Method for protecting and sharing trajectory privacy data
By performing sensitivity classification and risk assessment on trajectory data and dynamically adjusting differential privacy parameters, the balance between trajectory data privacy protection and sharing is resolved, achieving effective protection and sharing under different circumstances.
Patent Information
- Application Number
- CN202511140822.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-15
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2045-08-15
AI Technical Summary
Existing methods for protecting the privacy of trajectory data are insufficient when the amount of noise injected is small, and affect the availability of data when the amount of noise is large, making it difficult to balance the needs of privacy protection and sharing.
By classifying and assessing the sensitivity of trajectory data and dynamically adjusting differential privacy parameters, the adjustment of differential privacy parameters is determined based on the sensitivity benchmark index and dynamic risk index of trajectory data. Combined with the risk value of the accessing user, dynamic protection and sharing of trajectory data can be achieved.
By improving sharing efficiency when data sensitivity is low and the risk to users is low, and strengthening privacy protection when sensitivity is high and the risk is high, the privacy protection and sharing needs of trajectory data are balanced.
Smart Images

Figure CN120724482B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of trajectory data privacy protection, in particular to a trajectory privacy data protection and sharing method. BACKGROUND
[0002] Trajectory data is data information obtained by sampling the movement process of one or more moving objects in a space-time environment, including sampling point position, sampling time, speed, etc. These sampling point data information constitutes trajectory data according to the sampling sequence. Since sensitive information (such as some sensitive areas visited by the access user) may be included in the trajectory data, or other personal information (such as the home address, workplace, health status, and living habits of the access user) can be derived by running the trajectory, therefore, the privacy protection of the trajectory information is crucial.
[0003] The existing trajectory data privacy protection method mainly protects the privacy by splitting the privacy, adding mathematical noise (such as Laplace noise) to the trajectory data to confuse the real trajectory data, and ensuring that the attacker cannot restore the sensitive information through statistical inference.
[0004] In the process of protecting the trajectory data privacy by splitting the privacy, the noise injection parameters are set. However, when the noise injection value is small, the protection strength of the trajectory data privacy is weak, and when the noise injection value is large, although the trajectory data privacy can be effectively protected, the data usability is affected in the data sharing process. Therefore, how to balance the privacy protection and sharing demand of the trajectory data is the fundamental problem to be solved by the present application. SUMMARY
[0005] In order to balance the privacy protection and sharing demand of the trajectory data, the present application provides a trajectory privacy data protection and sharing method.
[0006] The following technical scheme is adopted:
[0007] The trajectory privacy data protection and sharing method comprises:
[0008] According to the trajectory data and the historical access information, the sensitivity is graded;
[0009] The behavior of each access user is identified by an event trigger, and the risk value of each access user is determined according to the identification result;
[0010] According to the risk value of each access user and the sensitivity of the access trajectory data, the differential privacy parameter of the trajectory data is dynamically adjusted;
[0011] The process of grading the sensitivity of the trajectory data comprises:
[0012] The AI is used to identify the condition and spatial dimension of the trajectory data, and obtain the depth of the associated information and the spatial accuracy;
[0013] The time dimension of the trajectory data is analyzed to obtain the time granularity value;
[0014] The depth of the associated information, the spatial accuracy and the time granularity value are weighted and summed to obtain the sensitivity reference index of the trajectory data;
[0015] The dynamic risk index of the trajectory data is obtained according to the historical access information of the trajectory data;
[0016] The sensitivity classification of the trajectory data is determined according to the sensitivity reference index and the dynamic risk index of the trajectory data.
[0017] By using the above technical scheme, the sensitivity of the trajectory data is judged, the trajectory data is classified according to the judgment result, the risk value is obtained by judging the risk state of the access user, and the trajectory data privacy protection of each data sharing access process is dynamically adjusted through the sensitivity classification and the risk value of each access user. When the data sensitivity is low and the access user risk is low, the differential privacy parameter of the trajectory data is reduced to improve the efficiency of trajectory data sharing. When the data sensitivity is high and the access user risk is high, the differential privacy parameter of the trajectory data is increased to protect the privacy of the trajectory data, balancing the privacy protection and sharing demand of the trajectory data. The sensitivity reference index of the trajectory data is obtained by comprehensively evaluating different factors of the trajectory data sensitivity. The risk state of the trajectory data is evaluated according to the historical access information of the trajectory data, and the dynamic risk index of the trajectory data is obtained according to the historical access information of the trajectory data. Therefore, the dynamic risk index reflects the risk state of the trajectory data in a period of time. The sensitivity classification of the trajectory data is determined according to the sensitivity reference index and the dynamic risk index of the trajectory data. The sensitivity classification of the trajectory data can be adjusted in real time according to the content of the trajectory data and the real-time access data of the trajectory data, and a more accurate reference basis is provided for the dynamic adjustment of the differential privacy parameter.
