Data directory sharing method, device, system and storage medium
By implementing data processing algorithms and quality assessments between data node devices and the platform, generating anonymized data directories and managing permissions, the problems of high cost and low security in data sharing are solved, and efficient and secure data directory sharing is achieved.
Patent Information
- Application Number
- CN202210505802.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-05-10
- Publication Date
- 2026-01-20
- Estimated Expiration
- 2042-05-10
AI Technical Summary
In existing technologies, data sharing between different institutions suffers from high costs, lack of security, and low communication efficiency, especially in the process of sharing data catalogs, where there is a lack of secure online sharing solutions.
By implementing data processing algorithms between the first node device and the platform, an anonymized first data directory is generated, and quality assessment and permission management are performed on the platform to achieve secure online sharing of the data directory, including anonymization, quality assessment, permission allocation, and contract generation.
It reduced the number of offline consultations, improved the efficiency of data element circulation, and ensured the security of the data catalog through platform authorization, thus realizing the secure online sharing of the data catalog.
Smart Images

Figure CN117081763B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of data security, and in particular to a data directory sharing method, device, system and storage medium. BACKGROUND
[0002] Due to factors such as security issues, competitive relationships, and approval processes, data exists in the form of "islands" within an industry, and even within a company. In reality, it is very costly to integrate data scattered in various places or institutions. Data sharing and application among industries, companies, and departments are very difficult.
[0003] With the development of big data technology and digital economy, data elements as a new type of production factor have been widely valued by all parties in society, and the security of data element circulation is becoming increasingly important, which may involve the security interests of individuals, organizations, society, and even the country.
[0004] In related technologies, due to the lack of public service facilities, institutions or enterprises often need to use point-to-point connection and data cooperation, which has high connection cost, no security and reliability guarantee, and high technical implementation cost, thereby increasing the threshold of data sharing and circulation. Taking data directory as an example, since data directory involves data privacy, direct publishing to the platform is unacceptable for most enterprises, therefore, existing data demanders and data providers generally use offline point-to-point communication. Since both parties do not know the data situation of each other, they need to negotiate offline for multiple rounds, and it is possible that after multiple rounds of communication, it is found that the data of the other party is not what they need, thereby missing industry business opportunities and affecting communication efficiency. SUMMARY
[0005] Therefore, the embodiments of the present application provide a data directory sharing method, device, system and storage medium, aiming to realize online and safe sharing of data directory.
[0006] The technical scheme of the embodiments of the present application is as follows:
[0007] In a first aspect, the embodiments of the present application provide a data directory sharing method applied to a first node device, and the method comprises:
[0008] performing data processing on original data and / or original data directory based on a data processing algorithm to obtain a first data directory;
[0009] sending the first data directory to a first platform;
[0010] receiving a first message from the first platform;
[0011] sending a second data directory to the first platform;
[0012] The first data directory can be accessed by the first node device and / or the second node device on the first platform, and the second data directory is accessed by the first node device and / or the second node device authorized by the first platform.
[0013] In the above scheme, the first data directory is obtained by performing data processing on the original data and / or the original data directory based on a data processing algorithm, and at least includes:
[0014] The original data directory is anonymized based on the first algorithm to obtain the first data directory.
[0015] In the above scheme, before the original data directory is anonymized based on the first algorithm, the method further includes:
[0016] The original data and / or the original data directory are quality evaluated based on a second algorithm to obtain an evaluation result.
[0017] It is determined whether to anonymize the original data directory based on the first algorithm according to the evaluation result.
[0018] In the above scheme, before the original data and / or the original data directory are quality evaluated based on the second algorithm, the method further includes:
[0019] The original data is preprocessed based on a third algorithm.
[0020] In the above scheme, the evaluation result is obtained by quality evaluating the original data and / or the original data directory based on the second algorithm, including:
[0021] A first encrypted evaluation result of the original data is generated based on a first sub-algorithm for data quality evaluation;
[0022] The first encrypted evaluation result is sent to the first platform;
[0023] A decrypted first evaluation result returned by the first platform based on the first encrypted evaluation result is received; and / or,
[0024] A second encrypted evaluation result of the original data directory is generated based on a second sub-algorithm for data directory quality evaluation;
[0025] The second encrypted evaluation result is sent to the first platform;
[0026] A decrypted second evaluation result returned by the first platform based on the second encrypted evaluation result is received.
[0027] In the above scheme, the determination of whether to anonymize the original data directory based on the first algorithm according to the evaluation result includes:
[0028] According to the first evaluation result and / or the second evaluation result, if it is determined that the data directory meets the anonymization condition, the original data directory is anonymized based on a first algorithm.
[0029] In the above scheme, the anonymization of the original data directory based on the first algorithm comprises:
[0030] Based on the mapping relationship between the fields and the sensitive levels, the sensitive levels of the fields of the original data directory are determined.
[0031] Based on the sensitive levels of the fields, the fields of the original data directory are merged to obtain the first data directory.
[0032] In the above scheme, before the first message from the first platform is received, the method further comprises:
[0033] Receiving a request message from the first platform;
[0034] Negotiating with a second node device, and a negotiation result of the negotiation is used for the first platform to assign permissions to the first node device and / or the second node device.
[0035] In the above scheme, the first data directory is an anonymized data directory, and the second data directory is an original data directory.
[0036] In a second aspect, an embodiment of the present application provides a data directory sharing method applied to a first platform, the method comprising:
[0037] Receiving a first data directory sent by at least one first node device and storing the first data directory in a public data area;
[0038] In response to a target data directory selected, sending a request message to a target first node device;
[0039] Receiving an acknowledgement message sent by a second node device, the acknowledgement message indicating a negotiation result negotiated between the second node device and the target first node device;
[0040] Based on the acknowledgement message, generating and storing a contract for data sharing;
[0041] Based on the contract, sending a first message to the target first node device and sending a second message to the second node device;
[0042] The first data directory can be accessed by the first node device and / or the second node device at the first platform, and the second data directory is accessed only by the first node device and / or the second node device authorized by the first platform.
[0043] In the above solution, the receiving and storing of the first data directory sent by the at least one first node device to the public data area include:
[0044] receiving the first data directory sent by the at least one first node device;
[0045] generating an audit result of the first data directory;
[0046] storing the first data directory to the public data area based on the audit result.
[0047] In the above solution, the method further includes:
[0048] receiving a second data directory sent by the target first node device, and storing the second data directory to a private data area.
[0049] In the above solution, the method further includes:
[0050] receiving an access request generated by the second node device based on the second message, and authorizing the second node device to view the second data directory within a set time length.
[0051] In the above solution, the method further includes:
[0052] determining that the second node device views the second data directory for a time length reaching the set time length, and deleting the second data directory.
[0053] In the above solution, the method further includes:
[0054] receiving a first encrypted evaluation result of the original data generated by the first node device based on a first sub-algorithm for data quality evaluation;
[0055] decrypting the first encrypted evaluation result to obtain a decrypted first evaluation result and returning the first evaluation result to the first node device; and / or,
[0056] receiving a second encrypted evaluation result of the original data directory generated by the first node device based on a second sub-algorithm for data directory quality evaluation;
[0057] decrypting the second encrypted evaluation result to obtain a decrypted second evaluation result and returning the second evaluation result to the first node device.
[0058] In a third aspect, an embodiment of the present application provides a data directory sharing method applied to a second node device, and the method includes:
[0059] access a public data area of the first platform, and obtain a first data directory sent by at least one first node device;
[0060] select a target data directory from the at least one first data directory, and trigger the first platform to send a request message to a target first node device;
[0061] receive a negotiation message generated by the target first node device based on the request message;
[0062] send a confirmation message to the first platform based on the negotiation message, the confirmation message indicating a negotiation result negotiated between the second node device and the target first node device;
[0063] access a private data area of the first platform based on a second message of the first platform, and obtain a second data directory corresponding to the target data directory;
[0064] The first data directory can be accessed by the first node device and / or the second node device at the first platform, and the second data directory can be accessed only by the first node device and / or the second node device authorized by the first platform.
[0065] In a fourth aspect, an embodiment of the present application provides a data directory sharing apparatus applied to a first node device, and the apparatus comprises:
[0066] a first data processing module configured to perform data processing on original data and / or an original data directory based on a data processing algorithm to obtain a first data directory;
[0067] a first sending module configured to send the first data directory to a first platform;
[0068] a first receiving module configured to receive a first message from the first platform;
[0069] The first sending module is further configured to send a second data directory to the first platform.
[0070] The first data directory can be accessed by the first node device and / or the second node device at the first platform, and the second data directory can be accessed only by the first node device and / or the second node device authorized by the first platform.
[0071] In a fifth aspect, an embodiment of the present application provides a data directory sharing apparatus applied to a first platform, and the apparatus comprises:
[0072] a second receiving module configured to receive a first data directory sent by at least one first node device and store the first data directory in a public data area;
[0073] The second sending module is configured to send a request message to the target first node device in response to the selected target data directory;
[0074] The second receiving module is further configured to receive an acknowledgement message sent by the second node device, the acknowledgement message indicating a negotiation result negotiated between the second node device and the target first node device;
[0075] The second data processing module is configured to generate and store a contract for data sharing based on the acknowledgement message;
[0076] The second sending module is further configured to send a first message to the target first node device and a second message to the second node device based on the contract;
[0077] The first data directory can be accessed by the first node device and / or the second node device on the first platform, and the second data directory can be accessed only by the first node device and / or the second node device authorized by the first platform.
