Multi-modal encrypted big data privacy desensitization protection method and storage medium
By employing a multimodal encryption method for big data privacy desensitization, the problem of privacy feature identification and protection in multimodal big data is solved. This method achieves closed-loop management throughout the entire process, ensuring unified protection of privacy features and data availability, and adapting to the differentiated processing needs of different modal data.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ZHUHAI FASITE SOFTWARE TECH CO LTD
- Filing Date
- 2026-05-07
- Publication Date
- 2026-08-04
AI Technical Summary
Existing technologies cannot effectively identify and protect privacy features in multimodal big data, resulting in incomplete desensitization of privacy information across different modalities, inconsistent protection strength, imperfect key management, inability to achieve coordinated protection of multimodal data, lack of closed-loop control throughout the entire process, and difficulty in meeting the privacy protection needs in multimodal big data scenarios.
The big data privacy desensitization protection method using multimodal encryption includes data type identification and structured decomposition, privacy feature extraction and classification, generation of differentiated desensitization rules, multimodal linkage encryption key system and attribute-based access control, to achieve auditing and anomaly identification of the entire process operation behavior.
It achieves full-coverage extraction and unified management of privacy features in multimodal big data, ensuring precise matching between the sensitivity level of privacy features and the strength of de-identification processing, improving the security and linkage of the encryption system, and realizing the traceability, auditability and controllability of data, thus meeting the privacy compliance requirements and business application needs of multimodal big data.
Smart Images

Figure CN122508618A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer data security technology, and in particular to a method and storage medium for big data privacy desensitization protection using multimodal encryption. Background Technology
[0002] With the continuous advancement of digitalization, the application scenarios of multimodal big data in various business systems are constantly expanding. Text, images, audio, and video—four types of integrated data—have become the core data carriers of various business systems. The risk of leakage of sensitive personal information and core business data contained within this data has become a key focus of data security management. Current data privacy protection regulations have put forward clear requirements for the full lifecycle protection of personal information and sensitive data. Traditional privacy desensitization technologies are mostly developed for single text-based structured data, and can only achieve basic desensitization processing of sensitive fields with fixed formats. They cannot adapt to the distribution characteristics of different types of privacy features in multimodal data, and their ability to identify privacy information in unstructured data such as images, audio, and video is insufficient. It is difficult to achieve full coverage identification and unified management of associated privacy features in multimodal data, and problems such as incomplete desensitization and inconsistent protection strength of the same subject's privacy information in different modal data are prone to occur, failing to meet the basic privacy protection needs in multimodal big data scenarios.
[0003] Existing privacy-de-identifying technologies for multimodal data mostly adopt a single-modal independent processing model, failing to establish a mapping relationship between privacy features of different modalities. De-identification rules and encryption systems are disconnected, failing to achieve coordinated protection of multimodal data. Current technologies rely heavily on manually set fixed rules for the classification and grading of privacy data, lacking quantitative criteria. This easily leads to a mismatch between privacy feature grading and de-identification strength; excessive de-identification can result in loss of data service availability, while insufficient de-identification strength fails to achieve effective privacy protection. Furthermore, existing key management systems often employ a single-key encryption mode, unable to adapt to the differentiated encryption needs of multimodal data, multiple access subjects, and various business scenarios. The key lifecycle management process is incomplete, posing security risks of key leakage and unauthorized access. Access control often adopts a fixed-role, coarse-grained management model, unable to achieve fine-grained access matching and dynamic control based on the multidimensional attributes of the access subject.
[0004] Existing multimodal data privacy protection technologies lack a closed-loop management system encompassing de-identification, encryption, access control, and behavior auditing. They lack the ability to record and audit data operations across the entire lifecycle in an immutable, multi-dimensional manner, making it impossible to identify and respond to abnormal access behavior in real time. Furthermore, existing technologies lack a refined control mechanism for the reversibility of de-identification, failing to classify and manage reversible and irreversible de-identification according to business scenario requirements. This makes it difficult to achieve an effective balance between the privacy protection strength and business usability of de-identified data, thus failing to simultaneously meet the privacy compliance requirements and business application needs of multimodal big data. Summary of the Invention
[0005] The present invention proposes a multimodal encryption method and storage medium for big data privacy desensitization protection, in order to solve the problems mentioned in the prior art.
[0006] To achieve the above objectives, the present invention adopts the following technical solution: a multimodal encryption method for big data privacy de-identification protection, comprising the following steps: A multimodal dataset to be processed is obtained, and the dataset is subjected to data type identification and structured splitting to obtain four basic modal data units: text, image, audio, and video. Standardized format conversion and invalid data cleaning are then performed on each modal data unit. Construct a multi-dimensional privacy data feature library, extract user identity features, behavioral trajectory features, location information features, biometric features and business-sensitive features from various modal data units, standardize and classify privacy features, and establish a mapping relationship between privacy features and desensitization levels; Based on the attribute characteristics and corresponding privacy levels of each modal data unit, differentiated desensitization rules adapted to the characteristics of each modal data are generated; at the same time, a multimodal linkage encryption key system is constructed based on the national cryptographic encryption algorithm system to generate encryption keys and decryption keys that correspond one-to-one with each modal data. According to the differentiated desensitization rules, the privacy feature regions in each modal data unit are located and corresponding levels of desensitization processing are performed; based on the multimodal linkage encryption key system, the desensitized modal data, the desensitization rule mapping table, and the privacy feature classification table are encrypted in layers to obtain the encrypted desensitized multimodal dataset; Construct an attribute-based access control system, set multi-dimensional access control hierarchical rules, verify the identity attributes, access scenarios and business permissions of the access subject, and match the corresponding data decryption and access permissions; log and audit the operations of data access, de-identification processing and key management.
