Multi-party data access authorization method based on federal learning

By setting up the same initial data processing model on the shared cloud platform to generate operation correction parameter matrix, calculate the total matching degree and set the permission level, and using the public access permission key and key splicing sequence for data access authorization, the problems of permission management complexity and computing resource requirements in multi-party data access control are solved, and simplified management and data privacy protection are achieved.

CN120337283AActive Publication Date: 2025-07-18SHANGRAO MIGU NETWORK TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510403038.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-01
Publication Date
2025-07-18
Estimated Expiration
2045-04-01

AI Technical Summary

Technical Problem

The existing federated learning and privacy computing methods have problems such as complexity in permission management and increased computing resource requirements in multi-party data access control, resulting in system scalability and inefficiency in implementation.

Method used

By setting the same initial data processing model on the shared cloud platform, generating operation correction parameter matrix, calculating the total matching degree and setting permission levels, using public access permission keys and key splicing sequences for data access authorization, reducing direct communication to ensure data privacy.

Benefits of technology

Simplifies the permission management process, improves the flexibility of computing resources, and effectively protects the data privacy of data participants.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337283A_ABST
    Figure CN120337283A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-party data access authorization method based on federated learning, and relates to the technical field of authorization certification, and the method comprises the steps: setting a same initial data processing model for each data participant, inputting the original data of each data participant into the initial data processing model by each data participant to generate an operation correction parameter; generating correction parameter matrixes according to the operation correction parameters, carrying out overlapping mapping on the correction parameter matrixes to obtain a total matching degree among the correction parameter matrixes, setting permission levels for the data participants according to the total matching degree, and when any data participant generates a data access request, sending the data access request to the data participant. The data access request is audited by the plurality of data participants, and the corresponding data participants are endowed with the data access permission according to the audit result, so that the data privacy of the data participants is effectively ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of authorization and authentication, and specifically to a multi-party data access authorization method based on federated learning. Background Art

[0002] Currently, the research on access control mainly focuses on the aspects of user identity, authorization and authentication, and access authorization combination, which poses new challenges to traditional access control. Especially, the sharp increase in user requirements and data volume has led to the complication of the access control management environment. In existing access control technologies, the use of federated learning and privacy computing is gradually increasing;

[0003] Although the authorization methods of federated learning and privacy computing have innovation and potential, there are still some existing defects. For example, when there are too many data participants, the different data access rights and data control rights of each data participant lead to the increasingly complex permission management that access control technology needs to handle. At the same time, when the number of participants increases, the complex technical requirements such as authorization and secure computing require a huge increase in computing resources and time, which limits the scalability and implementation efficiency of the system. How to reduce the complexity of permission management while improving the flexibility of computing resources is a difficult problem in the prior art. For this reason, a multi-party data access authorization method based on federated learning is provided. Summary of the Invention

[0004] In order to solve the above technical problems, the purpose of the present invention is to provide a multi-party data access authorization method based on federated learning.

[0005] To achieve the above purpose, the present invention provides the following technical solutions:

[0006] A multi-party data access authorization method based on federated learning, comprising the following steps:

[0007] Step 1, set up a shared cloud platform, set the same initial data processing model for each data participant, and each data participant inputs its own original data into the initial data processing model for training to generate operation correction parameters. At the same time, the shared cloud platform generates a corresponding correction parameter matrix according to the operation correction parameters of each data participant;

[0008] Step 2, perform overlapping mapping on each correction parameter matrix to obtain the total matching degree between each correction parameter matrix, and set the permission level for the data participants corresponding to each correction parameter matrix according to the total matching degree;

[0009] Step 3: Each data participant uploads its respective access permission key to the shared cloud platform. Subsequently, the shared cloud platform aggregates all the access permission keys to generate a public access permission key, divides the public access permission key into several public access permission sub-keys, randomly sends the public access permission sub-keys to each data participant, and simultaneously generates a key splicing sequence according to the sending order.

[0010] Step 4: Split the key splicing sequence into several key splicing sub-sequences and send them to the data participants with a higher permission level. When the shared cloud platform receives a data access request from any data participant, multiple data participants review the data access request and grant the corresponding data access permission to the data participant according to the review result.

[0011] Further, the generation process of the operation correction parameter includes:

[0012] Set up the shared cloud platform. Then, the shared cloud platform assigns numbers S1, S2, …, S n , where n is a natural number greater than 0;

[0013] The shared cloud platform simultaneously sends the preset initial data processing model to each data participant. The initial data processing model consists of an input layer, a processing layer, and an output layer.

