Data Processing Method, Apparatus, System and Device
The authentication information is processed through the joint desensitization model of the client and the server, which solves the problems of low authentication efficiency and insufficient security of private data, and realizes efficient authentication and privacy data protection.
Patent Information
- Application Number
- CN202210429505.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-22
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2042-04-22
AI Technical Summary
The existing identity verification technology is inefficient and has insufficient security of privacy data due to the sharp increase in user numbers, which is easy to be broken by attackers, resulting in the risk of privacy data leakage.
The joint desensitization model of the client and the server is adopted, and the identity authentication information of the target user is desensitized through the first privacy information desensitization model of the client and the second privacy information desensitization model of the server, thereby improving data processing efficiency and privacy data security.
It improves the efficiency of identity verification and the security of private data, reduces the risk of privacy data leakage, and achieves the protection of target users' privacy data.
Smart Images

Figure CN114817984B_ABST
Abstract
Description
Technical Field
[0001] This document relates to the technical field of data processing, and in particular, to a data processing method, apparatus, system, and device. Background Art
[0002] With the rapid development of computer technology, biometric recognition technology has been widely used in identity verification scenarios. For example, client devices such as access control devices and face-scanning payment devices can perform identity verification on users based on biometric (such as fingerprint, facial image, etc.) data input by the users.
[0003] The server can generate an encryption key for each user, then encrypt the biometric data provided by the user during registration using the encryption key, and store the encrypted biometric data. In this way, after receiving the biometric data sent by the client, the server can perform identity verification processing on the user using the encrypted biometric data and the received biometric data to obtain an identity verification result for the user.
[0004] However, in the above identity verification process, since the server needs to perform operations such as key generation and data encryption for each user, in the current situation where the number of users is increasing rapidly, it will lead to low data processing efficiency. In addition, the security of encrypting the biometric data of users by means of key encryption is low and is easily breached by attackers, resulting in a risk of leakage of users' private data. Therefore, a solution that can improve the identity verification efficiency and the security of private data in the identity verification scenario is needed. Summary of the Invention
[0005] The purpose of the embodiments of this specification is to provide a data processing method, apparatus, system, and device to provide a solution that can improve the identity verification efficiency and the security of private data in the identity verification scenario.
[0006] To achieve the above technical solution, the embodiments of this specification are implemented as follows:
[0007] In a first aspect, an embodiment of this specification provides a data processing method, which is applied to a client and includes: when receiving an authentication request of a target user for a target service, obtaining the authentication information of the target user; sending the authentication information of the target user to a server and receiving an authentication result returned by the server, where the authentication result is obtained by the server authenticating the target user based on the benchmark authentication information of the target user stored in advance and the authentication information, and the benchmark authentication information is the authentication information obtained by desensitizing the target authentication information of the target user based on a first privacy information desensitization model of the client and a second privacy information desensitization model of the server; when the authentication result is authentication passed, triggering the execution of the target service.
[0008] In a second aspect, an embodiment of this specification provides a data processing method, which is applied to a server and includes: receiving an authentication request of a target user for a target service sent by a client, where the authentication request includes the authentication information of the target user; authenticating the target user based on the benchmark authentication information of the target user stored in advance and the authentication information to obtain an authentication result, where the benchmark authentication information is the authentication information obtained by desensitizing the target authentication information of the target user based on a first privacy information desensitization model of the client and a second privacy information desensitization model of the server; sending the authentication result to the client so that the client triggers the execution of the target service when the authentication result is authentication passed.
[0009] In a third aspect, an embodiment of this specification provides a data processing system, including a client and a server, where: when the client receives an authentication request of a target user for a target service, it obtains the authentication information of the target user; the server authenticates the target user based on the benchmark authentication information of the target user stored in advance and the authentication information to obtain an authentication result, where the benchmark authentication information is the authentication information obtained by desensitizing the target authentication information of the target user based on a first privacy information desensitization model of the client and a second privacy information desensitization model of the server; the server sends the authentication result to the client; the client triggers the execution of the target service when the authentication result is authentication passed.
[0010] Fourth aspect, an embodiment of this specification provides a data processing device, including: a first acquisition module, configured to acquire the authentication information of the target user when receiving an authentication request of the target user for a target service; a result acquisition module, configured to send the authentication information of the target user to a server and receive an authentication result returned by the server, where the authentication result is obtained by the server performing authentication on the target user based on pre-stored reference authentication information of the target user and the authentication information, and the reference authentication information is authentication information obtained by performing desensitization processing on the target authentication information of the target user based on a first private information desensitization model of the client and a second private information desensitization model of the server; a service trigger module, configured to trigger the execution of the target service when the authentication result is authentication passed.
[0011] Fifth aspect, an embodiment of this specification provides a data processing device, including: a request receiving module, configured to receive an authentication request of a target user for a target service sent by a client, where the authentication request includes the authentication information of the target user; an authentication module, configured to perform authentication on the target user based on pre-stored reference authentication information of the target user and the authentication information, to obtain an authentication result, where the reference authentication information is authentication information obtained by performing desensitization processing on the target authentication information of the target user based on a first private information desensitization model of the client and a second private information desensitization model of the server; a first sending module, configured to send the authentication result to the client, so that the client triggers the execution of the target service when the authentication result is authentication passed.
[0012] Sixth aspect, an embodiment of this specification provides a data processing device, where the data processing device includes: a processor; and a memory arranged to store computer-executable instructions, where the executable instructions, when executed, cause the processor: acquire the authentication information of the target user when receiving an authentication request of the target user for a target service; send the authentication information of the target user to a server and receive an authentication result returned by the server, where the authentication result is obtained by the server performing authentication on the target user based on pre-stored reference authentication information of the target user and the authentication information, and the reference authentication information is authentication information obtained by performing desensitization processing on the target authentication information of the target user based on a first private information desensitization model of the data processing device and a second private information desensitization model of the server; trigger the execution of the target service when the authentication result is authentication passed.
[0013] Seventh aspect, an embodiment of this specification provides a data processing device, which includes: a processor; and a memory arranged to store computer-executable instructions, and the executable instructions, when executed, cause the processor to: receive an authentication request for a target service sent by a client, where the authentication request includes authentication information of the target user; authenticate the target user based on the pre-stored reference authentication information of the target user and the authentication information, and obtain an authentication result, where the reference authentication information is authentication information obtained by performing desensitization processing on the target authentication information of the target user based on a first privacy information desensitization model of the client and a second privacy information desensitization model of the data processing device; send the authentication result to the client, so that the client triggers the execution of the target service when the authentication result is authentication passed.
[0014] Eighth aspect, an embodiment of this specification provides a storage medium, which is used to store computer-executable instructions, and the executable instructions, when executed, implement the following process: when receiving an authentication request for a target service sent by a target user, obtain the authentication information of the target user; send the authentication information of the target user to a server, and receive an authentication result returned by the server, where the authentication result is obtained by the server authenticating the target user based on the pre-stored reference authentication information of the target user and the authentication information, and the reference authentication information is authentication information obtained by performing desensitization processing on the target authentication information of the target user based on a first privacy information desensitization model of the client and a second privacy information desensitization model of the server; when the authentication result is authentication passed, trigger the execution of the target service.
[0015] Ninth aspect, an embodiment of this specification provides a storage medium, which is used to store computer-executable instructions, and the executable instructions, when executed, implement the following process: receive an authentication request for a target service sent by a client, where the authentication request includes authentication information of the target user; authenticate the target user based on the pre-stored reference authentication information of the target user and the authentication information, and obtain an authentication result, where the reference authentication information is authentication information obtained by performing desensitization processing on the target authentication information of the target user based on a first privacy information desensitization model of the client and a second privacy information desensitization model of the server; send the authentication result to the client, so that the client triggers the execution of the target service when the authentication result is authentication passed. Description of the Drawings
[0016] To more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following will briefly introduce the accompanying drawings required for use in the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments recorded in this specification. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.
[0017] Figure 1A It is a flowchart of an embodiment of a data processing method in this specification;
[0018] Figure 1B It is a schematic diagram of the processing process of a data processing method in this specification;
[0019] Figure 2 It is a schematic diagram of the processing process of another data processing method in this specification;
[0020] Figure 3A It is a flowchart of an embodiment of another data processing method in this specification;
[0021] Figure 3B It is a schematic diagram of the processing process of another data processing method in this specification;
[0022] Figure 4 It is a schematic diagram of the processing process of another data processing method in this specification;
[0023] Figure 5 It is a schematic diagram of the processing process of another data processing method in this specification;
[0024] Figure 6 It is a schematic diagram of a data processing system in this specification;
[0025] Figure 7 It is a schematic diagram of another data processing system in this specification;
[0026] Figure 8 It is a schematic diagram of another data processing system in this specification;
[0027] Figure 9 It is a schematic diagram of the structure of an embodiment of a data processing device in this specification;
[0028] Figure 10 It is a schematic diagram of the structure of an embodiment of another data processing device in this specification;
[0029] Figure 11 It is a schematic diagram of the structure of a data processing device in this specification. Detailed implementation manners
[0030] The embodiments of this specification provide a data processing method, apparatus, system, and device.
[0031] To enable those skilled in the art to better understand the technical solutions in this specification, the following will clearly and completely describe the technical solutions in the embodiments of this specification with reference to the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all of them. Based on the embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of this specification.
[0032] Embodiment 1
[0033] As Figure 1A and 1B shown, the embodiments of this specification provide a data processing method. The execution subject of this method can be a client, and the client can be a device that can be used by a user. For example, the client can be a mobile terminal device such as a mobile phone or a tablet computer, or can also be a terminal device such as an access control device or a face recognition payment device. This method can specifically include the following steps:
[0034] In S102, when receiving an identity verification request from a target user for a target service, obtain the identity verification information of the target user.
