Data theft detection method, data publishing method and device under privacy computing
By obtaining and verifying the hash value and importance judgment benchmark of data in privacy computing, combined with zero-knowledge proof, the problem of detecting data theft in privacy computing is solved, ensuring the security and transparency of data.
Patent Information
- Application Number
- CN202310096739.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-19
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2043-01-19
AI Technical Summary
In privacy computing, data theft is difficult to detect, and traditional methods make it difficult to discover whether data is involved in theft during the data sharing process.
By obtaining the hash value and importance judgment benchmark of the original data, the authenticity of the data is verified, and a zero-knowledge proof algorithm is used to generate a proof of the data theft detection result to ensure the authenticity of the detection result.
It achieves effective detection of data theft in a privacy computing environment, ensures data sovereignty, and provides security and transparency in data release.
Smart Images

Figure CN116318850B_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of privacy computing technology, and in particular relates to a data theft detection method, data publishing method and device under privacy computing. Background Art
[0002] Privacy computing essentially addresses data circulation, data application, and other data service issues while protecting data privacy. With the development of privacy computing technology, data security during circulation has been further guaranteed. However, the resulting data theft has become increasingly serious.
[0003] Traditional data transaction processes mostly use plaintext transactions. After the data transaction, it is easy to detect whether the data has been stolen. However, when data is shared through privacy computing technology, it is difficult to detect whether the data is involved in theft, making data theft detection a technical problem that needs to be solved urgently. Summary of the Invention
[0004] The embodiments of the present application provide a data theft detection method, data publishing method and device under privacy computing, which can solve the above-mentioned technical problems.
[0005] In the first aspect, an embodiment of the present application provides a data theft detection method under privacy computing, which is executed by the detection party, including: in response to a data theft detection request, obtaining the first original data provided by the requesting party, the hash value corresponding to the first original data stored on the chain, the second original data provided by the party to be detected, and the hash value corresponding to the second original data stored on the chain; verifying the first original data provided by the requesting party and the second original data provided by the party to be detected according to the hash value corresponding to the first original data and the hash value corresponding to the second original data; if the verification passes, obtaining the first importance judgment criterion and the first importance judgment result stored on the chain, and controlling the party to be detected to calculate the second importance judgment result according to the second original data and the first importance judgment criterion; wherein the first importance judgment criterion and the first importance judgment result are the importance judgment criterion and the importance judgment result corresponding to the first original data; controlling the requesting party to calculate the first data detection result according to the first original data and the first importance judgment result, and controlling the party to be detected to calculate the second data detection result according to the second original data and the second importance judgment result; obtaining the data theft detection result according to the first data detection result and the second data detection result.
[0006] Furthermore, before responding to a data theft detection request, it includes: responding to a data release request, obtaining the data owner information, the data metadata corresponding to the data to be released, the importance judgment standard corresponding to the data to be released, the importance judgment result corresponding to the data to be released, and the hash value corresponding to the data to be released; and publishing the data owner information, the data metadata corresponding to the data to be released, the importance judgment standard corresponding to the data to be released, the importance judgment result corresponding to the data to be released, and the hash value corresponding to the data to be released on the chain.
[0007] Furthermore, the control unit to be tested calculates a second importance judgment result based on the second original data and the first importance judgment criterion, including: controlling the control unit to be tested to divide the second original data into first-category data and second-category data based on the median of the first importance judgment criterion; calculating the ratio between the number of first-category data corresponding to each column in the second original data and the total number of first-category data to obtain a first ratio corresponding to each column; calculating the ratio between the number of second-category data corresponding to each column in the second original data and the total number of second-category data to obtain a second ratio corresponding to each column; obtaining a second importance judgment result corresponding to each column in the second original data based on the first ratio corresponding to each column, the second ratio corresponding to each column and a preset importance calculation formula.
[0008] Furthermore, the first importance determination result includes the first importance determination result corresponding to each column in the first original data, and the second importance determination result includes the second importance determination result corresponding to each column in the second original data; the control requesting party calculates the first data detection result based on the first original data and the first importance determination result, and controls the party to be detected to calculate the second data detection result based on the second original data and the second importance determination result, including: controlling the requesting party to obtain the accumulated values corresponding to each column in the first original data, calculating the sum of the products of the accumulated values corresponding to each column in the first original data and the first importance determination results corresponding to each column in the first original data, and obtaining the first data detection result; controlling the party to be detected to obtain the accumulated values corresponding to each column in the second original data, calculating the sum of the products of the accumulated values corresponding to each column in the second original data and the second importance determination results corresponding to each column in the second original data, and obtaining the second data detection result.
[0009] Furthermore, based on the first data detection result and the second data detection result, a data theft detection result is obtained, including: calculating the difference between the first data detection result and the second data detection result, and calculating the ratio between the difference and the first data detection result to obtain a target ratio; and obtaining the data theft detection result based on the target ratio and a preset data theft detection classification standard.
[0010] Furthermore, the method also includes: generating a proof about the first original data, the second original data and the process of obtaining the data theft detection result according to a preset zero-knowledge proof algorithm; if the verification of the proof is successful, confirming that the data theft detection result is a true result; or, executing the data theft detection process under privacy computing in a trusted execution environment; wherein, the data theft detection process under privacy computing at least includes the process of obtaining the first original data, the second original data and the data theft detection result.
[0011] In the second aspect, an embodiment of the present application provides a data publishing method under privacy computing, which is executed by the data owner, including: obtaining data owner information, data to be published, data metadata corresponding to the data to be published, and a hash value corresponding to the data to be published; generating an importance judgment benchmark corresponding to the data to be published based on the data to be published and a preset importance judgment benchmark generation rule; calculating the importance judgment result corresponding to the data to be published based on the data to be published and the importance judgment benchmark corresponding to the data to be published; generating and sending a data publishing request to the execution subject of the data theft detection method of the first aspect based on the data owner information, the data metadata corresponding to the data to be published, the hash value corresponding to the data to be published, the importance judgment benchmark corresponding to the data to be published, and the importance judgment result corresponding to the data to be published; wherein, if the data to be published is designated as the first original data, the first importance judgment benchmark and the first importance judgment result stored on the chain in the data theft detection method of the first aspect are the importance judgment benchmark corresponding to the data to be published and the importance judgment result corresponding to the data to be published.
[0012] Furthermore, based on the data to be published and preset importance judgment criterion generation rules, an importance judgment criterion corresponding to the data to be published is generated, including: obtaining random numbers corresponding to each column in the data to be published; wherein the random numbers are within a preset value range; calculating the sum of the products of each column of data in the data to be published and the random numbers corresponding to each column in the data to be published to obtain a first reference vector; generating a second reference vector based on the value range corresponding to the first reference vector; generating an importance judgment criterion corresponding to the data to be published based on the value range corresponding to the second reference vector.
[0013] Furthermore, based on the data to be released and the importance judgment criteria corresponding to the data to be released, the importance judgment result corresponding to the data to be released is calculated, including: obtaining the median of the importance judgment criteria corresponding to the data to be released; dividing the data to be released into first category data and second category data according to the median of the importance judgment criteria corresponding to the data to be released; calculating the ratio between the number of first category data corresponding to each column in the data to be released and the total number of first category data, and obtaining the first ratio corresponding to each column; calculating the ratio between the number of second category data corresponding to each column in the data to be released and the total number of second category data, and obtaining the second ratio corresponding to each column; according to the first ratio corresponding to each column, the second ratio corresponding to each column and the preset importance calculation formula, the importance judgment result corresponding to the data to be released is obtained.
