Big data privacy protection system in cloud environment
By using a multi-source data collection and comprehensive analysis module, combined with dynamic factors, the big data privacy protection strategy in the cloud environment is dynamically adjusted, solving the problem of unbalanced field protection in existing technologies and achieving a precise balance between privacy protection and data utilization.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GUANGZHOU VOCATIONAL COLLEGE OF SCI & TECH
- Filing Date
- 2025-12-19
- Publication Date
- 2026-04-10
AI Technical Summary
Existing big data privacy protection methods in the cloud environment fail to prioritize data fields based on their actual privacy impact, resulting in over- or under-protection of high-risk fields. Furthermore, the lack of real-time integration of dynamic factors leads to resource waste and reduced data availability.
The system employs a multi-source privacy feature data acquisition module, a privacy data preprocessing module, a privacy data comprehensive analysis module, and a privacy protection strategy dynamic execution module. By analyzing the ethical sensitivity level, social harm coefficient, uniqueness index, patient personalized preference coefficient, and vulnerable group association coefficient of sensitive fields, and combining the access popularity of data blocks, the compliance history of recipients, and the trust level of access requests, the system dynamically adjusts protection measures.
It achieves differentiated protection for different fields and data blocks, dynamically adjusts resource allocation, improves data security and availability, meets ethical and compliance requirements, and enhances the system's competitiveness and user trust.
Smart Images

Figure CN121834883A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data access control, in particular to a big data privacy protection system in a cloud environment. BACKGROUND
[0002] With the rapid development of cloud computing technology, big data in medical and financial fields is gradually migrated to cloud platforms, realizing centralized storage and sharing of data. For example, medical big data, medical data sharing in a cloud environment supports remote diagnosis, multi-center scientific research cooperation and public health monitoring scenarios, but also brings serious privacy protection challenges. Medical data contains a large amount of sensitive information, and once leaked, it will cause serious consequences such as ethical harm and social discrimination to patients. Therefore, a big data privacy protection system in a cloud environment is needed.
[0003] The existing big data privacy protection method in a cloud environment may be relatively homogeneous in the protection strategy for sensitive fields in patient medical data, without distinguishing priorities according to the actual privacy impact of the fields, resulting in the same protection measures being taken for high-risk fields and low-risk fields, or over-protection (such as encrypting height fields leading to low data sharing efficiency), or insufficient protection (such as simple desensitization of genetic sequences causing privacy leakage).
[0004] In addition, the risk assessment of the existing technology for data blocks may only rely on static attributes (such as data type), and may not integrate dynamic factors such as access frequency and receiver compliance history in real time, resulting in high-risk data blocks that may not be subject to targeted enhanced protection, and low-risk data blocks that may be continuously encrypted redundantly, wasting cloud resources and reducing data availability. SUMMARY
[0005] The present application aims to provide a big data privacy protection system in a cloud environment, which solves the problems raised in the background art.
[0006] To achieve the above purpose, the present application provides a big data privacy protection system in a cloud environment, comprising:
[0007] A multi-source privacy feature data acquisition module is used to obtain sensitive field associated data, data block privacy associated data and access request associated data in medical data.
[0008] A privacy data preprocessing module is used to input the sensitive field associated data, data block privacy associated data and access request associated data obtained by the multi-source privacy feature data acquisition module. The privacy data preprocessing module cleans the input data and inputs the cleaned data into the privacy data comprehensive analysis module.
[0009] A privacy data comprehensive analysis module is used to analyze the cleaned data and obtain the privacy protection strategy of the sensitive field.
[0010] Based on the medical ethics sensitivity level, social harm coefficient, uniqueness index, patient personalized preference coefficient and vulnerable group association coefficient of the sensitive field i in the sensitive field association data, and performing weighted processing, the privacy weight of the sensitive field i is output, which provides a quantitative basis for the field protection priority for the system through the privacy weight of the sensitive field i, so that the system can take differentiated measures for fields with different weights;
[0011] Based on the recent access heat of the data block j, the privacy violation history coefficient of the data block j receiver and the encryption strength compensation factor of the data block j in the data block privacy association data, and combining the privacy weight of the sensitive field i, the data block j privacy risk score is output by summing processing, and the real-time risk level of the data block is marked through the data block j privacy risk score, so that the system can dynamically adjust the data block protection state;
[0012] Based on the trust level of the initiator of the access request k, the purpose compliance coefficient of the access request k and the patient emergency state coefficient corresponding to the access request k in the access request association data, and combining the privacy weight of the sensitive field i and the data block j privacy risk score, the access request k authorization decision value is output;
[0013] The privacy protection strategy dynamic execution module is used for inputting the privacy weight of the sensitive field i, the data block j privacy risk score and the access request k authorization decision value output by the privacy data comprehensive analysis module. The privacy protection strategy dynamic execution module executes privacy protection measures based on the input data.
[0014] Optionally, the privacy data comprehensive analysis module comprises a sensitive weight unit, a privacy risk unit and an access decision unit.
[0015] Optionally, the processing process of the sensitive weight unit is as follows:
[0016] A1, the sensitive data of the patient medical data is analyzed field by field, the severity of the field leakage violating the ethical criteria is analyzed, the parameter is assigned based on multiple cases, and the medical ethics sensitivity level of the sensitive field i is output;
[0017] A2, the number of social harm events caused by the leakage of the field i in the case library is counted, and the negative impact of the leakage on the patient's employment and social life is analyzed, and the social harm coefficient of the sensitive field i is output;
[0018] A3, the uniqueness index of the sensitive field i is calculated by combining the number of unique values of the field i and the total number of registered patients in the cloud platform, and the rarity of the field value in the data set is analyzed;
[0019] A4, reflecting the degree of rejection of unauthorized access by the patient by the patient's selection in the cloud platform privacy setting interface, to output the patient's personalized preference coefficient of the sensitive field i according to the patient's requirements;
[0020] A5, calculating the vulnerable group correlation coefficient of the sensitive field i by analyzing the medical group situation and level of the patient to which the field belongs;
[0021] A6, weighting the above steps to finally output the privacy weight of the sensitive field i.
