Security protection method, system and device for data sharing and exchange and medium
By identifying sensitive information during data sharing and exchange and dynamically adjusting differential privacy algorithms, generating privacy protection data, and ensuring data transmission security through transmission encryption and invisible watermarks, the problems of privacy information leakage and dynamic privacy protection in the existing technology are solved, and efficient privacy protection and data secure transmission are achieved.
Patent Information
- Application Number
- CN202510375275.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-27
- Publication Date
- 2025-06-17
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The prior art is difficult to effectively prevent the leakage of privacy information during data sharing and exchange, and the lack of a dynamic privacy protection mechanism, which makes it difficult to balance the intensity of privacy protection and the data usage needs.
By loading raw data to identify sensitive information, dynamically adjust the differential privacy algorithm according to user needs and target scenarios to add noise, generate privacy-protected data, and ensure data transmission is secure and traceable through transmission encryption and invisible watermarks.
It realizes effective hiding sensitive information while meeting the data accuracy requirements, reduces the risk of private information leakage, ensures privacy in the data sharing process, and improves the security and traceability of the data transmission process.
Smart Images

Figure CN120162811A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of data security, and particularly to a security protection method, system, device and medium for data sharing and exchange. Background Art
[0002] Currently, with the increasing value and application scope of data, and the growing demand for data sharing and exchange, data sharing and exchange refer to the process of data transmission and sharing between different entities through specific means among multiple systems or institutions in order to realize the value and application of data. Through the circulation and integration of data, business efficiency can be improved, the decision-making process can be optimized, and the potential commercial value of data can be mined. However, at the same time, data sharing and exchange also face severe privacy protection and security challenges. Especially when dealing with sensitive data, it is necessary to ensure both the privacy of the data and meet the requirements of efficient data utilization, which poses higher requirements for data protection technologies.
[0003] Existing traditional encryption technologies can protect the integrity of data during data transmission and storage, but they cannot effectively prevent the privacy information that may be leaked during the statistical analysis process. Using static anonymization methods is difficult to dynamically adapt to different user needs and scenario changes, easily resulting in too low data protection intensity or insufficient data availability. At the same time, the lack of the ability to dynamically adjust according to field correlation and access behavior leads to easy privacy leakage in frequently used or related fields.
[0004] The above-mentioned existing technical solutions have the following defects: The existing data protection methods lack a dynamic privacy protection mechanism for user needs and target scenarios, resulting in difficulty in balancing the privacy protection intensity and data usage requirements, so there is room for improvement. Summary of the Invention
[0005] In order to improve the security of data sharing, the present application provides a security protection method, system, device and medium for data sharing and exchange.
[0006] The first invention object of the present application is achieved through the following technical solutions: A security protection method for data sharing and exchange, the security protection method for data sharing and exchange includes: Loading the original data, identifying the sensitive information in the loaded data, and classifying the original data according to the category of the sensitive information; Obtaining user requirement information and the corresponding target scenario situation, and adding noise to the sensitive information through a differential privacy algorithm according to the user requirement information and the target scenario situation to generate privacy protection data; Perform transmission encryption processing on the privacy-protected data to obtain corresponding encrypted data, and then transmit the encrypted data through a corresponding encrypted channel. Record the operation logs during the data transmission process and embed invisible watermarks to track the usage of the encrypted data; Analyze the privacy protection requirements of the target scenario situation. According to the preset usage specifications, dynamically adjust the privacy protection parameters of the encrypted data, and recycle the encrypted data at the end of the life cycle of the encrypted data.
[0007] By adopting the above technical solutions, by loading the original data, identifying the sensitive information in the loaded data, and classifying the original data according to the categories of the sensitive information, it is possible to structurally organize the sensitive information in the data, clarify the types and scopes of different sensitive information, and thus provide accurate basic information for subsequent differential privacy protection and encrypted transmission; by obtaining the user requirement information and the corresponding target scenario situation, and according to the user requirement information and the target scenario situation, adding noise to the sensitive information through the differential privacy algorithm to generate privacy-protected data, it is possible to effectively hide the sensitive information while meeting the user's data accuracy requirements, thereby reducing the risk of sensitive information leakage and ensuring the privacy of the data during sharing; by performing transmission encryption processing on the privacy-protected data to obtain corresponding encrypted data, and then transmitting the encrypted data through a corresponding encrypted channel, recording the operation logs during the data transmission process, and embedding invisible watermarks to track the usage of the encrypted data, it is possible to provide double protection during the data transmission process, ensure transmission security through encryption, and achieve data traceability through invisible watermarks, thereby enhancing the security and traceability of the data transmission process; by analyzing the privacy protection requirements of the target scenario situation and dynamically adjusting the privacy protection parameters of the encrypted data according to the preset usage specifications, and recycling the encrypted data at the end of the life cycle of the encrypted data, it is possible to flexibly adjust the privacy protection parameters according to different scenarios, avoid resource waste, and perform safe recycling at the end of the data life cycle, thereby further improving the security and efficiency of data management.
[0008] In one example, the present application can be further configured as: the identifying the sensitive information in the loaded data and classifying the original data according to the categories of the sensitive information specifically includes: Quantify the association strength between the data fields in the original data and a preset associated reference data set through an association analysis model, and then determine the corresponding sensitive information according to the quantified data association strength; Evaluate the sensitive information based on a preset data risk rating strategy to obtain the corresponding data risk level, and classify the sensitive information into risk and association classifications according to the data risk level and the data association strength.
[0009] By adopting the above technical solution, the association strength between the data fields in the original data and the preset association benchmark data set is quantified through the association analysis model, and then the corresponding sensitive information is determined according to the quantified data association strength, which can accurately identify the potential sensitive information in the data and quantify the association degree between the data and the benchmark data, thereby providing a scientific basis for subsequent data classification and risk assessment; by evaluating the sensitive information based on the preset data risk rating strategy, obtaining the corresponding data risk level, and classifying the sensitive information into risk and association categories according to the data risk level and data association strength, the data sensitivity and association can be classified and managed hierarchically, thereby allocating more appropriate resources for differential privacy and encryption processing and improving the accuracy and efficiency of data protection.
