Data sharing methods, devices, equipment, media and program products

By performing privacy-preserving computations on user data and converting it into group characteristic data, the problems of user privacy leakage and experience disruption during data sharing are solved, enabling online real-time, secure data sharing and accurate data processing.

CN119272323BActive Publication Date: 2025-10-31ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411291287.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-14
Publication Date
2025-10-31
Estimated Expiration
2044-09-14

AI Technical Summary

Technical Problem

While protecting personal privacy and security, existing technologies pose risks of disrupting user experience and leaking data when acquiring user information and conducting data analysis during data sharing to achieve accurate recommendations.

Method used

By performing privacy calculations on user data, it is transformed into feature data that can only be used to distinguish user groups, and personal information is avoided from being directly exposed during the data sharing process, thus enabling online real-time sharing.

Benefits of technology

It protects user privacy and security, avoids privacy leaks during data sharing, and improves the flexibility and accuracy of data sharing, ensuring the effectiveness of data processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119272323B_ABST
    Figure CN119272323B_ABST
Patent Text Reader

Abstract

This specification discloses a data sharing method, apparatus, device, medium, and program product. The method includes: a first server corresponding to a first entity receiving a target data request sent by a second server corresponding to a second entity, the target data request carrying a target user identifier corresponding to a target user; responding to the target data request, obtaining first local user data corresponding to the target user based on the target user identifier; performing privacy calculations on the first local user data to obtain first local user features, the first local user features being used to distinguish target user group information; and sending the first local user features to the second server, so that the second server determines the target data processing result corresponding to the target user based on the first local user features.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of computer technology, and in particular to a data sharing method, apparatus, device, medium, and program product. Background Technology

[0002] In the era of Artificial Intelligence (AI), data plays a crucial role as the energy driving AI engines. In consumer-related fields, such as product recommendations, how to obtain as much user information as possible while protecting personal privacy, and then use data analysis and model training to recommend products based on an understanding of user needs, will become a critical issue in AI privacy compliance. Summary of the Invention

[0003] This specification provides a data sharing method, apparatus, device, medium, and program product, which enables online real-time sharing of privacy-protected data of individual users, avoiding privacy leaks during data sharing and ensuring user privacy security. The above technical solution is as follows:

[0004] In a first aspect, embodiments of this specification provide a data sharing method applied to a first server corresponding to a first subject. The method includes: receiving a target data request sent by a second server corresponding to a second subject; the target data request carrying a target user identifier corresponding to a target user; responding to the target data request, obtaining first local user data corresponding to the target user based on the target user identifier; performing privacy calculations on the first local user data to obtain a first local user feature; the first local user feature being used to distinguish target user group information; and sending the first local user feature to the second server, so that the second server determines the target data processing result corresponding to the target user based on the first local user feature.

[0005] In one possible implementation, the above-mentioned privacy calculation of the first local user data to obtain the first local user features includes: encoding the first local user data to obtain target encoded data; and performing feature processing on the target encoded data to obtain the first local user features.

[0006] In one possible implementation, the above-mentioned feature processing of the target encoded data to obtain the first local user feature includes: based on the target algorithm model, performing feature processing on the target encoded data to obtain the first local user feature;

[0007] The above-mentioned sending of the first local user feature to the second server, so that the second server can determine the target data processing result corresponding to the target user based on the first local user feature, includes: sending the first local user feature to the second server, so that the second server inputs the first local user feature into the target algorithm model and outputs the target data processing result corresponding to the target user; the target algorithm model is obtained by reinforcement learning based on historical local user features with known actual data processing results.

[0008] In one possible implementation, after receiving the target data request sent by the second server corresponding to the second subject, and before obtaining the first local user data corresponding to the target user based on the target user identifier in response to the target data request, the method further includes:

[0009] If the target data request is rejected according to the preset data sharing rules, then the step of responding to the target data request and obtaining the first local user data corresponding to the target user based on the target user identifier is executed.

[0010] In one possible implementation, the above-mentioned determination of whether to reject the target data request according to the preset data sharing rules includes: determining whether the target user has rejected data sharing in the first entity; and / or, determining whether the target data request violates the target compliance policy based on the target user information corresponding to the target user; and / or, determining whether the user whose target user identifier is in the first entity is a non-target user or is empty.

[0011] In one possible implementation, after determining whether to reject the target data request according to preset data sharing rules, the method further includes:

[0012] If the target data request is rejected, a target rejection result is sent to the second server. The target rejection result includes the target rejection factor corresponding to the target data request.

[0013] In one possible implementation, the aforementioned target data request also carries the target data request type corresponding to the aforementioned target user;

[0014] The above-mentioned response to the target data request, obtaining the first local user data corresponding to the target user based on the target user identifier, includes: in response to the target data request, obtaining the first local user data corresponding to the target user based on the target user identifier and the target data request type.

[0015] Secondly, embodiments of this specification provide a data sharing method. This method is applied to a second server corresponding to a second entity. The method includes: sending a target data request corresponding to a target user to a first server corresponding to a first entity, so that the first server obtains first local user data corresponding to the target user based on the target user identifier carried in the target data request, and performs privacy calculations on the first local user data to obtain a first local user feature; the first local user feature is used to distinguish target user group information; receiving the first local user feature sent by the first server; and determining the target data processing result corresponding to the target user based on the first local user feature.

[0016] In one possible implementation, the first local user feature is obtained by the first server processing the target encoded data after encoding the first local user data based on the target algorithm model.

[0017] The above-mentioned determination of the target data processing result corresponding to the target user based on the first local user feature includes: inputting the first local user feature into the target algorithm model and outputting the target data processing result corresponding to the target user; the target algorithm model is obtained by reinforcement learning based on the historical local user features of known actual data processing results.

[0018] In one possible implementation, the aforementioned historical local user characteristics include the first historical local user characteristics corresponding to the first server and / or the second historical local user characteristics corresponding to the second server.

[0019] The aforementioned target algorithm model is updated as the aforementioned historical local user characteristics are updated.

[0020] In one possible implementation, before determining the target data processing result corresponding to the target user based on the first local user characteristics, the method further includes: acquiring the second local user data of the target user in the second subject; and determining the second local user characteristics corresponding to the target user based on the second local user data.

[0021] The above-mentioned determination of the target data processing result corresponding to the target user based on the first local user feature includes: determining the target data processing result corresponding to the target user based on the first local user feature and the second local user feature.

[0022] In one possible implementation, after sending the target data request corresponding to the target user to the first server corresponding to the first subject, the method further includes: upon receiving the target rejection result corresponding to the target data request sent by the first server, determining the target data processing result corresponding to the target user based on the second local user characteristics.

[0023] Thirdly, embodiments of this specification provide a data sharing device, which is applied to a first server corresponding to a first subject. The data sharing device includes:

[0024] The first receiving module is used to receive a target data request sent by the second server corresponding to the second subject; the target data request carries the target user identifier corresponding to the target user.

[0025] The first acquisition module is used to respond to the above-mentioned target data request and acquire the first local user data corresponding to the above-mentioned target user based on the above-mentioned target user identifier;

[0026] The privacy computation module is used to perform privacy computation on the aforementioned first local user data to obtain first local user characteristics; the aforementioned first local user characteristics are used to distinguish target user group information.

[0027] The first sending module is used to send the first local user characteristics to the second server, so that the second server can determine the target data processing result corresponding to the target user based on the first local user characteristics.

