Position data differential privacy protection and availability balance optimization method and system

By generating query calibrator fingerprint index keys and non-negative constraint noise variance calibration, the problems of repeated calibration and insufficient error evaluation in traditional methods are solved, achieving a balance between location data differential privacy protection and availability optimization, and ensuring the stability and reliability of statistical results.

CN121985296APending Publication Date: 2026-05-05SHANDONG RUIBAO RUILI TRADING CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHANDONG RUIBAO RUILI TRADING CO LTD
Filing Date
2026-02-03
Publication Date
2026-05-05

AI Technical Summary

Technical Problem

Traditional location data differential privacy protection methods lack structured solidification and deterministic identification of caliber elements in multi-dimensional location statistics or multiple query scenarios, resulting in repeated calibration, large output fluctuations, insufficient error assessment, affecting interface stability and cross-team collaboration costs, and noise disturbances may cause abnormal statistical results.

Method used

By generating a query caliber fingerprint index key, combining the fence area and time span to calculate query sensitivity, introducing non-negative constraints, and calibrating the noise variance based on the error threshold, stable identification and parameter reuse of queries with the same caliber are achieved, reducing output fluctuations and maintaining data availability under multiple queries.

Benefits of technology

It achieves stable identification and parameter reuse for queries with the same caliber, reduces output fluctuations, maintains data availability and interface stability under multiple queries, and avoids abnormal phenomena in statistical results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121985296A_ABST
    Figure CN121985296A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of position privacy, in particular to a position data differential privacy protection and availability balance optimization method and system, and the method comprises the following steps: receiving a position statistical request, extracting a grid resolution fence boundary time window, a statistical type and a threshold value to form parameters, calculating a fence area and a time span to generate a fingerprint key, according to the method, the spatial resolution, the fence range, the time span, the statistical type and the aperture threshold value are acquired in a structured mode, and the deterministic aperture fingerprint is generated, so that stable identification and parameter multiplexing of same-aperture query are realized; the output fluctuation caused by repeated calibration is reduced, the query sensitivity is calculated in combination with the fence area and the time span, the noise intensity is made to be matched with the statistical scale, non-negative constraint and error threshold calibration are introduced into a disturbance result, and the result is kept stable under multiple queries.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of location privacy technology, and in particular to a method and system for balancing differential privacy protection and availability of location data. Background Technology

[0002] Location privacy technology primarily involves protecting the privacy of location information generated by mobile internet, IoT, and smart terminals during the collection, transmission, storage, sharing, and publication processes. Its core aspects include location data access authorization, trajectory association risk assessment, anonymization of location statistics, and data processing methods under privacy parameter constraints. Generally, location data protection processes are constructed through permission and accuracy restrictions, link encryption and authentication, hierarchical storage access control, and perturbation processing of statistics such as location counts, regional popularity, and number of stops before external publication. Among these, the traditional differential privacy protection and availability balance optimization method for location data refers to... When analyzing the results, random noise is added to the statistical output of multiple queries and the cumulative privacy consumption is limited according to the differential privacy budget allocation rules to meet the privacy parameter constraints. The technical issue addressed by this patent is how to set the privacy budget and select the noise injection method in multi-dimensional location statistics or multiple query scenarios to take into account statistical usability. Traditional methods usually use a fixed total privacy budget and distribute it equally according to the number of queries or according to the importance of the statistical task. Noise is injected into the location counting results, grid heat value or trajectory frequency results using Laplace mechanism or Gaussian mechanism, and the budget allocation and noise intensity are compared and adjusted by indicators such as absolute error, mean square error or confidence interval width.

[0003] Traditional location-based statistical differential privacy balance optimization models often allocate budgets based on query frequency or task importance, and independently add noise to the count or popularity value with each output. Statistical definitions are often implicitly expressed as parameter combinations at the actual interface layer, lacking structured, fixed, and deterministic identification of definition elements. This makes it difficult to reliably identify the same business definition across different callers, time window granularities, and fence fine-tuning scenarios, leading to duplicate calibration and trial calculations. Output fluctuations are amplified with accumulated query frequency, making it difficult for the business side to distinguish between trend changes and privacy disturbances. The sensitivity of the same type of statistics varies significantly across different geographical areas and time spans, but traditional operations tend to drive noise intensity with fixed rules, lacking explicit quantitative constraints based on fence area and time span. This results in errors in sparse counting scenarios with small fences and short time windows. The high proportion of discrepancies means that local hotspots in heatmaps may be smoothed out by noise, the number of dwell points may fluctuate abnormally, and the frequency ranking of trajectory segments may drift unstablely. Furthermore, publicly released count results may contain negative values ​​or semantically inappropriate statistics after noise accumulation, requiring additional correction or fault tolerance from the business side. This leads to inconsistencies in reporting methods and interpretation disputes; for example, negative hotspots in regional heat or negative numbers of dwell points directly undermine the credibility of reports. Error assessments often rely on offline comparisons and manual parameter tuning, lacking dynamic threshold constraints linked to online output. This results in errors deviating from the usable range for extended periods without timely convergence, or continuing to excessively fluctuate within the usable range, causing a decline in data value. Ultimately, this leads to insufficient interface stability, increased cross-team collaboration costs, and unpredictable service experiences for multiple queries. Summary of the Invention

[0004] To address the technical problems existing in the prior art, embodiments of the present invention provide a method for balancing location data differential privacy protection and availability optimization, comprising the following steps:

[0005] To achieve the above objectives, the present invention adopts the following technical solution: a location data differential privacy protection and availability balance optimization method, comprising the following steps:

[0006] S1: Receives query requests for regional heatmaps, grid counts, number of stop points and frequency of trajectory segments, extracts spatial grid resolution, geofence boundaries, start and end times of time windows, statistical type and statistical threshold, establishes a mapping relationship between requests and parameters, and forms a set of location statistics query parameters.

[0007] S2: Based on the location statistics query parameter set, calculate the geographic fence area and time window span, sequentially encode and splice the spatial raster resolution, fence area, time window span, statistical type and statistical caliber threshold, and generate a query caliber fingerprint index key.

[0008] S3: Based on the query caliber fingerprint index key, retrieve the sensitivity and noise parameter cache table. If the query sensitivity and noise variance are valid, reuse them. If the query sensitivity is not valid or is invalid, recalculate the query sensitivity and determine the noise variance in combination with the privacy budget and write it into the noise parameter cache table to obtain the query noise calibration parameter group.

[0009] S4: Based on the query noise calibration parameter group and the count value of the noise disturbance processing statistical results, generate the differential privacy disturbance statistical output value;

[0010] S5: Based on the differential privacy perturbation statistical output value, calculate the error metric value and compare it with the availability error threshold. If the threshold is exceeded, update the noise variance and write it into the noise parameter cache table. If the threshold is not exceeded, keep the parameter unchanged and form a noise parameter update record.

[0011] As a further aspect of the present invention, the location statistics query parameter set includes spatial raster resolution parameters, geofence boundary parameters, time window start and end time parameters, statistical type parameters, and statistical caliber threshold parameters; the query caliber fingerprint index key specifically includes resolution coding segment, geofence area coding segment, time window span coding segment, statistical type coding segment, and threshold coding segment; the query noise calibration parameter set includes query sensitivity parameters, noise variance parameters, validity period information parameters, and reuse marker parameters; the differential privacy perturbation statistical output value specifically includes perturbation synthesis count value, zero-value replacement count value, and non-negativity correction count value; the noise parameter update record includes error metric value entries, availability error threshold entries, noise variance update value entries, and cache write identifier entries.

[0012] As a further aspect of the present invention, the specific steps of S1 are as follows:

[0013] S101: Obtain the regional heat map query request, grid count query request, stop point number query request and trajectory segment frequency query request received by the location service statistics query interface, collect the request identifier and request type tag corresponding to the query request, record the access order for different request identifiers and form a request set number, and obtain the query request type tag value.

[0014] S102: Based on the query request type marker value, collect the spatial raster resolution, geofence boundary, start and end times of time window and statistical type carried by the query request, perform parameter field validation and compare the numerical format, and for the same request, integrate spatial parameters and time parameters by set number and record parameter group to obtain the query parameter combination quantity.