[0010] In one example, the present application can be further configured as follows: according to the user requirement information and the target scenario situation, adding noise to the sensitive information through the differential privacy algorithm to generate privacy-protected data, which specifically includes: Extracting the data usage frequency and statistical accuracy requirements from the user requirement information, and then calculating the privacy allocation parameters of the differential privacy algorithm according to the data usage frequency and the statistical accuracy requirements; Prioritizing the allocation of the privacy allocation parameters to high-risk and high-correlation data, and applying the asymmetric differential privacy algorithm to add random perturbations to the association between fields on the basis of adding noise; Based on the privacy allocation parameters, calculating the corresponding noise value for low-risk and low-correlation data, and optimizing the noise intensity in combination with the usage frequency and sensitivity of the fields.
[0011] By adopting the above technical solution, by extracting the data usage frequency and statistical accuracy requirements from the user requirement information, and then calculating the privacy allocation parameters of the differential privacy algorithm according to the data usage frequency and the statistical accuracy requirements, the privacy budget can be dynamically allocated according to the actual needs of the user, thereby maximizing the availability of the data while protecting the sensitive information; by prioritizing the allocation of the privacy allocation parameters to high-risk and high-correlation data, and applying the asymmetric differential privacy algorithm to add random perturbations to the association between fields on the basis of adding noise, stronger protection can be provided for high-risk data and high-correlation fields, reducing the risk of information leakage between fields, thereby enhancing the overall privacy protection strength of the data; by calculating the corresponding noise value for low-risk and low-correlation data based on the privacy allocation parameters and optimizing the noise intensity in combination with the usage frequency and sensitivity of the fields, the privacy protection strength of low-sensitive data can be effectively reduced, thereby optimizing the availability of the data on the premise of ensuring privacy protection.
[0012] In one example, the present application can be further configured as follows: calculating the privacy allocation parameters of the differential privacy algorithm according to the data usage frequency and the statistical accuracy requirement, specifically including: Calculating the usage frequency weight and the statistical accuracy weight according to the data usage frequency and the statistical accuracy requirement; Based on a preset global privacy budget, determining an initial value of the privacy allocation parameter through the usage frequency weight and the statistical accuracy weight, and the calculation formula of the initial value of the privacy allocation parameter is: where ε global is the preset global privacy budget, ω f is the usage frequency weight, ω s is the statistical accuracy weight; Combining the data risk level and the data association strength, optimizing and adjusting the privacy allocation parameter to obtain the final privacy allocation parameter, and the calculation formula of the privacy allocation parameter is: where ε initial is the initial value of the privacy allocation parameter, s i is the data risk level, r ij is the data association strength, is the sum of the risk levels of all fields, and max(r) is the maximum value of the association strength of all fields.
[0013] By adopting the above technical solutions, by calculating the usage frequency weight and the statistical accuracy weight according to the data usage frequency and the statistical accuracy requirement, the influencing factors of user requirements on privacy protection can be quantified, thereby laying a foundation for the reasonable allocation of privacy budgets; by determining the initial value of the privacy allocation parameter based on the preset global privacy budget through the usage frequency weight and the statistical accuracy weight, resources can be scientifically allocated according to the global privacy budget, thereby taking into account both the privacy protection intensity and the resource usage efficiency; by combining the data risk level and the data association strength, optimizing and adjusting the privacy allocation parameter to obtain the final privacy allocation parameter, while ensuring the privacy protection intensity of high-risk and highly associated fields, the overall privacy budget allocation can be further optimized, thereby improving the refinement level of data protection.
[0014] In one example, the present application can be further configured as follows: performing transmission encryption processing on the privacy-protected data to obtain corresponding encrypted data, and then transmitting the encrypted data through a corresponding encrypted channel, specifically including: Dynamically selecting an encryption algorithm and an encapsulation strategy according to the data risk level, the data association strength, and the security level of the target transmission path; Adopting a segmented encryption and encapsulation strategy for high-risk and highly associated data, dividing the data into multiple encrypted segments, and dynamically allocating independent keys to each encrypted segment.
[0015] By adopting the above technical solutions, by dynamically selecting encryption algorithms and encapsulation strategies according to the data risk level, data association strength, and security level of the target transmission path, appropriate encryption strategies can be selected for different risk scenarios, thereby optimizing the transmission efficiency while ensuring security; by adopting a segmented encryption and encapsulation strategy for high-risk and highly correlated data, dividing the data into multiple encrypted segments and dynamically allocating independent keys to each encrypted segment, the independence and transmission security of the data segments can be enhanced. Even if a single segment of data is leaked, the complete information cannot be restored, thus further improving the reliability of data transmission.
[0016] In one example, the present application can be further configured to: analyze the privacy protection requirements of the target scenario situation, and dynamically adjust the privacy protection parameters of the encrypted data according to preset usage specifications, specifically including: Obtain and analyze historical access data and the corresponding target scenarios and user privacy requirements, then extract access behavior characteristics, and construct a rule library of the access behavior data and the privacy protection parameters; By dynamically monitoring the user's access frequency, access time period, and data operation type, and combining with the rule library, evaluate the impact of the current access behavior on privacy protection; According to the evaluation result, when the change in the access behavior exceeds the preset access change range, adjust the privacy protection parameters.