[0035] Among them, the target service can be any service that requires user identity verification. For example, the client can be an access control device, and the corresponding target service can be opening the door. Or, the client can be a face recognition payment device, and the corresponding target service can be a resource transfer service, etc. The identity verification information of the target user can be information that can be used to verify the identity of the target user. For example, the identity verification information of the target user can be biometric data such as the fingerprint, facial image, iris, voiceprint, or gait of the target user.
[0036] In implementation, with the rapid development of computer technology, biometric recognition technology is widely applied to authentication scenarios. For example, client devices such as access control devices and face payment devices can authenticate users based on biometric data (such as fingerprints, facial images, etc.) input by users. The server can generate an encryption key for each user, then encrypt the biometric data provided by the user during registration using the encryption key, and store the encrypted biometric data. In this way, after receiving the biometric data sent by the client, the server can perform authentication processing on the user through the encrypted biometric data and the received biometric data to obtain an authentication result for the user. However, in the above authentication process, since the server needs to perform operations such as key generation and data encryption for each user, in the current situation where the number of users is increasing rapidly, it will lead to low data processing efficiency. In addition, the security of encrypting the user's biometric data by means of key encryption is low and is easily breached by attackers, resulting in a risk of leakage of the user's privacy data. Therefore, a solution that can improve the authentication efficiency and the security of privacy data in the authentication scenario is needed. For this reason, the embodiments of this specification provide a technical solution that can solve the above problems, and specific details can be seen in the following content.
[0037] Taking the access control device of a certain community as an example of the client, when a target user enters the community, they need to be authenticated through the access control device. Only when the authentication is passed can the access control device trigger and start the corresponding device to allow the target user to enter the community. Among them, the client can collect the facial image of the target user through devices such as cameras, and determine the collected facial image of the target user as the authentication information of the target user.
[0038] In addition, the client can actively collect face images within the collectible area through devices such as cameras. After collecting the face images (that is, it can be considered that the client has received the authentication request of the target user), the collected face images are determined as the authentication information of the target user. Among them, the images collected by the client may contain multiple face images. The client can generate a user identifier for each face image respectively, and determine the multiple users collected as the target user, and correspond the face images in the collected pictures to the generated user identifiers respectively.
[0039] The above takes the access control device with a higher usage frequency on the client side as an example. For clients with a lower usage frequency (such as access control devices during specific periods, self-service cabinets (such as express cabinets, self-service purchase cabinets, etc.)), when receiving an identity verification request from a target user for a target service, identity verification information of the target user can be obtained through devices such as cameras and fingerprint acquisition devices. For example, the target user can click the "pick up" control in the express cabinet (i.e., the client receives the identity verification request from the target user), and the client can obtain the facial image of the target user through the camera and use the facial image as the identity verification information of the target user.
[0040] In addition, to ensure the security of the target user's privacy information during information transmission, after obtaining the biometric data of the target user, the biometric data of the target user can be encrypted based on a preset encryption algorithm, and the encrypted biometric data is determined as the identity verification information of the target user. Among them, the preset encryption algorithm can be a row-column confusion encryption algorithm, a homomorphic encryption algorithm, etc.
[0041] The above method for obtaining the identity verification information of the target user is an optional and implementable method. In actual application scenarios, there can be various different acquisition methods, which can vary according to different actual application scenarios. The embodiments of this specification do not make specific limitations on this.
[0042] In S104, the identity verification information of the target user is sent to the server, and the identity verification result returned by the server is received.
[0043] Among them, the identity verification result can be obtained by the server based on the benchmark verification information and identity verification information of the target user stored in advance. The benchmark verification information can be the verification information obtained by desensitizing the target identity verification information of the target user based on the first privacy information desensitization model on the client side and the second privacy information desensitization model on the server side. The first privacy information desensitization model (or the second privacy information desensitization model) can be a model trained based on a preset deep learning algorithm for desensitizing privacy information. The target identity verification information of the target user can be biometric data such as fingerprints, facial images, irises, voiceprints, and gaits determined by a preset authoritative party and belonging to the target user.
[0044] In implementation, if there are multiple target users, the client can send the identity verification information of the target user and the user identifier of the target user to the server. In addition, the client needs to obtain the authorization of the target user before sending the identity verification information of the target user to the server.
[0045] Among them, the server can include a business processing server and a cloud server. The cloud server can store the benchmark verification information of the target user. The client can send the identity verification information of the target user to the business processing server. The business processing server can obtain the benchmark verification information of the target user from the cloud server, and then determine the identity verification result for the target user based on the benchmark verification information and the identity verification information.
[0046] In S106, when the identity verification result is verification passed, the target service is triggered to execute.
[0047] In implementation, if the identity verification result is verification failed, the client can output a preset prompt message. For example, the preset prompt message can be "Please enter the identity verification information again" to prompt the target user that the identity verification fails this time and can re-perform the identity verification. Additionally, if the number of times the target user fails the verification exceeds the preset number threshold, an alarm message can be output to a preset institution.
[0048] In addition, in the case of multiple target users, it can be determined whether to trigger the execution of the target service for the identity verification result of each target user. And when the identity verification results of multiple target users are verification passed, the target service is executed for each target user in sequence. For example, taking the client as an access control device, assuming there are 3 target users, and the identity verification information input by each target user is a facial image. If the identity verification results of target user 1 and target user 2 are verification passed, the client can output the facial images of target user 1 and target user 2, and output "Please let this user enter". At the same time, the client can collect the facial images of the users in front of the door through devices such as cameras, and perform matching processing on the collected facial images with the facial images of target user 1 and target user 2. If one of the image matching results is passed, the target service can be triggered to execute (that is, open the door to let target user 1 or target user 2 enter).
[0049] An embodiment of this specification provides a data processing method. When receiving an authentication request from a target user for a target service, obtain the authentication information of the target user, send the authentication information of the target user to the server, and receive the authentication result returned by the server. The authentication result is obtained by the server authenticating the target user based on the benchmark authentication information and the authentication information of the target user stored in advance. The benchmark authentication information is the authentication information obtained by desensitizing the target authentication information of the target user based on the first privacy information desensitization model of the client and the second privacy information desensitization model of the server. When the authentication result is authentication passed, trigger the execution of the target service. In this way, since the benchmark authentication information of the target user stored in the server is the authentication information obtained by desensitizing the target authentication information of the target user based on the first privacy information desensitization model of the client and the second privacy information desensitization model of the server, it is possible to avoid the problem of low privacy data security caused by only encrypting the target authentication information of the target user by the server, that is, it is possible to improve the storage security of the privacy data of the target user, reduce the leakage risk of the privacy data of the target user, and achieve the protection of the privacy data of the target user. In addition, the efficiency of data desensitization processing can be improved through the first privacy information desensitization model of the client and the second privacy information desensitization model of the server, so as to improve the authentication efficiency in the authentication scenario.
[0050] Embodiment 2
[0051] As Figure 2 shown, an embodiment of this specification provides a data processing method. The execution subject of this method can be a client, and the client can be a device that can be used by a user. For example, the client can be a mobile terminal device such as a mobile phone or a tablet computer, or can also be a terminal device such as an access control device or a face recognition payment device. This method can specifically include the following steps:
[0052] In S202, obtain historical first authentication information.
[0053] Among them, the historical first authentication information can be the authentication information stored by the client within a preset time period. For example, the historical first authentication information can be the facial image of the user stored by the client in the past 1 month. Or, the historical first authentication information can also be the authentication information within a preset time period sent by the server to the client.
[0054] In S204, input the historical first authentication information into the first privacy information desensitization model for desensitization processing to obtain the first authentication information.
[0055] Among them, the first privacy information desensitization model can be a model constructed based on a deep learning algorithm.
[0056] In implementation, due to the limited data processing capacity of the client, a three-layer convolutional layer can be used to construct the first privacy information desensitization model, and the historical first authentication information can be input into the first privacy information desensitization model for desensitization processing to obtain the first verification information.
[0057] In S206, the first verification information is input into the first reconstruction model for reconstruction processing to obtain the second verification information.
[0058] Among them, the first reconstruction model can be a model constructed by a deep learning algorithm for reconstruction processing. For example, the first reconstruction model can be a model constructed by a UNET decoder.
[0059] In implementation, the first verification information can be input into the first reconstruction model for reconstruction processing to obtain the second verification information.
[0060] In S208, according to the loss function, the historical first authentication information, the first verification information, the second verification information, and a preset first threshold, a first loss value is determined.
[0061] In implementation, in practical applications, the processing method of the above S208 can be various. The following provides an optional implementation method, which can be specifically referred to the processing of the following steps 1 to 3:
[0062] Step 1, based on the historical first authentication information and the second verification information, determine a first sub-loss value.
[0063] In implementation, the historical first authentication information and the second verification information can be input into the following formula to obtain the first sub-loss value.
[0064]
[0065] Among them, L reverse is the first sub-loss value, I is the historical first authentication information, and I reverse is the second verification information.
[0066] Step 2, based on the historical first authentication information, the first verification information, and a preset first threshold, determine a second sub-loss value.
[0067] Among them, the first preset threshold can be used to control the allowable loss amount, that is, the first preset threshold can be used to control the desensitization degree of the first privacy information desensitization model.
[0068] In implementation, the historical first authentication information, the first verification information, and the preset first threshold can be input into the following formula to obtain the second sub-loss value.
[0069]
[0070] where L privacy is the second sub-loss value, I is the historical first authentication information, I′ is the first authentication information, and m is a preset first threshold value.
[0071] Step 3: Determine the first loss value based on the first sub-loss value and the second sub-loss value.