[0028] Fourthly, embodiments of this specification provide a data sharing device, which is applied to a second server corresponding to a second subject. The data sharing device includes:

[0029] The second sending module is used to send a target data request corresponding to the target user to the first server corresponding to the first subject, so that the first server can obtain the first local user data corresponding to the target user based on the target user identifier carried in the target data request, and perform privacy calculations on the first local user data to obtain the first local user feature; the first local user feature is used to distinguish target user group information.

[0030] The second receiving module is used to receive the first local user characteristics sent by the first server.

[0031] The result determination module is used to determine the target data processing result corresponding to the target user based on the first local user characteristics mentioned above.

[0032] Fifthly, embodiments of this specification provide an electronic device, including: a processor and a memory;

[0033] The processor is connected to the memory.

[0034] The aforementioned memory is used to store executable program code;

[0035] The processor reads the executable program code stored in the memory to run the program corresponding to the executable program code, so as to execute the data sharing method provided by the first aspect or any possible implementation of the first aspect or the second aspect or any possible implementation of the embodiments of this specification.

[0036] Sixthly, embodiments of this specification provide a computer storage medium storing a plurality of instructions adapted for loading and executing by a processor the data sharing method provided by the first aspect or any possible implementation of the first aspect or the second aspect or any possible implementation of the second aspect of embodiments of this specification.

[0037] Seventhly, embodiments of this specification provide a computer program product containing instructions that, when run on a computer or processor, cause the computer or processor to execute the data sharing method provided by the first aspect or any possible implementation of the first aspect or the second aspect or any possible implementation of the second aspect of the embodiments of this specification.

[0038] In the embodiments of this specification, the first server corresponding to the first subject can perform privacy calculations on the local user data (first local user data) corresponding to the target user, convert it into a first local user feature that can only be used to distinguish target user group information, and then share the first local user feature with the second server corresponding to other subjects (second subjects) that send target data requests carrying the target user identifier corresponding to the target user. This ensures that the second server corresponding to other subjects (second subjects) can obtain the first local user feature of the target user to perform corresponding data processing and obtain the corresponding target data processing results. Furthermore, by sharing only the first local user feature that can only be used to distinguish target user group information, rather than the specific data of a single user or the full user data corresponding to the first subject, the shared data itself does not reveal personal association information. This enables the online real-time sharing of privacy-protected data of a single user, avoids the problem of user privacy leakage during data sharing, and protects user privacy security. Attached Figure Description

[0039] To more clearly illustrate the technical solutions in the embodiments of this specification, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0040] Figure 1 This is a schematic diagram illustrating a data sharing implementation process provided in related technologies;

[0041] Figure 2 This is a schematic diagram illustrating another data sharing implementation process provided in related technologies;

[0042] Figure 3 A schematic diagram illustrating an implementation process of data sharing provided for an exemplary embodiment of this specification;

[0043] Figure 4 A schematic diagram of the architecture of a data sharing system provided for an exemplary embodiment of this specification;

[0044] Figure 5 A flowchart illustrating a data sharing method provided for an exemplary embodiment of this specification;

[0045] Figure 6 A flowchart illustrating another data sharing method provided for an exemplary embodiment of this specification;

[0046] Figure 7 A flowchart illustrating another data sharing method provided for an exemplary embodiment of this specification;

[0047] Figure 8 A schematic diagram of the structure of a data sharing device provided for an exemplary embodiment of this specification;

[0048] Figure 9 A schematic diagram of another data sharing device provided as an exemplary embodiment of this specification;

[0049] Figure 10 This is a schematic diagram of the structure of an electronic device provided as an exemplary embodiment of this specification. Detailed Implementation

[0050] The technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings.

[0051] The terms "first," "second," "third," etc., used in this specification, claims, and the foregoing drawings are used to distinguish different objects, not to describe a specific order. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to such processes, methods, products, or apparatus.

[0052] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.), and signals involved in the embodiments of this specification are all authorized by the user or fully authorized by all parties, and the collection, use, and processing of related data must comply with the relevant laws, regulations, and standards of the relevant countries and regions. For example, the first local user data and the second local user data involved in this specification were obtained with full authorization.

[0053] As individuals, businesses, and other organizations continuously generate and collect massive amounts of data in their daily operations, how to securely and effectively share this data has become a significant technological and social issue. During data sharing, the risk of leakage of personal privacy data (such as identity information, financial information, and health data) increases significantly. Therefore, it is necessary to develop effective privacy protection technologies to ensure the security and privacy of data during the sharing process.

[0054] Related data sharing technologies mainly fall into two categories. One type is... Figure 1 As shown, when a user is experiencing an application scenario corresponding to the first entity (e.g., but not limited to using the first application corresponding to the first entity), if the system wants to share user data that the user has authorized to a second entity (e.g., but not limited to basic information, browsing habits, and preference information filled in by the user when using the second application corresponding to the second entity) for data processing (e.g., product recommendations), it is necessary to request authorization from the user. That is, based on user authorization, including pop-up authorization (small amount of information) and protocol authorization (large amount of information), user data is shared among multiple entities without the user's awareness. This approach disrupts the user experience. For example, if a user is browsing short videos and is suddenly asked to authorize their browsing history to an e-commerce company, and then a product recommendation is inserted, this will likely lead the user to refuse sharing and complain about the browsing experience.

[0055] To solve the above problems, the following approach was developed: Figure 2 Another option is shown. For example... Figure 2As shown, this approach establishes a neutral information processing center (neutral entity), allowing information-sharing entities (such as the first entity, second entity, etc.) to provide user data, i.e., outputting authorized user data to the neutral entity. Then, the information processing center (neutral entity) performs privacy-preserving computations using various privacy-protecting algorithms to calculate the data processing results required for the application scenario, such as the aforementioned product recommendations of user interest. This solution typically requires pre-calculation offline, lacks flexibility, and requires each entity to expose a large amount of user data to a neutral entity, resulting in a high risk of data leakage.

[0056] Based on this, the embodiments of this specification provide a data sharing method, specifically as follows: Figure 3 As shown, before sharing user data obtained with authorization, the second entity needs to perform privacy calculations on the user's data (second local user data) obtained by the second entity. This includes, but is not limited to, encoding the information in the user data (second local user data), then processing the encoded user data into user features (second local user features) that can only be used to distinguish user group information before sharing it with the first entity for data processing in the user's corresponding application scenario. This avoids disrupting the user experience in the application process, eliminates the need for multiple entities to provide large amounts of user data to a neutral entity, pre-calculate data processing results, and ensures that the entity that needs to process data in the application scenario (e.g., the first entity) can obtain the user features (second local user features) shared by other entities (e.g., the second entity) to perform corresponding data processing and obtain the corresponding data processing results. Furthermore, by sharing only user features that can only be used to distinguish user group information, rather than specific data of a single user or all user data, the shared data itself does not reveal personal association information. This enables online real-time sharing of privacy-protected data of a single user, avoiding the problem of user privacy leakage during data sharing and ensuring user privacy security.

[0057] Please refer to the following. Figure 4 This is a schematic diagram of the architecture of a data sharing system provided in an exemplary embodiment of this specification. Figure 1 As shown, the data sharing system includes: a first server 110 corresponding to a first entity, a second server 120 corresponding to a second entity, and a terminal 130. Wherein:

[0058] The first server 110 may be a server capable of providing data sharing services. It can receive target data requests sent by the second server 120 corresponding to the second entity via a network. These target data requests carry a target user identifier corresponding to the target user. Then, in response to the target data request, it obtains first local user data corresponding to the target user based on the target user identifier, and performs privacy calculations on the first local user data to obtain first local user characteristics. These first local user characteristics are used to distinguish target user group information. Finally, the first local user characteristics are sent to the second server 120, so that the second server determines the target data processing result corresponding to the target user based on the first local user characteristics. The first server 110 may be, but is not limited to, a hardware server, a virtual server, a cloud server, etc.