[0018] Optionally, the process of obtaining the depth of the associated information comprises:
[0019] The depth of the associated information D is calculated, wherein n is the number of condition identifications, i∈[1,n], is the judgment value of the i th condition identification, when the i th condition identification result is correct, ; otherwise, ; ; is the weight value of the i th condition identification;
[0020] The process of obtaining the spatial accuracy includes: determining the accuracy level of the position coordinates in the trajectory information based on the result of AI spatial dimension recognition, and determining the corresponding spatial accuracy based on the accuracy level;
[0021] The process of obtaining the time granularity value includes:
[0022] pass The time granularity value G is calculated, where T is the timestamp precision level in bits. s is the average time interval between timestamps, and s is the standard deviation of the interval between consecutive adjacent timestamps. As the first control function, This is the second control function. This is the third comparison function.
[0023] By adopting the above technical solutions, it is possible to judge the degree of privacy involved in trajectory data based on the depth of associated information D; it is possible to judge the sensitivity of trajectory data based on spatial accuracy; and through the process of obtaining the time granularity value G, it is possible to judge the degree of influence of timestamp accuracy, data continuity, and average timestamp interval on the sensitivity of trajectory data.
[0024] Optionally, the process of obtaining the dynamic risk index of trajectory data includes:
[0025] Based on the historical access information of the trajectory data for a preset time period before the current time point, establish a curve q(t) showing the change of the cumulative number of accesses over time, and obtain the maximum slope K of q(t) during the preset time period;
[0026] Through formula Calculate the dynamic risk index Where m is the total number of visits within the preset time period; This serves as a baseline reference value for the slope. The first adjustment factor is... The standard deviation of the time interval between consecutive adjacent access points. This is the reference value for the standard deviation.
[0027] By adopting the above technical solution, a dynamic risk index can be obtained. It can dynamically assess the risks of trajectory data and adjust the level of privacy protection accordingly.
[0028] Optionally, the process of determining the sensitivity classification of trajectory data also includes:
[0029] pass Calculate the sensitivity index R, and determine the corresponding sensitivity level based on the interval in which the sensitivity index R falls;
[0030] in, is a sensitivity reference index, is a normalized value of is a normalized value of
[0031] By adopting the above technical solution, the sensitivity state of the trajectory data is evaluated and classified by combining the sensitivity reference index with the dynamic risk index and further obtaining the sensitivity index R.
[0032] Optionally, the process of determining the risk value of each access user comprises:
[0033] determining the reference risk level of each access user according to the account information;
[0034] when the reference risk level of the access user is a low risk level, taking the reference risk value of the access user corresponding to the low risk level as the risk value of the access user;
[0035] otherwise, determining the risk value of the access user according to the reference risk value of the access user corresponding to the reference risk level and the access information of the access user.
[0036] By adopting the above technical solution, the efficiency of the access data risk judgment is improved through the preliminary screening process of the access user risk.
[0037] Optionally, the process of determining the risk value of the access user when the access user is not in the low risk level comprises:
[0038] judging whether the access user behavior triggers a preset event in the event trigger based on the event trigger, when the event is triggered, determining a first increment of the risk value corresponding to the triggered event;
[0039] determining a second increment of the risk value according to the access information of the access user, the process of calculating the second increment of the risk value comprises: obtaining a cumulative access frequency-time curve W(t) in a preset time period before a current time point of the access user, determining a maximum slope of the cumulative access frequency-time curve W(t) in the preset time period according to the cumulative access frequency-time curve W(t) , and calculating the second increment of the risk value by the formula ; wherein, W is the cumulative access frequency at the current time point, is an access frequency threshold, is a second adjustment coefficient, is an access amount slope reference value;
[0040] normalizing and accumulating the reference risk value of the access user, the first increment of the risk value and the second increment of the risk value respectively to obtain the risk value of the access user.
