A privacy data protection method and device

By storing private data and ordinary data separately and generating identification and desensitized data, the problems of low query efficiency and poor privacy data security in the existing technology are solved, and efficient and secure privacy data management is achieved.

CN113901508BActive Publication Date: 2025-09-09BEIJING CO WHEELS TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202010639048.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-07-06
Publication Date
2025-09-09
Estimated Expiration
2040-07-06

AI Technical Summary

Technical Problem

In the existing technology, private data and ordinary data are encrypted, stored and queried as a whole, resulting in low query efficiency and poor security of private data, which is easy to leak.

Method used

Private data and general data are stored in different storage locations, and identification and desensitized data are generated. Desensitized data is provided through identification and association relationships to replace private data for query. Private data is only provided after the data requester obtains the desensitized data.

Benefits of technology

It improves the security and query efficiency of private data, reduces the decryption operations of data requesters, and ensures the security and query efficiency of private data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113901508B_ABST
    Figure CN113901508B_ABST
Patent Text Reader

Abstract

The embodiments of the present disclosure disclose a privacy data protection method and device, which relate to the field of computer technology. The main technical solutions of the embodiments of the present disclosure include: determining the private data and ordinary data included in the target data to be stored; storing the private data and ordinary data in different storage locations respectively; generating an identifier and desensitized data corresponding to the private data, where the identifier is the basis that the private data and ordinary data belong to the same target data, and the desensitized data is the data obtained by desensitizing the private data; generating associations between the identifier and the desensitized data, ordinary data and private data respectively, where the associations are the basis for providing the desensitized data, ordinary data and identifier to the data requester, and the associations are also the basis for providing the private data to the data requester when the data requester requests the private data based on the identifier it obtains.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present disclosure relate to the field of computer technology, and in particular to a method and apparatus for protecting privacy data. Background Art

[0002] In the current era of big data, data has become the most important resource. People use the internet to transmit data and perform various online operations based on data. However, a large amount of data currently contains private information. Once leaked, this private information poses a threat to users' security and privacy. To ensure the security of private data, databases currently store data and typically encrypt the target data containing private information.

[0003] Currently, because private data and other data in the target data are encrypted as a whole, when users need to retrieve data from the database and query the private data, they must perform complex decryption operations on the target data to retrieve the private data. This requires complex decryption operations to retrieve the private data, resulting in low data query efficiency. Furthermore, because the database stores the target data as a whole, when users extract the target data from the database, the private data will also be extracted. If the target data is maliciously intercepted, the private data will be leaked, posing a security risk to the user and compromising the security of the private data. Summary of the Invention

[0004] In view of this, the embodiments of the present disclosure propose a method and apparatus for protecting private data, the main purpose of which is to uniformly manage private data, thereby improving data query efficiency and the security of private data. The main technical solutions include:

[0005] In a first aspect, an embodiment of the present disclosure provides a method for protecting privacy data, the method comprising:

[0006] Determining the private data and general data included in the target data to be stored;

[0007] Generate an identifier and desensitized data corresponding to the private data, wherein the identifier is the basis for the private data and the general data to belong to the same target data, and the desensitized data is data obtained by desensitizing the private data;

[0008] Generate associations between the identifier and the desensitized data, the normal data, and the private data, respectively, wherein the associations serve as a basis for providing the desensitized data, the normal data, and the identifier to the data requester. Furthermore, the associations serve as a basis for providing the private data to the data requester when the data requester requests the private data based on the identifier it obtained.

[0009] The private data and the common data are stored in different storage locations respectively.

[0010] In a second aspect, an embodiment of the present disclosure provides a method for protecting privacy data, the method comprising:

[0011] Based on the association relationships between the identifier and the desensitized data, the ordinary data, and the private data, the ordinary data, the identifier, and the desensitized data are provided to the data requester, wherein the desensitized data is data obtained by desensitizing the private data in the target data, and the identifier is evidence that the private data and the ordinary data belong to the same target data;

[0012] When receiving the private data acquisition request carrying the identifier sent by the data requester, the private data associated with the identifier is provided to the data requester according to the association relationship.

[0013] In a third aspect, an embodiment of the present disclosure provides a method for protecting privacy data, the method comprising:

[0014] Receive normal data, an identifier, and desensitized data provided by a data provider, wherein the normal data is included in the target data, the desensitized data is data obtained by desensitizing the private data included in the target data, and the identifier is evidence that the private data and the normal data belong to the same target data;

[0015] Displaying the normal data and the desensitized data;

[0016] If the user needs to obtain the private data, a private data acquisition request carrying the identifier is sent to the data provider;

[0017] When receiving the private data associated with the identifier provided by the data provider, the private data is displayed.

[0018] The normal data, identifier, and masked data are determined based on the associations between the identifier and the masked data, private data, and normal data, respectively. These associations serve as the basis for providing the masked data, normal data, and identifier to the data requester. Furthermore, these associations serve as the basis for providing the private data to the data requester when the data requester requests the private data based on the identifier it obtained.

[0019] In a fourth aspect, an embodiment of the present disclosure provides a privacy data protection method, which includes: the privacy data protection method described in the first aspect and the privacy data protection method described in the second aspect.

[0020] In a fifth aspect, an embodiment of the present disclosure provides a privacy data protection device, the device comprising:

[0021] a determining unit, configured to determine the private data and the common data included in the target data to be stored;

[0022] a first generating unit, configured to generate an identifier and desensitized data corresponding to the private data, wherein the identifier is a basis for determining that the private data and the general data belong to the same target data, and the desensitized data is data obtained by desensitizing the private data;

[0023] a second generating unit, configured to generate associations between the identifier and the desensitized data, the normal data, and the private data, respectively, wherein the associations serve as a basis for providing the desensitized data, the normal data, and the identifier to the data requester, and also as a basis for providing the private data to the data requester when the data requester requests the private data based on the identifier it obtains;

[0024] The storage unit is used to store the private data and the common data in different storage locations respectively.

[0025] In a sixth aspect, an embodiment of the present disclosure provides a privacy data protection device, the device comprising:

[0026] a first providing unit, configured to provide the ordinary data, the identifier, and the desensitized data to a data requester based on associations between the identifier and the desensitized data, the ordinary data, and the private data, respectively, wherein the desensitized data is data obtained by desensitizing the private data in the target data, and the identifier is evidence that the private data and the ordinary data belong to the same target data;

[0027] The second providing unit is configured to provide the private data associated with the identifier to the data requester according to the association relationship when receiving the private data acquisition request carrying the identifier sent by the data requester.

