Privacy grading and sharing control method for tourist travel itinerary

Through the multi-dimensional grading method, combined with regional sensitivity, user identity and equipment type, the sensitivity level of tourists' travel itinerary data is dynamically adjusted, and the problems of rough grading and poor dynamic adaptability in the existing technology are solved, and the accurate balance between privacy protection and data sharing is achieved, and the requirements of regulations are met.

CN120429889APending Publication Date: 2025-08-05GUANGXI LVFA TECH CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510444273.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-10
Publication Date
2025-08-05

AI Technical Summary

Technical Problem

In the prior art, the privacy protection method of tourists' travel itinerary data fails to comprehensively consider the correlation between the itinerary duration, activity risk, equipment type and other factors, resulting in the disconnection of protection strategies from actual risks, and the inability to dynamically adjust the sensitivity level according to the data sharing frequency and timeliness rules, which may result in excessive protection of expired data or insufficient protection of highly sensitive data.

Method used

The multi-dimensional hierarchical method is adopted, based on the classification rules of regional sensitivity, user identity and device type, combined with the itinerary duration, activity risk and sharing frequency, the sensitivity level of itinerary data is dynamically adjusted, and the access scope of shared objects is restricted through geographical location blurring and user identity anonymization, and the precise balance of data sharing is achieved.

Benefits of technology

It realizes fine-level classification based on complex scenarios, improves the flexibility of privacy grading, handles sensitive data targeted, meets GDPR and other regulatory requirements, and achieves an accurate balance between privacy protection and sharing effects, and avoids the one-sidedness of single-dimensional analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120429889A_ABST
    Figure CN120429889A_ABST
Patent Text Reader

Abstract

The invention is suitable for the technical field of privacy data processing, and provides a privacy grading and sharing control method for tourist travel itineraries, and the method comprises the steps: obtaining travel itinerary data of tourists; dividing the travel data into at least three basic privacy levels based on a preset region sensitivity classification rule, a user identity classification rule and an equipment type classification rule; in the basic privacy level, performing fine-grained sub-level division on the data according to interval division of travel duration, classification of activity risk levels and a historical sharing frequency threshold; based on the basic privacy level and the fine-grained sub-level, geographic position fuzzification and user identity anonymization processing are carried out on the travel data of the high-sensitivity level, and the access range of a shared object is limited through permission grading; and the sensitivity of the fine-grained sub-level is adjusted according to the real-time sharing frequency, and the sharing permission is updated, so that the accurate balance of the travel itinerary data between privacy protection and sharing effectiveness can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of privacy data processing, and in particular to a privacy classification and sharing control method for a tourist's travel itinerary. Background Art

[0002] With the rapid development of smart tourism, location-based services, and big data analytics, tourist itinerary data is widely collected, stored, and shared for use in scenarios such as personalized recommendations, emergency management, and resource scheduling. However, this data often contains highly sensitive personal information, such as identity identifiers, behavioral preferences, and cross-border movement records. Leakage or misuse of this data can lead to privacy violations, location tracking, and even personal safety risks. Current privacy protection methods for travel itinerary data primarily involve static grading based on a single dimension, as well as general data encryption and access control. For example, geofencing can be used to desensitize location data within sensitive areas, or fixed access permissions can be set based on user identity attributes. This approach fails to comprehensively consider factors such as trip duration, activity risk, and device type, leading to a disconnect between protection strategies and actual risks. Another example is the use of symmetric encryption, anonymization algorithms, or role-based access control to enforce a unified protection policy for all travel data. This approach fails to dynamically adjust sensitivity levels based on data sharing frequency and timeliness, potentially resulting in over-protection of expired data or under-protection of highly sensitive data.

[0003] In view of this, a privacy classification and sharing control method for tourists' travel itineraries is needed. Summary of the Invention

[0004] The present invention provides a privacy classification and sharing control method for a tourist's travel itinerary, which is used to solve the problem of insufficient protection of users' sensitive data.

[0005] The present invention provides a privacy classification and sharing control method for tourist travel itineraries, comprising:

[0006] Acquire the visitor's itinerary data, including location information, time information, user identification, activity type identification, device identification, and sharing records;

[0007] Classify the travel data into at least three basic privacy levels based on preset regional sensitivity classification rules, user identity classification rules, and device type classification rules;

[0008] Within the basic privacy level, data is divided into fine-grained sub-levels based on the interval division of trip duration, the classification of activity risk level, and the historical sharing frequency threshold. The sensitivity of the fine-grained sub-level is dynamically adjusted based on the timeliness rules after the sharing frequency exceeds the threshold or the end of the trip;

[0009] Based on the basic privacy level and fine-grained sub-levels, the highly sensitive travel data is geographically obscured and the user identity is anonymized, and the access scope of the shared objects is restricted through permission classification;

[0010] Adjust sensitivity at fine-grained sub-levels based on real-time sharing frequency and update sharing permissions.

