Data matching method and device, computing device, and computer-readable storage medium

Through homomorphic encryption and data desensitization processing, the conversion error and insufficient utilization of data characteristics caused by low privacy information in the RTA/DSP platform are solved, and efficient and secure data matching is achieved.

CN114491570BActive Publication Date: 2025-08-26TENCENT TECH SHANGHAI
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011262347.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-11-12
Publication Date
2025-08-26
Estimated Expiration
2040-11-12

AI Technical Summary

Technical Problem

In the existing advertising and sales system based on RTA/DSP platform, the use of low privacy information as the ID identification of user traffic results in high conversion error, conversion difficulty and conversion failure rate, and the rich data characteristics of each participant cannot be effectively utilized, and the data matching accuracy is low.

Method used

The original data is encrypted by homomorphic encryption method, and double-encrypted data is generated through different encryption methods with the same homomorphic characteristics, decrypted and matched, and characteristic data is generated by combining data desensitization.

Benefits of technology

It realizes the protection of data privacy during the data matching process, avoids unilateral cracking, strengthens data security, and improves the accuracy and efficiency of data matching.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114491570B_ABST
    Figure CN114491570B_ABST
Patent Text Reader

Abstract

The present disclosure provides a data matching method for matching data between a first business end and a second business end. This method applies a homomorphic encryption method in the data matching stage, so that a single matching process must go through an interaction between the matching party and the data owner to jointly generate the data to be matched to complete the matching process; in addition, the method also uses a set of hash functions to process the original data into non-reversible feature data, thereby achieving desensitization of the original data. As a result, this method eliminates the need to transmit the original data owned by the parties involved in the matching, but only transmits encrypted data or further desensitized feature data, which is beneficial to protecting the data security of each data owner and can protect against attacks based on analysis of feature information such as the distribution of the original data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of the Internet, and in particular to a data matching method and apparatus, a computing device, and a computer-readable storage medium. Background Art

[0002] With the popularization of the Internet and the development of network technology, more and more businesses are being conducted on the Internet. In the process of carrying out these businesses, all parties involved often need to match data and decide on the next action based on the results of the data matching.

[0003] For example, an advertising sales system that provides a multimedia advertising platform and charges advertisers for advertising on that platform is often based on an RTA / DSP platform (RTA, or Real-time API; DSP, or Demand-side Platform). This platform combines the basic functions of data and model exploration for both media and advertisers. Based on the direct delivery model of each media delivery platform, it sends real-time requests to advertisers, who then respond with decision information. The delivery platform then optimizes the platform based on the advertiser's information to improve the effectiveness of advertising delivery.

[0004] In actual applications, when an online request arrives, the RTA platform obtains the user information of the current request, such as gender, age, region, interests and other attributes, as well as device ID, cookie information, etc., and when it is determined that the user information of the current request meets the advertiser's delivery requirements, the user information of the current request is sent to the advertiser on the DSP side so that the advertiser can decide whether to participate in the bidding for the user's request; when the advertiser receives the information of the current request, it will determine whether the user information corresponding to the current request belongs to its target user traffic and make corresponding online decisions.

[0005] In the above business process, in order to protect the data privacy security on the RTA platform side, information with weaker data privacy (such as device ID, cookie information, etc.) is generally used as the ID identifier of user traffic. The DSP side generates a device ID / cookie information blacklist based on the device ID set of covered users to filter the ID identifier of user traffic.

[0006] However, in general, advertisers' management of their existing users is often not based on low-privacy information such as device IDs and cookie information, but on more private and recognizable information such as mobile phone numbers and WeChat accounts. There is a certain mapping conversion error between high-privacy information and low-privacy information. For users, there are scenarios where a user uses multiple devices, which will also lead to conversion errors when converting the user's high-privacy information (such as mobile phone numbers or WeChat accounts) to low-privacy information (such as device IDs and cookie information). In addition, the conversion of the above-mentioned high-privacy information to low-privacy information often requires the cooperation of multiple platforms, which increases the difficulty of data conversion and the conversion failure rate for the data owner.

[0007] Therefore, for existing advertising sales systems based on RTA / DSP platforms, the use of low-privacy information as the ID identifier of user traffic will lead to the following problems: First, conversion errors, conversion difficulty, and conversion failure rate will affect the accuracy of identifying user information; Second, each participant (for example, the RTA platform side and the DSP client side) usually has multi-dimensional user information, and only using low-privacy information as the basis for data matching between the participants will result in the inability to maximize the value of the rich data features of each participant (especially the RTA platform side), thereby causing the DSP client side to miss out on a large amount of high-value traffic. In addition, similar defects also exist in other Internet-based businesses where each participant needs to perform data matching to identify user information. Summary of the Invention

[0008] In view of this, the present disclosure provides a data matching method and apparatus, which is expected to overcome some or all of the above-mentioned deficiencies and other possible deficiencies.

[0009] According to one aspect of the present disclosure, a data matching method is provided, which is applied to a first business end, and the data matching method includes: obtaining first original data; encrypting the first original data using a first homomorphic encryption method to generate first encrypted data; sending the first encrypted data to a second business end, and receiving double encrypted data from the second business end, the double encrypted data is generated by the second business end encrypting the first encrypted data using a second homomorphic encryption method, and the first homomorphic encryption method and the second homomorphic encryption method are homomorphic encryption methods with the same homomorphic characteristics but different from each other; decrypting the double encrypted data using a decryption method corresponding to the first homomorphic encryption method to generate first decrypted data; obtaining first feature data for the first original data based on the first decrypted data; matching the first feature data with second feature data for the second original data, the second feature data is generated by the second business end based on the second encrypted data, and the second encrypted data is obtained by the second business end encrypting the second original data using the second homomorphic encryption method.