[0028] In a seventh aspect, an embodiment of the present disclosure provides a privacy data protection device, the device comprising:

[0029] a receiving unit, configured to receive ordinary data, an identifier, and desensitized data provided by a data provider, wherein the ordinary data is included in the target data, the desensitized data is data obtained by desensitizing the private data included in the target data, and the identifier is evidence that the private data and the ordinary data belong to the same target data;

[0030] A first display unit, configured to display the normal data and the desensitized data;

[0031] a sending unit, configured to send a private data acquisition request carrying the identifier to the data provider when a user has a need to acquire the private data;

[0032] The second display unit is configured to display the private data when receiving the private data associated with the identifier provided by the data provider.

[0033] In an eighth aspect, an embodiment of the present disclosure provides a storage medium, which includes a stored program, wherein when the program is running, the device where the storage medium is located is controlled to execute the privacy data protection method described in the first aspect, or the privacy data protection method described in the second aspect, or the privacy data protection method described in the third aspect.

[0034] In the ninth aspect, an embodiment of the present disclosure provides a human-computer interaction device, which includes a storage medium and one or more processors, wherein the storage medium is coupled to the processor, and the processor is configured to execute program instructions stored in the storage medium; when the program instructions are run, the privacy data protection method described in the first aspect is executed, or the privacy data protection method described in the second aspect is executed, or the privacy data protection method described in the third aspect is executed.

[0035] By means of the above technical solution, the privacy data protection method and device provided by the embodiments of the present disclosure, in order to uniformly manage privacy data, independently store the privacy data and ordinary data in the target data in different storage locations. When the target data is provided to the data requester, the privacy data is not provided directly to the data requester, but only the desensitized data corresponding to the privacy data is provided to the data requester for the user to query the privacy data. Only when the data requester has a need to obtain privacy data after obtaining the desensitized data, will the privacy data be provided to the data requester based on the identification of the privacy data. Since the desensitized data is used instead of the privacy data to be provided to the data requester, the desensitized data can be conveniently obtained without complex decryption operations. Therefore, the embodiments of the present disclosure can not only improve the security of privacy data but also reduce the decryption operations of the data requester.

[0036] The above description is only an overview of the technical solutions of the embodiments of the present disclosure. In order to more clearly understand the technical means of the embodiments of the present disclosure, they can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the embodiments of the present disclosure more obvious and easy to understand, the specific implementation methods of the embodiments of the present disclosure are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Various other advantages and benefits will become apparent to those skilled in the art upon reading the detailed description of the preferred embodiment below. The accompanying drawings are for illustration purposes only and are not to be considered as limiting the embodiments of the present disclosure. The same reference symbols are used throughout the accompanying drawings to represent the same components. In the accompanying drawings:

[0038] Figure 1 A flowchart of a privacy data protection method provided by an embodiment of the present disclosure is shown;

[0039] Figure 2 A flowchart of another privacy data protection method provided by an embodiment of the present disclosure is shown;

[0040] Figure 3 A flowchart of another privacy data protection method provided by an embodiment of the present disclosure is shown;

[0041] Figure 4 A flowchart of another privacy data protection method provided by an embodiment of the present disclosure is shown;

[0042] Figure 5 A flowchart of another privacy data protection method provided by an embodiment of the present disclosure is shown;

[0043] Figure 6 A flowchart of another privacy data protection method provided by an embodiment of the present disclosure is shown;

[0044] Figure 7 A block diagram showing a composition of a privacy data protection device provided by an embodiment of the present disclosure is shown;

[0045] Figure 8 A block diagram showing another privacy data protection device provided by an embodiment of the present disclosure is shown;

[0046] Figure 9 A block diagram showing a composition of another privacy data protection device provided by an embodiment of the present disclosure is shown;

[0047] Figure 10 A block diagram showing a composition of another privacy data protection device provided by an embodiment of the present disclosure is shown;

[0048] Figure 11 A block diagram of another privacy data protection device provided by an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0049] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art.

[0050] In a first aspect, an embodiment of the present disclosure provides a privacy data protection method, which can be applied to a data provider, which can be composed of one server or multiple servers. The method is a privacy data protection method when the data provider stores target data to be stored. Figure 1 As shown, the method mainly includes:

[0051] 101. Determine private data and general data included in target data to be stored.

[0052] In practical applications, target data refers to data to be stored with the data provider, including private data and general data. Private data refers to data designed to be highly secure and intended for disclosure. Private data can include data that can be used to identify or locate personal information. Examples of private data include identification card numbers, phone numbers, addresses, credit card numbers, authentication information, personal health status, and financial information. General data refers to data designed to be less secure than private data. General data can be any data other than private data, and its specific content is determined entirely based on the user's specific needs.

[0053] In order to facilitate unified management of private data and improve the security of private data, it is necessary to clearly determine the private data and general data included in the target data so that the private data and general data can be stored separately.

[0054] Exemplarily, the target data is the data shown in Table 1. After determining the private data and the common data in the target data, the private data shown in Table 2 and the common data shown in Table 3 are formed.

[0055] Table-1

[0056]

[0057] Table-2

[0058] telephone number Mail 1234567890 123456@youxiang.com

[0059] Table-3

[0060] Transaction Date Transaction data 2020-06-01 Sold 100 units of item A for a total of 1,000 yuan

[0061] 102. Generate identification and desensitized data corresponding to the privacy data.

[0062] In this embodiment, the identifier serves two purposes: First, it is used to distinguish private data and is unique. Second, it serves as the basis for determining whether private data and general data belong to the same target data. The identifier is used to determine which private data and which general data belong to the same target data.

[0063] The following describes methods for generating corresponding identifiers for private data. These methods include at least the following:

[0064] The first method is to generate a random number through a random number generation function and use the random number as an identifier.

[0065] A random number generator function is embedded in the data provider. Once target data needs to be stored at the data provider, the random number generator function will generate a random number as an identifier for the private data in the target data. The random number generator function can generate a unique random number each time.

[0066] It should be noted that the random number generator generates random numbers based on a seed value. The randomness of the random numbers generated by the random number generator decreases as the number of random numbers generated increases, increasing the probability of the random number generator generating the same random number. Therefore, to further ensure the uniqueness of the identifier, the seed value of the random number generator can be regularly replaced. When the randomness of the random numbers generated by the random number generator decreases, the randomness is restored based on the replaced seed value, reducing the probability of random number duplication.

[0067] The second method is to perform information digest algorithm MD5 calculation on the private data, generate an MD5 value, and use the MD5 value as an identifier.

[0068] Different target data generally has different privacy data, so the MD5 value obtained by performing MD5 calculation on the privacy data is also unique, and the MD5 value can be used as an identifier.

[0069] Furthermore, if, in actual applications, multiple target data have the same private data, then to ensure the uniqueness of the private data identifier, a combination of the private data's MD5 value and information reflecting the uniqueness of the target data is used as the identifier. Optionally, the uniqueness information of the target data can be the identifier of the target data.

