A privacy-protected multi-party data processing method, device, and apparatus
By generating ciphertext conditions and data shards, using oblivious pseudo-random functions or hash operations, splitting and transmitting data shards, and adopting multi-party secure computing protocols, the problem of privacy information leakage in multi-device joint data statistics is solved, and secure joint statistical results are achieved.
Patent Information
- Application Number
- CN202210871917.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-22
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2042-07-22
AI Technical Summary
In scenarios where multiple devices work together, how can we reduce the risk of privacy information leakage when performing data statistics? Especially when the table data stored on different devices is not exactly the same, how can we securely perform joint data statistics?
By generating ciphertext conditions and data fragments, using random pseudo-random functions or hash operations, splitting and transmitting data fragments, and using multi-party secure computing protocols for statistics, data security between devices is ensured.
Without directly obtaining the table data of other devices, the accuracy and privacy protection of data statistical results are achieved, the risk of data leakage is reduced, and joint statistics that meet data statistical conditions are achieved.
Smart Images

Figure CN115292729B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing technology, and in particular to a privacy-protected multi-party data processing method, apparatus, and device. Background Art
[0002] In scenarios where multiple devices work together, different devices can store different tabular data. Since the tabular data stored in each device is not exactly the same, when jointly performing data statistics on the tabular data stored in multiple devices, it is necessary to combine the tabular data stored in each device to complete the data statistics together.
[0003] However, the table data stored in each device involves a large amount of private information. In order to reduce the leakage of private information, it is necessary to provide a solution suitable for joint data processing by multiple devices. Summary of the Invention
[0004] The purpose of the embodiments of the present invention is to provide a privacy-preserving multi-party data processing method, apparatus, and device to reduce the risk of privacy leakage during data processing. The specific technical solution is as follows:
[0005] An embodiment of the present invention provides a privacy-preserving multi-party data processing method, which is applied to a first device. The method includes:
[0006] Obtaining information about each second field value of an identification field in the second table data stored on the second device, where the identification field is a field that exists in both the second table data and the first table data stored on the first device;
[0007] Determine, based on the obtained information about the second field value, a first data row in which the first field value of the identification field in the first table data is the same as the second field value in the second table data;
[0008] Splitting the third field value of the condition field in the data statistical condition in the first data row to obtain a first data fragment and a second data fragment;
[0009] Generate ciphertext conditions for data statistics conditions;
[0010] Sending the ciphertext condition, the second data fragment, and the condition field in the second table data to the second device, so that the second device splits the fourth field value of the condition field in the second table data to obtain a third data fragment and a fourth data fragment;
[0011] receiving the third data fragment and the second statistical result fed back by the second device, where the second statistical result is a statistical result of whether the second data fragment and the fourth data fragment meet the ciphertext condition by the second device;
[0012] Counting whether the first data fragment and the third data fragment meet the ciphertext condition to obtain a first statistical result;
[0013] Determining, based on the first statistical result and the second statistical result, a third data row in the second table data that meets the data statistical condition;
[0014] Information on the field value of the result field within the data statistical condition in the third data row is obtained from the second device to obtain a joint statistical result for the data statistical condition.
[0015] An embodiment of the present invention further provides a privacy-preserving multi-party data processing method, which is applied to a second device. The method includes:
[0016] Sending information of each second field value of the identification field in the second table data stored by the second device to the first device;
[0017] receiving a ciphertext condition of a data statistical condition, a second data fragment, and a condition field of the data statistical condition present in the second table data sent by the first device, where the second data fragment is a data fragment obtained by splitting the third field value of the condition field within the data statistical condition in the first data row, the first data row is a data row where a first field value of an identification field in the first table data is the same as a second field value in the second data row, and the identification field is a field present in both the second table data and the first table data stored by the first device;
[0018] Splitting the fourth field value of the conditional field in the second table data to obtain a third data fragment and a fourth data fragment;
[0019] Counting whether the second data fragment and the fourth data fragment meet the ciphertext condition to obtain a second statistical result;
[0020] Sending the third data slice and the second statistical result to the first device, so that the first device counts whether the first data slice and the third data slice meet the ciphertext condition, obtains a first statistical result, and determines, based on the first statistical result and the second statistical result, a third data row in the second table data that meets the data statistical condition;
[0021] Obtaining a result field of the statistical condition from the first device;
[0022] The field value information of the result field is sent to the first device, so that the first device obtains a joint statistical result for the data statistical condition according to the field value information of the result field within the data statistical condition in the third data row.
[0023] An embodiment of the present invention further provides a privacy-protected multi-party data processing apparatus, applied to a first device, comprising:
[0024] an information obtaining module, configured to obtain information about each second field value of an identification field in the second table data stored on the second device, where the identification field is a field that exists in both the second table data and the first table data stored on the first device;
[0025] A first data row determining module is configured to determine, based on the obtained second field value information, a first data row in which a first field value of an identification field in the first table data is identical to a second field value in the second table data;
[0026] A first splitting module is used to split the third field value of the condition field in the data statistical condition in the first data row to obtain a first data fragment and a second data fragment;
[0027] A ciphertext condition generation module, used to generate ciphertext conditions for data statistical conditions;
[0028] A first sending module, configured to send the ciphertext condition, the second data fragment, and the condition field present in the second table data to the second device, so that the second device splits the fourth field value of the condition field in the second table data to obtain a third data fragment and a fourth data fragment;
[0029] A first receiving module is configured to receive the third data fragment and a second statistical result fed back by the second device, where the second statistical result is a statistical result obtained by the second device regarding whether the second data fragment and the fourth data fragment meet the ciphertext condition;
[0030] A first statistical module is used to count whether the first data fragment and the third data fragment meet the ciphertext condition and obtain a first statistical result;
[0031] a data row determination module, configured to determine a third data row in the second table data that meets the data statistical condition based on the first statistical result and the second statistical result;
[0032] The joint statistics module is used to obtain information about the field value of the result field within the data statistics condition in the third data row from the second device, and obtain a joint statistics result for the data statistics condition.