[0041] By adopting the technical solution, the security risk of the access user is determined by accessing the risk value of the access user, the differential privacy parameter of the trajectory data is determined according to the risk of the access user and the sensitivity classification of the trajectory data, and the privacy protection and sharing demand of the trajectory data are balanced.
[0042] Optionally, the process of dynamically adjusting the differential privacy parameter of the trajectory data comprises:
[0043] The sensitivity index R is compared with the weighted sum of the risk value of the access user and the preset threshold interval group, and the corresponding differential privacy parameter is determined according to the interval.
[0044] The differential privacy parameter comprises a noise injection size.
[0045] By adopting the technical solution, the privacy protection of the trajectory data in each data sharing access process can be dynamically adjusted according to the sensitivity classification and the risk degree of each access user, and the privacy protection and sharing demand of the trajectory data are balanced.
[0046] In summary, the present application includes at least one of the following beneficial technical effects:
[0047] The present application dynamically adjusts the privacy protection of the trajectory data in each data sharing access process by the sensitivity classification and the risk value of each access user, reduces the differential privacy parameter of the trajectory data when the data sensitivity is low and the risk of the access user is low, thereby improving the efficiency of the trajectory data sharing, increases the differential privacy parameter of the trajectory data when the data sensitivity is high and the risk of the access user is high, thereby protecting the privacy of the trajectory data, and balances the privacy protection and sharing demand of the trajectory data. BRIEF DESCRIPTION OF DRAWINGS
[0048] Figure 1 is a flow diagram of the trajectory privacy data protection and sharing method in the present application. DETAILED DESCRIPTION
[0049] The embodiments of the present application are described in detail below, and examples of the embodiments are shown in the accompanying drawings.
[0050] In the description of the present specification, the description referring to the terms "certain embodiments", "one embodiment", "some embodiments", "illustrative embodiments", "example", "specific example" or "some examples" means that the particular feature, structure, material or characteristic being described is included in at least one embodiment or example of the present application. The illustrative appearances of the above-mentioned terms in this specification are not necessarily referring to the same embodiment or example. Moreover, the described particular features, structures, materials or characteristics can be combined in any suitable manner in one or more embodiments or examples.
[0051] Embodiments of the present application disclose a method for protecting and sharing trajectory privacy data, referring to Figure 1comprises: sensitivity grading according to trajectory data and historical access information thereof; identifying the behavior of each access user through an event trigger, determining the risk value of each access user according to the identification result; and dynamically adjusting the differential privacy parameter of the trajectory data according to the risk value of each access user and the sensitivity of the access trajectory data of each access user. The embodiment judges the sensitivity of the trajectory data, grades the trajectory data according to the judgment result, judges the risk state of the access user, obtains the risk value, dynamically adjusts the trajectory data privacy protection of each data sharing access process through the sensitivity grading and the risk value of each access user, reduces the differential privacy parameter of the trajectory data when the data sensitivity is low and the access user risk is low, thereby improving the efficiency of trajectory data sharing, and increases the differential privacy parameter of the trajectory data when the data sensitivity is high and the access user risk is high, thereby realizing the protection of the privacy of the trajectory data and balancing the privacy protection and sharing demand of the trajectory data. The process of grading the sensitivity of the trajectory data comprises: condition recognition and spatial dimension recognition of the trajectory data based on AI, obtaining the correlation information depth and spatial accuracy, wherein the condition recognition mainly judges whether there is high-sensitivity private data in the trajectory data, for example, the identity information of a person, and the spatial dimension recognition mainly judges the accuracy of the spatial position in the trajectory data, for example, the accurate coordinate position and specific home address information are all high-sensitivity information. The above identification process can be identified and judged through the existing AI model. The AI model inputs the demand command and sets the corresponding rules, which will judge the time data and spatial data involved in the trajectory data one by one. For example, when the position data is accurate to the coordinates and the time data is accurate to the seconds, it means that the position data and the time data are high-sensitivity information. The implementation of this process relies on the basic functions of the AI model as an auxiliary use, which is not described in detail. Then, the time dimension analysis of the trajectory data is performed to obtain the time granularity value. The time granularity value reflects the continuity, timestamp accuracy and high frequency of the trajectory data in time. Therefore, the correlation information depth, spatial accuracy and time granularity value are weighted and summed. The weights corresponding to the correlation information depth, spatial accuracy and time granularity value are set according to the type of the result trajectory data and the experience data. Therefore, the weighted sum is used to comprehensively evaluate different factors of the sensitivity of the trajectory data to obtain the sensitivity benchmark index of the trajectory data. At the same time, the embodiment also dynamically evaluates the risk state of the trajectory data according to the historical access information of the trajectory data. The dynamic risk index of the trajectory data is obtained according to the historical access information of the trajectory data. Therefore, the dynamic risk index reflects the risk state of the trajectory data in a period of time. The sensitivity grading of the trajectory data is determined according to the sensitivity benchmark index and the dynamic risk index of the trajectory data. The sensitivity grading of the trajectory data can be adjusted in real time according to the content of the trajectory data and the real-time access data of the trajectory data, thereby providing a more accurate reference basis for the dynamic adjustment of the differential privacy parameter.
