Privacy Protection Method, Terminal and Storage Medium for DBSCAN Algorithm
The method leverages DH protocol and secret sharing to securely perform DBSCAN clustering by minimizing computations and communications, addressing privacy and efficiency issues in existing DBSCAN algorithms.
Patent Information
- Application Number
- CN202310080172.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-30
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2043-01-30
AI Technical Summary
The existing DBSCAN algorithms have problems such as large computing volume, high client computing and communication costs in cloud computing environments, and the risk of data privacy leakage is high.
The DH protocol is used to establish the key between the client and the server, and the data points are divided into two parts through addition secret sharing, and then encrypted and sent to different servers. The multiplication secret sharing and inadvertent transmission technology are used to obtain the size relationship between the distance between the two points and the neighborhood range threshold, so as to realize the secure calculation of the DBSCAN algorithm.
It reduces the computing and communication costs of clients, reduces the computing burden of cloud servers, and protects data privacy through encryption technology to prevent eavesdropping.
Smart Images

Figure CN116094708B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information technology, and in particular to a privacy protection method, a terminal and a storage medium for the DBSCAN algorithm. Background Art
[0002] With the rapid development of cloud services, people's ways of processing and computing massive data have undergone tremendous changes. When the computing power of a local computer is limited and the amount of computing required to solve a problem is extremely large, the data can be uploaded to a cloud server, and with the help of the powerful computing power of the cloud server, our work can be completed. The content involved in today's cloud servers covers all aspects of life, such as personal physical conditions, family member information, company member composition, etc. These contents may be related to personal privacy or business secrets. If directly uploaded to the server, there will be a risk of leakage of privacy or business secrets. For the application scenarios of machine learning, because its data volume and computing volume are often relatively large, it is often outsourced to the server for operation. Common unsupervised machine learning algorithms include the K-means algorithm, the DBSCAN algorithm, etc. For the K-means algorithm, there already exist some efficient and secure computing methods. Compared with the K-means algorithm, the DBSCAN algorithm can find clustering clusters of arbitrary shapes in the presence of noise points, and has a significant effect on removing malicious data.
[0003] The prior art uses the BGV homomorphic encryption algorithm to keep the user data involved in the DBSCAN algorithm confidential. After the user encrypts the data and then uploads it to the cloud server, since the BGV algorithm satisfies the property of full homomorphism, the cloud server performs a series of calculations on the ciphertext and then sends the calculation result to the user, and the correct algorithm result can be obtained after the user decrypts it.
[0004] Due to the complexity of the full homomorphic encryption algorithm, during the operation of the algorithm, not only does it greatly increase the computing amount of the server, but there are also many operations that increase the computing cost and network cost of the client. For example, before data encryption, the data first needs to be encoded; matrix operations need to be performed for each data encryption; the amount of ciphertext after encryption may be several times that of the original data, and these ciphertexts need to be sent to the cloud server through the network. To solve this technical problem, a privacy protection method, a terminal and a storage medium for the DBSCAN algorithm are proposed. Summary of the Invention
[0005] In order to solve the technical problems existing in the above prior art, the present invention provides a privacy protection method, a terminal and a storage medium for the DBSCAN algorithm.
[0006] To achieve the above object, the embodiments of the present invention provide the following technical solutions:
[0007] First aspect, in an embodiment provided by the present invention, a privacy protection method for the DBSCAN algorithm is provided. The method includes the following steps:
[0008] Establish keys between the client and servers A and B respectively through the DH protocol;
[0009] Among them, let the key between the l-th client and server A be And the key between the client and server B be
[0010] The client uses additive secret sharing to divide the data points into two parts, encrypts them respectively using the corresponding keys, and sends them to the corresponding servers A and B;
[0011] Servers A and B decrypt the secret sharing values of the received data points respectively to obtain the distance between any two points and the magnitude of M;
[0012] Server A obtains the point set within the ε-neighborhood of each point based on the magnitude relationship between the distance between two points and ε; Server A obtains the clustering result through the DBSCAN algorithm.