[0014] In a third aspect, an embodiment of the present application provides a data theft detection device under privacy computing, including: a response unit, for obtaining, in response to a data theft detection request, the first original data provided by the requesting party, the hash value corresponding to the first original data stored on the chain, the second original data provided by the party to be detected, and the hash value corresponding to the second original data stored on the chain; a verification unit, for verifying the first original data provided by the requesting party and the second original data provided by the party to be detected according to the hash value corresponding to the first original data and the hash value corresponding to the second original data, respectively; a first control unit, for obtaining, if the verification passes, the first importance determination criterion and the first importance determination result stored on the chain, and controlling the party to be detected to calculate the second importance determination result based on the second original data and the first importance determination criterion; wherein the first importance determination criterion and the first importance determination result are the importance determination criterion and the importance determination result corresponding to the first original data; a second control unit, for controlling the requesting party to calculate the first data detection result based on the first original data and the first importance determination result, and controlling the party to be detected to calculate the second data detection result based on the second original data and the second importance determination result; a detection unit, for obtaining a data theft detection result based on the first data detection result and the second data detection result.
[0015] Furthermore, the device also includes: an acquisition unit, used to obtain the data owner information, data metadata corresponding to the data to be published, the importance judgment standard corresponding to the data to be published, the importance judgment result corresponding to the data to be published, and the hash value corresponding to the data to be published in response to the data publishing request; a publishing unit, used to publish the data owner information, data metadata corresponding to the data to be published, the importance judgment standard corresponding to the data to be published, the importance judgment result corresponding to the data to be published, and the hash value corresponding to the data to be published on the chain.
[0016] Furthermore, the first control unit is specifically used to: control the party to be detected to divide the second original data into first category data and second category data according to the median of the first importance judgment criterion; calculate the ratio between the number of first category data corresponding to each column in the second original data and the total number of first category data to obtain the first ratio corresponding to each column; calculate the ratio between the number of second category data corresponding to each column in the second original data and the total number of second category data to obtain the second ratio corresponding to each column; obtain the second importance judgment result corresponding to each column in the second original data according to the first ratio corresponding to each column, the second ratio corresponding to each column and the preset importance calculation formula.
[0017] Furthermore, the second control unit is specifically used to: control the requesting party to obtain the accumulated values corresponding to each column in the first original data, calculate the sum of the products of the accumulated values corresponding to each column in the first original data and the first importance judgment results corresponding to each column in the first original data, and obtain the first data detection result; control the party to be detected to obtain the accumulated values corresponding to each column in the second original data, calculate the sum of the products of the accumulated values corresponding to each column in the second original data and the second importance judgment results corresponding to each column in the second original data, and obtain the second data detection result.
[0018] Furthermore, the detection unit is specifically used to: calculate the difference between the first data detection result and the second data detection result, and calculate the ratio between the difference and the first data detection result to obtain a target ratio; obtain a data theft detection result based on the target ratio and a preset data theft detection classification standard.
[0019] Furthermore, the device also includes: a generation unit, used to generate a proof about the first original data, the second original data and the process of obtaining the data theft detection result according to a preset zero-knowledge proof algorithm; a proof unit, used to confirm that the data theft detection result is a true result if the verification of the proof is successful; or, the device is also specifically used to: execute a data theft detection process under privacy computing in a trusted execution environment; wherein, the data theft detection process under privacy computing at least includes the process of obtaining the first original data, the second original data and the data theft detection result.
[0020] In a fourth aspect, an embodiment of the present application provides a device comprising a processor, a memory, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the method of the first or second aspect described above is implemented.
[0021] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the method of the first or second aspect mentioned above.
[0022] In an embodiment of the present application, in the first aspect, the detecting party responds to a data theft detection request, obtains the first original data provided by the requesting party, the hash value corresponding to the first original data stored on the chain, the second original data provided by the party to be detected, and the hash value corresponding to the second original data stored on the chain; based on the hash value corresponding to the first original data and the hash value corresponding to the second original data, the first original data provided by the requesting party and the second original data provided by the party to be detected are verified respectively. Verification by hash value can ensure that the data provided here is the data calculated at that time, and avoid the theft party providing false data for calculation. If the verification is successful, the detecting party obtains the first importance determination benchmark and the first importance determination result stored on the chain, and controls the party to be detected to calculate the second importance determination result based on the second original data and the first importance determination benchmark, wherein the first importance determination benchmark and the first importance determination result are the importance determination benchmark and the importance determination result corresponding to the first original data. Afterwards, the requesting party is controlled to calculate the first data detection result based on the first original data and the first importance determination result, and the party to be detected is controlled to calculate the second data detection result based on the second original data and the second importance determination result. Since the first importance determination benchmark is based on The columns of data in the first original data are generated, and therefore, the value of the first importance determination result obtained according to the first importance determination criterion will not be very low. Here, the control test party uses the first importance determination criterion to calculate the second importance determination result. If there is plagiarized data in the second original data, then the second importance determination result corresponding to the plagiarized data in the second original data will not be very low. Then, the first data detection result and the first data detection result obtained by calculation can be used to detect data theft. The above method solves the problem that data theft is difficult to detect under privacy computing, and ensures data sovereignty in privacy computing.
[0023] Secondly, in order to realize data theft detection, when publishing data, it is necessary to obtain the data owner information, the data to be published, the data metadata corresponding to the data to be published, and the hash value corresponding to the data to be published; according to the data to be published and the preset importance judgment benchmark generation rules, the importance judgment benchmark corresponding to the data to be published is generated; then, according to the data to be published and the importance judgment benchmark corresponding to the data to be published, the importance judgment result corresponding to the data to be published is calculated; thereafter, according to the data owner information, the data metadata corresponding to the data to be published, the hash value corresponding to the data to be published, the importance judgment benchmark corresponding to the data to be published, and the importance judgment result corresponding to the data to be published, a data publishing request is generated and sent to the above-mentioned detection party; wherein, if the data to be published is designated as the above-mentioned first original data, the first importance judgment benchmark and the first importance judgment result stored on the chain described in the first aspect are the importance judgment benchmark corresponding to the data to be published and the importance judgment result corresponding to the data to be published. By publishing the data metadata corresponding to the data to be released, the security of the data can be guaranteed and the purchaser can understand the approximate content of the data. The hash value corresponding to the data to be released can be published, which can be used to verify the data before theft detection. In addition, the importance judgment benchmark corresponding to the data to be released and the importance judgment result corresponding to the data to be released can be published, which can be used to implement the data theft detection method of the first aspect and provide a data basis for data theft detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments or descriptions of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0025] Figure 1 This is a schematic flow chart of a data theft detection method under privacy computing provided by the first embodiment of the present application;
[0026] Figure 2 This is another schematic flow chart of a data theft detection method under privacy computing provided by the first embodiment of the present application;
[0027] Figure 3 This is a schematic flow chart of step S104 in a data theft detection method under privacy computing provided in the first embodiment of the present application;
[0028] Figure 4 This is a schematic flow chart of step S105 in a data theft detection method under privacy computing provided in the first embodiment of the present application;
[0029] Figure 5 This is a schematic flow chart of a data publishing method under privacy computing provided in the second embodiment of the present application;
[0030] Figure 6 This is a schematic flow chart of S202 in a data publishing method under privacy computing provided in the second embodiment of the present application;
[0031] Figure 7 This is a schematic flow chart of S203 in a data publishing method under privacy computing provided in the second embodiment of the present application;
[0032] Figure 8 is a schematic diagram of a data theft detection device under privacy computing provided by the third embodiment of the present application;
[0033] Figure 9 2 is a schematic diagram of a data theft detection device under privacy computing provided by the fourth embodiment of the present application;
[0034] Figure 10 This is a schematic diagram of the device provided in the fifth embodiment of the present application. DETAILED DESCRIPTION
[0035] In the following description, specific details such as specific system structures and techniques are provided for purposes of illustration rather than limitation to facilitate a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application may be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid obscuring the description of the present application with unnecessary detail.