[0052] In one embodiment, the acquisition process of the correlation information depth is given, including: The correlation information depth D is calculated, where n is the number of condition identification items, i∈[1, n], The judgment value of the i-th condition identification, when the i-th condition identification result is consistent, ; otherwise, ; The weight value of the i-th condition identification, the weight value According to the type of the corresponding condition, when the privacy level involved in the corresponding condition is high, for example, the identity ID of the user is accessed, then the corresponding weight is higher, therefore through the correlation information depth D, the privacy level involved in the trajectory data can be further judged; in addition, the acquisition process of the spatial accuracy includes: determining the accuracy level of the position coordinates in the trajectory information according to the result of the AI spatial dimension identification, wherein the accuracy level includes the accurate coordinate level, the street level and the city level, wherein the accurate coordinate level can determine the specific position, the street level can determine the corresponding area, and the city level can determine the specific city, therefore the privacy level of each accuracy level is different, the corresponding spatial accuracy is determined according to the accuracy level, and then the trajectory data sensitivity is realized through the spatial accuracy; in addition, the acquisition process of the time granularity value includes: The time granularity value G is calculated, where T is the timestamp accuracy bit level, which includes second level, minute, hour level and day level, The first contrast function, which sets different influence coefficients according to the accuracy bit level of the timestamp, the size of the influence coefficient is set according to the test data, therefore the influence degree of the timestamp accuracy bit level T on the time granularity value G is determined, s is the standard deviation of the continuous adjacent timestamp interval length, when the continuity of the trajectory data is higher, then the sensitivity is relatively high, and on the basis of the determination of the average interval time of the timestamp, when the consistency of the continuous adjacent timestamp interval length is higher, it means that the continuity of the data is higher, wherein, The second contrast function, which sets different influence coefficients according to the distribution range of the standard deviation s in the test data and its contrast result, and then realizes the judgment of the time granularity value G through the standard deviation s of the continuous adjacent timestamp interval length; at the same time The average interval time of the timestamp, when the average interval time interval is smaller, the corresponding sensitivity is higher, and the third contrast function The corresponding influence coefficient is set according to the range of the different average interval time of the timestamp, the influence coefficient is set according to the test fitting, therefore through the acquisition process of the time granularity value G, the influence degree of the timestamp accuracy, data continuity and average interval time interval of the timestamp on the sensitivity of the trajectory data can be judged.
[0053] In one embodiment, a dynamic risk index obtaining process of trajectory data is given, which comprises: establishing an access cumulative number-time curve q(t) according to historical access information of trajectory data in a preset time period before a current time point, the preset time period is set according to experience, and a slope maximum value K of q(t) in the preset time period is obtained; a dynamic risk index is obtained by formula ; wherein m is the total number of accesses in the preset time period, is a slope reference value for normalizing the slope maximum value K, and the value is set according to empirical data, is a first adjustment coefficient for adjusting the weight of the data access amount surge rate and the data access amount, wherein formula is a simplified result, is a standard deviation of the interval length of continuous adjacent access time points, is a standard deviation reference value for adjusting the quantity parameter of , and the specific value is set according to empirical data, so that when the user access amount is high, the user access amount surges, and the access time is regular in the preset time period, it indicates that the risk of the trajectory data is greater, and the dynamic risk index obtained by obtaining can realize the judgment of the dynamic risk of the trajectory data, and further adjust the level of privacy protection according to it.