[0013] As a further solution of the present invention, taking the data points And As an example. Suppose the secret sharing values of the data points And Obtained by server A are The secret sharing values of the data points And Obtained by server B are The obtaining of the distance between any two points and the magnitude of M includes the following steps:
[0014] S301. Server A calculates Server B calculates
[0015] S302. Through multiplicative secret sharing, servers A and B respectively obtain the data And And Satisfy
[0016] S303. Server A calculates and obtains the data Server B calculates and obtains the data
[0017] S304. Server B sends sign(V B ) to server A, and server A makes a preliminary judgment The magnitude relationship with ε;
[0018] S305. Use the method OT_Compare(|V A |,|V B |) to compare the magnitudes of |V A | and |V B |, and then obtain The magnitude relationship with ε.
[0019] As a further aspect of the present invention, the server B sends sign(V B ) to the server A, and the server A preliminarily determines The magnitude relationship with ε, which includes the following cases:
[0020] I. If both V A and V B are greater than or equal to 0, then it can be obtained that
[0021] II. If both V A and V B are less than or equal to 0, then it can be obtained that
[0022] III. If V A is greater than or equal to 0 and V B is less than 0, or V A is less than or equal to 0 and V B is greater than 0, then use the method OT_Compare(|V A |,|V B |) to compare the magnitudes of |V A | and |V B |, and then obtain The magnitude relationship with ε.
[0023] As a further aspect of the present invention, use the method OT_Compare(|V A |,|V B |) to compare the magnitudes of |V A | and |V B |, and then obtain The magnitude relationship with ε, which includes the following cases:
[0024] I. If sign(V A )·sign(|V A |-|V B |) ≥ 0, then it can be obtained that
[0025] II. If sign(V A )·sign(|VA |-|V B |)≤0 can be obtained
[0026] As a further solution of the present invention, the server A obtains the clustering result through the DBSCAN algorithm, which includes:
[0027] Input: sample set Neighborhood parameters (ε, M).
[0028] Output: class partition C = {C1, C2,..., C k}.
[0029] As a further solution of the present invention, the server A obtains the clustering result through the DBSCAN algorithm, including the following steps:
[0030] S401. Find all core points;
[0031] If the number of points within the ε-neighborhood of a certain point (for example ) is greater than M (i.e., ), this point is a core point; let the set of all core points be Ω;
[0032] S402. Mark all core points as unvisited;
[0033] S403. Take out a core point (after taking it out ), mark this point as visited, set the current class serial number k, create a queue for the current core point Create a set of points for the current class
[0034] S404. Take out an element from the core point queue Ω k and obtain all unvisited points within the ε-neighborhood of (after taking it out ), mark all these points within the ε-neighborhood of as visited, update the set of points for the current class to unvisited core point set Add the core point set of these points within the ε-neighborhood of to the core point queue (after adding ); ;
[0035] S405. Repeat step S404 until after executing step S404, the core point queue Ω k is empty; the set of points for the current class C k constitutes a class, and remove the core points marked as visited from Ω;
[0036] S406. Repeat steps S403 - S405 until the elements in Ω are empty, and obtain the category partition C = {C1, C2, …, C k}.
[0037] As a further solution of the present invention, servers A and B do not collude with each other.
[0038] As a further solution of the present invention, client data wherein, is an n - dimensional vector, and the value range of i is from 1 to m; both m and n are positive integers.
[0039] In a second aspect, in another embodiment provided by the present invention, a terminal is provided, including a memory and a processor. When the memory stores a computer program and the processor loads and executes the computer program, the steps of the privacy - protection method of the DBSCAN algorithm are implemented.
[0040] In a third aspect, in another embodiment provided by the present invention, a storage medium is provided, storing a computer program. When the computer program is loaded and executed by a processor, the steps of the privacy - protection method of the DBSCAN algorithm are implemented.