[0070] The third method is to perform hash operation on the private data, generate a hash value, and use the hash value as an identifier.

[0071] Different target data generally have different private data, so the hash value obtained by hashing the private data is also unique, and the hash value can be used as an identifier.

[0072] Furthermore, if, in actual applications, multiple target data have the same private data, then to ensure the uniqueness of the private data identifier, a combination of the private data's hash value and information reflecting the uniqueness of the target data is used as the identifier. Optionally, the uniqueness information of the target data can be the target data identifier.

[0073] In this embodiment, desensitization technology balances data security and data usability. Desensitized data obtained through desensitization technology can provide users with partially searchable information for data verification while ensuring data security. Therefore, when a data requester obtains target data, in order to improve the security of private data and reduce the data requester's decryption operations, it is necessary to desensitize the private data and generate desensitized data corresponding to the private data. When the target data is provided to the data requester, instead of directly providing the private data, only the desensitized data corresponding to the private data is provided to the data requester. This allows users to query and confirm private data by viewing the desensitized data.

[0074] When generating desensitized data corresponding to private data, the private data is actually deformed using preset desensitizing rules, which are for specific fields. For example, the desensitizing rules may include but are not limited to the following: first, only retain characters in specific positions, and delete characters in other positions. For example, the phone number is "1234567890", and its corresponding desensitized data only retains the last four digits, and the desensitized data is "7890"; second, retain all characters of the private data, and only replace characters in specific positions with specific symbols. For example, the phone number is "1234567890", and the fourth to ninth characters are replaced with the specific symbol "*", and the sensitive data is "123******0". Third, perform field inversion on the privacy data, and then combine it with the first or second rule mentioned above. For example, in combination with the second rule, the phone number is "1234567890", which is "0987654321" after inversion. Then, the fourth to ninth characters after inversion are replaced with a specific symbol "*", and the sensitive data is "098******1".

[0075] 103. Generate association relationships between the identifier and the desensitized data, the ordinary data, and the private data.

[0076] The association relationship is the basis for providing masked data, normal data, and identifiers to the data requester. It also serves as the basis for providing private data to the data requester when the data requester requests private data based on the identifier they obtained.

[0077] The purpose of generating an association between identifiers and desensitized data, private data, and ordinary data is as follows: First, whether the data requester requests the target data or provides the target data to the data requester on a regular basis, only the desensitized data, ordinary data, and identifiers are provided to the data requester, without exposing the private data directly to the data requester. Desensitized data reveals part of the private data, and users can perform operations related to the private data based on the desensitized data. The existence of desensitized data not only reduces decryption operations to a certain extent, but also provides users with queryable information in the private data while ensuring the security of the private data, allowing users to confirm the data. Second, the identifier can clarify which private data and the ordinary data belong to the same target data. After the data requester receives the identifier, ordinary data, and desensitized data, if they need to obtain further private data, they can request the private data based on the identifier they obtained.

[0078] The methods for generating association relationships between identifiers and desensitized data, ordinary data and privacy data respectively include at least the following: first, the identifier is directly associated with desensitized data, ordinary data and privacy data respectively; second, the identifier is directly associated with target data. Since the target data is associated with ordinary data, privacy data and desensitized data respectively, the association relationships between the identifier and ordinary data, privacy data and desensitized data respectively can be indirectly obtained through the association between the identifier and the target data; third, the identifier is directly associated with privacy data and ordinary data respectively, and there is an association relationship between ordinary data and desensitized data. The association relationship between the identifier and desensitized data is an indirect association relationship through the association relationship between ordinary data and desensitized data.

[0079] 104. Store the private data and the general data in different storage locations respectively.

[0080] In order to facilitate unified management of private data and improve the security of private data, after determining the private data and general data included in the target data, the private data and general data need to be stored in different storage locations respectively.

[0081] For example, ordinary data is stored in a first storage location, which can be a separate database or a specific storage space in a database (e.g., a data table). Private data is stored in a second storage location. The second storage location is independent of the first storage location. The purpose of the second storage location being independent of the first storage location is to manage the private data in the target data separately and uniformly. When the data requester requests the target data, the private data is avoided from being directly provided to the data requester. Instead, the desensitized data of the private data is provided to the target data. This ensures the security of the private data while improving the efficiency of data query by providing the desensitized data to the data requester.

[0082] It should be noted that when private data and general data are stored in different storage locations, in order to clearly distinguish which private data and which general data belong to the same target data, when private data and general data are stored, they can be stored based on the association relationship obtained in step 103.

[0083] The privacy data protection method provided by the embodiments of the present disclosure stores the privacy data and ordinary data in the target data in different storage locations independently in order to uniformly manage privacy data. When the target data is provided to the data requester, the privacy data is not provided directly to the data requester, but only the desensitized data corresponding to the privacy data is provided to the data requester for the user to query the privacy data. Only when the data requester has a need to obtain privacy data after obtaining the desensitized data, will the privacy data be provided to the data requester based on the identification of the privacy data. Since the desensitized data is used instead of the privacy data to be provided to the data requester, the desensitized data can be conveniently obtained without complex decryption operations. Therefore, the embodiments of the present disclosure can not only improve the security of privacy data but also reduce the decryption operations of the data requester.

[0084] In the second aspect, according to the method described in the first aspect, another embodiment of the present disclosure further provides a privacy data protection method, such as Figure 2 As shown, the method mainly includes:

[0085] 201. Determine private data and general data included in target data to be stored.

[0086] 202. Generate an identifier and desensitized data corresponding to the private data.

[0087] The identifier is the basis for private data and general data to belong to the same target data. The desensitized data is the data obtained by desensitizing the private data.

[0088] 203. Generate association relationships between the identifier and the desensitized data, general data, and private data.

[0089] This association serves as the basis for providing the desensitized data, standard data, and identifier to the data requester when the data requester requests the target data or at a scheduled time. This association also serves as the basis for providing the private data to the data requester when the data requester requests private data based on the identifier it obtains.

[0090] 204. Store the normal data in the storage location corresponding to the normal data.

[0091] To ensure the security of ordinary data, before storing it in its corresponding storage location, it is necessary to first encrypt the ordinary data to obtain the corresponding ciphertext data, and then store the ciphertext data in the storage location corresponding to the ordinary data. The encryption method can be determined based on business needs and is not specifically limited in this embodiment. Optionally, the encryption method is a hashing method.

[0092] It should be noted that in order to distinguish which ordinary data and which private data belong to the same target data, ordinary data is stored based on association. For example, masked data associated with the same identifier as ordinary data can be stored in the same storage location as the ordinary data. Of course, if business needs require it, masked data associated with the same identifier as ordinary data can be stored in a different storage location from the ordinary data.

