Network data processing method, device and equipment

By classifying, encrypting, homomorphically encrypting and differentially privacy processing data, the security and efficiency issues when sharing data across organizations are resolved, and privacy protection and efficient processing of data during transmission and use are achieved.

CN120658484AActive Publication Date: 2025-09-16HEFEI TANOVO INFORMATION SECURITY TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510942505.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-09
Publication Date
2025-09-16
Estimated Expiration
2045-07-09

AI Technical Summary

Technical Problem

Existing data security protection methods have problems of inefficiency and insufficient security when sharing data across organizations. In particular, there is a risk of leakage during data transmission and use, and it is difficult to achieve fine-grained access control.

Method used

By classifying the data to be transmitted, performing homomorphic encryption and differential privacy processing after encryption, the fourth data is generated, and a secure transmission protocol is adopted during the transmission process to ensure the privacy and security of the data during transmission and use.

Benefits of technology

It ensures the privacy and security of data during transmission and use, reduces the risk of leakage, improves data processing efficiency, supports fine-grained access control, and meets network security compliance requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658484A_ABST
    Figure CN120658484A_ABST
Patent Text Reader

Abstract

The invention provides a network data processing method, device and equipment, belongs to the technical field of data processing of network security compliance, and solves the problem that a large amount of data has a leakage risk in the transmission and use process when data is shared across organizations. The method comprises the following steps: receiving to-be-transmitted target data; classifying the target data to be transmitted to obtain at least one type of first data; respectively encrypting the at least one type of first data to obtain at least one piece of second data; performing homomorphic encryption processing on the at least one piece of second data to obtain third data; performing differential privacy processing on the third data to obtain fourth data; and transmitting the fourth data. According to the scheme, by enhancing the security and privacy of the data in the transmission, processing and storage processes, the requirement of network security compliance can be met, fine-grained access control is realized, and by reducing data decryption scenes, the data processing efficiency is remarkably improved, and efficient processing and sharing of the data are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security and compliant data processing, and in particular to a network data processing method, apparatus, and device. Background Art

[0002] With the rapid development of network technology, data security has become a core issue in the field of network compliance. Currently, most data security protection methods rely on traditional encryption technologies and access control mechanisms, but these methods often suffer from inefficiencies and inadequate security when processing large amounts of sensitive data. While current encryption technologies can provide a certain degree of data protection, decryption operations carry the risk of exposing sensitive information during data sharing and computation. Access control mechanisms struggle to provide fine-grained control over data use and can be easily bypassed in certain scenarios. Conventional encryption and decryption of data can easily lead to inefficient data processing, especially when processing large amounts of data, where encryption and decryption operations become performance bottlenecks. In particular, when data needs to be shared across organizations, ensuring the privacy of data during transmission and use becomes a pressing technical challenge. Summary of the Invention

[0003] The present invention provides a network data processing method, device and equipment, which solves the problem that when sharing data across organizations, a large amount of network data is at risk of leakage during transmission and user access and use.

[0004] In order to solve the above technical problems, the technical solutions of the present invention are as follows: An embodiment of the present invention provides a network data processing method, including: receiving target data to be transmitted; Classifying the target data to be transmitted to obtain at least one category of first data; encrypting the at least one type of first data respectively to obtain at least one second data; Performing homomorphic encryption on the at least one second data to obtain third data; Performing differential privacy processing on the third data to obtain fourth data; The fourth data is transmitted.

[0005] Optionally, classifying the target data to be transmitted to obtain at least one category of first data includes: Obtaining a classification label, wherein the classification label includes data sensitivity and sensitivity level; The transmission target data is classified according to the classification label to obtain at least one category of first data.

[0006] Optionally, encrypting the at least one type of first data separately to obtain at least one second data includes: Determine encryption algorithms of target types respectively corresponding to the at least one type of first data; The corresponding first data is encrypted using the encryption algorithm of the target type to obtain at least one second data.

[0007] Optionally, performing homomorphic encryption on the at least one second data to obtain third data includes: Generate a public-private key pair; encrypting the at least one second data using a public key in a public-private key pair to generate at least one encrypted second data ciphertext; performing at least one encryption operation on the at least one encrypted second data ciphertext to obtain third data; Among them, the private key is securely transmitted by offline physical transmission or dynamic key negotiation between the two parties.

[0008] Optionally, performing differential privacy processing on the third data to obtain fourth data includes: Setting privacy budget parameters; according to Determine the scale parameter of the noise; performing a noise adding operation on the third data according to a noise scale parameter to obtain fourth data; in, is the privacy budget parameter, is the sensitivity of the query function, is the scale parameter of the noise.

[0009] Optionally, the method further includes: Receive data access requests from users; Performing authorization authentication on the user according to the data access request and obtaining an authentication result; When the authentication result indicates that the authentication is passed, the stored fourth data is operated according to the preset access rule.