[0041] The technical solution provided by the present invention has the following beneficial effects:
[0042] For the privacy - protection method, terminal, and storage medium of the DBSCAN algorithm provided by the present invention, the present invention does not require too many matrix operations on the client side, and also greatly reduces the number of parameters uploaded to the cloud service, saving the computing and communication costs of the client. And the algorithm does not require the cloud server to perform extremely complex operations on the ciphertext, effectively reducing the computing cost of the cloud server. The data provider can be multiple clients. By using the additive secret - sharing technology, after splitting the data, each part after splitting is encrypted and sent to different servers respectively, which can prevent eavesdropping by others. Then, the multiplicative secret - sharing technology and the oblivious transfer technology are used between the two servers to obtain the size relationship between the distance between two points and the neighborhood range threshold, so as to be able to obtain the core points, density - reachable relationships, density - connected relationships, etc. in the DBCSCAN algorithm, and further realize the secure calculation of the DBSCAN algorithm. Compared with the existing results, the present invention saves the computing and communication costs of the client and reduces the computing cost of the cloud server.
[0043] These aspects or other aspects of the present invention will be more clearly understood in the following description of the embodiments. It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other embodiments can be obtained based on these drawings.
[0045] Figure 1 It is a flowchart of a privacy protection method for the DBSCAN algorithm according to an embodiment of the present invention;
[0046] Figure 2 It is a structural diagram of a terminal according to an embodiment of the present invention.
[0047] In the figure: processor - 501, communication interface - 502, memory - 503, communication bus - 504. Detailed implementation manners
[0048] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.
[0049] The flowchart shown in the accompanying drawings is only an example, and does not necessarily include all the contents and operations / steps, nor does it necessarily need to be executed in the described order. For example, some operations / steps can also be decomposed, combined, or partially merged. Therefore, the actual execution order may change according to the actual situation.
[0050] It should be understood that the terms used in the description of the present invention herein are only for the purpose of describing specific embodiments and are not intended to limit the present invention. As used in the description of the present invention and the appended claims, unless the context clearly indicates otherwise, the singular forms "a", "an", and "the" are intended to include the plural forms.
[0051] Specifically, the embodiments of the present invention will be further elaborated below with reference to the accompanying drawings.
[0052] Please refer to Figure 1 , Figure 1 which is a flowchart of a privacy protection method for the DBSCAN algorithm provided by an embodiment of the present invention. As Figure 1As shown in the figure, the privacy protection method of the DBSCAN algorithm includes steps S10 to S40. The privacy protection method of the DBSCAN algorithm is applied to a system, and the system includes at least one client and servers A and B.
[0053] S10. Establish keys between the client and servers A and B respectively through the DH protocol.
[0054] Among them, let the key between the l-th client and server A be and the key between the l-th client and server B be
[0055] S20. The client uses additive secret sharing to divide the data points into two parts, encrypts them respectively using the corresponding keys, and sends them to the corresponding servers A and B.
[0056] In an embodiment of the present invention, for example, the data point T represents matrix transpose, and it is divided into using additive secret sharing, and then is encrypted respectively using the corresponding keys and sent to servers A and B.
[0057] S30. Servers A and B decrypt the secret sharing values of the received data points respectively, and obtain the distance between any two points and the size of M using the following steps.
[0058] Taking the data points and as an example for illustration.
[0059] Suppose the secret sharing values of and obtained by server A are and the secret sharing values of and obtained by server B are The specific steps are as follows:
[0060] S301. Server A calculates Server B calculates
[0061] S302. Through multiplicative secret sharing, servers A and B respectively obtain the data which satisfy
[0062] S303. Server A calculates and obtains the data Server B calculates and obtains the data
[0063] It can be seen that V A+V B The result is As long as it can be determined whether V A +V B is related to 0, it can be judged the magnitude relationship with ε.
[0064] S304. Server B sends sign(V B ) to Server A, and Server A makes a preliminary judgment the magnitude relationship with ε. There are the following cases:
[0065] I. V A and V B are both greater than or equal to 0, and it can be obtained that
[0066] II. V A and V B are both less than or equal to 0, and it can be obtained that
[0067] III. V A is greater than or equal to 0 and V B is less than 0, V A is less than or equal to 0 and V B is greater than 0, then go to step S305.
