Privacy information retrieval method and device based on differential privacy

By combining differential privacy technology with private information retrieval, generating multiple indexes and adding noise, the problem of information leakage in user data queries is solved, and two-way security of user privacy and data protection is achieved.

CN120670467APending Publication Date: 2025-09-19ZHONGJINKE INFORMATION TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510499921.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-21
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Existing privacy protection technologies pose data security risks when querying a set of user data, leading to the risk of user information leakage.

Method used

A privacy information retrieval method based on differential privacy is adopted. By generating multiple indexes on the data processing server, traversing the XOR results, adding target Laplace noise, and generating the final query results, the privacy of the user's query intention and the queried data is protected.

Benefits of technology

It achieves the goal of protecting user query information while avoiding accurate inference of user information, ensuring two-way protection of user privacy and information retrieval.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120670467A_ABST
    Figure CN120670467A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of privacy protection, in particular to a privacy information retrieval method and device based on differential privacy, and the method comprises the steps: obtaining at least one piece of key information of a user, and generating a plurality of indexes in a data retrieval server according to the at least one piece of key information; searching a local group corresponding to each index in a data processing server; traversing the XOR result in the group corresponding to each index, and determining a target value corresponding to each index according to the XOR result; summing the target value corresponding to each index to obtain a summing result, and adding target Laplacian noise to the summing result to generate a final query result. Therefore, the problems that when a group of user data is queried by an existing privacy protection technology, certain hidden dangers in the aspect of data security can occur, and the risk of user information leakage occurs are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of privacy protection technology, and in particular to a privacy information retrieval method and device based on differential privacy. Background Art

[0002] With the rapid development of information technology, privacy protection and data security have become critical issues in the current data processing field. Among existing privacy protection technologies, advances in privacy information retrieval technology allow users to query data without revealing their query content to data service providers. Users can hide their specific search information, and the database can still accurately match query results. However, this technology presents certain data security risks when querying a set of user data, leading to the risk of user information leakage. For example, when a bank uses privacy information retrieval technology to retrieve the total assets of newly added high-net-worth users that year, if the bank learns that a specific user's data was added at a specific time, the bank will retrieve the updated data and subtract it from the previous data to obtain the user's information. This is clearly an unacceptable situation. Therefore, how to protect the personal information contained in the queried data while protecting the user's search information has become a pressing issue in practical applications. Summary of the Invention

[0003] The present invention provides a privacy information retrieval method and device based on differential privacy to solve the problem that when existing privacy protection technologies query a group of user data, certain data security risks may arise, leading to the risk of user information leakage.

[0004] An embodiment of the first aspect of the present invention provides a privacy information retrieval method based on differential privacy, comprising the following steps: obtaining at least one key information of a user, and generating multiple indexes in a data retrieval server based on the at least one key information; searching for a local group corresponding to each index in a data processing server; traversing the XOR results in the group corresponding to each index, and determining a target value corresponding to each index based on the XOR result; summing the target values ​​corresponding to each index to obtain a summation result, and adding target Laplace noise to the summation result to generate a final query result.

[0005] Optionally, before obtaining at least one key information of the user, the method further includes:

[0006] Storing multiple integer data in the database server;

[0007] The plurality of integer data are mapped to different groups of the data processing server, and a bitwise exclusive OR operation is performed with the locally stored data to complete the local storage of the plurality of integer data.

[0008] Optionally, mapping the plurality of integer data to different groups of the data processing server and performing a bitwise exclusive OR operation with the locally stored data to complete local storage of the plurality of integer data includes:

[0009] Divide the plurality of integer data into n groups of data, and send one group of data to the data processing server each time, wherein each group of data contains m pieces of data, m and n are both positive integers, and m and n are equal;

[0010] Performing preset encryption on the group sequence number and the local group sequence number of each group of data received by the data processing server to obtain the intra-group offset of each group of data, and determining the value to be operated in the corresponding group according to the intra-group offset of each group of data;

[0011] The value to be operated is XORed with the data stored in its corresponding local group using a bitwise XOR method to generate an XOR result in the corresponding local group. After an XOR result is generated in the local group corresponding to each group of data, the local storage of the value to be operated is completed.