[0010] Optionally, the method further includes: Obtaining user access operation records, and recording the access operation records in a log; Auditing the log to obtain an audit result; The audit result is output.

[0011] An embodiment of the present invention further provides a network data processing device, comprising: A receiving module, used for receiving target data to be transmitted; a processing module, configured to classify the target data to be transmitted to obtain at least one category of first data; encrypt the at least one category of first data respectively to obtain at least one second data; perform homomorphic encryption processing on the at least one second data to obtain third data; and perform differential privacy processing on the third data to obtain fourth data; A transmission module is used to transmit the fourth data.

[0012] An embodiment of the present invention further provides a computing device, comprising: a processor and a memory storing a computer program, wherein the computer program executes the above method when executed by the processor.

[0013] An embodiment of the present invention further provides a computer-readable storage medium storing instructions, which, when executed on a computer, enable the computer to execute the above method.

[0014] The technical solution of the present invention includes at least the following effects: The above-mentioned solution of the present invention comprises the following steps: receiving target data to be transmitted; classifying the target data to be transmitted to obtain at least one type of first data; encrypting the at least one type of first data to obtain at least one second data; homomorphically encrypting the at least one second data to obtain third data; performing differential privacy processing on the third data to obtain fourth data; and transmitting the fourth data. This solution can enhance the security and privacy of data during transmission, processing, and storage, meet network security compliance requirements, implement fine-grained access control, and significantly improve data processing efficiency by reducing data decryption scenarios, thereby achieving efficient data processing and sharing. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 is a flow chart of a network data processing method provided by an embodiment of the present invention; Figure 2 is a structural diagram of a network data processing device provided by an embodiment of the present invention; Figure 3 It is a structural diagram of a computing device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0016] Exemplary embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present invention are shown in the accompanying drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of the present invention and to fully convey the scope of the present invention to those skilled in the art.

[0017] like Figure 1As shown, an embodiment of the present invention provides a network data processing method, including: Step 11: Receive target data to be transmitted. The target data here may be target data to be transmitted generated by various data sources in the field of network security compliance. During the transmission of the target data, high requirements are placed on data security. Step 12: Classify the target data to be transmitted to obtain at least one category of first data. Here, the target data to be transmitted may be classified according to classification labels based on data sensitivity and security requirements. For example, personal identity information, financial information, or trade secrets are generally considered highly sensitive data. Step 13: encrypt the at least one type of first data respectively to obtain at least one second data; Step 14: performing homomorphic encryption on the at least one second data to obtain third data; Step 15: performing differential privacy processing on the third data to obtain fourth data; Step 16: Transmit the fourth data.

[0018] In this embodiment, the system or device acts as the data receiver, responsible for acquiring the target data to be transmitted from the data source. The data can come from various sources, such as sensor data, user input, and data transmitted from other systems. During the reception process, it is necessary to ensure the integrity and accuracy of the data to avoid data loss or corruption. Various verification mechanisms (such as checksums and hash values) can be used to verify that the received data is consistent with the original data.

[0019] After receiving the target data, the system will classify and process the data. The basis for classification can be determined based on multiple factors such as the characteristics, purpose, source, sensitivity, etc. of the data. Through classification, the original data is divided into at least one category of first data, thereby providing a more targeted strategy for subsequent encryption processing and improving encryption efficiency and security.

[0020] The system encrypts each category of classified first data using a corresponding encryption algorithm. The appropriate encryption algorithm is selected based on computing resources, data sensitivity, and actual security requirements. For highly sensitive data, a more powerful and complex encryption algorithm is used, while for less sensitive data, a more efficient but less secure encryption algorithm is selected to balance performance and security requirements. The encrypted data becomes unreadable and can only be decrypted and accessed with the corresponding key. The encrypted data is stored in a secure storage medium, such as an encrypted hard drive, database, or cloud storage. By encrypting each category of first data separately, at least one second data item is generated. This ensures that even if the data is intercepted during transmission, attackers cannot easily obtain the plaintext content of the original data.

[0021] Homomorphic encryption allows specific computational operations to be performed on encrypted data without first decrypting it. Homomorphic encryption aims to further enhance data security while allowing necessary computational operations to be performed on the data while it remains encrypted. For example, in a cloud computing environment, cloud service providers can perform statistical analysis and other operations on encrypted data without accessing the user's plaintext data. After obtaining the encrypted second data, the system performs homomorphic encryption on this data to produce the third data, which remains encrypted while being operable and computable.

[0022] In the differential privacy encryption step, by adding noise to the data, attackers cannot infer individual information from the data. After obtaining the third data after homomorphic encryption, the system will perform differential privacy processing on this data. The specific method is to add random noise that conforms to a specific distribution to the data. The size and distribution of the noise are selected according to the sensitivity and privacy requirements of the data. Through differential privacy processing, the fourth data is obtained. The fourth data protects the privacy information in the data to the greatest extent while ensuring the availability of the data.