[0014] After each data participant receives the initial data processing model, it inputs its respective original data into the input layer of the initial data processing model. Then, the input layer converts the original data of each data participant into the same data format through a data standardization algorithm and sends the converted original data to the processing layer.

[0015] Each data participant selects the required data processing algorithm to calculate the converted original data and outputs the same number of operation correction parameters at the output layer.

[0016] Further, the process of establishing a correction parameter matrix based on the operation correction parameter includes:

[0017] Each data participant integrates all the operation correction parameters to generate a parameter data packet, marks the corresponding number, and sends it to the shared cloud platform.

[0018] When the shared cloud platform determines that it has received the parameter data packets from all data participants, it extracts the operation correction parameters from each parameter data packet and establishes a correction parameter matrix K. The correction parameter matrix K can be expressed as:

[0019] where t i,a and m i,a represent the number S iThe a-th characteristic operation correction parameter and the target operation correction parameter of the data participant, K i Indicates the correction parameter matrix of the data participant numbered S i where a is a natural number greater than 0, and i is less than or equal to n.

[0020] Furthermore, the process of obtaining the total matching degree between each correction parameter matrix according to the correction parameter matrix includes:

[0021] Overlap-map each correction parameter matrix, and count the matching degree between each correction parameter matrix. Then, obtain the total matching degree according to the matching degree between each correction parameter matrix. The formula for the total matching is:

[0022]

[0023] where P i Indicates the total matching degree of the correction parameter matrix numbered K i , N = n - 1, M j,i and T j,i respectively represent the target matching degree and the characteristic matching degree between the correction parameter matrices numbered K j , K i .

[0024] Furthermore, the process of setting the permission level for the data participant according to the total matching degree includes:

[0025] Set a permission level pool with a fixed number of levels. At the same time, add up the total matching degrees of each correction parameter matrix, and then obtain the matching proportion p of each correction parameter matrix. The formula for the matching proportion p is:

[0026] Arrange the matching proportions of each correction parameter matrix from high to low in sequence. Then, starting from the correction parameter matrix with a high matching proportion, calculate the expected permission level G of each data participant, where

[0027] According to the expected permission level G of each data participant, the permission level pool assigns the same numerical permission level to the corresponding data participant from high to low in sequence. Whenever a data participant obtains a permission level from the permission level pool, the permission level pool subtracts the corresponding level. When the remaining levels in the permission level pool are less than the expected permission level G, the permission level pool assigns all the remaining levels to the corresponding data participant.

[0028] Furthermore, the generation process of the public access permission sub-key includes:

[0029] Each data participant generates its own access rights key and marks it with a corresponding number. When the shared cloud platform determines that it has received the access rights keys of all data participants, it concatenates the access rights keys in sequence according to the numbers attached to the access rights keys to obtain a public access rights key.

[0030] The public access permission key is divided into several public access permission sub-keys of equal size from left to right, and then the public access permission sub-keys are randomly distributed to each data participant. According to the division order of the public access permission sub-keys and the corresponding numbers of the receiving data participants, a key splicing sequence is generated.

[0031] Furthermore, the process of granting access authorization to the data participant includes:

[0032] Set a permission level threshold, and compare the permission level of each data participant with the permission level threshold, and then select data participants whose permission level is greater than or equal to the permission level threshold, and mark them as management data participants;

[0033] Splitting the key concatenation sequence into key concatenation subsequences of the same number as the management data participants, and then sending the key concatenation subsequences to each management data participant;

[0034] When any data participant sends a data access request to the shared cloud platform, the shared cloud platform sends the data access request to other data participants, where the data access request includes the number of the data participant it wishes to access;

[0035] When more than half of the data participants approve the data access request, the data access request is considered to be approved and the corresponding data participants are granted access rights; otherwise, the data access request is rejected.

[0036] Furthermore, after the data participants obtain access rights, each data participant uploads the public access rights subkey in its custody to the shared cloud platform;

[0037] According to the number of the data participant who sends the data access request and the number of the data participant that the data participant expects to access, the modified parameter matrices of both parties are overlapped and mapped, and the target parameter set and the characteristic parameter set are generated according to the overlapped parts of the two.