[0011] Furthermore, the regional sensitivity classification rules include:

[0012] The regional sensitivity classification rule is to determine the type of area to which the travel data belongs based on the geographic location coordinates, including first-category areas, second-category areas, and third-category areas. The coordinates of the first-category areas are located in border control areas, military restricted areas, or areas covered by sensitive facilities. The coordinates of the second-category areas are located in public tourist attractions, cultural heritage protection areas, or government-designated monitoring areas. The coordinates of the third-category areas are located in commercial areas, urban open roads, or non-sensitive public areas.

[0013] Furthermore, the user identity classification rules include:

[0014] The user identity classification rule is to divide user identities according to the authority attributes of the user identity identification code, including the first category identity, the second category identity and the third category identity. The first category identity includes ordinary tourists, and there is no special authority mark in the identity identification code. The second category identity includes minors or special groups who need supervision, and the identity identification code contains age or health status marks. The third category identity includes government-authorized agencies or cooperative enterprise users, and the identity identification code contains an institutional certification mark.

[0015] Furthermore, the device type classification rules include:

[0016] The device type classification rule is to divide the device type according to the registration information of the device unique identifier, including personal devices and public devices. The device unique identifier of the personal device is bound to the user identity identification code, and the device login requires biometric or password verification; the device unique identifier of the public device is not bound to the user identity identification code, and the device login only requires a temporary authorization code verification.

[0017] Furthermore, the trip data is divided into at least three basic privacy levels based on the preset regional sensitivity classification rules, user identity classification rules, and device type classification rules, including:

[0018] Train a machine learning model based on a historical privacy event dataset and dynamically assign weight coefficients for regional sensitivity classification rules, user identity classification rules, and device type classification rules;

[0019] Calculating a comprehensive sensitivity score according to the weight coefficient;

[0020] The comprehensive sensitivity score is mapped to a basic privacy level according to a preset dynamic threshold interval.

[0021] Furthermore, the interval division of the trip duration further includes:

[0022] Calculate the trip duration based on the time difference between the start and end of the trip, and classify it into single-day trips, multi-day continuous trips, and cross-region multi-day trips based on preset time length thresholds;

[0023] If the duration of the trip exceeds the time threshold and the activity area spans multiple types of areas, the sensitivity of the sub-level is increased and corrected;

[0024] If the duration of the trip does not exceed the time length threshold, the sub-level sensitivity is maintained.

[0025] Furthermore, the classification of the activity level further includes:

[0026] Activities are classified into high-risk, medium-risk and low-risk levels based on the mapping relationship between activity type codes and preset risk labels;

[0027] High-risk activities correspond to travel behaviors involving personal safety or cross-border data transmission, medium-risk activities correspond to travel behaviors involving visits to sensitive areas, and low-risk activities correspond to routine travel behaviors.

[0028] Sub-level sensitivities are graded and revised based on the risk level, with high-risk activities receiving greater revisions than medium- and low-risk activities.

[0029] Furthermore, the setting of the historical sharing frequency threshold further includes:

[0030] Dynamically set the corresponding sharing frequency threshold based on the basic privacy level. High sensitivity level corresponds to low threshold, and low sensitivity level corresponds to high threshold.

[0031] When the number of real-time sharing exceeds the threshold, the sensitivity of the sub-level is gradually increased, and the field range of the shared data is restricted;

[0032] The setting and updating of the threshold is based on the risk assessment results of historical shared records.

[0033] Furthermore, within the basic privacy level, the data is divided into fine-grained sub-levels according to the interval division of travel duration, classification of activity risk level and historical sharing frequency threshold, including:

[0034] Based on the time difference between the end of the trip and the current time, the sub-level sensitivity is gradually reduced according to the preset timeliness rules until the lowest sensitivity level is reached;

[0035] When the number of shares exceeds the threshold, the sub-level sensitivity is immediately increased, and the enhanced restrictions on sharing permissions are triggered;

[0036] The upgraded sub-level must go through a preset processing period before being downgraded according to timeliness rules.

