A data transaction method, system, electronic device, and storage medium

By introducing a three-tiered verification mechanism involving both disturbance producers and data consumers in data transactions, the problem of data owners implementing deviation disturbances is solved, achieving a balance between data privacy and availability, and ensuring the fairness and efficiency of data transactions.

CN116150781BActive Publication Date: 2026-05-19XIDIAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
XIDIAN UNIV
Filing Date
2022-12-16
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Under the existing data owner-based incentive model, data owners (DOs) may implement deviation perturbation strategies that are more perturbative than honest perturbations in order to better protect their privacy, thereby impairing the data availability of data consumers (DCs) and failing to solve the problem of the unverifiability of data perturbations.

Method used

The perturbation generator produces a perturbation strategy based on the degree of perturbation and sends it to the data owner. The data owner then performs the perturbation according to the strategy. The perturbation generator and the data consumer cooperate to conduct three levels of verification to ensure the legality of the perturbation strategy, the authenticity of the content, and the accuracy of the results. Finally, the transaction settlement result is determined based on the verification results.

Benefits of technology

While protecting the privacy of data owners, it is essential to ensure the availability of data for data consumers and to incentivize data owners to honestly manipulate data, thereby achieving verifiability and fairness in data transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116150781B_ABST
    Figure CN116150781B_ABST
Patent Text Reader

Abstract

The application provides a data transaction method, system, electronic equipment and storage medium. The data transaction method generates a disturbance strategy based on a disturbance degree by a disturbance generator, and sends the disturbance strategy to each data owner; wherein the disturbance degree is determined by a data consumer and a data owner; the data owner disturbs data based on the received disturbance strategy to obtain disturbed data; the disturbance generator, the data owner and the data consumer verify the disturbed data, and feed back the verification result to the data consumer and the data owner; and the data consumer and the data owner determine a transaction clearing result based on the verification result. The method protects the privacy of the DO, encourages the DO to honestly disturb the data, and ensures the data privacy requirement of the DO and the data availability requirement of the DC at the same time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of transaction security, and in particular relates to a data transaction method, system, electronic device, and storage medium. Background Technology

[0002] To incentivize data owners (DOs) to trade their data while protecting their privacy, existing work allows DOs to sell perturbed data to data consumers (DCs) and receive a price to compensate for the privacy losses incurred from the data trade. Depending on who implements the data perturbation, these incentive programs can be categorized into two models: agent-based incentive models and data owner-based incentive models.

[0003] The agent-based incentive model allows data agents to perturb the privacy data of DOs (Distributors of Data). The data agent is assumed to be a fully trusted third-party server. This paper first proposes an agent-based privacy data trading architecture and achieves no arbitrage during the data trading process. In their work, DOs submit their raw privacy data to a data agent, which is responsible for perturbing the raw data. Subsequently, DCs (Distributors of Data) can obtain data with arbitrary perturbation levels from the data agent through a query, paying a corresponding data price to compensate for the privacy loss incurred by the DOs due to the data trading. Based on this privacy data trading model, a higher perturbation level better protects the privacy of DOs, thus better incentivizing DOs to trade their privacy data, but it also reduces data availability, thereby lowering the data price paid by the DC. Based on this fact, researchers found a trade-off in data trading: how to determine the perturbation level to balance the privacy needs of DOs and the data availability needs of DCs. To address this trade-off, contract theory is used, and an optimal contract is designed considering the diversity and confidentiality of DOs' privacy needs. They require data agents to reasonably design the perturbation level and the data price based on the perturbation level to maximize their own utility. While acknowledging the confidentiality of Data Provider (DO) privacy requirements, the work still assumes that data brokers are aware of the probability distribution (rather than specific numerical values) that DO privacy requirements follow, an assumption that is somewhat idealistic. To eliminate this assumption, the privacy data pricing problem is further modeled as a multi-armed gambling machine problem. In their work, data brokers need to decide whether to retain the data price that has brought them the greatest utility in the past (utilization) or try new data prices to optimize their personal utility in the future (exploration). Focusing on correlated data in data transactions, they argue that measuring the privacy loss of DOs in this case is more difficult and challenging than in cases where the data is not correlated. Therefore, they use dependency differential privacy to measure the privacy loss of DOs and thus price perturbed data. Meanwhile, subsequent work focuses on scenarios where time-series data is traded under temporal correlation. Pufferfish privacy is used to quantify the privacy loss of each DO at each timestamp's dependency state. Furthermore, focusing on correlated queries, dependency differential privacy is used to determine data prices, and the market price of the data is predicted based on the ellipsoid method, thus determining the charge to the data broker (DC).

[0004] However, all of the above proxy-based approaches assume that the data proxy is a completely trusted third-party server, meaning that the data proxy will not snoop on or leak the DO's private information. Since completely trusted third-party servers are difficult to find in practice, this assumption is unrealistic. Therefore, the data proxy-based model is difficult to apply practically to privacy data transactions.

