacy computing unit, the first key including an encryption key, a decryption key, and a privacy computing key.
[0018] In this way, the privacy computing management node can generate the corresponding key according to the privacy computing resource information of the privacy computing unit, so as to support the key generated by the privacy computing management node to match the privacy computing resource information of the privacy computing unit, and thus can be used by the privacy computing unit.
[0019] In the first aspect, the type of the first key includes at least one of the following: a region-level key, a task-level key, a user-level key, or an application-level key.
[0020] In the first aspect, the determining of the first key according to the computing resource information of the at least one privacy computing unit includes: receiving key information from the at least one privacy computing unit; and determining the first key according to the privacy computing resource information of the at least one privacy computing unit and the key information of the at least one privacy computing unit.
[0021] In this way, the key generated by the privacy computing management node can be used by the privacy computing unit.
[0022] In the first aspect, the method further includes: receiving first ciphertext, the first ciphertext being ciphertext obtained after encryption processing using the encryption key; and sending the first ciphertext.
[0023] In this way, the privacy computing management node can manage the ciphertext, such as forwarding the ciphertext, which can enhance the security of the ciphertext.
[0024] In the first aspect, the method further includes: receiving indication information from the first privacy computing unit, the indication information indicating first subtask-related information, the first subtask-related information including at least one of the following: a subtask identifier, a subtask name, a subtask state, or a computing resource usage; and the subtask state includes at least one of the following: creating, to-be-executed, executing, execution success, execution failure, or end state.
[0025] In this way, this can support the privacy computing management node to obtain the information related to the execution of the privacy computing task, and further can manage the sub-tasks of the privacy computing task, etc.
[0026] In the first aspect, the obtaining of the computing resource information of the at least one privacy computing unit comprises: receiving the privacy computing resource information from the at least one privacy computing unit.
[0027] In this way, this can support the privacy computing management node to obtain the latest privacy computing resource information of the privacy computing unit.
[0028] In the first aspect, the privacy computing resource information further comprises at least one of the following: input parameter information, output parameter information, or state information.
[0029] For example, the input parameter information indicates the requirement required to be met by the parameter required to be input when the privacy computing unit executes the privacy computing task, etc., such as algorithm parameter (which can also be used to indicate data format information, etc.), input data format information, etc. In this way, the privacy computing management node can determine the configuration of the input parameter when the privacy computing unit executes the privacy computing task according to the input parameter information.
[0030] For example, the output parameter information indicates the information of the parameter output when the privacy computing unit executes the privacy computing task, such as report information, output model, output data (intermediate or result data), etc. In this way, the privacy computing management node can determine the configuration of the output parameter when the privacy computing unit executes the privacy computing task according to the output parameter information.
[0031] For example, the state information indicates that the privacy computing unit is in an active state or in an inactive state or in an idle state, etc. In this way, the privacy computing management node can determine whether the privacy computing unit is available according to the state information.
[0032] The second aspect provides a communication method, comprising: sending first privacy computing resource information, the first privacy computing resource information comprising at least one of the following: privacy computing algorithm information, privacy computing function information, and an identifier of a network node to which the first privacy computing resource information belongs; receiving first configuration information, the first configuration information being determined according to first request information and privacy computing resource information of at least one privacy computing unit, the first request information requesting execution of a first privacy computing task, the first configuration information being used for execution of the first privacy computing task, and the at least one privacy computing unit comprising a first privacy computing unit.
[0033] The solution of the second aspect can be performed by a device at the privacy computing unit side, which can be a privacy computing unit, a module (such as a chip system, etc.) in the privacy computing unit, or a logic node, a logic module, or software capable of realizing all or part of the functions of the privacy computing unit. For ease of description, the following describes the privacy computing unit.
[0034] In the above solution, the privacy computing unit sends privacy computing resource information to the privacy computing management node, and receives configuration information determined based on the request information and the privacy computing resource of the at least one privacy computing unit, and performs a privacy computing task according to the configuration information. Based on the above framework, the privacy computing unit can schedule or use its own privacy computing resources to perform a privacy computing task according to the configuration information sent by the privacy computing management node, thereby being able to support better execution of multiple privacy computing tasks in a wireless network.
[0035] In the second aspect, the first configuration information includes at least one of the following: a task flow description, a subtask index, a security cryptographic algorithm identifier, a privacy computing task type, or a privacy computing task identifier.
[0036] In the second aspect, the first privacy computing task includes a first subtask, and the receiving the first configuration information includes: receiving second request information, the second request information requesting to perform the first subtask; sending response information, the response information indicating an agreement to perform the first subtask; and receiving the first configuration information.
[0037] In the second aspect, the method further includes: receiving third request information, the third request information requesting to switch a state of the first subtask, the state of the first subtask including: starting, pausing, or stopping.
[0038] In the second aspect, the method further includes: sending key information, the key information being used for generation of a first key, the first key including an encryption key, a decryption key, and a privacy computing key.
[0039] In the second aspect, the attribute of the first key includes at least one of the following: a regional level key, a task level key, a user level key, or an application level key.
[0040] In the second aspect, the method further includes: sending first ciphertext, the first ciphertext being ciphertext obtained after encryption processing using the above-mentioned encryption key.
[0041] In a second aspect, the method further includes: sending indication information, the indication information indicating related information of the first subtask, the related information of the first subtask including at least one of the following: a subtask identifier, a subtask name, a subtask state, or a computing resource usage. The subtask state includes at least one of the following: a creating, a to-be-executed, an executing, an execution success, an execution failure, or an end state.
[0042] In the second aspect, the first privacy computing resource information further includes at least one of the following: input parameter information, output parameter information, or state information.
[0043] In a third aspect, a communication apparatus is provided. The communication apparatus can be a privacy computing management node, or a device or module for performing a function of the privacy computing management node, or a component or module (such as a logic circuit, a chip, a chip system, etc.) in the privacy computing management node.
[0044] In a possible implementation, the communication apparatus can include a module or unit corresponding to each of the methods / operations / steps / actions described in the first aspect. The module or unit can be a hardware circuit, or software, or a combination of hardware circuit and software.
[0045] For example, the communication apparatus includes a transceiver unit and a processing unit.
[0046] In a fourth aspect, a communication apparatus is provided. The communication apparatus can be a first privacy computing unit, or a device or module for performing a function of the first privacy computing unit, or a component or module (such as a logic circuit, a chip, a chip system, etc.) in the privacy computing management node.
[0047] In a possible implementation, the communication apparatus can include a module or unit corresponding to each of the methods / operations / steps / actions described in the second aspect. The module or unit can be a hardware circuit, or software, or a combination of hardware circuit and software.
[0048] For example, the communication apparatus includes a transceiver unit and a processing unit.
[0049] In a fifth aspect, a communication apparatus is provided. The communication apparatus includes a processor configured to cause the communication apparatus to perform the method described in the first aspect and any possible implementation of the first aspect, by executing computer programs or instructions, or by a logic circuit; or to cause the communication apparatus to perform the method described in the second aspect and any possible implementation of the second aspect.
[0050] In a possible implementation, the communication apparatus further includes a memory configured to store the computer programs or instructions.
[0051] In a possible implementation form of the communication apparatus, the communication apparatus further comprises a communication interface configured to input and / or output signals.
[0052] In a sixth aspect, a communication apparatus is provided, comprising a logic circuit and an input / output interface configured to input and / or output signals, and the logic circuit is configured to perform the method in the first aspect and any possible implementation of the first aspect, or the logic circuit is configured to perform the method in the second aspect and any possible implementation of the second aspect.
[0053] In a seventh aspect, a computer readable storage medium is provided, having stored thereon a computer program or instructions, which when executed on a computer, cause the method in the first aspect and any possible implementation of the first aspect to be performed, or cause the method in the second aspect and any possible implementation of the second aspect to be performed.
[0054] In an eighth aspect, a computer program product is provided, comprising instructions, which when executed on a computer, cause the method in the first aspect and any possible implementation of the first aspect to be performed, or cause the method in the second aspect and any possible implementation of the second aspect to be performed.
[0055] In a ninth aspect, a chip or chip system is provided, comprising: one or more processors configured to execute computer programs or instructions in the memory, so that the chip or chip system implements the method in the first aspect and any possible implementation of the first aspect, or implements the method in the second aspect and any possible implementation of the second aspect.
[0056] In a tenth aspect, a chip is provided, which is installed in a communication device, and the chip comprises a processor and a communication interface, and when the processor reads and executes instructions through the communication interface, the communication device performs the method in the first aspect and any possible implementation of the first aspect, or performs the method in the second aspect and any possible implementation of the second aspect.
[0057] In an eleventh aspect, a communication system is provided, comprising a privacy computing management node and a first privacy computing unit. The privacy computing management node is configured to perform the method in the first aspect and any possible implementation of the first aspect. The first privacy computing unit is configured to perform the method in the second aspect and any possible implementation of the second aspect.
[0058] The beneficial effects of the third aspect to the eleventh aspect can be referred to the description of the beneficial effects of the first aspect to the second aspect, and will not be repeated. BRIEF DESCRIPTION OF DRAWINGS
[0059] FIG. 1 is a schematic diagram of a communication system to which embodiments of the present application are applicable.
[0060] FIG. 2 is a schematic diagram of an application scenario of an embodiment of the present application.
[0061] FIG. 3 is a schematic diagram of a privacy computing framework of an embodiment of the present application.
[0062] FIG. 4 is a schematic diagram of an interaction flow of a communication method of an embodiment of the present application.
[0063] FIG. 5 is a schematic diagram of an architecture of a user-level key of an embodiment of the present application.
[0064] FIG. 6 is a schematic diagram of an interaction flow of another communication method of an embodiment of the present application.
[0065] FIG. 7 is a schematic diagram of an interaction flow of another communication method of an embodiment of the present application.
[0066] FIG. 8 is a schematic block diagram of a communication apparatus of an embodiment of the present application.
[0067] FIG. 9 is a schematic block diagram of another communication apparatus of an embodiment of the present application. DETAILED DESCRIPTION
[0068] In order to facilitate understanding of the embodiments of the present application, the following points are first explained.
