Data fusion system

By introducing encryption and obfuscation circuit technology into the data fusion system, the perceived data of the data provider is encrypted and data fusion is carried out on the computing server, the problems of low data security and uneven data distribution are solved, and the accuracy and security of the data fusion results are improved.

CN118764179BActive Publication Date: 2025-05-16STATE GRID HUBEI ELECTRIC POWER INFORMATION & TELECOMMUNICATION COMPANY +2
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202410743837.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-11
Publication Date
2025-05-16
Estimated Expiration
2044-06-11

AI Technical Summary

Technical Problem

During the data fusion process, the perceived data of the data provider is transmitted in plain text, resulting in low security; the different participation of the data provider leads to uneven data distribution, affecting the accuracy of the data fusion results; and when selecting the data provider, it is difficult to balance the perceived data volume and credibility weight.

Method used

A data fusion system is designed, including a key server, a computing server and a data collection server. By generating a data mask sequence and an disturbance sensing data sequence, the perceived data is encrypted, and the data fusion is used to ensure that the data is processed under the ciphertext.

Benefits of technology

It improves the perceived data security of the data provider, reduces the risk of data leakage, and improves the accuracy of data fusion results through weighted arithmetic averaging and other methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118764179B_ABST
    Figure CN118764179B_ABST
Patent Text Reader

Abstract

The embodiment of the present disclosure discloses a data fusion system. A specific implementation of the system includes: a key server, a computing server and at least two data collection servers, wherein each data collection server generates a data mask sequence and a disturbance perception data sequence; the key server performs obfuscation processing on each data mask to obtain at least two obfuscated data mask sequences; the key server performs obfuscation processing on at least two disturbance perception data sequences to obtain at least two obfuscated perception data sequences, and sends at least two obfuscated perception data sequences to the computing server to generate at least two target obfuscated perception data sequences; the computing server constructs a data fusion obfuscation circuit, and inputs at least two target obfuscated perception data sequences, at least two obfuscated data mask sequences and an initial perception target true value sequence into the obfuscation circuit; and generates a data fusion result. This implementation improves the security of the perception data of each data provider.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present disclosure relate to the field of computer technology, and in particular to a data fusion system. Background Art

[0002] Data fusion plays an important role in improving the accuracy of the perception results of the crowd perception task. At present, the method usually adopted for data fusion is that each data provider directly sends the perception data corresponding to the crowd perception task to the data fusion server, and the data fusion server directly performs data fusion processing on the received perception data plaintexts, and stores or sends the data fusion results to the initiator of the crowd perception task.

[0003] However, in practice, when the above method is used for data fusion, the following technical problems often occur:

[0004] First, since the perception data sent by each data provider is presented in plain text throughout the entire process of data fusion, the risk of data leakage is high, resulting in low security of the perception data of each data provider;

[0005] Second, due to the different degrees of participation of various data providers in the execution of crowd-sensing tasks, the amount of perception data submitted by each party varies greatly, which easily leads to the long-tail effect of data distribution. For example, some data providers with higher credibility submit less data, which leads to lower accuracy of data fusion results.

[0006] In the process of adopting technical solutions to solve the above-mentioned technical problems 1 and 2, the following technical problem 3 is often accompanied: how to select data providers to improve the accuracy of perception data. For the above-mentioned technical problem 3, the conventional solution is: when selecting data providers, select each data provider whose credibility weight is higher than the preset credibility threshold to perform the group intelligence perception task. However, the above-mentioned conventional solution still has the following problem: since there is no positive correlation between the amount of data provided by the data provider and the credibility weight, if a higher credibility threshold is set, the amount of perception data collected will be less, and if a lower credibility threshold is set, it is easy to reduce the data quality.

[0007] The above information disclosed in this Background section is only for enhancement of understanding of the background of the present disclosure concept and therefore it may contain information that does not form the prior art that is already known in this country to a person of ordinary skill in the art. Summary of the invention

[0008] The content of this disclosure is used to introduce concepts in a brief form, which will be described in detail in the detailed implementation section below. The content of this disclosure is not intended to identify the key features or essential features of the technical solution claimed for protection, nor is it intended to limit the scope of the technical solution claimed for protection.

[0009] Some embodiments of the present disclosure propose a data fusion system to solve one or more of the technical problems mentioned in the above background technology section.

[0010] In a first aspect, some embodiments of the present disclosure provide a data fusion system, the data fusion system comprising a key server, an operation server and at least two data collection servers, wherein each of the at least two data collection servers is configured to: in response to receiving a perception data sequence sent by a user terminal corresponding to the data collection server for a target perception task, generate a data mask sequence and a disturbance perception data sequence, and send the data mask sequence to the key server, and send the disturbance perception data sequence to the operation server; the key server is configured to, in response to receiving at least two data mask sequences sent by the at least two data collection servers, and in response to determining that preset obfuscation circuit connection information is not empty, perform obfuscation processing on each data mask in the at least two data mask sequences to obtain at least two obfuscated data mask sequences, and send the preset obfuscation circuit connection information and the at least two obfuscated data mask sequences to the operation server, wherein the preset obfuscation circuit connection information corresponds to a data fusion obfuscation circuit, and the data fusion obfuscation circuit is based on a pre-constructed data mask removal function. , a data collector weight update function and a perception target true value estimation function; the operation server is configured to send the at least two disturbance perception data sequences to the key server in response to receiving the at least two disturbance perception data sequences sent by the at least two data collection servers, and in response to receiving the preset obfuscation circuit connection information and the at least two obfuscation data mask sequences; the key server is also configured to perform obfuscation processing on the at least two disturbance perception data sequences in response to receiving the at least two disturbance perception data sequences to obtain at least two obfuscation perception data sequences, and send the at least two obfuscation perception data sequences to the operation server to generate at least two target obfuscation perception data sequences; the operation server is also configured to construct a data fusion obfuscation circuit based on the preset obfuscation circuit connection information, and input the at least two target obfuscation perception data sequences, the at least two obfuscation data mask sequences and the pre-generated initial perception target true value sequence as input parameters into the data fusion obfuscation circuit to output a fused perception target true value sequence; based on the fused perception target true value sequence, generate a data fusion result.