[0093] For example, as shown in Table 4 (which corresponds to Table 1), the normal data, identification and desensitized data are stored in the storage location corresponding to the normal data.

[0094] Table-4

[0095]

[0096] 205. Encrypt the private data to generate ciphertext data.

[0097] In order to ensure the security of private data, it is necessary to encrypt the private data so that the private data is not stored in plain text. Even if the storage location of the private data has problems such as database out of the database, the private data can still be protected.

[0098] The method for encrypting the private data is as follows: determining the encryption level of the private data, and using an encryption method corresponding to the encryption level to encrypt the private data.

[0099] Different private data has different security requirements. For example, the greater the loss to the user if private data is maliciously intercepted, the higher the security requirement. Different encryption methods require different computing power. More complex and secure encryption methods require greater computing power. Therefore, to reduce computing power consumption, private data with different security requirements can be encrypted using different encryption methods.

[0100] The encryption level of the private data may be determined based on the extent of the user's loss after the private data is maliciously intercepted, or the encryption level of the private data may be determined based on the identity of the sender of the target data.

[0101] 206. Store the ciphertext data in the storage location corresponding to the private data.

[0102] For example, as shown in Table 5 (Table 5 corresponds to Table 1), the ciphertext data and identifier stored in the storage location corresponding to the private data.

[0103] Table-5

[0104]

[0105] 207. Determine the privacy level of the private data.

[0106] In order to ensure the security of different private data, it is necessary to determine the privacy level of the private data so as to set corresponding permissions for the private data using the privacy level so that only users with permissions corresponding to the private data can access the private data.

[0107] The privacy level can be determined based on the privacy level of the private data, with the higher the privacy level, the higher the privacy level. For example, a mobile phone number with a low privacy level is assigned a privacy level of A, while an ID card with a high privacy level is assigned a privacy level of B, where the privacy level of B is higher than the privacy level of A.

[0108] 208. Based on the privacy level of the private data, determine which data requester has what authority to obtain the private data.

[0109] In order to improve the security of private data, permissions are assigned to private data according to its privacy level. Only the data requester with permissions corresponding to the permissions of the private data can obtain the private data.

[0110] For example, if the permission level for the private data "ID number" is B, only data requesters with B-level permissions can access this private data. If the permission level for the private data "mobile phone number" is A, then both data requesters with B-level permissions and A-level permissions can access this private data. The privacy level of B is higher than that of A.

[0111] In a third aspect, another embodiment of the present disclosure further provides a privacy data protection method, which can be applied to a data provider, which is composed of one or more servers. This method is a privacy data protection method when the data provider provides target data to the outside. Figure 3 As shown, the method mainly includes:

[0112] 301. Based on the association between the identifier and the desensitized data, the ordinary data and the privacy data respectively, the ordinary data, the identifier and the desensitized data are provided to the data requester.

[0113] Identification is the basis for identifying private data and general data as belonging to the same target data. Desensitized data is the result of desensitizing the private data within the target data. To facilitate unified management of private data and improve its security, the private data and general data within the target data need to be stored in separate locations.

[0114] The timings for providing normal data, identified data, and masked data to the data requester include at least the following two:

[0115] The first one is to provide the normal data, identification and desensitized data to the data requester upon receiving the acquisition request for the target data from the data requester.

[0116] The second method determines whether the current time point has reached a preset time point. If so, the normal data, identification, and desensitized data are provided to the data requester. This method is suitable for scenarios where target data is automatically reviewed.

[0117] The purpose of providing the normal data, identifier, and desensitized data to the data requester is as follows: First, it allows the data requester to perform queries related to the private data based on the corresponding desensitized data without having to obtain the private data. The presence of desensitized data not only reduces the number of decryption operations to a certain extent, but also provides users with queryable information within the private data, allowing them to confirm the data while ensuring data security. Second, the identifier is provided to the data requester along with the normal data and desensitized data. After receiving the desensitized data, if the data requester needs to obtain further private data, they can request the private data from the data provider based on the identifier they obtained.

[0118] It should be noted that in order to improve the security of data transmission, when ordinary data, identification and desensitized data are provided to the data requester, they can also be sent to the data requester in the form of ciphertext.

[0119] 302. When receiving a private data acquisition request carrying the identifier from a data requester, provide the private data associated with the identifier based on the association relationship to the data requester.

[0120] After the data requester receives the anonymized data, if the data requester further needs to obtain private data, the data provider will receive a private data acquisition request carrying an identifier sent by the data requester.

[0121] In order to improve the security of private data, after receiving a request to obtain private data and before providing the private data, it is necessary to determine whether the identifier is a legal identifier. If so, the private data associated with the identifier in the storage location corresponding to the private data will be provided to the data requester; otherwise, a prompt message of refusal to provide will be sent to the data requester.

[0122] The privacy data protection method provided by the embodiments of the present disclosure stores the privacy data and ordinary data in the target data in different storage locations independently in order to uniformly manage privacy data. When the target data is provided to the data requester, the privacy data is not provided directly to the data requester, but only the desensitized data corresponding to the privacy data is provided to the data requester for the user to query the privacy data. Only when the data requester has a need to obtain privacy data after obtaining the desensitized data, will the privacy data be provided to the data requester based on the identification of the privacy data. Since the desensitized data is used instead of the privacy data to be provided to the data requester, the desensitized data can be conveniently obtained without complex decryption operations. Therefore, the embodiments of the present disclosure can not only improve the security of privacy data but also reduce the decryption operations of the data requester.

[0123] In a fourth aspect, according to the method described in the third aspect, another embodiment of the present disclosure further provides a privacy data protection method, such as Figure 4 As shown, the method mainly includes:

[0124] 401. Determine whether the data requester has the authority to obtain private data; if so, proceed to 402; otherwise, proceed to 403.

[0125] In order to reduce the amount of data transmitted to the data requester, it is necessary to determine whether the data requester has the authority to obtain the private data. The identifier of the private data will be provided to the data requester only if the data requester has the authority to obtain the private data.

[0126] 402. Based on the association relationship between the identifier and the desensitized data, the ordinary data and the private data, the ordinary data, the identifier and the desensitized data are provided to the data requester, and step 404 is executed.

[0127] When it is determined that the data requester has the authority to obtain private data, it means that if the user needs private data, the private data can be provided to the data requester. Therefore, the ordinary data, identification and desensitized data are all provided to the data requester, so that after viewing the desensitized data, the data requester can further request private data based on the identification it received.

[0128] 403. Provide the normal data and the desensitized data to the data requester and end the current process.