[0069] I. Unless otherwise specified, the meaning of “multiple” is two or more.
[0070] II. If there is no special description and logical conflict, the terms and / or descriptions between different embodiments of the present application are consistent and can be mutually referred to. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0071] III. The various numerical numbers involved in the present application are only used for differentiation for convenience of description, and are not used to limit the protection scope of the present application. The size of the serial numbers involved in the present application does not mean the execution order. The execution order of each process should be determined according to its function and inherent logic. For example, the terms “first”, “second”, “third”, “fourth” and other various term labels (if any) in the specification and claims and drawings of the present application are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. Among them, the data thus used can be interchanged under appropriate circumstances, so that the embodiments described herein can be implemented in an order other than that illustrated or described herein.
[0072] Meanwhile, any embodiment or design scheme described as "exemplary" or "for example" in the present application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Rather, the use of "exemplary" or "for example" is intended to present concepts in a concrete manner for ease of understanding.
[0073] IV. The terms "comprising" and "having" and any variations thereof are intended to cover a non-exclusive inclusion, for example, a process, method, system, product or apparatus that includes a list of steps or units not necessarily limited to those explicitly listed, but can include other steps or units not expressly listed or inherent to such processes, methods, products or apparatus.
[0074] V. In the present application, "for indicating" can be understood as "enabling", and "enabling" includes direct enabling and indirect enabling. When describing that certain information is used to enable A, it can include that the information directly enables A or indirectly enables A, and it does not mean that A must be carried in the information.
[0075] The information enabled by the information is referred to as the to-be-enabled information. In the implementation process, there are many ways to enable the to-be-enabled information, for example, but not limited to, the to-be-enabled information can be directly enabled, such as the to-be-enabled information itself or an index of the to-be-enabled information. The to-be-enabled information can also be indirectly enabled by enabling other information, and there is an association relationship between the other information and the to-be-enabled information. The to-be-enabled information can also be enabled only in part, and the other part of the to-be-enabled information is known or agreed in advance. For example, the enabling of a specific information can also be achieved by means of the arrangement order of each information agreed in advance (for example, a protocol stipulates), thereby reducing the enabling overhead to a certain extent. Meanwhile, the common part of each information can also be identified and uniformly enabled, so as to reduce the enabling overhead caused by separately enabling the same information.
[0076] In addition, "indicating" can include direct indication, indirect indication, display indication, and implicit indication. When describing that certain indication information is used to indicate A, it can be understood that the indication information carries A, directly indicates A, or indirectly indicates A.
[0077] In this application, the information indicated by the instruction information is called the information to be instructed. In specific implementations, there are many ways to indicate the information to be instructed, such as, but not limited to, directly indicating the information to be instructed, such as the information to be instructed itself or its index. It can also indirectly indicate the information to be instructed by indicating other information, where there is a relationship between the other information and the information to be instructed. It can also indicate only a part of the information to be instructed, while the other parts are known or pre-agreed upon. For example, the instruction of specific information can be achieved by using a pre-agreed order of various information, thereby reducing instruction overhead to some extent. Furthermore, the information to be instructed can be sent as a whole or divided into multiple sub-information units, and the sending period and / or timing of these sub-information units can be the same or different.
[0078] VI. In this application, "pre-configuration" may include pre-defined terms, such as protocol definitions. These "pre-defined terms" can be implemented by pre-storing corresponding codes, tables, or other means of indicating relevant information in the device (e.g., including various network elements). This application does not limit the specific implementation method.
[0079] VII. The term "storage" or "preservation" in this application can refer to storage in one or more memory devices. These memory devices can be separately configured or integrated into an encoder, decoder, processor, or communication device. Alternatively, some memory devices can be separately configured, while others can be integrated into a decoder, processor, or communication device. The type of memory can be any form of storage medium, and this is not limited.
[0080] 8. The term "protocol" in this application may refer to standard protocols in the field of communications, for example, it may include fourth-generation (4G) protocols. th Generation 4G network, fifth generation (5G) network th This application does not limit the scope to 5G network protocols, 5.5G network protocols, or related protocols applied in future communication networks.
[0081] 9. The arrows or boxes indicated by dashed lines in the schematic diagrams in the accompanying drawings of this application represent optional steps or optional modules.
[0082] 10. Unless otherwise stated, " / " indicates that the objects before and after are in an "or" relationship. For example, A / B can mean A or B. In this application, "and / or" is merely a description of the relationship between the related objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, and B exists alone. A and B can be singular or plural.
[0083] Eleven, in this application, "sending" and "receiving" represent the direction of signal transmission. For example, "sending information to XX" can be understood as the destination of the information is XX, which can include direct transmission through the air interface, and also includes indirect transmission through the air interface by other units or modules. "Receiving information from YY" can be understood as the source of the information is YY, which can include direct reception from YY through the air interface, and also includes indirect reception from YY through the air interface from other units or modules. "Sending" can also be understood as the "output" of the chip interface, and "receiving" can also be understood as the "input" of the chip interface. In other words, sending and receiving can be between devices, such as between network devices and terminal devices, or within devices, such as between components, modules, chips, software modules or hardware modules within devices through buses, wires or interfaces.
[0084] First, the communication system to which the embodiments of the present application are applicable is described.
[0085] FIG. 1 is a schematic diagram of a communication system to which embodiments of the present application are applicable. As shown in FIG. 1, the communication system includes a radio access network (RAN) 100 and a core network (CN) 200. The RAN 100 includes at least one RAN node (such as 110a and 110b, collectively referred to as 110) and at least one terminal device (such as 120a-120j, collectively referred to as 120). The RAN 100 can also include other RAN nodes, such as wireless relay devices and / or wireless backhaul devices (not shown in FIG. 1), etc. The terminal devices 120 are connected to the RAN nodes 110 in a wireless manner. The RAN nodes 110 are connected to the CN 200 in a wireless or wired manner. The core network devices in the CN 200 and the RAN nodes 110 in the RAN 100 can be different physical devices respectively, or can be the same physical device integrated with the logical functions of the CN and the RAN.
[0086] The RAN 100 can be a third generation partnership project (3GPP) New Radio (NR) network, and the terminal device 120 can be a 3GPP NR terminal device. rdThe RAN 100 can be a 5G New Radio (NR) or 5G NR system, a 4G system, a system related to 3rd Generation Partnership Project (3GPP) Long Term Evolution (LTE), or a system related to 3GPP LTE-Advanced (LTE-A), or a future communication system. The RAN 100 can also be an open radio access network (O-RAN or ORAN), a cloud radio access network (C-RAN or CRAN), a wireless fidelity (Wi-Fi) system, or a combination of two or more of the above systems.
[0087] The RAN node 110 can also be an access network device, a RAN entity, an access node, or the like, to implement wireless access. The RAN nodes 110 can be nodes of the same type or nodes of different types. In some scenarios, the roles of the RAN node 110 and the terminal device 120 are opposite to each other. For example, the network element 120i can be a helicopter or a drone, which can be configured as a mobile base station. For a terminal device 120j that accesses the RAN 100 through the network element 120i, the network element 120i is a base station. However, for the base station 110a, the network element 120i is a terminal device. The RAN node 110 and the terminal device 120 are sometimes collectively referred to as communication apparatuses. For example, the network elements 110a and 110b can be understood as communication apparatuses with base station functions, and the network elements 120a-120j can be understood as communication apparatuses with terminal functions.
[0088] In a possible scenario, the RAN node can be a base station (BS), an evolved Node B (eNB), an access point (AP), a transmission point (TP), a transmission reception point (TRP), a next generation NodeB (gNB), a next generation base station in a future communication network, or an access node in a Wi-Fi system, or the like.
[0089] The RAN node can also be a server, a wearable device, a vehicle, or a vehicle-mounted device, or the like. The RAN node can also be a logical node, a logical module, or software that implements all or part of the functions of the RAN node, by running on hardware, or by virtualization of an instance on a platform such as a cloud platform. In addition, the RAN node can also be a logic node, a logic module, or software that implements all or part of the functions of the RAN node.
[0090] In another possible scenario, a plurality of RAN nodes cooperate to assist a terminal device to access wirelessly, and different RAN nodes respectively implement part of functions of a base station. For example, a RAN node is a central unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU), etc. The CU and the DU can be separately configured, or can be included in the same network element, for example, a baseband unit (BBU). The RU can be included in a radio frequency device or a radio frequency unit, for example, a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH).
[0091] In different communication systems, the CU (or CU-CP and CU-UP), the DU, or the RU can have different names, but those skilled in the art can understand their meanings. For example, in an ORAN system, the CU can be referred to as an O-CU (open CU), the DU can be referred to as an O-DU, the CU-CP can be referred to as an O-CU-CP, the CU-UP can be referred to as an O-CU-UP, and the RU can be referred to as an O-RU. For the sake of description, the CU, the CU-CP, the CU-UP, the DU, and the RU are taken as examples for description in this application. Any of the CU (or CU-CP, CU-UP), the DU, and the RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.
[0092] It can be understood that the number of each device in the above communication system is only illustrative, and is not limited thereto. In actual applications, the communication system can further include more terminal devices, more RAN devices, and can further include other devices.
[0093] In the embodiments of this application, the terminal device is a device with wireless transceiving function, and can be referred to as a user equipment (UE), an access terminal, a subscriber unit, a user station, a mobile station, a remote station, a remote terminal, a mobile device, a user terminal, a wireless communication device, a user agent, or a user apparatus.
[0094] In the embodiments of the present application, the terminal device can also be a satellite phone, a cellular phone, a smart phone, a wireless data card, a wireless modem, a machine type communication device, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a customer-premises equipment (CPE), a smart point of sale (POS) machine, a handheld device with wireless communication function, a computing device or other processing device connected to a wireless modem, a vehicle-mounted device, a communication device carried on an aerial vehicle, a wearable device, a drone, a robot, a terminal in device-to-device (D2D) communication, a terminal in vehicle-to-everything (V2X) communication, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a terminal in industrial control, a terminal in self driving, a terminal in telemedicine or telehealth services, a terminal in smart grid, a terminal in transportation safety, a terminal in smart city, a terminal in smart home, or a terminal device in a communication network evolved after 5G, etc., without limitation.
