De-identified information transmission method, device, equipment and computer-readable medium

Through the deidentified information transmission method, the encryption algorithm and mapping algorithm are used to process information requests, and combined with the target duplicate information database, the problem of insufficient security of information transmission is solved, and information isolation and secure transmission are realized.

CN114428973BActive Publication Date: 2025-09-02BEIJING STAR RIVER EXCELLENCE TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210086891.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-25
Publication Date
2025-09-02
Estimated Expiration
2042-01-25

AI Technical Summary

Technical Problem

During the existing information transmission process, it is difficult for the information requesting party and the information provider to ensure the security of information, resulting in the leakage of redundant data and confidential information.

Method used

The deidentified information transmission method is adopted to obtain the request by encrypting the information through the first encryption algorithm, and map it into local information and encrypted information using the corresponding mapping algorithm, and determine the target local information in combination with the target duplicate information database, and finally send the encrypted information through the mapping algorithm to achieve information isolation.

Benefits of technology

The security of information transmission is improved, the information requesting terminal and the execution subject are prevented from knowing the other party's local information, and information isolation is realized to ensure the security of information transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114428973B_ABST
    Figure CN114428973B_ABST
Patent Text Reader

Abstract

The embodiments of the present disclosure disclose a de-identified information transmission method, device, electronic device, and computer-readable medium. A specific implementation of the method includes: a trusted third-party device receives an information acquisition request and a target terminal identification sent by an information request terminal; maps the information acquisition request to first local information and second local information through a first mapping algorithm corresponding to the above-mentioned first encryption algorithm; determines a target duplicate information database; queries the target local information corresponding to the above-mentioned second local information in the first local information in the above-mentioned target duplicate information database; maps the above-mentioned target local information to target encrypted information through the above-mentioned first mapping algorithm, and then sends the above-mentioned target encrypted information to the above-mentioned information request terminal. This implementation improves the security of information transmission, ensures the information security of each participant in the information flow, and prevents the leakage of redundant information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present disclosure relate to the field of data processing technology, and more particularly to de-identified information transmission methods, devices, equipment, and computer-readable media. Background Art

[0002] With the development of information technology and the advancement of network technology, various information can be quickly transmitted through the network. Generally, the information requester can send a request to the information provider to obtain information. The information provider sends the target information to the information requester based on the request.

[0003] When information is transmitted between existing information requesters and information providers, although the target information can be encrypted, it is difficult to ensure information security during the transmission process, and redundant data and confidential information of the information requester may be leaked. Summary of the Invention

[0004] The content of this disclosure is used to briefly introduce concepts that will be described in detail in the detailed description section below. The content of this disclosure is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.

[0005] Some embodiments of the present disclosure propose de-identified information transmission methods, devices, equipment, and computer-readable media to solve the technical problems mentioned in the above background technology section.

[0006] In a first aspect, some embodiments of the present disclosure provide a de-identified information transmission method, which includes: receiving an information acquisition request and a target terminal identifier sent by an information requesting terminal, the information acquisition request being obtained by encrypting the first portrait information and target request information of the user to be processed by a first encryption algorithm on the information requesting terminal, the information acquisition request including first encryption information corresponding to the first portrait information and second encryption information corresponding to the target request information, the target terminal identifier being used to indicate that the target information corresponding to the target request information is obtained from the target terminal; mapping the information acquisition request into first local information and second local information through a first mapping algorithm corresponding to the first encryption algorithm, the first local information corresponding to the first encryption information, and the second local information corresponding to the second encryption information; determining a target duplicate information database, the target duplicate information database being composed of duplicate information in the target terminal corresponding to the information requesting terminal and the target terminal identifier; in response to the presence of the first local information in the target duplicate information database, querying the target local information corresponding to the second local information in the first local information in the target duplicate information database; after mapping the target local information into target encrypted information through the first mapping algorithm, sending the target encrypted information to the information requesting terminal.

[0007] In the second aspect, some embodiments of the present disclosure provide a de-identified information acquisition method, which includes: in response to obtaining business request information of a user to be processed, querying the target information of the business request information; in response to the absence of the above-mentioned target information, querying the target terminal identifier of the target terminal corresponding to the above-mentioned target information, and constructing target request information corresponding to the above-mentioned target information, wherein the above-mentioned target terminal identifier is used to indicate that the target information corresponding to the target request information is obtained from the target terminal; querying the first portrait information of the above-mentioned user to be processed, encrypting the above-mentioned first portrait information and the target request information through a first encryption algorithm to obtain an information acquisition request; sending the above-mentioned information acquisition request and the target terminal identifier to an information query server; in response to receiving the target encrypted information corresponding to the above-mentioned target request information sent by the above-mentioned information query server, decrypting the above-mentioned target encrypted information through a first decryption algorithm corresponding to the above-mentioned first encryption algorithm to obtain the target information.

[0008] On the third aspect, some embodiments of the present disclosure provide a de-identified information transmission device, which includes: a first information receiving unit, configured to receive an information acquisition request and a target terminal identifier sent by an information requesting terminal, the information acquisition request being obtained by encrypting the first portrait information and the target request information of the user to be processed by a first encryption algorithm on the information requesting terminal, the information acquisition request including the first encrypted information corresponding to the first portrait information and the second encrypted information corresponding to the target request information, the target terminal identifier being used to indicate that the target information corresponding to the target request information is obtained from the target terminal; an information mapping unit, configured to map the information acquisition request into a first encrypted information corresponding to the first encryption algorithm. local information and second local information, the first local information corresponding to the first encrypted information, and the second local information corresponding to the second encrypted information; an information library determination unit, configured to determine a target duplicate information library, the target duplicate information library being composed of duplicate information in a target terminal corresponding to the information request terminal and the target terminal identifier; an information query unit, configured to, in response to the presence of the first local information in the target duplicate information library, query the first local information in the target duplicate information library for target local information corresponding to the second local information; a first information sending unit, configured to map the target local information to target encrypted information using the first mapping algorithm, and then send the target encrypted information to the information request terminal.

