Data circulation control method and device, electronic equipment and storage medium

By obtaining the data to be circulated and its corresponding data circulation scenarios, determining the level of information sensitivity, trust value and privacy attitude, determining privacy security conditions based on these factors and evaluating privacy risks, the problem of the inability of existing technology to balance data privacy protection and sharing is solved, and flexibility and balance in data circulation is achieved.

CN119939663AActive Publication Date: 2025-05-06CHINA UNIV OF PETROLEUM (BEIJING)
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510072460.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-16
Publication Date
2025-05-06
Estimated Expiration
2045-01-16

AI Technical Summary

Technical Problem

The existing technology cannot effectively balance the privacy protection and data sharing needs of data subjects, making it difficult to meet the needs of different scenarios in data circulation control.

Method used

By obtaining the data to be circulated and its corresponding data circulation scenarios, we determine the degree of information sensitivity, the trust value of the data subject for the data audience, and the privacy attitude of the data audience to the data subject, determine the privacy security conditions based on these factors, and evaluate the privacy risks of each data audience through prospect theory, and finally determine the target privacy decisions for each data audience to control the sharing of data.

Benefits of technology

It realizes that without presetting data access conditions, the privacy protection and data sharing needs of the data subject are balanced and adapted to the needs of different data circulation scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939663A_ABST
    Figure CN119939663A_ABST
Patent Text Reader

Abstract

The invention provides a data circulation control method and apparatus, an electronic device and a storage medium. The method comprises the steps of determining an information sensitivity degree, a trust value of a data subject to a data audience and a privacy attitude of the data audience to the data subject based on to-be-circulated data and a data circulation scene; determining a privacy security condition based on a preset privacy protection strategy set, the information sensitivity degree, the privacy attitude of the data audience to the data subject and the trust value of the data subject to the data audience; determining the privacy risk of each data audience based on the information sensitivity degree in the privacy security condition, the privacy attitude of the data audience to the data subject and the risk preference value of the data subject; and determining a target privacy decision of each data audience based on the privacy risk and the privacy security condition of each data audience, so as to control the to-be-circulated data to be shared according to the target privacy decision. Therefore, the balance between data subject privacy protection and data sharing is realized based on a reinforcement learning method.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing technology, and in particular to a data flow control method, device, electronic equipment and storage medium. Background Art

[0002] Existing data flow control technologies mostly rely on access control or adopt static solutions.

[0003] In the access control-based method, the circulation conditions of information are pre-set to control the information within a predetermined range, such as only allowing information to circulate within a specified domain and only allowing visitors with specific permissions to access it. The above method requires pre-setting data access conditions, which is cumbersome to set and difficult to meet the needs of different scenarios. It cannot meet the balance between the privacy protection of data subjects and the data sharing needs. Summary of the invention

[0004] In view of this, the embodiments of the present invention provide a data flow control method, device, electronic device and storage medium to solve the problem in the prior art that the privacy protection of the data subject and data sharing cannot be balanced.

[0005] To achieve the above objectives, the embodiments of the present invention provide the following technical solutions:

[0006] A first aspect of an embodiment of the present invention shows a data flow control method, the method comprising:

[0007] Acquire the data to be circulated and its corresponding data circulation scenario, wherein the data to be circulated includes the data subject and its data content;

[0008] Determine the information sensitivity, the trust value of the data subject to the data audience, and the privacy attitude of the data audience to the data subject based on the data to be circulated and the data circulation scenario;

[0009] Determining privacy security conditions based on a preset privacy protection strategy set, the information sensitivity, the privacy attitude of the data audience towards the data subject, and the trust value of the data subject towards the data audience;

[0010] Determine the privacy risk of each data recipient based on the information sensitivity in the privacy security condition, the privacy attitude of the data recipient to the data subject, and the risk preference value of the data subject;

[0011] The target privacy decision of each data audience is determined based on the privacy risk of each data audience and the privacy security condition, so as to control the sharing of the data to be circulated according to the target privacy decision.

[0012] Optionally, determining the information sensitivity, the trust value of the data subject to the data audience, and the privacy attitude of the data audience to the data subject based on the data to be circulated and the data circulation scenario includes:

[0013] Determining the information sensitivity based on the data content in the data to be circulated and the data circulation scenario;

[0014] Determining the privacy attitude of the data recipient towards the data subject based on the data to be circulated;

[0015] The trust value of the data subject to the data audience is determined based on the privacy attitude and the data to be circulated.

[0016] Optionally, determining the trust value of the data subject to the data recipient based on the privacy attitude and the data to be circulated includes:

[0017] Setting the initial trust value of the data subject for the data recipient;

[0018] Calculate the trust impact function of the privacy threat based on the information sensitivity and the number of data audiences;

[0019] The trust value of the data subject to the data audience is determined based on the initial trust value and the trust impact function of the privacy threat.

[0020] Optionally, determining the privacy risk of each data recipient based on the information sensitivity in the privacy security condition, the privacy attitude of the data recipient towards the data subject, and the risk preference value of the data subject includes:

[0021] Determining a forwarding probability of the data recipient to the data subject based on the privacy attitude;

[0022] Determine the initial privacy risk by calculating based on the information sensitivity and the probability that the data to be circulated is forwarded;

[0023] The privacy risk of each data recipient is determined based on the risk preference value of the data subject and the initial privacy risk, wherein the risk preference value refers to the risk preference value selected by each data recipient in the data circulation scenario.

