Data sorting method and data processing method based on privacy protection

The privacy protection sorting of data through protocol rules for secure multi-party computing and secret sharing is solved, and the problem of data leakage in joint data processing is achieved, and efficient and secure data quality evaluation is achieved.

CN114254356BActive Publication Date: 2025-07-08SHANGHAI MATRIXELEMENTS TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111580174.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-22
Publication Date
2025-07-08
Estimated Expiration
2041-12-22

AI Technical Summary

Technical Problem

During the data processing process, how to achieve joint sorting and data quality evaluation while protecting the data privacy of each data party to avoid data leakage.

Method used

The protocol rules based on secure multi-party computing and secret sharing are adopted, and the data is sorted by translating operations and comparing functions to process the ciphertext data of the data, and the data quality is determined by using binning rules.

Benefits of technology

On the premise of protecting data privacy, complete data processing efficiently, avoid data leakage, accurately evaluate data quality, and reduce resource waste.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114254356B_ABST
    Figure CN114254356B_ABST
Patent Text Reader

Abstract

This specification provides a data sorting method and a data processing method based on privacy protection. Based on the above methods, computing nodes can, on the premise of protecting the data privacy of the first data party and the second data party, jointly use the ciphertext data of the first data group and the ciphertext data of the second data group through translation operations according to preset protocol rules for joint sorting, so as to efficiently obtain a target sequence group containing the ciphertext data of the first data and the ciphertext data of the second data arranged according to the preset sorting rules. Then, by using the above target sequence group, data binning is performed to obtain multiple data bins; and based on each data bin, an information value about the combined first data and second data is calculated to accurately determine the data quality of the first data and the second data, effectively avoiding the leakage of the data held by the first data party and the second data party during the above data processing process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification belongs to the field of Internet technologies, and particularly relates to a data sorting method and a data processing method based on privacy protection. Background Art

[0002] In some data processing scenarios, there may be a situation where different data parties respectively hold the same type of attribute data of different data objects. Sometimes, it is necessary for different data parties to cooperate, respectively use the attribute data they hold to perform a joint sorting, and then evaluate the data quality of the attribute data held by different data parties according to the data sequence after the joint sorting. At the same time, in order to protect data privacy, the data parties participating in the above data processing also require that their own held attribute data should not be leaked to other data parties during the joint sorting process.

[0003] Therefore, there is an urgent need for a method that can implement the above data processing on the premise of protecting the data privacy of the participating parties. Summary of the Invention

[0004] This specification provides a data sorting method and a data processing method based on privacy protection, which can efficiently and securely complete relevant data processing on the premise of protecting the data privacy of the participating parties.

[0005] An embodiment of this specification provides a data processing method, including: obtaining a target sequence group; wherein, the target sequence group includes ciphertext data of first data and ciphertext data of second data arranged according to a preset sorting rule; the target sequence group is obtained by a first data party holding the first data and a second data party holding the second data through joint sorting according to a preset protocol rule; performing binning processing on the target sequence group according to a preset binning rule to obtain a plurality of data bins; determining an information value about the combined first data and second data according to the plurality of data bins.

[0006] The embodiment of the present specification also provides a data sorting method based on privacy protection, which is applied to a computing node and includes: according to a preset protocol rule and ciphertext data of the previous comparison result, by performing corresponding translation operations on the ciphertext data of the previous first data group and the ciphertext data of the previous second data group, to obtain the ciphertext data of the current first data group and the ciphertext data of the current second data group; according to the preset protocol rule, extract elements at a preset position from the ciphertext data of the current first data group as the ciphertext data of the current first data; extract elements at a preset position from the ciphertext data of the current second data group as the ciphertext data of the current second data; according to the preset protocol rule, call a preset comparison function to process the ciphertext data of the current first data and the ciphertext data of the current second data to obtain the ciphertext data of the current comparison result; according to the ciphertext data of the current comparison result, save one of the ciphertext data of the current first data and the ciphertext data of the current second data in a target data group, so as to obtain a target sequence group containing the ciphertext data of the first data and the ciphertext data of the second data arranged according to a preset sorting rule.

[0007] In one embodiment, according to a preset protocol rule and ciphertext data of the previous comparison result, by performing corresponding translation operations on the ciphertext data of the previous first data group and the ciphertext data of the previous second data group, to obtain the ciphertext data of the current first data group and the ciphertext data of the current second data group, includes: according to the preset protocol rule, perform a translation operation on the ciphertext data of the previous first data group to obtain the ciphertext data of the previous first data group after the translation operation; perform a translation operation on the ciphertext data of the previous second data group to obtain the ciphertext data of the previous second data group after the translation operation; according to the preset protocol rule, call a preset first selection function, and according to the ciphertext data of the previous comparison result, determine the ciphertext data of the current first data group from the ciphertext data of the previous first data group and the ciphertext data of the previous first data group after the translation operation; call a preset second selection function, and according to the ciphertext data of the previous comparison result, determine the ciphertext data of the current second data group from the ciphertext data of the previous second data group and the ciphertext data of the previous second data group after the translation operation.

[0008] In one embodiment, according to the preset protocol rule, perform a translation operation on the ciphertext data of the previous first data group to obtain the ciphertext data of the previous first data group after the translation operation, includes: according to the preset protocol rule, translate the elements included in the ciphertext data of the previous first data group by one data bit along a preset direction to obtain the ciphertext data of the previous first data group after the translation operation.

[0009] In one embodiment, the preset protocol rules include protocol rules based on secure multi-party computation and secret sharing.

[0010] In one embodiment, before performing corresponding translation operations on the ciphertext data of the previous first data group and the ciphertext data of the previous second data group according to the preset protocol rules and the ciphertext data of the previous comparison result, the method further includes: receiving the ciphertext data of the first data group and the ciphertext data of the second data group; wherein, the ciphertext data of the first data group is obtained by the first data party arranging the first data held by it according to the preset sorting rules and performing encryption processing according to the preset protocol rules; the ciphertext data of the second data group is obtained by the second data party arranging the second data held by it according to the preset sorting rules and performing encryption processing according to the preset protocol rules.

[0011] In one embodiment, the first data party includes a first physical examination institution, and the second data party includes a second physical examination institution; correspondingly, the first data includes numerical physical examination parameters of a first sample object held by the first physical examination institution, and the second data includes numerical physical examination parameters of the same type of a second sample object held by the second physical examination institution.

[0012] In one embodiment, after receiving the ciphertext data of the first data group and the ciphertext data of the second data group, the method further includes: in response to a joint sorting request, according to the preset protocol rules, extracting elements at a preset position from the ciphertext data of the first data group as the ciphertext data of the first data for the current time; extracting elements at a preset position from the ciphertext data of the second data group as the ciphertext data of the second data for the current time; and according to the preset protocol rules, calling a preset comparison function to process the ciphertext data of the first data for the current time and the ciphertext data of the second data for the current time to obtain the ciphertext data of the comparison result for the current time.

[0013] In one embodiment, the received ciphertext data of the first data group further carries first length information of the ciphertext data of the first data group; the received ciphertext data of the second data group further carries second length information of the ciphertext data of the second data group.

[0014] In one embodiment, before performing corresponding translation operations on the ciphertext data of the previous first data group and the ciphertext data of the previous second data group according to the preset protocol rules and the ciphertext data of the previous comparison result, the method further includes: detecting whether the current length of the target data group is equal to a preset length threshold; wherein, the preset length threshold is determined according to the first length information and the second length information; and in the case where it is detected that the current length of the target data group is equal to the preset length threshold, determining the target data group as the target sequence group.

[0015] In one embodiment, the ciphertext data stored in the target data group further carries a position tag, and the position tag is used to represent the sorting position of the ciphertext data in the target data group.

[0016] This embodiment of the present specification also provides a data sorting method based on privacy protection, which is applied to an intermediate computing node and includes: receiving the ciphertext data of the first data of the current time provided by the first computing node and the ciphertext data of the second data of the current time provided by the second computing node; wherein, the first computing node is arranged at the first data party; the first computing node determines the ciphertext data of the first data of the current time according to a preset protocol rule and the ciphertext data of the previous comparison result; the second computing node determines the ciphertext data of the second data of the current time according to a preset protocol rule and the ciphertext data of the previous comparison result; according to the preset protocol rule, calling a preset comparison function to process the ciphertext data of the first data of the current time and the ciphertext data of the second data of the current time to obtain the ciphertext data of the current comparison result; and sending the ciphertext data of the current comparison result to the first computing node and the second computing node respectively; according to the ciphertext data of the current comparison result, saving one of the ciphertext data of the first data of the current time and the ciphertext data of the second data of the current time in the target data group to obtain a target sequence group containing the ciphertext data of the first data and the ciphertext data of the second data arranged according to a preset sorting rule.