[0009] In a fourth aspect, some embodiments of the present disclosure provide a de-identified information acquisition device, which includes: a target information query unit, configured to query the target information of the business request information in response to obtaining the business request information of the user to be processed; a target request information construction unit, configured to query the target terminal identifier of the target terminal corresponding to the above-mentioned target information in response to the absence of the above-mentioned target information, and construct target request information corresponding to the above-mentioned target information, wherein the above-mentioned target terminal identifier is used to indicate that the target information corresponding to the target request information is obtained from the target terminal; an information acquisition request acquisition unit, configured to query the first portrait information of the above-mentioned user to be processed, and encrypt the above-mentioned first portrait information and target request information through a first encryption algorithm to obtain an information acquisition request; a second information sending unit, configured to send the above-mentioned information acquisition request and target terminal identifier to an information query server; a second information receiving unit, configured to decrypt the above-mentioned target encrypted information through a first decryption algorithm corresponding to the above-mentioned first encryption algorithm in response to receiving the target encrypted information corresponding to the above-mentioned target request information sent by the above-mentioned information query server, to obtain the target information.

[0010] In a fifth aspect, some embodiments of the present disclosure provide an electronic device comprising: one or more processors; a storage device on which one or more programs are stored, wherein when the one or more programs are executed by one or more processors, the one or more processors implement the method described in any implementation of the first or second aspect above.

[0011] In a sixth aspect, some embodiments of the present disclosure provide a computer-readable medium having a computer program stored thereon, wherein when the program is executed by a processor, the method described in any implementation of the first or second aspect above is implemented.

[0012] The above-described embodiments of the present disclosure have the following beneficial effects: Information transmission security is improved through the de-identified information transmission methods of some embodiments of the present disclosure. Specifically, the reason for the low security of information transmission is that both parties in the information transmission know each other's local information. Based on this, the de-identified information transmission methods of some embodiments of the present disclosure receive an information acquisition request encrypted using a first encryption algorithm. Therefore, the executing entity cannot know the local information of the first encrypted information and the second encrypted information contained in the information acquisition request on the information requesting terminal. The executing entity then maps the information acquisition request into the first local information and the second local information using a first mapping algorithm corresponding to the first encryption algorithm. The executing entity then determines the target local information corresponding to the second encrypted information using a target duplicate information database corresponding to the information requesting terminal. Finally, the target local information is mapped into the target encrypted information using the first mapping algorithm and sent to the information requesting terminal. Therefore, the information requesting terminal does not receive the target local information on the executing entity. This prevents the information requesting terminal and the executing entity from knowing each other's local information, achieving information isolation and improving the security of information transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] The above and other features, advantages, and aspects of the various embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that components and elements are not necessarily drawn to scale.

[0014] Figure 1 is a schematic diagram of an application scenario of the de-identified information transmission method according to some embodiments of the present disclosure;

[0015] Figure 2 is a flowchart of some embodiments of the de-identified information transmission method according to the present disclosure;

[0016] Figure 3 is a flowchart of other embodiments of the method for constructing a target duplication information library according to the present disclosure;

[0017] Figure 4 are flowcharts of further embodiments of the de-identified information acquisition method according to the present disclosure;

[0018] Figure 5 is a schematic structural diagram of some embodiments of a de-identified information transmission device according to the present disclosure;

[0019] Figure 6 is a schematic structural diagram of some embodiments of a de-identified information acquisition device according to the present disclosure;

[0020] Figure 7 It is a structural diagram of an electronic device suitable for implementing some embodiments of the present disclosure. DETAILED DESCRIPTION

[0021] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as being limited to the embodiments described herein. On the contrary, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.

[0022] It should also be noted that, for ease of description, only the parts related to the invention are shown in the drawings. In the absence of conflict, the embodiments and features in the embodiments of the present disclosure may be combined with each other.

[0023] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0024] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, they should be understood as "one or more".

[0025] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.

[0026] The present disclosure will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments.

[0027] Figure 1 It is a schematic diagram of an application scenario of the de-identified information transmission method according to some embodiments of the present disclosure.

[0028] like Figure 1As shown, the present application may include an information request terminal 101 (i.e., the information requester) and an information query server 102. Information query server 102 is, in practice, a trusted third-party device. In practice, information query server 102 can establish data mapping algorithms with multiple devices, each of which is different from the other. This allows data isolation. For example, terminal A has data A, and terminal B also has data A. Terminal A encrypts data A into string A using its own encryption algorithm A. It then sends string A to information query server 102. After receiving string A, information query server 102 queries for the data mapping algorithm A corresponding to encryption algorithm A on terminal A and maps string A into string A' using data mapping algorithm A. Similarly, terminal B encrypts data A into string B using its own encryption algorithm B. It then sends string B to information query server 102. After receiving string B, information query server 102 queries for the data mapping algorithm B corresponding to encryption algorithm B on terminal B and maps string B into string A' using data mapping algorithm B. The encryption algorithm A on terminal A is different from the encryption algorithm B on terminal B. Therefore, string A and string B are different. To perform data comparison, information query server 102 needs to map string A to string A' using data mapping algorithm A, and map string B to string A' using data mapping algorithm B. Only in this way can information query server 102 determine whether the same data A exists on terminals A and B. Clearly, data mapping algorithm A corresponds to encryption algorithm A, and data mapping algorithm B corresponds to encryption algorithm B. Furthermore, both data mapping algorithm A and data mapping algorithm B generate string A'. That is, the same data processed using encryption algorithm A and data mapping algorithm A produces the same result as the same data processed using encryption algorithm B and data mapping algorithm B. This allows the same data on different terminals to be converted into the same data in a different format. Furthermore, string A' differs from data A on terminals A and B. Therefore, information query server 102 can only locally know string A' but not the corresponding data on terminals A and B. Similarly, terminals A and B cannot know the corresponding data on information query server 102 for their own data. Terminal A and Terminal B do not exchange information directly. Instead, they first exchange information with the information query server 102, which then exchanges information with Terminal B. Because Terminal A and Terminal B use different encryption algorithms, and the data on Terminal A and Terminal B must be compared using different data mapping algorithms on the information query server 102, Terminal A and Terminal B cannot know whether their data also exists on the other party. Even if both parties have the same data, they cannot determine which of their data is identical to which data on the other party.Through encryption and data mapping algorithms, Terminal A, Terminal B, and information query server 102 can only access their own local data and are unable to access data on other terminals. This achieves data isolation between multiple devices and ensures data transmission security. Optionally, each device can have multiple encryption algorithms, and information query server 102 can also have multiple data mapping algorithms to further improve the reliability of data isolation.