[0022] Optionally, the processing process of the privacy risk unit is as follows:
[0023] B1, providing the field sensitivity basis for data block risk assessment by introducing the privacy weight of the sensitive field i, and combining it with the binary variable 1;
[0024] B2, calculating the recent access heat of the data block j by counting the number of requests in the cloud platform access log in the past 30 days, and combining it with the access heat weight coefficient;
[0025] B3, reflecting the severity and frequency of privacy violation events of the receiver in a certain period of time by combining the severity level of the mth violation with the time decay factor, to calculate the privacy violation history coefficient of the receiver of the data block j;
[0026] B4, assigning values to the encryption strength value based on different encryption forms to reflect the degree of offset of the encryption method to the leakage risk, to calculate the encryption strength compensation factor of the data block j, and finally output the privacy risk score of the data block j.
[0027] Optionally, the processing process of the access decision unit is as follows:
[0028] C1, providing the field sensitivity basis for authorized decision by introducing the privacy weight of the sensitive field i into the access decision unit;
[0029] C2, making the overall risk of the data block into the decision by introducing the privacy risk score of the data block j into the access decision unit;
[0030] C3, reflecting the user compliance operation history by combining the number of compliance operations with the total number of operations, to output the trust level of the initiator of the access request k;
[0031] C4, assigning values according to the analysis of different use scenarios of medical privacy data to calculate the purpose compliance coefficient of the access request k;
[0032] C5, adjusting the flexibility of access authorization by analyzing the current medical emergency of the patient, reflecting the current medical emergency of the patient to calculate the patient emergency state coefficient corresponding to the access request k, and finally outputting the access request k authorization decision value.
[0033] Optionally, the specific operation of the privacy data preprocessing module for data cleaning is:
[0034] For removing duplicate data and completing missing data, and standardizing the data input into the privacy data preprocessing module, the field i, the data block j and the request k are bound.
[0035] Optionally, the specific execution of the privacy protection measure in the privacy protection strategy dynamic execution module is:
[0036] When the access request k authorization decision value is greater than 0.8, the protection measure is to refuse access;
[0037] When the access request k authorization decision value is greater than 0.8, the protection measure is to refuse access;
[0038] When the access request k authorization decision value is less than 0.5, the protection measure is original data access;
[0039] When the data block j privacy risk score is greater than 10, double encryption is enabled, and only authorized users can decrypt.
[0040] Optionally, the execution of the privacy protection measure further comprises:
[0041] When the protection measure is to refuse access: immediately issue a structured rejection response at the user end, record the full information of the request at the system end, including user ID, request time, target data block ID, sensitive field list involved, access request k authorization decision value, and store in the audit log, and keep for 180 days, and trigger the administrator real-time alarm;
[0042] When the protection measure is to desensitize access, differential privacy, field masking and data generalization are performed on the sensitive field;
[0043] When the protection measure is original data access, secondary identity verification, time-limited authorization, operation monitoring, access restriction and result feedback are performed.
[0044] Compared with the prior art, the beneficial effects of the present application are as follows:
[0045] I. The present application outputs the privacy weight of the sensitive field i through the sensitive weight unit, integrates the ethical sensitivity level, social harm coefficient, uniqueness index, patient personalized preference coefficient and vulnerable group correlation coefficient, balances the influence of each dimension on the privacy weight with the preset weight coefficient, and the ethical sensitivity level provides the ethical basis for field protection, the social harm coefficient reflects the social influence of field leakage, the uniqueness index identifies the field that is easy to cause identity uniqueness, the patient personalized preference coefficient respects the user's privacy autonomy, and the vulnerable group correlation coefficient protects the fields related to the vulnerable group preferentially, and the cooperative action of each parameter realizes the accurate quantization of the privacy weight of the sensitive field, and provides reliable field-level sensitive basis for subsequent data block risk assessment and access request authorization.
[0046] II. The present application outputs the privacy risk score of the data block j through the privacy risk unit, combines the sensitive field privacy weight, field existence binary variable, access heat, access heat weight coefficient, receiver privacy violation history coefficient and encryption strength compensation factor, the sensitive field privacy weight and the field existence binary variable together constitute the core sensitive basis of the data block, the access heat and the access heat weight coefficient reflect the real-time access risk of the data block, the receiver privacy violation history coefficient considers the potential risk of the data receiver, and the encryption strength compensation factor balances the offsetting effect of data encryption on the risk, and the cooperative action of each parameter realizes the comprehensive dynamic evaluation of the data block privacy risk score, and provides real-time and accurate basis for the hierarchical protection of the data block.
[0047] III. The present application outputs the authorization decision value of the access request k through the access decision unit, integrates the request involved field binary variable, data block privacy risk score, smoothing coefficient, user trust level, access purpose compliance coefficient and patient emergency state coefficient, the sensitive field privacy weight and the request involved field binary variable accurately identify the sensitivity of the request, the data block privacy risk score and the smoothing coefficient are included in the overall risk of the target data block, the user trust level and the trust level weight coefficient consider the reliability of the request initiator, the access purpose compliance coefficient, the purpose weight coefficient and the patient emergency state coefficient balance the compliance and emergency demand of the access, and the cooperative action of each parameter realizes the reasonable quantization of the access request authorization decision value, and provides dynamic and comprehensive basis for the permission control of the access request, which not only guarantees the privacy security but also considers the reasonable utilization of data. BRIEF DESCRIPTION OF DRAWINGS
[0048] Figure 1 The system block diagram of the present application is shown in the figure;
[0049] Figure 2 The system flow chart of the privacy data comprehensive analysis module and the privacy protection strategy dynamic execution module of the present application is shown in the figure;
[0050] Figure 3A running flowchart of the privacy data comprehensive analysis module of the present application. DETAILED DESCRIPTION
[0051] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of the present application.
[0052] Referring to Figures 1 to 3 The present embodiment provides a big data privacy protection system in a cloud environment, comprising:
[0053] The multi-source privacy feature data acquisition module is used to acquire sensitive field association data, data block privacy association data and access request association data in medical data.
