Business Collaboration Processing Method, Device, Medium and Equipment Based on Privacy Protection
By adjusting the initial target privacy sequence and processing the ciphertext, the leakage of privacy data in service collaborative processing is solved, efficient data collaborative processing under privacy protection is achieved, and communication complexity is reduced.
Patent Information
- Application Number
- CN202111580179.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-22
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2041-12-22
AI Technical Summary
In business collaborative processing, how to achieve privacy protection under multi-party computing without revealing the specific content and location adjustment methods of privacy data, especially in the process of AI training and data collaborative prediction, to ensure data privacy.
By using the position disruption algorithm to adjust the initial target privacy sequence, generate intermediate target privacy sequence shards, and use coordinated public sequences to perform position updates to realize business collaborative processing, ensuring data transmission and processing in ciphertext form, reducing the complexity of communication volume and communication rounds.
It realizes that without leaking private data content and location adjustment methods, completes business collaborative processing, protects data privacy, and greatly reduces the communication volume and communication round complexity.
Smart Images

Figure CN114254358B_ABST
Abstract
Description
Technical Field
[0001] This specification is applied to the technical field of business collaboration processing, and specifically relates to a method, device, medium, and equipment for business collaboration processing based on privacy protection. Background Art
[0002] Secure Multi-Party Computation (MPC for short) mainly solves the problem of how more than two participating parties can successfully complete a calculation without revealing their respective inputs to each other. The current application prospect of MPC is becoming more and more extensive, and the demand for business collaboration among enterprises, units, and individuals is becoming increasingly strong. A typical scenario is that during the rapid development of artificial intelligence, the need for data privacy is becoming more intense. The data required for AI training cannot be obtained in many business scenarios due to privacy compliance reasons, resulting in the inability to complete training or very poor training effects. Privacy AI is trying to use MPC to solve the privacy protection problem in AI training, that is, how to complete collaborative training and collaborative prediction without directly exposing the plaintext data of the data parties involved in AI training. Summary of the Invention
[0003] The purpose of the embodiments of this specification is to provide a method, device, medium, and equipment for business collaboration processing based on privacy protection, which can further achieve the purpose of privacy protection for business collaboration processing.
[0004] This specification provides a method, device, medium, and equipment for business collaboration processing based on privacy protection, which is implemented in the following ways:
[0005] A method for business collaboration processing based on privacy protection, which is applied to a designated business party for business collaboration processing. The method includes: obtaining a coordinated public sequence; the coordinated public sequence refers to the sequence publicly disclosed by the business party holding the basic privacy sequence after processing the coordinated privacy sequence using a position scrambling algorithm; the coordinated privacy sequence is used to represent the element position adjustment method of the basic privacy sequence in ciphertext form; using the position scrambling algorithm to scramble the positions of the elements in each slice of the initial target privacy sequence held by the designated business party in the initial target privacy sequence, obtaining an intermediate target privacy sequence slice; using the element value at any position in the coordinated public sequence to represent the position identifier of the element at the corresponding position in the intermediate target privacy sequence being reconfigured, and performing position adjustment on the intermediate target privacy sequence slice to obtain a target privacy sequence slice with updated positions; jointly with other business parties in business collaboration processing, at least using the target privacy sequence slices with updated positions held by each business party to perform business collaboration processing under privacy protection.
[0006] In some other embodiments, the coordinated privacy sequence is constructed by the service party holding the basic privacy sequence in the following manner: obtaining an initial coordination sequence, where the position identifier of the initial coordination sequence is the same as that of the basic privacy sequence, and the element value at any position in the initial coordination sequence is configured as the ciphertext form of the position identifier at the corresponding position; performing position adjustment on the initial coordination sequence based on the element position adjustment method of the basic privacy sequence to obtain the coordinated privacy sequence.
[0007] In some other embodiments, when the basic privacy sequence is jointly executed for position adjustment by two or more service parties, the coordinated public sequence is constructed by the service party holding the shard of the basic privacy sequence in the following manner: obtaining an initial coordination sequence shard, where the position identifier in the initial coordination sequence shard is the same as that of the shard of the basic privacy sequence held by the service party, and the element value at any position in the initial coordination sequence shard is configured as the ciphertext form of the position identifier at the corresponding position; performing position adjustment on the initial coordination sequence shard based on the element position adjustment method of the shard of the basic privacy sequence held by the service party to obtain the coordinated privacy sequence shard; using a position shuffling algorithm to shuffle the positions of the elements in the coordinated privacy sequence shard, and taking the shard obtained after the shuffling process as the coordinated public sequence shard for public disclosure; obtaining the coordinated public sequence shards publicly disclosed by other service parties holding the basic privacy sequence, and combining the coordinated public sequence shards to obtain the coordinated public sequence.
[0008] In some other embodiments, the position shuffling algorithm includes the shuffle algorithm.
[0009] On the other hand, this specification also provides a business collaboration processing device based on privacy protection, which is applied to a designated business party for business collaboration processing. The device includes: a public sequence acquisition module, configured to acquire a coordinated public sequence; the coordinated public sequence refers to the sequence publicly disclosed by the business party holding the basic privacy sequence after processing the coordinated privacy sequence using a position scrambling algorithm; the coordinated privacy sequence refers to the sequence used by the business party holding the basic privacy sequence to represent the element position adjustment method of the basic privacy sequence in ciphertext form; a first position adjustment module, configured to use the position scrambling algorithm to scramble the positions of the elements in the initial target privacy sequence shards held by the designated business party in the initial target privacy sequence, to obtain intermediate target privacy sequence shards; a second position adjustment module, configured to use the element value at any position in the coordinated public sequence to represent the position identifier at which the element at the corresponding position in the intermediate target privacy sequence is reconfigured, and perform position adjustment on the intermediate target privacy sequence shards held by the designated business party, to obtain the target privacy sequence shards with updated positions; a collaboration processing module, configured to collaborate with other business parties in business collaboration processing, and at least perform business collaboration processing under privacy protection using the target privacy sequence shards with updated positions held by each business party.