[0029] like Figure 1 As shown, information request terminal 101 (i.e., the information requester) can send an information acquisition request and a target terminal identifier to information query server 102. The information acquisition request can be obtained by encrypting the first profile information and target request information on information request terminal 101 using a first encryption algorithm. Accordingly, the information acquisition request includes first encrypted information corresponding to the first profile information and second encrypted information corresponding to the target request information. The first profile information is used to represent the pending user on information request terminal 101, and the target request information is used to represent the specified information of the pending user, i.e., the target information. For example, if the pending user applies for a service on information request terminal 101, information request terminal 101 first obtains the first profile information of the pending user and then queries the first profile information for information related to the requested service. If the information is present in the first profile information, information request terminal 101 can directly process the service for the pending user based on this information; if the information is not present in the first profile information, information request terminal 101 can set this information as the target information. The corresponding target request information can be used to describe the target information. For example, if the target information is academic qualifications, the target request information may be: "Obtain academic qualifications information." To obtain the target information, the information requesting terminal 101 may determine the target terminal identifier. The target terminal identifier represents the target terminal for which the target information may be present. In practice, the information requesting terminal 101 and the target terminal may be devices handling the same or similar services, and therefore may contain information related to the service.

[0030] After receiving the information acquisition request and the target terminal identifier from the information request terminal 101, the information query server 102 may map the information acquisition request into first local information and second local information using a first mapping algorithm corresponding to the first encryption algorithm on the information request terminal 101. The first local information corresponds to the first encrypted information, and the second local information corresponds to the second encrypted information.

[0031] Next, the information query server 102 can query the target duplicate information repository corresponding to the target terminal. The target duplicate information repository contains duplicate information for both the information requesting terminal 101 and the target terminal. For example, if duplicate information A exists in the target duplicate information repository, it indicates that both the information requesting terminal 101 and the target terminal contain duplicate information A. As can be seen from the above description, the same information is presented differently on the terminal and the information query server 102, thereby achieving information isolation and improving information security. If the first local information exists in the target duplicate information repository, it indicates that the first profile information of the user to be processed on the information requesting terminal 101 also exists on the target terminal. Furthermore, the information query server 102 can query the first local information in the target duplicate information repository for the target local information corresponding to the second local information. The target local information can be processed using the first mapping algorithm and the first decryption algorithm corresponding to the first encryption algorithm to obtain the target information. In this way, the target information required by the information requesting terminal 101 is found. Finally, the information query server 102 can use the first mapping algorithm to map the target local information into target encrypted information and then send the target encrypted information to the information requesting terminal 101. During this process, the information request terminal 101 and the target terminal transmit information through the information query server 102. The information query server 102 receives an encrypted information acquisition request, and is unable to determine the first portrait information and target request information on the information request terminal 101 based on the information acquisition request. This de-identifies the information. At the same time, the information request terminal 101 receives the target encrypted information mapped to the target local information of the information query server 102, and is unable to obtain the target local information of the information query server 102. This achieves information isolation between the information request terminal 101 and the information query server 102, ensuring the information security of all parties involved in the information flow and preventing the leakage of redundant information.

[0032] It should be understood that Figure 1 The number of information query servers 102, information request terminals 101 and target terminals in the embodiment is merely illustrative. Any number of information query servers 102, information request terminals 101 and target terminals may be provided according to implementation requirements.

[0033] Continue to refer Figure 2 , Figure 2 A process 200 of some embodiments of the de-identified information transmission method according to the present disclosure is shown. The de-identified information transmission method includes the following steps:

[0034] Step 201: Receive an information acquisition request and a target terminal identifier sent by an information requesting terminal.

[0035] In some embodiments, the execution subject of the de-identified information transmission method (e.g. Figure 1 The information query server 102 shown in the figure can receive the information acquisition request and the target terminal identifier from the information request terminal 101 via a wired connection or a wireless connection. It should be noted that the above-mentioned wireless connection method may include but is not limited to 3G / 4G / 5G connection, WiFi connection, Bluetooth connection, WiMAX connection, Zigbee connection, UWB (Ultra Wide Band) connection, and other wireless connection methods currently known or to be developed in the future.

[0036] In order to improve the security of information transmission, the information request terminal 101 stores a first encryption algorithm and a corresponding first decryption algorithm. When information needs to be sent, the information request terminal 101 encrypts the information using the first encryption algorithm; when the information request terminal 101 receives the result information corresponding to the sent information, it decrypts the result information using the first decryption algorithm. That is, the above-mentioned information acquisition request is obtained by encrypting the first portrait information and target request information of the user to be processed by the first encryption algorithm on the above-mentioned information request terminal 101. The target request information is used to indicate the acquisition of target information, and the above-mentioned target information is the information missing in the first portrait information. The above-mentioned information acquisition request includes the first encrypted information corresponding to the first portrait information and the second encrypted information corresponding to the target request information. The above-mentioned target terminal identifier is used to indicate the acquisition of the target information corresponding to the target request information from the target terminal.

[0037] Step 202: Map the information acquisition request into first local information and second local information using a first mapping algorithm corresponding to the first encryption algorithm.

[0038] In some embodiments, after receiving an information retrieval request, the execution entity may map the information retrieval request into first local information and second local information using a first mapping algorithm corresponding to the first encryption algorithm. The first local information corresponds to the first encrypted information, and the second local information corresponds to the second encrypted information. Preferably, the first local information and the first encrypted information may be of different information types, and the second local information and the second encrypted information may be of different information types.