[0024] Optionally, determining a target privacy decision for each data audience based on the privacy risk of each data audience and the privacy security condition includes:

[0025] For each data audience, selecting a privacy protection policy for the data audience from the set of preset privacy protection policies of the privacy security condition;

[0026] Based on the trust value of the data subject to the data audience in the privacy security condition, determine the benefits of the data subject to the data audience under each privacy policy;

[0027] For each data audience, the target privacy decision of the data audience is determined based on the benefits of the data subject under each privacy policy and the privacy risk of the data audience.

[0028] Optionally, also include:

[0029] For each data subject, determining a cumulative privacy risk based on the historical privacy risk of the data subject;

[0030] Determine the corresponding historical benefits based on the historical shared utility value and historical privacy risk of the data subject under each privacy policy;

[0031] Determine the privacy protection target of data element circulation by using the accumulated privacy risks, historical privacy protection strategies and historical benefits;

[0032] The target privacy protection strategy of the data subject is determined based on the privacy protection goal of the data element circulation to control the sharing of the data to be circulated in accordance with the target privacy decision.

[0033] A second aspect of an embodiment of the present invention shows a data flow control device, the device comprising:

[0034] A determination unit, used to obtain the data to be circulated and its corresponding data circulation scenario, wherein the data to be circulated includes a data body and data content;

[0035] A privacy security condition generating unit, configured to determine the information sensitivity, the trust value of the data subject to the data audience, and the privacy attitude of the data audience to the data subject based on the data to be circulated and the data circulation scenario; and determine the privacy security condition based on a preset privacy protection strategy set, the information sensitivity, the privacy attitude of the data audience to the data subject, and the trust value of the data subject to the data audience;

[0036] A privacy risk prediction unit, configured to determine the privacy risk of each data recipient based on the information sensitivity in the privacy security condition, the privacy attitude of the data recipient towards the data subject, and the risk preference value of the data subject;

[0037] A processing unit is used to determine a target privacy decision for each data audience based on the privacy risk of each data audience and the privacy security condition, so as to control the sharing of the data to be circulated according to the target privacy decision.

[0038] Optionally, the privacy risk prediction unit is specifically used to:

[0039] Determining a forwarding probability of the data recipient to the data subject based on the privacy attitude;

[0040] Determine the initial privacy risk by calculating based on the information sensitivity and the probability that the data to be circulated is forwarded;

[0041] The privacy risk of each data recipient is determined based on the risk preference value of the data subject and the initial privacy risk, wherein the risk preference value refers to the risk preference value selected by each data recipient in the data circulation scenario.

[0042] The third aspect of an embodiment of the present invention shows an electronic device, which includes a processor and a memory, wherein the memory is used to store program code and data generated by data, and the processor is used to call the program instructions in the memory to execute the data flow control method described in the first aspect of the embodiment of the present invention.

[0043] A fourth aspect of an embodiment of the present invention shows a storage medium, which includes a storage program, wherein when the program is running, the device where the storage medium is located is controlled to execute the data flow control method as described in the first aspect of the embodiment of the present invention.

[0044] Based on the above-mentioned embodiment of the present invention, a data circulation control method, device, electronic device and storage medium are provided, the method includes: obtaining the data to be circulated and its corresponding data circulation scenario; characterizing the privacy security conditions of the data subject based on the data to be circulated and the data circulation scenario; evaluating the privacy risk of each data audience based on the privacy security conditions, that is, evaluating the potential privacy risk of each data audience to the data subject based on prospect theory; determining the target privacy decision for each data audience based on the privacy risk of each data audience and the privacy security conditions, so as to control the sharing of the data to be circulated according to the target path. There is no need to pre-set the access conditions of the data, and the balance between the privacy protection of the data subject and the data sharing can be achieved based on the reinforcement learning method. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.

[0046] Figure 1 A schematic diagram of a flow chart of a data flow control method according to an embodiment of the present invention;

[0047] Figure 2A schematic diagram of privacy security conditions, privacy risks, and privacy decision generation shown in an embodiment of the present invention;

[0048] Figure 3 The present invention is a schematic diagram of the structure of a data flow control device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0049] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0050] The terms "first", "second", "third", "fourth", etc. (if any) in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0051] It should be noted that the descriptions of "first", "second", etc. in the present invention are only used for descriptive purposes and cannot be understood as indicating or implying their relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined as "first" and "second" may explicitly or implicitly include at least one of the features. In addition, the technical solutions between the various embodiments can be combined with each other, but they must be based on the ability of ordinary technicians in the field to implement them. When the combination of technical solutions is contradictory or cannot be implemented, it should be deemed that such a combination of technical solutions does not exist and is not within the scope of protection required by the present invention.

[0052] In this application, the terms "comprises", "comprising" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprising a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element.

[0053] See also Figure 1 , is a data flow control method shown in an embodiment of the present invention, the method comprising:

[0054] Step S101: Acquire the data to be circulated and its corresponding data circulation scenario;

[0055] In the specific implementation of step S101, the current data to be circulated and the data circulation scenario input by the user are obtained.

[0056] Before data is circulated, it is necessary to assess the privacy risks faced by the data subject under the influence of subjective privacy risk preferences based on prospect theory to determine whether the data can be circulated.

[0057] It should be noted that the data to be circulated includes data content and data body, and the data content includes multiple field data.

[0058] The data audiences corresponding to different data circulation scenarios are different, so the data audiences corresponding to the above data circulation scenarios are obtained.

[0059] Alternatively, the data to be circulated in different circulation paths or facing different data audiences will cause different privacy risks to the data subject. Therefore, it is necessary to predict the privacy risks in the data circulation process from the perspective of the data subject.