[0007] Furthermore, it also includes preprocessing steps for multimodal big data sets and accurate identification of privacy features. Specifically, for each modal data unit after format conversion and invalid data cleaning, feature enhancement processing of the corresponding modality is performed; for text data, word segmentation and named entity recognition are performed to extract privacy entity features; for image data, target region segmentation and optical character recognition are performed to extract image features; for audio data, speech-to-text processing and voiceprint feature extraction are performed; for video data, keyframe extraction and inter-frame correlation analysis are performed, simultaneously extracting image privacy features and audio privacy features from the video, and deduplication and correlation construction are performed on all extracted privacy features.
[0008] Furthermore, it also includes quantitative calculation steps for the classification and categorization of privacy data. Specifically, for each extracted privacy feature, a quantitative calculation of the privacy risk value is performed from three core dimensions: sensitivity level, scope of diffusion, and impact dimension. The calculation method is as follows: ; in, This represents the quantification of privacy risk for a single privacy feature. Quantify the inherent sensitivity level of privacy features. A quantification of the proliferative scope of privacy features. Quantification of the impact dimensions after privacy feature leakage. , , These are the weight coefficients corresponding to the sensitivity level, diffusion range, and impact dimension, respectively, and they satisfy the following conditions: + + =1. Based on the calculated privacy risk quantification value, privacy features are divided into four levels: low risk, medium risk, high risk, and extremely high risk, corresponding to four desensitization levels: Level 1, Level 2, Level 3, and Level 4.
[0009] Furthermore, it also includes a layered construction step for a multimodal linkage encryption key system, specifically: generating a root key pair based on the national cryptographic SM2 asymmetric encryption algorithm, wherein the root key pair includes a root public key and a root private key, the root private key is stored and managed offline by a hardware encryption machine, and the root public key is used for the encryption protection of upper-layer working keys; generating corresponding modal working keys for each type of modal data, generating corresponding task working keys for each independent de-identification processing task, and generating corresponding user working keys for each access subject based on the national cryptographic SM4 symmetric encryption algorithm; all working keys are encrypted and stored through the root public key, and a unique binding relationship is established between the working key and the corresponding modal data, de-identification task, and access subject; the entire process of key generation, distribution, update, and destruction is subject to operation recording and permission verification.
[0010] Furthermore, it also includes a differentiated desensitization rule generation step adapted to the characteristics of multimodal data. Specifically, for text data, based on the desensitization level of privacy features, four desensitization processing methods are set: replacement, masking, generalization, and emptying. For image data, based on the localization results of privacy feature regions, four desensitization processing methods are set: pixelation, Gaussian blurring, feature replacement, and region cropping. For audio data, based on the localization results of privacy features, four desensitization processing methods are set: voice changing, sensitive content muting, voiceprint feature perturbation, and content replacement. For video data, based on the privacy feature localization results of inter-frame correlation, four desensitization processing methods are set: dynamic face blurring, sensitive audio muting, subtitle content masking, and trajectory feature generalization.
[0011] Furthermore, it also includes a precise matching and verification step for attribute-based access permissions, specifically: when an access subject initiates a data access request, the attribute information of the access subject is obtained, and a multi-dimensional attribute set is constructed; the multi-dimensional attribute set is matched with preset access permission level rules, and the permission matching degree is calculated, the calculation method being: ; in, Match metric values to the permissions requested for the access request. To ensure compliance matching of the access subject's identity attributes, The matching value between the access principal role and the business permissions. Match the security level of the access environment to the specified value. This is a value used to match access time with the compliance requirements of the business scenario. , , , These are the weighting coefficients corresponding to identity attributes, business permissions, access environment, and access time, respectively, and they satisfy the following conditions: + + + =1.
[0012] Furthermore, it also includes reversible control and data restoration steps for de-identification processing. Specifically, it sets two processing modes for business scenarios: reversible and irreversible de-identification. For the privacy features in the irreversible de-identification mode, it performs generalization, emptying, or feature perturbation processing and destroys the corresponding original privacy feature data. For the privacy features in the reversible de-identification mode, it performs replacement or masking processing, establishes a mapping relationship table between the original privacy features and the de-identified features, and encrypts and stores the mapping relationship table using a modal working key. It verifies the identity and approves the operation of the access subject with corresponding permissions. After approval, it grants the decryption permission of the mapping relationship table and performs de-identified data restoration. It logs and audits the restoration operation in real time, and performs secondary encryption and permission locking on the mapping relationship table after the operation is completed.
[0013] Furthermore, it also includes full-process operation behavior auditing and abnormal risk warning steps, specifically: logging the entire data processing operation, storing the audit logs in an immutable manner, and verifying the integrity of the logs using the national cryptographic SM3 hash algorithm; constructing a machine learning abnormal behavior recognition model to identify and determine the risk level of high-frequency repeated access, cross-permission access, unauthorized modification of desensitization rules, unauthorized key management, and abnormal access from other locations; and performing operation blocking, account permission locking, and early warning information push for high-risk abnormal operations, and recording the abnormal behavior information in the audit log.