[0023] After obtaining the fourth data, the system transmits it to the target receiving end. The transmission process can be carried out through various network communication protocols. During the transmission process, a secure transmission protocol can be further adopted to ensure the security of the data in the transmission channel and prevent the data from being stolen or tampered with during transmission. After receiving the fourth data, the target receiving end can perform corresponding decryption and processing operations as needed to obtain usable information about the original data.

[0024] This solution ensures the privacy and security of data during transmission and use through homomorphic encryption and differential privacy, effectively reducing the risk of data being stolen, tampered with or leaked during transmission, and improving the efficiency of encrypted data processing in massive data scenarios.

[0025] In an optional embodiment of the present invention, step 12 may include: Step 121: Obtain a classification label, wherein the classification label includes data sensitivity and sensitivity level; Step 122: classify the transmission target data according to the classification label to obtain at least one category of first data.

[0026] In this embodiment, it is necessary to obtain a classification label, which contains important information about the data, covering two core elements: data sensitivity and sensitive data level.

[0027] Data sensitivity describes whether the data involves sensitive information or the specific sensitivity of the content. Different data may have different sensitivities. For example, in the medical field, patient medical records and genetic data are highly sensitive data because this information is directly related to personal health and privacy. Once leaked, it can have serious negative impacts on patients, such as discrimination and fraud. In some public market research data, statistical information about consumer purchasing preferences is relatively less sensitive because this information usually does not involve personal privacy and can be used publicly after proper processing.

[0028] The sensitive data level is a quantitative or graded representation of the sensitivity of the data, and is divided according to the potential risks and impact of the data. For example, sensitive data can be divided into four levels: high, medium, low, and none. High-level sensitive data includes data involving national security, commercial secrets or personal core privacy, such as military secrets, the core technology of an enterprise, and personal bank account information; intermediate-level sensitive data includes some data with certain commercial value or personal privacy information, such as a company's customer list and an individual's social relationship data; low-level sensitive data includes some public information or data that has less impact on individuals and enterprises after desensitization processing; non-sensitive information includes some data that can always be kept public and has no impact on the collective or individual.

[0029] Methods for obtaining the classification labels include: generating through predefined rules and standards. For example, an enterprise can formulate a detailed set of data classification rules based on its own business needs and data security policies to clarify the sensitivity and level of sensitive data of different types of data; automatic identification and classification through machine learning algorithms. This method uses learning and analysis of large amounts of historical data. The machine learning model can automatically identify the characteristics of the data and assign corresponding classification labels to the data based on these characteristics.

[0030] The system classifies the target data for transmission according to the classification labels, and can group data with similar sensitive situations and sensitive data levels into one category, so that different processing strategies can be adopted for different categories of data in the future.

[0031] The specific process is as follows: the system checks each data item in the target data to be transmitted one by one, and matches it with the pre-acquired classification label based on its characteristics. For example, for a piece of data containing a personal ID number, the system will determine that it is highly sensitive data based on the classification label; for a piece of public weather forecast data, the system will determine that it is non-sensitive data, because this type of data can always be kept fully open to both individuals and enterprises.

[0032] After the classification operation, the transmission target data will be divided into at least one category of first data, and each category of first data has the same sensitivity and sensitive data level. This classification method makes subsequent data processing more targeted and efficient.

[0033] In an optional embodiment of the present invention, step 13 may include: Step 131, determining encryption algorithms of target types corresponding to the at least one type of first data; Step 132: Encrypt the corresponding first data using the encryption algorithm of the target type to obtain at least one second data.

[0034] In this embodiment, the appropriate encryption algorithm for the target type can be determined manually or automatically to ensure data security. Because different types of first data vary in sensitivity, usage, storage, and transmission requirements, highly adaptable encryption algorithms are required for each type of data to ensure confidentiality, integrity, and availability during subsequent processing and transmission. Data sensitivity is a primary consideration when selecting an encryption algorithm. For highly sensitive data, an encryption algorithm with extremely high encryption strength and rigorously verified security is required, such as the Advanced Encryption Standard (AES) algorithm, which offers high encryption efficiency and security, effectively resisting various common attack vectors. For less sensitive data, an algorithm with slightly lower encryption strength but higher computational efficiency can be selected to balance security and processing performance. Furthermore, enterprises or organizations can pre-establish a set of encryption algorithm selection rules based on factors such as data classification labels and sensitivity levels, based on their business needs, data security policies, and industry standards, to clearly define the encryption algorithm type corresponding to different types of data.