[0078] In a sixth aspect, an embodiment of the present application provides a data directory sharing apparatus applied to a second node device, and the apparatus comprises:
[0079] The access module is configured to access a public data area of a first platform and acquire a first data directory sent by at least one first node device;
[0080] The selection module is configured to select a target data directory from the at least one first data directory and trigger the first platform to send a request message to a target first node device;
[0081] The third receiving module is configured to receive a negotiation message generated by the target first node device based on the request message;
[0082] The third sending module is configured to send an acknowledgement message to the first platform based on the negotiation message, the acknowledgement message indicating a negotiation result negotiated between the second node device and the target first node device;
[0083] The access module is further configured to access a private data area of the first platform based on the second message of the first platform and acquire a second data directory corresponding to the target data directory;
[0084] The first data directory can be accessed by the first node device and / or the second node device on the first platform, and the second data directory can be accessed only by the first node device and / or the second node device authorized by the first platform.
[0085] In a seventh aspect, an embodiment of the present application provides a first node device, comprising a processor and a memory for storing a computer program capable of running on the processor, wherein the processor is configured to execute the steps of the method in the first aspect of the embodiments of the present application when running the computer program.
[0086] In an eighth aspect, an embodiment of the present application provides a first platform, comprising a processor and a memory for storing a computer program capable of running on the processor, wherein the processor is configured to execute the steps of the method in the second aspect of the embodiments of the present application when running the computer program.
[0087] In a ninth aspect, an embodiment of the present application provides a second node device, comprising a processor and a memory for storing a computer program capable of running on the processor, wherein the processor is configured to execute the steps of the method in the third aspect of the embodiments of the present application when running the computer program.
[0088] In a tenth aspect, an embodiment of the present application provides a data sharing service system, comprising the first node device in the embodiments of the present application, the first platform in the embodiments of the present application, and the second node device in the embodiments of the present application.
[0089] In an eleventh aspect, an embodiment of the present application provides a storage medium, wherein the storage medium stores a computer program, and the computer program is configured to implement the steps of the method in the embodiments of the present application when executed by a processor.
[0090] The technical scheme provided by the embodiments of the present application is that the first node device performs data processing on the original data and / or the original data directory based on a data processing algorithm to obtain a first data directory; sends the first data directory to the first platform; receives a first message from the first platform, and sends a second data directory to the first platform; wherein the first data directory can be accessed by the first node device and / or the second node device on the first platform, and the second data directory is accessed only by the first node device and / or the second node device authorized by the first platform. In this way, the number of offline consultations can be reduced based on the first data directory on the first platform side, the efficiency of data element circulation can be improved, and the sharing of the second data directory can be realized based on the authorization of the first platform by the first node device and the second node device, thereby improving the security of online sharing of data directories. BRIEF DESCRIPTION OF DRAWINGS
[0091] Figure 1 FIG. 1 is a structural schematic diagram of a data sharing service system according to an embodiment of the present application;
[0092] Figure 2 FIG. 2 is a flowchart of a data directory sharing method according to an embodiment of the present application;
[0093] Figure 3Flowchart of another embodiment of the data catalog sharing method of the present application;
[0094] Figure 4 Flowchart of another embodiment of the data catalog sharing method of the present application;
[0095] Figure 5 Flowchart of another embodiment of the data catalog sharing method of the present application;
[0096] Figure 6 Flowchart of the "DSN uploading public domain data catalog" in the application embodiment of the present application;
[0097] Figure 7 Flowchart of the "auditing and right registration of public domain data catalog" in the application embodiment of the present application;
[0098] Figure 8 Flowchart of the "private domain data catalog authorization" in the application embodiment of the present application;
[0099] Figure 9 Flowchart of the "private domain data catalog shelving" in the application embodiment of the present application;
[0100] Figure 10 Structure diagram of the data catalog sharing device of an embodiment of the present application;
[0101] Figure 11 Structure diagram of the data catalog sharing device of another embodiment of the present application;
[0102] Figure 12 Structure diagram of the data catalog sharing device of another embodiment of the present application;
[0103] Figure 13 Structure diagram of the first node device of an embodiment of the present application;
[0104] Figure 14 Structure diagram of the first platform of an embodiment of the present application;
[0105] Figure 15 Structure diagram of the second node device of an embodiment of the present application. DETAILED DESCRIPTION
[0106] The present application will be further described in detail below in conjunction with the accompanying drawings and embodiments.
[0107] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used in the description herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the present application.
[0108] Before the data directory sharing method of the embodiments of the present application is described, the system to which the data directory sharing method of the embodiments of the present application is applied is described as follows:
[0109] The embodiments of the present application provide a data sharing service system for realizing online safe sharing of data directories. The system can also be referred to as a DSSN (Data Sharing Service Network) system. As shown in Figure 1 , the system comprises a first platform, i.e., a DSSP (Data Sharing Service Platform) shown in Figure 1 , and a plurality of node devices. According to different roles, the node devices are divided into first node devices as data providers and second node devices as data demanders. As shown in Figure 1 , the first node devices can also be referred to as data provider nodes (DSNs), and the second node devices can also be referred to as data demander nodes (DRNs). The DSSP and the node devices can be connected through an IP (Internet Protocol) private network to improve the security of data transmission.
[0110] In the embodiments of the present application, the first node device divides the data directory of the original data (also referred to as a data source) into a first data directory and a second data directory. The first data directory can be accessed by the first node device and / or the second node device on the first platform, i.e., the first data directory can be understood as a public domain data directory. The second data directory can be accessed only by the first node device and / or the second node device authorized by the first platform, i.e., the second data directory can be understood as a private domain data directory.
[0111] Here, the data directory can be understood as the field name of the original data, for example, including but not limited to: field name, field attribute, field type, etc.
[0112] Exemplarily, the first data directory is an anonymized data directory, and the second data directory is an original data directory.
[0113] The embodiments of the present application provide a data directory sharing method applied to the first node device described above. As shown in Figure 2 , the method comprises the following steps:
[0114] Step 201: Based on a data processing algorithm, the original data and / or the original data directory are processed to obtain a first data directory.
[0115] Exemplarily, the first node device can log in the first platform in advance, and download an algorithm package related to the data processing algorithm from the first platform. After installing the related algorithm package, the first node device performs data processing on the raw data and / or the raw data directory based on the data processing algorithm, to obtain a first data directory.
[0116] In step 202, the first data directory is sent to the first platform.
[0117] Here, after the first node device performs data processing on the raw data and / or the raw data directory based on the data processing algorithm to obtain the first data directory, the first node device can upload the first data directory to the first platform. Exemplarily, the first platform can perform auditing on the first data directory received from the first node device, for example, including but not limited to at least one of the following: whether the data source is reliable, whether the data format matches the requirement, whether the data is complete, whether the data is safe, etc. The auditing process can be manual review or automatic auditing based on an algorithm, and the embodiments of the present application do not limit this. The first platform can store the first data directory to a public data area based on the auditing result, for example, store the first data directory that passes the auditing to the public data area, so as to be accessed by each node device logged in the first platform.
[0118] In step 203, a first message from the first platform is received.
[0119] In step 204, a second data directory is sent to the first platform.
[0120] Here, the first message can be understood as an authorization instruction issued by the first platform to instruct the first node device to upload the second data directory. After receiving the first message, the first node device can send the second data directory to the first platform, for example, send the second data directory to the private data area of the first platform, so that the second data directory is only accessed by the node device authorized by the first platform, to guarantee the data security of the second data directory.
[0121] Exemplarily, the second node device as a data demander can select a target data directory (i.e., the selected first data directory) expected to cooperate after accessing the public data area of the first platform; the first platform sends a request message to the target first node device in response to the selected target data directory, the request message indicating that the data demander wants to access the second data directory corresponding to the target data directory to start the pricing negotiation between the data demander and the data provider; the target first node device generates and sends a negotiation message to the second node device based on the request message, and the second node device sends a confirmation message to the first platform, the confirmation message indicating the negotiation result negotiated between the second node device and the target first node device; the first platform generates and stores a contract for data sharing based on the confirmation message, and then sends a first message to the target first node device and a second message to the second node device based on the contract. The first message is used to instruct the target first node device to upload the second data directory, and the second message is used to authorize the second node device to access the second data directory.
[0122] It can be understood that based on the first data directory on the first platform side, the data demander can preliminarily screen the target data of interest, thereby reducing the number of offline negotiations between the data demander and the data provider, improving the efficiency of data element circulation, and based on the authorization of the first platform, the first node device uploads the second data directory to the private data area of the first platform, and the second data directory can only be accessed by the authorized node device, thereby improving the security of online sharing of data directories on the basis of improving the efficiency of data element circulation.
[0123] Exemplarily, the data processing algorithm is used to process the original data and / or the original data directory to obtain the first data directory, at least including:
[0124] The original data directory is anonymized based on the first algorithm to obtain the first data directory.