[0017] By adopting the above technical solutions, by obtaining and analyzing historical access data and the corresponding target scenarios and user privacy requirements, then extracting access behavior characteristics, and constructing a rule library of the access behavior data and the privacy protection parameters, privacy protection rules can be dynamically generated according to the user's access habits and scenario requirements, thereby improving the intelligent level of privacy protection; by dynamically monitoring the user's access frequency, access time period, and data operation type, and combining with the rule library, evaluate the impact of the current access behavior on privacy protection, abnormal access behaviors can be identified in real time and their privacy risks can be quantified, thereby providing a reliable basis for subsequent adjustment of privacy protection parameters; by adjusting the privacy protection parameters according to the evaluation result when the change in the access behavior exceeds the preset access change range, the changes in the user behavior can be responded to in a timely manner, and the privacy protection intensity can be dynamically adjusted, thereby realizing the flexibility and efficiency of data protection.
[0018] The second above-mentioned invention object of the present application is achieved by the following technical solutions: A security protection system for data sharing and exchange, the security protection system for data sharing and exchange includes: A data loading module for loading raw data, identifying sensitive information in the loaded data, and classifying the raw data according to the categories of the sensitive information; A privacy protection module for obtaining user demand information and corresponding target scenario conditions, and adding noise to the sensitive information through a differential privacy algorithm according to the user demand information and the target scenario conditions to generate privacy-protected data; An encryption transmission module for performing transmission encryption processing on the privacy-protected data to obtain corresponding encrypted data, and then transmitting the encrypted data through a corresponding encrypted channel, recording operation logs during the data transmission process, and embedding invisible watermarks to track the usage of the encrypted data; A dynamic adjustment module for analyzing the privacy protection requirements of the target scenario conditions, dynamically adjusting the privacy protection parameters of the encrypted data according to preset usage specifications, and recycling the encrypted data at the end of the life cycle of the encrypted data.
[0019] By adopting the above technical solutions, by loading raw data, identifying sensitive information in the loaded data, and classifying the raw data according to the categories of the sensitive information, the sensitive information in the data can be structurally sorted out, and the types and scopes of different sensitive information can be clarified, so as to provide accurate basic information for subsequent differential privacy protection and encryption transmission; by obtaining user demand information and corresponding target scenario conditions, and adding noise to the sensitive information through a differential privacy algorithm according to the user demand information and the target scenario conditions to generate privacy-protected data, the sensitive information can be effectively hidden while meeting the user's data accuracy requirements, thereby reducing the risk of sensitive information leakage and ensuring the privacy of data during sharing; by performing transmission encryption processing on the privacy-protected data to obtain corresponding encrypted data, and then transmitting the encrypted data through a corresponding encrypted channel, recording operation logs during the data transmission process, and embedding invisible watermarks to track the usage of the encrypted data, double protection can be provided during the data transmission process, ensuring transmission security through encryption and realizing data traceability through invisible watermarks, thereby enhancing the security and traceability of the data transmission process; by analyzing the privacy protection requirements of the target scenario conditions and dynamically adjusting the privacy protection parameters of the encrypted data according to preset usage specifications, and recycling the encrypted data at the end of the life cycle of the encrypted data, the privacy protection parameters can be flexibly adjusted according to different scenarios, avoiding resource waste, and performing secure recycling at the end of the data life cycle, thereby further improving the security and efficiency of data management.
[0020] The above object three of the present application is achieved through the following technical solutions: A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above-mentioned security protection method for data sharing and exchange are implemented.
[0021] The above-mentioned fourth object of the present application is achieved by the following technical solutions: A computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the steps of the above-mentioned security protection method for data sharing and exchange are implemented.
[0022] In summary, the present application includes the following beneficial technical effects: 1. By loading the original data, identifying the sensitive information in the loaded data, and classifying the original data according to the category of the sensitive information, the sensitive information in the data can be structurally organized, and the types and scopes of different sensitive information can be clarified, so as to provide accurate basic information for subsequent differential privacy protection and encrypted transmission; by obtaining the user demand information and the corresponding target scenario situation, and adding noise to the sensitive information through the differential privacy algorithm according to the user demand information and the target scenario situation to generate privacy protection data, the sensitive information can be effectively hidden while meeting the user's data accuracy requirements, thereby reducing the risk of sensitive information leakage and ensuring the privacy of data during sharing; by performing transmission encryption processing on the privacy protection data to obtain the corresponding encrypted data, and then transmitting the encrypted data through the corresponding encrypted channel, recording the operation logs during the data transmission process, and embedding invisible watermarks to track the usage of the encrypted data, double protection can be provided during the data transmission process, ensuring transmission security through encryption and realizing data traceability through invisible watermarks, thereby improving the security and traceability of the data transmission process; by analyzing the privacy protection requirements of the target scenario situation and dynamically adjusting the privacy protection parameters of the encrypted data according to the preset usage specifications, and recycling the encrypted data at the end of the life cycle of the encrypted data, the privacy protection parameters can be flexibly adjusted according to different scenarios to avoid resource waste, and secure recycling can be performed at the end of the data life cycle, thereby further improving the security and efficiency of data management. 2. By quantifying the association strength between the data fields in the original data and the preset associated reference data set through the association analysis model, and then determining the corresponding sensitive information according to the quantified data association strength, it is possible to accurately identify the potential sensitive information in the data and quantify the association degree between the data and the reference data, thereby providing a scientific basis for subsequent data classification and risk assessment; by evaluating the sensitive information based on the preset data risk rating strategy to obtain the corresponding data risk level, and classifying the sensitive information into risk and association categories according to the data risk level and data association strength, it is possible to conduct hierarchical management of data sensitivity and association, thereby allocating more appropriate resources for differential privacy and encryption processing and improving the accuracy and efficiency of data protection; 3. By extracting the data usage frequency and statistical accuracy requirements from the user demand information, and then calculating the privacy allocation parameters of the differential privacy algorithm according to the data usage frequency and statistical accuracy requirements, it is possible to dynamically allocate the privacy budget according to the actual needs of the user, thereby maximizing the availability of the data while protecting sensitive information; by preferentially allocating the privacy allocation parameters to high-risk and high-correlation data and applying the asymmetric differential privacy algorithm to add random perturbations to the association between fields on the basis of adding noise, it is possible to provide stronger protection for high-risk data and high-correlation fields, reduce the risk of information leakage between fields, and thereby enhance the overall data privacy protection intensity; by calculating the corresponding noise value for low-risk and low-correlation data based on the privacy allocation parameters and optimizing the noise intensity in combination with the usage frequency and sensitivity of the fields, it is possible to effectively reduce the privacy protection intensity of low-sensitive data, thereby optimizing the availability of the data on the premise of ensuring privacy protection. Brief Description of the Drawings
[0023] Figure 1 is a flowchart of a security protection method for data sharing and exchange in an embodiment of the present application; Figure 2 is a flowchart for implementing step S10 in the security protection method for data sharing and exchange in an embodiment of the present application; Figure 3 is a flowchart for implementing step S20 in the security protection method for data sharing and exchange in an embodiment of the present application; Figure 4 is a flowchart for implementing step S21 in the security protection method for data sharing and exchange in an embodiment of the present application; Figure 5 is a flowchart for implementing step S30 in the security protection method for data sharing and exchange in an embodiment of the present application; Figure 6 is a flowchart for implementing step S40 in the security protection method for data sharing and exchange in an embodiment of the present application; Figure 7It is a schematic block diagram of a security protection system for data sharing and exchange in an embodiment of the present application; Figure 8 It is a schematic diagram of a device in an embodiment of the present application. Detailed implementation manners
[0024] The present application will be further described in detail below with reference to the accompanying drawings.