[0017] This embodiment of the present specification also provides a data processing device, including: an acquisition module, configured to acquire a target sequence group; wherein, the target sequence group contains the ciphertext data of the first data and the ciphertext data of the second data arranged according to a preset sorting rule; the target sequence group is obtained by joint sorting of the first data party holding the first data and the second data party holding the second data according to a preset protocol rule; a binning module, configured to perform binning processing on the target sequence group according to a preset binning rule to obtain a plurality of data bins; a determination module, configured to determine the information values of the first data and the second data according to the plurality of data bins.

[0018] The embodiments of the present specification also provide a data sorting device based on privacy protection, which is applied to a computing node and includes: an operation module for, according to a preset protocol rule and ciphertext data of a previous comparison result, performing corresponding translation operations on the ciphertext data of a previous first data group and the ciphertext data of a previous second data group to obtain the ciphertext data of the current first data group and the ciphertext data of the current second data group; an extraction module for, according to a preset protocol rule, extracting elements at preset positions from the ciphertext data of the current first data group as the ciphertext data of the current first data; and extracting elements at preset positions from the ciphertext data of the current second data group as the ciphertext data of the current second data; a call module for, according to a preset protocol rule, calling a preset comparison function to process the ciphertext data of the current first data and the ciphertext data of the current second data to obtain the ciphertext data of the current comparison result; a storage module for, according to the ciphertext data of the current comparison result, storing one of the ciphertext data of the current first data and the ciphertext data of the current second data in a target data group to obtain a target sequence group containing the ciphertext data of the first data and the ciphertext data of the second data arranged according to a preset sorting rule.

[0019] The embodiments of the present specification also provide a server, including a processor and a memory for storing processor-executable instructions, and when the processor executes the instructions, relevant steps of the method are implemented.

[0020] The embodiments of the present specification also provide a computer-readable storage medium, on which computer instructions are stored, and when the instructions are executed, relevant steps of the method are implemented.

[0021] Based on the data sorting method and data processing method provided in this specification, the computing node can, on the premise of protecting the data privacy of the first data party and the second data party, according to the preset protocol rules, without additionally generating and using a selection vector, only by performing corresponding translation operations on the ciphertext data of the first data group and the ciphertext data of the second data group, can horizontally jointly use the ciphertext data of the first data group containing the ciphertext data of the first data and the ciphertext data of the second data group containing the ciphertext data of the second data, and complete the joint sorting under privacy protection with a lower data processing volume and a lower complexity, and efficiently obtain the target sequence group containing the ciphertext data of the first data and the ciphertext data of the second data arranged according to the preset sorting rules. Then, by using the above target sequence group, data binning is performed to obtain multiple data bins; and according to each data bin, the information value of the data after combining the first data and the second data is calculated to accurately determine the data quality of the first data and the second data, so as to avoid the leakage of the data information held by the first data party and the second data party respectively during the above data processing process, and can efficiently and securely complete the relevant data processing on the premise of effectively protecting the data privacy of the participating parties. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] In order to more clearly illustrate the embodiments of this specification, the drawings required for use in the embodiments will be briefly introduced below. The drawings described below are only some embodiments recorded in this specification. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0023] Figure 1 is a schematic flowchart of a data processing method provided by an embodiment of this specification;

[0024] Figure 2 is a schematic flowchart of a data sorting method based on privacy protection provided by an embodiment of this specification;

[0025] Figure 3 is a schematic diagram of an embodiment of applying the data sorting method based on privacy protection provided by an embodiment of this specification in a scenario example;

[0026] Figure 4 is a schematic diagram of an embodiment of applying the data sorting method based on privacy protection provided by an embodiment of this specification in a scenario example;

[0027] Figure 5 is a schematic diagram of an embodiment of applying the data sorting method based on privacy protection provided by an embodiment of this specification in a scenario example;

[0028] Figure 6It is a schematic diagram of an embodiment of applying the data sorting method based on privacy protection provided in the embodiments of this specification in a scenario example;

[0029] Figure 7 It is a schematic diagram of an embodiment of applying the data sorting method based on privacy protection provided in the embodiments of this specification in a scenario example;

[0030] Figure 8 It is a schematic diagram of an embodiment of applying the data sorting method based on privacy protection provided in the embodiments of this specification in a scenario example;

[0031] Figure 9 It is a schematic flowchart of the data sorting method based on privacy protection provided in another embodiment of this specification;

[0032] Figure 10 It is a schematic diagram of an embodiment of applying the data sorting method based on privacy protection provided in the embodiments of this specification in a scenario example;

[0033] Figure 11 It is a schematic diagram of an embodiment of applying the data sorting method based on privacy protection provided in the embodiments of this specification in a scenario example;

[0034] Figure 12 It is a schematic diagram of an embodiment of applying the data sorting method based on privacy protection provided in the embodiments of this specification in a scenario example;

[0035] Figure 13 It is a schematic diagram of the structural composition of a server provided in an embodiment of this specification;

[0036] Figure 14 It is a schematic diagram of the structural composition of a data processing device provided in an embodiment of this specification. Detailed implementation manners

[0037] In order to enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all the embodiments. Based on the embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this specification.

[0038] Refer to Figure 1 As shown, the embodiments of this specification provide a data processing method. Among them, this method can be specifically applied to the server side. When this method is specifically implemented, it can include the following content.

[0039] S101: Obtain a target sequence group, where the target sequence group includes ciphertext data of first data and ciphertext data of second data arranged according to a preset sorting rule; the target sequence group is obtained by joint sorting by a first data party holding the first data and a second data party holding the second data according to a preset protocol rule.

[0040] S102: Perform binning processing on the target sequence group according to a preset binning rule to obtain a plurality of data bins.

[0041] S103: Determine an information value regarding the combined first data and second data according to the plurality of data bins.

[0042] In this embodiment, the above server may specifically include a background server deployed on one side of a data user (for example, a certain health data statistics platform) and capable of implementing functions such as data transmission and data processing. Specifically, the server may be, for example, an electronic device having data operation, storage functions, and network interaction functions. Alternatively, the server may also be a software program running in the electronic device and providing support for data processing, storage, and network interaction. In this embodiment, the number of the servers is not specifically limited. The server may specifically be one server, or several servers, or a server cluster formed by several servers.

[0043] In one embodiment, before a data user determines to cooperate with a first data party and a second data party to jointly use the data held by both parties for required data processing (such as joint statistics or joint modeling, etc.), it is necessary to first perform data quality evaluation on the data obtained by jointly sorting the first data held by the first data party and the second data held by the second data party by determining a specific information value, so as to determine whether the data quality of the combined first data and second data meets the preset quality requirements, and then decide whether to cooperate with the first data party and the second data party to use the data held by both parties.

[0044] In some embodiments, the above first data and second data may specifically be numerical-type attribute data of the same type. And the first data is the data held by the first data party, and the second data is the data held by the second data party.

[0045] Specifically, for example, in the scenario of health data statistics, the above-mentioned first data and second data can be the same type of physical examination parameters in different regions statistically obtained by different physical examination institutions. For example, the above-mentioned first data can be the height data of residents in regions A and B statistically obtained and held by the first physical examination institution. The above-mentioned second data can be the height data of residents in regions C, D, and E statistically obtained and held by the second physical examination institution.

[0046] In some embodiments, the above-mentioned target sequence group can be specifically understood as an ordered data group that simultaneously integrates the first data held by the first data party and the second data held by the second data party, and is arranged according to a preset sorting rule.

[0047] Among them, the above-mentioned preset sorting rule can specifically include: a sorting rule for arranging the data values of the data from small to large, or a sorting rule for arranging the data values of the data from large to small, etc.

[0048] In some embodiments, the above-mentioned target sequence group can be specifically obtained by pre-applying the data sorting method based on privacy protection provided in the embodiments of this specification, and through horizontal joint use of the data of the two data parties for joint sorting based on a preset protocol rule on the premise of protecting the data privacy of the first data party and the second data party. The specific implementation process of the joint sorting will be described separately later.

[0049] In some embodiments, the above-mentioned preset protocol rule can specifically include protocol rules based on secure multi-party computation (MPC) and secret sharing.

[0050] Among them, the above-mentioned secret sharing (Secret Sharing, SS), also known as secret sharing, can specifically refer to a multi-party secure protocol. Based on secret sharing, a secret can be split in an appropriate way, and each split share (denoted as a share) can be held and managed by different participants, and a single participant cannot recover the secret information based on a single share. Only several participants can cooperate together to recover the secret message.