[0011] The above-mentioned embodiments of the present disclosure have the following beneficial effects: through the data fusion system of some embodiments of the present disclosure, the security of the perception data of each data provider is improved. Specifically, the reason for the low security of the perception data of each data provider is that in the entire process of data fusion, the data of each data provider is presented in plain text, which makes the risk of data leakage high, thus easily leading to the low security of the perception data of each data provider. Based on this, the data fusion system of some embodiments of the present disclosure includes a key server, a computing server and at least two data collection servers. Among them, first, each of the at least two data collection servers is configured to: in response to receiving the perception data sequence sent by the corresponding user terminal for the target perception task, generate a data mask sequence and a perturbation perception data sequence, and send the data mask sequence to the key server, and send the perturbation perception data sequence to the computing server. Among them, the data collection server in the at least two data collection servers corresponds to the user terminal in the user terminal set. In this way, the encrypted perception data of each data provider can be obtained, so that data fusion can be performed under ciphertext later to reduce the risk of data leakage. Secondly, the key server is configured to, in response to receiving at least two data mask sequences sent by the at least two data collection servers, and in response to determining that the preset obfuscation circuit connection information is not empty, perform obfuscation processing on each data mask in the at least two data mask sequences to obtain at least two obfuscated data mask sequences, and send the preset obfuscation circuit connection information and the at least two obfuscated data mask sequences to the operation server. Wherein, the preset obfuscation circuit connection information corresponds to the data fusion obfuscation circuit, and the data fusion obfuscation circuit is constructed according to the pre-constructed data mask removal function, the data collector weight update function and the perception target true value estimation function. Thus, the information of the obfuscation circuit for data fusion and the data mask for encrypting the perception data can be securely transmitted to the operation server. Then, the operation server is configured to, in response to receiving at least two perturbation perception data sequences sent by the at least two data collection servers, and in response to receiving the preset obfuscation circuit connection information and the at least two obfuscated data mask sequences, send the at least two perturbation perception data sequences to the key server. The key server is also configured to, in response to receiving the at least two disturbance perception data sequences, perform obfuscation processing on the at least two disturbance perception data sequences to obtain at least two obfuscated perception data sequences, and send the at least two obfuscated perception data sequences to the operation server to generate at least two target obfuscated perception data sequences.Thus, the operation server can select the obfuscated perception data that matches the perturbed perception data it has from all the obfuscated perturbation perception data provided by the key server, while ensuring that the key server cannot know the selection result of the operation server. Afterwards, the operation server is also configured to construct a data fusion obfuscation circuit based on the preset obfuscation circuit connection information, and input the at least two target obfuscated perception data sequences, the at least two obfuscated data mask sequences and the pre-generated initial perception target true value sequence as input parameters into the data fusion obfuscation circuit to output the fused perception target true value sequence. Thus, data fusion can be achieved for the perception data in the ciphertext state corresponding to each perception target, and the true value after data fusion can be obtained. Finally, based on the fused perception target true value sequence, a data fusion result is generated. Therefore, the data fusion system implemented encrypts the perception data of the corresponding data provider through the data collection server, and uses the obfuscation circuit to perform data fusion on the encrypted perception data on the data operation server, which can reduce the risk of data leakage and improve the security of the perception data of each data provider. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] The above and other features, advantages and aspects of the embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the accompanying drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that components and elements are not necessarily drawn to scale.

[0013] Figure 1 is an exemplary structural diagram of a data fusion system disclosed in the present invention;

[0014] Figure 2 is a timing diagram of a data fusion system according to the present disclosure. DETAILED DESCRIPTION

[0015] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as being limited to the embodiments set forth herein. On the contrary, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not intended to limit the scope of protection of the present disclosure.

[0016] It should also be noted that, for ease of description, only the parts related to the invention are shown in the drawings. In the absence of conflict, the embodiments and features in the embodiments of the present disclosure can be combined with each other.

[0017] It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0018] It should be noted that the modifications of "one" and "plurality" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, it should be understood as "one or more".

[0019] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.

[0020] The present disclosure will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments.

[0021] Figure 1 is an exemplary structural diagram of some embodiments of the data fusion system of the present disclosure.

[0022] Figure 1 FIG. 2 shows a schematic diagram of the structure of some embodiments of the data fusion system according to the present disclosure. Figure 1 As shown, the data fusion system provided by the present disclosure may include a key server 101, an operation server 102 and at least two data collection servers 103. Among them, the at least two data collection servers 103 may include data collection server 1, data collection server 2 and data collection server 3. Each of the at least two data collection servers 103 is independent of each other and is not connected to each other in communication. Each of the at least two data collection servers 103 is connected to the key server 101 and the operation server 102 in communication. The key server 101 is connected to the operation server 102 in communication.

[0023] It should be understood that Figure 1 The number of data collection servers is only for illustration. According to the needs of implementing the crowd intelligence perception task, the same number of data collection servers can be set for user terminals equal to or greater than 2. Among them, the user terminal is a terminal used by the data collector to send the collected perception data to the data collection server.

[0024] Further references Figure 2 , which shows a timing diagram of a data fusion system disclosed in the present invention.

[0025] like Figure 2As shown, a data fusion system includes: a key server, a computing server and at least two data collection servers. The interaction steps between the key server, the computing server and the at least two data collection servers may include the following steps:

[0026] Step 201: Each of at least two data collection servers generates a data mask sequence and a disturbance perception data sequence in response to receiving a perception data sequence sent by a user terminal of the corresponding data collection server for a target perception task.

[0027] In some embodiments, each of the at least two data collection servers may generate a data mask sequence and a disturbance perception data sequence in response to receiving a perception data sequence sent by a user terminal corresponding to the data collection server for a target perception task. The target perception task may be a crowd-sensing task including at least one perception target. The perception target may be information about the type of perception data to be collected. The perception target may correspond to a subtask of the crowd-sensing task. The data collection server may correspond to the data collector one-to-one. The data collector may be an organization or individual responsible for collecting the perception data required for the target perception task. Each data collector is associated with a data collector identifier. The data collector identifier may be a unique identifier of the data collector. For example, the data collector identifier may be a number. The user terminal may be a terminal for sending the collected perception data of the corresponding data collector. The perception data in the perception data sequence may correspond to the perception target one-to-one. The perception data sequence may be a sequence in which each perception data is arranged according to the order of the perception target corresponding to the perception data in a preset perception target sequence. The perception target sequence may be a pre-set, ordered set of each perception target. The perception data in the above-mentioned perception data sequence may be data collected by sensors corresponding to the perception target. For example, the perception data may include but is not limited to at least one of the following: temperature, humidity, pressure, and number of steps. The perception data in the perception data sequence may correspond one-to-one with the data mask with the same sequence number in the corresponding data mask sequence. The perception data in the perception data sequence may also correspond one-to-one with the disturbance perception data with the same sequence number in the corresponding disturbance perception data sequence. The data mask in the data mask sequence may be a random binary mask. The disturbance perception data in the disturbance perception data sequence may be encrypted perception data. It should be noted that the number of perception data collected by each data collector may be the same or different.

[0028] In some optional implementations of some embodiments, each of the at least two data collection servers may perform the following steps to generate a corresponding data mask sequence and a disturbance-aware data sequence:

[0029] The first step is to generate a data mask sequence based on the preset mask bit number information. The preset mask bit number information may be a preset value representing the number of bits of a binary mask. The data mask sequence may be generated based on the preset mask bit number information by a preset random mask generation method.

[0030] As an example, the above-mentioned random mask generation method may be a mask generation method based on a random number generator.

[0031] The second step is to generate a disturbed perception data sequence based on the data mask sequence and the perception data sequence. For each perception data in the perception data sequence, the following steps may be performed:

[0032] The first sub-step is to select a data mask matching the sensed data from the data mask sequence as a target data mask, wherein matching the sensed data may be that the sequence number of the data mask in the data mask sequence is the same as the sequence number of the sensed data in the sensed data sequence.

[0033] In the second sub-step, an XOR operation is performed on the target data mask and the perception data to obtain the disturbed perception data.

[0034] Step 202: Each of the at least two data collection servers sends a corresponding data mask sequence to a key server and a corresponding disturbance sensing data sequence to a computing server.