[0038] The shared cloud platform sends the target parameter set and the characteristic parameter set to the data participant who wishes to access the data in the data access request, and then retrieves the corresponding part from the original data according to the target parameter set and the characteristic parameters to generate access data;

[0039] Meanwhile, the shared cloud platform obtains the key splicing subsequences from each management data participant, generates a key splicing sequence based on the key splicing subsequences, and then splices the public access permission sub-keys according to the key splicing sequence to obtain the public access permission key;

[0040] Randomly select several access permission keys from the public access permission key, and then encrypt the access data through the selected access permission keys and generate corresponding decryption keys;

[0041] The shared cloud platform sends the decryption key and the access data to the corresponding data participants. After the data participants decrypt the access data according to the decryption key, they input the decrypted access data into their unique data processing model to obtain the data they need.

[0042] Compared with the prior art, the beneficial effects of the present invention are:

[0043] 1. In the present invention, by setting the same initial data processing model for each data participant, each data participant inputs its own original data into the initial data processing model for training to generate operation correction parameters. Meanwhile, the shared cloud platform generates corresponding correction parameter matrices according to the operation correction parameters of each data participant. The shared cloud platform overlaps and maps each correction parameter matrix with each other to obtain the total matching degree between each correction parameter matrix, and then sets the permission levels for the data participants corresponding to each correction parameter matrix according to the total matching degree, determines the data correlation between each data participant according to the correction parameters, and at the same time sets the corresponding permission levels for each data participant according to the data correlation, simplifying the management process of permission levels;

[0044] 2. In the present invention, each data participant uploads its own access permission key to the shared cloud platform. Then the shared cloud platform aggregates all the access permission keys to generate a public access permission key, divides the public access permission key into several public access permission sub-keys, randomly sends the public access permission sub-keys to each data participant, and at the same time generates a key splicing sequence according to the sending order, splits the key splicing sequence into several key splicing subsequences and sends them to the data participants with higher permission levels. When the shared cloud platform receives a data access request from any data participant, multiple data participants review the data access request, and grant the corresponding data access permission to the data participant according to the review result, thereby reducing the direct communication between each data participant and effectively ensuring the data privacy of the data participants. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required in the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other accompanying drawings can also be obtained based on these drawings.

[0046] Figure 1 It is the method flow chart of the present invention. Detailed implementation manners

[0047] To make the objectives, technical solutions, and advantages of the present invention clearer, the following will describe the technical solutions of the present invention in detail. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other implementation manners obtained by those of ordinary skill in the art without creative efforts belong to the scope protected by the present invention.

[0048] As Figure 1 shown, a multi-party data access authorization method based on federated learning includes the following steps:

[0049] Step 1: Set up a shared cloud platform, set the same initial data processing model for each data participant. Each data participant inputs its own original data into the initial data processing model for training to generate operation correction parameters. At the same time, the shared cloud platform generates a corresponding correction parameter matrix according to the operation correction parameters of each data participant;

[0050] Specifically, set up a shared cloud platform, and then the shared cloud platform numbers each data participant as S1, S2,..., S n , where n is a natural number greater than 0, and n represents the total number of data participants;

[0051] The shared cloud platform simultaneously sends the preset initial data processing model to each data participant. The initial data processing model consists of an input layer, a processing layer, and an output layer;

[0052] It should be noted that the input layer is preset with various data standardization algorithms for integrating the original data of each data participant into the same data format. The processing layer is preset with various data processing algorithms, such as linear regression algorithms, etc. The output layer is preset with the same data standardization algorithms as the input layer to ensure that the data formats of the original data processing results of each data participant are the same;

[0053] After each data participant receives the initial data processing model, they input their respective original data into the input layer of the initial data processing model. Subsequently, the input layer converts the original data of each data participant into the same data format through a data normalization algorithm and sends the converted original data to the processing layer;

[0054] Each data participant selects the required data processing algorithm to calculate the converted original data and outputs the same number of operation correction parameters in the output layer;

[0055] It should be noted that the operation correction parameters are divided into feature operation correction parameters and target operation correction parameters. Among them, the feature operation correction parameters are generated based on the data features of the original data, and the target operation correction parameters are generated based on the data targets of the original data. For example, if the original data of a data participant is bank business data, then the data features of the original data are loan types and deposit types, and the target features are deposit groups or loan groups;

[0056] Each data participant corrects the initial data processing model according to the operation correction parameters, and then generates their own unique data processing model;

[0057] Each data participant integrates all the operation correction parameters to generate a parameter data packet, marks the corresponding number, and sends it to the shared cloud platform;

[0058] When the shared cloud platform determines that it has received the parameter data packets of all data participants, it extracts the operation correction parameters from each parameter data packet and establishes a correction parameter matrix K. The correction parameter matrix K can be expressed as:

[0059] where t i,a and m i,a represent the a-th feature operation correction parameter and target operation correction parameter of the data participant numbered S, and i, a are natural numbers greater than 0, and i is less than or equal to n.