[0012] Optionally, traversing the XOR results in the group corresponding to each index and determining the target value corresponding to each index according to the XOR results includes:

[0013] Traverse the XOR results in the group corresponding to each index;

[0014] Calculate the corresponding intra-group offset of each index according to the group sequence number and the local group sequence number corresponding to each index;

[0015] According to the intra-group offset value, it solves the index of other values ​​stored in the local group sequence number;

[0016] The actual value is searched in the target database using the index of the other numerical value, and an XOR operation is performed on the actual value and the XOR result in the corresponding group to obtain the target value corresponding to each index.

[0017] The second aspect of the present invention provides a privacy information retrieval device based on differential privacy, including: a generation module for obtaining at least one key information of a user and generating multiple indexes in a data retrieval server based on the at least one key information; a search module for searching the local group corresponding to each index in the data processing server; a traversal module for traversing the XOR results in the group corresponding to each index and determining the target value corresponding to each index based on the XOR result; an adding module for summing the target values ​​corresponding to each index to obtain a sum result, and adding target Laplace noise to the sum result to generate a final query result.

[0018] Optionally, it also includes:

[0019] A storage module, used for storing multiple integer data in a database server;

[0020] A mapping module is used to map the plurality of integer data to different groups of the data processing server and perform a bitwise exclusive OR operation with the locally stored data to complete the local storage of the plurality of integer data.

[0021] Optionally, the processing module includes:

[0022] a sending unit, configured to divide the plurality of integer data into n groups of data, and send one group of data to the data processing server each time, wherein each group of data contains m pieces of data, m and n are both positive integers, and m and n are equal;

[0023] an encryption unit, configured to perform preset encryption on the group sequence number and the local group sequence number of each data set received by the data processing server to obtain an intra-group offset of each data set, and determine a value to be operated in the corresponding group according to the intra-group offset of each data set;

[0024] The XOR operation unit is used to perform an XOR operation on the value to be operated and the data stored in its corresponding local group in a bit-by-bit XOR manner to generate an XOR result in the corresponding local group. After an XOR result is generated in the local group corresponding to each group of data, the local storage of the value to be operated is completed.

[0025] Optionally, the traversal module includes:

[0026] A traversal unit, used for traversing the XOR results in the group corresponding to each index;

[0027] A solving unit, configured to solve the corresponding intra-group offset of each index according to the group sequence number and the local group sequence number corresponding to each index;

[0028] The search unit is used to use the intra-group offset to search for an actual value in the target database, and perform an XOR operation on the actual value and the XOR result in its corresponding group to obtain the target value corresponding to each index.

[0029] An embodiment of the third aspect of the present invention provides an electronic device, comprising: a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor executes the program to implement the privacy information retrieval method based on differential privacy as described in the above embodiment.

[0030] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, which stores a computer program. When the program is executed by a processor, it implements the above-mentioned privacy information retrieval method based on differential privacy.

[0031] The privacy information retrieval method and device based on differential privacy proposed in the embodiments of the present invention combine privacy information retrieval technology with differential privacy technology, utilizing the characteristics of privacy information retrieval technology to protect the user's query intention and the characteristics of differential privacy technology to protect the individual privacy of the queried data, thereby achieving comprehensive protection of user privacy data and database individual data.

[0032] Additional aspects and advantages of the present invention will be set forth in part in the description which follows and, in part, will be obvious from the description which follows, or may be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] The above and / or additional aspects and advantages of the present invention will become apparent and readily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:

[0034] Figure 1 A flowchart of a privacy information retrieval method based on differential privacy provided by an embodiment of the present invention;

[0035] Figure 2 A privacy information retrieval method based on differential privacy provided by an embodiment of the present invention;

[0036] Figure 3 A block diagram of a privacy information retrieval device based on differential privacy provided by an embodiment of the present invention;

[0037] Figure 4 The present invention provides a schematic structural diagram of an electronic device. DETAILED DESCRIPTION

[0038] The following describes embodiments of the present invention in detail, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present invention, and are not to be construed as limiting the present invention.