[0033] An embodiment of the present invention further provides a privacy-protected multi-party data processing apparatus, which is applied to a second device. The apparatus includes:
[0034] an information sending module, configured to send, to the first device, information of each second field value of the identification field in the second table data stored by the second device;
[0035] a second receiving module, configured to receive a ciphertext condition of a data statistical condition, a second data fragment, and a condition field of the data statistical condition present in the second table data, sent by the first device, wherein the second data fragment is a data fragment obtained by splitting a third field value of the condition field within the data statistical condition in the first data row, and the first data row is a data row in which a first field value of an identification field in the first table data is identical to a second field value in the second data row, and the identification field is a field present in both the second table data and the first table data stored by the first device;
[0036] A second splitting module is used to split the fourth field value of the condition field in the second table data to obtain a third data fragment and a fourth data fragment;
[0037] A second statistical module is used to count whether the second data fragment and the fourth data fragment meet the ciphertext condition and obtain a second statistical result;
[0038] a second sending module, configured to send the third data slice and the second statistical result to the first device, so that the first device counts whether the first data slice and the third data slice meet the ciphertext condition, obtains a first statistical result, and determines, based on the first statistical result and the second statistical result, a third data row in the second table data that meets the data statistical condition;
[0039] A result field obtaining module, configured to obtain a result field of a statistical condition from the first device;
[0040] The third sending module is used to send the field value information of the result field to the first device, so that the first device obtains the joint statistical result for the data statistical condition according to the field value information of the result field within the data statistical condition in the third data row.
[0041] An embodiment of the present invention further provides an electronic device, comprising a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus;
[0042] Memory for storing computer programs;
[0043] The processor is configured to implement any of the steps of the above-mentioned multi-party data processing method for privacy protection when executing a program stored in the memory.
[0044] An embodiment of the present invention further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the computer program implements any of the steps of the above-mentioned privacy-protected multi-party data processing method.
[0045] An embodiment of the present invention further provides a computer program product comprising instructions, which, when executed on a computer, enables the computer to execute any of the steps of the above-mentioned privacy-preserving multi-party data processing method.
[0046] Beneficial effects of the embodiments of the present invention:
[0047] In the solution provided by an embodiment of the present invention, the first device performing statistics obtains a joint statistical result by using the statistical results of the third data shard and the first, second, and fourth data shards without directly obtaining the table data on the second device. When performing statistics, the first device obtains the data shards of the second device. The data shards contain partial recovery information after splitting rather than complete recovery information, and cannot be used to directly obtain the field values of the table data on the second device. In other words, the first device does not obtain the actual table data on the second device. This reduces the first device's acquisition of data from other devices during the statistical process, thereby reducing the risk of privacy leakage during the data statistics process.
[0048] In the above process, each data shard is obtained by splitting the field values of the first table data and the second table data respectively. Using each data shard for statistics is equivalent to performing statistics on the plaintext first table data and the second table data according to the data statistical conditions. While reducing the risk of data privacy leakage, statistics are performed based on the table data on the two devices, and the statistical results meet the data statistical conditions, thereby realizing conditional joint statistics of multiple devices.
[0049] Of course, it is not necessary to achieve all of the advantages described above simultaneously in order to implement any product or method of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other embodiments can also be obtained based on these drawings.
[0051] Figure 1 A flowchart of a first privacy-preserving multi-party data processing method provided by an embodiment of the present invention.
[0052] Figure 2 A flowchart of a second privacy-preserving multi-party data processing method provided by an embodiment of the present invention.
[0053] Figure 3 This is a signaling flow chart of the first privacy-protected multi-party data processing method provided by an embodiment of the present invention.
[0054] Figure 4 A schematic structural diagram of a first privacy-protected multi-party data processing device provided by an embodiment of the present invention.
[0055] Figure 5 A schematic structural diagram of a second privacy-protected multi-party data processing device provided by an embodiment of the present invention.
[0056] Figure 6 A schematic structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0057] The following will be combined with the accompanying drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field based on this application are within the scope of protection of the present invention.
[0058] The following describes the execution subject of the embodiment of the present invention.
[0059] The first device is a device that needs to process data and obtain the results of that processing, such as a device that needs to obtain statistical results when collecting data. Correspondingly, the second device is a device that participates in the data processing process, providing data to support the data processing and not needing to obtain the processing results.
[0060] In the embodiment of the present invention, there may be multiple second devices, and each second device may perform data processing with the first device according to the steps of the subsequent embodiments.
[0061] The first device and the second device may be various types of electronic devices, such as desktop computers, servers, etc.
[0062] In order to reduce the leakage of private information generated when multiple devices jointly process data, embodiments of the present invention provide a privacy-protected multi-party data processing method, apparatus, device, and storage medium.
[0063] In one embodiment of the present invention, see Figure 1 , provides a flow chart of a first privacy-preserving multi-party data processing method, which is applied to a first device and includes the following steps S101-S109.
[0064] Step S101: obtaining information on each second field value of an identification field in second table data stored in a second device, where the identification field is a field existing in both the second table data and the first table data stored in the first device.
[0065] The identification field is a field shared by the second table data and the first table data, and is used to indicate the object to which the table data belongs. For example, the object can be a user, that is, different field values under the identification field can uniquely correspond to different users, indicating the users to which the data rows containing the field values belong.
[0066] For example, in the examples shown in Table 1 and Table 2 below, the id (identity document) field is an identification field.
[0067] Table 1
[0068] id gender age 1 0 34 2 1 40 3 1 32 4 0 53 5 0 42
[0069] Table 2
[0070] id Consumption amount Consumption frequency VIP information 1 400 4 0 4 200 5 1 5 100 5 1 7 800 7 0 8 1000 19 0
[0071] Among them, Table 1 is the first table data, and Table 2 is the second table data.
[0072] The fields of the first table data include ID, gender, and age; the field value of each row under the gender field is 0 or 1, 0 indicates female, and 1 indicates male; the fields of the second table include ID, consumption amount, number of consumptions, and VIP information. The field value of each row under the VIP information field is 0 or 1, 0 indicates not VIP, and 1 indicates VIP.