[0060] Step S102: determining the information sensitivity, the trust value of the data subject to the data audience, and the privacy attitude of the data audience to the data subject based on the data to be circulated and the data circulation scenario;

[0061] The specific implementation process of step S102 includes the following steps:

[0062] Step S11: Determine the information sensitivity M based on the data content in the data to be circulated and the data circulation scenario.

[0063] The specific implementation of step S11 includes the following steps:

[0064] Step S21: Determine the level corresponding to each other data element based on the data subject;

[0065] Since data subjects have different information sensitivities to data in different data circulation scenarios, several sensitivity levels are pre-divided to adapt to different data circulation scenarios.

[0066] The levels include S, A, B, C, D, and E in decreasing order from left to right.

[0067] Step S22: According to the level of each data, the preset level table is traversed to determine the information sensitivity of each data element to the data subject.

[0068] It should be noted that a correspondence between different levels and information sensitivity is preset, and a preset level table is constructed based on the correspondence.

[0069] In the specific implementation of step S22, the preset level table is traversed to find the information sensitivity corresponding to the level of each data element.

[0070] It should be noted that the information sensitivity level is a number between 0 and 1. The higher the level, the closer the corresponding information sensitivity level is to 1.

[0071] For example, in the cross-medical institution electronic medical record circulation scenario, the patient is the data subject, and it is determined that the level of data 1 affected by the data subject in the cross-medical institution electronic medical record circulation scenario is E, and the level of data 2 is B. Then, the preset level table is traversed to find that the information sensitivity corresponding to the level E of data 1 is 0.4, and the information sensitivity corresponding to the level B of data 2 is 0.7.

[0072] Among them, data element 1 is the ID number and data element 2 is the home address.

[0073] Step S12: Determine the privacy attitude of the data recipient towards the data subject based on the data to be circulated.

[0074] In the specific implementation of step S12, the privacy attitude of the data recipient towards the data subject is determined based on the personal attributes of the data recipient in the data to be circulated.

[0075] Specifically, the personal attributes of the data audience are input into the privacy information propagation model so that the privacy information propagation model maps the personal attributes to the corresponding privacy attitudes to determine the privacy attitude e of each data audience towards the circulating data.

[0076] It should be noted that the privacy information propagation model is used to describe how the forwarding decision of data recipients affects the spread of private information in social networks. In other words, the privacy information propagation model is used to express the personal attributes of data recipients and their attitude towards the privacy of circulating data.

[0077] Privacy attitude, that is, the privacy protection tendency of data recipients towards data subjects, refers to the tendency of data recipients to protect the privacy of subjects, including protective attitude and non-protective attitude.

[0078] Step S13: Determine the trust value of the data subject to the data audience based on the privacy attitude and the data to be circulated.

[0079] It should be noted that the specific implementation of step S13 includes the following steps:

[0080] Step S31: setting the data subject's initial trust value for the data audience;

[0081] In the specific implementation of step S31, the initial trust value of the data subject to the data audience is .

[0082] Step S32: Calculate the trust impact function of the privacy threat based on the information sensitivity and the number of data audiences.

[0083] In the specific implementation of step S32, since the privacy threat faced by the data subject is proportional to the sensitivity M of the data itself and the number of information recipients K, the product of the information sensitivity of each data element to the data subject and the number of information recipients is calculated to obtain the potential privacy threat r caused by the information forwarding behavior, that is, r=M*K; then, the inverse of the potential privacy threat r caused by the information forwarding behavior is used as the trust impact function f(r) on the privacy threat, that is, .

[0084] It should be noted that, since the information sensitivity is for each data audience, the number of trust impact functions f(r) of the privacy threat obtained is the same as the number of data audiences, and thus the number of trusts subsequently calculated is also multiple.

[0085] Step S33: Determine the trust value of the data subject to the data audience based on the initial trust value and the trust impact function of the privacy threat.

[0086] In the specific implementation of step S33, after receiving the data, the data recipient becomes the data receiver. If the data receiver further forwards the data, the trust value of the data subject to the data receiver will change accordingly. Specifically, the initial trust value The product of the trust impact function f(r) of the privacy threat is used to update the trust value T of the data subject to the data audience, that is, .

[0087] Wherein, f(r) is the trust impact function of the privacy threat.

[0088] This application can complete the data subject's dynamic trust assessment of the data recipient based on the privacy threat caused to the data subject by the data recipient's information forwarding behavior.

[0089] Step S103: Determine the privacy security condition based on the preset privacy protection policy set, the information sensitivity M, the privacy attitude e of the data audience towards the data subject, and the trust value T of the data subject towards the data audience.

[0090] The target privacy decision is determined based on the historical utility of the data subject's privacy risk preference.

[0091] The present invention proposes the concept of privacy security conditions (PSC) to describe the conditions that data subjects need to meet to achieve privacy protection in a contextual environment. Based on the basic elements in the data circulation scenario and the relationship between the elements, the sensitivity of the data M, the trust of the data subject in the data audience T, and the privacy protection tendency of the data audience to the data subject e are selected as the core elements of PSC without loss of generality. The remaining elements can be added according to the specific scenario and the specific privacy needs of the data subject, so that the elements in PSC determine the choice of privacy protection strategy.

[0092] In the specific implementation of step S103, a privacy protection strategy set is first pre-set for the data recipients in the data circulation process, which may include a shareable strategy, a non-shareable strategy, and other privacy desensitization strategies. The specific privacy protection strategy for each data recipient is selected from the preset privacy protection strategy set.