[0035] In some embodiments, each of the at least two data collection servers may send the corresponding data mask sequence to the key server and the corresponding disturbance perception data sequence to the operation server. In practice, each of the at least two data collection servers may communicate with the key server and the operation server through a data transmission protocol, and send the corresponding data mask sequence to the key server and the corresponding disturbance perception data sequence to the operation server. For example, the data transmission protocol may be the HTTPS (Hypertext Transfer Protocol Secure) protocol.

[0036] Optionally, each of the at least two data collection servers may also send a corresponding data collection party identifier to the operation server.

[0037] Step 203: In response to receiving at least two data mask sequences sent by at least two data collection servers and determining that the preset obfuscation circuit connection information is not empty, the key server performs obfuscation processing on each data mask in the at least two data mask sequences to obtain at least two obfuscated data mask sequences.

[0038] In some embodiments, the key server may be configured to, in response to receiving at least two data mask sequences sent by the at least two data collection servers, and in response to determining that the preset obfuscation circuit connection information is not empty, perform obfuscation processing on each data mask in the at least two data mask sequences to obtain at least two obfuscated data mask sequences, and send the preset obfuscation circuit connection information and the at least two obfuscated data mask sequences to the operation server. The preset obfuscation circuit connection information may correspond to the data fusion obfuscation circuit. The preset obfuscation circuit connection information may characterize the logical correspondence between the input and output of each subcircuit in the data fusion obfuscation circuit. The subcircuit may be an obfuscation circuit that implements a single function. The data fusion obfuscation circuit may be constructed according to a pre-constructed data mask removal function, a data collector weight update function, and a perception target true value estimation function. The data mask removal function may be a function that restores the perturbed perception data to the perception data by removing the data mask. The data collector weight update function may be a function for iteratively updating the credibility weight of the data collector. The credibility weight may characterize the credibility of the data collector. The perceptual target true value estimation function may be a function for iteratively updating the perceptual target true value. The perceptual target true value may be the true value of the perceptual data corresponding to the perceptual target. Each obfuscated data mask in the at least two obfuscated data mask sequences may be a data mask after obfuscation processing.

[0039] As an example, when the preset obfuscation circuit connection information is {"subcircuit 1": ["input 11", "input 12", "output 13"], "subcircuit 2": ["input 21", "input 22", "output 23"], "subcircuit connection information": [("subcircuit 1", "subcircuit 2", "output 3")]}, the input parameters of subcircuit 1 include input 11 and input 12, and the output parameter is output 13, and the input parameters of subcircuit 2 include input 21 and input 22, and the output parameter is output 23. At this time, the output parameters of subcircuit 1 and the output parameters of subcircuit 2 can be used as the input parameters of the same obfuscation circuit, thereby obtaining the output 3 of the obfuscation circuit output. For each data mask in the at least two data mask sequences, the key server can perform obfuscation processing on the data mask through the following obfuscation data mask generation step to generate the obfuscated data mask in the at least two obfuscation data mask sequences:

[0040] In the first step, based on a preset encryption key, each bit value in the data mask is encrypted to obtain an encrypted data mask. The preset encryption key may be a pre-set key for symmetrically encrypting the input column of the truth table corresponding to the gate circuit.

[0041] The second step is to shuffle the order of the values ​​of the encrypted data mask by calling a preset binary number reordering interface to obtain an obfuscated data mask. The binary number reordering interface can shuffle the order of the values ​​of the encrypted data mask by a random number generation algorithm and a bit operation method to obtain an obfuscated data mask.

[0042] Optionally, the above data mask removal function can be constructed as:

[0043]

[0044] Wherein, k represents the serial number corresponding to the data collector, t represents the serial number corresponding to the perceived target in the perceived target sequence, and d represents the perceived data. represents the perception data corresponding to the tth perception target of the kth data collector in the data collector sequence. The above data collector sequence can be an ordered set of data collectors that perform the above target perception task. Representing sensory data The corresponding perturbation-aware data. r represents the data mask. represents the data mask corresponding to the t-th perception target of the k-th data collector. OXR(·) represents the exclusive-OR operation.

[0045] Optionally, the above data collector weight update function can be constructed as:

[0046]

[0047] Where c represents the normalization coefficient. ω represents the credibility weight. T represents the perceived target sequence. * Represents the true value of the perceived target. represents the true value of the perceived target corresponding to the tth perceived target. k represents the normalization coefficient corresponding to the kth data collector. k Represents the perception target sequence corresponding to the perception data sequence of the kth data collector. k Represents the credibility weight of the kth data collector. 2 represents chi-square distribution. β represents the significance level.

[0048] Optionally, the above perception target true value estimation function can be constructed as:

[0049]

[0050] Where P represents the data collection party sequence. t It indicates the sequence of data collectors corresponding to the t-th perception target. It should be noted that the above function formula can better demonstrate the algorithm flow of data fusion. When the data fusion algorithm is actually executed later, the fusion operation can be performed on each perception data under the ciphertext according to the obfuscation circuit representing the above function formula.

[0051] The above-mentioned data collector weight update function and the above-mentioned data collector weight update function, as an inventive point of the embodiment of the present disclosure, solve the above-mentioned technical problem 2 "the accuracy of the data fusion result is low". The factors that lead to the low accuracy of the data fusion result are often as follows: due to the different participation of each data provider in the execution of the group intelligence perception task, the number of perception data submitted by each party is quite different, which is easy to cause the long tail effect of data distribution. For example, some data providers with higher credibility submit less data. If the above factors are solved, the effect of improving the accuracy of the data fusion result can be achieved. In order to achieve this effect, first, for each data collector, the credibility weight of the data collector is determined according to the difference between the perception data and the true value of each corresponding perception target. Then, on the basis of determining the credibility weight of each data collector, the result of weighted arithmetic averaging of the perception data of each data collector is further determined as the perception target true value. Finally, when the obfuscation circuit constructed by the above-mentioned functions is actually executed, the above-mentioned weight update and perception target true value estimation process are also iterated multiple times to make the algorithm result converge, thereby obtaining a data fusion result with higher accuracy.

[0052] Optionally, the computing server may perform the following steps:

[0053] The first step is to construct a data fusion Boolean circuit based on a preset number of iterations, a pre-built data mask removal function, a data collector weight update function, and a perception target true value estimation function in response to receiving at least two data mask sequences sent by the above-mentioned at least two data collection servers, and in response to determining that the above-mentioned preset obfuscation circuit connection information is empty. The above-mentioned preset number of iterations may be a preset number of times for updating and iterating the data collector weights and the perception target true values. The above-mentioned data fusion Boolean circuit may be a Boolean circuit for generating the data collector weights and the perception target true values ​​required for data fusion. The above-mentioned operation server may construct a data fusion Boolean circuit based on a preset number of iterations, a pre-built data mask removal function, a data collector weight update function, and a perception target true value estimation function through a preset Boolean circuit generation interface. The above-mentioned Boolean circuit generation interface may be an interface for calling a common electronic design automation tool to generate a Boolean circuit according to the input function information.