[0073] The information of each second field value is information generated according to each field value under the identification field, for example, information generated according to each field value <1, 4, 5, 7, 8> under the id field in Table 2.
[0074] The information of the second field value may be identification information generated based on the second field value, and the identification information does not include the original second field value. In one embodiment of the present invention, the information of the second field value may be pseudo-random information generated based on each second field value. The specific method for generating pseudo-random information can be referred to in the subsequent implementation of OPRF-PSI and will not be described in detail here. In this way, if an attacker exists, the pseudo-random information of the second field value sent by the second device to the first device cannot be directly determined by intercepting the pseudo-random information, thereby protecting the privacy and security of the second device.
[0075] In another embodiment of the present invention, the information of the second field may also be a hash value obtained by performing a hash operation on each second field value.
[0076] Directly sending field values from the second device to the first device can result in the first device gaining access to data stored on the second device. For example, a user of the first device can infer the user to whom the data stored on the second device belongs based on the field value under the second device's identification field. By sending the second field value information as an alternative, the first device cannot directly obtain the field value in the second device, thereby protecting the privacy of the second device.
[0077] Step S102: Determine, based on the obtained information about the second field value, a first data row in which the first field value of the identification field in the first table data is the same as the second field value in the second table data.
[0078] By comparing the information of each first field value and the second field value under the identification field, the first field value that is the same as the second field value can be determined, and the data row where the determined first field value is located is the first data row.
[0079] In one embodiment of the present invention, the first data row may be determined as follows:
[0080] Obtain a first field value of an identification field in the first table data; determine a first field value that intersects with the second field value based on the information of the obtained second field value; and determine a data row in the first table data where the determined first field value is located as a first data row.
[0081] In one embodiment of the present invention, information of a first field value can be generated, and the information of the first field value is of the same type as the information of the second field value. In this case, the identical parts of the information of the first field value and the information of the second field value correspond to the intersection of the first field value and the second field value. The data rows in the first table and the second table corresponding to each field value in the intersection belong to the same object, for example, they belong to the same user. In this case, when performing conditional statistics subsequently, only the data rows corresponding to the identification fields in the intersection need to be used, and there is no need to process the first table data and the second table data corresponding to each identification field value outside the intersection, thereby reducing the computing resources required for data statistics.
[0082] In the above process, the step of determining the first field value that intersects with the second field value can be implemented in a variety of ways, which are described below with examples.
[0083] In one implementation, the intersection can be determined based on the OPRF-PSI (Oblivious Pseudo Random Function-Private Set Intersection) protocol. In this case, the second field value information is the pseudo-random parameter output by the oblivious pseudo-random function using the second field value as an input parameter; the first field information is the pseudo-random parameter output by the same oblivious pseudo-random function using the first field value as an input parameter.
[0084] In this case, by comparing the pseudo-random parameters generated by each second field value and each first field value, an intersection of the pseudo-random parameters can be obtained. The first field value corresponding to the pseudo-random parameter in the intersection is the first field value that has an intersection with the second field value.
[0085] In another implementation, the second field value information is a hash value of each second field value. A hash operation is performed on each first field value using the same hash algorithm used to obtain the hash value of the second field value. The resulting hash values of the first field values are compared with the hash values of the second field values in pairs. The first field values corresponding to the first field values that have the same hash value are the first field values that have an intersection with the second field value.
[0086] Step S103: Split the third field value of the condition field in the data statistical condition in the first data row to obtain a first data fragment and a second data fragment.
[0087] The data statistics condition is: the condition for achieving the data statistics requirement of the first device. For example, corresponding to the examples described in Table 1 and Table 2 above, the data statistics condition is: counting the total amount of consumption of female people who are VIP customers.
[0088] The condition field is the field containing the field value to be filtered in the statistical condition; the result field is the field containing the field value required to obtain the statistical result. For example, if the statistical condition is to count the total spending amount of female VIP customers, the filtering condition is: the field value in the "Gender" field is 0 and the field value in the "VIP Information" field is 1; the result field is the "Spending Amount" field.
[0089] The third field value is split to obtain recovery information of the third field value, and the obtained recovery information is randomly divided into two groups. The obtained two groups of information are the first data fragment and the second data fragment.
[0090] In one embodiment of the present invention, the first data fragment and the second data fragment respectively include: part of the input parameters of the secret recovery function with the third field value as the output parameter.
[0091] In this case, the recovery information can be the split values of each third field value obtained by splitting the third field value. The numerical relationship between any split value and the third field value is undefined, and the split third field value can be restored using a preset number or more of the split values. In this case, the secret recovery function is a function used to implement the restoration process, and the split values are input parameters of the secret recovery function.
[0092] The method of using the secret recovery function to achieve restoration corresponds to the method of splitting to obtain each data fragment. For example, the split value can be the solution of an n-order linear equation system constructed with the third field value as a parameter. According to the characteristics of the equation system, n split values can solve the above equation system to obtain the third field value. The secret recovery function is formed based on the calculation process of solving the above equation system; conversely, if there are only n-1 split values, it is impossible to solve the above equation system and restore the third field value, that is, the above preset number is n. In this case, the numerical relationship between a single split value as a solution to the equation system and the parameters of the equation system is uncertain, that is, the third field value cannot be determined based on a single split value.
[0093] The first data shard may include less than a preset number of split values. Continuing with the above example, when forming the first data shard, each first data shard may be limited to contain a maximum of n-1 split values, and each first data shard cannot be used to restore the third field value.
[0094] The second data shard is similar to the first data shard, and the only difference is the replacement of the name concept between the second data shard and the first data shard, which will not be described in detail here.
[0095] In this case, when the first device sends the data slice to the second device, the data slice does not contain the original arbitrary table data, thereby ensuring the privacy security of the first device during the data transmission process.
[0096] In the embodiment of the present invention, splitting based on the n-order linear equation is only an example. Similarly, splitting can also be performed by other methods such as using a random string to perform an XOR operation on the third field value, and the embodiment of the present invention is not limited to this.
