Privacy calculation-based privacy data security exchange control method

Through the privacy computing method, the privacy data of the sender is preprocessed and classified into sensitivity levels, and data desensitization and encryption strategies are applied. Combined with the determination of difference rate and null value rate, adjustment instructions are generated to optimize the data interaction process, solving the problems of low efficiency and privacy leakage in data exchange, and realizing safe and efficient data exchange.

CN120614213AActive Publication Date: 2025-09-09GUANGDONG JUNLUE TECH CONSULTING CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202511113756.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-11
Publication Date
2025-09-09
Estimated Expiration
2045-08-11

AI Technical Summary

Technical Problem

The data exchange process in the existing technology lacks analysis and verification, resulting in low efficiency in obtaining qualified data to be exchanged, the risk of privacy leakage, and low exchange efficiency.

Method used

Through a privacy-based computing method, the privacy data of the sender is obtained for preprocessing and sensitivity level classification, and data desensitization and encryption strategies are applied. Combined with the determination of difference rate and null value rate, instructions for adjusting field masking ratio, data statistics or cleaning interval are generated to optimize the data interaction process.

Benefits of technology

It improves the efficiency of obtaining complete privacy data, ensures the security and accuracy of the data exchange process, reduces the risk of privacy data leakage, and improves the efficiency of data exchange.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120614213A_ABST
    Figure CN120614213A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of information security, in particular to a privacy calculation-based privacy data security exchange control method, which comprises the following steps of: obtaining privacy data in a sending end, processing according to a sensitivity level to obtain sensitive data, desensitizing the sensitive data to obtain desensitized data, and sending the desensitized data to a server; carrying out encryption processing on the desensitized data to obtain encrypted data; the encrypted data and the corresponding public key are transmitted to a receiving end, and the receiving end triggers an intelligent contract according to the authority to start a private key corresponding to the public key for decryption processing to obtain target data; respectively counting data volumes corresponding to the privacy data and the target data, processing to obtain a difference rate and a null value rate, judging whether a data interaction process is qualified based on the difference rate, further judging the interaction process based on a judgment result in combination with the null value rate, further determining a corresponding reason, generating an instruction based on the reason, and displaying the instruction. And corresponding parameters in the data interaction process are adjusted based on the instruction, so that the data interaction process is optimized, and the efficiency of obtaining qualified private data is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a privacy data security exchange control method based on privacy computing. Background Art

[0002] As society's digital transformation accelerates, the demand for cross-departmental data sharing is surging. However, traditional data exchange models carry the risk of privacy breaches, primarily stemming from the conflict between data sharing and data protection objectives. Typically, private data contains various proprietary information held by individual companies or departments. This type of data requires data privacy processing before it can be exchanged with other departments or companies. However, this exchange process presents security risks, resulting in low efficiency in successful data exchange. Therefore, improving the efficiency of private data exchange during data sharing is an urgent issue.

[0003] Chinese patent application publication number CN115664799B discloses a data exchange method and system for information technology security. The method comprises obtaining data to be exchanged from a first client and dividing it into first private data and second private data; encrypting the first private data using a first encryption rule to obtain first encrypted data; encrypting the second private data using a second encryption rule to obtain second encrypted data; and sending the first encrypted data and the second encrypted data to a second client to implement data exchange. While this method achieves privacy and computational efficiency during data exchange, it only addresses the encryption of the data to be exchanged. Because the process of obtaining the data to be exchanged lacks analysis and verification, the data to be exchanged may be unqualified during the data exchange process, resulting in low efficiency in obtaining qualified data to be exchanged. Summary of the Invention

[0004] To this end, the present invention provides a privacy data secure exchange control method based on privacy computing to solve the problem in the prior art that the data lacks analysis, verification and adjustment during the interaction process, resulting in low efficiency in obtaining qualified data to be exchanged.

[0005] To achieve the above objectives, the present invention provides a method for controlling the secure exchange of private data based on privacy computing, comprising: Obtaining a number of private data that needs to be exchanged at the sending end, performing pre-processing, and dividing the data according to sensitivity levels to obtain a number of sensitive data; Determining a corresponding data desensitization strategy according to the sensitivity level and processing a number of the sensitive data to obtain corresponding desensitized data; Determining a corresponding encryption strategy according to the data desensitization strategy and processing a number of the desensitized data to obtain corresponding encrypted data; Transmitting the obtained encrypted data and corresponding public keys to a receiving end; Triggering a smart contract according to the authority of the receiving end to determine to enable a private key corresponding to the public key to perform decryption processing to obtain target data; Counting the data volume of the private data and the corresponding data volume of the target data and processing them to obtain a difference rate and a null value rate; Determining whether the data interaction process is qualified based on the difference rate, and determining whether the process is qualified based on the determination result combined with the null value rate, or determining the reason for failure based on the difference rate, and generating corresponding instructions based on the reason, the instructions are to determine the field masking ratio in the data desensitization process, or the data statistics in the privacy data and the corresponding target data, or the data cleaning interval in the preprocessing process; The field masking ratio, the data statistics, or the data cleaning interval is adjusted based on the instruction.

[0006] Furthermore, the process of determining whether the data interaction process is qualified includes: Determining whether the data interaction process is qualified based on a comparison result of the difference rate and a preset difference rate, and determining whether the data interaction process is qualified based on the comparison result of the determination and a comparison result of the null value rate offset and a critical null value rate offset; When the data interaction process is determined to be unqualified, determining the cause according to the difference between the difference rate and the preset difference rate; The null value rate offset is the difference between the null value rate of the target data and the null value rate of the privacy data.