[0068] S305. Between Server A and Server B, use the method OT_Compare(|V A |,|V B |) to compare the magnitudes of |V A | and |V B |, and then obtain the magnitude relationship with ε. There are the following cases
[0069] I. If sign(V A )·sign(|V A |-|V B |)≥0, it can be obtained that
[0070] II. If sign(V A )·sign(|V A |-|V B |)≤0, it can be obtained that
[0071] S40. Server A obtains the set of points within the ε-neighborhood of each point based on the magnitude relationship between the distance between two points and ε; Server A obtains the clustering result through the DBSCAN algorithm.
[0072] First, the present invention divides data into two parts through the additive secret sharing technique, encrypts them, and sends them to the corresponding cloud servers. After the cloud servers decrypt the data, the secret sharing value of the square of the distance between two points can be obtained by using additive and multiplicative secret sharing. Then, the oblivious transfer is used to obtain the magnitude relationship between the square of the distance between two points and the square of the distance threshold, and further obtain the magnitude relationship between the distance between two points and the distance threshold. Next, one of the servers can use the magnitude relationship of the distances to obtain the core points, boundary points, and noise points in the DBSCAN algorithm, and obtain the density direct reachability, density reachability, and density connectivity relationships of the data points through them, thereby realizing the secure calculation of the DBSCAN algorithm.
[0073] The DBSCAN algorithm describes the compactness of a sample set based on the number of samples in the neighborhood. First, we describe the parameters related to the DBSCAN algorithm.
[0074] Suppose the data point set is There are the following related definitions
[0075] ε-neighborhood. For Its ε-neighborhood refers to the set of samples in the data point set D whose distance from is not greater than ε, that is The number of this set is denoted as
[0076] Core point. For any data point If its ε-neighborhood contains at least M samples, that is Then is a core point.
[0077] Density direct reachability. If is located in the ε-neighborhood of and is a core point, then it is said that is density directly reachable from Conversely, it is not necessarily the case, unless is also a core point. So density direct reachability is not symmetric.
[0078] Density reachability. For and If there exists a sample sequence satisfying And is density directly reachable from Then it is said that is density reachable from It is easy to see that density reachability has transitivity. Like density direct reachability, density reachability is also not symmetric.
[0079] Density-connected. For and If there exists a core object such that and are both density-reachable, then and are density-connected. It can be obtained that density-connected has symmetry.
[0080] Among them, servers A and B do not collude with each other.
[0081] Client data where T represents matrix transpose; that is, all data points are n-dimensional vectors. Neighborhood parameters (ε, M).
[0082] In the embodiment of the present invention, server A obtains a clustering result through the DBSCAN algorithm, which includes:
[0083] Input: Sample set Neighborhood parameters (ε, M).
[0084] Output: Class partition C = {C1, C2,..., C k} where the value of k is not known before the program runs.
[0085] In the embodiment of the present invention, server A obtains a clustering result through the DBSCAN algorithm, including the following steps:
[0086] S401. Find all core points. If the number of points within the ε-neighborhood of a certain point (e.g., ) is greater than M (i.e., ), this point is a core point. Let the set of all core points be Ω.
[0087] S402. Mark all core points as unvisited.
[0088] S403. Take out a core point (after taking it out ), mark this point as visited, set the current class serial number k, create a queue for the current core point Create a set of points for the current class
[0089] S404. Take out an element k from the core point queue Ω (after taking it out ), obtain all unvisited point sets within the ε-neighborhood of unvisited core point set Put These points within the ε-neighborhood are all marked as visited, and the current category point set is updated to the core point set among these points is added to the core point queue (after adding ).
[0090] S405. Repeat step S404 until, after executing step S404, the core point queue Ω k is empty. At this time, the current category point set C k constitutes one class, and the marked visited core points are removed from Ω.
[0091] S406. Repeat steps S403 - S405 until the elements in Ω are empty, and the category partition is obtained as C = {C1, C2, …, C k}.