[0125] Exemplarily, before the original data directory is anonymized based on the first algorithm, the method further includes:
[0126] The original data and / or the original data directory are quality evaluated based on a second algorithm to obtain an evaluation result.
[0127] It is determined whether to anonymize the original data directory based on the first algorithm according to the evaluation result.
[0128] It is understood that the first node device performs a quality assessment on the original data and / or the original data directory based on the second algorithm, and determines whether to perform anonymization processing on the original data directory based on the assessment result of the quality assessment, so that the first data directory obtained by anonymizing the original data directory based on the first algorithm can meet the requirements of the first platform.
[0129] In the above scheme, before performing quality assessment on the original data and / or the original data catalog based on the second algorithm, the method further includes:
[0130] The original data is preprocessed based on a third algorithm.
[0131] Here, preprocessing the original data based on the third algorithm may include converting the data format of the original data so that the data format of the original data conforms to the standard of the first platform.
[0132] For example, the quality assessment of the original data and / or the original data catalog based on the second algorithm to obtain the assessment result includes:
[0133] A first encrypted evaluation result of the original data is generated based on the first sub-algorithm used for data quality assessment;
[0134] Send the first encryption evaluation result to the first platform;
[0135] Receive the decrypted first evaluation result returned by the first platform based on the first encryption evaluation result; and / or,
[0136] A second encrypted evaluation result of the original data directory is generated based on a second sub-algorithm used for data directory quality assessment;
[0137] Send the second encryption evaluation result to the first platform;
[0138] Receive the decrypted second evaluation result returned by the first platform based on the second encryption evaluation result.
[0139] It should be noted that in this embodiment, the first node device performs quality assessment on the original data and / or the original data directory, avoiding the problem of easy leakage of the original data and / or the original data directory caused by the platform performing quality assessment on the original data and / or the original data directory in related technologies. This embodiment, based on a first sub-algorithm to perform quality assessment on the original data and / or a second sub-algorithm to perform quality assessment on the original data directory, can transmit the assessment results to the first platform without the original data and / or the original data directory leaving the database, facilitating the data requester's overall understanding of the data quality provided by the data provider.
[0140] In this embodiment of the application, both the first sub-algorithm and the second sub-algorithm are cryptographic algorithms. The entire calculation process is performed using encrypted computation, and the key is managed by the first platform. In this way, while preventing the first node device from tampering with the algorithm package, the first platform can obtain the relevant quality assessment results without touching the original data and / or the data directory.
[0141] In one example, the first cryptographic evaluation result of the original data generated based on the first sub-algorithm includes:
[0142] The first node device extracts the vacancy rate, number of users, and outlier percentage of each field of the preprocessed raw data to form a feature vector v1 = [vacancy rate of field 1, number of users, outlier percentage of field 1, ...]. Based on the feature vector v1, it encrypts it using the public key Puk1 in the algorithm package to obtain [v1]. Then, it performs ciphertext multiplication between [v1] and the encryption weight [w] corresponding to the feature vector v1 in the program to obtain the encryption score [score1], which is the first encryption evaluation result. The encrypted score [score1] is then sent to the first platform.
[0143] After receiving the encrypted score [score1], the first platform extracts the private key R1 corresponding to the public key Puk1, decrypts [score1] to obtain score1, and returns score1 to the first node device, that is, returns the decrypted first evaluation result to the first node device.
[0144] In one example, the second cryptographic evaluation result of the original data directory, generated based on the second sub-algorithm, includes:
[0145] The first node device extracts field names, update frequency, attribute descriptions, vacancy rates, etc. from the original data directory to obtain information such as whether each field is interpretable, the timeliness of each field, and whether the name and attribute description of each field correspond to each other. This information forms a feature vector v2 = [whether field 1 is interpretable, the timeliness of field 1, and whether the name and attribute description of field 1 correspond to each other]. The feature vector v2 is encrypted using the public key Puk2 in the algorithm package to obtain [v2]. Then, a ciphertext multiplication is performed between [v2] and the encryption weight [w1] corresponding to the feature vector v2 in the program to obtain the encryption score [score2], which is the second encryption evaluation result. The encryption score [score2] is then sent to the first platform.
[0146] After receiving the encrypted score [score2], the first platform extracts the private key R2 corresponding to the public key Puk2, decrypts [score2] to obtain score2, and compares score2 with the preset value Thred1. It then returns the comparison result to the first node device, i.e., returns the decrypted second evaluation result to the first node device. Here, the preset value Thred1 can be understood as the threshold for judging whether the data directory quality meets the standard. In other examples, the first platform can return score2 to the first node device, which then determines whether the data directory quality meets the standard based on the result of score2 and the preset value Thred1.
[0147] For example, determining whether to anonymize the original data directory based on the evaluation result includes:
[0148] If the data directory meets the anonymization criteria based on the first evaluation result and / or the second evaluation result, then the original data directory is anonymized based on the first algorithm.
[0149] It is understandable that the first node device can determine whether the data directory anonymization conditions are met based on at least one of the first evaluation results and the second evaluation results. For example, if both the first evaluation results and the second evaluation results meet the criteria, the data directory anonymization conditions are met, and the original data directory is anonymized based on the first algorithm to obtain the first data directory.
[0150] For example, the anonymization process of the original data directory based on the first algorithm includes:
[0151] The sensitivity level of each field in the original data directory is determined based on the mapping relationship between fields and sensitivity levels;
[0152] Based on the sensitivity level of each field, the fields of the original data directory are merged to obtain the first data directory.
[0153] It is understood that the first node device determines the sensitivity level of each field in the original data directory based on the mapping relationship between fields and sensitivity levels. For example, fields are classified and graded according to their sensitivity, wherein the sensitivity levels include: Level 1 (corresponding to normal), Level 2 (corresponding to moderately sensitive), Level 3 (corresponding to sensitive), and Level 4 (corresponding to extremely sensitive).
[0154] For example, the fields of the original data catalog are divided into a first category and a second category. The first category includes: Category A, which represents user identity; Category B, which represents user service content; Category C, which represents user service derivative content; and Category D, which represents enterprise operation data. The second category further subdivides the above categories A to D. Specifically, Category A includes: Category A1, which represents user entity identity verification; Category A2, which represents user network identity; Category A3, which represents user basic information; and Category A4, which represents user identity authentication. Category B includes: Category B1, which represents service content log data; and Category B2, which represents contact information. Category C includes: Category C1, which represents consumption information; Category C2, which represents internet access information; Category C3, which represents location information; Category C4, which represents device information; Category C5, which represents violation information; and Category C6, which represents subscription services. Category D includes: Category D1, which represents publicly disclosed enterprise business operation information; Category D2, which represents general enterprise market operation data; Category D3, which represents core enterprise operation data; Category D4, which represents network equipment and IT system resource data; and Category D5, which represents enterprise cooperation channel information.
[0155] For example, the sensitivity levels are divided as follows:
[0156] Fourth level: A1, A4;
[0157] Third level: A2, A3, B1, B2, C3, D2, D5;
[0158] Second level: C1, C2, C4, D3, D4;
[0159] Level 1: C5, C6, D1.
[0160] It should be noted that the above sensitivity levels and classifications are merely examples and do not constitute a limitation on the scope of protection of this application.
[0161] In one application example, the details of the original data catalog are shown in Table 1 below:
[0162] Table 1
[0163]
[0164]
[0165] After anonymization, the resulting first data directory is shown in Table 2 below:
[0166] Table 2
[0167] Field category Field number Sensitivity level User entity identity 1 Fourth level Traffic and call consumption information 4 Second level
[0168] For example, before receiving the first message from the first platform, the method further includes:
[0169] Receive a request message from the first platform;
[0170] The first platform negotiates with the second node device, and the negotiation result is used to assign permissions to the first node device and / or the second node device.
[0171] For example, the request message carries the identifier of the second node device and the identifier of the target data directory. The first node device can complete the data source pricing based on the identifier of the target data directory. For instance, it can generate a feature vector v3 = [expected profit margin of this data source, cost of this data source, etc.] based on a preset pricing algorithm according to information such as the expected profit margin and data cost of the data source. The distance D1 is calculated by comparing v3 with the preset vector w2 = [highest expected profit margin of comparable data sources in the market, highest cost of comparable data sources in the market, etc.] corresponding to the feature vector v3 in the algorithm package. D1 is then multiplied by the preset highest pricing range of comparable data sources in the market in the algorithm package to obtain the suggested price range M for this data source. If M is lower than the preset price range M1 of the first node device, then M = M1, and the pricing information carries this M.
[0172] Understandably, a second node device, acting as a data requester, can select a target data directory (i.e., the selected first data directory) after accessing the public data area of the first platform. In response to the selected target data directory, the first platform sends a request message to the target first node device. This request message indicates that the data requester wishes to access the second data directory corresponding to the target data directory, thus initiating pricing negotiations between the data requester and the data provider. The target first node device generates and sends a negotiation message to the second node device based on the request message. The second node device then sends a confirmation message to the first platform, indicating the negotiation result between the second node device and the target first node device. For example, the confirmation message indicates that the data requester agrees to the pricing information generated by the target node device based on the request message. The first platform generates and stores a contract for data sharing based on the confirmation message. The first platform then sends a first message to the target first node device and a second message to the second node device based on this contract. The first message instructs the target first node device to upload the second data directory, and the second message authorizes the second node device to access the second data directory.