[0054] In one embodiment, the sensitivity grading process of the trajectory data further comprises: obtaining a sensitivity index R by formula ; and determining the corresponding sensitivity classification according to the interval in which the sensitivity index R is located; wherein is a sensitivity reference index, is a normalized value of , and is a normalized value of , so that by combining the sensitivity reference index and the dynamic risk index, the sensitivity index R is obtained to evaluate the sensitivity state of the trajectory data and grade it.
[0055] In one embodiment, a process for determining the risk value of each access user is provided, including: determining a baseline risk level based on the access user's account information; when the access user's baseline risk level is low risk, the baseline risk value corresponding to the low risk level is used as the access user's risk value; otherwise, the access user's risk value is determined based on the access user's baseline risk value corresponding to the access user's baseline risk level and their access information. Specifically, the access user's account ID is used to determine whether the access user is an authorized management access user or a whitelist access user. If so, the access user is considered to be at a low risk level. The risk level of the access user can also be determined based on factors such as the user's registration duration, access IP address used, and whether a proxy network is used. The specific determination methods are not elaborated here. Through the whitelist screening process and the preliminary risk assessment process, the efficiency of access data risk assessment is improved.
[0056] Furthermore, when a user's risk level is not low, the process of determining the user's risk value includes: judging whether the user's behavior triggers a preset event in the event trigger based on an event trigger; when the event is triggered, determining the corresponding first increment of the risk value based on the triggered event; wherein, the event trigger sets corresponding conditions based on historical experience data; when a user triggers the condition, it indicates that the user's risk is high; therefore, determining the corresponding first increment of the risk value based on the triggered event, and thus determining the degree of risk. Simultaneously, this embodiment also determines a second increment of the risk value based on the user's access information. The process of calculating the second increment of the risk value includes obtaining the cumulative access count over time curve W(t) within a preset time period before the current time point of the user, and determining the maximum slope value of the cumulative access count over time curve W(t) within the preset time period. Through formula Calculate the second increment of the risk value Where W represents the cumulative number of visits at the current time. The threshold for the number of visits, This is the second adjustment factor. As a benchmark reference value for the visit rate slope, among the above parameters, the visit count threshold... and visitor traffic slope benchmark reference value All settings are selected based on the average level of empirical data, used to compare the current number of visits and the slope of the visit volume to determine if the values are out of tolerance. (Second adjustment coefficient) The weight between the access times and the access volume surge speed is adjusted according to the risk access data fitting in the experience data, so that the access user benchmark risk value, the risk value first increment and the risk value second increment are normalized and accumulated respectively, and then the access user risk value is obtained, the security risk of the access user is determined through the access user risk value, the sensitivity classification of the risk and the trajectory data of the access user is determined, and then the differential privacy parameter of the trajectory data is determined, and the privacy protection and sharing demand of the trajectory data are balanced.
[0057] In one embodiment, the process of dynamically adjusting the differential privacy parameter of the trajectory data includes: comparing the weighted sum of the sensitivity index R and the access user risk value with the preset threshold interval group, and determining the corresponding differential privacy parameter according to the interval, wherein the weights of the sensitivity index R and the access user risk value corresponding to the weights are set according to the data range, so that the weighted sensitivity index R and the access user risk value have the same dimension, the preset threshold interval group is manually divided and set according to the fitting result of the experience data, different preset threshold intervals are set with corresponding differential privacy parameters, and the differential privacy parameter is the noise injection size, so when the weighted sum is high, the privacy security risk of the trajectory data is higher, so the corresponding noise injection is in a higher range, and through the above process, the privacy protection of the trajectory data in each data sharing access process can be dynamically adjusted according to the sensitivity classification and the risk value of each access user, and the privacy protection and sharing demand of the trajectory data are balanced.
[0058] Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and cannot be understood as limiting the present application, and those skilled in the art can make changes, modifications, replacements and variations to the above embodiments within the scope of the present application.