[0005] Unlike the perturbation perpetrator in the data broker-based model, the data owner-based model allows DOs (Data Providers) to perturb their own private data. They were the first to point out that the assumption of a completely trustworthy data broker is unrealistic, as truly trustworthy third-party servers are difficult to find in reality. Therefore, directly exposing a DO's raw private data to a third-party server threatens the DO's privacy. To address this issue, they innovatively proposed a data owner-based model, in which the DO perturbs its private data locally and sells the perturbed data to a DC (Data Controller) at a certain price. To incentivize the DO to accept the perturbation level required by the DC, game theory is used to model the data transaction between the buyer and seller as a game, where the Nash equilibrium point represents the level of perturbation the DO agrees to the DC's demand. Based on this privacy data transaction model, a zero-sum game is used to model the transaction between the DO and the DC. They argue that the DO's privacy leakage is due to its disadvantageous position in the transaction. Therefore, by employing a zero-sum game, they ensure that the DO holds a dominant position in the game, allowing the DO to rationally adopt different strategies to reduce the risk of privacy leakage.

[0006] However, under a data owner-based model, DOs (Data Providers) may ignore the perturbation levels agreed upon with DCs (Data Centers) and implement deviating perturbation strategies to better protect their privacy. While existing work recognizes this problem, their solutions cannot be applied to data transactions. Specifically, some works attempt to discover true data using methods such as truth discovery and peer prediction, arguing that the closer the data provided by a DO is to the true data, the greater the likelihood of honest perturbation; conversely, they consider the DO to be perturbing the data deviating. However, due to the personalized and diverse nature of personal privacy data, there is no unique true data in privacy data transactions, rendering these solutions ineffective. Furthermore, in scenarios such as MCS (Multi-Channel System) and LBS (Location-Based Services), where the quality of service access depends on the quality of the data submitted, some works limit users' deviation perturbations through the idea of ​​reciprocity. However, in data transactions, DOs and DCs are different entities with conflicting interests, rendering the above solutions ineffective.

[0007] Under the existing incentive model based on data owner, DOs can implement deviation perturbation strategies with a perturbation level greater than honest perturbation in order to better protect their privacy, thereby impairing the data availability of DCs. The root cause of this problem is that existing work cannot solve the problem of the unverifiability of data perturbation.

[0008] Under the existing incentive model based on data owner, DOs can implement deviation perturbation strategies with a perturbation level greater than honest perturbation in order to better protect their privacy, thereby impairing the data availability of DCs. The root cause of this problem is that existing work cannot solve the problem of the unverifiability of data perturbation. Summary of the Invention

[0009] This invention provides a data transaction method, system, electronic device, and storage medium. The method protects the privacy of the Data Provider (DO) while incentivizing it to honestly perturb the data, thereby simultaneously ensuring both the DO's data privacy requirements and the data availability requirements of the Data Center (DC).

[0010] In a first aspect, this application provides a data transaction method, comprising: a disturbance generator generating a disturbance strategy based on the disturbance level, and sending the disturbance strategy to each data owner; wherein the disturbance level is determined by the data consumer and the data owner; the data owner perturbing the data based on the received disturbance strategy to obtain the perturbed data; the disturbance generator and the data owner cooperating with the data consumer to verify the perturbed data, and feeding back the verification result to the data consumer and the data owner; the data consumer and the data owner determining the transaction settlement result based on the verification result.

[0011] The step of the perturbation generator generating a perturbation strategy based on the perturbation level includes: the perturbation generator determining a perturbation probability based on the perturbation level using a localized differential privacy perturbation algorithm; determining a perturbation strategy based on the perturbation probability; and generating a verification bit for each perturbation strategy.

[0012] The step of the perturbation generator determining the perturbation probability based on the perturbation degree using a localized differential privacy perturbation algorithm includes: the perturbation generator determining a first perturbation probability and a second perturbation probability based on the perturbation degree using the localized differential privacy perturbation algorithm; the step of determining the perturbation strategy based on the perturbation probability includes: generating a first perturbation strategy based on the first perturbation probability, and generating a second perturbation strategy based on the second perturbation probability.

[0013] The step of sending the perturbation strategy to each data owner includes: the data owner obtaining a transaction sequence number, which is generated after the data owner and the data consumer reach a data transaction; determining the sequence number of the perturbation strategy based on the transaction sequence number; the data owner generating a ciphertext vector using a public key, the ciphertext vector including n elements, where the k-th element is determined based on the sequence number of the perturbation strategy; the data owner sending the ciphertext vector to the perturbation generator; the perturbation generator, in response to receiving the ciphertext vector, performing an inner product operation on the perturbation strategy and the received ciphertext vector, and sending the result to the data owner; and the data owner decrypting the result to obtain the perturbation strategy.

