Data, financial data security and trusted fusion method and device based on privacy protection

By performing data transformation, encryption, and splitting between the server and participating parties, and utilizing a trusted execution environment for data matching and classification to generate a contribution matrix, the system solves the data security and privacy issues in data fusion across different platforms, thereby improving the accuracy of user profiles and the precision of recommendations.

CN116527335BActive Publication Date: 2026-05-12HANGZHOU NUOWEI INFORMATION TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HANGZHOU NUOWEI INFORMATION TECHNOLOGY CO LTD
Filing Date
2023-04-07
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

In existing technologies, in order to protect data security and privacy, there is little data integration between different platforms, resulting in inaccurate user profiles and less precise recommendations.

Method used

By performing data transformation, encryption, and splitting between the server and participating parties, and using a trusted execution environment for data matching and classification, supplementary, fused, and similar data are generated. Data processing is then performed in an encrypted state to generate a contribution matrix.

Benefits of technology

It achieves data fusion among multiple participants while ensuring data security and privacy, thereby improving data utilization and recommendation accuracy, and reducing the data processing pressure on the server side.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116527335B_ABST
    Figure CN116527335B_ABST
Patent Text Reader

Abstract

The embodiment of the present application relates to a kind of data fusion method and device based on privacy protection, the method comprises: at least from the first trusted execution environment, data conversion scheme and key are sent to at least two participant ends;At least two participant ends send the encrypted submatrix received;At least in the first trusted execution environment, the encrypted submatrix sent by each participant end is matched, and according to the matching result, the encrypted data in the encrypted submatrix is classified, obtains to be supplemented data, to be fused data and similar data, and adds mark;The mark is sent to each participant end;The updated submatrix sent by each participant end is received, and the data of updated submatrix is handled;According to the result of data processing, the contribution matrix based on data fusion is generated.The technical scheme provided by the embodiment of the present application can realize the data fusion of multiple participant ends, and the data is not exposed to other participants, so that the security of data is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of privacy data processing technology, and in particular to a method and apparatus for the secure and reliable fusion of privacy-protected data and financial data. Background Technology

[0002] Data fusion between similar platforms can improve data utilization. For example, merging user preference profiles (such as liking a certain product or color) from one e-commerce platform to another can, on the one hand, compensate for the incompleteness of data from a single platform, and on the other hand, make extreme values ​​(such as being too high or too low) smoother.

[0003] In existing technologies, to protect the security and privacy of their own data, data fusion between different platforms is generally not performed. This results in inaccurate user profiles and inaccurate recommendations (such as goods or financial products in financial scenarios). Summary of the Invention

[0004] Based on the above-mentioned situation of the prior art, the purpose of this embodiment of the invention is to provide a method and apparatus for secure and reliable fusion of data and financial data based on privacy protection. By converting, encrypting, splitting and other processing of the data of each participating party and interacting with the server, the fusion of data from multiple participating parties is achieved under the premise of ensuring data security and privacy.

[0005] To achieve the above objectives, according to a first aspect of the present invention, a privacy-preserving data fusion method is provided, applied on a server side, comprising:

[0006] At least two participating parties are sent from a first trusted execution environment a first data conversion scheme and a second data conversion scheme, along with a first key and a second key; such that each participating party at least uses the first data conversion scheme to convert the data of its local first submatrix and encrypts it with the first key to form a first encrypted submatrix, and uses the second data conversion scheme to convert the data of its local second submatrix and encrypts it with the second key to form a second encrypted submatrix; the submatrix local to each participating party is generated by that participating party based on the data characteristics of its local data and predetermined data rules;

[0007] Receive at least a first encryption submatrix and a second encryption submatrix sent by at least two participating parties;

[0008] At least in the first trusted execution environment, the first encrypted sub-matrix sent by each participating party is matched, and the encrypted data in the first encrypted sub-matrix is ​​classified according to the matching results to obtain data to be supplemented, data to be merged, and similar data, and a mark is added. In the second trusted execution environment, the second encrypted sub-matrix sent by each participating party is matched, and the encrypted data in the second encrypted sub-matrix is ​​classified according to the matching results to obtain data to be supplemented, data to be merged, and similar data, and a mark is added.

[0009] The markers are sent to each participating party so that each participating party can filter out the data to be merged and the data to be supplemented based on the markers, and form an updated sub-matrix.

[0010] Receive the updated submatrix sent by each participating party, and process the data of the updated submatrix according to the corresponding tags;

[0011] A contribution matrix based on data fusion is generated from the results of data processing and provided to participating parties with a trusted execution environment.

[0012] Furthermore, the first data conversion scheme and the second data conversion scheme respectively include: retaining data with a value of 0 without conversion; converting data with a value of non-zero into an array containing multiple data, wherein the difference between each data value in the array and the data value of the original data is less than a conversion threshold; and encrypting the data in the converted sub-matrix.

[0013] The marker includes:

[0014] Information with data of 0 in each encrypted submatrix is ​​taken as data to be supplemented and marked as the first type;

[0015] Information with the same data at the same position in each encrypted submatrix having a number greater than or equal to the first threshold is considered similar data and marked as the second type;

[0016] The information of the remaining data in each encrypted submatrix is ​​taken as the data to be fused and marked as the third type.

[0017] Furthermore, the method also includes:

[0018] Data marked as Type 1 to be supplemented will be supplemented using data from other participants;

[0019] Data to be merged, categorized as the third type, will be processed using data from multiple participants.

[0020] It also includes: if any participant needs to supplement data that is greater than or equal to the second threshold, the participant will be refused data fusion.

[0021] Furthermore, the updated submatrix data is processed based on the corresponding labels, including:

[0022] The second trusted execution environment receives at least two first matrix components sent by at least the first participant and the second participant respectively. The first matrix components are generated by each participant locally by filtering data based on the full matrix sent by the server.

[0023] In the second trusted execution environment, an intermediate matrix is ​​established based on the first matrix components. A first mapping and a second mapping from the first matrix components of at least two participating parties to the intermediate matrix are determined. The first mapping and the second mapping are then sent to the first trusted execution environment so that the first trusted execution environment can perform data supplementation and data fusion based on the first mapping and the second mapping.

[0024] The method further includes:

[0025] The first trusted execution environment receives at least two second matrix components sent by at least the first participant and the second participant respectively. The second matrix components are generated by each participant locally by filtering data based on the full matrix sent by the server.

[0026] The system receives the first and second mappings sent by the second trusted execution environment from the first trusted execution environment, and performs supplementary or data fusion processing on the data according to different data types.

