Data sharing method and device, computer device, and storage medium
By using dynamic privacy risk mapping and trust level assessment, the privacy risks and insufficient trust management of existing data sharing methods are addressed, enabling efficient and secure data sharing.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- PING AN TECH (SHENZHEN) CO LTD
- Filing Date
- 2026-03-04
- Publication Date
- 2026-05-29
AI Technical Summary
Existing data sharing methods lack dynamic privacy protection strategies, cannot adapt to changes in the data environment, leading to increased privacy risks. Furthermore, the lack of dynamic assessment and management of the trust level of the target intelligent agent results in insufficient data sharing security.
A dynamic privacy risk map is used to assess the risk of privacy leakage, classify the risks, reverse map the maximum information loss threshold to determine the de-identification strategy, and combine the trust level assessment to determine data sharing. The de-identification module is used to generate target data to ensure secure transmission.
It enables data sharing that is dynamically adapted to changes in the data environment while protecting privacy, ensuring data availability and security.
Smart Images

Figure CN122113169A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of artificial intelligence technology, and more specifically to a data sharing method, apparatus, computer device, and computer-readable storage medium. Background Technology
[0002] Currently, with the rapid development of information technology, data sharing has become increasingly important in various fields such as finance, healthcare, and government. Data sharing can promote information flow, improve business efficiency, and support decision-making, but it also brings the risk of privacy breaches. This is especially true when sensitive information (such as personal identification information, financial data, and medical records) is involved. Therefore, how to achieve data sharing while protecting privacy has become an urgent problem to be solved, particularly in the healthcare and fintech fields where privacy protection requirements are high. Currently, existing data sharing methods have the following limitations:
[0003] 1. Static Privacy Protection Strategies: Most existing data sharing methods employ static privacy protection strategies, which perform fixed-pattern anonymization on data before sharing. However, this approach cannot dynamically adjust privacy protection measures based on real-time data environments and contexts, resulting in limited privacy protection effectiveness. Static strategies cannot adapt to the needs of dynamically changing data; once the data environment changes, privacy risks may increase sharply.
[0004] 2. Lack of dynamic risk assessment: Existing data sharing methods often lack dynamic assessment mechanisms for data privacy risks. Privacy risks depend not only on the sensitivity of the data itself, but also on factors such as the relationships between data and the scenarios in which the data is used.
[0005] 3. Insufficient Trust Management: In the data sharing process, the trust level of the target intelligent agent is crucial to the security of data sharing. However, existing data sharing methods often lack dynamic assessment and management mechanisms for the trust level of the target intelligent agent.
[0006] Therefore, how to provide a data sharing method, apparatus, computer equipment, and computer-readable storage medium that can achieve efficient and secure data sharing while protecting privacy is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention
[0007] In view of the shortcomings of the prior art, the purpose of this invention is to provide a data sharing method, apparatus, computer device and computer-readable storage medium, aiming to solve the problem of how to achieve efficient and secure data sharing while protecting privacy.
[0008] To achieve the above objectives, the present invention adopts the following technical solution: In a first aspect, the present invention provides a data sharing method, comprising: Based on the preset dynamic privacy risk map, determine the privacy leakage risk of the original data in the original intelligent agent; The original data is risk-classified according to the privacy leakage risk to obtain the risk level of the original data. The maximum information loss threshold acceptable to the target intelligent agent is back-mapped based on the risk level. The de-identification strategy of the original data is determined according to the maximum information loss threshold and the risk level. According to the desensitization strategy, the original data is desensitized to generate target data; Assess the trust level of the target intelligent agent, and based on the trust level assessment result and the privacy leakage risk, determine whether to share the target data with the target intelligent agent.
[0009] Secondly, the present invention provides a data sharing device, comprising: The risk assessment module is used to determine the privacy leakage risk of the original data in the original intelligent agent based on a preset dynamic privacy risk map. The strategy determination module is used to classify the original data according to the privacy leakage risk to obtain the risk level of the original data, back-map the maximum information loss threshold acceptable to the target intelligent agent based on the risk level, and determine the de-identification strategy of the original data according to the maximum information loss threshold and the risk level. The desensitization module is used to desensitize the original data according to the desensitization strategy and generate target data; An evaluation module is used to evaluate the trust level of the target intelligent agent and, based on the trust level evaluation result and the privacy leakage risk, determine whether to share the target data with the target intelligent agent.
[0010] Thirdly, the present invention provides a computer device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the data sharing method described above.
[0011] Fourthly, the present invention provides a computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor, implements the data sharing method described above.