[0037] Furthermore, based on the basic privacy level and the fine-grained sub-levels, the highly sensitive travel data is subjected to geographical obfuscation and user identity anonymization, and the access scope of the shared objects is restricted through permission classification, including:

[0038] Dynamically adjust the fuzzy area range of geographic coordinates based on the privacy level, and convert precise location information into a preset geographic area identifier;

[0039] Generate an anonymous user identifier through an irreversible conversion algorithm, and combine timeliness control to make the anonymous identifier expire after a preset period;

[0040] Set multi-level access rights based on the sensitivity of privacy sub-levels, and limit the access scope and operation permissions of shared objects through differentiated authentication methods and data field access control.

[0041] It can be seen from the above technical solutions that the present invention has the following advantages:

[0042] The present invention obtains multi-dimensional itinerary data of tourists to provide comprehensive input information for privacy classification, avoiding the one-sidedness of single-dimensional analysis; based on multi-rule collaborative judgment of regional sensitivity, user identity and device type, it can make fine-grained classifications according to complex scenarios; through analysis of itinerary duration, activity risk level and sharing frequency, it can improve the flexibility of privacy classification; targeted processing is carried out on sensitive data, and combined with multi-level permission authentication methods, data sharing strictly follows the "minimum necessary" principle. The solution of the present invention solves the defects of coarse classification granularity, poor dynamic adaptability and inflexible sharing control in the existing technology, and achieves a precise balance between privacy protection and sharing utility of travel itinerary data, meeting the core requirements of GDPR and other regulations on data minimization, purpose restriction and user control. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] Figure 1 The figure is a flow chart of an embodiment of a method for privacy classification and sharing control of tourist travel itineraries in the present invention. DETAILED DESCRIPTION

[0044] The terms "first," "second," "third," "fourth," and the like (if any) in the specification and claims of the present invention and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or sequential sequence. It should be understood that the numbers used in this manner are interchangeable where appropriate so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "corresponding to," and any variations thereof, are intended to cover non-exclusive inclusions, e.g., a process, method, system, product, or apparatus comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to these processes, methods, products, or apparatus.

[0045] Example 1

[0046] The implementation method of the present invention can be implemented in the system, can be implemented in the server, and can also be implemented in the terminal, and the specific implementation is not clearly limited. The following will introduce the privacy classification and sharing control method of the tourist travel itinerary in the present invention from the perspective of system implementation. Figure 1 , the method provided by the present invention comprises the following steps:

[0047] S11. Obtain the visitor's itinerary data, which includes location information, time information, user identification, activity type identification, device identification, and shared records;

[0048] Location information is obtained through the Global Positioning System (GPS), base station triangulation, Wi-Fi signal positioning, or Bluetooth beacon technology to obtain the visitor's real-time geographic coordinates, including longitude, latitude, and altitude. This information is then matched to the region type using a Geographic Information System (GIS) database. Time information is stored in Coordinated Universal Time by recording the start and end timestamps of the trip, as well as the time of the activity. Device clocks are synchronized via the Network Time Protocol to ensure time data consistency. User identity is identified by generating an anonymized unique user identifier and encrypting user registration information using an irreversible hashing algorithm to prevent direct association with real-world identities. Activity type identification is based on a predefined activity classification code table, such as "ACT-001" for sightseeing and "ACT-002" for dining. Trip activities are mapped to corresponding codes through natural language processing or manual annotation by the user. Device identification collects the device's unique identifier, operating system type, and version, and generates a composite device identifier using device fingerprinting technology to prevent device spoofing or tampering. Shared records are recorded by building a shared log database to record the recipient identification, sharing time, shared data fields and operation authorization credentials of each data sharing, and blockchain technology is used to ensure the immutability and traceability of the log.

[0049] After preprocessing the collected data, the data transmission channel is encrypted using the TLS 1.3 protocol to prevent man-in-the-middle attacks. When acquiring private data, only necessary fields directly related to the privacy classification are collected, avoiding redundant information such as device serial numbers and IP addresses. Dynamic permission pop-ups are used to obtain real-time user authorization for sensitive data such as location and device information, with support for revocation on demand.

[0050] This step ensures the efficient acquisition and secure storage of travel data through standardized data field definitions, multi-source collection technology integration, and strict privacy protection mechanisms, providing reliable input for subsequent privacy classification and sharing control.