[0059] The second server 120 can be a server capable of providing data processing services (such as, but not limited to, product recommendation, risk prediction, credit assessment, etc.). It can send a target data request corresponding to the target user to the first server 110 corresponding to the first entity via a network. This allows the first server 110 to obtain the first local user data corresponding to the target user based on the target user identifier carried in the target data request, and perform privacy calculations on the first local user data to obtain first local user characteristics. These first local user characteristics are used to distinguish target user group information. Simultaneously, it can also receive the first local user characteristics sent by the first server 110 via a network and determine the target data processing result corresponding to the target user based on these characteristics. The second server 120 can be, but is not limited to, a hardware server, a virtual server, a cloud server, etc.

[0060] Terminal 130 can be a user terminal corresponding to the first entity and / or the second entity. Terminal 130 may have, but is not limited to, programs or applications corresponding to the first entity and / or the second entity installed on it, allowing the user to experience the services provided by the first entity and / or the second entity. Terminal 130 can interact with the first server 110 corresponding to the first entity and the second server 120 corresponding to the second entity via a network, for example, sending first user data and first user operations to the first server 110 corresponding to the first entity, and sending second user data and second user operations to the second server 120 corresponding to the second entity. Terminal 130 can be hardware or software. When terminal 130 is hardware, it can be various electronic devices, including but not limited to smartwatches, smartphones, tablets, laptops, and desktop computers. When terminal 130 is software, it can be installed in the aforementioned electronic devices, and can be implemented as multiple software programs or software modules (e.g., to provide distributed services) or as a single software program or software module; no specific limitation is made here.

[0061] Understandably, the first server 110 can be a server that provides data processing services (such as, but not limited to, product recommendation, risk prediction, credit assessment, etc.), and the second server 120 can be a server that provides data sharing services. That is, the first server 110 can execute the data sharing steps executed by the second server 120, and the second server 120 can also execute the data request and data processing steps executed by the first server 110. This specification does not limit this aspect.

[0062] The network can be a medium that provides a communication link between any two of the first server 110 corresponding to the first entity, the second server 120 corresponding to the second entity, and the terminal 130, or it can be the Internet, which includes network devices and transmission media, and is not limited thereto. The transmission media can be a wired link, such as, but not limited to, coaxial cable, optical fiber, and digital subscriber line (DSL), or a wireless link, such as, but not limited to, wireless internet access (WIFI), Hypertext Transfer Protocol (HTTP), Bluetooth, and mobile device networks.

[0063] Understandably, Figure 1 The number of the first server 110, the second server 120, and the terminal 130 in the data sharing system shown is merely an example. In a specific implementation, the data sharing system can contain any number of first servers 110, second servers 120, and terminals 130. This specification does not specifically limit this. For example, but not limited to, the first server 110 can be a first server cluster composed of multiple first servers, the second server 120 can be a second server cluster composed of multiple second servers, and the terminal 130 can be a terminal cluster composed of multiple terminals.

[0064] To address the problems existing in the aforementioned related technologies, the following will combine... Figure 3 and Figure 4 This document describes the data sharing method provided in the embodiments of this specification. Please refer to [link / reference] for details. Figure 5 This is a flowchart illustrating a data sharing method provided in an exemplary embodiment of this specification. Figure 5 As shown, this data sharing method includes the following steps:

[0065] S502, the second server corresponding to the second subject sends a target data request corresponding to the target user to the first server corresponding to the first subject. The target data request carries the target user identifier corresponding to the target user.

[0066] Specifically, the aforementioned first and second entities can be different legal entities, referring to natural persons, legal persons, or unincorporated entities that are active under the law, enjoy rights, bear obligations and responsibilities, and are subject to regulation or legal constraints. Examples include, but are not limited to, different companies or enterprises corresponding to different applications. When a target user enters a specific application scenario of the second entity, such as, but not limited to, browsing short videos or reading novels, the second server corresponding to the second entity can perform corresponding data processing for that target user, such as, but not limited to, recommending products that the target user may be interested in, with the ultimate goal of achieving a transaction.

[0067] To gain a more accurate understanding of target users' needs and improve transaction conversion rates, the second server corresponding to the second entity needs to acquire more target user characteristics for more precise data processing. Therefore, the second server corresponding to the second entity can send a target data request for the target user to at least one first server corresponding to the first entity via the network, in order to request the corresponding data generated by the target user in other entities (the first entity).

[0068] Understandably, the aforementioned target data request can be sent to one or more other entities (first entities) that have already cooperated with the second entity. This specification does not limit this. The aforementioned first entity can be an entity that has already cooperated with the second entity, or it can be an entity that the target user has designated and authorized to initiate the target data request within the first entity. This specification does not limit this. The target user identifier carried in the aforementioned target data request is the user identifier (e.g., but not limited to, mobile phone number, account number, etc.) entered by the target user when authorizing use or registering in the first entity. The user identifier corresponding to the same user in the first entity and the second entity may be the same or different. For example, the target user identifier corresponding to the target user in the first entity may be the target user's mobile phone number A, while its target user identifier corresponding to the second entity may be the target user's identity code or mobile phone number B, etc. This specification does not limit this.

[0069] S504, the first server responds to the target data request and obtains the first local user data corresponding to the target user based on the target user identifier.

[0070] Specifically, after receiving a target data request sent by the second server corresponding to the second entity, the first server can directly respond to the target data request and query the first local user data corresponding to the target user in its local database (the first database corresponding to the first entity) based on the target user identifier carried in the target data request. The aforementioned first local user data may include, but is not limited to, user information entered by the target user corresponding to the first entity (e.g., but not limited to basic information during registration), operation information (e.g., but not limited to webpage or product browsing information), order information, preference information (e.g., but not limited to keywords searched when browsing videos), etc.

[0071] Optionally, the aforementioned target data request also carries a target data request type corresponding to the target user. This target data request type characterizes the data type (data content) of the target user requested by the second server from the first server. After receiving the target data request sent by the second server corresponding to the second entity, the first server can respond to the target data request by obtaining the first local user data corresponding to the target user based on the target user identifier and the target data request type. For example, but not limited to, querying the first local user data corresponding to the target user identifier and the target data request type in its local database (the first database corresponding to the first entity). For example, but not limited to, when the target data request type is a basic type, the first local user data can be the target user's basic information in the first entity; when the target data request type is an operation type, the first local user data can be the target user's operation information in the first entity; when the target data request type is a preference type, the first local user data can be the target user's preference information in the first entity.

[0072] In the embodiments of this specification, the first server can more accurately obtain the data required by the second server for data processing by carrying the target user identifier and target data request type in the target data request. This improves the granularity of data sharing, sharing only one or more types of data required for data processing at the user level. This avoids the problem of invalid sharing of data from other users and data that is not needed for other data processing at the user level, thus improving the effectiveness of data sharing. It also ensures the security of the user data corresponding to the first subject to a certain extent, avoiding the problem of large amounts of user data being leaked.

[0073] S506, the first server performs privacy calculations on the first local user data to obtain the first local user characteristics, which are used to distinguish target user group information.