[0095] In the embodiments of the present application, the terminal device can also be a device with communication function in a future communication network, without limitation on the form or type of the terminal device in the future communication network, etc.
[0096] In the embodiments of the present application, the communication apparatus for implementing the function of the terminal device can be a terminal device, or an apparatus capable of supporting the terminal device to implement the function, such as a chip system. The apparatus can be installed in the terminal device or used in matching with the terminal device. In the present application, the chip system can be composed of a chip, or include a chip and other discrete devices.
[0097] In the embodiments of the present application, the network device is a device with wireless transceiving function, which is used for communication with the terminal device. The network device can be a node in the RAN, which can be a base station or a RAN node or an eNB of long term evolution (LTE) or a base station of a 5G network or a base station in a public land mobile network (PLMN) evolved after 5G or a broadband network gateway (BNG) or a convergence switch or a network device in 3GPP, etc.
[0098] In the embodiments of the present application, the network device can include various forms of base stations, such as: macro base station, micro base station, relay station, TRP, TP, mobile switching center, and devices that undertake the function of base station in D2D, V2X, machine-to-machine (M2M) communication, network device in non-terrestrial network (NTN), etc.
[0099] In the embodiments of the present application, the communication device for implementing the function of the network device can be the network device, or can be a device capable of supporting the network device to implement the function, such as a chip system. The device can be installed in the network device or used in matching with the network device. The chip system in the embodiments of the present application can be composed of a chip, or can include a chip and other discrete devices.
[0100] The network architecture and service scenarios described in the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the present application. It can be known by those skilled in the art that, with the evolution of the communication network architecture and the appearance of new service scenarios, the technical solutions provided by the present application are also applicable to similar technical problems. For example, the present application can be applicable to the V2X scenario.
[0101] Based on the communication system shown in FIG. 1, the present application further provides an application scenario, which can be referred to FIG. 2.
[0102] FIG. 2 is a schematic diagram of an application scenario of an embodiment of the present application. As shown in FIG. 2, in order to protect the privacy of data, the data holder and the data user can protect the data that needs to be interacted. For example, the data holder (such as a smart car, a network device, etc.) uses an encryption key to encrypt the sensitive data generated by the data holder, obtains ciphertext 1, and sends the ciphertext 1 to a privacy computing party (such as a network device), the privacy computing party uses a privacy computing key to perform privacy computing on the ciphertext 1, obtains ciphertext 2, and sends the ciphertext 2 to the data user (such as a smart car, a network device, etc.), and the data user uses a decryption key to decrypt the ciphertext 2 to obtain the sensitive data generated by the data holder. Through the above steps, the privacy of the data interacted between the data holder and the data user can be effectively protected.
[0103] It can be understood that there can be many execution requirements of privacy computing tasks (including steps of encryption processing, privacy computing processing, and decryption processing, etc.) in a wireless network. Therefore, how to support the execution of privacy computing tasks in a wireless network is a technical problem to be solved at present.
[0104] Therefore, the present application provides a privacy computing framework, which can support the execution of a privacy computing task (or multiple privacy computing tasks) in a wireless network. The description of the privacy computing framework can be referred to FIG. 3.
[0105] FIG. 3 is a schematic diagram of a privacy computing framework of an embodiment of the present application. As shown in FIG. 3, the privacy computing framework includes an encryption node, a privacy computing management node, a ciphertext computing node, and a decryption node.
[0106] The encryption node is a subject for performing data encryption processing, the privacy computing management node is a subject for performing privacy computing management, the ciphertext computing node is a subject for performing privacy computing processing, and the decryption node is a subject for performing data decryption processing. The privacy computing management node can manage the encryption node, the decryption node, and the ciphertext computing node.
[0107] The encryption node, the ciphertext computing node, and the decryption node can correspond to different or same entities, for example, the encryption node is a terminal device, a network device, a network element or a network function (NF) in a CN, or a server, etc., the ciphertext computing node is a terminal device or a network device or a network element or a network function in a CN, or a server, etc., and the decryption node is a terminal device, a network device, a network element or a network function in a CN, or a server, etc. The above nodes (such as the encryption node, the ciphertext computing node, or the decryption node) have algorithm, computing power, or data resources, etc., which are used for the function implementation of the nodes.
[0108] The description of the node can also refer to Table 1. The content of Table 1 is only as an example, not as the final limit.
[0109] Table 1
[0110] As shown in Table 1:
[0111] • The node type indicates the type of the node as a terminal device or a network device or an NF, etc., and the node identifier is used to uniquely identify the node;
[0112] • The privacy computing unit list indicates the information of one or more privacy computing units included in the node, and the information of the privacy computing unit includes the identifier of the privacy computing unit and the function information of the privacy computing unit;
[0113] • The network state indicates the network state of the node, including connected and non-connected;
[0114] • The computing power resource list indicates the computing power resources of the node, such as central processing unit (CPU) information (for example, including frequency, core number, or cache size), graphics processing unit (GPU) information (for example, including signal, compute unified device architecture (CUDA) core number, video memory size, or video memory bandwidth), field programmable gate array (FPGA) information (for example, number of logic units, IO port number, or internal storage size), application specific integrated circuit (ASIC) information (for example, number of specific functional units, processing rate, power consumption, or process);
[0115] • The algorithm resource list indicates the algorithm resources of the node, such as federated learning (FL) (for example, including parameter information), multiparty computing (MPC) (for example, including corresponding parameter information), and differential privacy (DP) (for example, including corresponding parameter information);
[0116] • The data resource list indicates the data resources of the node, such as network data (for example, including corresponding data information), AI data (for example, including corresponding data information), user data, perception data, terminal data, etc.
[0117] The security type, function type, software and hardware type, etc. of each of the one or more privacy computing units included in the node can be different or the same. The security type refers to support for different security technologies, such as multi-party secure computation, federated learning, homomorphic encryption, trusted execution environment, differential privacy, zero-knowledge proof, etc. The function type can include encryption, decryption, privacy computation, etc. The function type can also include privacy computation function types such as perception compression, AI training and inference, etc. The software and hardware type indicates different software and hardware architectures used to implement the privacy computing unit. The software stack can include specific encryption algorithm libraries and privacy computing protocols. The hardware architecture can include general-purpose processors of x86 or ARM architecture, GPUs, FPGAs, ASICs, etc. privacy computing accelerators, trusted execution environment (TEE) security hardware, etc. For example, the encryption node includes a privacy computing unit 1 and a privacy computing unit 2. The security type of the privacy computing unit 1 is different from the security type of the privacy computing unit 2, or the function type of the privacy computing unit 1 is different from the function type of the privacy computing unit 2.
[0118] In an embodiment of the present application, the privacy computing unit is a module or unit that encapsulates algorithm functions (data processing and model calculation, etc. privacy computation, encryption, decryption, etc.), software and hardware resource information (computing / storage, etc.), etc. and has the function of independently performing privacy computation tasks.
[0119] In an embodiment of the present application, the privacy computing unit can be carried in a physical entity or a virtual entity. For example, the privacy computing unit is a module or an integrated circuit or a chip in a terminal or a network device, etc. Alternatively, the privacy computing unit is a server or software resource carried in a core network, etc.
[0120] In summary, the embodiments of the present application do not limit the form of the encryption node, the decryption node, the ciphertext computing node, and the privacy computing unit.
[0121] In one possible implementation, the privacy computing management node can include a key management unit, a resource management unit, and a task management unit. Optionally, the privacy computing management node can also include a ciphertext management unit.
[0122] For example, the key management unit is used to perform functions related to keys, such as key generation and distribution, etc. For example, sending an encryption key to an encryption node, sending a decryption key to a decryption node, and sending a privacy computing key to a ciphertext computing node.
[0123] For example, the resource management unit is configured to perform scheduling of resources related to the execution of the privacy computing task, etc., such as determining a privacy computing unit in the encryption node for performing the encryption processing function, determining a privacy computing unit in the decryption node for performing the decryption processing function, and determining a privacy computing unit in the ciphertext computing node for performing the privacy computing processing function.
[0124] Optionally, the resource management unit can also be configured to manage the privacy computing unit. For example, the resource management unit is configured to perform the following functions: registration, deregistration, addition, update, and activation of the privacy computing unit, etc.
[0125] When the privacy computing unit performs the registration process, the privacy computing unit actively reports the privacy computing resource information to the resource management unit; or the resource management unit sends request information for requesting to obtain the privacy computing resource to the privacy computing unit, and the privacy computing unit sends the privacy computing resource information to the resource management unit according to the request information. The description of the privacy computing resource information can be referred to in the following description.
[0126] When the privacy computing unit performs the update process, the resource management unit can issue a specific algorithm component to the privacy computing unit, so as to complete the update or reconfiguration of the privacy computing unit.
[0127] For example, the task management unit is configured to perform functions related to the management of the privacy computing task, such as determining the execution process of the privacy computing task, such as determining that the first privacy computing unit in the ciphertext computing node performs the first process, and the second privacy computing unit in the ciphertext computing node performs the second process, etc.
[0128] Optionally, the task management unit can also perform the following functions: creation of the privacy computing task, decomposition of the subtask of the privacy computing task, selection of the matched privacy computing unit, and sending of the subtask request information to the corresponding privacy computing unit. The specific description can be referred to in the following description.
[0129] For example, the ciphertext management unit is configured to perform functions related to the management of the ciphertext, such as storing the ciphertext (from the encryption node) or sending the ciphertext to the ciphertext computing node, etc.
[0130] Based on the privacy computing framework shown in FIG. 3, the present application provides a communication method and a communication device, which can support the execution of the privacy computing task in the wireless network.
[0131] The communication method and the communication device of the embodiments of the present application are described below with reference to the accompanying drawings.
[0132] For the convenience of understanding and description, the communication method of the embodiments of the present application is described below taking the privacy computing management node and the first privacy computing unit as examples, but this should not constitute any limitation on the execution subject of the communication method of the embodiments of the present application. For example, the privacy computing management node can be the privacy computing management node itself, or a functional module (such as a circuit, a chip, or a chip system, etc.), or a logical node, a logical module, or software capable of realizing all or part of the functions of the privacy computing management node. Similarly, the first privacy computing unit can be the first privacy computing unit itself, or a functional module (such as a circuit, a chip, or a chip system, etc.), or a logical node, a logical module, or software capable of realizing all or part of the functions of the first privacy computing unit.