[0014] The step of the data owner processing the data based on the received perturbation strategy to obtain perturbed data includes: in response to the data owner receiving a perturbation strategy including a first perturbation strategy, the data owner submits the original data as the actual perturbation data to obtain perturbed data with honest perturbation; or the data owner submits other data as the actual perturbation data to obtain perturbed data with deviations; in response to the data owner receiving a perturbation strategy including a second perturbation strategy, the data owner submits other data as the actual perturbation data to obtain perturbed data with honest perturbation; or the data owner submits other data as the actual perturbation data to obtain perturbed data with deviations.

[0015] The step of the disturbance generator, the data owner, and the data consumer verifying the disturbed data includes: the disturbance generator, the data owner, and the data consumer performing a first-level verification, a second-level verification, and a third-level verification; the first-level verification verifies the legality of the disturbance strategy; the second-level verification verifies whether the disturbance strategy involves submitting real data or false data; and the third-level verification verifies whether the disturbed data is obtained from the original data according to the disturbance strategy.

[0016] The step of the data consumer and the data owner determining the transaction settlement result based on the verification result includes: in response to the verification result being characterized as an honesty disturbance, the data consumer compensating the data owner for privacy loss; in response to the verification result being characterized as a deviation disturbance, the data owner compensating the data consumer for data availability loss; wherein, if any one of the first-level verification, the second-level verification, or the third-level verification fails, it indicates that the verification result is a deviation disturbance.

[0017] Secondly, this application provides a data trading system, comprising: a disturbance generator, a data owner, and a data consumer; the disturbance generator generates a disturbance strategy based on the disturbance level and sends the disturbance strategy to each data owner; wherein the disturbance level is determined by the data consumer and the data owner; the data owner disturbs the data based on the received disturbance strategy to obtain disturbed data; the disturbance generator and the data owner cooperate with the data consumer to verify the disturbed data and feed back the verification result to the data consumer and the data owner; the data consumer and the data owner determine the transaction settlement result based on the verification result.

[0018] Thirdly, this application provides an electronic device, the electronic device including a processor and a memory, wherein the memory is used to store program instructions for constructing a method for implementing any one of the data transaction methods; and the processor is used to execute the program instructions stored in the memory.

[0019] Fourthly, this application provides a storage medium storing a program file that can be executed to implement any of the data transaction methods described above.

[0020] The data transaction method of this invention involves a perturbation generator producing a perturbation strategy based on the degree of perturbation and sending the perturbation strategy to each data owner. The degree of perturbation is determined by the data consumer and the data owner. The data owner perturbs the data based on the received perturbation strategy to obtain perturbed data. The perturbation generator, the data owner, and the data consumer cooperate to verify the perturbed data and feed back the verification result to both the data consumer and the data owner. The data consumer and the data owner determine the transaction settlement result based on the verification result. This method protects the privacy of data entities (DOs) while incentivizing them to honestly perturb the data, thereby simultaneously ensuring both the data privacy requirements of DOs and the data availability requirements of data centers (DCs). Attached Figure Description

[0021] Figure 1 This is a flowchart illustrating the first embodiment of the data transaction method of the present invention;

[0022] Figure 2 This is a schematic diagram of the structure of one embodiment of the Faming Data Transaction System;

[0023] Figure 3 This is a schematic diagram of the structure of an embodiment of the electronic device of the present invention;

[0024] Figure 4 This is a schematic diagram of the structure of an embodiment of the storage medium of the present invention. Detailed Implementation

[0025] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0026] Please see Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the data transaction method of the present invention, specifically including:

[0027] Step S11: The perturbation generator generates a perturbation strategy based on the perturbation level and sends the perturbation strategy to each data owner; wherein the perturbation level is determined by the data consumer and the data owner.

[0028] Specifically, the disturbance generator is denoted as DG, the data owner as DO, and the data consumer as DC.

[0029] In one embodiment, the perturbation generator determines a perturbation probability based on the perturbation level using a localized differential privacy perturbation algorithm; determines a perturbation strategy based on the perturbation probability, and generates a verification bit for each perturbation strategy.

[0030] In one embodiment, the step of the perturbation generator determining the perturbation probability based on the perturbation degree using a localized differential privacy perturbation algorithm includes: the perturbation generator determining a first perturbation probability and a second perturbation probability based on the perturbation degree using a localized differential privacy perturbation algorithm;

[0031] The step of determining the perturbation strategy based on the perturbation probability includes: generating a first perturbation strategy based on the first perturbation probability, and generating a second perturbation strategy based on the second perturbation probability.

[0032] Specifically, based on the random response mechanism, DG determines the perturbation level negotiated between DOs and DC. A series of perturbation strategies are generated :

[0033]

[0034] in and They are respectively Honest perturbated data and undisturbed raw data. Let represent the i-th data owner. Specifically, DG, with the first probability Generate the first perturbation strategy , Upon receiving this policy, its original data needs to be... As honest perturbation data Submitted to DC, i.e. Meanwhile, DG won with the second highest probability. Generate a second perturbation strategy , When this policy is received, other versions of the data need to be included. As honest perturbation data Submitted to DC, i.e. .