[0007] Furthermore, the process of determining whether the data interaction process is qualified based on the comparison result of the null rate offset and the critical null rate offset includes: Based on a comparison result of the null rate offset and the critical null rate offset, it is determined whether to reduce the field masking ratio.

[0008] Furthermore, the process of determining whether to reduce the field masking ratio includes: When it is determined that the null rate offset is greater than the critical null rate offset, determining to reduce the field masking ratio; Calculating a difference between the void rate offset and the critical void rate offset and recording the difference as the offset difference; Based on the comparison result of the offset difference and the preset offset difference, a corresponding instruction is generated to reduce the field masking ratio, and the reduction amplitude of the field masking ratio is positively correlated with the offset difference.

[0009] Furthermore, the process of determining whether to reduce the field masking ratio further includes: When it is determined that the null rate offset is greater than the critical null rate offset, determining to reduce the field masking ratio; The sensitivity level of the sensitive data is determined, and corresponding instructions are generated based on the division of the sensitivity levels to reduce the field masking ratio, wherein the reduction extent of the field masking ratio is negatively correlated with the sensitivity level.

[0010] Furthermore, the process of determining the cause according to the difference between the difference rate and the preset difference rate includes: Calculating the difference between the difference rate and the preset difference rate and recording it as a difference deviation value; Determining the reason why the data interaction process fails based on a comparison result of the difference deviation value and a preset difference deviation value; A corresponding instruction is generated based on the reason to determine increasing the data statistics or adjusting the data cleaning interval.

[0011] Further, the preset difference deviation value includes a first preset difference deviation value, and when it is determined that the difference deviation value is less than or equal to the first preset difference deviation value, it is determined to increase the data statistic; Calculating the difference between the first preset difference deviation value and the difference deviation value and recording it as the deviation difference; Based on a comparison result of the deviation difference and a preset deviation difference, a corresponding instruction is generated to increase the data statistic, and an increase amplitude of the data statistic is negatively correlated with the deviation difference.

[0012] Furthermore, the preset difference deviation value further includes a second preset difference deviation value, and when it is determined that the difference deviation value is greater than the first preset difference deviation value and less than or equal to the second preset difference deviation value, it is determined to adjust the data cleaning interval; Counting the number of target data whose difference rate is greater than the preset difference rate during the current transmission process and recording the number of abnormal data, and counting the number of abnormal data during the historical transmission process, and performing variance calculation based on the number of abnormal data to obtain the abnormal data variance; Based on the comparison result of the abnormal data variance and the critical abnormal data variance, it is determined whether to expand the data cleaning interval or to reduce the data cleaning interval.

[0013] Further, when it is determined that the abnormal data variance is less than or equal to the critical abnormal data variance, it is determined to expand the data cleaning interval; Calculate the ratio of the number of abnormal data to the total number of target data and record it as the abnormality ratio; Based on the comparison result of the abnormality ratio and the preset abnormality ratio, a corresponding instruction is generated to expand the data cleaning interval, and the expansion range of the data cleaning interval is positively correlated with the abnormality ratio.

[0014] Further, when it is determined that the abnormal data variance is greater than the critical abnormal data variance, it is determined to reduce the data cleaning interval; Calculate the difference between the abnormal data variance and the critical abnormal data variance and record it as the variance difference; Based on a comparison result between the variance difference value and a preset variance difference value, a corresponding instruction is generated to reduce the data cleaning interval, and the reduction extent of the data cleaning interval is positively correlated with the variance difference value.

[0015] Compared with the prior art, the privacy data secure exchange control method based on privacy computing of the present invention has the beneficial effect that the method obtains the privacy data that the sending end needs to interact with and processes it according to the sensitivity level to obtain sensitive data, desensitizes the sensitive data to obtain desensitized data, and then encrypts the desensitized data to obtain encrypted data; transmits the encrypted data and the corresponding public key to the receiving end, and the receiving end triggers the smart contract according to the authority to determine to enable the private key corresponding to the public key to perform decryption processing to obtain the target data; counts the data volume corresponding to the privacy data and the target data respectively and processes them to obtain the difference rate and the null value rate, determines whether the data interaction process is qualified based on the difference rate, and further determines the status of the data interaction process based on the determination result combined with the null value rate, and then determines the corresponding cause, generates an instruction based on the cause, and adjusts the field masking ratio, or data statistics, or data cleaning interval in the data interaction process based on the instruction, thereby optimizing the data interaction process to improve the efficiency of obtaining qualified privacy data.

[0016] Furthermore, the present invention also determines the reduction of the field masking ratio based on the comparison result of the null value rate offset and the preset null value rate offset, and determines the reduction amplitude of the field masking ratio based on the comparison result of the offset difference and the preset offset difference, so as to achieve accurate adjustment of the field masking ratio of the data when desensitizing, thereby improving the efficiency of obtaining complete privacy data.

[0017] Furthermore, the present invention also determines the reduction extent of the field masking ratio according to the sensitivity level of sensitive data, and adjusts the field masking ratio in the desensitization process according to the classification to achieve precise masking, thereby improving the efficiency of obtaining complete privacy data.

[0018] Furthermore, the present invention can also determine the reason why the data interaction process is unqualified based on the comparison result of the difference deviation value and the preset difference deviation value, and then determine the corresponding processing based on the reason, including: increasing data statistics or dynamically adjusting the data cleaning interval, so as to improve the pass rate of the data interaction process in a targeted manner, so as to improve the efficiency of obtaining complete privacy data.