[0014] Furthermore, it includes usability verification and optimization steps for the de-identified multimodal data. Specifically, it performs multi-dimensional data usability verification on the multimodal dataset after de-identification and encryption. For text data, it verifies the semantic integrity and consistency of business statistical characteristics of the de-identified text; for image data, it verifies the integrity of non-privacy areas of the de-identified image and its usability for business analysis; for audio data, it verifies the intelligibility and semantic integrity of the non-sensitive content of the de-identified audio; for video data, it verifies the continuity of the video footage and the integrity of the non-sensitive content. When the verification result does not meet the preset usability threshold, the processing parameters of the corresponding de-identification rule are automatically adjusted and the de-identification process is re-executed while maintaining the same level of privacy protection, until the verification result meets the usability requirements.
[0015] Compared with existing technologies, the beneficial effects of this invention are: This invention, through the structured decomposition of multimodal big data and the accurate identification of privacy features of corresponding modalities, can adapt to the characteristics of four different types of data: text, image, audio, and video. It achieves full-coverage extraction and association construction of privacy features in all modal data, solves the problem of insufficient privacy identification capability of traditional technologies for unstructured multimodal data, and realizes unified management and matching of protection strength of privacy features of the same subject in different modal data.
[0016] This invention provides a standardized basis for generating differentiated de-identification rules by quantitatively classifying and categorizing privacy features. It enables precise matching between the sensitivity level of privacy features and the intensity of de-identification processing, achieving effective privacy protection while preserving the business application value of the data, thus balancing the relationship between the strength of privacy protection and data usability. By setting differentiated de-identification rules adapted to the characteristics of different data modalities, it can employ appropriate de-identification processing methods for the privacy features of different types of data, improving the targeting and effectiveness of de-identification processing.
[0017] This invention constructs a multimodal linkage encryption key system in a hierarchical manner, based on the national cryptographic algorithm system, to achieve hierarchical management of the root key and multi-level working keys, establish a unique binding relationship between the key and modal data, processing tasks, and access subjects, improve the control process of the key's entire life cycle, enhance the security and linkage of the encryption system, and achieve hierarchical encryption protection of desensitized data, rule mapping tables, and hierarchical tables, thus solving the problem of the separation between desensitization and encryption systems in traditional technologies.
[0018] This invention utilizes an attribute-based access control system to achieve precise matching and dynamic verification of permissions based on the multi-dimensional attributes of the accessing entity, enabling refined control over data access permissions. Through chain-like storage auditing of the entire operational process and real-time identification of abnormal behavior, it achieves traceability, auditability, and controllability of data operations throughout their entire lifecycle. It can also perform real-time coordinated responses to high-risk abnormal operations, thus improving the closed-loop control system for data security protection.
[0019] This invention, through a classification and control mechanism of reversible and irreversible data anonymization, can adapt to the differentiated processing needs of different business scenarios, realize full-process access control and auditing of anonymized data restoration, and continuously optimize the anonymization effect without reducing the strength of privacy protection by verifying the availability of the anonymized data and automatically optimizing the rules. This ensures the business availability of the anonymized data and meets the compliance requirements and business application needs of multimodal big data privacy protection. Attached Figure Description
[0020] Figure 1 This is a schematic block diagram of the multimodal encryption big data privacy desensitization protection method and storage medium proposed in this invention; Figure 2 Flowchart for multimodal data preprocessing and accurate identification of privacy features; Figure 3 Flowchart for the hierarchical construction of a multimodal linkage encryption key system; Figure 4 Flowchart for generating and optimizing differentiated de-identification rules and usability verification; Figure 5 This is a flowchart for attribute-based permission verification and full-process auditing and early warning. Detailed Implementation
[0021] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0022] In the description of this invention, it should be understood that the terms "center," "longitudinal," "lateral," "length," "width," "thickness," "upper," "lower," "front," "rear," "left," "right," "vertical," "horizontal," "top," "bottom," "inner," "outer," "clockwise," and "counterclockwise," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing this invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this invention.
[0023] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of the stated features. In the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified. Furthermore, the terms "installed," "connected," and "linked" should be interpreted broadly; for example, they may refer to a fixed connection, a detachable connection, or an integral connection; they may refer to a mechanical connection or an electrical connection; they may refer to a direct connection or an indirect connection through an intermediate medium; and they may refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this invention based on the specific circumstances. The invention will now be described in further detail with reference to the accompanying drawings.
[0024] Reference Figures 1 to 5 A multimodal encryption method for big data privacy de-identification protection includes the following steps: The system acquires a multimodal dataset to be processed, performs data type identification and structured splitting on the dataset, and splits it into four basic modal data units: text data, image data, audio data, and video data. It also completes the standardized format conversion and invalid data cleaning of the multimodal data. Construct a multi-dimensional privacy data feature library, extract user identity features, behavioral trajectory features, location information features, biometric features, and business-sensitive features contained in various modal data, complete the standardized labeling and hierarchical classification of privacy features, and establish a mapping relationship between privacy features and desensitization levels; Based on the attribute characteristics and corresponding privacy levels of each modal data unit after splitting, differentiated desensitization rules adapted to the characteristics of each modal data are generated. At the same time, a multimodal linkage encryption key system is constructed based on the national cryptographic encryption algorithm system to generate encryption keys and decryption keys that correspond one-to-one with each modal data. According to the generated differentiated desensitization rules, the privacy feature regions in each modal data unit are precisely located and desensitized according to the corresponding level. Simultaneously, based on the multimodal linkage encryption key system, the desensitized modal data, desensitization rule mapping table, and privacy feature classification table are subjected to layered encryption processing to generate an encrypted desensitized multimodal dataset. Construct an attribute-based access control system, set multi-dimensional access control hierarchical rules, verify the identity attributes, access scenarios, and business permissions of the access subject, and match the corresponding data decryption and data access permissions; perform full-process logging and behavior auditing for all data access operations, de-identification operations, and key management operations, and complete the full-process closed-loop control of multimodal big data privacy de-identification protection.