[0010] In some embodiments of the present disclosure, the second feature data is obtained by the second business end performing data desensitization processing on the second encrypted data, and obtaining the first feature data for the first original data based on the first decrypted data includes: performing the same data desensitization processing on the first decrypted data to obtain the first feature data.

[0011] In some embodiments according to the present disclosure, performing the same data desensitization processing on the first decrypted data to obtain the first feature data includes: determining n data elements of the first decrypted data; using k hash functions to map each of the n data elements into k index values; setting the values ​​of the bits corresponding to the k index values ​​in a bit vector with a length of m bits to 1, and setting the values ​​of the remaining bits to 0, to obtain the first feature data; wherein k, m and n are positive integers, m is greater than k×n and greater than the maximum value of the k×n index values.

[0012] In some embodiments according to the present disclosure, obtaining the first original data includes: obtaining the traffic data received by the first business end; determining the directional traffic data that meets the traffic direction conditions of the second business end from the traffic data; and obtaining the first original data from the directional traffic data.

[0013] In some embodiments according to the present disclosure, the traffic directional conditions include directional dimensions and thresholds corresponding to each dimension; the directional dimensions include at least one of the following: region, content, price, gender, age, interest, time, traffic source type, and network environment.

[0014] In some embodiments according to the present disclosure, the second encrypted data is determined as the second characteristic data, and wherein obtaining the first characteristic data for the first original data based on the first decrypted data includes: determining the first decrypted data as the first characteristic data.

[0015] In some embodiments according to the present disclosure, the first homomorphic encryption method and the second homomorphic encryption method are RSA encryption methods using different keys respectively.

[0016] In some embodiments according to the present disclosure, the first business end includes an information recommendation end, the second business end includes a delivery decision end, the first original data includes terminal user identity identification data obtained by the information recommendation end, and the second original data includes existing user identity identification data possessed by the delivery decision end.

[0017] In some embodiments according to the present disclosure, the first business end includes an online payment end, the second business end includes a financial service end, the first original data includes terminal user identity identification data obtained by the online payment end, and the second original data includes existing user identity identification data of the financial service end.

[0018] According to another aspect of the present disclosure, a data matching device is provided, which is used for a first business end, and the data matching device includes: a first original data acquisition module, which is configured to acquire first original data; a first encrypted data generation module, which is configured to encrypt the first original data using a first homomorphic encryption method to generate first encrypted data; a double encrypted data acquisition module, which is configured to send the first encrypted data to a second business end, and receive double encrypted data from the second business end, the double encrypted data is generated by the second business end encrypting the first encrypted data using a second homomorphic encryption method, and the first homomorphic encryption method and the second homomorphic encryption method are respectively used. are homomorphic encryption methods that have the same homomorphic characteristics but are different from each other; a decryption module, which is configured to decrypt the double encrypted data using a decryption method corresponding to the first homomorphic encryption method to generate the first decrypted data; a first feature data acquisition module, which is configured to obtain first feature data for the first original data based on the first decrypted data; a matching module, which is configured to match the first feature data with second feature data for the second original data, wherein the second feature data is generated by the second business end based on the second encrypted data and the second encrypted data is obtained by the second business end encrypting the second original data using the second homomorphic encryption method.

[0019] According to yet another aspect of the present disclosure, a computing device is provided, comprising a processor and a memory, wherein the memory is configured to store computer-executable instructions, wherein the computer-executable instructions are configured to cause the processor to perform the method described above when executed on the processor.

[0020] According to yet another aspect of the present disclosure, a computer-readable storage medium is provided, which is configured to store computer-executable instructions. When the computer-executable instructions are executed on a processor, the processor is configured to execute the method described above.

[0021] The data matching method disclosed herein includes at least the following beneficial technical effects: First, by applying the homomorphic encryption method in the data matching stage, the original data owned by the parties involved in the matching does not need to be transmitted, but only the encrypted data or the feature data after further desensitization is transmitted, which is beneficial to protecting the data security of each data owner; Second, a single matching process must go through an interaction between the matching party and the data owner in order to jointly generate the data to be matched to complete the matching process, thereby avoiding a single party from cracking the encrypted data through brute force. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] The specific embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings so that more details, features and advantages of the present disclosure can be more fully appreciated and understood. In the accompanying drawings:

[0023] Figure 1 Schematically illustrates a general application scenario of a business system according to some embodiments of the present disclosure;

[0024] Figure 2 Shown Figure 1 A schematic diagram of the business system shown in FIG being applied to an information recommendation scenario;

[0025] Figure 3 It is schematically shown Figure 1 and Figure 2 A schematic diagram of the basic principle of data matching in the business system shown;

[0026] Figure 4 is a flow chart schematically illustrating a data matching method according to some embodiments of the present disclosure;

[0027] Figure 5 is a schematic diagram showing the Figure 4 A flow chart of a method for obtaining first feature data in the data matching method shown;

[0028] Figure 6 is a schematic diagram showing the Figure 5Flowchart of the data desensitization method shown;

[0029] Figure 7 is a schematic diagram showing the Figure 4 A flowchart of a method for obtaining first original data in the data matching method shown;

[0030] Figure 8 Schematically shows a structural block diagram of a data matching device according to some embodiments of the present disclosure; and

[0031] Figure 9 A structural block diagram of a computing device according to some embodiments of the present disclosure is schematically shown. The computing device includes the data matching apparatus described herein, so that the data matching method described herein can be implemented.

[0032] It should be noted that the contents shown in the drawings are schematic only and therefore are not necessarily drawn to scale. In addition, in all drawings, the same features are indicated by the same reference numerals. DETAILED DESCRIPTION

[0033] The following description provides specific details of various embodiments of the present disclosure so that those skilled in the art can fully understand and practice the various embodiments of the present disclosure.