[0019] Furthermore, when determining that the data statistics need to be increased, the present invention can compare the deviation difference with the preset deviation difference to determine the increase in the data statistics, and then accurately increase the data statistics amplitude to reduce the difference rate, thereby improving the pass rate of the data interaction process and improving the efficiency of obtaining complete privacy data.

[0020] Furthermore, when determining that the data cleaning interval needs to be dynamically adjusted, the present invention can determine whether to expand the data cleaning interval or reduce the data cleaning interval based on the comparison result of the abnormal data variance and the critical abnormal data variance; when determining that the data cleaning interval needs to be expanded, the expansion range of the data cleaning interval is determined based on the comparison result of the abnormal proportion and the preset abnormal proportion, so as to accurately adjust the data cleaning interval in the data preprocessing process, thereby ensuring data consistency; when determining that the data cleaning interval needs to be reduced, the reduction range of the data cleaning interval is determined based on the comparison result of the variance difference and the preset variance difference, so as to accurately adjust the data cleaning interval in the data preprocessing process, thereby avoiding process processing; the above two adjustment methods for the data cleaning interval can both improve the pass rate of the data interaction process, thereby improving the efficiency of obtaining complete privacy data. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 This is a module diagram of the privacy data secure exchange control system based on privacy computing in the present invention; Figure 2 Schematic diagram of the flow of the privacy data secure exchange control method based on privacy computing in the present invention; Figure 3 A logical decision diagram for determining whether a data interaction process is qualified and corresponding processing based on the difference rate in the present invention; Figure 4 This is a logic decision diagram for determining the reasons for the failure of the data interaction process based on the difference deviation value and the corresponding processing in the present invention. DETAILED DESCRIPTION

[0022] In order to make the objects and advantages of the present invention more clearly understood, the present invention is further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are merely used to explain the present invention and are not intended to limit the present invention.

[0023] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood by those skilled in the art that these embodiments are only used to explain the technical principles of the present invention and are not intended to limit the scope of protection of the present invention.

[0024] It should be noted that, in the description of the present invention, unless otherwise expressly specified or limited, the term "connection" should be understood in a broad sense. For example, it can mean a fixed connection, a detachable connection, or an integral connection; it can mean a mechanical connection or an electrical connection; it can mean a direct connection or an indirect connection through an intermediate medium; it can mean internal communication between two components. Those skilled in the art will understand the specific meanings of the above terms in the present invention based on specific circumstances.

[0025] Privacy computing refers to a collection of technologies that implement data analysis and calculations while protecting the data itself from external leakage. Its core goal is to achieve "available but invisible" data. Privacy computing uses encryption technology to ensure that data is not leaked during the calculation process, while allowing specific computing operations to be performed in an encrypted state, and ultimately obtaining the correct results through decryption.

[0026] See also Figure 1As shown, it is a module schematic diagram of the privacy data secure exchange control system based on privacy computing in this embodiment. The system includes a sending end, a receiving end, a data acquisition module, a data desensitization module, a data encryption module, a data transmission module, a data decryption module, a statistics module, an analysis module, and a control module. The data acquisition module is connected to the sending end to obtain a number of private data to be exchanged from the sending end for pre-processing, and to process the number of private data according to the sensitivity level to obtain corresponding sensitive data. The data desensitization module is connected to the data acquisition module to determine a corresponding data desensitization strategy based on the sensitivity level, and to process the number of sensitive data based on the data desensitization strategy to obtain corresponding desensitized data. The data encryption module is connected to the data desensitization module to determine a corresponding encryption strategy based on the data desensitization strategy, and to process the number of desensitized data based on the encryption strategy to obtain corresponding encrypted data. The data transmission module is connected to the data encryption module and the receiving end respectively to transmit the number of encrypted data and the corresponding public key to the receiving end. The data decryption module is connected to the receiving end and is used to trigger a smart contract based on the receiving end's permissions to determine the activation of the private key corresponding to the public key, and to perform decryption processing based on the private key to obtain target data, wherein a single target data corresponds to a single private data sent by the sending end. The statistics module is connected to the data acquisition module and the data decryption module respectively, and is used to count the data volume of the private data and the data volume of the corresponding target data, and process them to obtain a difference rate and a null value rate. The analysis module is connected to the statistics module and is used to determine whether the process of obtaining the target data is qualified based on the difference rate, and to determine whether the process is qualified based on the determination result and the null value rate, or to determine the reason for failure based on the difference rate, and generate corresponding instructions based on the reason, the instructions being to determine the field masking ratio in the data desensitization process, the data statistics between the private data and the corresponding target data, or the data cleaning interval in the preprocessing process. The control module is connected to the analysis module, the data acquisition module, the data desensitization module, and the statistics module respectively, and is used to adjust the field masking ratio, the data statistics, or the data cleaning interval based on the instructions.