[0039] The following describes a differential privacy-based privacy information retrieval method and apparatus according to an embodiment of the present invention with reference to the accompanying drawings.

[0040] It should be noted that the privacy information retrieval method based on differential privacy proposed in the embodiment of the present invention is aimed at numerical data retrieval. By using privacy information retrieval technology and adding noise to the index results, it protects the user index information while achieving the protection of individual data in the database.

[0041] Specifically, Figure 1 A flowchart of a privacy information retrieval method based on differential privacy provided by an embodiment of the present invention.

[0042] like Figure 1 As shown, the privacy information retrieval method based on differential privacy includes the following steps:

[0043] In step S101, at least one key information of a user is obtained, and a plurality of indexes are generated on a data retrieval server according to the at least one key information.

[0044] In some embodiments, before obtaining at least one key information of the user, the method further includes:

[0045] Storing multiple integer data in the database server;

[0046] Map multiple integer data to different groups on the data processing server and perform bitwise XOR operations with the locally stored data to complete the local storage of multiple integer data.

[0047] In some embodiments, mapping multiple integer data items to different groups of data processing servers and performing a bitwise exclusive OR operation with locally stored data to complete local storage of the multiple integer data items includes:

[0048] Divide multiple integer data into n groups, and send one group of data to the data processing server each time. Each group of data contains m data, and m and n are both positive integers and equal to each other.

[0049] Performing preset encryption on the group sequence number and local group sequence number of each data set received by the data processing server to obtain the intra-group offset of each data set, and determining the value to be operated in the corresponding group according to the intra-group offset of each data set;

[0050] Using a bitwise XOR method, the value to be operated is XORed with the data stored in its corresponding local group to generate an XOR result in the corresponding local group. After an XOR result is generated in the local group corresponding to each group of data, the local storage of the value to be operated is completed.

[0051] It should be noted that if Figure 2 As shown, there are four roles: user, data retrieval server, data processing server and database server. Among them, the user is the initiator of the query, the data retrieval server is used to generate the retrieval of the target data based on the information provided by the user, the data processing server is used to retrieve privacy information and add noise to the indexed value, and the database server is used to generate and transmit data.

[0052] In the actual implementation process, the embodiment of the present invention can be divided into two stages: offline data processing stage and online data query stage. In the offline data processing stage, k integer data need to be stored in the database server in advance and sent to the data processing server. Each time a set of data b is sent to the data processing server, i , each group has m data, here That is, the database server needs to send n sets of data, and m=n. The data processing server, as a trusted server, will record the maximum and minimum values ​​of all received data and calculate the absolute value of their difference. This value is used as the parameter Δf to subsequently generate the target Laplace noise. At the same time, the data processing server maps the data in each received group b to the local computer and stores them in different groups d. Each group d can store m' pieces of data, and a total of n' sets of data need to be stored. Similarly,

[0053] The specific mapping method is as follows: i The data processing server uses the group number i, the group number j, and a special tag value p to obtain the group offset t according to the method in formula (1). AES-128 is used in this solution, & is a bitwise AND operation, b i [t] is the offset within each group of data to determine the value to be operated in the corresponding group, and compare it with the value already stored in d j The values ​​are bitwise XORed to generate an XOR result in the corresponding local group. After an XOR result is generated in the local group corresponding to each group of data, the local storage of the value to be operated is completed.

[0054] t=Enc(i,j,p)&m (1)

[0055] Among them, Enc is the encryption method selected according to actual needs.

[0056] According to this process, the data processing server processes different groups b in turn and stores them in different local groups d. That is to say, the data processing server will eventually get n′ different d i And save, each d i A value V is stored in the table, which contains the XOR result of m' values. In addition, for security reasons, the data processing server will also generate a backup based on other different tag values ​​to replace the used V in the future. i The offline data processing phase is the preparation phase before the query phase, and only one subsequent operation is required to conduct multiple queries.