[0012] Compared to existing technologies, this invention provides a data sharing method, apparatus, computer device, and computer-readable storage medium. The method involves: determining the privacy leakage risk of original data in the original intelligent agent based on a preset dynamic privacy risk map; classifying the original data according to the privacy leakage risk to obtain a risk level; mapping the risk level back to the maximum acceptable information loss threshold for the target intelligent agent; determining a de-identification strategy for the original data based on the maximum information loss threshold and the risk level; performing de-identification processing on the original data according to the de-identification strategy to generate target data; evaluating the trust level of the target intelligent agent; and determining whether to share the target data with the target intelligent agent based on the trust level evaluation result and the privacy leakage risk. Thus, this invention enables efficient and secure data sharing while protecting privacy. Attached Figure Description
[0013] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0014] Figure 1 This is a schematic diagram illustrating the application environment of a data sharing method provided in an embodiment of the present invention.
[0015] Figure 2 This is a flowchart illustrating a data sharing method according to an embodiment of the present invention.
[0016] Figure 3 This is a schematic diagram of the program modules of a data sharing device provided in an embodiment of the present invention.
[0017] Figure 4 This is a schematic diagram of the structure of a computer device provided in an embodiment of the present invention.
[0018] Figure 5 This is another structural schematic diagram of a computer device provided in an embodiment of the present invention. Detailed Implementation
[0019] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0020] It should be understood that, when used in this specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or collections thereof.
[0021] It should also be understood that the term “and / or” as used in this specification and the appended claims refers to any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.
[0022] As used in this specification and the appended claims, the term "if" may be interpreted, depending on the context, as "when," "once," "in response to determination," or "in response to detection." Similarly, the phrase "if determined" or "if [the described condition or event] is detected" may be interpreted, depending on the context, as meaning "once determined," "in response to determination," "once [the described condition or event] is detected," or "in response to detection of [the described condition or event]."
[0023] Furthermore, in the description of this invention and the appended claims, the terms "first," "second," "third," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.
[0024] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of the invention include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including, but not limited to," unless otherwise specifically emphasized.
[0025] It should be understood that the sequence number of each step in the following embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0026] To illustrate the technical solution of the present invention, specific embodiments are described below.
[0027] An embodiment of the present invention provides a data sharing method that can be applied to, for example... Figure 1In the application environment shown, the client and server communicate via a network. The client includes, but is not limited to, handheld computers, desktop computers, laptops, ultra-mobile personal computers (UMPCs), netbooks, cloud computing devices, and personal digital assistants (PDAs). The server can be a standalone server or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.
[0028] Please see Figure 2 An embodiment of the present invention provides a data sharing method, wherein the method includes the following steps: S100. Based on the preset dynamic privacy risk map, determine the privacy leakage risk of the original data in the original intelligent agent; S200. The original data is classified according to the privacy leakage risk to obtain the risk level of the original data. The maximum information loss threshold acceptable to the target intelligent agent is mapped back based on the risk level. The de-identification strategy of the original data is determined according to the maximum information loss threshold and the risk level. S300. According to the desensitization strategy, the original data is desensitized to generate target data; S400. Assess the trust level of the target intelligent agent, and determine whether to share the target data with the target intelligent agent based on the trust level assessment result and the privacy leakage risk.
[0029] In practical implementation, the data sharing method of this embodiment achieves efficient and secure data sharing while protecting privacy through a series of innovative steps. First, a dynamic privacy risk map enables real-time monitoring and assessment of the privacy leakage risk of raw data, ensuring a comprehensive understanding of privacy risks in the data environment. Next, based on the privacy leakage risk and the maximum acceptable information loss threshold for the target agent, a de-identification strategy is dynamically determined, and corresponding de-identification processing is applied to generate target data that satisfies both privacy protection and usage requirements. Finally, by assessing the trust level of the target agent and combining it with the privacy leakage risk, a comprehensive judgment is made on whether to share the data, ensuring the security of data sharing. This method not only dynamically adapts to changes in the data environment but also flexibly adjusts privacy protection measures, balancing privacy protection and data usability, thereby achieving efficient and secure data sharing while protecting privacy.
[0030] Understandably, the data sharing method provided in this embodiment of the invention can be applied to data sharing scenarios related to the medical and health field. The following is a specific example: Scenario Description: In the healthcare field, hospitals need to share patients' electronic medical records (EHRs) for remote consultations, disease research, or patient referrals. This data contains a large amount of sensitive information, such as patient names, ID numbers, medical history, and test results, making privacy protection crucial.
[0031] Applying the data sharing method of this invention: 1. Privacy Breach Risk Assessment Hospital A needs to share patients' electronic medical record data with Hospital B. First, a dynamic privacy risk graph is used to identify sensitive information entities in the medical records (such as patient names, ID numbers, and disease diagnoses) and assess the associated risks between these entities. For example, the association between a patient's name and a specific disease diagnosis may increase the risk of privacy breaches.
[0032] The dynamic privacy risk map monitors the data environment in real time and automatically updates the risk assessment when new sensitive information or relationships are discovered.
