Budget Processing Method and Device Based on Privacy Protection
The method addresses the issue of data set unavailability due to budget depletion by recovering budget through processing consumption records, ensuring continuous usability and privacy protection in differential privacy scenarios.
Patent Information
- Application Number
- CN202011136101.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-10-22
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2040-10-22
AI Technical Summary
In differential privacy protection, when the total budget is exhausted, the dataset and the products that apply the dataset become unavailable, resulting in an increased risk of individual privacy data breaches and the ongoing availability of the dataset is affected.
By receiving budget recovery requests, obtaining budget consumption records of the target data set, and reducing budget consumption values in the consumption records while meeting budget recovery conditions, thereby restoring the budget of the data set, ensuring the protection intensity of individual privacy data and the continuous availability of the data set.
While ensuring individual privacy data protection, it enhances the continuous availability of data sets and application data set products, avoiding unavailability caused by budget exhaustion.
Smart Images

Figure CN114386083B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this specification relate to the field of information security. Specifically, they relate to a budget processing method and device based on privacy protection. Background Art
[0002] With the rapid development of information technology and Internet technology, individual data is continuously collected, used, and analyzed. Data analysis and data mining applications can help people better understand business and data. However, the adverse effect is that the privacy data of individuals is leaked in this process. In order to prevent the leakage of individual privacy data during the process of data collection and analysis, it is necessary to protect individual privacy when data collectors perform data publishing and analysis.
[0003] In practice, various privacy protection algorithms with budget control and management capabilities can be used for individual privacy protection. Such algorithms can include, for example, but are not limited to, differential privacy protection algorithms, etc.
[0004] Taking differential privacy protection as an example, for a data set and a data analysis scenario, if the presence or absence of an individual in it has no impact on the data analysis result, then the privacy data of the individual will not be leaked due to multiple queries or multiple publications by attackers, thus achieving the purpose of protecting privacy. Such privacy protection means is differential privacy protection.
[0005] In differential privacy protection, in order to limit the number of queries for a data set and meet the privacy protection intensity, it is necessary to configure a corresponding total budget for the data set. Among them, each query will consume a certain amount of budget. When the total budget is exhausted, it usually causes the data set corresponding to the total budget to be unavailable, and further causes the product applying the data set to be unavailable.
[0006] Therefore, a reasonable and reliable method is needed to perform budget recovery processing for the data set, so as to ensure the continuous availability of the data set and the product applying the data set while ensuring the protection intensity of individual privacy data. Summary of the Invention
[0007] The embodiments of this specification provide a budget processing method and device based on privacy protection.
[0008] In a first aspect, an embodiment of this specification provides a budget processing method based on privacy protection, including: receiving a budget recovery request for a target data set, where the target data set corresponds to an accumulated value of budget consumption under differential privacy protection; according to the budget recovery request, obtaining at least one budget consumption record corresponding to the target data set, where a single budget consumption record includes a budget consumption value generated by a single query for the target data set; for the obtained budget consumption record, if the budget consumption record meets the budget recovery condition, reducing the accumulated budget consumption value by the budget consumption value in the budget consumption record.
[0009] In some embodiments, after reducing the accumulated budget consumption value by the budget consumption value in the budget consumption record, the method further includes: generating and storing a budget recovery log corresponding to the budget consumption record.
[0010] In some embodiments, the receiving a budget recovery request for a target data set includes: receiving the budget recovery request triggered regularly; and the obtaining at least one budget consumption record corresponding to the target data set includes: obtaining the budget consumption records corresponding to the target data set that have not been processed for budget recovery as the at least one budget consumption record.
[0011] In some embodiments, the budget consumption record further includes a budget consumption time; and the budget recovery condition includes any one of the following: after the budget consumption time, the target data set has changed; the budget consumption time is earlier than the start time of the current budget recovery cycle.
[0012] In some embodiments, the change of the target data set includes: adding data to the target data set; or modifying at least one piece of data in the target data set; or deleting at least one piece of data in the target data set.
[0013] In some embodiments, the receiving a budget recovery request for a target data set includes: receiving the budget recovery request triggered by an application party, where the budget recovery request includes specified conditions; and the obtaining at least one budget consumption record corresponding to the target data set includes: obtaining the budget consumption records corresponding to the target data set that meet the specified conditions as the at least one budget consumption record.
[0014] In some embodiments, before determining that the budget consumption record meets the budget recovery condition, the method further includes: determining whether the budget consumption record meets the specified conditions; in response to determining that the budget consumption record meets the specified conditions, further determining whether the budget consumption record meets the budget recovery condition.
[0015] In some embodiments, the budget recovery condition includes that the budget consumption record has not been processed by automatic budget recovery.
[0016] In some embodiments, the target data set also corresponds to a single budget consumption value for differential privacy protection; and the method further includes: in response to receiving a query result to be processed from the target data set, determining the budget consumption value of the query result to be processed according to the single budget consumption value; adding the budget consumption value of the query result to be processed to the budget consumption cumulative value; and generating and storing a budget consumption record according to the budget consumption value of the query result to be processed.
[0017] In a second aspect, an embodiment of the present specification provides a budget processing method based on privacy protection, including: receiving a budget recovery request for a target data set triggered regularly, where the target data set corresponds to a cumulative budget consumption value for differential privacy protection; according to the budget recovery request, obtaining an unprocessed budget consumption record corresponding to the target data set, where a single budget consumption record includes a budget consumption value generated by a single query for the target data set; for the obtained budget consumption record, if the budget consumption record meets the budget recovery condition, reducing the cumulative budget consumption value by the budget consumption value in the budget consumption record.
[0018] In a third aspect, an embodiment of the present specification provides a budget processing method based on privacy protection, including: receiving a budget recovery request for a target data set triggered by an application party, where the target data set corresponds to a cumulative budget consumption value for differential privacy protection, and the budget recovery request includes specified conditions; according to the budget recovery request, obtaining a budget consumption record corresponding to the target data set that meets the specified conditions, where a single budget consumption record includes a budget consumption value generated by a single query for the target data set; for the obtained budget consumption record, if the budget consumption record meets the budget recovery condition, reducing the cumulative budget consumption value by the budget consumption value in the budget consumption record.
[0019] In a fourth aspect, an embodiment of the present specification provides a budget processing method based on privacy protection, including: receiving a budget recovery request for a target data set, where the target data set corresponds to a cumulative budget consumption value for privacy protection; according to the budget recovery request, obtaining at least one budget consumption record corresponding to the target data set, where a single budget consumption record includes a budget consumption value generated by a single query for the target data set; for the obtained budget consumption record, if the budget consumption record meets the budget recovery condition, reducing the cumulative budget consumption value by the budget consumption value in the budget consumption record.
[0020] Fifth aspect, an embodiment of this specification provides an access control method for an application based on privacy protection, including: receiving a data access request from an application party for a target data set, where the target data set corresponds to the cumulative budget consumption value after budget restoration processing for privacy protection; determining whether to allow the application party to perform this data access according to the cumulative budget consumption value after budget restoration processing.