[0074] Specifically, after obtaining the target user's initial local user data, to prevent privacy breaches due to data theft during data sharing with the second server, the first server can perform privacy calculations on the initial local user data. This removes sensitive information and yields initial local user characteristics that can only be used to differentiate the target user group. This protects the privacy and security of the shared user data, ensuring no sensitive information is leaked during processing, while allowing user data to be calculated and analyzed across different entities, realizing its value and insights. Furthermore, the initial local user characteristics do not reveal the target user's personal information (such as age, address, etc.); they only distinguish the target user's user group, such as, but not limited to, being middle-aged or located in a first-tier city. Therefore, even if the initial local user characteristics are leaked during data sharing with the second server, the specific target user cannot be located using these characteristics, nor can their private data be accessed, thus maximizing user privacy during data sharing.

[0075] Optionally, the above-mentioned privacy computation process may include, but is not limited to, the following: firstly, lightweight privacy computation is used to encode the first local user data to obtain target encoded data, thereby achieving a certain degree of privacy protection for the target user. The above-mentioned encoding rules may include, but are not limited to, firstly extracting keywords or entities from the first local user data, then encoding the keywords or entities into corresponding strings according to a preset encoding mapping relationship, and finally combining the strings corresponding to each keyword or entity to obtain the target encoded data corresponding to the first local user data. The preset encoding mapping relationship is used to characterize the correspondence between different keywords or entities and each string. Different keywords or entities correspond to different strings. The above encoding can be text encoding or video encoding, and can be performed according to a preset encoding mapping relationship or encoding lookup table, or other encoding methods can be used. This specification does not limit this. For example, but not limited to, when the first local user data is "aged in their 20s, recently bought a certain brand of milk," it can be encoded as "01010001, MABC" (target encoded data).

[0076] Even in scenarios involving partial data leakage, it's still possible to deduce the original user privacy information (first local user data) from the encoded target data. Therefore, a second layer of privacy computation defense can be implemented before sharing data with the second server. This involves feature processing of the target encoded data (e.g., but not limited to vectorization). Through feature processing, the target encoded data is transformed into machine data (first local user features) that can only be used by specific algorithms. These first local user features can only be used to distinguish different user groups, i.e., to differentiate target user group information. This avoids the leakage of the original user privacy information (first local user data) in scenarios involving partial data leakage, further enhancing the security of privacy protection during data sharing.

[0077] S508, the first server sends the first local user characteristics to the second server.

[0078] Specifically, after obtaining the first local user characteristics that can only be used to distinguish information about the target user group, the first server can also send the first local user characteristics to the second server via the network, thereby achieving data sharing.

[0079] S510, the second server determines the target data processing result corresponding to the target user based on the characteristics of the first local user.

[0080] Specifically, after receiving the first local user characteristics shared by the first server, the second server can, but is not limited to, directly perform corresponding data processing based on these first local user characteristics to obtain the target data processing results corresponding to the target user. The aforementioned data processing may include, but is not limited to, data decision-making, product recommendation (recommending products that the target user may be interested in), risk assessment (assessing whether the target user is a risky user), etc.

[0081] In the embodiments of this specification, the first server corresponding to the first subject can perform privacy calculations on the local user data (first local user data) corresponding to the target user, convert it into a first local user feature that can only be used to distinguish target user group information, and then share the first local user feature with the second server corresponding to other subjects (second subjects) that send target data requests carrying the target user identifier corresponding to the target user. This ensures that the second server corresponding to other subjects (second subjects) can obtain the first local user feature of the target user to perform corresponding data processing and obtain the corresponding target data processing results. Furthermore, by sharing only the first local user feature that can only be used to distinguish target user group information, rather than the specific data of a single user or the full user data corresponding to the first subject, the shared data itself does not reveal personal association information. This enables the online real-time sharing of privacy-protected data of a single user, avoids the problem of user privacy leakage during data sharing, and protects user privacy security.

[0082] Please refer to the following. Figure 6 This is a flowchart illustrating another data sharing method provided in an exemplary embodiment of this specification. Figure 6 As shown, this data sharing method includes the following steps:

[0083] S602, the second server corresponding to the second subject sends a target data request corresponding to the target user to the first server corresponding to the first subject. The target data request carries the target user identifier corresponding to the target user.

[0084] Specifically, S602 is the same as S502, and will not be repeated here.

[0085] S604, the first server responds to the target data request and obtains the first local user data corresponding to the target user based on the target user identifier.

[0086] Specifically, S604 is the same as S504, and will not be repeated here.

[0087] S606, the first server encodes the first local user data to obtain the target encoded data.

[0088] Specifically, after obtaining the target user's initial local user data, lightweight privacy-preserving computation can be used to encode the data. This includes, but is not limited to, extracting keywords or entities from the initial local user data, encoding these keywords or entities into corresponding strings according to a preset encoding mapping relationship, and finally combining the strings corresponding to each keyword or entity to obtain the target encoded data corresponding to the initial local user data. This achieves a certain degree of privacy protection for the target user. The aforementioned preset encoding mapping relationship is used to represent the correspondence between different keywords or entities and each string.

[0089] Understandably, different keywords or entities correspond to different strings. The above encoding can be text encoding or video encoding, and can be performed according to a preset encoding mapping relationship or encoding lookup table, or other encoding methods can be used. This specification does not limit this. For example, but not limited to, when the first local user data is "aged in the 20s, recently bought a certain brand of milk", it can be encoded as "01010001, MABC" (target encoded data).

[0090] S608, the first server processes the target encoded data based on the target algorithm model to obtain the first local user features, which are used to distinguish target user group information.

[0091] Specifically, in abnormal scenarios involving partial data leakage, it is still possible to deduce the original user privacy information (first local user data) from the encoded target data. Therefore, a second layer of privacy computation defense can be performed before sharing the data with the second server. This involves using the target algorithm model to process the target encoded data through feature processing (e.g., but not limited to vectorization). This feature processing transforms the target encoded data into machine data (first local user features) that can only be used by a specific algorithm (i.e., the target algorithm used by the target algorithm model). These first local user features can only be used to distinguish different user groups, i.e., to differentiate target user group information. This avoids the problem of the original user privacy information (first local user data) being leaked in abnormal scenarios involving partial data leakage, further improving the security of privacy protection during data sharing.

[0092] Understandably, the aforementioned target algorithm model can be shared by the second server corresponding to the second subject. For example, but not limited to, when the second server corresponding to the second subject sends a target data request for the target user to the first server corresponding to the first subject, it will also send the target algorithm model it will use for data processing to the first server. This allows the first server to use the target algorithm model to process the data it wants to share (first local user data) into data (first local user features) that only the target algorithm model can understand. This ensures data privacy and security during data sharing and also pre-processes the first local user data for features, thereby improving the efficiency of data processing by the second server to a certain extent. The aforementioned target algorithm model can also be an algorithm model pre-set on the respective servers of the first and second subjects after negotiation or cooperation. This target algorithm model can be learned, updated, and parameter-shared among the respective servers of multiple cooperating subjects (e.g., but not limited to the first subject and the second subject) using federated learning technology. The embodiments in this specification do not limit this.

[0093] S610, the first server sends the first local user characteristics to the second server.

[0094] Specifically, S610 is identical to S508, which will not be repeated here.

[0095] S612, the second server inputs the first local user features into the target algorithm model and outputs the target data processing result corresponding to the target user.

[0096] Specifically, after receiving the first local user features shared by the first server, the second server can, but is not limited to, directly input the first local user features into the target algorithm model and output the target data processing result corresponding to the target user. The aforementioned target algorithm model can, but is not limited to, be obtained through reinforcement learning based on historical local user features with known actual data processing results.