[0173] This application also provides a data directory sharing method, applied to a first platform, such as... Figure 3 As shown, the method includes:
[0174] Step 301: Receive a first data directory sent by at least one first node device and store the first data directory in the public domain data area.
[0175] Here, the first platform can receive the first data directory uploaded by the first node device and store the first data directory in the public domain data area for data requesters to access.
[0176] For example, receiving a first data directory sent by at least one first node device and storing the first data directory in the public domain data area includes:
[0177] Receive a first data directory sent by at least one first node device;
[0178] Generate the audit results for the first data directory;
[0179] Based on the audit results, the first data directory is stored in the public domain data area.
[0180] Here, the first platform can review the first data directory received from the first node device, including but not limited to at least one of the following: whether the data source is reliable, whether the data format matches the requirements, whether the data is complete, and whether the data is secure. This review process can be manual or algorithm-based automatic review, and this application embodiment does not limit this. Based on the review results, the first platform stores the first data directory in the public domain data area. For example, the first data directory that has passed the review is stored in the public domain data area for access by various data requesters who log in to the first platform.
[0181] Step 302: In response to the selected target data directory, send a request message to the target first node device.
[0182] Here, the request message indicates that the data requester wishes to access the second data directory corresponding to the target data directory. The second node device logged into the first platform can access the first data directory in the public domain data area and can select a target data directory for cooperation. For example, it can select a target data directory for cooperation based on the first data directory and related quality assessment results. In response to the selected target data directory, the first platform sends a request message to the target first node device that provides the target data directory. The target first node device can then send a negotiation message to the second node device, which is the data requester, based on this request message.
[0183] Understandably, the request message carries the identifier of the second node device and the identifier of the target data directory. The first node device can complete the data source pricing based on the identifier of the target data directory. For example, it can generate a feature vector v3 = [expected profit margin of this data source, cost of this data source, etc.] based on a preset pricing algorithm and information such as the expected profit margin and data cost of the data source. The distance D1 is calculated by comparing v3 with the preset vector w2 = [highest expected profit margin of comparable data sources in the market, highest cost of comparable data sources in the market, etc.] corresponding to the feature vector v3 in the algorithm package. D1 is then multiplied by the preset highest pricing range of comparable data sources in the market in the algorithm package to obtain the suggested price range M for this data source. If M is lower than the preset price range M1 of the first node device, then M = M1, and the negotiation message carries this M.
[0184] Step 303: Receive a confirmation message sent by the second node device as the data requester, the confirmation message indicating the negotiation result between the second node device and the target first node device.
[0185] Here, after receiving the negotiation message from the target first node device, the second node device sends a confirmation message to the first platform. For example, the confirmation message indicates that the data requester agrees to the pricing information generated by the target first node device based on the request message, that is, the data requester and the data provider reach an agreement on the data sharing transaction.
[0186] Step 304: Generate and store a contract for data sharing based on the confirmation message.
[0187] The first platform generates and stores a contract for data sharing based on the confirmation message. For example, before storing the contract, the first platform may also send a contract confirmation request to the aforementioned target first node device and second node device, and store the contract after receiving the contract confirmation response from both parties, for example, by storing the contract in a private domain data area.
[0188] Step 305: Send a first message to the target first node device and a second message to the second node device based on the contract.
[0189] Here, the first platform sends a first message to the target first node device and a second message to the second node device based on the contract. The first message is used to instruct the target first node device to upload the second data directory, and the second message is used to authorize the second node device to access the second data directory. In this way, the secure sharing of the data directory is achieved.
[0190] For example, the method further includes:
[0191] Receive the second data directory sent by the target first node device, and store the second data directory in the private domain data area.
[0192] It is understandable that after receiving the first message sent by the first platform, the target first node device can send the second data directory to the first platform, for example, send the second data directory to the private data area of the first platform, so that the second data directory can only be accessed by node devices authorized by the first platform, thus ensuring the data security of the second data directory.
[0193] For example, the method further includes:
[0194] Receive the access request generated by the second node device based on the second message, and authorize the second node device to view the second data directory within a set time period.
[0195] After receiving the second message, the second node device can generate and send an access request to the first platform, which will then authorize the second node device to view the second data directory within a set time period.
[0196] For example, the method further includes:
[0197] If the second node device is found to have viewed the second data directory for a set duration, then the second data directory is deleted.
[0198] Understandably, the first platform can delete the second data directory after determining that the second node device has viewed the second data directory for the set duration. The second node device can only view the data in the second directory within the set duration, effectively avoiding the risk of data directory details being leaked.
[0199] For example, the method further includes:
[0200] Receive the first encrypted evaluation result of the original data generated by the first node device based on the first sub-algorithm used for data quality assessment;
[0201] The first encryption evaluation result is decrypted to obtain the decrypted first evaluation result, and the first evaluation result is returned to the first node device; and / or,
[0202] Receive the second encrypted evaluation result of the original data directory generated by the first node device based on the second sub-algorithm used for data directory quality assessment;
[0203] The second encryption evaluation result is decrypted to obtain the decrypted second evaluation result, and the second evaluation result is returned to the first node device.
[0204] In this embodiment of the application, both the first sub-algorithm and the second sub-algorithm are cryptographic algorithms. The entire calculation process is performed using encrypted computation, and the key is managed by the first platform. In this way, while preventing the first node device from tampering with the algorithm package, the first platform can obtain the relevant quality assessment results without touching the original data and / or the original data directory.
[0205] This application also provides a data directory sharing method, applied to a second node device, such as... Figure 4 As shown, the method includes:
[0206] Step 401: Access the public domain data area of the first platform and obtain the first data directory sent by at least one first node device.
[0207] It is understandable that the second-node device, as the data demander, can access the public domain data area of the first platform and then obtain and view the first data directory uploaded by each first-node device.
[0208] Step 402: Select a target data directory from at least one first data directory and trigger the first platform to send a request message to the target first node device.
[0209] Understandably, users can view each primary data directory and its corresponding quality assessment results, thereby selecting the target data directory for potential cooperation. This avoids the shortcomings of traditional transactions where both parties are unaware of each other's data and only discover after multiple rounds of communication that the other party's data is not what they need, thus improving the efficiency of data transactions.
[0210] Here, the first platform responds to the selected target data directory by sending a request message to the target first node device, and the target first node device generates and sends a negotiation message to the second node device based on the request message.
[0211] Step 403: Receive the negotiation message generated by the target first node device based on the request message.
[0212] Here, the second node device receives a negotiation message generated by the target node device based on the request message. For example, the negotiation message carries pricing information.
[0213] Step 404: Send a confirmation message to the first platform based on the negotiation message. The confirmation message indicates the negotiation result between the second node device and the target first node device.
[0214] Here, if the user agrees to the pricing information sent by the target node device, the second node device can send a confirmation message to the first platform. This confirmation message indicates that the data requester agrees to the pricing information generated by the target first node device based on the request message.
[0215] Step 405: Based on the second message from the first platform, access the private data area of the first platform to obtain the second data directory corresponding to the target data directory.
[0216] Here, the first platform generates and stores a contract for data sharing based on the confirmation message, and then sends a second message to the second node device based on the contract. The second message authorizes the second node device to access the second data directory.
[0217] Figure 5 This application illustrates a data directory sharing method applied to a data sharing service system, as shown in the embodiments of this application. Figure 5 The data sharing service system includes: a Data Service Provider (DSSP), a Data Service Provider (DSN) as the data provider, and a Data Requester (DRN) as the data requester. The method includes:
[0218] Step 501: Download the relevant algorithm package.
[0219] Here, DSN logs into DSSP and downloads the relevant algorithm packages from DSSP, such as the algorithm packages for the first, second, and third algorithms mentioned above.
[0220] Step 502: Receive the algorithm packet.
[0221] Here, DSN retrieves the downloaded algorithm package.
[0222] Step 503: Install, deploy, and run the algorithm package.
[0223] Here, DSN installs, deploys, and runs the previously downloaded algorithm package.
[0224] Step 504: Anonymize directory information.
[0225] Here, DSN processes the original data and the original data directory based on the installed algorithm package to generate the first data directory, that is, it performs anonymization processing on the original data directory to obtain the first data directory and uploads the first data directory to DSSP.
[0226] Step 505: Review the public domain directory.
[0227] Here, the public domain directory received by the DSSP for review, that is, the first data directory for reviewing DSN uploads, includes, but is not limited to, at least one of the following: whether the data source is reliable, whether the data format matches the requirements, whether the data is complete, and whether the data is secure.
[0228] Step 506: Return the audit results.
[0229] Here, the DSSP returns the audit results to the DSN.
[0230] Step 507: After approval, request data catalog ownership confirmation.
[0231] Here, the DSN confirms whether the review is approved based on the review results. If the review is approved, it sends a data directory ownership confirmation request to the DSSP. If the review is not approved, it needs to regenerate and upload the anonymized data directory (i.e., the first data directory).
[0232] Step 508: Public Domain Directory Ownership Registration.