[0034] First, some of the terms used in the embodiments of the present disclosure are explained to facilitate understanding by those skilled in the art:

[0035] Homomorphic encryption method: Homomorphic encryption method is an encryption method that satisfies the following condition: the result obtained by encrypting plaintext and then performing an operation on the encrypted ciphertext is the same as the result obtained by performing the same operation on the plaintext and then encrypting the result of the operation on the plaintext.

[0036] That is, an encryption method x1,x2,…,x n →[x1],[x2],…,[x n ], if the condition f([x1],[x2],…,[x n ])=[f(x1,x2,…,x n )], where [] indicates data encryption and f indicates an operation, then the encryption method is a homomorphic encryption method.

[0037] Homomorphic properties: Homomorphic properties refer to the characteristics of the operations that a homomorphic encryption method supports on ciphertext. If a homomorphic encryption method supports multiplication on ciphertext, then the homomorphic property of the homomorphic encryption method is multiplication homomorphism; if a homomorphic encryption method supports addition on ciphertext, then the homomorphic property of the homomorphic encryption method is additive homomorphism; if a homomorphic encryption method supports both multiplication and addition on ciphertext, then the homomorphic property of the homomorphic encryption method is fully homomorphic.

[0038] For example, the RSA encryption method is a homomorphic encryption method with multiplicative homomorphism, while the Paillier encryption method is a homomorphic encryption algorithm with additive homomorphism.

[0039] Data desensitization: Data desensitization refers to a data processing technique that modifies data containing sensitive information using specific desensitization rules to reduce its sensitivity. Appropriate use of data desensitization technology can effectively reduce exposure to data during collection, transmission, and use, lowering the risk of sensitive data leakage and thus reliably protecting sensitive and private data.

[0040] Now see Figure 1 , which schematically illustrates a general application scenario of the business system 100 according to some embodiments of the present disclosure. Figure 1 As shown, the business system 100 includes a first business terminal 110 and a second business terminal 120, wherein the first business terminal 110 and the second business terminal 120 can communicate via a network 140, and the first business terminal 110 can also communicate with one or more terminal devices 130 via the network 140. The first business terminal 110 and the second business terminal 120 cooperate with each other to carry out business for users of the one or more terminal devices 130, including but not limited to advertising, payment, etc.

[0041] The first business end 110 and the second business end 120 can store and run computer instructions that can execute the various methods described in the present disclosure accordingly, and each of them can be a single server or a server cluster or a cloud server. The server can be an independent physical server, or a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The terminal can be a smart phone, tablet computer, laptop computer, desktop computer, smart speaker, smart watch, etc., but is not limited to this. The terminal and the server can be directly or indirectly connected via wired or wireless communication, which is not limited in the present disclosure.

[0042] The terminal device 130 may be any type of mobile device, including but not limited to: a mobile computer (e.g., devices, personal digital assistants (PDAs), laptop computers, notebook computers, tablet computers such as Apple iPad™, netbooks, etc.), mobile phones (e.g., cellular phones, such as Microsoft Smartphone, Apple iPhone, realized AndroidTM operating system phone, equipment, devices, etc.), wearable computing devices (e.g. smart watches, head-mounted devices, including smart glasses, such as Glass™, etc.) or other types of mobile devices. In some embodiments, the terminal device 130 can also be a fixed device, such as a desktop computer, a game console, a smart TV, a set-top box, an outdoor advertising display screen, a car-mounted advertising display screen, etc.

[0043] Examples of the network 140 may include any combination of a local area network (LAN), a wide area network (WAN), a personal area network (PAN), and / or a communication network such as the Internet. Each of the first service end 110, the second service end 120, and the one or more terminal devices 130 may include at least one communication interface (not shown) capable of communicating via the network. Such a communication interface may be one or more of the following: any type of network interface (e.g., a network interface card (NIC)), a wired or wireless (such as an IEEE 802.11 wireless LAN (WLAN)) wireless interface, a Worldwide Interoperability for Microwave Access (Wi-MAX) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth™ interface, a Near Field Communication (NFC) interface, and the like.

[0044] exist Figure 1In the illustrated scenario, a user can perform operations on a terminal device 130, such as submitting a service request or opening an application. These operations generate traffic data containing the request and user identity information through the terminal device 130, and the traffic data is sent by the terminal device 130 to the first service end 110 via the network 140. Upon receiving this traffic data, the first service end 110 can obtain service data required for performing the corresponding service and requiring confirmation by the second service end 120, such as user identity data reflecting the user identity of the terminal device 130, including but not limited to the device ID of the terminal device 130, cookie information, the user's mobile phone number and / or WeChat ID, etc. The first service end 110 and the second service end 120 interact to confirm whether the service data obtained from the traffic data by the first service end 110 (e.g., the user identity data of the terminal device 130) matches the service data already held by the second service end 120 (e.g., existing user identity data that meets the service requirements). Based on the matching result, the second service end 120 can make a decision and notify the first service end 110 to take appropriate measures.

[0045] It should be noted that Figure 1 The illustrated scenario is a general application scenario of the business system 100. As will be described below, depending on the specific functions that the first business terminal 110 and the second business terminal 120 can implement, they can be used in more specific scenarios.

[0046] See also Figure 2 , which schematically shows Figure 1 The business system 100 shown is applied to the information recommendation scenario. Figure 2 In the figure, the business system is an information recommendation system 100a for information recommendation, which includes an information recommendation terminal 110a and a delivery decision terminal 120a, wherein the information recommendation terminal 110a and the delivery decision terminal 120a can communicate through a network 140, and the information recommendation terminal 110a can also communicate with one or more terminal devices 130 through the network 140.