[0010] In some other embodiments, the coordinated privacy sequence is constructed by the business party holding the basic privacy sequence in the following manner: acquiring an initial coordinated sequence, where the position identifier of the initial coordinated sequence is the same as that of the basic privacy sequence, and the element value at any position in the initial coordinated sequence is configured as the ciphertext form of the position identifier at the corresponding position; performing position adjustment on the initial coordinated sequence based on the element position adjustment method of the basic privacy sequence, to obtain the coordinated privacy sequence.
[0011] In some other embodiments, when the basic privacy sequence is adjusted in position by two or more service parties including the specified service party in a collaborative manner, the device further includes a coordinated public sequence construction module; wherein, the coordinated public sequence construction module includes: an initial coordinated sequence acquisition unit, configured to acquire an initial coordinated sequence shard, where the position identifier in the initial coordinated sequence shard is the same as the position identifier of the basic privacy sequence shard held by the service party, and the element value at any position in the initial coordinated sequence shard is configured as the ciphertext form of the position identifier at the corresponding position; a position adjustment unit, configured to perform position adjustment on the initial coordinated sequence shard based on the element position adjustment method of the basic privacy sequence shard held by the service party to obtain a coordinated privacy sequence shard; a position shuffling unit, configured to use a position shuffling algorithm to shuffle the positions of the elements in the coordinated privacy sequence shard, and use the shuffled shard as a coordinated public sequence shard; a public unit, configured to publicly disclose the coordinated public sequence shard; and a sequence shard combination unit, configured to acquire the coordinated public sequence shards publicly disclosed by other service parties holding the basic privacy sequence, and combine the coordinated public sequence shards to obtain a coordinated public sequence.
[0012] In some other embodiments, the position shuffling algorithm includes the shuffle algorithm.
[0013] On the other hand, an embodiment of this specification further provides a computer-readable storage medium, on which computer instructions are stored, and when the instructions are executed by a processor, the steps of the method described in any one or more of the above embodiments are implemented.
[0014] On the other hand, an embodiment of this specification further provides a computer device, including a memory, a processor, and computer instructions stored on the memory, and the processor executes the computer instructions to implement the steps of the method described in any one or more of the above embodiments.
[0015] The method, device, medium, and equipment for service collaborative processing based on privacy protection provided by one or more embodiments of this specification can complete the process of adjusting the position of the target privacy sequence according to the element position adjustment method of the basic privacy sequence without exposing the specific content and the element position adjustment method of the basic privacy sequence, and realize service collaborative processing based on privacy protection. At the same time, during the collaborative position adjustment process, the service parties only need to transmit the coordinated public sequence shards once, achieving a communication volume complexity of O(n) and a communication round complexity of O(1), greatly reducing the communication volume complexity and the communication round complexity of service collaborative processing based on privacy protection. Description of the Drawings
[0016] To more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in this specification. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings. In the drawings:
[0017] Figure 1 Schematic diagram of the position collaborative rearrangement of the target privacy sequence provided by this specification;
[0018] Figure 2 Schematic diagram of the position collaborative rearrangement of the basic privacy sequence provided by this specification;
[0019] Figure 3 Schematic diagram of the circular shift during the execution of the position collaborative rearrangement provided by this specification;
[0020] Figure 4 Schematic diagram of the sequence expansion during the execution of the position collaborative rearrangement provided by this specification;
[0021] Figure 5 Schematic diagram of the interaction process of service collaborative processing based on privacy protection provided by this specification;
[0022] Figure 6 Schematic diagram of the position collaborative rearrangement of the standard privacy sequence provided by this specification;
[0023] Figure 7 Schematic diagram of the implementation process of the method for service collaborative processing based on privacy protection provided by this specification;
[0024] Figure 8 Schematic diagram of the construction of the coordinated privacy sequence for multi-party collaborative position rearrangement provided by this specification;
[0025] Figure 9 Schematic diagram of the module structure of the service collaborative processing module based on privacy protection provided by this specification;
[0026] Figure 10 Schematic diagram of the module structure of the computer device provided by this specification. Detailed implementation manners
[0027] To enable those skilled in the art to better understand the technical solutions in this specification, the following will clearly and completely describe the technical solutions in one or more embodiments of this specification in conjunction with the accompanying drawings in one or more embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of the specification, rather than all the embodiments. Based on one or more embodiments of the specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of the embodiments of the specification.
[0028] The solutions provided in the embodiments of this specification can be applied to each business party in business collaboration processing. Each business party in the business collaboration processing can be, for example, a device corresponding to an enterprise, a unit, an individual, etc. In view of the differences among the business parties involved in the business collaboration processing, the plaintext data of each business party involved in the business collaboration processing needs to be protected for privacy and cannot be directly exposed to other business parties. Under this business application requirement, the business collaboration processing based on privacy protection that can be generated includes, for example, model collaborative training and collaborative prediction based on privacy protection, business collaboration data analysis based on privacy protection, and so on.
[0029] In a scenario example, assume that the business parties in the business collaboration processing are P1 and P2. Each business party can respectively read business data from the corresponding business system and perform business collaboration processing based on multi-party secure computing. Of course, in the process of business collaboration processing, a coordination service device may also be involved. This coordination service device can communicate with the devices of each business party to execute processing instructions and the like involved in relaying or unifying the business collaboration processing.
[0030] In the business processing processes such as model collaborative training and collaborative prediction based on privacy protection, and business collaboration data analysis based on privacy protection, the collaborative adjustment of the business data positions of each business party is one of the business processing sub-links that are usually involved in many business collaboration processing processes. Therefore, how to process the collaborative adjustment of business data positions based on privacy protection is very crucial for business collaboration processing. And in the process of collaborative adjustment of business data positions based on privacy protection, it is necessary to adjust the position of the privacy sequence without revealing the specific data content of the privacy sequence and without revealing the position adjustment method, so as to protect the privacy of the business data involved in the business collaboration processing as much as possible.