[0054] The privacy data preprocessing module is used to input the sensitive field association data, data block privacy association data and access request association data acquired by the multi-source privacy feature data acquisition module. The privacy data preprocessing module cleans the input data, and inputs the cleaned data into the privacy data comprehensive analysis module.
[0055] Further, the data cleaning specifically includes:
[0056] The data cleaning is used to remove duplicate data and complete missing data, and standardize the data input into the privacy data preprocessing module, and bind the field i, the data block j and the request k.
[0057] The privacy data comprehensive analysis module comprises a sensitive weight unit, a privacy risk unit and an access decision unit.
[0058] Firstly, the sensitive weight unit is based on the medical ethics sensitive level, the social harm coefficient, the uniqueness index, the patient individualized preference coefficient and the vulnerable group association coefficient of the sensitive field i in the sensitive field association data, and performs weighted processing to output the privacy weight of the sensitive field i. The privacy weight of the sensitive field i provides a quantitative basis for the field protection priority of the system, so that the system can take differentiated measures for different weight fields.
[0059] Secondly, the privacy risk unit is based on the recent access heat of the data block j, the privacy violation history coefficient of the data block j receiver and the encryption intensity compensation factor of the data block j in the data block privacy association data, and combines the privacy weight of the sensitive field i to perform summation processing to output the data block j privacy risk score. The data block j privacy risk score is used to mark the real-time risk level of the data block, so that the system can dynamically adjust the data block protection state.
[0060] Thirdly, an access decision unit initiates an access request k grant decision value based on a trust level of an access request k initiator in the access request association data, a compliance coefficient of a purpose of the access request k, and a patient emergency state coefficient corresponding to the access request k, and in combination with a privacy weight of the sensitive field i and a data block j privacy risk score, to output the access request k grant decision value;
[0061] A privacy protection policy dynamic execution module is configured to input the privacy weight of the sensitive field i, the data block j privacy risk score, and the access request k grant decision value output by the privacy data comprehensive analysis module, and execute a privacy protection measure based on the input data;
[0062] Further, the privacy protection measure is specifically:
[0063] When the access request k grant decision value is greater than 0.8, the protection measure is to reject access;
[0064] When the protection measure is to reject access, a structured rejection response is immediately sent at the user end, and full information of the request is recorded at the system end, including a user ID, a request time, a target data block ID, a list of sensitive fields involved, the access request k grant decision value, and is stored in an audit log and retained for 180 days, and an administrator is triggered to give a real-time alarm;
[0065] When the access request k grant decision value is between 0.5 and 0.8, the protection measure is to perform desensitization access;
[0066] When the protection measure is to perform desensitization access, differential privacy, field masking, and data generalization are performed on the sensitive fields;
[0067] The differential privacy can add Gaussian noise to the data, and the noise intensity is positively correlated with the access request k grant decision value, for example, when the noise intensity and the access request k grant decision value = 0.8, the noise σ = 0.5, and when the noise intensity and the access request k grant decision value = 0.5, the noise σ = 0.2;
[0068] The field masking can perform data masking on the identity card and mobile phone number information in the patient medical data;
[0069] The data generalization can perform data generalization on the patient diagnosis results and patient occupation in the medical data;
[0070] When the access request k grant decision value is less than 0.5, the protection measure is to access the original data;
[0071] When the protection measure is to access the original data, secondary identity verification, time-limited authorization, operation monitoring, access restriction, and result feedback are performed;
[0072] The secondary authentication among the above is to send a 6-digit verification code to the user's bound mobile phone, and the user can access after verification;
[0073] The time-limited authorization among the above is to grant 30-minute access to raw data (timeout automatically recovers, and cannot be downloaded and copied)
[0074] The operation monitoring among the above is to record user behavior (viewing duration, click field, and whether to take screenshots) in real time and store it in audit logs;
[0075] The access restriction among the above is to prohibit batch export (a maximum of 10 records can be downloaded at a time);
[0076] The result feedback among the above is that the user receives the raw data + prompt "Your access permission will expire in 30 minutes, please operate in time", and the administrator can view the access track in the background to ensure compliance;
[0077] When the data block j privacy risk score > 10, enable double encryption (AES-256+homomorphic encryption), only authorized users can decrypt.
[0078] Based on the above, the sensitive weight unit, the privacy risk unit and the access decision unit form a full-link privacy protection closed loop from field-level evaluation, data block-level risk perception and access-level dynamic decision, covering the storage, transmission and access of the data lifecycle in the cloud environment, avoiding the blindness of indiscriminate protection through field weight quantification; through data block risk assessment, dynamic risk perception is realized, and through access decision, the authorized scenario adaptability is ensured, and the combination of the three makes the system protection more accurate;
[0079] Real-time risk calculation of the privacy risk unit and dynamic authorization of the access decision unit enable the system to respond to dynamic scenarios such as changes in data access frequency and changes in recipient risk status in the cloud environment, avoiding the lag of static protection;
[0080] The access decision unit combines access purpose and patient emergency status, allowing legal and compliant business access while strictly protecting privacy, balancing privacy protection and data value release, and solving the core contradiction between privacy and availability in the cloud environment;
[0081] The three units from the bottom field to the middle data block to the top access request build a complete privacy protection logic chain, covering the entire lifecycle of data in the cloud environment, ensuring that the privacy protection capability of the system has no dead angle;
[0082] Finally, the combination of the three units enables the big data privacy protection system in the cloud environment to shift from passive defense to active prevention, from static configuration to dynamic adaptation, from indiscriminate protection to precise measures, realizing the synergy of privacy protection and business value, and improving the core competitiveness and user trust of the system;
[0083] The following will explain the calculation system of the three groups of units in the system:
