A cloud platform-oriented user privacy data security protection method and system

By acquiring and analyzing user location time-series sequences and dynamically adjusting encryption levels, the problem of resource waste and privacy leaks caused by differences in location sensitivity in cloud platforms is solved, achieving personalized privacy protection and resource optimization.

CN121644225BActive Publication Date: 2026-05-29BEIJING SHENPU INFORMATION TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING SHENPU INFORMATION TECHNOLOGY CO LTD
Filing Date
2025-12-30
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

In existing technologies, the unified encryption strategy for user location information by cloud platforms cannot identify and adapt to the differences in privacy sensitivity of different locations, resulting in wasted computing resources and the risk of privacy leakage in highly sensitive locations.

Method used

By acquiring the location time series of target users over multiple time periods and combining it with time series feature analysis, the impact of each location on user movement behavior can be quantified, and the data encryption level can be dynamically adjusted to achieve personalized privacy protection.

Benefits of technology

It achieves personalized protection that dynamically changes based on location privacy sensitivity, avoiding over-encryption of low-sensitivity locations, ensuring privacy and security of high-sensitivity locations, and balancing resource utilization efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121644225B_ABST
    Figure CN121644225B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of data security, in particular to a user privacy data security protection method and system for a cloud platform, which solves the technical problem that, in the prior art, a unified privacy protection strategy is adopted for all position information, adaptive differential protection cannot be carried out according to the actual sensitivity of positions, and the technical problems of waste of computing resources and insufficient personalized protection are caused. The method comprises the following steps: acquiring a position time sequence of a target user in multiple time periods; for each time period, performing time sequence feature analysis according to the position time sequence to determine a position influence index of each position; the position influence index is used for representing the influence degree of the position on the moving behavior of the target user; according to the change of the position influence index of each position in the multiple time periods, the data encryption level corresponding to each position is determined, and each position data is stored after being encrypted according to the data encryption level.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data security technology, specifically to a method and system for protecting user privacy data security on cloud platforms. Background Technology

[0002] With the widespread adoption and in-depth application of cloud computing technology, various cloud platforms have become indispensable data aggregation and processing centers for business sectors with data sharing needs, generating a large amount of user location information during operation. This location information can be extracted to form user movement trajectories, and the leakage of these trajectories will directly lead to serious breaches of personal privacy. Therefore, how to effectively protect the trajectory data formed by user location information and prevent attackers from piecing together complete movement trajectories from fragmented location information has become a crucial issue that urgently needs to be addressed in the field of cloud platform data security.

[0003] Currently, a common method for protecting user location on cloud platforms is to uniformly configure privacy protection strategies for all collected location information. This includes implementing uniform encryption algorithms and strengths, and using the same encryption costs and protection standards for all users' location information. This approach attempts to comprehensively block the risk of privacy leaks and has played a certain role at the foundational level of data security protection.

[0004] However, in real-world applications, the sensitivity of geographical location to user privacy varies significantly across different contexts. For example, the sensitivity of home location differs drastically from that of a temporary visit to a shopping mall. Existing uniform protection strategies fail to recognize and adapt to these differentiated privacy needs. This leads to high-strength encryption of low-sensitivity location information, resulting in unnecessary consumption of computing and storage resources, while high-sensitivity locations may be at risk of leakage due to insufficient protection levels. Summary of the Invention

[0005] To address the technical problem in existing technologies where a uniform privacy protection strategy is applied to all location information, resulting in an inability to adaptively differentiate protection based on the actual sensitivity of the location, leading to wasted computing resources and insufficient personalized protection, the present invention aims to provide a method and system for protecting user privacy data security on cloud platforms. The specific technical solution adopted is as follows:

[0006] Firstly, a method for protecting user privacy data security on a cloud platform is provided, comprising: acquiring the location time series sequence of a target user's access over multiple time periods; for each time period, performing time series feature analysis based on the location time series sequence to determine the location influence index for each location; the location influence index is used to characterize the degree of influence of location on the target user's movement behavior; determining the data encryption level corresponding to each location based on the changes in the location influence index of each location over multiple time periods, and encrypting and storing the data for each location according to the data encryption level.

[0007] Based on the above technical solution, in the user privacy data security protection method for cloud platforms provided by this invention, the location time series sequence of the target user over multiple time periods is obtained, and the influence of each location on the user's movement behavior is quantified by combining time series feature analysis. This replaces the uniform encryption strategy in the prior art. It can adapt to the dynamic changes of the privacy sensitivity characteristics of different locations based on the changes in the location influence index over multiple periods, and achieve personalized privacy protection. It can also avoid the waste of computing resources caused by excessive encryption of low-sensitivity locations, while ensuring the privacy security of high-sensitivity locations. This effectively balances the privacy protection effect and resource utilization efficiency of cloud platform user location data.

[0008] In conjunction with the first aspect mentioned above, in one possible implementation, the method for determining the location influence index of each location by performing time-series feature analysis based on the location time-series sequence specifically includes: extracting the access behavior features of each visit by the target user from the location time-series sequence to determine the location sensitivity of the target user to each location for each visit; the access behavior features include access frequency and access duration; dividing the location time-series sequence into multiple behavior intervals based on the time-series changes in location sensitivity; and determining the location influence index of each location based on at least one behavior interval to which each location belongs in the location time-series sequence.

[0009] In conjunction with the first aspect above, in one possible implementation, the method for extracting the access behavior features of the target user for each access from the location time series and determining the location sensitivity of the target user for each access to each location specifically includes: for each access, comparing the duration of this access with the average access duration of the target user at the current location to determine a first sensitivity factor for each access; for each location, comparing the number of times the target user accesses the current location with the number of times the target user accesses neighboring locations to determine a second sensitivity factor for each location; and determining the location sensitivity of the target user for each access to each location based on the first sensitivity factor and the second sensitivity factor.