[0051] The above-mentioned secure multi-party computation (Secure Muti-Party Computation, MPC) can specifically refer to an algorithm for protecting data privacy and security. Multi-party secure computation enables multiple data parties to perform collaborative computations without leaking their own data.

[0052] Further, the above-mentioned preset protocol rules can also be protocol rules combined with oblivious transfer. Among them, the above-mentioned oblivious transfer (OT) can specifically refer to a communication protocol that can protect the data privacy of both parties. Based on this protocol, neither party in the communication can know the specific data input by the other party, enabling the two parties in the communication to transmit data information in a way of selective obfuscation.

[0053] In some embodiments, the preset binning rules can specifically include at least one of the following: equal-frequency binning rules, chi-square binning rules, equal-width binning rules, decision tree binning rules, and so on. Of course, it should be noted that the above-listed preset binning rules are only illustrative. In specific implementation, according to specific application scenarios and processing requirements, other types of binning rules can also be introduced and used as the preset binning rules. This specification does not make any limitations in this regard.

[0054] In some embodiments, the above-mentioned Information Value (IV) can specifically be understood as a parameter value that can measure the prediction ability of the overall data with respect to the data label. Generally, if the information value of the data is larger, it indicates that the prediction ability of this group of data is higher, and the application effect for related model training or data statistics is better. On the contrary, if the information value of the data is smaller, it indicates that the prediction ability of this group of data is lower, and the application effect for model training or data statistics is worse.

[0055] In some embodiments, the data user can initiate a request for determining the data information value. The first data party and the second data party can receive and respond to the request for determining the data information value, and cooperate to generate a target sequence group according to the preset protocol rules; and provide the target sequence group to the data user. Correspondingly, the data user can obtain the above-mentioned target sequence group.

[0056] In some embodiments, the data user can perform specific binning processing on the target sequence group according to the preset binning rules to obtain corresponding multiple data bins. Each of the data bins contains multiple first data and / or second data respectively.

[0057] In some embodiments, the data user can calculate the information value of the overall combination of the first data and the second data based on the first data and / or the second data contained in each of the multiple data bins.

[0058] In some embodiments, after determining the information value of the combined first data and second data according to the multiple data bins, when the method is specifically implemented, the following content may further be included: comparing the information value with a preset information value threshold to obtain a corresponding comparison result; and determining whether the data quality of the combined first data and second data meets the preset quality requirement according to the comparison result.

[0059] Specifically, according to the comparison result, when it is determined that the information value of the combined first data and second data is greater than or equal to the preset information value threshold, it can be determined that the data quality of the combined first data and second data meets the preset quality requirement. Furthermore, the data user can decide to cooperate with the first data party and the second data party to jointly use the data held by the first data party and the second data party respectively for model training.

[0060] On the contrary, according to the comparison result, when it is determined that the information value of the combined first data and second data is less than the preset information value threshold, it can be determined that the data quality of the combined first data and second data does not meet the preset quality requirement. Furthermore, the data user can decide not to cooperate with the first data party and the second data party, which can effectively reduce the waste of processing resources and processing time.

[0061] Through the above embodiments, the data user can first perform data binning on a target sequence group including ciphertext data of the first data arranged according to a preset sorting rule and ciphertext data of the second data to obtain multiple data bins; then calculate the information value of the combined first data and second data according to each data bin; and accurately determine the data quality of the combined first data and second data by using the above information value. Thus, on the premise of protecting the data privacy of the first data party and the second data party, the data quality of the combined first data and second data can be accurately evaluated, providing a highly valuable reference basis for the decision-making of the data user.

[0062] Refer to Figure 2 As shown, an embodiment of the present specification further provides a data sorting method based on privacy protection, where the method is specifically applied to the computing node side. When specifically implemented, the method may include the following content:

[0063] S201: According to preset protocol rules and ciphertext data of the previous comparison result, perform corresponding translation operations on the ciphertext data of the previous first data group and the ciphertext data of the previous second data group to obtain the ciphertext data of the current first data group and the ciphertext data of the current second data group;

[0064] S202: Extract the elements at the preset positions from the ciphertext data of the first data group of the current instance as the ciphertext data of the first data of the current instance; extract the elements at the preset positions from the ciphertext data of the second data group of the current instance as the ciphertext data of the second data of the current instance.

[0065] S203: According to the preset protocol rules, call the preset comparison function to process the ciphertext data of the first data of the current instance and the ciphertext data of the second data of the current instance to obtain the ciphertext data of the comparison result of the current instance.

[0066] S204: According to the ciphertext data of the comparison result of the current instance, save one of the ciphertext data of the first data of the current instance and the ciphertext data of the second data of the current instance in the target data group to obtain a target sequence group containing the ciphertext data of the first data and the ciphertext data of the second data arranged according to the preset sorting rules.

[0067] In some embodiments, the above computing node can be specifically understood as a secure computing node configured with preset protocol rules, a preset comparison function, a preset first selection function, and a preset second selection function. Among them, the above computing node can be specifically understood as an entity device or a virtual functional module with certain data processing functions. Specifically, the above computing node can be a server, a computer, a smart phone, a computing chip, etc., or a computing unit, an operation module, a processing system, etc. The above computing node can specifically include one or more computing nodes.

[0068] In some embodiments, the above preset protocol rules can specifically include protocol rules based on secure multi-party computation (MPC) and secret sharing.

[0069] Correspondingly, the above preset comparison function, preset first selection function, and preset second selection function can specifically be encrypted functions that protect data privacy constructed based on the above preset protocol rules. In this way, when the subsequent computing node uses the above preset comparison function, preset first selection function, and preset second selection function to perform corresponding function operations, it is also impossible to know the true plaintext value of the operation result, thus being able to better protect the data privacy of the data party.

[0070] In some embodiments, specifically, it can be referred to Figure 3 As shown, the above computing node can be respectively connected to the first data party and the second data party. Among them, the first data party holds the first data, and the second data party holds the second data. The above first data and second data can specifically be attribute data of the same type of different data objects. Specifically, the above first data and second data belong to numerical attribute data.

[0071] Specifically, for example, the above-mentioned first data party may be the first physical examination institution, and the second data party may be the second physical examination institution. Correspondingly, the above-mentioned first data may be the first type of physical examination parameters (such as height data) of the residents in area A, and the second data may be the first type of physical examination parameters (such as the same height data) of the residents in area B. It should be noted that the collection and use of the above-mentioned first data and second data are pre-approved and authorized by the users, and the leakage of user privacy information will not be involved in the process of collecting and using the above data.

[0072] In some embodiments, the above-mentioned preset sorting rule may specifically be a sorting rule based on the numerical value of the data. For example, a sorting rule from small to large based on the numerical value of the data, or a sorting rule from large to small based on the numerical value of the data.

[0073] Currently, the first data party and the second data party expect to cooperate, respectively utilize the data they hold, interact with the computing node, and through joint sorting, obtain a target sequence group that simultaneously includes the first data and the second data, and the data included is arranged according to the preset sorting rule; at the same time, it is also required that during the process of joint sorting, the data privacy of both parties should be protected to avoid disclosing the data held by one's own party to the other party or other third parties.

[0074] In some embodiments, specifically in implementation, any one of the first data party, the second data party, and the computing node may initiate a joint sorting request first.

[0075] In some embodiments, refer to Figure 4 As shown, the first data party can respond to the joint sorting request, first sort the first data held according to the preset sorting rule according to the preset protocol rule to obtain the corresponding first data group; then encrypt each first data in the first data column according to the preset protocol rule to obtain the ciphertext data of the corresponding first data group. Among them, the ciphertext data of the first data group includes the ciphertext data of the first data arranged according to the preset sorting rule. Then, the first data party can send the above-mentioned ciphertext data of the first data group to the computing node.

[0076] Similarly, the second data party can respond to the joint sorting request, utilize the second data held to generate the ciphertext data of the second data group; and send the ciphertext data of the second data group to the computing node. Among them, the ciphertext data of the second data group includes the ciphertext data of the second data arranged according to the preset sorting rule.

[0077] Among them, the above-mentioned ciphertext data of the first data group (which can be denoted as A[i]) and the ciphertext data of the second data group (which can be denoted as B[j]) may specifically be ciphertext data in vector form.