[0057] Furthermore, when the user needs to retrieve information, the online data query phase begins. In order to retrieve the target data, the user needs to enter at least one key information. For example, if the user wants to retrieve the total asset value of male high-net-worth users in Bank A, after entering the command sum to calculate the total asset value, the command will be transmitted to the data retrieval server to generate the indexes i1, i2, ...i of the assets of male high-net-worth users in the bank database. l , and index i1,i2,...i l Sent to the data processing server.

[0058] In step S102 , the local group corresponding to each index is searched in the data processing server.

[0059] In step S103 , the XOR results in the group corresponding to each index are traversed, and the target value corresponding to each index is determined according to the XOR results.

[0060] In some embodiments, traversing the XOR results in the group corresponding to each index and determining the target value corresponding to each index according to the XOR results includes:

[0061] Traverse the XOR results in the group corresponding to each index;

[0062] Calculate the corresponding intra-group offset of each index based on its group number and local group number.

[0063] According to the offset value within the group, it solves the index of other values ​​stored in the local group sequence number;

[0064] Use the index of other numerical values ​​to find the actual value in the target database, and perform XOR operation on the actual value and the XOR result in its corresponding group to obtain the target value corresponding to each index.

[0065] In the actual implementation process, Figure 2 As shown, in the online data query phase, the data processing server receives indexes i1, i2, ...i l Then, search for each index i in the data processing server x The group number h stored locally i , traverse each index i x The XOR result in the corresponding group is used, and the mapping method in the current stage (i.e., formula (1)) is used to calculate the group number corresponding to each index and the local group number h i Solve the corresponding intra-group offset, and according to the intra-group offset value, solve the index v of other values ​​stored in the local group sequence number 1 ,v 2 ,..v m-1 , using the index v of other values 1 ,v 2,..v m-1 Find the actual value in the target database and perform XOR operation on the actual value and the XOR result in its corresponding group to obtain the target value v corresponding to each index i .

[0066] In step S104 , the target value corresponding to each index is summed to obtain a summation result, and target Laplace noise is added to the summation result to generate a final query result.

[0067] In the actual implementation process, Figure 2 As shown, according to formula (2), the target Laplace noise Δf is added to the XOR result of each group to generate the final query result O and return it to the user.

[0068]

[0069] Where Z is the noise generated according to the target Laplace noise Δf. The specific explanation is as follows: the generation process of the Lap function in formula (4).

[0070] The Laplace used in this scheme can be described as:

[0071]

[0072] Here, μ is the location parameter, which describes the expected value of the noise distribution and is usually set to 0. b>0 is the scale parameter, which is used to represent the distribution of the noise.

[0073] The specific noise generating function obtained by inverting formula (3) is as shown in formula (4), where x∈[0,1] is a randomly generated value. In the embodiment of the present invention, the target Laplace noise Δf is the absolute value of the difference between the maximum value and the minimum value stored in the above-mentioned data processing server.

[0074]

[0075] Furthermore, the embodiments of the present invention conduct a feasibility analysis of adding noise to numerical private information retrieval. Specifically, there are different schemes in private information retrieval technology, involving homomorphic encryption methods that operate on ciphertext and strategic methods that operate on plaintext. In homomorphic encryption-based methods, the noisy plaintext is added to the encrypted index result, and the ciphertext of the corresponding value sum is still obtained. Similarly, for private information retrieval technology that operates on plaintext, adding noise means adding noise to the plaintext result. In other words, no matter which private information retrieval scheme is used, the required value can be returned by directly adding the obtained index value to the noise.

[0076] In addition, since there are still a few cases in reality where it is still necessary to query categorized data, in this case, the retrieved information cannot be protected by adding noise. For example, to set a date for a conference, the schedules of the participants are collected. The time of the conference should conflict with the participants' time as little as possible. In order to protect the information of the participants, a date that is suitable for most of the participants must be obtained. Therefore, the obtained results cannot be simply added with noise. For example, adding noise to Friday and changing it to Saturday will result in completely different results. For this reason, the embodiment of the present invention proposes the use of an exponential mechanism. Specifically, the database service provider needs to specify a scoring function (Scoring Function), which outputs the score of each reply in the set of alternative replies. The exponential mechanism achieves differential privacy protection by returning the result with a certain probability value, where the probability is determined by the score. Under this mechanism, the entire scheme also needs to be simply adjusted.