[0010] In conjunction with the first aspect above, in one possible implementation, the method of dividing a location time series into multiple behavioral intervals based on the temporal changes in location sensitivity specifically includes: determining the behavioral coefficient for each visit based on the location sensitivity of each visit and the location sensitivity of multiple historical visits; the behavioral coefficient is used to characterize the degree of difference between the target user's current visit and multiple historical visits; analyzing the changing trend of the behavioral coefficient difference between consecutive visits in the location time series, and using the visit position corresponding to the peak of the behavioral coefficient difference as the cutoff point to divide the location time series into multiple behavioral intervals.

[0011] In conjunction with the first aspect above, in one possible implementation, the method for determining the behavioral coefficient of each visit based on the location sensitivity of each visit and the location sensitivity of multiple historical visits specifically includes: for each visit, comparing the location sensitivity of the current visit with the location sensitivity of multiple historical visits to the current location to determine a single change index of the location sensitivity of the current visit; determining an overall change index of the location sensitivity within the preceding time period based on the target user's multiple visits to any location within the preceding time period; and determining the behavioral coefficient of the current visit based on the single change index and the overall change index.

[0012] In conjunction with the first aspect above, in one possible implementation, the target location is any location in the aforementioned location time series. The method for determining the location influence index of the target location based on at least one behavioral interval to which the target location belongs in the location time series specifically includes: aligning at least one behavioral interval to which the target location belongs according to the target location, and determining the minimum interval length covering at least one behavioral interval; for each behavioral interval to which the target location belongs, comparing the boundary distance of the target location within the behavioral interval with the minimum interval length to determine the temporal ranking factor of the target location in each behavioral interval; for each behavioral interval to which the target location belongs, comparing the behavioral coefficient of the target location with the behavioral coefficients of multiple visits within the behavioral interval to determine the behavioral performance deviation factor of the target location in each behavioral interval; and determining the location influence index of the target location based on the temporal ranking factor and the behavioral performance deviation factor corresponding to each behavioral interval.

[0013] In conjunction with the first aspect mentioned above, in one possible implementation, the target location is any position in the aforementioned position time series. The method for determining the data encryption level corresponding to the target location based on the changes in the position influence index of the target location over multiple time periods specifically includes: for the target location, comparing the change magnitude of the position influence index in the current time period compared to the previous time period, and combining the change magnitudes of the position influence index of the target location in multiple consecutive time periods to determine the relative change magnitude of the position influence index of the target location in the current time period; for the target location, comparing the position influence index of the current time period with the position influence index within a reference period to determine the relative position influence index of the target location in the current time period; the reference period includes time periods where the change trend of the position influence index is consistent with the current time period and is continuous with the current time period; determining an encryption level determination factor based on the relative change magnitude of the position influence index of the target location in the current time period and the relative position influence index; and mapping the encryption level determination factor to multiple preset encryption levels to determine the data encryption level corresponding to the target location within the current time period.

[0014] In conjunction with the first aspect above, in one possible implementation, the aforementioned multiple encryption levels include: a first level, a second level, a third level, and a fourth level; the method for encrypting and storing location data according to the data encryption level specifically includes: processing the location data of the first level using a symmetric encryption algorithm of first strength; processing the location data of the second level using a symmetric encryption algorithm of second strength; the second strength is higher than the first strength; encrypting the location data of the third level using a combination of a symmetric encryption algorithm of second strength and an asymmetric encryption algorithm; and processing the location data of the fourth level using a key management method based on a hardware security module.

[0015] In conjunction with the first aspect above, in one possible implementation, the method for obtaining the location time sequence of a target user's access over multiple time periods specifically includes: acquiring raw location data containing location coordinates, timestamps, and user identifiers through a data acquisition module deployed on the target user's terminal device; transmitting the raw location data through an encrypted communication protocol and verifying the validity of the raw location data; storing the verified raw location data in a database isolated from the public network; and extracting the target user's location coordinates over multiple time periods from the database according to the user identifier, and sorting them according to the corresponding timestamps to form a location time sequence.

[0016] Secondly, a user privacy data security protection system for cloud platforms is provided, including: a data acquisition module, an impact assessment module, and an encryption control module; the data acquisition module is used to acquire the location time series sequence of target user access within multiple time periods; the impact assessment module is used to perform time series feature analysis based on the location time series sequence for each time period to determine the location impact index of each location; the location impact index is used to characterize the degree of influence of location on the target user's movement behavior; the encryption control module is used to determine the data encryption level corresponding to each location based on the changes in the location impact index of each location within multiple time periods, and to encrypt and store the data of each location according to the data encryption level.

[0017] Thirdly, a user privacy data security protection device for a cloud platform is provided, comprising: a processor and a storage medium; the storage medium includes instructions, and the processor is used to execute the instructions to perform the actions described in the first aspect and any possible implementation thereof. This user privacy data security protection device for a cloud platform can be an electronic device or a chip within an electronic device.

[0018] Fourthly, a computer-readable storage medium is provided, which stores instructions that, when executed on a cloud-based user privacy data security protection device, cause the cloud-based user privacy data security protection device to perform the actions described in the first aspect and any possible implementation thereof.

[0019] Fifthly, a computer program product containing instructions is provided, which, when run on a cloud-based user privacy data security protection device, causes the cloud-based user privacy data security protection device to perform the actions described in the first aspect and any possible implementation thereof.

[0020] The present invention has the following beneficial effects:

[0021] By acquiring the location time series of target users over multiple time periods and combining time series feature analysis to quantify the impact of each location on user movement behavior, this technology replaces the uniform encryption strategy in existing technologies. It can adapt to the dynamic changes in the privacy sensitivity of different locations based on the changes in the location influence index over multiple periods, achieving personalized privacy protection. At the same time, it can avoid the waste of computing resources caused by over-encryption of low-sensitivity locations, while ensuring the privacy security of high-sensitivity locations. This effectively balances the privacy protection effect and resource utilization efficiency of cloud platform user location data. Attached Figure Description

[0022] To more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0023] Figure 1 A system architecture diagram of a user privacy data security protection system for cloud platforms provided in one embodiment of the present invention;

[0024] Figure 2 This is one of the flowcharts of a method for protecting user privacy data security on a cloud platform, provided by an embodiment of the present invention.

[0025] Figure 3 A second flowchart of a method for protecting user privacy data security on a cloud platform, provided as an embodiment of the present invention;

[0026] Figure 4 This is a schematic diagram illustrating the alignment of behavioral intervals at the same position, as provided in one embodiment of the present invention.