[0047] exist Figure 2In the illustrated embodiment, the information recommendation terminal 110a is a platform that provides recommended information display to the placement decision terminal (e.g., advertiser) 120a on a paid basis. The billing methods of the information recommendation terminal 110a may include, but are not limited to, CPM (Cost Per Mille), CPT (Cost Per Time), CPC (Cost Per Click), etc. CPM refers to a method of selling advertising based on the amount of traffic exposed to each thousand users. For example, if the placement decision terminal 120a purchases 1 CPM of information recommendation traffic, it means that the same recommended information from the placement decision terminal 120a will be exposed 1,000 times. The characteristic of CPM is that as long as the recommended information content of the placement decision terminal 120a is displayed to a sufficient number of users, the placement decision terminal 120a is required to pay for it. Recommended information placed under this billing method is generally mainly for brand display and product release, such as the GD (Guaranteed Delivery) information recommendation of news clients, which generally has a good exposure effect. CPT refers to a method of buying out ad space for a fixed period of time, with billing based on the buyout period. Examples include splash screen recommendations and keyword drop-downs in app stores. CPC refers to a method of billing based on the number of clicks on an ad. Keyword bidding generally uses the CPC method.

[0048] One form of information recommendation is video information recommendation, also known as pre-roll ads. These ads take up the viewer's viewing time. Based on the timing and placement of the ads, they can be categorized as pre-roll, post-roll, and mid-roll. Pre-roll ads play before the video begins, post-roll ads play after the video ends, and mid-roll ads play during the video.

[0049] The front-end platform of the information recommendation terminal 110a processes the traffic data containing real-time requests from the terminal device 130, and obtains the terminal user identity information of the current request (including but not limited to device ID, cookie information, mobile phone number, WeChat account, etc.) so that the back-end information recommendation decision model can make decision matching.

[0050] The information recommendation decision model of the information recommendation terminal 110a can match the user identity information input by the front-end platform based on the delivery conditions sent in advance by the delivery decision terminal 120a, and send the matching results to the delivery decision terminal 120a. The delivery conditions can be determined by the delivery decision terminal 120a based on the existing user identity information.

[0051] After receiving the matching result, the information delivery decision model of the delivery decision terminal 120a can decide whether to participate in the bidding for the user's requested traffic based on the matching result.

[0052] like Figure 2 As shown, optionally, the information recommendation terminal 110a may further include an information recommendation user data accumulation and modeling module, which may be configured to update and improve the information recommendation decision model based on the click volume and exposure rate contained in the traffic data. In addition, optionally, the delivery decision terminal 120a may further include an information delivery user data accumulation and modeling module, which may be configured to update and improve the information delivery decision model based on the specific data of existing users (such as, but not limited to, whether the user is activated, registered, purchased, active, retained, etc.).

[0053] See also Figure 3 , which schematically illustrates the process of Figure 1 The business system 100 and Figure 2 The basic principle of data matching in the media recommendation system 100a is shown.

[0054] like Figure 3 As shown, the second business end 120 and the delivery decision end 120a can use the second homomorphic encryption method f to encrypt the existing data X to generate encrypted data f(X). For example, but not limited to, the existing data X may include existing user identity identification data that is already available at the second business end 120 and the delivery decision end 120a and meets the relevant business targeting conditions and / or information recommendation rules. Such user identity identification data may include highly private information such as mobile phone numbers and WeChat accounts, and may have multi-dimensional information, such as but not limited to information on dimensions such as region, gender, age, and interests, so as to facilitate the identification of existing users. The encrypted data f(X) may also undergo data desensitization processing to generate second feature data Feature(X) for the existing data X.

[0055] Optionally, a data desensitization processing method includes using a very long binary vector (bitmap) and a series of random mapping functions (hash functions) to desensitize the data, including: for existing data X, determining that it has n data elements; using k hash functions to map each of the n data elements into k index values; setting the values ​​of the bits corresponding to the k index values ​​in the bit vector with a length of m bits to 1, and the values ​​of the remaining bits to 0, so that the binary vector obtained constitutes the feature data corresponding to the existing data X; wherein k, m and n are positive integers, m is greater than k×n and greater than the maximum value of the k×n index values. The feature data obtained in this way will have a certain error rate. Assuming that the tolerable error rate is p, and the number of hash functions is k, the length of the binary vector is m, and the number of data elements is n, then these parameters satisfy the following formula:

[0056]

[0057] In addition, as a non-limiting example, a Bloom filter may also be used to perform data desensitization processing.

[0058] Continue to see Figure 3 , the second business terminal 120 and the delivery decision terminal 120a can send the second feature data Feature(X) to the first business terminal 110 and the information recommendation terminal 110a for use in subsequent data matching. Figure 3 In FIG, data flows related to existing data X are depicted by solid arrows.

[0059] When the first service end 110 and the information recommendation end 110a receive traffic data containing a request sent from the terminal device 130, the first service end 110 and the information recommendation end 110a can obtain the original data x from the traffic data. For example, but not limited to, the original data x can include terminal user identification data related to the service targeting conditions and / or information recommendation rules. The terminal user identification data can also include highly private information such as mobile phone number and WeChat ID, and can also have multi-dimensional information, such as but not limited to information on dimensions such as region, gender, age, and interests, to facilitate the identification of the terminal user. The first service end 110 and the information recommendation end 110a can encrypt the original data x using the first homomorphic encryption method g to generate the first encrypted data g(x). It should be noted that the first homomorphic encryption method g and the second homomorphic encryption method f are different homomorphic encryption methods, but they have the same homomorphic properties, that is, the first homomorphic encryption method g and the second homomorphic encryption method f can both be multiplication homomorphic, or the first homomorphic encryption method g and the second homomorphic encryption method f can both be additive homomorphic. As a non-limiting example, the first homomorphic encryption method g and the second homomorphic encryption method f may be RSA encryption methods using different keys.