[0084] Further, different fields of patient data have differentiated sensitive properties, and overall calculation can mask the risk characteristics of high-sensitive fields, making it impossible to apply adaptive protection measures;
[0085] In the cloud environment, data is stored and transmitted in data blocks as the basic unit, and access requests usually point to specific data blocks rather than the entire patient data, and processing data blocks by data blocks conforms to the actual interaction logic of the cloud architecture;
[0086] Patient privacy preferences are strongly associated with specific fields, and if overall calculation is performed, the patient's autonomous authorization wishes for different fields may not be reflected, violating the principle of privacy autonomy;
[0087] Further, the multi-dimensional characteristics of privacy risks are accurately described, covering different levels of needs such as ethical compliance, social impact, and individual rights;
[0088] The hierarchical protection strategy provides a basis for different risk levels of fields and data blocks to obtain adaptive protection strength;
[0089] It can balance privacy protection and data value release, and avoid reducing the usability of low-risk data due to excessive protection;
[0090] Further, in the medical field and other fields with high privacy and ethical requirements, the detailed classification of the system, that is, the accurate classification of fields and data blocks, does not exist. Over-simplification, the privacy risks of medical data are associated with individual life and health, social ethics, scientific research value balance, and other complex dimensions, which must be covered by detailed classification. In non-sensitive fields, if the same degree of classification is used, there may be resource waste, but the current system is designed for medical scenarios, and its level of detail matches the needs of the scene, and it is reasonable;
[0091] The system realizes hierarchical and accurate protection, so that high-risk fields and data blocks obtain stronger encryption, access control and other measures, and low-risk parts remain moderately open;
[0092] It can improve the scientific nature of authorization decisions, and the authorization result of access requests is based on the specific fields and data blocks involved, rather than the patient's sensitive tags;
[0093] It meets the compliance requirements and satisfies the special processing requirements of sensitive data in data protection regulations, providing traceable risk assessment basis;
[0094] It is convenient to optimize system resource allocation, concentrate protection resources on high-risk objects, and improve overall protection efficiency;
[0095] The system calculates the substantial significance of sensitive cases to big data privacy protection:
[0096] Provides quantitative decision basis for privacy protection measures, replaces subjective judgment, and ensures the objectivity of protection strategies;
[0097] Supports dynamic privacy protection, enabling the system to adjust protection strength in real time according to risk changes, and adapts to the dynamic characteristics of data in the cloud environment;
[0098] Balances privacy protection and data value utilization, allowing low-risk data to be reasonably used within a safe range, and avoiding the inhibition of data value due to excessive protection;
[0099] Enhances the credibility and compliance of the system, providing clear risk assessment results for users, institutions and regulatory authorities, and meeting audit and regulatory needs;
[0100] Facilitates the transition of privacy protection from passive defense to active prevention by quantifying risks in advance and actively avoiding potential privacy leakage risks.
[0101] Please refer to Figure 1 , Figure 2 and Figure 3 , the sensitive weight unit is specifically:
[0102] A1, analyze the sensitive data of patient medical data field by field, analyze the severity of violating ethical standards by analyzing field leakage, assign parameters based on multiple cases, and output the medical ethics sensitive level of sensitive field i;
[0103] A2, analyze the negative impact on patients' employment and social life by counting the number of social harm events caused by field i leakage in the case library, and analyzing the negative impact on patients' employment and social life, and output the social harm coefficient of sensitive field i;
[0104] A3, calculate the uniqueness index of sensitive field i by combining the number of unique values of field i and the total number of patients registered on the cloud platform, to analyze the rarity of field values in the data set;
[0105] A4, according to the patient's requirement, assign values by himself through the patient's selection in the privacy setting interface of the cloud platform, to reflect the patient's rejection degree of unauthorized access, and output the patient's personalized preference coefficient of sensitive field i;
[0106] A5, calculate the vulnerable group correlation coefficient of sensitive field i by analyzing the medical group situation and level of the patients to which the field belongs;
[0107] A6, weight the above steps to finally output the privacy weight of sensitive field i;
[0108] The calculation formula of the sensitive weight unit is as follows:
[0109] ;
[0110] Wherein:
[0111] WE i denotes the privacy weight of the sensitive field i;
[0112] WS i denotes the medical ethics sensitivity level of the sensitive field i, which is used to reflect the severity of the violation of ethical standards caused by the leakage of the field (such as the genetic sequence leakage level being higher than the height and weight), and is determined by the expert scoring method (1-5 points, 5 being the highest), and the specific assignment situation is given in this embodiment:
[0113] WS i 5 points: genetic sequence, rare disease gene mutation site, HIV diagnosis record (leakage will lead to serious ethical violations);
[0114] WS i 4 points: cancer staging, mental illness diagnosis and abortion history (leakage will lead to moderate ethical violations);
[0115] WS i 3 points: chronic disease medication record and surgery history (leakage will lead to mild ethical violations);
[0116] WS i 2 points: routine physical examination report and height and weight (leakage has no direct ethical violations);
[0117] WS i 1 point: patient anonymous ID and name pinyin initial (non-sensitive field);
[0118] The introduction of this parameter provides an ethical basis for field protection priority, ensuring that high-ethics-risk fields (such as genetic data) are given priority protection;
[0119] WH i denotes the social harm coefficient of the sensitive field i, which is used to reflect the negative impact of leakage on patients' employment and social life (such as HIV diagnosis record leakage which is likely to lead to discrimination), and the calculation formula is as follows:
[0120] WH i = the number of social harm events in the case library caused by the leakage of field i (such as patients being fired and online violence) ÷ the total number of social harm events caused by the leakage of all fields in the case library × 10;
[0121] Wherein, the purpose of × 10 is to convert the proportion (0-1) into an intuitive score of 1-10 points (such as a proportion of 0.5 → 5 points);
[0122] For example:
[0123] WH i 10 points, HIV diagnosis record (high proportion of leakage events, serious social harm);
[0124] WH i 5 points, chronic disease medication record (moderate proportion, general harm);
[0125] WH i 1 point, height and weight (low proportion, minor harm);
[0126] The introduction of this parameter is used to identify fields that have a significant impact on the social rights of patients, and to increase their weight to reduce indirect harm.