[0027] Figure 5 This is a schematic diagram of the hardware structure of a user privacy data security protection device for a cloud platform, provided as an embodiment of the present invention. Detailed Implementation

[0028] To further illustrate the technical means and effects adopted by the present invention to achieve its intended purpose, the following, in conjunction with the accompanying drawings and preferred embodiments, details the specific implementation, structure, features, and effects of a user privacy data security protection method and system for cloud platforms proposed according to the present invention. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. Furthermore, specific features, structures, or characteristics in one or more embodiments can be combined in any suitable form.

[0029] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.

[0030] The following description, in conjunction with the accompanying drawings, details a specific scheme for a user privacy data security protection method and system for cloud platforms provided by the present invention.

[0031] Please see Figure 1The diagram illustrates a system architecture of a cloud platform-oriented user privacy data security protection system according to an embodiment of the present invention. The cloud platform-oriented user privacy data security protection system includes: a data acquisition module 1, an impact assessment module 2, and an encryption control module 3.

[0032] Among them, the data acquisition module 1 is the basic data support unit of the system, responsible for the complete collection, secure transmission and standardized storage of the target user's location-related data, providing standardized input for the subsequent impact assessment module 2.

[0033] In some implementations, the data acquisition module 1 includes a data acquisition module 11, a transmission verification submodule 12, and a storage and sorting submodule 13.

[0034] The data acquisition module 11 is deployed on the target user terminal device (such as a smartphone or tablet computer), for example, the terminal's software development kit (SDK), to accurately acquire raw location data containing location coordinates, timestamps, and user identifiers, ensuring the unique association between the data and the target user.

[0035] The transmission verification submodule 12 uses an encrypted communication protocol (such as Hypertext Transfer Protocol Secure, HTTPS) to transmit the original location data to the cloud platform backend through a network transmission gateway. Then, a dedicated data ingestion service (DIS) verifies the validity of the data's format integrity and logical rationality, filtering out invalid and abnormal data to ensure the security of the transmission and verification process.

[0036] The storage and sorting submodule 13 stores the verified raw location data in a dedicated database isolated from the public network (such as a database node in a cloud server cluster). During application, the location coordinates of the target user within multiple time periods are extracted by user identifier and sorted in ascending order according to the corresponding timestamps to form a location time series sequence. This sequence is directly synchronized to the impact assessment module 2, serving as the core data source for time series feature analysis.

[0037] Impact assessment module 2 is the core analysis unit of the system. It is responsible for in-depth processing of location time series, quantifying the degree of privacy-related impact of each location, and providing decision-making basis for encryption control module 3.

[0038] In some implementations, the impact assessment module 2 includes a behavior feature extraction submodule 21, a behavior interval division submodule 22, and a location impact index calculation submodule 23.

[0039] The behavior feature extraction submodule 21 receives the location time series output by the data acquisition module 1 and extracts the access behavior features (including access frequency and access duration) of each access by the target user. Then, by comparing the access duration of this access with the average access duration of the current location, the first sensitivity factor of each access is determined. Then, by comparing the access frequency of the current location with that of neighboring locations, the second sensitivity factor of each location is determined. The location sensitivity of the target user to each location for each access is calculated by combining the two factors.

[0040] The behavior interval segmentation submodule 22, based on the location sensitivity output by the behavior feature extraction submodule 21, compares the location sensitivity of the current visit with the location sensitivity of multiple historical visits to that location to determine the single change index. Then, it combines the location sensitivity of all location visits in the preceding time period to determine the overall change index, and then calculates the behavior coefficient for each visit (representing the degree of difference between the current visit and historical visits). Next, it analyzes the changing trend of the difference in behavior coefficients between consecutive visits, and uses the visit location corresponding to the peak of the difference as the cutoff point to divide the location time series into multiple behavior intervals. The results of these intervals are synchronized to the location influence index calculation submodule 23.

[0041] The location influence index calculation submodule 23 extracts at least one behavioral interval for any target location in the location time series, aligns all associated behavioral intervals according to the target location, and determines the minimum interval length covering these intervals. Then, it compares the boundary distance of the target location in each behavioral interval with the minimum interval length to obtain a time series ranking factor. Next, it compares the behavioral coefficient of the target location with the behavioral coefficients of multiple visits within the corresponding behavioral interval to obtain a behavioral performance deviation factor. Combining these two factors, it calculates the location influence index of the target location (characterizing the degree of influence of location on the target user's movement behavior), which is directly output to the encryption control module 3.

[0042] Encryption control module 3 is the system's privacy protection execution unit, responsible for formulating and executing differentiated encryption strategies based on the location influence index to ensure secure data storage.

[0043] In some implementations, the encryption control module 3 includes an encryption level calculation submodule 31 and a differential encryption submodule 32:

[0044] The encryption level calculation submodule 31 receives the location influence index output by the influence evaluation module 2, compares the change in the location influence index of the target location in the current time period with that of the previous time period, and combines the change in the change in multiple consecutive time periods to determine the relative change magnitude. Then, it selects a continuous time period with the same change trend as the current time period as a reference period, compares the location influence index of the current time period with the index average of the reference period, and determines the relative location influence index. Combining the relative change magnitude and the relative location influence index, the encryption level determination factor is calculated.

[0045] The differentiated encryption submodule 32 maps the encryption level determination factor to four preset encryption levels (level 1, level 2, level 3, and level 4), and performs encryption operations through corresponding physical devices: for level 1, a first-strength symmetric encryption device (such as an advanced encryption standard (AES)-128 encryption module) is used; for level 2, a higher-strength second-strength symmetric encryption device (such as an AES-256 encryption module) is used; for level 3, a combination of a second-strength symmetric encryption device and an asymmetric encryption device (such as an RSA-2048 encryption module) is used for double encryption; for level 4, a hardware security module (HSM) is used for key management, and a dedicated security server is used to achieve physical isolation between data processing and storage; the encrypted location data is sent back to the storage sorting submodule 13 of the data acquisition module 1 to complete secure storage.