[0025] This invention also includes preprocessing and precise identification of privacy features for multimodal big data sets. Specifically, for each modal data unit after format conversion and invalid data cleaning, feature enhancement processing corresponding to the modality is performed. For text data, word segmentation and named entity recognition are performed to extract privacy entity features such as name, ID number, mobile phone number, bank card number, address information, and business number. For image data, target region segmentation and optical character recognition are performed to extract facial features, document information features, license plate information features, and text privacy features. For audio data, speech-to-text processing and voiceprint feature extraction are performed to extract voice content privacy features and voiceprint biometric features. For video data, keyframe extraction and inter-frame correlation analysis are performed to simultaneously extract image privacy features and audio privacy features from the video, achieving full coverage extraction and precise localization of privacy features across all modal data. At the same time, deduplication and association relationship construction are performed on all extracted privacy features to clarify the privacy feature association mapping relationship of the same subject in different modal data.
[0026] This invention also includes a quantitative calculation step for the classification and grading of privacy data. Specifically, for each extracted privacy feature, a quantitative calculation of the privacy risk value is performed from three core dimensions: sensitivity level, diffusion range, and impact dimension. The calculation method is as follows: ; in, This represents the quantification of privacy risk for a single privacy feature. Quantify the inherent sensitivity level of privacy features. A quantification of the proliferative scope of privacy features. Quantification of the impact dimensions after privacy feature leakage. , , These are the weight coefficients corresponding to the sensitivity level, diffusion range, and impact dimension, respectively, and they satisfy the following conditions: + + =1. Based on the calculated privacy risk quantification value, privacy features are divided into four levels: low risk, medium risk, high risk, and extremely high risk. Correspondingly, four de-identification levels are generated: Level 1, Level 2, Level 3, and Level 4. This provides a quantitative numerical basis for the generation of differentiated de-identification rules. At the same time, the privacy risk quantification value and the corresponding de-identification level are synchronously entered into the multi-dimensional privacy data feature library.
[0027] This invention also includes a layered construction step for a multimodal linkage encryption key system. Specifically, it generates a root key pair based on the national standard SM2 asymmetric encryption algorithm. The root key pair includes a root public key and a root private key. The root private key is stored and managed offline by a hardware encryption machine, and the root public key is used for the encryption protection of the upper-layer working keys. Based on the national standard SM4 symmetric encryption algorithm, a corresponding modal working key is generated for each type of modal data, a corresponding task working key is generated for each independent de-identification processing task, and a corresponding user working key is generated for each access subject. All working keys are encrypted and stored through the root public key. At the same time, a unique binding relationship is established between the working key and the corresponding modal data, de-identification task, and access subject. The entire process of key generation, distribution, update, and destruction is recorded and verified for permissions. Only subjects with key management permissions can perform the full lifecycle management operation of the key. At the same time, the working key is automatically updated according to a preset time period. The updated key synchronously completes the re-encryption processing of the corresponding encrypted data, thereby improving the security and linkage of the multimodal data encryption system.
[0028] This invention also includes a differentiated desensitization rule generation step adapted to the characteristics of multimodal data. Specifically, for text data, based on the desensitization level of privacy features, four desensitization processing methods are set: replacement, masking, generalization, and emptying. For image data, based on the location results of privacy feature regions, four desensitization processing methods are set: pixelation, Gaussian blurring, feature replacement, and region cropping. For audio data, based on the location results of privacy features, four desensitization processing methods are set: voice changing, sensitive content muting, voiceprint feature perturbation, and content replacement. For video data, based on the privacy feature location results of inter-frame correlation, four desensitization processing methods are set: dynamic face blurring, sensitive audio muting, subtitle content masking, and trajectory feature generalization. At the same time, processing parameters corresponding to the desensitization level are set for each desensitization processing method, so that different levels of desensitization processing meet the privacy protection and data availability requirements of the corresponding scenarios. The generated desensitization rules are uniquely bound to the corresponding modal data and privacy feature level, and are synchronously entered into the multi-dimensional privacy data feature library.
[0029] This invention also includes a precise matching and verification step for attribute-based access permissions. Specifically, when an access subject initiates a data access request, the access subject's identity attributes, role attributes, business permission attributes, access environment attributes, and access time attributes are first collected to construct a multi-dimensional attribute set for the access subject. This multi-dimensional attribute set is then matched against preset access permission level rules to calculate the access request's permission matching degree. The calculation method is as follows: ; in, Match metric values to the permissions requested for the access request. To ensure compliance matching of the access subject's identity attributes, The matching value between the access principal role and the business permissions. Match the security level of the access environment to the specified value. This is a value used to match access time with the compliance requirements of the business scenario. , , , These are the weighting coefficients corresponding to identity attributes, business permissions, access environment, and access time, respectively, and they satisfy the following conditions: + + + =1. When the calculated permission matching metric value is higher than the preset matching threshold, the access request is deemed compliant, and the access subject is granted the corresponding level of data access permission and decryption permission. When the permission matching metric value is lower than the preset matching threshold, the access request is directly rejected, and auditing and early warning of abnormal access behavior are triggered at the same time.