[0078] Since the first data party and the second data party send ciphertext data of the first data group and ciphertext data of the second data group to the computing node, and the computing node does not have the corresponding decryption key. Therefore, the computing node also cannot know the true plaintext data of the first data and the true plaintext data of the second data. This can effectively avoid disclosing the data held by the first data party and the second data party to the computing node. At the same time, since the transmitted data is ciphertext data, it can also prevent other third parties from intercepting the data midway, resulting in the disclosure of the data held by the first data party and the second data party.

[0079] In some embodiments, for the computing node, before performing corresponding translation operations on the ciphertext data of the previous first data group and the ciphertext data of the previous second data group according to the preset protocol rules and the ciphertext data of the previous comparison result, when the method is specifically implemented, the following content may further be included: receiving the ciphertext data of the first data group and the ciphertext data of the second data group; wherein, the ciphertext data of the first data group is obtained by the first data party arranging the first data held by it according to the preset sorting rules and performing encryption processing according to the preset protocol rules; the ciphertext data of the second data group is obtained by the second data party arranging the second data held by it according to the preset sorting rules and performing encryption processing according to the preset protocol rules.

[0080] In some embodiments, for the computing node, refer to Figure 4 As shown, after receiving the ciphertext data of the first data group and the ciphertext data of the second data group, when the method is specifically implemented, the first comparison may also be performed in the following manner:

[0081] S1: In response to the joint sorting request, according to the preset protocol rules, extract the element at the preset position from the ciphertext data of the first data group as the ciphertext data of the first data for the current time; extract the element at the preset position from the ciphertext data of the second data group as the ciphertext data of the second data for the current time;

[0082] S2: According to the preset protocol rules, call the preset comparison function to process the ciphertext data of the first data for the current time and the ciphertext data of the second data for the current time, and obtain the ciphertext data of the comparison result for the current time.

[0083] Wherein, the above preset position may specifically be the first position from left to right in the ciphertext data of the first data group and the ciphertext data of the second data group.

[0084] In some embodiments, the ciphertext data of the first data group sent by the first data direction calculation node may also carry first length information. The first length information is used to characterize the number of first data included in the first data group. Similarly, the ciphertext data of the second data group sent by the second data direction calculation node may also carry second length information.

[0085] In some embodiments, when performing the first comparison, the calculation node may, according to the preset protocol rules, extract the element at the preset position from the ciphertext data of the first data group as the ciphertext data of the first data for the current time, so as to select the ciphertext data of the first data for the first time participating in the first comparison from the ciphertext data of the first data group (which can be denoted as a1). Refer to Figure 4 as shown.

[0086] Specifically, for example, it can be referred to Figure 5 as shown, the preset position may be the first position from left to right in the first ciphertext data (A[i] (1) ) of the first data group. Correspondingly, the extracted ciphertext data of the first data for the first time is the element "1". It should be noted that the elements "1", "2", "3", "4", "5", "6", "7" marked in the figure are only schematic representations of the different ciphertext data of the first data in the ciphertext data of the first data group.

[0087] It should be added that in specific implementation, according to the specific situation and the protocol rules used, other positions may also be selected as the above-mentioned preset position. As long as it is ensured that in each comparison, according to the preset protocol rules, the calculation node extracts the corresponding data from the fixed same preset position in the ciphertext data of the first data group and the ciphertext data of the second data group at that time to participate in the comparison.

[0088] Similarly, the calculation node may, according to the preset protocol rules, extract the element at the preset position from the ciphertext data of the first data group, and select the ciphertext data of the second data for the first time participating in the first comparison from the ciphertext data of the second data group (which can be denoted as b1).

[0089] In some embodiments, when performing the first comparison, the calculation node may, according to the preset protocol rules, input the ciphertext data a1 of the first data participating in the first comparison and the ciphertext b1 of the second data into the preset comparison function to calculate the ciphertext data of the current comparison result (i.e., the comparison result ciphertext data of the first comparison, which can be denoted as c(1)), and specifically can be expressed in the following form: c(1) = private_compare(a1, b1).

[0090] Among them, c1 is also a ciphertext data, which is used to represent the comparison result determined after numerically comparing the input a1 and b1 under the premise of privacy protection based on a preset comparison function (private_compare).

[0091] For example, according to the preset protocol rules, when a1 is less than or equal to b1, c(1) can be ciphertext data with a plaintext string of "1". Among them, "1" indicates that the ciphertext data of the first data in the current comparison is less than or equal to the ciphertext data of the second data. On the contrary, when a1 is greater than b1, c(1) can be ciphertext data with a plaintext string of "0". Among them, "0" indicates that the ciphertext data of the first data in the current comparison is greater than the ciphertext data of the second data.

[0092] In some embodiments, the computing node can also be configured with a selection function. Specifically, the selection function can be an encrypted function that protects data privacy constructed based on preset protocol rules.

[0093] When performing the first comparison, the computing node can input the ciphertext data a1 of the first data in the current comparison, the ciphertext data b1 of the second data in the current comparison, and the ciphertext data c(1) of the comparison result in the current comparison into the selection function together. The selection function can select the ciphertext data with a relatively smaller numerical value of a plaintext data from a1 and b1 according to c(1) and save it in the target data group in order.

[0094] Specifically, for example, when c(1) is ciphertext data with a plaintext string of "1", by running the selection function, a1 can be selected from a1 and b1 according to c(1), and only a1 is saved in the target sequence group. Since the current comparison is the first comparison, a1 will be saved in the first position in the target sequence group in order. It is also possible to save a1 in the target sequence group and set a data label "1" indicating the first comparison for a1. Thus, the first comparison is completed.

[0095] In the above processing process, since a1 and b1 input to the function, as well as c(1) output by the function, are all ciphertext data, and the function used is also a function encrypted based on a preset protocol rule. Therefore, on the one hand, the computing node (including other data parties) cannot know what data is selected from the ciphertext data of the first data group and the ciphertext data of the second data group respectively to participate in the current comparison; on the other hand, it cannot know the specific comparison result, and cannot know which data group's data is specifically retained in the target sequence group after the current comparison. Thus, it can better protect the data privacy of the data parties and avoid the data held by the data parties (such as the first data and the second data), as well as related information (such as which data party's data has a relatively larger value, which data party's data is retained in the current time, etc.) from being leaked, effectively protecting the data security of the data parties.

[0096] After completing the first comparison in the above manner, the next comparison (such as the second comparison, the third comparison, etc.) can be continued. Taking a certain current comparison (such as the pth comparison) after the first comparison as an example, specific description is as follows.

[0097] In some embodiments, referring to Figure 6 as shown, the computing node can first obtain the ciphertext data of the comparison result of the previous time (the (p - 1)th time) (such as c(p - 1)), as well as the ciphertext data of the first data group obtained after the previous comparison (which can be denoted as A[i] (p-1) ) and the ciphertext data of the second data group obtained after the previous comparison (which can be denoted as B[j] (p-1) ); and based on the preset protocol rule, according to the ciphertext data of the comparison result of the previous time, perform corresponding translation operations on the ciphertext data of the first data group of the previous time or the ciphertext data of the second data group of the previous time to obtain the corresponding ciphertext data of the first data group of the current time (which can be denoted as A[i] (p) ), the ciphertext data of the second data group of the current time (which can be denoted as B[j] (p) ). Specifically, it can refer to Figure 7 as shown.

[0098] In some embodiments, the ciphertext data based on the preset protocol rules and the previous comparison result is obtained by performing corresponding translation operations on the ciphertext data of the previous first data group and the ciphertext data of the previous second data group to obtain the ciphertext data of the current first data group and the ciphertext data of the current second data group. Specifically, it may include: According to the preset protocol rules, performing a translation operation on the ciphertext data of the previous first data group to obtain the translated ciphertext data of the previous first data group; performing a translation operation on the ciphertext data of the previous second data group to obtain the translated ciphertext data of the previous second data group; According to the preset protocol rules, calling a preset first selection function (for example, it can be denoted as private_selectA), and based on the ciphertext data of the previous comparison result, determining the ciphertext data of the current first data group from the ciphertext data of the previous first data group and the translated ciphertext data of the previous first data group; calling a preset second selection function (for example, it can be denoted as private_selectB), and based on the ciphertext data of the previous comparison result, determining the ciphertext data of the current second data group from the ciphertext data of the previous second data group and the translated ciphertext data of the previous second data group.