[0035] After determining the encryption algorithm, the system will use the algorithm to encrypt the corresponding first data, thereby converting the original plaintext data into ciphertext data and obtaining at least one second data. The specific process is as follows: Generate a key: The key is generated using a dedicated key generation algorithm or hardware device and should comply with strict randomness and security requirements; Execute encryption: Based on the selected target type encryption algorithm, the first data and the generated key are used as input to execute the calculation process of the encryption algorithm. The encryption algorithm will perform a series of mathematical transformations on the original data, such as replacement, permutation, XOR, etc., to convert the plaintext data into ciphertext data; Verify data: In order to ensure that the data has not been tampered with during the encryption process, a data integrity check value, such as a hash value, will also be calculated at the same time. The hash value is transmitted or stored together with the encrypted data. After receiving and decrypting the data, the hash value of the data is recalculated and compared with the received hash value to verify the integrity of the data.

[0036] In an optional embodiment of the present invention, step 14 may include: Step 141, generating a public-private key pair; Step 142: encrypt the at least one second data using a public key in a public-private key pair to generate at least one encrypted second data ciphertext; Step 143: perform at least one encryption operation on the at least one encrypted second data ciphertext to obtain third data; wherein the private key is securely transmitted by offline physical transmission or by dynamically negotiating a key between the two parties.

[0037] In this embodiment, homomorphic encryption is used to protect data privacy while supporting the processing and analysis of encrypted data. In step 141, a public-private key pair is generated. The public key is used to encrypt data, and the private key is used to decrypt data or perform decryption after homomorphic operation. The private key generation process includes: Randomly select a random number between 1 and n-1; In the finite field GF(2 256 ) is: 2 =x 3 +ax+b; where coefficients: a is the first preset value, b is the second preset value; the coordinates of the base point G on the curve are: x G =x1,y G =y1; The order of the curve G, that is, the smallest positive integer n such that nG = infinity; use this value of n as the private key; Serialize the private key into a standard encoding format (such as PEM format); Get the public key, which can be obtained through public_key=private_key.public_key(); Serialize the public key into a standard encoding format (such as PEM format).

[0038] In step 142, the second data is encrypted using the public key to generate a ciphertext. The ciphertext can be calculated without exposing the original data. After the calculation, the result ciphertext can be obtained, that is, the third data. The third data not only includes the result after the homomorphic operation, but also ensures the privacy and security of the data through secure private key management.

[0039] In this embodiment, in order to ensure that information is not stolen by attackers, a more secure protection method is required for the private key. Therefore, the private key needs to be securely transmitted by offline physical transmission or dynamic negotiation of the key between the two parties. The dynamic negotiation of the key between the two parties refers to the use of a key exchange protocol, so that the communicating parties can negotiate a shared key by exchanging public information without directly transmitting the private key. The key can be used for subsequent private key transmission or data encryption communication; at the same time, the private key needs to be replaced regularly to reduce the risk of the private key being cracked in the long term and ensure that it is not eavesdropped or tampered with during the transmission process.

[0040] In step 143, at least one encryption operation is performed on the at least one encrypted second data ciphertext to obtain third data. For example, for two ciphertexts (C_1) and (C_2), (C_3=C_1+C_2) or (C_4=C_1×C_2) can be directly calculated without first decrypting. Finally, the private key is used to decrypt the ciphertext result after the homomorphic operation to obtain the plaintext result after the operation.

[0041] In an optional embodiment of the present invention, step 15 may include: Step 151, obtaining preset privacy budget parameters; Step 152, according to Determine the scale parameter of the noise; where, To preset privacy budget parameters; is the sensitivity of the query function; is the scale parameter of the noise; Step 153: performing a noise adding operation on the third data according to the noise scale parameter to obtain fourth data.

[0042] In this embodiment, differential privacy is used to process the third data. The essence of the process is to establish a provable mathematical balance between "privacy protection" and "data utility". Through the rigorous design of the noise mechanism, it is ensured that the data analysis results do not leak any individual's sensitive information. It is necessary to protect data privacy by adding noise while minimizing the impact on data availability. The main process includes: Define a dataset and adjacent datasets. The dataset contains n records, each record represents the information of an individual, represented by D and ; If two data sets D and Only one record differs (i.e. = D ± {x}, where x is a record), the two are "adjacent datasets." It is necessary to ensure that the distribution of the algorithm's output results for adjacent datasets is minimally different, thereby hiding the impact of individual records.

[0043] Determine a query function, which is an analytical operation on a data set and is represented by f(), for example: statistical query: calculate the number of records in a data set that meet a certain condition; aggregation query: calculate the mean and sum data.

[0044] Calculate the sensitivity of the query function, which is a measure of the maximum impact of a single record on the query result. It is defined as the maximum difference in query results on adjacent data sets, expressed as Δf, that is, .

[0045] Different queries have different sensitivities. The sensitivity of count queries is 1 (adding or deleting a record changes the count result by at most 1). Sensitivity for sum queries: If the data values ​​are bounded (for example, the age range is [0, 120]), the sensitivity is the difference between the maximum and minimum values ​​(for example, 120). Depending on the definition of the norm, sensitivity is calculated using different methods: L1 sensitivity and L2 sensitivity. L1 sensitivity is calculated by summing the absolute values, while L2 sensitivity is calculated by taking the square root of the square root.