[0025] In an embodiment, as Figure 1 shown, the present application discloses a security protection method for data sharing and exchange, which specifically includes the following steps: S10: Load the original data, identify the sensitive information in the loaded data, and classify the original data according to the category of the sensitive information.
[0026] Specifically, load the original data from the specified storage location into the running environment, perform formatting processing on the loaded data to ensure the integrity and consistency of the data structure, scan each field in the data one by one, compare the content of the field with the predefined sensitive information template, when the content of the field meets the matching rule of the sensitive information template, mark the field as sensitive information, and at the same time record the name, type and the data row number where it is located, and perform a preliminary classification on the field based on the category of the sensitive information. For example, classify the fields related to personal identity as identity information, classify the fields related to financial information as transaction information, and keep the unidentifiable fields as unknown categories for subsequent further analysis.
[0027] S20: Obtain the user requirement information and the corresponding target scenario situation, and according to the user requirement information and the target scenario situation, add noise to the sensitive information through the differential privacy algorithm to generate privacy-protected data.
[0028] Specifically, parse the specific target scenario information from the requirement description input by the user, including the category of the data usage scenario and the requirements for data privacy protection, perform semantic analysis on the user requirement information to extract the requirements for data accuracy and usage frequency, allocate privacy budgets for the differential privacy algorithm according to the scenario and requirement information, and add an appropriate amount of random noise to each sensitive information field through the differential privacy algorithm to ensure that the actual information of the specific values in the sensitive fields is hidden while keeping the overall statistical characteristics of the data set unchanged, and at the same time save the generated privacy-protected data as a new data set for subsequent use.
[0029] S30: Perform transmission encryption processing on the privacy-protected data to obtain the corresponding encrypted data, and then transmit the encrypted data through the corresponding encrypted channel, record the operation logs during the data transmission process, and embed invisible watermarks to trace the usage of the encrypted data.
[0030] Specifically, before transmitting privacy-protected data, a suitable data encryption algorithm is selected to encrypt the data. The data is divided into chunks and encrypted one by one to improve the transmission efficiency. When transmitting, a secure encryption channel such as the TLS protocol is selected to ensure the security of the data during transmission. Detailed records of each operation step in the transmission process, including data encryption time, encryption method, transmission nodes, etc., are generated to form an operation log. At the same time, an invisible watermark is embedded in the data to mark the data user and the data generation time. The watermark information is hidden in the redundant bits of the data to ensure that it does not affect the statistical analysis performance of the data, and the watermark information can be extracted by decoding for tracking during the data usage process.
[0031] S40: Analyze the privacy protection requirements of the target scenario, and dynamically adjust the privacy protection parameters of the encrypted data according to the preset usage specifications, and recycle the encrypted data at the end of the life cycle of the encrypted data.
[0032] Specifically, the priority of data protection is parsed according to the specific requirements for privacy protection in the target scenario, and the scenario requirements with different priorities are mapped to the corresponding privacy protection parameter adjustment rules. The encryption intensity is dynamically adjusted according to the access frequency, data flow path, and usage method of the encrypted data. For example, the encryption level of frequently accessed data is increased or the rotation period of the encryption key is shortened. At the same time, when the life cycle of the encrypted data is approaching the end, a recycling process is triggered, and the recycled data is encrypted and destroyed to ensure irrecoverability. Detailed records of the data destruction operation are generated and stored for subsequent auditing and traceability.
[0033] In one embodiment, as Figure 2 shown, in step S10, that is, identifying sensitive information in the loaded data and classifying the original data according to the category of the sensitive information, specifically including: S11: Quantify the association strength between the data fields in the original data and the preset associated reference data set through an association analysis model, and then determine the corresponding sensitive information according to the quantified data association strength.
[0034] Specifically, by comparing each field in the original data with the preset associated reference data set one by one, the comparison criteria include the similarity of field content, the consistency of data patterns, and the semantic relevance of field names. A predefined quantification model is used to score the association strength of the fields. When the scoring result exceeds the set threshold, the field is marked as sensitive information, and the association strength value is recorded for subsequent use. The identified sensitive fields are sorted from high to low according to the association strength, and the fields with higher association strength are processed preferentially to improve the effect of sensitive information protection.
