Agricultural product cross-platform heterogeneous data privacy protection method

By constructing a cross-platform heterogeneous data privacy protection system, combined with preliminary and secondary de-identification processing and user permission management, the privacy leakage problem in the process of sharing agricultural product data has been solved, and the security and usability of data have been improved.

CN121456899APending Publication Date: 2026-02-03SOUTHWEST PETROLEUM UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511577762.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-31
Publication Date
2026-02-03

AI Technical Summary

Technical Problem

Existing technologies lack in-depth privacy protection measures in the process of cross-platform data sharing of agricultural products, which cannot effectively prevent data privacy leaks and lack dynamic permission management, resulting in low security.

Method used

Construct a cross-platform heterogeneous data privacy protection system, including a data source platform, a data processing platform, and a data usage platform. Through preliminary and secondary de-identification processes, combined with user permission management, generate target data whose privacy protection level matches the user's permissions.

Benefits of technology

Effectively protect the privacy of agricultural product data across platforms, improve data availability and system security, meet the personalized data access needs of different users, and enhance the security and compliance of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121456899A_ABST
    Figure CN121456899A_ABST
Patent Text Reader

Abstract

The invention provides an agricultural product cross-platform heterogeneous data privacy protection method, which relates to the technical field of data privacy protection, and comprises the following steps: constructing a cross-platform heterogeneous data privacy protection system which comprises a data source platform, a data processing platform and a data use platform; on the data source platform, performing preliminary desensitization processing on the agricultural product data according to a preset first privacy protection strategy to generate first desensitization data; on a data processing platform, according to a preset second privacy protection strategy, performing secondary desensitization processing on the first desensitization data to generate second desensitization data; on a data using platform, the second desensitized data are decrypted or restored according to the user permission, target data are generated, and the privacy protection level of the target data is matched with the user permission; the privacy of cross-platform agricultural product data can be effectively protected, and the availability of the data and the security of the system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data privacy protection, and particularly to a method for protecting the privacy of cross-platform heterogeneous data of agricultural products. Background Art

[0002] Agricultural product data not only covers the planting information in the production process, but also includes the sales channels, price information in the sales link, and transportation and warehousing information in the logistics link. These data are of great significance for optimizing agricultural production, enhancing market competitiveness, and ensuring the efficient operation of the agricultural product supply chain. However, with the extensive use and sharing of data, data privacy and security issues have become increasingly prominent. In the process of cross-platform data sharing, how to ensure the privacy of data during transmission and use is a key issue. Existing methods only perform preliminary desensitization processing at the data source end, lacking deep privacy protection measures. This single desensitization processing may not effectively prevent the privacy leakage of data during subsequent processing and sharing, lacking dynamic permission management, and unable to dynamically adjust the privacy protection level of data according to the roles and permissions of users, which may lead to unauthorized access to data and lower security. Summary of the Invention

[0003] To solve the above technical problems, the present invention provides a method for protecting the privacy of cross-platform heterogeneous data of agricultural products, which can effectively protect the privacy of cross-platform agricultural product data and improve the availability of data and the security of the system.

[0004] An embodiment of the present invention provides a method for protecting the privacy of cross-platform heterogeneous data of agricultural products, including the following steps:

[0005] Construct a cross-platform heterogeneous data privacy protection system, which includes a data source platform, a data processing platform, and a data usage platform;

[0006] At the data source platform, perform preliminary desensitization processing on agricultural product data according to a preset first privacy protection policy to generate first desensitized data;

[0007] At the data processing platform, perform secondary desensitization processing on the first desensitized data according to a preset second privacy protection policy to generate second desensitized data;

[0008] At the data usage platform, decrypt or restore the second desensitized data according to user permissions to generate target data, where the privacy protection level of the target data matches the user permissions.

[0009] In some embodiments, the data source platform includes multiple different data sources, and the data sources include agricultural product production data sources, agricultural product sales data sources, and agricultural product logistics data sources.