[0233] Here, after receiving the data directory ownership confirmation request, the DSSP stores the first data directory in the public domain data area, completing the ownership registration of the first data directory. It is understandable that the first data directory, after ownership registration, can be accessed by each DRN after logging into the DSSP.
[0234] Step 509: Check the public domain data directory and confirm the cooperative DSN.
[0235] Here, after logging into DSSP, DRN can access the public domain data area, view the public domain data directory, and select the DSN and public domain data directory to which they wish to cooperate.
[0236] Step 510: Complete pricing.
[0237] Here, the DRN interacts with the target DSN that it wishes to cooperate with to complete the pricing.
[0238] Understandably, after the DRN selects the target data directory on the DSSP, the DSSP sends a pricing request to the target DSN. The target DSN generates pricing information based on the pricing request and sends the pricing information to the DRN. The DRN then sends a confirmation message to the DSSP to confirm the pricing information, thus completing the pricing process.
[0239] Step 511, grant private directory authorization.
[0240] Here, the DSSP generates a contract for data sharing based on the confirmation information, and sends a first message to the target DSN and a second message to the DRN based on the contract to implement private domain directory authorization, that is, instructing the target DSN to upload the second data directory and authorizing the DRN to access the second data directory.
[0241] Step 512: Upload detailed information about the data directory.
[0242] Here, the DSN uploads the detailed information of the data directory (i.e., the second data directory) to the DSSP based on the first message. For example, it uploads the second data directory to the private domain data area of the DSSP.
[0243] Step 513: View the private domain data directory of DSN.
[0244] Here, the authorized DRN can view the data catalog details of the target DSN within the authorization period. For example, the data catalog details include: field names, data quality, etc.
[0245] Step 514: Send cooperation confirmation information.
[0246] Here, the DSSP sends a cooperation confirmation message to both the DRN and the DSN.
[0247] Step 515: Return the cooperation confirmation information result.
[0248] Here, DRN and DSN respectively return cooperation information confirmation results to DSSP, thereby achieving cooperation online and improving data transaction efficiency.
[0249] The present application will now be described in further detail with reference to an application embodiment.
[0250] In this application embodiment, the DSSP is divided into the following three subsystems according to its functional responsibilities:
[0251] 1) Computing Coordination Platform (DSS-C): For data requesters and providers, it connects and coordinates multiple computing nodes to complete secure data computing tasks. Key functions include DSSN private network management, node management, engine / model download, and computing project management.
[0252] 2) Data Trading Platform (DSS-T): Provides full-process data trading services for data demanders and data providers. Its main functions include data catalog listing, data ownership confirmation, data pricing, transaction matching, contract signing, data trading, transaction notarization, billing and settlement, payment, auditing and supervision, etc.
[0253] 3) Management Support Platform (DSS-M): For DSSP operators and managers, it provides functions such as operation management, security management and maintenance management.
[0254] In this application embodiment, DSN and DRN are mainly divided into a connection module, a data calculation module, and a data catalog management module based on their functions.
[0255] The data directory sharing method in this application embodiment includes the following stages:
[0256] 1) Upload public domain data directory via DSN;
[0257] 2) Review and registration of public domain data directories;
[0258] 3) Private domain data directory authorization;
[0259] 4) Private domain data catalog is put on the shelf.
[0260] The following sections will provide a detailed explanation of stages 1) to 4) of the above-mentioned stages.
[0261] The above stage 1) can be understood as the data provider completing the assessment of data quality and data catalog quality on the local node, and then anonymizing the data catalog according to the sensitivity of the fields before uploading it to DSSP. After the review is completed, it is published to the public domain data catalog module of the DSSP platform for platform users to view, thus completing the sharing of the anonymized catalog.
[0262] like Figure 6 As shown, stage 1) above may specifically include:
[0263] Step 601, Log in.
[0264] Here, when logging into the DSSP using a DSN, the login parameters may include information such as username, password, and organization identifier.
[0265] Step 602: Download data governance and other algorithm packages.
[0266] DSN downloads algorithm packages such as data governance, data quality assessment, data catalog quality assessment, and anonymization data catalog algorithms from the engine / algorithm download module of DSS-C.
[0267] Step 603: Receive the algorithm packet.
[0268] DSN acquires algorithm packages such as data governance, data quality assessment, data catalog quality assessment, and anonymous data catalog algorithms.
[0269] Step 604: Install and deploy data governance and other algorithm packages.
[0270] DSN installs and deploys algorithm packages such as data governance, data quality assessment, data catalog quality assessment, and anonymized data catalog algorithms.
[0271] Step 605: Synchronize algorithm configuration information.
[0272] After the algorithm package is installed and deployed, the DSN can synchronize the algorithm configuration information to the DSS-C connection module.
[0273] Step 606: Run the data governance algorithm package.
[0274] The DSN starts the data governance algorithm package, which preprocesses the data source information of the DSN node to make its format conform to the DSSP platform standard, that is, the aforementioned preprocessing of the original data based on the third algorithm.
[0275] Step 607: Run the data quality assessment algorithm package.
[0276] The DSN launches a data quality assessment algorithm package (corresponding to the first sub-algorithm mentioned above) to obtain an encrypted score [score1]. The algorithm package extracts information such as the vacancy rate, number of users, and outlier percentage of each field in the DSN-governed data to form a feature vector v1 = [vacancy rate of field 1, number of users, outlier percentage of field 1, ...]. The feature vector v1 is encrypted into [v1] using the public key Puk1 in the algorithm package. [v1] is multiplied by the encryption weight [w] corresponding to the feature vector v1 in the program to obtain the encrypted score [score1].
[0277] Step 608, synchronize [score1].
[0278] The DSN synchronizes the encrypted score [score1] to the DSS-C calculation module via the DSS-C connection module.
[0279] Step 609, decrypt [score1].
[0280] The DSS-C computation module decrypts [score1] to obtain score1. The computation process involves extracting the private key R1 corresponding to the public key Puk1 in the computation module and decrypting [score1] to obtain score1.
[0281] Step 610, synchronize score1.
[0282] The DSS-C calculation module synchronizes score1 to DSN via the DSS-C connection module.
[0283] Step 611: Run the data catalog quality assessment algorithm package.
[0284] The DSN launches a data catalog quality assessment algorithm package (corresponding to the second sub-algorithm mentioned above) to obtain an encrypted score [score2]. The algorithm package extracts field names, update frequency, attribute descriptions, and vacancy rates from the DSN data catalog details to obtain information such as whether each field is interpretable, the timeliness of each field, and whether the name and attribute description of each field correspond to each other. This information forms a feature vector v2 = [whether field 1 is interpretable, the timeliness of field 1, and whether the name and attribute description of field 1 correspond to each other]. The feature vector v2 is encrypted into [v2] using the public key Puk2 in the algorithm package. [v2] is multiplied by the encryption weight [w1] corresponding to the feature vector v2 in the program to obtain the encrypted score [score2].
[0285] Step 612, synchronize [score2].
[0286] The DSN synchronizes the encrypted score [score2] to the DSS-C calculation module via the DSS-C connection module.
[0287] Step 613, decrypt [score2].
[0288] The DSS-C calculation module decrypts [score2] to obtain score2.
[0289] Step 614: Obtain the alignment result by comparing score2 and Thred1.
[0290] The DSS-C calculation module compares score2 with the preset value Thred1 to obtain the comparison results.
[0291] Step 615: Synchronize and compare the results.
[0292] The DSS-C calculation module synchronizes the comparison results to the DSN via the DSS-C connection module.
[0293] Step 616: If the comparison result is greater than Thred1, run the data directory anonymization algorithm package.
[0294] If the comparison result is greater than Thred1, DSN starts the data directory anonymization algorithm package (corresponding to the first algorithm mentioned above) to obtain the anonymized data directory, that is, to obtain the first data directory. The specific data directory anonymization process can be referred to the above description, and will not be repeated here.
[0295] Step 617: Synchronize the anonymized data directory.
[0296] The DSN synchronizes the anonymized data directory to the public domain data directory module of the DSS-T via the DSS-C connection module.
[0297] Step 618: Review the anonymized data directory.
[0298] DSSP audits are synchronized to the anonymous data directory in the public domain data directory module of DSS-T.
[0299] Stage 2) above can be understood as the process by which DSSP reviews and registers the anonymized data catalog, referring to... Figure 7 Specifically, it includes:
[0300] Step 701: Review the public domain directory.
[0301] The DSS-T public domain data directory module completes the public domain data directory review. The public domain data directory refers to the anonymized data directory uploaded by DSN.
[0302] It is understood that the review of public domain data catalogs includes, but is not limited to, at least one of the following: whether the data source is reliable, whether the data format matches the requirements, whether the data is complete, and whether the data is secure. This review process can be manual or algorithm-based automatic review, and this application embodiment does not limit it.
[0303] Step 702: Synchronize the audit results.
[0304] The DSS-T public domain data directory module will feed back the audit results to the DSN through the DSS-C connection module.
[0305] Step 703: Request data ownership confirmation.
[0306] If the DSN receives the approval result, the DSN sends a data catalog ownership request to the DSS-T data ownership module through the DSS-C connection module.
[0307] Step 704: Public Domain Directory Ownership Registration.
[0308] The DSS-T data ownership module maps the public domain data directory uploaded by DSN to the enterprise information and stores it in the public domain data directory module.