[0051] S12. Classify the trip data into at least three basic privacy levels based on preset regional sensitivity classification rules, user identity classification rules, and device type classification rules;

[0052] Regional sensitivity classification rules include:

[0053] The regional sensitivity classification rule is to determine the type of area to which the travel data belongs based on the geographic location coordinates, including first-class areas, second-class areas and third-class areas. The coordinates of the first-class areas are located in border control areas, military restricted areas or areas covered by sensitive facilities. The coordinates of the second-class areas are located in public tourist attractions, cultural heritage protection areas or government-designated monitoring areas. The coordinates of the third-class areas are located in commercial areas, urban open roads or non-sensitive public areas.

[0054] Specifically, the regional type is achieved by establishing a GIS database containing multiple types of sensitive areas. The first type of area stores the coordinate boundaries of border control areas, coordinate polygons of military restricted areas and sensitive facilities provided by the National Geographic Survey and Mapping Administration, such as longitude and latitude vertex sequences, and coordinate coverage of sensitive facilities such as nuclear power plants or government agencies.

[0055] The second type of area integrates the coordinate data of public tourist attractions, cultural heritage protection areas and government monitoring areas.

[0056] The third type of area obtains the coordinate range of commercial areas and urban open roads through the open map API.

[0057] Coordinate range matching includes: inputting the real-time geographic location coordinates of tourists, such as longitude X and latitude Y; calling the geometric spatial query interface of the GIS database to determine whether the coordinates fall within the polygon range of a certain type of area. If the coordinates fall into multiple areas at the same time, such as a border control area and a scenic area, and the two overlap, the highest level area type is selected according to the sensitivity priority, where the sensitivity priority of the first category is greater than the second category, and the second category is greater than the third category.

[0058] User identity classification rules include:

[0059] The user identity classification rule is to divide user identities according to the authority attributes of the user identity identification code, including the first category identity, the second category identity and the third category identity. The first category identity includes ordinary tourists, and there is no special authority mark in the identity identification code. The second category identity includes minors or special groups who need supervision, and the identity identification code contains age or health status marks. The third category identity includes government-authorized agencies or cooperative enterprise users, and the identity identification code contains an institutional certification mark.

[0060] Specifically, the encoding rules are as follows: the first type of identity code consists of pure numbers, is 16 bits long, and has no extension fields. The second type of identity code prefix indicates the type, such as MIN- for minors and SPC- for special populations, followed by a hashed age or health status code, such as MIN-a1b2c3d4. The third type of identity code prefix is the organization code, such as GOV- for government agencies and CORP- for cooperative enterprises, followed by a digital signature field and a valid timestamp, such as GOV-XXXX-20251231. Identity type verification is performed by matching the input user identity code with a regular expression. If it matches [0-9]{16}, it is determined to be a first type identity. If it matches (MIN-│SPC-)[a-f0-9]{8}, it is determined to be a second type identity. The metadata associated with the hash value is then parsed. If the age is 18 or above, the user is automatically upgraded to a regular tourist. If it matches GOV-│CORP-)[A-Z0-9]{8}-[0-9]{8}, the public key is called to verify the digital signature. If the verification passes and the timestamp has not expired, it is determined to be a third-category identity.

[0061] Equipment type classification rules, including:

[0062] The device type classification rule is to divide the device type into personal devices and public devices based on the registration information of the device's unique identifier. The device's unique identifier for personal devices is bound to the user's identity code, and device login requires biometric or password verification; the device's unique identifier for public devices is not bound to the user's identity code, and device login only requires temporary authorization code verification.

[0063] Specifically, the identifier format for personal devices is PER-prefix + SHA-256 hash value of the user identity code, such as PER-a1b2c3d4, and is bound to the user account system. The identifier format for public devices is PUB-prefix + serial number provided by the device manufacturer, such as PUB-12345678, which is stored in the device's factory firmware. When logging in to a personal device, it is necessary to collect biometrics or enter a preset password, such as fingerprint or facial recognition; the biometric template or password hash value is verified through a security chip, and the device identifier is activated if it matches. When logging in to a public device, a one-time temporary authorization code is generated and sent to the user via SMS or email; after the user enters the authorization code, the device identifier is activated and bound to the current session, and the session automatically expires after a certain set time.

[0064] This step also includes the following:

[0065] 1. Train a machine learning model based on a historical privacy event dataset and dynamically assign weight coefficients to regional sensitivity classification rules, user identity classification rules, and device type classification rules;

[0066] The historical privacy event dataset extracts travel data records of privacy events from security logs and performs desensitization processing. The obtained fields include the region type, user identity type, device type label, and the corresponding actual risk level label of the historical travel data. The acquired data is subjected to feature extraction, where the region type (first category = 100, second category = 60, third category = 20), user identity type (second category = 80, third category = 50, first category = 10), and device type (public device = 70, personal device = 30) are encoded as numerical features. A random forest regression model is used, which inputs a feature vector and outputs a weight coefficient representing the region, a weight coefficient representing the identity, and a weight coefficient representing the device. The training goal is to minimize the mean squared error between the predicted weight and the actual privacy risk level.