[0010] In some embodiments, the first privacy protection strategy includes encrypting, replacing, or deleting sensitive information in agricultural product data.

[0011] In some embodiments, the data processing platform includes a data cleaning module, a data conversion module, and a data desensitization module, wherein:

[0012] The data cleaning module is used to clean the first desensitized data, removing duplicate data, erroneous data, and irrelevant data;

[0013] The data conversion module is used to convert the cleaned data into a unified format; the data desensitization module is used to perform secondary desensitization processing on the converted data according to the second privacy protection strategy.

[0014] In some embodiments, the second privacy protection strategy includes further encrypting, obfuscating, or anonymizing key information in the first de-identified data.

[0015] In some embodiments, the data usage platform includes a user rights management module and a data decryption and restoration module, wherein:

[0016] The user permission management module is used to assign access and operation permissions to the second de-identified data according to the user's permission level.

[0017] The data decryption and restoration module is used to decrypt or restore the second de-identified data according to user permissions to generate target data.

[0018] In some embodiments, the user permissions include administrator permissions, regular user permissions, and visitor permissions. The administrator permissions allow users to access and manipulate all data, the regular user permissions allow users to access some data and perform limited operations, and the visitor permissions allow users to view only some publicly available data.

[0019] In some embodiments, the privacy protection level of the target data is dynamically adjusted based on user permissions. When user permissions change, the data usage platform automatically adjusts the privacy protection level of the target data.

[0020] Compared with the prior art, the present invention has the following beneficial effects:

[0021] A cross-platform heterogeneous data privacy protection system is constructed, comprising a data source platform, a data processing platform, and a data usage platform. On the data source platform, agricultural product data undergoes preliminary de-identification processing according to a preset first privacy protection strategy, generating first de-identified data. On the data processing platform, the first de-identified data undergoes secondary de-identification processing according to a preset second privacy protection strategy, generating second de-identified data. On the data usage platform, the second de-identified data is decrypted or restored according to user permissions to generate target data, wherein the privacy protection level of the target data matches the user permissions. This system effectively protects the privacy of agricultural product data across platforms, improving data availability and system security. Attached Figure Description

[0022] The embodiments of the present invention will be further described below with reference to the accompanying drawings:

[0023] Figure 1 A schematic diagram illustrating the implementation process of a cross-platform heterogeneous data privacy protection method for agricultural products provided in an embodiment of the present invention;

[0024] Figure 2 This is a schematic diagram of the composition structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0025] To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limitations on the present invention. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0026] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0027] If the application documents contain similar descriptions such as "first, second, third", the following explanation shall be added: In the following description, the terms "first, second, third" are used only to distinguish similar objects and do not represent a specific order of objects. It is understood that "first, second, third" may be interchanged in a specific order or sequence where permitted, so that the embodiments of the present invention described herein can be implemented in an order other than that illustrated or described herein.

[0028] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. The terminology used herein is for the purpose of describing embodiments of the invention only and is not intended to limit the invention.

[0029] To address the problems existing in related technologies, this invention provides a method for protecting the privacy of heterogeneous data across platforms for agricultural products. The subject of this protection method can be an electronic device. The electronic device can be various types of terminals such as laptops, tablets, desktop computers, set-top boxes, and mobile devices (e.g., mobile phones, portable music players, personal digital assistants, dedicated messaging devices, portable gaming devices), or it can be implemented as a server. The server can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms.

[0030] In some embodiments, the functions implemented by the protection method provided in this invention can be achieved by the processor of an electronic device calling program code, wherein the program code can be stored in a computer storage medium.