[0077] Simply put, during the offline phase, the solution remains largely the same as for numerical data described above. However, during the online query phase, the data processing server provides additional services, acting as a trusted third party. When performing an online data search, the database returns the retrieved information to the data processing server. After obtaining a specific set of values, the data processing server compiles statistics on this data, uses a scoring function to generate a score for each query result, and then regenerates a set of query results that reflect the result distribution and returns them to the user, effectively protecting the data in the database.

[0078] In summary, the privacy information retrieval method based on differential privacy proposed in an embodiment of the present invention combines privacy information retrieval technology with differential privacy technology, utilizes the characteristics of privacy information retrieval technology to protect the user's query intention, and utilizes differential privacy technology to process the query data results, so that the contribution of individual data in the data to the overall data results is blurred without losing its original meaning. This just makes up for the shortcomings of privacy information retrieval technology, aiming to achieve the query information provided by the user cannot be obtained on the database server, while avoiding the user's accurate inference of specific information, thereby ensuring two-way information protection of user privacy and information retrieval.

[0079] Next, a privacy information retrieval device based on differential privacy according to an embodiment of the present invention will be described with reference to the accompanying drawings.

[0080] Figure 3 4 is a block diagram of a privacy information retrieval device based on differential privacy according to an embodiment of the present invention.

[0081] like Figure 3 As shown, the privacy information retrieval device 30 based on differential privacy includes: a generation module 301 , a search module 302 , a traversal module 303 and an adding module 304 .

[0082] The generation module is configured to obtain at least one key piece of information from a user and generate multiple indexes on the data retrieval server based on the at least one key piece of information. The search module is configured to search the data processing server for the local group corresponding to each index. The traversal module is configured to traverse the XOR results in the group corresponding to each index and determine the target value corresponding to each index based on the XOR results. The addition module is configured to sum the target values ​​corresponding to each index to obtain a summed result and add the target Laplace noise to the summed result to generate the final query result.

[0083] In some embodiments, further comprising:

[0084] A storage module, used for storing multiple integer data in a database server;

[0085] The mapping module is used to map multiple integer data to different groups of the data processing server and perform bitwise XOR operation with the locally stored data to complete the local storage of multiple integer data.

[0086] In some embodiments, the processing module includes:

[0087] The sending unit is used to divide the plurality of integer data into n groups of data, and send one group of data to the data processing server each time, wherein each group of data contains m data, and m and n are both positive integers and are equal to each other;

[0088] An encryption unit is used to pre-encrypt the group sequence number and local group sequence number of each data set received by the data processing server to obtain the intra-group offset of each data set, and determine the value to be operated in the corresponding group according to the intra-group offset of each data set;

[0089] The XOR operation unit is used to perform an XOR operation on the value to be operated and the data stored in its corresponding local group in a bit-by-bit XOR manner to generate an XOR result in the corresponding local group. After an XOR result is generated in the local group corresponding to each group of data, the local storage of the value to be operated is completed.

[0090] In some embodiments, the traversal module includes:

[0091] The traversal unit is used to traverse the XOR results in the group corresponding to each index;

[0092] A solving unit, used for solving the corresponding intra-group offset of each index according to the group sequence number and the local group sequence number corresponding to each index;

[0093] The search unit is used to use the intra-group offset to search for the actual value in the target database, and perform an XOR operation on the actual value and the XOR result in its corresponding group to obtain the target value corresponding to each index.

[0094] It should be noted that the aforementioned explanation of the embodiment of the privacy information retrieval method based on differential privacy is also applicable to the privacy information retrieval device based on differential privacy in this embodiment, and will not be repeated here.

[0095] The privacy information retrieval device based on differential privacy proposed in an embodiment of the present invention combines privacy information retrieval technology with differential privacy technology, utilizes the characteristics of privacy information retrieval technology to protect the user's query intention, and utilizes differential privacy technology to process the query data results, so that the contribution of individual data in the data to the overall data results is blurred without losing its original meaning. This just makes up for the shortcomings of privacy information retrieval technology, and aims to achieve that the query information provided by the user cannot be obtained on the database server side, while avoiding the user's accurate inference of specific information, thereby ensuring two-way information protection of user privacy and information retrieval.

