Safety processing method and device for user data, storage medium and electronic equipment
By encrypting the user data of the rental vehicle platform and generating fake location data, the risk of user data leakage during the query process is resolved, comprehensive protection of identity and location data is achieved, and data security is improved.
Patent Information
- Application Number
- CN202511002545.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-21
- Publication Date
- 2025-09-30
AI Technical Summary
Although existing encryption algorithms improve data security when processing user data on rental vehicle platforms, there is still a risk of leakage when querying location data. In particular, user location data is difficult to effectively protect during data sharing and querying.
Sensitive identity data is encrypted, and the location data required to initiate a query is generalized. Multiple fake location data are used to hide the real location data, and a target data set containing real and fake locations is generated to execute the query request.
By encrypting identity data and using fake location data to obfuscate the real location, comprehensive protection of users' multi-faceted privacy data is achieved, the security of location data is improved, and the leakage of real location is avoided.
Smart Images

Figure CN120729607A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing technology, and in particular to a method, device, storage medium and electronic device for securely processing user data. Background Art
[0002] When renting a vehicle, users are required to provide the rental platform with sensitive data such as personal information and driving qualifications. Furthermore, during the use of the rental vehicle, users also generate data such as their travel history. Car rental platforms must ensure the compliance management of this user data and provide a full lifecycle security strategy, which is a core requirement for ensuring user data security. Summary of the Invention
[0003] To solve the above problems, an object of the embodiments of the present invention is to provide a method, apparatus, storage medium and electronic device for securely processing user data.
[0004] In a first aspect, an embodiment of the present invention provides a method for securely processing user data, including: Obtaining target user data to be processed; the target user data includes target identity data and target location data; Encrypting the target identity data to generate and save encrypted identity data; In response to a target query request initiated according to the target location data, generating false location data corresponding to the target location data; A target data set including the target location data and at least a portion of the pseudo location data is determined, and query processing corresponding to the target query request is performed according to the target data set.
[0005] In a second aspect, an embodiment of the present invention further provides a device for securely processing user data, comprising: An acquisition module, configured to acquire target user data to be processed; the target user data includes target identity data and target location data; An encryption module, used to encrypt the target identity data, generate and save the encrypted identity data; a location generating module, configured to generate false location data corresponding to the target location data in response to a target query request initiated according to the target location data; The processing module is configured to determine a target data set including the target location data and at least a portion of the pseudo location data, and perform query processing corresponding to the target query request according to the target data set.
[0006] In a third aspect, an embodiment of the present invention further provides a computer storage medium, wherein the computer storage medium stores computer-executable instructions, and the computer-executable instructions are used for any of the above-mentioned methods for securely processing user data.
[0007] In a fourth aspect, an embodiment of the present invention further provides an electronic device, including: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute any one of the above-mentioned methods for securely processing user data.
[0008] In the solution provided in the first aspect of the embodiment of the present invention, sensitive identity data is encrypted, and the location data required for querying is generalized. Multiple fake location data are used to hide the real location data, thereby protecting the location data. This fully protects multiple aspects of the user's privacy data and effectively ensures user data security. By obfuscating the user's real location coordinates with multiple fake location coordinates, unauthorized users cannot distinguish between the real location data and the fake location data, thus achieving the purpose of data generalization and effectively improving the security of location data during querying. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0010] Figure 1 A flowchart of a method for securely processing user data provided by an embodiment of the present invention is shown; Figure 2 A flowchart showing another method for securely processing user data provided by an embodiment of the present invention is shown; Figure 3 A schematic diagram of verifying an identity card number according to an embodiment of the present invention is shown; Figure 4 A schematic diagram showing the distribution of position coordinates provided by an embodiment of the present invention is shown; Figure 5 A schematic diagram of screening undetermined position coordinates provided by an embodiment of the present invention is shown; Figure 6A schematic diagram of generating a target data set according to an embodiment of the present invention is shown; Figure 7 A schematic structural diagram of a user data security processing device provided by an embodiment of the present invention is shown; Figure 8 A schematic structural diagram of an electronic device provided by an embodiment of the present invention is shown. DETAILED DESCRIPTION
[0011] In the description of the present invention, the terms "first" and "second" are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of the technical features indicated. Therefore, a feature specified as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of the present invention, "plurality" means two or more, unless otherwise specifically defined.
[0012] When renting a vehicle, users need to provide the rental platform with personal information such as mobile phone number and ID number, as well as driving qualification information such as driver's license number. After obtaining explicit authorization from the user (such as checking "Agree to Data Collection Agreement"), the rental platform will collect personal information, driving qualification information and other data required for renting a vehicle. These data involve the user's privacy and need to be processed securely to avoid problems such as user privacy leaks.
[0013] Furthermore, users typically regularly report the location of their rental vehicles, generating real-time data such as their travel history. Car rental platforms need to securely store user data and prevent data leaks when using it, ensuring compliance management.
[0014] For example, the car rental platform needs to share data with other partners (such as insurance companies, other car rental platforms, etc.), and may need to share user identity information at this time; in addition, the car rental platform may need to provide users' travel trajectory data to other third-party services (such as map service providers, weather services), etc., to meet information query needs.
[0015] Currently, encryption algorithms are commonly used to encrypt user data to ensure data security. Examples include SM4 (the pinyin abbreviation for Shang Mi, representing the fourth generation of commercial encryption) and AES (Advanced Encryption Standard). While these encryption algorithms can improve data security, queries based on user location data still require the provision of unencrypted raw data, posing the risk of data leakage.
[0016] This embodiment of the present invention provides a method for securely processing user data. It encrypts sensitive identity data, generalizes the location data required for querying, and uses multiple fake location data to hide the actual location data, thereby protecting the location data. This method can comprehensively protect multiple aspects of a user's private data and effectively ensure user data security.
[0017] This embodiment provides a method for securely processing user data, which can be applied to a car rental platform. Figure 1 FIG. 1 is a flow chart showing a method for securely processing user data according to an embodiment of the present invention. Figure 1 As shown, the method includes the following steps.