[0127] WU i Refers to the uniqueness index of sensitive field i, which reflects the rarity of field value in the data set (such as rare disease gene mutation sites owned by only a few patients), the calculation formula is as follows:
[0128] WU i = Number of unique values of field i ÷ Total number of patients registered on the cloud platform × 3;
[0129] Among them, the purpose of × 3 is to convert the proportion (0-1) to a score of 1-3;
[0130] Among them, the number of unique values of field i refers to the total number of different values of sensitive field i in the cloud environment medical big data set, and its core function is to quantify the rarity of field value. If the number of unique values of field i is larger, it means that the value of the field is more diversified, and it is easier to locate a unique patient through the field (high risk of identity de-anonymization), if the number of unique values of field i is smaller, the value is more concentrated, and the risk of identity leakage is lower;
[0131] For example:
[0132] Field i = patient DNA fingerprint: Each patient's DNA fingerprint is unique, so the number of unique values of field i is equal to the total number of patients on the cloud platform;
[0133] Field i = patient gender: The value is only "male / female / unknown" 3, the number of unique values of field i = 3;
[0134] Field i = patient age: The value range is 0-120 years old, the number of unique values of field i ≈ 121 (assuming all ages exist);
[0135] Range processing: if the calculation result is <1, take 1, if the calculation result is >3, take 3 (ensure the range is 1-3 points);
[0136] The introduction of this parameter is used to identify the field that is easy to cause the patient's identity to be unique, and to reduce the risk of identity leakage.
[0137] WP i The patient personalized preference coefficient of the sensitive field i, which is used to reflect the degree of rejection of unauthorized access by the patient, can be selected by the patient in the cloud platform privacy setting interface, and is directly stored as a numerical value. The specific assignment process is as follows:
[0138] WP i = 1, indicating that unauthorized access is completely prohibited (only the patient himself can view);
[0139] WP i = 0.5, indicating that authorized access is allowed (the patient needs to manually agree to the third party request);
[0140] WP i = 0, allowing public disclosure (no access restrictions);
[0141] The introduction of this parameter is used to respect the patient's privacy autonomy and avoid one-size-fits-all protection, and to improve user trust;
[0142] WG i The vulnerable group correlation coefficient of the sensitive field i, which is used to reflect whether the patient belonging to the field belongs to a medical vulnerable group (children, pregnant women, rare disease patients and severely disabled persons, etc.), and the vulnerability level of the group. After the leakage of the privacy of such groups, more serious ethical harm may be caused (such as the leakage of children's genetic data affecting their lifelong development), which needs to be additionally strengthened. The protection formula is as follows:
[0143] WG i = group vulnerability level x correlation between field and group characteristics;
[0144] In the above formula, the group vulnerability level, which is assigned in this embodiment, if it is a child, then WG i = 0.9, if it is a pregnant woman, then WG i = 0.8, if it is a rare disease patient, then WG i = 0.7, if it is a severe disability, then WG i = 0.6, if it is an ordinary adult, then WG i = 0.1;
[0145] In the above formula, the correlation between the field and the group characteristics, if the field is a group-specific characteristic (such as children's vaccination records and rare disease genetic mutation sites), the correlation is 1, and if it is a general field (such as height), the correlation is 0.3;
[0146] wa refers to the weight factor of the medical ethics sensitivity level, which is initially assigned to 0.3 in this embodiment;
[0147] wb refers to the weight factor of the social harm coefficient, which is initially assigned as 0.2 in this embodiment;
[0148] wc refers to the weight factor of the uniqueness index, which is initially assigned as 0.1 in this embodiment;
[0149] wd refers to the weight factor of the patient personalized preference coefficient, which is initially assigned as 0.1 in this embodiment;
[0150] we refers to the weight factor of the vulnerable group association coefficient, which is initially assigned as 0.3 in this embodiment;
[0151] It should be noted that, in order to avoid the situation that part of the dimension influence is ignored due to the scale difference between multiple parameters in the calculation formula of this unit, the multiple parameters calculated above are further processed in this embodiment, as follows:
[0152] Medical ethics sensitive level WS of sensitive field i i Subtract 1 first and then divide by 4 to limit the scale;
[0153] Social harm coefficient WH of sensitive field i i Subtract 1 first and then divide by 9 to limit the scale;
[0154] Uniqueness index WU of sensitive field i i Subtract 1 first and then divide by 2 to limit the scale;
[0155] Vulnerable group association coefficient WG of sensitive field i i Subtract 0.1 first and then divide by 0.8 to limit the scale;
[0156] Based on the above, this sensitive weight unit quantifies and weights each sensitive field from the five dimensions of medical ethics, social harm, field uniqueness, user preference and vulnerable group association, constructs a field-level privacy importance evaluation system, solves the core problem of which fields need to be protected first in the cloud environment, avoids resource waste or insufficient protection of key fields caused by indiscriminate protection, enables the system to accurately distinguish the privacy priority of different fields, provides a bottom basis for subsequent data block risk assessment and access authorization decision-making, and ensures that fields with high ethical risk, high social harm, high uniqueness, user sensitivity or involving vulnerable groups are given special attention;
[0157] Privacy weight WE of sensitive field i iAs a core input parameter of the privacy risk unit, it also supports the configuration of the system's field-level protection strategy, providing the system with a quantitative basis for field protection priorities, enabling the system to take differentiated measures for fields with different weights (such as using homomorphic encryption for high-weight fields and ordinary encryption for low-weight fields), ensuring accurate and efficient resource allocation.
[0158] Please see Figure 1 , Figure 2 and Figure 3 The privacy risk unit is specifically as follows:
[0159] B1. By introducing the privacy weight of the sensitive field i, a basis for the field sensitivity of data block risk assessment is provided, and it is combined with binary variable i for calculation.
[0160] B2. Count the number of requests in the cloud platform access logs by the number of access requests in the past 30 days, calculate the recent access popularity of data block j, and combine it with the access popularity weight coefficient.
[0161] B3. By combining the severity level of the m-th violation with the time decay factor, the severity and frequency of privacy violation events of the recipient within a certain period of time are reflected, so as to calculate the privacy violation history coefficient of the recipient of data block j.
[0162] B4. Based on different encryption methods, the encryption strength value is assigned to reflect the degree to which the encryption method offsets the risk of leakage, so as to calculate the encryption strength compensation factor of data block j, and finally output the privacy risk score of data block j.