[0036] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, integers, steps, operations, elements and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or collections thereof.
[0037] It will also be understood that the term "and / or" used in this specification and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.
[0038] As used in this specification and the appended claims, the term "if" can be interpreted as "when" or "upon" or "in response to determining" or "in response to detecting," depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "upon determination" or "in response to determining" or "upon detection of [described condition or event]" or "in response to detecting [described condition or event]," depending on the context.
[0039] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.
[0040] References to "one embodiment" or "some embodiments" in this specification mean that a particular feature, structure, or characteristic described in conjunction with that embodiment is included in one or more embodiments of the present application. Thus, phrases such as "in one embodiment," "in some embodiments," "in other embodiments," and "in other embodiments" appearing in various places in this specification do not necessarily refer to the same embodiment, but rather mean "one or more but not all embodiments," unless otherwise specifically emphasized. The terms "including," "comprising," "having," and variations thereof all mean "including but not limited to," unless otherwise specifically emphasized.
[0041] See Figure 1 , Figure 1 This is a schematic flow chart of a data theft detection method under privacy computing provided by the first embodiment of this application. In this embodiment, the execution subject of a data theft detection method under privacy computing is a detection party, which refers to a device used to implement the data theft detection method under privacy computing. The device can be a server, a server cluster, or a processor, a microprocessor, etc., and is not specifically limited. Figure 1 The data theft detection method under privacy computing shown may include:
[0042] S101: In response to a data theft detection request, obtain first original data provided by the requesting party, a hash value corresponding to the first original data stored on the chain, second original data provided by the party to be detected, and a hash value corresponding to the second original data stored on the chain.
[0043] The detecting party (i.e., the platform supporting data transactions) responds to the requesting party's request for data theft detection, where the data theft detection request needs to specify the requesting party (the party requesting the theft detection), the party to be detected (the party suspected of data theft), and which data to be detected for theft.
[0044] In this embodiment, the requesting party can be specified by the identity information of the requesting party, and the party to be detected can be specified by the identity information of the party to be detected. The data for the theft detection is the first original data and the second original data. The purpose is to detect whether the second original data has stolen the first original data. The first original data is provided by the requesting party, and the second original data is provided by the party to be detected.
[0045] Since data falsification may occur, the detection party also needs to obtain the hash value corresponding to the first original data stored on the chain and the hash value corresponding to the second original data stored on the chain.
[0046] Regardless of the hash value corresponding to any data, it is submitted to the chain when the data is released. The chain can refer to any type of blockchain and is not limited here.
[0047] S102: Verify the first original data provided by the requesting party and the second original data provided by the party to be detected according to the hash value corresponding to the first original data and the hash value corresponding to the second original data.
[0048] If the first original data provided by the requesting party and the second original data provided by the party to be tested are both real data, then the hash value of the first original data provided by the requesting party is recalculated, and the calculation result should be consistent with the hash value corresponding to the first original data stored on the chain. Similarly, the hash value of the second original data provided by the party to be tested is recalculated, and the calculation result should also be consistent with the hash value corresponding to the second original data stored on the chain. If they are consistent, it means that the verification has passed. If they are inconsistent, the real data needs to be re-provided for theft detection.
[0049] S103: If the verification is successful, obtain the first importance judgment criterion and the first importance judgment result stored on the chain, and control the party to be tested to calculate the second importance judgment result based on the second original data and the first importance judgment criterion; wherein, the first importance judgment criterion and the first importance judgment result are the importance judgment criterion and importance judgment result corresponding to the first original data.
[0050] If the verification is successful, the testing party obtains the first importance determination benchmark and the first importance determination result stored on the chain.
[0051] The first importance determination criterion and the first importance determination result are the importance determination criterion and the importance determination result corresponding to the first original data. The following describes what content needs to be published when publishing data in this embodiment.
[0052] See also Figure 2 , Figure 2 This is another schematic flow chart of a data theft detection method under privacy computing provided by the first embodiment of the present application. Before S101, it includes:
[0053] S106: In response to the data publishing request, obtain the data owner information, the data metadata corresponding to the data to be published, the importance judgment standard corresponding to the data to be published, the importance judgment result corresponding to the data to be published, and the hash value corresponding to the data to be published.
[0054] S107: Publish the data owner information, the data metadata corresponding to the data to be released, the importance judgment criteria corresponding to the data to be released, the importance judgment result corresponding to the data to be released, and the hash value corresponding to the data to be released on the chain.
[0055] No matter which user publishes the data, he or she needs to send a data publishing request to the platform. The platform here is also the aforementioned detection party. Here, the detection party responds to the data publishing request sent by the data owner, obtains the data owner information, the data metadata corresponding to the data to be published, the importance judgment standard corresponding to the data to be published, the importance judgment result corresponding to the data to be published, and the hash value corresponding to the data to be published.
[0056] The data owner information is used to indicate to which user the data to be published belongs.
[0057] To ensure the security of the data, the data metadata corresponding to the data to be released will be extracted and released instead of the complete data. This process allows the buyer to understand the general content of the data.
[0058] Data metadata includes, but is not limited to, data field information and data description information. For example, if the data to be published is employee salary data, the data metadata may include numeric field information (such as name, social security, provident fund, and actual salary), as well as description information about the employee's salary data. The above is only an example and is not intended to be limiting.
[0059] The hash value corresponding to the data to be published can be used to verify the authenticity of the data, as explained in steps S101 to S102.
[0060] After being published on the chain, the importance determination criteria and the importance determination results corresponding to the data to be released can be used to detect data theft. How the data owner calculates the importance determination criteria and the importance determination results corresponding to the data to be released has been fully described in the second embodiment, so please refer to the second embodiment. It should be clarified here that after the importance determination criteria and the importance determination results corresponding to the data to be released are published on the chain, the detection party can call them from the chain when needed.
[0061] As described in step S103, after the detection unit obtains the first importance judgment criterion and the first importance judgment result stored on the chain, the detection unit controls the detected party to calculate the second importance judgment result based on the second original data and the first importance judgment criterion.
[0062] Since the first importance determination criterion is generated based on the data in each column of the first original data, the value of the first importance determination result obtained according to the first importance determination criterion will not be very low. Here, the control test party uses the first importance determination criterion to calculate the second importance determination result. If there is plagiarized data in the second original data, then the second importance determination result corresponding to the plagiarized data in the second original data will not be very low.
[0063] Specifically, the party to be tested is controlled to divide the second original data into first category data and second category data according to the median of the first importance judgment criterion; the ratio between the number of first category data corresponding to each column in the second original data and the total number of first category data is calculated to obtain the first ratio corresponding to each column; the ratio between the number of second category data corresponding to each column in the second original data and the total number of second category data is calculated to obtain the second ratio corresponding to each column; according to the first ratio corresponding to each column, the second ratio corresponding to each column and the preset importance calculation formula, the second importance judgment result corresponding to each column in the second original data is obtained.