[0021] Sixth aspect, an embodiment of this specification provides a budget processing device based on privacy protection, including: a receiving unit configured to receive a budget restoration request for a target data set, where the target data set corresponds to the cumulative budget consumption value for differential privacy protection; an obtaining unit configured to obtain at least one budget consumption record corresponding to the target data set according to the budget restoration request, where a single budget consumption record includes the budget consumption value generated by a single query for the target data set; a budget processing unit configured to, for the obtained budget consumption record, if the budget consumption record meets the budget restoration condition, reduce the cumulative budget consumption value by the budget consumption value in the budget consumption record.
[0022] Seventh aspect, an embodiment of this specification provides a budget processing device based on privacy protection, including: a receiving unit configured to receive a periodically triggered budget restoration request for a target data set, where the target data set corresponds to the cumulative budget consumption value for differential privacy protection; an obtaining unit configured to obtain the budget consumption record corresponding to the target data set that has not undergone budget restoration processing according to the budget restoration request, where a single budget consumption record includes the budget consumption value generated by a single query for the target data set; a budget processing unit configured to, for the obtained budget consumption record, if the budget consumption record meets the budget restoration condition, reduce the cumulative budget consumption value by the budget consumption value in the budget consumption record.
[0023] Eighth aspect, an embodiment of this specification provides a budget processing device based on privacy protection, including: a receiving unit configured to receive a budget restoration request for a target data set triggered by an application party, where the target data set corresponds to the cumulative budget consumption value for differential privacy protection, and the budget restoration request includes specified conditions; an obtaining unit configured to obtain the budget consumption record corresponding to the target data set that meets the specified conditions according to the budget restoration request, where a single budget consumption record includes the budget consumption value generated by a single query for the target data set; a budget processing unit configured to, for the obtained budget consumption record, if the budget consumption record meets the budget restoration condition, reduce the cumulative budget consumption value by the budget consumption value in the budget consumption record.
[0024] In a ninth aspect, an embodiment of the present specification provides a budget processing device based on privacy protection, including: a receiving unit configured to receive a budget recovery request for a target data set, where the target data set corresponds to an accumulated value of budget consumption for privacy protection; an obtaining unit configured to obtain at least one budget consumption record corresponding to the target data set according to the budget recovery request, where a single budget consumption record includes a budget consumption value generated by a single query for the target data set; and a budget processing unit configured to, for the obtained budget consumption record, if the budget consumption record meets the budget recovery condition, reduce the accumulated value of budget consumption by the budget consumption value in the budget consumption record.
[0025] In a tenth aspect, an embodiment of the present specification provides an access control device for an application based on privacy protection, including: a receiving unit configured to receive a data access request from an application party for a target data set, where the target data set corresponds to an accumulated value of budget consumption after budget recovery processing for privacy protection; and an access control unit configured to determine whether to allow the application party to perform the current data access according to the accumulated value of budget consumption after budget recovery processing.
[0026] In an eleventh aspect, an embodiment of the present specification provides a computer-readable storage medium, on which a computer program is stored, where when the computer program is executed on a computer, the computer is caused to execute the method described in any one of the first aspect to the fifth aspect.
[0027] In a twelfth aspect, an embodiment of the present specification provides a computing device, including a memory and a processor, where an executable code is stored in the memory, and when the processor executes the executable code, the method described in any one of the first aspect to the fifth aspect is implemented.
[0028] The budget processing method and device based on privacy protection provided in the above embodiments of the present specification, by receiving a budget recovery request for a target data set, where the target data set corresponds to an accumulated value of budget consumption for privacy protection, then obtaining at least one budget consumption record corresponding to the target data set according to the budget recovery request, where a single budget consumption record includes a budget consumption value generated by a single query for the target data set, and then for the obtained budget consumption record, in response to the budget consumption record meeting the budget recovery condition, reducing the accumulated value of budget consumption by the budget consumption value in the budget consumption record. Thus, by reducing the accumulated value of budget consumption, the remaining budget of the target data set can be increased, thereby realizing the recovery of the budget of the target data set. Therefore, while ensuring the protection intensity of individual privacy data, the continuous availability of the target data set and the product using the target data set can also be ensured. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] To more clearly illustrate the technical solutions of the multiple embodiments disclosed in this specification, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only the multiple embodiments disclosed in this specification. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0030] Figure 1a is an exemplary system architecture diagram in which some embodiments of this specification can be applied;
[0031] Figure 1b is another exemplary system architecture diagram in which some embodiments of this specification can be applied;
[0032] Figure 1c is yet another exemplary system architecture diagram in which some embodiments of this specification can be applied;
[0033] Figure 2 is a flowchart of an embodiment of the privacy - protected budget processing method according to this specification;
[0034] Figure 3 is a flowchart of another embodiment of the privacy - protected budget processing method according to this specification;
[0035] Figure 4 is a flowchart of yet another embodiment of the privacy - protected budget processing method according to this specification;
[0036] Figure 5 is a flowchart of still another embodiment of the privacy - protected budget processing method according to this specification;
[0037] Figure 6 is a flowchart of an embodiment of the access control method for privacy - protected applications according to this specification;
[0038] Figure 7 is a structural schematic diagram of an embodiment of the privacy - protected budget processing device according to this specification;
[0039] Figure 8 is another structural schematic diagram of the privacy - protected budget processing device according to this specification;
[0040] Figure 9 is yet another structural schematic diagram of the privacy - protected budget processing device according to this specification;
[0041] Figure 10 is still another structural schematic diagram of the privacy - protected budget processing device according to this specification;
[0042] Figure 11 It is a schematic structural diagram of an access control device for a privacy protection-based application according to this specification. Detailed implementation manners
[0043] The following further elaborates on this specification in conjunction with the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are merely for explaining the relevant invention and not for limiting the invention. The described embodiments are only a part of the embodiments of this specification, rather than all the embodiments. Based on the embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of this application.
[0044] It should be noted that for the sake of convenience of description, only parts related to the relevant invention are shown in the accompanying drawings. Without conflict, the embodiments in this specification and the features in the embodiments can be combined with each other.
[0045] As mentioned above, in differential privacy protection, in order to limit the number of queries for a data set and meet the privacy protection intensity, it is necessary to configure a corresponding total budget for the data set. When the total budget is exhausted, it usually causes the data set corresponding to the total budget to be unavailable, and further causes the product applying the data set to be unavailable.
[0046] Based on this, some embodiments of this specification provide a budget processing method based on privacy protection. Through the method provided in this specification, while ensuring the protection intensity of individual privacy data, the continuous availability of the target data set and the product applying the target data set can also be ensured. Specifically, Figure 1a - Figure 1c An exemplary system architecture diagram applicable to these embodiments is shown.
[0047] As Figure 1a shown, it shows a privacy protection system, which may include a budget management server, and the budget management server can be used for budget control and management. Among them, the privacy protection system can adopt various privacy protection algorithms with budget control and management capabilities for individual privacy protection. Such algorithms may include, for example, but are not limited to, differential privacy protection algorithms, etc. It should be noted that when the privacy protection system adopts a differential privacy protection algorithm, the privacy protection system can be called a differential privacy protection system.
[0048] Optionally, the privacy protection system may further include an information processing server (not shown in the figure), and the information processing server can be used to provide privacy protection services, such as differential privacy protection services, etc. Among them, the information processing server and the budget management server can be hardware modules or software modules, and no specific limitation is made here.