[0096] Figure 4 This is a schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. The electronic device may include:

[0097] Memory 401 , processor 402 , and computer programs stored in the memory 401 and executable on the processor 402 .

[0098] When the processor 402 executes the program, the privacy information retrieval method based on differential privacy provided in the above embodiment is implemented.

[0099] Furthermore, the electronic device further includes:

[0100] The communication interface 403 is used for communication between the memory 401 and the processor 402 .

[0101] The memory 401 is used to store computer programs that can be run on the processor 402 .

[0102] The memory 401 may include a high-speed RAM memory, and may also include a non-volatile memory (non-volatile memory), such as at least one disk memory.

[0103] If the memory 401, the processor 402, and the communication interface 403 are implemented independently, the communication interface 403, the memory 401, and the processor 402 can be connected to each other via a bus and communicate with each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 4 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.

[0104] Optionally, in a specific implementation, if the memory 401 , the processor 402 and the communication interface 403 are integrated on a chip, the memory 401 , the processor 402 and the communication interface 403 can communicate with each other through an internal interface.

[0105] The processor 402 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present invention.

[0106] An embodiment of the present invention further provides a computer-readable storage medium having a computer program stored thereon. When the program is executed by a processor, the differential privacy-based privacy information retrieval method described above is implemented.

[0107] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or N embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine different embodiments or examples described in this specification and the features of different embodiments or examples without contradiction.

[0108] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of technical features indicated. Thus, a feature specified as "first" or "second" may explicitly or implicitly include at least one such feature. In the description of the present invention, "N" means at least two, such as two, three, etc., unless otherwise specifically defined.

[0109] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, segment or portion of code comprising one or N executable instructions for implementing a custom logical function or step of a process, and the scope of the preferred embodiments of the present invention includes alternative implementations in which functions may be performed out of the order shown or discussed, including performing functions in a substantially simultaneous manner or in the reverse order depending on the functions involved, which should be understood by those skilled in the art to which the embodiments of the present invention pertain.

[0110] The logic and / or steps represented in the flowcharts or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing the logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can fetch and execute instructions from an instruction execution system, apparatus, or device). For purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection with one or N wires (electronic devices), a portable computer disk cartridge (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and programmable read-only memory (EPROM or flash memory), fiber optic devices, and a portable compact disc read-only memory (CDROM). In addition, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program can be obtained electronically by optically scanning the paper or other medium and then editing, interpreting or processing it in other suitable ways as necessary, and then storing it in a computer memory.

[0111] It should be understood that various parts of the present invention can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiment, the N steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. If implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used: a discrete logic circuit having logic gate circuits for implementing logic functions on data signals, an application-specific integrated circuit having suitable combinational logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0112] Those skilled in the art will understand that all or part of the steps in the method of the above embodiment can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiment.

[0113] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing module, or each unit may exist physically separately, or two or more units may be integrated into a single module. The aforementioned integrated modules may be implemented in the form of hardware or in the form of software functional modules. If the integrated modules are implemented in the form of software functional modules and sold or used as independent products, they may also be stored in a computer-readable storage medium.

[0114] The storage medium mentioned above may be a read-only memory, a magnetic disk, or an optical disk, etc. Although the embodiments of the present invention have been shown and described above, it is understood that the above embodiments are exemplary and are not to be construed as limiting the present invention. Persons skilled in the art may make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present invention.

Claims

1. A privacy information retrieval method based on differential privacy, characterized in that: The following steps are involved: Acquire at least one key information of the user, and generate multiple indexes on the data retrieval server according to the at least one key information; Find the local group corresponding to each index in the data processing server; Traversing the XOR results in the group corresponding to each index, and determining the target value corresponding to each index according to the XOR results; The target values ​​corresponding to each index are summed to obtain a summation result, and target Laplace noise is added to the summation result to generate a final query result.