[0129] When it is determined that the data requester does not have the authority to obtain private data, it means that even if the data requester requests the data, the private data cannot be provided to the data requester. In order to reduce the data transmission volume of the data provider, only ordinary data and desensitized data associated with the ordinary data will be provided to the data requester.

[0130] 404. Upon receiving the private data acquisition request carrying the identifier from the data requester, determine whether the data requester has the authority to obtain the private data; if so, execute 405; otherwise, execute 406.

[0131] A privacy data acquisition request is sent to a data provider after the data requester receives normal data and desensitized data and needs to obtain privacy data for corresponding query operations.

[0132] In order to ensure the security of private data, when receiving a request to obtain private data, it is necessary to determine whether the data requester has the authority to obtain the private data. Only when the data requester has the authority will the private data corresponding to the identifier be provided to the data requester.

[0133] It should be noted that step 404 is another permission determination after step 401. The two permission determinations can maximize the guarantee that only the data requester with the permission to obtain private data can obtain the private data corresponding to the identifier, thereby improving the security of private data.

[0134] 405. Provide the private data associated with the identifier to the data requester based on the association relationship, and end the current process.

[0135] If it is determined that the data requester has permission to access the private data, to further enhance the security of the private data, the private data corresponding to the identifier is extracted from the storage location corresponding to the private data, encrypted, and ciphertext data corresponding to the private data is generated. The ciphertext data is then provided to the data requester. The encryption method can be determined based on business requirements, and the encryption method for the private data can also be determined based on the encryption level of the private data. The selection of the encryption method is detailed in step 204 above.

[0136] 406. Send a prompt message to the data requester indicating that the private data acquisition failed.

[0137] When it is determined that the data requester does not have the authority to obtain the private data, it is necessary to send a prompt message indicating that the private data acquisition failed to the data requester, so that the data requester is aware of the fact that the private data acquisition failed.

[0138] In a fifth aspect, another embodiment of the present disclosure further provides a privacy data protection method, which can be applied to a data requester, which can be any client. This method is a privacy data protection method when the data requester obtains target data. Figure 5 As shown, the method mainly includes:

[0139] 501. Receive normal data, identification and desensitized data provided by the data provider.

[0140] The target data includes general data and private data. The general data is included in the target data. The desensitized data is the data obtained by desensitizing the private data included in the target data. The identifier is the basis for determining that the private data and general data belong to the same target data.

[0141] Because desensitized data balances data security and usability, it provides users with partially searchable information for data verification. Therefore, data requesters can perform queries using this desensitized data without having to directly retrieve the private data. Furthermore, even if this desensitized data is maliciously stolen or lost, since it is only partial data, it will not compromise the security of the private data.

[0142] The purpose of receiving the identifier provided by the data provider is that after the data provider queries the anonymized data, if it further needs to obtain private data, it can request the private data based on the identifier it obtained.

[0143] The occasions for receiving normal data, identified data, and desensitized data from data providers include at least the following two:

[0144] The first method is to receive normal data, identification and desensitized data provided by the data provider after sending a request for obtaining target data to the data provider.

[0145] The second method is to receive the normal data, identification data, and desensitized data provided by the data provider when the current time point reaches the preset time point. This method is suitable for scenarios where the target data is automatically reviewed.

[0146] 502. Display the normal data and the desensitized data.

[0147] After receiving the normal data and the desensitized data, the data requester will display the normal data and the desensitized data for the user to view.

[0148] Furthermore, in order to be able to send a private data acquisition request to the data provider in a timely and convenient manner when the user needs to request private data, the data requester binds the obtained identifier with the trigger component so that when the user needs to request private data, the trigger component can be directly triggered.

[0149] It should be noted that in order to ensure that the identifier bound to the trigger component corresponds to the currently displayed normal data and desensitized data, the identifier bound to the trigger component will be cleared in time after the normal data and desensitized data are displayed.

[0150] 503. If the user needs to obtain the private data, a private data acquisition request carrying an identifier is sent to the data provider.

[0151] In order to prevent the identifier from being maliciously stolen, the identifier needs to be encrypted when a private data acquisition request carrying the identifier is sent to the data provider.

[0152] 504. When receiving the private data associated with the identifier provided by the data provider, display the private data.

[0153] When the data provider determines that the data requester has permission to access private data, it will provide the private data associated with the identifier to the data requester. To enhance the security of the private data, the data provider encrypts the private data it sends. If the private data received is encrypted, it must first be decrypted and then displayed for user interaction.

[0154] Furthermore, if the data provider determines that the data requester does not have permission to obtain private data, it will send a prompt message to the data requester indicating that the private data acquisition failed. When the data requester receives the prompt message, it will display the prompt message to inform the data requester of the fact that the private data acquisition failed.

[0155] The privacy data protection method provided by the embodiment of the present disclosure stores the privacy data and ordinary data in the target data in different storage locations independently in order to uniformly manage privacy data. When the target data is provided to the data requester, the privacy data is not provided directly to the data requester, but only the desensitized data corresponding to the privacy data is provided to the data requester for the user to query the privacy data. Only when the data requester has a need to obtain privacy data after obtaining the desensitized data, the privacy data will be provided to the data requester based on the identification of the privacy data. Since the desensitized data is used instead of the privacy data to be provided to the data requester, the desensitized data can be conveniently obtained without complex decryption operations. Therefore, the embodiment of the present disclosure can not only improve the security of privacy data but also reduce the decryption operations of the data requester.

[0156] In a sixth aspect, another embodiment of the present disclosure further provides a privacy data protection method, which is applied to a system consisting of a data provider and a data requester, such as Figure 6 As shown, the method mainly includes:

[0157] 601. The data provider determines the private data and general data included in the target data to be stored.

[0158] 602. The data provider generates an identifier and desensitized data corresponding to the private data.

[0159] 603. The data provider generates an identifier and associates it with the desensitized data, general data, and private data.

[0160] 604. Store the normal data in a storage location corresponding to the normal data.

[0161] 605. The data provider encrypts the private data to generate ciphertext data.

[0162] 606. The data provider stores the ciphertext data in the storage location corresponding to the private data.

[0163] 607. The data provider determines the privacy level of the private data, and based on the privacy level of the private data, determines what permissions the data requester has to obtain the private data.

[0164] 608 , the data provider receives a request from the data requester to obtain the target data, or the data provider determines that the current time point reaches a preset time point, and then executes 609 .

[0165] 609. The data provider determines whether the data requester has the authority to obtain the private data; if so, execute 610; otherwise, execute 611.

[0166] 610. The data provider will provide the normal data, identification and desensitized data to the data requester based on the association relationship and execute step 612.

[0167] 611. The data provider provides the normal data and the desensitized data to the data requester, and executes 619.