[0060] Step 2, the shared cloud platform overlaps and maps each correction parameter matrix with each other, and then obtains the total matching degree between each correction parameter matrix. Then, according to the total matching degree, it sets the permission levels for the data participants corresponding to each correction parameter matrix;

[0061] Specifically, the shared cloud platform overlaps and maps the correction parameter matrix numbered K1 with other correction parameter matrices in turn, and counts the matching degree between the correction parameter matrix numbered K1 and other correction parameter matrices;

[0062] It should be noted that during the process of overlapping and mapping each correction parameter matrix, the feature operation correction parameters and target operation correction parameters are overlapped and mapped separately;

[0063] Obtain the total matching degree based on the matching degree between the correction parameter matrix numbered K1 and other correction parameter matrices;

[0064] The process of obtaining the total matching degree of the corresponding correction parameter matrix according to the matching degree includes:

[0065] Calculate the total matching degree according to the matching degree between the correction parameter matrix and other correction parameter matrices, where the calculation formula for the total matching is:

[0066]

[0067] Where P i represents the total matching degree of the correction parameter matrix numbered K i , N = n - 1, M j,i and T j,i respectively represent the target matching degree and the feature matching degree between the correction parameter matrices numbered K j , K i ;

[0068] Obtain the total matching degree of all correction parameter matrices using the same method, and then set the permission levels for the corresponding data participants according to the total matching degree of each correction parameter matrix;

[0069] The process of setting the permission levels for the data participants according to the total matching degree includes:

[0070] Set a permission level pool with a total of 100 levels. At the same time, add up the total matching degrees of each correction parameter matrix, and then obtain the matching proportion p of each correction parameter matrix. The calculation formula for the matching proportion p is:

[0071] Arrange the matching proportions of each correction parameter matrix in descending order, and then start from the correction parameter matrix with the highest matching proportion to calculate the expected permission level G of each data participant. Where

[0072] According to the expected permission level G of each data participant, the permission level pool assigns the same numerical permission level to the corresponding data participant in descending order. Whenever a data participant obtains a permission level from the permission level pool, the permission level pool subtracts the corresponding level. When the remaining levels in the permission level pool are less than the expected permission level G, the permission level pool assigns all the remaining levels to the corresponding data participant.

[0073] Step 3: Each data participant uploads their respective access permission keys to the shared cloud platform. Then, the shared cloud platform aggregates all the access permission keys to generate a public access permission key, divides the public access permission key into several public access permission sub-keys, randomly sends the public access permission sub-keys to each data participant, and generates a key splicing sequence according to the sending order.

[0074] Specifically, each data participant generates their respective access permission keys and marks corresponding numbers, and then sends the access permission keys to the shared cloud computing platform.

[0075] The shared cloud platform counts the access permission keys with numbers and then determines whether it has received the access permission keys of all data participants.

[0076] When the shared cloud platform determines that it has received the access permission keys of all data participants, according to the numbers carried by each access permission key, it splices each access permission key in sequence to obtain a public access permission key.

[0077] The public access permission key is divided into 100 equal-sized public access permission sub-keys from left to right, and then the public access permission sub-keys are randomly distributed to each data participant. According to the division order of the public access permission sub-keys and the numbers of the corresponding receiving data participants, a key splicing sequence is generated.

[0078] Step 4: The key splicing sequence is split into several key splicing sub-sequences and sent to the data participants with a higher permission level. When the shared cloud platform receives a data access request from any data participant, multiple data participants review the data access request and grant corresponding data access permissions to the data participants according to the review results.

[0079] Specifically, a permission level threshold is set, and the permission levels of each data participant are compared with the permission level threshold. Then, the data participants with a permission level greater than or equal to the permission level threshold are selected and marked as management data participants.

[0080] The key splicing sequence is split into the same number of key splicing sub-sequences as the management data participants, and then the key splicing sub-sequences are sent to each management data participant.