[0309] Step 705: Synchronize the data ownership confirmation results.
[0310] The DSS-T data ownership confirmation module sends the results of the data directory ownership confirmation request to the DSN via the DSS-C connection module.
[0311] Stage 3) above can be understood as the authorization process for the private domain data directory, refer to... Figure 8 Specifically, it can include:
[0312] Step 801, Log in.
[0313] DRN logs into the DSSP platform.
[0314] Step 802: View the public domain directory and select the cooperation intention DSN.
[0315] DRNs access the DSS-T public domain data directory module through the DSS-C connection module, view all publicly available public domain data directories, and select the desired DSN from them. The public domain data directory is the directory of anonymized data uploaded by the DSN.
[0316] Step 803: Send a pricing request.
[0317] The DSS-C connection module sends a pricing request (corresponding to the aforementioned request message) to the intended DSN.
[0318] Step 804: Complete data pricing.
[0319] The intended DSN receives a pricing request from the DSS-C connection module and completes data source pricing. The data pricing rule involves an algorithm package generating a feature vector v3 = [expected profit margin of this data source, cost of this data source, etc.] based on information such as the expected profit margin and data cost of the data source. The distance D1 is calculated between v3 and the preset vector w2 = [highest expected profit margin of comparable data sources in the market, highest cost of comparable data sources in the market, etc.] corresponding to feature vector v3 in the algorithm package. D1 is multiplied by the preset highest pricing range of comparable data sources in the market in the algorithm package to obtain the suggested price range M for this data source. If M is lower than the DSN's preset price range M1, then M = M1.
[0320] Step 805: Send data source pricing.
[0321] The prospective DSN sends the data source pricing M (corresponding to the aforementioned negotiation message) to the DRN.
[0322] Step 806: Confirm data source price.
[0323] DRN confirms the data source price sent by DSN.
[0324] Step 807: Confirm the result synchronously.
[0325] DRN will synchronize the result of confirming the data source price (corresponding to the aforementioned confirmation message) to the transaction storage module of DSS-M via the DSS-C connection module.
[0326] Step 808: If the DRN agrees, generate the cooperation contract information between the two parties.
[0327] If the transaction storage module of DSS-M receives the result of the DRN confirming the data source price, it generates a contract in which the DRN and the intended DSN agree to share the data directory.
[0328] Step 809: Send contract confirmation information.
[0329] The DSS-M transaction storage module synchronizes contract confirmation information to the DRN and the intended DSN via the DSS-C connection module.
[0330] Step 810: Confirm cooperation information.
[0331] Both the DRN and the intended DSN confirmed the contract information.
[0332] Step 811, synchronize results.
[0333] The DRN and the intended DSN will synchronize the confirmation results to the transaction storage module of DSS-M via the DSS-C connection module.
[0334] Step 812: If both parties agree, the contract information will be stored and registered.
[0335] If the DSS-M transaction storage module receives confirmation that both the DRN and the intended DSN have been approved, then it stores the contracts for the DRN and the intended DSN.
[0336] Step 813, Authorization.
[0337] The DSS-T private domain data directory module sends authorization information to the DRN and the intended DSN respectively. For example, it sends a first authorization instruction to the intended DSN and a second authorization instruction to the DRN. The first authorization instruction is used to instruct the intended DSN to upload the private domain data directory, and the second authorization instruction is used to authorize the DRN to access the private domain data directory uploaded by the intended DSN.
[0338] Stage 4) above can be understood as the process of viewing the private domain data directory, as described above. Figure 9 The above stage 4) may specifically include:
[0339] Step 901: Synchronously upload the data directory details within the specified time.
[0340] Based on the authorization information, the intended DSN uploads the data directory details (i.e., the second data directory) to the private domain data directory module in DSS-T through the DSS-C connection module within the specified time.
[0341] Step 902: View the private domain data directory information.
[0342] Based on the authorization information, within the validity period of viewing the private domain data directory module of DSS-T, DRN can view the details of the data directory to be uploaded by the intended DSN and the data quality score through the connection module of DSS-C.
[0343] Step 903: If the authorized time has expired, destroy the data directory details.
[0344] After the authorized time expires, the DSS-T private domain data directory module will activate the destruction device to destroy the data directory details and data quality score information of the intended DSN.
[0345] Step 904: Revoke authorization.
[0346] The DSS-C connection module revokes the DRN's access permission to the private domain data directory module.
[0347] Step 905: Second confirmation of cooperation information.
[0348] The transaction storage module of DSS-M sends a secondary cooperation confirmation request to DRN through the connection module of DSS-C, which can be used for subsequent access to the DRN data directory.
[0349] Step 906, confirm information.
[0350] The DRN confirms the result via the DSS-C connection module and sends it to the DSS-M transaction storage module.
[0351] Step 907: If agreed, initiate the contract.
[0352] If the DSS-M transaction storage module receives the agreement, it will initiate a contract containing transaction information and pricing details from both parties, facilitating subsequent billing based on the actual number of data interactions, data volume, and data pricing between the two parties.
[0353] In order to implement the method of the embodiments of this application, the embodiments of this application also provide a data directory sharing device. The data directory sharing device is applied to a first node device and corresponds to the data directory sharing method on the first node device side. The steps in the embodiments of the data directory sharing method on the first node device side are also fully applicable to the embodiments of this data directory sharing device.
[0354] like Figure 10 As shown, the data directory sharing device includes: a first data processing module 1001, a first sending module 1002, and a first receiving module 1003. The first data processing module 1001 is used to process the original data and / or the original data directory based on a data processing algorithm to obtain a first data directory; the first sending module 1002 is used to send the first data directory to a first platform; the first receiving module 1003 is used to receive a first message from the first platform; the first sending module 1002 is also used to send a second data directory to the first platform; wherein, the first data directory can be accessed by a first node device and / or a second node device on the first platform, and the second data directory is only accessible by the first node device and / or the second node device authorized by the first platform.
[0355] In some embodiments, the first data processing module 1001 is specifically used for:
[0356] The original data directory is anonymized based on the first algorithm to obtain the first data directory.
[0357] In some embodiments, before the first data processing module 1001 performs anonymization processing on the original data directory based on the first algorithm, it is further configured to:
[0358] The quality of the original data and / or the original data catalog is evaluated based on the second algorithm to obtain the evaluation results.
[0359] Based on the evaluation results, determine whether to anonymize the original data directory using the first algorithm.
[0360] In some embodiments, before the first data processing module 1001 performs a quality assessment on the raw data and / or the raw data catalog based on the second algorithm, it is further configured to:
[0361] The original data is preprocessed based on a third algorithm.
[0362] In some embodiments, the first data processing module 1001 performs a quality assessment on the original data and / or the original data catalog based on a second algorithm to obtain an assessment result, including:
[0363] A first encrypted evaluation result of the original data is generated based on the first sub-algorithm used for data quality assessment;
[0364] Send the first encryption evaluation result to the first platform;
[0365] Receive the decrypted first evaluation result returned by the first platform based on the first encryption evaluation result; and / or,
[0366] A second encrypted evaluation result of the original data directory is generated based on a second sub-algorithm used for data directory quality assessment;
[0367] Send the second encryption evaluation result to the first platform;
[0368] Receive the decrypted second evaluation result returned by the first platform based on the second encryption evaluation result.
[0369] In some embodiments, the first data processing module 1001 determines whether to anonymize the original data directory based on the evaluation result, including:
[0370] If the data directory meets the anonymization criteria based on the first evaluation result and / or the second evaluation result, then the original data directory is anonymized based on the first algorithm.
[0371] In some embodiments, the first data processing module 1001 performs anonymization processing on the original data directory based on a first algorithm, including:
[0372] The sensitivity level of each field in the original data directory is determined based on the mapping relationship between fields and sensitivity levels;
[0373] Based on the sensitivity level of each field, the fields of the original data directory are merged to obtain the first data directory.
[0374] In some embodiments, the first receiving module 1003 is further configured to receive a request message from the first platform; the first sending module 1002 is further configured to negotiate with the second node device, and the negotiation result is used by the first platform to allocate permissions to the first node device and / or the second node device.
[0375] In some embodiments, the first data directory is an anonymous data directory, and the second data directory is the original data directory.
[0376] In practical applications, the first data processing module 1001, the first transmitting module 1002, and the first receiving module 1003 can be implemented by the processor in the data directory sharing device. Of course, the processor needs to run the computer program in the memory to implement its functions.
[0377] In order to implement the method of the embodiments of this application, the embodiments of this application also provide a data directory sharing device. The data directory sharing device is applied to a first platform and corresponds to the data directory sharing method on the first platform side. The steps in the embodiments of the data directory sharing method on the first platform side are also fully applicable to the embodiments of this data directory sharing device.
[0378] like Figure 11 As shown, the data directory sharing device includes: a second receiving module 1101, a second sending module 1102, and a second data processing module 1103. The second receiving module 1101 is used to receive a first data directory sent by at least one first node device and store the first data directory in a public domain data area; the second sending module 1102 is used to send a request message to a target first node device in response to a selected target data directory; the second receiving module 1101 is also used to receive a confirmation message sent by a second node device, the confirmation message indicating the negotiation result between the second node device and the target first node device; the second data processing module 1103 is used to generate and store a contract for data sharing based on the confirmation message; the second sending module 1102 is also used to send a first message to the target node device and a second message to the second node device based on the contract; wherein, the first data directory can be accessed by the first node device and / or the second node device on the first platform, and the second data directory is only accessed by the first node device and / or the second node device authorized by the first platform.