[0093] Next, according to the influence of the information sensitivity M, the privacy attitude of the data audience to the data subject e and the trust value T of the data subject to the data audience on the privacy protection strategy, the preset privacy protection set Substituting into formula (1), we get the privacy security condition PSC. That is, the privacy security condition PSC at this time includes the preset privacy protection strategy set , the information sensitivity M, the privacy attitude e of the data audience towards the data subject and the trust value T of the data subject towards the data audience.

[0094] Formula (1):

[0095] (1)

[0096] Among them, the preset privacy protection strategy set , A set of m preset privacy protection policies that can be selected by the data subject.

[0097] It should be further explained that the privacy security condition PSC at this time is the condition that needs to be met to meet the privacy needs of the data subject.

[0098] The data subject's trust level T in the data audience and the data audience's privacy protection tendency e towards the data subject can both be in the form of a set or a numerical range.

[0099] Step S104: Based on the information sensitivity M in the privacy security condition, the privacy attitude of the data audience towards the data subject e and the risk preference value of the data subject Determine the privacy risk g(r) for each data audience.

[0100] Specifically, based on the influencing factors (M, T, e) in PSC, the risk preference value of the data subject is evaluated based on prospect theory. Determine the impact of the privacy risk g(r) on each data audience.

[0101] In this application, the data to be circulated in different circulation paths or facing different data audiences will cause different privacy risks to the data subject. Therefore, it is necessary to predict the privacy risks in the data circulation process from the perspective of the data subject, that is, to predict the privacy risks of different data audiences to the data subject. The present invention invents a privacy risk prediction method based on prospect theory, so that the prediction results of privacy risk can reflect the subjective privacy risk preference of the data subject.

[0102] The specific implementation process of step S104 includes the following steps:

[0103] Step S41: Determine the forwarding probability of the data recipient to the data subject based on the privacy attitude.

[0104] In the specific implementation of step S41, the number of data audiences whose privacy attitude towards the data to be circulated is non-protective is calculated and taken as the first number; then, the ratio of the first number to the total data of all data audiences is calculated to obtain the probability of the data audience forwarding the data subject, i.e., the forwarding probability. In other words, the privacy attitude of the information audience towards the circulated data is calculated to obtain the probability distribution of each information audience's privacy protection attitude and non-privacy protection attitude towards the data subject, and further, the probability of the data audience forwarding the circulated data, i.e., the forwarding probability P(A), is evaluated.

[0105] Among them, P (A) is proportional to the data audience's privacy protection tendency e towards the data subject.

[0106] Step S42: Calculate based on the information sensitivity M and the probability P(A) of the data to be circulated being forwarded to determine the initial privacy risk r.

[0107] In the specific implementation of step S42, without considering the subjective privacy risk preference of the data subject, the privacy risk r caused by the data recipient is the product of the information sensitivity M and the probability P(A) that the data to be circulated will be forwarded, that is, r=M*P(A).

[0108] Step S43: Based on the risk preference value of the data subject The privacy risk g(r) of each data audience is determined by the initial privacy risk r.

[0109] Among them, the risk preference value refers to the risk preference value selected by each data audience in the data circulation scenario, that is, the subjective privacy risk preference, and the specific value can be set by the data subject.

[0110] In the specific implementation of step S43, for each data audience, first obtain the risk preference value of the data audience in the data circulation scenario; then Substitute the initial privacy risk r into formula (2) to determine the privacy risk g(r) of the data recipient.

[0111] Formula (2):

[0112] (2)

[0113] Among them, parameter α>1, parameter , parameter α and parameter The values ​​are preset.

[0114] Formula (2) expresses the impact of the data subject’s subjective privacy risk preference on the actual privacy risk. The data subject can choose the risk preference values ​​of different data audiences in different data circulation scenarios to obtain the privacy risk in that scenario.

[0115] Step S105: Determine a target privacy decision for each data audience based on the privacy risk of each data audience and the privacy security condition, so as to control the sharing of the data to be circulated according to the target privacy decision.

[0116] The specific implementation of step S105 includes the following steps:

[0117] Step S51: for each data audience, a privacy protection policy for the data audience is selected from the preset privacy protection policy set of the privacy security condition.

[0118] The privacy protection strategy includes the shareable strategy and non-shareable strategy of the data recipient, and other privacy protection strategies such as privacy desensitization strategy may also be added.

[0119] In the process of implementing step S51, for each data audience, an optional privacy protection strategy is preset, including a shareable strategy and a non-shareable strategy, and a privacy desensitization strategy can be added as needed, so as to subsequently determine which strategy is the optimal strategy, that is, the target strategy.

[0120] Step S52: Based on the trust value of the data subject to the data audience in the privacy security condition, determine the benefits of the data subject to the data audience under each privacy protection strategy;

[0121] Specifically, when the data subject chooses to share data, the data subject's benefit s(t) under the sharing strategy is related to the data subject's trust value T for the data recipient. In other words, the data subject's benefit s(t) under the sharing strategy is proportional to the data subject's trust value T for the data recipient. Based on this, the benefit s(t) of the data subject to the data audience under the shareable strategy is determined according to the trust value T of the data subject to the data audience.

[0122] At this time, the privacy loss is consistent with the privacy risk prediction result, that is, C i =g(r).

[0123] When the data subject chooses not to share data with the data audience, that is, the data audience adopts a non-sharing strategy, the benefit of the data subject to the data audience under the non-sharing strategy is 0, that is, s(t)=0.

[0124] The privacy loss at this time corresponds to the privacy risk result when the privacy risk preference value of the data subject is 0, that is, C i =g(0).