[0060] The first service end 110 and the information recommendation end 110a send the first encrypted data g(x) to the second service end 120 and the delivery decision end 120a. After receiving the first encrypted data g(x), the second service end 120 and the delivery decision end 120a encrypt the first encrypted data g(x) using the second homomorphic encryption method f to generate double-encrypted data f·g(x). They then send the double-encrypted data f·g(x) to the first service end 110 and the information recommendation end 110a.

[0061] After receiving the double encrypted data f·g(x), the first service terminal 110 and the information recommendation terminal 110a use the decryption method g corresponding to the first homomorphic encryption method g to -1 Decrypt the double encrypted data f·g(x) to generate encrypted data f(x) encrypted by the second homomorphic encryption method f. The encrypted data f(x) can undergo the same data desensitization process to generate the first feature data Feature(x) for the original data x. The first feature data Feature(x) is used in subsequent data matching. Figure 3 In , the data flows related to the original data x are depicted by dotted arrows.

[0062] Then, the first business end 110 and the information recommendation end 110a can match the first feature data Feature(x) and the second feature data Feature(X), and send the matching results to the second business end 120 and the delivery decision end 120a so that they can determine whether to carry out the corresponding business, such as information recommendation business.

[0063] Furthermore, according to some embodiments of the present disclosure, Figure 1 In the illustrated business system 100, the first business end 110 may include an online payment system, and the second business end 120 may include a financial service end. Thus, the business system 100 can also be used to match data and conduct corresponding services between an online payment end and a financial service end, such as a bank. In this application scenario, the first raw data may include terminal user identity data obtained from traffic data, and the second raw data may include existing user identity data held by the financial service end. In this scenario, the first business end 110 and the second business end 120 can conduct, for example, payment services based on the matching results.

[0064] exist Figure 3 In the data matching and interaction process shown, homomorphic encryption is applied during the data matching phase, eliminating the need to transmit the original data held by all parties involved. Instead, only the encrypted data and further desensitized feature data are transmitted, thus facilitating data privacy protection. Furthermore, a single matching process requires a single interaction between the matching executor and the data owner to jointly generate the matching data and complete the matching process. This prevents a single party from brute-forcing encrypted data.

[0065] It should also be pointed out that Figure 3The application of data desensitization is also shown. The data desensitization method described above can achieve the following advantages: First, the feature data obtained after data desensitization is irreversible, thereby desensitizing it from the original data and preventing attacks based on the distribution of characteristic information in the original data during downstream processing, thereby further protecting data privacy. Second, the feature data obtained after data desensitization is a bit vector. Compared with the original data before processing, the storage space required for the feature data, data transmission time, and data processing time are greatly reduced. Of course, data desensitization is not necessary. In situations where the requirements for data privacy protection are not too high, and the requirements for the size of the matching data, data transmission time, and data processing time are not too stringent, data desensitization can be omitted. Instead, the encrypted data f(X) of the existing data X and the encrypted data f(x) of the original data x can be directly used as the feature data to be matched. In addition, other data desensitization methods are also possible, such as data deformation or partial shielding according to certain desensitization rules, or Bloom filters.

[0066] See also Figure 4 , which schematically illustrates a data matching method 400 according to some embodiments of the present disclosure in the form of a flowchart. The data matching method 400 can be applied to the first service end 110 and can be applied to various scenarios described in the present disclosure.

[0067] In step 410, the first original data is obtained. The first business end 110 can determine whether the traffic data from the terminal device 130 is received, and obtain the first original data from the received traffic data. As described above, the traffic data can be data containing requests generated by the terminal device 130 when the user operates the terminal device 130, and these data are sent to the first business end 110 through the network 140. The traffic data can include any information related to the business of the first business end 110 and the second business end 120, which depends on the specific functions implemented by the first business end 110 and the second business end 120. For example, but not limited to, the traffic data can include device ID, cookie information, etc. related to the terminal device 130, and can also include information related to the user using the terminal device 130, such as mobile phone number, WeChat account, etc. In addition, the traffic data can also include information such as region, gender, age, interests, content, price, time, traffic source type, network environment, audience attributes, etc., so that multi-dimensional user data can be established.

[0068] At step 420, the first original data is encrypted using a first homomorphic encryption method to generate first encrypted data. As an example, the first homomorphic encryption method may be an RSA encryption method.

[0069] In step 430, the first encrypted data is sent to the second business end 120, and the doubly encrypted data is received from the second business end 120. The doubly encrypted data is generated by the second business end 120 by encrypting the first encrypted data using the second homomorphic encryption method. The first homomorphic encryption method and the second homomorphic encryption method are different homomorphic encryption methods from each other, but both have the same homomorphic characteristics. That is, both the first homomorphic encryption method and the second homomorphic encryption method have multiplicative homomorphism, or both the first homomorphic encryption method and the second homomorphic encryption method have additive homomorphism. As an example, the second homomorphic encryption method can be an RSA encryption method that uses a different key from the first homomorphic encryption method.

[0070] In step 440, the double-encrypted data is decrypted using a decryption method corresponding to the first homomorphic encryption method to generate first decrypted data. It should be understood that due to the use of a homomorphic encryption method, the first decrypted data here actually represents the encrypted data obtained by encrypting the first original data using the second homomorphic encryption method. Therefore, the first decrypted data, and the first feature data obtained thereby, are jointly generated by both parties involved in the matching process (e.g., the first service end 110 and the second service end 120).