[0054] The second step is to perform obfuscation conversion processing on the data fusion Boolean circuit to obtain a converted obfuscated circuit. The converted obfuscated circuit may be an obfuscated Boolean circuit. The operation server may perform obfuscation conversion processing on the data fusion Boolean circuit by using obfuscation circuit technology to obtain a converted obfuscated circuit.

[0055] As an example, the operation server generally performs the following steps for each gate circuit in the data fusion Boolean circuit according to the obfuscation circuit technology: first, a truth table corresponding to the gate circuit is created. Then, each value in the truth table corresponding to the gate circuit is symmetrically encrypted and replaced to obtain a replacement truth table corresponding to the gate circuit. Among them, the same input column or output column uses the same encryption key. Afterwards, according to the two input columns in the replacement truth table, the output column is encrypted to obtain an encrypted replacement truth table, and finally, through a preset reordering algorithm, each row in the encrypted replacement truth table is reordered to obtain an obfuscated truth table corresponding to the gate circuit. For example, the reordering algorithm can be a shuffling algorithm. In response to determining that each gate circuit in the data fusion Boolean circuit has a corresponding obfuscated truth table, the operation server can determine the data fusion Boolean circuit as a converted obfuscated circuit.

[0056] The third step is to perform obfuscation processing on each data mask in the at least two data mask sequences to obtain at least two obfuscated data mask sequences. For each data mask in the at least two data mask sequences, the obfuscated data mask generating step can be used to generate an obfuscated data mask in the at least two obfuscated data mask sequences.

[0057] The fourth step is to send the converted obfuscation circuit and the at least two obfuscated data mask sequences to the operation server to generate a fused perception target true value sequence.

[0058] Step 204: The key server sends the preset obfuscation circuit connection information and at least two obfuscation data mask sequences to the operation server.

[0059] In some embodiments, the key server may send the preset obfuscation circuit connection information and the at least two obfuscation data mask sequences to the operation server. In practice, the key server may send the preset obfuscation circuit connection information and the at least two obfuscation data mask sequences to the operation server via the data transmission protocol.

[0060] Step 205: In response to receiving at least two disturbance-aware data sequences sent by at least two data collection servers and receiving preset obfuscation circuit connection information and at least two obfuscation data mask sequences, the operation server sends at least two disturbance-aware data sequences to the key server.

[0061] In some embodiments, the operation server may send the at least two disturbance-perceiving data sequences to the key server in response to receiving the at least two disturbance-perceiving data sequences sent by the at least two data collection servers, and in response to receiving the preset obfuscation circuit connection information and the at least two obfuscation data mask sequences.

[0062] As an example, the operation server may, in response to receiving at least two disturbance-perceiving data sequences sent by the at least two data collection servers, and in response to receiving the preset obfuscation circuit connection information and the at least two obfuscated data mask sequences, sort the at least two disturbance-perceiving data sequences by bubble sorting according to the data collector identifier corresponding to each disturbance-perceiving data sequence and the preset data collector identifier sequence, and send the sorted at least two disturbance-perceiving data sequences to the key server by oblivious transfer protocol. The data collector identifier sequence may be a collection of data collector identifiers arranged in chronological order according to the time when the corresponding data collector first performs the crowd intelligence perception task.

[0063] Optionally, the computing server may further perform the following steps to generate at least two initial perception target true value sequences:

[0064] The first step is to generate a Gaussian random variable group in response to receiving at least two disturbance perception data sequences sent by the at least two data collection servers. The Gaussian random variables in the Gaussian random variable group may be random variables that obey the same Gaussian distribution. The Gaussian random variable group may be generated by a random variable generation method based on Gaussian distribution.

[0065] The second step is to determine the initial perception target true value sequence corresponding to the at least two perturbed perception data sequences based on the Gaussian random variable group. The initial perception target true value in the initial perception target true value sequence may be the true value of the perception data corresponding to the perception target set by the initialization. Specifically, the following steps may be performed:

[0066] In a first sub-step, each perception target corresponding to at least two disturbance perception data sequences is determined as a perception target set.

[0067] The second sub-step is to sort the above-mentioned perception target set according to the order of the preset global perception target sequence to obtain the perception target sequence. The above-mentioned global perception target sequence may be an ordered set of perception targets corresponding to each group intelligence perception task. The above-mentioned perception target set may be a subset of the above-mentioned global perception target sequence. The above-mentioned perception target set may be sorted according to the order of the preset global perception target sequence by a preset sorting algorithm to obtain the perception target sequence.

[0068] As an example, the above sorting algorithm may include but is not limited to at least one of the following: bubble sort, quick sort.

[0069] The third sub-step is to randomly select a Gaussian random variable from the above-mentioned Gaussian random variable group for each perception target in the above-mentioned perception target sequence, and determine the selected Gaussian random variable as the initial perception target true value corresponding to the above-mentioned perception target.

[0070] Step 206: The key server is further configured to, in response to receiving at least two disturbance-aware data sequences, perform obfuscation processing on the at least two disturbance-aware data sequences to obtain at least two obfuscated data sequences.

[0071] In some embodiments, the key server may, in response to receiving the at least two disturbance-perceived data sequences, perform obfuscation processing on the at least two disturbance-perceived data sequences to obtain at least two obfuscated perception data sequences. The obfuscated perception data in the at least two obfuscated perception data sequences may be disturbance-perceived data with a disrupted order. The key server may perform obfuscation processing on each disturbance-perceived data sequence in the at least two disturbance-perceived data sequences by the reordering algorithm to obtain at least two obfuscated perception data sequences.

[0072] As an example, the key server may perform obfuscation processing on the order corresponding to each disturbance perception data sequence according to the order of each disturbance perception data sequence received by the reordering algorithm to obtain at least two obfuscated perception data sequences. As another example, when the computing server packages the at least two disturbance perception data sequences into a data packet and sends it to the key server, the key server may perform obfuscation processing on the order corresponding to each disturbance perception data sequence according to the order of each disturbance perception data sequence received by the computing server to obtain at least two obfuscated perception data sequences.

[0073] Step 207: The key server sends at least two obfuscation perception data sequences to the operation server to generate at least two target obfuscation perception data sequences.

[0074] In some embodiments, the key server sends the at least two confusion perception data sequences to the operation server to generate at least two target confusion perception data sequences. The target confusion perception data in the at least two target confusion perception data sequences may be confusion perception data corresponding to the disturbance perception data in the at least two disturbance perception data sequences. The key server may send the at least two confusion perception data sequences to the operation server through the oblivious transfer protocol to generate at least two target confusion perception data sequences. The operation server may select, for each disturbance perception data sequence in the at least two disturbance perception data sequences, a confusion perception data sequence corresponding to the disturbance perception data sequence from the at least two confusion perception data sequences as a target confusion perception data sequence. The disturbance perception data sequence corresponding to the disturbance perception data sequence may be a confusion perception data sequence in which the order of the confusion perception data sequence is disrupted.

[0075] Step 208: The computing server constructs a data fusion obfuscation circuit based on the preset obfuscation circuit connection information.

[0076] In some embodiments, the computing server may construct a data fusion obfuscation circuit based on the preset obfuscation circuit connection information in various ways.