[0097] Step S104: Generate ciphertext conditions for data statistical conditions.
[0098] The ciphertext condition is a statistical condition for the split values in a data shard. This statistical condition uses the same statistical method as the data statistical condition. For example, if the data statistical condition is to calculate the cumulative sum under field value A, the corresponding ciphertext condition is an addition condition. The statistical method is to perform an addition operation on the split values, and the result is the statistical result for the data shard.
[0099] Under the same statistical method, the ciphertext conditions may include: sub-relations formed by randomly splitting the original numerical relations in the data statistical conditions; for example, after the data statistical condition of judging a>10 is split, several ciphertext conditions of a>X can be formed, where X is a random number split from 10.
[0100] In this way, compared with the data statistical conditions, the ciphertext conditions are random, and when the second device obtains the ciphertext conditions, it cannot directly infer the data statistical conditions accurately based on the ciphertext conditions.
[0101] The specific ciphertext conditions are generated based on the MPC (Secure Multi-Party Computation) protocol. Using these ciphertext conditions for statistics conceals the plaintext information of the statistical conditions, making the statistical process more secure. This allows the statistical device to hide the statistical conditions based on the ciphertext conditions when using these ciphertext conditions for each data shard, thus achieving conditional hiding of the statistical conditions. If the statistical conditions contain sensitive information from the first device, this sensitive information cannot be accessed by the second device, thus ensuring the information security of the first device.
[0102] Step S105: Send the ciphertext condition, the second data fragment, and the condition field in the second table data to the second device.
[0103] After receiving the above information sent by the first device, the second device may split the fourth field value of the condition field in the second table data to obtain a third data fragment and a fourth data fragment.
[0104] Among them, the information contained in the condition field itself is only the field name, and does not contain specific data on the second device, so the risk of privacy leakage is relatively small.
[0105] Before executing the solution provided by the embodiment of the present invention, the first device may pre-acquire the field name of the condition field of the second device, and thereby determine the condition field existing in the second table data from the data statistical conditions.
[0106] In one embodiment of the present invention, the third data fragment and the fourth data fragment respectively include: part of the input parameters of the secret recovery function with the fourth field value as the output parameter.
[0107] The specific splitting to obtain the third data shard and the fourth data shard is similar to the first data shard and the second data shard in the aforementioned step S103. The only difference is the replacement of the name concepts such as the third data shard and the first data shard, the second data shard and the fourth data shard, and the different field values involved in the splitting: all field values under the second device splitting condition field, and the field value of the first data row under the first device splitting condition field.
[0108] In this way, when the second device sends the data slice to the first device, the data slice does not contain any table data, thereby ensuring the privacy and security of the second device during the data transmission process.
[0109] Step S106: Receive the third data fragment and the second statistical result fed back by the second device.
[0110] The second statistical result is: a statistical result of whether the second data fragment and the fourth data fragment meet the ciphertext condition by the second device.
[0111] The screening method specified in the ciphertext condition may be an expression corresponding to the judgment logic representing the data statistical condition, and the expression may be generated based on a generation method specified by the MPC protocol.
[0112] Among them, the above expression can take the split values belonging to the same identification field in the first data fragment and the third data fragment as input parameters to obtain output parameters, and the output parameters can be parameter values indicating whether the second data fragment and the fourth data fragment meet the ciphertext conditions.
[0113] In the aforementioned step S102, the intersection of the first field value and the second field value is determined. Based on the positional relationship corresponding to the first data row and the second data row in the intersection, the third field value and the fourth field value belonging to the same identification field in the first data shard and the third data shard can be determined. The split values obtained by splitting the determined field value also belong to the identification field. By only using the positional relationship of the obtained intersection, compared to allowing the first device to directly obtain the data row of the field value under the identification field of the second device in the intersection, the field value information contained in the intersection, such as the ID information in the examples shown in Tables 1 and 2, is hidden, including the field value information in the second device. This reduces the first device's acquisition of information from the second device, thereby reducing the risk of privacy leakage of the second device.
[0114] Step S107: Count whether the first data fragment and the third data fragment meet the ciphertext condition to obtain a first statistical result.
[0115] The method for obtaining the first statistical result is the same as the method for obtaining the second statistical result in step S106. The only difference is the replacement of the name concepts of the first data shard and the second data shard, the third data shard and the fourth data shard, and the execution entity for obtaining the first statistical result is the first device, which will not be described in detail here.
[0116] Step S108: Determine a third data row in the second table data that meets the data statistics condition according to the first statistical result and the second statistical result.
[0117] Since the secret recovery function can use split values as input parameters, correspondingly, values of the same type as the split values can also be used as input parameters. For example, split values 1 and 2 can be used as input parameters for secret recovery function A. The sum, average, and other statistical results of split values 1 and 2, which are of the same type as the split values, can also be used as input parameters.
[0118] As described above, the first and second statistical results have the same numerical type as the split value. The first and second statistical results are used as input parameters of the secret recovery function, and the resulting output parameter represents the plaintext statistical result. In this process, the intersection of the first and second field values obtained in the aforementioned steps is only used to provide a positional relationship. Furthermore, the statistics are actually performed using ciphertext conditions rather than data statistical conditions. This prevents the disclosure of either intersection information or data statistical conditions, thereby improving the security of the joint statistics.
[0119] Step S109: obtaining information on the field value of the result field within the data statistical condition in the third data row from the second device, and obtaining a joint statistical result for the data statistical condition.
[0120] In the above process, the first device obtains information on all field values under the result field from the second device. In this case, the second device will not know the specific field values that the first device needs to use to obtain the joint statistical results, and accordingly will not know how the data statistical conditions filter the field values. In this way, only the first device that actually performs the statistics holds the data statistical conditions and knows the method of filtering the data statistical conditions, thereby protecting the privacy information of the first device.