[0071] In step 450, first characteristic data for the first original data is obtained based on the first decrypted data. Optionally, the first service end 110 may use the first decrypted data as the first characteristic data, or may process the first decrypted data to obtain the first characteristic data, as described below. Figure 5 described.

[0072] In step 460, the first feature data is matched with the pre-acquired second feature data. The second feature data is generated by the second business terminal 120 by encrypting its existing second original data using a second homomorphic encryption method, and is sent to the first business terminal 110 through the network 140. The second original data can be business data (for example, existing user identity identification data) that is already available at the second business terminal 120 and meets the directional conditions of the relevant business (for example, media recommendation business, payment business, etc.). Similarly, the second original data can contain highly private information such as mobile phone numbers and WeChat accounts, and can have multi-dimensional information, such as but not limited to information on dimensions such as region, gender, age, and interests, to increase recognition.

[0073] In addition, optionally, the first business end 110 may send the matching result to the second business end 120 so that the second business end 120 can make a decision based on the matching result.

[0074] Figure 4The illustrated data matching method 400 utilizes homomorphic encryption during the data matching phase, eliminating the need to transmit the original data held by the matching parties. Instead, only the encrypted data and further desensitized feature data are transmitted, thereby facilitating data privacy protection. Furthermore, a single matching process requires a single interaction between the matching executor and the data owner to jointly generate the matching data and complete the matching process. This prevents a single party from brute-forcing encrypted data.

[0075] Figure 5 A method for determining first characteristic data is schematically shown in the form of a flow chart, which can be used to implement Figure 4 Step 450 of the data matching method 400 is shown. Figure 5 As shown, Figure 4 Step 450 in the data matching method 400 shown includes steps 450a and 450b:

[0076] In step 450a, data desensitization processing is performed on the first decrypted data;

[0077] In step 450b, the result of the data desensitization processing is used as the first feature data.

[0078] As already explained, data desensitization uses specific desensitization rules to transform, mask, or map data containing sensitive information, thereby desensitizing the processed data from the original data. Desensitized data cannot be reversed, effectively reducing exposure to data during collection, transmission, and use, lowering the risk of sensitive data leakage and thus enabling reliable protection of sensitive privacy data.

[0079] Furthermore, Figure 6 A data desensitization processing method is schematically shown in the form of a flow chart, which can be used to implement Figure 5 Step 450a is shown.

[0080] like Figure 6 As shown, Figure 5 Step 450 in the data matching method 400 shown includes steps 451, 452 and 450b:

[0081] At step 451, n data elements of the first decrypted data are determined;

[0082] At step 452, each of the n data elements is mapped to k index values ​​using k hash functions;

[0083] In step 453, the values ​​of the bits corresponding to the k index values ​​in the bit vector with a length of m bits are set to 1, and the values ​​of the remaining bits are set to 0 to generate the first desensitized data.

[0084] The various parameters in the above data desensitization processing should satisfy the following requirements: k, m and n are positive integers, m is greater than k×n and greater than the maximum value of k×n index values.

[0085] In addition, other data desensitization processing methods are also possible, such as deforming or partially shielding the data according to certain desensitization rules, or using a suitably constructed Bloom filter.

[0086] The above-mentioned data desensitization processing method can achieve the following advantages: First, the characteristic data obtained after the data desensitization processing is not reversible, thereby desensitizing it from the original data, avoiding the possibility of attacks based on the cracking of characteristic information such as the distribution of the original data in the downstream processing link, thereby further protecting data privacy; Second, the characteristic data obtained after the data desensitization processing is a bit vector. Compared with the original data before processing, the storage space, data transmission time and data processing time required for the characteristic data are greatly reduced.

[0087] See also Figure 7 , which schematically illustrates a method for obtaining first original data in the form of a flow chart, which can be applied to Figure 4 Step 410 of the data matching method 400 is shown.

[0088] like Figure 7 As shown, Figure 4 Step 410 in the data matching method 400 may include steps 410a, 410b, and 410c:

[0089] In step 410a, traffic data received by the first service end 110 is obtained;

[0090] In step 410b, directional flow data that meets the flow directional conditions of the second service end 120 is determined from the flow data;

[0091] In step 410c, first raw data is obtained from the directional traffic data.

[0092] Traffic targeting conditions may include at least one targeting dimension and a predetermined threshold for each targeting dimension. Targeting dimensions may include region, content, price, gender, age, interest, time, traffic source type, network environment, etc.

[0093] As a non-limiting example, the second service end 120 may determine the directional dimension of the traffic directional condition as time, predefine the threshold under the directional dimension to, for example, 18:00 to 22:00 every day, and send the traffic directional condition to the first service end 110. Therefore, when the first service end 110 receives traffic data, it will first filter the traffic data according to the traffic directional condition: if the traffic data is not generated in the time period of 18:00 to 22:00, the first service end 110 will not obtain the first raw data from the traffic data; if the traffic data is generated in the time period of 18:00 to 22:00, the first service end 110 will obtain the first raw data from the traffic data.

[0094] By using the preset traffic directional conditions of the second business end 120 to filter the traffic data, and then extracting relevant user data from the directional traffic data that meets the requirements to generate the first original data, the accuracy of the traffic can be improved, thereby improving the matching accuracy.

[0095] Figure 8 FIG1 shows a structural block diagram of a data matching device 800 according to some embodiments of the present disclosure. The data matching device 800 can be used at the first service terminal 110 and can be applied to various scenarios described in the present disclosure. Figure 8 As shown, the data matching device 800 includes: a first original data acquisition module 810, a first encrypted data generation module 820, a double encrypted data acquisition module 830, a decryption module 840, a first feature data acquisition module 850, and a matching module 860.