[0064] The first original data is represented as V1, which can be understood as a matrix containing n1 columns of data, namely v 1 1,...,v 1 n1 , n1 is a positive integer.
[0065] The first importance judgment criterion is expressed as v 1 n1+1 , v 1 n1+1 is a vector whose dimension is the same as the dimension of each column vector in the first original data. m1 is used to represent the dimension of the vector, and m1 is a positive integer.
[0066] Here, v 1 1,...,v 1 n1 and v 1 n1+1 The superscript 1 in the numerals is only used to indicate that these data are related to the first original data and has no other limiting effect.
[0067] The party to be tested needs to first obtain the median of the first importance judgment benchmark, that is, take v 1 n1+1The median of all data in the second original data is then used to divide the second original data into the first category and the second category. Data greater than the median are classified as the first category, and data not greater than the median are classified as the second category.
[0068] The party to be detected calculates the ratio between the quantity of the first category data corresponding to each column in the second original data and the total quantity of the first category data to obtain a first ratio corresponding to each column.
[0069] In this embodiment, the first ratio corresponding to the i-th column in the second original data is expressed as R 2 _i.
[0070] The party to be detected calculates the ratio between the quantity of the second type of data corresponding to each column in the second original data and the total quantity of the second type of data to obtain a second ratio corresponding to each column.
[0071] In this embodiment, the second ratio corresponding to the i-th column in the second original data is expressed as K 2 _i.
[0072] The party to be detected obtains a second importance judgment result corresponding to each column in the second original data according to the first ratio corresponding to each column, the second ratio corresponding to each column, and a preset importance calculation formula.
[0073] The preset importance calculation formula is expressed as IM i =(R_i-K_i)*WOE_i, WOE_i=R_i / K_i.
[0074] In this embodiment, the second importance judgment result corresponding to the i-th column in the second original data is expressed as IM i 2 , IM i 2 =(R 2 _i-K 2 _i)*WOE 2 _i
[0075] WOE 2 _i=R 2 _i / K 2 _i.
[0076] Among them, IM i 2 、R 2 _i, K 2 _i and WOE 2 The superscript 2 in _i is used to indicate that these data are related to the second original data and has no other limiting effect.
[0077] S104: The control requesting party calculates a first data detection result based on the first original data and the first importance determination result, and controls the party to be detected to calculate a second data detection result based on the second original data and the second importance determination result.
[0078] The detecting party controls the requesting party to calculate and obtain a first data detection result based on the first original data and the first importance determination result.
[0079] The detecting party controls the party to be detected to calculate and obtain a second data detection result based on the second original data and the second importance determination result.
[0080] The first importance determination result includes the first importance determination result corresponding to each column in the first original data, and the second importance determination result includes the second importance determination result corresponding to each column in the second original data. Figure 3 , Figure 3 This is a schematic flow chart of step S104 in a data theft detection method under privacy computing provided in the first embodiment of the present application. S104 includes:
[0081] S1041: The control requesting party obtains the accumulated values corresponding to each column in the first original data, calculates the sum of the products of the accumulated values corresponding to each column in the first original data and the first importance determination results corresponding to each column in the first original data, and obtains the first data detection result.
[0082] The requesting party accumulates the data in the same column of the first original data to obtain accumulated values corresponding to each column.
[0083] The accumulated values corresponding to each column in the first original data are expressed as
[0084] in, represents the data in the i-th column and j-th row in the first original data V1, and m1 represents the number of rows of the first original data V1.
[0085] The requesting party calculates the sum of the products of the accumulated values corresponding to each column in the first original data and the first importance determination results corresponding to each column in the first original data to obtain a first data detection result.
[0086] The first data detection result is represented as S1,
[0087] The first importance judgment result corresponding to the i-th column in the first original data V1 is expressed as IM i 1 , n1 represents the number of columns of the first original data V1.
[0088] IM i 1The 1 in is a superscript to distinguish the first importance judgment result from the second importance judgment result, and it has no special meaning.
[0089] S1042: Control the party to be detected to obtain the accumulated values corresponding to each column in the second original data, calculate the sum of the products of the accumulated values corresponding to each column in the second original data and the second importance judgment results corresponding to each column in the second original data, and obtain the second data detection result.
[0090] The party to be detected accumulates the data in the same column of the second original data to obtain accumulated values corresponding to each column.
[0091] The accumulated values corresponding to each column in the second original data are expressed as
[0092] in, represents the data in the i-th column and j-th row in the second original data V2, and m1 represents the number of rows of the second original data V2.
[0093] The requesting party calculates the sum of the products of the accumulated values corresponding to each column in the second original data and the second importance determination results corresponding to each column in the second original data to obtain a second data detection result.
[0094] The second data detection result is represented as S2,
[0095] The second importance judgment result corresponding to the i-th column in the second original data V2 is expressed as IM i 2 , n2 represents the number of columns of the second original data V2.
[0096] S105: Obtain a data theft detection result according to the first data detection result and the second data detection result.
[0097] The detecting party obtains a data theft detection result based on the first data detection result S1 and the second data detection result S2.
[0098] In an optional embodiment, if the first data detection result S1 is close to the second data detection result S2, it means that the data theft detection result is that data theft is confirmed to have occurred.
[0099] In another alternative embodiment, see Figure 4 , Figure 4 This is a schematic flow chart of step S105 in a data theft detection method under privacy computing provided in the first embodiment of the present application. S105 includes:
[0100] S1051: Calculate the difference between the first data detection result and the second data detection result, and calculate the ratio between the difference and the first data detection result to obtain a target ratio.
[0101] The target ratio is expressed as The first data detection result is represented as S1, and the second data detection result is represented as S2. It can be understood that the 1 in S1 and the 2 in S2 are marks to distinguish the first data detection result from the second data detection result, and they have no special meaning.
[0102] S1052: Obtaining a data theft detection result according to the target ratio and a preset data theft detection classification standard.
[0103] The detection party obtains a data theft detection result based on the target ratio and a preset data theft detection classification standard. In one optional embodiment, the preset data theft detection classification standard may include a single classification standard for determining whether the data has been stolen or not. In another optional embodiment, the preset data theft detection classification standard may also include multiple classification standards for determining whether the data has been stolen in full, in part, or not.
[0104] In an optional embodiment, in order to prevent the detection party from tampering with the original data and intervening in the data theft detection process, thereby affecting the authenticity of the data theft detection result, the method also includes: generating a proof of the first original data, the second original data and the process of obtaining the data theft detection result according to a preset zero-knowledge proof algorithm; if the verification of the proof is successful, the data theft detection result is confirmed to be a true result.
[0105] That is, in this embodiment, a certificate is generated for the process of obtaining the first original data, the process of obtaining the second original data, and the process of obtaining the data theft detection result.
[0106] Among them, the process of obtaining data theft detection results can also be understood as the execution process of the data theft detection method under privacy computing.
[0107] This proof is generated based on the existing zero-knowledge proof algorithm, and the specific generation process of the proof will not be described in detail here.
[0108] Afterwards, the certificate will be verified. If the verification is successful, it can be confirmed that the detection party did not perform any malicious behavior during the process of obtaining the first original data and the first original data and the execution of the data theft detection method. Therefore, it can be ensured that the data theft detection result is a true result.