[0027] See also Figure 2 , which is a flow chart of the method for controlling the secure exchange of private data based on privacy computing in this embodiment. The process includes at least the following steps: S1: Obtaining a number of private data to be exchanged at the sender, performing pre-processing, and classifying the data according to sensitivity levels to obtain a number of sensitive data; S2: Determine the corresponding data desensitization strategy according to the sensitivity level and process the sensitive data to obtain the corresponding desensitized data; S3: Determine a corresponding encryption strategy based on the data desensitization strategy and process the desensitized data to obtain corresponding encrypted data; S4: transmitting the obtained encrypted data and the corresponding public key to the receiving end; S5: triggering the smart contract based on the receiving end's permissions to enable the private key corresponding to the public key to perform decryption processing to obtain the target data; S6: Counting the amount of private data and the amount of corresponding target data and processing them to obtain a difference rate; S7: Determine whether the process of obtaining the target data is qualified based on the difference rate, and determine whether the process is qualified based on the determination result combined with the null value rate, or determine the reason for failure based on the difference rate, and generate corresponding instructions based on the reason. The instructions are to determine the field masking ratio in the data desensitization process, or the data statistics between the privacy data and the corresponding target data, or the data cleaning interval in the preprocessing process; S8: Adjust the field masking ratio, data statistics, or data cleaning interval based on the instruction.

[0028] Specifically, in this embodiment, the encryption strategy includes adopting a homomorphic encryption algorithm, generating a public-private key pair through the algorithm, the public key is used for data encryption, and the private key is used for result decryption. After sensitive data is input, the public key is called to execute the encryption function and output the ciphertext. The corresponding calculation can be directly performed in the encrypted state, and the ciphertext operation result is decrypted using the private key to verify the homomorphism of the calculation process; different homomorphic encryption algorithms are used for sensitive data of different sensitivity levels. For example, highly sensitive data uses fully homomorphic encryption (FHE) or an improved version of the national secret SM9, and medium and low sensitive data use Paillier additive homomorphic encryption or a modified version of SM2 elliptic curve encryption, etc. Data desensitization strategies include strong desensitization rules and basic desensitization rules, which directly process sensitive data through masking, replacement, or deformation techniques to reduce its identifiability. Among them, sensitivity levels include highly sensitive fields, generally sensitive fields, and non-sensitive fields. Differentiated strategies are formulated based on the sensitivity level of the data. For example, highly sensitive fields (such as financial data) require strong desensitization rules (such as full masking), while generally sensitive fields (such as occupational categories) and non-sensitive fields (such as public reports or administrative division codes) may only require basic processing (such as partial masking). Smart contracts automatically verify data integrity based on preset conditions and trigger the encrypted transmission process. End-to-end encryption operations can be completed without the intervention of a third party. The receiving user can obtain the corresponding private key based on the smart contract to match the corresponding public key for decryption, thereby realizing the "authorization verification → key release → data decryption" process. Difference rate = (|number of target-side records - number of source-side records| / number of source-side records) × 100%, where the number of target-side records refers to the amount of data in a single target data set, and the number of source-side records refers to the amount of data in a single private data set. When calculating the difference rate, the number of records counted can be part or all of the total amount of data. Null value rate = (number of field null values ​​ / total number of records) × 100%, with the null value rate on the target side corresponding to the receiving side and the null value rate on the source side corresponding to the sending side.

[0029] See also Figure 3 As shown, it is a logical decision diagram for determining whether a data interaction process is qualified based on the difference rate and the corresponding processing according to this embodiment. The process of determining whether a data interaction process is qualified includes: determining whether the data interaction process is qualified based on the comparison result of the difference rate and the preset difference rate, and determining whether the data interaction process is qualified based on the determination result combined with the comparison result of the null value rate offset and the critical null value rate offset; when the data interaction process is determined to be unqualified, determining the cause based on the difference between the difference rate and the preset difference rate; wherein the null value rate offset is the difference between the null value rate of the target data and the null value rate of the private data.

[0030] Specifically, in this embodiment, by analyzing historical data collected in the past and combining statistical methods with application scenarios to determine subsequent preset or critical parameter values. In order to more reliably judge the data interaction process and accurately adjust the corresponding parameters in the interaction process, the preset difference rate Q0 can be divided into a first preset difference rate Q1 and a second preset difference rate Q2, and a gradient analysis of the judgment process can be performed using a hierarchical design; when it is determined that the application scenario is for secure interaction of private data, Q1 = 0.9% and Q2 = 1.1%. The specific comparison process based on the difference rate Q with Q1 and Q2 is as follows: If Q is less than or equal to Q1, it is determined that the settings of Q1 and Q2 are accurate and that no other conditions occur by default in this solution. This indicates that the difference between the private data sent by the sender and the corresponding target data received by the receiver is within an acceptable range and has not reached a significant level. Therefore, the data exchange process can be determined to be qualified. If Q is greater than Q1 and less than or equal to Q2, it indicates that there are observable deviations in the data exchange process, but they have not yet reached the level of serious failure. In this case, further judgment can be made based on the judgment results, combining the null rate offset and the critical null rate offset. Based on the judgment results, appropriate processing is determined to optimize the data exchange process. Introducing new parameters can avoid relying on a single indicator and improve the accuracy of the judgment process. If Q is greater than Q2, it is determined that no other conditions occur by default. Based on the comparison between Q and Q0, the difference between the private data and the corresponding target data is relatively large and significant. Therefore, the data exchange process can be directly determined to be unqualified. The reason for the failure can be determined by the difference between Q and Q0, that is, the difference between Q and Q2.

[0031] Furthermore, the process of determining whether the data interaction process is qualified based on the comparison result of the null value rate offset and the critical null value rate offset includes: determining whether to reduce the field masking ratio based on the comparison result of the null value rate offset and the critical null value rate offset.