[0096] The first original data acquisition module 810 is configured to acquire first original data. The first encrypted data generation module 820 is configured to encrypt the first original data using a first homomorphic encryption method to generate first encrypted data. The double encrypted data acquisition module 830 is configured to send the first encrypted data to the second business end 120 and receive double encrypted data from the second business end 120. The double encrypted data is generated by the second business end 120 encrypting the first encrypted data using a second homomorphic encryption method, and the first homomorphic encryption method and the second homomorphic encryption method are homomorphic encryption methods with the same homomorphic characteristics but different from each other. The decryption module 840 is configured to decrypt the double encrypted data using a decryption method corresponding to the first homomorphic encryption method to generate the first decrypted data. The first feature data acquisition module 850 is configured to obtain first feature data for the first original data based on the first decrypted data. The matching module 860 is configured to match the first feature data with the second feature data for the second original data, where the second feature data is generated by the second business terminal 120 based on the second encrypted data and the second encrypted data is obtained by the second business terminal 120 encrypting the second original data using the second homomorphic encryption method. Figure 4 The operations of steps 410 to 460 are described above, and thus are not described again here.

[0097] Above about Figure 8 Each module described can be implemented in hardware or in hardware in combination with software and / or firmware. For example, these modules can be implemented as computer executable code / instructions, which are configured to be executed in one or more processors and stored in a computer-readable storage medium. Alternatively, these modules can be implemented as hardware logic / circuits. For example, in some embodiments, one or more of these modules can be implemented together in a system on a chip (SoC). The SoC can include an integrated circuit chip (which includes a processor (e.g., a central processing unit (CPU), a microcontroller, a microprocessor, a digital signal processor (DSP)), a memory, one or more communication interfaces, and / or one or more components in other circuits), and can optionally execute the received program code and / or include embedded firmware to perform functions.

[0098] Figure 9 A schematic block diagram of an exemplary computing device 900 according to some embodiments of the present disclosure is shown. The exemplary computing device 900 may represent Figure 1 The first business terminal 110 and Figure 2 The information recommendation terminal 110a shown, and the exemplary computing device 900 can be used in various scenarios described in this disclosure.

[0099] The computing device 900 may include at least one processor 902, memory 904, communication interface(s) 906, a display device 908, other input / output (I / O) devices 910, and one or more mass storage devices 912, all capable of communicating with one another, such as via a system bus 914 or other appropriate connection.

[0100] The processor 902 may be a single processing unit or multiple processing units, all of which may include a single or multiple computing units or multiple cores. The processor 902 may be implemented as one or more microprocessors, microcomputers, microcontrollers, digital signal processors, central processing units, state machines, logic circuits, and / or any device that manipulates signals based on operational instructions. Among other capabilities, the processor 902 may be configured to retrieve and execute computer-readable instructions stored in the memory 904, mass storage device 912, or other computer-readable media, such as program code for an operating system 916, program code for application programs 918, program code for other programs 920, and the like.

[0101] The memory 904 and the mass storage device 912 are examples of computer storage media for storing instructions that are executed by the processor 902 to implement the various functions described above. For example, the memory 904 may generally include both volatile memory and non-volatile memory (e.g., RAM, ROM, etc.). In addition, the mass storage device 912 may generally include a hard drive, a solid-state drive, removable media, including external and removable drives, memory cards, flash memory, floppy disks, optical disks (e.g., CDs, DVDs), storage arrays, network attached storage, storage area networks, etc. The memory 904 and the mass storage device 912 may all be collectively referred to herein as memory or computer storage media, and may be non-transitory media capable of storing computer-readable, processor-executable program instructions as computer executable code, which may be executed by the processor 902 as a specific machine configured to implement the operations and functions described in the examples of the present disclosure.

[0102] A plurality of program modules may be stored on the mass storage device 912. These program modules include an operating system 916, one or more application programs 918, other programs 920, and program data 922, and may be executed by the processor 902. Examples of such application programs or program modules may include, for example, computer program logic (e.g., computer executable code or instructions) for implementing the following components / functions: a first original data acquisition module 810, a first encrypted data generation module 820, a double encrypted data acquisition module 830, a decryption module 840, a first feature data acquisition module 850, and a matching module 860.

[0103] Although Figure 9 904 of the computing device 900, but modules 916, 918, 920, and 922, or portions thereof, may be implemented using any form of computer-readable media accessible by the computing device 900. As used herein, "computer-readable media" includes at least two types of computer-readable media, namely, computer storage media and communication media.

[0104] Computer storage media includes volatile and nonvolatile, removable and non-removable media implemented in any method or technology for storage of information, such as computer-readable instructions, data structures, program modules, or other data. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVDs), or other optical storage devices, magnetic cassettes, magnetic tape, magnetic disk storage devices or other magnetic storage devices, or any other non-transmission media that can be used to store information for access by a computing device.

[0105] In contrast, communication media may embody computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism. Computer storage media as defined herein does not include communication media.

[0106] The computing device 900 may also include one or more communication interfaces 906 for exchanging data with other devices, such as via a network, direct connection, etc. The communication interfaces 906 may facilitate communication within a variety of network and protocol types, including wired networks (e.g., LAN, cable, etc.) and wireless networks (e.g., WLAN, cellular, satellite, etc.), the Internet, etc. The communication interfaces 906 may also provide for communication with external storage devices (not shown), such as in storage arrays, network attached storage, storage area networks, etc.

[0107] In some examples, the computing device 900 may include a display device 908, such as a monitor, for displaying information and images. Other I / O devices 910 may be devices that receive various inputs from a user and provide various outputs to the user, including but not limited to touch input devices, gesture input devices, cameras, keyboards, remote controls, mice, printers, audio input / output devices, and the like.