[0031] This invention provides a method for protecting the privacy of heterogeneous data across platforms for agricultural products. Figure 1 This is a schematic diagram illustrating the implementation process of a cross-platform heterogeneous data privacy protection method for agricultural products provided in an embodiment of the present invention, as shown below. Figure 1 As shown, it includes the following steps:

[0032] Step S1: Construct a cross-platform heterogeneous data privacy protection system, which includes a data source platform, a data processing platform, and a data usage platform;

[0033] In this embodiment of the invention, the data source platform is responsible for collecting and storing raw data. The data source platform is the data entry point for the entire system; it obtains agricultural product data from multiple different data sources and can perform preliminary data anonymization. After obtaining data from the data source platform, the data processing platform performs data cleaning, data transformation, and further data anonymization. The data usage platform is responsible for decrypting or restoring the data according to user permissions and providing the processed data to users.

[0034] Step S2: On the data source platform, perform preliminary desensitization processing on agricultural product data according to the preset first privacy protection strategy to generate the first desensitized data;

[0035] In this embodiment of the invention, by performing preliminary desensitization processing on agricultural product data on the data source platform, the sensitivity of the data is effectively reduced, data privacy is protected, and most of the information in the data is retained, ensuring that the data remains usable in subsequent processing and analysis.

[0036] In some embodiments, the data source platform includes multiple different data sources, including agricultural product production data sources, agricultural product sales data sources, and agricultural product logistics data sources.

[0037] In this embodiment of the invention, the agricultural product production data source records data on the production stages of agricultural products, such as planting, breeding, and harvesting, including information on the place of origin, growers, and production dates. The agricultural product sales data source records data on the sales stages, such as sales channels, sales prices, and sales times. The agricultural product logistics data source records data on the logistics stages, such as transportation, storage, and distribution, including transportation routes, storage time, and transportation methods.

[0038] In some embodiments, the first privacy protection strategy includes encrypting, replacing, or deleting sensitive information in agricultural product data.

[0039] In this embodiment of the invention, encryption algorithms are used to encrypt sensitive information to ensure that the data is not read by unauthorized third parties during transmission and storage. Sensitive information is replaced with other non-sensitive information, such as replacing real names with anonymous identifiers, or replacing specific prices with price ranges. Certain sensitive information is directly deleted to reduce the sensitivity of the data, such as deleting specific grower contact information.

[0040] Step S3: On the data processing platform, according to the preset second privacy protection strategy, the first de-identified data is subjected to a second de-identification process to generate the second de-identified data;

[0041] In this embodiment of the invention, the data processing platform receives first-stage de-identified data from the data source platform. This data has already had its sensitivity reduced through encryption, replacement, or deletion, but it may still contain some critical information requiring further processing. The data processing platform performs a second de-identification process on the first-stage de-identified data, further reducing its sensitivity and enhancing data security and privacy protection.

[0042] In some embodiments, the data processing platform includes a data cleaning module, a data conversion module, and a data desensitization module, wherein:

[0043] The data cleaning module is used to clean the first desensitized data, removing duplicate data, erroneous data, and irrelevant data;

[0044] The data conversion module is used to convert the cleaned data into a unified format; the data desensitization module is used to perform secondary desensitization processing on the converted data according to the second privacy protection strategy.

[0045] In this embodiment of the invention, the data processing platform ensures that data undergoes rigorous processing and privacy protection before entering the platform through the collaborative work of a data cleaning module, a data transformation module, and a data anonymization module. This process not only improves data quality and consistency but also further reduces data sensitivity through in-depth privacy protection measures, enhancing the system's security and compliance.

[0046] In some embodiments, the second privacy protection strategy includes further encrypting, obfuscating, or anonymizing key information in the first de-identified data.

[0047] In this embodiment of the invention, key information undergoes more advanced encryption to ensure greater data security during transmission and storage. Key information is obfuscated to retain a certain amount of information while making it difficult to identify precisely. For example, specific prices are replaced with price ranges, or specific dates are replaced with time periods. Key information is also anonymized to ensure it cannot be traced back to a specific individual or entity. For example, specific sales channel names are replaced with numbers.

[0048] Step S4: On the data usage platform, the second de-identified data is decrypted or restored according to user permissions to generate target data, wherein the privacy protection level of the target data matches the user permissions.