[0046] After the sensitivity is determined, it is necessary to set an appropriate privacy budget parameter. The privacy budget parameter is a parameter used to measure the degree of privacy protection in differential privacy. The smaller the value of the privacy budget parameter, the higher the level of privacy protection, but the data availability will be correspondingly reduced; the larger the value of the privacy budget parameter, the higher the data availability will be, but the degree of privacy protection will be weakened. Therefore, different privacy budget parameters need to be set in different usage scenarios.

[0047] Set appropriate privacy budget parameters based on actual circumstances. The process of setting appropriate privacy budget parameters includes: Initially set a privacy budget parameter, check whether the data after adding noise meets the privacy and availability requirements of the data, and dynamically adjust the privacy budget parameter until a balance between privacy and availability requirements is found. This is the appropriate privacy budget parameter for the current scenario, usually ϵ is between 0.1 and 10; When the privacy budget parameters are determined, according to The calculation mechanism to determine the appropriate noise scale parameter and realize the privacy of query is as follows: Noise compliance , the probability density function is , the output result is f(D)+η; where, is the privacy budget parameter; is the sensitivity of the query function, which reflects the sensitivity of the query result to the change of data records; x represents the possible value of noise; η represents the actual noise value, that is, an instance of x; Represents the noise scale parameter. The noise scale parameter determines the intensity of the noise added to the data. The larger the noise scale parameter value, the greater the added noise intensity, thus providing stronger privacy protection, but also further reducing the availability of data. If the sensitivity of the count query Δf=1, the privacy budget parameter = 1, the mean of the noise added by the Laplace mechanism is 0. This mean is always 0, independent of the noise scale parameter, which is 1 / 1=1, meaning the noise follows Lap(0,1). Depending on the query function type and the characteristics of the data, for scalar query results, the generated random noise can be directly added to the query result and the noisy result output to obtain the fourth data. If the third data is multidimensional (such as a vector or matrix), noise must be added to each dimension separately to obtain the fourth data.

[0048] After adding noise, it is necessary to verify whether the data after adding noise meets the definition of differential privacy through theoretical analysis or simulation experiments, and to evaluate the impact of the data after adding noise on subsequent analysis and application. The availability of data can be measured mainly by calculating the error, accuracy and other indicators of the data. The privacy of the output data is verified to ensure that for any adjacent data set D and , and any possible output result set S that satisfies , wherein the Mechanism() is a randomized algorithm; D and is an adjacent dataset; S is an arbitrary output subset, covering all possible privacy leakage scenarios; is the privacy budget parameter; Pr[Mechanism(D)∈S] is the probability that the output of the mechanism on the dataset D belongs to S; Pr[Mechanism( )∈S] is the mechanism in the dataset The probability that the above output belongs to S; this inequality ensures that the upper limit of the impact of the existence or absence of a single record on the result is controlled by the privacy budget parameter.

[0049] In an optional embodiment of the present invention, the data access control process includes: Step 171, receiving a user's data access request; Step 172: Authenticate the user according to the data access request and obtain an authentication result. Step 173 , when the authentication result indicates that the authentication is passed, the stored fourth data is operated according to the preset access rules; wherein the user can perform specific operations of different authority levels according to the preset access rules that are met.

[0050] In this embodiment, a fine-grained access control policy can be implemented to ensure that only authorized users can access specific data. Before a user attempts to access data, the system will first confirm the user's identity through a multi-factor authentication mechanism to ensure that only legitimate users can enter the next step of the permission verification process, that is, obtain the authentication result; after the user's identity authentication is successful, the system will dynamically generate the user's access permission list based on the user's role, position, department and other attributes, as well as the preset access control rules (i.e., which role, position, department and other attributes of the user can perform which level of operation); and subdivide the data access permission into multiple levels, such as read, write, execute, modify, delete, etc., each level corresponding to different operation permissions; and the system administrator can assign different permission levels to different users or user groups through the management interface to achieve flexible permission management; for highly sensitive data, the system can also set up additional approval processes, such as dual authentication or leadership approval, to ensure the legitimacy of data access.

[0051] During the process of user access to data, the system will monitor the user's operation behavior in real time and perform permission verification based on the user's permission list. If the user attempts to perform an operation beyond the scope of his or her permission, the system will immediately block and record the behavior, and send an alert to the system administrator. All user access behaviors will be recorded in detail, including access time, access location, access content, etc., for subsequent auditing and tracking. As the business develops and user roles change, the access control module supports dynamic adjustment of user access rights. System administrators can also review and update user permissions regularly or as needed to ensure the rationality and effectiveness of permission allocation.

[0052] In an optional embodiment of the present invention, the data audit process includes: Step 181: Obtain the user's access operation record and record the access operation record in a log; Step 182: audit the log to obtain an audit result; Step 183: output the audit result.