[0163] The formula for calculating the privacy risk unit is as follows:
[0164] ;
[0165] in:
[0166] RP j Refers to the privacy risk score of data block j;
[0167] Sensitive field i Privacy weight WE i The introduction of this provides a basis for assessing the sensitivity of fields in data block risk assessment;
[0168] RPX i,j This refers to a binary variable, where index i represents a sensitive field and j represents a data block. A value of 1 indicates that field i exists in data block j, and 0 indicates otherwise. Specifically, the metadata of data block j records the IDs of all contained sensitive fields. If the ID of field i exists, then RPX... i,j =1, otherwise =0;
[0169] The introduction of this parameter is used to identify the sensitive fields contained in the data block, and to accurately calculate the total sensitive weight;
[0170] The subscript i represents the sum of the privacy weight of all existing sensitive fields i in the data block j, reflecting the core sensitivity of the data block, and providing the basis for the risk score;
[0171] It should be noted that the maximum number of sensitive fields in the preset data block is 10;
[0172] Therefore, the is divided by 10 to obtain the normalized value (0-1), and then multiplied by 10 to scale to the range of 0-10;
[0173] SA refers to the access popularity weight coefficient, which is preset to 0.1 in this embodiment, and is used to balance the influence of access popularity on risk score, avoiding extreme evaluation results;
[0174] RPA j RPA refers to the recent access popularity of the data block j, which is used to reflect the number of access requests in the past 30 days. The number of requests in the cloud platform access log can be counted, and the process is as follows:
[0175] Data source: cloud platform access log system (records the time and data block ID of each request);
[0176] Statistical rule: count the total number of access requests (including successful and failed requests) of the data block j in the past 30 days;
[0177] And the recent access popularity of the data block j obtained after the above processing needs to be normalized, which maps RPA j to the range of 0-10, that is, RPA j = min (the recent access popularity of the data block j obtained after the above processing ÷ 10, 10), that is, each 10 accesses adds 1 point, and the maximum is 10 points;
[0178] The introduction of this parameter is used to identify high-frequency access data blocks (such as popular disease diagnosis and treatment records), which have higher risk of leakage and need to be strengthened;
[0179] RPF j RPF refers to the privacy violation history coefficient of the receiver of the data block j, that is, the severity and frequency of privacy violation events of the receiver in the past 12 months, reflecting its data security credibility, and the calculation formula is as follows:
[0180] ;
[0181] Among them, Sm is the severity level of the mth violation (1 for slight, 2 for moderate, and 3 for severe);
[0182] Wherein, DTm is the number of months since the violation occurred;
[0183] Wherein, is the time decay factor (recent violations are weighted higher);
[0184] The calculation process is to query the violation records of the receiving agency, calculate the score of each event one by one, and store the sum in the receiving risk database;
[0185] The introduction of this parameter is used to avoid risks from the source, refuse to transmit high-risk data blocks to agencies with bad privacy records, and reduce the probability of leakage;
[0186] And The violation history coefficient is normalized to 0-1.5;
[0187] RPE j Refers to the encryption strength compensation factor of data block j, which reflects the degree of offset of encryption method to leakage risk, and the calculation formula is as follows:
[0188] RPE j = 1-encryption strength value, (that is, the stronger the encryption, the smaller the RPE j );
[0189] Wherein, the assignment value of the encryption strength value is 0.4 for homomorphic encryption, 0.3 for AES-256, 0.1 for DES, and 0 for non-encryption.
[0190] Based on the above, the real-time risk level of the data block is evaluated by the privacy risk unit based on the field weight of the sensitive weight unit, combined with the access frequency of the data block, the receiving agency violation history, and the encryption strength, solving the dynamic perception problem of which data block has the highest current risk in the cloud environment. Because the data block is the basic unit of cloud storage and transmission, its risk directly affects the overall privacy security, so that the system can capture the risk changes of the data block in real time, such as data blocks with high-frequency access and receiving agencies with violation records will be marked as high-risk, thereby triggering targeted protection measures to avoid the defects that static protection cannot cope with dynamic risks;
[0191] The privacy risk score RP j of data block j is used as an input parameter of the access decision unit, and at the same time triggers the risk response mechanism of the system (such as automatically increasing the encryption strength of high-risk data blocks and limiting the access frequency), marks the real-time risk level of the data block, so that the system can dynamically adjust the protection state of the data block, avoid privacy leakage caused by risk accumulation, and improve the active defense capability of the system.
[0192] Please refer to Figure 1 , Figure 2 and Figure 3 , the access decision unit is specifically:
[0193] C1, introducing the privacy weight of the sensitive field i into the access decision unit to provide the field sensitivity basis for the authorization decision;
[0194] C2, introducing the data block j privacy risk score into the access decision unit to include the overall risk of the data block in the decision;
[0195] C3, combining the number of compliance operations with the total number of operations to reflect the user's compliance operation history, and output the trust level of the initiator of the access request k;
[0196] C4, for the analysis of different use scenarios of medical privacy data, the corresponding assignment is made to calculate the purpose compliance coefficient of the access request k;
[0197] C5, by analyzing the current medical emergency level of the patient, the flexibility of access authorization is adjusted, which is used to reflect the current medical emergency level of the patient to calculate the patient emergency state coefficient corresponding to the access request k, and finally output the access request k authorization decision value;
[0198] The calculation formula of the access decision unit is as follows:
[0199]
[0200] Wherein:
[0201] DQ k refers to the access request k authorization decision value;
[0202] WE i is introduced to provide the field sensitivity basis for the authorization decision;
[0203] SW refers to the weight influence coefficient of the privacy weight, which is preset to 0.3 in the embodiment;
[0204] RP j is introduced to include the overall risk of the data block in the decision, and strict control is made on high-risk data blocks (such as vulnerable group records requested by illegal institutions);
[0205] DQY i,k represents a binary variable two, the subscript i is a sensitive field, k is an access request, and the value 1 indicates that the request k needs the field i, and 0 indicates the opposite;
[0206] The introduction of this parameter is used to accurately identify the sensitive fields involved in the request and control the authorization;