[0015] S103: Based on the query parameter combination quantity, collect the statistical threshold carried by the query request, determine the consistency between the threshold and the parameter combination quantity under the request set number and call the threshold, record the correspondence between the threshold and the parameter combination quantity, establish a mapping record between the query request and all parameters, and obtain the location statistics query parameter set.

[0016] As a further aspect of the present invention, the specific steps of S2 are as follows:

[0017] S201: Based on the location statistics query parameter set, collect the geofence boundary coordinate sequence and coordinate unit, determine the consistency of the first and last points of the boundary coordinate sequence and remove duplicate points, calculate the cumulative value of the line surface connecting adjacent coordinate points and record the area calculation identifier to obtain the geofence area value.

[0018] S202: Call the geofence area value, collect the start and end times of the time window and the time zone mark, calculate the difference between the start and end times and convert it into a second-level span, determine that the span is non-negative and record the time window number, merge the area value and the time window number to form a combined record, and obtain the time window span value;

[0019] S203: Based on the time window span value, call the spatial raster resolution, geofence area value, statistical type and statistical caliber threshold, sequentially encode the fields and concatenate the delimiter, determine that the length of the concatenation result is consistent with the number of fields and write it into the index key library, establish a query caliber field sequence mapping record, and generate a query caliber fingerprint index key.

[0020] As a further aspect of the present invention, the specific steps of S3 are as follows:

[0021] S301: Based on the query fingerprint index key, perform sensitivity and noise parameter cache table retrieval and locate matching record items, determine cache hit status and validity status, and write status flags. For the hit and valid status, read query sensitivity and noise variance and write reuse flags, record the correspondence between index key, status flag and reuse flag, and generate cache hit valid flag quantity.

[0022] S302: Based on the number of valid cache hits, for the missing or invalid state, call the location statistics query parameter set and read the spatial raster resolution, geofence area, time window span, statistical type, and statistical caliber threshold. Calculate the ratio of spatial raster resolution to geofence area, calculate the product of the ratio and the time window span, write it into the parameter record, and encode the statistical type and statistical caliber threshold combination into the parameter record to generate a query sensitivity value.

[0023] S303: Call the query sensitivity value, collect the global sensitivity and privacy budget parameters and write them into the budget identifier, calculate the ratio of global sensitivity to query sensitivity, calculate the quotient of the ratio and the privacy budget parameter, write the noise variance and validity period information into the sensitivity and noise parameter cache table, and generate a query noise calibration parameter group.

[0024] As a further aspect of the present invention, the specific steps of S4 are as follows:

[0025] S401: Call the query noise calibration parameter group, read the noise variance and the corresponding query request identifier, collect the query request statistical result count value and write it into the count flag, determine that the noise variance and the count flag have valid values ​​and write them into the verification identifier, record the correspondence between the query request identifier and the noise variance and count value, establish a mapping record index, and generate the noise count mapping quantity.

[0026] S402: Based on the noise count mapping, calculate the square root of the noise variance and write it into the scale label, collect a random sampling sequence, calculate the product of the random sampling sequence and the scale label, record the noise sampling value and write it into the sampling label, calculate the noise sampling value, sum it with the statistical result count value and write it into the synthesis identifier, and generate the perturbation synthesis result.

[0027] S403: Based on the perturbation synthesis result, determine the non-negativity of the synthesis result and write it into the determination flag. For the synthesis result determined to be negative, perform zero value replacement and write it into the replacement flag. Record the correspondence between the query request identifier and the replacement flag, write it into the differential privacy output value cache table, and generate differential privacy perturbation statistical output value.

[0028] As a further aspect of the present invention, the specific steps of S5 are as follows:

[0029] S501: Based on the differential privacy perturbation statistical output value, collect the corresponding query request statistical result count value and write it into the count flag, calculate the difference between the perturbation statistical output value and the statistical result count value and take the absolute value, record the correspondence between the difference and the query request identifier, write the error calculation identifier, and generate the error measurement value.

[0030] S502: Call the error metric value, obtain the availability error threshold and write it into the threshold flag, calculate the difference between the error metric value and the availability error threshold, record the comparison flag, determine the positive or negative value of the difference and write it into the threshold determination flag, establish the correspondence between the query request identifier and the threshold determination flag, and generate the threshold exceedance flag quantity.

[0031] S503: Based on the threshold over-limit marker quantity, for the over-limit marker being true, collect the current noise variance and calculate the update step size value, calculate the sum of the noise variance and the update step size and write it into the update marker, for the over-limit marker being false, record the noise variance preservation marker, write it into the sensitivity and noise parameter cache table, and generate a noise parameter update record.

[0032] As a further aspect of the present invention, the location service statistics query interface is an interface provided by the location service system for receiving location statistics query requests and returning statistical results, and its source is the statistics query module of the location service system.

[0033] The location statistics query request is a request type consisting of any one of the following: regional heat map query request, grid count query request, number of stop points query request, and trajectory segment frequency query request. Its source is a statistical query initiated by the upper-layer business system or the client.

[0034] The spatial grid resolution is a spatial grid division scale parameter, which means the side length, area or level code of the grid cell, and its source is the spatial statistical parameters carried in the query request.

[0035] The geofence boundary is a boundary parameter of a statistical spatial range. It means boundary information represented by a sequence of polygon vertex coordinates, the center point and radius of a circle, or an administrative region code. Its source is the fence parameter carried in the query request.

[0036] The start and end times of the time window are the start and end times of the statistical time range, which are derived from the time window parameters carried in the query request.

[0037] The statistical type is a type identifier for the category of statistical results, which means one or more of the following categories: count, frequency, number of stops, popularity, etc., and its source is the statistical type field carried in the query request;

[0038] The statistical threshold is a threshold parameter of the statistical rule, which means one or a combination of thresholds such as the dwell determination threshold, trajectory segment division threshold, and minimum count threshold. Its source is the caliber configuration parameter carried in the query request.

[0039] The location statistics query parameter set is a structured set of query request parameters. It means that it includes at least the spatial raster resolution, geofence boundary and / or geofence area, time window start and end time and / or time window span, statistical type, and statistical threshold. It is a set obtained by parsing, collecting and merging the query request parameters.

[0040] As a further embodiment of the present invention, the geofence area is an area value calculated from the geofence boundary, which is derived from the result of performing area calculation on the geofence boundary carried in the query request.

[0041] The time window span is the length of time calculated from the start and end times of the time window, and it is derived from the result of calculating the difference between the end time and the start time.

[0042] The query caliber fingerprint index key is an index key that represents the query statistical caliber. Its meaning is a string or hash value formed by encoding and concatenating spatial grid resolution, geofence area, time window span, statistical type and statistical caliber threshold in a preset order. Its source is the encoding result generated based on the location statistical query parameter set.

[0043] The sensitivity and noise parameter cache table is a cache storage structure, which means that it is a table structure or key-value storage structure that records query sensitivity, noise variance and validity information with the query caliber fingerprint index key as the index. Its source is the set of record items formed by cache miss or invalid branch writing.

[0044] The query sensitivity is a sensitivity parameter for differential privacy statistical queries. It means the upper bound of the statistical result change under adjacent dataset conditions. Its source is the sensitivity result calculated based on spatial raster resolution, geofence area, time window span, statistical type, and statistical caliber threshold.

[0045] The privacy budget parameter is the budget parameter of the differential privacy mechanism. It means a single parameter or a set of two parameters of the differential privacy budget. Its source is the system privacy configuration strategy or the privacy configuration field carried in the query request.

[0046] The noise variance is the variance parameter of the noise distribution or a scale parameter equivalent to variance. It is derived from the parameter value calculated based on query sensitivity or global sensitivity and privacy budget parameters and written into the sensitivity and noise parameter cache table.