[0053] In this embodiment, the system logs all data manipulation activities, including data access, modification, and deletion, for subsequent tracking and auditing. Through deep integration of the audit process with the system, every data manipulation event is captured. For each data manipulation event, key information is extracted from the log and recorded, including the time of operation, operation type (e.g., access, modification, deletion), operation object (specific data item or dataset), and operator (user or system performing the operation). Complete records are stored in log form to ensure information integrity and traceability. The system reviews, analyzes, and evaluates the log records to verify the compliance, security, and effectiveness of the system, generating an audit report. The audit report includes an overview of the manipulation activities, detailed operation records, and analysis of abnormal operations, enabling administrators to understand data usage and conduct necessary compliance reviews. When automated means identify system risks in the audit report, an alert is sent to the administrator via SMS or email to provide early warning and timely identification and correction of any issues. Furthermore, administrators can review the audit report to track data manipulation activities, helping to ensure data usage compliance.

[0054] A specific embodiment of the data processing method provided by the embodiment of the present invention is: Step 1: Receive target data to be transmitted. The target data may come from a plurality of different data sources such as a database, a file system, an external system, etc.

[0055] Step 2: Obtain a classification label by generating it through predefined rules and standards. The classification label contains important information about the data, covering two core elements: data sensitivity and sensitive data level. Data sensitivity is used to describe whether the data involves sensitive information or the specific sensitivity level of the content. Different data will have different sensitivities. Classify the target data according to the classification label to obtain different types of first data.

[0056] Step 3: Automatically or manually select an appropriate encryption algorithm based on the different types of first data divided by the classification labels, and encrypt the original data using a variety of different encryption algorithms such as the Advanced Encryption Standard and elliptic curve cryptography to obtain encrypted second data.

[0057] Step 4: Obtain the second data and perform homomorphic encryption on the second data to obtain the second data ciphertext. This includes: selecting an appropriate homomorphic encryption algorithm, such as partially homomorphic encryption, limited homomorphic encryption, or fully homomorphic encryption; performing data preprocessing operations, such as standard format conversion and data cleansing; generating a key pair, wherein a public key is used for encryption and a private key is used for decryption; and encrypting the second data using the public key in the key pair to obtain the second data ciphertext. Homomorphic operations and data computation tasks, including data analysis, data mining, and machine learning model training, can be performed on the encrypted second data ciphertext to obtain the encrypted result ciphertext, i.e., the third data. In order to ensure that information is not stolen by attackers, a more secure protection method is needed for private keys. Therefore, private keys need to be securely transmitted using offline physical transmission or dynamic key negotiation between the two parties. The dynamic key negotiation between the two parties refers to the use of a key exchange protocol, which allows the communicating parties to negotiate a shared key by exchanging public information without directly transmitting the private key. This key can be used for subsequent private key transmission or data encryption communication; at the same time, private keys need to be replaced regularly to reduce the risk of long-term cracking of private keys and ensure that they are not eavesdropped or tampered with during transmission.

[0058] Step 5: Perform differential privacy processing on the third data to obtain the number of users with diabetes in the statistical data set. The data set contains 1000 user records. The query function is obtained according to f(D)=count(x∈D|diabetes=True). Since the increase or decrease of a single record in the count query will change the result by at most 1, the sensitivity Δf=1, where D is the data set, f() is the query function, and x is each data record. Set an appropriate privacy budget as =1; where is the privacy budget parameter; The sensitivity of the query function reflects the sensitivity of the query result to the change of data records; is the scale parameter of the noise, which determines the intensity of the noise added to the data. The larger the value of the noise scale parameter, the greater the intensity of the added noise, thereby providing stronger privacy protection, but it will also further reduce the availability of the data. After determining the privacy budget parameter, according to Calculate the corresponding noise scale parameter and get , thereby adding noise of corresponding intensity to the query result, and the actual noise after addition obeys , where η is the actual noise value. We randomly obtain an actual noise value η=2, and according to f(D)+η=120+2=122, we get the fourth data after differential privacy processing. Even if a user deletes his own record (the dataset changes from D to )、f( )=119, the output 122 after adding noise must satisfy ,but =3, then the probability density ratio , satisfying differential privacy, the influence of a single user can be masked by noise, making it insensitive to changes in a single record during data processing, that is, ensuring data privacy while ensuring data availability.

[0059] Step 6: Transmit the fourth data to a device or system that needs to be used.