[0133] When the steps involving sending or receiving are performed by modules (such as circuits, chips, or chip systems, etc.), logical nodes, logical modules, or software, etc. in the privacy computing management node and the first privacy computing unit, the sending / receiving can be understood as communication through a communication interface, an input / output interface, a pin, or a circuit, etc.
[0134] It needs to be uniformly stated that all the terms appearing below are only examples and are not the final limitation. For example, the privacy computing unit, the privacy computing resource information, etc. appearing below are only examples and do not limit other term expressions.
[0135] FIG. 4 is an interaction flow diagram of a communication method according to an embodiment of the present application. As shown in FIG. 4, the method comprises:
[0136] S401, the privacy computing management node obtains privacy computing resource information of at least one privacy computing unit.
[0137] The privacy computing management node can obtain the privacy computing resource information of the at least one privacy computing unit in various ways.
[0138] Method #1:
[0139] The privacy computing management node can obtain the corresponding privacy computing resource information from the at least one privacy computing unit.
[0140] Please refer to S401a: the first privacy computing unit sends the first privacy computing resource information to the privacy computing management node. Correspondingly, the privacy computing management node receives the first privacy computing resource information of the first privacy computing unit.
[0141] The first privacy computing unit can actively send the first privacy computing resource information to the privacy computing management node, or passively send the first privacy computing resource information to the privacy computing management node. For example, the privacy computing management node sends information to the first privacy computing unit to request the first privacy computing resource information, and the first privacy computing unit sends the first privacy computing resource information to the privacy computing management node according to the information. In this way, the privacy computing management node can obtain the latest privacy computing resource information of the first privacy computing unit.
[0142] Method #2:
[0143] The privacy computing resource information of the at least one privacy computing unit is preconfigured in the privacy computing management node. In this way, the signaling interaction overhead of the privacy computing management node obtaining the privacy computing resource information of the at least one privacy computing unit can be reduced.
[0144] In the embodiments of the present application, the privacy computing resource information of the privacy computing unit includes at least one of the following:
[0145] • privacy computing algorithm information;
[0146] • privacy computing function information;
[0147] • an identifier of a network node to which the privacy computing unit belongs.
[0148] For example, the privacy computing algorithm information indicates an algorithm or function supported by the privacy computing unit, such as a convolutional neural network (CNN), a recurrent neural network (RNN), a generative adversarial network (GAN), or a support vector machine (SVM). In this way, the privacy computing management node can determine the algorithm supported by the privacy computing unit according to the privacy computing algorithm information.
[0149] For example, the privacy computing function information indicates information related to a computing function supported by the privacy computing unit, such as:
[0150] • homomorphic encryption information, including: ring structure size, ciphertext modulus, plaintext modulus, key, etc.;
[0151] • multiparty computing (MPC) information, including: number of participants, MPC algorithm information (such as key based on garbled circuit (GC) related information, secret sharing related information), and other information;
[0152] • Differential privacy (DP) information, including: privacy budget (i.e., quantifying the strength of noise), maximum output difference, probability of deviation, and noise standard deviation, etc.
[0153] In this way, the privacy computing management node can determine the privacy computing function supported by the privacy computing unit according to the privacy computing function information.
[0154] For example, the identity of the network node to which the privacy computing unit belongs is used to indicate the network node to which the privacy computing unit belongs, such as a terminal device or a network device or an NF, etc. In this way, the privacy computing management node can determine the network node to which the privacy computing unit belongs according to the identity of the network node.
[0155] In one possible implementation, the privacy computing resource information can further include at least one of the following:
[0156] • Input parameter information;
[0157] • Output parameter information;
[0158] • State information.
[0159] For example, the input parameter information indicates the requirements required to be met by the input parameters when the privacy computing unit performs the privacy computing task, such as algorithm parameters (which can also be used to indicate data format information, etc.), input data format information, etc. In this way, the privacy computing management node can determine the configuration of the input parameters when the privacy computing unit performs the privacy computing task according to the input parameter information.
[0160] For example, the output parameter information indicates the information of the parameters output by the privacy computing unit when performing the privacy computing task, such as report information, output model, output data (intermediate or result data), etc. In this way, the privacy computing management node can determine the configuration of the output parameters when the privacy computing unit performs the privacy computing task according to the output parameter information.
[0161] For example, the state information indicates that the privacy computing unit is in an active state or in an inactive state or in an idle state, etc. In this way, the privacy computing management node can determine whether the privacy computing unit is available according to the state information.
[0162] The description of the privacy computing resource information can also refer to Table 2. The content shown in Table 2 is only used as an example and is not limited.
[0163] Table 2
[0164] As shown in Table 2:
[0165] • The identity is used to uniquely identify the privacy computing unit;
[0166] • Source information indicates the network node to which the privacy computing unit belongs, for example, the privacy computing unit belongs to a network device or a terminal device or an NF, etc.
[0167] • Implementation type indicates whether the privacy computing unit belongs to a persistent type or a disposable type or whether it is updatable (isUpdatable);
[0168] • Privacy computing function information indicates the computing function supported by the privacy computing unit, which can be referred to the foregoing description;
[0169] • Privacy computing algorithm information indicates the algorithm or function supported by the privacy computing unit, such as CNN / RNN / GAN / SVM, etc.
[0170] • Resource is used to describe the computing and storage resources of software and hardware, such as CPU, GPU, FPGA, ASIC, etc. The resource can also be used to indicate the computing performance and / or storage performance of the privacy computing unit, etc.
[0171] • Input parameter information indicates algorithm parameters, input data format information, etc.
[0172] • Output parameter information indicates report information, output model, output data (intermediate or result data), etc.
[0173] • State information indicates whether the privacy computing unit is in an activated state or a non-activated state or an unavailable state, etc. When the privacy computing unit is in the activated state, the privacy computing unit can execute a privacy computing task. When the privacy computing unit is in the non-activated state, the privacy computing unit does not currently execute a privacy computing task. When the privacy computing unit is in the unavailable state, the privacy computing unit cannot execute a privacy computing task.
[0174] Based on one or more of the contents described in Table 2, the privacy computing management node can implement scheduling and management of the privacy computing resources of the privacy computing unit according to the one or more contents.
[0175] S402, the privacy computing management node receives first request information.
[0176] For example, a requester (a network element or node used to request execution of a privacy computing task) sends first request information to the privacy computing management node, and the first request information requests execution of a privacy computing task 1. Correspondingly, the privacy computing management node receives the first request information.
[0177] In one possible implementation, the first request information includes at least one of the following: task type, quality of service, number of encryption parties, encryption party parameter, number of data users, and data user parameter.
[0178] The description of the first request information can refer to Table 3. The content shown in Table 3 is only as an example, not as the final limit.
[0179] Table 3
[0180] As shown in Table 3:
[0181] • The task type indicates the type of the privacy computing task, for example, an AI training / inference task, or a data compression task, etc.
[0182] • The quality of service indicates the quality requirement required when the privacy computing task is executed, such as a time delay requirement and a security requirement (for example, the identification of a secure cryptographic algorithm, or a security level, which can be used to determine the corresponding secure cryptographic algorithm), etc.
[0183] • The number of encryption parties indicates the number of encryption parties;
[0184] • The encryption party parameter indicates the global identification, data type, and data rate of the data encryption party;
[0185] • The number of data users indicates the number of data users;
[0186] • The data user parameter indicates the global identification, data type, and data rate of the data user.
[0187] Based on the content shown in Table 3, the privacy computing management node can determine the corresponding parameters of the privacy computing task 1.
[0188] S403, the privacy computing management node sends at least one configuration information according to the privacy computing resource information of at least one privacy computing unit and the first request information.
[0189] For example, the privacy computing management node determines the configuration information corresponding to at least one privacy computing unit according to the content indicated by the first request information and the privacy computing resource information of at least one privacy computing unit.
[0190] For example, in the case of two privacy computing units, the first request information indicates the security requirement and the task type of the privacy computing task, the security requirement includes the identifier of the secure cryptographic algorithm, for example, the identifier of the BGV (Brakerski, Gentry, Vaikuntanathan) algorithm, and the task type is AI inference. The privacy computing resource information of the first privacy computing unit indicates that the first privacy computing unit supports CNN and BGV algorithms, and the privacy computing resource information of the second privacy computing unit indicates that the second privacy computing unit supports CNN and BGV algorithms. Correspondingly, the first configuration information configured by the privacy computing management node for the first privacy computing unit includes the type information and the security cryptographic algorithm identifier information of the privacy computing task 1, and the second configuration information configured by the privacy computing management node for the second privacy computing unit includes the type information and the security cryptographic algorithm identifier information of the privacy computing task 1. In the above scheme, the privacy computing management node can determine the privacy computing resource indicated by the privacy computing resource information of the at least one privacy computing unit and configure corresponding configuration information for each privacy computing unit in the at least one privacy computing unit in combination with the first request information, thereby supporting the at least one privacy computing unit to cooperatively execute the privacy computing task.
[0191] Based on the above framework, when there are multiple privacy computing task execution requirements in the wireless network, the privacy computing management node can coordinate or schedule or manage the privacy computing resource of each privacy computing unit to execute each privacy computing task, thereby being able to support better execution of the privacy computing task in the wireless network, for example, the privacy computing management node can reasonably allocate the privacy computing resource of each privacy computing unit, or in other words, can support the privacy computing unit to reasonably allocate its own privacy computing resource according to the received configuration information, thereby being able to support the privacy computing unit to execute multiple privacy computing tasks in the wireless network.
[0192] In one possible implementation, the configuration information includes at least one of the following:
[0193] a task flow description;
[0194] a subtask index;
[0195] a security cryptographic algorithm identifier;
[0196] a privacy computing task type;
[0197] a subtask computing algorithm identifier;
[0198] a privacy computing task identifier.