[0168] 612. When the data requester receives the normal data, identification data and desensitized data from the data provider, it shall display the normal data and desensitized data.

[0169] 613. If the user has a need to obtain the private data, the data requester sends a private data acquisition request carrying an identifier to the data provider.

[0170] 614. When the data provider receives the private data acquisition request carrying the identifier, it determines whether the data requester has the authority to obtain the private data; if so, execute 615; otherwise, execute 616.

[0171] 615 . The data provider provides the private data associated with the identifier in the storage location corresponding to the private data to the data requester, and executes step 617 .

[0172] 616 . Send a prompt message indicating failure in obtaining private data to the data requester, and execute step 618 .

[0173] 617. When the data requester receives the private data associated with the identifier from the data provider, the data requester displays the private data.

[0174] 618. When the data requester receives the prompt message sent by the data provider indicating that the private data acquisition has failed, the data requester displays the prompt message.

[0175] 619. When the data requester receives the normal data and the desensitized data from the data provider, it shall display the normal data and the desensitized data.

[0176] Seventh, based on Figure 1 or Figure 2 Another embodiment of the present disclosure further provides a privacy data protection device, such as Figure 7 As shown, the device mainly includes:

[0177] a determining unit 71, configured to determine the private data and general data included in the target data to be stored;

[0178] A first generating unit 72 is configured to generate an identifier and desensitized data corresponding to the private data, wherein the identifier is a basis for confirming that the private data and the general data belong to the same target data, and the desensitized data is data obtained by desensitizing the private data;

[0179] A second generating unit 73 is configured to generate associations between the identifier and the desensitized data, the normal data, and the private data, respectively. The associations serve as a basis for providing the desensitized data, the normal data, and the identifier to the data requester. Furthermore, the associations serve as a basis for providing the private data to the data requester when the data requester requests the private data based on the identifier it obtained.

[0180] The storage unit 74 is configured to store the private data and the common data in different storage locations.

[0181] The privacy data protection device provided by the embodiment of the present disclosure stores the privacy data and ordinary data in the target data in different storage locations independently in order to uniformly manage privacy data. When the target data is provided to the data requester, the privacy data is not provided directly to the data requester, but only the desensitized data corresponding to the privacy data is provided to the data requester for the user to query the privacy data. Only when the data requester has a need to obtain privacy data after obtaining the desensitized data, the privacy data will be provided to the data requester based on the identification of the privacy data. In addition, since the desensitized data is used instead of the privacy data to be provided to the data requester, the desensitized data can be conveniently obtained without complex decryption operations. Therefore, the embodiment of the present disclosure can not only improve the security of privacy data but also reduce the decryption operations of the data requester.

[0182] In some embodiments, as Figure 8 As shown, the storage unit 74 includes:

[0183] The generating module 741 is configured to determine the encryption level of the private data and encrypt the private data using an encryption method corresponding to the encryption level.

[0184] In some embodiments, as Figure 8 As shown, the device also includes:

[0185] a determining unit 75, configured to determine a privacy level of the private data;

[0186] The allocating unit 76 is configured to determine, based on the privacy level of the private data, which permissions a data requester has to obtain the private data.

[0187] In some embodiments, as Figure 8 As shown, the generating unit 72 is used to generate a random number through a random number generating function, and use the random number as the identifier; or, perform information digest algorithm MD5 calculation on the private data to generate an MD5 value, and use the MD5 value as the identifier; or, perform hash operation on the private data to generate a hash value, and use the hash value as the identifier.

[0188] The privacy data protection device provided in the embodiment of the seventh aspect can be used to execute the privacy data protection method provided in the embodiment of the first aspect or the second aspect. The relevant meaning and specific implementation methods can be found in the relevant descriptions in the embodiments of the first aspect or the second aspect, and will not be described in detail here.

[0189] Eighth aspect, based on Figure 3 or Figure 4 Another embodiment of the present disclosure further provides a privacy data protection device, such as Figure 9As shown, the device mainly includes:

[0190] A first providing unit 81 is configured to provide the ordinary data, the identifier, and the desensitized data to a data requester based on associations between the identifier and the desensitized data, the ordinary data, and the private data, respectively. The desensitized data is obtained by desensitizing the private data in the target data, and the identifier is evidence that the private data and the ordinary data belong to the same target data.

[0191] The second providing unit 82 is configured to provide the private data associated with the identifier to the data requester according to the association relationship when receiving the private data acquisition request carrying the identifier sent by the data requester.

[0192] The privacy data protection device provided by the embodiment of the present disclosure stores the privacy data and ordinary data in the target data in different storage locations independently in order to uniformly manage privacy data. When the target data is provided to the data requester, the privacy data is not provided directly to the data requester, but only the desensitized data corresponding to the privacy data is provided to the data requester for the user to query the privacy data. Only when the data requester has a need to obtain privacy data after obtaining the desensitized data, the privacy data will be provided to the data requester based on the identification of the privacy data. Since the desensitized data is used instead of the privacy data to be provided to the data requester, the desensitized data can be conveniently obtained without complex decryption operations. Therefore, the embodiment of the present disclosure can not only improve the security of privacy data but also reduce the decryption operations of the data requester.

[0193] In some embodiments, as Figure 10 As shown, the device also includes:

[0194] The first judging unit 83 is used to judge whether the data requesting party has the authority to obtain the private data; if so, the first providing unit 81 is triggered; otherwise, the third providing unit 84 is triggered;

[0195] The first providing unit 81 is configured to provide the normal data, the identifier, and the desensitized data to the data requester when triggered by the first determining unit 83;

[0196] The third providing unit 84 is configured to provide the normal data and the desensitized data to the data requester under the triggering of the first judging unit 83 .

[0197] In some embodiments, as Figure 10 As shown, the device also includes:

[0198] The second determining unit 85 is configured to determine whether the data requesting party has the authority to obtain the private data. If so, the second providing unit 82 is triggered; otherwise, a prompt message indicating that the private data acquisition failed is sent to the data requesting party.

[0199] The second providing unit 82 is configured to provide the private data associated with the identifier to the data requester under the triggering of the second determining unit.

[0200] The privacy data protection device provided in the embodiment of the eighth aspect can be used to execute the privacy data protection method provided in the embodiment of the third aspect or the fourth aspect. The relevant meaning and specific implementation methods can be found in the relevant descriptions in the embodiments of the third aspect or the fourth aspect, and will not be described in detail here.