[0077] In the process of adopting technical solutions to solve the technical problems in the background technology, the following problem often arises: how to construct a data fusion obfuscation circuit to shorten the time it takes to generate data fusion results. In response to the above problems, the conventional solution is to optimize the obfuscation circuit. However, the above conventional solution still has the following problem: when the algorithm or encryption method corresponding to the data fusion obfuscation circuit is more complex, the structure of the obfuscation circuit is also more complex. Even if it can be properly optimized, it still takes a lot of time to construct the data fusion obfuscation circuit during the execution of the algorithm, which results in a longer time to generate the data fusion results and difficulty in generating the data fusion results in a timely manner. Therefore, considering the problems existing in the above conventional solutions, the following solutions can be adopted:

[0078] In some optional implementations of some embodiments, the data fusion system may further include an obfuscated arithmetic circuit component library server. The obfuscated arithmetic circuit component library server may be a server for storing obfuscated arithmetic circuits. The arithmetic circuit may be a circuit composed of various logic gate circuits for performing basic arithmetic operations. For example, the arithmetic circuit may include but is not limited to at least one of the following: an addition circuit, a subtraction circuit, and a multiplication circuit. The preset obfuscated circuit connection information may include an obfuscated arithmetic circuit identification set, inter-subcircuit connection information, data preprocessing subcircuit connection information, weight update subcircuit connection information, and truth value estimation subcircuit connection information. The obfuscated arithmetic circuit identification in the obfuscated arithmetic circuit identification set may be a unique identification of the obfuscated arithmetic circuit. The obfuscated arithmetic circuit may be an arithmetic circuit obtained by offline calculation before the data fusion algorithm is started, and the truth table corresponding to each logic gate circuit included is an obfuscated truth table. The inter-subcircuit connection information may characterize the logical connection relationship between the various subcircuits. The data preprocessing subcircuit connection information may characterize the logical connection relationship between the obfuscated arithmetic circuits in the data preprocessing subcircuit. The data preprocessing subcircuit may be an obfuscation circuit corresponding to the above-mentioned data mask removal function. The above-mentioned weight update subcircuit connection information may characterize the logical connection relationship between the obfuscated arithmetic circuits in the weight update subcircuit. The above-mentioned weight update subcircuit may be an obfuscation circuit corresponding to the above-mentioned data collector weight update function. The above-mentioned truth value estimation subcircuit connection information may characterize the logical connection relationship between the obfuscated arithmetic circuits in the truth value estimation subcircuit. The above-mentioned truth value estimation subcircuit may be an obfuscation circuit corresponding to the above-mentioned perception target truth value estimation function. Among them, the above-mentioned operation server may construct a data fusion obfuscation circuit based on the preset obfuscation circuit connection information through the following steps:

[0079] Step 1: Send the obfuscated arithmetic circuit identification set included in the preset obfuscated circuit connection information to the obfuscated arithmetic circuit component library server, and receive the obfuscated arithmetic circuit set sent by the obfuscated arithmetic circuit component library server. The obfuscated arithmetic circuit in the obfuscated arithmetic circuit set may be an arithmetic circuit corresponding to the obfuscated arithmetic circuit identification in the obfuscated arithmetic circuit identification set.

[0080] Optionally, the obfuscated arithmetic circuit component library server may also be configured to, in response to receiving the obfuscated arithmetic circuit identification set, select an obfuscated arithmetic circuit that matches the obfuscated arithmetic circuit identification set from the stored obfuscated arithmetic circuits to obtain the obfuscated arithmetic circuit set. Matching the obfuscated arithmetic circuit identification set may be that the identification corresponding to the obfuscated arithmetic circuit exists in the obfuscated arithmetic circuit identification set.

[0081] Step 2: construct a data preprocessing subcircuit based on the data preprocessing subcircuit connection information included in the above-mentioned preset obfuscation circuit connection information and the above-mentioned obfuscation arithmetic circuit set. Wherein, the data preprocessing subcircuit can be constructed through a preset circuit link generation interface based on the data preprocessing subcircuit connection information included in the above-mentioned preset obfuscation circuit connection information and the above-mentioned obfuscation arithmetic circuit set. The above-mentioned circuit link generation interface can encapsulate a subcircuit link generation method and a subcircuit connection method. The above-mentioned subcircuit link generation method can be a method for connecting each arithmetic circuit according to the logical connection relationship between the arithmetic circuits. The above-mentioned subcircuit connection method can be a method for connecting each subcircuit according to the logical connection relationship between the subcircuits.

[0082] Step 3: construct a weight update subcircuit based on the weight update subcircuit connection information included in the preset obfuscation circuit connection information and the obfuscation arithmetic circuit set. The weight update subcircuit can be constructed based on the weight update subcircuit connection information included in the preset obfuscation circuit connection information and the obfuscation arithmetic circuit set by using the subcircuit link generation method included in the circuit link generation interface.

[0083] Step 4: construct a truth value estimation subcircuit based on the truth value estimation subcircuit connection information included in the preset obfuscation circuit connection information and the obfuscation arithmetic circuit set. The truth value estimation subcircuit can be constructed based on the truth value estimation subcircuit connection information included in the preset obfuscation circuit connection information and the obfuscation arithmetic circuit set by using the subcircuit link generation method included in the circuit link generation interface.

[0084] Step 5: construct a data fusion obfuscation circuit based on the above-mentioned inter-subcircuit connection information, the above-mentioned data preprocessing subcircuit, the above-mentioned weight updating subcircuit and the above-mentioned true value estimation subcircuit. The data fusion obfuscation circuit can be constructed based on the above-mentioned inter-subcircuit connection information, the above-mentioned data preprocessing subcircuit, the above-mentioned weight updating subcircuit and the above-mentioned true value estimation subcircuit through the inter-subcircuit connection method included in the above-mentioned circuit link generation interface.

[0085] In practice, the sub-circuit connection information also includes sub-circuit reuse information. The sub-circuit reuse information may be information about the number of times the sub-circuit is reused. The sub-circuit reuse information may correspond to the preset number of iterations. For example, when the preset number of iterations is 5, the number of times the weight update sub-circuit and the true value estimation sub-circuit are reused is also 5.

[0086] The above-mentioned data fusion obfuscation circuit construction method and its related contents, as an inventive point of an embodiment of the present disclosure, solve the problem of "how to construct a data fusion obfuscation circuit to shorten the generation time of data fusion results". The above-mentioned operation server pre-calculates and generates each obfuscation arithmetic circuit in an offline manner, and when the data fusion algorithm needs to be executed, the various obfuscation arithmetic circuits are connected online according to the connection relationship of the data fusion obfuscation circuit to form a data fusion obfuscation circuit for executing the data fusion algorithm. Therefore, when the algorithm or encryption method corresponding to the data fusion obfuscation circuit is more complex, the structure of the obfuscation circuit is also more complex. By means of the above-mentioned inventive point, when the algorithm is executed, the required obfuscation circuit can be quickly constructed for data fusion by connecting each obfuscation arithmetic circuit component pre-calculated offline. Thereby, the generation time of the data fusion result can be shortened, and the data fusion result can be generated in time.

[0087] Step 209, the computing server uses at least two target obfuscated perception data sequences, at least two obfuscated data mask sequences, and a pre-generated initial perception target true value sequence as input parameters, and inputs them into a data fusion obfuscation circuit to output a fused perception target true value sequence.