[0199] For example, the task flow description is used to describe the following content:
[0200] • A list of privacy computing units, including information of at least one privacy computing unit, information of one privacy computing unit including: a privacy computing unit identifier, an algorithm resource identifier, an input parameter, an output parameter, and the like;
[0201] • An operation sequence between the privacy computing units and a dependency relationship between the input and output of the privacy computing units;
[0202] • An interaction protocol between the privacy computing units, such as “Privacy Computing Cross-Platform Interconnection” published by China Information and Communication Research Institute (China Institute of Information and Communication), International Electrotechnical Commission (IEC), International Organization for Standardization (ISO), or Institute of Electrical and Electronics Engineers (IEEE), and the like, “IEEE P3117 Standard for Interworking Framework for Privacy-Preserving Computation”, and the like.
[0203] For example, the subtask index is used to indicate a specific subtask performed by each privacy computing unit.
[0204] For example, the secure cryptographic algorithm identifier is used to indicate a secure cryptographic algorithm used by the privacy computing unit.
[0205] For example, the privacy computing task type is used to indicate a type of the privacy computing task 1.
[0206] For example, the subtask computing algorithm identifier is used to indicate a computing algorithm required by a subtask corresponding to the aforementioned subtask index.
[0207] For example, the privacy computing task identifier is used to identify the privacy computing task 1.
[0208] Based on one or more parameters described above, this can support reasonable scheduling of the privacy computing unit or use of its own privacy computing resources, thereby being able to support execution of multiple privacy computing tasks.
[0209] It should be noted that any one of the above listed parameters can be related to the scheduling or management of the privacy computing resources of the privacy computing unit. For example, based on the task flow description, the privacy computing unit can determine the computing resources that need to be scheduled; based on the subtask index, the privacy computing unit can determine the computing resources required for executing the subtask indicated by the subtask index, etc.; based on the security cryptographic algorithm identifier, the privacy computing unit can determine the security cryptographic algorithm to be used, and then determine the specific computing resources, etc.; based on the privacy computing task type, the privacy computing unit can determine the computing resources to be used, for example, for complex privacy computing tasks, the privacy computing unit can invoke more than a threshold of computing resources, for simple privacy computing tasks, the privacy computing unit can schedule less than a threshold of computing resources, and the like.
[0210] The description of the configuration information can also refer to Table 4. The content shown in Table 4 is only as an example, not as the final limit.
[0211] Table 4
[0212] As shown in Table 4:
[0213] • The privacy computing task identifier is used to uniquely identify the privacy computing task 1;
[0214] • The task type is used to indicate that the type of the privacy computing task 1 is a type such as AI training inference, etc.;
[0215] • The task requester information is used to indicate the identification, data type and rate, etc. of the requester;
[0216] • The data provider information is used to indicate the identification, data type and rate, etc. of the data holder;
[0217] • The result user information is used to indicate the identification, data type and rate, etc. of the data user;
[0218] • The task flow, which can be referred to the foregoing description;
[0219] • The sub-index, which is used to indicate the specific subtask executed by the privacy computing unit;
[0220] • The subtask number, which is used to indicate the number of subtasks included in the privacy computing task 1;
[0221] • The subtask computing algorithm identifier, which is used to indicate the computing algorithm required for the subtask, such as CNN or GAN, etc.;
[0222] • The security cryptographic algorithm identifier is used to indicate the security algorithm to be used, such as BGV algorithm, BFV algorithm, CKKS algorithm, TFHE algorithm, etc.
[0223] • A participant list indicating {participant role, identity, computation function, input parameter, output parameter}; participant role: encryptor, decryptor, computation party; encryptor: data type (integer, floating point, complex number), data rate, etc.; decryptor: decryption strategy, decryption key, etc. The decryptor needs to have all or part of the decryption key; computation party: computation task, performance requirement (latency / storage requirement, etc.).
[0224] Optionally, the configuration information described above can also include sub-task state information. For example, the sub-task state information includes Create, start, executing, abnormal, finish, etc. When the privacy computing management node receives feedback from the privacy computing unit about the state of the sub-task, the privacy computing management node updates the original configuration information. The updated configuration information can include the sub-task state information described above, and the privacy computing management node can send the updated configuration information to the privacy computing unit.
[0225] In one possible implementation, after receiving the first request information, the privacy computing management node can decompose the privacy computing task 1 into multiple sub-tasks according to the privacy computing resource information of each privacy computing unit, and each sub-task corresponds to a privacy unit. For details, please refer to Table 5. The content shown in Table 5 is only an example and is not the final limitation.
[0226] Table 5
[0227] As shown in Table 5:
[0228] • Corresponding to the privacy computing task 1, it includes sub-task 11 and sub-task 12, sub-task 11 is executed by the privacy computing unit 1, and sub-task 12 is executed by the privacy computing unit 2;
[0229] • Corresponding to the privacy computing task 2, it includes sub-task 21 and sub-task 22, sub-task 21 is executed by the privacy computing unit 1, and sub-task 22 is executed by the privacy computing unit 2.
[0230] Taking the privacy computing task 1 as an example, the privacy computing management node determines the configuration information 1 for the privacy computing unit 1, and the configuration information 1 is used for the execution of the sub-task 1. The privacy computing management node determines the configuration information 2 for the privacy computing unit 2, and the configuration information 2 is used for the execution of the sub-task 2.
[0231] In one possible implementation, the method 400 can further include:
[0232] S403a, the privacy computing management node sends second request information to the first privacy computing unit, and the second request information requests to execute the first sub-task.
[0233] S403b, the first privacy computing unit sends response information to the privacy computing management node. Correspondingly, the privacy computing management node receives the response information, which is used to indicate whether the first privacy computing unit can execute the first subtask.
[0234] S403c, the privacy computing management node sends first configuration information to the first privacy computing unit. Correspondingly, the first privacy computing unit receives the first configuration information.
[0235] Specifically, when the response information indicates that the first privacy computing unit can execute the first subtask, the privacy computing unit node sends the first configuration information to the first privacy computing unit. When the response information indicates that the first privacy computing unit cannot execute the first subtask, the privacy computing unit node does not send the first configuration information to the first privacy computing unit. In this way, it can be avoided to send configuration information when the first privacy computing unit cannot execute the first subtask, to avoid wasting communication resources, and to ensure the smooth execution of the first subtask.
[0236] Based on the above information interaction, the privacy computing management node can decompose one privacy computing task into multiple subtasks, and execute corresponding subtasks by corresponding privacy computing units, and issue configuration information corresponding to the subtask to be executed to the corresponding privacy computing unit.
[0237] In one possible implementation, the second request information can also indicate the computing configuration information related to the first subtask. For example, the requirements that need to be met for hardware resources or software resources, such as the number of CPU cores needs to be greater than a threshold, and the like.
[0238] In this way, the first privacy computing unit can determine whether it can execute the first subtask according to the computing configuration information related to the first subtask included in the second request information.
[0239] In one possible implementation, the method 400 can further include:
[0240] S404, the privacy computing management node sends third request information to the first privacy computing unit. Correspondingly, the first privacy computing unit receives the third request information.
[0241] The third request information requests to switch the state of the first subtask, and the state of the first subtask includes: starting, pausing, or stopping.
[0242] For example, the third request information requests the first privacy computing unit to start executing the first subtask.
[0243] For example, the third request information requests the first privacy computing unit to pause executing the first subtask.
[0244] For example, the third request information requests the first privacy computing unit to stop performing the first subtask.
[0245] In this way, this can support the privacy computing management node to control the state of each subtask.
[0246] In one possible implementation, the method 400 can further include:
[0247] S405, the privacy computing management node determines a first key according to the privacy computing resource information of the at least one privacy computing unit. The first key includes an encryption key, a decryption key, and a privacy computing key.
[0248] In this way, this can support the privacy computing management node to configure the corresponding key according to the privacy computing resource information of the privacy computing unit, and further can support the privacy computing unit to be able to use the key to perform the privacy computing task. Or, the privacy computing management node can generate the corresponding key according to the privacy computing resource information of the privacy computing unit, so as to be able to support the key generated by the privacy computing management node to be used by the privacy computing unit.
[0249] In one possible implementation, the type of the first key can include at least one of the following:
[0250] The area-level key, the task-level key, the user-level key, or the application-level key.
[0251] For example, the area-level key refers to that a region composed of certain devices shares a set of keys, for example, device 1 and device 2 are located in region 1, and device 1 and device 2 can use the same set of keys to perform different privacy computing tasks.
[0252] For example, the task-level key refers to that different privacy computing tasks use a corresponding set of keys, for example, privacy computing task 1 uses key 1, and privacy computing task 2 uses key 2, and key 1 is different from key 2.
[0253] For example, the user-level key refers to that the same user can use the same set of keys to perform different privacy computing tasks, for example, for user 1, key 1 can be used to perform privacy computing task 1 and privacy computing task 2.
[0254] For example, the application-level key refers to that the same application can use the same set of keys, for example, for application 1, key 1 can be used to perform privacy computing task 1 and privacy computing task 2; for application 2, key 2 can be used to perform privacy computing task 3 and privacy computing task 4, and so on.
[0255] The type of the first key can be determined by the privacy computing management node or by the privacy computing service requester. For example, the privacy service requester requests the privacy computing management node to configure a corresponding key for a specific area or a specific privacy computing service or a specific user or a specific application. For example, when the privacy computing management node configures a corresponding key for a specific area, the devices in the specific area can share the key, and the privacy computing management node does not need to interact with the devices in the area again, thereby reducing the power consumption of the privacy computing management node and the like.
[0256] The user-level key can be derived according to a superior key. The superior key can be a security anchor function (SEAF) key K SEAF、 , an access and mobility management function (AMF) key K SEAF , and the like. Further description of the user-level key can also be referred to FIG. 5.
[0257] FIG. 5 is an architecture diagram of a user-level key according to an embodiment of the present application. As shown in FIG. 5, the SEAF has a key K AMF , the AMF has a key K AMF , based on the key K NASint , a Non-access stratum (NAS) integrity key K NASenc , a NAS security key K AMF_PC , and K NF , the NF has a key K NF , based on the key K NF_PC , a key K N3IWF , the non-3GPP interworking function (N3IWF) has a key K N3IWF , based on the key K N3IWF_PC , a key K gNB , the base station has a key K gNB , based on the key K RRCint , a key K RRCenc , a key K gNB_PC , a key K UPint , and a key K UPenc .