[0081] It should be noted that after the shared cloud platform sends the key splicing sub-sequences to each management data participant, the shared cloud platform automatically deletes the generation records of the public access permission sub-keys and the key splicing sub-sequences.

[0082] After any data participant sends a data access request to the shared cloud platform, the shared cloud platform sends the data access request to other data participants, where the data access request includes the number of the data participant it expects to access;

[0083] When more than half of the data participants pass the data access request, it is determined that the data access request is approved, and the corresponding data participants are granted access rights. Otherwise, the data access request is rejected, and at the same time, each data participant uploads the public access right sub-key it holds to the shared cloud platform;

[0084] According to the number of the data participant sending the data access request and the number of the data participant it expects to access, the shared cloud platform retrieves the corresponding correction parameter matrix, overlaps and maps the correction parameter matrices of both parties, and generates a target parameter set and a feature parameter set based on the overlapping part of the two;

[0085] The shared cloud platform sends the target parameter set and the feature parameter set to the data participant expected to be accessed in the data access request. Then, based on the target parameter set and the feature parameters, it retrieves the corresponding part from the original data to generate access data and uploads it to the shared cloud platform;

[0086] At the same time, the shared cloud platform obtains the key splicing sub-sequence from each management data participant, generates a key splicing sequence based on the key splicing sub-sequence, and then splices the public access right sub-keys according to the key splicing sequence to obtain the public access right key;

[0087] Randomly select several access right keys from the public access right key, and then encrypt the access data with the selected access right keys and generate the corresponding decryption keys;

[0088] The shared cloud platform sends the decryption key and the access data to the corresponding data participant. After the data participant decrypts the access data with the decryption key, it inputs the decrypted access data into its unique data processing model to obtain the data it needs.

[0089] The above embodiments are only used to illustrate the technical method of the present invention and not to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical method of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical method of the present invention.

Claims

1. A multi-party data access authorization method based on federated learning, characterized in that, It includes the following steps: Step 1: Set up a shared cloud platform and set the same initial data processing model for each data participant. Each data participant inputs its own original data into the initial data processing model for training to generate operation correction parameters. At the same time, the shared cloud platform generates a corresponding correction parameter matrix based on the operation correction parameters of each data participant; Step 2: Overlap and map each correction parameter matrix to obtain the total matching degree between each correction parameter matrix, and set the permission level for the data participants corresponding to each correction parameter matrix according to the total matching degree; Step 3: Each data participant uploads its own access permission key to the shared cloud platform. Then the shared cloud platform aggregates all access permission keys to generate a public access permission key, divides the public access permission key into several public access permission sub-keys, randomly sends the public access permission sub-keys to each data participant, and generates a key splicing sequence according to the sending order; Step 4: Split the key splicing sequence into several key splicing sub-sequences and send them to the data participants with a higher permission level. When the shared cloud platform receives a data access request from any data participant, multiple data participants review the data access request, and grant the corresponding data participant data access permission according to the review result.

2. The multi-party data access authorization method based on federated learning according to claim 1, characterized in that The generation process of the operation correction parameters includes: Set up a shared cloud platform, and then the shared cloud platform assigns numbers S1, S2, ……, S to each data participant n , where n is a natural number greater than 0; The shared cloud platform sends the preset initial data processing model to each data participant at the same time. The initial data processing model consists of an input layer, a processing layer, and an output layer; After each data participant receives the initial data processing model, it inputs its own original data into the input layer of the initial data processing model. Then the input layer converts the original data of each data participant into the same data format through a data standardization algorithm, and sends the converted original data to the processing layer; Each data participant selects the required data processing algorithm to calculate the converted original data, and outputs the same number of operation correction parameters at the output layer.

3. The multi-party data access authorization method based on federated learning according to claim 2, wherein, The process of establishing a correction parameter matrix according to the operation correction parameters includes: Each data participant integrates all operation correction parameters to generate a parameter data packet, marks the corresponding number, and sends it to the shared cloud platform; After the shared cloud platform determines that parameter data packets from all data participants have been received, it extracts operation correction parameters from each parameter data packet and establishes a correction parameter matrix K, where the correction parameter matrix K is expressed as: where t i,a and m i,a represent the a-th characteristic operation correction parameter and the target operation correction parameter of the data participant numbered S i , K i represents the correction parameter matrix of the data participant numbered S i , a is a natural number greater than 0, and i is less than or equal to n.