[0035] Furthermore, in this step, the perturbation strategy needs to be sent to each data owner. Specifically, the data owner obtains a transaction sequence number, which is generated after the data owner and the data consumer reach a data transaction agreement. For example, after reaching a data transaction agreement with the data consumer, each... Get a random and non-repeating number This number can be considered a transaction sequence number.

[0036] The sequence number of the perturbation strategy is determined based on the transaction sequence number. Specifically, each calculate Where r is a random number secretly negotiated by all DOs, and k represents the number to be allocated to... The sequence number of the perturbation strategy.

[0037] The data owner generates a ciphertext vector using a public key. This ciphertext vector comprises n elements, where the k-th element is determined based on the sequence number of the perturbation strategy. Specifically, the perturbation strategy is obtained privately from the data manager (DG). Using its public key Generate an n-dimensional ciphertext vector: Among them, the k-th element For the reason public key The ciphertext of the encrypted 1, that is Other elements are based on public key The ciphertext containing encrypted zeros, i.e. Subsequently, This ciphertext vector Send to DG to secretly obtain the perturbation strategy.

[0038] The data owner sends the ciphertext vector to the perturbation generator; in response to receiving the ciphertext vector, the perturbation generator performs an inner product operation on the perturbation strategy and the received ciphertext vector, and sends the result back to the data owner. Specifically, the perturbation generator DG receives... Submitted ciphertext vector After that, DG With perturbation strategy set Perform the inner product operation and return the result to The calculation result can be expressed as:

[0039] .

[0040] The data owner decrypts the computation result to obtain the perturbation strategy. Specifically, due to the characteristics of homomorphic encryption, the result of the ciphertext computation is equal to the result of the plaintext computation and then decrypted, that is:

[0041] .

[0042] Based on this, after receiving the ciphertext calculation result, Use your own private key Decipher the result and obtain its perturbation strategy: .

[0043] Step S12: The data owner perturbs the data based on the received perturbation strategy to obtain the perturbated data.

[0044] Specifically, in response to the data owner receiving a perturbation strategy including a first perturbation strategy, the data owner submits the original data as the actual perturbation data to obtain the perturbated data with honest perturbation data; or the data owner submits other data as the actual perturbation data to obtain the perturbated data with deviating perturbation data.

[0045] In response to the data owner receiving a perturbation strategy that includes a second perturbation strategy, the data owner submits other data as actual perturbation data to obtain perturbed data with honest perturbation data; or the data owner submits other data as actual perturbation data to obtain perturbed data with deviating perturbation data.

[0046] For example, in one embodiment, the data owner (DO) obtains the perturbation strategy. back, One can strategically choose to honestly perturb the data according to the received perturbation strategy. Or implement divergent perturbations to better protect their own privacy.

[0047] Specifically, You can choose to perturb the data honestly according to the received perturbation strategy. If The received perturbation strategy is:

[0048] ,

[0049] This means .therefore, The original data needs to be submitted. As actual disturbance data ,Right now: .

[0050] In addition, if The received perturbation strategy is:

[0051] ,

[0052] This means .therefore, Additional data needs to be submitted. As actual disturbance data ,Right now: .

[0053] at the same time, A strategy that deviates from the received perturbation can be chosen to perturb the data. If The received perturbation strategy is:

[0054] ,

[0055] This means Considering the potential privacy breaches that could result from exposing raw data, Unwilling to submit raw data directly To better protect their privacy, Implementing a divergence strategy involves data perturbation, i.e., submitting additional data. As actual disturbance data : .

[0056] In addition, if The received perturbation strategy is:

[0057] ,

[0058] This means This perturbation strategy can effectively protect... Privacy. Therefore. Willing to implement data perturbation according to the received perturbation strategy, i.e., submit additional data. As actual disturbance data : .

[0059] Based on the above steps The perturbated data is submitted to the DC.

[0060] Step S13: The disturbance generator and the data owner cooperate with the data consumer to verify the disturbed data, and feed back the verification result to the data consumer and the data owner.

[0061] Specifically, since the data perturbation is carried out locally by the DO (Data Consumer) rather than by the DC (Data Owner) or a trusted third-party server, the DC may question the honesty of the DO's data perturbation. Therefore, the DC strategically decides whether to verify the honesty of the DO's perturbation data. After the DC decides to verify, the DG (Data Provider) assists the DC in completing the verification and finally feeds back the verification results to the data consumer DC and the data owner DO to ensure the non-repudiation of the verification results.

[0062] Specifically, the steps for the perturbation generator, the data owner, and the data consumer to verify the perturbated data include: the perturbation generator, the data owner, and the data consumer performing a first-level verification, a second-level verification, and a third-level verification; the first-level verification verifies the legality of the perturbation strategy; the second-level verification verifies whether the perturbation strategy involves submitting real data or false data; and the third-level verification verifies whether the perturbated data is obtained from the original data according to the perturbation strategy.

[0063] In one embodiment, if the DC requires verification, the DO must cooperate in the verification. The verification results of the data perturbation can be expressed as: .