[0035] S12: Evaluate the sensitive information based on a preset data risk rating strategy to obtain the corresponding data risk level, and classify the sensitive information according to the data risk level and data association strength for risk and association classification.
[0036] Specifically, analyze the attributes of each sensitive field according to the preset risk rating strategy, including the sensitive category of the field, the scope of potential leakage impact, and the context environment associated with the field. Quantify the risk value of the field according to the scoring rules defined in the risk rating strategy, and divide the risk value from high to low into high-risk, medium-risk, and low-risk levels. Prioritize high-risk fields and high-association-strength fields into the high-sensitivity category, and classify low-risk and low-association-strength fields into the ordinary-sensitivity category to provide a classification basis for subsequent privacy protection and data usage.
[0037] In one embodiment, as Figure 3 shown, in step S20, that is, according to the user demand information and the target scenario, add noise to the sensitive information through the differential privacy algorithm to generate privacy-protected data, specifically including: S21: Extract the data usage frequency and statistical accuracy requirements from the user demand information, and then calculate the privacy allocation parameters of the differential privacy algorithm according to the data usage frequency and statistical accuracy requirements.
[0038] Specifically, extract the operation mode of the data by analyzing the demand information input by the user, such as the time frequency of the user accessing the data, the query range, and the coverage of the fields. Convert these operation modes into data usage frequency indicators. The statistical accuracy requirement is extracted according to the user's tolerance for the error of the data analysis result. Map the data usage frequency and statistical accuracy requirements to weight values respectively. Among them, the usage frequency is inversely proportional to the weight value, the higher the frequency, the lower the weight value, and the statistical accuracy requirement is directly proportional to the weight value, the higher the accuracy requirement, the higher the weight value. Combine the two weight values and input them into the budget calculation model of the differential privacy algorithm, and generate privacy allocation parameters according to the calculation result to ensure meeting the dual requirements of the user for privacy protection and data usage accuracy.
[0039] S22: Prioritize the allocation of privacy allocation parameters to high-risk and high-correlation data, and apply the asymmetric differential privacy algorithm to add random perturbations to the association between fields on the basis of adding noise.
[0040] Specifically, according to the risk level of sensitive information and the association strength of fields, the privacy allocation parameters are tilted towards high-risk fields and high-association fields. First, determine the privacy budget ratio of high-risk fields globally to ensure that these fields are allocated a higher budget. Then, use the asymmetric differential privacy algorithm to generate random noise for these fields. The size of the noise is dynamically adjusted according to the global sensitivity of the fields. To reduce the risk of association leakage between fields, further add random perturbations to the values between high-association fields. The perturbation values are generated by a random number generator and calculated based on a Gaussian distribution or a Laplace distribution to ensure that the association information between fields is effectively hidden while maintaining the overall usability of the data within the range of user requirements.
[0041] S23: Based on the privacy allocation parameters, calculate the corresponding noise values for low-risk and low-association data, and optimize the noise intensity in combination with the usage frequency and sensitivity of the fields.
[0042] Specifically, when allocating the privacy budget, allocate a relatively low budget to low-risk and low-association fields. Determine the basic noise values that need to be added to these fields through the calculation of local sensitivity. Appropriately increase the noise intensity for fields with a higher access frequency to enhance the privacy protection ability. Reduce the noise addition for fields with a lower access frequency or lower sensitivity to retain higher data accuracy. Dynamically adjust the noise intensity in combination with the usage frequency and sensitivity level of the data fields to ensure that the privacy protection of low-risk fields meets the security standards while retaining efficient data analysis performance.
[0043] In one embodiment, as Figure 4 shown, in step S21, that is, calculate the privacy allocation parameters of the differential privacy algorithm according to the data usage frequency and statistical accuracy requirements, specifically including: S211: Calculate the usage frequency weight and statistical accuracy weight according to the data usage frequency and statistical accuracy requirements.
[0044] Specifically, by analyzing the description of data access in the user requirement information, extract the usage frequency of a certain data field by the user. The usage frequency is quantified by counting the access times, query range, and time distribution. Assign a smaller weight value to the data with a high usage frequency and a larger weight value to the data with a low usage frequency. At the same time, analyze the requirements for data statistical accuracy from the user requirements, perform an inverse mapping of the allowed error range. The smaller the error, the higher the accuracy requirement, and assign a larger accuracy weight value. Standardize the frequency weight and accuracy weight to a unified range respectively to ensure that the weight values can participate in the calculation of subsequent privacy budget allocation.
[0045] S212: Based on the preset global privacy budget, determine the initial value of the privacy allocation parameter through the usage frequency weight and statistical accuracy weight. The calculation formula for the initial value of the privacy allocation parameter is: Among them, ε global is the preset global privacy budget, ω f is the usage frequency weight, ω s is the statistical accuracy weight.
[0046] Specifically, taking the preset global privacy budget ε global as the total allocation amount, through the calculated usage frequency weight ω f and the statistical accuracy weight ω s input into the formula to calculate the initial value of the privacy allocation parameter. For data with a smaller frequency weight, that is, data used frequently, the initial allocated value will be correspondingly reduced to avoid privacy leakage caused by frequent access; for data with a larger accuracy weight, that is, fields with high accuracy requirements, the initial privacy allocation parameter will increase to meet the user's requirements for analysis accuracy. At the same time, the formula result is normalized to ensure that the sum of the initial allocation parameters of all fields does not exceed the global privacy budget.
[0047] S213: Combine the data risk level and the data association strength to optimize and adjust the privacy allocation parameter to obtain the final privacy allocation parameter. The calculation formula of the privacy allocation parameter is: Among them, ε initial is the initial value of the privacy allocation parameter, s i is the data risk level, r ij is the data association strength, is the sum of the risk levels of all fields, and max(r) is the maximum value of the association strength of all fields.