[0092] The key to the secrecy of the DBSCAN algorithm lies in the secrecy of user data information. It can be seen that in the above algorithm, as long as we can secretly judge the distance between points and the size of ε, we can achieve the secure calculation of the DBSCAN algorithm. Regarding the measurement method of the distance between data points, in the present invention, we adopt the Euclidean distance.
[0093] Among them, secret sharing is an important technology in multi-party secure computing. Since it is relatively simple to use, it is widely used in the field of privacy protection. In the present invention, only two-party additive secret sharing is used, and a brief introduction to it is given below.
[0094] In additive secret sharing, the data x is randomly split into the sum of two data (x0, x1), that is, x = x0 + x1, and then x0 and x1 are respectively stored in the participating parties P0 and P1. The data x must be combined with the data of the participating parties P0 and P1 to be restored.
[0095] Suppose without loss of generality that the participating party P0 has the data x and the other participating party P1 has the data y. According to the following process, additive secret sharing can be achieved.
[0096] 1. P0 generates a random number x0, and calculates x1 = x - x0, and then sends x1 to P1.
[0097] 2. P1 generates a random number y0, and calculates y1 = y - y0, and then sends y0 to P0.
[0098] 3. P0 calculates z0 = x0 + y0, and P1 calculates z1 = x1 + y1.
[0099] At this time, to calculate the sum of x and y, we only need to aggregate z0 and z1 to the requester, and the resulting value is z0 + z1. It can be seen that during this process, the data x and y are not leaked, and data privacy is well protected.
[0100] In addition, if the data information is eavesdropped during the data transmission process, there is still a risk of data privacy leakage. We can encrypt the data before the sender sends the data. For the sake of simplicity in calculation, we can use traditional symmetric encryption algorithms. Regarding the transmission of the encryption key, we adopt the Diffie–Hellman (hereinafter referred to as DH) key exchange method. Next, we will briefly introduce the DH key exchange protocol.
[0101] Alice and Bob want to share a key for symmetric encryption. However, the communication channel between them is not secure. All information passing through this channel will be seen by the adversary: Eve. How can they exchange information so that Eve does not know this key?
[0102] The security of the DH algorithm depends on the difficulty of calculating discrete logarithms. The concept of primitive roots is needed in the following scheme, and we first give its definition.
[0103] Definition 1: If the smallest positive power m such that a m = 1 mod n holds satisfies m = Φ n , then a is called a primitive root of n. Where Φ n is the Euler's totient function.
[0104] Therefore, for any integer b and a primitive root a of a prime number p, there is a unique power i such that b = a i mod p, 0 ≤ i ≤ p - 1. The discrete logarithm problem is that given a, b, and p, it is very difficult to calculate i.
[0105] The following is the scheme of the DH protocol:
[0106] 1. Alice and Bob first reach an agreement on p and g, where p is a large prime number and g is a primitive root of p, and p and g are made public. Eve also knows their values.
[0107] 2. Alice takes a private integer a, without letting anyone know, and sends it to Bob to calculate the result: A = g a mod p. Eve also sees the value of A.
[0108] 3. Similarly, Bob takes a private integer b and sends it to Alice to calculate the result B = g b mod p. Similarly, Eve will also see what B is being transmitted.
[0109] 4. Alice calculates S = Ba mod p = (g b ) a mod p = g ab mod p.
[0110] 5. Bob can also calculate S = A b mod p = (g a ) b mod p = g ab mod p.
[0111] Alice and Bob now have a shared secret key S. Although Eve sees p, g, A, B, due to the difficulty of computing the discrete logarithm, she cannot know the specific values of a and b. So Eve has no way of knowing what the secret key S is.
[0112] 1-out-of-N OT can be implemented as follows:
[0113] 1. Preparation phase. The protocol operates in a group of order a large prime q (that is, the operation results of this protocol are all in the sense of modulo q), and a primitive root g of the group is selected. A random oracle function H (such as SHA-1) is selected. The parameters q, g, H are shared by Alice and Bob.