[0099] In some embodiments, according to the preset protocol rules, performing a translation operation on the ciphertext data of the previous first data group to obtain the translated ciphertext data of the previous first data group may specifically include: According to the preset protocol rules, shifting the elements included in the ciphertext data of the previous first data group by one data bit along a preset direction to obtain the translated ciphertext data of the previous first data group. Similarly, performing a translation operation on the ciphertext data of the previous second data group to obtain the translated ciphertext data of the previous second data group may specifically include: According to the preset protocol rules, shifting the elements included in the ciphertext data of the previous second data group by one data bit along the same preset direction to obtain the translated ciphertext data of the previous second data group.

[0100] In some embodiments, a preset first selection function is called. According to the ciphertext data of the previous comparison result, the ciphertext data of the current first data group is determined from the ciphertext data of the previous first data group and the ciphertext data of the previous first data group after a translation operation. Specifically, in implementation, it may include: processing the ciphertext data of the previous comparison result with the preset first selection function. When the ciphertext data of the previous comparison result is equal to a preset threshold (for example, the ciphertext data corresponding to the plaintext string "1"), the preset first selection function will automatically select and output the ciphertext data of the previous first data group after the translation operation as the ciphertext data of the current first data group. Otherwise, the preset first selection function will automatically select and output the ciphertext data of the previous first data group as the ciphertext data of the current first data group.

[0101] Similarly, a preset second selection function is called. According to the ciphertext data of the previous comparison result, the ciphertext data of the current second data group is determined from the ciphertext data of the previous second data group and the ciphertext data of the previous second data group after a translation operation. Specifically, in implementation, it may include: processing the ciphertext data of the previous comparison result with the preset second selection function. When the ciphertext data of the previous comparison result is not equal to the preset threshold, the preset second selection function will automatically select and output the ciphertext data of the previous second data group after the translation operation as the ciphertext data of the current first data group. Otherwise, the preset second selection function will automatically select and output the ciphertext data of the previous second data group as the ciphertext data of the current first data group.

[0102] When specifically performing the translation operation, for example, taking the preset position as the first position and the preset direction as the left direction, and taking the translation operation on the ciphertext data of the previous first data group as an example, the elements at other positions except the preset position in the ciphertext data of the previous first data group can be translated one data bit to the left; at the same time, the element at the preset position is translated to the end position of the ciphertext data of the first data group, thus completing the translation operation and obtaining the ciphertext data of the first data group after the translation operation. The translation operation for the ciphertext data of the second data group is similar to the above process, and this specification will not elaborate.

[0103] Specifically, refer to Figure 7 As shown, through the translation operation, the element originally at the first position in the ciphertext data A[i] of the previous first data group (p-1) is translated to the second position in the ciphertext data A[i] of the current first data group (p) The element originally at the first position in the ciphertext data A[i] of the previous first data group (p-1)The element at the second position in (p) is translated to the first position in the ciphertext data A[i] of the first data group of the current instance.

[0104] In some embodiments, according to the preset protocol rules, the computing node can extract the element at the preset position (for example, the first position) from the ciphertext data (A[i] (p) ) of the first data group of the current instance as the ciphertext data (which can be denoted as ap) of the first data of the current instance participating in the current comparison. Extract the element at the preset position from the ciphertext data (B[i] (p) ) of the second data group of the current instance as the ciphertext data (which can be denoted as bp) of the second data of the current instance participating in the current comparison.

[0105] Then, the computing node can call the preset comparison function for processing according to the preset protocol rules in the following manner to obtain the ciphertext data of the current comparison result: c(p) = private_compare(ap, bp). Refer to Figure 6 as shown.

[0106] Furthermore, according to the ciphertext data of the current comparison result, a ciphertext data with a relatively smaller real value of the plaintext data can be selected from the ciphertext data ap of the first data of the current instance and the ciphertext data bp of the second data of the current instance, and it is stored in the target data group in sequence next to the ciphertext data stored during the previous comparison. Alternatively, the ciphertext data is directly saved in the target data group, and a data label "p" for indicating the current comparison is set on the ciphertext data. Thus, the current comparison is completed.

[0107] In some embodiments, before the specific implementation, it can also be determined whether to trigger the execution of the current comparison first.

[0108] In some embodiments, the ciphertext data of the first data group received by the computing node also carries the first length information of the ciphertext data of the first data group; the ciphertext data of the second data group received also carries the second length information of the ciphertext data of the second data group. Among them, the above first length information can specifically represent the number of ciphertext data of the first data included in the ciphertext data of the first data group. The above second length information can specifically represent the number of ciphertext data of the second data included in the ciphertext data of the second data group.

[0109] In some embodiments, before performing corresponding translation operations on the ciphertext data of the previous first data group and the ciphertext data of the previous second data group according to the preset protocol rules and the ciphertext data of the previous comparison result, when the method is specifically implemented, the following content can also be included:

[0110] S1: Detect whether the current length of the target data group is equal to a preset length threshold; wherein, the preset length threshold is determined according to the first length information and the second length information;

[0111] S2: When it is detected that the current length of the target data group is equal to the preset length threshold, determine the target data group as the target sequence group.

[0112] In specific implementation, when it is detected that the current length of the target data group is less than the preset length threshold, the above-mentioned current comparison can be triggered. On the contrary, when it is detected that the current length of the target data group is greater than or equal to the preset length threshold, the current comparison is no longer triggered, and the current data group is determined as the target sequence group that has been jointly sorted.

[0113] Specifically, based on a recursive algorithm, multiple comparisons can be made in the above manner until it is detected that the current length of the target data group is greater than or equal to the preset length threshold, and the joint sorting is completed to obtain the target sequence group.

[0114] In some embodiments, when the method is specifically implemented, the following may also be included: obtaining the first length information of the ciphertext data of the first data group provided by the first data party, and the second length information of the ciphertext data of the second data group provided by the second data party; determining the preset length threshold according to the first length information and the second length information.

[0115] In some embodiments, in order to avoid the leakage of the above-mentioned associated information and better protect the data privacy of the data parties, the ciphertext data of the first data group and the ciphertext data of the second data group can also be respectively expanded.

[0116] In some embodiments, after receiving the ciphertext data of the first data group and the ciphertext data of the second data group, when the method is specifically implemented, the following may also be included: splicing at least one expansion data bit at the end of the ciphertext data of the first data group, and filling the maximum floating point number (for example, it can be denoted as max) in the expansion data bit to obtain the expanded ciphertext data of the first data group; splicing at least one expansion data bit at the end of the ciphertext data of the second data group, and filling the maximum floating point number in the expansion data bit to obtain the expanded ciphertext data of the second data group.

[0117] Specifically, as shown in Figure 8 the ciphertext data of the first data group can be expanded to obtain the corresponding expanded ciphertext data of the first data group.

[0118] After obtaining the ciphertext data of the first data group and the ciphertext data of the second data group after the above expansion, the ciphertext data of the first data group and the ciphertext data of the second data group after the above expansion can be used to participate in subsequent comparisons instead of the original ciphertext data of the first data group and the second data group, so as to more effectively protect the data privacy of the data party and avoid the leakage of associated information.

[0119] In some embodiments, when specifically performing the expansion process, a preset number of expansion data bits can be concatenated at the end of the ciphertext data of the first data group and the ciphertext data of the second data group respectively. Wherein, the preset number is an integer greater than or equal to 1.

[0120] In some embodiments, when it is determined that the current length of the target data group is equal to the preset length threshold, the method can further include the following when specifically implemented: determining the current target data group as the target sequence group; and sending the target sequence group to the requester according to the preset protocol rules.

[0121] Among them, the above requester can specifically be the first data party, or the second data party, or also a data user who has the right to use the target sequence group according to the preset cooperation agreement. The requester can train a model based on the received target sequence group, or evaluate the data quality of the combined first data and second data.

[0122] In some embodiments, when specifically implemented, after receiving the target sequence group, the requester first performs binning processing on the target sequence group according to the preset binning rules to obtain a plurality of data bins; then determines the information value regarding the combined first data and second data based on the plurality of data bins; furthermore, can determine the data quality of the combined first data and second data according to the information value; and determine whether to cooperate with the first data party and the second data party and whether to obtain the first data and the second data for related data processing based on this data quality.

[0123] In some embodiments, the first data party can specifically include a first physical examination institution, and the second data party can specifically include a second physical examination institution; correspondingly, the first data can include the numerical physical examination parameters of the first sample object held by the first physical examination institution, and the second data can include the same type of numerical physical examination parameters of the second sample object held by the second physical examination institution. Among them, the above physical examination parameters can specifically be height data, weight data, body fat percentage data, and so on.

[0124] Of course, the above-listed first data and second data are only illustrative. When specifically implemented, according to the specific application scenario and processing requirements, the above first data and second data can also include other types of attribute data. This specification does not limit this.