[0121] In one embodiment of the present invention, the joint statistical results can be obtained in the following manner:
[0122] Generate position information representing the position of the third data row in the second table data; obtain information about the fifth field value of the result field in the second table data from the second device; perform joint statistics based on the generated position information and the fifth field value information to obtain a joint statistical result for the data statistical condition.
[0123] The position information can be represented by a vector, where the order of the numerical values contained in the vector corresponds to the order of the data rows in the second table data. The position of the third data row can be represented by 1 in the vector, and the positions of all other data rows except the third data row can be represented by 0. For example, in the examples shown in Tables 1 and 2, the third data row in Table 2 is the data row with IDs 4 and 5, and the corresponding position information can be: <0,1,1,0,0>.
[0124] Similarly, the fifth field value information can also be a vector representing all field values under the result field, with the order of the values in the vector also corresponding to the order of the data rows in the second table data. For example, in Table 2 above, the fifth field value information can be represented as a consumption amount vector <400, 200, 100, 800, 1000>.
[0125] The location information and the fifth field value correspond to the same data row. In this case, the fifth field value corresponding to the position represented by the value 1 in the vector can be determined, resulting in a joint statistical result that meets the data statistical conditions. In the examples of Tables 1 and 2, the resulting joint statistical result is 300, which is the total amount of consumption by users with IDs 4 and 5. These two users are female and VIPs, meeting the data statistical conditions. In this way, the location information can be used to obtain the fifth field value in the second table data that meets the statistical conditions, thereby obtaining the data statistical results.
[0126] The location information and the fifth field value information can be split into data segments in the manner shown in step S103 above, and the MPC protocol can be used to generate an expression for the ciphertext condition for calculating the joint statistical result for statistics, similar to steps S103-108 above, which will not be described in detail here. In this way, the accuracy and privacy of the statistical process can be guaranteed based on the MPC protocol.
[0127] In the solution provided by an embodiment of the present invention, the first device performing statistics obtains a joint statistical result by using the statistical results of the third data shard and the first, second, and fourth data shards without directly obtaining the table data on the second device. When performing statistics, the first device obtains the data shards of the second device. The data shards contain partial recovery information after splitting rather than complete recovery information, and cannot be used to directly obtain the field values of the table data on the second device. In other words, the first device does not obtain the actual table data on the second device. This reduces the first device's acquisition of data from other devices during the statistical process, thereby reducing the risk of privacy leakage during the data statistics process.
[0128] In the above process, each data shard is obtained by splitting the field values of the first table data and the second table data respectively. Using each data shard for statistics is equivalent to performing statistics on the plaintext first table data and the second table data according to the data statistical conditions. While reducing the risk of data privacy leakage, statistics are performed based on the table data on the two devices, and the statistical results meet the data statistical conditions, thereby realizing conditional joint statistics of multiple devices.
[0129] In one embodiment of the present invention, see Figure 2, provides a flow chart of a second privacy-protected multi-party data processing method, which is applied to a second device. The method includes the following steps S201-S207.
[0130] Step S201: Sending information of each second field value of an identification field in second table data stored in a second device to a first device.
[0131] Step S202: receiving the ciphertext condition of the data statistical condition, the second data fragment, and the condition field of the data statistical condition existing in the second table data sent by the first device.
[0132] The second data shard is: a data shard obtained by splitting the third field value of the condition field in the data statistical condition in the first data row, the first data row is: a data row in which the first field value of the identification field in the first table data is the same as the second field value in the second data row, and the identification field is a field that exists in both the second table data and the first table data stored in the first device.
[0133] Step S203: Split the fourth field value of the conditional field in the second table data to obtain a third data fragment and a fourth data fragment.
[0134] Step S204: Count whether the second data fragment and the fourth data fragment meet the ciphertext condition to obtain a second statistical result.
[0135] Step S205: Send the third data fragment and the second statistical result to the first device.
[0136] This step enables the first device to count whether the first data fragment and the third data fragment meet the ciphertext condition, obtain a first statistical result, and determine the third data row in the second table data that meets the data statistical condition based on the first statistical result and the second statistical result.
[0137] Step S206: Obtain the result field of the statistical condition from the first device.
[0138] Step S207: Send information about the field value of the result field to the first device.
[0139] This step enables the first device to obtain a joint statistical result for the data statistical condition based on the field value information of the result field within the data statistical condition in the third data row.
[0140] The concepts of each name in steps S201-S207 are the same as those in the aforementioned steps S101-S109 and will not be described in detail here.
[0141] As can be seen from the above, when the second device participates in the data statistics process, it sends the third data shard and the second statistical result to the first device, which does not include the specific data when the data rows are filtered according to the data statistical conditions. Combined with the aforementioned embodiment of the first device, it can be seen that the data contained in the third data shard and the second statistical result are all split values of the field value or the statistical results of the split value, and do not include the original field value information. Therefore, the first device minimizes the acquisition of data from the second device during the data statistics process, and includes the privacy information of the second device.
[0142] In one embodiment of the present invention, sending information about a field value of a result field to a first device so that the first device obtains a joint statistical result for the data statistical condition based on the field value information of the result field within the data statistical condition in a third data row includes:
[0143] Generate information about the fifth field value of the result field in the second table data; send the information about the fifth field value to the first device, so that the first device performs joint statistics based on the location characteristics and the information about the fifth field value to obtain joint statistical results for the data statistical conditions.
[0144] The method of generating the fifth field value information and performing joint statistics is as described in the above step S109 and will not be described in detail here.
[0145] In this case, the first device can obtain the fifth field value that meets the statistical conditions in the second table data through the location information to obtain the data statistical results.
[0146] Below through Figure 3 The illustrated embodiment illustrates the overall process of privacy-preserving multi-party data processing.
[0147] In one embodiment of the present invention, see Figure 3 , provides a signaling flow chart of a privacy-preserving multi-party data processing method. For ease of explanation, this embodiment continues to use Tables 1 and 2 for data processing.
[0148] The id column extracted in step S301 is the first field value under the identification field. Because the first device maintains the data statistical conditions, it can use these conditions to pre-select field values that meet the conditions during extraction, reducing the computational complexity of finding intersections in subsequent steps. For example, if the data statistical conditions are to count the total amount of spending by female VIP customers, the first device can pre-select the first field value with sex = 0 from Table 1, i.e., id = 1, 4, and 5.