[0039] Step 203: Determine the target duplicate information database.

[0040] In some embodiments, the execution entity can establish information communication with multiple different terminal devices and obtain information on each terminal. Then, a duplicate information library is established on different terminals. That is, the target duplicate information library is composed of duplicate information in the target terminal corresponding to the information request terminal and the target terminal identifier. In this way, the execution entity can directly determine locally whether there is target local information corresponding to the target information of the information request terminal 101 through the duplicate information library. In this way, the transmission of de-identified information between the execution entity and the target device is reduced, the risk of information leakage is reduced, and information security is improved. At the same time, determining the target local information locally on the execution entity also improves information processing efficiency.

[0041] Step 204: In response to the existence of the first local information in the target duplicate information database, query the target duplicate information database for target local information corresponding to the second local information in the first local information.

[0042] In some embodiments, when the first local information exists in the target duplicate information database, it indicates that both the information requesting terminal 101 and the target terminal have the first profile information of the user to be processed. At this point, the executing entity can query the target local information corresponding to the second local information from the first local information. The target local information can be processed using the first mapping algorithm and the first decryption algorithm corresponding to the first encryption algorithm to obtain the target information. In other words, the target local information is the target information required by the information requesting terminal 101, as represented on the executing entity. For example, the target information can be Chinese characters, and the target local information can be a string of characters.

[0043] Step 205: After mapping the target local information into target encrypted information through the first mapping algorithm, the target encrypted information is sent to the information requesting terminal.

[0044] After determining the target local information, the execution entity can again use the first mapping algorithm to map the target local information into target encrypted information and send the target encrypted information to the information request terminal 101. During this process, the execution entity obtains the encrypted first and second encrypted information. Therefore, the execution entity cannot know the corresponding information of the first and second encrypted information on the information request terminal 101. Information request terminal 101 obtains the target encrypted information, so it cannot know the target local information of the target encrypted information on the execution entity's local computer. This achieves information isolation and secure information transmission.

[0045] In some optional implementations of some embodiments, after mapping the target local information to target encrypted information using the first mapping algorithm, sending the target encrypted information to the information requesting terminal may include the following steps:

[0046] In the first step, in response to the absence of target local information corresponding to the second encrypted information, dummy information is set for the second encrypted information for which the target local information does not exist.

[0047] In practice, the information requesting terminal may send multiple information acquisition requests, and each information acquisition request may contain multiple second encrypted information. The executing entity may find the corresponding target local information, or it may not find the target local information. If the executing entity only maps the found target local information into target encrypted information and sends it to the information requesting terminal, the information requesting terminal will know how many pieces of information on the information requesting terminal are on the target terminal, thereby causing indirect information leakage to a certain extent. To this end, when there is no target local information corresponding to the second encrypted information, the executing entity can set corresponding virtual information for the second encrypted information for which there is no target local information. The above-mentioned virtual information is set with a virtual identifier. The above-mentioned virtual identifier is used to indicate that the corresponding virtual information is invalid. For example, the virtual information can be information of the same type as the local information. The executing entity can set a specified virtual identifier at the beginning, specified position, or end position of the content of the information to indicate that the information is actually invalid.

[0048] The second step is to encapsulate the virtual information and the target local information into an information packet.

[0049] The executing entity can encapsulate the target local information corresponding to the second encrypted information, as well as dummy information for second encrypted information that does not have corresponding target local information, into an information packet. The number of pieces of information in the information packet is the same as the number of pieces of second encrypted information. In this way, regardless of whether the target local information is found, the information requesting terminal will receive the same amount of information. This further prevents indirect information leakage and improves the security of information transmission.

[0050] In the third step, after mapping the information packet into target encrypted information through the first mapping algorithm, the target encrypted information is sent to the information requesting terminal.

[0051] Afterwards, the execution entity may map the information packet into target encrypted information and send the target encrypted information to the information requesting terminal.

[0052] In some optional implementations of some embodiments, the above-mentioned encapsulation of the above-mentioned virtual information and the above-mentioned target local information into an information package may include: setting an information tag for the target local information corresponding to each second encrypted information, and the above-mentioned information tag is used to indicate the target request information corresponding to the target local information.

[0053] After adding the virtual information, the information request terminal can obtain the target local information that is the same as the second encrypted information. After the information request terminal obtains the target encrypted information, it can decrypt the information packet from the target encrypted information, and then obtain the target information and invalid information of the corresponding virtual information. In practice, the information request terminal needs to perform business processing based on the valid target information. If the information request terminal obtains multiple target local information, it is possible that the target local information cannot be matched with the corresponding target information. For this reason, the present application also sets an information tag for the target local information. To indicate which target information the target local information corresponds to. In this way, the information request terminal can accurately obtain the target information, thereby improving the accuracy and effectiveness of information matching.

[0054] The de-identified information transmission method disclosed in some embodiments of the present disclosure transmits information, improving the security of information transmission. Specifically, the reason for the low security of information transmission is that both parties in the information transmission know each other's local information. Based on this, the de-identified information transmission method in some embodiments of the present disclosure receives an information acquisition request encrypted using a first encryption algorithm. Therefore, the executing entity cannot know the local information of the first encrypted information and second encrypted information contained in the information acquisition request on the information requesting terminal. The executing entity then maps the information acquisition request into the first local information and the second local information using a first mapping algorithm corresponding to the first encryption algorithm. The executing entity then determines the target local information corresponding to the second encrypted information using a target duplicate information database corresponding to the information requesting terminal. Finally, the target local information is mapped into the target encrypted information using the first mapping algorithm and sent to the information requesting terminal. Therefore, the information requesting terminal does not receive the target local information on the executing entity. This prevents the information requesting terminal and the executing entity from knowing each other's local information, achieving information isolation and improving the security of information transmission.

[0055] Continue to refer Figure 3 , Figure 3 The process 300 of some embodiments of the target duplicate information library construction method according to the present disclosure is shown. The target duplicate information library construction method includes the following steps:

[0056] Step 301: Receive the first information database sent by the information request terminal and the second information database sent by the target terminal.