[0125] As can be seen from the above, based on the data sorting method based on privacy protection provided in the embodiments of this specification, the computing node can, without disclosing the first data and the second data respectively held by the first data party and the second data party, according to the preset protocol rules, without the need to additionally generate and use a selection vector, and through a translation operation, horizontally jointly use the ciphertext data of the first data group containing the first data and the ciphertext data of the second data group containing the second data, so as to efficiently obtain, with a relatively small amount of data processing, a target sequence group containing the ciphertext data of the first data and the ciphertext data of the second data arranged according to the preset sorting rules, and avoid disclosing the data and associated information held by itself to the other party or other data parties during the joint sorting process, thereby being able to better protect the data security of the data parties.

[0126] Refer to Figure 9 As shown, the embodiments of this specification also provide another data sorting method based on privacy protection. This method can be specifically applied to an intermediate computing node. When this method is specifically implemented, it may include the following content.

[0127] S901: Receive the ciphertext data of the first data for the current time provided by the first computing node, and the ciphertext data of the second data for the current time provided by the second computing node; wherein, the first computing node is arranged at the first data party; the first computing node determines the ciphertext data of the first data for the current time according to the preset protocol rules and the ciphertext data of the comparison result of the previous time; the second computing node determines the ciphertext data of the second data for the current time according to the preset protocol rules and the ciphertext data of the comparison result of the previous time;

[0128] S902: According to the preset protocol rules, call a preset comparison function to process the ciphertext data of the first data for the current time and the ciphertext data of the second data for the current time, and obtain the ciphertext data of the comparison result for the current time; and send the ciphertext data of the comparison result for the current time to the first computing node and the second computing node respectively;

[0129] S903: According to the ciphertext data of the comparison result for the current time, save one of the ciphertext data of the first data for the current time and the ciphertext data of the second data for the current time in the target data group, so as to obtain a target sequence group containing the ciphertext data of the first data and the ciphertext data of the second data arranged according to the preset sorting rules.

[0130] In some embodiments, it can be referred to Figure 10As shown, the system includes at least a first computing node, a second computing node, and an intermediate computing node. Among them, the first computing node is deployed at the first data party, and the second computing node is deployed at the second data party. The first computing node is at least configured with a preset protocol rule and a preset first selection function. The second computing node is at least configured with a preset protocol rule and a preset second selection function. The intermediate computing node is at least configured with a preset protocol rule and a preset comparison function. The above intermediate computing node may specifically include one or more computing nodes.

[0131] In some embodiments, when performing the current comparison, the first computing node can perform a translation operation on the ciphertext data of the previous first data group locally according to the preset protocol rule to obtain the ciphertext data of the previous first data group after the translation operation; then call the preset first comparison function, and select and output one of the ciphertext data of the previous first data group and the ciphertext data of the previous first data group after the translation operation by processing the ciphertext data of the previous comparison result as the ciphertext data of the current first data group; then extract the ciphertext data of the current first data from a preset position of the ciphertext data of the current first data group; and send the ciphertext data of the current first data to the intermediate computing node.

[0132] Similarly, the second computing node can extract the ciphertext data of the current second data locally according to the preset protocol rule and the ciphertext data of the previous comparison result; and send the ciphertext data of the current second data to the intermediate computing node.

[0133] In some embodiments, after the current comparison is completed, after saving one of the ciphertext data of the current first data and the ciphertext data of the current second data in the target data group, the intermediate node can also detect whether the current length of the target data group is equal to a preset length threshold. According to the detection result, when it is determined that the current length of the target data group is less than the preset length threshold, the intermediate computing node can send the ciphertext data of the current comparison result to the first computing node and the second computing node respectively to trigger the next comparison. On the contrary, according to the detection result, when it is determined that the current length of the target data group is equal to the preset length threshold, the intermediate computing node can determine that the joint sorting is completed and determine the current target data group as the target sequence group.

[0134] Through the above embodiments, it is possible to prevent the first data group from leaving the first data party and the second data group from leaving the second data party, and more securely and reliably achieve, without disclosing the first data held by the first data party and the second data held by the second data party respectively, according to the preset protocol rules, by horizontally jointly using the ciphertext data of the first data group containing the ciphertext data of the first data and the ciphertext data of the second data group containing the ciphertext data of the second data, so as to obtain the required target sequence group, further protecting the data security of the data parties participating in the joint sorting.

[0135] The embodiments of this specification also provide a privacy protection-based data sorting method involving multiple data parties. This method is specifically applied to a computing node, and specifically, the following content may be included during implementation.

[0136] S1: Receive the ciphertext data of multiple data groups provided by multiple data parties;

[0137] S2: Divide the ciphertext data of multiple data groups into multiple groups; wherein, each of the multiple groups contains the ciphertext data of two data groups;

[0138] S3: According to the preset protocol rules, use the ciphertext data of the data groups contained in the groups to obtain multiple sequence groups respectively corresponding to the multiple groups; wherein, the sequence group contains the ciphertext data of the data in the corresponding group, and the ciphertext data of the data is arranged in the sequence group according to the preset sorting rules;

[0139] S4: Based on a recursive algorithm, generate a target sequence group according to the multiple sequence groups; wherein, the target sequence group contains the ciphertext data of the data in the ciphertext data of multiple data groups arranged according to the preset sorting rules.

[0140] In some embodiments, the above multiple data parties may specifically be 3 data parties, 4 data parties, or a greater number of data parties. Among them, each data party holds numerical attribute data of the same type for different data objects.

[0141] In some embodiments, specifically, taking the case of processing multiple data parties including 4 data parties: a first data party, a second data party, a third data party, and a fourth data party as an example, refer to Figure 11As shown in the figure. After the computing node receives the ciphertext data of the first data group, the ciphertext data of the second data group, the ciphertext data of the third data group, and the ciphertext data of the fourth data group provided by the first data party, the second data party, the third data party, and the fourth data party, it can first divide the ciphertext data of the above 4 data groups into two groups according to a preset grouping rule or by using a random grouping method. For example, grouping 1 includes the ciphertext data of the first data group and the ciphertext data of the second data group, and grouping 2 includes the ciphertext data of the third data group and the ciphertext data of the fourth data group. Then, according to the preset protocol rule, joint sorting is performed on the above two groups respectively to obtain two sequence groups: sequence group 1 corresponding to grouping 1 and sequence group 2 corresponding to grouping 2. Among them, the above sequence group 1 includes the ciphertext data of the first data and the ciphertext data of the second data arranged according to the preset sorting rule. The above sequence group 2 includes the ciphertext data of the third data and the ciphertext data of the fourth data arranged according to the preset sorting rule. Then, according to the preset protocol rule, the above sequence group 1 and sequence group 2 can be used for joint sorting to obtain a target sequence group that combines sequence group 1 and sequence group 2. Among them, the target sequence group includes the ciphertext data of the first data, the ciphertext data of the second data, the ciphertext data of the third data, and the ciphertext data of the fourth data arranged according to the preset sorting rule.

[0142] In some embodiments, specifically, taking the case where multiple data parties include 3 data parties: the first data party, the second data party, and the third data party as an example, refer to Figure 12 As shown in the figure. After the computing node receives the ciphertext data of the first data group, the ciphertext data of the second data group, and the ciphertext data of the third data group provided by the first data party, the second data party, and the third data party respectively, it can first divide the ciphertext data of the above 3 data groups into two groups according to a preset grouping rule or by using a random grouping method. For example, grouping 1 includes the ciphertext data of the first data group and the ciphertext data of the second data group, and grouping 2 only includes the ciphertext data of the third data group. Then, according to the preset protocol rule, joint sorting is performed on grouping 1 to obtain the corresponding sequence group 1. Among them, the above sequence group 1 includes the ciphertext data of the first data and the ciphertext data of the second data arranged according to the preset sorting rule. Then, according to the preset protocol rule, the above sequence group 1 and the ciphertext data of the third data group can be used for joint sorting to obtain a target sequence group that combines sequence group 1 and the ciphertext data of the third data group. Among them, the target sequence group includes the ciphertext data of the first data, the ciphertext data of the second data, and the ciphertext data of the third data arranged according to the preset sorting rule.

[0143] In some embodiments, for more complex situations involving more data parties, the above method can be referred to. First, pairwise grouping is performed, and then joint sorting is carried out according to the preset protocol rules to determine the sequence groups for each group. Then, pairwise grouping is performed on the obtained sequence groups. By analogy, based on the recursive algorithm, grouping and joint sorting can be continuously carried out until finally a sequence group is obtained, which is the target sequence group of the ciphertext data containing data of multiple data parties arranged according to the preset sorting rules.