[0048] Specifically, combine the initial value ε of the privacy allocation parameter initial with the risk level s of each data field i and the association strength r between fields ij for dynamic optimization. Prioritize the allocation of fields according to the risk level. Fields with a higher risk level are allocated more privacy budgets to improve the protection intensity. At the same time, analyze the correlation between fields, and perform additional deduction processing on the allocation parameter for highly correlated fields. The degree of deduction is proportional to the association strength to ensure that the privacy leakage risk between fields is effectively controlled. Finally, obtain the optimized privacy allocation parameter. The optimized parameter can more evenly balance privacy protection and data usage requirements.
[0049] In one embodiment, as Figure 5 shown, in step S30, that is, perform transmission encryption processing on the privacy-protected data to obtain the corresponding encrypted data, and then transmit the encrypted data through the corresponding encrypted channel, specifically including: S31: Dynamically select the encryption algorithm and encapsulation strategy according to the data risk level, the data association strength, and the security level of the target transmission path.
[0050] Specifically, different encryption algorithms are selected for fields with different risk levels according to the data risk level. For example, the AES-256 algorithm with higher security is selected for high-risk data, and the AES-128 algorithm is selected for medium-risk data. At the same time, an additional encryption encapsulation layer is added to high-correlation fields according to the correlation strength of the fields, and the security of the transmission path is dynamically evaluated. If there are untrusted intermediate nodes in the path, the end-to-end encryption method is preferentially selected; if the security of the path nodes is relatively high, the segmented encryption method is selected to improve the transmission efficiency, and the length and validity period of the encryption key are adjusted according to the security level of the transmission path to ensure the security of data under different path conditions.
[0051] S32: Adopt a segmented encryption and encapsulation strategy for high-risk and high-correlation data, divide the data into multiple encrypted segments, and dynamically allocate independent keys for each encrypted segment.
[0052] Specifically, high-risk and high-correlation data is divided into multiple independent encrypted segments, an encryption key is independently generated for each segment, and the key generation is based on a random number generator combined with a timestamp or a unique identifier to ensure uniqueness. The segmented data is encrypted block by block and encapsulated into independent encrypted units. An integrity verification tag is attached to each encrypted unit during the transmission process to ensure that the data transmission is not tampered with. At the same time, a key negotiation protocol is adopted during key distribution to ensure the security of the key and the uncrackability of the segmented data. Finally, the segmented data is combined into a complete transmission data packet through the encapsulation strategy and transmitted.
[0053] In one embodiment, as Figure 6 shown, in step S40, that is, analyze the privacy protection requirements of the target scenario situation, and dynamically adjust the privacy protection parameters of the encrypted data according to the preset usage specifications, specifically including: S41: Obtain and analyze historical access data and the corresponding target scenario and user privacy requirements, and then extract access behavior characteristics to construct a rule library of access behavior data and privacy protection parameters.
[0054] Specifically, extract the operation mode of users on data from historical access records, including the frequency of access, time distribution, and data operation types. Combine the operation mode with the privacy protection requirements in the target scenario, extract access behavior characteristics through data analysis algorithms, mark the behavior characteristics with high access frequency and operation time concentrated in non-working hours as potentially high-risk behaviors, map the rules to the corresponding privacy protection parameters to form a rule library, and continuously update the rule library to adapt to changes in user behavior, providing an accurate decision-making basis for subsequent adjustment of privacy protection parameters.
[0055] S42: By dynamically monitoring the user's access frequency, access time period, and data operation type, and combining with the rule base, evaluate the impact of the current access behavior on privacy protection.
[0056] Specifically, by recording each user access behavior in real time, including the accessed fields, operation types, and the time when the operation occurs, dynamically count the access frequency and compare it with historical access data. Combining with the definition of high-risk behaviors in the rule base, identify abnormal access patterns, such as high-frequency access within a short period or a large number of data queries during non-working hours. According to the identification results, evaluate the potential impact of the current behavior on privacy protection, and provide a risk level assessment basis for subsequent adjustment of privacy protection parameters.
[0057] S43: According to the evaluation results, when the change in the access behavior exceeds the preset access change range, adjust the privacy protection parameters.
[0058] Specifically, by comparing the evaluation results with the preset access behavior change range, when there are significant abnormalities in the access frequency, operation type, or access time period, such as the access frequency exceeding the set threshold or the access time period being concentrated in sensitive periods, trigger the privacy protection parameter adjustment process, including increasing the data encryption intensity, shortening the key rotation period, or increasing the noise addition amount of the differential privacy algorithm. At the same time, store the adjustment records for subsequent auditing to ensure that the privacy protection level matches the user's access behavior.
[0059] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not mean the order of execution. The execution order of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.
[0060] In one embodiment, a security protection system for data sharing and exchange is provided. The security protection system for data sharing and exchange corresponds one-to-one with the security protection method for data sharing and exchange in the above embodiments. As Figure 7 shown, the security protection system for data sharing and exchange includes a data loading module, a privacy protection module, an encrypted transmission module, and a dynamic adjustment module. The detailed description of each functional module is as follows: The data loading module is used to load the original data, identify the sensitive information in the loaded data, and classify the original data according to the category of the sensitive information; The privacy protection module is used to obtain the user requirement information and the corresponding target scenario situation. According to the user requirement information and the target scenario situation, add noise to the sensitive information through the differential privacy algorithm to generate privacy protection data; The encryption transmission module is used to perform transmission encryption processing on privacy-protected data to obtain corresponding encrypted data, and then transmit the encrypted data through a corresponding encrypted channel, record the operation logs during the data transmission process, and embed invisible watermarks to track the usage of the encrypted data; The dynamic adjustment module is used to analyze the privacy protection requirements of the target scenario, dynamically adjust the privacy protection parameters of the encrypted data according to the preset usage specifications, and recycle the encrypted data at the end of the life cycle of the encrypted data.