[0057] In order to directly query the target local information from the target duplicate information database, the execution entity needs to first build the target duplicate information database. The execution entity can receive the first information database sent by the above-mentioned information request terminal and the second information database sent by the above-mentioned target terminal. Here, each first information in the above-mentioned first information database is obtained by encrypting the corresponding first portrait information on the information request terminal using the first encryption algorithm on the above-mentioned information request terminal. Each second information in the above-mentioned second information database is obtained by encrypting the corresponding second portrait information on the target terminal using the second encryption algorithm on the above-mentioned target terminal.

[0058] Step 302: Map each first information in the first information base into first local information by using a first mapping algorithm corresponding to the first encryption algorithm to obtain a first local information base.

[0059] The execution entity may search for a first mapping algorithm corresponding to the first encryption algorithm, and map each first information into first local information.

[0060] Step 303: Map each second information in the second information base into second local information by using a second mapping algorithm corresponding to the second encryption algorithm to obtain a second local information base.

[0061] The execution entity can search for the second mapping algorithm corresponding to the second encryption algorithm and map each second information into second local information. As can be seen from the above description, the information obtained by applying the first encryption algorithm and the first mapping algorithm to a certain information is the same as the information obtained by applying the second encryption algorithm and the second mapping algorithm to the same information. In other words, the information type of the second local information is the same as the information type of the first local information, making comparison possible.

[0062] Step 304: construct a target duplicate information database using the same portrait information in the first local information database and the second local information database.

[0063] The executing entity can merge the information contained in the same profile information to obtain the target duplicate information. For example, the profile information of the user to be processed on the information request terminal contains 3 pieces of information, and the profile information of the same user to be processed on the target terminal contains 5 pieces of information. And 2 pieces of information exist in both the above 3 pieces of information and the above 5 pieces of information. Then the executing entity can merge the above 3 pieces of information and 5 pieces of information to obtain 6 pieces of information about the user to be processed. It can be seen that the target duplicate information on the executing entity contains all the information of the same profile information on multiple terminals.

[0064] Further references Figure 4 , which shows a process 400 of another embodiment of a method for obtaining de-identified information. The process 400 of the method for obtaining de-identified information includes the following steps:

[0065] Step 401: In response to obtaining the service request information of the user to be processed, query the target information of the service request information.

[0066] In some embodiments, the execution subject (e.g. Figure 1 When accepting a request for a service from a pending user, the information request terminal 101 can obtain the user's service request information and query the target information of the service request information. The target information can be information required to process the service. For example, if the service is to purchase real estate, the target information can be the user's existing real estate information.

[0067] Step 402: In response to the absence of the target information, query the target terminal identifier of the target terminal corresponding to the target information, and construct target request information corresponding to the target information.

[0068] In some embodiments, when the target information exists locally on the executing entity, the business can be processed directly using the target information. If the target information does not exist, the executing entity can query the target terminal identifier of the target terminal where the target information may exist and construct a target request message. The target terminal identifier is used to indicate that the target information corresponding to the target request message should be obtained from the target terminal. For example, if the target information is real estate information, the target terminal can be a device such as a bank server that contains the real estate information of the user to be processed, and the target terminal identifier can be the bank identifier of the corresponding bank server. The target request message can be: Obtain real estate information.

[0069] Step 403: query the first portrait information of the user to be processed, encrypt the first portrait information and target request information through a first encryption algorithm to obtain an information acquisition request.

[0070] In some embodiments, the target terminal typically contains information on multiple users. To accurately obtain the target information of the user to be processed, the executing entity needs to query the first profile information of the user to be processed and encrypt the first profile information and the target request information using a first encryption algorithm to obtain an information acquisition request. That is, the information acquisition request includes the first encrypted information corresponding to the first profile information and the second encrypted information corresponding to the target request information.

[0071] Step 404: Send the information acquisition request and the target terminal identifier to the information query server.

[0072] In some embodiments, the execution entity may send the information acquisition request and the target terminal identifier to Figure 1 The information query server 102 shown. The information query server 102 can be Figure 2 and Figure 3The corresponding embodiment method queries the target local information corresponding to the target information and returns the target encrypted information.

[0073] Step 405: In response to receiving the target encrypted information corresponding to the target request information sent by the information query server, the target encrypted information is decrypted using a first decryption algorithm corresponding to the first encryption algorithm to obtain target information.

[0074] In some embodiments, when the executing entity receives the target encrypted information corresponding to the target request information, it decrypts the target encrypted information using a first decryption algorithm corresponding to the first encryption algorithm to obtain the target information. During this process, the target encrypted information obtained by the executing entity is not local to the information query server 102, so there is no possibility of information leakage from the information query server 102 to the executing entity. Furthermore, the information query server 102 also receives an encrypted information retrieval request, and the information query server 102 is unable to know the local information of the executing entity. This achieves information isolation and ensures the security of information transmission.

[0075] In some optional implementations of some embodiments, decrypting the target encrypted information using a first decryption algorithm corresponding to the first encryption algorithm to obtain the target information may include the following steps:

[0076] The first step is to decrypt the target encrypted information to obtain at least one target information to be processed.

[0077] The execution subject can decrypt at least one piece of target information to be processed from the target encrypted information using a first decryption algorithm.

[0078] In the second step, for the at least one piece of target information to be processed, if the target information to be processed includes a virtual identifier, the target information to be processed is marked invalid; otherwise, the target information to be processed is marked valid.

[0079] In practice, the target information may not be found. To prevent information leakage, the information query server 102 can construct virtual information to replace the target information. The virtual information itself serves to compensate for the number of target information that has not been found. To enable the executing entity to identify the virtual information, the information query server 102 sets a virtual identifier for the virtual information. When the executing entity detects that the target information to be processed contains the virtual identifier, it can be identified as virtual information constructed by the information query server 102. At this time, the executing entity can locally mark the target information to be processed as invalid. Otherwise, it marks the target information to be processed as valid.