[0047] A location data differential privacy protection and availability balance optimization system, including:

[0048] The location query access module is used to execute S1: to obtain the regional heat map query request, grid count query request, stop point number query request and trajectory segment frequency query request received by the location service statistical query interface, collect the spatial grid resolution, geofence boundary, time window start and end time and statistical type carried in the query request, read the statistical caliber threshold carried in the query request, record the correspondence between the query request and the parameters, and generate a location statistical query parameter set;

[0049] The caliber fingerprint generation module is used to execute S2: based on the location statistics query parameter set, calculate the geofence area and time window span, sequentially encode and concatenate the spatial raster resolution, geofence area, time window span, statistical type and statistical caliber threshold to generate the query caliber fingerprint index key;

[0050] The noise calibration cache module is used to execute S3: based on the query caliber fingerprint index key, it retrieves the sensitivity and noise parameter cache table, determines the cache hit status and validity period status. The cache table record is formed by the parameter record written by the missed or invalid branch. When it hits and is valid, it reads the query sensitivity and noise variance in the cache table record and writes them into the reuse mark. When it misses or is invalid, it calls the location statistics query parameter set to read the spatial raster resolution, geofence area, time window span, statistical type and statistical caliber threshold, and calculates the query sensitivity. Based on the global sensitivity and privacy budget parameters, it determines the noise variance and writes the query sensitivity, noise variance and validity period information into the sensitivity and noise parameter cache table to generate the query noise calibration parameter group.

[0051] The privacy perturbation output module is used to execute S4: call the query noise calibration parameter group, read the noise variance and the statistical result count value of the corresponding query request, calculate the noise sampling value and perturb the statistical result count value, obtain the perturbation synthesis result, determine the non-negativity of the perturbation synthesis result and replace the negative value with the zero value, and generate the differential privacy perturbation statistical output value;

[0052] The error constraint adjustment module is used to execute S5: based on the differential privacy perturbation statistical output value, calculate the error metric value, obtain the availability error threshold, compare the error metric value with the availability error threshold, update the noise variance and write it to the sensitivity and noise parameter cache table when the availability error threshold is exceeded, and keep the noise variance unchanged when the availability error threshold is not exceeded, and generate a noise parameter update record.

[0053] Compared with the prior art, the advantages and positive effects of the present invention are as follows:

[0054] In this invention, by structurally collecting spatial resolution, fence range, time span, statistical type and caliber threshold in statistical queries and generating deterministic caliber fingerprints, stable identification and parameter reuse of queries with the same caliber are achieved, reducing output fluctuations caused by repeated calibration. The query sensitivity is calculated by combining fence area and time span, so that the noise intensity fits the statistical scale. Non-negative constraints are introduced into the perturbation results and the noise variance is calibrated based on the error threshold to maintain stability under multiple queries. Attached Figure Description

[0055] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0056] Figure 1 This is a schematic diagram of the steps of the present invention;

[0057] Figure 2 This is a detailed schematic diagram of S1 of the present invention;

[0058] Figure 3 This is a detailed schematic diagram of S2 of the present invention;

[0059] Figure 4 This is a detailed schematic diagram of S3 of the present invention;

[0060] Figure 5 This is a detailed schematic diagram of S4 of the present invention;

[0061] Figure 6 This is a detailed schematic diagram of S5 of the present invention. Detailed Implementation

[0062] The technical solution of the present invention will now be described with reference to the accompanying drawings.

[0063] In embodiments of the present invention, words such as "exemplarily," "for example," etc., are used to indicate that something is an example, illustration, or description. Any embodiment or design described as "exemplary" in the present invention should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of the word "exemplary" is intended to present the concept in a concrete manner. Furthermore, in embodiments of the present invention, the meaning expressed by "and / or" can be both, or either one.

[0064] In the embodiments of this invention, the terms "image" and "picture" may sometimes be used interchangeably. It should be noted that, without emphasizing the distinction between them, they convey the same meaning. Similarly, the terms "of," "corresponding (relevant)," and "corresponding" may sometimes be used interchangeably. It should be noted that, without emphasizing the distinction between them, they convey the same meaning.

[0065] In this embodiment of the invention, sometimes a subscript such as W1 may be written in a non-subscript form such as W1. When the difference is not emphasized, the meaning they express is the same.

[0066] To make the technical problems, technical solutions and advantages of the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments.

[0067] Please see Figure 1 This invention provides a method for balancing location data differential privacy protection and availability optimization, comprising the following steps:

[0068] S1: Receives regional heatmap query requests, raster count query requests, stop point quantity query requests, and trajectory segment frequency query requests from the location service statistics query interface. It collects the spatial raster resolution, geofence boundaries, start and end times of the time window, and statistical type carried in the query requests. It also reads the statistical threshold carried in the query requests, records the correspondence between the query requests and parameters, and generates a location statistics query parameter set. The location service statistics query interface is the interface in the location service system that provides the external interface for receiving location statistics query requests and returning statistical results. Its source is the location service system's statistics query module.

[0069] Location statistics query requests are any of the following request types: regional heatmap query requests, grid count query requests, number of stop points query requests, and trajectory segment frequency query requests. Their source is a statistical query initiated by the upper-layer business system or the client.

[0070] Spatial raster resolution is a spatial raster division scale parameter, which means the side length, area or level code of the raster cell, and its source is the spatial statistical parameters carried in the query request;

[0071] Geofencing boundaries are boundary parameters of statistical spatial ranges. They are boundary information represented by a sequence of polygon vertex coordinates, the center point and radius of a circle, or an administrative region code. Their source is the fencing parameters carried in the query request.

[0072] The start and end times of the time window are the start and end times of the statistical time range, which are derived from the time window parameters carried in the query request.

[0073] The statistical type is a type identifier for the category of statistical results. It means one or more of the following categories: count, frequency, number of stops, popularity, etc., and its source is the statistical type field carried in the query request.

[0074] The statistical threshold is a threshold parameter of the statistical rule. It means one or a combination of thresholds such as the dwell determination threshold, trajectory segment division threshold, and minimum count threshold. Its source is the caliber configuration parameter carried in the query request.

[0075] The location statistics query parameter set is a structured set of query request parameters. It means that it includes at least the spatial raster resolution, geofence boundary and / or geofence area, time window start and end time and / or time window span, statistical type, and statistical threshold. It is a set obtained by parsing, collecting and merging the query request parameters.

[0076] S2: Based on the location statistics query parameter set, calculate the geofence area and time window span, sequentially encode and concatenate the spatial raster resolution, geofence area, time window span, statistical type and statistical caliber threshold to generate a query caliber fingerprint index key.

[0077] The geofence area is the area value calculated from the geofence boundary, and its source is the result of performing area calculation on the geofence boundary carried in the query request;

[0078] The time window span is the length of time calculated from the start and end times of the time window. It is derived from the result of calculating the difference between the end time and the start time.

[0079] The query caliber fingerprint index key is an index key that represents the query statistical caliber. It means that the spatial raster resolution, geofence area, time window span, statistical type and statistical caliber threshold are encoded and concatenated in a preset order to form a string or hash value. Its source is the encoding result generated based on the location statistical query parameter set.

[0080] S3: Based on the query caliber fingerprint index key, retrieve the sensitivity and noise parameter cache table, determine the cache hit status and validity period status. The cache table record is formed by the parameter record written by the missed or invalid branch. When the hit is valid, read the query sensitivity and noise variance in the cache table record and write it to the reuse mark. When the hit is missed or invalid, call the location statistics query parameter set to read the spatial raster resolution, geofence area, time window span, statistical type and statistical caliber threshold, and calculate the query sensitivity. Determine the noise variance based on the global sensitivity and privacy budget parameters, and write the query sensitivity, noise variance and validity period information into the sensitivity and noise parameter cache table to generate the query noise calibration parameter set.

[0081] The sensitivity and noise parameter cache table is a cache storage structure. It means that it is a table structure or key-value storage structure that records query sensitivity, noise variance and validity information using the query caliber fingerprint index key as an index. Its source is the set of record items formed by cache misses or invalid branches.

[0082] Query sensitivity is a sensitivity parameter for differential privacy statistics queries. It represents the upper bound of the statistical result change under adjacent dataset conditions. It is derived from the sensitivity result calculated based on spatial raster resolution, geofence area, time window span, statistical type, and statistical caliber threshold.

[0083] Privacy budget parameters are the budget parameters for differential privacy mechanisms. They can be either single parameters or a set of two parameters for differential privacy budgeting. Their source is the system privacy configuration policy or the privacy configuration field carried in the query request.