[0027] Furthermore, the method also includes: in a first trusted execution environment,

[0028] Determine the contribution matrix of data from other participants to the data from the target participant;

[0029] The contribution matrix is ​​converted into a first contribution matrix corresponding to the first matrix component of the first participating party and a second contribution matrix corresponding to the first matrix component of the second participating party according to the first mapping and the second mapping.

[0030] The first contribution matrix and the second contribution matrix are stored and provided to the participant with a trusted execution environment for use by the participant based on the first matrix components and the second contribution matrix.

[0031] According to a second aspect of the present invention, a privacy-preserving data fusion method is provided, applied to a participating party, comprising:

[0032] Generate an object feature matrix based on the data characteristics of local data;

[0033] The object feature matrix is ​​split into at least a first sub-matrix and a second sub-matrix according to predetermined data rules;

[0034] Receive at least a first data conversion scheme and a second data conversion scheme, as well as a first key and a second key, sent by the server.

[0035] The first submatrix is ​​converted using a first data conversion scheme and encrypted using a first key to obtain a first encrypted submatrix. The second submatrix is ​​converted using a second data conversion scheme and encrypted using a second key to obtain a second encrypted submatrix.

[0036] At least the first encryption submatrix and the second encryption submatrix are sent to the first trusted execution environment and the second trusted execution environment on the server side, respectively, so that the server side can perform data processing on the corresponding encryption submatrix in the trusted execution environment;

[0037] The method further includes:

[0038] Receive the full matrix sent by the server;

[0039] Based on the full matrix, filter the corresponding data locally and form a matrix to be uploaded;

[0040] The matrix to be uploaded is converted into a first matrix component and a second matrix component, and the first matrix component and the second matrix component are multiplied together to form the matrix to be uploaded;

[0041] The first matrix component is uploaded to the second trusted execution environment on the server side, and the second matrix component is uploaded to the first trusted execution environment on the server side, so that the server side determines the contribution matrix based on the first matrix component and the second matrix component.

[0042] Furthermore, the method also includes:

[0043] Before generating the object feature matrix, the local data is formatted according to predefined data format rules.

[0044] According to a third aspect of the present invention, a method for making recommendations based on the data fusion method described in the first aspect of the present invention is provided, applied on a server side, comprising:

[0045] Establish a trusted execution environment;

[0046] The first analysis results are obtained using the contribution matrix and the first matrix component in a trusted execution environment;

[0047] Receive a second analysis result sent by at least one participating party, the second analysis result being obtained by the participating party locally using the unfused portion of the data in the submatrix;

[0048] A comprehensive recommendation result is generated using the results of the first and second analyses.

[0049] According to a fourth aspect of the present invention, a privacy-preserving financial data fusion method is provided, applied on a server side, comprising:

[0050] Obtain user permission from each participating party, wherein each participating party's local data includes financial user preference profile data;

[0051] A first data transformation scheme and a first key are sent from at least a first trusted execution environment to at least two participating parties; such that each participating party at least uses the first data transformation scheme to transform the data of its local first submatrix and encrypts it with the first key, and uses a second data transformation scheme to transform the data of its local second submatrix and encrypts it with the second key; the local submatrix of each participating party is generated by the participating party based on the data characteristics of its local data and predetermined data rules;

[0052] Receive at least a first encryption submatrix and a second encryption submatrix sent by at least two participating parties;

[0053] At least in the first trusted execution environment, the first encrypted sub-matrix sent by each participating party is matched, and the encrypted data in the first encrypted sub-matrix is ​​classified according to the matching results to obtain data to be supplemented, data to be merged, and similar data, and a mark is added. In the second trusted execution environment, the data in the second encrypted sub-matrix sent by each participating party is marked with different data types.

[0054] The markers are sent to each participating party so that each participating party can filter out the data to be merged and the data to be supplemented based on the markers, and form an updated sub-matrix.

[0055] Receive the updated submatrix sent by each participating party and process the data in the updated submatrix;

[0056] A contribution matrix based on financial data fusion is generated from the data processing results and provided to participants with a trusted execution environment.

[0057] According to a fifth aspect of the present invention, a privacy-preserving data fusion apparatus is provided, applied on a server side, comprising:

[0058] The data transformation rule determination module is used to send a first data transformation scheme and a second data transformation scheme, as well as a first key and a second key, from at least a first trusted execution environment to at least two participating parties; so that each participating party at least uses the first data transformation scheme to transform the data of its local first sub-matrix and encrypts it with the first key to form a first encrypted sub-matrix, and uses the second data transformation scheme to transform the data of its local second sub-matrix and encrypt it with the second key to form a second encrypted sub-matrix; the sub-matrix of each participating party is generated by the participating party according to the data characteristics of its local data and predetermined data rules;

[0059] A data tagging module is used to receive at least a first encrypted submatrix and a second encrypted submatrix sent by at least two participating parties; at least in a first trusted execution environment, the module matches the first encrypted submatrix sent by each participating party, and classifies the encrypted data in the first encrypted submatrix according to the matching results to obtain data to be supplemented, data to be merged, and similar data, and adds tags; in a second trusted execution environment, the module matches the second encrypted submatrix sent by each participating party, and classifies the encrypted data in the second encrypted submatrix according to the matching results to obtain data to be supplemented, data to be merged, and similar data, and adds tags.

[0060] The data processing module sends the tags to each participating party so that each participating party can filter out the data to be fused and the data to be supplemented according to the tags to form an updated sub-matrix; receives the updated sub-matrix sent by each participating party, processes the data in the updated sub-matrix according to the tags corresponding to the data; and generates a contribution matrix based on data fusion according to the data processing results, so as to provide it to the participating party with a trusted execution environment.