[0097] For example, in a product recommendation scenario, the aforementioned first local user data may include, but is not limited to, the target user's historical purchase information, basic information, and product browsing information corresponding to the first entity. The aforementioned target algorithm model may be a product recommendation model, and the aforementioned target data processing result may include, but is not limited to, the target product recommendation result (i.e., recommending products that the target user may be interested in to the target user on the application page corresponding to the second entity). The aforementioned actual data processing result may include, for example, the target user's actual purchase status of products recommended by the second server. In a risk assessment scenario, the aforementioned first local user data may include, but is not limited to, the target user's asset information, basic information, and loan information corresponding to the first entity. The aforementioned target algorithm model may be a risk assessment model, and the aforementioned target data processing result may include, but is not limited to, the target risk assessment result (e.g., the probability that the target user is a risky user or the risk level of the target user as assessed by the second server corresponding to the second entity). The aforementioned actual data processing result may include, for example, the actual risk situation of the target user corresponding to the second entity.

[0098] Furthermore, the aforementioned historical local user features may include, but are not limited to, the first historical local user features corresponding to the first server and / or the second historical local user features corresponding to the second server; that is, the aforementioned target algorithm model can be trained based on the user features of the user data corresponding to the first subject and / or the user features of the user data corresponding to the second subject, given the known actual data processing results. The aforementioned target algorithm model updates as the historical local user features are updated; that is, the target algorithm model possesses reinforcement learning capabilities, does not rely on a large amount of user data for cold start, and can continuously correct and optimize model parameters and improve model performance as the number of positive and negative samples (historical local user features of known actual data processing results) increases.

[0099] Please refer to the following. Figure 7 This is a flowchart illustrating another data sharing method provided in an exemplary embodiment of this specification. Figure 7 As shown, this data sharing method includes the following steps:

[0100] S702, the second server corresponding to the second entity obtains the target user's second local user data in the second entity.

[0101] Specifically, when a target user enters a certain application scenario of the second entity, such as but not limited to browsing short videos, reading novels, or browsing products online, the second server corresponding to the second entity can perform corresponding data processing for the target user, such as but not limited to recommending products that the target user may be interested in, with the ultimate goal of achieving a transaction conversion.

[0102] Since the second entity also possesses data about the current target user, such as but not limited to video search keywords, historically viewed video content, and basic registration information, the second server can, in addition to sending a target data request to the first server corresponding to the first entity to request the corresponding data generated by the target user in other entities (the first entity) for data processing, also directly query the target user's local database (the second database corresponding to the second entity) using the target user identifier to obtain the target user's second local user data for data processing. This improves the richness and accuracy of the data during processing. The aforementioned second local user data may include, but is not limited to, user information entered by the target user in the second entity (e.g., but not limited to basic registration information), operation information (e.g., but not limited to webpage or product browsing information), order information, preference information (e.g., but not limited to keywords searched while browsing videos), etc.

[0103] Understandably, the aforementioned target users can be users who are currently in the application scenario corresponding to the second subject, such as, but not limited to, users who are using the software or mini-program corresponding to the second subject to browse short videos, browse products, read novels, etc. This specification embodiment does not limit this.

[0104] S704, the second server determines the characteristics of the second local user corresponding to the target user based on the second local user data.

[0105] Specifically, after obtaining the second local user data of the target user, the second server can directly identify the second local user data as the second local user feature corresponding to the target user, or it can, but is not limited to, first encode the second local user data, and then perform feature processing on the encoded second local user data to obtain the second local user feature corresponding to the target user. This embodiment of the specification does not limit this. The above encoding process is similar to the encoding process in S606 above, and the above feature processing process is similar to the feature processing process in S608 above, and will not be described again here.

[0106] S706, the second server sends a target data request corresponding to the target user to the first server corresponding to the first subject. The target data request carries the target user identifier corresponding to the target user.

[0107] Specifically, S706 is the same as S502, and will not be repeated here.

[0108] Understandably, S702 and S706 can be executed sequentially or synchronously. This description is an embodiment and does not limit this.

[0109] Please continue to refer to the following. Figure 7 ,like Figure 7 As shown, after the first server receives the target data request corresponding to the target user sent by the second server, the data sharing method may also include, but is not limited to, the following:

[0110] S708, the first server determines whether to reject the target data request according to the preset data sharing rules.

[0111] Specifically, in order to ensure the legality and security of data sharing and improve user experience, after receiving the target data request corresponding to the target user sent by the second server, the first server can first determine whether to reject the target data request according to the preset data sharing rules. For example, but not limited to, determining whether the target user has rejected data sharing in the first entity, and / or, determining whether the target data request violates the target compliance policy based on the target user information corresponding to the target user, and / or determining whether the user corresponding to the target user identifier in the first entity is a non-target user or is empty, etc.

[0112] Optionally, after receiving the target data request corresponding to the target user sent by the second server, the first server can first query the target user's authorization information in the first database (i.e., the first server's local database), and determine whether the target user has refused data sharing in the first entity based on the target user's authorization information. For example, but not limited to, the target user has explicitly requested not to participate in any marketing recommendation activities in the first entity. If the target user has refused data sharing in the first entity, it can be determined that the target data request needs to be rejected, that is, the relevant data of the target user will not be shared with the second server, thereby providing users with personalized authorization services in data scenarios and improving the user experience.

[0113] Optionally, after receiving the target data request for the target user from the second server, the first server may first query the target user information corresponding to the first entity (such as, but not limited to, the target user's occupation, age, and other basic information), and then determine whether the target data request violates the target compliance policy based on the target user information. For example, but not limited to, when the target user is a child, according to the provision in the target compliance policy that children's data cannot be shared externally, it can be determined that the target data request violates the target compliance policy, and it can be determined that the target data request needs to be rejected, that is, the relevant data of the target user will not be shared with the second server, thereby ensuring the legality of data sharing.

[0114] Optionally, the aforementioned target data request may also carry user information corresponding to the target user in the second entity (e.g., but not limited to, the mobile phone number and terminal device identifier used by the target user when registering in the second entity). After receiving the target data request corresponding to the target user sent by the second server, the first server may first query the target user information corresponding to the target user identifier in the first entity (e.g., but not limited to, the mobile phone number and terminal device identifier used by the target user identifier when registering in the first entity); then, it determines whether the user corresponding to the target user identifier in the first entity is not the target user or is empty. If the user information corresponding to the target user identifier in the second entity is inconsistent with the target user information corresponding to the target user identifier in the first entity, it can be determined that the user corresponding to the target user identifier in the first entity is not the target user, that is, not the target user, and it can be determined that the target data request needs to be rejected, that is, the relevant data of the target user will not be shared with the second server, thereby avoiding the problem that the target user's information is stolen or lent to others for use in the first entity, resulting in the leakage of user data in the second entity, and that the data shared by the first entity is not the target user's data at all, which affects the accuracy of data processing in the second entity. If the target user identifier cannot be found in the first entity, that is, if the user corresponding to the target user identifier in the first entity is empty, such as the target user not generating data in the first entity, it means that the first server has no data related to the target user that can be shared. Therefore, it can be determined that the target data request should be rejected, that is, the target user's data will not be shared with the second server.

[0115] Please continue to refer to the following. Figure 7 ,like Figure 7 As shown in S708 above, after the first server determines whether to reject the target data request according to the preset data sharing rules, the data sharing method may also include, but is not limited to, the following:

[0116] S710, if the first server allows the target data request, it executes a response to the target data request and obtains the first local user data corresponding to the target user based on the target user identifier.