[0149] The id column extracted in step S302 is the second field value under the identification field of the second table data.
[0150] In step S303 , the PSI protocol is run. The first device may set an implementation method for determining the intersection of the first field value and the second field value according to the PSI protocol. Step S304 is similar to step S303 .
[0151] In step S305, the second device as the sender sends ID information, that is, information of the second field value, to the first device as the receiver;
[0152] The intersection vector of step S306 is obtained based on the intersection of the first field value and the second field value, indicating the position of the data row of the second field value in the intersection in the second table data. See Table 2. The intersection is id=1,4,5, which are the first three rows in the second table data, corresponding to the position where 1 appears in the vector <1,1,1,0,0>.
[0153] Step S307: Synchronize information to the second device. The synchronized information includes the ciphertext condition, the condition field in the second table data, and the result field.
[0154] Step S308 splits the data slices to obtain the first and second data slices. Step S309 splits the data slices to obtain the third and fourth data slices, and exchanges the data slices according to the MPC protocol to obtain the first statistical result and the second statistical result, see the above steps S104-S107.
[0155] The screening result obtained in step S310 is the third data row determined based on the first statistical result and the second statistical result, that is, the data row with id=4 and 5 in Table 2, and the corresponding position information is: <0,1,1,0,0>
[0156] The consumption amount vector <400, 200, 100, 800, 1000> generated in step S311.
[0157] Based on the MPC protocol, the location information and consumption amount vector are calculated, and the joint statistical result, that is, the consumption amount of users who meet the data statistical conditions, can be obtained according to step S312, and the total consumption amount is calculated as 300 according to step S313.
[0158] Reference Figure 3If there are multiple devices, and the data table on each device has some condition fields in the data statistical conditions, then the first device and each second device can communicate according to the above process. The only difference from the existence of one second device is that when S307 synchronizes information to the second device, the synchronized condition fields are different, which are the condition fields actually possessed by the data table in each second device, and when splitting the data fragments, if there are n first and second devices in total, and n>2, each device can split n data fragments, and send n-1 of the data fragments to the other n-1 devices respectively, so that each device obtains the fragment statistical results based on its own unsent data fragments and received data fragments, and then the first device collects all the fragment statistical results to obtain the joint statistical results. Its specific implementation method is the same as the above-mentioned embodiment and will not be described in detail here.
[0159] Corresponding to the above-mentioned privacy protection multi-party data processing method, in one embodiment of the present invention, see Figure 4 , provides a structural diagram of a first privacy-preserving multi-party data processing device, the device comprising:
[0160] An information obtaining module 401 is configured to obtain information about each second field value of an identification field in second table data stored on the second device, where the identification field is a field present in both the second table data and the first table data stored on the first device.
[0161] A first data row determining module 402 is configured to determine, based on the obtained second field value information, a first data row in which a first field value of an identification field in the first table data is identical to a second field value in the second table data;
[0162] A first splitting module 403 is configured to split the third field value of the condition field in the data statistical condition in the first data row to obtain a first data fragment and a second data fragment;
[0163] A ciphertext condition generating module 404 is used to generate ciphertext conditions for data statistical conditions;
[0164] A first sending module 405 is configured to send the ciphertext condition, the second data fragment, and the condition field in the second table data to the second device, so that the second device splits the fourth field value of the condition field in the second table data to obtain a third data fragment and a fourth data fragment;
[0165] A first receiving module 406 is configured to receive the third data fragment and the second statistical result fed back by the second device, where the second statistical result is a statistical result obtained by the second device regarding whether the second data fragment and the fourth data fragment meet the ciphertext condition;
[0166] A first statistical module 407 is configured to count whether the first data fragment and the third data fragment meet the ciphertext condition, and obtain a first statistical result;
[0167] A data row determination module 408 is configured to determine a third data row in the second table data that meets the data statistics condition based on the first statistical result and the second statistical result;
[0168] The joint statistics module 409 is configured to obtain information on the field value of the result field within the data statistics condition in the third data row from the second device, and obtain a joint statistics result for the data statistics condition.
[0169] In the solution provided by an embodiment of the present invention, the first device performing statistics obtains a joint statistical result by using the statistical results of the third data shard and the first, second, and fourth data shards without directly obtaining the table data on the second device. When performing statistics, the first device obtains the data shards of the second device. The data shards contain partial recovery information after splitting rather than complete recovery information, and cannot be used to directly obtain the field values of the table data on the second device. In other words, the first device does not obtain the actual table data on the second device. This reduces the first device's acquisition of data from other devices during the statistical process, thereby reducing the risk of privacy leakage during the data statistics process.
[0170] In the above process, each data shard is obtained by splitting the field values of the first table data and the second table data respectively. Using each data shard for statistics is equivalent to performing statistics on the plaintext first table data and the second table data according to the data statistical conditions. While reducing the risk of data privacy leakage, statistics are performed based on the table data on the two devices, and the statistical results meet the data statistical conditions, thereby realizing conditional joint statistics of multiple devices.
[0171] In one embodiment of the present invention, the joint statistics module 409 is specifically used to generate position information representing the position of the third data row in the second table data; obtain information about the fifth field value of the result field in the second table data from the second device; and perform joint statistics based on the generated position information and the fifth field value information to obtain joint statistical results for the data statistical conditions.
[0172] In this way, the fifth field value that meets the statistical conditions in the second table data can be obtained through the position information to obtain the data statistical results.
[0173] In one embodiment of the present invention, the first data row determination module 402 is specifically used to obtain a first field value of an identification field in the first table data; determine a first field value that intersects with the second field value based on the information of the obtained second field value; and determine the data row where the determined first field value is located in the first table data as the first data row.
[0174] In this case, when performing conditional statistics subsequently, only the data rows corresponding to the identification fields in the intersection need to be used, without the need to process the first table data and the second table data corresponding to the identification field values outside the intersection, thereby reducing the computing resources required for data statistics.