[0258] K SEAF is a mobile equipment (ME) (which can be understood as the terminal device described above) and an authentication server function (AUSF) from KAUSF Derived anchor key. K SEAF SEAF is provided to the service network by AUSF. K AMF ME and SEAF from K SEAF Derived key. K AMF During horizontal key derivation, it is further derived from ME and source AMF. K NASint ME and AMF from K AMF A derived key, which is only used to protect NAS signaling using a specific integrity algorithm. NASenc ME and AMF from K AMF The derived key is used only to protect NAS signaling using a specific encryption algorithm. K gNB ME and AMF from K AMF Derived key. K gNB When performing horizontal or vertical key export, it is further exported from the ME and the source gNB. UPint ME and gNB from K gNB The derived key is used only to protect data transmitted on the user plane (UP) using a specific encryption algorithm. UPenc ME and gNB from K gNB A derived key that is only used to protect UP traffic between the ME and gNB using a specific integrity algorithm. UPint ME and gNB from K gNB A derived key, which is used only to protect RRC signaling using a specific integrity algorithm. UPenc ME and gNB from K gNB A derived key, which is used only to protect RRC signaling using a specific encryption algorithm. N3IWF ME and AMF from K AMF Derived keys for non-3GPP access. K N3IWF Do not forward between N3IWFs.
[0259] K AMF_PC K NF_PC K gNB_PC K N3IWF_PC These represent different upper-level keys (such as K). AMF K NF K gNB K N3IWF The privacy computing key derived from it is specifically used to perform ciphertext computation or privacy computation.
[0260] It should be noted that the number of encryption keys involved in privacy computing task 1 is related to the number of terminal devices. The first key generated mentioned above has a lifecycle, including key generation, distribution, use, updating, storage, and destruction.
[0261] In an embodiment of the present application, when the upper key is updated, the privacy calculation management node can re-derive the privacy calculation key.
[0262] • K AUSF Updated scenarios: terminal initial access or re-registration, periodic authentication, network migration or handover, service change or permission adjustment, security event triggering, user active request, roaming, etc.
[0263] • K SEAF Updated scenarios: terminal initial access or re-registration, terminal mobility management triggered handover (handover across AMF or gNB-CU), security event response, network function upgrade, key update policy, specific service demand.
[0264] • K gNB Updated scenarios: terminal initial access or re-registration, terminal mobility management triggered handover, periodic key update, security event response, network function upgrade, key management policy change, specific service demand.
[0265] In one possible implementation, when the privacy calculation management node determines the first key, the privacy calculation management node sends the corresponding key to different nodes. For example, the privacy calculation management node sends the encryption key to the encryption node, the privacy calculation management node sends the decryption key to the decryption node, and the privacy calculation management node sends the privacy calculation key to the ciphertext calculation node.
[0266] In one possible implementation, the S405 can further include:
[0267] S405a, the privacy calculation management node receives key information from at least one privacy calculation unit.
[0268] For example, the key information can include but is not limited to: historical keys or key generation materials (for example, based on K AUSF derived key information and key generation parameters or based on K SEAF derived key information and key generation parameters, etc.
[0269] S405b, the privacy calculation management node determines the first key according to the privacy calculation resource information of at least one privacy calculation unit and the key information of at least one privacy calculation unit.
[0270] In this way, it can support the privacy calculation management node to generate a key corresponding to each privacy calculation unit. Or, the key generated by the privacy calculation management node can be used by the privacy calculation unit.
[0271] In a possible implementation, when a change occurs in a privacy computing unit performing a privacy computing task, the privacy computing management node can perform new key generation and distribution.
[0272] For example, when the privacy computing unit 1 in the network device 1 is used to perform the privacy computing task 1, the privacy computing management node configures a key for the privacy computing unit 1 in the network device 1. When the privacy computing unit 1 in the network device 1 no longer performs the privacy computing task 1, and the privacy computing task 1 is performed by the privacy computing unit 2 in the network device 2, the privacy computing management node configures a new key for the privacy computing unit 2 in the network device 2.
[0273] For example, when the privacy computing unit 1 in the AMF 1 is used to perform the privacy computing task 1, the privacy computing management node configures a key for the privacy computing unit 1 in the AMF 1. When the privacy computing unit 1 in the AMF 1 no longer performs the privacy computing task 1, and the privacy computing task 1 is performed by the privacy computing unit 2 in the AMF 2, the privacy computing management node configures a new key for the privacy computing unit 2 in the AMF 2.
[0274] For example, when the privacy computing unit 1 in the user plane function (UPF) 1 is used to perform the privacy computing task 1, the privacy computing management node configures a key for the privacy computing unit 1 in the UPF 1. When the privacy computing unit 1 in the UPF 1 no longer performs the privacy computing task 1, and the privacy computing task 1 is performed by the privacy computing unit 2 in the UPF 2, the privacy computing management node configures a new key for the privacy computing unit 2 in the UPF 2.
[0275] After the privacy computing unit obtains the corresponding configuration information and the key, the privacy computing unit can perform the privacy computing task. For example, the privacy computing unit performing the encryption function uses the encryption key to perform encryption processing on the original data to obtain corresponding ciphertext. The privacy computing unit performing the privacy computing function uses the privacy computing key to perform privacy computing processing on the received ciphertext to obtain ciphertext after re-encryption processing. The privacy computing unit performing the decryption function uses the decryption key to perform decryption processing on the received ciphertext after re-encryption processing to obtain the original data. In a possible implementation, the above ciphertext can be transmitted through the privacy computing management node.
[0276] In a possible implementation, the method 400 can further include:
[0277] S406, the privacy computing management node receives the first ciphertext.
[0278] For example, after the encryption node obtains the encryption key, the encryption key encrypts the sensitive data generated by the encryption key using the encryption key to obtain the first ciphertext, and sends the first ciphertext to the privacy calculation management node. Correspondingly, the privacy calculation management node stores the first ciphertext.
[0279] S407, the privacy calculation management node sends the first ciphertext.
[0280] For example, the privacy calculation management node sends the first ciphertext to the ciphertext calculation node. In this way, this can support the ciphertext calculation node to perform privacy calculation processing on the first ciphertext.
[0281] In this way, the privacy calculation management node can manage the ciphertext, such as forwarding the ciphertext, which can enhance the security of the ciphertext.
[0282] Optionally, the encryption node can send the first ciphertext to the ciphertext calculation node. In this way, this can reduce the power consumption of the privacy calculation management node.
[0283] Optionally, after the ciphertext calculation node performs privacy calculation on the first ciphertext, the ciphertext calculation node sends the first ciphertext after privacy calculation to the decryption node, and the decryption ciphertext uses the decryption key to decrypt the first ciphertext after privacy calculation to obtain the sensitive data corresponding to the first ciphertext.
[0284] One possible implementation, the method 400 can also include:
[0285] S408, the first privacy calculation unit sends the first indication information to the privacy calculation management node. Correspondingly, the privacy calculation management node receives the first indication information.
[0286] For example, the first indication information indicates the related information of the first subtask. For example, the related information of the first subtask includes at least one of the following:
[0287] Subtask identifier, subtask name, subtask state, subtask execution situation or computing resource usage.
[0288] Among them, the subtask state includes at least one of the following:
[0289] Creating, to be executed, executing, execution success, execution failure or end state.
[0290] In addition, the subtask execution situation can include but is not limited to:
[0291] Start time, end time or stop reason.
[0292] In this way, the privacy computing management node obtains the related information of each subtask, and further ensures that the privacy computing task 1 can be executed. Alternatively, this can support the privacy computing management node to obtain the information related to the execution of the privacy computing task, and further manage the subtasks of the privacy computing task, etc. For example, when the privacy computing management node determines that the state of the first subtask is in creation, the privacy computing management node can instruct the first privacy computing unit to speed up the execution of the first subtask, etc. For another example, when the privacy computing management node determines that the state of the first subtask is execution failure, the privacy computing management node can instruct other privacy computing units to execute the first subtask, etc.
[0293] The method shown in FIG. 4 is further described below in combination with FIG. 6.
[0294] FIG. 6 is an interaction flow diagram of another communication method according to an embodiment of the present application. FIG. 6 takes the task management unit, the resource management unit, the privacy computing unit 1, and the privacy computing unit 2 as examples. The task management unit and the resource management unit belong to the privacy computing management node. As shown in FIG. 6, the method includes the following steps.
[0295] S601, the request information 1 is sent to the task management unit. Correspondingly, the task management unit receives the request information 1.
[0296] For example, the request information 1 is used to request the execution of the privacy computing task 1.
[0297] The description of the request information 1 can refer to the description of the first request information described above.
[0298] S602, the task management unit obtains the privacy computing resource information 1 and the privacy computing resource information 2.
[0299] For example, the task management unit obtains the privacy computing resource information 1 of the privacy computing unit 1 and the privacy computing resource information 2 of the privacy computing unit 2 through information interaction between the task management unit and the resource management unit.
[0300] The description of how the resource management unit obtains the privacy computing resource information 1 and the privacy computing resource information 2 can refer to the description of S401.
[0301] S603, the task management unit sends the request information 2 to the privacy computing unit 1. Correspondingly, the privacy computing unit 1 receives the request information 2.
[0302] For example, the request information 2 is used to request the privacy computing unit 1 to execute the subtask 1.
[0303] S604, the task management unit sends the request information 3 to the privacy computing unit 2. Correspondingly, the privacy computing unit 2 receives the request information 3.
[0304] For example, the request information 3 is used to request the privacy computing unit 2 to execute the subtask 2.
[0305] When the task management unit determines to execute the privacy computing task 1, the task management unit performs subtask granularity decomposition on the privacy computing task 1, that is, the task management unit decomposes the privacy computing task 1 into the subtask 1 and the subtask 2, and determines, in combination with the privacy computing resource information 1 and the privacy computing resource information 2, that the subtask 1 is executed by the privacy computing unit 1 and the subtask 2 is executed by the privacy computing unit 2.