[0072] In implementation, the combined value of the first sub-loss value and the second sub-loss value can be determined as the first loss value. In addition, there can be multiple methods for determining the first loss value. For example, the mean value, the highest value, etc. of the first sub-loss value and the second sub-loss value can also be determined as the first loss value. The method for determining the first loss value can vary according to different actual application scenarios, and this embodiment of the specification does not make specific limitations thereon.
[0073] In S210, if the first loss value satisfies the stop training condition, stop training the first privacy information desensitization model and the first reconstruction model.
[0074] In implementation, the first privacy information desensitization model and the first reconstruction model can be trained in combination with the Stochastic Gradient Descent (SGD) method until convergence.
[0075] In S212, determine the first privacy information desensitization model at the time of stopping training as the pre-trained first privacy information desensitization model.
[0076] In S214, obtain the target authentication information of the target user.
[0077] The target authentication information of the target user can be biometric data input by the target user stored on the client during the registration operation (and registration is successful). For example, taking the client as an access control device, the user can perform a user registration operation on the access control device and input biometric data (such as fingerprints) during registration, and the access control device can store the fingerprint as the target authentication information of the user.
[0078] In S216, send the target authentication information to the server and receive the first authentication information returned by the server.
[0079] The first authentication information can be the authentication information obtained by the server through desensitizing the target authentication information based on the pre-trained second privacy information desensitization model.
[0080] In S218, desensitize the first authentication information based on the pre-trained first privacy information desensitization model to obtain the reference authentication information of the target user.
[0081] In implementation, the client can input the first authentication information into a pre-trained first privacy information desensitization model for desensitization processing to obtain the reference authentication information of the target user. In this way, the reference authentication information of the target user is obtained by the server and the client respectively based on the locally trained models to desensitize the target authentication information of the target user in sequence, which can improve the security of privacy data.
[0082] In S220, send the reference authentication information to the server.
[0083] In S102, when receiving the authentication request of the target user for the target service, obtain the authentication information of the user.
[0084] In S104, send the authentication information of the target user to the server and receive the authentication result returned by the server.
[0085] In S106, when the verification result is verification passed, trigger the execution of the target service.
[0086] In S222, if it is determined based on the reference verification information and the first authentication information that the pre-trained privacy information desensitization model does not meet the desensitization requirements of the scenario where the client is located, obtain the historical first authentication information within the preset training period.
[0087] In implementation, since desensitization in different scenarios is different, if the scenario where the client is located changes, the pre-trained first privacy information desensitization model may not meet the desensitization requirements of the current scenario where the client is located. Therefore, it is necessary to judge whether the pre-trained first privacy information desensitization model meets the desensitization requirements of the current scenario where the client is located. For example, based on a preset distance algorithm (such as the Euclidean distance algorithm, cosine algorithm, etc.), determine the target distance between the reference verification information and the first authentication information. If the target distance is less than the preset distance threshold, it can be determined that the pre-trained first privacy information desensitization model does not meet the desensitization requirements of the scenario where the client is located. At this time, the historical first authentication information within the preset training period can be obtained.
[0088] The above method for judging whether the pre-trained privacy information desensitization model meets the desensitization requirements of the scenario where the client is located is an optional and implementable judgment method. In actual application scenarios, there can also be various different judgment methods, which can vary according to different actual application scenarios. The embodiments of this specification do not make specific limitations on this.
[0089] In S224, retrain the pre-trained first privacy information desensitization model based on the historical first authentication information within the preset training period.
[0090] In implementation, the specific process of retraining the pre-trained first privacy information desensitization model can refer to the above S202 - S212 and will not be elaborated here.
[0091] In S226, the first privacy information desensitization model obtained through retraining is determined as the pre-trained first privacy information desensitization model.
[0092] In implementation, the pre-trained first privacy information desensitization model can be updated, that is, the first privacy information desensitization model obtained through retraining is determined as the pre-trained first privacy information desensitization model.
[0093] In addition, the pre-trained first privacy information desensitization model can be obtained by the client training the first privacy information desensitization model based on a preset first number of historical first authentication information in a target scenario, and the pre-trained second privacy information desensitization model can be obtained by the server training the second privacy information desensitization model based on a preset second number of historical authentication information in multiple scenarios.
[0094] For example, the client can be an access control device, the target scenario can be an access control scenario. The client can obtain a preset first number of historical first authentication information in the access control scenario and train the first privacy information desensitization model based on the historical first authentication information to obtain the pre-trained first privacy information desensitization model. At the same time, the server can also obtain a preset second number of historical authentication information in multiple scenarios (such as access control scenarios, face brushing payment scenarios, etc.) and train the second privacy information desensitization model to obtain the pre-trained second privacy information desensitization model. Among them, the historical first authentication information can be obtained by the server desensitizing the historical authentication information in the target scenario based on the pre-trained second privacy information desensitization model.
[0095] In this way, the desensitization effect of the pre-trained second privacy information desensitization model is better, and the influence of the scenario can be reduced. At the same time, the pre-trained first privacy information desensitization model can perform desensitization processing for the scenario where the client is located and can perform targeted desensitization processing.
[0096] An embodiment of this specification provides a data processing method. When receiving an authentication request from a target user for a target service, obtain the authentication information of the target user, send the authentication information of the target user to the server, and receive the authentication result returned by the server. The authentication result is obtained by the server authenticating the target user based on the pre-stored benchmark authentication information and authentication information of the target user. The benchmark authentication information is the authentication information obtained by desensitizing the target authentication information of the target user based on the first private information desensitization model of the client and the second private information desensitization model of the server. When the authentication result is authentication passed, trigger the execution of the target service. In this way, since the benchmark authentication information of the target user stored in the server is the authentication information obtained by desensitizing the target authentication information of the target user based on the first private information desensitization model of the client and the second private information desensitization model of the server, it is possible to avoid the problem of low privacy data security caused by the method of only encrypting the target authentication information of the target user by the server, that is, it is possible to improve the storage security of the privacy data of the target user, reduce the leakage risk of the privacy data of the target user, and realize the protection of the privacy data of the target user. In addition, the efficiency of data desensitization processing can be improved through the first private information desensitization model of the client and the second private information desensitization model of the server, so as to improve the authentication efficiency in the authentication scenario.
[0097] Embodiment III
[0098] As Figure 3A and 3B shown, an embodiment of this specification provides a data processing method. The execution subject of this method can be the server, and the server can be a server. Among them, the server can be an independent server or a server cluster composed of multiple servers. This method can specifically include the following steps:
[0099] In S302, receive the authentication request from the client for the target user for the target service.
[0100] Among them, the authentication request may include the authentication information of the target user, and the authentication information of the target user may be biometric data such as the fingerprint, facial image, iris, voiceprint, and gait of the target user.
[0101] In S304, authenticate the target user based on the pre-stored benchmark authentication information and authentication information of the target user to obtain an authentication result.
[0102] Among them, the benchmark verification information can be the verification information obtained by desensitizing the target authentication information of the target user based on the first privacy information desensitization model of the client and the second privacy information desensitization model of the server.
[0103] In implementation, if the benchmark verification information is obtained by the second privacy information desensitization model of the server desensitizing the first authentication, where the first authentication information can be obtained by the client desensitizing the target authentication information of the target user, then the authentication information of the target user sent by the client can be the information desensitized by the client based on the first privacy information desensitization model. The server can desensitize the authentication information of the target user based on the second privacy information desensitization model to obtain the verifiable authentication information. By performing a matching process on the benchmark verification information and the verifiable authentication information, the authentication result for the target user can be determined according to the matching result.
[0104] Alternatively, if the benchmark verification information is obtained by the first privacy information desensitization model of the client desensitizing the first authentication, where the first authentication information is obtained by the server desensitizing the target authentication information of the target user, the server can desensitize the authentication information of the target user based on the second privacy information desensitization model to obtain the processed authentication information, then return the processed authentication information to the client, and receive the verifiable authentication information obtained by the client desensitizing the processed authentication information based on the first privacy information desensitization model. Then, perform a matching process on the verifiable authentication information and the benchmark verification information. Finally, the authentication result for the target user can be determined according to the matching result.
[0105] The above method for determining the authentication result is an optional and implementable determination method. In actual application scenarios, there can be multiple different determination methods. For example, the matching degree between the benchmark verification information and the authentication information can be determined based on a pre-trained matching degree determination model, and the authentication result for the target user can be determined according to the matching degree. Among them, the matching degree determination model can be trained by a machine learning algorithm based on historical benchmark verification information and historical authentication information. The method for determining the authentication result can vary according to different actual application scenarios, and this specification does not make specific limitations on this.
[0106] In S306, the authentication result is sent to the client so that the client triggers the execution of the target service when the authentication result is verification passed.
[0107] An embodiment of this specification provides a data processing method. The method receives an authentication request for a target service sent by a client. The authentication request includes authentication information of the target user. Based on the benchmark authentication information of the target user and the authentication information pre-stored, the method authenticates the target user to obtain an authentication result. The benchmark authentication information is the authentication information obtained by desensitizing the target authentication information of the target user based on a first private information desensitization model of the client and a second private information desensitization model of the server. The method then sends the authentication result to the client, so that when the authentication result indicates successful authentication, the client is triggered to execute the target service. In this way, since the benchmark authentication information of the target user stored on the server is the authentication information obtained by desensitizing the target authentication information of the target user based on the first private information desensitization model of the client and the second private information desensitization model of the server, it is possible to avoid the problem of low privacy data security caused by only encrypting the target authentication information of the target user on the server. That is, it is possible to improve the storage security of the privacy data of the target user, reduce the risk of leakage of the privacy data of the target user, and achieve the protection of the privacy data of the target user. In addition, the efficiency of data desensitization processing can be improved through the first private information desensitization model of the client and the second private information desensitization model of the server, so as to improve the authentication efficiency in the authentication scenario.