[0144] Through the above embodiments, in a complex data processing scenario involving multiple data parties, on the premise of protecting the data privacy of the data parties, it is possible to horizontally jointly use the data of multiple data parties to complete the joint sorting of the data, obtain the required rich and ordered target sequence group, and avoid data leakage during the sorting process, thereby effectively protecting the data security of the data parties.

[0145] The embodiments of this specification also provide a server, including a processor and a memory for storing instructions executable by the processor. When specifically implemented, the processor can execute the following steps according to the instructions: obtain a target sequence group; wherein, the target sequence group contains the ciphertext data of the first data and the ciphertext data of the second data arranged according to the preset sorting rules; the target sequence group is obtained by the first data party holding the first data and the second data party holding the second data through joint sorting according to the preset protocol rules; perform binning processing on the target sequence group according to the preset binning rules to obtain multiple data bins; determine the information value about the combined first data and second data according to the multiple data bins.

[0146] In order to be able to complete the above instructions more accurately, refer to Figure 13 As shown, the embodiments of this specification also provide another specific server. Among them, the server includes a network communication port 1301, a processor 1302, and a memory 1303. The above structures are connected by internal cables so that each structure can perform specific data interactions.

[0147] Among them, the network communication port 1301 can specifically be used to obtain a target sequence group; wherein, the target sequence group contains the ciphertext data of the first data and the ciphertext data of the second data arranged according to the preset sorting rules; the target sequence group is obtained by the first data party holding the first data and the second data party holding the second data through joint sorting according to the preset protocol rules.

[0148] The processor 1302 can specifically be used to perform binning processing on the target sequence group according to the preset binning rules to obtain multiple data bins; determine the information value about the combined first data and second data according to the multiple data bins.

[0149] The memory 1303 can be specifically used to store corresponding instruction programs.

[0150] In this embodiment, the network communication port 1301 can be bound to different communication protocols, so as to send or receive different data as a virtual port. For example, the network communication port can be a port responsible for web data communication, or a port responsible for FTP data communication, or a port responsible for mail data communication. In addition, the network communication port can also be a physical communication interface or communication chip. For example, it can be a wireless mobile network communication chip, such as GSM, CDMA, etc.; it can also be a Wifi chip; it can also be a Bluetooth chip.

[0151] In this embodiment, the processor 1302 can be implemented in any suitable manner. For example, the processor can take the form of, for example, a microprocessor or a processor, and a computer-readable medium storing computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, application specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers, etc. This specification does not make any limitations.

[0152] In this embodiment, the memory 1303 can include multiple levels. In a digital system, anything that can store binary data can be a memory; in an integrated circuit, a circuit without a physical form but with a storage function is also called a memory, such as RAM, FIFO, etc.; in a system, a storage device with a physical form is also called a memory, such as a memory module, a TF card, etc.

[0153] Another server is also provided in an embodiment of this specification, including a processor and a memory for storing executable instructions of the processor. When specifically implemented, the processor may execute the following steps according to the instructions: According to the preset protocol rules and the ciphertext data of the previous comparison result, perform corresponding translation operations on the ciphertext data of the previous first data group and the ciphertext data of the previous second data group to obtain the ciphertext data of the current first data group and the ciphertext data of the current second data group; According to the preset protocol rules, extract the elements at the preset positions from the ciphertext data of the current first data group as the ciphertext data of the current first data; Extract the elements at the preset positions from the ciphertext data of the current second data group as the ciphertext data of the current second data; According to the preset protocol rules, call the preset comparison function to process the ciphertext data of the current first data and the ciphertext data of the current second data to obtain the ciphertext data of the current comparison result; According to the ciphertext data of the current comparison result, save one of the ciphertext data of the current first data and the ciphertext data of the current second data in the target data group to obtain a target sequence group containing the ciphertext data of the first data and the ciphertext data of the second data arranged according to the preset sorting rules.

[0154] An embodiment of this specification also provides a computer storage medium based on the above data processing method. The computer storage medium stores computer program instructions, and when the computer program instructions are executed, it realizes: obtaining a target sequence group; wherein, the target sequence group contains the ciphertext data of the first data and the ciphertext data of the second data arranged according to the preset sorting rules; the target sequence group is obtained by the first data party holding the first data and the second data party holding the second data through joint sorting according to the preset protocol rules; according to the preset binning rules, perform binning processing on the target sequence group to obtain a plurality of data bins; according to the plurality of data bins, determine the information value regarding the combined first data and second data.

[0155] The embodiments of this specification also provide a computer storage medium based on the above privacy protection data sorting method. The computer storage medium stores computer program instructions, which when executed implement: according to the preset protocol rules and the ciphertext data of the previous comparison result, by performing corresponding translation operations on the ciphertext data of the first data group and the ciphertext data of the second data group of the previous time, to obtain the ciphertext data of the first data group and the ciphertext data of the second data group of the current time; according to the preset protocol rules, extract the elements at the preset positions from the ciphertext data of the first data group of the current time as the ciphertext data of the first data of the current time; extract the elements at the preset positions from the ciphertext data of the second data group of the current time as the ciphertext data of the second data of the current time; according to the preset protocol rules, call a preset comparison function to process the ciphertext data of the first data of the current time and the ciphertext data of the second data of the current time to obtain the ciphertext data of the current comparison result; according to the ciphertext data of the current comparison result, save one of the ciphertext data of the first data of the current time and the ciphertext data of the second data of the current time in the target data group, so as to obtain a target sequence group containing the ciphertext data of the first data and the ciphertext data of the second data arranged according to the preset sorting rules.

[0156] In this embodiment, the above storage medium includes but is not limited to Random Access Memory (RAM), Read-Only Memory (ROM), Cache, Hard Disk Drive (HDD), or Memory Card. The memory can be used to store computer program instructions. The network communication unit can be set according to the standards specified by the communication protocol and is used for the interface of network connection communication.

[0157] In this embodiment, the functions and effects specifically implemented by the program instructions stored in the computer storage medium can be explained in comparison with other embodiments and will not be elaborated here.

[0158] Refer to Figure 14 As shown, at the software level, the embodiments of this specification also provide a data processing device, which specifically may include the following structural modules:

[0159] An acquisition module 1401, which specifically can be used to acquire a target sequence group; wherein, the target sequence group contains the ciphertext data of the first data and the ciphertext data of the second data arranged according to the preset sorting rules; the target sequence group is obtained by the first data party holding the first data and the second data party holding the second data through joint sorting according to the preset protocol rules;

[0160] The binning module 1402 can be specifically used to perform binning processing on the target sequence group according to the preset binning rules to obtain multiple data bins;

[0161] The determination module 1403 can be specifically used to determine the information values of the first data and the second data according to the multiple data bins.

[0162] An embodiment of this specification also provides a data sorting device based on privacy protection, which may specifically include the following structural modules:

[0163] The operation module can be specifically used to perform corresponding translation operations on the ciphertext data of the first data group and the ciphertext data of the second data group in the previous time according to the preset protocol rules and the ciphertext data of the comparison result in the previous time, so as to obtain the ciphertext data of the first data group and the ciphertext data of the second data group in the current time;

[0164] The extraction module can be specifically used to extract the elements at the preset positions from the ciphertext data of the first data group in the current time according to the preset protocol rules as the ciphertext data of the first data in the current time; extract the elements at the preset positions from the ciphertext data of the second data group in the current time as the ciphertext data of the second data in the current time;

[0165] The calling module can be specifically used to call a preset comparison function to process the ciphertext data of the first data and the ciphertext data of the second data in the current time according to the preset protocol rules to obtain the ciphertext data of the comparison result in the current time;

[0166] The saving module can be specifically used to save one of the ciphertext data of the first data and the ciphertext data of the second data in the current time in the target data group according to the ciphertext data of the comparison result in the current time, so as to obtain a target sequence group containing the ciphertext data of the first data and the ciphertext data of the second data arranged according to the preset sorting rules.

[0167] It should be noted that the units, devices or modules described in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. For the convenience of description, when describing the above devices, they are divided into various modules according to functions and described separately. Of course, when implementing this specification, the functions of each module can be implemented in the same or multiple software and / or hardware, or the modules implementing the same function can be implemented by a combination of multiple sub-modules or sub-units, etc. The device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the couplings or direct couplings or communication connections shown or discussed with each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be electrical, mechanical or other forms.