[0018] Step 101: Acquire target user data to be processed; the target user data includes target identity data and target location data.
[0019] When renting a car, the car rental user needs to provide identity-related data, such as the car rental user's mobile phone number, ID number, etc. For the convenience of description, the car rental user is called the target user. Accordingly, the target user can provide identity data related to himself, that is, the target identity data.
[0020] Furthermore, during subsequent use of the rental vehicle, the target user can periodically or on demand report their current location data, i.e., the target location data. For example, when searching for nearby gas stations or vehicle return points, the user can report their current target location data.
[0021] It can be understood that the above-mentioned target user data is obtained legally in accordance with relevant laws and regulations, and the above-mentioned target user data needs to be authorized by the user, and the user must be informed of the scope of use, usage scenarios, etc. of the target user data.
[0022] Step 102: Encrypt the target identity data to generate and save the encrypted identity data.
[0023] In this embodiment, since the target identity data is fixed and its data volume is relatively small, the target identity data of the target user is encrypted to obtain encrypted identity data. By storing the encrypted identity data, the security of the target identity data is improved.
[0024] For example, the target identity data may be encrypted based on a preset symmetric encryption algorithm. This embodiment does not limit the specific encryption method.
[0025] Step 103: In response to a target query request initiated according to the target location data, generate pseudo location data corresponding to the target location data.
[0026] In this embodiment, the target user can report his or her target location data in real time, and the car rental platform can save this target location data; in addition, based on actual needs, the target user can actively or periodically initiate a query request containing the target location data, that is, a target query request, and the car rental platform can also obtain the corresponding target location data.
[0027] For example, the target user can initiate navigation requests, query nearby car repair points, car return points, and other target query requests.
[0028] After receiving a target query request including target location data, if the target location data needs to be provided to a third-party service, false location data corresponding to the target location data, ie, fake location data, is generated.
[0029] For example, a plurality of false positions may be generated around the target position data, and the coordinate data corresponding to these false positions may be used as the false position data.
[0030] Step 104: Determine a target data set including the target location data and at least part of the false location data, and perform query processing corresponding to the target query request according to the target data set.
[0031] In this embodiment, when responding to the target query request, some or all of the generated fake location data is selected and added to the actual target location data to obtain a dataset for subsequent use, namely the target dataset. It will be understood that this target dataset includes the actual location and multiple fake locations. Subsequent query processing corresponding to the target query request is performed based on this target dataset, making it impossible to distinguish between the real and fake locations during the query, thereby concealing the actual location and preventing its disclosure.
[0032] In this embodiment, each location data item includes corresponding location coordinates, wherein the target location data includes the current, true target location coordinates, and the false location data includes multiple false location coordinates. A target dataset can be generated based on a K-anonymity algorithm. Specifically, appropriate K-1 false location coordinates can be selected from the false location data and combined with the true target location coordinates to generate the target dataset. That is, the target dataset contains a total of K location coordinates, only one of which is true. Subsequent query operations based on this target dataset cannot directly obtain the true target location coordinates from the K location coordinates.
[0033] For example, a target dataset containing K location coordinates can be sent to a third-party service, instructing it to return query results corresponding to the K location coordinates. The car rental platform then selects the actual query results corresponding to the target location coordinates and returns them to the target user. This ensures that the query is completed while preventing the leakage of the true location coordinates. The specific value of K can be determined based on actual circumstances and is not limited in this embodiment.
[0034] The user data security processing method provided by the embodiments of the present invention encrypts sensitive identity data and generalizes the location data required for query initiation, using multiple fake location data to hide the real location data to achieve location data protection. This can comprehensively protect multiple aspects of user privacy data and effectively ensure user data security. By obfuscating the user's real location coordinates with multiple fake location coordinates, unauthorized users cannot distinguish between the real location data and the fake location data, achieving the purpose of data generalization and effectively improving the security of location data during query.
[0035] This embodiment provides a method for securely processing user data, which can be applied to a car rental platform. Figure 2 FIG. 1 is a flow chart showing a method for securely processing user data according to an embodiment of the present invention. Figure 2 As shown, the method includes the following steps.
[0036] Step 201: Acquire target user data to be processed; the target user data includes target identity data and target location data.
[0037] For details, please refer to Figure 1 The description of step 101 in the illustrated embodiment will not be repeated here.
[0038] Step 202: Encrypt the target identity data to generate and save the encrypted identity data.
[0039] For details, please refer to Figure 1 The description of step 102 in the illustrated embodiment will not be repeated here.
[0040] In some optional implementations, the target identity data includes: at least one of a real first ID card number, a first mobile phone number, and a first driver's license number.
[0041] The above-mentioned step 202 "encrypting the target identity data" may include: encrypting at least one of the first ID card number, encrypting the first mobile phone number, and encrypting the first driver's license number.
[0042] The encryption process of the first ID number includes: Step A1: Convert the first ID card number into a second ID card number that complies with the ID card number format, and encrypt the second ID card number; the second ID card number is different from the first ID card number.
[0043] Encrypt the first mobile phone number, including: Step A2: Convert the first mobile phone number into a second mobile phone number that conforms to the mobile phone number format, and encrypt the second mobile phone number; the second mobile phone number is different from the first mobile phone number.
[0044] Encrypt the first driver's license number, including: Step A3: Convert the first driver's license number into a second driver's license number that complies with the driver's license number format, and encrypt the second driver's license number; the second driver's license number is different from the first driver's license number.
[0045] In this embodiment, the target identity data includes real ID numbers, mobile phone numbers, and driver's license numbers. For ease of description, these real ID numbers, mobile phone numbers, and driver's license numbers are referred to as the first ID number, first mobile phone number, and first driver's license number, respectively. These real ID numbers are first converted to different ID numbers and then encrypted to further enhance their security.
[0046] Taking the ID card number as an example, the first ID card number is converted into another ID card number that conforms to the ID card number format, that is, the second ID card number, which is different from the first ID card number. The converted second ID card number is then encrypted and the encrypted result of the second ID card number is subsequently saved.