[0032] Specifically, in this embodiment, the null value ratio offset E is an absolute value and is used to measure the degree of change in the null value ratio of the target data relative to the private data. E = |target data null value ratio − private data null value ratio|. It should be noted that the critical null value ratio offset E0 is set differently for data of different sensitivity levels. For data with a general sensitive data field sensitivity level, E0 can be set to 2.3%. The specific comparison process based on the null value ratio offset E and E0 is as follows: If E is less than or equal to E0, this indicates that no abnormal interference or over-masking was introduced during data acquisition, complying with the core principle of privacy computing: "data available but invisible." At this point, E has no impact on the process of acquiring the target data and is not a key factor affecting the data interaction process. If Q is greater than Q1 and less than or equal to Q2, the current data interaction process can be determined to be unqualified, and the cause can be determined based on the difference between Q and Q2. If E is greater than E0, this indicates data tampering, over-anonymization, or a computing protocol violation, leading to an excessively large E. In this case, there are many abnormal missing values, causing Q to be greater than Q1 and less than or equal to Q2. In this case, the field masking ratio during the data masking process can be reduced. The field masking ratio is the ratio of the number of masked fields to the total number of fields. The above determinations are based solely on the comparison of E and E0 to determine the cause, and no other situations are considered by default.

[0033] Furthermore, the process of determining whether to reduce the field masking ratio includes: when it is determined that the null value rate offset is greater than the critical null value rate offset, determining to reduce the field masking ratio; calculating the difference between the null value rate offset and the critical null value rate offset and recording it as the offset difference; generating a corresponding instruction based on the comparison result of the offset difference and the preset offset difference to reduce the field masking ratio, and the reduction amplitude of the field masking ratio is positively correlated with the offset difference.

[0034] Specifically, in this embodiment, when it is determined that E is greater than E0, the preset offset difference Y0 can be divided into a first preset offset difference Y1 and a second preset offset difference Y2. The offset difference Y is compared with Y1 and Y2 to accurately determine the reduction in the field masking ratio. Y1=0.4%, Y2=0.8% can be set. The specific comparison process based on the offset difference Y with Y1 and Y2 is as follows: Taking the data sensitivity level of the general sensitive data field as an example, if Y is less than or equal to Y1, then the corresponding first adjustment masking ratio indicator is generated. The control data masking process is reduced by 5% on the basis of the original field masking ratio; if Y is greater than Y1 and less than or equal to Y2, then the control data masking process is determined to generate the corresponding second adjustment masking ratio instruction to reduce the original field masking ratio by 10%; if Y is greater than Y2, then the control data masking process is determined to generate the corresponding third adjustment masking ratio instruction to reduce the original field masking ratio by 18%, or directly trigger the manual review mechanism to avoid compliance risks caused by automatic adjustment. After the field masking ratio is reduced, the masked fields are rounded up. It should be noted that the reduction in the field masking ratio can also be set to other values ​​that meet the requirements. For example, when Y is less than or equal to Y1, it is set to reduce the original field masking ratio by 6%. The original field masking ratio has different original values ​​according to different application scenarios.

[0035] Furthermore, the process of determining whether to reduce the field masking ratio also includes: when it is determined that the null value rate offset is greater than the critical null value rate offset, determining to reduce the field masking ratio; determining the sensitivity level of the sensitive data, and generating corresponding instructions based on the division of the sensitivity level to reduce the field masking ratio, and the reduction amplitude of the field masking ratio is negatively correlated with the sensitivity level.

[0036] Specifically, in this embodiment, the field masking ratio can also be adjusted hierarchically according to the sensitivity level. If the data sensitivity level is a non-sensitive field, a corresponding fourth instruction for adjusting the masking ratio is generated, and the data desensitization process is controlled based on the instruction to reduce the original field masking ratio by 20%; if the data sensitivity level is a generally sensitive field, a corresponding fifth instruction for adjusting the masking ratio is generated, and the data desensitization process is controlled based on the instruction to reduce the original field masking ratio by 13%; if the data sensitivity level is a highly sensitive field, a corresponding sixth instruction for adjusting the masking ratio is generated, and the data desensitization process is controlled based on the instruction to reduce the original field masking ratio by 4%, or still maintain full masking. It should be noted that the reduction in the field masking ratio can also be set to other values ​​that meet the requirements. For example, when the data sensitivity level is determined to be a non-sensitive field, the original field masking ratio is reduced by 18%. After the field masking ratio is reduced, the masked fields are all rounded up. It can be understood that adjusting the field masking ratio according to the level is not the same as adjusting the field masking ratio based on the comparison of Y with Y1 and Y2, and the two do not conflict with each other.

[0037] See also Figure 4 The figure shows a logic decision diagram for determining the reason for data interaction failure based on the difference deviation value and the corresponding processing according to this embodiment. The process of determining the reason based on the difference between the difference rate and the preset difference rate includes: calculating the difference between the difference rate and the preset difference rate and recording it as the difference deviation value; determining the reason for the data interaction failure based on the comparison result of the difference deviation value and the preset difference deviation value; and generating a corresponding instruction based on the reason to determine whether to increase the data statistics or adjust the data cleaning interval.

[0038] Specifically, in this embodiment, the reason for failure is analyzed only by comparing the difference deviation value D with the preset difference deviation value D0. It is assumed that other situations will not occur. D0 can be divided into a first preset difference deviation value D1 and a second preset difference deviation value D2. By comparing D with D1 and D2, the reason for failure can be accurately determined. D1 can be set to 0.3% and D2 to 0.6%. The specific process based on the comparison of D with D1 and D2 is as follows: If D is less than or equal to D1, it can be determined that the data sampling method does not meet the statistical requirements, resulting in insufficient sample representativeness. It is necessary to increase the statistics of the data volume of the privacy data and the corresponding target data, that is, to increase the data statistics, in order to reprocess and analyze to determine the difference rate. It should be noted that the data statistics at this time are partial statistics of the total data volume. If D is greater than D1 and less than or equal to D2, it can be determined that the data cleaning rules are not strictly enforced, and there are unprocessed outliers or format errors. It is necessary to dynamically adjust the data cleaning interval to improve the cleaning efficiency and redetermine the difference rate. If D is greater than D2, it means that the current difference rate Q is much greater than the second preset difference rate Q2. At this time, the manual review mechanism is directly triggered to avoid compliance risks caused by automatic adjustments.