[0031] For example, in the process of executing business collaboration processing, it involves that business party P1 holds business data of some business types and business party P2 holds business data of another part of business types. It is necessary to comprehensively utilize the business data held by the two business parties to collaboratively complete business processing. For example, in the process of user risk prediction, it involves the situation where business party P1 holds user commodity transaction data and business party P2 holds basic user account information. In the process of risk prediction, it is necessary to comprehensively use user commodity transaction data and basic user account information to achieve user risk prediction. However, in the process of user risk prediction based on privacy protection, it is necessary to ensure that in the process of user risk prediction, the user commodity transaction data held by business party P1 and the basic user account information held by business party P2 do not leave the local devices of each business party, and there is no risk of indirect leakage, so as to protect the privacy of user data to the greatest extent. Correspondingly, the user risk prediction model needs to be collaboratively completed by the two business parties under privacy protection.
[0032] In the process of constructing a user risk prediction model, it usually involves sorting the elements involved in the feature vector to perform model training processing based on the sorted feature vector. For example, when training a user risk prediction model, business parties P1 and P1 respectively hold partial information of the feature vector (user transaction feature information, user account feature information). For the sake of easy expression, the partial feature information held by each business party can be described as a feature vector shard. In the process of model training, the feature vector shards held by each business party can be encrypted locally in advance to obtain privacy sequence shards representing the feature vector shards in ciphertext form, so as to further protect the privacy of the feature data in the model training process. For example, a homomorphic encryption algorithm can be used to encrypt the feature vector shards, so that the result obtained by performing a certain operation on the ciphertext data is exactly equal to the ciphertext obtained by encrypting the expected operation on the plaintext data before encryption.
[0033] As Figure 1 shown, assume that shard A 1 and A 2 are respectively the ciphertext forms of the initial feature vector shards input during business model training. Array A is the combined form of A 1 and A 2 . It should be noted that Figure 1 the array A shown in is the combined form of each shard directly given for easy display. In fact, the array A corresponding to shards A 1 and A 2 of business parties P1 and P2 are respectively stored locally in business parties P1 and P2 and will not leave business parties P1 and P2.
[0034] In the case where the business model training involves adjusting the positions of the elements in the feature vector, it is necessary for business parties P1 and P2 to cooperate to adjust the positions of the elements in array A to obtain array A'. For example, as Figure 2 shown, each business party can respectively construct one-hot vectors A _index , B _index , and then, based on the one-hot vectors, cooperate to complete the overall position adjustment of A 1 , A 2 . It should be noted that for the sake of convenience of explanation, Figure 2 , Figure 3 the one-hot vectors shown are in plaintext form. In actual applications, the one-hot vectors exist in ciphertext form. For example, the one-hot vectors can be encrypted using a homomorphic encryption algorithm to obtain the ciphertext form of the one-hot vectors.
[0035] Each business party can respectively calculate the inner products of one-hot vectors A _index , B _index with A 1 , A 2 , and extract the corresponding elements of A 1 , A 2 . For example, by calculating the inner product of A _index and A 1 , the first element of A 1 can be extracted, and the same applies to A 2 . After extraction, a comparison can be made b = private_compare(11, 10) to obtain the comparison result b. The value of b is 1 or 0. For example, it can be set that if the element extracted from A 1 is larger than the element extracted from A 2 , then b takes 1; if the element extracted from A 1 is smaller than the element extracted from A 2 , b takes 0. It can also be set that if the element extracted from A 2 is larger than the element extracted from A 1 , then b takes 1; if the element extracted from A 2 is smaller than the element extracted from A 1 , b takes 0. Then, based on the comparison result b, a selection can be made between 10 and 11 in ciphertext, res = private_select(11, 10, b), to select which of the elements 10 and 11 is configured as the position identifier 1 of the new array A'.
[0036] Next, the subscript of A 2 is moved to the right to extract its second element and participate in the next round of comparison. The problem is that if B _index is directly operated on, it is obvious that it is telling others that the previous comparison result is A 2The elements are small, so in this round of loop, update B _index The process of... leaks information about the relative size of the data. Therefore, as Figure 3 shown, it is possible to additionally generate shifted one-hot vectors A _next_index and B _next_index . The generation method is that business parties P1 and P2 respectively perform circular shifts on A _index , B _index locally. For example, the last bit of A _index or B _index can be moved to its beginning, and this operation does not leak information. Of course, the first bit of A _index or B_index can also be moved to its end, etc., and the operation method can be changed according to needs.
[0037] After that, according to the comparison result b obtained, a ciphertext-based selection can be made between A _index and A _next_index : A _index = private_select(A _index , A _next_index , 1 - b). The selected one is the vector for taking the inner product with A 1 to remove elements in the next round. Whether it is A _index or A _next_index , as well as private_select, are all performed under ciphertext, so no information is exposed. Similarly, the same operation can be performed on B _index and B _next_index . In this way, since the selection result is also in ciphertext, it does not reveal whether A _index is shifted to the right or B _index is shifted to the right, nor does it reveal whether A _index is not shifted to the right or B _index is not shifted to the right. Then the loop can be repeated again, taking out elements and comparing, and so on.
[0038] Since when traversing A 1 and A 2 , there may be a situation where one shard finishes traversing first. In this case, even using the previous scheme will expose information: the elements of the remaining shard are relatively large. Therefore, for this situation, as Figure 4 shown, at least two positions can be added after A 1 and A 2 , and the value of float64_max is configured at these two added positions, so that A _index or B _indexWhen moving to point to the max value, the dot product extracts the max value. When comparing again, it will never be smaller than other numbers, thus making A _index or B _index will no longer move to the right, thus avoiding exposing that the elements of the remaining shard are relatively large, further achieving the purpose of privacy protection.
[0039] Through the above-mentioned position adjustment method, business parties P1 and P2 respectively locally implement the adjustment of the positions of each element in A 1 and A 2 That is, locally record the position information of each element in A 1 and A 2 after the adjustment of each element, so that overall it is equivalent to realizing the reordering of the array A to obtain A'. After that, the training of the user risk prediction model can be performed based on the array A' to obtain the user risk prediction model.