[0306] S605, the privacy computing unit 1 sends response information 1 to the task management unit. Correspondingly, the task management unit receives the response information 1.
[0307] S606, the privacy computing unit 2 sends response information 2 to the task management unit. Correspondingly, the task management unit receives the response information 2.
[0308] The privacy computing unit 1 and the privacy computing unit 2 can determine whether to execute the subtask 1 and the subtask 2 according to the privacy computing resource conditions of the privacy computing unit 1 and the privacy computing unit 2, and send corresponding response information to the task management unit.
[0309] S607, the task management unit determines configuration information of the privacy computing task 1.
[0310] The description of the configuration information of the privacy computing task 1 can be referred to Table 4.
[0311] Optionally, the task management unit can respectively issue corresponding configuration information to the privacy computing unit 1 and the privacy computing unit 2.
[0312] S608, the privacy computing unit 1 sends indication information 1 to the task management unit. Correspondingly, the task management unit receives the indication information 1.
[0313] For example, the indication information 1 indicates related information of the subtask 1.
[0314] S609, the privacy computing unit 1 sends indication information 2 to the task management unit. Correspondingly, the task management unit receives the indication information 2.
[0315] For example, the indication information 2 indicates related information of the subtask 2.
[0316] The description of the indication information 1 and the indication information 2 can be referred to the foregoing description of the first indication information, and will not be described herein.
[0317] Through the foregoing method, the embodiment of the present application can support better execution of the privacy computing task 1.
[0318] FIG. 7 is an interaction flow diagram of another communication method according to an embodiment of the present application. FIG. 7 takes the requester, the privacy computing management node, the privacy computing unit 1, the privacy computing unit 2, and the privacy computing unit 3 as an example. The privacy computing unit 1 is configured to perform encryption, the privacy computing unit 2 is configured to perform privacy computation, and the privacy computing unit 3 is configured to perform decryption. As shown in FIG. 7, the method comprises the following steps.
[0319] S701. The privacy computing unit 1 sends the request information 1 to the privacy computing management node. Correspondingly, the privacy computing management node receives the request information 1.
[0320] S703. The privacy computing unit 2 sends the privacy computing resource information 2 to the privacy computing management node. Correspondingly, the privacy computing management node receives the privacy computing resource information 2.
[0321] S704. The privacy computing unit 3 sends the privacy computing resource information 3 to the privacy computing management node. Correspondingly, the privacy computing management node receives the privacy computing resource information 3.
[0322] S705-S707. The privacy computing management node sends the configuration information 1, the configuration information 2, and the configuration information 3 to the privacy computing unit 1, the privacy computing unit 2, and the privacy computing unit 3, respectively. Correspondingly, the privacy computing unit 1 receives the configuration information 1, the privacy computing unit 2 receives the configuration information 2, and the privacy computing unit 3 receives the configuration information 3.
[0323] The description of the configuration information 1-configuration information 3 can refer to the description of the first configuration information in the foregoing, and will not be repeated here.
[0324] S708-S710. The privacy computing unit 1, the privacy computing unit 2, and the privacy computing unit 3 send the response information 3, the response information 4, and the response information 5 to the privacy computing management node, respectively. Correspondingly, the privacy computing management node receives the response information 3, the response information 4, and the response information. The description of the response information 3, the response information 4, and the response information 5 can refer to the description of the response information 1 and the response information 2.
[0325] S711. The privacy computing management node sends the encryption key to the privacy computing unit 1. Correspondingly, the privacy computing unit 1 receives the encryption key.
[0326] S712. The privacy computing management node sends the decryption key to the privacy computing unit 3. Correspondingly, the privacy computing unit 3 receives the decryption key.
[0327] S713, the privacy computing unit 1 sends the ciphertext 1 to the privacy computing management node. Correspondingly, the privacy computing management node receives the ciphertext 1.
[0328] For example, the ciphertext 1 is a ciphertext obtained by the privacy computing unit 1 encrypting data generated by the privacy computing unit using an encryption key. S714, the privacy computing management node sends the privacy computing key and the ciphertext 1 to the privacy computing unit 2. Correspondingly, the privacy computing unit 2 receives the privacy computing key and the ciphertext 1.
[0329] For example, the privacy computing key and the ciphertext 1 can be sent simultaneously or not simultaneously, which is not limited.
[0330] S715, the privacy computing unit 2 sends the ciphertext 2 to the privacy computing unit 3. Correspondingly, the privacy computing unit 3 receives the ciphertext 2.
[0331] For example, the privacy computing unit 2 performs privacy computing processing on the ciphertext 1 using the privacy computing key to obtain the ciphertext 2. Further, the privacy computing unit 3 can perform decryption processing on the ciphertext 2 using a decryption key to obtain the sensitive data generated by the privacy computing unit 1.
[0332] Through the above method, the embodiment of the application can support performing the privacy computing task 1 in the wireless network.
[0333] In order to implement the functions in the method provided in the application, the privacy computing management node and the first privacy computing unit can each include a hardware structure and / or a software module to implement the above functions in the form of a hardware structure, a software module, or a hardware structure plus a software module. Whether a certain function in the above functions is executed in the form of a hardware structure, a software module, or a hardware structure plus a software module depends on the specific application and design constraints of the technical solution.
[0334] FIG. 8 is a schematic block diagram of a communication device according to an embodiment of the application. The communication device includes processing circuitry 810 and transceiver circuitry 820, which can be connected or coupled to each other, such as through a bus 830. The communication device can be a privacy computing management node or a first privacy computing unit.
[0335] Optionally, the communication apparatus can further include a memory 840. The memory 840 includes, but is not limited to, a cache, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read only memory (EPROM), a synchronous dynamic random access memory (SDRAM), a hard disk drive (HDD), a solid-state drive (SSD), or a compact disc read-only memory (CD-ROM). The memory 840 is any other medium capable of storing the desired program code in the form of instructions or data structures and that can be accessed by a computer, but is not limited thereto. The memory in the embodiments of the present application can also be a circuit or any other device capable of realizing a storage function, used for storing computer programs or instructions, and / or data.
[0336] The processing circuit 810 can be all or part of one or more processors, or be one or more processors. The processor can be a central processing unit (CPU). In the case where the processing circuit 810 is a CPU, the CPU can be a single-core CPU or a multi-core CPU. The processing circuit 810 can be a signal processor, a chip, or other integrated circuit capable of implementing the method of the present application, or part of the foregoing processor, chip, or integrated circuit for processing functions. In addition, the transceiver circuit 820 can also be a transceiver, or an input / output interface, an input / output interface for input or output of signals or data, and can also be referred to as an input / output circuit.
[0337] When the communication apparatus is a privacy computing management node, the processing circuit 810 is configured to perform the following operations, for example: obtaining privacy computing resource information of at least one privacy computing unit; receiving first request information; and sending at least one configuration information according to the privacy computing resource information of the at least one privacy computing unit and the first request information.
[0338] When the communication apparatus is a first privacy computing unit, the processing circuit 810 is configured to perform the following operations, for example: sending first privacy computing resource information; and receiving first configuration information.
[0339] When the communication apparatus is the privacy computing management node or the first privacy computing unit, it will be responsible for performing one or more of the methods or steps in the foregoing method embodiments related to the privacy computing management node or the first privacy computing unit.
[0340] When the communication apparatus is the privacy computing management node or the first privacy computing unit, the transceiver circuit 820 can be a transceiver.
[0341] When the communication apparatus is a chip for the privacy computing management node or the first privacy computing unit, the transceiver circuit 820 can be an input / output circuit.
[0342] The foregoing description is only an exemplary description. The specific content can refer to the content shown in the foregoing method embodiments.
[0343] The implementation of each operation in FIG. 8 can also correspond to the description of the corresponding method embodiments shown in FIGS. 4 to 7.
[0344] FIG. 9 is a schematic block diagram of another communication apparatus according to an embodiment of the present application. The communication apparatus can be a privacy computing management node or a first privacy computing unit, and is used to implement the method related to the foregoing embodiments.
[0345] The communication apparatus includes a transceiver unit 910 and a processing unit 920. The transceiver unit 910 can include a sending unit and a receiving unit. The sending unit is used to perform the sending action of the communication apparatus, and the receiving unit is used to perform the receiving action of the communication apparatus. For the convenience of description, the sending unit and the receiving unit are combined into one transceiver unit in the embodiments of the present application. This is uniformly described here, and will not be described again hereinafter.
[0346] When the communication apparatus is the privacy computing management node, the transceiver unit 910 is used to, for example, acquire the privacy computing resource information of at least one privacy computing unit, receive first request information, send at least one configuration information according to the privacy computing resource information of the at least one privacy computing unit and the first request information, and the processing unit 920 is used to determine the first configuration information, etc.
[0347] When the communication apparatus is the first privacy computing unit, the transceiver unit 910 is used to, for example, send the first privacy computing resource information and receive the first configuration information, and the processing unit 920 is used to determine the first privacy computing resource information, etc.
[0348] When the communication apparatus is the privacy computing management node or the first privacy computing unit, it will be responsible for performing one or more of the methods or steps in the foregoing method embodiments related to the privacy computing management node or the first privacy computing unit.
[0349] Optionally, the communication apparatus 900 further includes a storage unit 930, which is used to store programs or codes for implementing the foregoing methods.
[0350] The transceiver unit in FIG. 9 can correspond to the transceiver circuit in FIG. 8, and the processing unit in FIG. 9 can correspond to the processing circuit in FIG. 8.
[0351] The apparatus embodiments shown in FIG. 8 and FIG. 9 are used to implement the content described in FIG. 4 to FIG. 7. The specific execution steps of the apparatus shown in FIG. 8 and FIG. 9 can refer to the content described in the foregoing method embodiments.
[0352] The present application also provides a chip comprising a processor, which is configured to invoke and run instructions stored in a memory, so that a communication device installed with the chip performs the method in each of the examples described above. The memory can be integrated in the chip, or located outside the chip.
[0353] The present application also provides another chip comprising an input interface, an output interface, and a processing circuit, wherein the input interface, the output interface, and the processing circuit are connected through internal connection paths, and the processing circuit is configured to execute code in a memory, and when the code is executed, the processing circuit is configured to perform the method in each of the examples described above.