[0061] Optionally, the data loading module specifically includes: The correlation analysis sub-module is used to quantify the correlation strength between the data fields in the original data and the preset correlation benchmark data set through a correlation analysis model, and then determine the corresponding sensitive information according to the quantified data correlation strength; The risk assessment sub-module is used to evaluate the sensitive information based on a preset data risk rating strategy to obtain the corresponding data risk level, and classify the sensitive information into risk and correlation categories according to the data risk level and data correlation strength.
[0062] Optionally, the privacy protection module specifically includes: The requirement analysis sub-module is used to extract the data usage frequency and statistical accuracy requirements from the user requirement information, and then calculate the privacy allocation parameters of the differential privacy algorithm according to the data usage frequency and statistical accuracy requirements; The noise allocation sub-module is used to preferentially allocate the privacy allocation parameters to high-risk and high-correlation data, and apply the asymmetric differential privacy algorithm to add random perturbations to the correlation between fields on the basis of adding noise; The noise optimization sub-module is used to calculate the corresponding noise value for low-risk and low-correlation data based on the privacy allocation parameters, and optimize the noise intensity in combination with the usage frequency and sensitivity of the fields.
[0063] Optionally, the requirement analysis sub-module specifically includes: The weight calculation unit is used to calculate the usage frequency weight and statistical accuracy weight according to the data usage frequency and statistical accuracy requirements; the initial allocation unit is used to determine the initial value of the privacy allocation parameter based on the preset global privacy budget through the usage frequency weight and statistical accuracy weight. The calculation formula for the initial value of the privacy allocation parameter is: where ε global is the preset global privacy budget, ω f is the usage frequency weight, ω s is the statistical accuracy weight; The optimization adjustment unit is used to optimize and adjust the privacy allocation parameter in combination with the data risk level and data correlation strength to obtain the final privacy allocation parameter. The calculation formula for the privacy allocation parameter is: Among them, ε initial is the initial value of the privacy allocation parameter, s i is the data risk level, r ij is the data association strength, is the sum of the risk levels of all fields, and max(r) is the maximum value of the association strength of all fields.
[0064] Optionally, the encryption transmission module specifically includes: An encryption policy sub-module, which is used to dynamically select an encryption algorithm and an encapsulation policy according to the data risk level, the data association strength, and the security level of the target transmission path; A segmented encryption sub-module, which is used to adopt a segmented encryption and encapsulation policy for high-risk and high-correlation data, divide the data into multiple encrypted segments, and dynamically allocate independent keys for each encrypted segment.
[0065] Optionally, the dynamic adjustment module specifically includes: A rule library construction sub-module, which is used to obtain and analyze historical access data and the corresponding target scenarios and user privacy requirements, and then extract access behavior characteristics to construct a rule library of access behavior data and privacy protection parameters; A behavior monitoring sub-module, which is used to evaluate the impact of the current access behavior on privacy protection by dynamically monitoring the user's access frequency, access time period, and data operation type and combining with the rule library; A parameter adjustment sub-module, which is used to adjust the privacy protection parameters according to the evaluation result when the change in the access behavior exceeds the preset access change range.
[0066] For the specific limitations of the security protection system for data sharing and exchange, reference can be made to the limitations of the security protection method for data sharing and exchange in the above text, which will not be elaborated here. Each module in the above security protection system for data sharing and exchange can be implemented in whole or in part by software, hardware, and their combinations. The above-mentioned modules can be embedded in or independent of the processor in the computer device in the form of hardware, or stored in the memory of the computer device in the form of software, so as to facilitate the processor to call and execute the operations corresponding to the above-mentioned modules.
[0067] In one embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 8As shown in the figure. The computer device includes a processor, a memory, a network interface, and a database connected by a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it realizes a security protection method for data sharing and exchange.
[0068] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are realized: Load the original data, identify the sensitive information in the loaded data, and classify the original data according to the category of the sensitive information; obtain the user requirement information and the corresponding target scenario situation, and according to the user requirement information and the target scenario situation, add noise to the sensitive information through the differential privacy algorithm to generate privacy-protected data; Perform transmission encryption processing on the privacy-protected data to obtain the corresponding encrypted data, and then transmit the encrypted data through the corresponding encrypted channel, record the operation log during the data transmission process, and embed an invisible watermark to track the usage of the encrypted data; analyze the privacy protection requirements of the target scenario situation, and dynamically adjust the privacy protection parameters of the encrypted data according to the preset usage specifications, and recycle the encrypted data at the end of the life cycle of the encrypted data.
[0069] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the following steps are realized: Load the original data, identify the sensitive information in the loaded data, and classify the original data according to the category of the sensitive information; obtain the user requirement information and the corresponding target scenario situation, and according to the user requirement information and the target scenario situation, add noise to the sensitive information through the differential privacy algorithm to generate privacy-protected data; Perform transmission encryption processing on the privacy-protected data to obtain the corresponding encrypted data, and then transmit the encrypted data through the corresponding encrypted channel, record the operation log during the data transmission process, and embed an invisible watermark to track the usage of the encrypted data; analyze the privacy protection requirements of the target scenario situation, and dynamically adjust the privacy protection parameters of the encrypted data according to the preset usage specifications, and recycle the encrypted data at the end of the life cycle of the encrypted data.
[0070] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0071] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the above division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the system can be divided into different functional units or modules to complete all or part of the functions described above.
[0072] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.