[0080] In some optional implementations of some embodiments, decrypting the target encrypted information using a first decryption algorithm corresponding to the first encryption algorithm to obtain the target information may include the following steps:

[0081] In the first step, in response to the fact that there are multiple valid target information to be processed, an information tag is parsed from each target information to be processed.

[0082] When there are multiple valid target information to be processed, it is also necessary to determine which target user each valid target information to be processed corresponds to. The execution entity can parse the information tag from each target information to be processed, and the information tag is used to indicate the target request information corresponding to the target local information.

[0083] The second step is to determine the target information to be processed corresponding to the business request information based on the above information tags.

[0084] The information tag is used to indicate the target request information of the execution entity corresponding to the target local information of the information query server 102. Furthermore, the execution entity can use the target request information to determine the corresponding user to be processed. This achieves accurate matching of multiple target information to be processed with the user to be processed, ensuring the effectiveness of the services handled by the user to be processed.

[0085] In some optional implementations of some embodiments, the above method may further include: generating business information based on the above target information.

[0086] After obtaining the target information, the execution entity can perform business processing based on the target information to generate business information.

[0087] Further references Figure 5 As an implementation of the methods shown in the above figures, the present disclosure provides some embodiments of a de-identified information transmission device. These device embodiments are similar to Figure 2 Corresponding to the method embodiments shown, the device can be specifically applied to various electronic devices.

[0088] like Figure 5As shown, some embodiments of the de-identified information transmission device 500 include: a first information receiving unit 501, an information mapping unit 502, an information library determination unit 503, an information query unit 504 and a first information sending unit 505. The first information receiving unit 501 is configured to receive an information acquisition request and a target terminal identifier sent by an information request terminal, the information acquisition request is obtained by encrypting the first portrait information and the target request information of the user to be processed by the first encryption algorithm on the information request terminal, the information acquisition request includes the first encrypted information corresponding to the first portrait information and the second encrypted information corresponding to the target request information, and the target terminal identifier is used to indicate that the target information corresponding to the target request information is obtained from the target terminal; the information mapping unit 502 is configured to map the information acquisition request into first local information and second local information through a first mapping algorithm corresponding to the first encryption algorithm, and the first local information The information corresponds to the first encrypted information, and the second local information corresponds to the second encrypted information; the information database determining unit 503 is configured to determine a target duplicate information database, where the target duplicate information database is composed of duplicate information in the target terminal corresponding to the information requesting terminal and the target terminal identifier; the information query unit 504 is configured to, in response to the presence of the first local information in the target duplicate information database, query the target local information corresponding to the second local information in the first local information in the target duplicate information database; the first information sending unit 505 is configured to map the target local information to target encrypted information through the first mapping algorithm, and then send the target encrypted information to the information requesting terminal.

[0089] In an optional implementation of some embodiments, the above-mentioned de-identified information transmission device 500 may include a duplicate information library construction unit (not shown in the figure), which is configured to construct a target duplicate information library. The above-mentioned duplicate information library construction unit includes: an information library receiving subunit (not shown in the figure), a first mapping subunit (not shown in the figure), a second mapping subunit (not shown in the figure) and a duplicate information library construction subunit (not shown in the figure). Among them, the information database receiving subunit is configured to receive the first information database sent by the above-mentioned information request terminal and the second information database sent by the above-mentioned target terminal. Each first information in the above-mentioned first information database is obtained by encrypting the corresponding first portrait information on the information request terminal through the first encryption algorithm on the above-mentioned information request terminal, and each second information in the above-mentioned second information database is obtained by encrypting the corresponding second portrait information on the target terminal through the second encryption algorithm on the above-mentioned target terminal; the first mapping subunit is configured to map each first information in the above-mentioned first information database to first local information through a first mapping algorithm corresponding to the above-mentioned first encryption algorithm to obtain a first local information database; the second mapping subunit is configured to map each second information in the above-mentioned second information database to second local information through a second mapping algorithm corresponding to the above-mentioned second encryption algorithm to obtain a second local information database, and the information type of the above-mentioned second local information is the same as the information type of the above-mentioned first local information; the duplicate information database construction subunit is configured to construct a target duplicate information database through the same portrait information in the above-mentioned first local information database and the second local information database.

[0090] In an optional implementation of some embodiments, the information acquisition request includes multiple second encrypted information; and the first information sending unit 505 may include: a virtual information setting subunit (not shown in the figure), an information packet acquisition subunit (not shown in the figure), and an information sending subunit (not shown in the figure). The virtual information setting subunit is configured to, in response to the absence of target local information corresponding to the second encrypted information, set virtual information for the second encrypted information for which the target local information does not exist, wherein the virtual information is provided with a virtual identifier, and the virtual identifier is used to indicate that the corresponding virtual information is invalid; the information packet acquisition subunit is configured to encapsulate the virtual information and the target local information into an information packet; and the information sending subunit is configured to map the information packet to the target encrypted information using the first mapping algorithm, and then send the target encrypted information to the information request terminal.

[0091] In an optional implementation of some embodiments, the above-mentioned information packet acquisition sub-unit includes: an information tag setting module (not shown in the figure), which is configured to set an information tag for the target local information corresponding to each second encrypted information, and the above-mentioned information tag is used to indicate the target request information corresponding to the target local information.

[0092] It is understood that the units described in the device 500 are similar to those in the reference Figure 2 Therefore, the operations, features and beneficial effects described above for the method are also applicable to the device 500 and the units included therein, and will not be repeated here.

[0093] Further references Figure 6 As an implementation of the methods shown in the above figures, the present disclosure provides some embodiments of a de-identified information acquisition device. These device embodiments are similar to Figure 4 Corresponding to the method embodiments shown, the device can be specifically applied to various electronic devices.