[0047] It is understandable that for situations where real user data is required, such as real-name verification, the real first ID number must still be used for processing. When the ID number is needed internally, a false second ID number can be provided to prevent the real first ID number from being leaked. Alternatively, even if an illegal person cracks the ID number encryption method, the second ID number obtained is a false one. Since the second ID number conforms to the ID number format, the illegal person cannot easily determine that the second ID number is false, reducing the illegal person's motivation to reversely deduce the first ID number from the second ID number, thereby reducing the possibility of the first ID number being leaked.
[0048] For mobile phone numbers, driver's license numbers, etc., the encryption principle is the same as that of ID card numbers, so I will not go into details here.
[0049] Alternatively, since the formats of mobile phone numbers and driver's license numbers are relatively simple, it's relatively easy to generate a fake mobile phone number (i.e., a second mobile phone number) and a fake driver's license number (i.e., a second driver's license number). For example, the fake mobile phone number and fake driver's license number can be randomly generated. However, the format of the ID card number is relatively special and is not suitable for random generation. It is necessary to ensure that the checksum of the last digit of the ID card number is correct. In this embodiment, step A1, "Converting the first ID card number into a second ID card number that conforms to the ID card number format," includes steps A11 through A16.
[0050] Step A11: Extract the values corresponding to the 7th to 14th digits of the first ID number and calculate the corresponding first check value; the first check value C1 is: ; n7, n8, ..., n 14 These are the values corresponding to the 7th to 14th digits in the first ID number, and mod() represents the remainder function.
[0051] Since the last digit of the ID number is the verification code, the specific value of the verification code is related to the previous 17 digits. Figure 3 A schematic diagram of verifying the ID number is shown. Figure 3 As shown, for the ID number, its first 17 digits need to be multiplied by different coefficients, and the coefficients from the first to the 17th digit are: 7, 9, 10, 5, 8, 4, 2, 1, 6, 3, 7, 9, 10, 5, 8, 4, 2; the first 17 digits of the ID number are multiplied by the corresponding coefficients, and the multiplication results are added. Finally, the added result is divided by 11, and the remainder corresponds to the check code. Specifically, the remainder can only be 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10. Each remainder corresponds to the last digit of the ID number: 1, 0, X, 9, 8, 7, 6, 5, 4, 3, 2.
[0052] by Figure 3 Taking the ID number 123456 20000101 7892 shown as an example, the result of multiplying the first 17 digits by the coefficient, summing them and taking the remainder is 10, so the last check digit is 2.
[0053] In this embodiment, only the year and date in the first ID number are replaced to generate the second ID number, that is, only the 7th to 14th digits in the first ID number are replaced.
[0054] It can be proved that for any two numbers x and y, taking the remainder of their sum and taking the remainder of each separately and then summing them up will give the same remainder, that is, it satisfies: .
[0055] In this embodiment, first calculate the first check value C1 corresponding to the 7th to 14th digits in the first ID number; Figure 3 As shown, it can be calculated based on the corresponding coefficients. Figure 3 Taking 20000101 as an example, the first check value is 7.
[0056] If only the 7th to 14th digits in the first ID number are replaced, it is only necessary to ensure that the remainder of the corresponding values of the 7th to 14th digits after replacement divided by 11 is equal to the first verification value C1. At this time, it can be guaranteed that the verification code of the last digit of the second ID number obtained after replacement is correct.
[0057] Step A12: Calculate the three-digit year parameter according to the first preset value, and the three-digit year parameter for: ; The first three digits of the current year, Num1 is the first preset value, and Div1 is the preset fixed parameter.
[0058] Step A13: Calculate the date parameter according to the second preset value, and the date parameter for: ; Num2 is the second preset value, A mapping function that maps a number to a four-digit date format.
[0059] Step A14: Based on the year parameter and date parameters Calculate the corresponding second check value; the second check value C2 is: ; Among them, y1, y2, and y3 are year parameters The first, second, and third digit values of the date; d1, d2, d3, and d4 are date parameters respectively. The first, second, third, and fourth digit values of the .
[0060] In this embodiment, since the 7th to 14th digits in the ID number represent the user's date of birth, which has certain constraints, this embodiment divides these eight digits (i.e., the 7th to 14th digits) into three parts: the first part is the first three digits, i.e., the 7th to 9th digits; the second part is the 10th digit with a higher degree of freedom; and the third part is the last four digits, i.e., the 11th to 14th digits.
[0061] The first three digits of the current year must meet the year format requirements. For example, if this year is 2025, then A first preset value Num1 and a fixed parameter Div1 are preset; wherein, the first preset value Num1 may be a fixed value that needs to be kept confidential, or may be a value obtained based on other encryption methods, which is not limited in this embodiment.
[0062] The fixed parameter Div1 is used to convert the first preset value Num1 to a value that meets the year requirement. For example, due to the human lifespan, the span of user birth dates is not very large, so the fixed parameter Div1 is set based on the human lifespan. For example, if the human lifespan is 100 years, the fixed parameter Div1 can be set to 10.
[0063] In addition, users on the car rental platform are generally users with a driver's license and are required to be over 18 years old, so the first three digits of the current year are Subtract 2 from the value of the second ID number, and try to ensure that the age corresponding to the birth year in the second ID number is greater than 18. Based on this, we can get the three-digit year parameter , the year parameter It can be used as the 7th to 9th digits of the second ID number.
[0064] For the date in the ID number, directly take the remainder of 365 based on the second preset value Num2, and then map the date parameter of the four-digit date format based on the remainder result. For example, the function It can be said that the number 0 is mapped to 0101, the number 1 is mapped to 0102, ..., and the number 364 is mapped to 1231.
[0065] The second preset value Num2 is similar to the first preset value Num1 and can be a fixed value or obtained through encryption. For example, the second preset value Num2 can also be the same as the first preset value Num1.