[0060] Step 7: Before a user attempts to access data, the system first confirms the user's identity through a multi-factor authentication mechanism to ensure that only legitimate users can enter the next step of the permission verification process. After the user's identity verification is successful, the system will dynamically generate the user's access permission list based on the user's role, position, department, and other attributes, as well as the preset access control rules. Data access permissions are divided into multiple levels, such as read, write, execute, delete, etc., and each level corresponds to different operation permissions. For particularly sensitive data, the system can also set up additional approval processes, such as two-factor authentication or leadership approval, to ensure the legitimacy of data access. During the user's access to data, the system will monitor the user's operation behavior in real time and verify the permissions according to the user's permission list. If a user attempts to perform an operation beyond their permission, the system will immediately block and record the behavior and send an alert to the system administrator. All user access behaviors will be recorded in detail, including access time, access location, access content, etc., for subsequent auditing and tracking. As the business develops and user roles change, the access control module supports dynamic adjustment of user access rights. System administrators can use the management interface to assign different permission levels to different users or user groups to achieve flexible permission management; system administrators can review and update user permissions regularly or as needed to ensure the rationality and effectiveness of permission allocation, thereby implementing fine-grained access control policies to ensure that only authorized users can access specific data.

[0061] In step 8, the system logs all data manipulation activities, including data access, modification, and deletion, for subsequent tracking and auditing. Deep integration of the audit process with the system ensures that every data manipulation event is captured. For each data manipulation event, key information is extracted from the log and recorded, including the time of operation, operation type (e.g., access, modification, deletion), operation object (specific data item or dataset), and operator (user or system performing the operation). Complete records are stored in log form to ensure information integrity and traceability. The system reviews, analyzes, and evaluates log records to verify system compliance, security, and effectiveness, generating an audit report. This report includes an overview of the manipulation activities, detailed operation records, and analysis of abnormal operations, enabling administrators to understand data usage and conduct necessary compliance reviews. When automated means identify system risks in the audit report, an alert is sent to administrators via SMS or email to provide early warning and timely identification and correction of any issues. Administrators can also review the audit report to track data manipulation activities, helping to ensure data compliance.

[0062] The data processing method proposed in the present invention integrates homomorphic encryption technology and differential privacy technology through a privacy computing engine, allowing calculations on encrypted data without decryption first. The calculation results after decryption are the same as the results of direct calculations on plaintext data. It supports data analysis and processing while protecting data privacy, can meet data computing needs in different scenarios, achieve a balance between data security and data usage performance, and support the safe circulation and sharing of data in the field of network security compliance.

[0063] like Figure 2 As shown, the embodiment of the present invention further provides a network data processing device 20, including: Receiving module 21, used for receiving target data to be transmitted; The processing module 22 is configured to classify the target data to be transmitted to obtain at least one type of first data; encrypt the at least one type of first data to obtain at least one second data; perform homomorphic encryption on the at least one second data to obtain third data; and perform differential privacy processing on the third data to obtain fourth data. The transmission module 23 is configured to transmit the fourth data.

[0064] Optionally, classifying the target data to be transmitted to obtain at least one category of first data includes: Obtaining a classification label, wherein the classification label includes data sensitivity and sensitivity level; The transmission target data is classified according to the classification label to obtain at least one category of first data.

[0065] Optionally, encrypting the at least one type of first data separately to obtain at least one second data includes: Determine encryption algorithms of target types respectively corresponding to the at least one type of first data; The corresponding first data is encrypted using the encryption algorithm of the target type to obtain at least one second data.

[0066] Optionally, performing homomorphic encryption on the at least one second data to obtain third data includes: Generate a public-private key pair; encrypting the at least one second data using a public key in a public-private key pair to generate at least one encrypted second data ciphertext; performing at least one encryption operation on the at least one encrypted second data ciphertext to obtain third data; Among them, the private key is securely transmitted by offline physical transmission or dynamic key negotiation between the two parties.

[0067] Optionally, performing differential privacy processing on the third data to obtain fourth data includes: Setting privacy budget parameters; according to Determine the scale parameter of the noise; performing a noise adding operation on the third data according to a noise scale parameter to obtain fourth data; in, is the privacy budget parameter, is the sensitivity of the query function, is the scale parameter of the noise.

[0068] Optionally, the method further includes: Receive data access requests from users; Performing authorization authentication on the user according to the data access request and obtaining an authentication result; When the authentication result indicates that the authentication is passed, operating the stored fourth data according to the preset access rule; Among them, users can perform specific operations of different permission levels according to the preset access rules they meet.

[0069] Optionally, the processing module 22 is further configured to: Obtaining user access operation records, and recording the access operation records in a log; Auditing the log to obtain an audit result; The audit result is output.

[0070] It should be noted that this device is a device corresponding to the above method, and all implementation methods in the above method embodiment are applicable to this embodiment and can achieve the same technical effect.

[0071] like Figure 3 As shown, an embodiment of the present invention further provides a computing device 30, including a processor 31, a memory 32, and a program or instruction stored in the memory 32 and executable on the processor 31. When the program or instruction is executed by the processor 31, the various processes of the above-mentioned network data processing method embodiment are implemented and can achieve the same technical effects. To avoid repetition, they are not described here. It should be noted that the computing device in the embodiment of the present invention includes the above-mentioned mobile electronic device and non-mobile electronic device.