[0114] 2. Initialization phase: Alice selects N - 1 random numbers C1, C2,..., C N-1 . Then a random number r is selected, and g r is calculated, and then C1, C2,..., C N-1 , g r are sent to Bob. Alice pre-computes (C1) r , (C2) r ,..., (C N-1 ) r . (Due to the difficulty of the discrete logarithm, Bob cannot obtain the discrete logarithms of C1, C2,..., C N-1 and the value of r).
[0115] 3. Online calculation phase:
[0116] a. Bob selects a random number k, sets
[0117]
[0118] and then sends PK0 to Alice. (Alice cannot obtain the value of k).
[0119] b. Alice calculates (PK0) r , and then calculates (PKi ) r =(C i / PK0) r , 1 ≤ i ≤ N - 1. Then select a random string R (the selection of R here should be long enough to ensure that the Hash values corresponding to two different data are different) and encrypt each M i , 0 ≤ i ≤ N - 1 as H((PK i ) r , R, i) ⊕ M i , and then send the encryption result and R to Bob.
[0120] c. Bob can calculate (PK σ ) r =(C σ / PK0) r =(g k ) r =(g r ) k , and then use H((PK σ ) r , R, σ) to decrypt and obtain M σ .
[0121] Then, two numbers can be safely compared using this protocol.
[0122] Suppose Alice has data x and Bob has data y. And x, y ∈ {0,..., N - 1}. We can compare the magnitudes of x and y using the following steps.
[0123] 1. Alice constructs N plaintext messages
[0124] 2. Bob obtains the value of m y through 1-out-of-N OT and can get the result
[0125]
[0126] Then Bob sends the magnitude result of the two to Alice.
[0127] If x and y are general real numbers, x can be represented in base-N form, such as x = x p-1 …x0.x -1 …x -q , that is the integer part has p digits and the decimal part has q digits. y can also be represented in base-N form as y = y p-1 …y0·y -1 …y -q . Then compare the magnitudes of the two starting from the highest bit,
[0128] 1. If x i = y i , -q ≤ i ≤ p, then x = y.
[0129] 2. If there exists k such that when i > k, x i = y i , and when i = k, x i > y i , then x > y.
[0130] 3. If there exists k such that when i > k, x i = y i , and when i = k, x i < y i , then x < y.
[0131] We use OT_Compare(x, y) to represent the above process of comparing the magnitudes of the two.
[0132] Secret sharing is an important technology in multi-party secure computing. Since it is relatively simple to use, it is widely used in the field of privacy protection.
[0133] In two-party additive secret sharing, the data x is randomly split into the sum of two data (x0, x1), that is, x = x0 + x1. Then x0 and x1 are respectively stored in the participating parties P0 and P1. The data x must be combined with the data of the participating parties P0 and P1 to be recovered.
[0134] Without loss of generality, let the participating party P0 have the data x, and the other participating party P1 have the data y. The additive secret sharing can be achieved according to the following process.
[0135] 1. P0 generates a random number x0 and calculates x1 = x - x0, then sends x1 to P1.
[0136] 2. P1 generates a random number y0 and calculates y1 = y - y0, then sends y0 to P0.
[0137] 3. P0 calculates z0 = x0 + y0, and P1 calculates z1 = x1 + y1.
[0138] At this time, to calculate the sum of x and y, only need to aggregate z0 and z1 to the requester, and the resulting value is z0 + z1. It can be seen that in this process, the data x and y are not leaked, which well protects the data privacy.
[0139] Two-party multiplicative secret sharing can be achieved using 1-out-of-N OT.
[0140] Let the participating party P0 have the data x, and the participating party P1 have the data y. Represent x in the N -ary form x = xp-1 …x0·x -1 …x -q , that is The integer part has p digits and the fractional part has q digits. y can also be expressed in the N - base form y = y p-1 …y0·y -1 …y -q . When i = -q, …, p - 1, the following methods are used for calculation respectively
[0141] 1. Bob generates (m i,0 , …, m i,N-1 ), where m i,0 is a random number, m i,j = N i jy - m i,0 .
[0142] 2. Alice uses 1 - out - of - N OT to obtain
[0143] 3. Alice calculates Bob calculates
[0144] It is easy to see that there is z A + z B = x·y. That is, to obtain the value of x·y, only the values of z A , z B need to be aggregated, and the values of x and y do not need to be leaked.