[0125] Step S53: For each data audience, based on the benefits of the data subject to the data audience under each privacy protection strategy and the privacy risk g(r) of the data audience, determine the target privacy decision of the data audience.

[0126] Specifically, the non-sharing strategy for data recipients is: =0, =0, the benefit s(t) of the data subject = 0, and the privacy risk result with a privacy risk preference value of 0, that is, the privacy risk g(0), is substituted into formula (3) to obtain the utility value of the data subject under the non-sharing strategy;

[0127] Next, a shareable strategy for the data audience, i.e. =1, the strategy can be shared = 1, the benefit s(t) of the data subject to the data recipient under the sharing strategy, and the privacy risk C i =g(r) is substituted into formula (3) to obtain the utility value of the data subject in the shareable strategy;

[0128] Then, for each additional privacy policy for the data audience, add the policy The value of , the benefit s(t) of the data subject, and the privacy risk are substituted into formula (3) to obtain the utility value of the data subject under other privacy policies.

[0129] Finally, the strategy with the largest utility value is taken as the optimal privacy decision, that is, the target privacy decision. In other words, the final utility of the data subject under each privacy protection strategy is compared to take the privacy protection strategy corresponding to the final maximum benefit as the optimal privacy decision, that is, the target privacy decision.

[0130] Based on the above specific process, the target privacy decision of each data audience is determined by formula (3).

[0131] Based on this, the data subject can choose the optimal privacy decision according to formula (3):

[0132] Formula (3):

[0133] (3)

[0134] in, Represents the privacy protection policy set of the data subject, s i (t) represents the benefit corresponding to the i-th privacy protection strategy, g i (r) represents the privacy risk corresponding to the i-th privacy protection strategy, which is a negative number.

[0135] In the embodiment of the present invention, the process from step S51 to step S53 is applicable to the cold start situation, that is, when there is less historical interaction information between the data subject and the data audience. Further, in order to achieve a balance between privacy protection and data sharing, the present invention determines the optimal privacy decision through a privacy decision method based on reinforcement learning to control the data to be circulated to be shared according to the target privacy decision.

[0136] In order to better understand the method shown in the above embodiment of the present invention, an example is given below.

[0137] The present invention verifies path control in social networks and evaluates the changes in privacy risks faced by data subjects when sharing data when using the path control. When data is transmitted in social networks, it will face different data audiences, and different data audiences have heterogeneous characteristics.

[0138] If it is determined that the trust value of the data subject V to the social network users is a Gaussian distribution , the privacy protection tendency of the data receiver W for the data subject V is uniformly distributed .

[0139] Three different privacy scenarios are set, namely scenario x, scenario y and scenario z, where the information sensitivity levels are 0.8, 0.5, and 0.2 respectively, and the privacy risk preference values ​​of the data subject are 0.8, 0.5, and 0.2 respectively.

[0140] Assuming data sensitivity M=0.8 and the privacy risk preference value of the data subject =0.5 as an example.

[0141] First, based on the sampling of the trust value T between social network users and the privacy protection tendency e of the data recipient to the data subject, the privacy security condition of the data subject W is determined, for example: PSC=({l},0.6,0.8), where the privacy decision , 1 means sending data. A value of 0 means no data is sent.

[0142] It should be noted that the privacy decisions here include target privacy decisions for multiple data audiences.

[0143] Then, based on the prospect theory, a prediction is made on the privacy risk g(r) faced by the data subject V.

[0144]

[0145] Where r=0.8*P(A), .

[0146] Then, formula (3) is used to obtain the optimal privacy decision in this scenario, maximizing the data sharing utility while ensuring privacy security.

[0147] In the embodiment of the present invention, the privacy security conditions of the data subject are characterized based on the privacy needs of the data subject, and the conditions that need to be met to meet the privacy needs of the data subject are obtained. Then, the privacy risks faced by the data subject in the context of data circulation are evaluated based on the prospect theory. Finally, according to the privacy security conditions of the data subject itself and the privacy risks faced, the privacy protection strategy for each data audience is determined to transform the privacy protection problem into a utility maximization problem and obtain the control decision of the data circulation path. Without the need to pre-set the access conditions of the data, a balance between the privacy protection of the data subject and data sharing is achieved.

[0148] Optionally, based on the method shown in the above embodiment of the present invention, the present invention also shows another implementation method, including the following steps:

[0149] Step S61: For each data subject, determine the cumulative privacy risk based on the historical privacy risk of the data subject.

[0150] In the process of implementing step S61, after executing step S101, for each data audience, each historical privacy risk g(r) of the circulation of data elements in the historical time period is obtained; and the sum is accumulated to obtain the cumulative privacy risk S=∑g(r).

[0151] In the specific implementation, the cumulative privacy risk S faced by the data subject in the historical circulation path of data elements is used as the state of the Markov Decision Process (MDP).

[0152] Step S62: Determine the corresponding historical benefits based on the historical sharing utility value of the data subject in each privacy policy and the historical privacy risk g(r).

[0153] In the specific implementation of step S62, the historical sharing utility value s of the data subject under each privacy policy and the historical privacy risk g(r) are substituted into formula (4) for processing to obtain the benefit for each privacy protection policy.

[0154] (4)

[0155] in, The benefit is defined as the difference between the utility of sharing data elements and the privacy risk. It represents the data sharing benefits obtained by the data subject when the privacy protection strategy l is adopted and the trust value of the data audience is T. It indicates the privacy leakage risk faced by the data subject when adopting privacy protection strategy l.