[0049] In practice, the privacy protection system can be communicatively connected to at least one application system. The at least one application system can include, but is not limited to, an e-commerce system, a medical system, an audio-video system, a social system, and / or a game system, etc.
[0050] Specifically, the application party to which the application system accessing the privacy protection system belongs can configure a total budget value for the data set involved in the application system. The total budget value is usually a natural number greater than 0. The total budget value can be understood as the total number of queries allowed to be executed on the data set.
[0051] The information processing server can receive an information processing request from the application system, and the request can include the query result to be processed. Among them, the query result can include, for example, the counted number of people in a population, etc. The query result involves individual privacy and needs to be protected. The information processing server can use a privacy protection algorithm for the query result to determine the corresponding noise value, and determine the sum between the query result and the noise value as the noise-added query result, and return the noise-added query result to the corresponding application system. In addition, the information processing server can also send the query result to the budget management server, and the budget management server performs corresponding budget control and management. In the following text, the data set involved in the application system accessing the privacy protection system is referred to as the target data set.
[0052] The budget management server can determine the budget consumption value of the query result in response to receiving the query result to be processed from the target data set. In addition, the budget consumption cumulative value corresponding to the target data set can be increased by the budget consumption value of the query result. As Figure 1a shown, it shows the budget consumption cumulative value after increasing the budget consumption value corresponding to the target data set. And the budget management server can also generate and store a budget consumption record according to the budget consumption value of the query result, where the budget consumption record includes, but is not limited to, the budget consumption value of the query result.
[0053] In addition, the budget management server can also receive a budget recovery request for the target data set, and in response to the request, obtain at least one budget consumption record corresponding to the target data set, and perform a subtraction operation on the budget consumption cumulative value corresponding to the target data set according to the budget consumption value included in the obtained budget consumption record, so as to implement the budget recovery process for the target data set, and obtain the budget consumption cumulative value that becomes smaller after the budget recovery process for the target data set. In this way, by reducing the budget consumption cumulative value, the remaining budget of the target data set can be increased, so as to achieve the purpose of budget recovery.
[0054] Optionally, the privacy protection system can be set with a timed task, and the timed task is used to periodically trigger a budget recovery request for the target data set. As Figure 1bAs shown, it shows another exemplary system architecture diagram applicable to some embodiments of the privacy - protected budget processing method provided in this specification. In Figure 1b in addition to showing Figure 1a the content related to the budget recovery request in Figure 1b it also shows a timing task. Specifically,
[0055] Optionally, the privacy protection system can support the application party to manually trigger a budget recovery request for the target data set. As Figure 1c shown, it shows yet another exemplary system architecture diagram applicable to some embodiments of the privacy - protected budget processing method provided in this specification. In Figure 1c in addition to showing Figure 1a the content related to the budget recovery request in Figure 1c it also shows the application party. Specifically,
[0056] Next, in combination with specific embodiments, the specific implementation steps of the above - mentioned method will be described.
[0057] Referring to Figure 2 which shows the process 200 of an embodiment of the privacy - protected budget processing method. The execution subject of this method can be the privacy protection system as Figure 1a shown, or the budget management server in this system. This method includes the following steps:
[0058] Step 201, receive a budget recovery request for a target data set, where the target data set corresponds to the cumulative value of budget consumption for privacy protection;
[0059] Step 203, according to the budget recovery request, obtain at least one budget consumption record corresponding to the target data set, where a single budget consumption record includes the budget consumption value generated by a single query for the target data set;
[0060] Step 205, for the obtained budget consumption record, if the budget consumption record meets the budget recovery condition, then reduce the cumulative value of budget consumption by the budget consumption value in this budget consumption record.
[0061] In this embodiment, the privacy protection in step 201 corresponds to the privacy protection algorithm adopted by the privacy protection system. For example, if the privacy protection system adopts the differential privacy protection algorithm, then the privacy protection in step 201 is differential privacy protection.
[0062] Optionally, after reducing the budget consumption value in the budget consumption record by the cumulative budget consumption value, a budget recovery log corresponding to the budget consumption record may be generated and stored.
[0063] Optionally, in step 201, a periodically triggered budget recovery request may be received. Further, in step 203, the budget consumption records corresponding to the target data set that have not been processed for budget recovery may be obtained as the at least one budget consumption record.
[0064] Optionally, the budget consumption record may further include the budget consumption time. The budget recovery condition may include any one of the following: after the budget consumption time, the target data set changes; the budget consumption time is earlier than the start time of the current budget recovery cycle.
[0065] Optionally, the change of the target data set may include: data is added to the target data set; or at least one piece of data in the target data set is modified; or at least one piece of data in the target data set is deleted.
[0066] Optionally, in step 201, a budget recovery request triggered by an application party may be received, and the budget recovery request may include specified conditions. Further, in step 203, the budget consumption records corresponding to the target data set that meet the specified conditions may be obtained as the at least one budget consumption record.
[0067] Optionally, when the budget recovery request includes specified conditions, in step 205, for the obtained budget consumption record, it may first be determined whether the budget consumption record meets the specified conditions. If it is determined that the budget consumption record meets the specified conditions, it may further be determined whether the budget consumption record meets the budget recovery conditions. If it is determined that the budget consumption record meets the budget recovery conditions, the cumulative budget consumption value may be reduced by the budget consumption value in the budget consumption record.
[0068] Optionally, if the budget recovery request is triggered by an application party, the budget recovery condition may include that the budget consumption record has not been automatically processed for budget recovery.
[0069] Optionally, the target data set also corresponds to a single budget consumption value for privacy protection. The above execution entity may also, in response to receiving the query result to be processed from the target data set, determine the budget consumption value of the query result to be processed according to the single budget consumption value, increase the cumulative budget consumption value by the budget consumption value of the query result to be processed, and generate and store a budget consumption record according to the budget consumption value of the query result to be processed.
[0070] It should be noted that for the specific processing of the above steps and the resulting technical effects, reference may be made to the relevant descriptions in the method embodiments applied to specific application scenarios in the following text.
[0071] Next, a budget processing method in the differential privacy protection scenario will be further introduced.
[0072] Refer to Figure 3 , which shows the process 300 of another embodiment of the budget processing method based on privacy protection. Among them, in this embodiment, Figure 1a the privacy protection system shown is a differential privacy protection system, and the execution subject of this method can be this differential privacy protection system, or the budget management server in this differential privacy protection system. This method includes the following steps:
[0073] Step 301, receive a budget recovery request for a target data set, where the target data set corresponds to the cumulative value of budget consumption for differential privacy protection;
[0074] Step 303, according to the budget recovery request, obtain at least one budget consumption record corresponding to the target data set, where a single budget consumption record includes the budget consumption value generated by a single query for the target data set;
[0075] Step 305, for the obtained budget consumption record, if the budget consumption record meets the budget recovery condition, then reduce the cumulative value of budget consumption by the budget consumption value in the budget consumption record.
[0076] Next, steps 301-305 will be described.
[0077] In step 301, the above execution subject can receive the budget recovery request for the target data set in real time or regularly. Among them, the target data set is the data set to which differential privacy protection is applied. The target data set corresponds to the cumulative value of budget consumption for differential privacy protection. The cumulative value of budget consumption is obtained by accumulating the budget consumption values of the query results from the target data set.