[0033] 2. Determine the desensitization strategy The system dynamically selects anonymization strategies based on the privacy risk and the maximum acceptable information loss threshold for Hospital B. For example, if Hospital B only needs basic health indicators (such as blood pressure and blood sugar) for preliminary analysis and does not require the patient's name and ID number, the system chooses a minimal replacement strategy, replacing the patient's name with an anonymous identifier while retaining the necessary health indicators.
[0034] 3. Desensitization treatment The electronic medical record data is anonymized according to the selected anonymization strategy. For example, the patient's name "Zhang San" is replaced with "Patient 001", and the ID number "123456789012345678" is replaced with "345678", while retaining health indicators such as blood pressure and blood sugar.
[0035] 4. Trust Level Assessment and Shared Decision-Making Assess Hospital B's trust level, considering its historical data usage records, security measures, and compliance. If Hospital B's trust level is high and the risk of privacy breach is low, the system decides to share the anonymized data. During the sharing process, the data is sent to Hospital B via an encrypted transmission protocol (such as TLS).
[0036] Technical benefits: Through the above methods, Hospital A can efficiently and securely share necessary medical data with Hospital B while protecting patient privacy, supporting telemedicine and disease research, and ensuring data availability and security.
[0037] It is understood that the data sharing method provided in this embodiment of the invention can also be applied to data sharing scenarios related to the fintech field. The following is a specific example: Scenario Description: In the fintech sector, financial institutions need to share customer data. For example, Bank A might need to share customer transaction records with Bank B for joint risk assessment or anti-fraud analysis. This data contains sensitive customer information such as names, account balances, and transaction records, making privacy protection and data security critical.
[0038] Applying the data sharing method of this invention: 1. Privacy Breach Risk Assessment Bank A needs to share its customers' transaction records with Bank B. A dynamic privacy risk graph is used to identify sensitive information entities in the transaction records (such as customer names, account numbers, and transaction amounts) and assess the associated risks between these entities. For example, the association between a customer's name and large transaction records may increase the risk of privacy breaches.
[0039] 2. Determine the desensitization strategy The system dynamically selects anonymization strategies based on the privacy risk and Bank B's acceptable maximum information loss threshold. For example, Bank B only needs the transaction amount and time for risk assessment, without the customer's name and account number. Therefore, the system selects a semantic generalization strategy, generalizing the transaction amount "10,000 yuan" to "the range of 10,000-20,000 yuan," while retaining the transaction time.
[0040] 3. Desensitization treatment According to the selected de-identification strategy, the customer's transaction records are de-identified. For example, the transaction amount "10,000 yuan" is generalized to "10,000-20,000 yuan range", the transaction time "2024-05-15" is kept unchanged, and the customer's name and account number are encrypted.
[0041] 4. Trust Level Assessment and Shared Decision-Making Assess Bank B's trust level, considering its historical data usage records, security measures, and compliance. If Bank B's trust level is high and the risk of privacy breach is low, the system decides to share the anonymized data. During the sharing process, the data is sent to Bank B via an encrypted transmission protocol (such as TLS).
[0042] Technical benefits: Through the above methods, Bank A can efficiently and securely share necessary transaction data with Bank B while protecting customer privacy, supporting joint risk assessment and anti-fraud analysis, while ensuring data availability and security.
[0043] In other words, the data sharing method of this invention can effectively achieve a balance between privacy protection and data sharing in both the healthcare and fintech fields. Through dynamic privacy risk mapping, dynamic anonymization strategies, trust level assessments, and secure sharing mechanisms, it ensures that data availability and security are maximized while protecting privacy. This method is particularly suitable for industries with high privacy and data security requirements.
[0044] Furthermore, in one embodiment, the data sharing method, before determining the privacy leakage risk of the original data in the original intelligent agent based on a preset dynamic privacy risk map, specifically includes: Acquire business data provided by several intelligent agents, and perform preprocessing such as cleaning, deduplication, and formatting on the business data; Extract the first sensitive information entity from the preprocessed business data and identify the association information between each of the first sensitive information entities; Based on the first sensitive information entity and the associated relationship information, a dynamic privacy risk map is constructed.
[0045] Furthermore, in the aforementioned data sharing method, the step of determining the privacy leakage risk of the original data in the original intelligent agent based on a preset dynamic privacy risk map specifically includes: Using a distributed data collector, raw data from the original intelligent agent is collected in real time, and the second sensitive information entity in the raw data is identified. Based on the dynamic privacy risk map, calculate the privacy leakage risk value for each of the second sensitive information entities; The privacy leakage risk values of the original data are generated by weighting and summing all the aforementioned privacy leakage risk values.
[0046] In practice, the specific implementation process of this embodiment is roughly as follows: 1. Data Acquisition: Distributed data collectors are used to acquire business data from multiple agents (such as different systems or data sources). This data may include user information, transaction records, medical records, etc.
[0047] The data collector supports multiple data sources, including databases, log files, and real-time data streams, ensuring the comprehensiveness and timeliness of the data.