[0046] Please see Figure 2 The diagram illustrates a flowchart of a method for protecting user privacy data security on a cloud platform, according to an embodiment of the present invention. This method includes:

[0047] S1. Obtain the location time sequence of the target user's access within multiple time periods.

[0048] In some implementations, raw location data, including location coordinates, timestamps, and user identifiers, is acquired by deploying a data acquisition module on the target user's terminal device. This raw location data is then transmitted via encrypted communication protocols (such as HTTPS) to prevent theft, tampering, or interception during public network transmission, ensuring the security of the data transmission link. After the data is transmitted to the cloud platform backend, a dedicated data access service verifies the validity of the raw location data, filtering out invalid data with incorrect formats, logical contradictions, or abnormal forgery, ensuring the availability of data entering the storage stage. Finally, the verified raw location data is stored in a database isolated from the public network, avoiding the risk of data leakage due to attacks on the public network.

[0049] When applied, the location coordinates of the target user in multiple time periods (which can be adjusted according to the actual scenario, for example, a single time period can be set to 30 days) are extracted from the database by user identifier and sorted according to the corresponding timestamps to form a location time sequence.

[0050] Furthermore, this method can also perform desensitization and region mapping operations on the original location coordinates in the location time series: extracting the specific location coordinates of the target user in the location time series, and using a preset hash encryption algorithm (such as the secure hash algorithm (SHA) 256 algorithm) to encrypt and map the coordinates, transforming latitude and longitude data with explicit geographical information into location identifiers containing only unique identifiers, avoiding direct exposure of the original location coordinates and minimizing the risk of user location information leakage. Simultaneously, because the SHA256 algorithm has the characteristic that the same input corresponds to the same output, when the target user repeatedly arrives at the same original location, the encrypted location identifier remains consistent, enabling accurate identification of access behavior to the same location.

[0051] S2. For each time period, perform time series feature analysis based on the location time series to determine the location influence index for each location.

[0052] Among them, the location influence index is used to characterize the degree of influence of location on the target user's mobile behavior.

[0053] In one possible implementation, combining Figure 2 ,like Figure 3 As shown, the method in S2 above can be specifically implemented through the following steps S21 to S23, which are explained in detail below:

[0054] S21. Extract the access behavior features of the target user for each visit from the location time series, and determine the location sensitivity of the target user for each location for each visit.

[0055] Among these, access behavior characteristics include access frequency and access duration. Location sensitivity refers to the target user's sensitivity to changes in the access characteristics of a location. That is, when the target user's access behavior (stay time / frequency) at a certain location changes, the more easily the change is identified, the higher the location sensitivity.

[0056] In some implementations, firstly, for each visit, the duration of this visit is compared with the average visit duration of the target user at the current location to determine the first sensitivity factor for each visit, denoted as:

[0057]

[0058] In the formula, This represents the duration of the target user's stay at the j-th location during the q-th visit; This represents the average duration of all visits by the target user to the j-th location across the Q visits, i.e., the average visit duration.

[0059] This represents the relative proportion of the current dwell time to the historical average dwell time. Subtracting 1 and taking the absolute value yields the degree of deviation of the current dwell time from the historical average, which is the first sensitivity factor for the target user's q-th visit to the j-th location. The greater the deviation, The larger it is. Specifically, if q=1, meaning this is the first visit, then... , This can objectively reflect the state of having no historical reference.

[0060] Simultaneously, for each location, the nearest neighboring location with the smallest distance is selected from the locations visited by the target user in the current time period. The number of times the target user visits the current location is compared with the number of times the target user visits the nearest neighboring locations, thus determining the second sensitivity factor for each location, expressed as:

[0061]

[0062] In the formula, This represents the number of times the target user has accessed the j-th location; This represents the number of times the target user has visited the neighboring locations of the j-th location (the neighboring locations are visited locations, and the number of visits is not 0).

[0063] This represents the relative percentage of visits to the current location compared to visits to neighboring locations, i.e., the target user's second sensitivity factor for the j-th location. The frequency of visits to this location is higher than that of nearby locations. The larger.

[0064] Finally, based on the first and second sensitivity factors, the location sensitivity of the target user for each location per visit is determined, expressed as:

[0065]

[0066] In the formula, and These are the weights of the first and second sensitive factors, respectively. < , For example, take , .

[0067] First sensitive factor The higher the sensitivity, the more significant the change in visit duration, a key visit characteristic; location sensitivity. The higher the perception of changes in dwell time, the more sensitive the frequency of visits (i.e., the second sensitivity factor) is. This is directly related to the user's core activity area, which is usually a fixed scenario that requires high sensitivity. As the dominant indicator of location sensitivity, it has a large weight.

[0068] Second sensitive factor The higher the frequency of visits, the easier it is to perceive changes in this access characteristic, and the higher the location sensitivity. The higher the perception of changes in access frequency, the more sensitive the dwell time deviation (i.e., the first sensitivity factor) is to the fluctuation of access time in the associated scenario. This is an auxiliary quantitative indicator of location sensitivity, rather than a direct determining factor, and has a smaller weight.

[0069] Through the first sensitive factor With the second sensitive factor By weighted summation, combining abnormal deviations in dwell time with the relative frequency of location access, the dominance of core privacy scenarios is highlighted while retaining the auxiliary judgment value of fluctuations in visit duration. This comprehensive quantification of the sensitivity to changes caused by a single visit yields the target user's location sensitivity to the j-th location on the q-th visit. , The larger the value, the more sensitive the position.

[0070] S22. Based on the temporal changes in location sensitivity, the location time series is divided into multiple behavioral intervals.