[0084] Noise variance is the variance parameter of the noise distribution or a scale parameter equivalent to variance. It is derived from the parameter value calculated based on query sensitivity or global sensitivity and privacy budget parameters and written into the sensitivity and noise parameter cache table.

[0085] S4: Call the query noise calibration parameter group, read the noise variance and the statistical result count value of the corresponding query request, calculate the noise sampling value and perturb the statistical result count value, obtain the perturbation synthesis result, determine the non-negativity of the perturbation synthesis result and replace the negative value with the zero value, and generate the differential privacy perturbation statistical output value.

[0086] S5: Based on the differential privacy perturbation statistical output value, calculate the error metric, obtain the availability error threshold, compare the error metric with the availability error threshold, update the noise variance and write it to the sensitivity and noise parameter cache table when the availability error threshold is exceeded, keep the noise variance unchanged when the availability error threshold is not exceeded, and generate a noise parameter update record.

[0087] Please see Figure 2 The specific steps of S1 are as follows:

[0088] S101: Obtain the regional heat map query request, grid count query request, stop point number query request and trajectory segment frequency query request received by the location service statistics query interface, collect the request identifier and request type tag corresponding to the query request, record the access order for different request identifiers and form a request set number, and obtain the query request type tag value.

[0089] The system first performs a unified access parsing operation on each query request entering the interface. By parsing the request header fields, it obtains the request number and request type information. The request number is used to distinguish calls from different sources and batches, while the request type is used to distinguish different statistical semantics such as regional heatmaps, grid counts, stop point counts, and trajectory segment frequency statistics. After parsing, the system immediately records the millisecond-level timestamp corresponding to the arrival time of the request and writes the timestamp into the sequential buffer. Then, it performs a size comparison operation on multiple timestamp values ​​in the buffer and assigns access sequence numbers to requests in ascending order. The earliest arriving request is set to 1, and subsequent requests are sequentially incremented to form a continuous sequence number. Based on this, the access sequence number and the request number are concatenated to generate a set number. At the same time, a step-by-step comparison mapping operation is performed on the request type field. The parsed type string is compared with the entries in the preset type table. If a match is successful, the corresponding numerical tag is returned and written into the request record structure. Through the continuous execution of the above field decomposition, time sorting, sequence number generation, and type mapping, the system completes the structured identification processing of each query request, providing a stable index foundation for subsequent parameter collection and integration.

[0090] S102: Based on the query request type tag value, collect the spatial raster resolution, geofence boundary, start and end time of time window and statistical type carried by the query request, perform parameter field validation and compare the numerical format, and for the same request, integrate spatial parameters and time parameters by set number and record parameter group to obtain the query parameter combination quantity.

[0091] The system uses the set number as an index to perform decomposition and integration operations on the spatial and temporal parameters carried in the request body. During execution, it first reads the spatial raster resolution field and parses it into an integer value. Then, it confirms its validity by comparing it twice with the preset lower limit of 50 meters and upper limit of 1000 meters. Next, it reads the geofence boundary field and splits it into four independent floating-point values: minimum longitude, minimum latitude, maximum longitude, and maximum latitude. It performs format validation and size comparison on each of the four values, confirming that the minimum longitude is less than the maximum longitude and the minimum latitude is less than the maximum latitude, and then writes them to the parameter buffer. Next, it reads the start and end fields of the time window and converts the time string into a second-level timestamp value. The time window length is obtained by subtracting the start timestamp from the end timestamp and recorded. Then, it parses the statistical type field and maps it to an internal encoded value. Under the same set number, the above spatial and temporal parameters are integrated into a parameter combination record in a fixed order. The corresponding data is directly incorporated into the table format after row and column permutation, as explained below.

[0092] Table 1: Row and Column Permutation Table for Query Parameter Combinations

[0093] Parameters G001 G002 G003 Request type tag value 1 2 4 Spatial raster resolution (m) 200 500 100 Minimum longitude 118.10 121.30 113.20 Minimum latitude 31.90 30.95 23.00 Maximum longitude 118.50 121.80 113.60 Maximum latitude 32.20 31.40 23.30 Start timestamp (s) 1717200000 1717210800 1717221600 End timestamp (s) 1717207200 1717214400 1717225200 Time window length (s) 7200 3600 3600 Statistical type coding 01 02 01

[0094] In the table above, the set number is displayed in columns, and the parameter items are arranged in rows. In actual execution, the system uses the column corresponding to the set number as the processing object, performs independent verification and writing operations on the parameter values ​​in each column, and verifies the accuracy of the time window length field by using timestamp difference calculation, thereby completing the centralized recording of the query parameter combination quantity.

[0095] S103: Based on the number of query parameter combinations, collect the statistical threshold carried by the query request, determine the consistency between the threshold and the number of parameter combinations under the request set number and call the threshold, record the correspondence between the threshold and the number of parameter combinations, establish a mapping record between the query request and all parameters, and obtain the location statistics query parameter set.

[0096] The system reads the statistical threshold field carried in the set number reading request and performs a consistency check. During execution, the threshold field is first parsed into an integer value. Then, based on the statistical type code corresponding to the set number, the legal range of the threshold is determined. When the statistical type code is 01, the threshold range is set to 1 to 10000; when the statistical type code is 02, the threshold range is set to 1 to 100000. The system compares the read threshold value with both the lower and upper limits of the range twice to determine if it falls within the range. After the range check passes, the system continues to call the time window length value from the aforementioned parameter combination record. The system performs a proportional calculation, dividing the threshold value by the number of seconds in the time window to obtain the proportional result. This proportional result is then compared with a preset proportional range of 0.001 to 1. When the proportional value simultaneously meets the condition of being greater than or equal to 0.001 and less than or equal to 1, a mapping relationship is established between the threshold and the corresponding set number and parameter combination record, and the result is written into the parameter mapping structure. For thresholds that fail the proportional comparison, only their inconsistent state is recorded and they are not involved in subsequent processing. Through the continuous execution process of the above-mentioned item-by-item numerical parsing, interval comparison, proportional calculation, and mapping writing, the system finally completes the complete association between the query request, the number of parameter combinations, and the statistical threshold.

[0097] Please see Figure 3 The specific steps of S2 are as follows:

[0098] S201: Based on the location statistics query parameter set, collect the geofence boundary coordinate sequence and coordinate unit, determine the consistency of the first and last points of the boundary coordinate sequence and remove duplicate points, calculate the cumulative value of the area of ​​the line connecting adjacent coordinate points and record the area calculation identifier to obtain the geofence area value.

[0099] Based on the existing geofence parameters in the location statistics query parameter set, the system reads the coordinate sequence and coordinate unit markers corresponding to the geofence boundary item by item during execution. The coordinate sequence is stored in the form of an ordered point set, where each point consists of longitude and latitude values, and the coordinate unit is marked as decimal degrees in the field form. Then, a sequential traversal operation is performed on the coordinate sequence, extracting the first and last coordinate points in turn, and comparing the longitude and latitude values ​​of the two points respectively. If the longitude difference is equal to 0 and the latitude difference is equal to 0, the first and last points are considered to be consistent. If either difference is not 0, the first and last points are considered to be inconsistent, and the first coordinate point is appended to the end of the sequence to form a closed coordinate structure. After processing, the coordinate sequence is traversed again, and adjacent coordinate points are read one by one. The difference between the longitude and latitude values ​​of the two adjacent points is calculated. When the difference between the longitude and latitude is 0, the adjacent point is determined to be a duplicate point and the next point is removed from the sequence. After the duplicate points are removed, the processed coordinate sequence is renumbered and adjacent coordinate point pairs are read in sequence. For each pair of adjacent points, the longitude and latitude values ​​are calculated to obtain the cumulative area value corresponding to the single line. The area calculation identifier is recorded for this value. After all adjacent point pairs are processed, the cumulative area values ​​are added sequentially, and the absolute value of the result is processed and proportionally converted. Finally, the area value of the corresponding geofence is obtained and written into the location statistics query parameter set.

[0100] S202: Call the geofence area value, collect the start and end times of the time window and the time zone marker, calculate the difference between the start and end times and convert it into a second-level span, determine that the span is non-negative and record the time window number, merge the area value and the time window number to form a combined record, and obtain the time window span value.