[0048] 2. Data preprocessing: The collected business data is cleaned, deduplicated, and formatted. The cleaning process includes removing invalid data and correcting erroneous data.
[0049] Deduplication ensures the uniqueness of data and avoids the impact of duplicate data on privacy risk assessments.
[0050] Formatting converts data into a uniform format, making it easier for subsequent processing.
[0051] 3. Sensitive information entity extraction: Extract sensitive information entities (first sensitive information entities) from the preprocessed business data. These entities may include names, ID numbers, account information, etc.
[0052] Use natural language processing (NLP) techniques and machine learning algorithms, such as named entity recognition (NER), to identify sensitive information.
[0053] 4. Relationship identification: Identify the relationships between various sensitive information entities. For example, the relationship between a user's name and account number, or the relationship between transaction amount and transaction time.
[0054] By using techniques such as graph neural networks (GNNs) to analyze the strength of relationships between entities, a foundation can be laid for the construction of a privacy risk graph.
[0055] 5. Map Construction: Based on the extracted sensitive information entities and the identified relationships, a dynamic privacy risk map is constructed.
[0056] The nodes in the graph represent sensitive information entities, the edges represent the relationships between entities, and the edge weights represent the strength of the relationships.
[0057] The map supports dynamic updates, enabling it to reflect changes in the data environment in real time.
[0058] 6. Real-time data acquisition and sensitive information identification: Using a distributed data collector, raw data from the original intelligent agent is collected in real time, and sensitive information entities (secondary sensitive information entities) are identified.
[0059] Real-time data collection ensures the timeliness of privacy risk assessment.
[0060] 7. Privacy Leakage Risk Calculation: Based on a dynamic privacy risk graph, the privacy leakage risk value of each sensitive information entity is calculated. The risk value calculation takes into account the sensitivity of the entity and the strength of the relationship between them.
[0061] A multi-dimensional risk assessment model is used to comprehensively consider factors such as the frequency of data use and the direction of data flow.
[0062] 8. Summary of Privacy Breach Risks: The privacy risk values of all sensitive information entities are weighted and aggregated to generate a comprehensive privacy risk assessment of the original data.
[0063] Weighted aggregation takes into account the importance of different entities and relationships to ensure the accuracy of risk assessment.
[0064] Through the above steps, this invention enables a complete process from data acquisition, preprocessing, sensitive information extraction, and correlation identification to the construction of a dynamic privacy risk map and the assessment of privacy leakage risks. This process not only ensures real-time monitoring and dynamic assessment of privacy risks but also provides a scientific basis for subsequent data sharing decisions, making it particularly suitable for scenarios with high privacy protection requirements.
[0065] Further, in one embodiment, the data sharing method, wherein the step of risk-classifying the original data according to the privacy leakage risk to obtain a risk level of the original data, back-mapping a maximum information loss threshold acceptable to the target intelligent agent based on the risk level, and determining a de-identification strategy for the original data according to the maximum information loss threshold and the risk level, specifically includes: Based on the aforementioned privacy leakage risks, a risk assessment is performed on the raw data to obtain the risk level of the raw data; Based on the privacy protection configuration information preset by the target intelligent agent, the data requirements of the target intelligent agent are obtained, and based on the risk level and the data requirements, the maximum information loss threshold acceptable to the target intelligent agent is derived in reverse. Based on the maximum information loss threshold and the risk level, a de-identification strategy for the original data is generated, and simulation verification is used to ensure that the data de-identified by the de-identification strategy meets the data requirements of the target intelligent agent.
[0066] Furthermore, in the data sharing method, the step of de-identifying the original data according to the de-identification strategy to generate target data specifically includes: Parse the content of the de-identification strategy to obtain the minimization replacement strategy, semantic generalization strategy, and homomorphic encryption strategy; The original data is desensitized using at least one of the minimization replacement strategy, the semantic generalization strategy, and the homomorphic encryption strategy to generate desensitized data. Based on the data requirements of the target intelligent agent, the de-identification effect of the de-identified data is evaluated. When the de-identification effect evaluation result meets the data requirements, the de-identified data is used as target data to be shared with the target intelligent agent.
[0067] In practice, the specific implementation process of this embodiment is roughly as follows: 1. Privacy Breach Risk Assessment: Based on the privacy leakage risk calculated from the dynamic privacy risk map, a detailed risk assessment is conducted on the raw data.
[0068] 2. Risk Level Classification: Based on the pre-set risk assessment model, the risk assessment results of the raw data are divided into different risk levels (such as low, medium, and high).
[0069] The risk level classification is based on industry standards, regulatory requirements, and the company's own privacy policy to ensure the scientific validity and compliance of the risk assessment results.
[0070] 3. Data requirements for acquiring the target intelligent agent: Based on the target agent's preset privacy protection configuration information, obtain its specific data requirements.