[0040] As the business system architecture becomes more and more complex, many large enterprises execute the training, testing, and release and use of business models by deploying a business model release pipeline to achieve decoupling of each link and improve the flexibility of the business model from training to use. For example, a business model construction subsystem, a testing subsystem, a usage subsystem, etc. can be deployed in the business system. Correspondingly, the testing subsystem and the usage subsystem can only obtain the model structure parameters of the business model and cannot obtain the sample set used in the construction process of the business model to further ensure the privacy of business data. Correspondingly, when testing the constructed business model, the testing subsystem may need to know the initial arrangement method of the elements in the feature vector to realize the test analysis of the business model architecture and the training process. Correspondingly, the testing subsystems of different business parties need to cooperate to restore the initial arrangement method of each element in the feature vector input to the business model based on the arrangement method of the feature vector elements under the constructed business model.
[0041] Correspondingly, in this scenario example, during the above-mentioned process of adjusting the position of the array A, the array I can be further introduced. For the convenience of distinction and description, the array A can be described as the basic privacy sequence, and the array I can be described as the initial coordination sequence. Among them, the position identifier of the initial coordination sequence is the same as that of the basic privacy sequence, and the element value at any position in the initial coordination sequence is configured as the ciphertext form of the position identifier of the corresponding position.
[0042] In this scenario example, P1 and P2 can first cooperate to configure position identifiers for the array A, that is, for A 1 and A 2 configure position identifiers. Such as Figure 1As shown, assuming that after the position identifier configuration is completed, the position identifiers of A are 1, 2, …, 9 from left to right, then the position identifiers of array I are also 1, 2, …, 9 from left to right, and the element values at each position identifier are also 1, 2, …, 9 from left to right. Of course, if the position identifier of array A starts from zero, such as 0, 1, …, 8 from left to right, then the position identifiers and element values of array I are also 0, 1, …, 8 from left to right. Of course, the above configuration of the position identifier of the basic privacy sequence is only a preferred example for illustration, and those skilled in the art can also make changes according to needs. For example, the feature type identifier can be used as the position identifier, etc.
[0043] Given that A 1 and A 2 are distributed among different business parties, and array I is configured corresponding to the shards A 1 、A 2 held by the business parties. Therefore, in fact, array I also includes shards I 1 、I 2 distributed among two business parties P1 and P2, corresponding to A 1 、A 2 respectively. Figure 1 In [reference document], array I is shown in plaintext. In fact, each shard of array I is also stored locally in each business party in ciphertext form. For example, a homomorphic encryption algorithm can be used to encrypt each shard of array I so that the result obtained by performing a certain operation on the ciphertext data is exactly equal to the ciphertext obtained by encrypting the data after performing the expected operation on the data before encryption.
[0044] Business parties P1 and P2 can cooperate to change array I to array I′ based on the same element position adjustment method as array A. In the above scenario example, since in the process of changing array A to array A′, its essence is completed through private_select. For example, the first element of array A′ is selected between 11 and 10. Therefore, array I can be changed to array I′ through the same selection and movement. That is, in the sorting process, another initial coordination array I is introduced, and according to the comparison results in the sorting process, each business party performs the same operations on the shards of the initial coordination array I it holds as on the shards of the array A it holds to obtain array I′. The specific implementation method refers to the above sorting implementation process of array A and will not be elaborated here. It should be noted that Figure 1 the array I′ shown in [reference document] is an example display for easy explanation. In fact, each business party locally adjusts the positions of the elements in the shards I 1 、I 2 it holds and locally records the shards I 1 、I 2The adjusted position information of each element in, so as to achieve, in shard I 1 , I 2 On the basis that each element of does not leave business parties P1 and P2, overall, it is equivalent to realizing the change of array I to array I'.
[0045] For example Figure 1 As shown, in plaintext display, after the position of array A is adjusted, the element at position identifier 1 of array A' is the element "10" at position identifier 5 of array A. Correspondingly, the element value at position identifier 1 of array I' corresponds to position identifier 5 of array A; the element at position identifier 2 of array A' is the element "11" at position identifier 1 of array A. Correspondingly, the element value at position identifier 2 of array I' corresponds to position identifier 1 of array A; and so on. In plaintext display, the element value at each position in array I' is the position identifier of the element to which array A is adjusted to the corresponding position.
[0046] It should be noted that Figure 1 The array I' and I' shown in new are also displayed in plaintext. However, in actual applications, since array I exists in ciphertext form, and in the process of changing array I to array I' and I' new , there is no processing of the element values of array I. Therefore, I' and I' new also exist in ciphertext form. Correspondingly, in actual applications, the element values at each position in array I' can be used to represent the position identifier of the element to which array A is adjusted to the corresponding position in ciphertext form. For the convenience of distinction and description, array I' can be described as a coordinated privacy sequence. Correspondingly, shard I 1 , I 2 The shard information formed after the above position adjustment can be described as the coordinated privacy sequence shard corresponding to shard I 1 , I 2 .
[0047] After obtaining array I', business parties P1 and P2 can further cooperate to perform a shuffle transformation on the positions of each element of array I'. Figure 1 The shuffle process shown in is to move the first three elements of array I' to the end, so as to shuffle the position information of the elements of array I'. Of course, this shuffle processing example is only for illustration, and can be configured according to needs during specific implementation. For example Figure 1As shown in the figure, after the business party P1 performs a shuffle transformation on the coordinated privacy sequence shards it holds, the obtained position information is as follows: the position identifier of element "1" is 8, the position identifier of element "2" is 9, the position identifier of element "3" is 3, and the position identifier of element "4" is 5. After the business party P2 shuffles the element positions of the coordinated privacy sequence shards it holds, the obtained position information is as follows: the position identifier of element "5" is 7, the position identifier of element "6" is 1, the position identifier of element "7" is 2, the position identifier of element "8" is 4, and the position identifier of element "9" is 6. The business parties P1 and P2 can locally record the position information of each element in the array I' after the element positions are scrambled.