[0067] 2. Calculate the comprehensive sensitivity score based on the weight coefficient;

[0068] Comprehensive sensitivity score calculation process: When the input trip data is the first-category area, the second-category identity and public equipment, the model output is that the weight coefficient of the first-category area is 0.6, the weight coefficient of the second-category identity is 0.3, and the weight coefficient of the public equipment is 0.1, then the final sensitivity score is 91 points.

[0069] 3. Map the comprehensive sensitivity score to the basic privacy level based on the preset dynamic threshold range.

[0070] Finally, the K-means clustering algorithm is used to cluster the comprehensive sensitivity scores S of the historical dataset, generating three centers as thresholds T1 (high sensitivity), T2 (medium sensitivity), and T3 (low sensitivity). If S≥T1, it is classified into the first-level basic privacy level, that is, high sensitivity; if T2≤S<T1, it is classified into the second-level basic privacy level, that is, medium sensitivity; if S<T2, it is classified into the third-level basic privacy level, that is, low sensitivity. The model is retrained and the thresholds are updated monthly to adapt to the changes in data distribution; when the newly added privacy event data exceeds 10% of the historical data volume, the model is triggered for real-time fine-tuning.

[0071] The above-mentioned division of basic privacy levels: using machine learning to dynamically allocate weights to avoid insufficient scenario adaptability caused by fixed coefficients, and optimizing the thresholds through clustering to enhance the basis for classification.

[0072] S13. Within the basic privacy level, the data is further divided into fine-grained sub-levels according to the interval division of the trip duration, the classification of activity risk levels, and the historical sharing frequency threshold. The sensitivity of the fine-grained sub-levels is dynamically adjusted based on the sharing frequency exceeding the threshold or the timeliness rule after the trip ends;

[0073] The interval division of the trip duration further includes:

[0074] Calculate the trip duration based on the time difference between the start and end timestamps of the trip, and divide it into single-day trips, multi-day continuous trips, and multi-day cross-regional trips based on a preset time length threshold;

[0075] If the trip duration exceeds the time length threshold and the activity area spans multiple types of regions, the sensitivity of the sub-level is increased and corrected;

[0076] If the trip duration does not exceed the time length threshold, the sensitivity of the sub-level remains unchanged.

[0077] Specifically, the start timestamp and end timestamp of the collected trip are stored in the UTC time format, and the unit for calculating the duration is hours or days. The duration of a single-day trip in the preset time length threshold is less than or equal to 24 hours, the duration of a multi-day continuous trip is greater than 24 hours and less than or equal to 72 hours, and the activity area does not span multiple types of regions; the duration of a multi-day cross-regional trip is greater than 72 hours or the activity area spans multiple types of regions, such as entering the second type of region from the first type of region. If the trip is a multi-day cross-regional trip, the sensitivity of the sub-level is increased by one level (such as rising from L2.1 to L2.2), and the sensitivity of a single-day or multi-day continuous trip remains the same.

[0078] The classification of activity levels further includes:

[0079] The activities are classified into high-risk, medium-risk, and low-risk levels according to the mapping relationship between the activity type code and the preset risk label;

[0080] High-risk activities correspond to travel behaviors involving personal safety or cross-border data transmission, medium-risk activities correspond to travel behaviors involving visits to sensitive areas, and low-risk activities correspond to routine travel behaviors.

[0081] Sub-level sensitivities are graded and revised based on risk levels, with high-risk activities receiving greater revisions than medium- and low-risk activities.

[0082] Specifically, the pre-set risk tag library includes high-risk, medium-risk, and low-risk activities. The risk level is determined by matching the activity type code with the tag library. If no match occurs, the activity is classified as low risk by default. The sensitivity of the sub-level for high-risk activities increases by two levels (e.g., from L1.1 to L1.3); the sensitivity of the sub-level for medium-risk activities increases by one level (e.g., from L2.2 to L2.3); and the sensitivity of low-risk activities remains at the original level.

[0083] The setting of the historical sharing frequency threshold further includes:

[0084] Dynamically set the corresponding sharing frequency threshold based on the basic privacy level. High sensitivity level corresponds to low threshold, and low sensitivity level corresponds to high threshold.