[0071] Data requirements include key parameters such as required data fields, data precision, and data purpose. This information can be obtained through configuration files or API interfaces.
[0072] 4. Obtain the maximum information loss threshold Based on the risk level of the original data and the data requirements of the target intelligent agent, the maximum information loss threshold acceptable to the target intelligent agent is derived in reverse.
[0073] 5. Determine the desensitization strategy: By combining the risk level of the original data with the maximum acceptable information loss threshold for the target agent, a suitable desensitization strategy is dynamically selected.
[0074] De-identification strategies may include minimizing substitution, semantic generalization, homomorphic encryption, etc., and the specific choice depends on the risk level and the maximum information loss threshold.
[0075] Using an intelligent decision engine, the system automatically recommends the optimal de-identification strategy based on real-time risk assessment results and the maximum information loss threshold.
[0076] 6. Analysis of desensitization strategies: The selected de-identification strategy is analyzed to obtain the specific parameters and rules of the minimization substitution strategy, semantic generalization strategy, and homomorphic encryption strategy.
[0077] For example, a minimization substitution strategy may include specific substitution rules (such as replacing a name with an anonymous identifier), a semantic generalization strategy may include specific generalization ranges (such as generalizing the age "25" to "20-30 years old"), and a homomorphic encryption strategy may include encryption algorithms and key management methods.
[0078] 7. Perform desensitization processing: Based on the analysis results, at least one desensitization method is used to desensitize the original data to generate desensitized data.
[0079] During the data anonymization process, it is essential to ensure a balance between data privacy and usability. For example, more stringent anonymization measures may be required for high-risk data.
[0080] 8. Desensitization effect evaluation: The effectiveness of data anonymization is evaluated based on the data requirements of the target intelligent agent.
[0081] Evaluation metrics include the degree of privacy protection (such as the degree of concealment of sensitive information) and data availability (such as the integrity and accuracy of data).
[0082] If the desensitization effect evaluation results do not meet the data requirements of the target agent, the system will readjust the desensitization strategy and process it.
[0083] 9. Preparation for target data generation and sharing: When the desensitization effect evaluation results meet the data requirements of the target intelligent agent, the desensitized data will be used as the target data to be shared with the target intelligent agent.
[0084] The target data undergoes final verification before being shared to ensure it meets both privacy and data availability standards.
[0085] Through the above steps, the data sharing method of the present invention can dynamically determine and execute de-identification strategies based on privacy leakage risks and the data needs of the target intelligent agent, generating target data that meets the requirements of privacy protection and data availability. This process not only ensures the security and efficiency of data sharing, but also adapts to complex and ever-changing data environments through dynamic adjustment and real-time evaluation mechanisms.
[0086] Furthermore, in one embodiment, the data sharing method, wherein assessing the trust level of the target agent and determining whether to share the target data with the target agent based on the trust level assessment result and the privacy leakage risk, specifically includes: According to the preset trust level assessment strategy, the trust level of the target intelligent agent is assessed, and a trust level assessment result is generated. Based on a preset data sharing decision-making strategy, the trust level assessment results and the privacy leakage risk are analyzed to generate a sharing decision result for the target data; Based on the generated shared decision result, it is determined whether to share the target data with the target agent.
[0087] Furthermore, in the data sharing method, the step of determining whether to share the target data with the target agent based on the generated sharing decision result specifically includes: When the sharing decision result indicates that the data can be shared, the target data is shared to the target agent, and a data sharing result is generated. According to the preset result display strategy, the data sharing results are sent to the target terminal for display.
[0088] In practice, the specific implementation process of this embodiment is roughly as follows: 1. Trust Level Assessment: The trust level of the target intelligent agent is evaluated according to the preset trust level evaluation strategy.
[0089] Trust level assessment strategies include multi-dimensional analysis, such as the target agent's historical behavior records, security sandbox level, data usage compliance, and code review results.
[0090] Machine learning algorithms (such as random forests or neural networks) are used to analyze the behavioral patterns of target agents and dynamically adjust their trust levels.
[0091] 2. Generate trust level assessment results: Trust level assessment results are presented in the form of trust levels, which are usually divided into three levels: low, medium, and high.
[0092] Record key indicators and parameters in detail during the evaluation process to ensure the traceability of trust level evaluation results.
[0093] 3. Data sharing decision analysis: Based on the preset data sharing decision-making strategy, a comprehensive analysis is conducted, taking into account the trust level assessment results of the target intelligent agent and the risk of privacy leakage.
[0094] The data sharing decision-making strategy includes a quantitative scoring model that weights trust level and privacy leakage risk to generate a comprehensive risk score.
[0095] Using an intelligent decision engine, shared decision results are generated based on comprehensive risk scores and preset decision rules to produce target data.
[0096] 4. Generate shared decision results: The decision-making results clearly indicate whether the target data should be shared, usually in the form of "can be shared" or "cannot be shared".