[0175] In one embodiment of the present invention, the information of each second field value is: pseudo-random information generated according to each second field value;
[0176] or,
[0177] The first data slice and the second data slice respectively include: part of the input parameters of the secret recovery function with the second field value as the output parameter;
[0178] or,
[0179] The third data fragment and the fourth data fragment respectively include: part of the input parameters of the secret recovery function with the fourth field value as the output parameter.
[0180] In this way, if an attacker exists, the second device cannot directly determine the second field value by intercepting the pseudo-random information of the second field value sent to the first device, thereby protecting the privacy security of the first device.
[0181] When the first device sends the data slice to the second device, the data slice does not contain the original arbitrary table data, thereby ensuring the privacy security of the first device during the data transmission process.
[0182] When the second device sends the data slice to the first device, the data slice does not contain the original arbitrary table data, thereby ensuring the privacy security of the second device during the data transmission process.
[0183] See also Figure 5 , provides a structural diagram of a second privacy-preserving multi-party data processing apparatus, which is applied to a second device, and includes:
[0184] An information sending module 501 is configured to send information of each second field value of an identification field in second table data stored by a second device to a first device;
[0185] A second receiving module 502 is configured to receive, from the first device, a ciphertext condition of the data statistical condition, a second data fragment, and a condition field of the data statistical condition present in the second table data, wherein the second data fragment is a data fragment obtained by splitting the third field value of the condition field within the data statistical condition in the first data row, and the first data row is a data row in which a first field value of an identification field in the first table data is identical to a second field value in the second data row, and the identification field is a field present in both the second table data and the first table data stored by the first device;
[0186] A second splitting module 503 is configured to split the fourth field value of the condition field in the second table data to obtain a third data fragment and a fourth data fragment;
[0187] A second statistical module 504 is configured to count whether the second data fragment and the fourth data fragment meet the ciphertext condition, and obtain a second statistical result;
[0188] The second sending module 505 is configured to send the third data slice and the second statistical result to the first device, so that the first device counts whether the first data slice and the third data slice meet the ciphertext condition, obtains a first statistical result, and determines, based on the first statistical result and the second statistical result, a third data row in the second table data that meets the data statistical condition;
[0189] A result field obtaining module 506 is configured to obtain a result field of the statistical condition from the first device;
[0190] The third sending module 507 is used to send the field value information of the result field to the first device, so that the first device obtains the joint statistical result for the data statistical condition according to the field value information of the result field within the data statistical condition in the third data row.
[0191] As can be seen from the above, when the second device participates in the data statistics process, it sends the third data shard and the second statistical result to the first device, which does not include the specific data when the data rows are filtered according to the data statistical conditions. Combined with the aforementioned embodiment of the first device, it can be seen that the data contained in the third data shard and the second statistical result are all split values of the field value or the statistical results of the split value, and do not include the original field value information. Therefore, the first device minimizes the acquisition of data from the second device during the data statistics process, and includes the privacy information of the second device.
[0192] In one embodiment of the present invention, the third sending module 507 is specifically used to: generate information about the fifth field value of the result field in the second table data; and send information about the fifth field value to the first device so that the first device performs joint statistics based on location features and the information about the fifth field value to obtain joint statistical results for data statistical conditions.
[0193] In this case, the first device can obtain the fifth field value that meets the statistical conditions in the second table data through the location information to obtain the data statistical results.
[0194] The embodiment of the present invention further provides an electronic device, such as Figure 6 As shown, it includes a processor 601, a communication interface 602, a memory 603 and a communication bus 604, wherein the processor 601, the communication interface 602, and the memory 603 communicate with each other through the communication bus 604.
[0195] Memory 603, used for storing computer programs;
[0196] The processor 601 is configured to implement the steps of the multi-party data processing method for privacy protection applied to the first device or the multi-party data processing method for privacy protection applied to the second device in the aforementioned embodiment when executing the program stored in the memory 603 .
[0197] The communication bus mentioned in the electronic device mentioned above may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, only one thick line is used in the figure, but this does not mean that there is only one bus or only one type of bus.
[0198] The communication interface is used for communication between the above electronic device and other devices.
[0199] The memory may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage. Alternatively, the memory may be at least one storage device located away from the processor.
[0200] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, and discrete hardware components.
[0201] In another embodiment provided by the present invention, a computer-readable storage medium is also provided, which stores a computer program. When the computer program is executed by a processor, it implements the multi-party data processing method for privacy protection applied to the first device or the steps of the multi-party data processing method for privacy protection applied to the second device in the aforementioned embodiment.
[0202] In another embodiment provided by the present invention, a computer program product containing instructions is also provided. When the computer is run on a computer, the computer executes the steps of the multi-party data processing method for privacy protection applied to the first device or the multi-party data processing method for privacy protection applied to the second device in the aforementioned embodiment.
[0203] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present invention are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive (SSD)).
[0204] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.
[0205] Each embodiment in this specification is described in a related manner. Similar portions between the various embodiments can be referenced to each other. Each embodiment focuses on the differences from other embodiments. In particular, the device, equipment, and storage medium embodiments are generally similar to the method embodiments, so their descriptions are relatively simple. For related portions, reference can be made to the descriptions of the method embodiments.
[0206] The above description is only a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention are included in the scope of protection of the present invention.
Claims
1. A privacy-preserving multi-party data processing method, characterized in that: Applied to a first device, the method includes: Obtaining information about each second field value of an identification field in the second table data stored on the second device, where the identification field is a field that exists in both the second table data and the first table data stored on the first device; Determine, based on the obtained information about the second field value, a first data row in which the first field value of the identification field in the first table data is the same as the second field value in the second table data; Splitting the third field value of the condition field in the data statistical condition in the first data row to obtain a first data fragment and a second data fragment; Generate ciphertext conditions for data statistics conditions; Sending the ciphertext condition, the second data fragment, and the condition field in the second table data to the second device, so that the second device splits the fourth field value of the condition field in the second table data to obtain a third data fragment and a fourth data fragment; receiving the third data fragment and the second statistical result fed back by the second device, where the second statistical result is a statistical result of whether the second data fragment and the fourth data fragment meet the ciphertext condition by the second device; Counting whether the first data fragment and the third data fragment meet the ciphertext condition to obtain a first statistical result; Determining, based on the first statistical result and the second statistical result, a third data row in the second table data that meets the data statistical condition; generating position information representing a position of the third data row in the second table data; obtaining information of a fifth field value of a result field in the second table data from the second device; Joint statistics are performed based on the generated position information and the information of the fifth field value to obtain a joint statistical result for the data statistical conditions.