[0085] When the number of real-time sharing exceeds the threshold, the sensitivity of the sub-level is gradually increased, and the field range of the shared data is restricted;

[0086] Thresholds are set and updated based on risk assessment results from historical shared records.

[0087] The threshold mapping rules are as follows: the sharing frequency threshold for the first level of basic privacy is 3 times, the sharing frequency threshold for the second level is 5 times, and the sharing frequency threshold for the third level is 10 times. Based on risk events in historical sharing records, such as the number of leaks and the frequency of illegal access, the threshold is dynamically adjusted through a risk assessment model. If a risk event has occurred in a certain level of data within the past 30 days, the threshold is reduced by 20%. When the number of real-time sharing times exceeds the threshold, the sensitivity of the sub-level is gradually increased (e.g., L1.1 → L1.2), restricting the shared data fields.

[0088] This step also includes the following:

[0089] 1. Based on the time difference between the trip end time and the current time, the sensitivity of the sub-level is gradually reduced according to the preset timeliness rules until the lowest sensitivity level is reached;

[0090] 2. When the number of shares exceeds the threshold, the sub-level sensitivity is immediately increased, triggering enhanced restrictions on sharing permissions;

[0091] 3. Upgraded sub-levels are subject to a pre-set processing period before being downgraded according to timeliness rules.

[0092] First, calculate the difference between the end time of the trip and the current time. If the difference is less than 7 days, the original sensitivity is maintained; if the difference is greater than 7 days and less than or equal to 30 days, the sensitivity is reduced by one level; if the difference is greater than 30 days, the sensitivity is reduced to the lowest level. When the number of sharing times exceeds the threshold, the sub-level sensitivity is immediately increased (such as L1.2→L1.3), triggering enhanced restrictions: only government agencies are allowed to access, and secondary authorization is required. The upgraded sub-level must go through a fixed period (such as 24 hours) before it can be downgraded according to the timeliness rules; if the threshold is exceeded again within the period, the sensitivity continues to increase.

[0093] For example, a tourist uses public equipment for a five-day, cross-regional hike in a border area classified as a Category 1 zone. Cross-regional hiking is considered a high-risk activity and is classified as Level 1 (High Sensitivity). If the trip lasts 120 hours (>72 hours) and crosses regions, it is classified as a multi-day, cross-regional trip, and the sensitivity is increased to Level 1.2. If the activity type is considered high-risk, the sensitivity is increased two levels to Level 1.4. If the initial sharing threshold is three times and the number of real-time shares reaches four, the sensitivity is increased to Level 1.5, and the shared fields are restricted to only time information. Ten days after the trip, the sensitivity is reduced from Level 1.5 to Level 1.4. If the user shares the data a fifth time within the downgrade period, the sensitivity is increased to Level 1.6, and sharing is prohibited for 24 hours.

[0094] S14. Based on the basic privacy level and fine-grained sub-levels, the geolocation of highly sensitive travel data is obscured and the user identity is anonymized, and access to shared objects is restricted through permission classification.

[0095] 1. Dynamically adjust the fuzzy area of geographic coordinates based on the privacy level, converting precise location information into a preset geographic area identifier;

[0096] Based on the basic privacy level and sub-level sensitivity, geographic grids of different precisions are dynamically generated. For example: the grid of the high-sensitivity sub-level (such as L1.3) covers a circular area with a radius of 5 kilometers; the grid of the medium-sensitivity sub-level (such as L2.2) covers a hexagonal area with a radius of 2 kilometers; the grid of the low-sensitivity sub-level (such as L3.1) covers a square area with a radius of 500 meters. Use the spatial index algorithm to map the original coordinates to the center point of the corresponding grid to generate a fuzzy area identifier. When the sub-level sensitivity is upgraded, the grid coverage is automatically expanded, such as from a radius of 2 kilometers to 5 kilometers. When the sensitivity is downgraded, the grid range is reduced to restore data accuracy. The fuzzy area identifier is embedded in the metadata field of the travel data, replacing the original coordinates. Establish a mapping table between grid identifiers and administrative divisions for authorized parties to parse on demand.

[0097] 2. Generate an anonymized user identifier through an irreversible conversion algorithm, and use timeliness control to ensure the anonymous identifier expires after a preset period;

[0098] A SHA-256 hash is performed on the user's ID code to generate an anonymized identifier of fixed length. A salt value is added to prevent rainbow table attacks. The salt value is dynamically generated and encrypted by the key management system. A time-sensitive key is generated for each anonymized identifier, and the identifier automatically becomes invalid upon expiration. Key renewal rules: If travel data is accessed again within the validity period, the key validity period is extended to the last access time plus 24 hours. Expired identifiers cannot be reversed to the original identity, and only desensitized statistical information is retained in the associated data.