[0108] Embodiment 4
[0109] As Figure 4 shown, an embodiment of this specification provides a data processing method. The execution subject of this method can be a server, and the server can be a single server or a server cluster composed of multiple servers. The method specifically may include the following steps:
[0110] In S402, historical authentication information in multiple scenarios is obtained.
[0111] The historical authentication information may include the corresponding scenarios, and the multiple scenarios may include an access control scenario, a face recognition payment scenario, etc.
[0112] In S404, the historical authentication information is input into a second private information desensitization model for desensitization processing to obtain third authentication information.
[0113] The second private information desensitization model may be a model constructed based on a deep learning algorithm. For example, the second private information desensitization model may be a desensitization model constructed based on a ViT encoder.
[0114] In implementation, for example, historical authentication information can be input into a second privacy information desensitization model constructed based on a ViT encoder to obtain a feature map of the historical authentication information, and this feature map can be used as the third verification information.
[0115] In S406, the third verification information is input into a second reconstruction model for reconstruction processing to obtain the fourth verification information.
[0116] Among them, the second reconstruction model can be a model constructed by a deep learning algorithm for reconstruction processing. For example, the second reconstruction model can be a model constructed by a UNET decoder.
[0117] In S408, the third verification information is input into a preset classification model to obtain the first probability distribution corresponding to the historical authentication information.
[0118] Among them, the first probability distribution can include the probabilities of the historical authentication information belonging to each of multiple scenarios, and the preset classification model can be a pre-trained model for determining the probabilities of the authentication information belonging to each of multiple preset scenarios.
[0119] In implementation, cross-domain adaptive classification training can be performed based on the preset classification model. For example, the third verification information can be input into the preset classification model to obtain the first probability classification corresponding to the historical authentication information. Suppose there are 3 scenarios, namely Scenario 1, Scenario 2, and Scenario 3. The first probability distribution output by the preset classification model can include the probabilities of the historical authentication information belonging to each of these three scenarios. Specifically, for example, the probability of historical authentication information 1 belonging to Scenario 1 is a%, the probability of belonging to Scenario 2 is b%, and the probability of belonging to Scenario 3 is c%. Then the first probabilities of historical authentication information 1 can be {a%, b%, c%}, where a% + b% + c% = 1.
[0120] In S410, according to the loss function, the historical authentication information, the third verification information, the fourth verification information, the first probability distribution, and a preset second threshold, a second loss value is determined.
[0121] In implementation, in practical applications, the processing method of the above S410 can be various. The following provides an optional implementation method, which can specifically refer to the processing in the following Step 1 to Step 4:
[0122] Step 1, based on the historical authentication information and the fourth verification information, determine a first sub-loss value.
[0123] In implementation, the historical authentication information and the fourth verification information can be input into the following formula to obtain the first sub-loss value.
[0124]
[0125] wherein, L reverse is the first sub-loss value, I is the historical authentication information, and I reverse is the fourth authentication information.
[0126] Step 2: Determine a second sub-loss value based on the historical authentication information, the third authentication information, and a preset second threshold.
[0127] The second preset threshold can be used to control the allowable loss amount, that is, the second preset threshold can be used to control the desensitization degree of the second privacy information desensitization model.
[0128] In implementation, the historical authentication information, the third authentication information, and the preset second threshold can be input into the following formula to obtain the second sub-loss value.
[0129]
[0130] wherein, L privacy is the second sub-loss value, I is the historical authentication information, I′ is the third authentication information, and m is the preset second threshold.
[0131] Step 3: Determine a target probability distribution based on the number of multiple scenarios, and determine a third sub-loss value based on the first probability distribution and the target probability distribution.
[0132] In implementation, for example, assuming there are 3 scenarios, the target probabilities can be {1 / 3, 1 / 3, 1 / 3} respectively, that is, the probability corresponding to each scenario in the target probability distribution can be 1 / n (the reciprocal of the number of scenarios).
[0133] The first probability distribution and the target probability distribution can be input into the following formula to obtain the third sub-loss value.
[0134] L domain = ||P prediction - P average ||2
[0135] wherein, L domain is the third sub-loss value, P prediction is the first probability distribution, and P average is the target probability distribution.
[0136] Step 4: Determine a second loss value based on the first sub-loss value, the second sub-loss value, and the third sub-loss value.
[0137] In implementation, the combined value of the first sub-loss value, the second sub-loss value, and the third sub-loss value can be determined as the second loss value. In addition, there can be multiple methods for determining the second loss value. For example, one of the mean value, the maximum value, etc. of the first sub-loss value, the second sub-loss value, and the third sub-loss value can also be determined as the second loss value. The method for determining the second loss value can vary according to different actual application scenarios, and this embodiment of the specification does not make specific limitations on this.
[0138] In S412, if the second loss value meets the stop training condition, stop training the second privacy information desensitization model, the second reconstruction model, and the preset classification model.
[0139] In implementation, the second privacy information desensitization model, the second reconstruction model, and the preset classification model can be trained in combination with the Stochastic Gradient Descent (SGD) method until convergence.
[0140] In this way, the influence of the scenario on the second privacy information desensitization model can be reduced through the preset classification model.
[0141] In S414, based on the second privacy information desensitization model at the time of stopping training, determine the pre-trained second privacy information desensitization model.
[0142] In S416, receive the target authentication information of the target user sent by the client.
[0143] In S418, input the target authentication information of the target user into the pre-trained second privacy information desensitization model for desensitization processing to obtain the first authentication information.
[0144] In S420, send the first authentication information to the client and receive the benchmark authentication information of the target user returned by the client.
[0145] Among them, the benchmark authentication information can be the authentication information obtained by the client through desensitization processing of the target authentication information based on the pre-trained first privacy information desensitization model.
[0146] In S302, receive the authentication request of the target user for the target service sent by the client.
[0147] Among them, the authentication request includes the authentication information of the target user.
[0148] In S304, authenticate the target user based on the pre-stored benchmark authentication information and authentication information of the target user to obtain the authentication result.
[0149] In S306, send the authentication result to the client so that the client triggers the execution of the target service when the authentication result is passed.
[0150] An embodiment of this specification provides a data processing method. Receive an authentication request of a target user for a target service sent by a client. The authentication request includes the authentication information of the target user. Based on the benchmark authentication information and the authentication information of the target user stored in advance, authenticate the target user to obtain an authentication result. The benchmark authentication information is the authentication information obtained by desensitizing the target authentication information of the target user based on the first privacy information desensitization model of the client and the second privacy information desensitization model of the server. Send the authentication result to the client so that the client triggers the execution of the target service when the authentication result is passed. In this way, since the benchmark authentication information of the target user stored in the server is the authentication information obtained by desensitizing the target authentication information of the target user based on the first privacy information desensitization model of the client and the second privacy information desensitization model of the server, it is possible to avoid the problem of low privacy data security caused by only encrypting the target authentication information of the target user by the server, that is, it is possible to improve the storage security of the privacy data of the target user, reduce the leakage risk of the privacy data of the target user, and realize the protection of the privacy data of the target user. In addition, the efficiency of data desensitization processing can be improved through the first privacy information desensitization model of the client and the second privacy information desensitization model of the server, so as to improve the authentication efficiency in the authentication scenario.
[0151] Embodiment 5
[0152] As Figure 5 shown, an embodiment of this specification provides a data processing method. The execution subject of this method can be a server, and the server can be a server. Among them, the server can be an independent server or a server cluster composed of multiple servers. The method can specifically include the following steps:
[0153] In S502, receive the first authentication information of the target user sent by the client.
[0154] Among them, the first authentication information can be the authentication information obtained by the client desensitizing the target authentication information based on the pre-trained first privacy information desensitization model.
[0155] In S504, desensitize the first authentication information based on the pre-trained second privacy information desensitization model to obtain the benchmark authentication information.
[0156] In S302, receive an authentication request for a target service sent by a client.
[0157] Among them, the authentication request includes the authentication information of the target user.
[0158] In S304, authenticate the target user based on the benchmark authentication information and the authentication information of the target user stored in advance to obtain an authentication result.
[0159] In S306, send the authentication result to the client so that the client triggers the execution of the target service when the authentication result is authentication passed.
[0160] In addition, before S502, the second privacy information desensitization model can also be trained based on historical first authentication information. The specific training process can refer to S402 - S414 in the fourth embodiment above and will not be elaborated here. Among them, the historical first authentication information can be the authentication information obtained by different clients in multiple scenarios through desensitizing the historical authentication information based on the first privacy information desensitization model pre-trained locally. In this way, the first privacy information desensitization model can desensitize the authentication information of the target user based on the desensitization requirements of the local scenario, and then the second privacy information desensitization model on the server side desensitizes the authentication information desensitized by the client, which can reduce the influence of the scenario and improve the security of the authentication information.
[0161] An embodiment of this specification provides a data processing method, which receives an authentication request for a target service sent by a client. The authentication request includes authentication information of the target user. Based on the pre-stored reference authentication information and the authentication information of the target user, the target user is authenticated to obtain an authentication result. The reference authentication information is the authentication information obtained by desensitizing the target authentication information of the target user based on the first privacy information desensitization model of the client and the second privacy information desensitization model of the server. The authentication result is sent to the client so that the client triggers the execution of the target service when the authentication result is authentication passed. In this way, since the reference authentication information of the target user stored in the server is the authentication information obtained by desensitizing the target authentication information of the target user based on the first privacy information desensitization model of the client and the second privacy information desensitization model of the server, it is possible to avoid the problem of low privacy data security caused by only encrypting the target authentication information of the target user by the server, that is, it is possible to improve the storage security of the privacy data of the target user, reduce the leakage risk of the privacy data of the target user, and achieve the protection of the privacy data of the target user. In addition, the efficiency of data desensitization processing can be improved through the first privacy information desensitization model of the client and the second privacy information desensitization model of the server, so as to improve the authentication efficiency in the authentication scenario.