[0071] In some implementations, a behavioral coefficient for each visit is determined based on the location sensitivity of each visit and the location sensitivity of multiple historical visits. The behavioral coefficient characterizes the degree of difference between the target user's current visit and multiple historical visits. Specific methods for determining the behavioral coefficient include:

[0072] First, configure the observation window for the location time series: set the initial size of the observation window to 0 and the expansion step size to 1. This window slides sequentially along the time sequence of the location time series, and after each slide, synchronously acquire the location sensitivity corresponding to the current location. When the (j+1)th location is added to the current window during the q-th visit, extract the difference between the sensitivity of that location and the two parts:

[0073] The first part compares the location sensitivity of this visit with the location sensitivity of multiple historical visits to this location to determine the single-time change index of the location sensitivity of this visit, expressed as:

[0074]

[0075] In the formula, This represents the position sensitivity of the (j+1)th position during the qth visit; This represents the position sensitivity of the (j+1)th position during the (q-1)th access. This represents the average sensitivity of all positions visited during the (j+1)th position in the previous q-1 visits.

[0076] The single-time change index is obtained by calculating the difference between the position sensitivity of the (j+1)th position on the qth visit and the position sensitivity of the previous visit, relative to the average historical position sensitivity. This characterizes the magnitude and direction of a single change in the location's access characteristics. Specifically, if q=1, there are no previous q-1 visits, and the single change index is defined as 0, not included in the formula calculation.

[0077] The second part determines the overall change index of location sensitivity during the preceding period based on the target user's location sensitivity to multiple visits to any location within the preceding time period, expressed as:

[0078]

[0079] In the formula, This represents the position sensitivity of all positions before the (j+1)th position is visited for the wth time; n represents the total number of visits to all positions before the (j+1)th position is visited for the qth time. This represents the average sensitivity of all positions up to the (j+1)th position during the qth visit; It represents the standard deviation of the sensitivity of all positions up to the (j+1)th position when the qth visit is made.

[0080] The overall change index is obtained by calculating the average amplification level of the deviation of the sensitivity of all positions before the (j+1)th position at the qth visit from the window mean. This characterizes the difference in the distribution of the original position sensitivity within the window. Among them, The parameter q is used to determine the degree of deviation between the sensitivity and the mean within the nonlinear amplification window. Its value range is [2, 4]. This achieves the amplification effect while avoiding excessive amplification of extreme values, preventing a few extremely large deviations from dominating the overall summation result and distorting the behavioral coefficients. Specifically, if q = 1, then n = 0, defining the overall change index as 0, which is not included in the formula calculation.

[0081] Next, based on the single change index and the overall change index, the behavioral coefficient for this visit is determined, expressed as:

[0082]

[0083] In the formula, the single change index and overall change indicators Multiplication yields the behavior coefficient. This comprehensively reflects the combined impact of changes in the location's own behavior and the current window's behavior distribution on the degree of difference. Among these, the single-change index... The larger the value, the more significant the difference between the behavior characteristics of this visit and historical behavior, and the greater the difference in behavior coefficient. Positive correlation; overall change indicators The larger the value, the more dispersed the behavioral characteristics of the original positions within the window, and the more difficult it is for the new positions to integrate into the current behavioral pattern, which is related to the behavior coefficient. They are positively correlated.

[0084] Then, the changing trend of the behavioral coefficient difference between consecutive visits in the location time series is analyzed. Using the visit location corresponding to the peak of the behavioral coefficient difference as the cutoff, the location time series is divided into multiple behavioral intervals. Specifically, this includes:

[0085] The behavioral coefficients obtained after each window expansion are arranged in chronological order to obtain a behavioral coefficient sequence. The difference between adjacent elements in the behavioral coefficient sequence is calculated, and the absolute value of the difference is taken to form a sequence of absolute difference values. The automatic multiscale-based peak detection (AMPD) algorithm is used to identify the extreme points in the sequence of absolute difference values.

[0086] It's important to note that the behavior coefficient sequence is a quantified value of the correlation between user access behaviors arranged chronologically. Taking the absolute value of the difference between adjacent elements measures the amplitude of behavioral pattern fluctuations between two consecutive visits (focusing only on the significance of the change, not the direction of the fluctuation). The extreme points in the absolute value sequence correspond to locations where the behavioral pattern fluctuations between adjacent visits are particularly drastic, indicating a significant difference in the behavioral characteristics (relationship between dwell time and access frequency) between two consecutive visits. These are critical nodes where user access behavior patterns switch. By using the positions corresponding to these extreme points as cutoff points to divide intervals, consecutive access segments with consistent behavioral characteristics can be divided into independent behavioral intervals, thus accurately classifying different user access behaviors.

[0087] The identified extreme points are mapped back to the original behavioral coefficient sequence. For each extreme point, two adjacent behavioral coefficients are found, and the sequence is truncated between these two coefficients. This process is repeated for all extreme points to complete the sequence splitting. The set of positions corresponding to each split subsequence constitutes a behavioral interval. Time-series segments with consistent sensitivity change characteristics are divided into independent behavioral intervals.

[0088] S23. Determine the positional influence index of each position based on at least one behavioral interval to which each position belongs in the positional time series.

[0089] In some implementations, the target location is any position in the time-series location sequence. Taking the target location as an example: First, as... Figure 4 As shown, at least one behavioral interval to which the target position belongs is aligned according to the target position, and the minimum interval length covering at least one behavioral interval is determined. In particular, if two (or more) identical positions appear in a behavioral interval, they are aligned with each of those positions as the center position to avoid local deviations caused by a single occurrence of a position.

[0090] Then, for each behavior interval to which the target location belongs, the temporal ranking factor of the target location in each behavior interval is determined by comparing the boundary distance of the target location in the behavior interval with the minimum interval length, as expressed as:

[0091]

[0092] In the formula, This represents the distance from the j-th position to the end of the sequence within the S-th row interval, i.e., the boundary distance.

[0093] L represents the minimum number of positions in the minimum interval that covers the k behavior intervals to which the j-th position belongs (at least one interval must be covered, L≥1), i.e., the minimum interval length. This represents the boundary distance centered at the j-th position, serving as the benchmark for time-series ranking.

[0094] By comparing the relative relationship between the temporal position of the j-th position in the S-th behavioral interval and the minimum interval length benchmark, the temporal ranking factor of the j-th position in the S-th behavioral interval is obtained. .

[0095] Next, for each behavior interval to which the target location belongs, the behavior coefficient of the target location is compared with the behavior coefficients of multiple visits within the behavior interval to determine the behavior deviation factor of the target location in each behavior interval, expressed as:

[0096]

[0097] In the formula, This represents the behavior coefficient of the j-th position in the S-th behavior interval; This represents the average behavior coefficient across all positions within the S-th behavior interval; It represents the standard deviation of the behavior coefficients at all positions within the S-th behavior interval.