[0061] In summary, embodiments of the present invention provide a privacy-preserving data fusion method and apparatus. The method includes: sending a first data conversion scheme and a second data conversion scheme, as well as a first key and a second key, from at least a first trusted execution environment to at least two participating parties; receiving at least a first encrypted sub-matrix and a second encrypted sub-matrix sent by at least two participating parties; in at least the first trusted execution environment, matching the first encrypted sub-matrix sent by each participating party, and classifying the encrypted data in the first encrypted sub-matrix according to the matching results to obtain data to be supplemented, data to be fused, and similar data, and adding tags; in the second trusted execution environment, matching the second encrypted sub-matrix sent by each participating party, and classifying the encrypted data in the second encrypted sub-matrix according to the matching results to obtain data to be supplemented, data to be fused, and similar data, and adding tags; sending the tags to each participating party; receiving updated sub-matrix sent by each participating party, processing the data in the updated sub-matrix; and generating a contribution matrix based on data fusion according to the data processing results, for use by participating parties with a trusted execution environment. The technical solution provided by this invention adopts an encrypted but not decrypted approach to determine data that does not need to be processed, thereby improving data security while reducing the data processing pressure on the server side; after the data is transformed and segmented, it is processed in a distributed manner, which achieves data fusion among multiple participants without exposing the data to other participants, thus ensuring the privacy and security of the data. Attached Figure Description

[0062] Figure 1 This is a flowchart of a privacy-preserving data fusion method provided in one embodiment of the present invention;

[0063] Figure 2 This is a flowchart of a privacy-preserving data fusion method provided in another embodiment of the present invention;

[0064] Figure 3 This is a schematic diagram illustrating the process of data interaction between the server and two participating parties to establish a contribution matrix;

[0065] Figure 4 This is a block diagram of a privacy-preserving data fusion device provided in one embodiment of the present invention;

[0066] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0067] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to specific embodiments and the accompanying drawings. It should be understood that these descriptions are merely exemplary and not intended to limit the scope of the invention. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concept of the invention.

[0068] It should be noted that, unless otherwise defined, the technical or scientific terms used in one or more embodiments of the present invention should have the ordinary meaning understood by one of ordinary skill in the art to which this disclosure pertains. The terms "first," "second," and similar terms used in one or more embodiments of the present invention do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Terms such as "comprising" or "including" mean that the element or object preceding the word encompasses the element or object listed following the word and its equivalents, without excluding other elements or objects. Terms such as "connected" or "linked" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect.

[0069] The technical solution of the present invention will be described in detail below with reference to the accompanying drawings. The technical solution provided in the embodiments of the present invention includes a server and at least two participating parties. Each participating party can be, for example, an e-commerce platform that provides goods and offers product recommendations, or a distributed banking platform that provides financial products and offers financial product recommendations, or other platforms that provide goods and product recommendation services. Data fusion between various platforms is achieved through the privacy-preserving data fusion method provided in the embodiments of the present invention.

[0070] An embodiment of the present invention provides a privacy-preserving data fusion method applied to the server side. Figure 1 The flowchart of the method is shown below, which includes the following steps:

[0071] S202. At least two participating terminals are sent from a first Trusted Execution Environment (TEE) to at least two participating terminals. Each participating terminal uses the first data conversion scheme to convert data in its local first submatrix and encrypts it using the first key to form a first encrypted submatrix, and uses the second data conversion scheme to convert data in its local second submatrix and encrypt it using the second key to form a second encrypted submatrix. The submatrix local to each participating terminal is generated by that participating terminal based on the data characteristics of its local data and predetermined data rules. On the server side, at least two trusted execution environments are set up, such as a first trusted execution environment and a second trusted execution environment. The number of trusted execution environments can be the same as the number of submatrixes sent by the participating terminals, for data marking and processing of each submatrix. The submatrix sent by each participating terminal is generated by that participating terminal based on the data characteristics of its local data and predetermined data rules.

[0072] The following explanation uses the example of setting up two trusted execution environments (a first trusted execution environment and a second trusted execution environment) and two participating parties (a first participating party and a second participating party) on the server side. On the first participating party and the second participating party, there are first sub-matrices and second sub-matrices generated according to the data characteristics of local data and predetermined data rules, respectively (for example, the first participating party has a first sub-matrice A1 and a second sub-matrice A2, and the second participating party has a first sub-matrice B1 and a second sub-matrice B2). The server sends a first data conversion scheme and a second data conversion scheme, as well as a first key and a second key, to the first participant and the second participant through a first trusted execution environment. This allows the first participant to convert the data in the first submatrix A1 using the first data conversion scheme and then encrypt it using the first key to form the first encrypted submatrix of the first participant. Similarly, the second participant converts the data in the first submatrix B1 using the first data conversion scheme and then encrypts it using the first key to form the first encrypted submatrix of the second participant. The same applies to the second participant converting the data in the second submatrix A2 using the second data conversion scheme and then encrypting it using the second key to form the second encrypted submatrix of the first participant. The data conversion scheme (including the first and second data conversion schemes) does not include the conversion of data 0 (i.e., data with a value of 0 is retained without conversion). For data with a value other than 0, it is converted into an array containing multiple data values, where the difference between each data value in the array and the original data value is less than a conversion threshold. The data in the converted sub-matrix are then encrypted. For example, the first data conversion scheme could be to convert the data in the sub-matrix into multiple adjacent values ​​(adjacent means the difference between the converted data and the original data is less than a first threshold), such as converting 0.6 into 0.58, 0.59, 0.60, 0.61, and 0.62. After conversion, each value is encrypted and stored in the same position in the sub-matrix. The second data conversion scheme could be the same or similar conversion method as the first data conversion scheme (e.g., the difference between the converted data and the original data is less than a second threshold).

[0073] S204. Receive at least a first encrypted sub-matrix and a second encrypted sub-matrix sent by at least two participating parties. Each participating party converts and encrypts the sub-matrix using a first data conversion scheme and a first key, and a second data conversion scheme and a second key, and then transmits the encrypted sub-matrix to the server. In at least a first trusted execution environment and a second trusted execution environment, match the first encrypted sub-matrix and the second encrypted sub-matrix sent by each participating party, and classify the encrypted data in the first encrypted sub-matrix and the second encrypted sub-matrix according to the matching results to obtain data to be supplemented, data to be merged, and similar data, and add tags.