[0168] As can be seen from the above, based on the data sorting device provided in the embodiments of this specification, it is possible to achieve the joint sorting of data from multiple data parties for horizontal joint use with a relatively low data processing volume and processing complexity while protecting the data privacy of the data party, and obtain the required rich and ordered target sequence group, avoiding data leakage during the sorting process and effectively protecting the data security of the data party.

[0169] Although this specification provides method operation steps as described in the embodiments or flowcharts, there may be more or fewer operation steps based on conventional or non-creative means. The step order listed in the embodiments is only one of the many step execution orders and does not represent the only execution order. When the actual device or client product is executed, it can be executed in the method order shown in the embodiments or the drawings or in parallel (such as in a parallel processor or multi-threaded processing environment, or even in a distributed data processing environment). The term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, product or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, product or device. Without further limitation, there is no exclusion of additional identical or equivalent elements in the process, method, product or device including the said elements. The words such as first, second, etc. are used to represent names and do not represent any specific order.

[0170] Those skilled in the art also know that, in addition to implementing the controller in the form of pure computer-readable program code, the method steps can be logically programmed to enable the controller to implement the same functions in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, embedded microcontrollers, etc. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be regarded as the structures within the hardware component. Or even, the devices for implementing various functions can be regarded as either software modules for implementing the method or structures within the hardware component.

[0171] This specification can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, classes, etc. that perform specific tasks or implement specific abstract data types. This specification can also be practiced in a distributed computing environment, where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.

[0172] From the description of the above embodiments, those skilled in the art can clearly understand that this specification can be implemented by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solutions of this specification can essentially be embodied in the form of a software product, which can be stored in a storage medium such as ROM / RAM, magnetic disk, optical disc, etc., and includes several instructions to enable a computer device (which can be a personal computer, mobile terminal, server, or network device, etc.) to execute the methods described in various embodiments or some parts of the embodiments of this specification.

[0173] The various embodiments in this specification are described in a progressive manner. For the same or similar parts between the various embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. This specification can be used in numerous general or special computer system environments or configurations. For example: personal computers, server computers, handheld devices or portable devices, tablet devices, multi-processor systems, microprocessor-based systems, set-top boxes, programmable electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, etc.

[0174] Although this specification is depicted through embodiments, those of ordinary skill in the art know that this specification has many variations and changes without departing from the spirit of this specification, and it is hoped that the appended claims will cover these variations and changes without departing from the spirit of this specification.

Claims

1. A data sorting method based on privacy protection, characterized in that, Applied to a computing node, including: According to the preset protocol rules and the ciphertext data of the previous comparison result, by performing corresponding translation operations on the ciphertext data of the previous first data group and the ciphertext data of the previous second data group, to obtain the ciphertext data of the current first data group and the ciphertext data of the current second data group; According to the preset protocol rules, extract the elements at the preset positions from the ciphertext data of the current first data group as the ciphertext data of the current first data; extract the elements at the preset positions from the ciphertext data of the current second data group as the ciphertext data of the current second data; According to the preset protocol rules, call a preset comparison function to process the ciphertext data of the current first data and the ciphertext data of the current second data, to obtain the ciphertext data of the current comparison result; According to the ciphertext data of the current comparison result, save one of the ciphertext data of the current first data and the ciphertext data of the current second data in the target data group, to obtain a target sequence group containing the ciphertext data of the first data and the ciphertext data of the second data arranged according to the preset sorting rules.

2. The method according to claim 1, wherein According to the preset protocol rules and the ciphertext data of the previous comparison result, by performing corresponding translation operations on the ciphertext data of the previous first data group and the ciphertext data of the previous second data group, to obtain the ciphertext data of the current first data group and the ciphertext data of the current second data group, including: According to the preset protocol rules, perform a translation operation on the ciphertext data of the previous first data group to obtain the translated ciphertext data of the previous first data group; perform a translation operation on the ciphertext data of the previous second data group to obtain the translated ciphertext data of the previous second data group; According to the preset protocol rules, call a preset first selection function, and according to the ciphertext data of the previous comparison result, determine the ciphertext data of the current first data group from the ciphertext data of the previous first data group and the translated ciphertext data of the previous first data group; call a preset second selection function, and according to the ciphertext data of the previous comparison result, determine the ciphertext data of the current second data group from the ciphertext data of the previous second data group and the translated ciphertext data of the previous second data group.

3. The method according to claim 2, wherein According to the preset protocol rules, perform a translation operation on the ciphertext data of the previous first data group to obtain the translated ciphertext data of the previous first data group, including: According to the preset protocol rules, translate the elements included in the ciphertext data of the previous first data group by one data bit along the preset direction to obtain the translated ciphertext data of the previous first data group.

4. The method according to claim 1, characterized in that The preset protocol rules include protocol rules based on secure multi-party computation and secret sharing.

5. The method according to claim 1, wherein Before, according to the preset protocol rules and the ciphertext data of the previous comparison result, by performing corresponding translation operations on the ciphertext data of the previous first data group and the ciphertext data of the previous second data group, the method further includes: Receive the ciphertext data of the first data group and the ciphertext data of the second data group; wherein, the ciphertext data of the first data group is obtained by the first data party arranging the first data it holds according to a preset sorting rule and performing encryption processing according to a preset protocol rule; the ciphertext data of the second data group is obtained by the second data party arranging the second data it holds according to a preset sorting rule and performing encryption processing according to a preset protocol rule.

6. The method according to claim 5, wherein The first data party includes a first physical examination institution, and the second data party includes a second physical examination institution; correspondingly, the first data includes the numerical physical examination parameters of the first sample object held by the first physical examination institution, and the second data includes the same type of numerical physical examination parameters of the second sample object held by the second physical examination institution.

7. The method according to claim 5, characterized in that, After receiving the ciphertext data of the first data group and the ciphertext data of the second data group, the method further includes: In response to a joint sorting request, according to a preset protocol rule, extract the element at a preset position from the ciphertext data of the first data group as the ciphertext data of the first data for the current time; extract the element at a preset position from the ciphertext data of the second data group as the ciphertext data of the second data for the current time; According to a preset protocol rule, call a preset comparison function to process the ciphertext data of the first data for the current time and the ciphertext data of the second data for the current time, and obtain the ciphertext data of the comparison result for the current time.

8. The method according to claim 5, wherein The received ciphertext data of the first data group also carries the first length information of the ciphertext data of the first data group; the received ciphertext data of the second data group also carries the second length information of the ciphertext data of the second data group.

9. The method according to claim 8, wherein Before performing corresponding translation operations on the ciphertext data of the previous first data group and the ciphertext data of the previous second data group according to a preset protocol rule and the ciphertext data of the previous comparison result, the method further includes: Detect whether the current length of the target data group is equal to a preset length threshold; wherein, the preset length threshold is determined according to the first length information and the second length information; In the case where it is detected that the current length of the target data group is equal to the preset length threshold, determine the target data group as the target sequence group.

10. The method according to claim 1, wherein The ciphertext data saved in the target data group also carries a position tag, and the position tag is used to represent the sorting position of the ciphertext data in the target data group.

11. A data sorting device based on privacy protection, characterized in that, Applied to a computing node, including: An operation module, configured to, according to a preset protocol rule and the ciphertext data of the previous comparison result, perform corresponding translation operations on the ciphertext data of the previous first data group and the ciphertext data of the previous second data group to obtain the ciphertext data of the first data group for the current time and the ciphertext data of the second data group for the current time; An extraction module, configured to, according to a preset protocol rule, extract the element at a preset position from the ciphertext data of the first data group for the current time as the ciphertext data of the first data for the current time; extract the element at a preset position from the ciphertext data of the second data group for the current time as the ciphertext data of the second data for the current time; A calling module, configured to call a preset comparison function to process the ciphertext data of the first data of the current time and the ciphertext data of the second data of the current time according to preset protocol rules, so as to obtain the ciphertext data of the comparison result of the current time; A saving module, configured to save one of the ciphertext data of the first data of the current time and the ciphertext data of the second data of the current time in a target data group according to the ciphertext data of the comparison result of the current time, so as to obtain a target sequence group including the ciphertext data of the first data and the ciphertext data of the second data arranged according to preset sorting rules.

12. A server, characterized in that, It includes a processor and a memory for storing processor-executable instructions, and when the processor executes the instructions, the steps of the method according to any one of claims 1 to 10 are implemented.

13. A computer-readable storage medium, characterized in that, Computer instructions are stored thereon, and when the instructions are executed, the steps of the method according to any one of claims 1 to 10 are implemented.

Citation Information

Patent Citations

  • Data binning method, device and equipment and computer readable storage medium

    CN110704535A

  • Data processing method and device, and device for data processing

    CN112685747A