[0201] Ninth aspect, based on Figure 5 Another embodiment of the present disclosure further provides a privacy data protection device, such as Figure 11 As shown, the device mainly includes:

[0202] Receiving unit 91, configured to receive normal data, an identifier, and desensitized data provided by a data provider, wherein the normal data is included in the target data, the desensitized data is data obtained by desensitizing the private data included in the target data, and the identifier is evidence that the private data and the normal data belong to the same target data;

[0203] A first display unit 92 is used to display the normal data and the desensitized data;

[0204] The sending unit 93 is configured to send a private data acquisition request carrying the identifier to the data provider if the user has a need to acquire the private data;

[0205] The second display unit 94 is configured to display the private data when receiving the private data associated with the identifier provided by the data provider.

[0206] The privacy data protection device provided by the embodiment of the present disclosure stores the privacy data and ordinary data in the target data in different storage locations independently in order to uniformly manage privacy data. When the target data is provided to the data requester, the privacy data is not provided directly to the data requester, but only the desensitized data corresponding to the privacy data is provided to the data requester for the user to query the privacy data. Only when the data requester has a need to obtain privacy data after obtaining the desensitized data, the privacy data will be provided to the data requester based on the identification of the privacy data. Since the desensitized data is used instead of the privacy data to be provided to the data requester, the desensitized data can be conveniently obtained without complex decryption operations. Therefore, the embodiment of the present disclosure can not only improve the security of privacy data but also reduce the decryption operations of the data requester.

[0207] The privacy data protection device provided in the embodiment of the ninth aspect can be used to execute the privacy data protection method provided in the embodiment of the fifth aspect. The relevant meaning and specific implementation methods can be found in the relevant description in the embodiment of the fifth aspect and will not be described in detail here.

[0208] In the tenth aspect, an embodiment of the present disclosure provides a storage medium, which includes a stored program, wherein when the program is running, the device where the storage medium is located is controlled to execute the privacy data protection method described in any one of the first to seventh aspects.

[0209] The storage medium may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.

[0210] In the fifth aspect, an embodiment of the present disclosure provides a human-computer interaction device, which includes a storage medium and one or more processors, wherein the storage medium is coupled to the processor, and the processor is configured to execute program instructions stored in the storage medium; when the program instructions are run, the privacy data protection method described in any one of the first to seventh aspects is executed.

[0211] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0212] It will be understood by those skilled in the art that the embodiments of the present disclosure may be provided as methods, systems, or computer program products. Therefore, the embodiments of the present disclosure may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the embodiments of the present disclosure may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0213] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products of the embodiments of the present disclosure. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0214] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0215] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0216] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0217] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0218] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.

[0219] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.

[0220] It will be understood by those skilled in the art that the embodiments of the present disclosure may be provided as methods, systems, or computer program products. Therefore, the embodiments of the present disclosure may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the embodiments of the present disclosure may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0221] The above are merely embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.

Claims

1. A privacy data protection method, characterized in that: The method is applied to a data provider to protect private data in target data that includes both private data and general data. The method includes: Determining the private data and general data included in the target data to be stored; generating an identifier and desensitized data corresponding to the private data, wherein the identifier is a basis for determining that the private data and the general data belong to the same target data, so as to determine that the private data and the general data belong to the same target data based on the identifier, and the desensitized data is data obtained by desensitizing the private data; Generate associations between the identifier and the desensitized data, the ordinary data, and the private data, respectively. The associations serve as a basis for providing the desensitized data, the ordinary data, and the identifier to the data requester when, upon receiving a request for obtaining target data from the data requester, it is determined that the data requester has permission to obtain the private data. Furthermore, the associations serve as a basis for providing the private data associated with the identifier to the data requester when, after obtaining the desensitized data, the ordinary data, and the identifier, the data requester requests the private data based on the identifier it obtained. Based on the association relationship, the private data and the common data are stored in different storage locations, respectively, so as to clearly identify the private data and common data belonging to the same target data in different storage locations.

2. The method according to claim 1, characterized in that Before storing the private data and the general data in different storage locations, the method further includes: determining an encryption level of the private data; The private data is encrypted using an encryption method corresponding to the encryption level.

3. The method according to any one of claims 1-2, characterized in that The method further comprises: determining a privacy level of the private data; Based on the privacy level of the private data, it is determined whether a data requester has what authority to obtain the private data.

4. The method according to any one of claims 1-2, characterized in that Generating an identifier corresponding to the private data includes: Generate a random number using a random number generation function, and use the random number as the identifier; or Performing MD5 calculation on the private data to generate an MD5 value, and using the MD5 value as the identifier; or Perform a hash operation on the private data to generate a hash value, and use the hash value as the identifier.

5. A privacy data protection method, characterized in that: The method is applied to a data provider to protect private data in target data that includes both private data and general data. The method includes: Upon receiving an acquisition request for target data sent by a data requester, determining whether the data requester has permission to obtain the private data; if the data requester has permission to obtain the private data, providing the ordinary data, the identifier, and the desensitized data to the data requester based on the association relationships between the identifier and the desensitized data, ordinary data, and private data, respectively. The desensitized data is data obtained by desensitizing the private data in the target data, the identifier is the basis for the private data and ordinary data belonging to the same target data, so as to determine the private data and ordinary data belonging to the same target data based on the identifier, and the identifier is generated by the data provider for the private data; the association relationship is generated by the data provider to reflect the association relationship between the private data and ordinary data included in the same target data, and the desensitized data corresponding to the private data and the identifier; Upon receiving a private data acquisition request carrying the identifier sent by the data requester, it is determined whether the data requester has the authority to obtain the private data. If it is determined that the data requester has the authority to obtain the private data, the private data associated with the identifier is provided to the data requester based on the association relationship.

6. The method according to claim 5, characterized in that The method further comprises: Before providing the normal data, the identifier and the desensitized data to the data requester, if it is determined that the data requester does not have the authority to obtain the private data, the normal data and the desensitized data are provided to the data requester.

7. The method according to claim 5, characterized in that The method further comprises: Before providing the private data associated with the identifier to the data requester based on the association relationship, if it is determined that the data requester does not have the authority to obtain the private data associated with the identifier, a prompt message indicating that the private data acquisition failed is sent to the data requester.

8. A privacy data protection method, characterized in that: The method is applied to a data requester and is used to protect private data in target data that includes both private data and general data. The method includes: Receiving normal data, an identifier, and desensitized data provided by a data provider, wherein the normal data, the identifier, and the desensitized data are provided by the data provider when the data provider determines that the data requester has permission to obtain the private data upon receiving an acquisition request for target data from the data requester; the normal data is included in the target data; the desensitized data is data obtained by desensitizing the private data included in the target data; the identifier is evidence that the private data and the normal data belong to the same target data, and the identifier is generated by the data provider for the private data; Displaying the normal data and the desensitized data; If the user needs to obtain the private data, a private data acquisition request carrying the identifier is sent to the data provider; When receiving the private data associated with the identifier provided by the data provider, the private data is displayed. The private data is provided when the data provider determines that the data requester has the authority to obtain the private data associated with the identifier.