[0064] It indicates The degree of privacy loss suffered during the perturbation verification process, and .in express raw data Exposed express No privacy was compromised. Furthermore, It indicates Whether the disturbance is honest, and ,in express The disturbance is honest. express The disturbance is contrary to the norm.

[0065] If DC chooses not to verify the honesty of DO perturbations, that is, DC believes that DO is honestly perturbed in accordance with the received perturbation strategy, then the verification result is recorded as: .

[0066] If DC chooses to verify the honesty of the DO perturbation, then the three-level verification algorithm designed in this application is implemented:

[0067] First, a first-level verification is performed, specifically, the perturbation generator verifies the legality of the perturbation strategy employed by the data owner. If the perturbation strategy is legal, a second-level verification is performed, specifically verifying whether the perturbation strategy involves submitting genuine data or falsified data. If the perturbation strategy involves submitting genuine data, a third-level verification is performed, specifically verifying whether the perturbated data was obtained from the original data according to the perturbation strategy. If the perturbated data is indeed obtained from the original data according to the perturbation strategy, the perturbation is determined to be an honest perturbation. Conversely, if any of the first, second, or third-level verifications fails, the verification result indicates a deviation from the perturbation strategy. In other words, if the perturbation strategy is illegal, or the perturbation strategy involves submitting falsified data, or the perturbated data is not obtained from the original data according to the perturbation strategy, then it is a deviation from the perturbation strategy.

[0068] Specifically, DC, with the help of DG, first conducts the first level of verification, namely, verifying the legality of the DOs interference strategy, where legality means... Disturbance strategy DG is based on the degree of disturbance This is generated. To achieve this goal, Its perturbation strategy Send it to DG, who will verify whether the strategy is based on the degree of perturbation. The generated verification result is as follows:

[0069] ,

[0070] in, express Disturbance strategy It is legal, and express Disturbance strategy This is illegal. After verifying the legality of the perturbation strategy, DG signs the verification result and sends it to DC. This makes it impossible for either party to deny the verification results. Based on If the strategy validity verification result is... , It will be directly identified as a deviation disturbance, and the verification process did not leak information. Therefore, the perturbation verification result is: (The perturbation verification result is:) .like , The perturbation strategy is legitimate, and DC further performs a second level of verification, namely, verification... The content of the perturbation strategy. That is, the data consumer verifies the content of the perturbation strategy; in response to the perturbation strategy being an honest perturbation, the data consumer verifies the perturbation data and feeds back the verification result.

[0071] Specifically, when , Other data should be submitted. As its honest perturbation data .in this case, They will inevitably follow the received perturbation strategy and honestly perturb the data, because doing so is in their best interest in protecting their privacy. Therefore, when , It was determined to be an honest disturbance. During this process... Inevitably, additional privacy losses will occur because DC can deduce... The original data meets the following conditions .therefore, The perturbation verification results are ,in for Privacy losses suffered during the verification process.

[0072] when , The original data should be submitted. As its honest perturbation data .in this case, They might implement divergence perturbations to better protect their privacy. Therefore, DC needs to implement a third level of perturbation: perturbation data verification. Perturbation data verification involves comparing the perturbation data with the actual perturbation data. The encrypted text and the original data The encrypted text. To achieve this goal, we employ a one-way collision-resistant hash function, which guarantees that no one can encrypt the text based on... The ciphertext was deduced The plaintext.

[0073] Specifically, the DC will receive the actual disturbance data. Get by hashing , Its original data Get by hashing The DG then compares the two hash results to see if they are the same. If the comparison results are different, that is... , It was confirmed as a divergent disturbance, and during the verification process... They will inevitably suffer additional privacy losses, and DC is able to deduce that The original data satisfies .therefore, The perturbation verification results are .

[0074] Furthermore, if the comparison results are the same, that is , It was confirmed as an honest perturbation, and during the verification process... They will inevitably suffer additional privacy losses, and DC is able to deduce that The original data satisfies .therefore, The perturbation verification results are .

[0075] After verification is complete, DG will sign the verification result and send it to DC. This is to ensure that neither party to the transaction can deny the verification results.

[0076] Step S14: The data consumer and the data owner determine the transaction settlement result based on the verification result.

[0077] Based on the disturbance verification results, the two parties to the transaction, DC and DO, determine the penalty or compensation amount for DO and complete the transaction settlement. Specifically, there are two scenarios: in response to the verification result being characterized as an honest disturbance, the data consumer compensates the data owner for the privacy loss; in response to the verification result being characterized as a divergent disturbance, the data owner compensates the data consumer for the data availability loss.

[0078] Specifically, the first type is: honesty disturbance.

[0079] when When the disturbance is verified as honest, the data owner will not be penalized, and at the same time, The privacy loss needs to be compensated by the DC. Specifically, Privacy losses caused by transaction-related data disturbances need to be compensated by the DC in the form of data pricing; The additional privacy losses suffered during the perturbation verification process need to be compensated by the DC.