[0030] This invention also includes reversible control and data restoration steps for desensitization processing. Specifically, for desensitization processing requirements in high-level business scenarios, two processing modes are set: reversible desensitization and irreversible desensitization. In the irreversible desensitization mode, irreversible generalization, nullification, and feature perturbation processing are directly performed on privacy features. After processing, the corresponding original privacy feature data is destroyed simultaneously. In the reversible desensitization mode, reversible replacement and masking processing are performed on privacy features. At the same time, a unique mapping relationship table between the original privacy features and the desensitized features is established. The mapping relationship table is stored with high-strength encryption using a modal working key. Only the access subject with the highest level of permission can obtain the decryption permission of the mapping relationship table after completing full-dimensional identity verification and multi-level operation approval, thus completing the accurate restoration of the desensitized data. The entire restoration operation process is logged and audited in real time. After the operation is completed, the mapping relationship table is automatically encrypted again and the permission is locked.
[0031] This invention also includes a full-process operation behavior audit and abnormal risk warning step. Specifically, it involves the full-process operation of data collection, data splitting, feature extraction, de-identification, encryption, key management, permission verification, data access, and data restoration. It executes full-dimensional log recording of the operation subject, operation time, operation content, operation environment, and operation results. All audit logs are stored in an immutable chain, and log integrity is verified using the national cryptographic SM3 hash algorithm. Simultaneously, a machine learning-based abnormal behavior identification model is constructed to perform real-time identification and risk level determination of high-frequency repeated access, cross-permission unauthorized access, unauthorized de-identification rule modification, unauthorized key management operations, and abnormal access from different locations. For abnormal operation behaviors determined to be high-risk, a coordinated response is immediately triggered, including operation blocking, account permission locking, and pushing warning information to the administrator. Abnormal behavior information is also synchronously recorded in the audit logs, achieving traceability, auditability, and controllability of all operation behaviors.
[0032] This invention also includes a usability verification and optimization step for the de-identified multimodal data. Specifically, for the multimodal dataset after de-identification and encryption, a multi-dimensional data usability verification is performed. For text data, the semantic integrity and consistency of business statistical characteristics of the de-identified text are verified. For image data, the integrity of the non-privacy areas of the de-identified image and its usability for business analysis are verified. For audio data, the intelligibility and semantic integrity of the non-sensitive content of the de-identified audio are verified. For video data, the continuity of the video frame and the integrity of the non-sensitive content are verified. When the verification result does not meet the preset usability threshold, the processing parameters of the corresponding de-identification rule are automatically adjusted. Under the premise of maintaining the privacy protection strength unchanged, the de-identification process is re-executed until the verification result meets the usability requirements. At the same time, the optimized de-identification rule is synchronously updated to the multi-dimensional privacy data feature library.
[0033] This invention also provides a computer-readable storage medium storing a multimodal encrypted big data privacy desensitization protection program. When executed by a processor, the program can implement the aforementioned multimodal encrypted big data privacy desensitization protection method. The method includes: acquiring, splitting, and preprocessing a multimodal big data dataset; constructing a multi-dimensional privacy data feature library and completing the annotation and hierarchical classification of privacy features; generating differentiated desensitization rules adapted to the characteristics of each modality of data; constructing a multimodal linked encryption key system based on the national cryptographic encryption algorithm system; performing hierarchical desensitization processing on privacy feature regions and layered encryption on the desensitized data; constructing an attribute-based access control system and logging and auditing the entire process.
[0034] The specific embodiments of the present invention are further illustrated below: Example 1: The application scenario of this example is a municipal government service integrated big data platform. The platform gathers multimodal data generated throughout the entire process of personal government affairs and business license processing, covering four core data types: personal identity information text, certificate scan images, government consultation audio, and remote service verification video, covering all the basic modal data units described in this invention.
[0035] Before implementation, complete the platform deployment preparation work, and set up corresponding data processing nodes, hardware encryption machines, access control nodes and audit log storage nodes. The hardware encryption machines are used for offline storage and management of core keys. All nodes are connected to the government intranet to perform network isolation and boundary protection.
[0036] First, the platform acquires a multimodal dataset of government services to be processed. The dataset undergoes full data type identification and structured splitting, resulting in four basic data modalities: text, image, audio, and video, based on data storage format and content attributes. Standardization conversion is then performed on each modal: text data is converted to UTF-8 encoding, image data to standard bitmap format with fixed resolution, audio data to mono with a fixed sampling rate, and video data to standard encoding format with a fixed frame rate. Simultaneously, invalid data cleaning is performed, removing corrupted, empty, or redundant data, thus completing the preprocessing of the multimodal data.
[0037] A multi-dimensional privacy data feature library for government service scenarios is constructed. Based on the business attributes of government service data, user identity features, behavioral trajectory features, location information features, biometric features, and business-sensitive features are extracted from various modalities. User identity features include name, ID card number, mobile phone number, bank card number, and unified social credit code; behavioral trajectory features include service time, service window, and processing records; location information features include service location, IP address, and permanent address; biometric features include facial image features and voiceprint features; and business-sensitive features include enterprise business information, personal real estate information, and social security and medical insurance information. All extracted privacy features are standardized, labeled, and categorized, establishing a mapping relationship between privacy features and anonymization levels, and are simultaneously entered into the multi-dimensional privacy data feature library.