[0066] Step A15: Determine an adjustment value based on the difference between the first check value C1 and the second check value C2; the adjustment value r 10 satisfy: .
[0067] Step A16: Replace the 7th to 9th digits of the first ID number with the year parameter The first, second, and third digits of the first ID number are replaced with the adjusted value, and the 11th to 14th digits of the first ID number are replaced with the date parameters. The first, second, third and fourth digits of the ID card are combined to obtain the second ID card number.
[0068] In this embodiment, the 10th digit in the second ID number is used for calibration, and selecting a suitable value can ensure that the final check code of the second ID number is correct.
[0069] Specifically, if , then the adjustment value r 10It can be used as the 10th digit of the second ID number. Replace the 7th to 9th digits of the first ID number with the year parameter The first, second, and third digits of the first ID number are replaced with the adjusted value, and the 11th to 14th digits of the first ID number are replaced with the date parameters. The first, second, third and fourth digits of the ID number can be replaced as the second ID number.
[0070] For example, if the first ID number is Figure 3 The ID number shown is processed based on the 7th to 14th digits 20000101 to obtain the year parameter , date parameter , the second check value C2 = 2 can be obtained by calculation; and the first check value C1 = 7, based on which the adjustment value r can be calculated 10 =9, so we can determine that the second ID number is: 123456 19990312 7892.
[0071] After the above conversion, a second ID card number that meets the ID card format requirements can be obtained, and the verification code of the last digit in the second ID card number is correct.
[0072] Optionally, the above step A1 of "converting the first ID card number into a second ID card number that conforms to the ID card number format" further includes steps A17 and A18: Step A17: After determining the first check value C1 and the second check value C2, determine Is it 8? If the value is not 8, the adjustment value is determined according to the difference between the first check value C1 and the second check value C2, that is, the subsequent steps A15 and A16 are executed; If it is 8, execute step A17.
[0073] Step A17: When the value is 8, the year parameter Performing a subtraction process to update the year parameter, and determining a new adjustment value based on the updated year parameter; Replace the 7th to 9th digits of the first ID number with the first, second, and third digits of the updated year parameter, replace the 10th digit of the first ID number with the new adjusted value, and replace the 11th to 14th digits of the first ID number with the date parameter. The first, second, third and fourth digits of the ID card are combined to obtain the second ID card number.
[0074] In this embodiment, since the 10th digit of the ID card number can only be any value between 0 and 9, and the divisor when calculating the check value is 11; if only the 10th digit (i.e. the adjustment value r 10 ) to adjust the check value, there is a case where the final check value does not meet the requirements. It can be proved that for the 10th digit of the ID number, after multiplying it by 3 and dividing it by 11, the remainder cannot be 8. Therefore, if , then no matter how you set the adjustment value r 10 The size of the year parameter cannot meet the requirements of the check code. , adjustment value r 10 , date parameters The determined check value must be different from the first check value C1.
[0075] Therefore, if , then by choosing a suitable adjustment value r 10 , it is ensured that the new year, month, and day (eight digits) and the year, month, and day in the first ID number (i.e., digits 7 to 14) have the same check value, namely, the first check value C1. Therefore, the second ID number can be generated according to steps A15 and A16.
[0076] On the contrary, if , the year parameter Subtract one, which not only ensures the rationality of the new year, but also The third digit of is reduced, and the corresponding coefficient is 6, so the second check value C2 is reduced by 6, that is, Increased by 6. Because , so at this time ; Combined with the coefficient of the 10th bit being 3, the 10th bit should be 1, which is the new adjustment value r 10 = 1. Then use the updated year parameter and the new adjustment value r 10 (For example 1), etc., you can get the second ID number that meets the requirements.
[0077] It is understandable that if the year parameter If the third digit is 0, then the year parameter After subtracting one, it is necessary to determine the appropriate adjustment value r based on the adaptability of the new second check value corresponding to the updated year parameter. 10 That’s it, I won’t go into details here.
[0078] Step 203: In response to the target query request initiated according to the target location data, generate pseudo location data corresponding to the target location data.
[0079] For details, please refer to Figure 1 The description of step 103 in the illustrated embodiment will not be repeated here.
[0080] Step 204: Determine a target data set including the target location data and at least part of the false location data, and perform query processing corresponding to the target query request according to the target data set.
[0081] Specifically, as shown above, the target position data includes the current target position coordinates, and the false position data includes multiple false position coordinates. Figure 2 As shown, step 204 “determine a target data set including target location data and at least part of false location data” may include steps 2041 to 2045 .
[0082] Step 2041: multiple false position coordinates in the false position data whose distances from the target position coordinates are less than a preset threshold are used as candidate position coordinates; the number of candidate position coordinates is M.
[0083] In this embodiment, the fake location data includes multiple fake location coordinates. These fake location coordinates can be randomly generated or generated based on the real location coordinates of the previous query request. This embodiment does not limit the method of generating the fake location coordinates.
[0084] In order to quickly determine the appropriate target data set, we first determine the distance between each false position coordinate and the real target position coordinate. If the distance is less than the preset threshold, it means that the false position coordinate is relatively close to the real target position coordinate and is more easily confused. Therefore, the false position coordinate can be used as the position coordinate to be used later, that is, the candidate position coordinate.
[0085] The number of candidate position coordinates is M, where M≥2, meaning that multiple candidate position coordinates need to be selected first.
[0086] Step 2042: Generate multiple different first data sets; the first data set includes the target position coordinates and N-1 candidate position coordinates; N <M。
[0087] From the M candidate location coordinates that have been screened, N-1 candidate location coordinates are randomly selected and combined with the actual target location coordinates to obtain a dataset containing N location coordinates, i.e., the first dataset. Different first datasets can be obtained by selecting different candidate location coordinates.
[0088] It is understandable that for any two first data sets, the N-1 candidate position coordinates contained therein are not exactly the same; in other words, for any two first data sets, there is at least one candidate position coordinate in one first data set that does not exist in the other first data set.