[0101] The system processes time window span parameters based on the area value. During execution, it reads the start and end times of the time window, along with the corresponding time zone marker, from the location statistics query parameter set. The time zone marker represents the hourly offset from UTC as an integer. After reading, the start and end times are converted to second-level time values ​​using a unified time zone conversion. Then, the end and start times are subtracted to obtain the time span value. A non-negativity check is performed on the time span; if the span value is greater than or equal to 0, a unique number is assigned to the time window. The geofence area value, time window number, and time span value are merged and written into the same combined record. The corresponding information is embedded in the following data table format.

[0102] Table 2: Record of Geographic Fence Area and Time Window Span Combination

[0103] Set Number Geographic fence area Start time value End time value Time window span (s) Time window number G001 76.20 1717200000 1717207200 7200 TW001 G002 145.80 1717210800 1717214400 3600 TW002 G003 98.40 1717221600 1717225200 3600 TW003

[0104] In the table above, each row of data comes from the parameter records under the same set number. The geofence area is calculated from the coordinate sequence, the time window span is calculated from the difference between the start and end time values, and the time window number is generated according to the processing order. Before writing the table records, the system performs numerical type verification and integrity verification on each field. After confirming that there are no errors, the system completes the registration of the time window span value.

[0105] S203: Based on the time window span value, call the spatial raster resolution, geofence area value, statistical type and statistical caliber threshold, sequentially encode the fields and concatenate the delimiter, determine whether the length of the concatenation result is consistent with the number of fields and write it into the index key library, establish a query caliber field sequence mapping record, and generate a query caliber fingerprint index key.

[0106] The system generates a query caliber fingerprint index key based on the span value. During the process, it sequentially reads the spatial raster resolution value, geofence area value, time window span value, statistical type code, and statistical caliber threshold value from the parameter set. The reading order follows the pre-defined field order. Then, each of the above fields is processed into a string, and the area value is uniformly retained to two decimal places. Then, fixed separators are inserted between adjacent fields according to the field order to complete the concatenation. After the concatenation is completed, the number of fields and character integrity are checked. After confirming that the number of fields is consistent and there are no missing fields, the concatenation result is written to the index key library. At the same time, a mapping record is established between this index key and the corresponding spatial resolution, area value, time window span, statistical type, and threshold fields. Finally, a unique query caliber fingerprint index key is formed and stored in the system index structure.

[0107] Please see Figure 4 The specific steps of S3 are as follows:

[0108] S301: Based on the query fingerprint index key, perform sensitivity and noise parameter cache table retrieval and locate matching record items, determine cache hit status and validity status, and write status flags. For hit and valid status, read query sensitivity and noise variance and write reuse flags, record the correspondence between index key, status flag and reuse flag, and generate cache hit valid flag count.

[0109] Based on the query fingerprint index key as the initial reference, the system first writes the index key into the cache retrieval request during execution. Then, it reads the stored index key field from the sensitivity and noise parameter cache table record by record in order. A character-level bitwise comparison is performed between the read index key and the currently requested index key. If every character matches, it is considered a cache hit; if any character does not match, the comparison of the current record is immediately terminated and the system moves to the next record. After completing the index key matching, the system continues to read the corresponding validity period field from the matched record. The validity period is expressed in seconds. The remaining validity time is obtained by performing a difference operation between the current system time value and the validity period time value. When the remaining time is greater than 0... If the remaining time is less than or equal to 0, it is determined to be in a valid state. If the remaining time is less than or equal to 0, it is determined to be in an invalid state. Then, the hit status and validity status are combined and written to the status flag field. Under the condition of hit and validity, the system reads the stored query sensitivity value and noise variance value from the cache record and writes the reuse flag field to 1 to indicate that direct reuse is allowed. When the index key is not hit or the validity period is determined to be invalid, the status flag is written as hit or invalid, and the reuse flag field is written to 0. At the same time, a one-to-one correspondence between the index key and the status flag and reuse flag is established in the current request record. After completing the index key comparison, time validity judgment and flag writing, a cache hit valid flag quantity that can be directly used for subsequent process branch judgment is generated.

[0110] S302: Based on the number of valid cache hits, for the missing or invalid state, call the location statistics query parameter set and read the spatial raster resolution, geofence area, time window span, statistical type, and statistical caliber threshold. Calculate the ratio of spatial raster resolution to geofence area, calculate the product of the ratio and the time window span, write it to the parameter record, and encode the statistical type and statistical caliber threshold combination into the parameter record to generate a query sensitivity value.

[0111] Based on the number of valid cache hits as the basis for process branching, the system recalculates query sensitivity for records marked as "missed" or "invalid." During execution, it sequentially reads spatial raster resolution, geofence area, time window span, statistical type encoding, and statistical threshold from the location statistics query parameter set. Spatial raster resolution is stored in meters (m), geofence area is a numerical record, time window span is recorded in seconds (s), statistical type encoding is a discrete value, and statistical threshold is an integer value. After reading, the system first performs a ratio calculation between the geofence area and spatial raster resolution values. By dividing the area value by the resolution value, it obtains the area ratio per unit resolution. Then, it multiplies this ratio by the time window span value to obtain the intermediate result required for query sensitivity calculation. In actual execution, when the spatial raster resolution... With a resolution of 200m, a geofence area of ​​76.20, and a time window span of 7200s, the ratio of area to resolution is 0.381. Multiplying this ratio by the time window span yields 2743.2, which is written into the parameter record as an intermediate value for query sensitivity calculation. Subsequently, the system performs combined coding processing on the statistical type code and the statistical caliber threshold. The combined code is an identifier field and does not participate in numerical calculations. It is generated by placing the statistical type code first and the statistical caliber threshold last, connected by a fixed separator. For example, when the statistical type code is 01 and the statistical caliber threshold is 500, the generated combined code identifier is 01_500, used to represent a specific statistical caliber configuration. The system writes the intermediate calculation results and the combined code together into the parameter record. To clearly express the correspondence between each parameter and the calculation results at this stage, the relevant data is preserved in tabular form as follows.

[0112] Table 3: Query Sensitivity Calculation Parameters and Result Row and Column Permutation Table

[0113] Parameters numerical values Spatial raster resolution (m) 200 Geographic fence area 76.20 Time window span (s) 7200 Area to resolution ratio 0.381 Intermediate calculation results 2743.2 Statistical type coding 01 Statistical threshold 500 Combined coding identifier <![CDATA[01 _ 500]]>

[0114] In the table above, the parameter items are arranged vertically. The values ​​on the right all come from the parameter set records corresponding to the same request. The combined code identifier is used to distinguish different statistical types and threshold combination configurations. It is not used as a numerical field participating in the calculation. The intermediate calculation results are confirmed as query sensitivity values ​​and written into the parameter set after the value range is verified.

[0115] S303: Call the query sensitivity value, collect the global sensitivity and privacy budget parameters and write them into the budget identifier, calculate the ratio of global sensitivity to query sensitivity, calculate the ratio and the quotient of privacy budget parameters, write the noise variance and validity period information into the sensitivity and noise parameter cache table, and generate a query noise calibration parameter group;

[0116] The system uses the query sensitivity value as input to execute a noise calibration process. During execution, it first reads the global sensitivity value and the privacy budget parameter value from the system configuration parameters. The global sensitivity value is set based on historical statistical ranges and stored as a fixed value. The privacy budget parameter is maintained periodically and recorded numerically. After reading, the system performs a ratio calculation on the global sensitivity value and the query sensitivity value to obtain the sensitivity ratio between the global and query values. Then, it performs a quotient calculation on this ratio and the privacy budget parameter to obtain the base value for noise variance calculation. In a specific example, when the global sensitivity is 100, the query sensitivity... When the sensitivity is 2743.2 and the privacy budget parameter is 1.0, the resulting base value of noise variance is 0.0365. The system writes this noise variance value and the corresponding validity period information into the sensitivity and noise parameter cache table. The validity period is generated by adding the current system time value to the preset cache period. Before writing to the cache table, a uniqueness check is performed on the index key field. After confirming that there are no valid records with the same index key, the writing is completed, and a one-to-one correspondence between the index key and the noise variance is established simultaneously. Finally, a query noise calibration parameter group containing query sensitivity, noise variance and validity period information is formed and stored in the system cache structure.