[0038] For each preprocessed modal data unit, feature enhancement and precise privacy feature recognition are performed accordingly. For text data, word segmentation and named entity recognition are performed to extract various privacy entity features. For image data, target region segmentation and optical character recognition are performed to extract facial features and document text information features. For audio data, speech-to-text processing and voiceprint feature extraction are performed to extract privacy features of the audio content and voiceprint biometric features. For video data, keyframe extraction and inter-frame correlation analysis are performed, simultaneously extracting image and audio privacy features. This process achieves full coverage extraction and precise localization of privacy features across all modalities. All extracted privacy features are then deduplicated and association relationships are constructed to clarify the privacy feature mapping relationships of the same entity across different modalities.
[0039] For each extracted privacy feature, a quantitative calculation of the privacy risk value is performed from three core dimensions: sensitivity level, diffusion range, and impact dimension. Based on the calculated privacy risk quantification value, the privacy feature is divided into four levels: low risk, medium risk, high risk, and extremely high risk, and four de-identification levels are generated accordingly, providing a quantitative numerical basis for the generation of differentiated de-identification rules. At the same time, the privacy risk quantification value and the corresponding de-identification level are entered into the multi-dimensional privacy data feature library.
[0040] Based on the attribute features and corresponding privacy levels of the split modal data units, differentiated desensitization rules adapted to the characteristics of each modal data are generated. For text data, four desensitization methods are set according to the desensitization level of privacy features: replacement, masking, generalization, and emptying. For image data, four desensitization methods are set according to the localization results of privacy feature regions: pixelation, Gaussian blurring, feature replacement, and region cropping. For audio data, four desensitization methods are set according to the localization results of privacy features: voice changing, sensitive content muting, voiceprint feature perturbation, and content replacement. For video data, four desensitization methods are set according to the privacy feature localization results of inter-frame correlation: dynamic face blurring, sensitive audio muting, subtitle content masking, and trajectory feature generalization. Processing parameters corresponding to the desensitization level are set for each desensitization method, so that different levels of desensitization processing meet the privacy protection and data availability requirements of the corresponding scenarios. The generated desensitization rules are uniquely bound to the corresponding modal data and privacy feature level, and are synchronously entered into a multi-dimensional privacy data feature library.
[0041] A multimodal linked encryption key system is constructed based on the national cryptographic algorithm framework. A root key pair is generated using the SM2 asymmetric encryption algorithm, consisting of a root public key and a root private key. The root private key is stored offline in a hardware encryption device for storage and management, while the root public key is used for encryption protection of upper-layer working keys. Based on the SM4 symmetric encryption algorithm, a corresponding modal working key is generated for each type of modal data, a corresponding task working key is generated for each independent de-identification processing task, and a corresponding user working key is generated for each platform access subject. All working keys are encrypted and stored using the root public key. A unique binding relationship is established between the working key and its corresponding modal data, de-identification task, and access subject. The entire process of key generation, distribution, updating, and destruction is logged and verifiable. Only subjects with key management permissions can perform full lifecycle management operations on the keys. Working keys are automatically updated according to a preset time period, and the updated key synchronously performs re-encryption processing on the corresponding encrypted data.
[0042] To address the needs of different business scenarios in government services, two processing modes are set up: reversible and irreversible desensitization. For government data publicly available to the public, the irreversible desensitization mode is used, directly performing irreversible generalization, nullification, and feature perturbation on privacy features. After processing, the corresponding original privacy feature data is destroyed simultaneously. For internal government approval and review scenarios, the reversible desensitization mode is used, performing reversible replacement and masking on privacy features. A unique mapping table between the original privacy features and the desensitized features is established, and this mapping table is stored with high-strength encryption using a modal working key. Only access subjects with the highest level of privileges can obtain decryption rights to the mapping table after completing full-dimensional identity verification and multi-level operation approval, enabling accurate restoration of the desensitized data. The entire restoration process is logged and audited in real time, and after the operation is completed, the mapping table is automatically re-encrypted and access is locked.
[0043] Based on the generated differentiated de-identification rules, precise location and corresponding level of de-identification processing are performed on the privacy feature regions in each modal data unit. Simultaneously, based on a multimodal linkage encryption key system, layered encryption processing is performed on the de-identified modal data, de-identification rule mapping table, and privacy feature classification table to generate an encrypted de-identified multimodal dataset. For the de-identified and encrypted multimodal dataset, multi-dimensional data usability verification is performed. For text data, the semantic integrity and consistency of business statistical characteristics of the de-identified text are verified. For image data, the integrity of non-privacy regions of the de-identified image and its usability for business analysis are verified. For audio data, the intelligibility and semantic integrity of the non-sensitive content of the de-identified audio are verified. For video data, the continuity of the video frame and the integrity of the non-sensitive content are verified. When the verification result does not meet the preset usability threshold, the processing parameters of the corresponding de-identification rule are automatically adjusted. While maintaining the same level of privacy protection, the de-identification process is re-executed until the verification result meets the usability requirements. Simultaneously, the optimized de-identification rules are updated to the multi-dimensional privacy data feature library.
[0044] An attribute-based access control system is constructed, setting multi-dimensional access permission grading rules. When an access subject initiates a data access request, its identity attributes, role attributes, business permission attributes, access environment attributes, and access time attributes are first collected to construct a multi-dimensional attribute set for the access subject. This multi-dimensional attribute set is then matched against the preset access permission grading rules to calculate the access request's permission matching degree. When the calculated permission matching metric value is higher than the preset matching threshold, the access request is deemed compliant, and the access subject is granted the corresponding level of data access permission and decryption permission. When the permission matching metric value is lower than the preset matching threshold, the access request is directly rejected, and auditing and early warning of abnormal access behavior are triggered simultaneously.