[0074] S206. At least in the first trusted execution environment, the first encrypted sub-matrix sent by each participating party is matched, and the encrypted data in the first encrypted sub-matrix is ​​classified according to the matching result to obtain data to be supplemented, data to be fused and similar data, and a mark is added; in the second trusted execution environment, the second encrypted sub-matrix sent by each participating party is matched, and the encrypted data in the second encrypted sub-matrix is ​​classified according to the matching result to obtain data to be supplemented, data to be fused and similar data, and a mark is added. The added mark can include the following methods: information with data of 0 in each encrypted sub-matrix is ​​taken as data to be supplemented and marked as the first type; information with the same number of data in the same position in each encrypted sub-matrix that is greater than or equal to the first threshold is taken as similar data and marked as the second type; information of the remaining data in each encrypted sub-matrix is ​​taken as data to be fused and marked as the third type. The following explains each type: (1) Extract information with data of 0 in the sub-matrix and mark the first type at the corresponding position; because the data conversion scheme does not include the conversion of data of 0, it can be directly extracted according to the encrypted sub-matrix. (2) Extract the same or similar values ​​from each submatrix (e.g., the first submatrix A1 sent by the first participant and the first submatrix B1 sent by the second participant) and mark them as second type at the corresponding positions. Specifically, similar values ​​can be determined in the encrypted state because each participant converts the original data into multiple adjacent values ​​using the same key for encryption. If the original data is the same, the multiple encrypted results will be consistent. If the data is similar, the number of repeated results in the multiple encrypted results will exceed the threshold. Thus, the same and similar values ​​of the data at the same position of different participants can be determined without decryption. For example, in the data of the first participant, user A's liking for product x is 0.6; in the data of the second participant, user A's liking for product x is 0.62; (the two are not much different and are similar). The process of analyzing similar values ​​is as follows: For example, the first participant converts the data 0.6 in the first submatrix A1 into 0.58, 0.59, 0.60, 0.61 and 0.62, and then encrypts it with the first key; the second participant converts the data 0.62 in the corresponding position in the first submatrix B1 into 0.60, 0.61, 0.62, 0.63 and 0.64, and then encrypts it with the first key. The server receives the first encrypted submatrix from the first participant and the first encrypted submatrix from the second participant. For the positions of the above data in the two first encrypted submatrixes, it determines whether the same data is greater than or equal to the first threshold (in this example, the first threshold is set to 3, and the same data includes 0.60, 0.61 and 0.62, which are equal to the first threshold). At this time, it is determined that the two data are similar. (3) The positions corresponding to the remaining data with large differences are marked as the third type.The technical solution of this invention identifies identical and similar data by using encryption without decryption, thereby determining data that does not require processing. This eliminates the need for decryption, enhancing data security. Irreversible encryption can be used. Furthermore, data requiring no processing does not need to be transmitted to the trusted execution environment on the server side, thus reducing the data processing load on the trusted execution environment.

[0075] S208. The markers are sent to each participating party so that each participating party can filter out the data to be merged and the data to be supplemented based on the markers, and form an updated sub-matrix.

[0076] S210. Receive the updated sub-matrix sent by each participating party, and process the data of the updated sub-matrix according to the corresponding tags. In this step, the data of the updated sub-matrix is ​​processed according to the corresponding tags. The server receives at least two first matrix components sent by at least the first participating party and the second participating party respectively from the second trusted execution environment. The first matrix components are generated by each participating party locally by filtering data based on the full matrix sent by the server. An intermediate matrix is ​​established in the second trusted execution environment based on the first matrix components. A first mapping and a second mapping from the first matrix components of at least two participating parties to the intermediate matrix are determined. The first mapping and the second mapping are sent to the first trusted execution environment so that the first trusted execution environment can perform data supplementation and data fusion based on the first mapping and the second mapping.

[0077] In this step, at least two second matrix components sent by at least the first participant and the second participant can be received from the first trusted execution environment. The second matrix components are generated by each participant locally by filtering data based on the full matrix sent by the server. The first mapping and the second mapping sent by the second trusted execution environment can be received from the first trusted execution environment, and the data can be supplemented or fused according to different data types.

[0078] S212. Generate a contribution matrix based on data fusion according to the results of data processing, and provide it to the participant end with a trusted execution environment for use. According to some optional embodiments, the method further includes: in the first trusted execution environment, determining the contribution matrix of data from other participant ends to data from the target participant end; converting the contribution matrix into a first contribution matrix corresponding to a first matrix component of the first participant end and a second contribution matrix corresponding to a first matrix component of the second participant end according to a first mapping and a second mapping; storing the first contribution matrix and the second contribution matrix for use by the participant end with the trusted execution environment based on the first matrix component and the second contribution matrix.

[0079] The following explanation uses two participating parties (the first participating party and the second participating party) as an example. The contribution matrix to be uploaded by the first participating party is M1, and the contribution matrix to be uploaded by the second participating party is N1. The first participating party converts matrix M1 into a first matrix component a11 and a second matrix component a12, and the second participating party converts N1 into a first matrix component b11 and a second matrix component b12. The first matrix component a11 sent by the first participating party and the first matrix component b11 sent by the second participating party are received from the second trusted execution environment. An intermediate matrix c11 is established based on the first matrix component a11 and the first matrix component b11. Based on the first matrix component a11, the first matrix component b11, and the intermediate matrix c11, the first mapping G1 from the first matrix component a11 to the intermediate matrix c11 and the second mapping G2 from the first matrix component b11 to the intermediate matrix c11 are determined.

[0080] The system receives a second matrix component a12 sent by the first participant and a second matrix component b12 sent by the second participant from the first trusted execution environment. It also receives a first mapping G1 and a second mapping G2 sent by the second trusted execution environment, and processes the different types of data tags according to the aforementioned steps (e.g., data supplementation or fusion). For example, dividing the second matrix component a12 from the first participant by the second mapping G2 yields the matrix of the second matrix component a12 from the first participant relative to the intermediate matrix c11; dividing the second matrix component b12 from the second participant by the second mapping G2 yields the matrix of the second matrix component b12 from the second participant relative to the intermediate matrix c11.

[0081] Specifically, the contribution matrix of data from other participating parties to the data of the target participating party is determined. This contribution matrix is ​​equivalent to the matrix of intermediate matrix c11. According to the first mapping and the second mapping, the contribution matrix is ​​converted into a first contribution matrix corresponding to the first matrix component and a second contribution matrix corresponding to the second matrix component. Following the first mapping G1, which maps the first matrix component a11 of the first participating party to the intermediate matrix c11, and the first mapping G2, which maps the first matrix component b11 of the second participating party to the intermediate matrix c11, the contribution matrix is ​​converted into a contribution matrix AA corresponding to the first matrix component a11 of the first participating party and a contribution matrix BB corresponding to the first matrix component b11 of the second participating party. Since contribution matrices AA and BB are only half-matrices and need to be used in conjunction with a11 and b11, there is no risk of data leakage. The first and second contribution matrices are stored for use by participating parties with a trusted execution environment. The contribution matrix AA and contribution matrix BB are stored on the server side. When a participant needs to use the complete matrix, the server can first determine that the participant's device is a trusted execution environment before providing the contribution matrix AA. Within the participant's trusted execution environment, the contributions of other parties can be determined based on the first matrix component a11 and the contribution matrix AA. Then, combined with the participant's local data, the complete content is obtained for analysis. The method provided by this invention stores the contribution matrix on the server side, without providing it to the user end, thus avoiding exposure of other participants' data. Furthermore, the contribution matrix requires the participation's local first matrix component a11 or b11 to be used, and is not exposed to backend users, ensuring data security and privacy.