[0379] In some embodiments, the second receiving module 1101 is specifically used for:
[0380] Receive a first data directory sent by at least one first node device;
[0381] Generate the audit results for the first data directory;
[0382] Based on the audit results, the first data directory is stored in the public domain data area.
[0383] In some embodiments, the second receiving module 1101 is further configured to: receive the second data directory sent by the first node device, and store the second data directory in the private domain data area.
[0384] In some embodiments, the second receiving module 1101 is further configured to: receive an access request generated by the second node device based on the second message, and authorize the second node device to view the second data directory within a set time period.
[0385] In some embodiments, the second data processing module 1103 is further configured to: if the duration for which the second node device views the second data directory reaches the set duration, then delete the second data directory.
[0386] In some embodiments, the second receiving module 1101 is further configured to receive a first encrypted evaluation result of the original data generated by the first node device based on a first sub-algorithm for data quality assessment; the second data processing module 1103 is further configured to decrypt the first encrypted evaluation result to obtain a decrypted first evaluation result; the second sending module 1102 is further configured to return the first evaluation result to the first node device; and / or, the second receiving module 1101 is further configured to receive a second encrypted evaluation result of the original data directory generated by the first node device based on a second sub-algorithm for data directory quality assessment; the second data processing module 1103 is further configured to decrypt the second encrypted evaluation result to obtain a decrypted second evaluation result; the second sending module 1102 is further configured to return the second evaluation result to the first node device.
[0387] In practical applications, the second receiving module 1101, the second transmitting module 1102, and the second data processing module 1103 can be implemented by the processor in the data directory sharing device. Of course, the processor needs to run the computer program in the memory to implement its functions.
[0388] In order to implement the method of the embodiments of this application, the embodiments of this application also provide a data directory sharing device. The data directory sharing device is applied to a second node device and corresponds to the data directory sharing method on the second node device side. The steps in the embodiments of the data directory sharing method on the second node device side are also fully applicable to the embodiments of this data directory sharing device.
[0389] like Figure 12As shown, the data directory sharing device includes: an access module 1201, a selection module 1202, a third receiving module 1203, and a third sending module 1204. The access module 1201 accesses the public domain data area of the first platform to obtain a first data directory sent by at least one first node device; the selection module 1202 selects a target data directory from at least one first data directory, triggering the first platform to send a request message to the target first node device; the third receiving module 1203 receives a negotiation message generated by the target first node device based on the request message; the third sending module 1204 sends a confirmation message to the first platform based on the negotiation message, the confirmation message indicating the negotiation result between the second node device and the target first node device; the access module 1201 is also used to access the private domain data area of the first platform based on a second message from the first platform to obtain a second data directory corresponding to the target data directory; wherein, the first data directory can be accessed by the first node device and / or the second node device on the first platform, and the second data directory is only accessed by the first node device and / or the second node device authorized by the first platform.
[0390] In practical applications, the access module 1201, selection module 1202, third receiving module 1203, and third sending module 1204 can be implemented by the processor in the data directory sharing device. Of course, the processor needs to run the computer program in the memory to implement its functions.
[0391] It should be noted that the data directory sharing device provided in the above embodiments is only illustrated by the division of the above program modules when performing data directory sharing. In actual applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the processing described above. In addition, the data directory sharing device and the data directory sharing method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process can be found in the method embodiments, which will not be repeated here.
[0392] Based on the hardware implementation of the above program modules, and in order to implement the method of the embodiments of this application, the embodiments of this application also provide a first node device. Figure 13 This is only an exemplary structure of the first node device, not the entire structure; implementation is possible as needed. Figure 13 The structure shown may be part or all of the structure.
[0393] like Figure 13As shown, the first node device 1300 provided in this embodiment includes at least one processor 1301, a memory 1302, a user interface 1303, and at least one network interface 1304. The various components in the first node device 1300 are coupled together via a bus system 1305. It can be understood that the bus system 1305 is used to implement communication between these components. In addition to a data bus, the bus system 1305 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 13 The general designated all buses as Bus System 1305.
[0394] The user interface 1303 may include a monitor, keyboard, mouse, trackball, click wheel, buttons, touchpad, or touch screen.
[0395] The memory 1302 in this embodiment is used to store various types of data to support the operation of the first node device. Examples of such data include any computer program used to operate on the first node device.
[0396] The data directory sharing method disclosed in this application can be applied to or implemented by the processor 1301. The processor 1301 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the data directory sharing method can be completed by the integrated logic circuitry in the hardware of the processor 1301 or by instructions in software form. The processor 1301 can be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor 1301 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor, etc. The steps of the method disclosed in the embodiments of this application can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software modules can be located in a storage medium, which is located in the memory 1302. The processor 1301 reads the information in the memory 1302 and, in conjunction with its hardware, completes the steps of the data directory sharing method provided in the embodiments of this application.
[0397] In an exemplary embodiment, the first node device may be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components to perform the aforementioned method.
[0398] Based on the hardware implementation of the above program modules, and in order to implement the method of the embodiments of this application, the embodiments of this application also provide a first platform. Figure 14 This is merely an exemplary structure of the first platform, not the entire structure; implementation is possible as needed. Figure 14 The structure shown may be part or all of the structure.
[0399] like Figure 14 As shown, the first platform 1400 provided in this application embodiment includes: at least one processor 1401, a memory 1402, a user interface 1403, and at least one network interface 1404. The various components in the first platform 1400 are coupled together via a bus system 1405. It can be understood that the bus system 1405 is used to implement communication between these components. In addition to a data bus, the bus system 1405 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 14 The general labeled all buses as Bus System 1405.
[0400] The user interface 1403 may include a monitor, keyboard, mouse, trackball, click wheel, buttons, touchpad, or touch screen.
[0401] The memory 1402 in this embodiment is used to store various types of data to support the operation of the first platform. Examples of such data include any computer program used to operate on the first platform.
[0402] The data directory sharing method disclosed in this application can be applied to or implemented by the processor 1401. The processor 1401 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the data directory sharing method can be completed by integrated logic circuits in the hardware of the processor 1401 or by instructions in software form. The processor 1401 can be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor 1401 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor, etc. The steps of the method disclosed in the embodiments of this application can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software modules can be located in a storage medium, which is located in the memory 1402. The processor 1401 reads information from the memory 1402 and, in conjunction with its hardware, completes the steps of the data directory sharing method provided in the embodiments of this application.
[0403] In an exemplary embodiment, the first platform may be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.
[0404] Based on the hardware implementation of the above program modules, and in order to implement the method of the embodiments of this application, the embodiments of this application also provide a second node device. Figure 15 This is only an exemplary structure of the second node device, not the entire structure; it can be implemented as needed. Figure 15 The structure shown may be part or all of the structure.
[0405] like Figure 15 As shown, the second node device 1500 provided in this embodiment includes at least one processor 1501, a memory 1502, a user interface 1503, and at least one network interface 1504. The various components in the second node device 1500 are coupled together via a bus system 1505. It can be understood that the bus system 1505 is used to implement communication between these components. In addition to a data bus, the bus system 1505 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in… Figure 15 The general labeled all buses as Bus System 1505.
[0406] The user interface 1503 may include a monitor, keyboard, mouse, trackball, click wheel, buttons, touchpad, or touch screen.
[0407] The memory 1502 in this embodiment is used to store various types of data to support the operation of the second node device. Examples of such data include any computer program used to operate on the second node device.
[0408] The data directory sharing method disclosed in this application embodiment can be applied to or implemented by the processor 1501. The processor 1501 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the data directory sharing method can be completed by integrated logic circuits in the hardware of the processor 1501 or by instructions in software form. The processor 1501 can be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor 1501 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor, etc. The steps of the method disclosed in the embodiments of this application can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software modules can be located in a storage medium, which is located in the memory 1502. The processor 1501 reads information from the memory 1502 and, in conjunction with its hardware, completes the steps of the data directory sharing method provided in the embodiments of this application.
[0409] In an exemplary embodiment, the second node device may be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.
[0410] It is understood that memories 1302, 1402, and 1502 can be volatile or non-volatile memories, or both. Non-volatile memories can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), ferromagnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disc, or compact disc read-only memory (CD-ROM); magnetic surface memory can be disk storage or magnetic tape storage. Volatile memories can be random access memory (RAM), used as external cache. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDRSDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), SyncLink Dynamic Random Access Memory (SLDRAM), and Direct Rambus Random Access Memory (DRRAM).The memories described in the embodiments of this application are intended to include, but are not limited to, these and any other suitable types of memories.
[0411] This application also provides a data sharing service system, including: a first node device as described in this application embodiment, a first platform as described in this application embodiment, and a second node device as described in this application embodiment. For example, as... Figure 1 As shown, the first platform, the first node device, and the second node device can be connected via a private IP network to improve the security of data transmission.