[0145] The present invention adopts the additive secret sharing technology. After the data is segmented, each segmented part is encrypted and sent to different servers respectively, which can prevent eavesdropping by others. Then, the multiplicative secret sharing technology and the oblivious transfer technology are used between two servers to obtain the size relationship between the distance between two points and the neighborhood range threshold, so as to obtain the core points, density - reachable relationships, density - connected relationships, etc. in the DBCSCAN algorithm, and further realize the secure calculation of the DBSCAN algorithm. Compared with the existing results, our method saves the computing and communication costs of the client and reduces the computing cost of the cloud server.
[0146] It should be understood that although the above is described in a certain order, these steps are not necessarily executed in the above order successively. Unless there is a clear description in this article, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, some steps of this embodiment may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same moment, but can be executed at different moments. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.
[0147] In one embodiment, referring to Figure 2 As shown, in the embodiment of the present invention, a terminal is further provided, including a processor 501, a communication interface 502, a memory 503, and a communication bus 504. Among them, the processor 501, the communication interface 502, and the memory 503 complete mutual communication through the communication bus 504.
[0148] The memory 503 is used to store a computer program;
[0149] The processor 501, when executing the computer program stored on the memory 503, executes the privacy protection method of the DBSCAN algorithm. When the processor executes the instructions, it implements the steps in the above method embodiment:
[0150] The communication bus mentioned in the above terminal may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, only a thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.
[0151] The communication interface is used for the communication between the above terminal and other devices.
[0152] The memory may include a Random Access Memory (RAM), and may also include a non-volatile memory, such as at least one disk memory. Optionally, the memory may also be at least one storage device located far from the aforementioned processor.
[0153] The above-mentioned processor may be a general-purpose processor, including a central processing unit (CPU for short), a network processor (NP for short), etc.; it may also be a digital signal processor (DSP for short), an application-specific integrated circuit (ASIC for short), a field-programmable gate array (FPGA for short), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0154] The terminal includes a user device and a network device. Among them, the user device includes, but is not limited to, a computer, a smart phone, a PDA, etc.; the network device includes, but is not limited to, a single network server, a server group composed of multiple network servers, or a cloud composed of a large number of computers or network servers based on cloud computing. Among them, cloud computing is a type of distributed computing and consists of a super virtual computer composed of a group of loosely coupled computer sets. Among them, the terminal can run independently to implement the present invention, or can be connected to the network and implement the present invention through interactive operations with other terminals in the network. Among them, the network where the terminal is located includes, but is not limited to, the Internet, a wide area network, a metropolitan area network, a local area network, a VPN network, etc.
[0155] It should also be understood that the term "and / or" used in the specification and appended claims of the present invention refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0156] In an embodiment of the present invention, a storage medium is further provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above method embodiment are implemented.
[0157] Those of ordinary skill in the art can understand that all or part of the processes in the above method embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it may include the processes of the above method embodiments. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided by the present invention may include at least one of non-volatile and volatile memories.
[0158] It should be understood that, as used herein, unless the context clearly supports the exception, the singular form "a" is intended to also include the plural form. It should also be understood that the "and / or" used herein refers to any and all possible combinations including one or more of the associated listed items. The serial numbers of the disclosed embodiments of the present invention above are only for description and do not represent the advantages or disadvantages of the embodiments.
[0159] Those of ordinary skill in the art should understand that the discussion of any of the above embodiments is only exemplary and is not intended to imply that the scope of the disclosure of the embodiments of the present invention (including the claims) is limited to these examples; under the concept of the embodiments of the present invention, the technical features in the above embodiments or different embodiments can also be combined, and there are many other variations in different aspects of the embodiments of the present invention as described above, which are not provided in detail for the sake of brevity. Therefore, any omission, modification, equivalent replacement, improvement, etc. made within the spirit and principle of the embodiments of the present invention shall be included in the protection scope of the embodiments of the present invention.