[0072] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.

[0073] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0074] In the embodiments provided by the present invention, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be through some interface, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0075] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0076] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0077] If the functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product, stored in a storage medium, includes instructions for causing a computer device (such as a personal computer, server, or network device) to execute all or part of the steps of the various embodiments of the method of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, mobile hard drives, ROM, RAM, magnetic disks, or optical disks.

[0078] In addition, it should be pointed out that in the apparatus and method of the present invention, it is obvious that each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of the present invention. Moreover, the steps of performing the above-mentioned series of processing can naturally be performed in chronological order according to the order of description, but they do not necessarily need to be performed in chronological order, and some steps can be performed in parallel or independently of each other. For those of ordinary skill in the art, it can be understood that all or any steps or components of the method and apparatus of the present invention can be implemented in hardware, firmware, software or a combination thereof in any computing device (including a processor, storage medium, etc.) or a network of computing devices. This can be achieved by those of ordinary skill in the art using their basic programming skills after reading the description of the present invention.

[0079] Therefore, the purpose of the present invention can also be achieved by running a program or a group of programs on any computing device. The computing device can be a well-known general-purpose device. Therefore, the purpose of the present invention can also be achieved simply by providing a program product containing program code for implementing the method or device. That is to say, such a program product also constitutes the present invention, and the storage medium storing such a program product also constitutes the present invention. Obviously, the storage medium can be any well-known storage medium or any storage medium developed in the future. It should also be pointed out that in the device and method of the present invention, it is obvious that each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent schemes of the present invention. In addition, the steps of performing the above-mentioned series of processing can naturally be performed in chronological order according to the order of description, but do not necessarily need to be performed in chronological order. Certain steps can be performed in parallel or independently of each other.

[0080] The above is a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.

Claims

1. A network data processing method, characterized in that: include: receiving target data to be transmitted; Classifying the target data to be transmitted to obtain at least one category of first data; encrypting the at least one type of first data respectively to obtain at least one second data; Performing homomorphic encryption on the at least one second data to obtain third data; Performing differential privacy processing on the third data to obtain fourth data; The fourth data is transmitted.

2. The network data processing method according to claim 1, wherein: Classifying the target data to be transmitted to obtain at least one category of first data includes: Obtaining a classification label, wherein the classification label includes data sensitivity and sensitivity level; The transmission target data is classified according to the classification label to obtain at least one category of first data.

3. The network data processing method according to claim 1, wherein: Encrypting the at least one type of first data respectively to obtain at least one second data includes: Determine encryption algorithms of target types respectively corresponding to the at least one type of first data; The corresponding first data is encrypted using the encryption algorithm of the target type to obtain at least one second data.

4. The network data processing method according to claim 1, wherein: Performing homomorphic encryption on the at least one second data to obtain third data includes: Generate a public-private key pair; encrypting the at least one second data using a public key in a public-private key pair to generate at least one encrypted second data ciphertext; performing at least one encryption operation on the at least one encrypted second data ciphertext to obtain third data; Among them, the private key is securely transmitted by offline physical transmission or dynamic key negotiation between the two parties.

5. The network data processing method according to claim 1, wherein: Performing differential privacy processing on the third data to obtain fourth data includes: Setting privacy budget parameters; according to Determine the scale parameter of the noise; performing a noise adding operation on the third data according to a noise scale parameter to obtain fourth data; in, is the privacy budget parameter, is the sensitivity of the query function, is the scale parameter of the noise.

6. The network data processing method according to claim 1, wherein: The method further comprises: Receive data access requests from users; Performing authorization authentication on the user according to the data access request and obtaining an authentication result; When the authentication result indicates that the authentication is passed, the stored fourth data is operated according to the preset access rule.

7. The network data processing method according to claim 1, wherein: The method further comprises: Obtaining user access operation records, and recording the access operation records in a log; Auditing the log to obtain an audit result; The audit result is output.

8. A network data processing device, characterized in that: include: A receiving module, used for receiving target data to be transmitted; a processing module, configured to classify the target data to be transmitted to obtain at least one category of first data; encrypting the at least one type of first data respectively to obtain at least one second data; Performing homomorphic encryption on the at least one second data to obtain third data; Performing differential privacy processing on the third data to obtain fourth data; A transmission module is used to transmit the fourth data.

9. A computing device, characterized in that include: A processor and a memory storing a computer program, wherein when the computer program is executed by the processor, the method according to any one of claims 1 to 7 is performed.

10. A computer-readable storage medium, characterized in that The device stores instructions, which, when executed on a computer, enable the computer to execute the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Data security risk assessment method and system based on privacy calculation

    CN118940291A

  • Private data protection method and system based on homomorphic encryption and federated learning

    CN119513919A

  • Security protection method, system and device for data sharing and exchange and medium

    CN120162811A

  • Feature processing method and device based on differential privacy

    WO2023045503A1