4. A method for multi-party data access authorization based on federated learning according to claim 3, characterized in that The process of obtaining the total matching degree between each correction parameter matrix according to the correction parameter matrix includes: Overlap and map each correction parameter matrix, and count the matching degree between each correction parameter matrix. Then obtain the total matching degree according to the matching degree between each correction parameter matrix. The formula for total matching is: Where P i represents the total matching degree of the correction parameter matrix numbered K i , N = n - 1, M j,i and T j,i respectively represent the target matching degree and the feature matching degree between the correction parameter matrices numbered K j , K i .

5. The multi-party data access authorization method based on federated learning according to claim 4, wherein The process of setting the permission level for data participants according to the total matching degree includes: Set up a permission level pool with a fixed number of levels, and at the same time add up the total matching degrees of each correction parameter matrix to obtain the matching proportion p of each correction parameter matrix. The calculation formula of the matching proportion p is as follows: Arrange the matching ratios of each correction parameter matrix in descending order, and then start from the correction parameter matrix with a high matching ratio to calculate the expected permission level G of each data participant, where According to the expected permission level G of each data participant, the permission level pool assigns the same numerical permission level to the corresponding data participant in order from high to low. Whenever a data participant obtains a permission level from the permission level pool, the permission level pool subtracts the corresponding level. When the remaining level in the permission level pool is less than the expected permission level G, the permission level pool assigns all the remaining levels to the corresponding data participant.

6. The multi-party data access authorization method based on federated learning according to claim 5, characterized in that, The generation process of the public access permission sub-key includes: Each data participant generates its own access rights key and marks it with a corresponding number. When the shared cloud platform determines that it has received the access rights keys of all data participants, it concatenates the access rights keys in sequence according to the numbers attached to the access rights keys to obtain a public access rights key. The public access permission key is divided into several public access permission sub-keys of equal size, and the public access permission sub-keys are randomly distributed to each data participant. A key splicing sequence is generated according to the division order of the public access permission sub-keys and the numbers of the corresponding receiving data participants.

7. A multi-party data access authorization method based on federated learning according to claim 6, characterized in that, The process of granting access authorization to the data participant includes: Set a permission level threshold, and compare the permission level of each data participant with the permission level threshold, select data participants whose permission level is greater than or equal to the permission level threshold, and mark them as management data participants; Splitting the key concatenation sequence into key concatenation subsequences of the same number as the management data participants, and then sending the key concatenation subsequences to each management data participant; When any data participant sends a data access request to the shared cloud platform, the shared cloud platform sends the data access request to other data participants, where the data access request includes the number of the data participant it wishes to access; When more than half of the data participants approve the data access request, the data access request is deemed approved and the corresponding data participants are granted access rights; otherwise, the data access request is rejected.

8. A multi-party data access authorization method based on federated learning according to claim 7, characterized in that After the data participants obtain access rights, each data participant uploads the public access rights subkey that it keeps to the shared cloud platform; According to the number of the data participant who sends the data access request and the number of the data participant that the data participant expects to access, the modified parameter matrices of both parties are overlapped and mapped, and the target parameter set and the characteristic parameter set are generated according to the overlapped parts of the two. The shared cloud platform sends the target parameter set and the characteristic parameter set to the data participant who wishes to access the data in the data access request, and then it retrieves the corresponding part from the original data according to the target parameter set and the characteristic parameters to generate access data; At the same time, the shared cloud platform obtains the key splicing subsequence from each data management participant, generates a key splicing sequence based on the key splicing subsequence, and then splices the public access permission subkey based on the key splicing sequence to obtain the public access permission key; Randomly select a number of access rights keys from the public access rights keys, and then encrypt the access data using the selected access rights keys and generate corresponding decryption keys; The shared cloud platform sends the decryption key and access data to the corresponding data participant. After the data participant decrypts the access data according to the decryption key, it inputs the decrypted access data into its unique data processing model to obtain the data it needs.

Citation Information

Patent Citations

  • Authority management method, system and device applied to federated learning and electronic equipment

    CN114329611A

  • Gene data privacy domain dynamic prevention and control system and method based on adaptive mechanism

    CN115391841A

  • Multi-private-domain visitor portrait sharing and privacy protection routing method based on federal learning

    CN119383014A

  • Data sharing method and apparatus, and digital gateway and computer-readable storage medium

    WO2020098336A1

Cited By

  • Federal learning-based data privacy enhancement protection method and system

    CN121093383A