[0048] During the above processing, when the values of the corresponding elements in the array I' exist in ciphertext form, I' will not disclose the specific content of the position identifiers of the array A; further, after shuffling the positions of each element in I', it is also possible to avoid exposing the position information of each element in the array I', so that the element position adjustment method of the array A cannot be deduced based on the sequence shards obtained after the shuffle transformation. Correspondingly, each business party can publicly disclose the sequence shards obtained after performing a shuffle transformation on the coordinated privacy sequence shards it holds. The publicly disclosed sequence shard information will not expose the specific content of the position identifiers of the underlying privacy sequence shards held by each business party, nor will it disclose the element position adjustment method of each element in the underlying privacy sequence shards, ensuring the data privacy of each business party. For the sake of convenience of expression, the sequence shards obtained after the shuffle transformation of the coordinated privacy sequence shards can be described as coordinated public sequence shards.
[0049] The business party P1 (P2) can directly send the coordinated public sequence shards to the business party P2 (P1). The business party P1 (P2) can also send the coordinated public sequence shards to the coordination service device, which forwards them to the business party P2 (P1). Of course, the business party P1 (P2) can also obtain the coordinated public sequence shards publicly disclosed by the business party P2 (P1) through other means.
[0050] The business parties P1 and P2 can obtain the coordinated public sequence shards publicly disclosed by the other business party, and combine the obtained coordinated public sequence shards and the coordinated public sequence shards they hold to obtain I'. new . For the sake of convenience of distinction and expression, the array I' new can be used as the coordinated public sequence.
[0051] During the business model testing stage, the test subsystems of the business parties P1 and P2 can obtain the trained business model and the array I' new , so that they can be based on the array I' newand the initial arrangement of the elements of the business model parameter restoration feature vector.
[0052] It should be noted that this scenario example is to more intuitively compare and demonstrate the reverse process, and still takes the example of obtaining array A by reversely inferring from array A′. In practical applications, when it comes to the privacy of feature data, the test subsystem usually cannot obtain the ciphertext form of the feature data used in model training (array A′). It can only obtain the arrangement of each feature type involved in the feature vector in the business model architecture based on the constructed business model parameters, and then based on array I′ new , inversely deduce the initial arrangement of each feature type involved in the feature vector. By using the public auxiliary array I′ new , the test subsystem can be based on the constructed business model architecture and the public array I′ without knowing the feature information used in business model training. new , and work together to infer the initial arrangement of each feature type involved in the feature vector. And the public array I′ new The specific information of the feature vector and the position adjustment method during business model training are not exposed to the outside world, protecting the privacy of business data involved in the collaborative construction of the business model as much as possible.
[0053] like Figure 5 As shown, business parties P1 and P2 can collaborate to perform shuffle processing on array A′. Then, each business party can new Collaboratively adjust the position of shuffle(A′) so that each business party can new The position inverse adjustment is performed locally on each slice of the array A′ held, and the element position information in the slice held by each business party is restored locally, which is equivalent to performing the position inverse adjustment on the array A′ as a whole to obtain data A.
[0054] like Figure 1 As shown, business parties P1 and P2 can collaborate to perform shuffle transformation on array A′ based on the above shuffle transformation method, and then perform shuffle transformation on array I′ based on the above shuffle transformation method. new Collaboratively perform position adjustment on shuffle(A′). For example, I′ new Business party P1 can obtain I′ new The element value at position 5 is "4", which means that the position of element "98" at position 5 of array shuffle(A') is reconfigured to 4; business party P1 can record array A new The element with position ID 5 is adjusted to position ID 4. Business party P2 can obtain I′ newThe element value "6" at position identifier 1, where "6" means that the position identifier of the element "44" with position identifier 1 in the array shuffle(A′) is reconfigured to 6; business party P2 can record that the adjusted position identifier of the element with position identifier 1 in the array shuffle(A′) is 6. And so on, the position adjustment can be expressed as: A[I′ new [i]] = shuffle(A′)[i]. That is, the element values at any position can represent the position identifiers that the elements of shuffle(A′) at the corresponding positions need to be reconfigured, and the position adjustment is performed on each element position of shuffle(A′) to obtain the array A. new The element value at any position represents the position identifier that the element of shuffle(A′) at the corresponding position needs to be reconfigured, and the position adjustment is performed on each element position of shuffle(A′) to obtain the array A.
[0055] For the convenience of distinction and description, the array A′ can be described as the initial target privacy sequence, and the partial information held by each business party in the array A′ can be described as the initial target privacy sequence shards; the shard information obtained after each business party performs position shuffling on the held initial target privacy sequence shards can be described as the intermediate target privacy sequence shards; the shard information obtained after performing position adjustment on the intermediate target privacy sequence shards based on the array I′ new is described as the target privacy sequence shards after position update.
[0056] In the above processing process, the element information contained in each shard has always been processed locally by each business party and has not left each business party, and the publicly available array I′ new also does not expose the element information of each business party and the position adjustment method, so that the above business collaboration processing process can protect the privacy of the business data involved as much as possible.
[0057] Of course, the implementation manners described in the above scenario examples are only preferred examples for illustration. For example, the position adjustment method of the above array A can also adopt other types of position adjustment methods, but as long as their implemented functions and effects are the same or similar, they should all be covered within the protection scope of this specification. For example, in other scenario examples, it may also involve the situation of performing anti-position adjustment on another array B based on the position adjustment method of the array A, such as Figure 6 shown. First, the position of each element in the array B can be shuffled based on the position shuffling algorithm to obtain B′, and then based on the array I′ new , the position adjustment is performed on B′, B new [I′ new [i]] = B′[i], to obtain B new .
[0058] Based on the above scenario example, an embodiment of this specification provides a business collaboration processing method based on privacy protection, and the method can be applied to a specified business party in business collaboration processing. The specified business party can refer to any one of the business parties involved in business collaboration processing, or can refer to a certain pre-specified business party. As Figure 7 shown, the method may include the following steps.
[0059] S70: Obtain a coordinated public sequence; the coordinated public sequence refers to the sequence publicly disclosed by the business party holding the basic privacy sequence after processing the coordinated privacy sequence using a position scrambling algorithm; the coordinated privacy sequence refers to the sequence used by the business party holding the basic privacy sequence to represent the element position adjustment method of the basic privacy sequence in ciphertext form.