[0045] The system performs comprehensive logging of the entire data acquisition, data splitting, feature extraction, de-identification, encryption, key management, permission verification, data access, and data restoration process. This includes recording the operation subject, time, content, environment, and results across all dimensions. All audit logs are stored in an immutable chain, and log integrity is verified using the national cryptographic SM3 hash algorithm. Simultaneously, a machine learning-based abnormal behavior identification model is built to identify and assess the risk level of high-frequency repeated access, cross-permission unauthorized access, unauthorized modification of de-identification rules, unauthorized key management operations, and abnormal access from different locations in real time. For abnormal operations deemed high-risk, the system immediately triggers a coordinated response, including operation blocking, account permission locking, and notification of alerts to administrators. The abnormal behavior information is also synchronously recorded in the audit logs, completing a closed-loop management system for multimodal big data privacy de-identification protection.
[0046] Table 1: Comparison of Privacy Protection and Data Availability Performance of Different Methods in Government Service Scenarios The data in Table 1 comes from parallel test results of the same batch of multimodal datasets in the government service scenario of this embodiment. All tests were conducted under the same operating environment and data. The data shows that the method of this invention significantly outperforms traditional single-modal desensitization methods in three core indicators: privacy feature recognition rate of four types of data, completeness of full-modal desensitization, and data availability retention rate after desensitization. This invention solves the problem of insufficient privacy recognition capability of traditional methods for unstructured data through a multimodal associated privacy feature recognition system. Through hierarchical matching of differentiated desensitization rules, it achieves a balance between privacy protection strength and data availability, fully adapting to the multimodal data privacy protection needs of government service scenarios.
[0047] Example 2: The application scenario of this example is a regional medical and health big data platform. The platform gathers multimodal data of the entire clinical diagnosis and treatment process of medical institutions within the jurisdiction, covering five core data types: electronic medical record text, medical examination images, doctor-patient consultation audio, surgical teaching videos, and remote consultation videos, which fully cover the four basic modal data units described in this invention.
[0048] Before implementation, platform deployment preparations were completed, including building a corresponding data processing cluster, hardware encryption machine, access control server, and audit log storage array. The hardware encryption machine was used for offline secure storage of core keys. All devices were connected to a dedicated medical network, implementing strict network hierarchical protection and data isolation.
[0049] First, the platform acquires a large dataset of multimodal medical and health data to be processed. The dataset undergoes full data type identification and structured splitting, resulting in four basic data modalities: text, image, audio, and video, based on data storage format and clinical business attributes. Standardized format conversion is then performed on each modal data segment. Text-based electronic medical records are converted to a standard encoding format, medical imaging data to a standard medical digital imaging format, consultation audio data to a standard audio format with fixed sampling parameters, and surgical and consultation video data to a standard encoding format with fixed playback parameters. Simultaneously, invalid data cleaning is performed, removing corrupted, missing, and redundant data, thus completing the preprocessing of the multimodal medical data.
[0050] A multi-dimensional privacy data feature library for healthcare scenarios is constructed. Based on the business attributes and privacy protection requirements of medical data, user identity features, treatment behavior trajectory features, location information features, biometric features, and business-sensitive features are extracted from various modalities. User identity features include patient name, ID number, medical insurance card number, medical card number, and contact information. Treatment behavior trajectory features include consultation time, department visited, and treatment process flow records. Location information features include the medical institution visited and permanent address. Biometric features include patient facial features and voiceprint features. Business-sensitive features include patient medical history, diagnosis results, examination reports, surgical records, and medical orders. All extracted privacy features are standardized, labeled, and categorized, establishing a mapping relationship between privacy features and anonymization levels, and are simultaneously entered into the multi-dimensional privacy data feature library.
[0051] For each preprocessed modal data unit, feature enhancement and precise privacy feature recognition are performed accordingly. For text-based electronic medical record data, word segmentation and medical entity naming recognition are performed to extract various privacy entity features from the text. For medical image data, target region segmentation and optical character recognition are performed to extract patient personal information features and privacy annotations from the images. For consultation audio data, speech-to-text processing and voiceprint feature extraction are performed to extract privacy features of the consultation content and voiceprint features of patients and medical staff from the audio. For video data, keyframe extraction and inter-frame correlation analysis are performed, simultaneously extracting facial privacy features, subtitle privacy information, and audio privacy features from the video. This process achieves full coverage extraction and precise localization of privacy features across all modalities. All extracted privacy features are deduplicated and association relationships are constructed to clarify the privacy feature mapping relationships of the same patient across different modalities.
[0052] For each extracted privacy feature, a quantitative calculation of the privacy risk value is performed from three core dimensions: sensitivity level, diffusion range, and impact dimension. Based on the calculated privacy risk quantification value, the privacy feature is divided into four levels: low risk, medium risk, high risk, and extremely high risk, and four de-identification levels are generated accordingly, providing a quantitative numerical basis for the generation of differentiated de-identification rules. At the same time, the privacy risk quantification value and the corresponding de-identification level are entered into the multi-dimensional privacy data feature library.