[0088] In some embodiments, the computing server may input the at least two target obfuscated perception data sequences, the at least two obfuscated data mask sequences, and the pre-generated initial perception target true value sequence into the data fusion obfuscation circuit to output a fused perception target true value sequence. The fused perception target true value in the fused perception target true value sequence may be the true value of each perception data of the corresponding perception target after fusion.

[0089] In some optional implementations of some embodiments, the operation server may, in response to determining that the preset obfuscation circuit connection information is empty, input the at least two target obfuscated perception data sequences, the at least two obfuscation data mask sequences and the pre-generated initial perception target true value sequence as input parameters into the converted obfuscation circuit to output a fused perception target true value sequence.

[0090] Step 210: The computing server generates a data fusion result based on the fused perception target true value sequence.

[0091] In some embodiments, the computing server may generate a data fusion result based on the fused perception target true value sequence, wherein the data fusion result may be a result of fusion of the perception data provided by the data collectors to improve the data accuracy.

[0092] In some optional implementations of some embodiments, the computing server may generate a data fusion result based on the fused perception target true value sequence through the following steps:

[0093] Step 1: Send each fused perception target true value in the fused perception target true value sequence to the key server in sequence to perform a decryption operation, and receive a perception target result data sequence corresponding to the fused perception target true value sequence sent by the key server. The perception target result data in the perception target result data sequence may be the result of fusion of each perception data corresponding to the perception target. For example, when the perception target is air temperature, the perception target result data may be a temperature value obtained by weighted average of each temperature perception data from different data collectors.

[0094] Optionally, in response to receiving any fused perceived target true value sent by the operation server, the key server may decrypt the any fused perceived target true value to obtain perceived target result data, and send the perceived target result data to the operation server. The key server may decrypt the any fused perceived target true value by using the key corresponding to the any fused perceived target true value to obtain perceived target result data, and send the perceived target result data to the operation server.

[0095] It should be noted that after the key server sends at least two obfuscation mask sequences to the operation server, the operation server and the key server perform interactive communication via the oblivious transfer protocol.

[0096] Step 2: Determine the above-mentioned perception target result data sequence and the preset perception task type identifier as the data fusion result, and store the above-mentioned data fusion result in a preset database. Among them, the above-mentioned preset perception task type identifier can be a unique identifier of a preset target perception task. The above-mentioned preset database can be a preset database for storing various data fusion results.

[0097] Optionally, the data fusion system may further include a data request client. The data request client may be a terminal for a data requester to input a data request. The computing server may perform the following steps:

[0098] The first step is to, in response to receiving the data request information sent by the above-mentioned data request client, perform a query operation on the above-mentioned preset database based on the above-mentioned data request information to obtain a query result. Among them, the above-mentioned data request information may include but is not limited to the data requester identifier and the task type identifier. The above-mentioned data requester identifier may be a unique identifier of the user who initiated the data request. The above-mentioned task type identifier may be a unique identifier of the crowd intelligence perception task. The above-mentioned query result may be information on the data fusion result corresponding to the above-mentioned data request information. The above-mentioned operation server may use the task type identifier included in the above-mentioned data request information as a query keyword, perform a query operation on the above-mentioned preset database, and obtain a query result.

[0099] In the second step, in response to determining that the query result is not empty, the query result is sent to the data requesting client for display.

[0100] Optionally, the data requesting client displays the query result in response to receiving the query result.

[0101] In some optional implementations of some embodiments, the data request information may include a data requester identifier and request text information. The request text information may be a text describing a crowd intelligence perception task for which data results are to be obtained. The computing server may further perform the following steps:

[0102] In the first step, in response to determining that the query result is empty, the request text information included in the data request information is segmented to obtain a text segmentation group. The text segmentation in the text segmentation group may be a word obtained after segmentation. The request text information included in the data request information may be segmented by a preset text segmentation method to obtain a text segmentation group. For example, the text segmentation method may include but is not limited to at least one of the following: a hidden Markov model, a segmentation algorithm based on a conditional random field model.

[0103] The second step is to determine the target keywords corresponding to the above text word groups. The above target keywords can represent the group intelligence perception task to be performed. Specifically, the following steps can be performed:

[0104] The first sub-step is to match a preset stop word list with the text segmentation group to obtain a first processed text segmentation group. The stop word list may be a data table recording stop words. For each text segmentation in the text segmentation group, in response to determining that the stop word list does not contain the same stop word as the text segmentation, the text segmentation is determined as the first processed text segmentation.

[0105] The second sub-step is to select a first processed text segmentation satisfying a preset word count condition from the first processed text segmentation group as a reference keyword. The preset word count condition may be: the word count corresponding to the first processed text segmentation is the maximum value among the word counts corresponding to the first processed text segmentations.

[0106] In the third sub-step, the first processed text segmentation that does not match the reference keyword is selected from the first processed text segmentation group as the keyword to be spliced, and each keyword to be spliced ​​is obtained. The first processed text segmentation that does not match the reference keyword may be that the similarity between the first processed text segmentation and the reference keyword is not greater than the lower limit of the similarity. For example, the lower limit of the similarity may be 0.

[0107] The fourth sub-step is to perform adjacent splicing processing on the reference keyword and each keyword to be spliced ​​according to the text order of the request text information to obtain the target keyword. The adjacent splicing processing can be directly splicing each word to be spliced ​​in sequence according to the splicing order, and there is no space or character between each word.

[0108] The third step is to query the pre-built perception task allocation knowledge graph based on the data requester identifier included in the above data request information to obtain a perception task information group. Among them, the above perception task allocation knowledge graph can be a knowledge graph with crowd perception tasks and data collectors as nodes and the association relationship between crowd perception tasks and data collectors as edges. Among them, the association relationship between crowd perception tasks and data collectors can be an allocation relationship. The allocation relationship can represent that the crowd perception task is assigned to the data collector. The perception task information in the above perception task information group can be text information corresponding to the name of the crowd perception task.

[0109] The fourth step is to match the above-mentioned perception task information group with the above-mentioned target keyword to generate target perception task information. The above-mentioned target perception task information may be perception task information with a high degree of similarity to the target keyword. Specifically, the following steps may be performed:

[0110] In the first sub-step, the target keyword is subjected to word embedding processing to obtain a keyword feature vector. The keyword feature vector can represent the target keyword. The target keyword can be subjected to word embedding processing by a preset word embedding processing method to obtain a keyword feature vector.

[0111] As an example, the above-mentioned word embedding processing method may include but is not limited to at least one of the following: one-hot encoding, bag-of-words model.

[0112] The second sub-step is to perform the following steps for each perception task information in the above perception task information group:

[0113] Sub-step 1: word embedding processing is performed on the above-mentioned perception task information to obtain a task text feature vector. The above-mentioned task text feature vector can represent the above-mentioned perception task information. The above-mentioned word embedding processing method can be used to perform word embedding processing on the above-mentioned perception task information to obtain a task text feature vector.

[0114] Sub-step 2: performing association analysis on the keyword feature vector and the task text feature vector to obtain text similarity. The text similarity can represent the similarity between the perceived task information and the target keyword. The keyword feature vector and the task text feature vector can be associated with each other using a preset association analysis method to obtain text similarity.