[0109] In another optional embodiment, the data theft detection process under privacy computing can also be performed in a trusted execution environment, which can also prevent the detecting party from tampering with the original data and intervening in the data theft detection process, thereby affecting the authenticity of the data theft detection results.
[0110] It can be understood that the data theft detection process under privacy computing at least includes the process of obtaining the first original data, the second original data and the data theft detection result.
[0111] In an embodiment of the present application, the detecting party obtains the first original data provided by the requesting party, the hash value corresponding to the first original data stored on the chain, the second original data provided by the party to be detected, and the hash value corresponding to the second original data stored on the chain in response to the data theft detection request; and verifies the first original data provided by the requesting party and the second original data provided by the party to be detected according to the hash value corresponding to the first original data and the hash value corresponding to the second original data. Verification by hash value can ensure that the data provided here is the data calculated at that time, and avoid the theft party providing false data for calculation. If the verification is successful, the detecting party obtains the first importance determination benchmark and the first importance determination result stored on the chain, and controls the party to be detected to calculate the second importance determination result according to the second original data and the first importance determination benchmark, wherein the first importance determination benchmark and the first importance determination result are the importance determination benchmark and the importance determination result corresponding to the first original data. Afterwards, the requesting party is controlled to calculate the first data detection result according to the first original data and the first importance determination result, and the party to be detected is controlled to calculate the second data detection result according to the second original data and the second importance determination result. Since the first importance determination benchmark is based on The columns of data in the first original data are generated, and therefore, the value of the first importance determination result obtained according to the first importance determination criterion will not be very low. Here, the control test party uses the first importance determination criterion to calculate the second importance determination result. If there is plagiarized data in the second original data, then the second importance determination result corresponding to the plagiarized data in the second original data will not be very low. Then, the first data detection result and the first data detection result obtained by calculation can be used to detect data theft. The above method solves the problem that data theft is difficult to detect under privacy computing, and ensures data sovereignty in privacy computing.
[0112] See Figure 5 , Figure 5 This is a schematic flow chart of a data publishing method under privacy computing provided by the second embodiment of this application. In this embodiment, the execution subject of a data publishing method under privacy computing is a detection party, which refers to a device used to implement the data publishing method under privacy computing. The device can be a server, a server cluster, or a processor, a microprocessor, etc., and is not specifically limited. Figure 5 The data publishing method under the privacy computing shown may include:
[0113] S201: Acquire data owner information, data to be published, data metadata corresponding to the data to be published, and a hash value corresponding to the data to be published.
[0114] In order to publish data, the data owner needs to prepare the data owner information, the data to be published, the data metadata corresponding to the data to be published, and the hash value corresponding to the data to be published.
[0115] The data owner information may be the identity information of the data owner, which is used to indicate which user currently needs to publish the data.
[0116] The data metadata corresponding to the data to be published and the hash value corresponding to the data to be published have been described in the first embodiment and will not be repeated here.
[0117] S202: Generate an importance determination criterion corresponding to the data to be published according to the data to be published and a preset importance determination criterion generation rule.
[0118] In order to detect data theft, the data owner needs to provide a benchmark for determining the importance of the data to be released when releasing the data.
[0119] Specifically, the data owner generates an importance determination criterion corresponding to the data to be released based on the data to be released and preset importance determination criterion generation rules.
[0120] The preset importance judgment benchmark generation rule is used to generate a corresponding importance judgment benchmark for the data to be released. The importance judgment benchmark is generated based on each column of data in the data to be released.
[0121] See also Figure 6 , Figure 6 This is a schematic flow chart of S202 in a data publishing method under privacy computing provided in the second embodiment of the present application. S202 includes:
[0122] S2021: Obtain a random number corresponding to each column in the data to be published; wherein the random number is within a preset value range.
[0123] In this embodiment, the data to be published is represented by V, which is a matrix including n columns of data, namely v1,...,v n , n is a positive integer.
[0124] Since the data to be published contains n columns of data, n random data are generated, which are the random numbers corresponding to each column. To avoid reducing the importance of some columns, it is necessary to ensure that the random numbers are within a preset value range, which is not limited here.
[0125] The random numbers corresponding to each column are represented as r1,...,r n.
[0126] S2022: Calculate the sum of the products of each column of data in the data to be published and the random numbers corresponding to each column in the data to be published to obtain a first reference vector.
[0127] The data owner calculates the data columns v1,...,v in the data to be released n The random numbers r1,...,r corresponding to each column in the data to be released n The sum of the products of
[0128] S2023: Generate a second reference vector according to the value range corresponding to the first reference vector.
[0129] The data owner generates a second reference vector according to the value range corresponding to the first reference vector.
[0130] The value range corresponding to the first reference vector refers to the minimum value to the maximum value of all data in the first reference vector, which is expressed as [minT, maxT].
[0131] According to the value range [minT, maxT] corresponding to the first reference vector, a second reference vector is generated, and the values of all data in the second reference vector are within the value range [minT, maxT] corresponding to the first reference vector.
[0132] The second reference vector is denoted as R, R∈[minT,maxT].
[0133] S2024: Generate an importance determination criterion corresponding to the data to be released based on the value range corresponding to the second reference vector.
[0134] The data owner generates an importance determination criterion corresponding to the data to be released based on the value range corresponding to the second reference vector.
[0135] The importance judgment benchmark corresponding to the data to be released is expressed as v n+1 , v n+1 All data values in are within the value range corresponding to the second reference vector R.
[0136] The value range corresponding to the second reference vector R refers to the minimum value to the maximum value of all data in the second reference vector R.
[0137] S203: Calculate the importance determination result corresponding to the data to be released based on the data to be released and the importance determination criterion corresponding to the data to be released.
[0138] The data owner calculates the importance determination result of the data to be released based on the data to be released and the importance determination benchmark corresponding to the data to be released.
[0139] See also Figure 7 , Figure 7 This is a schematic flow chart of S203 in a data publishing method under privacy computing provided in the second embodiment of the present application. S203 includes:
[0140] S2031: Obtain the median of the importance judgment criteria corresponding to the data to be released.
[0141] The data owner obtains the median of the importance judgment criteria corresponding to the data to be released, that is, take v n+1 The median of all data in .
[0142] S2032: Divide the data to be released into first category data and second category data according to the median of the importance judgment criteria corresponding to the data to be released.
[0143] The data owner classifies the data to be released into Category I and Category II based on the median of the importance criteria corresponding to the data to be released. Data with a value greater than the median is classified as Category I, and data with a value not greater than the median is classified as Category II.
[0144] S2033: Calculate the ratio between the quantity of the first category data corresponding to each column in the data to be published and the total quantity of the first category data to obtain a first ratio corresponding to each column.
[0145] The data owner calculates the ratio between the quantity of the first category data corresponding to each column in the data to be released and the total quantity of the first category data to obtain a first ratio corresponding to each column.
[0146] In this embodiment, the first ratio corresponding to the i-th column in the data to be published is expressed as R_i.
[0147] S2034: Calculate the ratio between the quantity of the second category data corresponding to each column in the data to be published and the total quantity of the second category data to obtain a second ratio corresponding to each column.
[0148] The data owner calculates the ratio between the quantity of the second category data corresponding to each column in the data to be released and the total quantity of the second category data to obtain a second ratio corresponding to each column.
[0149] In this embodiment, the second ratio corresponding to the i-th column in the data to be published is expressed as K_i.