[0089] Step 2043: For each first data set, determine an evaluation index of the first data set; the evaluation index is used to represent the distribution of query requests corresponding to each position coordinate in the first data set.
[0090] Each first data set includes N location coordinates (including one target location coordinate and N-1 candidate location coordinates), and each location coordinate may correspond to a certain number of query requests. In this embodiment, an indicator for evaluating the uniformity of the query request distribution of the first data set, i.e., an evaluation indicator, is determined based on the distribution of query requests corresponding to each location coordinate in the first data set.
[0091] Since the first data set contains N-1 false candidate location coordinates, these candidate location coordinates may be inappropriate. For example, the real target location coordinates are coordinates on the road, while the candidate location coordinates are coordinates in a lake or the sea. Since vehicles generally do not enter a lake or the sea, such candidate location coordinates are invalid. Moreover, since there are basically no query requests for such candidate location coordinates, the corresponding query requests are basically 0.
[0092] In this embodiment, the number of query requests corresponding to each location coordinate is analyzed to calculate the evaluation index of each first data set, and a more realistic first data set can be selected based on the evaluation index.
[0093] The number of query requests for a certain location coordinate may be determined based on historical data.
[0094] For example, Figure 4 A distribution diagram of position coordinates is shown. Figure 4 As shown in , the black triangle represents the real position, and its coordinates are the target position coordinates. The circle represents the virtual position, and each virtual position corresponds to a false candidate position coordinate. Figure 4 As shown, the entire location area is divided into multiple sub-areas. Figure 4 In the example, 6×10 square areas are divided into the sub-areas. For each sub-area, the number of query requests that have been initiated in the sub-area can be determined and used as the number of query requests for each position coordinate in the sub-area.
[0095] Optionally, the evaluation indicator is: .
[0096] Among them, Ind represents the evaluation index of the first data set; n i Indicates the number of query requests corresponding to the i-th position coordinate in the first data set, n j represents the number of query requests corresponding to the j-th location coordinate in the first data set; N is the number of location coordinates in the first data set.
[0097] In this embodiment, the first data set includes N position coordinates, and the number of query requests corresponding to each position coordinate can be determined; and for the j-th position coordinate in the first data set, the number of query requests is n i , and its corresponding query request ratio is .
[0098] Moreover, information entropy is used as an indicator to measure the distribution of query requests. Based on the information entropy formula, the evaluation index is: The larger the evaluation index Ind is, the higher the uncertainty between the user's real location and other false locations, and the more difficult it is for illegal attackers to determine the real target location coordinates (for example, it is difficult to find the characteristics of the real location through statistical query requests). This can ensure better privacy and better protection of location data.
[0099] Step 2044: Eliminate the target position coordinates in the first data set with the largest evaluation index to obtain a second data set.
[0100] As shown above, the larger the evaluation index, the better the first dataset protects the location data. Therefore, the first dataset with the largest evaluation index is preferentially used. Furthermore, the true target location coordinates in the first dataset are extracted, that is, only N-1 false candidate location coordinates are retained, thereby obtaining the second dataset. In other words, the second dataset only includes the N-1 false candidate location coordinates from the first dataset with the largest evaluation index.
[0101] Step 2045: Select K-1 candidate position coordinates from the second data set to generate a target data set including the target position coordinates and the K-1 candidate position coordinates.
[0102] In this embodiment, the N-1 candidate location coordinates in the second dataset are further screened to select K-1 candidate location coordinates. It will be appreciated that K is less than N, and K ≥ 2. After selecting K-1 candidate location coordinates, combined with the true target location coordinates, a target dataset is obtained. This target dataset includes one target location coordinate and K-1 candidate location coordinates, for a total of K location coordinates. When query processing is subsequently performed based on this target dataset, there is only a 1 / K probability of determining the true target location coordinates.
[0103] For example, any K-1 candidate position coordinates and target position coordinates may be determined again to calculate the evaluation index, and the K-1 candidate position coordinates corresponding to the maximum evaluation index may be finally selected as the K-1 candidate position coordinates of the target data set.
[0104] Optionally, the above step 2045 of “selecting K-1 candidate position coordinates from the second data set” may include steps B1 and B2.
[0105] Step B1: Determine a historical data set corresponding to a historical query request, where the historical data set includes real historical location coordinates and K-1 false first location coordinates.
[0106] Step B2: for any first position coordinate, determine a second position coordinate in the second data set corresponding to the path of the first position coordinate; the second position coordinate is one of K-1 candidate position coordinates selected from the second data set; The process of "determining the second position coordinates corresponding to the first position coordinate path in the second data set" in step B2 specifically includes the following steps B21 to B23.
[0107] Step B21: For any pending position coordinate in the second data set, determine the distance between the first position coordinate and the pending position coordinate, and the angle between the first path from the first position coordinate to the pending position coordinate and the second path from the historical position coordinate to the target position coordinate.
[0108] Step B22: When the distance is less than the preset distance value and the included angle is less than the preset angle, determine the transition probability of moving from the first position coordinate to the to-be-determined position coordinate.
[0109] Step B23: taking the undetermined position coordinate with the maximum transfer probability as the second position coordinate corresponding to the first position coordinate path.
[0110] In this embodiment, if the current time is time t, the dataset used for the query at the previous time (i.e., time t-1) can be determined, i.e., the historical dataset. Similar to the target dataset, this historical dataset also includes one true location coordinate and K-1 false location coordinates, i.e., the true historical location coordinate and K-1 false first location coordinates. It will be appreciated that if no historical dataset exists, other methods can be used to determine the target dataset, such as randomly selecting K-1 candidate location coordinates.
[0111] For ease of description, Represents the real historical position coordinates at time t-1. Similarly, represents the real position coordinates at time t, i.e. the target position coordinates. 、 、…、 etc. represent K-1 false first position coordinates.
[0112] For any first position coordinate , i=1,2,…,K-1, a suitable candidate position coordinate can be selected from the N-1 candidate position coordinates of the second data set, and the candidate position coordinate is used as the candidate position coordinate required at time t, that is, the second position coordinate.