[0162] Embodiment Six
[0163] An embodiment of this specification provides a data processing system, including a client and a server. The client can be a device that a user can use. For example, the client can be a mobile terminal device such as a mobile phone or a tablet computer, or can also be a terminal device such as an access control device or a face recognition payment device. The server can be a server, where the server can be an independent server or a server cluster composed of multiple servers, and:
[0164] The client can obtain the authentication information of the target user when receiving an authentication request for a target service sent by the target user.
[0165] The server authenticates the target user based on the pre-stored reference authentication information and the authentication information, and obtains an authentication result. Among them, the reference authentication information can be the authentication information obtained by desensitizing the target authentication information of the target user based on the first privacy information desensitization model of the client and the second privacy information desensitization model of the server.
[0166] The server sends the authentication result to the client. The client triggers the execution of the target service when the authentication result is authentication passed.
[0167] In addition, as Figure 6 shown, the server can include a service processing server and a cloud server. When the client receives an authentication request from the target user for the target service, it can send the obtained authentication information of the target user to the service processing server. The service processing server then sends the authentication request to the cloud server and obtains the reference authentication information of the target user from the cloud server. Then, the service processing server can determine the authentication result based on the obtained reference authentication information and the authentication information of the target user, and then return the determined authentication result to the client.
[0168] In addition, as Figure 7 shown, different clients can correspond to one or more different service processing servers, and multiple service processing servers can correspond to the same cloud server. When generating the reference authentication information of the target user, the client can first desensitize the target authentication information of the target user based on the locally pre-trained first privacy information desensitization model to obtain the first authentication information, and then send the first authentication information to the corresponding service processing server. The service processing server then desensitizes the first authentication information based on the pre-trained second privacy information desensitization model to obtain the reference authentication information of the target user, and sends the reference authentication information of the target user to the cloud server for storage.
[0169] Alternatively, the client can also send the target authentication information of the target user to the service processing server. The service processing server can desensitize the target authentication information based on the pre-trained second privacy information desensitization model to obtain the first authentication information. The service processing server then returns the first authentication information to the corresponding client. The client can desensitize the first authentication information based on the pre-trained first privacy information desensitization model to obtain the reference authentication information of the target user. The client can directly send the reference authentication information of the target user to the cloud server for storage.
[0170] Or, as Figure 8 shown, the client can desensitize the target authentication information of the target user based on the locally pre-trained first privacy information desensitization model to obtain the first authentication information, and then send the first authentication information to the cloud server. The cloud processing server then desensitizes the first authentication information based on the pre-trained second privacy information desensitization model to obtain and store the reference authentication information of the target user. In this way, since the cloud server has strong data processing capabilities, a large amount of data can be obtained on the cloud server and the second privacy information desensitization model can be trained to make the performance of the pre-trained second privacy information desensitization model good, that is, the data desensitization effect is good.
[0171] In addition, to solve the problem that the first privacy information desensitization model of the client cannot meet the desensitization requirements of the scenario in cross-scenario situations, the first privacy information desensitization model of the client can also be adaptively trained periodically, so as to improve the model generalization ability for specific scenarios. For example, assume that the baseline authentication information of the user is first desensitized by the server based on a pre-trained second privacy information desensitization model for the target authentication information of the user to obtain the first authentication information, and then the client desensitizes the first authentication information based on a pre-trained first privacy information desensitization model. Then, based on a preset inspection cycle, it can be determined whether the distance between the user's baseline authentication information and the first authentication information is less than a preset distance threshold. If it is less than the preset distance threshold, it can be determined that the current first privacy information desensitization model cannot meet the desensitization requirements of the scenario where the client is located. The adaptive training process can be entered, that is, n pieces of historical first authentication information can be obtained, and the first privacy information desensitization model can be trained during a preset update period (such as from 23:00 to 3:00 the next day every day), and the first privacy information desensitization model obtained through training can be determined as the pre-trained first privacy information desensitization model, that is, the update process of the first privacy information desensitization model is realized.
[0172] Among them, the historical first authentication information can be stored locally on the client, or obtained by the client from a cloud server or a business processing server. Or, the historical first authentication information can also be authentication information obtained from a cloud server or a business processing server based on the scenario identifier of the current scenario, so that the first privacy information desensitization model after the update process meets the desensitization requirements of the scenario where the client is located.
[0173] During the data transmission process, to improve the security during data transmission, the data can be encrypted. For example, the authentication information of the target user sent by the client to the server can be authentication information after obfuscation encryption or homomorphic encryption. Or, the client can also generate verifiable information (such as a hash value, etc.) based on the authentication information of the target user, so that the server can verify whether the authentication information of the target user has been tampered with during the transmission process based on the verifiable information. Similarly, when the server sends data such as an authentication result or a first verification information to the client, corresponding verifiable information can also be generated to improve the security of the data during the transmission process.
[0174] An embodiment of this specification provides a data processing system. When the client receives an authentication request from a target user for a target service, it can obtain the authentication information of the target user. The server authenticates the target user based on the pre-stored benchmark authentication information of the target user and the authentication information, and obtains an authentication result. Among them, the benchmark authentication information can be the authentication information obtained by desensitizing the target authentication information of the target user based on the first privacy information desensitization model of the client and the second privacy information desensitization model of the server. The server sends the authentication result to the client, and when the authentication result is authentication passed, the client triggers the execution of the target service. In this way, since the benchmark authentication information of the target user stored in the server is the authentication information obtained by desensitizing the target authentication information of the target user based on the first privacy information desensitization model of the client and the second privacy information desensitization model of the server, it is possible to avoid the problem of low privacy data security caused by only encrypting the target authentication information of the target user by the server, that is, it is possible to improve the storage security of the privacy data of the target user, reduce the leakage risk of the privacy data of the target user, and realize the protection of the privacy data of the target user. In addition, the first privacy information desensitization model of the client and the second privacy information desensitization model of the server can also be used to improve the efficiency of data desensitization processing, so as to improve the authentication efficiency in the authentication scenario.
[0175] Embodiment Seven
[0176] The above is the data processing method provided by the embodiments of this specification. Based on the same idea, the embodiments of this specification also provide a data processing device, as Figure 9 shown.
[0177] The data processing device includes: a first acquisition module 901, a result acquisition module 902, and a service trigger module 903, where:
[0178] The first acquisition module 901 is configured to obtain the authentication information of the target user when receiving an authentication request from the target user for the target service;
[0179] The result acquisition module 902 is configured to send the authentication information of the target user to the server and receive the authentication result returned by the server. The authentication result is obtained by the server authenticating the target user based on the pre-stored benchmark authentication information of the target user and the authentication information. The benchmark authentication information is the authentication information obtained by desensitizing the target authentication information of the target user based on the first privacy information desensitization model of the client and the second privacy information desensitization model of the server;
[0180] A service trigger module 903, configured to trigger the execution of the target service when the authentication result is verified.
[0181] In the embodiments of this specification, the apparatus further includes:
[0182] A second acquisition module, configured to acquire the target authentication information of the target user;
[0183] A first sending module, configured to send the target authentication information to the server and receive the first authentication information returned by the server, where the first authentication information is the authentication information obtained by the server based on the pre-trained second privacy information desensitization model for desensitizing the target authentication information;
[0184] A first processing module, configured to desensitize the first authentication information based on the pre-trained first privacy information desensitization model to obtain the reference authentication information of the target user;
[0185] A second sending module, configured to send the reference authentication information of the target user to the server.
[0186] In the embodiments of this specification, the apparatus further includes:
[0187] A third acquisition module, configured to acquire historical first authentication information;
[0188] A second processing module, configured to input the historical first authentication information into the first privacy information desensitization model for desensitization processing to obtain first verification information;
[0189] A reconstruction module, configured to input the first verification information into the first reconstruction model for reconstruction processing to obtain second verification information;
[0190] A data determination module, configured to determine a first loss value according to a loss function, the historical first authentication information, the first verification information, the second verification information, and a preset first threshold;
[0191] A first judgment module, configured to stop training the first privacy information desensitization model and the first reconstruction model if the first loss value meets the stop training condition;
[0192] A first determination module, configured to determine the first privacy information desensitization model at the time of stopping training as the pre-trained first privacy information desensitization model.
[0193] In the embodiments of this specification, the data determination module is configured to:
[0194] Determine a first sub-loss value based on the historical first authentication information and the second authentication information;
[0195] Determine a second sub-loss value based on the historical first authentication information, the first authentication information, and the preset first threshold;
[0196] Determine the first loss value based on the first sub-loss value and the second sub-loss value.
[0197] In the embodiments of this specification, the apparatus further includes:
[0198] A second determination module, configured to, if it is determined that the pre-trained first privacy information de-sensitization model does not meet the de-sensitization requirements of the scenario where the client is located based on the reference authentication information and the first authentication information, obtain the historical first authentication information within a preset training period;
[0199] A model training module, configured to re-train the pre-trained first privacy information de-sensitization model based on the historical first authentication information within the preset training period;
[0200] A second determination module, configured to determine the first privacy information de-sensitization model obtained through re-training as the pre-trained first privacy information de-sensitization model.
[0201] In the embodiments of this specification, the pre-trained first privacy information de-sensitization model is obtained by the client training the first privacy information de-sensitization model based on a preset first number of historical first authentication information in a target scenario, and the pre-trained second privacy information de-sensitization model is obtained by the server training the second privacy information de-sensitization model based on a preset second number of historical authentication information in multiple scenarios.