[0115] As an example, the above-mentioned association analysis processing method may be a cosine similarity method.

[0116] Sub-step three, in response to determining that the text similarity satisfies a preset similarity threshold condition, determining the perception task information as candidate perception task information. The preset similarity threshold condition may be that the text similarity is not less than a preset similarity threshold. The preset similarity threshold may be a preset lower limit of the similarity. For example, the preset similarity threshold condition may be 65%.

[0117] The third sub-step is to select candidate perception task information that meets a preset similarity condition from the determined candidate perception task information as target perception task information. The preset similarity condition may be that the text similarity corresponding to the candidate perception task information is the maximum value among the text similarities corresponding to the candidate perception task information.

[0118] In the fifth step, based on the target perception task information, a query operation is performed on the perception task allocation knowledge graph to obtain a data collector information group. Among them, each data collector information in the data collector information group may include a data collector identifier, a historical credibility weight mean, a historical task completion mean, and a user static attribute information group. The data collector identifier may be a unique identifier of the data collector. The historical credibility weight mean may be the mean of the credibility weights of each group intelligence perception task performed by the corresponding data collector within 1 month from the current time. The historical task completion mean may be the mean of the amount of data submitted by each group intelligence perception task performed by the corresponding data collector within 1 month from the current time. Each user static attribute information in the user static attribute information group may include a feature attribute identifier and a feature value. The feature attribute identifier may be a unique identifier of any static feature of the data collector. A static feature may be a feature that does not change over time. For example, a static feature may include, but is not limited to, at least one of the following: data provider type, location, and position. The provider type may be one of the following: organization, individual. The feature value may be the value of a static feature.

[0119] In the sixth step, each characteristic attribute identifier corresponding to the data collector information group is determined as a characteristic attribute identifier group, and the characteristic attribute identifier group is sent to the data request client for selection.

[0120] Step 7: In response to receiving the feature attribute selection information group sent by the data request client, a target data collector identification group corresponding to the target perception task information is generated based on the feature attribute selection information group and the data collector information group. The feature attribute selection information in the feature attribute selection information group may be an identification corresponding to a static feature selected by a user. The target data collector identification in the target data collector identification group may be a unique identification of a data collector for executing the crowd perception task corresponding to the target perception task information.

[0121] In addition, the present disclosure takes into account the problem existing in the conventional solution of "when selecting data providers, selecting each data provider whose credibility weight is higher than the preset credibility threshold to perform the crowd intelligence perception task", facing the above-mentioned technical problem three mentioned in the background technology part, combined with the technical advantages of the solution development team itself in the field of crowd intelligence perception, therefore, the present disclosure decides to adopt the following solution.

[0122] In some optional implementations of some embodiments, the computing server may perform the following steps to generate a target data collector identification group corresponding to the target perception task information based on the feature attribute selection information group and the data collector information group:

[0123] Step 1: For each piece of data collector information in the above data collector information group, perform the following steps:

[0124] Sub-step 1: Select user static attribute information that matches the above-mentioned characteristic attribute selection information group from the user static attribute information group included in the above-mentioned data collector information as clustered static attribute information to obtain the clustered static attribute information group. Wherein, matching the above-mentioned characteristic attribute selection information group may be that the characteristic attribute identifier included in the user static attribute information is the same as any characteristic attribute selection information in the above-mentioned characteristic attribute selection information group.

[0125] Sub-step 2: determining the data collector identifier, the historical task completion average and the clustering attribute information group included in the data collector information as clustering user information.

[0126] Step 2: clustering the determined individual clustered user information to obtain a clustered user information group set. The clustered user information group in the clustered user information group set may represent a cluster composed of individual clustered user information. The determined individual clustered user information may be clustered using a preset clustering method to obtain a clustered user information group set.

[0127] As an example, the above clustering method may include but is not limited to at least one of the following: spectral clustering, density-based clustering.

[0128] Step 3: Determine the lower limit of the credibility weight corresponding to each cluster user information group in the cluster user information group set to obtain a credibility weight lower limit value group. For each cluster user information group in the cluster user information group set, determine the minimum value of each historical credibility weight mean value corresponding to the cluster user information group as the credibility weight lower limit value.

[0129] Step 4: Determine the average value of each credibility weight lower limit value in the credibility weight lower limit value group as the reference lower limit value.

[0130] Step 5: Based on the reference lower limit, determine the target cluster user information group corresponding to each cluster user information group in the cluster user information group set to obtain the target cluster user information group set. For each cluster user information group in the cluster user information group set, select cluster user information whose corresponding credibility weight lower limit is greater than the reference lower limit from the cluster user information group as the target cluster user information to obtain the target cluster user information group.

[0131] Step six: determine the target data collector identification group corresponding to each data collector identification in the target clustering user information group set as the target data collector identification group.

[0132] In the eighth step, the data request information is sent to each data collection server corresponding to the target data collector identification group so as to collect the perception data from each perception data collector.

[0133] The above-mentioned target data collector identification group generation step and its related content, as an inventive point of an embodiment of the present disclosure, solve the above-mentioned technical problem three "how to select data providers to improve the accuracy of perception data". The above-mentioned operation server first clusters according to the static characteristics and historical task completion average of each data provider, thereby dividing the categories according to the similarity of each data provider, so that data providers can be selected from different categories in the future to alleviate the imbalance of data distribution. Then, according to the lower limit value of the credibility weight of each clustering category, the comprehensive reference lower limit value between each clustering category can be determined. After that, for each clustering category, a data provider with a relatively high weight compared to the reference lower limit value is selected. In this way, it is convenient to collect perception data with higher accuracy. Finally, tasks are assigned according to the selected data providers. Thereby, more perception data can be collected while improving the accuracy of perception data.