[0108] The terms used herein are only used to describe the embodiments in the present disclosure and are not intended to limit the present disclosure. As used herein, the singular forms "a", "an" and "the" are intended to also include the plural forms, unless the context clearly indicates otherwise. It will also be understood that the terms "include" and "comprise" when used in the present disclosure refer to the presence of the features described, but do not exclude the presence of one or more other features or the addition of one or more other features. As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed items. It will be understood that although the terms "first", "second", "third" etc. can be used to describe various features in this article, these features should not be limited by these terms. These terms are only used to distinguish one feature from another.

[0109] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by those skilled in the art to which the present disclosure belongs. It is also understood that terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the relevant art and / or the context of this specification, and will not be interpreted in an idealized or overly formal sense unless explicitly defined as such herein.

[0110] In the description of this specification, the description of the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present disclosure. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine different embodiments or examples described in this specification and features of different embodiments or examples without contradiction.

[0111] Various techniques are described herein in the general context of software and hardware elements or program modules. Generally, these modules include routines, programs, objects, elements, components, data structures, etc. that perform specific tasks or implement specific abstract data types. As used herein, the terms "module," "function," and "component" generally refer to software, firmware, hardware, or a combination thereof. The techniques described herein are platform-independent, meaning that these techniques can be implemented on a variety of computing platforms with a variety of processors.

[0112] The logic and / or steps represented in the flowcharts or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing the logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can fetch instructions from and execute instructions on an instruction execution system, apparatus, or device). For purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples of computer-readable media can include, for example, an electrical connection having one or more wires (electronic devices), a portable computer disk cartridge (magnetic device), random access memory, read-only memory, erasable programmable read-only memory, or flash memory, fiber optic devices, and portable compact disc read-only memory. Furthermore, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium and then editing, interpreting or processing it in another suitable manner if necessary, and then storing it in a computer memory.

[0113] It should be understood that various parts of the present disclosure can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, any one of the following technologies known in the art or a combination thereof can be used to implement the present invention: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0114] Those skilled in the art will appreciate that all or part of the steps of the method of the above embodiment may be accomplished through hardware associated with program instructions, and the program may be stored in a computer-readable storage medium, which, when executed, includes executing one or a combination of the steps of the method embodiment.

[0115] Although the present disclosure has been described in detail in connection with some embodiments, it is not intended to be limited to the specific forms set forth herein. Rather, the scope of the present disclosure is to be limited only by the appended claims.

Claims

1. A business system, characterized in that: The business system includes an information recommendation terminal and an investment decision terminal, wherein: The information recommendation terminal includes: The front-end platform is configured to: process traffic data including real-time requests to obtain first original data, wherein the first original data includes terminal user identification data of the user; The information recommendation decision model is configured to: Encrypting the first original data using a first homomorphic encryption method to generate first encrypted data; Sending the first encrypted data to the delivery decision end; Receiving double-encrypted data from the delivery decision end, wherein the double-encrypted data is generated by the delivery decision end encrypting the first encrypted data using a second homomorphic encryption method, and the first homomorphic encryption method and the second homomorphic encryption method are homomorphic encryption methods that have the same homomorphic characteristics but are different from each other; Decrypting the double-encrypted data using a decryption method corresponding to the first homomorphic encryption method to generate first decrypted data; obtaining first feature data for the first original data based on the first decrypted data; matching the first feature data with second feature data of second original data received from the delivery decision end; Sending the matching result to the delivery decision end; An information recommendation user data accumulation and modeling module is configured to update and improve the information recommendation decision model based on the click volume and exposure rate included in the traffic data; The delivery decision-making end includes: The information delivery decision model is configured as follows: Encrypting the second original data using the second homomorphic encryption method to obtain second encrypted data, and generating the second feature data based on the second encrypted data; sending the second characteristic data to the information recommendation terminal; receiving the first encrypted data; encrypting the first encrypted data using the second homomorphic encryption method to generate the double encrypted data; sending the double-encrypted data to the information recommendation terminal; receiving a result of the matching; Determine whether to participate in bidding for the user requested traffic based on the matching result; The information delivery user data accumulation and modeling module is configured to update and improve the information delivery decision model based on the specific data of existing users.

2. The business system according to claim 1, wherein: The second feature data is obtained by performing data desensitization processing on the second encrypted data by the delivery decision end, and the first feature data for the first original data obtained based on the first decrypted data includes: The same data desensitization process is performed on the first decrypted data to obtain the first feature data.

3. The business system according to claim 2, wherein: Performing the same data desensitization processing on the first decrypted data to obtain the first feature data includes: Determine the first decrypted data n data elements; use k A hash function converts the n Each of the data elements is mapped to k index value; The length is m The bit vector of the bit k The value of the bit corresponding to the index value is set to 1, and the values ​​of the remaining bits are set to 0, so as to obtain the first feature data; in, k 、 m and n is a positive integer, m Greater than k × n and greater than k × n The maximum value among the index values.

4. The business system according to claim 1, wherein: The acquiring of the first original data comprises: Obtaining traffic data received by the information recommendation terminal; Determining, from the traffic data, directed traffic data that satisfies the traffic directing conditions of the delivery decision end; The first raw data is obtained from the directional traffic data.

5. The business system according to claim 4, wherein: The traffic orientation condition includes an orientation dimension and a threshold value corresponding to the orientation dimension; The targeting dimension includes at least one of the following: region, content, price, gender, age, occupation, interest, time, traffic source type, and network environment.

6. The business system according to claim 1, wherein the second encrypted data is determined as the second feature data, and in, Obtaining first feature data for the first original data based on the first decrypted data includes: The first decrypted data is determined as the first feature data.

Citation Information

Patent Citations

  • Data processing method and device, server and computer readable medium

    CN110070374A

  • Data determination method and device, storage medium and electronic device

    CN110400164A