[0156] Step S63: The accumulated privacy risks, historical privacy protection strategies and historical benefits are used to determine the privacy protection goals of data element circulation.

[0157] First, based on MDP, the privacy protection decision-making process of data subjects during the circulation of data elements is described.

[0158] Among them, the state, action, and benefit of MDP are defined as follows:

[0159] The state refers to the cumulative privacy risks faced by the data subject in the historical circulation path of the data elements in the data element circulation scenario, that is, S=∑g(r).

[0160] Action refers to the set of privacy protection strategies that the data subject can adopt. The specific historical privacy protection strategy in .

[0161] Benefit refers to the fact that the circulation of data elements brings certain positive benefits to data subjects while causing privacy leakage risks. Benefit is defined as the difference between the utility of data element sharing and the privacy risk, that is, formula (4).

[0162] Next, based on the description of MDP, the privacy protection goal of data element circulation is determined, that is, the historical reward of the data element circulation process is maximized by selecting appropriate strategies for each data audience.

[0163] Specifically, the description based on MDP is substituted into formula (5) for calculation to obtain the privacy protection target of data element circulation.

[0164] Formula (5):

[0165] (5)

[0166] in, and Represent the states at time t and time t+1 respectively; is the relative entropy ‌KL divergence algorithm, which is used to measure the data utility loss caused by the privacy protection strategy l; Represents raw data, that is, unprocessed data to be circulated. Indicates the data to be circulated after being processed by l.

[0167] It should be noted that the accumulated value of g(r) at different time points is less than the preset value. conditions .

[0168] Among them, the preset value It is set based on multiple experiments.

[0169] Step S64: Determine the target privacy protection strategy of the data subject based on the privacy protection goal of the data element circulation, so as to control the sharing of the data to be circulated according to the target privacy decision.

[0170] In the specific implementation of step S64, the privacy protection goal of the data element circulation, that is, each data audience selects a suitable strategy to maximize the reward of the data element circulation process, is input into formula (6) for processing to find the target privacy protection strategy for each data subject, that is, the optimal privacy protection strategy.

[0171] Formula (6):

[0172] (6)

[0173] Among them, through the above privacy protection goals, find the optimal privacy protection strategy for the data subject , that is, to maximize the long-term benefits in the process of data element circulation; ∈[0,1] is the discount factor.

[0174] The specific implementation process of step S63 and step S64 can be performed in a trained deep Q network.

[0175] It should be noted that the specific training process of the deep Q network includes:

[0176] Step S71: using the reinforcement learning algorithm Q-Learning to map the states and actions described in the MDP.

[0177] In the specific implementation of step S71, the reinforcement learning algorithm Q-learning is used to learn the mapping relationship between state and action, that is, the Q function, so as to subsequently predict the expected reward of taking a certain action in a certain state based on the Q function.

[0178] Among them, the Q function can be obtained based on the Bellman equation, formula (7) is as follows:

[0179] (7)

[0180] in, Represents the mapping relationship between the state and action of the next time step, Represents the mapping relationship between the state and action of the current time step, represents the preset learning rate, Represents the mapping relationship between the state of the current time step under the influence of the discount factor and the optimal action, represents the initial privacy risk at the current time step.

[0181] Step S72: Initialize the main network and the target network.

[0182] In the specific implementation of step S72, a multilayer perceptron with the same structure is constructed, that is, the main network is and the target network is .

[0183] Step S73: Based on the mapping relationship between states and actions, and the benefit of selecting the privacy protection strategy li in state Si.

[0184] Specifically, first, a privacy protection strategy is selected based on the ε-greedy principle, that is, in each time step, the privacy protection strategy with the maximum benefit is selected with a probability of ε, and a random privacy protection strategy l is selected with a probability of (1-ε).

[0185] Among them, the ε-greedy strategy is a commonly used exploration strategy in reinforcement learning, which aims to balance exploration and exploitation.

[0186] That is to say, if the privacy protection strategy li is selected in state Si, the state Si will be transformed into the Si' state in the corresponding circulation path. At this time, the corresponding reward Reward can be determined as Re i Then, the currently selected state, the privacy protection strategy li selected in state Si, the new state Si' and the corresponding benefit Re i As a tuple, and the tuple <Si,li,Si’,Re i >Store in the replay unit; determine multiple tuples at different time steps for each data audience in the above manner.

[0187] The replay unit is used to store and randomly sample multiple tuples from the past to break the correlation between data and improve learning efficiency.

[0188] Step S74: Perform deep Q network training based on the main network, the target network, and the tuple to obtain a trained Q network.

[0189] Specifically, based on the main network and target network In each training round, a certain number of round samples are randomly selected from the replay unit to update its strategy, that is, gradient descent is performed through formula (8) to update the parameters in the main network, that is, strategy update is performed.

[0190] Among them, each sample is a tuple.

[0191] Formula (8):

[0192] (8)

[0193] The parameters θ of the target network are periodically copied and updated from the main network, which helps reduce instability during training.

[0194] It should be noted that after each training, Is it less than the preset value? If so, the current target network is the trained deep Q network; if not, continue to the next training round.

[0195] Optionally, the process of step S63 and step S64 is performed based on the above-trained deep Q network to obtain the optimal privacy protection strategy. .