[0078] In step 303, the above execution subject can obtain at least one budget consumption record corresponding to the target data set according to the received budget recovery request. Among them, a single budget consumption record includes the budget consumption value generated by a single query for the target data set. In fact, this budget consumption value is the budget consumed by this single query.
[0079] Generally, there are budget consumption records that have not been processed for budget recovery in the above at least one budget consumption record, and the budget consumption values included in the budget consumption records that have not been processed for budget recovery have been accumulated into the cumulative value of budget consumption corresponding to the target data set.
[0080] In step 305, for the obtained budget consumption record, if the budget consumption record meets the budget recovery condition, the budget consumption cumulative value corresponding to the target data set can be reduced by the budget consumption value in the budget consumption record. In this way, the budget consumed for a single query corresponding to the budget consumption record can be recovered.
[0081] It should be noted that in addition to the budget consumption value, the budget consumption record may also include, but is not limited to, the budget consumption time, the data set identifier, and so on. The budget recovery condition may include, for example, any one of the following: the target data set has changed after the budget consumption time, the budget consumption time is earlier than the start time of the current budget recovery cycle, and so on. It should be understood that the budget recovery condition can be designed according to actual needs and is not specifically limited here.
[0082] Among them, the change of the target data set may include any one of the following: data is added to the target data set, at least one piece of data in the target data set is modified, at least one piece of data in the target data set is deleted, and so on.
[0083] In practice, multiple budget recovery cycles can be configured in advance for the target data set. The duration of each budget recovery cycle can be, for example, 1 day, 2 days, half a month, or 1 month, etc., and is not specifically limited here. During each budget recovery cycle, budget recovery processing can be performed on the budget consumption records generated before the budget recovery cycle.
[0084] It should be understood that the budget consumption records that have undergone budget recovery processing before usually will not be subject to secondary budget recovery processing.
[0085] Taking the budget recovery condition including that the target data set has changed after the budget consumption time as an example, step 305 will be further described. For example, among the above at least one budget consumption record, there is an unprocessed budget consumption record A, and the budget consumption record A includes the budget consumption time T. The above execution subject can obtain the change log of the target data set, where the change time of the target data set is recorded in the log. Then, the budget consumption time T can be compared with the latest change time in the change log. If the latest change time is later than the budget consumption time T, it can be determined that the target data set has changed after the budget consumption time T, and thus it can be determined that the budget consumption record A meets the budget recovery condition. Then, the budget consumption cumulative value corresponding to the target data set can be reduced by the budget consumption time T.
[0086] Optionally, for any one of the at least one budget consumption record described above, after reducing the budget consumption cumulative value by the budget consumption value in this budget consumption record, a budget recovery log corresponding to this budget consumption record can be generated and stored. The budget recovery log can include, for example, but is not limited to, the record identifier of its corresponding budget consumption record, the budget recovery value (the budget consumption value in this budget consumption record), and the budget recovery time, etc.
[0087] It should be noted that, in order to avoid calculation errors, the above-mentioned execution entity can process the budget consumption records in the at least one budget consumption record one by one, for example, in the order of the earliest to the latest or the latest to the earliest budget consumption time, and process them one by one.
[0088] Optionally, the target data set can also correspond to the single budget consumption value of differential privacy protection. This single budget consumption value can be configured by the application party or automatically set by the differential privacy protection system, and no specific limitation is made here. The above-mentioned execution entity can also respond to receiving the query result to be processed from the target data set, determine the budget consumption value of this query result according to the single budget consumption value corresponding to the target data set, and increase the budget consumption cumulative value corresponding to the target data set by the budget consumption value of this query result. In addition, a budget consumption record can also be generated and stored according to the budget consumption value of this query result. In this way, the above-mentioned execution entity can realize the control and management of the budget consumption of the query result.
[0089] In practice, the single budget consumption value corresponding to the target data set can be directly determined as the budget consumption value of the above-mentioned query result to be processed.
[0090] The budget processing method based on privacy protection provided in this embodiment receives a budget recovery request for a target data set, where the target data set corresponds to a budget consumption cumulative value of differential privacy protection, and then according to the budget recovery request, obtains at least one budget consumption record corresponding to the target data set, where a single budget consumption record includes the budget consumption value generated by a single query for the target data set. Then, for the obtained budget consumption record, in response to this budget consumption record satisfying the budget recovery condition, the budget consumption cumulative value is reduced by the budget consumption value in this budget consumption record. Thus, by reducing the budget consumption cumulative value, the remaining budget of the target data set can be increased, thereby realizing the recovery of the budget of the target data set. Therefore, while ensuring the protection intensity of individual privacy data, the continuous availability of the target data set and the product applying the target data set can also be ensured.
[0091] Next, taking the periodic triggering of the budget recovery request as an example, the budget processing method based on privacy protection will be further described.
[0092] SeeFigure 4 , which shows the process 400 of another embodiment of the privacy protection-based budget processing method. Among them, in this embodiment, Figure 1b The privacy protection system shown is a differential privacy protection system. The execution subject of this method can be this differential privacy protection system, or the budget management server in this differential privacy protection system. This method includes the following steps:
[0093] Step 401, receive a budget recovery request for a target data set triggered regularly, where the target data set corresponds to the cumulative value of budget consumption for differential privacy protection;
[0094] Step 403, according to the budget recovery request, obtain the budget consumption record corresponding to the target data set that has not undergone budget recovery processing, where a single budget consumption record includes the budget consumption value generated by a single query for the target data set;
[0095] Step 405, for the obtained budget consumption record, if the budget consumption record meets the budget recovery condition, then reduce the cumulative budget consumption value by the budget consumption value in the budget consumption record.
[0096] Next, steps 401-405 will be further described.
[0097] In step 401, the differential privacy protection system can preset a timing task, and this timing task can regularly trigger a budget recovery request for the target data set. Specifically, this timing task can automatically trigger this budget recovery request in response to the arrival of the target time point. In addition, the differential privacy protection system can be configured with multiple budget recovery cycles as described above. The target time point can include the start time of the budget recovery cycle.
[0098] In step 403, when the differential privacy protection system supports both automatic budget recovery processing and manual budget recovery processing, not undergoing budget recovery processing can mean not undergoing automatic budget recovery processing and not undergoing manual budget recovery processing. Among them, automatic budget recovery processing can refer to budget recovery processing in response to a regularly triggered budget recovery request. Manual budget recovery processing can refer to budget recovery processing in response to a budget recovery request triggered by the application party.
[0099] In step 405, for the obtained budget consumption record, if the budget consumption record meets the budget recovery condition, then the cumulative budget consumption value corresponding to the target data set can be reduced by the budget consumption value in the budget consumption record. Optionally, a budget recovery log corresponding to this budget consumption record can also be generated and stored.
[0100] Among them, the budget consumption record may further include the budget consumption time. The budget recovery condition may include any one of the following: the target data set changes after the budget consumption time, the budget consumption time is earlier than the start time of the current budget recovery cycle, etc. It should be understood that the budget recovery condition can be designed according to actual needs and is not specifically limited here. Here, for the explanation of the change of the target data set, reference can be made to the relevant description in the foregoing text.