[0080] Specifically, if The perturbation verification results are This means For honest perturbations, and the degree of privacy loss suffered during the verification process is .therefore, Not only can they obtain the data price previously negotiated with DC ,in for Due to the degree of leakage disturbance raw data The resulting loss of privacy For variable parameters, Furthermore, during the perturbation verification process, The degree of suffering is The privacy loss. Therefore, DC needs to compensate for these additional privacy losses, with the compensation amount being [amount missing]. ,in for Due to the degree of leakage disturbance raw data The resulting loss of privacy For variable parameters, .

[0081] like The perturbation verification results are This means It is considered an honest disturbance, and no privacy was compromised. In this case, Will receive the data price negotiated with the DC. .

[0082] Furthermore, due to the honest perturbation of the DO, the data availability requirement of the DC is met. Therefore, the DO no longer needs to compensate the DC.

[0083] The second type is the deviation disturbance.

[0084] when When a data disturbance is verified to be a deviation from the agreed-upon price, the data owner not only forfeits the data price negotiated with the data controller (DC), but is also penalized. This penalty is implemented by compensating the DC for the loss of data availability. Without penalty, such behavior would be tacitly condoned. The deviation from privacy policies is increasingly common, and more and more DOs are implementing deviations from privacy policies on their personal data to better protect their privacy while profiting. Therefore, penalizing DOs that engage in deviations from privacy policies is essential. Furthermore, due to... Data on divergence disturbances were submitted. The accuracy of statistical data is reduced, which in turn impairs the data availability requirements of the data center (DC). Therefore, requiring the data center (DO) to compensate the DC for the loss of data availability due to deviations is an effective punitive measure. This not only constrains the deviation behavior of the DO but also protects the interests of the DC.

[0085] Specifically, if The perturbation verification results are Or the perturbation verification result is , It was verified as a deviation from the disturbance. In this case, They will be punished in the following manner: The agreed-upon data price will not be obtained. Regardless of whether any additional privacy breaches occur during the verification process, Neither of them can receive compensation from DC; The loss of data availability at the data center needs to be compensated.

[0086] The aforementioned penalty measures can effectively constrain the deviation disturbances of DO, while also ensuring that the data availability requirements of DC are met.

[0087] Based on the aforementioned data transaction process, we model the perturbation-verification process between DC and DO as a game. Specifically, DO can strategically choose honest perturbation ( or deviation from disturbance ( DC can strategically choose to believe in the honesty of DO's perturbations. Or verify the honesty of the DO perturbation ( Since different choices lead to different utilities, both parties in a transaction will rationally choose strategies to try to maximize their own utility. Meanwhile, the solution proposed in this patent aims to ensure that the Do (Distributor) chooses honest perturbations, while the DC (Distributor) chooses to believe in the honesty of the Do perturbations. Therefore, we adopt the definition of Nash equilibrium to reasonably determine data prices. and privacy compensation amount The specific constraints are as follows:

[0088] ,

[0089] This means that the DO can gain greater utility through honest interference than the privacy compensation gained during the verification process; if the DC chooses to verify, the utility he gains is less than the total compensation he receives from the DO.

[0090] Under the aforementioned constraints, DOs tend to honestly perturb their own data, while DCs tend to believe the honesty of the DOs' perturbations without verification. Therefore, the solution proposed in this application can guarantee both the privacy needs of DOs and the data availability needs of DCs.

[0091] This application designs a data trading method that verifies data perturbations. Specifically, the Data Generator (DG) first generates a perturbation strategy with a checksum based on localized differential privacy. Then, based on the idea of ​​privacy information retrieval, the generated perturbation strategy is secretly, randomly, and conflict-free distributed to each Distributor (DO). After receiving the perturbation data from the DO, the Data Controller (DC) strategically decides whether to verify the honesty of the DO's perturbation. The accuracy of the verification result is guaranteed by our designed three-level verification algorithm, where the legality and honesty of the perturbation strategy are verified progressively and in a privacy-conscious manner. Specifically, based on the verification results in the previous module, we design a compensation strategy for honest perturbation DOs and a penalty strategy for deviating perturbation DOs. Specifically, we model privacy data trading as a game, where DOs can choose honest perturbations and deviating perturbations, and DCs can choose to verify DO perturbations or believe in DO perturbations. In the game, we use the Nash equilibrium definition to determine the compensation and penalty amounts for DOs, constraining the utility of DOs and DCs to incentivize DOs to choose honest perturbations and DCs to choose to believe in the honesty of DO perturbations.

[0092] Please see Figure 2 , Figure 2 This is a schematic diagram of the structure of an embodiment of the data trading system of the present invention. Specifically, the data trading system includes: a disturbance generator, a data owner, and a data consumer; wherein, the disturbance generator is denoted as DG, the data owner is denoted as DO, and the data consumer is denoted as DC.