[0098] By comparing the fluctuation of the behavior coefficient of the j-th position in the S-th behavior interval with the overall fluctuation of the interval, the deviation factor of the behavior of the j-th position in the S-th behavior interval is obtained. Specifically, if the standard deviation of the behavioral coefficients for all positions within the S-th behavioral interval is 0, it indicates that the behavioral coefficients for all positions, including the j-th position, are completely consistent, and a behavioral deviation factor is directly defined. =0, does not participate in the formula calculation.

[0099] Finally, based on the temporal ranking factor and behavioral performance deviation factor corresponding to each behavioral interval, the positional influence index of the target position is determined, expressed as:

[0100]

[0101] In the formula, the time-series ranking factor The larger the value, the farther the j-th position is from the end of the interval, the greater the difference in interval between it and the abnormal position at the end, and the earlier its influence position is in the interval. It is positively correlated with the degree of influence of the j-th position; behavioral deviation factor. The larger the value, the more significant the behavioral fluctuation at position j (positive value indicates above the interval mean, negative value indicates below the interval mean), and the more likely it is to produce positive or negative effects.

[0102] By time-series ranking factor Deviation factor from behavioral performance Multiplying these values ​​yields the degree and direction of influence of the j-th position within the S-th action interval. Then, summing these values ​​across k intervals yields the overall directional influence of the j-th position across all its action intervals, i.e., the position influence index. This reflects the combined influence of the j-th position's temporal location (interval with abnormal positions) and behavioral fluctuations (difference from the overall interval) on the abnormal behavior within the interval. Position Influence Index The larger the absolute value of j, the stronger the influence of j on the abnormal behavior of the behavior range.

[0103] S3. Based on the changes in the position influence index of each location over multiple time periods, determine the data encryption level corresponding to each location, and encrypt and store the data of each location according to the data encryption level.

[0104] In some implementations, taking the target location as an example: First, compare the change in the position influence index of the current time period with that of the previous time period. Then, combine this with the change in the position influence index of the target location across multiple consecutive time periods to determine the relative change in the position influence index of the target location in the current time period, expressed as:

[0105]

[0106] In the formula, This represents the positional influence index of the j-th position within the z-th time period; This represents the positional influence index of the j-th position within the (z-1)-th time period; It represents the range of the positional influence index of the j-th position within all time periods, that is, the absolute difference between the maximum and minimum values.

[0107] This represents the relative magnitude of the behavioral change in the current period compared to the previous period. It is then normalized by dividing by the range to obtain the relative magnitude of the positional influence index at the j-th position within the z-th time period. The value range is [0, 1]. Specifically, if the position of the j-th position influences the range of the index across all time periods... A value of 0 indicates that the positional influence index of the j-th position is consistent across all time periods, directly defining the relative change magnitude. =0, does not participate in the formula calculation.

[0108] Then, by comparing the positional influence index of the current time period with the positional influence index within the reference period, the relative positional influence index of the target location in the current time period is determined. The reference period includes time periods (including the current time period) where the trend of the positional influence index is consistent with and continuous with the current time period. For example, if the current time period is the 5th time period, and the positional influence indices for the 5 time periods are (5, 3, 4, 6, 7), and the trends from the 2nd time period onwards compared to the previous time period are (decreasing, increasing, increasing, increasing), then the 3rd to 5th consecutive time periods are selected as the reference period with the same trend.

[0109] The relative position influence index is expressed as:

[0110]

[0111] In the formula, This represents the positional influence index of the j-th position within the z-th time period.

[0112] If there is a reference period with the same trend in the z-th time period and These represent the maximum and minimum values ​​of the positional influence index at the j-th position within the same trend reference period, respectively; if there is no same trend reference period for the z-th time period, and Let $j$ represent the maximum and minimum values ​​of the position-influence index of the j-th position across all historical periods (excluding the current period). If the data exceeds the historical range, it is considered an abnormal scenario and can be handled by truncation (e.g., greater than...). hour Take 1, less than hour Take 0).

[0113] This represents the relative level of the current cycle influence index compared to a reference period or historical period with the same trend, yielding the relative position influence index of the j-th position within the z-th time period. The value range is [0, 1]. Specifically, if the difference between the maximum and minimum values ​​in the same trend reference period or historical period is 0, it indicates that the current position's influence on the index is not fluctuating, and the relative change amplitude is directly defined. =0, not included in the formula calculation. If the z-th time period is the first time period appearing at the j-th position, and there is no historical reference, the current period is assumed to be at a neutral relative level. The value is set to 0.5 to avoid misjudgment based on extreme values.

[0114] Next, based on the relative change magnitude of the target location's influence on the index within the current time period and the relative position influence index, the encryption level determination factor is determined, expressed as:

[0115]

[0116] In the formula, the relative change range The larger the value, the greater the behavioral fluctuation in the current time period compared to the overall fluctuation in the entire period. This indicates that the access behavior at this location deviates from the user's usual pattern and is often associated with higher privacy risks. It is positively correlated with encryption strength.

[0117] Relative position influence index The larger the value, the greater the influence of that position within the current time period compared to the same trend period or historical periods, and it is positively correlated with encryption strength.

[0118] Since the highest encryption level is only required when a location simultaneously meets the criteria of significant behavioral fluctuations (deviation from the norm) and high relative influence (associated with a core location), and a location that only meets one of these criteria does not pose sufficient privacy risk to justify high encryption, the relative magnitude of change is chosen. Relative position influence index Multiply to calculate the encryption level determination factor at position j within the z-th time period. The value range is [0, 1]. The larger the value, the stronger the encryption.

[0119] Finally, the encryption level determination factor is mapped to multiple preset encryption levels to determine the data encryption level corresponding to the target location within the current time period.