[0082] According to some optional embodiments, the method further includes: supplementing the data to be supplemented, which is marked as a first type, with data from other participants; fusing the data to be fused, which is marked as a third type, with data from multiple participants, including but not limited to averaging the data from two parties or using methods such as maximizing or minimizing the values; and leaving the data marked as a second type unprocessed. To further improve data security, the method may also include: if any participant needs to supplement data that is greater than or equal to a second threshold, rejecting data fusion for that participant. This judgment step can prevent the risk of data theft by some participants during data fusion.

[0083] Embodiments of the present invention also provide a privacy-preserving data fusion method, applied to the participating party. Figure 2 The flowchart of the method is shown below, which includes the following steps:

[0084] S402. Generate an object feature matrix based on the data characteristics of the local data. To ensure data consistency, the local data can be formatted according to predetermined data format rules before generating the object feature matrix. For example, the format of the data from the first participant (e.g., e-commerce platform 1) and the second participant (e.g., e-commerce platform 2) can be unified. Methods for format unification include: unifying data close to 0 to 0, and retaining data not close to 0 to the same number of decimal places, such as two decimal places. After data format unification, an object feature matrix can be generated based on the data characteristics of the local data. For example, if the first object feature is a user and the second object feature is a product, the object feature matrix is ​​generated based on the first and second object features. The data in the object feature matrix represents the degree of correlation between the first and second object features; in this example, it might be the degree to which a user likes a product. Through this method, each participant obtains its own object feature matrix. Alternatively, the data can be converted into fixed categories to unify the data from multiple participants, where data within the same category is identical or similar. For example, user preferences for products can be categorized into six levels: very high, high, medium, low, very low, and 0. When identifying identical and similar data across multiple participants, the categories can be encrypted using the same key. By judging whether the encrypted data is consistent (no decryption required), it can be determined whether the data from multiple participants belong to the same category, thus classifying data of the same category as similar data (data that does not require data fusion). S404: The object feature matrix is ​​split into at least a first sub-matrix and a second sub-matrix according to predetermined data rules. To reduce the amount of data analyzed, a distributed approach is used to analyze the object feature matrices of each participant. At each participant, the object feature matrix is ​​split into a first sub-matrix and a second sub-matrix. The data in each first sub-matrix corresponds to the data in each second sub-matrix. For example, the first participant splits the object feature matrix into a first sub-matrix A1 and a second sub-matrix A2, and the second participant splits the object feature matrix into a first sub-matrix B1 and a second sub-matrix B2. The data in the first sub-matrix A1 corresponds to the data in the first sub-matrix B1, and the data in the second sub-matrix A2 corresponds to the data in the second sub-matrix B2. The predefined data rules are set based on the actual data volume. For example, data on 1000 people can be divided into two sets of 500 people each. In this step, by splitting the object feature matrix into two sub-matrices and performing distributed processing through two trusted execution environments on the server side, the data processing pressure can be reduced.

[0085] S406: Receive at least a first data conversion scheme and a second data conversion scheme, as well as a first key and a second key, sent by the server; perform data conversion on the first sub-matrix using at least the first data conversion scheme and encrypt it using the first key to obtain a first encrypted sub-matrix; perform data conversion on the second sub-matrix using the second data conversion scheme and encrypt it using the second key to obtain a second encrypted sub-matrix. This step has been described in the embodiments of the present invention above, and its description is omitted here.

[0086] S408. At least the first encryption submatrix and the second encryption submatrix are sent to the first trusted execution environment and the second trusted execution environment on the server side, respectively, so that the server side can perform data processing on the corresponding encryption submatrix in the trusted execution environment.

[0087] According to some optional embodiments, the method further includes the step of transmitting supplementary data to the server, including:

[0088] Receive the full matrix sent by the server, filter the corresponding data locally based on the full matrix, and form a matrix to be uploaded.

[0089] The matrix to be uploaded is converted into a first matrix component and a second matrix component. The first matrix component and the second matrix component are multiplied to form the matrix to be uploaded. Here, we still use two participating parties (the first participating party and the second participating party) as an example. The matrix to be uploaded by the first participating party is M1, and the matrix to be uploaded by the second participating party is N1. The first participating party converts matrix M1 into a first matrix component a11 and a second matrix component a12. The two components are multiplied to form matrix M1, and no other data can be derived from each component. For example, the user's preference for products 1, 2, and 3 (0.6, 0.3, 0.1) forms matrix M1. The first matrix component a11 can be established using product type (lightweight, material, brand, etc.) and products 1, 2, and 3 (the values ​​represent different weights of the products) as two dimensions. Based on the first matrix component a11, the second matrix component a12 can be determined. Similarly, the second participating party converts N1 into a first matrix component b11 and a second matrix component b12.

[0090] The first matrix component is uploaded to the second trusted execution environment on the server side, and the second matrix component is uploaded to the first trusted execution environment on the server side, so that the server side determines the contribution matrix based on the first matrix component and the second matrix component.

[0091] This allows the second trusted execution environment to build an intermediate matrix based on the first matrix components and determine the first mapping from the first matrix components to the intermediate matrix. For example, Figure 3The diagram illustrates the process of data interaction between the server and two participants (Participant 1 and Participant 2) to establish a contribution matrix. Figure 3 As shown, participant 1 uploads the first matrix component a11 to the second trusted execution environment on the server and uploads the second matrix component a12 to the first trusted execution environment on the server; participant 2 uploads the first matrix component b11 to the second trusted execution environment on the server and uploads the second matrix component b12 to the first trusted execution environment on the server. The second trusted execution environment on the server receives the first matrix component a11 sent by participant 1 and the first matrix component b11 sent by participant 2. Based on these components, it establishes an intermediate matrix c11 and determines a first mapping G1 from the first matrix component a11 to the intermediate matrix c11 and a second mapping G2 from the first matrix component b11 to the intermediate matrix c11. It then sends the first mapping G1 and the second mapping G2 relative to the intermediate matrix c11 to the first trusted execution environment. The first trusted execution environment determines the contribution matrix based on the second matrix component a12, the second matrix component b12, the first mapping G1, and the second mapping G2. The data to be supplemented is converted into two matrix components. The two matrix components on one participant's end are not processed in the same trusted execution environment, but in two separate trusted execution environments, which further enhances the security of the data.