[0060] The business collaboration processing can be a business processing method jointly executed by at least two business parties. As described in the above scenario example, the business collaboration processing can be the collaborative training and testing of a business model jointly executed by business parties P1 and P2. Of course, in other scenario examples, the business collaboration processing can also include other business processing types, such as the collaborative comparison and analysis of business indicators, etc. The business parties involved in business collaboration processing can be two parties or multiple parties. As Figure 8 shown, during the position adjustment process of two parties, the same operation can be performed on array I at the same time, as described above. After multiple pairwise operations, array I' can be obtained. Next, the element positions of array I' can be scrambled and then publicly disclosed.
[0061] In various business processing processes, the business data to be processed can be stored in the form of a sequence. For example, in the above feature vector, each element of the feature vector corresponds to the feature value of a different feature type. Correspondingly, the feature vector can be a set of data sequences at the data level. The values of the elements in the data sequence can be numerical values or characters.
[0062] To facilitate the identification of the positions of the elements in the data sequence during the position adjustment process, position identifiers can be pre-configured for the positions of the elements in the data sequence. As Figure 1 shown, for example, the position identifiers of the elements in the data sequence can be sequentially configured as 1, 2, 3,... from left to right. Of course, the position identifiers of the elements in the data sequence can also be sequentially configured as 0, 1, 2,... from left to right; or, the position identifiers of the elements in the data sequence can be sequentially configured as 0, 1, 2,... from right to left; of course, the position identifiers of the elements in the data sequence can also not increase sequentially from left to right or from right to left, but be randomly determined, or given based on other rules, which are not limited here.
[0063] In the business processing procedures such as collaborative training and collaborative prediction of models based on privacy protection, and data analysis of business collaboration based on privacy protection, the collaborative adjustment of the positions of business data of each business party is one of the business processing sub-links usually involved in many business collaboration processes. Therefore, how to perform collaborative adjustment of business data positions based on privacy protection is very crucial for business collaboration processing.
[0064] In the process of collaborative adjustment of the positions of data sequences, for the convenience of description, the data sequence used as the reference arrangement can be described as the basic privacy sequence, and the data sequence that performs position adjustment by referring to the element position adjustment method of other data sequences can be described as the target privacy sequence. Figure 1 The array A in is the basic privacy sequence, and the array A' is the initial target privacy sequence to be position-adjusted. Figure 6 In, the array B is the initial target privacy sequence to be position-adjusted.
[0065] A coordination sequence can be further constructed to complete the collaborative position adjustment by using this coordination sequence. As described in the above scenario example, an initial coordination sequence can be constructed in advance. The position identifier of the initial coordination sequence is the same as that of the basic privacy sequence, and the element value at any position in the initial coordination sequence is configured as the ciphertext form of the position identifier at the corresponding position. The initial coordination sequence can be constructed by the business party holding the basic privacy sequence or by the coordination service device.
[0066] The business party holding the basic privacy sequence can obtain the initial coordination sequence and perform position adjustment on the initial coordination sequence based on the element position adjustment method of the basic privacy sequence to obtain the coordinated privacy sequence. The business party holding the basic privacy sequence can perform the corresponding position adjustment on the initial coordination sequence synchronously during the process of performing position adjustment on the basic privacy sequence; or it can perform the corresponding position adjustment on the initial coordination sequence based on the recorded element position adjustment method after the position adjustment of the basic privacy sequence.
[0067] The business party holding the basic privacy sequence can further perform position shuffling on the elements of the coordinated privacy sequence to obtain the coordinated public sequence. For example, the shuffle algorithm can be used to perform position shuffling on the elements of the coordinated privacy sequence. Of course, other types of position shuffling algorithms can also be used to perform processing on the coordinated privacy sequence. Correspondingly, the elements of the coordinated public sequence will neither expose the position information of the basic privacy sequence nor expose the element position adjustment method of the basic privacy sequence. After that, the business party holding the basic privacy sequence can make the coordinated public sequence public.
[0068] In some embodiments, when the basic privacy sequence is adjusted in position through the collaboration of two or more service providers, the coordinated public sequence may also be constructed by the service providers holding the shards of the basic privacy sequence in the following manner: obtaining an initial coordinated sequence shard, where the position identifiers in the initial coordinated sequence shard are the same as those of the shards of the basic privacy sequence held by the service providers, and the element value at any position in the initial coordinated sequence shard is configured as the ciphertext form of the position identifier at the corresponding position; performing position adjustment on the initial coordinated sequence shard based on the element position adjustment method of the shards of the basic privacy sequence held by the service providers to obtain a coordinated privacy sequence shard; using a position scrambling algorithm to scramble the positions of the elements in the coordinated privacy sequence shard, and taking the shard obtained after the scrambling process as the coordinated public sequence shard for public disclosure; obtaining the coordinated public sequence shards publicly disclosed by other service providers holding the basic privacy sequence, and combining the coordinated public sequence shards to obtain a coordinated public sequence.
[0069] S72: Using the position scrambling algorithm to scramble the positions of the elements in the initial target privacy sequence shard held by the specified service provider in the initial target privacy sequence, to obtain an intermediate target privacy sequence shard.
[0070] S74: Using the element value at any position in the coordinated public sequence to represent the position identifier at which the element at the corresponding position in the intermediate target privacy sequence is reconfigured, and performing position adjustment on the intermediate target privacy sequence shard to obtain a target privacy sequence shard with updated positions.
[0071] S76: Collaborating with other service providers in business collaboration processing, and at least using the target privacy sequence shards with updated positions held by each service provider to perform business collaboration processing under privacy protection.
[0072] After the service provider obtains the target privacy sequence shard with updated positions, the specified service provider may collaborate with other service providers in business collaboration processing, and use the target privacy sequence shards with updated positions held by each service provider to perform other business processing links in business collaboration processing under privacy protection.