[0120] In some implementations, multiple preset encryption levels include: Level 1 (corresponding to an encryption level determination factor of, for example, 0-0.25), Level 2 (corresponding to an encryption level determination factor of, for example, 0.25-0.5), Level 3 (corresponding to an encryption level determination factor of, for example, 0.5-0.75), and Level 4 (corresponding to an encryption level determination factor of, for example, 0.75-1). The encryption level thresholds can be dynamically adjusted according to the security policy. Level 1 location data is processed using a first-strength symmetric encryption algorithm (such as AES-128); Level 2 location data is processed using a second-strength symmetric encryption algorithm (such as AES-256), where the second strength is higher than the first strength; Level 3 location data is encrypted using a combination of a second-strength symmetric encryption algorithm (such as AES-256) and an asymmetric encryption algorithm (such as RSA-2048); and Level 4 location data is processed using a key management method based on a hardware security module.

[0121] Based on the above technical solution, by acquiring the location time series of the target user over multiple time periods and combining time series feature analysis to quantify the impact of each location on the user's movement behavior, this replaces the uniform encryption strategy in the existing technology. It can adapt to the dynamic changes in the privacy sensitivity characteristics of different locations based on the changes in the location influence index over multiple periods, achieving personalized privacy protection. At the same time, it can avoid the waste of computing resources caused by excessive encryption of low-sensitivity locations, while ensuring the privacy security of high-sensitivity locations. This effectively balances the privacy protection effect and resource utilization efficiency of cloud platform user location data.

[0122] It should be noted that the order of the above embodiments of the present invention is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. The processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0123] The various embodiments in this specification are described in a progressive manner. The same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on describing the differences from other embodiments.

[0124] In this embodiment of the invention, the user privacy data security protection device for cloud platforms can be divided into functional units according to the above method example. For example, each function can be divided into its own functional unit, or two or more functions can be integrated into one processing unit. The integrated unit can be implemented in hardware or as a software functional unit. It should be noted that the unit division in this embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.

[0125] This invention also provides a hardware structure diagram of a user privacy data security protection device for cloud platforms, see [link / reference]. Figure 5 The cloud-based user privacy data security protection device 500 includes a processor 501, and optionally, a memory 502 connected to the processor 501.

[0126] In the first possible implementation, see Figure 5 The user privacy data security protection device 500 for cloud platforms also includes a transceiver 503. The processor 501, memory 502, and transceiver 503 are connected via a bus. The transceiver 503 is used to communicate with other devices or communication networks. Optionally, the transceiver 503 may include a transmitter and a receiver. The device in the transceiver 503 that implements the receiving function can be considered as a receiver, which is used to perform the receiving steps in the embodiments of the present invention. The device in the transceiver 503 that implements the transmitting function can be considered as a transmitter, which is used to perform the transmitting steps in the embodiments of the present invention.

[0127] Based on the first possible implementation method Figure 5 The structural diagram shown can be used to illustrate the structure of the user privacy data security protection device for cloud platforms involved in the above embodiments.

[0128] in, Figure 5 This can also be illustrated by a system chip in a cloud-based user privacy data security protection device. In this case, the actions performed by the aforementioned cloud-based user privacy data security protection device can be implemented by this system chip; the specific actions performed are described above and will not be repeated here.

[0129] In implementation, each step of the method provided in this embodiment can be completed by integrated logic circuits in the processor or by instructions in software form. The steps of the method disclosed in this embodiment can be directly manifested as being executed by a hardware processor, or being executed by a combination of hardware and software modules in the processor.

[0130] The processor in this invention may include, but is not limited to, at least one of the following: a central processing unit (CPU), a microprocessor, a digital signal processor (DSP), a microcontroller unit (MCU), or an artificial intelligence processor, etc., which are various computing devices that run software. Each computing device may include one or more cores for executing software instructions to perform calculations or processing. The processor may be a standalone semiconductor chip or integrated with other circuits into a single semiconductor chip. For example, it may be integrated with other circuits (such as encoding / decoding circuits, hardware acceleration circuits, or various bus and interface circuits) to form a System-on-a-Chip (SoC), or it may be integrated as a built-in processor within an ASIC. The ASIC with the integrated processor may be packaged separately or together with other circuits. In addition to the cores for executing software instructions to perform calculations or processing, the processor may further include necessary hardware accelerators, such as field-programmable gate arrays (FPGAs), programmable logic devices (PLDs), or logic circuits that implement dedicated logic operations.

[0131] The memory in the embodiments of the present invention may include at least one of the following types: read-only memory (ROM) or other types of static storage devices capable of storing static information and instructions; random access memory (RAM) or other types of dynamic storage devices capable of storing information and instructions; or electrically erasable programmable read-only memory (EEPROM). In some scenarios, the memory may also be a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto.

[0132] This invention also provides a computer-readable storage medium including instructions that, when run on a computer, cause the computer to perform any of the methods described above.

[0133] This invention also provides a computer program product containing instructions that, when run on a computer, cause the computer to perform any of the methods described above.

[0134] This invention also provides a chip, which includes a processor and an interface circuit. The interface circuit is coupled to the processor. The processor is used to run computer programs or instructions to implement the above-described method. The interface circuit is used to communicate with other modules outside the chip.

[0135] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented using software programs, implementation can be, in whole or in part, in the form of a computer program product. This computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present invention are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device containing one or more servers, data centers, etc., that can be integrated with the medium. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state disks (SSDs)).

[0136] Although the invention has been described herein in conjunction with various embodiments, those skilled in the art, by reviewing the accompanying drawings and the disclosure, will understand and implement other variations of the disclosed embodiments in carrying out the claimed invention. In this invention, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude a plurality. A single processor or other unit can implement several of the functions listed in this invention.

[0137] Although the invention has been described in conjunction with specific features and embodiments, it is obvious that various modifications and combinations can be made therein without departing from the spirit and scope of the invention. Accordingly, this specification and drawings are merely illustrative of the invention and are to be considered as covering any and all modifications, variations, combinations, or equivalents within the scope of the invention. Clearly, those skilled in the art can make various alterations and modifications to the invention without departing from its spirit and scope. Thus, if such modifications and modifications of the invention fall within the scope of the invention and its equivalents, the invention is also intended to include such modifications and modifications.