[0354] Optionally, the chip further comprises a memory configured to store a computer program or code. The input interface and the output interface can be independent of each other, or can be integrated into an input / output interface.
[0355] The processing circuit can be all or part of one or more processors, or one or more processors.
[0356] The present application also provides a processor configured to be coupled with a memory, and configured to perform the method and functions related to the network device or the terminal device in any of the embodiments described above.
[0357] In another embodiment of the present application, a computer program product comprising instructions is provided, and when the computer program product is run on a computer, the method of the foregoing embodiments is implemented.
[0358] The present application also provides a computer program, and when the computer program is run on a computer, the method of the foregoing embodiments is implemented.
[0359] In another embodiment of the present application, a computer readable storage medium is provided, and the computer readable storage medium stores a computer program, and when the computer program is executed by a computer, the method of the foregoing embodiments is implemented.
[0360] It should be understood that, in the embodiments of the present application, the processor can be a CPU, and the processor can also be one or a combination of other general-purpose processors, baseband processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), microprocessor units (MPUs), microcontroller units (MCUs), graphics processing units (GPUs), artificial intelligence processors (AI processors), neural processing units (NPUs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gates or transistor logic, discrete hardware components, and the like. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor.
[0361] It should also be understood that the memory in the embodiments of the present application can be volatile or nonvolatile memory, or can include both volatile and nonvolatile memory. The nonvolatile memory can be read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), electrically EPROM (EEPROM), or flash memory. The volatile memory can be cache, random access memory (RAM), and the RAM can be used as external cache. By way of example, and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), Synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM). It is to be noted that the system and method described herein are intended to include all types of memory, and are not limited to the types of memory described herein.
[0362] The above-described embodiments can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented by software, the above-described embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are wholly or partially generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable apparatus. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center through a wired or wireless (such as infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium accessible by a computer or a data storage device such as a server, data center, etc. containing one or more available medium sets. The available medium can be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium (such as a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state disk.
[0363] It should be understood that the size of the sequence number of each process described above in various embodiments of the present application does not mean the order of execution, and the execution order of each process should be determined by its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0364] Those skilled in the art can appreciate that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solutions. Those skilled in the art can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application. Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described system, device and unit can refer to the corresponding processes in the foregoing method embodiments, which will not be described here. In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the above-described device embodiments are only schematic, for example, the division of units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interface, device or unit, and can be electrical, mechanical or other forms.
[0365] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, i.e. can be located in one place or can be distributed to multiple network units. Some or all of the units can be selected to achieve the purpose of the embodiment according to actual needs. In addition, the functional units in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present alone, or two or more units can be integrated in one unit. When the above functions are realized in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the parts that make contributions to the prior art or parts of the technical solutions can be embodied in the form of software products, which are stored in a storage medium and include a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the methods described in each embodiment of the present application. The foregoing storage medium includes: U disk, mobile hard disk, read-only memory, random access memory, magnetic disk or optical disk, and various program code storage media.
[0366] Those skilled in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized in electronic hardware, or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on specific applications and design constraints of the technical solutions. Those skilled in the art can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
Claims
1. A communication method characterized by comprising: The method comprises: obtaining privacy computing resource information of at least one privacy computing unit, the privacy computing resource information comprising at least one of privacy computing algorithm information, privacy computing function information, and an identifier of a network node to which the privacy computing unit belongs; receiving first request information requesting execution of a first privacy computing task; sending at least one configuration information corresponding to the at least one privacy computing unit according to the privacy computing resource information of the at least one privacy computing unit and the first request information, the configuration information being used for execution of the first privacy computing task.
2. The method of claim 1, wherein, The configuration information comprises at least one of the following: task flow description, subtask index, security cipher algorithm identifier, privacy computing task type, or privacy computing task identifier.
3. The method according to claim 1 or 2, characterized in that, The at least one privacy computing unit comprises a first privacy computing unit, and the first privacy computing task comprises a first subtask, and the sending of the at least one configuration information comprises: sending second request information to the first privacy computing unit, the second request information requesting execution of the first subtask; receiving response information from the first privacy computing unit, the response information indicating agreement to execute the first subtask; sending first configuration information to the first privacy computing unit according to the response information, the at least one configuration information comprising the first configuration information.
4. The method of claim 3, wherein, The method further comprises: sending third request information to the first privacy computing unit, the third request information requesting switching of a state of the first subtask, the state of the first subtask comprising: start, pause, or stop.
5. The method according to any one of claims 1 to 4, characterized in that, The method further comprises: determining a first key according to the privacy computing resource information of the at least one privacy computing unit, the first key comprising an encryption key, a decryption key, and a privacy computing key.
6. The method of claim 5, wherein, The type of the first key comprises at least one of the following: region-level key, task-level key, user-level key, or application-level key.
7. The method according to claim 5 or 6, characterized in that, The determination of the first key according to the privacy computing resource information of the at least one privacy computing unit comprises: receiving key information from the at least one privacy computing unit; determining the first key according to the privacy computing resource information of the at least one privacy computing unit and the key information of the at least one privacy computing unit.
8. The method according to any one of claims 5 to 7, characterized in that, The method further comprises: receiving first ciphertext, the first ciphertext being ciphertext obtained after encryption processing using the encryption key; sending the first ciphertext.
9. The method according to any one of claims 2 to 8, characterized in that, The method further comprises: receiving first indication information from the first privacy computing unit, the first indication information indicating information related to the first subtask, the information related to the first subtask comprising at least one of the following: subtask identifier, subtask name, subtask state, or computing resource usage; the subtask state comprising at least one of the following: creating, to-be-executed, executing, execution success, execution failure, or end state.
10. The method according to any one of claims 1 to 9, characterized in that, The obtaining of the computing resource information of the at least one privacy computing unit comprises: receiving privacy computing resource information from the at least one privacy computing unit.
11. The method according to any one of claims 1 to 10, characterized in that, The privacy computing resource information further comprises at least one of the following: Input parameter information, output parameter information, or state information.
12. A communication method, comprising: The application is applied to a first privacy computing unit, and comprises: sending first privacy computing resource information, the first privacy computing resource information comprising at least one of privacy computing algorithm information, privacy computing function information, and an identifier of a network node to which the first privacy computing unit belongs; receiving first configuration information, the first configuration information being determined according to first request information and privacy computing resource information of at least one privacy computing unit, the first request information requesting execution of a first privacy computing task, and the first configuration information being used for execution of the first privacy computing task, the at least one privacy computing unit comprising the first privacy computing unit.
13. The method of claim 12, wherein, The first configuration information comprises at least one of the following: task flow description, subtask index, security cipher algorithm identifier, privacy computing task type, or privacy computing task identifier.
14. The method according to claim 12 or 13, characterized in that, The first privacy computing task comprises a first subtask, and the receiving first configuration information comprises: receiving second request information, the second request information requesting execution of the first subtask; sending response information, the response information indicating consent to execution of the first subtask; receiving the first configuration information.
15. The method of claim 14, wherein, The method further comprises: receiving third request information, the third request information requesting switching of a state of the first subtask, the state of the first subtask comprising: start, pause, or stop.
16. The method according to any one of claims 12 to 15, characterized in that, The method further comprises: sending key information, the key information being used for generation of a first key, the first key comprising an encryption key, a decryption key, and a privacy computing key.
17. The method of claim 16, wherein, The type of the first key comprises at least one of the following: region-level key, task-level key, user-level key, or application-level key.
18. The method according to claim 16 or 17, characterized in that, The method further comprises: sending first ciphertext, the first ciphertext being ciphertext obtained after encryption processing using the encryption key.
19. The method according to any one of claims 12 to 18, characterized in that, The method further comprises: sending first indication information, the first indication information indicating related information of the first subtask, the related information of the first subtask comprising at least one of the following: subtask identifier, subtask name, subtask state, or computing resource usage of the first unit; the subtask state comprising at least one of the following: creating, to-be-executed, executing, execution success, execution failure, or end state.
20. The method of any one of claims 12-19, wherein, The first privacy computing resource information further comprises at least one of the following: input parameter information, output parameter information, or state information.
21. A communications device, characterized by The communication device comprises a processor, the processor being configured to execute the method according to any one of claims 1 to 20 by executing computer programs or instructions or by a logic circuit.
22. The communication apparatus according to claim 21, wherein, The communication device further comprises a memory, the memory being configured to store the computer programs or instructions.
23. The communication apparatus according to claim 21 or 22, wherein, The communication device further comprises a communication interface, the communication interface being configured to input and / or output signals.
24. A communications device, characterized by The communication device comprises a logic circuit and an input / output interface, the input / output interface being configured to input and / or output signals, and the logic circuit being configured to execute the method according to any one of claims 1 to 20.
25. A computer-readable storage medium, characterized in that, The computer readable storage medium has stored thereon computer programs or instructions, which when executed on a computer, cause the method of any one of claims 1-20 to be performed.
26. A computer program product, characterised in that, A computer program product comprising instructions which when executed on a computer, cause the method of any one of claims 1-20 to be performed.
27. A chip, characterized by Comprising: One or more processors for executing computer programs or instructions in memory, causing the chip to implement the method of any one of claims 1-20.
28. A chip system, characterized by Comprising: One or more processors for executing computer programs or instructions in memory, causing the chip system to implement the method of any one of claims 1-20.
29. A chip mounted in a communication device, characterized by The chip comprises a processor and a communication interface, the processor reads instructions through the communication interface and runs, causing the communication device to perform the method of any one of claims 1-20.
30. A communication system, characterized by Comprising: A privacy computing management node for performing the method of any one of claims 1-11 and a first privacy computing unit for performing the method of any one of claims 12-20.
Citation Information
Patent Citations
Method, device and system for determining computing resources in privacy computing
CN115525919A
Task execution method and device based on privacy computing, equipment and storage medium
CN117113416A
Method, device and system for performing algorithm negotiation on privacy computation
WO2022257731A1
Privacy computing method and apparatus, and electronic device and computer-readable storage medium
WO2023116466A1