[0117] Please see Figure 5 The specific steps of S4 are as follows:

[0118] S401: Call the query noise calibration parameter group, read the noise variance and the corresponding query request identifier, collect the query request statistical result count value and write it to the count flag, determine that the noise variance and the count flag have valid values ​​and write them to the verification identifier, record the correspondence between the query request identifier and the noise variance and count value, establish a mapping record index, and generate the noise count mapping quantity.

[0119] Based on the noise calibration parameter set as the starting point, the system first reads the noise variance value associated with the current query request and the corresponding query request identifier from the parameter set item by item. During the reading process, the noise variance field is validated for its value type. After confirming that it is a non-negative value by comparing it with 0, processing continues. At the same time, the system reads the statistical result count value corresponding to the query request from the statistical result storage area and writes the count value into the count flag field. After completing the reading of the noise variance and count value, the system performs validity judgment operations on the noise variance and count value respectively. The judgment process is to compare the noise variance with 0. First, confirm that the value is not less than 0. Then, compare the count value with 0 to confirm that it is an integer not less than 0. When both judgments are true, write the verification identifier field to the valid state. Then, write the query request identifier, noise variance value, and statistical result count value into the same mapping record structure, and generate an index item with the query request identifier to complete the registration. In the actual example, when the query request identifier is QID_001, the noise variance is 0.0365, the statistical result count value is 120, and both values ​​pass the validity judgment, the system completes the mapping record writing and forms a noise count mapping quantity that can be directly called for subsequent processing.

[0120] S402: Based on the noise count mapping, calculate the square root of the noise variance and write it into the scale label, collect a random sampling sequence, calculate the product of the random sampling sequence and the scale label, record the noise sampling value and write it into the sampling label, calculate the noise sampling value, sum it with the statistical result count value and write it into the synthesis identifier, and generate the perturbation synthesis result;

[0121] The system performs noise sampling and perturbation synthesis based on this mapping value. During execution, it first reads the noise variance value from the mapping record and performs a square root operation on this value to obtain the noise scale value. Then, it collects a single sample value from a random sampling sequence from a random source. The random sample value is a real number distributed within the positive and negative intervals. The system multiplies this random sample value with the noise scale value to obtain the noise sample value. After the noise sample value is generated, the system continues to read the statistical result count value from the same mapping record and performs a summation operation on the noise sample value and the statistical result count value to obtain the perturbation synthesis result. To visually represent the correspondence between the parameters and the calculation results at this stage, the rows and columns of the aforementioned table are rearranged and embedded as follows.

[0122] Table 4: Row and Column Permutation Table for Noise Sampling and Disturbance Synthesis Calculation Parameters

[0123] Parameters <![CDATA[QID _ 001]]> noise variance 0.0365 Noise scale value 0.191 Random sample value -0.42 Noise sample value -0.080 Statistical results count value 120 Perturbation synthesis results 119.92

[0124] In the table above, the parameter items are arranged in vertical order, and the corresponding values ​​all come from the mapping records under the same query request identifier. The noise scale value is obtained by performing a square root operation on the noise variance, the noise sample value is obtained by performing a product operation on the random sample value and the noise scale value, and the perturbation synthesis result is obtained by performing a sum operation on the statistical result count value and the noise sample value. Before recording the above values, the system performs a value type and range check on each field, and completes the recording of the perturbation synthesis result after confirming that there are no errors.

[0125] S403: Based on the perturbation synthesis result, determine that the synthesis result is non-negative and write it into the determination flag. For the synthesis result that is determined to be negative, perform zero value replacement and write it into the replacement flag. Record the correspondence between the query request identifier and the replacement flag, write it into the differential privacy output value cache table, and generate differential privacy perturbation statistical output value.

[0126] Based on this result, the system performs output value correction and caching operations. During the execution process, the perturbation synthesis result value is first read and compared with 0. When the synthesis result is greater than or equal to 0, the judgment flag field is set to a non-negative state. When the synthesis result is less than 0, the judgment flag field is set to a negative state. In the case of a negative state, the synthesis result is subjected to zero value replacement processing by rewriting the result value to 0 and setting the replacement flag field to a replaced state. In the case of a non-negative state, the original synthesis result remains unchanged and the replacement flag field is set to an unreplaced state. Subsequently, the correspondence between the query request identifier and the replacement flag is written into the record structure. After the replacement judgment and flag writing are completed, the final determined output value is written into the differential privacy output value cache table. Before writing to the cache, the uniqueness of the query request identifier is checked. After confirming that there are no duplicate valid records, the writing is completed. Finally, a differential privacy perturbation statistical output value that can be directly read by the subsequent query process is generated.

[0127] Please see Figure 6 The specific steps of S5 are as follows:

[0128] S501: Based on the differential privacy perturbation statistical output value, collect the corresponding query request statistical result count value and write it into the count flag, calculate the difference between the perturbation statistical output value and the statistical result count value and take the absolute value, record the correspondence between the difference and the query request identifier, write it into the error calculation identifier, and generate the error measurement value.

[0129] Starting with the differential privacy perturbation statistical output value, the system first locates the corresponding original statistical result record by using the query request identifier associated with the output value. It then reads the original statistical result count value of the query request from the statistical result storage area and writes this count value into the count flag field. In the example scenario, when the original statistical result count value corresponding to the query request identifier is 120, the system completes the count value writing. Subsequently, the system performs a difference operation between the perturbation statistical output value and the original statistical result count value. By subtracting the perturbation statistical output value of 119.92 from the original statistical result count value of 120, the difference is obtained as -0. The system first calculates the difference to 0.08, then performs a sign check on this difference and takes its absolute value to obtain 0.08. This absolute difference is then written to the error value field, and the error calculation completion status is written to the error calculation flag field as a numerical marker. A value of 1 indicates that the error value corresponding to the query request has been generated, and 0 indicates that it has not been generated. After completing the difference calculation and status marker writing, the system uniformly writes the query request identifier, the original statistical result count value, the disturbance statistical output value, the error value, and the error calculation flag into the error record structure. To standardize the display of the error data formed at this stage, the corresponding records are represented in a table format with row and column permutations as follows.

[0130] Table 5: Row and Column Replacement Table for Calculating Disturbance Statistical Output Error

[0131] project <![CDATA[QID _ 001]]> Original statistical results count value 120 Disturbance Statistical Output Value 119.92 Error value 0.08 Error calculation mark 1

[0132] In the table above, each item is presented in a vertical arrangement. The values ​​on the right all correspond to the same query request identifier. The error value is obtained by taking the absolute value of the difference between the disturbance statistical output value and the original statistical result count value. The error calculation mark is a pure numerical status field, which is only used to indicate whether the error value has been calculated and does not participate in any numerical calculation. The system performs a non-negativity check on the error value before writing it into the table and then completes the error measurement value registration.

[0133] S502: Call the error metric, obtain the availability error threshold and write it to the threshold flag, calculate the difference between the error metric and the availability error threshold, record the comparison flag, determine the positive or negative value of the difference and write it to the threshold judgment flag, establish the correspondence between the query request identifier and the threshold judgment flag, and generate the threshold exceedance flag quantity.

[0134] Based on the generated error metric as input, the system further performs availability error threshold determination processing. During this process, the system first reads the availability error threshold value from the configuration parameter area and writes it into the threshold flag field. In actual configuration, this threshold is stored as a fixed value, for example, a threshold set to 5. Then, the system reads the error value 0.08 under the corresponding query request identifier and performs a difference operation between the error value and the availability error threshold. By subtracting the threshold value 5 from the error value 0.08, the system obtains a comparison result of -4.92. The system performs a sign judgment on this comparison result. After confirming that it is less than 0 by comparing it with 0, the system writes the threshold determination flag field to 0 to indicate that the threshold is not exceeded. When the comparison result is greater than 0, the system writes the threshold determination flag field to 1 to indicate that the threshold is exceeded. Subsequently, the system establishes a one-to-one correspondence between the query request identifier and the threshold determination flag and writes this correspondence into the threshold determination record structure, thereby generating a threshold exceedance flag quantity to characterize whether each query request exceeds the availability error threshold.