9. A privacy data protection method, characterized in that: The method for protecting private data in target data including both private data and general data includes: The data provider determines the private data and general data included in the target data to be stored; The data provider generates an identifier and desensitized data corresponding to the private data, wherein the identifier is the basis for determining that the private data and the general data belong to the same target data, so as to determine that the private data and the general data belong to the same target data based on the identifier, and the desensitized data is data obtained by desensitizing the private data; The data provider generates associations between the identifier and the desensitized data, the ordinary data, and the private data, respectively. The associations are the basis for providing the desensitized data, the ordinary data, and the identifier to the data requester when the data requester is determined to have the authority to obtain the private data upon receiving the acquisition request for the target data sent by the data requester. The associations are also the basis for providing the private data associated with the identifier to the data requester when the data requester, after obtaining the desensitized data, the ordinary data, and the identifier, requests the private data based on the identifier it obtained. The data provider stores the private data and the common data in different storage locations based on the association relationship, so as to clearly identify the private data and common data belonging to the same target data in different storage locations; Upon receiving a request for obtaining target data from a data requester, the data provider determines whether the data requester has permission to obtain the private data. If the data requester has permission to obtain the private data, the data provider provides the public data, the identifier, and the desensitized data to the data requester based on the association relationships between the identifier and the desensitized data, the public data, and the private data, respectively. Upon receiving the private data acquisition request carrying the identifier sent by the data requester, the data provider determines whether the data requester has the authority to obtain the private data. If it is determined that the data requester has the authority to obtain the private data, the data provider provides the private data associated with the identifier to the data requester based on the association relationship.

10. The method according to claim 9, characterized in that After the data provider provides the ordinary data, the identifier, and the desensitized data to the data requester based on the association relationships between the identifier and the desensitized data, the ordinary data, and the private data, the method further includes: The data requester receives the normal data, identifier, and desensitized data provided by the data provider; the normal data, identifier, and desensitized data are provided by the data provider when the data provider determines that the data requester has the authority to obtain the private data upon receiving the acquisition request for the target data sent by the data requester; The data requester displays the normal data and the desensitized data; If the user has a need to obtain the private data, the data requester sends a private data acquisition request carrying the identifier to the data provider; When the data requester receives the private data associated with the identifier from the data provider, the data requester displays the private data. The private data is provided when the data provider determines that the data requester has the authority to obtain the private data associated with the identifier.

11. A privacy data protection device, characterized in that: The device is applied to a data provider and is used to protect the privacy data in target data that includes both private data and general data. The device includes: a determining unit, configured to determine the private data and the common data included in the target data to be stored; a first generating unit, configured to generate an identifier and desensitized data corresponding to the private data, wherein the identifier is a basis for determining that the private data and the general data belong to the same target data, so as to determine that the private data and the general data belong to the same target data based on the identifier, and the desensitized data is data obtained by desensitizing the private data; a second generating unit, configured to generate associations between the identifier and the desensitized data, the ordinary data, and the private data, respectively, wherein the associations are a basis for providing the desensitized data, the ordinary data, and the identifier to the data requester when determining that the data requester has permission to obtain the private data upon receiving an acquisition request for target data from the data requester; and the associations are also a basis for providing the private data associated with the identifier to the data requester when determining that the data requester has permission to obtain the private data associated with the identifier after obtaining the desensitized data, the ordinary data, and the identifier and requesting the private data based on the identifier obtained; The storage unit is configured to store the private data and the common data in different storage locations based on the association relationship, so as to clarify the private data and the common data belonging to the same target data in different storage locations.

12. A privacy data protection device, characterized in that: The device is applied to a data provider and is used to protect the privacy data in target data that includes both private data and general data. The device includes: A first providing unit is configured to, upon receiving an acquisition request for target data sent by a data requester, determine whether the data requester has permission to obtain the private data; if the data requester has permission to obtain the private data, provide the ordinary data, the identifier, and the desensitized data to the data requester based on the association relationships between the identifier and the desensitized data, ordinary data, and private data, respectively, wherein the desensitized data is data obtained by desensitizing the private data in the target data, the identifier is a basis for the private data and the ordinary data to belong to the same target data, so as to determine the private data and ordinary data belonging to the same target data based on the identifier, and the identifier is generated by the data provider for the private data; the association relationship is generated by the data provider to reflect the association relationship between the private data and ordinary data included in the same target data, and the desensitized data corresponding to the private data and the identifier; The second providing unit is configured to, upon receiving a private data acquisition request carrying the identifier sent by the data requesting party, determine whether the data requesting party has the authority to obtain the private data; and if it is determined that the data requesting party has the authority to obtain the private data, provide the private data associated with the identifier to the data requesting party based on the association relationship.

13. A privacy data protection device, characterized in that: The device is applied to a data requester and is used to protect the privacy data in target data including both private data and general data. The device includes: a receiving unit, configured to receive ordinary data, an identifier, and desensitized data provided by a data provider, wherein the ordinary data, the identifier, and the desensitized data are provided by the data provider when the data provider determines that the data requester has permission to obtain the private data upon receiving an acquisition request for target data from the data requester; the ordinary data is included in the target data; the desensitized data is data obtained by desensitizing the private data included in the target data; the identifier is evidence that the private data and the ordinary data belong to the same target data, and the identifier is generated by the data provider for the private data; A first display unit, configured to display the normal data and the desensitized data; a sending unit, configured to send a private data acquisition request carrying the identifier to the data provider if the user has a need to acquire the private data; The second display unit is configured to display the private data associated with the identifier upon receiving the private data provided by the data provider, wherein the private data is provided when the data provider determines that the data requester has the authority to obtain the private data associated with the identifier.

14. A storage medium, characterized in that The storage medium includes a stored program, wherein, when the program is running, the device where the storage medium is located is controlled to execute the privacy data protection method described in any one of claims 1 to 4, or the privacy data protection method described in any one of claims 5 to 7, or the privacy data protection method described in claim 8.

15. A human-computer interaction device, characterized in that: The device includes a storage medium and one or more processors, the storage medium is coupled to the processor, and the processor is configured to execute program instructions stored in the storage medium; when the program instructions are executed, the privacy data protection method described in any one of claims 1 to 4, or the privacy data protection method described in any one of claims 5 to 7, or the privacy data protection method described in claim 8 is executed.

Citation Information

Patent Citations

  • Method for displaying and storing private data

    CN111191289A

  • Desensitization storage method and device for sensitive data

    CN111262835A

  • Method of protecting privacy data of an application program and apparatus using the same

    US20140373168A1