[0099] 3. Set multi-level access permissions based on the sensitivity of privacy sub-levels, and limit the access scope and operation permissions of shared objects through differentiated authentication methods and data field access control.

[0100] Level 1, the highest level in the permission hierarchy, allows access to obfuscated area identification, anonymized user identifiers, and high-risk activity types. Authentication methods include multi-factor authentication, such as biometrics plus dynamic passwords, and are limited to government-authorized agencies. Level 2, the intermediate level, allows access to travel time ranges, regular activity types, and device types. Authentication is digital certificate verification, suitable for public service agencies. Level 3, the lowest level, only allows access to statistical aggregated data, such as tourist flow heat maps, and does not include individual information. Authentication can be verified by API key and is open to cooperating commercial organizations.

[0101] Field-level access control dynamically masks data fields based on sub-level sensitivity. High-sensitivity sub-levels (e.g., L1.3) hide device identifiers and shared records, leaving only obfuscated locations accessible. Low-sensitivity sub-levels (e.g., L3.1) open all fields but restrict access frequency. Real-time permission linkage automatically updates sharing permission policies as sub-level sensitivity dynamically adjusts. Through field-level control and multi-level authentication, we ensure the "minimum necessary" and "minimized permissions" of data sharing.

[0102] S15. Adjust the sensitivity of the fine-grained sub-level according to the real-time sharing frequency and update the sharing permission.

[0103] This step monitors the sharing frequency of travel data in real time, combines the stream processing framework with distributed counters to count the number of sharing times, and triggers sub-level sensitivity upgrades. For example, after exceeding the threshold, the sensitivity is increased and the data fields are restricted. The permission policy is updated, such as strengthening the authentication method, shielding sensitive fields, and introducing a cooling-off period mechanism to prevent frequent fluctuations. At the same time, based on timeliness rules such as automatic downgrade after the end of the trip, two-way dynamic adjustment of sensitivity and permissions is achieved to ensure that data sharing meets the minimum necessary principle and compliance requirements while responding to risks in real time.

[0104] Those skilled in the art will appreciate that the units of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition of each example has been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.

[0105] In the embodiments provided herein, it should be understood that the division of units is merely a logical functional division. In actual implementation, other division methods may be employed, such as combining multiple units into one unit, splitting a unit into multiple units, or ignoring certain features. Furthermore, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically as a separate unit, or two or more units may be integrated into a single unit. These integrated units may be implemented in either hardware or software functional units.

[0106] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-0nly Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk, etc., various media that can store program code.

[0107] It can be understood that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or make equivalent replacements for some or all of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present invention, and they should all be included in the scope of the claims and description of the present invention.

Claims

1. A privacy classification and sharing control method for tourist travel itineraries, characterized in that: include: Acquire the visitor's itinerary data, including location information, time information, user identification, activity type identification, device identification, and sharing records; Classify the travel data into at least three basic privacy levels based on preset regional sensitivity classification rules, user identity classification rules, and device type classification rules; Within the basic privacy level, data is divided into fine-grained sub-levels based on the interval division of trip duration, the classification of activity risk level, and the historical sharing frequency threshold. The sensitivity of the fine-grained sub-level is dynamically adjusted based on the timeliness rules after the sharing frequency exceeds the threshold or the end of the trip; Based on the basic privacy level and fine-grained sub-levels, the highly sensitive travel data is geographically obscured and the user identity is anonymized, and the access scope of the shared objects is restricted through permission classification; Adjust sensitivity at fine-grained sub-levels based on real-time sharing frequency and update sharing permissions.

2. The privacy classification and sharing control method for tourist travel itineraries according to claim 1 is characterized in that: The regional sensitivity classification rules include: The regional sensitivity classification rule is to determine the type of area to which the travel data belongs based on the geographic location coordinates, including first-category areas, second-category areas, and third-category areas. The coordinates of the first-category areas are located in border control areas, military restricted areas, or areas covered by sensitive facilities. The coordinates of the second-category areas are located in public tourist attractions, cultural heritage protection areas, or government-designated monitoring areas. The coordinates of the third-category areas are located in commercial areas, urban open roads, or non-sensitive public areas.