[0207] To divide by the maximum number of sensitive fields 10 to perform normalization processing;
[0208] And the data block j privacy risk score RPj Divide by the maximum value of the privacy risk unit 16.5 to perform normalization processing;
[0209] DQC k Reference to the trusted level of the access request k initiator, used to reflect the user compliance operation history (such as the level of three A doctors is higher), the calculation formula is as follows:
[0210] DQC k =Compliance operation times÷(Compliance times+Violation times);
[0211] Scope: 0-1 points, the higher the score, the higher the trusted level (such as three A doctors→DQC k =0.9, new registered user→DQC k =0.5);
[0212] If compliance times+Violation times=0, then DQC k =0.5, the default value for new users;
[0213] The introduction of this parameter makes users with high trustworthiness can be granted more leniently, improving system efficiency;
[0214] DQM k Reference to the purpose compliance coefficient of access request k, used to reflect whether the request conforms to ethical regulations (such as higher compliance of clinical diagnosis than commercial analysis), the specific evaluation process is as follows:
[0215] Select the entry: "Purpose selection" area of the access request submission page;
[0216] Option corresponding value:
[0217] DQM k =1 point: Clinical diagnosis (need to upload doctor's practice certificate number verification);
[0218] DQM k =0.7 points: Scientific research (need to upload ethical review number verification);
[0219] DQM k =0.3 points: Commercial analysis (need to upload user authorization verification);
[0220] DQM k =0 points: Illegal purpose (automatically identified and rejected by the system);
[0221] Verification process: After submission, the system automatically verifies the validity of the credentials, and assigns the corresponding score if it is met;
[0222] The introduction of this parameter is used to prioritize compliance requests (such as emergency medical record access) and restrict non-compliance requests;
[0223] DQEk DQE refers to the patient emergency state coefficient corresponding to the access request k, which is used to reflect the current medical emergency degree of the patient (such as emergency state requiring rapid access), and the specific evaluation acquisition process is as follows:
[0224] The current medical emergency degree of the patient (such as emergency and emergency) determines the flexibility of access authorization (emergency needs to relax the authority), and is based on the real-time medical label of the patient:
[0225] When in the emergency state, DQE k is 1;
[0226] When in the emergency state, DQE k is 0.8;
[0227] When in the ordinary outpatient state, DQE k is 0.5;
[0228] When in the rehabilitation follow-up state, DQE k is 0.2;
[0229] When in the health examination state, DQE k is 0.1;
[0230] The introduction of this parameter is used to balance privacy protection and medical timeliness, such as allowing doctors to quickly access the complete medical record of the patient (decision value is reduced) in emergency, and strictly controlling the authority in non-emergency;
[0231] D1 refers to the privacy weight of all sensitive fields i involved in request k, which reflects the sensitivity of the request and provides a direct basis for authorization decision;
[0232] D1 refers to the smoothing coefficient, which is preset to 0.4 in this embodiment;
[0233] D2 refers to the weight coefficient of the initiator's trust level, which is preset to 0.15 in this embodiment, and is used to balance the influence of each dimension on the decision, so that the authorization is more reasonable;
[0234] D3 refers to the weight coefficient of the purpose compliance coefficient, which is preset to 0.15 in this embodiment, to balance the influence of each dimension on the decision, so that the authorization is more reasonable.
[0235] Based on the above, the access decision unit combines the field weight involved in the request, the data block risk, the user trust level, the access purpose compliance, the patient emergency state, dynamically calculates the authorization decision value, decides the processing mode of the access request, solves the intelligent decision problem of whether to allow a certain access in the cloud environment, balances privacy protection and data availability (such as the urgent need for clinical diagnosis), enables the system to dynamically adjust the authorization policy according to the specific scene of the request, avoids business blockage or privacy leakage caused by the one-size-fits-all authorization mode, and realizes the cooperation of privacy protection and business efficiency;
[0236] authorization decision value DQ of the access request k k directly decides the processing result (rejected, allowed after desensitization, and allowed for original data) of the access request, realizes intelligent dynamic authorization of the access request, enables the system to meet the legal and compliant business needs (such as emergency access for clinical first aid) on the premise of protecting privacy, and improves the practicability and user trust of the system.
[0237] It is worth noting that the embodiment gives an iterative form, and the calculation result of the access decision unit is the authorization decision value DQ of the access request k k Further calculation is performed to affect and iterate the weight factor we of the vulnerable group correlation coefficient in the sensitive weight unit, so as to achieve the purpose of echo and cyclic optimization, and the specific iterative processing process is as follows:
[0238] we t+1 =we t + α × (DSWE - DQ k,t );
[0239] Wherein:
[0240] we t+1 refers to the weight factor of the vulnerable group correlation coefficient after the t+1th iteration;
[0241] we t refers to the weight factor of the vulnerable group correlation coefficient after the tth iteration;
[0242] α refers to the learning rate, which is preset to 0.01 in the embodiment;
[0243] DSWE refers to the target decision value, which is an ideal value for balancing privacy and availability, and is preset to 0.6 in the embodiment;
[0244] DQ k,t refers to the authorization decision value of the access request k after the tth iteration;
[0245] It should be noted that:
[0246] If DQ k < DSWE, it means that the authorization is too loose and the privacy risk is high, DSWE - DQt >0, the weight factor we of the vulnerable group correlation coefficient increases, and the vulnerable group correlation coefficient WG of the sensitive field i is improved i Weight, strengthen the protection of the vulnerable group field;
[0247] If DQ k >DSWE, indicating that the authorization is too strict, and the availability is insufficient, DSWE-DQ t <0, the weight factor we of the vulnerable group correlation coefficient decreases, and the vulnerable group correlation coefficient WG of the sensitive field i is reduced i Weight, balance privacy and availability;
[0248] It is worth noting that an iteration termination condition also needs to be set. The embodiment is based on three termination conditions for iteration convergence. When any one of the following three conditions is met, the iteration is terminated.
[0249] Condition one: the number of iterations reaches an upper limit. In the embodiment, the maximum number of iterations is set to 20 to avoid the iteration from falling into a dead loop and to ensure the real-time performance of the system.