[0412] In exemplary embodiments, this application also provides a storage medium, namely a computer storage medium, specifically a computer-readable storage medium, such as a memory 1302 including a computer program, which can be executed by the processor 1301 of a first node device to complete the steps described in the first node device-side method of this application embodiment; or, for example, a memory 1402 including a computer program, which can be executed by the processor 1401 of a first platform to complete the steps described in the first platform-side method of this application embodiment; or, for example, a memory 1502 including a computer program, which can be executed by the processor 1501 of a second node device to complete the steps described in the second node device-side method of this application embodiment. The computer-readable storage medium can be a ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM, etc.
[0413] It should be noted that terms such as "first" and "second" are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.
[0414] Furthermore, the technical solutions described in the embodiments of this application can be combined arbitrarily without conflict.
[0415] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A data directory sharing method, characterized in that, Applied to a first-node device, the method includes: The original data and / or the original data directory are processed using data processing algorithms to obtain the first data directory; Send the first data directory to the first platform; Receive the first message from the first platform; Send the second data directory to the first platform; The first data directory can be accessed by the first node device and / or the second node device on the first platform, while the second data directory can only be accessed by the first node device and / or the second node device authorized by the first platform. The first data directory is an anonymous data directory, and the second data directory is the original data directory.
2. The method according to claim 1, characterized in that, The first data directory, obtained by processing the original data and / or the original data directory based on the data processing algorithm, includes at least: The original data directory is anonymized based on the first algorithm to obtain the first data directory.
3. The method according to claim 2, characterized in that, Before performing anonymization processing on the original data directory based on the first algorithm, the method further includes: The quality of the original data and / or the original data catalog is evaluated based on the second algorithm to obtain the evaluation results. Based on the evaluation results, determine whether to anonymize the original data directory using the first algorithm.
4. The method according to claim 3, characterized in that, Before performing quality assessment on the original data and / or the original data catalog based on the second algorithm, the method further includes: The original data is preprocessed based on a third algorithm.
5. The method according to claim 3, characterized in that, The quality assessment of the original data and / or the original data catalog based on the second algorithm, to obtain the assessment results, includes: A first encrypted evaluation result of the original data is generated based on the first sub-algorithm used for data quality assessment; Send the first encryption evaluation result to the first platform; Receive the decrypted first evaluation result returned by the first platform based on the first encryption evaluation result; and / or, A second encrypted evaluation result of the original data directory is generated based on a second sub-algorithm used for data directory quality assessment; Send the second encryption evaluation result to the first platform; Receive the decrypted second evaluation result returned by the first platform based on the second encryption evaluation result.
6. The method according to claim 5, characterized in that, The step of determining whether to anonymize the original data directory based on the evaluation result includes: If the data directory meets the anonymization criteria based on the first evaluation result and / or the second evaluation result, then the original data directory is anonymized based on the first algorithm.
7. The method according to claim 2, characterized in that, The anonymization process of the original data directory based on the first algorithm includes: The sensitivity level of each field in the original data directory is determined based on the mapping relationship between fields and sensitivity levels; Based on the sensitivity level of each field, the fields of the original data directory are merged to obtain the first data directory.
8. The method according to claim 1, characterized in that, Before receiving the first message from the first platform, the method further includes: Receive a request message from the first platform; The first platform negotiates with the second node device, and the negotiation result is used to assign permissions to the first node device and / or the second node device.
9. A data directory sharing method, characterized in that, Applied to a first platform, the method includes: Receive a first data directory sent by at least one first node device and store the first data directory in the public domain data area; In response to the selected target data directory, a request message is sent to the target first node device; Receive a confirmation message sent by the second node device, the confirmation message indicating the negotiation result between the second node device and the target first node device; A contract for data sharing is generated and stored based on the confirmation message; Based on the contract, a first message is sent to the target first node device and a second message is sent to the second node device; Wherein, the first message is used to instruct the target first node device to upload the second data directory, the second message is used to authorize the second node device to access the second data directory, the first data directory can be accessed by the first node device and / or the second node device on the first platform, the second data directory can only be accessed by the first node device and / or the second node device authorized by the first platform, the first data directory is an anonymous data directory, and the second data directory is an original data directory.
10. The method according to claim 9, characterized in that, The step of receiving a first data directory sent by at least one first node device and storing the first data directory in the public domain data area includes: Receive a first data directory sent by at least one first node device; Generate the audit results for the first data directory; Based on the audit results, the first data directory is stored in the public domain data area.
11. The method according to claim 9, characterized in that, The method further includes: Receive the second data directory sent by the target first node device, and store the second data directory in the private domain data area.
12. The method according to claim 9, characterized in that, The method further includes: Receive the access request generated by the second node device based on the second message, and authorize the second node device to view the second data directory within a set time period.
13. The method according to claim 12, characterized in that, The method further includes: If the second node device is found to have viewed the second data directory for a set duration, then the second data directory is deleted.
14. The method according to claim 9, characterized in that, The method further includes: Receive the first encrypted evaluation result of the original data generated by the first node device based on the first sub-algorithm used for data quality assessment; The first encryption evaluation result is decrypted to obtain the decrypted first evaluation result, and the first evaluation result is returned to the first node device; and / or, Receive the second encrypted evaluation result of the original data directory generated by the first node device based on the second sub-algorithm used for data directory quality assessment; The second encryption evaluation result is decrypted to obtain the decrypted second evaluation result, and the second evaluation result is returned to the first node device.
15. A data directory sharing method, characterized in that, Applied to a second node device, the method includes: Access the public domain data area of the first platform and obtain the first data directory sent by at least one first node device; Selecting a target data directory in at least one first data directory triggers the first platform to send a request message to the target first node device. Receive the negotiation message generated by the target first node device based on the request message; A confirmation message is sent to the first platform based on the negotiation message, and the confirmation message indicates the negotiation result between the second node device and the target first node device; Based on the second message from the first platform, access the private data area of the first platform to obtain the second data directory corresponding to the target data directory; The first data directory can be accessed by the first node device and / or the second node device on the first platform, while the second data directory can only be accessed by the first node device and / or the second node device authorized by the first platform. The first data directory is an anonymous data directory, and the second data directory is the original data directory.
16. A data directory sharing device, characterized in that, Applied to a first node device, the device includes: The first data processing module is used to process the original data and / or the original data directory based on the data processing algorithm to obtain the first data directory. The first sending module is used to send the first data directory to the first platform; The first receiving module is used to receive a first message from the first platform; The first sending module is also used to send the second data directory to the first platform; The first data directory can be accessed by the first node device and / or the second node device on the first platform, while the second data directory can only be accessed by the first node device and / or the second node device authorized by the first platform. The first data directory is an anonymous data directory, and the second data directory is the original data directory.
17. A data directory sharing device, characterized in that, Applied to a first platform, the device includes: The second receiving module is used to receive a first data directory sent by at least one first node device and store the first data directory in the public domain data area. The second sending module is used to send a request message to the target first node device in response to the selected target data directory; The second receiving module is further configured to receive a confirmation message sent by the second node device, the confirmation message indicating the negotiation result between the second node device and the target first node device; The second data processing module is used to generate and store a contract for data sharing based on the confirmation message; The second sending module is further configured to send a first message to the target first node device and a second message to the second node device based on the contract; Wherein, the first message is used to instruct the target first node device to upload the second data directory, the second message is used to authorize the second node device to access the second data directory, the first data directory can be accessed by the first node device and / or the second node device on the first platform, the second data directory can only be accessed by the first node device and / or the second node device authorized by the first platform, the first data directory is an anonymous data directory, and the second data directory is an original data directory.
18. A data directory sharing device, characterized in that, Applied to a second node device, the device includes: The access module is used to access the public domain data area of the first platform and obtain the first data directory sent by at least one first node device; The selection module is used to select a target data directory from at least one first data directory and trigger the first platform to send a request message to the target first node device. The third receiving module is used to receive the negotiation message generated by the target first node device based on the request message; The third sending module is used to send a confirmation message to the first platform based on the negotiation message, wherein the confirmation message indicates the negotiation result between the second node device and the target first node device; The access module is also used to access the private domain data area of the first platform based on the second message of the first platform, and obtain the second data directory corresponding to the target data directory; The first data directory can be accessed by the first node device and / or the second node device on the first platform, while the second data directory can only be accessed by the first node device and / or the second node device authorized by the first platform. The first data directory is an anonymous data directory, and the second data directory is the original data directory.
19. A first node device, characterized in that, include: A processor and memory for storing computer programs that can run on the processor, wherein, The processor, when running a computer program, performs the steps of the method according to any one of claims 1 to 8.
20. A first platform, characterized in that, include: A processor and memory for storing computer programs that can run on the processor, wherein, The processor, when running a computer program, performs the steps of the method according to any one of claims 9 to 14.
21. A second node device, characterized in that, include: A processor and memory for storing computer programs that can run on the processor, wherein, The processor is configured to execute the steps of the method of claim 15 when running a computer program.
22. A data sharing service system, characterized in that, include: The first node device as described in claim 19, the first platform as described in claim 20, and the second node device as described in claim 21.
23. A storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 15.
Citation Information
Patent Citations
Systems and methods for anonymizing navigation information
CA3087718A1
Data processing method and device, electronic equipment and readable medium
CN111143880A