[0150] S2035: Obtain the importance judgment result corresponding to the data to be released according to the first ratio corresponding to each column, the second ratio corresponding to each column, and a preset importance calculation formula.
[0151] The data owner obtains the importance judgment result corresponding to the data to be released based on the first ratio R_i corresponding to each column, the second ratio K_i corresponding to each column, and a preset importance calculation formula.
[0152] The preset importance calculation formula is expressed as IM i =(R_i-K_i)*WOE_i, WOE_i=R_i / K_i.
[0153] The importance judgment result of the data to be released is expressed as IM, IM={IM1,IM2,...,IM n}Includes the importance judgment results corresponding to each column in the data to be released, and the importance judgment result IM corresponding to the i-th column i .
[0154] S204: Generate and send a data publishing request to the execution subject of the data theft detection method of the first embodiment based on the data owner information, the data metadata corresponding to the data to be published, the hash value corresponding to the data to be published, the importance determination criterion corresponding to the data to be published, and the importance determination result corresponding to the data to be published; wherein, if the data to be published is designated as the first original data, then the first importance determination criterion and the first importance determination result stored on the chain in the data theft detection method of the first embodiment are the importance determination criterion and the importance determination result corresponding to the data to be published.
[0155] The data owner generates and sends a data release request to the execution entity of the data theft detection method of the first embodiment based on the data owner information, the data metadata corresponding to the data to be released, the hash value corresponding to the data to be released, the importance judgment criterion corresponding to the data to be released, and the importance judgment result corresponding to the data to be released, that is, generates and sends a data release request to the detection party in the first embodiment (that is, the platform party that supports data transactions).
[0156] Here, if the data to be released is designated as the first original data, it can be understood that the first importance determination criterion and the first importance determination result stored on the chain in the data theft detection method of the first embodiment are the importance determination criterion and the importance determination result corresponding to the data to be released in this embodiment.
[0157] In an embodiment of the present application, in order to realize data theft detection, when publishing data, it is necessary to obtain the data owner information, the data to be published, the data metadata corresponding to the data to be published, and the hash value corresponding to the data to be published; according to the data to be published and the preset importance judgment benchmark generation rules, the importance judgment base corresponding to the data to be published is generated; and then, according to the data to be published and the importance judgment benchmark corresponding to the data to be published, the importance judgment result corresponding to the data to be published is calculated; thereafter, according to the data owner information, the data metadata corresponding to the data to be published, the hash value corresponding to the data to be published, the importance judgment benchmark corresponding to the data to be published, and the importance judgment result corresponding to the data to be published, a data publishing request is generated and sent to the above-mentioned detection party; wherein, if the data to be published is designated as the above-mentioned first original data, the first importance judgment benchmark and the first importance judgment result stored on the chain described in the first embodiment are the importance judgment benchmark corresponding to the data to be published and the importance judgment result corresponding to the data to be published. By publishing the data metadata corresponding to the data to be released, the security of the data can be guaranteed and the purchaser can understand the approximate content of the data. The hash value corresponding to the data to be released can be published, which can be used to verify the data before theft detection. In addition, the importance judgment benchmark corresponding to the data to be released and the importance judgment result corresponding to the data to be released can be published, which can be used to implement the data theft detection method of the first embodiment and provide a data basis for data theft detection.
[0158] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0159] See Figure 8 , Figure 8 This is a schematic diagram of a data theft detection device under privacy computing provided by the third embodiment of the present application. The units included are used to perform Figure 1 Each step in the corresponding embodiment. Please refer to Figure 1 For the convenience of explanation, only the parts related to this embodiment are shown. Figure 8 , the data theft detection device 8 under privacy computing includes:
[0160] A response unit 81 is configured to respond to a data theft detection request by obtaining first original data provided by the requesting party, a hash value corresponding to the first original data stored on the chain, second original data provided by the party to be detected, and a hash value corresponding to the second original data stored on the chain;
[0161] A verification unit 82, configured to verify the first original data provided by the requesting party and the second original data provided by the party to be detected, respectively, based on a hash value corresponding to the first original data and a hash value corresponding to the second original data;
[0162] The first control unit 83 is configured to, if the verification passes, obtain the first importance determination criterion and the first importance determination result stored on the chain, and control the party to be tested to calculate the second importance determination result based on the second original data and the first importance determination criterion; wherein the first importance determination criterion and the first importance determination result are the importance determination criterion and the first importance determination result corresponding to the first original data;
[0163] A second control unit 84 is configured to control the requesting party to calculate a first data detection result based on the first original data and the first importance determination result, and to control the party to be detected to calculate a second data detection result based on the second original data and the second importance determination result;
[0164] The detection unit 85 is configured to obtain a data theft detection result based on the first data detection result and the second data detection result.
[0165] Furthermore, the device 8 also includes: an acquisition unit, which is used to obtain the data owner information, the data metadata corresponding to the data to be released, the importance judgment standard corresponding to the data to be released, the importance judgment result corresponding to the data to be released, and the hash value corresponding to the data to be released in response to the data release request; and a release unit, which is used to publish the data owner information, the data metadata corresponding to the data to be released, the importance judgment standard corresponding to the data to be released, the importance judgment result corresponding to the data to be released, and the hash value corresponding to the data to be released on the chain.
[0166] Furthermore, the first control unit 83 is specifically used to: control the party to be detected to divide the second original data into first category data and second category data according to the median of the first importance judgment criterion; calculate the ratio between the number of first category data corresponding to each column in the second original data and the total number of first category data to obtain the first ratio corresponding to each column; calculate the ratio between the number of second category data corresponding to each column in the second original data and the total number of second category data to obtain the second ratio corresponding to each column; obtain the second importance judgment result corresponding to each column in the second original data according to the first ratio corresponding to each column, the second ratio corresponding to each column and the preset importance calculation formula.
[0167] Furthermore, the second control unit 84 is specifically used to: control the requesting party to obtain the accumulated values corresponding to each column in the first original data, calculate the sum of the products of the accumulated values corresponding to each column in the first original data and the first importance judgment results corresponding to each column in the first original data, and obtain the first data detection result; control the party to be detected to obtain the accumulated values corresponding to each column in the second original data, calculate the sum of the products of the accumulated values corresponding to each column in the second original data and the second importance judgment results corresponding to each column in the second original data, and obtain the second data detection result.
[0168] Furthermore, the detection unit 85 is specifically used to: calculate the difference between the first data detection result and the second data detection result, and calculate the ratio between the difference and the first data detection result to obtain a target ratio; and obtain a data theft detection result based on the target ratio and a preset data theft detection classification standard.
[0169] See Figure 9 , Figure 9 This is a schematic diagram of a data theft detection device under privacy computing provided by the fourth embodiment of the present application. The units included are used to perform Figure 2 Each step in the corresponding embodiment. Please refer to Figure 2 For the convenience of explanation, only the parts related to this embodiment are shown. Figure 9 , the data publishing device 9 under privacy computing includes:
[0170] An acquisition unit 91 is configured to acquire data owner information, data to be published, data metadata corresponding to the data to be published, and a hash value corresponding to the data to be published;
[0171] An acquisition unit 92 is configured to generate an importance determination criterion corresponding to the data to be released based on the data to be released and a preset importance determination criterion generation rule;
[0172] A calculation unit 93 is configured to calculate an importance determination result corresponding to the data to be released based on the data to be released and the importance determination criterion corresponding to the data to be released;
[0173] The publishing unit 94 is used to generate and send a data publishing request to the execution subject of the data theft detection method of the first embodiment based on the data owner information, the data metadata corresponding to the data to be published, the hash value corresponding to the data to be published, the importance determination criterion corresponding to the data to be published, and the importance determination result corresponding to the data to be published; wherein, if the data to be published is designated as the first original data, the first importance determination criterion and the first importance determination result stored on the chain in the data theft detection method of the first embodiment are the importance determination criterion and the importance determination result corresponding to the data to be published.