[0097] If the decision is "cannot be shared", record the specific reasons for refusing to share, such as too low trust level or too high risk of privacy leakage.
[0098] 5. Shared decision execution: When the sharing decision result is "can be shared", the target data is shared to the target intelligent agent.
[0099] To ensure the security of data transmission, use encrypted transmission protocols (such as TLS / SSL) for data sharing.
[0100] Generate data sharing results and record information such as sharing time, data volume, and sharing status.
[0101] 6. Results Display and Feedback: According to the preset result display strategy, the data sharing results are sent to the target terminal (such as the administrator terminal or the operation interface of the target intelligent agent) for display.
[0102] The displayed content includes detailed information such as sharing status (success or failure), sharing time, data volume, and reason for operation.
[0103] It provides a real-time feedback mechanism to support target agents and administrators in confirming and providing feedback on the results of data sharing.
[0104] Through the above steps, the data sharing method of the present invention can dynamically generate sharing decision results based on the trust level and privacy leakage risk of the target intelligent agent, and securely share data based on the sharing decision results. This process ensures the security and efficiency of data sharing.
[0105] As can be seen from the above method embodiments, the data sharing method provided by the present invention includes: determining the privacy leakage risk of original data in the original intelligent agent based on a preset dynamic privacy risk map; classifying the original data according to the privacy leakage risk to obtain the risk level of the original data; mapping the maximum information loss threshold acceptable to the target intelligent agent based on the risk level; determining the desensitization strategy of the original data according to the maximum information loss threshold and the risk level; performing desensitization processing on the original data according to the desensitization strategy to generate target data; evaluating the trust level of the target intelligent agent; and determining whether to share the target data with the target intelligent agent based on the trust level evaluation result and the privacy leakage risk. Thus, the method of the present invention can achieve efficient and secure data sharing while protecting privacy.
[0106] It should be understood that although this application provides the method operation steps as described in the embodiments or flowcharts, conventional or non-inventive labor may include more or fewer operation steps, and these operation steps are not necessarily executed sequentially according to the order of the embodiments or flowcharts. The order of steps listed in the embodiments or flowcharts is merely one way of executing many steps and does not represent the only execution order. It should be noted that there is no necessary sequential order between the above steps. Those skilled in the art can understand from the description of the embodiments of the present invention that the above steps may have different execution orders in different embodiments, that is, they may be executed in parallel or in exchange, etc. Moreover, at least some steps in the embodiments or flowcharts may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but may be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but may be executed in turn, alternately, or synchronously with other steps or at least a part of the sub-steps or stages of other steps.
[0107] Based on the above method embodiments, please refer to Figure 3 Another embodiment of the present invention also provides a data sharing device, wherein the device includes: Risk determination module 11 is used to determine the privacy leakage risk of the original data in the original intelligent agent based on the preset dynamic privacy risk map; The strategy determination module 12 is used to classify the original data according to the privacy leakage risk to obtain the risk level of the original data, back-map the maximum information loss threshold acceptable to the target intelligent agent based on the risk level, and determine the de-identification strategy of the original data according to the maximum information loss threshold and the risk level. The desensitization module 13 is used to perform desensitization processing on the original data according to the desensitization strategy to generate target data; The evaluation module 14 is used to evaluate the trust level of the target intelligent agent and, based on the trust level evaluation result and the privacy leakage risk, determine whether to share the target data with the target intelligent agent.
[0108] Furthermore, in one embodiment, the data sharing device, before determining the privacy leakage risk of the original data in the original intelligent agent based on a preset dynamic privacy risk map, specifically includes: Acquire business data provided by several intelligent agents, and perform preprocessing such as cleaning, deduplication, and formatting on the business data; Extract the first sensitive information entity from the preprocessed business data and identify the association information between each of the first sensitive information entities; Based on the first sensitive information entity and the associated relationship information, a dynamic privacy risk map is constructed.
[0109] Furthermore, in the aforementioned data sharing device, the step of determining the privacy leakage risk of the original data in the original intelligent agent based on a preset dynamic privacy risk map specifically includes: Using a distributed data collector, raw data from the original intelligent agent is collected in real time, and the second sensitive information entity in the raw data is identified. Based on the dynamic privacy risk map, calculate the privacy leakage risk value for each of the second sensitive information entities; The privacy leakage risk values of the original data are generated by weighting and summing all the aforementioned privacy leakage risk values.
[0110] Further, in one embodiment, the data sharing device, wherein the step of risk-classifying the original data according to the privacy leakage risk to obtain a risk level of the original data, back-mapping a maximum information loss threshold acceptable to the target intelligent agent based on the risk level, and determining a de-identification strategy for the original data according to the maximum information loss threshold and the risk level, specifically includes: Based on the aforementioned privacy leakage risks, a risk assessment is performed on the raw data to obtain the risk level of the raw data; Based on the privacy protection configuration information preset by the target intelligent agent, the data requirements of the target intelligent agent are obtained, and based on the risk level and the data requirements, the maximum information loss threshold acceptable to the target intelligent agent is derived in reverse. Based on the maximum information loss threshold and the risk level, a de-identification strategy for the original data is generated, and simulation verification is used to ensure that the data de-identified by the de-identification strategy meets the data requirements of the target intelligent agent.