[0039] Furthermore, the preset difference deviation value includes a first preset difference deviation value. When it is determined that the difference deviation value is less than or equal to the first preset difference deviation value, it is determined to increase the data statistic; the difference between the first preset difference deviation value and the difference deviation value is calculated and recorded as the deviation difference; based on the comparison result of the deviation difference and the preset deviation difference, a corresponding instruction is generated to increase the data statistic, and the increase in the data statistic is negatively correlated with the deviation difference.

[0040] Specifically, in this embodiment, when D is less than or equal to D1, the larger the deviation difference N, the greater the difference between D and D1, that is, the smaller D, and therefore the smaller the difference rate Q, and the smaller the required increase in the data statistics. The preset deviation difference N0 can be divided into a first preset deviation difference N1 and a second preset deviation value N2. By comparing N with N1 and N2, the increase in the data statistics can be accurately determined. N1 can be set to 0.1% and N2 can be set to 0.15%. The specific comparison process based on N with N1 and N2 is as follows: when the data sensitivity level is a general sensitive field, if N is less than or equal to N1, an instruction to generate a corresponding first adjustment statistic is determined, and the statistical process is controlled to increase the original data statistics by 80%; if N is greater than N1 and less than or equal to N2, an instruction to generate a corresponding second adjustment statistic is determined, and the statistical process is controlled to increase the original data statistics by 70%; if N is greater than N2, an instruction to generate a corresponding third adjustment statistic is determined, and the statistical process is controlled to increase the original data statistics by 55%. It should be noted that the increase in the data statistics can also be set to other values ​​that meet the requirements. For example, when N is greater than N2, the increase is 60% based on the original data statistics.

[0041] Furthermore, the preset difference deviation value also includes a second preset difference deviation value. When it is determined that the difference deviation value is greater than the first preset difference deviation value and less than or equal to the second preset difference deviation value, the data cleaning interval is determined to be adjusted; the number of target data whose difference rate is greater than the preset difference rate in the current transmission process is counted and recorded as the number of abnormal data, and the number of abnormal data in the historical transmission process is counted, and the variance is calculated based on several numbers of abnormal data to obtain the abnormal data variance; based on the comparison result of the abnormal data variance and the critical abnormal data variance, it is determined to expand the data cleaning interval or shrink the data cleaning interval.

[0042] Specifically, in this embodiment, when N is greater than N1 and less than or equal to N2, it is necessary to re-determine whether to expand or reduce the data cleaning interval. The current number of abnormal data and several historical abnormal data numbers can be counted, and variance calculation can be performed based on this. The critical abnormal data variance M0 can be set to 5.05. The specific comparison process based on the abnormal data variance M and M0 is as follows: if M is less than or equal to M0, it indicates that the number of abnormal data fluctuates slightly and the data distribution is more concentrated, indicating that the abnormal data appears in multiple fields or time periods, and the data cleaning interval needs to be expanded to ensure data consistency; if M is greater than M0, it indicates that the number of abnormal data fluctuates greatly and the data distribution is more dispersed. When only specific target data has abnormalities, the data cleaning interval should be shortened to avoid over-processing.

[0043] Furthermore, when it is determined that the abnormal data variance is less than or equal to the critical abnormal data variance, it is determined to expand the data cleaning interval; the ratio of the number of abnormal data to the total number of target data is calculated and recorded as the abnormal proportion; based on the comparison result of the abnormal proportion with the preset abnormal proportion, a corresponding instruction is generated to expand the data cleaning interval, and the expansion extent of the data cleaning interval is positively correlated with the abnormal proportion.

[0044] Specifically, in this embodiment, the preset abnormality ratio P0 can be divided into a first preset abnormality ratio P1 and a second preset abnormality ratio P2. By comparing the abnormality ratio P with P1 and P2, the expansion range of the data cleaning interval can be accurately determined. P1 can be set to 5% and P2 can be set to 10%. The specific process based on the comparison of P with P1 and P2 is as follows: if P is less than or equal to P1, then the corresponding first adjustment cleaning interval instruction is generated, and the preprocessing process is controlled to expand by 10% based on the original data cleaning interval; if P is greater than P1 and less than or equal to P2, then the corresponding second adjustment cleaning interval instruction is generated, and the preprocessing process is controlled to expand by 20% based on the original data cleaning interval; if P is greater than P2, then the corresponding third adjustment cleaning interval instruction is generated, and the preprocessing process is controlled to expand by 40% based on the original data cleaning interval, or a full review mechanism is triggered to re-determine the cause of the abnormality. It should be noted that the expansion range of the data cleaning interval can also be set to other values ​​that meet the requirements. For example, when P is greater than P2, the data cleaning interval can be expanded by 50% based on the original data cleaning interval.