[0117] Specifically, the first server determines, according to preset data sharing rules, whether to reject the target data request. That is, if the first server allows the target data request, it can execute a response to the target data request and obtain the first local user data corresponding to the target user based on the target user identifier. The process of obtaining the first local user data is the same as S504 above, and will not be repeated here.

[0118] S712, the first server encodes the first local user data to obtain the target encoded data.

[0119] Specifically, S712 is identical to S606, and will not be repeated here.

[0120] S714, the first server processes the target encoded data to obtain the first local user feature, which is used to distinguish target user group information.

[0121] Specifically, the feature processing in S714 is similar to that in S608, and will not be described again here.

[0122] S716, the first server sends the first local user characteristics to the second server.

[0123] Specifically, S716 is identical to S610, and will not be repeated here.

[0124] S718, the second server determines the target data processing result corresponding to the target user based on the first local user characteristics and the second local user characteristics.

[0125] Specifically, after obtaining the second local user characteristics of its own local system and the first local user characteristics shared by the first entity, the second server can determine the target data processing result corresponding to the target user based on the first local user characteristics and the second local user characteristics. For example, but not limited to, directly inputting the first local user characteristics and the second local user characteristics into the target algorithm model and outputting the corresponding target data processing result, thereby improving the accuracy of the data processing of the second server to a certain extent.

[0126] Please continue to refer to the following. Figure 7 ,like Figure 7 As shown in S708 above, after the first server determines whether to reject the target data request according to the preset data sharing rules, the data sharing method may also include, but is not limited to, the following:

[0127] S720: If the first server rejects the target data request, it sends the target rejection result corresponding to the target data request to the second server.

[0128] Specifically, if the first server determines that the target data request is non-compliant or poses a risk of data leakage according to the preset data sharing rules, the first server will not share the target user's data with the second server. The first server can send the target rejection result corresponding to the target data request to the second server. The target rejection result may include, but is not limited to, the target rejection factors corresponding to the target data request, thereby informing the second entity that the target data request has been rejected and the reason for the rejection, thus avoiding the problem of the second entity waiting for the first entity to share data, which affects its data processing efficiency.

[0129] Please continue to refer to the following. Figure 7 ,like Figure 7As shown, this data sharing method may also include, but is not limited to:

[0130] S722, when the second server receives the target rejection result corresponding to the target data request sent by the first server, it determines the target data processing result corresponding to the target user based on the second local user characteristics.

[0131] Specifically, after receiving the target rejection result corresponding to the target data request sent by the first server, the second server can directly determine the target data processing result corresponding to the target user based on its local second user characteristics. For example, but not limited to, directly inputting the second local user characteristics into the target algorithm model and outputting the target data processing result corresponding to the target user, thereby ensuring the efficiency and success rate of the second subject in data processing by the second server.

[0132] Please refer to the following. Figure 8 This is a schematic diagram of a data sharing device provided in an exemplary embodiment of this specification. The aforementioned data sharing device is applied to a first server corresponding to a first entity, such as... Figure 8 As shown, the data sharing device 800 includes:

[0133] The first receiving module 810 is used to receive a target data request sent by the second server corresponding to the second subject; the target data request carries a target user identifier corresponding to the target user.

[0134] The first acquisition module 820 is used to respond to the above-mentioned target data request and acquire the first local user data corresponding to the target user based on the above-mentioned target user identifier;

[0135] The privacy computation module 830 is used to perform privacy computation on the aforementioned first local user data to obtain first local user characteristics; the aforementioned first local user characteristics are used to distinguish target user group information.

[0136] The first sending module 840 is used to send the first local user feature to the second server so that the second server can determine the target data processing result corresponding to the target user based on the first local user feature.

[0137] In one possible implementation, the privacy computing module 830 includes:

[0138] The encoding unit is used to encode the aforementioned first local user data to obtain target encoded data;

[0139] The feature processing unit is used to process the target encoded data to obtain the first local user feature.

[0140] In one possible implementation, the feature processing unit is specifically used to: process the target encoded data based on the target algorithm model to obtain the first local user feature.

[0141] The first sending module 840 is specifically used to: send the first local user feature to the second server, so that the second server inputs the first local user feature into the target algorithm model and outputs the target data processing result corresponding to the target user; the target algorithm model is obtained by reinforcement learning based on the historical local user features of known actual data processing results.

[0142] In one possible implementation, the data sharing device 800 further includes:

[0143] The judgment module is used to determine whether to reject the above target data request according to the preset data sharing rules.

[0144] An execution module is configured to, if the target data request is permitted, execute the step of obtaining the first local user data corresponding to the target user based on the target user identifier in response to the target data request.

[0145] In one possible implementation, the aforementioned judgment module is specifically used to: determine whether the aforementioned target user has refused data sharing in the aforementioned first entity; and / or, determine whether the aforementioned target data request violates the target compliance policy based on the target user information corresponding to the aforementioned target user; and / or, determine whether the user whose identifier is the aforementioned target user in the aforementioned first entity is a non-target user or is empty.

[0146] In one possible implementation, the data sharing device 800 further includes:

[0147] The result sending module is used to send a target rejection result to the second server if the target data request is rejected; the target rejection result includes the target rejection factor corresponding to the target data request.

[0148] In one possible implementation, the target data request also carries the target data request type corresponding to the target user; the first acquisition module 820 is specifically used for:

[0149] In response to the aforementioned target data request, the first local user data corresponding to the aforementioned target user is obtained based on the aforementioned target user identifier and the aforementioned target data request type.

[0150] Please refer to the following. Figure 9 This is a schematic diagram of another data sharing device provided in an exemplary embodiment of this specification. The aforementioned data sharing device is applied to a second server corresponding to the second entity, such as... Figure 9As shown, the data sharing device 900 includes:

[0151] The second sending module 910 is used to send a target data request corresponding to the target user to the first server corresponding to the first subject, so that the first server can obtain the first local user data corresponding to the target user based on the target user identifier carried in the target data request, and perform privacy calculations on the first local user data to obtain the first local user features; the first local user features are used to distinguish target user group information.

[0152] The second receiving module 920 is used to receive the first local user characteristics sent by the first server.

[0153] The result determination module 930 is used to determine the target data processing result corresponding to the target user based on the first local user characteristics mentioned above.

[0154] In one possible implementation, the first local user feature is obtained by the first server processing the target encoded data after encoding the first local user data based on the target algorithm model; the result determination module 930 is specifically used to: input the first local user feature into the target algorithm model and output the target data processing result corresponding to the target user; the target algorithm model is obtained by reinforcement learning based on the historical local user features with known actual data processing results.

[0155] In one possible implementation, the aforementioned historical local user characteristics include the first historical local user characteristics corresponding to the first server and / or the second historical local user characteristics corresponding to the second server.

[0156] The aforementioned target algorithm model is updated as the aforementioned historical local user characteristics are updated.

[0157] In one possible implementation, the data sharing device 900 further includes:

[0158] The second acquisition module is used to acquire the second local user data of the target user in the second entity.

[0159] The feature determination module is used to determine the second local user features corresponding to the target user based on the second local user data mentioned above.

[0160] The result determination module 930 is specifically used to: determine the target data processing result corresponding to the target user based on the first local user characteristics and the second local user characteristics.

[0161] In one possible implementation, the result determination module 930 is further configured to: upon receiving the target rejection result corresponding to the target data request sent by the first server, determine the target data processing result corresponding to the target user based on the second local user characteristics.