[0049] In this embodiment of the invention, the target data is generated by decrypting or restoring the second de-identified data according to user permissions on the data usage platform, ensuring that the privacy protection level of the target data matches the user permissions. This dynamic permission management not only meets the needs of different users and provides personalized data access services, but also enhances the security of the system.

[0050] In some embodiments, the data usage platform includes a user rights management module and a data decryption and restoration module, wherein:

[0051] The user permission management module is used to assign access and operation permissions to the second de-identified data according to the user's permission level.

[0052] The data decryption and restoration module is used to decrypt or restore the second de-identified data according to user permissions to generate target data.

[0053] In this embodiment of the invention, through the collaborative work of the user permission management module and the data decryption and restoration module, the data usage platform can dynamically adjust the privacy protection level of the data according to the user's permission level, and decrypt or restore the second de-identified data to generate the target data. This mechanism not only meets the needs of different users and provides personalized data access services, but also enhances the security of the system.

[0054] In some embodiments, the user permissions include administrator permissions, regular user permissions, and visitor permissions. The administrator permissions allow users to access and manipulate all data, the regular user permissions allow users to access some data and perform limited operations, and the visitor permissions allow users to view only some publicly available data.

[0055] In this embodiment of the invention, users initiate a registration request to the data usage platform through the system interface or API, providing necessary identity information (such as username, password, email, etc.). The system verifies the user's identity information to ensure the authenticity of the user's identity. Verification methods may include username and password verification, email verification, mobile SMS verification, etc. Based on the user's role and responsibilities, the system assigns users to different permission levels. Typically, system administrators are assigned permission to access and manipulate all data; ordinary users are assigned permission to access some data and perform limited operations; and unregistered or temporarily accessing users are only allowed to view some publicly available data. When a user initiates a data access request, the system verifies the user's permission level through the user permission management module. Based on the user's permission level, the system decides whether to allow the user to access specific data and restricts the operations the user can perform.

[0056] In some embodiments, the privacy protection level of the target data is dynamically adjusted based on user permissions. When user permissions change, the data usage platform automatically adjusts the privacy protection level of the target data.

[0057] In this embodiment of the invention, the system monitors the user's permission status in real time to ensure timely detection of permission changes. Based on these changes, the system automatically adjusts the privacy protection level of the target data, ensuring a balance between data security and availability. For users with elevated permissions, the system provides more sensitive information through decryption or restoration operations while ensuring data availability. For users with degraded permissions, the system reduces the exposure of sensitive information through re-desensitization, further protecting data privacy.

[0058] It should be noted that, in the embodiments of the present invention, if the above-described protection method is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), magnetic disks, or optical disks. Thus, the embodiments of the present invention are not limited to any specific hardware and software combination.

[0059] Accordingly, embodiments of the present invention provide a storage medium storing a computer program thereon, characterized in that the computer program, when executed by a processor, implements the steps in the protection method provided in the above embodiments.

[0060] This invention provides an electronic device; Figure 2 This is a schematic diagram of the composition structure of an electronic device provided in an embodiment of the present invention, such as... Figure 2 As shown, the electronic device 400 includes: a processor 401, at least one communication bus 402, a user interface 403, at least one external communication interface 404, and a memory 405. The communication bus 402 is configured to enable communication between these components. The user interface 403 may include a display screen, and the external communication interface 404 may include standard wired and wireless interfaces. The processor 401 is configured to execute a program of a protection method stored in the memory to implement the steps of the protection method provided in the above embodiments.

[0061] It should be noted that the descriptions of the storage medium and electronic device embodiments above are similar to the descriptions of the method embodiments above, and have similar beneficial effects. For technical details not disclosed in the storage medium and device embodiments of the present invention, please refer to the descriptions of the method embodiments of the present invention for understanding.