[0073] By performing collaborative position adjustment on the business data sequence through the above-mentioned implementation manners, it is possible to complete the process of adjusting the position of the target privacy sequence according to the element position adjustment manner of the basic privacy sequence without exposing the specific content of the basic privacy sequence and the element position adjustment manner, so as to achieve business collaborative processing based on privacy protection. At the same time, by using the above-mentioned implementation manners, during the collaborative position adjustment process, the business party only needs to send the coordinated public sequence shards to another business party, achieving a communication volume complexity of O(n) and a communication round complexity of O(1), greatly reducing the communication volume complexity and communication round complexity of business collaborative processing based on privacy protection.
[0074] Certainly, those skilled in the art may also have other alternative implementation manners under the inspiration of the technical essence of the embodiments in this specification. However, as long as the functions and effects achieved are the same or similar, they should all be covered within the protection scope of this specification.
[0075] Each embodiment in this specification is described in a progressive manner. The same or similar parts among the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. Specifically, reference can be made to the descriptions of the relevant processing-related embodiments mentioned above, and details will not be repeated here.
[0076] The above describes specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the specific order or continuous order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0077] Such as Figure 9As shown, based on the above privacy protection-based business collaboration processing method, an embodiment of this specification further provides a privacy protection-based business collaboration processing device, which is applied to a designated business party for business collaboration processing. The device includes: a public sequence acquisition module 90, configured to acquire a coordinated public sequence; the coordinated public sequence refers to the sequence publicly disclosed by the business party holding the basic privacy sequence after processing the coordinated privacy sequence using a position scrambling algorithm; the coordinated privacy sequence refers to the sequence used by the business party holding the basic privacy sequence to represent the element position adjustment method of the basic privacy sequence in ciphertext form; a first position adjustment module 92, configured to use the position scrambling algorithm to scramble the positions of the elements in the initial target privacy sequence shards held by the designated business party, to obtain intermediate target privacy sequence shards; a second position adjustment module 94, configured to use the element value at any position in the coordinated public sequence to represent the position identifier of the element at the corresponding position in the intermediate target privacy sequence being reconfigured, and perform position adjustment on the intermediate target privacy sequence shards held by the designated business party, to obtain the target privacy sequence shards with updated positions; a collaboration processing module 96, configured to collaborate with other business parties for business collaboration processing, and at least use the target privacy sequence shards with updated positions held by each business party to perform business collaboration processing under privacy protection.
[0078] In some other embodiments, when the reference privacy sequence is jointly adjusted in position by two or more business parties including the designated business party, the device further includes a public auxiliary sequence construction module; wherein, the public auxiliary sequence construction module includes: an initial coordinated sequence acquisition unit, configured to acquire initial coordinated sequence shards, where the position identifiers in the initial coordinated sequence shards are the same as the position identifiers of the basic privacy sequence shards held by the business parties, and the element value at any position in the initial coordinated sequence shards is configured as the ciphertext form of the position identifier at the corresponding position; a position adjustment unit, configured to perform position adjustment on the initial coordinated sequence shards based on the element position adjustment method of the basic privacy sequence shards held by the business parties, to obtain coordinated privacy sequence shards; a position scrambling unit, configured to use the position scrambling algorithm to scramble the positions of the elements in the coordinated privacy sequence shards, and use the shards obtained after the scrambling process as coordinated public sequence shards; a public unit, configured to publicly disclose the coordinated public sequence shards; a sequence shard combination unit, configured to acquire the coordinated public sequence shards publicly disclosed by other business parties holding the basic privacy sequence, and combine the coordinated public sequence shards to obtain a coordinated public sequence.
[0079] It should be noted that the above-described device may also include other implementation manners according to the descriptions of the method embodiments and scenario examples. The specific implementation manners may refer to the descriptions of the relevant method embodiments, and will not be elaborated here one by one.
[0080] As Figure 10 shown, based on the above-mentioned business collaboration processing method based on privacy protection, this specification also provides a computer device, which includes a memory, a processor, and computer instructions stored on the memory. The processor executes the computer instructions to implement the steps of the method described in any one or more of the above embodiments. The processor may take the form of, for example, a microprocessor or a processor, a computer-readable medium storing computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers, etc. The memory includes, but is not limited to, random access memory (RAM), read-only memory (ROM), cache, hard disk drive (HDD), or memory card. The computer device may be, for example, a server for the method described in the above embodiments. Of course, the computer device may also include module structures such as an input device and a transmission module. In this embodiment, the specific functions and effects implemented by the computer device may be explained in comparison with other embodiments and will not be elaborated here.
[0081] In addition, an embodiment of this specification also provides a computer-readable storage medium, on which computer instructions are stored. When the instructions are executed by a processor, the steps of the method described in any one or more of the above embodiments are implemented. The storage medium may include a physical device for storing information, usually by digitizing the information and then storing it using media such as electricity, magnetism, or optics. The storage medium may include: devices that store information using electrical energy, such as various memories, such as RAM and ROM; devices that store information using magnetic energy, such as hard disks, floppy disks, magnetic tapes, magnetic core memories, bubble memories, and USB flash drives; devices that store information using optical methods, such as CDs or DVDs. Of course, there are also other ways of readable storage media, such as quantum memories and graphene memories, etc.
[0082] It should be noted that the embodiments of this specification are not limited to those that must conform to the standard data model / template or the situations described in the embodiments of this specification. Some industry standards or implementation schemes slightly modified on the basis of the implementation described by using a custom method or embodiment can also achieve the same, equivalent, or similar, or predictable implementation effects after deformation as the above embodiments. The embodiments obtained by applying these modified or deformed data acquisition, storage, judgment, processing methods, etc. still fall within the scope of the optional implementation schemes of this specification.
[0083] The various embodiments in this specification are described in a progressive manner. For the same or similar parts among the various embodiments, reference can be made to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for system embodiments, since they are basically similar to method embodiments, the description is relatively simple, and the relevant parts can refer to the description of the method embodiments. In the description of this specification, the description with reference to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of this specification. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0084] The above is only the embodiment of this specification and is not used to limit this specification. For those skilled in the art, various changes and modifications can be made to this specification. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this specification shall be included within the scope of the claims of this specification.