Claims
1. A security protection method for data sharing and exchange, characterized in that: The security protection method for data sharing and exchange includes: Loading original data, identifying sensitive information in the loaded data, and classifying the original data according to the category of the sensitive information; Obtaining user demand information and corresponding target scenario conditions, and adding noise to the sensitive information through a differential privacy algorithm according to the user demand information and the target scenario conditions to generate privacy-preserving data; Performing transmission encryption processing on the privacy protection data to obtain corresponding encrypted data, and then transmitting the encrypted data through a corresponding encryption channel, recording an operation log during the data transmission process, and embedding an invisible watermark to track the use of the encrypted data; The privacy protection requirements of the target scenario are analyzed, the privacy protection parameters of the encrypted data are dynamically adjusted according to preset usage specifications, and the encrypted data is recycled at the end of its life cycle.
2. The data sharing and exchange security protection method according to claim 1 is characterized in that: The identifying the sensitive information in the loaded data and classifying the original data according to the category of the sensitive information specifically includes: quantifying the association strength between the data fields in the original data and the preset association benchmark data set through an association analysis model, and then determining the corresponding sensitive information according to the quantified data association strength; The sensitive information is evaluated based on a preset data risk rating strategy to obtain a corresponding data risk level, and the sensitive information is classified into risk and relevance categories according to the data risk level and the data association strength.
3. The data sharing and exchange security protection method according to claim 2 is characterized in that: The step of adding noise to the sensitive information by using a differential privacy algorithm according to the user demand information and the target scenario to generate privacy-preserving data specifically includes: Extracting data usage frequency and statistical accuracy requirements from the user demand information, and then calculating the privacy allocation parameters of the differential privacy algorithm according to the data usage frequency and the statistical accuracy requirements; The privacy allocation parameters are allocated preferentially to high-risk and high-correlation data, and an asymmetric differential privacy algorithm is applied to add random perturbations to the correlation between fields on the basis of adding noise; Based on the privacy allocation parameters, the corresponding noise value is calculated for low-risk and low-correlation data, and the noise intensity is optimized in combination with the frequency of use and sensitivity of the field.
4. The data sharing and exchange security protection method according to claim 3 is characterized in that: The calculating of the privacy allocation parameter of the differential privacy algorithm according to the data usage frequency and the statistical accuracy requirement specifically includes: Calculate the usage frequency weight and the statistical accuracy weight according to the data usage frequency and the statistical accuracy requirement; Based on the preset global privacy budget, the initial value of the privacy allocation parameter is determined by the usage frequency weight and the statistical accuracy weight. The calculation formula of the initial value of the privacy allocation parameter is: Among them, the ε global is the preset global privacy budget, ω f is the usage frequency weight, ω s is the statistical accuracy weight; In combination with the data risk level and the data association strength, the privacy allocation parameter is optimized and adjusted to obtain the final privacy allocation parameter. The calculation formula of the privacy allocation parameter is: Among them, ε initial The initial value of the privacy allocation parameter, s i is the data risk level, r ij is the data association strength, is the sum of the risk levels of all fields, and max(r) is the maximum value of the association strength of all fields.
5. The data sharing and exchange security protection method according to claim 2 is characterized in that: The performing transmission encryption processing on the privacy protection data to obtain corresponding encrypted data, and then transmitting the encrypted data through the corresponding encryption channel specifically includes: Dynamically select an encryption algorithm and an encapsulation strategy according to the data risk level, the data association strength, and the security level of the target transmission path; A segmented encryption encapsulation strategy is adopted for high-risk and high-correlation data, which divides the data into multiple encryption segments and dynamically allocates independent keys to each of the encryption segments.
6. The data sharing and exchange security protection method according to claim 1 is characterized in that: The step of analyzing the privacy protection requirements of the target scenario and dynamically adjusting the privacy protection parameters of the encrypted data according to the preset usage specification specifically includes: Acquire and analyze historical access data and corresponding target scenarios and user privacy requirements, and then extract access behavior features and build a rule base of the access behavior data and the privacy protection parameters; By dynamically monitoring the user's access frequency, access period and data operation type, combined with the rule base, the impact of the current access behavior on privacy protection is evaluated; According to the evaluation result, when the change of the access behavior exceeds the preset access change range, the privacy protection parameter is adjusted.
7. A data sharing and exchange security protection system, characterized in that: The data sharing and exchange security protection system includes: A data loading module, used to load original data, identify sensitive information in the loaded data, and classify the original data according to the category of the sensitive information; A privacy protection module is used to obtain user demand information and corresponding target scenario conditions, and add noise to the sensitive information through a differential privacy algorithm according to the user demand information and the target scenario conditions to generate privacy protection data; An encryption transmission module is used to perform transmission encryption processing on the privacy protection data to obtain corresponding encrypted data, and then transmit the encrypted data through a corresponding encryption channel, record the operation log during the data transmission process, and embed an invisible watermark to track the use of the encrypted data; The dynamic adjustment module is used to analyze the privacy protection requirements of the target scenario, dynamically adjust the privacy protection parameters of the encrypted data according to the preset usage specifications, and recycle the encrypted data at the end of the life cycle of the encrypted data.
8. The data sharing and exchange security protection system according to claim 7, characterized in that: The data loading module specifically includes: An association analysis submodule, used to quantify the association strength between the data fields in the original data and the preset association benchmark data set through an association analysis model, and then determine the corresponding sensitive information according to the quantified data association strength; The risk assessment submodule is used to assess the sensitive information based on a preset data risk rating strategy to obtain a corresponding data risk level, and classify the sensitive information into risk and relevance categories according to the data risk level and the data association strength.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the data sharing and exchange security protection method as claimed in any one of claims 1 to 6 are implemented.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the data sharing and exchange security protection method as claimed in any one of claims 1 to 6 are implemented.
Citation Information
Cited By
Sensitive data automatic identification method and system, medium and electronic equipment
CN120449192A
Network data processing method, device and equipment
CN120658484A
A network data processing method, device and equipment
CN120658484B
Digital operation management and control platform based on shared service operation management
CN120910108A
A digital operation and management platform based on shared service operation and management
CN120910108B