[0092] For example, in a product recommendation scenario, the fused data can be understood as a user profile (including the user's preferences for various types of products). Participant 1 identifies the user for whom a product is to be recommended and inputs the first matrix component a11 of that user and the local user profile 1 into its local trusted execution environment. After the server confirms that the participant is a trusted execution environment, it inputs the contribution matrix AA into the participant's trusted execution environment. After AA*a11, profile 1 is then fused to obtain a complete profile 2. Therefore, product recommendations can be made to the user based on the complete profile 2. The recommended content includes products and product ranking. The product ranking is determined based on the complete profile 2 and sent to the user terminal in an encrypted state. The user terminal then displays the products according to the ranking. Participant 1 does not obtain the ranking, preventing the participant from obtaining the contribution matrix (data from other participants) through other means.

[0093] Embodiments of the present invention also provide a privacy-preserving data fusion device applied to the server side. Figure 4 The diagram shows the configuration of the device, including:

[0094] The data conversion rule determination module 401 is used to send a first data conversion scheme and a second data conversion scheme, as well as a first key and a second key, from at least a first trusted execution environment to at least two participating parties; so that each participating party at least uses the first data conversion scheme to convert the data of its local first submatrix and encrypts it with the first key to form a first encrypted submatrix, and uses the second data conversion scheme to convert the data of its local second submatrix and encrypts it with the second key to form a second encrypted submatrix; the submatrix of each participating party is generated by the participating party according to the data characteristics of its local data and predetermined data rules. The data tagging module 402 is used to receive at least a first encrypted sub-matrix and a second encrypted sub-matrix sent by at least two participating parties; at least in a first trusted execution environment, it matches the first encrypted sub-matrix sent by each participating party, and classifies the encrypted data in the first encrypted sub-matrix according to the matching results to obtain data to be supplemented, data to be merged, and similar data, and adds tags; in a second trusted execution environment, it matches the second encrypted sub-matrix sent by each participating party, and classifies the encrypted data in the second encrypted sub-matrix according to the matching results to obtain data to be supplemented, data to be merged, and similar data, and adds tags.

[0095] The data processing module 403 sends the markers to each participating party so that each participating party can filter out the data to be fused and the data to be supplemented according to the markers to form an updated sub-matrix; receives the updated sub-matrix sent by each participating party, processes the data in the updated sub-matrix according to the markers corresponding to the data; and generates a contribution matrix based on data fusion according to the data processing results, so as to provide it to the participating party with a trusted execution environment.

[0096] The specific process by which each module in the privacy-preserving data fusion device provided in the above embodiments of the present invention implements its function is the same as the steps of the privacy-preserving data fusion method provided in the above embodiments of the present invention. Therefore, repeated descriptions will be omitted here.

[0097] An embodiment of the present invention also provides a method for making recommendations based on the data fusion method described in the above embodiments, applied on the server side, including the following steps:

[0098] S602. Establish a trusted execution environment.

[0099] S604. Obtain the first analysis result using the contribution matrix and the first matrix component in a trusted execution environment.

[0100] S606. Receive a second analysis result sent by at least one participating party, the second analysis result being obtained by the participating party locally using the unfused portion of the data in the submatrix.

[0101] S608. Generate a comprehensive recommendation result using the results of the first and second analyses.

[0102] The contribution matrix and matrix components used in this embodiment of the present invention can refer to the methods for generating or obtaining the contribution matrix and matrix components involved in the embodiments above, and their repeated description will be omitted here. Using the technical solution of this embodiment of the present invention, recommendations for products such as financial products can be made based on the data fusion methods involved in the above embodiments. Because the data provided by each participating party is fused, the reliability of the recommendation results is improved.

[0103] An embodiment of the present invention also provides a privacy-preserving financial data fusion method, applied on the server side, comprising the following steps:

[0104] S802. Obtain user permission from each participating party, wherein each participating party's local data includes financial user preference profile data.

[0105] S804. Send a first data conversion scheme and a first key from at least the first trusted execution environment to at least two participating parties; such that each participating party at least uses the first data conversion scheme to convert the data of its local first submatrix and encrypts it with the first key, and uses a second data conversion scheme to convert the data of its local second submatrix and encrypts it with the second key; the local submatrix of each participating party is generated by the participating party according to the data characteristics of its local data and predetermined data rules.

[0106] S806, Receive at least a first encryption submatrix and a second encryption submatrix sent by at least two participating parties.

[0107] S808. At least in the first trusted execution environment, the first encrypted sub-matrix sent by each participating party is matched, and the encrypted data in the first encrypted sub-matrix is ​​classified according to the matching result to obtain data to be supplemented, data to be merged and similar data, and a mark is added. In the second trusted execution environment, the data in the second encrypted sub-matrix sent by each participating party is marked with different data types.

[0108] S810. The marker is sent to each participating party so that each participating party can filter out the data to be merged and the data to be supplemented based on the marker, and form an updated sub-matrix.

[0109] S812: Receive the updated submatrix sent by each participating party and process the data of the updated submatrix.

[0110] S814. Generate a contribution matrix based on financial data fusion based on the results of data processing, and provide it to the participants with a trusted execution environment.

[0111] The technical solution provided in this embodiment of the invention is used for the fusion of financial data, such as financial user preference profile data. The generated contribution matrix based on the fusion of financial data can be provided to financial stakeholders for use. The specific implementation of each step of this method is similar to the methods involved in the embodiments of the invention above, and their repeated descriptions will be omitted here.

[0112] An embodiment of the present invention also provides an electronic device. Figure 5 The diagram shown is a structural schematic of an electronic device provided according to an embodiment of the present invention. Figure 5 As shown, the electronic device 500 includes: one or more processors 501 and a memory 502; and computer program instructions stored in the memory 502, which, when executed by the processor 501, cause the processor 501 to perform a privacy-preserving data fusion method as described in any of the above embodiments. The processor 501 may be a central processing unit (CPU) or other form of processing unit with data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device to perform desired functions.

[0113] The memory 502 may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, and the processor 1001 may execute the program instructions to implement the steps in the privacy-preserving data fusion methods of the various embodiments of the present invention described above, and / or other desired functions.

[0114] In some embodiments, the electronic device may further include an input device 503 and an output device 504, these components being connected via a bus system and / or other forms of connection mechanism. Figure 5 (Not shown in the diagram) Interconnected. For example, when the electronic device is a standalone device, the input device 503 can be a communication network connector for receiving acquired input signals from external mobile devices. Furthermore, the input device 503 may also include, for example, a keyboard, mouse, microphone, etc. The output device 504 can output various information to the outside, and may include, for example, a monitor, speaker, printer, and communication network and its connected remote output devices.

[0115] In addition to the methods and devices described above, embodiments of the present invention may also be computer program products, including computer program instructions that, when executed by a processor, cause the processor to perform the steps in the privacy-preserving data fusion method of any of the above embodiments.