[0174] Furthermore, the generation unit 92 is specifically used to: obtain random numbers corresponding to each column in the data to be published; wherein the random numbers are within a preset value range; calculate the sum of the products of each column of data in the data to be published and the random numbers corresponding to each column in the data to be published to obtain a first reference vector; generate a second reference vector based on the value range corresponding to the first reference vector; and generate an importance judgment benchmark corresponding to the data to be published based on the value range corresponding to the second reference vector.
[0175] Furthermore, the calculation unit 93 is specifically used to: obtain the median of the importance judgment criteria corresponding to the data to be released; divide the data to be released into first category data and second category data according to the median of the importance judgment criteria corresponding to the data to be released; calculate the ratio between the number of first category data corresponding to each column in the data to be released and the total number of first category data, and obtain the first ratio corresponding to each column; calculate the ratio between the number of second category data corresponding to each column in the data to be released and the total number of second category data, and obtain the second ratio corresponding to each column; obtain the importance judgment result corresponding to the data to be released according to the first ratio corresponding to each column, the second ratio corresponding to each column and the preset importance calculation formula.
[0176] It should be noted that the information interaction, execution process, etc. between the above-mentioned devices / units are based on the same concept as the method embodiment of this application. Their specific functions and technical effects can be found in the method embodiment section and will not be repeated here.
[0177] See Figure 10 , Figure 10 This is a schematic diagram of the device provided in the fifth embodiment of the present application. Figure 10 As shown, the device 10 of this embodiment includes: a processor 100, a memory 101, and a computer program 102 stored in the memory 101 and executable on the processor 100, such as a data theft detection program under privacy computing or a data publishing program under privacy computing. When the processor 100 executes the computer program 102, the steps in the above-mentioned embodiments of the data theft detection method under privacy computing or the steps in the embodiments of the data publishing method under privacy computing are implemented, such as Figure 1 Steps S101 to S105 shown or Figure 5 Alternatively, when the processor 100 executes the computer program 102, the functions of the modules / units in the above-mentioned device embodiments are realized, for example, Figure 8 The functions of the response unit 81 to the detection unit 85 shown, or Figure 9The functions of the acquisition unit 91 to the publishing unit 94 are shown. Exemplarily, the computer program 102 can be divided into one or more modules / units, and the one or more modules / units are stored in the memory 101 and executed by the processor 100 to complete the present application. The one or more modules / units can be a series of computer program instruction segments that can perform specific functions, and the instruction segments are used to describe the execution process of the computer program 102 in the device 10. For example, the computer program 102 can be divided into a response unit, a verification unit, a first control unit, a second control unit and a detection unit, and the specific functions of each unit are as follows:
[0178] A response unit, configured to, in response to a data theft detection request, obtain first original data provided by the requesting party, a hash value corresponding to the first original data stored on the chain, second original data provided by the party to be detected, and a hash value corresponding to the second original data stored on the chain;
[0179] a verification unit, configured to verify the first original data provided by the requesting party and the second original data provided by the party to be detected, respectively, according to a hash value corresponding to the first original data and a hash value corresponding to the second original data;
[0180] A first control unit is configured to, if verification is successful, obtain the first importance determination criterion and the first importance determination result stored on the chain, and control the detected party to calculate a second importance determination result based on the second original data and the first importance determination criterion; wherein the first importance determination criterion and the first importance determination result are the importance determination criterion and the importance determination result corresponding to the first original data;
[0181] a second control unit, configured to control the requesting party to calculate a first data detection result based on the first original data and the first importance determination result, and control the party to be detected to calculate a second data detection result based on the second original data and the second importance determination result;
[0182] The detection unit is configured to obtain a data theft detection result based on the first data detection result and the second data detection result.
[0183] For another example, the computer program 102 may be divided into an acquisition unit, a generation unit, a calculation unit, and a publishing unit, and the specific functions of each unit are as follows:
[0184] An acquisition unit, configured to acquire data owner information, data to be published, data metadata corresponding to the data to be published, and a hash value corresponding to the data to be published;
[0185] A generating unit, configured to generate an importance determination criterion corresponding to the data to be released according to the data to be released and a preset importance determination criterion generating rule;
[0186] a calculation unit, configured to calculate an importance determination result corresponding to the data to be published based on the data to be published and an importance determination criterion corresponding to the data to be published;
[0187] A publishing unit is used to generate and send a data publishing request to the execution subject of the data theft detection method of the first embodiment based on the data owner information, the data metadata corresponding to the data to be published, the hash value corresponding to the data to be published, the importance determination criterion corresponding to the data to be published, and the importance determination result corresponding to the data to be published; wherein, if the data to be published is designated as the first original data, then the first importance determination criterion and the first importance determination result stored on the chain in the data theft detection method of the first embodiment are the importance determination criterion and the importance determination result corresponding to the data to be published.
[0188] The device 10 may include, but is not limited to, a processor 100 and a memory 101. Those skilled in the art will appreciate that Figure 10 This is merely an example of the device 10 and does not constitute a limitation on the device 10. The device 10 may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, the device 10 may also include input and output devices, network access devices, buses, etc.
[0189] The processor 100 may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.
[0190] The memory 101 may be an internal storage unit of the device 10, such as a hard disk or memory of the device 10. The memory 101 may also be an external storage device of the device 10, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. equipped on the device 10. Furthermore, the device 10 may include both an internal storage unit of the device 10 and an external storage device. The memory 101 is used to store the computer program and other programs and data required by the device 10. The memory 101 may also be used to temporarily store data that has been output or is about to be output.
[0191] An embodiment of the present application also provides a network device, which includes: at least one processor, a memory, and a computer program stored in the memory and executable on the at least one processor, wherein the processor implements the steps of any of the above-mentioned method embodiments when executing the computer program.
[0192] An embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in the above-mentioned various method embodiments can be implemented.
[0193] An embodiment of the present application provides a computer program product. When the computer program product is run on a mobile terminal, the mobile terminal can implement the steps in the above-mentioned various method embodiments when executing the computer program product.
[0194] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the process of the above-mentioned method embodiment by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, it can implement the steps of each of the above-mentioned method embodiments. The computer program includes computer program code, which can be in source code form, object code form, executable file, or some intermediate form. The computer-readable medium can at least include: any entity or device capable of carrying computer program code to the camera / terminal device, recording medium, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal, and software distribution medium. For example, a USB flash drive, mobile hard drive, magnetic disk, or optical disk. In some jurisdictions, according to legislation and patent practice, computer-readable media cannot be electric carrier signals or telecommunication signals.
[0195] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.
[0196] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0197] In the embodiments provided in this application, it should be understood that the disclosed devices / network equipment and methods can be implemented in other ways. For example, the device / network equipment embodiments described above are merely illustrative. For example, the division of the modules or units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0198] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0199] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the scope of protection of the present application.