2. The privacy information retrieval method based on differential privacy according to claim 1, characterized in that: Before obtaining at least one key information of the user, it also includes: Storing multiple integer data in the database server; The plurality of integer data are mapped to different groups of the data processing server, and a bitwise exclusive OR operation is performed with the locally stored data to complete the local storage of the plurality of integer data.

3. The privacy information retrieval method based on differential privacy according to claim 2, characterized in that: Mapping the plurality of integer data to different groups of the data processing server and performing a bitwise exclusive OR operation with the locally stored data to complete local storage of the plurality of integer data, including: Divide the plurality of integer data into n groups of data, and send one group of data to the data processing server each time, wherein each group of data contains m pieces of data, m and n are both positive integers, and m and n are equal; Performing preset encryption on the group sequence number and the local group sequence number of each group of data received by the data processing server to obtain the intra-group offset of each group of data, and determining the value to be operated in the corresponding group according to the intra-group offset of each group of data; The value to be operated is XORed with the data stored in its corresponding local group using a bitwise XOR method to generate an XOR result in the corresponding local group. After an XOR result is generated in the local group corresponding to each group of data, the local storage of the value to be operated is completed.

4. The privacy information retrieval method based on differential privacy according to claim 1, characterized in that: Traversing the XOR results in the group corresponding to each index, and determining the target value corresponding to each index according to the XOR results, including: Traverse the XOR results in the group corresponding to each index; Calculate the corresponding intra-group offset of each index according to the group sequence number and the local group sequence number corresponding to each index; According to the intra-group offset value, it solves the index of other values ​​stored in the local group sequence number; The actual value is searched in the target database using the index of the other numerical value, and an XOR operation is performed on the actual value and the XOR result in the corresponding group to obtain the target value corresponding to each index.

5. A privacy information retrieval device based on differential privacy, characterized in that: include: A generating module, configured to obtain at least one key information of a user and generate a plurality of indexes on a data retrieval server according to the at least one key information; A search module, used to search the local group corresponding to each index in the data processing server; A traversal module, configured to traverse the XOR results in the group corresponding to each index, and determine the target value corresponding to each index according to the XOR results; An adding module is used to sum the target values ​​corresponding to each index to obtain a summation result, and add target Laplace noise to the summation result to generate a final query result.

6. The privacy information retrieval device based on differential privacy according to claim 5, characterized in that: Also includes: A storage module, used for storing multiple integer data in a database server; A mapping module is used to map the plurality of integer data to different groups of the data processing server and perform a bitwise exclusive OR operation with the locally stored data to complete the local storage of the plurality of integer data.

7. The privacy information retrieval device based on differential privacy according to claim 6, characterized in that: The processing module includes: a sending unit, configured to divide the plurality of integer data into n groups of data, and send one group of data to the data processing server each time, wherein each group of data contains m pieces of data, m and n are both positive integers, and m and n are equal; an encryption unit, configured to perform preset encryption on the group sequence number and the local group sequence number of each data set received by the data processing server to obtain an intra-group offset of each data set, and determine a value to be operated in the corresponding group according to the intra-group offset of each data set; The XOR operation unit is used to perform an XOR operation on the value to be operated and the data stored in its corresponding local group in a bit-by-bit XOR manner to generate an XOR result in the corresponding local group. After an XOR result is generated in the local group corresponding to each group of data, the local storage of the value to be operated is completed.

8. The privacy information retrieval device based on differential privacy according to claim 7, characterized in that: The traversal module includes: A traversal unit, used for traversing the XOR results in the group corresponding to each index; A solving unit, configured to solve the corresponding intra-group offset of each index according to the group sequence number and the local group sequence number corresponding to each index; The search unit is used to use the intra-group offset to search for an actual value in the target database, and perform an XOR operation on the actual value and the XOR result in its corresponding group to obtain the target value corresponding to each index.

9. An electronic device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the privacy information retrieval method based on differential privacy according to any one of claims 1 to 4.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: The program is executed by a processor to implement the privacy information retrieval method based on differential privacy as described in any one of claims 1 to 4.