[0111] Furthermore, in the data sharing device, the step of performing de-identification processing on the original data according to the de-identification strategy to generate target data specifically includes: Parse the content of the de-identification strategy to obtain the minimization replacement strategy, semantic generalization strategy, and homomorphic encryption strategy; The original data is desensitized using at least one of the minimization replacement strategy, the semantic generalization strategy, and the homomorphic encryption strategy to generate desensitized data. Based on the data requirements of the target intelligent agent, the de-identification effect of the de-identified data is evaluated. When the de-identification effect evaluation result meets the data requirements, the de-identified data is used as target data to be shared with the target intelligent agent.
[0112] Furthermore, in one embodiment, the data sharing apparatus, wherein assessing the trust level of the target agent and determining whether to share the target data with the target agent based on the trust level assessment result and the privacy leakage risk, specifically includes: According to the preset trust level assessment strategy, the trust level of the target intelligent agent is assessed, and a trust level assessment result is generated. Based on a preset data sharing decision-making strategy, the trust level assessment results and the privacy leakage risk are analyzed to generate a sharing decision result for the target data; Based on the generated shared decision result, it is determined whether to share the target data with the target agent.
[0113] Furthermore, in the data sharing device, the step of determining whether to share the target data with the target agent based on the generated sharing decision result specifically includes: When the sharing decision result indicates that the data can be shared, the target data is shared to the target agent, and a data sharing result is generated. According to the preset result display strategy, the data sharing results are sent to the target terminal for display.
[0114] It should be noted that, in the device embodiments of the present invention, the information interaction and execution process between the above modules are based on the same concept as in the method embodiments of the present invention. For details on their specific functions and the resulting technical effects, please refer to the aforementioned method embodiments section, which will not be repeated here.
[0115] Based on the above method embodiments, another embodiment of the present invention also provides a computer device, which can be a server, and its internal structure diagram can be as follows. Figure 4 As shown. The computer device includes a processor, memory, network interface, and database connected via a system bus. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The network interface is used to communicate with external terminals via a network connection. When the computer program is executed by the processor, it implements the functions or steps of the data sharing method server-side as described in any of the above method embodiments.
[0116] Based on the above method embodiments, another embodiment of the present invention also provides a computer device, which can be a client, and its internal structure diagram can be as follows. Figure 5As shown, the computer device includes a processor, memory, network interface, display screen, and input device connected via a system bus. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The network interface is used to communicate with external terminals via a network connection. When executed by the processor, the computer program implements the functions or steps of the data sharing method on the client side as described in any of the above method embodiments.
[0117] Those skilled in the art will understand that Figure 4 and Figure 5 The structural schematic diagram shown is only a schematic diagram of a part of the structure related to the present invention and does not constitute a limitation on the computer device on which the present invention is applied. The specific computer device may include more components than shown in the figure, or combine certain components, or have different component arrangements.
[0118] The processor referred to herein can be a CPU, but it can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor.
[0119] The memory includes readable storage media, internal memory, etc., where internal memory can be the RAM of a computer device. Internal memory provides an environment for the operation of the operating system and computer-readable instructions stored in the readable storage media. The readable storage media can be the hard drive of the computer device, or in other embodiments, it can be an external storage device of the computer device, such as a plug-in hard drive, Smart Media Card (SMC), Secure Digital (SD) card, or Flash Card. Furthermore, the memory can include both internal storage units and external storage devices of the computer device. The memory is used to store the operating system, applications, bootloader, data, and other programs, such as program code for computer programs. The memory can also be used to temporarily store data that has been output or will be output.
[0120] Based on the above method embodiments, another embodiment of the present invention provides a computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor, implements the data sharing method as described in any of the above method embodiments. The computer-readable storage medium may be non-volatile or volatile.
[0121] It should be noted that the functions or steps that can be achieved by the computer-readable storage medium or computer device, and the technical effects brought about by the functions / steps, can be referred to the relevant descriptions in the foregoing method embodiments. To avoid repetition, they will not be described one by one here.
[0122] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc. The disclosed memory components or memories of the operating environment described herein are intended to include one or more of these and / or any other suitable types of memory.
[0123] Those skilled in the art will understand that, for the sake of convenience and brevity, the embodiments of the device of the present invention are only illustrated by the division of the above-mentioned functional units and modules. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of the present invention. The specific working process of the units and modules in the above device can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here. If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium.
[0124] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.