[0101] The budget processing method based on privacy protection provided in this embodiment, compared with Figure 3 the corresponding embodiment, highlights the limitation on the triggering method of the budget recovery request and the limitation on the obtained budget consumption record. Therefore, the solution provided in this embodiment can not only achieve Figure 3 the technical effects that the corresponding embodiment can achieve, but also enrich the budget control and management functions.
[0102] Next, taking the manual triggering of the budget recovery request as an example, the budget processing method based on privacy protection will be further described.
[0103] Referring to Figure 5 , which shows the process 500 of another embodiment of the budget processing method based on privacy protection. Among them, in this embodiment, Figure 1c the privacy protection system shown is a differential privacy protection system. The execution subject of this method can be this differential privacy protection system or the budget management server in this differential privacy protection system. This method includes the following steps:
[0104] Step 501, receive a budget recovery request for the target data set triggered by the application party, where the target data set corresponds to the cumulative budget consumption value of differential privacy protection, and the budget recovery request includes specified conditions;
[0105] Step 503, according to the budget recovery request, obtain the budget consumption records corresponding to the target data set that meet the specified conditions, where a single budget consumption record includes the budget consumption value generated by a single query for the target data set;
[0106] Step 505, for the obtained budget consumption records, if the budget consumption record meets the budget recovery condition, reduce the cumulative budget consumption value by the budget consumption value in the budget consumption record.
[0107] Next, steps 501-505 will be further described.
[0108] In this embodiment, in order to flexibly perform budget recovery processing, enrich the budget management function of the application party, and improve the user experience, a manual budget recovery service can be provided to the application party. The application party can trigger a budget recovery request for the target data set by performing a specific budget recovery trigger operation on the target data set.
[0109] Therefore, in step 501, the above-mentioned execution entity can receive in real time a budget recovery request triggered by the application party through performing a specific budget recovery trigger operation on the target data set. The budget recovery request may include specified conditions of the application party. The specified conditions are used for screening budget consumption records.
[0110] In practice, the budget consumption records may include budget consumption values, budget consumption times, etc. of query results from the target data set. The specified conditions may include, for example, but are not limited to, that the budget consumption time is within a specified time period. It should be understood that the application party can set the specified conditions according to actual needs, and no specific limitation is made here.
[0111] In step 503, since the budget recovery request is triggered by the application party, therefore, each budget consumption record obtained may be a budget consumption record that has not been manually budget recovered.
[0112] In step 505, for the obtained budget consumption records, if the budget consumption record meets the budget recovery conditions, the budget consumption cumulative value corresponding to the target data set can be reduced by the budget consumption value in the budget consumption record. Optionally, a budget recovery log corresponding to the budget consumption record can also be generated and stored.
[0113] Optionally, while supporting manual budget recovery processing, the differential privacy protection system also supports automatic budget recovery processing. In this case, the budget recovery conditions may include, for example, but are not limited to, that the budget consumption record has not been automatically budget recovered. It should be understood that the budget recovery conditions can be designed according to actual needs, and no specific limitation is made here.
[0114] Optionally, since the differential privacy protection system can support parallel processing, there may be budget consumption records that no longer meet the specified conditions among the obtained budget consumption records. To avoid performing budget recovery processing on budget consumption records that no longer meet the specified conditions, for the obtained budget consumption records, calling the budget consumption record a to-be-processed budget consumption record, the above-mentioned execution entity can perform the following budget processing operations:
[0115] A. Determine again whether the to-be-processed budget consumption record meets the specified conditions;
[0116] B. In response to determining that the to-be-processed budget consumption record meets the specified conditions, further determine whether the to-be-processed budget consumption record meets the budget recovery conditions;
[0117] C. In response to determining that the to-be-processed budget consumption record meets the budget recovery conditions, reduce the budget consumption cumulative value by the budget consumption value in the to-be-processed budget consumption record;
[0118] D. In response to determining that the budget consumption record to be processed does not meet the specified conditions or the budget recovery conditions, and determining that there is a next budget consumption record of the budget consumption record to be processed among the obtained budget consumption records, perform step A for the next budget consumption record.
[0119] The budget processing method based on privacy protection provided in this embodiment, compared with Figure 3 the corresponding embodiment, highlights the limitation on the triggering manner of the budget recovery request and the limitation on the obtained budget consumption records. Thus, the solution provided in this embodiment can not only achieve Figure 3 the technical effects that the corresponding embodiment can achieve, but also enrich the budget control and management functions. Specifically, it can improve the flexibility of budget recovery processing, enrich the budget management functions of the application party, and improve the user experience.
[0120] Figure 3 - Figure 5 The corresponding embodiments respectively describe the budget processing methods in the differential privacy protection scenario. For the budget processing methods in other privacy protection scenarios, they can be analogously obtained based on the solutions provided in the Figure 3 - Figure 5 corresponding embodiments respectively, and will not be elaborated one by one here.
[0121] In practice, after the budget consumption cumulative value corresponding to the target data set undergoes budget recovery processing, application access control can be performed based on the budget consumption cumulative value after the budget recovery processing.
[0122] As Figure 6 shown, it shows a flowchart 600 of an embodiment of the access control method for an application based on privacy protection. The execution subject of this method can be the application, or the server of the application, etc., which is not specifically limited here. This method includes the following steps:
[0123] Step 601, receive a data access request from the application party for the target data set, where the target data set corresponds to the budget consumption cumulative value after privacy protection and budget recovery processing;
[0124] Step 603, determine whether to allow the application party to perform this data access according to the budget consumption cumulative value after the budget recovery processing.
[0125] Next, steps 601 - 603 will be described.
[0126] In step 601, the above-mentioned execution entity can receive in real time a data access request for a target data set triggered by the application party in the application. Among them, the data requested to be accessed by the data access request can be any data in the target data set. Optionally, the data requested to be accessed by the data access request can be, for example, the number of people in the population involved in at least one piece of data in the target data set. No specific limitation is made here.
[0127] The above-mentioned budget consumption cumulative value after budget recovery processing can be Figure 2 - Figure 5 The budget consumption cumulative value obtained by processing using any of the methods described in the corresponding embodiments respectively. In step 603, the above-mentioned execution entity can determine whether to allow the application party to perform this data access according to the above-mentioned budget consumption cumulative value after budget recovery processing. As an example, the target data set also corresponds to the total budget value of privacy protection. The above-mentioned execution entity can determine whether the budget consumption cumulative value reaches the total budget value. If it does not reach, it can be determined to allow the application party to perform this data access. If it reaches, it can be determined not to allow the application party to perform this data access.
[0128] Optionally, before step 603, the above-mentioned execution entity can obtain the above-mentioned budget consumption cumulative value after budget recovery processing. For example, the above-mentioned execution entity can obtain the budget consumption cumulative value from the local or the budget management server as described above.
[0129] Optionally, after step 603, the above-mentioned execution entity can, in response to determining to allow the application party to perform this data access, obtain the corresponding data according to the above-mentioned data access request and return the data to the application party. Among them, in order to protect individual privacy, the data can be data after noise addition processing.
[0130] Optionally, after step 603, the above-mentioned execution entity can, in response to determining not to allow the application party to perform this data access, return a prompt message indicating prohibited data access.