[0045] Furthermore, when it is determined that the abnormal data variance is greater than the critical abnormal data variance, it is determined to reduce the data cleaning interval; the difference between the abnormal data variance and the critical abnormal data variance is calculated and recorded as the variance difference; based on the comparison result of the variance difference and the preset variance difference, a corresponding instruction is generated to reduce the data cleaning interval, and the reduction extent of the data cleaning interval is positively correlated with the variance difference.

[0046] Specifically, in this embodiment, the preset variance difference K0 can be divided into a first preset variance difference K1 and a second preset variance difference K2. The reduction range of the data cleaning interval can be accurately determined by comparing the variance difference K with K1 and K2. K1=0.55 and K2=0.85 can be set. The specific process based on the comparison of K with K1 and K2 is as follows: if K is less than or equal to K1, an instruction for generating a corresponding fourth adjustment cleaning interval is determined, and the preprocessing process is controlled to be reduced by 8% on the basis of the original data cleaning interval; if K is greater than K1 and less than or equal to K2, an instruction for generating a corresponding fifth adjustment cleaning interval is determined, and the preprocessing process is controlled to be reduced by 15% on the basis of the original data cleaning interval; if K is greater than K2, an instruction for generating a corresponding sixth adjustment cleaning interval is determined, and the preprocessing process is controlled to be reduced by 30% on the basis of the original data cleaning interval, or a full review mechanism is triggered to re-determine the cause of the abnormality. It should be noted that the reduction range of the data cleaning interval can also be set to other values ​​that meet the requirements. For example, when K is less than or equal to K1, the data cleaning interval is reduced by 10% based on the original data cleaning interval.

[0047] Furthermore, the process of obtaining a number of sensitive data by dividing according to the sensitivity level includes: obtaining a sensitivity score corresponding to the privacy data, determining the sensitivity level based on the comparison result of the sensitivity score and the sensitivity threshold, and processing to obtain the corresponding sensitive data; wherein, the types of sensitive data include highly sensitive data, medium sensitive data and low sensitive data, and the sensitivity score is determined by the type of sensitive data, the strength of the correlation between the data, and the leakage impact coefficient.

[0048] Specifically, in this embodiment, the sensitivity score range is 0-100, the first sensitivity threshold is set to 65, and the second sensitivity threshold is set to 80; when the sensitivity score is less than or equal to the first sensitivity threshold, the sensitivity level of the private data is determined to be a non-sensitive field, and the type of the corresponding sensitive data is determined to be low-sensitivity data; when the sensitivity score is greater than the first sensitivity threshold and less than or equal to the second sensitivity threshold, the sensitivity level of the private data is determined to be a general sensitive field, and the type of the corresponding sensitive data is determined to be medium-sensitivity data; when the sensitivity score is greater than the second sensitivity threshold, the sensitivity level of the private data is determined to be a high-sensitivity field, and the type of the corresponding sensitive data is determined to be high-sensitivity data. This achieves a hierarchical classification of private data, and determines different desensitization strategies and encryption strategies based on private data of different sensitivity levels. This balances precise protection and cost control, facilitates operation and maintenance, and simplifies key management. Moreover, different user permissions are determined based on different desensitization strategies and encryption strategies. For example, only authorized users can decrypt and obtain highly sensitive data, thereby enhancing the security of private data.

[0049] Furthermore, the process of obtaining the corresponding desensitized data includes: determining the data desensitization strategy based on the sensitivity level of the sensitive data, including, determining the data desensitization strategy as irreversible desensitization according to the highly sensitive data, and determining the data desensitization strategy as reversible desensitization according to the medium sensitive data and the low sensitive data.

[0050] Specifically, in this embodiment, irreversible desensitization of highly sensitive data can completely block the risk of data leakage to ensure data security, and reversible desensitization of medium and low sensitive data can achieve a balance between security and availability and reduce processing costs; the hierarchical strategy makes it difficult for attackers to infer highly sensitive data through medium and low sensitive data.

[0051] Furthermore, the process of obtaining the corresponding encrypted data includes: determining the encryption strategy based on the data desensitization strategy of the desensitized data, including determining to use fully homomorphic encryption for the desensitized data according to the irreversible desensitization, and determining to use additive homomorphic encryption for the desensitized data according to the reversible desensitization.

[0052] Specifically, in this embodiment, the importance of data can be determined based on the data desensitization strategy, and different encryption algorithms can be selected based on the importance to ensure that more important data is more securely protected. Private data cannot be restored after irreversible desensitization. By adding fully homomorphic encryption on this basis, even decryption can only obtain the desensitized data, thus protecting it.

[0053] It is understandable that in the embodiments of the present invention, no specific limitation is imposed on any preset parameter or critical parameter, and the above values ​​are not limited thereto. Those skilled in the art may adjust the preset parameters or critical parameters accordingly based on actual needs, analysis of historical data, or equipment usage.

[0054] Thus far, the technical solutions of the present invention have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art may make equivalent changes or substitutions to the relevant technical features, and the technical solutions after such changes or substitutions will fall within the scope of protection of the present invention.

[0055] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that the present invention is susceptible to various modifications and variations. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.