[0113] As shown in steps B21 to B23, for the first position coordinate , the first position coordinates can be calculated Any undetermined position coordinates in the second dataset The distance between them, where j=1,2,…,N-1. And, from the first position coordinate To the undetermined location coordinates A moving path, namely the first path, can be determined, and, from the historical position coordinates To target position coordinates A movement path, namely the second path, may also be determined, and the angle between the two paths may then be determined.
[0114] It can be understood that the “pending position coordinates” are also “candidate position coordinates”. Just to distinguish the description, the candidate position coordinates in the second data set are referred to as pending position coordinates.
[0115] Figure 5 A schematic diagram of screening the coordinates of pending positions is shown. Figure 5 As shown, for the undetermined position coordinates in the second data set , according to the first position coordinates and the coordinates of the undetermined position The coordinate values of the first position are used to calculate the distance L (e.g., Euclidean distance) between the two positions; and With the undetermined position coordinates The first path is between them, the length of which is L, and the historical position coordinates and target position coordinates The second path is between the first path and the second path, and the angle between the first path and the second path is θ.
[0116] Under normal circumstances, the distance L cannot be too large, for example, it cannot exceed the maximum distance traveled from time t-1 to time t when the vehicle is traveling at maximum speed. Furthermore, the angle θ cannot be too large, otherwise it will indicate that the false first path deviates too much from the true second path, making it easy for an unauthorized person to propose a false first path. The values of the preset distance (e.g., maximum speed) and preset angle can be determined based on actual circumstances. For example, the maximum speed can be 120 km / h, and the preset angle can be 60°. This embodiment does not limit this.
[0117] Therefore, if the distance L is greater than the preset distance value, or the angle θ is greater than the preset angle, it means that the coordinates of the undetermined position are With the first position coordinates If it does not match, the pending position coordinates can be ignored. On the contrary, if the distance L is less than the preset distance value and the angle θ is less than the preset angle, the coordinates of the pending position can be determined. Can it be used as the final second position coordinate?
[0118] Specifically, it can be determined from the first position coordinates Move to the undetermined position coordinates The probability of the transition is the transition probability. The transition probability can be determined based on the distance between the two, the angle with the second path, etc., or other parameters such as the number of query requests. This embodiment does not limit the specific calculation method of the transition probability. The larger the transition probability, the more likely it is to go from the first position coordinate to the next position. Move to the undetermined position coordinates , so the undetermined position coordinate with the largest transfer probability is taken as the second position coordinate corresponding to the first position coordinate path.
[0119] After the above processing, the first position coordinates can be determined A corresponding second position coordinate. For any first position coordinate , that is, when i takes any value among 1, 2, ..., K-1, the corresponding second position coordinates can be determined, and a total of K-1 second position coordinates are obtained. The K-1 second position coordinates are the final K-1 candidate position coordinates, combined with the target position coordinates , we can get the target data set containing K location coordinates, and then perform the corresponding query processing operations.
[0120] Figure 6 A schematic diagram of generating a target dataset based on a historical dataset is shown in FIG. Figure 6 As shown, the paths corresponding to each location coordinate are the same as those from the historical location coordinates. To target position coordinates The second path is relatively close, and it is difficult for illegal attackers to distinguish the authenticity of the location coordinates from the path, thereby avoiding the problem that when the user initiates query requests multiple times, the path corresponding to the location coordinates is excluded by the illegal attacker, which leads to the leakage of the real path and real location.
[0121] In the embodiment of the present invention, multi-faceted protection of user data can be achieved, and by constructing false location coordinates, an abstract description of the location coordinates can be achieved, and external illegal users cannot distinguish the real data, thereby improving the security of the location data. When constructing the target data set, the candidate location coordinates are first preliminarily screened out based on the distance between the location coordinates, and then the evaluation parameters are used to further screen out the appropriate N-1 candidate location coordinates, and finally the final required K-1 candidate location coordinates are selected from them. This not only ensures that the selected candidate location coordinates can generalize the real target location coordinates, but also ensures the screening efficiency through multi-layer screening. Determining the current target data set based on the previous historical data set can ensure that the path changes corresponding to the location coordinates are reasonable, and can minimize the situation where the real location is broken into by illegal users due to the exclusion of unreasonable paths.
[0122] The above describes in detail the process of the method for securely processing user data. This method can also be implemented by a corresponding device. The structure and function of the device are described in detail below.
[0123] Based on the same inventive concept, the embodiment of the present invention also provides a user data security processing device, see Figure 7 As shown, the device includes: An acquisition module 71 is configured to acquire target user data to be processed; the target user data includes target identity data and target location data; An encryption module 72 is used to encrypt the target identity data, generate and save the encrypted identity data; a location generating module 73 for generating false location data corresponding to the target location data in response to a target query request initiated according to the target location data; The processing module 74 is configured to determine a target data set including the target location data and at least a portion of the pseudo location data, and perform query processing corresponding to the target query request according to the target data set.
[0124] Optionally, the target identity data includes: at least one of a real first ID card number, a first mobile phone number, and a first driver's license number; The encrypting the target identity data includes: encrypting at least one of the first ID card number, the first mobile phone number, and the first driver's license number; The encrypting of the first ID number includes: converting the first ID number into a second ID number that conforms to an ID number format, and encrypting the second ID number; the second ID number is different from the first ID number; The encrypting of the first mobile phone number includes: converting the first mobile phone number into a second mobile phone number that conforms to a mobile phone number format, and encrypting the second mobile phone number; the second mobile phone number is different from the first mobile phone number; The encryption processing of the first driver's license number includes: converting the first driver's license number into a second driver's license number that conforms to the driver's license number format, and encrypting the second driver's license number; the second driver's license number is different from the first driver's license number.