[0131] The access control method for an application based on privacy protection provided in this embodiment, after the budget consumption cumulative value corresponding to the target data set is processed by budget recovery, by receiving the data access request of the application party for the target data set, and then determining whether to allow the application party to perform this data access according to the budget consumption cumulative value corresponding to the target data set after budget recovery processing, can achieve effective access control of the application and ensure the continuous availability of the target data set and the application.
[0132] Further referring to Figure 7 As an implementation of the methods shown in some of the above figures, this specification provides an embodiment of a budget processing device based on privacy protection. This device embodiment is related to Figure 2The method embodiments shown correspond to this, and the device can be applied to, for example, Figure 1a the privacy protection system shown, or the budget management server in this system.
[0133] For example, Figure 7 As shown, the privacy protection-based budget processing device 700 in this embodiment includes: a receiving unit 701, an obtaining unit 703, and a budget processing unit 705. Among them, the receiving unit 701 is configured to receive a budget recovery request for a target data set, where the target data set corresponds to the cumulative value of budget consumption for privacy protection; the obtaining unit 703 is configured to obtain at least one budget consumption record corresponding to the target data set according to the budget recovery request, where a single budget consumption record includes the budget consumption value generated by a single query for the target data set; the budget processing unit 705 is configured to, for the obtained budget consumption record, if the budget consumption record meets the budget recovery condition, reduce the cumulative value of budget consumption by the budget consumption value in the budget consumption record.
[0134] In this embodiment, for the specific processing of the receiving unit 701, the obtaining unit 703, and the budget processing unit 705 and the technical effects brought thereby, reference can be made respectively to Figure 2 the relevant descriptions of steps 201, step 203, and step 205 in the corresponding embodiments, which will not be elaborated here.
[0135] Further referring to Figure 8 , as an implementation of the methods shown in some of the above figures, this specification provides another embodiment of a privacy protection-based budget processing device. This device embodiment corresponds to Figure 3 the method embodiments shown, and the device can be applied to a differential privacy protection system, or the budget management server in this system.
[0136] For example, Figure 8 As shown, the privacy protection-based budget processing device 800 in this embodiment includes: a receiving unit 801, an obtaining unit 803, and a budget processing unit 805. Among them, the receiving unit 801 is configured to receive a budget recovery request for a target data set, where the target data set corresponds to the cumulative value of budget consumption for differential privacy protection; the obtaining unit 803 is configured to obtain at least one budget consumption record corresponding to the target data set according to the budget recovery request, where a single budget consumption record includes the budget consumption value generated by a single query for the target data set; the budget processing unit 805 is configured to, for the obtained budget consumption record, if the budget consumption record meets the budget recovery condition, reduce the cumulative value of budget consumption by the budget consumption value in the budget consumption record.
[0137] In this embodiment, for the specific processing of the receiving unit 801, the obtaining unit 803, and the budget processing unit 805 and the technical effects brought thereby, reference can be made respectively to Figure 3 the relevant descriptions of steps 301, step 303, and step 305 in the corresponding embodiments, which will not be elaborated here.
[0138] Optionally, the budget processing unit 805 can also be configured to: for the obtained budget consumption record, after reducing the budget consumption cumulative value by the budget consumption value in the budget consumption record, generate and store a budget recovery log corresponding to the budget consumption record.
[0139] Optionally, the receiving unit 801 can be further configured to: receive the above-mentioned budget recovery request triggered regularly; and the obtaining unit 803 can be further configured to: obtain the budget consumption records corresponding to the target data set that have not undergone budget recovery processing as the above-mentioned at least one budget consumption record.
[0140] Optionally, the budget consumption record can also include the budget consumption time; and the budget recovery condition can include any one of the following: the target data set changes after the budget consumption time, the budget consumption time is earlier than the start time of the current budget recovery cycle, etc.
[0141] Optionally, the change of the target data set can mean that data is added to the target data set, at least one piece of data in the target data set is modified, or at least one piece of data in the target data set is deleted, etc.
[0142] Optionally, the receiving unit 801 can be further configured to: receive the above-mentioned budget recovery request triggered by the application party, and the above-mentioned budget recovery request includes specified conditions; and the obtaining unit 803 can be further configured to: obtain the budget consumption records corresponding to the target data set that meet the specified conditions as the above-mentioned at least one budget consumption record.
[0143] Optionally, when the receiving unit 801 receives the above-mentioned budget recovery request triggered by the application party, the budget processing unit 805 can be further configured to: for the obtained budget consumption record, determine whether the budget consumption record meets the specified conditions; in response to determining that the budget consumption record meets the specified conditions, further determine whether the budget consumption record meets the budget recovery conditions; if the budget consumption record meets the budget recovery conditions, reduce the budget consumption cumulative value by the budget consumption value in the budget consumption record.
[0144] Optionally, when the receiving unit 801 receives the above-mentioned budget recovery request triggered by the application party, the budget recovery condition can include that the budget consumption record has not undergone automatic budget recovery processing.
[0145] Optionally, the target data set may also correspond to the single-budget consumption value of differential privacy protection; and the budget processing unit 805 may also be configured to: in response to receiving the query result to be processed from the target data set, determine the budget consumption value of the query result according to the single-budget consumption value; increase the budget consumption cumulative value by the budget consumption value of the query result; generate and store a budget consumption record according to the budget consumption value of the query result.
[0146] The budget processing device based on privacy protection provided in this embodiment receives a budget restoration request for a target data set through a receiving unit, where the target data set corresponds to the budget consumption cumulative value of differential privacy protection. Then, through an obtaining unit, at least one budget consumption record corresponding to the target data set is obtained according to the budget restoration request, where a single budget consumption record includes the budget consumption value generated by a single query for the target data set. Then, for the obtained budget consumption record, in response to the budget consumption record satisfying the budget restoration condition, the budget processing unit reduces the budget consumption cumulative value by the budget consumption value in the budget consumption record. Thus, by reducing the budget consumption cumulative value, the remaining budget of the target data set can be increased, thereby realizing the restoration of the budget of the target data set. Therefore, while ensuring the protection intensity of individual privacy data, the continuous availability of the target data set and the product applying the target data set can also be ensured.
[0147] Further referring to Figure 9 , as an implementation of the methods shown in some of the above figures, this specification provides another embodiment of a budget processing device based on privacy protection. This device embodiment corresponds to the Figure 4 shown method embodiment, and this device can be applied to a differential privacy protection system or a budget management server in this system.
[0148] As Figure 9 shown, the budget processing device 900 based on privacy protection in this embodiment includes: a receiving unit 901, an obtaining unit 903, and a budget processing unit 905. Among them, the receiving unit 901 is configured to receive a budget restoration request for a target data set triggered regularly, where the target data set corresponds to the budget consumption cumulative value of differential privacy protection; the obtaining unit 903 is configured to obtain an unprocessed budget consumption record corresponding to the target data set according to the budget restoration request, where a single budget consumption record includes the budget consumption value generated by a single query for the target data set; the budget processing unit 905 is configured to, for the obtained budget consumption record, if the budget consumption record satisfies the budget restoration condition, reduce the budget consumption cumulative value by the budget consumption value in the budget consumption record.