[0196] In the embodiment of the present invention, the privacy protection decision-making process of the data subject in the data element circulation process is described based on MDP; the actions, states and benefits in the MDP are used to determine that each data audience selects a suitable strategy to maximize the reward of the data element circulation process, and then find the target privacy protection strategy for each data subject, that is, the optimal privacy protection strategy, and use the potential privacy risk caused by each data audience to the data subject as the control basis for the data element circulation path, so as to control the sharing of the data to be circulated according to the target privacy decision. There is no need to pre-set the access conditions of the data, so as to achieve a balance between the privacy protection of the data subject and data sharing.

[0197] Optionally, based on the data flow control method shown in the above embodiment of the present invention, the embodiment of the present invention also shows a structural schematic diagram of a data flow control device, such as Figure 3 As shown, the device comprises;

[0198] A determination unit 301 is used to obtain the data to be circulated and its corresponding data circulation scenario;

[0199] The privacy security condition generating unit 302 is used to determine the information sensitivity, the trust value of the data subject to the data audience, and the privacy attitude of the data audience to the data subject based on the data to be circulated and the data circulation scenario; determine the privacy security condition based on the preset privacy protection strategy set, the information sensitivity, the privacy attitude of the data audience to the data subject, and the trust value of the data subject to the data audience;

[0200] A privacy risk prediction unit 303 is used to determine the privacy risk of each data audience based on the information sensitivity in the privacy security condition, the privacy attitude of the data audience to the data subject, and the risk preference value of the data subject;

[0201] The processing unit 304 is used to determine the target privacy decision of each data audience based on the privacy risk of each data audience and the privacy security condition, so as to control the sharing of the data to be circulated according to the target privacy decision.

[0202] The specific principles and execution processes of each unit in the data flow control device disclosed in the above embodiment of the present invention are the same as the corresponding contents in the data flow control method provided in the above embodiment of the present invention. Please refer to the corresponding parts of the data flow control method disclosed in the above embodiment of the present invention, and will not be repeated here.

[0203] In the embodiment of the present invention, the privacy security conditions of the data subject are characterized based on the privacy needs of the data subject, and the conditions that need to be met to meet the privacy needs of the data subject are obtained. Then, the privacy risks faced by the data subject in the context of data circulation are evaluated based on the prospect theory. Finally, according to the privacy security conditions of the data subject itself and the privacy risks faced, the target non-sharing strategy of each data audience is determined to transform the privacy protection problem into a utility maximization problem and obtain the control decision of the data circulation path. Therefore, there is no need to pre-set the access conditions of the data, so as to achieve a balance between the privacy protection of the data subject and the data sharing.

[0204] Optionally, based on the data circulation control device shown in the above embodiment of the present invention, a privacy security condition generating unit 302 is used to determine the information sensitivity, the trust value of the data subject to the data audience, and the privacy attitude of the data audience to the data subject based on the data to be circulated and the data circulation scenario, and is specifically used to:

[0205] Determining the information sensitivity based on the data content in the data to be circulated and the data circulation scenario;

[0206] Determining the privacy attitude of the data recipient towards the data subject based on the data to be circulated;

[0207] The trust value of the data subject to the data audience is determined based on the privacy attitude and the data to be circulated.

[0208] Wherein, determining the trust value of the data subject to the data recipient based on the privacy attitude and the data to be circulated includes:

[0209] Setting the initial trust value of the data subject for the data recipient;

[0210] Calculate the trust impact function of the privacy threat based on the information sensitivity and the number of data audiences;

[0211] The trust value of the data subject to the data audience is determined based on the initial trust value and the trust impact function of the privacy threat.

[0212] Optionally, based on the data flow control device shown in the above embodiment of the present invention, the privacy risk prediction unit 303 is specifically used to:

[0213] Determining a forwarding probability of the data recipient to the data subject based on the privacy attitude;

[0214] Determine the initial privacy risk by calculating based on the information sensitivity and the probability that the data to be circulated is forwarded;

[0215] The privacy risk of each data recipient is determined based on the risk preference value of the data subject and the initial privacy risk, wherein the risk preference value refers to the risk preference value selected by each data recipient in the data circulation scenario.

[0216] Optionally, based on the data flow control device shown in the above embodiment of the present invention, the processing unit 304 is specifically configured to:

[0217] For each data audience, selecting a privacy protection policy for the data audience from the set of preset privacy protection policies of the privacy security condition;

[0218] Based on the trust value of the data subject to the data audience in the privacy security condition, determine the benefits of the data subject to the data audience under each privacy policy;

[0219] For each data audience, the target privacy decision of the data audience is determined based on the benefits of the data subject under each privacy policy and the privacy risk of the data audience.

[0220] Optionally, based on the data flow control device shown in the above embodiment of the present invention, the processing unit 304 is further configured to:

[0221] For each data subject, determining a cumulative privacy risk based on the historical privacy risk of the data subject;

[0222] Determine the corresponding historical benefits based on the historical shared utility value and historical privacy risk of the data subject under each privacy policy;

[0223] Determine the privacy protection target of data element circulation by using the accumulated privacy risks, historical privacy protection strategies and historical benefits;

[0224] The target privacy protection strategy of the data subject is determined based on the privacy protection goal of the data element circulation to control the sharing of the data to be circulated in accordance with the target privacy decision.

[0225] An embodiment of the present application provides an electronic device, which includes a processor and a memory, wherein the memory is used to store data flow control program code and data, and the processor is used to call program instructions in the memory to execute the steps shown in the data flow control method in the above embodiment.

[0226] An embodiment of the present invention provides a storage medium, which includes the electronic device provided by the above-mentioned embodiment of the present application, and the electronic device is used to execute the data flow control method disclosed in the embodiment of the present application.

[0227] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can refer to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system or system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can refer to the partial description of the method embodiment. The system and system embodiments described above are merely schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without creative work.