[0125] Optionally, converting the first ID card number into a second ID card number that conforms to an ID card number format includes: Extract the values corresponding to the 7th to 14th digits of the first ID number and calculate the corresponding first check value; the first check value C1 is: ; n7, n8, ..., n 14 are the values corresponding to the 7th to 14th digits in the first ID number, respectively, and mod() represents the remainder function; The three-digit year parameter is calculated according to the first preset value, and the three-digit year parameter for: ; is the first three digits of the current year, Num1 is the first preset value, and Div1 is a preset fixed parameter; The date parameter is calculated according to the second preset value, and the date parameter for: ; Num2 is the second preset value, A mapping function that maps numbers to four-digit date formats; According to the year parameters and the date parameter Calculate the corresponding second check value; the second check value C2 is: ; Among them, y1, y2, and y3 are the year parameters The first, second and third digit values of the date; d1, d2, d3 and d4 are the date parameters respectively. The first, second, third, and fourth digit values of The adjustment value is determined according to the difference between the first check value C1 and the second check value C2; the adjustment value r 10 satisfy: ; Replace the 7th to 9th digits of the first ID number with the year parameter The first, second and third digits of the first ID number are replaced by the adjustment value, and the 11th to 14th digits of the first ID number are replaced by the date parameter to obtain the second ID number.
[0126] Optionally, the converting the first ID card number into a second ID card number that conforms to an ID card number format further includes: After determining the first check value C1 and the second check value C2, it is determined Is it 8? exist If the value is not 8, the step of determining the adjustment value according to the difference between the first check value C1 and the second check value C2 is performed; exist When the value is 8, the year parameter performing a subtraction process to update the year parameter, and determining a new adjustment value based on the updated year parameter; Replace the 7th to 9th digits of the first ID number with the first, second, and third digits of the updated year parameter respectively, replace the 10th digit of the first ID number with the new adjusted value, and replace the 11th to 14th digits of the first ID number with the date parameter respectively. to obtain the second ID number.
[0127] Optionally, the target position data includes current target position coordinates, and the false position data includes multiple false position coordinates; The determining of a target data set including the target location data and at least a portion of the false location data comprises: taking multiple false position coordinates in the false position data whose distances from the target position coordinates are less than a preset threshold as candidate position coordinates; the number of the candidate position coordinates is M; Generate multiple different first data sets; the first data sets include the target position coordinates and N-1 candidate position coordinates; N <M; For each of the first data sets, determining an evaluation index for the first data set; the evaluation index is used to represent a distribution of query requests corresponding to each location coordinate in the first data set; Eliminating the target position coordinates in the first data set with the largest evaluation index to obtain a second data set; K-1 candidate position coordinates are selected from the second data set to generate a target data set including the target position coordinates and the K-1 candidate position coordinates.
[0128] Optionally, selecting K-1 candidate position coordinates from the second data set includes: Determine a historical data set corresponding to the historical query request, where the historical data set includes real historical location coordinates and K-1 false first location coordinates; For any of the first position coordinates, determining a second position coordinate in the second data set corresponding to the first position coordinate path; the second position coordinate is one of K-1 candidate position coordinates selected from the second data set; The determining of the second position coordinates corresponding to the first position coordinate path in the second data set includes: For any undetermined location coordinate in the second data set, determining the distance between the first location coordinate and the undetermined location coordinate, and the angle between a first path from the first location coordinate to the undetermined location coordinate and a second path from the historical location coordinate to the target location coordinate; When the distance is less than a preset distance value and the included angle is less than a preset angle, determining a transition probability of moving from the first position coordinate to the undetermined position coordinate; The undetermined position coordinate with the maximum transfer probability is used as the second position coordinate corresponding to the first position coordinate path.
[0129] Optionally, the evaluation index is: ; Where, Ind represents the evaluation index of the first data set; n i Indicates the number of query requests corresponding to the i-th position coordinate in the first data set, and n j represents the number of query requests corresponding to the j-th position coordinate in the first data set; N is the number of position coordinates in the first data set.
[0130] An embodiment of the present invention further provides a computer storage medium storing computer executable instructions, which includes a program for executing the above-mentioned method for securely processing user data. The computer executable instructions can execute the method in any of the above-mentioned method embodiments.
[0131] Among them, the computer storage medium can be any available medium or data storage device that can be accessed by the computer, including but not limited to magnetic storage (such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO)), optical storage (such as CDs, DVDs, BDs, HVDs, etc.), and semiconductor storage (such as ROM, EPROM, EEPROM, non-volatile memory (NANDFLASH), solid-state drives (SSDs)), etc.
[0132] Figure 8 The block diagram of the structure of an electronic device according to another embodiment of the present invention is shown. The electronic device 1100 may be a host server with computing capabilities, a personal computer (PC), or a portable computer or terminal. The specific embodiments of the present invention do not limit the specific implementation of the electronic device.
[0133] The electronic device 1100 includes at least one processor 1110 , a communication interface 1120 , a memory array 1130 , and a bus 1140 . The processor 1110 , the communication interface 1120 , and the memory array 1130 communicate with each other via the bus 1140 .
[0134] The communication interface 1120 is used to communicate with network elements, where the network elements include, for example, a virtual machine management center, shared storage, etc.
[0135] The processor 1110 is used to execute programs. The processor 1110 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present invention.
[0136] Memory 1130 is used for executable instructions. Memory 1130 may include high-speed RAM memory, or may also include non-volatile memory, such as at least one disk storage device. Memory 1130 may also be a memory array. Memory 1130 may also be divided into blocks, and the blocks may be combined into virtual volumes according to certain rules. The instructions stored in memory 1130 can be executed by processor 1110, so that processor 1110 can execute the user data security processing method in any of the above-mentioned method embodiments.
[0137] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.
Claims
1. A method for securely processing user data, characterized in that: include: Obtain target user data to be processed; The target user data includes target identity data and target location data; Encrypting the target identity data to generate and save encrypted identity data; In response to a target query request initiated according to the target location data, generating false location data corresponding to the target location data; A target data set including the target location data and at least a portion of the pseudo location data is determined, and query processing corresponding to the target query request is performed according to the target data set.