[0135] S503: Based on the threshold over-limit marker quantity, for the over-limit marker being true, collect the current noise variance and calculate the update step size value. After calculating the sum of the noise variance and the update step size, write it to the update marker. For the over-limit marker being false, record the noise variance preservation marker and write it to the sensitivity and noise parameter cache table to generate a noise parameter update record.

[0136] Based on the threshold exceedance flag as the basis for processing branches, the system reads the threshold judgment flag field corresponding to each query request. When the threshold judgment flag is 1, indicating that the current query request error exceeds the availability error threshold, the system reads the currently effective noise variance value from the sensitivity and noise parameter cache table and calculates the update step size based on this noise variance. The update step size is obtained by multiplying the current noise variance by a preset update ratio. In the example, when the noise variance is 0.0365 and the update ratio is 0.1, the update step size is 0.00365. The system then performs the update step size calculation. The addition operation yields the updated noise variance of 0.04015, and the update flag field is set to 1 to indicate that the update has been performed. When the threshold judgment flag is 0, i.e., the state is not exceeded, the system does not perform numerical adjustment on the noise variance, but only sets the update flag field to 0 to indicate the state is maintained. Subsequently, the system writes the updated noise variance or the unchanged noise variance into the sensitivity and noise parameter cache table. During the writing process, the consistency check between the query request identifier and the noise variance record is performed, and finally, a noise parameter update record containing the query request identifier, the current noise variance value, and the update flag is generated.

[0137] A location data differential privacy protection and availability balance optimization system, including:

[0138] The location query access module is used to execute S1: to obtain the regional heat map query request, grid count query request, stop point number query request and trajectory segment frequency query request received by the location service statistical query interface, collect the spatial grid resolution, geofence boundary, time window start and end time and statistical type carried in the query request, read the statistical caliber threshold carried in the query request, record the correspondence between the query request and the parameters, and generate a location statistical query parameter set;

[0139] The caliber fingerprint generation module is used to execute S2: based on the location statistics query parameter set, calculate the geofence area and time window span, sequentially encode and concatenate the spatial raster resolution, geofence area, time window span, statistical type and statistical caliber threshold to generate the query caliber fingerprint index key;

[0140] The noise calibration cache module is used to execute S3: based on the query caliber fingerprint index key, it retrieves the sensitivity and noise parameter cache table, determines the cache hit status and validity period status. The cache table record is formed by the parameter record written by the missed or invalid branch. When it hits and is valid, it reads the query sensitivity and noise variance in the cache table record and writes them into the reuse mark. When it misses or is invalid, it calls the location statistics query parameter set to read the spatial raster resolution, geofence area, time window span, statistical type and statistical caliber threshold, and calculates the query sensitivity. Based on the global sensitivity and privacy budget parameters, it determines the noise variance and writes the query sensitivity, noise variance and validity period information into the sensitivity and noise parameter cache table to generate the query noise calibration parameter group.

[0141] The privacy perturbation output module is used to execute S4: call the query noise calibration parameter group, read the noise variance and the statistical result count value of the corresponding query request, calculate the noise sampling value and perturb the statistical result count value, obtain the perturbation synthesis result, determine the non-negativity of the perturbation synthesis result and replace the negative value with the zero value, and generate the differential privacy perturbation statistical output value;

[0142] The error constraint adjustment module is used to execute S5: based on the differential privacy perturbation statistical output value, calculate the error metric value, obtain the availability error threshold, compare the error metric value with the availability error threshold, update the noise variance and write it to the sensitivity and noise parameter cache table when the availability error threshold is exceeded, and keep the noise variance unchanged when the availability error threshold is not exceeded, and generate a noise parameter update record.

[0143] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A method for balancing location data differential privacy protection and availability optimization, characterized in that, Includes the following steps: S1: Receives query requests for regional heatmaps, grid counts, number of stop points and frequency of trajectory segments, extracts spatial grid resolution, geofence boundaries, start and end times of time windows, statistical type and statistical threshold, establishes a mapping relationship between requests and parameters, and forms a set of location statistics query parameters. S2: Based on the location statistics query parameter set, calculate the geographic fence area and time window span, sequentially encode and splice the spatial raster resolution, fence area, time window span, statistical type and statistical caliber threshold, and generate a query caliber fingerprint index key. S3: Based on the query caliber fingerprint index key, retrieve the sensitivity and noise parameter cache table. If the query sensitivity and noise variance are valid, reuse them. If the query sensitivity is not valid or is invalid, recalculate the query sensitivity and determine the noise variance in combination with the privacy budget and write it into the noise parameter cache table to obtain the query noise calibration parameter group. S4: Based on the query noise calibration parameter group and the count value of the noise disturbance processing statistical results, generate the differential privacy disturbance statistical output value; S5: Based on the differential privacy perturbation statistical output value, calculate the error metric value and compare it with the availability error threshold. If the threshold is exceeded, update the noise variance and write it into the noise parameter cache table. If the threshold is not exceeded, keep the parameter unchanged and form a noise parameter update record.

2. The location data differential privacy protection and availability balance optimization method according to claim 1, characterized in that, The location statistics query parameter set includes spatial raster resolution parameters, geofence boundary parameters, time window start and end time parameters, statistical type parameters, and statistical caliber threshold parameters; the query caliber fingerprint index key specifically includes resolution coding segment, geofence area coding segment, time window span coding segment, statistical type coding segment, and threshold coding segment; the query noise calibration parameter set includes query sensitivity parameters, noise variance parameters, validity period information parameters, and reuse marker parameters; the differential privacy perturbation statistical output value specifically includes perturbation composite count value, zero-value replacement count value, and non-negativity correction count value; the noise parameter update record includes error metric value entries, availability error threshold entries, noise variance update value entries, and cache write identifier entries.

3. The location data differential privacy protection and availability balance optimization method according to claim 1, characterized in that, The specific steps of S1 are as follows: S101: Obtain the regional heat map query request, grid count query request, stop point number query request and trajectory segment frequency query request received by the location service statistics query interface, collect the request identifier and request type tag corresponding to the query request, record the access order for different request identifiers and form a request set number, and obtain the query request type tag value. S102: Based on the query request type marker value, collect the spatial raster resolution, geofence boundary, start and end times of time window and statistical type carried by the query request, perform parameter field validation and compare the numerical format, and for the same request, integrate spatial parameters and time parameters by set number and record parameter group to obtain the query parameter combination quantity. S103: Based on the query parameter combination quantity, collect the statistical threshold carried by the query request, determine the consistency between the threshold and the parameter combination quantity under the request set number and call the threshold, record the correspondence between the threshold and the parameter combination quantity, establish a mapping record between the query request and all parameters, and obtain the location statistics query parameter set.

4. The location data differential privacy protection and availability balance optimization method according to claim 3, characterized in that, The specific steps of S2 are as follows: S201: Based on the location statistics query parameter set, collect the geofence boundary coordinate sequence and coordinate unit, determine the consistency of the first and last points of the boundary coordinate sequence and remove duplicate points, calculate the cumulative value of the line surface connecting adjacent coordinate points and record the area calculation identifier to obtain the geofence area value. S202: Call the geofence area value, collect the start and end times of the time window and the time zone mark, calculate the difference between the start and end times and convert it into a second-level span, determine that the span is non-negative and record the time window number, merge the area value and the time window number to form a combined record, and obtain the time window span value; S203: Based on the time window span value, call the spatial raster resolution, geofence area value, statistical type and statistical caliber threshold, sequentially encode the fields and concatenate the delimiter, determine that the length of the concatenation result is consistent with the number of fields and write it into the index key library, establish a query caliber field sequence mapping record, and generate a query caliber fingerprint index key.