Claims

1. A privacy data secure exchange control method based on privacy computing, characterized in that: include: Obtaining a number of private data that needs to be exchanged at the sending end, performing pre-processing, and dividing the data according to sensitivity levels to obtain a number of sensitive data; Determining a corresponding data desensitization strategy according to the sensitivity level and processing a number of the sensitive data to obtain corresponding desensitized data; Determining a corresponding encryption strategy according to the data desensitization strategy and processing a number of the desensitized data to obtain corresponding encrypted data; Transmitting the obtained encrypted data and corresponding public keys to a receiving end; Triggering a smart contract according to the authority of the receiving end to determine to enable a private key corresponding to the public key to perform decryption processing to obtain target data; Counting the data volume of the private data and the corresponding data volume of the target data and processing them to obtain a difference rate and a null value rate; Determining whether the data interaction process is qualified based on the difference rate, and determining whether the process is qualified based on the determination result combined with the null value rate, or determining the reason for failure based on the difference rate, and generating corresponding instructions based on the reason, the instructions are to determine the field masking ratio in the data desensitization process, or the data statistics in the privacy data and the corresponding target data, or the data cleaning interval in the preprocessing process; The field masking ratio, the data statistics, or the data cleaning interval is adjusted based on the instruction.

2. The privacy data secure exchange control method based on privacy computing according to claim 1 is characterized in that: The process of determining whether the data interaction process is qualified includes: Determining whether the data interaction process is qualified based on a comparison result of the difference rate and a preset difference rate, and determining whether the data interaction process is qualified based on the comparison result of the determination and a comparison result of the null value rate offset and a critical null value rate offset; When the data interaction process is determined to be unqualified, determining the cause according to the difference between the difference rate and the preset difference rate; The null value rate offset is the difference between the null value rate of the target data and the null value rate of the privacy data.

3. The privacy data secure exchange control method based on privacy computing according to claim 2 is characterized in that: The process of determining whether the data interaction process is qualified based on the comparison result of the null rate offset and the critical null rate offset includes: Based on a comparison result of the null rate offset and the critical null rate offset, it is determined whether to reduce the field masking ratio.

4. The privacy data secure exchange control method based on privacy computing according to claim 3 is characterized in that: The process of determining whether to reduce the field masking ratio includes: When it is determined that the null rate offset is greater than the critical null rate offset, determining to reduce the field masking ratio; Calculating a difference between the void rate offset and the critical void rate offset and recording the difference as the offset difference; Based on the comparison result of the offset difference and the preset offset difference, a corresponding instruction is generated to reduce the field masking ratio, and the reduction amplitude of the field masking ratio is positively correlated with the offset difference.

5. The privacy data secure exchange control method based on privacy computing according to claim 3 is characterized in that: The process of determining whether to reduce the field masking ratio further includes: When it is determined that the null rate offset is greater than the critical null rate offset, determining to reduce the field masking ratio; The sensitivity level of the sensitive data is determined, and corresponding instructions are generated based on the division of the sensitivity levels to reduce the field masking ratio, wherein the reduction extent of the field masking ratio is negatively correlated with the sensitivity level.

6. The privacy data secure exchange control method based on privacy computing according to claim 2 is characterized in that: The process of determining the cause according to the difference between the difference rate and the preset difference rate includes: Calculating the difference between the difference rate and the preset difference rate and recording it as a difference deviation value; Determining the reason why the data interaction process fails based on a comparison result of the difference deviation value and a preset difference deviation value; A corresponding instruction is generated based on the reason to determine increasing the data statistics or adjusting the data cleaning interval.

7. The privacy data secure exchange control method based on privacy computing according to claim 6 is characterized in that: The preset difference deviation value includes a first preset difference deviation value, and when it is determined that the difference deviation value is less than or equal to the first preset difference deviation value, determining to increase the data statistic; Calculating the difference between the first preset difference deviation value and the difference deviation value and recording it as the deviation difference; Based on a comparison result of the deviation difference and a preset deviation difference, a corresponding instruction is generated to increase the data statistic, and an increase amplitude of the data statistic is negatively correlated with the deviation difference.

8. The privacy data secure exchange control method based on privacy computing according to claim 7 is characterized in that: The preset difference deviation value further includes a second preset difference deviation value, and when it is determined that the difference deviation value is greater than the first preset difference deviation value and less than or equal to the second preset difference deviation value, determining to adjust the data cleaning interval; Counting the number of target data whose difference rate is greater than the preset difference rate during the current transmission process and recording the number of abnormal data, and counting the number of abnormal data during the historical transmission process, and performing variance calculation based on the number of abnormal data to obtain the abnormal data variance; Based on the comparison result of the abnormal data variance and the critical abnormal data variance, it is determined whether to expand the data cleaning interval or to reduce the data cleaning interval.

9. The privacy data secure exchange control method based on privacy computing according to claim 8, characterized in that: When it is determined that the abnormal data variance is less than or equal to the critical abnormal data variance, determining to expand the data cleaning interval; Calculate the ratio of the number of abnormal data to the total number of target data and record it as the abnormality ratio; Based on the comparison result of the abnormality ratio and the preset abnormality ratio, a corresponding instruction is generated to expand the data cleaning interval, and the expansion range of the data cleaning interval is positively correlated with the abnormality ratio.

10. The privacy data secure exchange control method based on privacy computing according to claim 8, characterized in that: When it is determined that the abnormal data variance is greater than the critical abnormal data variance, determining to reduce the data cleaning interval; Calculate the difference between the abnormal data variance and the critical abnormal data variance and record it as the variance difference; Based on a comparison result between the variance difference value and a preset variance difference value, a corresponding instruction is generated to reduce the data cleaning interval, and the reduction extent of the data cleaning interval is positively correlated with the variance difference value.

Citation Information

Patent Citations

  • A data exchange method and system for information technology security

    CN115664799B

  • Financial privacy data trusted computing method and system based on multiple data sources

    CN116881973A

  • Smart city big data acquisition system

    CN118297438A

  • Private data access method and apparatus, and electronic device

    WO2021190017A1