[0093] The perturbation generator generates a perturbation strategy based on the perturbation level and sends the perturbation strategy to each data owner; wherein, the perturbation level is determined by the data consumer and the data owner; the data owner perturbs the data based on the received perturbation strategy to obtain perturbed data; the perturbation generator and the data owner cooperate with the data consumer to verify the perturbed data and feed back the verification result to the data consumer and the data owner; the data consumer and the data owner determine the transaction settlement result based on the verification result.

[0094] Specifically, the data consumer (DC) needs to purchase relevant data with a certain level of perturbation and pay for this data after verification. The perturbation generator (DG) generates perturbation strategies for all DOs based on the perturbation level negotiated between the DC and DO. The data owner (DO) must comply with the perturbation strategies generated by the DG to perturb their personal data (or disobey and choose to deviate from the perturbation), and then submit the perturbated data to the DC, receiving a data price after verification.

[0095] The proposed solution can be divided into two modules: a perturbation verification module and a transaction clearing module. Specifically, in the perturbation verification module, the DG first generates a perturbation strategy with a checksum based on localized differential privacy. Then, based on the concept of privacy information retrieval, the generated perturbation strategy is secretly, randomly, and conflict-free distributed to each DO. Upon receiving the perturbation data from the DO, the DC strategically decides whether to verify the honesty of the DO's perturbation. The accuracy of the verification result is guaranteed by our designed three-level verification algorithm, in which the legality of the perturbation strategy and the honesty of the perturbation are verified progressively and in a privacy-conscious manner.

[0096] In the transaction settlement module, based on the verification results from the previous module, we designed a compensation strategy for honest perturbations (DOs) and a penalty strategy for deviating perturbations (DOs). Specifically, we model privacy data transactions as a game, where DOs can choose between honest perturbations and deviating perturbations, and DCs can choose between verifying DOs' perturbations and believing in DOs' perturbations. In the game, we use the definition of Nash equilibrium to determine the compensation and penalty amounts for DOs, thereby constraining the utilities of DOs and DCs, and incentivizing DOs to choose honest perturbations and DCs to choose to believe in the honesty of DO perturbations.

[0097] Please see Figure 3 , Figure 3 This is a schematic diagram of the structure of an embodiment of the electronic device of this application, including a memory 52 and a processor 51 connected to each other.

[0098] The memory 52 is used to store program instructions for implementing any of the above methods.

[0099] Processor 51 is used to execute program instructions stored in memory 52.

[0100] The processor 51 can also be referred to as a CPU (Central Processing Unit). The processor 51 may be an integrated circuit chip with signal processing capabilities. The processor 51 can also be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an off-the-shelf programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. A general-purpose processor can be a microprocessor or any conventional processor.

[0101] The memory 52 can be a memory module, TF card, etc., and can store all information in the smart terminal, including raw input data, computer programs, intermediate running results, and final running results. It stores and retrieves information according to the location specified by the controller. With memory, the smart terminal has a memory function and can ensure normal operation. Memory in a smart terminal can be classified according to its purpose into main memory (RAM) and auxiliary memory (external storage), or it can be classified into external memory and internal memory. External storage is usually magnetic media or optical discs, which can store information for a long time. RAM refers to the storage components on the motherboard, used to store currently executing data and programs, but it is only used for temporary storage; the data will be lost when the power is turned off.

[0102] In the several embodiments provided in this application, it should be understood that the disclosed methods and apparatus can be implemented in other ways. For example, the apparatus implementations described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0103] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment, depending on actual needs.

[0104] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0105] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, a system server, or a network device, etc.) or a processor to execute all or part of the steps of the methods of the various embodiments of this application.

[0106] Please see Figure 4 This is a schematic diagram of the structure of the storage medium of the present invention. The storage medium of this application stores a program file 61 capable of implementing all the above methods. The program file 61 can be stored in the storage medium in the form of a software product, including several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods of various embodiments of this application. The aforementioned storage device includes various media capable of storing program code, such as a USB flash drive, portable hard drive, read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk, or terminal devices such as computers, servers, mobile phones, and tablets.

[0107] The above are merely embodiments of the present invention and do not limit the patent scope of the present invention. Any equivalent structural or procedural transformations made based on the content of the present invention's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of the present invention.