Claims
1. A method for protecting and sharing trajectory privacy data, characterized in that, The method comprises the following steps: sensitivity grading according to trajectory data and historical access information thereof; identifying the behavior of each access user through an event trigger, and determining the risk value of each access user according to the identification result; dynamically adjusting the differential privacy parameter of the trajectory data according to the risk value of each access user and the sensitivity of the access trajectory data thereof; The process of sensitivity grading of trajectory data comprises: based on AI, the conditional recognition and spatial dimension recognition of trajectory data are performed to obtain the depth of associated information and the spatial accuracy; time dimension analysis is performed on the trajectory data to obtain the time granularity value; the depth of associated information, the spatial accuracy and the time granularity value are weighted and summed to obtain the sensitivity benchmark index of the trajectory data; the dynamic risk index of the trajectory data is obtained according to the historical access information of the trajectory data; the sensitivity grading of the trajectory data is determined according to the sensitivity benchmark index and the dynamic risk index of the trajectory data; The process of obtaining the depth of associated information comprises: By The correlation information depth D is calculated, where n is the number of condition recognitions, i ∈ [1, n], is the judgment value of the i-th condition recognition, when the i-th condition recognition result is consistent, ; otherwise, ; is the weight value of the i-th condition recognition; The process of obtaining the spatial accuracy comprises: determining the accuracy level of the position coordinates in the trajectory information according to the result of AI spatial dimension recognition, and determining the corresponding spatial accuracy according to the accuracy level; The process of obtaining the time granularity value comprises: By a time granularity value G is computed, where T is the timestamp precision bit level, is the timestamp average interval time, s is the standard deviation of the interval duration between consecutive adjacent timestamps, is a first control function, is a second control function, is a third control function; The process of obtaining the dynamic risk index of the trajectory data comprises: establishing an access cumulative frequency-time variation curve q(t) according to the historical access information of the trajectory data in a preset time period before the current time point, and obtaining the maximum value K of the slope of q(t) in the preset time period; The dynamic risk index is calculated by the formula ; wherein m is the total number of accesses accumulated in a preset period, is a slope reference value, is a first adjustment coefficient, is a standard deviation of the interval duration between consecutive adjacent access time points, is a standard deviation reference value. 2. The method of claim 1, wherein, The process of determining the sensitivity grading of the trajectory data further comprises: By The sensitivity index R is calculated, and the corresponding sensitivity classification is determined according to the interval in which the sensitivity index R is located. wherein, is a sensitivity reference index, is is a normalized value of is is a normalized value of 3. The method of claim 2, wherein, The process of determining the risk value of each access user comprises: determining the benchmark risk level of each access user according to the account information: when the benchmark risk level of the access user is a low risk level, the benchmark risk value of the access user corresponding to the low risk level is taken as the risk value of the access user; otherwise, the risk value of the access user is determined according to the access information and the benchmark risk value of the access user corresponding to the benchmark risk level in which the access user is located.
4. The method of claim 3, wherein, The process of determining the risk value of the access user when the access user is not in the low risk level comprises: judging whether the behavior of the access user triggers a preset event in the event trigger based on the event trigger, when the event is triggered, determining a corresponding risk value first increment according to the triggered event; According to the access information of the access user, a risk value second increment is determined, and a process for calculating the risk value second increment comprises: obtaining a cumulative access frequency change curve W(t) with time in a preset time period before a current time point of the access user, and determining a maximum slope value of the cumulative access frequency change curve W(t) in the preset time period , and the risk value second increment is calculated by a formula ; wherein W is a cumulative access frequency at the current time point, is an access frequency threshold value, is a second adjustment coefficient, is an access amount slope reference value; the access user benchmark risk value, the risk value first increment and the risk value second increment are normalized and accumulated respectively to obtain the access user risk value.
5. The method of claim 4, wherein, The process of dynamically adjusting the differential privacy parameter of the trajectory data comprises: comparing the weighted sum of the sensitivity index R and the risk value of the access user with a preset threshold interval group, and determining the corresponding differential privacy parameter according to the interval in which it is located; The differential privacy parameter comprises noise injection size.
Citation Information
Patent Citations
Track release privacy protection method based on sensitivity analysis
CN117540411A
Privacy grading and sharing control method for tourist travel itinerary
CN120429889A