[0149] In this embodiment, for the specific processing of the receiving unit 901, the obtaining unit 903, and the budget processing unit 905 and the technical effects brought thereby, reference can be respectively made to Figure 4 the relevant descriptions of steps 401, step 403, and step 405 in the corresponding embodiments, which will not be elaborated here.
[0150] The budget processing device based on privacy protection provided in this embodiment, compared with Figure 8 the corresponding device embodiment, highlights the limitation on the triggering method of the budget recovery request and the limitation on the obtained budget consumption records. Therefore, the solution provided in this embodiment can not only achieve Figure 8 the technical effects that the corresponding embodiments can achieve, but also enrich the budget control and management functions.
[0151] Further referring to Figure 10 , as an implementation of the methods shown in some of the above figures, this specification provides another embodiment of a budget processing device based on privacy protection. This device embodiment corresponds to Figure 5 the method embodiment shown, and this device can be applied to a differential privacy protection system or a budget management server in this system.
[0152] As Figure 10 shown, the budget processing device 1000 based on privacy protection in this embodiment includes: a receiving unit 1001, an obtaining unit 1003, and a budget processing unit 1005. Among them, the receiving unit 1001 is configured to receive a budget recovery request triggered by an application party for a target data set, where the target data set corresponds to the cumulative budget consumption value of differential privacy protection, and the budget recovery request includes specified conditions; the obtaining unit 1003 is configured to obtain budget consumption records corresponding to the target data set that meet the specified conditions according to the budget recovery request, where a single budget consumption record includes the budget consumption value generated by a single query for the target data set; the budget processing unit 1005 is configured to, for the obtained budget consumption records, if the budget consumption record meets the budget recovery condition, reduce the cumulative budget consumption value by the budget consumption value in the budget consumption record.
[0153] In this embodiment, for the specific processing of the receiving unit 1001, the obtaining unit 1003, and the budget processing unit 1005 and the technical effects brought thereby, reference can be respectively made to Figure 5 the relevant descriptions of steps 501, step 503, and step 505 in the corresponding embodiments, which will not be elaborated here.
[0154] The budget processing device based on privacy protection provided in this embodiment, compared with Figure 8Compared with the corresponding apparatus embodiments, it highlights the limitation on the triggering manner of the budget recovery request and the limitation on the obtained budget consumption record. Thus, the solution provided in this embodiment can not only achieve Figure 8 the technical effects that the corresponding embodiments can achieve, but also enrich the budget control and management functions. Specifically, it can improve the flexibility of budget recovery processing, enrich the budget management functions of the application party, and improve the user experience.
[0155] Further referring to Figure 11 , as an implementation of the methods shown in some of the above figures, this specification provides an embodiment of an access control apparatus for an application based on privacy protection. This apparatus embodiment corresponds to Figure 6 the method embodiment shown, and this apparatus can be applied to this application or the server side of this application, etc.
[0156] As Figure 11 shown, the access control apparatus 1100 for an application based on privacy protection in this embodiment includes: a receiving unit 1101 and an access control unit 1103. Among them, the receiving unit 1101 is configured to receive a data access request from an application party for a target data set, where the target data set corresponds to the budget consumption cumulative value after budget recovery processing for privacy protection; the access control unit 1103 is configured to determine whether to allow the application party to perform this data access according to the budget consumption cumulative value after budget recovery processing.
[0157] In this embodiment, for the specific processing of the receiving unit 1101 and the access control unit 1103 and the resulting technical effects, reference can be made to Figure 6 the relevant descriptions of step 601 and step 603 in the corresponding embodiments, which will not be elaborated here.
[0158] This specification embodiment also provides a computer-readable storage medium, on which a computer program is stored. When this computer program is executed on a computer, it causes the computer to execute the methods respectively shown in the above method embodiments.
[0159] This specification embodiment also provides a computing device, including a memory and a processor. Among them, an executable code is stored in this memory, and when the processor executes this executable code, it implements the methods respectively shown in the above method embodiments.
[0160] This specification embodiment also provides a computer program product, which when executed on a data processing device, causes the data processing device to implement the methods respectively shown in the above method embodiments.
[0161] Those skilled in the art should be able to realize that in one or more of the above examples, the functions described in the multiple embodiments disclosed in this specification can be implemented by hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium.
[0162] In some cases, the actions or steps recited in the claims can be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0163] The specific embodiments described above further elaborate on the objectives, technical solutions, and beneficial effects of the multiple embodiments disclosed in this specification. It should be understood that the above are only the specific embodiments of the multiple embodiments disclosed in this specification and are not used to limit the protection scope of the multiple embodiments disclosed in this specification. Any modifications, equivalent replacements, improvements, etc. made on the basis of the technical solutions of the multiple embodiments disclosed in this specification should be included in the protection scope of the multiple embodiments disclosed in this specification.
Claims
1. A budget processing method based on privacy protection, comprising: Receiving a budget recovery request for a target data set, wherein the target data set corresponds to an accumulated budget consumption value for differential privacy protection, and the accumulated budget consumption value is obtained by accumulating the budget consumption values of query results from the target data set; According to the budget recovery request, obtaining at least one budget consumption record corresponding to the target data set, wherein a single budget consumption record includes the budget consumption value and budget consumption time generated by a single query for the target data set; For the obtained budget consumption record, if the budget consumption record meets the budget recovery condition, reducing the accumulated budget consumption value by the budget consumption value in the budget consumption record; the budget recovery condition includes any one of the following: after the budget consumption time, the target data set has changed; the budget consumption time is earlier than the start time of the current budget recovery cycle.
2. The method according to claim 1, wherein, After reducing the accumulated budget consumption value by the budget consumption value in the budget consumption record, the method further includes: Generating and storing a budget recovery log corresponding to the budget consumption record.
3. The method according to claim 1, wherein, The receiving a budget recovery request for a target data set includes: Receiving the budget recovery request triggered regularly; and The obtaining at least one budget consumption record corresponding to the target data set includes: Obtaining the budget consumption records corresponding to the target data set that have not been processed for budget recovery as the at least one budget consumption record.
4. The method according to claim 1, wherein The change of the target data set includes: Adding data to the target data set; or Modifying at least one piece of data in the target data set; or Deleting at least one piece of data in the target data set.
5. The method according to claim 1, wherein The receiving a budget recovery request for a target data set includes: Receiving the budget recovery request triggered by an application party, and the budget recovery request includes specified conditions; and The obtaining at least one budget consumption record corresponding to the target data set includes: Obtaining the budget consumption records corresponding to the target data set that meet the specified conditions as the at least one budget consumption record.
6. The method according to claim 5, wherein, Before the step of if the budget consumption record meets the budget recovery condition, the method further includes: Determining whether the budget consumption record meets the specified conditions; In response to determining that the budget consumption record meets the specified conditions, further determining whether the budget consumption record meets the budget recovery condition.
7. The method according to claim 5, wherein, The budget recovery condition includes that the budget consumption record has not been automatically processed for budget recovery.
8. The method according to claim 1, wherein The target data set also corresponds to a single budget consumption value for differential privacy protection; And The method further includes: In response to receiving a query result to be processed from the target data set, determining the budget consumption value of the query result to be processed according to the single budget consumption value; Increasing the accumulated budget consumption value by the budget consumption value of the query result to be processed; Generating and storing a budget consumption record according to the budget consumption value of the query result to be processed.