[0162] The division of modules in the above-described data sharing device is for illustrative purposes only. In other embodiments, the data sharing device can be divided into different modules as needed to complete all or part of the functions of the data sharing device. The implementation of each module in the data sharing device provided in the embodiments of this specification can be in the form of a computer program. This computer program can run on a server. The program modules constituted by this computer program can be stored in the memory of the access server. When the computer program is executed by a processor, it implements all or part of the steps of the data sharing method described in the embodiments of this specification.

[0163] Please refer to the following. Figure 10 This is a schematic diagram of the structure of an electronic device provided in an exemplary embodiment of this specification. Figure 10 As shown, the electronic device 1000 may include: at least one processor 1010, at least one communication bus 1020, a user interface 1030, at least one network interface 1040, and a memory 1050. The communication bus 1020 can be used to enable communication between the aforementioned components.

[0164] The user interface 1030 may include a display screen and a camera. Optional user interfaces may also include standard wired interfaces and wireless interfaces.

[0165] The network interface 1040 may optionally include a Bluetooth module, a Near Field Communication (NFC) module, a Wi-Fi module, etc.

[0166] The processor 1010 may include one or more processing cores. The processor 1010 connects to various parts within the electronic device 1000 using various interfaces and lines. It executes various functions and processes data of the routing electronic device 1000 by running or executing instructions, programs, code sets, or instruction sets stored in the memory 1050, and by calling data stored in the memory 1050. Optionally, the processor 1010 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logical Array (PLA). The processor 1010 may integrate one or more of the following: a central processing unit (CPU), a graphics processing unit (GPU), and a modem. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the content required for display on the screen; and the modem handles wireless communication. It is understandable that the aforementioned modem may not be integrated into the processor 1010, but may be implemented using a separate chip.

[0167] The memory 1050 may include random access memory (RAM) or read-only memory (ROM). Optionally, the memory 1050 may include a non-transitory computer-readable medium. The memory 1050 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 1050 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as privacy computing, data sharing, encoding, etc.), instructions for implementing the various method embodiments described above, etc.; the data storage area may store data involved in the various method embodiments described above, etc. Optionally, the memory 1050 may also be at least one storage device located remotely from the aforementioned processor 1010. Figure 10 As shown, the memory 1050, which serves as a computer storage medium, may include an operating system, a network communication module, a user interface module, and application programs.

[0168] In some possible embodiments, the electronic device 1000 is the first server corresponding to the first subject mentioned in the foregoing embodiments or Figure 8The data sharing device 800 shown can be used by processor 1010 to call the application stored in memory 1050 and specifically perform the following operations: receiving a target data request sent by a second server corresponding to a second subject; the target data request carries a target user identifier corresponding to the target user; in response to the target data request, obtaining first local user data corresponding to the target user based on the target user identifier; performing privacy calculations on the first local user data to obtain a first local user feature; the first local user feature is used to distinguish target user group information; and sending the first local user feature to the second server so that the second server determines the target data processing result corresponding to the target user based on the first local user feature.

[0169] In some possible embodiments, when the processor 1010 performs the privacy calculation on the first local user data to obtain the first local user characteristics, it is specifically used to perform:

[0170] The first local user data is encoded to obtain target encoded data; the target encoded data is then processed to obtain the first local user features.

[0171] In some possible embodiments, when the processor 1010 performs the feature processing on the target encoded data to obtain the first local user feature, it is specifically used to perform: based on the target algorithm model, perform feature processing on the target encoded data to obtain the first local user feature.

[0172] When the processor 1010 executes the above-mentioned method of sending the first local user feature to the second server so that the second server can determine the target data processing result corresponding to the target user based on the first local user feature, it is specifically used to perform: sending the first local user feature to the second server so that the second server inputs the first local user feature into the target algorithm model and outputs the target data processing result corresponding to the target user; the target algorithm model is obtained by reinforcement learning based on historical local user features with known actual data processing results.

[0173] In some possible embodiments, after the processor 1010 executes the target data request sent by the second server corresponding to the second subject, and before obtaining the first local user data corresponding to the target user based on the target user identifier in response to the target data request, it is further configured to perform:

[0174] If the target data request is rejected according to the preset data sharing rules, then the step of responding to the target data request and obtaining the first local user data corresponding to the target user based on the target user identifier is executed.

[0175] In some possible embodiments, when the processor 1010 executes the above-mentioned determination of whether to reject the target data request according to the preset data sharing rules, it is specifically used to perform: determining whether the target user has rejected data sharing in the first subject; and / or, determining whether the target data request violates the target compliance policy based on the target user information corresponding to the target user; and / or, determining whether the user identified by the target user in the first subject is a non-target user or is empty.

[0176] In some possible embodiments, after the processor 1010 performs the above-described determination of whether to reject the target data request according to the preset data sharing rules, it is further configured to perform:

[0177] If the target data request is rejected, a target rejection result is sent to the second server. The target rejection result includes the target rejection factor corresponding to the target data request.

[0178] In some possible embodiments, the target data request also carries the target data request type corresponding to the target user; when the processor 1010 executes the above-mentioned response to the target data request to obtain the first local user data corresponding to the target user based on the target user identifier, it is specifically used to perform: in response to the target data request, obtain the first local user data corresponding to the target user based on the target user identifier and the target data request type.

[0179] In some possible embodiments, the electronic device 1000 is the second server corresponding to the second subject mentioned in the foregoing embodiments or Figure 9 The data sharing device 900 shown can be used by processor 1010 to call the application stored in memory 1050 and specifically perform the following operations: send a target data request corresponding to the target user to a first server corresponding to the first subject, so that the first server obtains the first local user data corresponding to the target user based on the target user identifier carried in the target data request, and performs privacy calculations on the first local user data to obtain a first local user feature; the first local user feature is used to distinguish target user group information; receive the first local user feature sent by the first server; and determine the target data processing result corresponding to the target user based on the first local user feature.

[0180] In some possible embodiments, the first local user feature is obtained by the first server processing the target encoded data after encoding the first local user data based on the target algorithm model; when the processor 1010 executes the above-mentioned target data processing result for determining the target user based on the first local user feature, it is specifically used to: input the first local user feature into the target algorithm model and output the target data processing result corresponding to the target user; the target algorithm model is obtained by reinforcement learning based on historical local user features with known actual data processing results.

[0181] In some possible embodiments, the aforementioned historical local user characteristics include the first historical local user characteristics corresponding to the first server and / or the second historical local user characteristics corresponding to the second server.

[0182] The aforementioned target algorithm model is updated as the aforementioned historical local user characteristics are updated.

[0183] In some possible embodiments, before the processor 1010 executes the above-mentioned target data processing result based on the first local user characteristics to determine the target user corresponding to the target user, it is further configured to execute:

[0184] Obtain the second local user data of the target user in the second subject; determine the second local user characteristics corresponding to the target user based on the second local user data.

[0185] When the processor 1010 executes the above-mentioned target data processing result based on the first local user characteristics to determine the target data processing result corresponding to the target user, it is specifically used to execute: determining the target data processing result based on the first local user characteristics and the second local user characteristics.

[0186] In some possible embodiments, after the processor 1010 executes the above-mentioned sending of the target data request corresponding to the target user to the first server corresponding to the first subject, it is further configured to: upon receiving the target rejection result corresponding to the target data request sent by the first server, determine the target data processing result corresponding to the target user based on the second local user characteristics.