5. The location data differential privacy protection and availability balance optimization method according to claim 4, characterized in that, The specific steps for S3 are as follows: S301: Based on the query fingerprint index key, perform sensitivity and noise parameter cache table retrieval and locate matching record items, determine cache hit status and validity status, and write status flags. For the hit and valid status, read query sensitivity and noise variance and write reuse flags, record the correspondence between index key, status flag and reuse flag, and generate cache hit valid flag quantity. S302: Based on the number of valid cache hits, for the missing or invalid state, call the location statistics query parameter set and read the spatial raster resolution, geofence area, time window span, statistical type, and statistical caliber threshold. Calculate the ratio of spatial raster resolution to geofence area, calculate the product of the ratio and the time window span, write it into the parameter record, and encode the statistical type and statistical caliber threshold combination into the parameter record to generate a query sensitivity value. S303: Call the query sensitivity value, collect the global sensitivity and privacy budget parameters and write them into the budget identifier, calculate the ratio of global sensitivity to query sensitivity, calculate the quotient of the ratio and the privacy budget parameter, write the noise variance and validity period information into the sensitivity and noise parameter cache table, and generate a query noise calibration parameter group.

6. The location data differential privacy protection and availability balance optimization method according to claim 5, characterized in that, The specific steps of S4 are as follows: S401: Call the query noise calibration parameter group, read the noise variance and the corresponding query request identifier, collect the query request statistical result count value and write it into the count flag, determine that the noise variance and the count flag have valid values ​​and write them into the verification identifier, record the correspondence between the query request identifier and the noise variance and count value, establish a mapping record index, and generate the noise count mapping quantity. S402: Based on the noise count mapping, calculate the square root of the noise variance and write it into the scale label, collect a random sampling sequence, calculate the product of the random sampling sequence and the scale label, record the noise sampling value and write it into the sampling label, calculate the noise sampling value, sum it with the statistical result count value and write it into the synthesis identifier, and generate the perturbation synthesis result. S403: Based on the perturbation synthesis result, determine the non-negativity of the synthesis result and write it into the determination flag. For the synthesis result determined to be negative, perform zero value replacement and write it into the replacement flag. Record the correspondence between the query request identifier and the replacement flag, write it into the differential privacy output value cache table, and generate differential privacy perturbation statistical output value.

7. The location data differential privacy protection and availability balance optimization method according to claim 6, characterized in that, The specific steps of S5 are as follows: S501: Based on the differential privacy perturbation statistical output value, collect the corresponding query request statistical result count value and write it into the count flag, calculate the difference between the perturbation statistical output value and the statistical result count value and take the absolute value, record the correspondence between the difference and the query request identifier, write the error calculation identifier, and generate the error measurement value. S502: Call the error metric value, obtain the availability error threshold and write it into the threshold flag, calculate the difference between the error metric value and the availability error threshold, record the comparison flag, determine the positive or negative value of the difference and write it into the threshold determination flag, establish the correspondence between the query request identifier and the threshold determination flag, and generate the threshold exceedance flag quantity. S503: Based on the threshold over-limit marker quantity, for the over-limit marker being true, collect the current noise variance and calculate the update step size value, calculate the sum of the noise variance and the update step size and write it into the update marker, for the over-limit marker being false, record the noise variance preservation marker, write it into the sensitivity and noise parameter cache table, and generate a noise parameter update record.

8. The location data differential privacy protection and availability balance optimization method according to claim 1, characterized in that, The location service statistics query interface is an interface in the location service system that provides external access to receive location statistics query requests and return statistical results. Its source is the statistics query module of the location service system. The location statistics query request is a request type consisting of any one of the following: regional heat map query request, grid count query request, number of stop points query request, and trajectory segment frequency query request. Its source is a statistical query initiated by the upper-layer business system or the client. The spatial grid resolution is a spatial grid division scale parameter, which means the side length, area or level code of the grid cell, and its source is the spatial statistical parameters carried in the query request. The geofence boundary is a boundary parameter of a statistical spatial range. It means boundary information represented by a sequence of polygon vertex coordinates, the center point and radius of a circle, or an administrative region code. Its source is the fence parameter carried in the query request. The start and end times of the time window are the start and end times of the statistical time range, which are derived from the time window parameters carried in the query request. The statistical type is a type identifier for the category of statistical results, which means one or more of the following categories: count, frequency, number of stops, popularity, etc., and its source is the statistical type field carried in the query request; The statistical threshold is a threshold parameter of the statistical rule, which means one or a combination of thresholds such as the dwell determination threshold, trajectory segment division threshold, and minimum count threshold. Its source is the caliber configuration parameter carried in the query request. The location statistics query parameter set is a structured set of query request parameters. It means that it includes at least the spatial raster resolution, geofence boundary and / or geofence area, time window start and end time and / or time window span, statistical type, and statistical threshold. It is a set obtained by parsing, collecting and merging the query request parameters.

9. The location data differential privacy protection and availability balance optimization method according to claim 1, characterized in that, The geofence area is the area value calculated from the geofence boundary, and its source is the result of performing area calculation on the geofence boundary carried in the query request; The time window span is the length of time calculated from the start and end times of the time window, and it is derived from the result of calculating the difference between the end time and the start time. The query caliber fingerprint index key is an index key that represents the query statistical caliber. Its meaning is a string or hash value formed by encoding and concatenating spatial grid resolution, geofence area, time window span, statistical type and statistical caliber threshold in a preset order. Its source is the encoding result generated based on the location statistical query parameter set. The sensitivity and noise parameter cache table is a cache storage structure, which means that it is a table structure or key-value storage structure that records query sensitivity, noise variance and validity information with the query caliber fingerprint index key as the index. Its source is the set of record items formed by cache miss or invalid branch writing. The query sensitivity is a sensitivity parameter for differential privacy statistical queries. It means the upper bound of the statistical result change under adjacent dataset conditions. Its source is the sensitivity result calculated based on spatial raster resolution, geofence area, time window span, statistical type, and statistical caliber threshold. The privacy budget parameter is the budget parameter of the differential privacy mechanism. It means a single parameter or a set of two parameters of the differential privacy budget. Its source is the system privacy configuration strategy or the privacy configuration field carried in the query request. The noise variance is the variance parameter of the noise distribution or a scale parameter equivalent to variance. It is derived from the parameter value calculated based on query sensitivity or global sensitivity and privacy budget parameters and written into the sensitivity and noise parameter cache table.

10. A location data differential privacy protection and availability balance optimization system, characterized in that, The system is used to implement the location data differential privacy protection and availability balance optimization method according to any one of claims 1-9, the system comprising: The location query access module is used to execute S1: to obtain the regional heat map query request, grid count query request, stop point number query request and trajectory segment frequency query request received by the location service statistical query interface, collect the spatial grid resolution, geofence boundary, time window start and end time and statistical type carried in the query request, read the statistical caliber threshold carried in the query request, record the correspondence between the query request and the parameters, and generate a location statistical query parameter set; The caliber fingerprint generation module is used to execute S2: based on the location statistics query parameter set, calculate the geofence area and time window span, sequentially encode and concatenate the spatial raster resolution, geofence area, time window span, statistical type and statistical caliber threshold to generate the query caliber fingerprint index key; The noise calibration cache module is used to execute S3: based on the query caliber fingerprint index key, it retrieves the sensitivity and noise parameter cache table, determines the cache hit status and validity period status. The cache table record is formed by the parameter record written by the missed or invalid branch. When it hits and is valid, it reads the query sensitivity and noise variance in the cache table record and writes them into the reuse mark. When it misses or is invalid, it calls the location statistics query parameter set to read the spatial raster resolution, geofence area, time window span, statistical type and statistical caliber threshold, and calculates the query sensitivity. Based on the global sensitivity and privacy budget parameters, it determines the noise variance and writes the query sensitivity, noise variance and validity period information into the sensitivity and noise parameter cache table to generate the query noise calibration parameter group. The privacy perturbation output module is used to execute S4: call the query noise calibration parameter group, read the noise variance and the statistical result count value of the corresponding query request, calculate the noise sampling value and perturb the statistical result count value, obtain the perturbation synthesis result, determine the non-negativity of the perturbation synthesis result and replace the negative value with the zero value, and generate the differential privacy perturbation statistical output value; The error constraint adjustment module is used to execute S5: based on the differential privacy perturbation statistical output value, calculate the error metric value, obtain the availability error threshold, compare the error metric value with the availability error threshold, update the noise variance and write it to the sensitivity and noise parameter cache table when the availability error threshold is exceeded, and keep the noise variance unchanged when the availability error threshold is not exceeded, and generate a noise parameter update record.