[0134] The above-mentioned embodiments of the present disclosure have the following beneficial effects: through the data fusion system of some embodiments of the present disclosure, the security of the perception data of each data provider is improved. Specifically, the reason for the low security of the perception data of each data provider is that in the entire process of data fusion, the data of each data provider is presented in plain text, which makes the risk of data leakage high, thus easily leading to the low security of the perception data of each data provider. Based on this, the data fusion system of some embodiments of the present disclosure includes a key server, a computing server and at least two data collection servers. Among them, first, each of the at least two data collection servers is configured to: in response to receiving the perception data sequence sent by the corresponding user terminal for the target perception task, generate a data mask sequence and a perturbation perception data sequence, and send the data mask sequence to the key server, and send the perturbation perception data sequence to the computing server. Among them, the data collection server in the at least two data collection servers corresponds to the user terminal in the user terminal set. In this way, the encrypted perception data of each data provider can be obtained, so that data fusion can be performed under ciphertext later to reduce the risk of data leakage. Secondly, the key server is configured to, in response to receiving at least two data mask sequences sent by the at least two data collection servers, and in response to determining that the preset obfuscation circuit connection information is not empty, perform obfuscation processing on each data mask in the at least two data mask sequences to obtain at least two obfuscated data mask sequences, and send the preset obfuscation circuit connection information and the at least two obfuscated data mask sequences to the operation server. Wherein, the preset obfuscation circuit connection information corresponds to the data fusion obfuscation circuit, and the data fusion obfuscation circuit is constructed according to the pre-constructed data mask removal function, the data collector weight update function and the perception target true value estimation function. Thus, the information of the obfuscation circuit for data fusion and the data mask for encrypting the perception data can be securely transmitted to the operation server. Then, the operation server is configured to, in response to receiving at least two perturbation perception data sequences sent by the at least two data collection servers, and in response to receiving the preset obfuscation circuit connection information and the at least two obfuscated data mask sequences, send the at least two perturbation perception data sequences to the key server. The key server is also configured to, in response to receiving the at least two disturbance perception data sequences, perform obfuscation processing on the at least two disturbance perception data sequences to obtain at least two obfuscated perception data sequences, and send the at least two obfuscated perception data sequences to the operation server to generate at least two target obfuscated perception data sequences.Thus, the operation server can select the obfuscated perception data that matches the perturbed perception data it has from all the obfuscated perturbation perception data provided by the key server, while ensuring that the key server cannot know the selection result of the operation server. Afterwards, the operation server is also configured to construct a data fusion obfuscation circuit based on the preset obfuscation circuit connection information, and input the at least two target obfuscated perception data sequences, the at least two obfuscated data mask sequences and the pre-generated initial perception target true value sequence as input parameters into the data fusion obfuscation circuit to output the fused perception target true value sequence. Thus, data fusion can be achieved for the perception data in the ciphertext state corresponding to each perception target, and the true value after data fusion can be obtained. Finally, based on the fused perception target true value sequence, a data fusion result is generated. Therefore, the data fusion system implemented encrypts the perception data of the corresponding data provider through the data collection server, and uses the obfuscation circuit to perform data fusion on the encrypted perception data on the data operation server, which can reduce the risk of data leakage and improve the security of the perception data of each data provider.

[0135] The above descriptions are only some preferred embodiments of the present disclosure and an explanation of the technical principles used. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present disclosure is not limited to the technical solutions formed by a specific combination of the above-mentioned technical features, but should also cover other technical solutions formed by any combination of the above-mentioned technical features or their equivalent features without departing from the above-mentioned inventive concept. For example, the above-mentioned features are replaced with the technical features with similar functions disclosed in the embodiments of the present disclosure (but not limited to) and the technical solutions formed.

Claims

1. A data fusion system, comprising a key server, a computing server and at least two data collection servers, wherein: Each of the at least two data collection servers is configured to: in response to receiving a perception data sequence for a target perception task and sent by a user terminal corresponding to the data collection server, generate a data mask sequence and a disturbance perception data sequence, and send the data mask sequence to the key server and the disturbance perception data sequence to the operation server; The key server is configured to, in response to receiving at least two data mask sequences sent by the at least two data collection servers and in response to determining that the preset obfuscation circuit connection information is not empty, perform obfuscation processing on each data mask in the at least two data mask sequences to obtain at least two obfuscated data mask sequences, and send the preset obfuscation circuit connection information and the at least two obfuscated data mask sequences to the operation server, wherein the preset obfuscation circuit connection information corresponds to a data fusion obfuscation circuit, and the data fusion obfuscation circuit is constructed according to a pre-constructed data mask removal function, a data collector weight update function, and a perception target true value estimation function; The operation server is configured to, in response to receiving at least two disturbance-perceived data sequences sent by the at least two data collection servers, and in response to receiving the preset obfuscation circuit connection information and the at least two obfuscation data mask sequences, send the at least two disturbance-perceived data sequences to the key server; The key server is further configured to, in response to receiving the at least two disturbance-perceived data sequences, perform obfuscation processing on the at least two disturbance-perceived data sequences to obtain at least two obfuscated data sequences, and send the at least two obfuscated data sequences to the operation server to generate at least two target obfuscated data sequences, wherein the at least two target obfuscated data sequences are generated by the operation server by performing the following steps: The computing server selects, for each of the at least two disturbance perception data sequences, a confusion perception data sequence corresponding to the disturbance perception data sequence from the at least two confusion perception data sequences as a target confusion perception data sequence, wherein the confusion perception data sequence corresponding to the disturbance perception data sequence is: a confusion perception data sequence in each confusion perception data sequence that is the same as a result of scrambling the order of the disturbance perception data sequence; The operation server is also configured to construct a data fusion obfuscation circuit based on the preset obfuscation circuit connection information, and input the at least two target obfuscated perception data sequences, the at least two obfuscated data mask sequences and the pre-generated initial perception target true value sequence as input parameters into the data fusion obfuscation circuit to output a fused perception target true value sequence; and generate a data fusion result based on the fused perception target true value sequence.

2. The data fusion system according to claim 1, wherein: Each of the at least two data collection servers is further configured to: Generate a data mask sequence based on preset mask bit number information; A disturbance sensing data sequence is generated based on the data mask sequence and the sensing data sequence.

3. The data fusion system according to claim 1, wherein: The computing server is further configured to: generating a group of Gaussian random variables in response to receiving at least two disturbance-perceived data sequences sent by the at least two data collection servers; Based on the Gaussian random variable group, an initial perception target true value sequence corresponding to the at least two disturbance perception data sequences is determined.

4. The data fusion system according to claim 1, wherein: The key server is further configured to: In response to receiving at least two data mask sequences sent by the at least two data collection servers, and in response to determining that the preset obfuscation circuit connection information is empty, constructing a data fusion Boolean circuit based on a preset number of iterations, a pre-constructed data mask removal function, a data collector weight update function, and a perception target true value estimation function; Performing obfuscation conversion processing on the data fusion Boolean circuit to obtain a converted obfuscated circuit; Obfuscating each data mask in the at least two data mask sequences to obtain at least two obfuscated data mask sequences; The converted obfuscation circuit and the at least two obfuscated data mask sequences are sent to the operation server to generate a fused perceptual target true value sequence.

5. The data fusion system according to claim 4, wherein: The computing server is further configured to: In response to determining that the preset obfuscation circuit connection information is empty, the at least two target obfuscated perception data sequences, the at least two obfuscation data mask sequences and the pre-generated initial perception target true value sequence are input as input parameters into the converted obfuscation circuit to output a fused perception target true value sequence.

6. The data fusion system according to claim 5, wherein: The computing server is further configured to: Sending each fused perceptual target true value in the fused perceptual target true value sequence to the key server in sequence to perform a decryption operation, and receiving a perceptual target result data sequence corresponding to the fused perceptual target true value sequence sent by the key server; The perception target result data sequence and the preset perception task type identifier are determined as a data fusion result, and the data fusion result is stored in a preset database.

7. The data fusion system according to claim 6, wherein: The key server is further configured to: In response to receiving any fused perceived target true value sent by the operation server, decrypting the any fused perceived target true value to obtain perceived target result data, and sending the perceived target result data to the operation server.

8. The data fusion system according to claim 6, wherein: The data fusion system further includes a data request client; and the operation server is further configured to: In response to receiving the data request information sent by the data request client, based on the data request information, performing a query operation on each data fusion result in the preset database to obtain a query result; In response to determining that the query result is not empty, the query result is sent to the data requesting client for display.

Citation Information

Cited By

  • Smart campus resource scheduling method based on data fusion

    CN121032104A