Claims

1. A method for protecting user privacy data security on a cloud platform, characterized in that, include: Obtain the location time sequence of target user access within multiple time periods; For each visit, compare the duration of this visit with the average visit duration of the target user at the current location to determine the primary sensitivity factor for each visit; For each location, compare the number of times the target user visits the current location with the number of times the target user visits the neighboring locations of the current location to determine the second sensitivity factor for each location; Based on the first sensitivity factor and the second sensitivity factor, determine the location sensitivity of the target user for each location and each visit; Based on the temporal changes in the location sensitivity, the location temporal sequence is divided into multiple behavioral intervals; For any target location in the location time series, align at least one behavior interval to which the target location belongs according to the target location, and determine the minimum interval length covering the at least one behavior interval; For each behavior interval to which the target location belongs, compare the boundary distance of the target location in the behavior interval with the minimum interval length to determine the temporal ranking factor of the target location in each behavior interval; For each behavior interval to which the target location belongs, the behavior coefficient of the target location is compared with the behavior coefficients of multiple visits within the behavior interval to determine the behavior performance deviation factor of the target location in each behavior interval; based on the time-series ranking factor and behavior performance deviation factor corresponding to each behavior interval, the location influence index of the target location is determined; the location influence index is used to characterize the degree of influence of location on the target user's mobile behavior; Based on the changes in the location influence index of each location over multiple time periods, the data encryption level corresponding to each location is determined, and the data of each location is encrypted and stored according to the data encryption level.

2. The method for protecting user privacy data security according to claim 1, characterized in that, Based on the temporal changes in the location sensitivity, the location temporal sequence is divided into multiple behavioral intervals, including: The behavioral coefficient for each visit is determined based on the location sensitivity of each visit and the location sensitivity of multiple historical visits; the behavioral coefficient is used to characterize the degree of difference between the target user's current visit and multiple historical visits. The changing trend of the behavioral coefficient difference between consecutive visits in the location time series is analyzed, and the access position corresponding to the peak of the behavioral coefficient difference is used as the cutoff point to divide the location time series into multiple behavioral intervals.

3. The method for protecting user privacy data security according to claim 2, characterized in that, Based on the location sensitivity of each visit and the location sensitivity of multiple historical visits, the behavioral coefficients for each visit are determined, including: For each visit, compare the location sensitivity of this visit with the location sensitivity of multiple historical visits to the location of this visit to determine the single change index of the location sensitivity of this visit; Based on the target user's location sensitivity to multiple visits to any location within the preceding time period, determine the overall change index of location sensitivity within the preceding time period; The behavioral coefficients for this visit are determined based on the single change index and the overall change index.

4. The user privacy data security protection method according to claim 1, characterized in that, The target location is any position in the time sequence of the location; Based on the changes in the influence index of the target location over multiple time periods, the data encryption level corresponding to the target location is determined, including: For the target location, compare the change in the index caused by the current location in the previous time period with the change in the index caused by the current location. Combine the change in the index caused by the target location in multiple consecutive time periods to determine the relative change in the index caused by the target location in the current time period. For a target location, the location influence index in the current time period is compared with the location influence index in the reference period to determine the relative location influence index in the current time period; the reference period includes time periods in which the change trend of the location influence index is consistent with the current time period and is continuous with the current time period. The encryption level determination factor is determined based on the relative change magnitude of the index and the relative position influence index of the target location in the current time period. The encryption level determination factor is mapped to multiple preset encryption levels to determine the data encryption level corresponding to the target location within the current time period.

5. The user privacy data security protection method according to claim 4, characterized in that, The multiple encryption levels include: Level 1, Level 2, Level 3, and Level 4; data at each location is encrypted and stored according to the data encryption level, including: The location data of the first level is processed using a symmetric encryption algorithm of the first strength; The location data at the second level is processed using a symmetric encryption algorithm of second strength; the second strength is higher than the first strength. The location data at the third level is encrypted using a combination of a second-strength symmetric encryption algorithm and an asymmetric encryption algorithm. The location data at the fourth level is processed using a key management method based on a hardware security module.

6. The method for protecting user privacy data security according to claim 1, characterized in that, Obtain the location time series sequence of the target user's access within multiple time periods, including: By deploying a data acquisition module on the target user's terminal device, raw location data containing location coordinates, timestamps, and user identifiers can be obtained; The original location data is transmitted through an encrypted communication protocol, and the validity of the original location data is verified. The verified original location data is stored in a database isolated from the public network; From the database, the location coordinates of the target user within multiple time periods are extracted according to the user identifier and sorted according to the corresponding timestamps to form the location time series.

7. A user privacy data security protection system for cloud platforms, characterized in that, include: Data acquisition module, impact assessment module, and encryption control module; The data acquisition module is used to acquire the location time sequence of the target user's access within multiple time periods; The impact assessment module is used to compare the duration of each visit with the average visit duration of the target user at the current location to determine the first sensitive factor for each visit. For each location, compare the number of times the target user visits the current location with the number of times the target user visits the neighboring locations of the current location to determine the second sensitivity factor for each location; Based on the first sensitivity factor and the second sensitivity factor, determine the location sensitivity of the target user for each location and each visit; Based on the temporal changes in the location sensitivity, the location temporal sequence is divided into multiple behavioral intervals; For any target location in the location time series, align at least one behavior interval to which the target location belongs according to the target location, and determine the minimum interval length covering the at least one behavior interval; For each behavior interval to which the target location belongs, compare the boundary distance of the target location in the behavior interval with the minimum interval length to determine the temporal ranking factor of the target location in each behavior interval; For each behavior interval to which the target location belongs, the behavior coefficient of the target location is compared with the behavior coefficients of multiple visits within the behavior interval to determine the behavior performance deviation factor of the target location in each behavior interval; based on the time-series ranking factor and behavior performance deviation factor corresponding to each behavior interval, the location influence index of the target location is determined; the location influence index is used to characterize the degree of influence of location on the target user's mobile behavior; The encryption control module is used to determine the data encryption level corresponding to each location based on the changes in the location influence index of each location over multiple time periods, and to encrypt and store the data of each location according to the data encryption level.