3. The privacy classification and sharing control method for tourist travel itineraries according to claim 1 is characterized in that: The user identity classification rules include: The user identity classification rule is to divide user identities according to the authority attributes of the user identity identification code, including the first category identity, the second category identity and the third category identity. The first category identity includes ordinary tourists, and there is no special authority mark in the identity identification code. The second category identity includes minors or special groups who need supervision, and the identity identification code contains age or health status marks. The third category identity includes government-authorized agencies or cooperative enterprise users, and the identity identification code contains an institutional certification mark.

4. The privacy classification and sharing control method for tourist travel itineraries according to claim 1 is characterized in that: The device type classification rules include: The device type classification rule is to divide the device type according to the registration information of the device unique identifier, including personal devices and public devices. The device unique identifier of the personal device is bound to the user identity identification code, and the device login requires biometric or password verification; the device unique identifier of the public device is not bound to the user identity identification code, and the device login only requires a temporary authorization code verification.

5. The privacy classification and sharing control method for tourist travel itineraries according to any one of claims 1 to 4, characterized in that: The trip data is divided into at least three basic privacy levels based on the preset regional sensitivity classification rules, user identity classification rules, and device type classification rules, including: A machine learning model is trained based on a historical privacy event dataset to dynamically assign weight coefficients to regional sensitivity classification rules, user identity classification rules, and device type classification rules. Calculating a comprehensive sensitivity score according to the weight coefficient; The comprehensive sensitivity score is mapped to a basic privacy level according to a preset dynamic threshold interval.

6. The privacy classification and sharing control method for tourist travel itineraries according to claim 1 is characterized in that: The interval division of the trip duration further includes: Calculate the trip duration based on the time difference between the start and end of the trip, and classify it into single-day trips, multi-day continuous trips, and cross-region multi-day trips based on preset time length thresholds; If the duration of the trip exceeds the time threshold and the activity area spans multiple types of areas, the sensitivity of the sub-level is increased and corrected; If the duration of the trip does not exceed the time length threshold, the sub-level sensitivity is maintained.

7. The privacy classification and sharing control method for tourist travel itineraries according to claim 6 is characterized in that: The classification of activity levels further includes: Activities are classified into high-risk, medium-risk and low-risk levels based on the mapping relationship between activity type codes and preset risk labels; High-risk activities correspond to travel behaviors involving personal safety or cross-border data transmission, medium-risk activities correspond to travel behaviors involving visits to sensitive areas, and low-risk activities correspond to routine travel behaviors. Sub-level sensitivities are graded and revised based on the risk level, with high-risk activities receiving greater revisions than medium- and low-risk activities.

8. The privacy classification and sharing control method for tourist travel itineraries according to claim 7 is characterized in that: The setting of the historical sharing frequency threshold further includes: Dynamically set the corresponding sharing frequency threshold based on the basic privacy level. High sensitivity level corresponds to low threshold, and low sensitivity level corresponds to high threshold. When the number of real-time sharing exceeds the threshold, the sensitivity of the sub-level is gradually increased, and the field range of the shared data is restricted; The setting and updating of the threshold is based on the risk assessment results of historical shared records.

9. The privacy classification and sharing control method for tourist travel itineraries according to claim 8 is characterized in that: Within the basic privacy level, data is divided into fine-grained sub-levels based on the interval division of travel duration, classification of activity risk level, and historical sharing frequency threshold, including: Based on the time difference between the end of the trip and the current time, the sub-level sensitivity is gradually reduced according to the preset timeliness rules until the lowest sensitivity level is reached; When the number of shares exceeds the threshold, the sub-level sensitivity is immediately increased, and the enhanced restrictions on sharing permissions are triggered; The upgraded sub-level must go through a preset processing period before being downgraded according to timeliness rules.

10. The privacy classification and sharing control method for tourist travel itineraries according to claim 1 is characterized in that: The high-sensitivity travel data is geographically obscured and user identity anonymized based on the basic privacy level and fine-grained sub-levels, and the access scope of shared objects is restricted through permission classification, including: Dynamically adjust the fuzzy area range of geographic coordinates based on privacy levels, converting precise location information into a preset geographic area identifier; Generate an anonymous user identifier through an irreversible conversion algorithm, and combine timeliness control to make the anonymous identifier expire after a preset period; Set multi-level access rights based on the sensitivity of privacy sub-levels, and limit the access scope and operation permissions of shared objects through differentiated authentication methods and data field access control.

Citation Information

Cited By

  • Track privacy data protection and sharing method

    CN120724482A

  • Method for protecting and sharing trajectory privacy data

    CN120724482B