[0116] Computer program products can be written in any combination of one or more programming languages ​​to perform the operations of the embodiments of the present invention. The programming languages ​​include object-oriented programming languages ​​such as Java and C++, as well as conventional procedural programming languages ​​such as C or similar languages. The program code can be executed entirely on the user's computing device, partially on the user's computing device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0117] Furthermore, embodiments of the present invention may also be computer-readable storage media storing computer program instructions that, when executed by a processor, cause the processor to perform the steps in the privacy-preserving data fusion methods of various embodiments of the present invention.

[0118] Computer-readable storage media may take the form of any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may, for example, include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: electrical connections having one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0119] It should be understood that the processor in the embodiments of the present invention can be a Central Processing Unit (CPU), but it can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor.

[0120] In summary, the embodiments of the present invention relate to a method and apparatus for secure and trusted fusion of data and financial data based on privacy protection. The method includes: sending a first data conversion scheme and a second data conversion scheme, as well as a first key and a second key, from at least a first trusted execution environment to at least two participating parties; receiving at least a first encrypted sub-matrix and a second encrypted sub-matrix sent by at least two participating parties; in at least the first trusted execution environment, matching the first encrypted sub-matrix sent by each participating party, and classifying the encrypted data in the first encrypted sub-matrix according to the matching results to obtain data to be supplemented, data to be fused, and similar data, and adding tags; in the second trusted execution environment, matching the second encrypted sub-matrix sent by each participating party, and classifying the encrypted data in the second encrypted sub-matrix according to the matching results to obtain data to be supplemented, data to be fused, and similar data, and adding tags; sending the tags to each participating party; receiving the updated sub-matrix sent by each participating party, processing the data in the updated sub-matrix; and generating a contribution matrix based on data fusion according to the data processing results, for use by participating parties with a trusted execution environment. The technical solution provided by this invention adopts an encrypted but not decrypted approach to determine data that does not need to be processed, thereby improving data security while reducing the data processing pressure on the server side; after the data is transformed and segmented, it is processed in a distributed manner, which achieves data fusion among multiple participants without exposing the data to other participants, thus ensuring the privacy and security of the data.

[0121] It should be understood that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of the invention (including the claims) is limited to these examples. Within the framework of this invention, technical features of the above embodiments or different embodiments can also be combined, steps can be implemented in any order, and many other variations exist regarding different aspects of one or more embodiments of the invention as described above, which are not provided in the details for the sake of brevity. The specific embodiments described above are merely illustrative or explanatory of the principles of the invention and do not constitute a limitation thereof. Therefore, any modifications, equivalent substitutions, improvements, etc., made without departing from the spirit and scope of the invention should be included within the protection scope of the invention. Furthermore, the appended claims are intended to cover all variations and modifications falling within the scope and boundaries of the appended claims, or equivalent forms of such scope and boundaries.

Claims

1. A privacy-preserving data fusion method, characterized in that, Applied to the server side, including: At least two participating parties are sent from a first trusted execution environment a first data conversion scheme and a second data conversion scheme, along with a first key and a second key; such that each participating party at least uses the first data conversion scheme to convert the data of its local first submatrix and encrypts it with the first key to form a first encrypted submatrix, and uses the second data conversion scheme to convert the data of its local second submatrix and encrypts it with the second key to form a second encrypted submatrix; the submatrix local to each participating party is generated by that participating party based on the data characteristics of its local data and predetermined data rules; Receive at least a first encryption submatrix and a second encryption submatrix sent by at least two participating parties; At least in the first trusted execution environment, the first encrypted sub-matrix sent by each participating party is matched, and the encrypted data in the first encrypted sub-matrix is ​​classified according to the matching results to obtain data to be supplemented, data to be merged, and similar data, and a mark is added. In the second trusted execution environment, the second encrypted sub-matrix sent by each participating party is matched, and the encrypted data in the second encrypted sub-matrix is ​​classified according to the matching results to obtain data to be supplemented, data to be merged, and similar data, and a mark is added. The markers are sent to each participating party so that each participating party can filter out the data to be merged and the data to be supplemented based on the markers, and form an updated sub-matrix. Receive the updated submatrix sent by each participating party, and process the data of the updated submatrix according to the corresponding tags; A contribution matrix based on data fusion is generated based on the results of data processing and provided to the participating parties with a trusted execution environment. The first data conversion scheme and the second data conversion scheme respectively include: retaining data with a value of 0 without conversion; converting data with a value of non-zero into an array containing multiple data, wherein the difference between each data value in the array and the data value of the original data is less than a conversion threshold; and encrypting the data in the converted sub-matrix. The labeling includes: taking information with data of 0 in each encrypted sub-matrix as data to be supplemented and labeling it as a first type; taking information with the same number of identical data at the same position in each encrypted sub-matrix as similar data and labeling it as a second type; and taking information of the remaining data in each encrypted sub-matrix as data to be fused and labeling it as a third type. The method further includes: supplementing data marked as the first type with data from other participants; fusing data marked as the third type with data from multiple participants; and rejecting data fusion for any participant if the data to be supplemented by any participant is greater than or equal to a second threshold.

2. The method according to claim 1, characterized in that, The updated submatrix data is processed based on the labels corresponding to the data, including: The second trusted execution environment receives at least two first matrix components sent by at least the first participant and the second participant respectively. The first matrix components are generated by each participant locally by filtering data based on the full matrix sent by the server. In the second trusted execution environment, an intermediate matrix is ​​established based on the first matrix components. A first mapping and a second mapping from the first matrix components of at least two participating parties to the intermediate matrix are determined. The first mapping and the second mapping are then sent to the first trusted execution environment so that the first trusted execution environment can perform data supplementation and data fusion based on the first mapping and the second mapping. The method further includes: The first trusted execution environment receives at least two second matrix components sent by at least the first participant and the second participant respectively. The second matrix components are generated by each participant locally by filtering data based on the full matrix sent by the server. The system receives the first and second mappings sent by the second trusted execution environment from the first trusted execution environment, and performs supplementary or data fusion processing on the data according to different data types.

3. The method according to claim 2, characterized in that, The method further includes: in a first trusted execution environment, Determine the contribution matrix of data from other participants to the data from the target participant; The contribution matrix is ​​converted into a first contribution matrix corresponding to the first matrix component of the first participating party and a second contribution matrix corresponding to the first matrix component of the second participating party according to the first mapping and the second mapping. The first contribution matrix and the second contribution matrix are stored and provided to the participant with a trusted execution environment for use by the participant based on the first matrix components and the second contribution matrix.