Claims
1. A business collaboration processing method based on privacy protection, characterized in that, A specified business party applied to business collaboration processing, the method includes: Obtain a coordinated public sequence; the coordinated public sequence refers to the sequence publicly disclosed by the business party holding the basic privacy sequence after processing the coordinated privacy sequence using a position shuffling algorithm; the coordinated privacy sequence is used to represent the element position adjustment method of the basic privacy sequence in ciphertext form; Use the position shuffling algorithm to shuffle the positions of the elements in the initial target privacy sequence slice held by the specified business party in the initial target privacy sequence, and obtain an intermediate target privacy sequence slice; the initial target privacy sequence is an undisclosed sequence obtained by the business party holding the basic privacy sequence after adjusting the position of the held basic privacy sequence; Use the element value at any position in the coordinated public sequence to represent the position identifier of the element at the corresponding position in the intermediate target privacy sequence, and perform position adjustment on the intermediate target privacy sequence slice to obtain a target privacy sequence slice with updated position; Collaborate with other business parties in business collaboration processing, and at least use the target privacy sequence slices with updated positions held by each business party to perform business collaboration processing under privacy protection.
2. The method according to claim 1, characterized in that, The coordinated privacy sequence is constructed by the business party holding the basic privacy sequence in the following manner: Obtain an initial coordinated sequence, the position identifier of the initial coordinated sequence is the same as that of the basic privacy sequence, and the element value at any position in the initial coordinated sequence is configured as the ciphertext form of the position identifier at the corresponding position; Based on the element position adjustment method of the basic privacy sequence, perform position adjustment on the initial coordinated sequence to obtain a coordinated privacy sequence.
3. The method according to claim 2, wherein In the case where the basic privacy sequence is jointly adjusted in position by two or more business parties, the coordinated public sequence is constructed by the business party holding the basic privacy sequence slice in the following manner: Obtain an initial coordinated sequence slice, the position identifier in the initial coordinated sequence slice is the same as that of the basic privacy sequence slice held by the business party, and the element value at any position in the initial coordinated sequence slice is configured as the ciphertext form of the position identifier at the corresponding position; Based on the element position adjustment method of the basic privacy sequence slice held by the business party, perform position adjustment on the initial coordinated sequence slice to obtain a coordinated privacy sequence slice; Use the position shuffling algorithm to shuffle the positions of the elements in the coordinated privacy sequence slice, and use the obtained slice after shuffling as the coordinated public sequence slice and disclose it externally; Obtain the coordinated public sequence slices publicly disclosed by other business parties holding the basic privacy sequence, and combine each coordinated public sequence slice to obtain a coordinated public sequence.
4. The method according to claim 1, wherein The position shuffling algorithm includes the shuffle algorithm.
5. A business collaboration processing device based on privacy protection, characterized in that, A specified business party applied to business collaboration processing, the device includes: The public sequence acquisition module is used to acquire the coordinated public sequence; the coordinated public sequence refers to the sequence publicly disclosed by the business party holding the basic privacy sequence after processing the coordinated privacy sequence using the position shuffling algorithm; the coordinated privacy sequence refers to the sequence used by the business party holding the basic privacy sequence to represent the element position adjustment method of the basic privacy sequence in ciphertext form. The first position adjustment module is used to shuffle the positions of the elements in the initial target privacy sequence shards held by the specified business party in the initial target privacy sequence using the position shuffling algorithm to obtain intermediate target privacy sequence shards; the initial target privacy sequence is an undisclosed sequence obtained by the business party holding the basic privacy sequence after adjusting the position of the basic privacy sequence held. The second position adjustment module is used to use the element value at any position in the coordinated public sequence to represent the position identifier where the element at the corresponding position in the intermediate target privacy sequence is reconfigured, and perform position adjustment on the intermediate target privacy sequence shards held by the specified business party to obtain the target privacy sequence shards with updated positions. The collaborative processing module is used to jointly process with other business parties in business collaboration, and at least perform business collaboration under privacy protection using the target privacy sequence shards with updated positions held by each business party.
6. The device according to claim 5, wherein The coordinated privacy sequence is constructed by the business party holding the basic privacy sequence in the following manner: Obtain the initial coordinated sequence, where the position identifier of the initial coordinated sequence is the same as that of the basic privacy sequence, and the element value at any position in the initial coordinated sequence is configured as the ciphertext form of the position identifier at the corresponding position. Perform position adjustment on the initial coordinated sequence based on the element position adjustment method of the basic privacy sequence to obtain the coordinated privacy sequence.
7. The device according to claim 5, characterized in that, In the case where the basic privacy sequence is jointly adjusted in position by two or more business parties including the specified business party, the device further includes a coordinated public sequence construction module; wherein, the coordinated public sequence construction module includes: The initial coordinated sequence acquisition unit is used to acquire initial coordinated sequence shards, where the position identifier in the initial coordinated sequence shards is the same as that of the basic privacy sequence shards held by the business party, and the element value at any position in the initial coordinated sequence shards is configured as the ciphertext form of the position identifier at the corresponding position. The position adjustment unit is used to perform position adjustment on the initial coordinated sequence shards based on the element position adjustment method of the basic privacy sequence shards held by the business party to obtain coordinated privacy sequence shards. The position shuffling unit is used to shuffle the positions of the elements in the coordinated privacy sequence shards using the position shuffling algorithm, and use the shuffled shards as coordinated public sequence shards. The public unit is used to publicly disclose the coordinated public sequence shards. The sequence shard combination unit is used to acquire the coordinated public sequence shards publicly disclosed by other business parties holding the basic privacy sequence, and combine the coordinated public sequence shards to obtain the coordinated public sequence.
8. The device according to claim 5, characterized in that, The position shuffling algorithm includes the shuffle algorithm.
9. A computer-readable storage medium having computer instructions stored thereon, characterized in that, When the instructions are executed by a processor, the steps of the method according to any one of claims 1-4 are implemented.
10. A computer device, comprising a memory, a processor, and computer instructions stored on the memory, characterized in that, The processor executes the computer instructions to implement the steps of the method according to any one of claims 1-4.
Citation Information
Patent Citations
Method and device for jointly training business models
CN111723404A
Data processing method and device based on privacy protection and server
CN112100643A