[0202] An embodiment of this specification provides a data processing device. When receiving an authentication request of a target user for a target service, the device obtains the authentication information of the target user, sends the authentication information of the target user to the server, and receives the authentication result returned by the server. The authentication result is obtained by the server authenticating the target user based on the benchmark authentication information and the authentication information of the target user stored in advance. The benchmark authentication information is the authentication information obtained by desensitizing the target authentication information of the target user based on the first privacy information desensitization model of the client and the second privacy information desensitization model of the server. When the authentication result is authentication passed, the device triggers the execution of the target service. In this way, since the benchmark authentication information of the target user stored in the server is the authentication information obtained by desensitizing the target authentication information of the target user based on the first privacy information desensitization model of the client and the second privacy information desensitization model of the server, it is possible to avoid the problem of low privacy data security caused by only encrypting the target authentication information of the target user by the server, that is, it is possible to improve the storage security of the privacy data of the target user, reduce the leakage risk of the privacy data of the target user, and realize the protection of the privacy data of the target user. In addition, the efficiency of data desensitization processing can be improved through the first privacy information desensitization model of the client and the second privacy information desensitization model of the server, so as to improve the authentication efficiency in the authentication scenario.
[0203] Embodiment VIII
[0204] The above is the data processing method provided by the embodiments of this specification. Based on the same idea, the embodiments of this specification also provide a data processing device, as Figure 10 shown.
[0205] The data processing device includes: a request receiving module 1001, an authentication module 1002, and a first sending module 1003, where:
[0206] The request receiving module 1001 is configured to receive an authentication request of a target user for a target service sent by a client, where the authentication request includes the authentication information of the target user;
[0207] The authentication module 1002 is configured to authenticate the target user based on the benchmark authentication information and the authentication information of the target user stored in advance, and obtain an authentication result. The benchmark authentication information is the authentication information obtained by desensitizing the target authentication information of the target user based on the first privacy information desensitization model of the client and the second privacy information desensitization model of the server;
[0208] The first sending module 1003 is configured to send the authentication result to the client, so that the client triggers the execution of the target service when the authentication result is verified.
[0209] In the embodiments of the present specification, the apparatus further includes:
[0210] The first receiving module is configured to receive the first authentication information of the target user sent by the client, where the first authentication information is the authentication information obtained by the client through desensitization processing of the target authentication information based on the pre-trained first private information desensitization model;
[0211] The information determination module is configured to desensitize the first authentication information based on the pre-trained second private information desensitization model to obtain the reference authentication information.
[0212] In the embodiments of the present specification, the apparatus further includes:
[0213] The second receiving module is configured to receive the target authentication information of the target user sent by the client;
[0214] The first processing module is configured to input the target authentication information of the target user into the pre-trained second private information desensitization model for desensitization processing to obtain the first authentication information;
[0215] The second sending module is configured to send the first authentication information to the client and receive the reference authentication information of the target user returned by the client, where the reference authentication information is the authentication information obtained by the client through desensitization processing of the target authentication information based on the pre-trained first private information desensitization model.
[0216] In the embodiments of the present specification, the apparatus further includes:
[0217] The information acquisition module is configured to acquire the historical authentication information in the multiple scenarios, where the historical authentication information includes the corresponding scenarios;
[0218] The second processing module is configured to input the historical authentication information into the second private information desensitization model for desensitization processing to obtain the third authentication information;
[0219] The reconstruction module is configured to input the third authentication information into the second reconstruction model for reconstruction processing to obtain the fourth authentication information;
[0220] A third processing module, configured to input the third verification information into a preset classification model to obtain a first probability distribution corresponding to the historical authentication information, where the first probability distribution includes the probabilities that the historical authentication information belongs to each of the multiple scenarios;
[0221] A data determination module, configured to determine a second loss value according to a loss function, the historical authentication information, the third verification information, the fourth verification information, the first probability distribution, and a preset second threshold;
[0222] A judgment module, configured to stop training the second privacy information desensitization model, the second reconstruction model, and the preset classification model if the second loss value satisfies a stop training condition;
[0223] A first determination module, configured to determine the pre-trained second privacy information desensitization model based on the second privacy information desensitization model at the time of stopping training.
[0224] In an embodiment of this specification, the data determination module is configured to:
[0225] Determine a first sub-loss value based on the historical authentication information and the fourth verification information;
[0226] Determine a second sub-loss value based on the historical authentication information, the third verification information, and the preset second threshold;
[0227] Determine a target probability distribution based on the number of the multiple scenarios, and determine a third sub-loss value based on the first probability distribution and the target probability distribution;
[0228] Determine the second loss value based on the first sub-loss value, the second sub-loss value, and the third sub-loss value.
[0229] An embodiment of this specification provides a data processing device that receives an authentication request for a target user for a target service sent by a client. The authentication request includes the authentication information of the target user. Based on the pre-stored reference authentication information and authentication information of the target user, the target user is authenticated to obtain an authentication result. The reference authentication information is the authentication information obtained by desensitizing the target authentication information of the target user based on the first privacy information desensitization model of the client and the second privacy information desensitization model of the server. The authentication result is sent to the client so that the client triggers the execution of the target service when the authentication result is authentication passed. In this way, since the reference authentication information of the target user stored on the server is the authentication information obtained by desensitizing the target authentication information of the target user based on the first privacy information desensitization model of the client and the second privacy information desensitization model of the server, it is possible to avoid the problem of low privacy data security caused by only encrypting the target authentication information of the target user on the server, that is, it is possible to improve the storage security of the privacy data of the target user, reduce the leakage risk of the privacy data of the target user, and achieve the protection of the privacy data of the target user. In addition, the first privacy information desensitization model of the client and the second privacy information desensitization model of the server can also be used to improve the efficiency of data desensitization processing to improve the authentication efficiency in the authentication scenario.
[0230] Embodiment 49
[0231] Based on the same idea, an embodiment of this specification also provides a data processing device, as Figure 11 shown.
[0232] The data processing device may vary greatly due to configuration or performance, and may include one or more processors 1101 and a memory 1102. One or more application programs or data may be stored in the memory 1102. Among them, the memory 1102 may be transient storage or persistent storage. The application programs stored in the memory 1102 may include one or more modules (not shown in the figure), and each module may include a series of computer-executable instructions in the data processing device. Further, the processor 1101 may be set to communicate with the memory 1102 and execute a series of computer-executable instructions in the memory 1102 on the data processing device. The data processing device may also include one or more power supplies 1103, one or more wired or wireless network interfaces 1104, one or more input / output interfaces 1105, and one or more keyboards 1106.
[0233] Specifically, in this embodiment, the data processing device includes a memory and one or more programs. One or more of the programs are stored in the memory, and one or more of the programs may include one or more modules. Each module may include a series of computer-executable instructions in the data processing device and is configured to be executed by one or more processors. The one or more programs include the following computer-executable instructions for:
[0234] Upon receiving an authentication request from a target user for a target service, obtain the authentication information of the target user;
[0235] Send the authentication information of the target user to the server and receive the authentication result returned by the server. The authentication result is obtained by the server authenticating the target user based on the pre-stored reference authentication information of the target user and the authentication information. The reference authentication information is the authentication information obtained by desensitizing the target authentication information of the target user based on the first privacy information desensitization model of the data processing device and the second privacy information desensitization model of the server;
[0236] If the authentication result is authentication passed, trigger the execution of the target service.
[0237] Optionally, before obtaining the authentication information of the target user upon receiving an authentication request from a target user for a target service, the method further includes:
[0238] Obtain the target authentication information of the target user;
[0239] Send the target authentication information to the server and receive the first authentication information returned by the server. The first authentication information is the authentication information obtained by the server desensitizing the target authentication information based on the pre-trained second privacy information desensitization model;
[0240] Desensitize the first authentication information based on the pre-trained first privacy information desensitization model to obtain the reference authentication information of the target user;
[0241] Send the reference authentication information of the target user to the server.
[0242] Optionally, before desensitizing the first authentication information based on the pre-trained first privacy information desensitization model to obtain the target authentication information, the method further includes:
[0243] Obtain the historical first authentication information;
[0244] Input the historical first authentication information into the first privacy information desensitization model for desensitization processing to obtain the first verification information;
[0245] Input the first verification information into the first reconstruction model for reconstruction processing to obtain the second verification information;
[0246] Determine the first loss value according to the loss function, the historical first authentication information, the first verification information, the second verification information, and a preset first threshold;
[0247] If the first loss value meets the stop training condition, stop training the first privacy information desensitization model and the first reconstruction model;
[0248] Determine the first privacy information desensitization model at the time of stopping training as the pre-trained first privacy information desensitization model.
[0249] Optionally, the determining the first loss value according to the loss function, the historical first authentication information, the first verification information, the second verification information, and the preset first threshold includes:
[0250] Determine the first sub-loss value based on the historical first authentication information and the second verification information;
[0251] Determine the second sub-loss value based on the historical first authentication information, the first verification information, and the preset first threshold;
[0252] Determine the first loss value based on the first sub-loss value and the second sub-loss value.
[0253] Optionally, the method further includes:
[0254] If it is determined that the pre-trained first privacy information desensitization model does not meet the desensitization requirements of the scenario where the data processing device is located based on the reference verification information and the first authentication information, obtain the historical first authentication information within the preset training period;
[0255] Retrain the pre-trained first privacy information desensitization model based on the historical first authentication information within the preset training period;
[0256] Determine the first privacy information desensitization model obtained after retraining as the pre-trained first privacy information desensitization model.