[0187] This specification also provides a computer-readable storage medium storing instructions that, when executed on a computer or processor, cause the computer or processor to perform one or more steps in the above embodiments. If the constituent modules of the above-described data sharing device are implemented as software functional units and sold or used as independent products, they can be stored in the above-described computer-readable storage medium.

[0188] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions. When these computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this specification are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in or transmitted through a computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, Digital Subscriber Line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The aforementioned available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., digital versatile discs (DVDs)), or semiconductor media (e.g., solid-state drives (SSDs)).

[0189] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. This program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the methods described above. The aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks. Unless otherwise specified, the technical features of this embodiment and its implementation can be combined arbitrarily.

[0190] The embodiments described above are merely preferred embodiments of this specification and are not intended to limit the scope of this specification. Any modifications and improvements made by those skilled in the art to the technical solutions of this specification without departing from the spirit of this specification should fall within the protection scope defined by the claims.

[0191] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims and specification may be performed in a different order than in the embodiments described in the specification and still achieve the desired results. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

Claims

1. A data sharing method, the method being applied to a first server corresponding to a first subject, the method comprising: Receive the target data request sent by the second server corresponding to the second entity; The target data request carries the target user identifier corresponding to the target user; In response to the target data request, the first local user data corresponding to the target user is obtained based on the target user identifier; Perform privacy calculations on the first local user data to obtain the first local user characteristics; The first local user feature is used to distinguish target user group information; The first local user feature is sent to the second server so that the second server can determine the target data processing result corresponding to the target user based on the first local user feature. The step of performing privacy calculations on the first local user data to obtain the first local user characteristics includes: The first local user data is encoded to obtain the target encoded data; Based on the target algorithm model, the target encoded data is processed to obtain the first local user features; The step of sending the first local user feature to the second server, so that the second server determines the target data processing result corresponding to the target user based on the first local user feature, includes: The first local user feature is sent to the second server, so that the second server inputs the first local user feature into the target algorithm model and outputs the target data processing result corresponding to the target user; the target algorithm model is obtained by reinforcement learning based on the historical local user features with known actual data processing results.

2. The method as described in claim 1, wherein after receiving the target data request sent by the second server corresponding to the second subject, and before obtaining the first local user data corresponding to the target user based on the target user identifier in response to the target data request, the method further includes: Determine whether to reject the target data request according to preset data sharing rules; If the target data request is allowed, then the step of obtaining the first local user data corresponding to the target user based on the target user identifier in response to the target data request is performed.

3. The method as described in claim 2, wherein determining whether to reject the target data request according to a preset data sharing rule includes: Determine whether the target user has rejected data sharing in the first entity; and / or Based on the target user information corresponding to the target user, determine whether the target data request violates the target compliance policy; and / or Determine whether the user corresponding to the target user identifier in the first subject is a non-target user or is empty.

4. The method as described in claim 2, wherein after determining whether to reject the target data request according to a preset data sharing rule, the method further includes: If the target data request is rejected, a target rejection result is sent to the second server; The target rejection result includes the target rejection factors corresponding to the target data request.

5. The method as described in claim 1, wherein the target data request further carries the target data request type corresponding to the target user; The step of obtaining the first local user data corresponding to the target user based on the target user identifier in response to the target data request includes: In response to the target data request, the first local user data corresponding to the target user is obtained based on the target user identifier and the target data request type.

6. A data sharing method, the method being applied to a second server corresponding to a second subject, the method comprising: Send a target data request corresponding to the target user to the first server corresponding to the first subject, so that the first server can obtain the first local user data corresponding to the target user based on the target user identifier carried in the target data request, and perform privacy calculation on the first local user data to obtain the first local user features; The first local user feature is used to distinguish target user group information; Receive the first local user characteristics sent by the first server; The first local user feature is obtained by the first server processing the target encoded data after encoding the first local user data based on the target algorithm model; The target data processing result corresponding to the target user is determined based on the first local user characteristics; The step of determining the target data processing result corresponding to the target user based on the first local user characteristics includes: The first local user feature is input into the target algorithm model, and the target data processing result corresponding to the target user is output. The target algorithm model is obtained by reinforcement learning based on historical local user features with known actual data processing results.

7. The method as described in claim 6, wherein the historical local user features include the first historical local user features corresponding to the first server and / or the second historical local user features corresponding to the second server; The target algorithm model is updated as the historical local user characteristics are updated.

8. The method of claim 6, wherein before determining the target data processing result corresponding to the target user based on the first local user characteristics, the method further comprises: Obtain the target user's second local user data in the second subject; Based on the second local user data, determine the second local user characteristics corresponding to the target user; The step of determining the target data processing result corresponding to the target user based on the first local user characteristics includes: The target data processing result corresponding to the target user is determined based on the first local user characteristics and the second local user characteristics.

9. The method of claim 8, wherein after sending the target data request corresponding to the target user to the first server corresponding to the first subject, the method further includes: Upon receiving the target rejection result corresponding to the target data request sent by the first server, the target data processing result corresponding to the target user is determined based on the second local user characteristics.

10. A data sharing device, wherein the data sharing device is applied to a first server corresponding to a first subject, the data sharing device comprising: The first receiving module is used to receive the target data request sent by the second server corresponding to the second subject; The target data request carries the target user identifier corresponding to the target user; The first acquisition module is used to, in response to the target data request, acquire the first local user data corresponding to the target user based on the target user identifier; The privacy computation module is used to perform privacy computation on the first local user data to obtain the first local user characteristics; The first local user feature is used to distinguish target user group information; A first sending module is configured to send the first local user feature to the second server, so that the second server determines the target data processing result corresponding to the target user based on the first local user feature. The privacy computing module is specifically used for: The first local user data is encoded to obtain the target encoded data; Based on the target algorithm model, the target encoded data is processed to obtain the first local user features; The first sending module is specifically used for: The first local user feature is sent to the second server, so that the second server inputs the first local user feature into the target algorithm model and outputs the target data processing result corresponding to the target user. The target algorithm model is obtained by reinforcement learning based on historical local user features with known actual data processing results.

11. A data sharing device, wherein the data sharing device is applied to a second server corresponding to a second subject, the data sharing device comprising: The second sending module is used to send a target data request corresponding to the target user to the first server corresponding to the first subject, so that the first server can obtain the first local user data corresponding to the target user based on the target user identifier carried in the target data request, and perform privacy calculation on the first local user data to obtain the first local user feature. The first local user feature is used to distinguish target user group information; The second receiving module is used to receive the first local user characteristics sent by the first server; The first local user feature is obtained by the first server processing the target encoded data after encoding the first local user data based on the target algorithm model; The result determination module is used to determine the target data processing result corresponding to the target user based on the first local user characteristics. The result determination module is specifically used for: The first local user feature is input into the target algorithm model, and the target data processing result corresponding to the target user is output; the target algorithm model is obtained by reinforcement learning based on the historical local user features with known actual data processing results.

12. An electronic device, comprising: Processor and memory; The processor is connected to the memory; The memory is used to store executable program code; The processor runs a program corresponding to the executable program code stored in the memory to perform the method as described in any one of claims 1-9.

13. A computer storage medium storing a plurality of instructions adapted for loading by a processor and performing the method steps of any one of claims 1-9.

14. A computer program product comprising instructions that, when run on a computer or processor, cause the computer or processor to perform the data sharing method as described in any one of claims 1-9.

Citation Information

Patent Citations

  • System and method for protecting data across multiple users and devices

    CN115398859A

  • Privacy protection method and device, electronic equipment and computer storage medium

    CN116155538A