[0250] Condition two: |we t+1 -we t |<0.001, indicating that the weight adjustment has tended to be stable;
[0251] Condition three: the access decision unit access request k authorization decision value DQ k falls in the target interval [0.5, 0.8] for three times in a row (a reasonable range balancing privacy and availability);
[0252] Based on the above content, the iteration system converts the fixed weight into adaptive dynamic adjustment, making the privacy weight calculation of the sensitive weight unit more in line with the dynamic needs of the actual authorization scenario, improving the self-optimization ability of the system. The access request k authorization decision value DQ k of formula three directly reflects the balance state of privacy protection and availability under the current weight setting. The weight factor we of the vulnerable group correlation coefficient can be adjusted through the privacy weight WE i of the sensitive field i of the sensitive weight unit, which is transmitted to the privacy risk unit and the access decision unit to form a closed-loop feedback, ensuring that the weight adjustment is strongly associated with the actual decision effect. Because of the static weight, it may not be able to cope with the dynamically changing access scenarios (such as the change of the access frequency of the vulnerable group data and the adjustment of the privacy risk preference). The iteration mechanism can allow the system to continuously optimize according to the feedback, avoid over-protection or insufficient protection, and achieve dynamic balance of privacy and availability.
[0253] While embodiments of the application have been shown and described, it is to be understood that the embodiments described are merely exemplary of the principles and application of the present application. Numerous modifications and adaptions can be effected without departing from the spirit and scope of the present application, which is not limited to the exact construction and arrangement described. It is intended, therefore, to cover all modifications and adaptions that fall within the scope of the claims and their equivalents.
Claims
1. A system for privacy protection of big data in a cloud environment, characterized in that, The method comprises the following steps: A multi-source privacy feature data acquisition module is used to acquire sensitive field association data, data block privacy association data and access request association data in medical data; A privacy data preprocessing module is used to input the sensitive field association data, data block privacy association data and access request association data acquired by the multi-source privacy feature data acquisition module, the privacy data preprocessing module cleans the input data, and the cleaned data is input into a privacy data comprehensive analysis module; The privacy data comprehensive analysis module comprises a sensitive weight unit, a privacy risk unit and an access decision unit. The processing process of the sensitive weight unit is as follows: A1. The sensitive data of the patient medical data is analyzed field by field, the severity of the violation of the ethical code by the field leakage is analyzed, parameters are assigned based on multiple situations, and the medical ethics sensitivity level of the sensitive field i is output; A2. The number of social harm events caused by the leakage of the field i is counted in the case library, the negative impact of the leakage on the employment and socialization of the patient is analyzed, the negative impact of the leakage on the social life such as the employment and socialization of the patient is analyzed, and the social harm coefficient of the sensitive field i is output; A3. The combination of the number of unique values of the field i and the total number of registered patients in the cloud platform is calculated to analyze the rarity of the field value in the data set, and the uniqueness index of the sensitive field i is calculated; 2.The cloud environment big data privacy protection system of claim 1, characterized in that: A4. The selection of the patient in the privacy setting interface of the cloud platform is used to assign values according to the requirements of the patient to reflect the degree of rejection of the patient to unauthorized access, and the patient individual preference coefficient of the sensitive field i is output. 3.The cloud environment big data privacy protection system of claim 2, characterized in that: A5, calculate the vulnerable group correlation coefficient of the sensitive field i by analyzing the medical group situation and level of the patient to which the field belongs; A6, perform weighted processing on the above steps to finally output the privacy weight of the sensitive field i.
4. The system for privacy protection of big data in cloud environment according to claim 3, characterized in that: The processing process of the privacy risk unit is as follows: B1, provide the field sensitivity basis for data block risk assessment by introducing the privacy weight of the sensitive field i, and combine it with binary variable 1 to calculate; B2, calculate the recent access heat of data block j by counting the number of requests in the cloud platform access log in the past 30 days, and combine it with the access heat weight coefficient; B3, reflect the severity and frequency of privacy violation events of the receiver in a certain period of time by combining the severity level of the mth violation with the time decay factor to calculate the privacy violation history coefficient of the receiver of data block j; B4, assign values to the encryption strength value based on different encryption forms to reflect the degree of offset of the encryption method to the leakage risk, and calculate the encryption strength compensation factor of data block j, and finally output the privacy risk score of data block j. 5.The system for big data privacy protection in cloud environment of claim 4, characterized in that: The processing process of the access decision unit is as follows: C1, introduce the privacy weight of the sensitive field i into the access decision unit to provide the field sensitivity basis for authorization decision; C2, introduce the privacy risk score of data block j into the access decision unit to include the overall risk of the data block into the decision; C3, reflect the user compliance operation history by combining the number of compliance operations with the total number of operations to output the trust level of the initiator of access request k; C4, assign values according to the analysis of different use scenarios of medical privacy data to calculate the purpose compliance coefficient of access request k; C5, adjust the flexibility of access authorization by analyzing the current medical emergency level of the patient to reflect the current medical emergency level of the patient to calculate the patient emergency state coefficient corresponding to access request k, and finally output the authorization decision value of access request k. 6.The system for big data privacy protection in cloud environment of claim 1, wherein: The specific operation of the privacy data preprocessing module for data cleaning is: Used to remove duplicate data and complete missing data, and to standardize the data input into the privacy data preprocessing module, to bind field i, data block j and request k. 7.The system for big data privacy protection in cloud environment of claim 1, wherein: The specific execution of the privacy protection strategy dynamic execution module is: When the access request k authorization decision value is greater than 0.8, the protection measure is to refuse access; When 0.5≤access request k authorization decision value≤0.8, the protection measure is desensitization access; When the access request k authorization decision value is less than 0.5, the protection measure is raw data access; When the privacy risk score of data block j is greater than 10, enable double encryption, only authorized users can decrypt. 8.The system for big data privacy protection in cloud environment of claim 7, wherein: The execution of the privacy protection measure also includes: When the protection measure is to refuse access: immediately issue a structured rejection response at the user end, record the full information of the request at the system end, including user ID, request time, target data block ID, sensitive field list involved, access request k authorization decision value, and store it in the audit log, and keep it for 180 days, and trigger the administrator real-time alarm; When the protection measure is in desensitized access, perform differential privacy, field masking, and data generalization on sensitive fields; When the protection measure is in raw data access, perform secondary authentication, time-limited authorization, operation monitoring, access restriction, and result feedback.