[0125] In the embodiments provided by this invention, it should be understood that the disclosed apparatus / computer devices and methods can be implemented in other ways. For example, the apparatus / computer device embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0126] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0127] It should be noted that if any software tools or components not belonging to this company appear in the embodiments of this application, they are merely illustrative examples and do not represent actual use. The above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.
Claims
1. A data sharing method, characterized in that, include: Based on the preset dynamic privacy risk map, determine the privacy leakage risk of the original data in the original intelligent agent; The original data is risk-classified according to the privacy leakage risk to obtain the risk level of the original data. The maximum information loss threshold acceptable to the target intelligent agent is back-mapped based on the risk level. The de-identification strategy of the original data is determined according to the maximum information loss threshold and the risk level. According to the desensitization strategy, the original data is desensitized to generate target data; Assess the trust level of the target intelligent agent, and based on the trust level assessment result and the privacy leakage risk, determine whether to share the target data with the target intelligent agent.
2. The data sharing method according to claim 1, characterized in that, Before determining the privacy leakage risk of the original data in the original intelligent agent based on the preset dynamic privacy risk map, the process includes: Acquire business data provided by several intelligent agents, and perform preprocessing such as cleaning, deduplication, and formatting on the business data; Extract the first sensitive information entity from the preprocessed business data and identify the association information between each of the first sensitive information entities; Based on the first sensitive information entity and the associated relationship information, a dynamic privacy risk map is constructed.
3. The data sharing method according to claim 2, characterized in that, The step of determining the privacy leakage risk of the original data in the original intelligent agent based on a preset dynamic privacy risk map includes: Using a distributed data collector, raw data from the original intelligent agent is collected in real time, and the second sensitive information entity in the raw data is identified. Based on the dynamic privacy risk map, calculate the privacy leakage risk value for each of the second sensitive information entities; The privacy leakage risk values of the original data are generated by weighting and summing all the aforementioned privacy leakage risk values.
4. The data sharing method according to claim 1, characterized in that, The process of risk-classifying the original data based on the privacy leakage risk to obtain the risk level of the original data, back-mapping the maximum information loss threshold acceptable to the target intelligent agent based on the risk level, and determining the de-identification strategy of the original data based on the maximum information loss threshold and the risk level includes: Based on the aforementioned privacy leakage risks, a risk assessment is performed on the raw data to obtain the risk level of the raw data; Based on the privacy protection configuration information preset by the target intelligent agent, the data requirements of the target intelligent agent are obtained, and based on the risk level and the data requirements, the maximum information loss threshold acceptable to the target intelligent agent is derived in reverse. Based on the maximum information loss threshold and the risk level, a de-identification strategy for the original data is generated, and simulation verification is used to ensure that the data de-identified by the de-identification strategy meets the data requirements of the target intelligent agent.
5. The data sharing method according to claim 4, characterized in that, The step of performing de-identification processing on the original data according to the de-identification strategy to generate target data includes: Parse the content of the de-identification strategy to obtain the minimization replacement strategy, semantic generalization strategy, and homomorphic encryption strategy; The original data is desensitized using at least one of the minimization replacement strategy, the semantic generalization strategy, and the homomorphic encryption strategy to generate desensitized data. Based on the data requirements of the target intelligent agent, the de-identification effect of the de-identified data is evaluated. When the de-identification effect evaluation result meets the data requirements, the de-identified data is used as target data to be shared with the target intelligent agent.
6. The data sharing method according to claim 1, characterized in that, The process of assessing the trust level of the target agent and determining whether to share the target data with the target agent based on the trust level assessment result and the privacy leakage risk includes: According to the preset trust level assessment strategy, the trust level of the target intelligent agent is assessed, and a trust level assessment result is generated. Based on a preset data sharing decision-making strategy, the trust level assessment results and the privacy leakage risk are analyzed to generate a sharing decision result for the target data; Based on the generated shared decision result, it is determined whether to share the target data with the target agent.
7. The data sharing method according to claim 6, characterized in that, The step of determining whether to share the target data with the target agent based on the generated sharing decision result includes: When the sharing decision result indicates that the data can be shared, the target data is shared to the target agent, and a data sharing result is generated. According to the preset result display strategy, the data sharing results are sent to the target terminal for display.
8. A data sharing device, characterized in that, include: The risk assessment module is used to determine the privacy leakage risk of the original data in the original intelligent agent based on a preset dynamic privacy risk map. The strategy determination module is used to classify the original data according to the privacy leakage risk to obtain the risk level of the original data, back-map the maximum information loss threshold acceptable to the target intelligent agent based on the risk level, and determine the de-identification strategy of the original data according to the maximum information loss threshold and the risk level. The desensitization module is used to desensitize the original data according to the desensitization strategy and generate target data; An evaluation module is used to evaluate the trust level of the target intelligent agent and, based on the trust level evaluation result and the privacy leakage risk, determine whether to share the target data with the target intelligent agent.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the data sharing method as described in any one of claims 1-7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the data sharing method as described in any one of claims 1-7.