[0257] Optionally, the pre-trained first privacy information desensitization model is obtained by the data processing device training the first privacy information desensitization model based on a preset first quantity of historical first authentication information in a target scenario, and the pre-trained second privacy information desensitization model is obtained by the server training the second privacy information desensitization model based on a preset second quantity of historical authentication information in multiple scenarios.
[0258] In addition, specifically in this embodiment, the data processing device includes a memory and one or more programs, where one or more programs are stored in the memory, and one or more programs may include one or more modules, and each module may include a series of computer executable instructions in the data processing device, and is configured to be executed by one or more processors. The one or more programs include the following computer executable instructions:
[0259] Receive an authentication request for a target user for a target service sent by a client, where the authentication request includes the authentication information of the target user;
[0260] Based on the pre-stored reference authentication information of the target user and the authentication information, authenticate the target user to obtain an authentication result, where the reference authentication information is the authentication information obtained by desensitizing the target authentication information of the target user based on the first privacy information desensitization model of the client and the second privacy information desensitization model of the data processing device;
[0261] Send the authentication result to the client, so that the client triggers the execution of the target service when the authentication result is authentication passed.
[0262] Optionally, before authenticating the target user based on the pre-stored reference authentication information of the target user and the authentication information to obtain an authentication result, it further includes:
[0263] Receive the first authentication information of the target user sent by the client, where the first authentication information is the authentication information obtained by the client desensitizing the target authentication information based on the pre-trained first privacy information desensitization model;
[0264] Desensitize the first authentication information based on the pre-trained second privacy information desensitization model to obtain the reference authentication information.
[0265] Optionally, before authenticating the target user based on the pre-stored benchmark authentication information and the authentication information of the target user to obtain an authentication result, the method further includes:
[0266] Receiving the target authentication information of the target user sent by the client;
[0267] Inputting the target authentication information of the target user into the pre-trained second privacy information desensitization model for desensitization processing to obtain first authentication information;
[0268] Sending the first authentication information to the client and receiving the benchmark authentication information of the target user returned by the client, where the benchmark authentication information is the verification information obtained by the client through desensitization processing of the target authentication information based on the pre-trained first privacy information desensitization model.
[0269] Optionally, before authenticating the target user based on the pre-stored benchmark authentication information and the authentication information of the target user to obtain an authentication result, the method further includes:
[0270] Obtaining historical authentication information in the multiple scenarios, where the historical authentication information includes the corresponding scenarios;
[0271] Inputting the historical authentication information into the second privacy information desensitization model for desensitization processing to obtain third verification information;
[0272] Inputting the third verification information into a second reconstruction model for reconstruction processing to obtain fourth verification information;
[0273] Inputting the third verification information into a preset classification model to obtain a first probability distribution corresponding to the historical authentication information, where the first probability distribution includes the probabilities of the historical authentication information belonging to each of the multiple scenarios;
[0274] Determining a second loss value according to a loss function, the historical authentication information, the third verification information, the fourth verification information, the first probability distribution, and a preset second threshold;
[0275] If the second loss value satisfies a stop training condition, stop training the second privacy information desensitization model, the second reconstruction model, and the preset classification model;
[0276] Based on the second privacy information desensitization model at the time of stopping training, determine the pre-trained second privacy information desensitization model.
[0277] Optionally, determining a second loss value according to the loss function, the historical authentication information, the third authentication information, the fourth authentication information, the first probability distribution, and a preset second threshold includes:
[0278] Determining a first sub-loss value based on the historical authentication information and the fourth authentication information;
[0279] Determining a second sub-loss value based on the historical authentication information, the third authentication information, and the preset second threshold;
[0280] Determining a target probability distribution based on the number of the multiple scenarios, and determining a third sub-loss value based on the first probability distribution and the target probability distribution;
[0281] Determining the second loss value based on the first sub-loss value, the second sub-loss value, and the third sub-loss value.
[0282] An embodiment of this specification provides a data processing device. Since the reference authentication information of the target user stored in the server is the authentication information obtained by performing desensitization processing on the target authentication information of the target user based on the first privacy information desensitization model of the client and the second privacy information desensitization model of the server, it is possible to avoid the problem of low privacy data security caused by only encrypting the target authentication information of the target user by the server, that is, it is possible to improve the storage security of the privacy data of the target user, reduce the leakage risk of the privacy data of the target user, and achieve the protection of the privacy data of the target user. In addition, the efficiency of data desensitization processing can be improved through the first privacy information desensitization model of the client and the second privacy information desensitization model of the server, so as to improve the authentication efficiency in the authentication scenario.
[0283] Embodiment Ten
[0284] An embodiment of this specification also provides a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, it implements each process of the above data processing method embodiment and can achieve the same technical effect. To avoid repetition, it will not be elaborated here. Among them, the computer-readable storage medium is, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc, etc.
[0285] An embodiment of this specification provides a computer-readable storage medium. Since the reference verification information of the target user stored on the server is the verification information obtained by desensitizing the target authentication information of the target user based on the first privacy information desensitization model of the client and the second privacy information desensitization model of the server, it is possible to avoid the problem of low privacy data security caused by the method of only encrypting the target authentication information of the target user by the server. That is, it is possible to improve the storage security of the privacy data of the target user, reduce the leakage risk of the privacy data of the target user, and achieve the protection of the privacy data of the target user. In addition, the efficiency of data desensitization processing can be improved through the first privacy information desensitization model of the client and the second privacy information desensitization model of the server, so as to improve the authentication efficiency in the authentication scenario.
[0286] The specific embodiments of this specification have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in a different order than in the embodiments and still achieve the desired results. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0287] In the 1990s, it was obvious to distinguish whether an improvement in a technology was a hardware improvement (e.g., improvement in circuit structures such as diodes, transistors, switches, etc.) or a software improvement (improvement in method processes). However, with the development of technology, many improvements in method processes today can be regarded as direct improvements in hardware circuit structures. Almost all designers obtain the corresponding hardware circuit structures by programming the improved method processes into the hardware circuits. Therefore, it cannot be said that an improvement in a method process cannot be implemented with a hardware entity module. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logical function is determined by the user programming the device. The designer can program by himself to "integrate" a digital system on a PLD, without having to ask a chip manufacturer to design and fabricate a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly implemented using "logic compiler" software, which is similar to the software compiler used in program development and writing. The original code before compilation also has to be written in a specific programming language, which is called a Hardware Description Language (HDL). There is not only one kind of HDL, but many kinds, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones currently are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also be aware that by simply making a little logical programming of the method process with the above-mentioned several hardware description languages and programming it into an integrated circuit, it is easy to obtain the hardware circuit that implements the logical method process.
[0288] The controller can be implemented in any suitable manner. For example, the controller can take the form of, for example, a microprocessor or a processor and a computer-readable medium storing computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of the controller include, but are not limited to, the following microcontrollers: ARC625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that, in addition to implementing the controller in the form of pure computer-readable program code, it is entirely possible to logically program the method steps to enable the controller to be implemented in the form of logic gates, switches, application specific integrated circuits, programmable logic controllers, embedded microcontrollers, etc. to achieve the same functions. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be regarded as the structures within the hardware component. Or even, the devices for implementing various functions can be regarded as either software modules for implementing the method or the structures within the hardware component.
[0289] The systems, devices, modules, or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.
[0290] For the convenience of description, when describing the above devices, they are described separately as various units according to their functions. Of course, when implementing one or more embodiments of this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0291] Those skilled in the art should understand that the embodiments of this specification can be provided as a method, a system, or a computer program product. Therefore, one or more embodiments of this specification can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, one or more embodiments of this specification can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer-usable program code.
[0292] Embodiments of the present specification are described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present specification. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a means for implementing the functions specified in one or more flows in the flowchart and / or one or more blocks in the block diagram.
[0293] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction means that implements the functions specified in one or more flows in the flowchart and / or one or more blocks in the block diagram.
[0294] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more flows in the flowchart and / or one or more blocks in the block diagram.
[0295] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and a memory.
[0296] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. The memory is an example of computer-readable media.
[0297] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0298] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0299] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Thus, one or more embodiments of this specification may take the form of a fully hardware embodiment, a fully software embodiment, or an embodiment combining software and hardware. Furthermore, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0300] One or more embodiments of the present specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. One or more embodiments of the present specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.
[0301] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other, and the key point of each embodiment is to illustrate the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and for the relevant parts, reference can be made to the partial description of the method embodiment.
[0302] The above is only the embodiment of this specification and is not used to limit this specification. For those skilled in the art, various modifications and changes can be made to this specification. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this specification shall be included within the scope of the claims of this specification.
Claims
1. A data processing method, applied to a client, includes: Obtain the target authentication information of the target user; Send the target authentication information to the server and receive the first authentication information returned by the server, where the first authentication information is the authentication information obtained by the server through desensitizing the target authentication information based on a pre-trained second privacy information desensitization model; Desensitize the first authentication information based on a pre-trained first privacy information desensitization model to obtain the benchmark authentication information of the target user; Send the benchmark authentication information of the target user to the server; When receiving an authentication request of the target user for a target service, obtain the authentication information of the target user; Send the authentication information of the target user to the server and receive the authentication result returned by the server, where the authentication result is obtained by the server through authenticating the target user based on the pre-stored benchmark authentication information and the authentication information of the target user; When the authentication result is authentication passed, trigger the execution of the target service.
2. The method according to claim 1, before desensitizing the first authentication information based on the pre-trained first privacy information desensitization model to obtain the benchmark authentication information of the target user, the method further includes: Obtain historical first authentication information; Input the historical first authentication information into the first privacy information desensitization model for desensitization processing to obtain first authentication information; Input the first authentication information into a first reconstruction model for reconstruction processing to obtain second authentication information; Determine a first loss value according to a loss function, the historical first authentication information, the first authentication information, the second authentication information, and a preset first threshold; If the first loss value meets the stop training condition, stop training the first privacy information desensitization model and the first reconstruction model; Determine the first privacy information desensitization model at the time of stopping training as the pre-trained first privacy information desensitization model.