[0094] like Figure 6 As shown, the de-identified information acquisition device 600 of some embodiments includes: a target information query unit 601, a target request information construction unit 602, an information acquisition request acquisition unit 603, a second information sending unit 604 and a second information receiving unit 605. Among them, the target information query unit 601 is configured to query the target information of the business request information in response to obtaining the business request information of the user to be processed; the target request information construction unit 602 is configured to query the target terminal identifier of the target terminal corresponding to the above target information in response to the absence of the above target information, and construct the target request information corresponding to the above target information, and the above target terminal identifier is used to indicate that the target information corresponding to the target request information is obtained from the target terminal; the information acquisition request acquisition unit 603 is configured to query the first portrait information of the above user to be processed, and obtain the information acquisition request after encrypting the above first portrait information and the target request information through the first encryption algorithm; the second information sending unit 604 is configured to send the above information acquisition request and the target terminal identifier to the information query server; the second information receiving unit 605 is configured to decrypt the above target encrypted information through the first decryption algorithm corresponding to the above first encryption algorithm in response to receiving the target encrypted information corresponding to the above target request information sent by the above information query server to obtain the target information.

[0095] In an optional implementation of some embodiments, the second information receiving unit 605 may include: a decryption subunit (not shown in the figure) and an information marking subunit (not shown in the figure). The decryption subunit is configured to decrypt the target encrypted information to obtain at least one piece of target information to be processed; the information marking subunit is configured to mark the target information in the at least one piece of target information to be processed as invalid if the target information contains a virtual identifier; otherwise, mark the target information to be processed as valid.

[0096] In an optional implementation of some embodiments, the second information receiving unit may include: an information tag parsing subunit (not shown in the figure) and an information matching subunit (not shown in the figure). The information tag parsing subunit is configured to, in response to the number of valid target information to be processed, parse an information tag from each target information to be processed, wherein the information tag is used to indicate the target request information corresponding to the target local information; and the information matching subunit is configured to determine the target information to be processed corresponding to the service request information based on the information tag.

[0097] In an optional implementation of some embodiments, the de-identified information acquisition device 600 further includes: a business information generation unit (not shown in the figure), which is configured to generate business information based on the target information.

[0098] It is understood that the units described in the device 600 are similar to those in the reference Figure 4 Therefore, the operations, features and beneficial effects described above for the method are also applicable to the device 600 and the units included therein, and will not be repeated here.

[0099] like Figure 7 As shown, the electronic device 700 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 701, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 702 or a program loaded from a storage device 708 into a random access memory (RAM) 703. Various programs and data required for the operation of the electronic device 700 are also stored in the RAM 703. The processing device 701, the ROM 702, and the RAM 703 are connected to each other via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.

[0100] Typically, the following devices may be connected to the I / O interface 705: an input device 706 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 707 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 708 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 709. The communication device 709 may allow the electronic device 700 to communicate with other devices wirelessly or by wire to exchange data. Although Figure 7 The electronic device 700 is shown with various devices, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead. Figure 7 Each block shown in the figure may represent one device, or may represent multiple devices as needed.

[0101] In particular, according to some embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, some embodiments of the present disclosure include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In some such embodiments, the computer program can be downloaded and installed from a network via the communication device 709, or installed from the storage device 708, or installed from the ROM 702. When the computer program is executed by the processing device 701, the above-mentioned functions defined in the method of some embodiments of the present disclosure are performed.

[0102] It should be noted that in some embodiments of the present disclosure, the computer-readable medium mentioned above may be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In some embodiments of the present disclosure, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device, or device. In some embodiments of the present disclosure, the computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any suitable medium, including but not limited to wires, optical cables, RF (radio frequency), etc., or any suitable combination thereof.

[0103] In some embodiments, the client and server can communicate using any currently known or future developed network protocol, such as HTTP (HyperText Transfer Protocol), and can be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or future developed network.

[0104] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device. The computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device: receives an information acquisition request and a target terminal identifier sent by an information request terminal, the information acquisition request is obtained by encrypting the first portrait information and target request information of the user to be processed by the first encryption algorithm on the information request terminal, the information acquisition request includes first encryption information corresponding to the first portrait information and second encryption information corresponding to the target request information, and the target terminal identifier is used to indicate that the target information corresponding to the target request information is obtained from the target terminal; maps the information acquisition request into first local information and second local information through a first mapping algorithm corresponding to the first encryption algorithm, the first local information corresponds to the first encryption information, and the second local information corresponds to the second encryption information; determines a target duplicate information database, the target duplicate information database being composed of duplicate information in the target terminal corresponding to the information request terminal and the target terminal identifier; in response to the presence of the first local information in the target duplicate information database, queries the target local information corresponding to the second local information in the first local information in the target duplicate information database; after mapping the target local information into target encrypted information through the first mapping algorithm, sends the target encrypted information to the information request terminal.

[0105] Computer program code for performing the operations of some embodiments of the present disclosure may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, C++, and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).

[0106] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0107] The units described in some embodiments of the present disclosure may be implemented in software or hardware. The units described may also be provided in a processor. For example, they may be described as follows: a processor including a first information receiving unit, an information mapping unit, an information library determination unit, an information query unit, and a first information sending unit. The names of these units do not, in some cases, constitute limitations on the units themselves. For example, the information query unit may also be described as a "unit for querying target local information corresponding to target information."

[0108] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip (SOCs), complex programmable logic devices (CPLDs), and the like.

[0109] The above description is only an illustration of some preferred embodiments of the present disclosure and the technical principles used. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present disclosure is not limited to the technical solutions formed by the specific combination of the above-mentioned technical features, but should also cover other technical solutions formed by any combination of the above-mentioned technical features or their equivalent features without departing from the above-mentioned inventive concept. For example, the above-mentioned features are replaced with (but not limited to) technical features with similar functions disclosed in the embodiments of the present disclosure.