4. A privacy-preserving data fusion method, characterized in that, Applied to the participating parties, including: Generate an object feature matrix based on the data characteristics of local data; The object feature matrix is ​​split into at least a first sub-matrix and a second sub-matrix according to predetermined data rules; Receive at least a first data conversion scheme and a second data conversion scheme, as well as a first key and a second key, sent by the server. The first submatrix is ​​converted using a first data conversion scheme and encrypted using a first key to obtain a first encrypted submatrix. The second submatrix is ​​converted using a second data conversion scheme and encrypted using a second key to obtain a second encrypted submatrix. At least the first encryption submatrix and the second encryption submatrix are sent to the first trusted execution environment and the second trusted execution environment on the server side, respectively, so that the server side can perform data processing on the corresponding encryption submatrix in the trusted execution environment; The method further includes: Receive the full matrix sent by the server; Based on the full matrix, filter the corresponding data locally and form a matrix to be uploaded; The matrix to be uploaded is converted into a first matrix component and a second matrix component, and the first matrix component and the second matrix component are multiplied together to form the matrix to be uploaded; The first matrix component is uploaded to the second trusted execution environment on the server side, and the second matrix component is uploaded to the first trusted execution environment on the server side, so that the server side can determine the contribution matrix based on the first matrix component and the second matrix component. The first data conversion scheme and the second data conversion scheme respectively include: retaining data with a value of 0 without conversion; converting data with a value of non-zero into an array containing multiple data, wherein the difference between each data value in the array and the data value of the data is less than a conversion threshold; and encrypting the data in the converted sub-matrix.

5. The method according to claim 4, characterized in that, The method further includes: Before generating the object feature matrix, the local data is formatted according to predefined data format rules.

6. A method for making recommendations based on the data fusion method according to any one of claims 1-3, characterized in that, Applied to the server side, including: Establish a trusted execution environment; The first analysis results are obtained using the contribution matrix and the first matrix component in a trusted execution environment; Receive a second analysis result sent by at least one participating party, the second analysis result being obtained by the participating party locally using the unfused portion of the data in the submatrix; A comprehensive recommendation result is generated using the results of the first and second analyses.

7. A privacy-preserving financial data fusion method, characterized in that, Applied to the server side, including: Obtain user permission from each participating party, wherein each participating party's local data includes financial user preference profile data; A first data transformation scheme and a first key are sent from at least a first trusted execution environment to at least two participating parties; such that each participating party at least uses the first data transformation scheme to transform the data of its local first submatrix and encrypts it with the first key, and uses a second data transformation scheme to transform the data of its local second submatrix and encrypts it with the second key; the local submatrix of each participating party is generated by the participating party based on the data characteristics of its local data and predetermined data rules; Receive at least a first encryption submatrix and a second encryption submatrix sent by at least two participating parties; At least in the first trusted execution environment, the first encrypted sub-matrix sent by each participating party is matched, and the encrypted data in the first encrypted sub-matrix is ​​classified according to the matching results to obtain data to be supplemented, data to be merged, and similar data, and a mark is added. In the second trusted execution environment, the data in the second encrypted sub-matrix sent by each participating party is marked with different data types. The markers are sent to each participating party so that each participating party can filter out the data to be merged and the data to be supplemented based on the markers, and form an updated sub-matrix. Receive the updated submatrix sent by each participating party and process the data in the updated submatrix; A contribution matrix based on financial data fusion is generated based on the results of data processing and provided to participating parties with a trusted execution environment. The first data conversion scheme and the second data conversion scheme respectively include: retaining data with a value of 0 without conversion; converting data with a value of non-zero into an array containing multiple data, wherein the difference between each data value in the array and the data value of the original data is less than a conversion threshold; and encrypting the data in the converted sub-matrix. The labeling includes: taking information with data of 0 in each encrypted sub-matrix as data to be supplemented and labeling it as a first type; taking information with the same number of identical data at the same position in each encrypted sub-matrix as similar data and labeling it as a second type; and taking information of the remaining data in each encrypted sub-matrix as data to be fused and labeling it as a third type. The method further includes: supplementing data marked as the first type with data from other participants; fusing data marked as the third type with data from multiple participants; and rejecting data fusion for any participant if the data to be supplemented by any participant is greater than or equal to a second threshold.

8. A privacy-preserving data fusion device, characterized in that, Applied to the server side, including: The data transformation rule determination module is used to send a first data transformation scheme and a second data transformation scheme, as well as a first key and a second key, from at least a first trusted execution environment to at least two participating parties; so that each participating party at least uses the first data transformation scheme to transform the data of its local first sub-matrix and encrypts it with the first key to form a first encrypted sub-matrix, and uses the second data transformation scheme to transform the data of its local second sub-matrix and encrypt it with the second key to form a second encrypted sub-matrix; the sub-matrix of each participating party is generated by the participating party according to the data characteristics of its local data and predetermined data rules; A data tagging module is used to receive at least a first encrypted submatrix and a second encrypted submatrix sent by at least two participating parties; at least in a first trusted execution environment, the module matches the first encrypted submatrix sent by each participating party, and classifies the encrypted data in the first encrypted submatrix according to the matching results to obtain data to be supplemented, data to be merged, and similar data, and adds tags; in a second trusted execution environment, the module matches the second encrypted submatrix sent by each participating party, and classifies the encrypted data in the second encrypted submatrix according to the matching results to obtain data to be supplemented, data to be merged, and similar data, and adds tags. The data processing module sends the tags to each participating party so that each participating party can filter out the data to be fused and the data to be supplemented according to the tags to form an updated sub-matrix; receives the updated sub-matrix sent by each participating party, processes the data in the updated sub-matrix according to the tags corresponding to the data; and generates a contribution matrix based on data fusion according to the data processing results, so as to provide it to the participating party with a trusted execution environment. The first data conversion scheme and the second data conversion scheme respectively include: retaining data with a value of 0 without conversion; converting data with a value of non-zero into an array containing multiple data, wherein the difference between each data value in the array and the data value of the original data is less than a conversion threshold; and encrypting the data in the converted sub-matrix. The labeling includes: taking information with data of 0 in each encrypted sub-matrix as data to be supplemented and labeling it as a first type; taking information with the same number of identical data at the same position in each encrypted sub-matrix as similar data and labeling it as a second type; and taking information of the remaining data in each encrypted sub-matrix as data to be fused and labeling it as a third type. The data processing module will supplement data marked as the first type with data from other participants; it will also merge data marked as the third type with data from multiple participants; if any participant needs to supplement data that is greater than or equal to the second threshold, it will refuse to merge the data for that participant.