Claims

1. A data transaction method, characterized in that, include: The perturbation generator generates a perturbation strategy based on the perturbation level and sends the perturbation strategy to each data owner; wherein, the perturbation level is determined by the data consumer and the data owner; the step of the perturbation generator generating a perturbation strategy based on the perturbation level includes: the perturbation generator determining a first perturbation probability and a second perturbation probability based on the perturbation level using a localized differential privacy perturbation algorithm; generating a first perturbation strategy based on the first perturbation probability, and generating a second perturbation strategy based on the second perturbation probability, and generating a verification bit for each perturbation strategy; specifically expressed as: in and They are respectively Honest perturbated data and undisturbed raw data, This indicates that the i-th data owner, the perturbation generator DG, has the first probability. Generate the first perturbation strategy , When the policy is received, its raw data As honest perturbation data Submitted to the data consumer (DC), i.e. Meanwhile, the perturbation generator DG, with the second probability Generate a second perturbation strategy , When this policy is received, other versions of the data need to be included. As honest perturbation data Submitted to the data consumer (DC), i.e. , The degree of disturbance; The data owner perturbs the data based on the received perturbation strategy to obtain perturbed data; specifically, this includes: in response to the data owner receiving a perturbation strategy including a first perturbation strategy, the data owner submits the original data as the actual perturbation data to obtain perturbed data with honest perturbation; or the data owner submits other data as the actual perturbation data to obtain perturbed data with deviations; in response to the data owner receiving a perturbation strategy including a second perturbation strategy, the data owner submits other data as the actual perturbation data to obtain perturbed data with honest perturbation; or the data owner submits other data as the actual perturbation data to obtain perturbed data with deviations. The disturbance generator and the data owner cooperate with the data consumer to verify the disturbed data, and feed back the verification results to the data consumer and the data owner; The data consumer and the data owner determine the transaction settlement result based on the verification result.

2. The data transaction method according to claim 1, characterized in that, The step of sending the perturbation strategy to each data owner includes: The data owner obtains a transaction sequence number, which is generated after the data owner and the data consumer reach a data transaction agreement. The sequence number of the perturbation strategy is determined based on the transaction sequence number; The data owner uses a public key to generate a ciphertext vector, which includes n elements, where the k-th element is determined based on the sequence number of the perturbation strategy. The data owner sends the ciphertext vector to the perturbation generator; In response to receiving the ciphertext vector, the perturbation generator performs an inner product operation on the perturbation strategy and the received ciphertext vector, and sends the operation result to the data owner. The data owner decrypts the calculation result to obtain the perturbation strategy.

3. The data transaction method according to claim 1, characterized in that, The steps for the disturbance generator, the data owner, and the data consumer to verify the disturbed data include: The perturbation generator and the data owner cooperate with the data consumer to perform first-level verification, second-level verification, and third-level verification. The first-level verification verifies the legality of the perturbation strategy. The second-level verification verifies whether the perturbation strategy involves submitting real data or fake data. The third-level verification verifies whether the perturbed data is obtained from the original data according to the perturbation strategy.

4. The data transaction method according to claim 3, characterized in that, The steps for the data consumer and the data owner to determine the transaction settlement result based on the verification result include: In response to the verification result being characterized as an honest perturbation, the data consumer compensates the data owner for the loss of privacy. In response to the verification result being characterized as a deviation disturbance, the data owner compensates the data consumer for the loss of data availability; If any one of the first-level verification, the second-level verification, or the third-level verification fails, it indicates that the verification result is a deviation from the perturbation.

5. A data transaction system, characterized in that, include: Disturbance generators, data owners, and data consumers; The perturbation generator generates a perturbation strategy based on the perturbation level and sends the perturbation strategy to each data owner; wherein, the perturbation level is determined by the data consumer and the data owner; the step of the perturbation generator generating a perturbation strategy based on the perturbation level includes: the perturbation generator determining a first perturbation probability and a second perturbation probability based on the perturbation level using a localized differential privacy perturbation algorithm; generating a first perturbation strategy based on the first perturbation probability, and generating a second perturbation strategy based on the second perturbation probability, and generating a verification bit for each perturbation strategy; specifically expressed as: in and They are respectively Honest perturbated data and undisturbed raw data, This indicates that the i-th data owner, the perturbation generator DG, has the first probability. Generate the first perturbation strategy , When the policy is received, its raw data As honest perturbation data Submitted to the data consumer (DC), i.e. Meanwhile, the perturbation generator DG, with the second probability Generate a second perturbation strategy , When this policy is received, other versions of the data need to be included. As honest perturbation data Submitted to the data consumer (DC), i.e. , The degree of disturbance; The data owner perturbs the data based on the received perturbation strategy to obtain perturbed data; specifically, this includes: in response to the data owner receiving a perturbation strategy including a first perturbation strategy, the data owner submits the original data as the actual perturbation data to obtain perturbed data with honest perturbation; or the data owner submits other data as the actual perturbation data to obtain perturbed data with deviations; in response to the data owner receiving a perturbation strategy including a second perturbation strategy, the data owner submits other data as the actual perturbation data to obtain perturbed data with honest perturbation; or the data owner submits other data as the actual perturbation data to obtain perturbed data with deviations. The disturbance generator and the data owner cooperate with the data consumer to verify the disturbed data, and feed back the verification results to the data consumer and the data owner; The data consumer and the data owner determine the transaction settlement result based on the verification result.

6. An electronic device, characterized in that, The electronic device includes a processor and a memory, wherein, The memory is used to store program instructions for constructing a data transaction method as described in any one of claims 1 to 4; The processor is used to execute the program instructions stored in the memory.

7. A storage medium, characterized in that, The system contains a program file that can be executed to implement the data transaction method as described in any one of claims 1 to 4.