Claims

1. A method for transmitting de-identified information, comprising: receiving an information acquisition request and a target terminal identifier sent by an information requesting terminal, the information acquisition request being obtained by encrypting first portrait information of a user to be processed and target request information using a first encryption algorithm on the information requesting terminal, the information acquisition request including first encrypted information corresponding to the first portrait information and second encrypted information corresponding to the target request information, the target terminal identifier being used to indicate obtaining target information corresponding to the target request information from the target terminal; Mapping the information acquisition request into first local information and second local information using a first mapping algorithm corresponding to the first encryption algorithm, where the first local information corresponds to the first encrypted information and the second local information corresponds to the second encrypted information; Determine a target duplicate information database, wherein the target duplicate information database is composed of duplicate information in a target terminal corresponding to the information request terminal and the target terminal identifier; In response to the presence of the first local information in the target duplicate information database, querying the target duplicate information database for target local information corresponding to the second local information in the first local information; After mapping the target local information into target encrypted information using the first mapping algorithm, sending the target encrypted information to the information requesting terminal; The information acquisition request includes a plurality of second encrypted information; and after mapping the target local information to target encrypted information using the first mapping algorithm, sending the target encrypted information to the information requesting terminal includes: In response to the absence of target local information corresponding to the second encrypted information, setting virtual information for the second encrypted information for which the target local information does not exist, the virtual information being provided with a virtual identifier, the virtual identifier being used to indicate that the corresponding virtual information is invalid; encapsulating the virtual information and the target local information into an information packet; After mapping the information packet into target encrypted information through the first mapping algorithm, the target encrypted information is sent to the information requesting terminal.

2. The method according to claim 1, wherein The step of encapsulating the virtual information and the target local information into an information packet includes: An information tag is set for the target local information corresponding to each second encrypted information, where the information tag is used to indicate the target request information corresponding to the target local information.

3. A method for obtaining de-identified information, comprising: In response to obtaining the service request information of the user to be processed, querying the target information of the service request information; In response to the absence of the target information, querying a target terminal identifier of a target terminal corresponding to the target information, and constructing target request information corresponding to the target information, wherein the target terminal identifier is used to instruct the target terminal to obtain the target information corresponding to the target request information; Querying the first portrait information of the user to be processed, and encrypting the first portrait information and target request information using a first encryption algorithm to obtain an information acquisition request; Sending the information acquisition request and the target terminal identifier to the information query server; In response to receiving the target encrypted information corresponding to the target request information sent by the information query server, decrypting the target encrypted information using a first decryption algorithm corresponding to the first encryption algorithm to obtain target information; The decrypting the target encrypted information by using a first decryption algorithm corresponding to the first encryption algorithm to obtain the target information includes: Decrypting the target encrypted information to obtain at least one piece of target information to be processed; For the at least one piece of target information to be processed, if the target information to be processed includes a virtual identifier, the target information to be processed is marked invalid; otherwise, the target information to be processed is marked valid.

4. The method according to claim 3, wherein: Decrypting the target encrypted information by using a first decryption algorithm corresponding to the first encryption algorithm to obtain target information includes: In response to there being multiple valid target information to be processed, parsing an information tag from each target information to be processed, the information tag being used to indicate target request information corresponding to the target local information; The target information to be processed corresponding to the service request information is determined based on the information tag.

5. A de-identified information transmission device, comprising: a first information receiving unit configured to receive an information acquisition request and a target terminal identifier sent by an information requesting terminal, the information acquisition request being obtained by encrypting first portrait information of a to-be-processed user and target request information using a first encryption algorithm on the information requesting terminal, the information acquisition request including first encrypted information corresponding to the first portrait information and second encrypted information corresponding to the target request information, and the target terminal identifier being used to indicate that target information corresponding to the target request information is to be acquired from the target terminal; an information mapping unit configured to map the information acquisition request into first local information and second local information using a first mapping algorithm corresponding to the first encryption algorithm, wherein the first local information corresponds to the first encrypted information and the second local information corresponds to the second encrypted information; an information base determining unit configured to determine a target duplicate information base, wherein the target duplicate information base is formed by duplicate information in a target terminal corresponding to the information requesting terminal and the target terminal identifier; an information query unit configured to query the first local information in the target duplicate information database for target local information corresponding to the second local information in response to the presence of the first local information in the target duplicate information database; a first information sending unit configured to map the target local information into target encrypted information using the first mapping algorithm, and then send the target encrypted information to the information requesting terminal; The information acquisition request includes a plurality of second encrypted information, and the first information sending unit includes: a virtual information setting subunit configured to, in response to the absence of target local information corresponding to the second encrypted information, set virtual information for the second encrypted information for which the target local information does not exist, wherein the virtual information is set with a virtual identifier, and the virtual identifier is used to indicate that the corresponding virtual information is invalid; an information packet acquiring subunit, configured to encapsulate the virtual information and the target local information into an information packet; The information sending subunit is configured to map the information packet into target encrypted information through the first mapping algorithm, and then send the target encrypted information to the information requesting terminal.

6. A de-identified information acquisition device, comprising: a target information query unit configured to query target information of the service request information in response to obtaining the service request information of the user to be processed; a target request information constructing unit configured to, in response to the absence of the target information, query a target terminal identifier of a target terminal corresponding to the target information, and construct target request information corresponding to the target information, wherein the target terminal identifier is used to indicate that the target information corresponding to the target request information is to be obtained from the target terminal; an information acquisition request acquiring unit configured to query first portrait information of the user to be processed, and encrypt the first portrait information and target request information using a first encryption algorithm to obtain an information acquisition request; a second information sending unit, configured to send the information acquisition request and the target terminal identifier to the information query server; a second information receiving unit configured to, in response to receiving target encrypted information corresponding to the target request information sent by the information query server, decrypt the target encrypted information using a first decryption algorithm corresponding to the first encryption algorithm to obtain target information; The second information receiving unit includes: a decryption subunit, configured to decrypt the target encrypted information to obtain at least one piece of target information to be processed; The information marking subunit is configured to mark the at least one piece of target information to be processed as invalid if the target information to be processed includes a virtual identifier; otherwise, mark the target information to be processed as valid.

7. An electronic device comprising: one or more processors; a storage device having one or more programs stored thereon, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 4.

8. A computer-readable medium having a computer program stored thereon, wherein: When the program is executed by a processor, the method according to any one of claims 1 to 4 is implemented.

Citation Information

Patent Citations

  • Data query method, computing device and system

    CN109299619A