9. A budget processing method based on privacy protection, comprising: Receive a budget recovery request for a target data set triggered periodically, where the target data set corresponds to the cumulative value of budget consumption for differential privacy protection, and the cumulative value of budget consumption is obtained by accumulating the budget consumption values of query results from the target data set; According to the budget recovery request, obtain the budget consumption record of the target data set that has not been processed for budget recovery, where a single budget consumption record includes the budget consumption value and budget consumption time generated by a single query for the target data set; For the obtained budget consumption record, if the budget consumption record meets the budget recovery condition, reduce the cumulative value of budget consumption by the budget consumption value in the budget consumption record; the budget recovery condition includes any one of the following: after the budget consumption time, the target data set has changed; the budget consumption time is earlier than the start time of the current budget recovery cycle.
10. A budget processing method based on privacy protection, including: Receive a budget recovery request for a target data set triggered by an application party, where the target data set corresponds to the cumulative value of budget consumption for differential privacy protection, the budget recovery request includes specified conditions, and the cumulative value of budget consumption is obtained by accumulating the budget consumption values of query results from the target data set; According to the budget recovery request, obtain the budget consumption record of the target data set that meets the specified conditions, where a single budget consumption record includes the budget consumption value and budget consumption time generated by a single query for the target data set; For the obtained budget consumption record, if the budget consumption record meets the budget recovery condition, reduce the cumulative value of budget consumption by the budget consumption value in the budget consumption record; the budget recovery condition includes any one of the following: after the budget consumption time, the target data set has changed; the budget consumption time is earlier than the start time of the current budget recovery cycle.
11. A budget processing method based on privacy protection, including: Receive a budget recovery request for a target data set, where the target data set corresponds to the cumulative value of budget consumption for privacy protection, and the cumulative value of budget consumption is obtained by accumulating the budget consumption values of query results from the target data set; According to the budget recovery request, obtain at least one budget consumption record of the target data set, where a single budget consumption record includes the budget consumption value and budget consumption time generated by a single query for the target data set; For the obtained budget consumption record, if the budget consumption record meets the budget recovery condition, reduce the cumulative value of budget consumption by the budget consumption value in the budget consumption record; the budget recovery condition includes any one of the following: after the budget consumption time, the target data set has changed; the budget consumption time is earlier than the start time of the current budget recovery cycle.
12. An access control method for an application based on privacy protection, including: Receive a data access request for a target data set from an application party, where the target data set corresponds to a budget consumption cumulative value after privacy protection and budget recovery processing, and the budget consumption cumulative value is obtained by accumulating the budget consumption values of query results from the target data set; the budget recovery processing is implemented by using the method described in claim 1. Determine whether to allow the application party to perform this data access according to the budget consumption cumulative value after the budget recovery processing.
13. A budget processing device based on privacy protection, comprising: A receiving unit configured to receive a budget recovery request for a target data set, where the target data set corresponds to a budget consumption cumulative value of differential privacy protection, and the budget consumption cumulative value is obtained by accumulating the budget consumption values of query results from the target data set. An obtaining unit configured to obtain at least one budget consumption record corresponding to the target data set according to the budget recovery request, where a single budget consumption record includes the budget consumption value and budget consumption time generated by a single query for the target data set. A budget processing unit configured to, for the obtained budget consumption record, if the budget consumption record meets the budget recovery condition, reduce the budget consumption cumulative value by the budget consumption value in the budget consumption record; the budget recovery condition includes any one of the following: after the budget consumption time, the target data set has changed; the budget consumption time is earlier than the start time of the current budget recovery cycle.
14. A budget processing device based on privacy protection, comprising: A receiving unit configured to receive a periodically triggered budget recovery request for a target data set, where the target data set corresponds to a budget consumption cumulative value of differential privacy protection, and the budget consumption cumulative value is obtained by accumulating the budget consumption values of query results from the target data set. An obtaining unit configured to obtain an unprocessed budget consumption record corresponding to the target data set according to the budget recovery request, where a single budget consumption record includes the budget consumption value and budget consumption time generated by a single query for the target data set. A budget processing unit configured to, for the obtained budget consumption record, if the budget consumption record meets the budget recovery condition, reduce the budget consumption cumulative value by the budget consumption value in the budget consumption record; the budget recovery condition includes any one of the following: after the budget consumption time, the target data set has changed; the budget consumption time is earlier than the start time of the current budget recovery cycle.
15. A budget processing device based on privacy protection, comprising: A receiving unit configured to receive a budget recovery request for a target data set triggered by an application party, where the target data set corresponds to a budget consumption cumulative value of differential privacy protection, the budget recovery request includes specified conditions, and the budget consumption cumulative value is obtained by accumulating the budget consumption values of query results from the target data set. An acquisition unit, configured to acquire budget consumption records corresponding to the target data set that meet the specified conditions according to the budget recovery request, where a single budget consumption record includes a budget consumption value and a budget consumption time generated for a single query of the target data set; A budget processing unit, configured to, for the acquired budget consumption records, if the budget consumption record meets the budget recovery conditions, reduce the budget consumption cumulative value by the budget consumption value in the budget consumption record; the budget recovery conditions include any one of the following: after the budget consumption time, the target data set changes; the budget consumption time is earlier than the start time of the current budget recovery cycle.
16. A budget processing device based on privacy protection, comprising: A receiving unit, configured to receive a budget recovery request for a target data set, where the target data set corresponds to a budget consumption cumulative value for privacy protection, and the budget consumption cumulative value is obtained by accumulating budget consumption values of query results from the target data set; An acquisition unit, configured to acquire at least one budget consumption record corresponding to the target data set according to the budget recovery request, where a single budget consumption record includes a budget consumption value and a budget consumption time generated for a single query of the target data set; A budget processing unit, configured to, for the acquired budget consumption records, if the budget consumption record meets the budget recovery conditions, reduce the budget consumption cumulative value by the budget consumption value in the budget consumption record; the budget recovery conditions include any one of the following: after the budget consumption time, the target data set changes; the budget consumption time is earlier than the start time of the current budget recovery cycle.
17. An access control device for an application based on privacy protection, comprising: A receiving unit, configured to receive a data access request from an application party for a target data set, where the target data set corresponds to a budget consumption cumulative value after budget recovery processing for privacy protection, and the budget consumption cumulative value is obtained by accumulating budget consumption values of query results from the target data set; the budget recovery processing is implemented by using the device according to claim 14; An access control unit, configured to determine whether to allow the application party to perform the current data access according to the budget consumption cumulative value after the budget recovery processing.
18. A computer-readable storage medium having a computer program stored thereon, wherein, When the computer program is executed on a computer, the computer is made to execute the method according to any one of claims 1-12.
19. A computing device, comprising a memory and a processor, wherein, The memory stores executable code, and when the processor executes the executable code, the method according to any one of claims 1-12 is implemented.
Citation Information
Patent Citations
Differential privacy budget allocation-based data query method and system
CN108197492A
A multi-privacy budget local differential privacy data sharing method and system
CN109902506A
Information processing method and device capable of protecting privacy
CN114386082A
Differentially Private Query Budget Refunding
US20200250335A1