[0228] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.

[0229] The above description of the disclosed embodiments enables one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A data flow control method, characterized in that: The method comprises: Acquire the data to be circulated and its corresponding data circulation scenario, wherein the data to be circulated includes the data subject and its data content; Determine the information sensitivity, the trust value of the data subject to the data audience, and the privacy attitude of the data audience to the data subject based on the data to be circulated and the data circulation scenario; Determining privacy security conditions based on a preset privacy protection strategy set, the information sensitivity, the privacy attitude of the data audience towards the data subject, and the trust value of the data subject towards the data audience; Determine the privacy risk of each data recipient based on the information sensitivity in the privacy security condition, the privacy attitude of the data recipient to the data subject, and the risk preference value of the data subject; The target privacy decision of each data audience is determined based on the privacy risk of each data audience and the privacy security condition, so as to control the sharing of the data to be circulated according to the target privacy decision.

2. The method according to claim 1, characterized in that Determining the information sensitivity, the trust value of the data subject to the data audience, and the privacy attitude of the data audience to the data subject based on the data to be circulated and the data circulation scenario, including: Determining the information sensitivity based on the data content in the data to be circulated and the data circulation scenario; Determining the privacy attitude of the data recipient towards the data subject based on the data to be circulated; The trust value of the data subject to the data audience is determined based on the privacy attitude and the data to be circulated.

3. The method according to claim 2, characterized in that Determining the trust value of the data subject to the data recipient based on the privacy attitude and the data to be circulated includes: Setting the initial trust value of the data subject for the data recipient; Calculate the trust impact function of the privacy threat based on the information sensitivity and the number of data audiences; The trust value of the data subject to the data audience is determined based on the initial trust value and the trust impact function of the privacy threat.

4. The method according to claim 1, characterized in that: The privacy risk of each data audience is determined based on the information sensitivity in the privacy security condition, the privacy attitude of the data audience to the data subject, and the risk preference value of the data subject, including: Determining a forwarding probability of the data recipient to the data subject based on the privacy attitude; Determine the initial privacy risk by calculating based on the information sensitivity and the probability that the data to be circulated is forwarded; The privacy risk of each data recipient is determined based on the risk preference value of the data subject and the initial privacy risk, wherein the risk preference value refers to the risk preference value selected by each data recipient in the data circulation scenario.

5. The method according to claim 1, characterized in that Determining a target privacy decision for each data audience based on the privacy risk of each data audience and the privacy security condition includes: For each data audience, selecting a privacy protection policy for the data audience from the set of preset privacy protection policies of the privacy security condition; Based on the trust value of the data subject to the data audience in the privacy security condition, determine the benefits of the data subject to the data audience under each privacy policy; For each data audience, the target privacy decision of the data audience is determined based on the benefits of the data subject under each privacy policy and the privacy risk of the data audience.

6. The method according to claim 1, characterized in that Also includes: For each data subject, determining a cumulative privacy risk based on the historical privacy risk of the data subject; Determine the corresponding historical benefits based on the historical shared utility value and historical privacy risk of the data subject under each privacy policy; Determine the privacy protection target of data element circulation by using the accumulated privacy risks, historical privacy protection strategies and historical benefits; The target privacy protection strategy of the data subject is determined based on the privacy protection goal of the data element circulation to control the sharing of the data to be circulated in accordance with the target privacy decision.

7. A data flow control device, characterized in that: The device comprises: A determination unit, used to obtain the data to be circulated and its corresponding data circulation scenario, wherein the data to be circulated includes a data body and data content; A privacy security condition generating unit, configured to determine the information sensitivity, the trust value of the data subject to the data audience, and the privacy attitude of the data audience to the data subject based on the data to be circulated and the data circulation scenario; and determine the privacy security condition based on a preset privacy protection strategy set, the information sensitivity, the privacy attitude of the data audience to the data subject, and the trust value of the data subject to the data audience; A privacy risk prediction unit, configured to determine the privacy risk of each data recipient based on the information sensitivity in the privacy security condition, the privacy attitude of the data recipient towards the data subject, and the risk preference value of the data subject; A processing unit is used to determine a target privacy decision for each data audience based on the privacy risk of each data audience and the privacy security condition, so as to control the sharing of the data to be circulated according to the target privacy decision.

8. The device according to claim 7, characterized in that The privacy risk prediction unit is specifically used to: Determining a forwarding probability of the data recipient to the data subject based on the privacy attitude; Determine the initial privacy risk by calculating based on the information sensitivity and the probability that the data to be circulated is forwarded; The privacy risk of each data recipient is determined based on the risk preference value of the data subject and the initial privacy risk, wherein the risk preference value refers to the risk preference value selected by each data recipient in the data circulation scenario.

9. An electronic device, characterized in that: The electronic device includes a processor and a memory, wherein the memory is used to store program codes and data generated by data, and the processor is used to call program instructions in the memory to execute the data flow control method as described in any one of claims 1-6.

10. A storage medium, characterized in that: The storage medium includes a storage program, wherein when the program is running, the device where the storage medium is located is controlled to execute the data flow control method as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Location privacy protection system and method based on differential privacy noise addition selection

    CN109617877A

  • Privacy protection multi-party reinforcement learning system and method based on Shamir security multi-party computing

    CN114118368A

  • Image privacy prediction method based on scene context perception

    CN116310920A

  • Strategy determination method and device, equipment, storage medium and program product

    CN118797719A

  • Data security risk assessment method and system based on privacy calculation

    CN118940291A