3. The method according to claim 2, the determining the first loss value according to a loss function, the historical first authentication information, the first authentication information, the second authentication information, and a preset first threshold includes: Determine a first sub-loss value based on the historical first authentication information and the second authentication information; Determine a second sub-loss value based on the historical first authentication information, the first authentication information, and the preset first threshold; Determine the first loss value based on the first sub-loss value and the second sub-loss value.
4. The method according to claim 1, the method further includes: If it is determined based on the benchmark authentication information and the first authentication information that the pre-trained first privacy information desensitization model does not meet the desensitization requirements of the scenario where the client is located, obtain the historical first authentication information within a preset training period; Retrain the pre-trained first privacy information desensitization model based on the historical first authentication information within the preset training period; Determine the retrained first privacy information desensitization model as the pre-trained first privacy information desensitization model.
5. The method according to claim 1, wherein the pre-trained first privacy information desensitization model is obtained by the client training the first privacy information desensitization model based on a preset first number of historical first authentication information in a target scenario, and the pre-trained second privacy information desensitization model is obtained by the server training the second privacy information desensitization model based on a preset second number of historical authentication information in multiple scenarios.
6. A data processing method applied to a server, comprising: Receiving target authentication information of a target user sent by a client; Inputting the target authentication information of the target user into a pre-trained second privacy information desensitization model for desensitization processing to obtain first authentication information; Sending the first authentication information to the client and receiving the benchmark authentication information of the target user returned by the client, where the benchmark authentication information is the authentication information obtained by the client through desensitization processing of the target authentication information based on the pre-trained first privacy information desensitization model; Receiving an authentication request of the target user for a target service sent by the client, where the authentication request includes the authentication information of the target user; Authenticating the target user based on the pre-stored benchmark authentication information and the authentication information of the target user to obtain an authentication result; Sending the authentication result to the client so that the client triggers the execution of the target service when the authentication result is authentication passed.
7. The method according to claim 6, before the authenticating the target user based on the pre-stored benchmark authentication information and the authentication information of the target user to obtain an authentication result, the method further comprises: Obtaining historical authentication information in multiple scenarios, where the historical authentication information includes corresponding scenarios; Inputting the historical authentication information into the second privacy information desensitization model for desensitization processing to obtain third authentication information; Inputting the third authentication information into a second reconstruction model for reconstruction processing to obtain fourth authentication information; Inputting the third authentication information into a preset classification model to obtain a first probability distribution corresponding to the historical authentication information, where the first probability distribution includes the probabilities of the historical authentication information belonging to each of the multiple scenarios; Determining a second loss value according to a loss function, the historical authentication information, the third authentication information, the fourth authentication information, the first probability distribution, and a preset second threshold; If the second loss value satisfies the stop training condition, stop training the second privacy information desensitization model, the second reconstruction model, and the preset classification model; Determine the pre-trained second privacy information desensitization model based on the second privacy information desensitization model at the time of stopping training.
8. The method according to claim 7, wherein determining the second loss value according to the loss function, the historical authentication information, the third authentication information, the fourth authentication information, the first probability distribution, and a preset second threshold includes: Determine a first sub-loss value based on the historical authentication information and the fourth authentication information; Determine a second sub-loss value based on the historical authentication information, the third authentication information, and the preset second threshold; Determine a target probability distribution based on the number of the multiple scenarios, and determine a third sub-loss value based on the first probability distribution and the target probability distribution; Determine the second loss value based on the first sub-loss value, the second sub-loss value, and the third sub-loss value.
9. A data processing system, comprising a client and a server, wherein: The client obtains target authentication information of a target user and sends the target authentication information to the server; The server performs desensitization processing on the target authentication information based on a pre-trained second privacy information desensitization model to obtain first authentication information, and sends the first authentication information to the client; The client performs desensitization processing on the first authentication information based on a pre-trained first privacy information desensitization model to obtain benchmark authentication information of the target user; And sends the benchmark authentication information of the target user to the server; The client obtains the authentication information of the target user when receiving an authentication request of the target user for a target service; The server authenticates the target user based on the benchmark authentication information and the authentication information of the target user stored in advance to obtain an authentication result; The server sends the authentication result to the client; The client triggers the execution of the target service when the authentication result is authentication passed.
10. A data processing device, comprising: A second obtaining module, configured to obtain target authentication information of a target user; A first sending module, configured to send the target authentication information to a server and receive the first authentication information returned by the server, where the first authentication information is authentication information obtained by the server performing desensitization processing on the target authentication information based on a pre-trained second privacy information desensitization model; A first processing module, configured to perform desensitization processing on the first authentication information based on a pre-trained first privacy information desensitization model to obtain benchmark authentication information of the target user; A second sending module, configured to send the benchmark authentication information of the target user to the server; A first obtaining module, configured to obtain the authentication information of the target user when receiving an authentication request of the target user for a target service; A result acquisition module, configured to send the authentication information of the target user to the server and receive the authentication result returned by the server, where the authentication result is obtained by the server authenticating the target user based on the benchmark authentication information of the target user stored in advance and the authentication information; A service trigger module, configured to trigger the execution of the target service when the authentication result is authentication passed.
11. A data processing device, comprising: A second receiving module, configured to receive the target authentication information of the target user sent by the client; A first processing module, configured to input the target authentication information of the target user into a pre-trained second privacy information desensitization model for desensitization processing to obtain first authentication information; A second sending module, configured to send the first authentication information to the client and receive the benchmark authentication information of the target user returned by the client, where the benchmark authentication information is the authentication information obtained by the client desensitizing the target authentication information based on a pre-trained first privacy information desensitization model; A request receiving module, configured to receive the authentication request of the target user for the target service sent by the client, where the authentication request includes the authentication information of the target user; An authentication module, configured to authenticate the target user based on the benchmark authentication information of the target user stored in advance and the authentication information to obtain an authentication result; A first sending module, configured to send the authentication result to the client, so that the client triggers the execution of the target service when the authentication result is authentication passed.
12. A data processing device, the data processing device comprising: A processor; And A memory arranged to store computer-executable instructions, where the executable instructions, when executed, cause the processor to: Obtain the target authentication information of the target user; Send the target authentication information to the server and receive the first authentication information returned by the server, where the first authentication information is the authentication information obtained by the server desensitizing the target authentication information based on a pre-trained second privacy information desensitization model; Desensitize the first authentication information based on a pre-trained first privacy information desensitization model to obtain the benchmark authentication information of the target user; Send the benchmark authentication information of the target user to the server; When receiving the authentication request of the target user for the target service, obtain the authentication information of the target user; Send the authentication information of the target user to the server and receive the authentication result returned by the server, where the authentication result is obtained by the server authenticating the target user based on the benchmark authentication information of the target user stored in advance and the authentication information; When the authentication result is authentication passed, trigger the execution of the target service.
13. A data processing device, the data processing device comprising: A processor; And A memory arranged to store computer-executable instructions, the executable instructions, when executed, causing the processor to: Receive target authentication information of a target user sent by a client; Input the target authentication information of the target user into a pre-trained second privacy information desensitization model for desensitization processing to obtain first authentication information; Send the first authentication information to the client and receive the reference authentication information of the target user returned by the client, the reference authentication information being the authentication information obtained by the client based on a pre-trained first privacy information desensitization model for desensitization processing of the target authentication information; Receive an authentication request of the target user for a target service sent by the client, the authentication request including the authentication information of the target user; Authenticate the target user based on the pre-stored reference authentication information and the authentication information of the target user to obtain an authentication result; Send the authentication result to the client so that the client triggers the execution of the target service when the authentication result is authentication passed.
14. A storage medium, the storage medium being used to store computer-executable instructions, the executable instructions, when executed, implementing the following process: Obtain target authentication information of a target user; Send the target authentication information to a server and receive first authentication information returned by the server, the first authentication information being the authentication information obtained by the server based on a pre-trained second privacy information desensitization model for desensitization processing of the target authentication information; Perform desensitization processing on the first authentication information based on a pre-trained first privacy information desensitization model to obtain the reference authentication information of the target user; Send the reference authentication information of the target user to the server; When receiving an authentication request of the target user for a target service, obtain the authentication information of the target user; Send the authentication information of the target user to the server and receive an authentication result returned by the server, the authentication result being obtained by the server based on the pre-stored reference authentication information and the authentication information of the target user to authenticate the target user; When the authentication result is authentication passed, trigger the execution of the target service.
15. A storage medium, the storage medium being used to store computer-executable instructions, the executable instructions, when executed, implementing the following process: Receive target authentication information of a target user sent by a client; Input the target authentication information of the target user into a pre-trained second privacy information desensitization model for desensitization processing to obtain first authentication information; Send the first authentication information to the client and receive the reference authentication information of the target user returned by the client, where the reference authentication information is the authentication information obtained by the client through desensitizing the target authentication information based on a pre-trained first privacy information desensitization model; Receive an authentication request of the target user for a target service sent by the client, where the authentication request includes the authentication information of the target user; Authenticate the target user based on the pre-stored reference authentication information and the authentication information of the target user to obtain an authentication result; Send the authentication result to the client so that the client triggers the execution of the target service when the authentication result is authentication passed.
Citation Information
Patent Citations
Verification method, device and equipment based on verification information and private data
CN111917799A
Privacy protection-based privacy data processing method, device and equipment
CN113221747A
Data processing method, device and equipment
CN114238910A