Claims
1. A data theft detection method based on privacy computing, characterized in that: Performed by the testing party, including: In response to a data theft detection request, obtain the first original data provided by the requesting party, the hash value corresponding to the first original data stored on the chain, the second original data provided by the party to be detected, and the hash value corresponding to the second original data stored on the chain; Verifying the first original data provided by the requesting party and the second original data provided by the party to be detected, respectively, according to the hash value corresponding to the first original data and the hash value corresponding to the second original data; If the verification is successful, the first importance determination criterion and the first importance determination result stored on the chain are obtained, and the party to be tested is controlled to calculate the second importance determination result based on the second original data and the first importance determination criterion; wherein the first importance determination criterion and the first importance determination result are the importance determination criterion and the importance determination result corresponding to the first original data; Controlling the requesting party to calculate a first data detection result based on the first original data and the first importance determination result, and controlling the party to be detected to calculate a second data detection result based on the second original data and the second importance determination result; A data theft detection result is obtained according to the first data detection result and the second data detection result.
2. The data theft detection method under privacy computing as claimed in claim 1, characterized in that: Before responding to the data theft detection request, the method includes: In response to a data publishing request, obtain data owner information, data metadata corresponding to the data to be published, an importance determination criterion corresponding to the data to be published, an importance determination result corresponding to the data to be published, and a hash value corresponding to the data to be published; The data owner information, the data metadata corresponding to the data to be released, the importance judgment standard corresponding to the data to be released, the importance judgment result corresponding to the data to be released, and the hash value corresponding to the data to be released are published on the chain.
3. The data theft detection method under privacy computing according to claim 1 or 2, characterized in that: The controlling the detected party to calculate a second importance determination result based on the second original data and the first importance determination criterion includes: Control the party to be detected to divide the second original data into first category data and second category data according to the median of the first importance judgment criterion; calculate the ratio between the number of first category data corresponding to each column in the second original data and the total number of first category data to obtain the first ratio corresponding to each column; calculate the ratio between the number of second category data corresponding to each column in the second original data and the total number of second category data to obtain the second ratio corresponding to each column; obtain the second importance judgment result corresponding to each column in the second original data according to the first ratio corresponding to each column, the second ratio corresponding to each column and the preset importance calculation formula.
4. The data theft detection method under privacy computing according to claim 1 or 2, characterized in that: The first importance determination result includes a first importance determination result corresponding to each column in the first original data, and the second importance determination result includes a second importance determination result corresponding to each column in the second original data; The controlling the requesting party to calculate a first data detection result based on the first original data and the first importance determination result, and controlling the party to be detected to calculate a second data detection result based on the second original data and the second importance determination result, includes: Controlling the requesting party to obtain the accumulated values corresponding to each column in the first original data, calculating the sum of the products of the accumulated values corresponding to each column in the first original data and the first importance determination results corresponding to each column in the first original data, to obtain the first data detection result; Control the party to be detected to obtain the accumulated values corresponding to each column in the second original data, calculate the sum of the products of the accumulated values corresponding to each column in the second original data and the second importance judgment results corresponding to each column in the second original data, and obtain the second data detection result.
5. The data theft detection method under privacy computing according to claim 1 or 2, characterized in that: Obtaining a data theft detection result based on the first data detection result and the second data detection result includes: Calculating a difference between the first data detection result and the second data detection result, and calculating a ratio between the difference and the first data detection result to obtain a target ratio; The data theft detection result is obtained according to the target ratio and a preset data theft detection classification standard.
6. The data theft detection method under privacy computing according to claim 1 or 2, characterized in that: Also includes: Generate, according to a preset zero-knowledge proof algorithm, a proof of the first original data, the second original data, and the process of obtaining the data theft detection result; If the verification of the certificate is successful, the data theft detection result is confirmed to be a true result; or, A data theft detection process under privacy computing is performed in a trusted execution environment; wherein the data theft detection process under privacy computing at least includes a process of obtaining the first original data, the second original data and the data theft detection result.
7. A data publishing method under privacy computing, characterized in that: Performed by the data owner, including: Obtaining data owner information, data to be published, data metadata corresponding to the data to be published, and a hash value corresponding to the data to be published; Generate an importance determination criterion corresponding to the data to be released according to the data to be released and a preset importance determination criterion generation rule; Calculating the importance determination result corresponding to the data to be released based on the data to be released and the importance determination benchmark corresponding to the data to be released; Based on the data owner information, the data metadata corresponding to the data to be released, the hash value corresponding to the data to be released, the importance determination criterion corresponding to the data to be released, and the importance determination result corresponding to the data to be released, a data release request is generated and sent to the execution entity of the data theft detection method described in any one of claims 1 to 6; wherein, if the data to be released is designated as the first original data, the first importance determination criterion and the first importance determination result stored on the chain in the data theft detection method described in any one of claims 1 to 6 are the importance determination criterion corresponding to the data to be released and the importance determination result corresponding to the data to be released.
8. The data publishing method under privacy computing according to claim 7, characterized in that: Generating the importance determination criterion corresponding to the data to be released according to the data to be released and a preset importance determination criterion generation rule includes: Obtaining a random number corresponding to each column in the data to be published; wherein the random number is within a preset value range; Calculating the sum of products of each column of data in the data to be published and the random numbers corresponding to each column in the data to be published to obtain a first reference vector; generating a second reference vector according to a value range corresponding to the first reference vector; An importance determination criterion corresponding to the data to be released is generated according to a value range corresponding to the second reference vector.
9. The data publishing method under privacy computing according to claim 7, characterized in that: The calculating, based on the data to be released and the importance determination benchmark corresponding to the data to be released, to obtain the importance determination result corresponding to the data to be released includes: Obtaining the median of the importance determination criteria corresponding to the data to be released; Classify the data to be released into first category data and second category data according to the median of the importance determination criteria corresponding to the data to be released; Calculating the ratio between the quantity of the first category data corresponding to each column in the data to be published and the total quantity of the first category data to obtain a first ratio corresponding to each column; Calculating the ratio between the quantity of the second category data corresponding to each column in the data to be published and the total quantity of the second category data to obtain a second ratio corresponding to each column; According to the first ratios corresponding to the columns, the second ratios corresponding to the columns, and a preset importance calculation formula, an importance judgment result corresponding to the data to be released is obtained.
10. A data theft detection device under privacy computing, characterized in that: include: A response unit, configured to, in response to a data theft detection request, obtain first original data provided by the requesting party, a hash value corresponding to the first original data stored on the chain, second original data provided by the party to be detected, and a hash value corresponding to the second original data stored on the chain; a verification unit, configured to verify the first original data provided by the requesting party and the second original data provided by the party to be detected, respectively, according to a hash value corresponding to the first original data and a hash value corresponding to the second original data; A first control unit is configured to, if the verification is successful, obtain a first importance determination criterion and a first importance determination result stored on the chain, and control the detected party to calculate a second importance determination result based on the second original data and the first importance determination criterion; wherein the first importance determination criterion and the first importance determination result are the importance determination criterion and the importance determination result corresponding to the first original data; a second control unit, configured to control the requesting party to calculate a first data detection result based on the first original data and the first importance determination result, and control the party to be detected to calculate a second data detection result based on the second original data and the second importance determination result; The detection unit is configured to obtain a data theft detection result based on the first data detection result and the second data detection result.
11. A device comprising: A processor, a memory, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 or any one of claims 7 to 9 are implemented.
12. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 6 or any one of claims 7 to 9 is implemented.
Citation Information
Patent Citations
User privacy data storage method and device in social application
CN110278204A
Certificate generation method and device, electronic equipment and storage medium
CN114389810A