2. The method according to claim 1, characterized in that The target identity data includes: at least one of a real first ID card number, a first mobile phone number, and a first driver's license number; The encrypting the target identity data includes: encrypting at least one of the first ID card number, the first mobile phone number, and the first driver's license number; The encrypting of the first ID number includes: converting the first ID number into a second ID number that conforms to an ID number format, and encrypting the second ID number; the second ID number is different from the first ID number; The encrypting of the first mobile phone number includes: converting the first mobile phone number into a second mobile phone number that conforms to a mobile phone number format, and encrypting the second mobile phone number; the second mobile phone number is different from the first mobile phone number; The encryption processing of the first driver's license number includes: converting the first driver's license number into a second driver's license number that conforms to the driver's license number format, and encrypting the second driver's license number; the second driver's license number is different from the first driver's license number.
3. The method according to claim 2, characterized in that The converting the first ID card number into a second ID card number that conforms to the ID card number format includes: Extract the values corresponding to the 7th to 14th digits of the first ID number and calculate the corresponding first check value; the first check value C1 is: ; n7, n8, ..., n 14 are the values corresponding to the 7th to 14th digits in the first ID number, respectively, and mod() represents the remainder function; The three-digit year parameter is calculated according to the first preset value, and the three-digit year parameter for: ; is the first three digits of the current year, Num1 is the first preset value, and Div1 is a preset fixed parameter; The date parameter is calculated according to the second preset value, and the date parameter for: ; Num2 is the second preset value, A mapping function that maps numbers to four-digit date formats; According to the year parameters and the date parameter Calculate the corresponding second check value; the second check value C2 is: ; Among them, y1, y2, and y3 are the year parameters The first, second and third digit values of the date; d1, d2, d3 and d4 are the date parameters respectively. The first, second, third, and fourth digit values of The adjustment value is determined according to the difference between the first check value C1 and the second check value C2; the adjustment value r 10 satisfy: ; Replace the 7th to 9th digits of the first ID number with the year parameter The first, second and third digits of the first ID number are replaced by the adjustment value, and the 11th to 14th digits of the first ID number are replaced by the date parameter to obtain the second ID number.
4. The method according to claim 3, characterized in that The step of converting the first ID card number into a second ID card number that conforms to the ID card number format further includes: After determining the first check value C1 and the second check value C2, it is determined Is it 8? exist If the value is not 8, the step of determining the adjustment value according to the difference between the first check value C1 and the second check value C2 is performed; exist When the value is 8, the year parameter performing a subtraction process to update the year parameter, and determining a new adjustment value based on the updated year parameter; Replace the 7th to 9th digits of the first ID number with the first, second, and third digits of the updated year parameter respectively, replace the 10th digit of the first ID number with the new adjusted value, and replace the 11th to 14th digits of the first ID number with the date parameter respectively. to obtain the second ID number.
5. The method according to any one of claims 1 to 4, characterized in that The target position data includes the current target position coordinates, and the false position data includes a plurality of false position coordinates; The determining of a target data set including the target location data and at least a portion of the false location data comprises: taking multiple false position coordinates in the false position data whose distances from the target position coordinates are less than a preset threshold as candidate position coordinates; the number of the candidate position coordinates is M; Generate multiple different first data sets; the first data sets include the target position coordinates and N-1 candidate position coordinates; N <M; For each of the first data sets, determining an evaluation index for the first data set; the evaluation index is used to represent a distribution of query requests corresponding to each location coordinate in the first data set; Eliminating the target position coordinates in the first data set with the largest evaluation index to obtain a second data set; K-1 candidate position coordinates are selected from the second data set to generate a target data set including the target position coordinates and the K-1 candidate position coordinates.
6. The method according to claim 5, characterized in that The selecting K-1 candidate position coordinates from the second data set includes: Determine a historical data set corresponding to the historical query request, where the historical data set includes real historical location coordinates and K-1 false first location coordinates; For any of the first position coordinates, determining a second position coordinate in the second data set corresponding to the first position coordinate path; the second position coordinate is one of K-1 candidate position coordinates selected from the second data set; The determining of the second position coordinates corresponding to the first position coordinate path in the second data set includes: For any undetermined location coordinate in the second data set, determining the distance between the first location coordinate and the undetermined location coordinate, and the angle between a first path from the first location coordinate to the undetermined location coordinate and a second path from the historical location coordinate to the target location coordinate; When the distance is less than a preset distance value and the included angle is less than a preset angle, determining a transition probability of moving from the first position coordinate to the undetermined position coordinate; The undetermined position coordinate with the maximum transfer probability is used as the second position coordinate corresponding to the first position coordinate path.
7. The method according to claim 5, characterized in that The evaluation indicators are: ; Where, Ind represents the evaluation index of the first data set; n i Indicates the number of query requests corresponding to the i-th position coordinate in the first data set, and n j represents the number of query requests corresponding to the j-th position coordinate in the first data set; N is the number of position coordinates in the first data set.
8. A user data security processing device, characterized in that: include: An acquisition module is used to obtain target user data to be processed; The target user data includes target identity data and target location data; An encryption module, used to encrypt the target identity data, generate and save the encrypted identity data; a location generating module, configured to generate false location data corresponding to the target location data in response to a target query request initiated according to the target location data; The processing module is configured to determine a target data set including the target location data and at least a portion of the pseudo location data, and perform query processing corresponding to the target query request according to the target data set.
9. A computer storage medium, characterized in that The computer storage medium stores computer-executable instructions, and the computer-executable instructions are used to execute the user data security processing method according to any one of claims 1 to 7.
10. An electronic device, characterized in that: include: at least one processor; as well as, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the user data security processing method described in any one of claims 1 to 7.
Citation Information
Patent Citations
Personalized position privacy protection method based on position k-anonymization
CN108600304A
A location privacy protection method and device based on anonymity
CN109067750A
Privacy protection method and device for user track
CN113672975A
Privacy protection method and device based on false position and storage medium
CN115146300A
Data processing method and device, equipment and storage medium
CN117313159A