[0062] It should be understood that the phrase "one embodiment" or "an embodiment" throughout the specification means that a specific feature, structure, or characteristic related to the embodiment is included in at least one embodiment of the invention. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. It should be understood that in the various embodiments of the invention, the sequence numbers of the above-described processes do not imply a sequential order of execution; the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the invention. The sequence numbers of the above-described embodiments of the invention are merely descriptive and do not represent the superiority or inferiority of the embodiments.

[0063] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, object, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, object, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, object, or apparatus that includes that element.

[0064] In the several embodiments provided by this invention, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple units or components can be combined, or integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed can be through some interfaces, and the indirect coupling or communication connection between devices or units can be electrical, mechanical, or other forms.

[0065] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units. They may be located in one place or distributed across multiple network units. Some or all of the units may be selected to achieve the purpose of this embodiment according to actual needs.

[0066] In addition, in the various embodiments of the present invention, each functional unit can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the integrated unit can be implemented in hardware or in the form of hardware plus software functional units.

[0067] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium includes various media that can store program code, such as mobile storage devices, read-only memory (ROM), magnetic disks, or optical disks.

[0068] Alternatively, if the integrated units of this invention are implemented as software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of this invention, or the parts that contribute to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a controller to execute all or part of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, ROMs, magnetic disks, or optical disks.

[0069] The above description is merely an embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A method for protecting the privacy of heterogeneous data across platforms for agricultural products, characterized in that, Includes the following steps: Construct a cross-platform heterogeneous data privacy protection system, the system including a data source platform, a data processing platform, and a data usage platform; On the data source platform, the agricultural product data is initially de-identified according to the preset first privacy protection policy to generate the first de-identified data. On the data processing platform, the first de-identified data is subjected to a second de-identification process according to a preset second privacy protection strategy to generate the second de-identified data; On the data usage platform, the second de-identified data is decrypted or restored according to user permissions to generate target data, wherein the privacy protection level of the target data matches the user permissions.

2. The method for protecting the privacy of heterogeneous cross-platform agricultural product data according to claim 1, characterized in that, The data source platform includes multiple different data sources, including agricultural product production data sources, agricultural product sales data sources, and agricultural product logistics data sources.

3. The method for protecting the privacy of heterogeneous cross-platform data related to agricultural products according to claim 1, characterized in that, The first privacy protection strategy includes encrypting, replacing, or deleting sensitive information in agricultural product data.

4. The method for protecting the privacy of heterogeneous cross-platform agricultural product data according to claim 1, characterized in that, The data processing platform includes a data cleaning module, a data conversion module, and a data desensitization module, wherein: The data cleaning module is used to clean the first desensitized data, removing duplicate data, erroneous data, and irrelevant data; The data conversion module is used to convert the cleaned data into a unified format; The data desensitization module is used to perform secondary desensitization processing on the converted data according to the second privacy protection strategy.

5. The method for protecting the privacy of heterogeneous cross-platform agricultural product data according to claim 1, characterized in that, The second privacy protection strategy includes further encrypting, obfuscating, or anonymizing key information in the first de-identified data.

6. The method for protecting privacy of heterogeneous cross-platform agricultural product data according to claim 1, characterized in that, The data usage platform includes a user permission management module and a data decryption and restoration module, wherein: The user permission management module is used to assign access and operation permissions to the second de-identified data according to the user's permission level. The data decryption and restoration module is used to decrypt or restore the second de-identified data according to user permissions to generate target data.

7. The method for protecting the privacy of heterogeneous cross-platform data related to agricultural products according to claim 1, characterized in that, The user permissions include administrator permissions, regular user permissions, and visitor permissions. Administrator permissions allow users to access and manipulate all data, regular user permissions allow users to access some data and perform limited operations, and visitor permissions allow users to view only some public data.

8. The method for protecting privacy of heterogeneous cross-platform agricultural product data according to claim 1, characterized in that, The privacy protection level of the target data is dynamically adjusted based on user permissions. When user permissions change, the data usage platform automatically adjusts the privacy protection level of the target data.