2. The method according to claim 1, characterized in that The determining, based on the obtained information about the second field value, of a first data row having the same first field value of the identification field in the first table data as the second field value in the second table data includes: Obtaining a first field value of an identified field in the first table data; Determine, based on the obtained information about the second field value, a first field value that intersects with the second field value; The data row where the determined first field value is located in the first table data is determined as the first data row.
3. The method according to any one of claims 1 to 2, characterized in that The information of each second field value is: pseudo-random information generated according to each second field value; or, The first data slice and the second data slice respectively include: part of the input parameters of the secret recovery function with the third field value as the output parameter; or, The third data fragment and the fourth data fragment respectively include: part of the input parameters of the secret recovery function with the fourth field value as the output parameter.
4. A privacy-preserving multi-party data processing method, characterized in that: Applied to the second device, the method includes: Sending information of each second field value of the identification field in the second table data stored by the second device to the first device; receiving a ciphertext condition of a data statistical condition, a second data fragment, and a condition field of the data statistical condition present in the second table data sent by the first device, where the second data fragment is a data fragment obtained by splitting the third field value of the condition field within the data statistical condition in the first data row, the first data row is a data row where a first field value of an identification field in the first table data is the same as a second field value in the second data row, and the identification field is a field present in both the second table data and the first table data stored by the first device; Splitting the fourth field value of the conditional field in the second table data to obtain a third data fragment and a fourth data fragment; Counting whether the second data fragment and the fourth data fragment meet the ciphertext condition to obtain a second statistical result; Sending the third data slice and the second statistical result to the first device, so that the first device counts whether the first data slice and the third data slice meet the ciphertext condition, obtains a first statistical result, and determines, based on the first statistical result and the second statistical result, a third data row in the second table data that meets the data statistical condition; Obtaining a result field of the statistical condition from the first device; Generate information of a fifth field value of a result field in the second table data; The information of the fifth field value is sent to the first device, so that the first device performs joint statistics based on the location feature and the information of the fifth field value to obtain a joint statistical result for the data statistical condition.
5. A privacy-preserving multi-party data processing device, characterized in that: Applied to a first device, the apparatus includes: an information obtaining module, configured to obtain information about each second field value of an identification field in the second table data stored on the second device, where the identification field is a field that exists in both the second table data and the first table data stored on the first device; A first data row determining module is configured to determine, based on the obtained second field value information, a first data row in which a first field value of an identification field in the first table data is identical to a second field value in the second table data; A first splitting module is used to split the third field value of the condition field in the data statistical condition in the first data row to obtain a first data fragment and a second data fragment; A ciphertext condition generation module, used to generate ciphertext conditions for data statistical conditions; A first sending module, configured to send the ciphertext condition, the second data fragment, and the condition field present in the second table data to the second device, so that the second device splits the fourth field value of the condition field in the second table data to obtain a third data fragment and a fourth data fragment; A first receiving module is configured to receive the third data fragment and a second statistical result fed back by the second device, where the second statistical result is a statistical result obtained by the second device regarding whether the second data fragment and the fourth data fragment meet the ciphertext condition; A first statistical module is used to count whether the first data fragment and the third data fragment meet the ciphertext condition and obtain a first statistical result; a data row determination module, configured to determine a third data row in the second table data that meets the data statistical condition based on the first statistical result and the second statistical result; The joint statistics module is specifically used to generate position information representing the position of the third data row in the second table data; obtain information about the fifth field value of the result field in the second table data from the second device; perform joint statistics based on the generated position information and the fifth field value information to obtain joint statistical results for the data statistical conditions.
6. A privacy-preserving multi-party data processing device, characterized in that: Applied to the second device, the apparatus includes: an information sending module, configured to send, to the first device, information of each second field value of the identification field in the second table data stored by the second device; a second receiving module, configured to receive a ciphertext condition of a data statistical condition, a second data fragment, and a condition field of the data statistical condition present in the second table data, sent by the first device, wherein the second data fragment is a data fragment obtained by splitting a third field value of the condition field within the data statistical condition in the first data row, and the first data row is a data row in which a first field value of an identification field in the first table data is identical to a second field value in the second data row, and the identification field is a field present in both the second table data and the first table data stored by the first device; A second splitting module is used to split the fourth field value of the condition field in the second table data to obtain a third data fragment and a fourth data fragment; A second statistical module is used to count whether the second data fragment and the fourth data fragment meet the ciphertext condition and obtain a second statistical result; a second sending module, configured to send the third data slice and the second statistical result to the first device, so that the first device counts whether the first data slice and the third data slice meet the ciphertext condition, obtains a first statistical result, and determines, based on the first statistical result and the second statistical result, a third data row in the second table data that meets the data statistical condition; A result field obtaining module, configured to obtain a result field of a statistical condition from the first device; The third sending module is specifically used to generate information about the fifth field value of the result field in the second table data; and send the information about the fifth field value to the first device so that the first device performs joint statistics based on the location characteristics and the information about the fifth field value to obtain joint statistical results for the data statistical conditions.
7. An electronic device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus; Memory for storing computer programs; A processor, configured to implement the method steps described in any one of claims 1 to 3 or 4 when executing a program stored in a memory.
8. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method steps of any one of claims 1 to 3 or 4 are implemented.
Citation Information
Patent Citations
Database operation method and system for private data and storage medium
CN112000979A
Multi-party joint security statistics method and device
CN112084530A