Claims
1. A privacy protection method for the DBSCAN algorithm, characterized in that, The method includes: Establish keys between the client and the server respectively through the Diffie-Hellman (DH) protocol A , B ; Among them, let the key between the l th client and the server A be , and the key between the server B be ; The client uses additive secret sharing to divide the data points into two parts, encrypts them with the corresponding keys respectively, and sends them to the corresponding servers. A , B ; Server A , B decrypt the secret sharing values of the received data points respectively to obtain the distance between any two points and M magnitude; Server A Based on the distance between two points and ε the magnitude relationship, obtain the point set within the neighborhood of each point; Server A Obtain the clustering result through the DBSCAN algorithm; Server A Obtain data points and The secret sharing value of is , the server B Obtain data points and The secret sharing value of is ; T is the matrix transpose, and obtaining the distance between any two points and M The size of includes the following steps: Server A Calculate , the server B Calculate ; Through multiplicative secret sharing, the server respectively obtains data , , and satisfies ; Server Calculated data , the server B Calculated data , where ε is the domain radius of the data point; Server B Send sign( V B ) to the server A , and let the server A make a preliminary judgment on the size of ε ; On the server A , B Adopt the method To compare With To obtain With ε The magnitude; Among them, ε is the domain radius of the data points, and M is the number of samples.
2. The privacy protection method of the DBSCAN algorithm according to claim 1, characterized in that, The server B sends sign( V B ) to the server A , and the server A makes a preliminary judgment on the size of ε , and the situations include the following: V A and V B are both greater than or equal to 0, then we get ; V A and V B are both less than or equal to 0, then we get ; V A greater than or equal to 0 and V B less than 0, V A less than or equal to 0 and V B greater than 0, then on the server A , B adopt method to compare with and obtain the comparison between ε and 3. The privacy protection method of the DBSCAN algorithm according to claim 1, characterized in that On the server A , B Use the method between Compare with to obtain the size of and ε The size of, which includes the following situations: If , then we get , If , then we get .
4. The privacy protection method of the DBSCAN algorithm according to claim 1, characterized in that, The server A obtains a clustering result through the DBSCAN algorithm, which includes: Input: sample set , neighborhood parameter ( ε , M ); Output: Class partition .
5. The privacy protection method of the DBSCAN algorithm according to claim 1, wherein The said server A Obtain the clustering result through the DBSCAN algorithm, including the following steps: S401. Find all the core points; If the number of points in the neighborhood of a certain point is greater than M , then this point is a core point; let the set of all core points be Ω ; S402. Mark the core points as unvisited; S403. Take out a core point from Ω and mark this point as visited, set the current category serial number , create a queue for the current core point k , and create a set of points for the current category ; S404, from the core point queue Ω k Take an element out , after taking out , get all of The set of points not visited in the neighborhood , the set of unvisited core points ;Will of These points in the neighborhood are marked as visited, and the current category point set is updated to , the core point set among these points Join the core point queue; S405. Repeat step S404 until the core point queue is empty after executing step S404; the current category point set Ω k forms a class, and the core points marked as visited are removed from C k it; Ω S406. Repeat steps S403 - S405 until Ω the elements in are empty, obtaining the category division as .
6. The privacy protection method of the DBSCAN algorithm according to claim 1, characterized in that The said server A , B do not collude with each other.
7. The privacy protection method of the DBSCAN algorithm according to claim 1, characterized in that Client data , where , is n a vector of dimension i whose value range is from 1 to m; both m and n are positive integers.
8. A terminal, comprising a memory and a processor, where the memory stores a computer program, and when the processor loads and executes the computer program, the steps of the privacy protection method of the DBSCAN algorithm according to any one of claims 1-7 are implemented.
9. A storage medium stores a computer program, and when the computer program is loaded and executed by a processor, the steps of the privacy protection method of the DBSCAN algorithm according to any one of claims 1-7 are implemented.
Citation Information
Patent Citations
Federal learning security aggregation method and apparatus, and electronic device
CN113919513A
Privacy protection outsourcing data KNN algorithm based on non-collusion double cloud servers
CN114154554A