[0053] Based on the attribute features and corresponding privacy levels of the decomposed modal data units, differentiated desensitization rules are generated to adapt to the characteristics of various modal data in medical scenarios. For text-based medical record data, four desensitization methods are set based on the desensitization level of privacy features: replacement, masking, generalization, and emptying. For medical image data, four desensitization methods are set based on the location results of privacy feature regions: privacy information region masking, feature replacement, and region cropping. For consultation audio data, three desensitization methods are set based on the location results of privacy features: sensitive content muting, voiceprint feature perturbation, and content replacement. For video data, three desensitization methods are set based on the privacy feature location results of inter-frame correlation: dynamic face blurring, sensitive audio muting, and patient information subtitle masking. Processing parameters corresponding to the desensitization level are set for each desensitization method to ensure that different levels of desensitization meet the privacy protection and data application requirements of medical scenarios. The generated desensitization rules are uniquely bound to the corresponding modal data and privacy feature level, and are simultaneously entered into a multi-dimensional privacy data feature library.
[0054] A multimodal linked encryption key system is constructed based on the national cryptographic algorithm framework. A root key pair is generated using the SM2 asymmetric encryption algorithm, consisting of a root public key and a root private key. The root private key is stored offline in a hardware encryption device for storage and management, while the root public key is used for encryption protection of upper-layer working keys. Based on the SM4 symmetric encryption algorithm, a corresponding modal working key is generated for each type of modal data, a corresponding task working key is generated for each independent de-identification processing task, and a corresponding user working key is generated for each platform access subject. All working keys are encrypted and stored using the root public key. A unique binding relationship is established between the working key and its corresponding modal data, de-identification task, and access subject. The entire process of key generation, distribution, updating, and destruction is logged and verifiable. Only subjects with key management permissions can perform full lifecycle management operations on the keys. Working keys are automatically updated according to a preset time period, and the updated key synchronously performs re-encryption processing on the corresponding encrypted data.
[0055] To address the needs of different business scenarios in healthcare, two processing modes are set up: reversible and irreversible desensitization. For medical data used in medical research and teaching, the irreversible desensitization mode is used, directly performing irreversible generalization, nullification, and feature perturbation on privacy features. After processing, the corresponding original privacy feature data is destroyed simultaneously, eliminating the identifiability of the patient's personal information. For clinical follow-up visits and multidisciplinary consultations, the reversible desensitization mode is used, performing reversible replacement and masking on privacy features. A unique mapping table between the original privacy features and the desensitized features is established, and this mapping table is stored with high-strength encryption using a modal working key. Only clinical medical staff with the highest level of access can obtain decryption rights to the mapping table after completing full-dimensional identity verification and patient authorization approval, enabling accurate restoration of the desensitized data. The entire restoration operation is logged and audited in real time, and after the operation is completed, the mapping table is automatically re-encrypted and access is locked.
[0056] Based on the generated differentiated anonymization rules, precise location and corresponding level of anonymization processing are performed on the privacy feature regions in each modal data unit. Simultaneously, based on a multimodal linkage encryption key system, layered encryption processing is performed on the anonymized modal data, the anonymization rule mapping table, and the privacy feature classification table to generate an encrypted anonymized multimodal dataset. For the anonymized and encrypted multimodal dataset, multi-dimensional data usability verification is performed. For text-based medical record data, the completeness of the diagnostic semantics and consistency with clinical statistical characteristics of the anonymized text are verified. For medical image data, the completeness of the diagnostic region and clinical analysis usability of the anonymized image are verified. For audio data, the intelligibility and semantic completeness of the consultation content of the anonymized audio are verified. For video data, the continuity of the diagnostic footage and the completeness of the teaching content of the anonymized video are verified. When the verification result does not meet the preset usability threshold, the processing parameters of the corresponding anonymization rule are automatically adjusted. While maintaining the same level of privacy protection, the anonymization process is re-executed until the verification result meets the usability requirements. Simultaneously, the optimized anonymization rules are updated to the multi-dimensional privacy data feature library.
[0057] An attribute-based access control system is constructed, setting multi-dimensional access permission grading rules. When an access subject initiates a data access request, its identity attributes, professional qualification attributes, business permission attributes, access environment attributes, and access time attributes are first collected to construct a multi-dimensional attribute set for the access subject. This multi-dimensional attribute set is then matched against the preset access permission grading rules to calculate the access request's permission matching degree. When the calculated permission matching metric value is higher than the preset matching threshold, the access request is deemed compliant, and the access subject is granted the corresponding level of data access permission and decryption permission. When the permission matching metric value is lower than the preset matching threshold, the access request is directly rejected, and auditing and early warning of abnormal access behavior are triggered simultaneously.
[0058] The system manages the entire process of data collection, data splitting, feature extraction, desensitization, encryption, key management, access control, and data restoration. It records all aspects of the operation, including the operator, time, content, environment, and results. All audit logs are stored in an immutable chain, and log integrity is verified using the national cryptographic SM3 hash algorithm. Simultaneously, a machine learning-based abnormal behavior identification model is built to identify and assess the risk level of high-frequency repeated access, cross-authority access, unauthorized modification of desensitization rules, unauthorized key management operations, and abnormal access outside of working hours. For high-risk abnormal behaviors, it immediately triggers a coordinated response, including operation blocking, account permission locking, and notification of alerts to administrators. The abnormal behavior information is also synchronously recorded in the audit logs, completing a closed-loop management system for the entire process of multimodal medical big data privacy desensitization protection.
[0059] Table 2: Comparison of Safety Performance of Different Methods in Medical and Health Scenarios The data in Table 2 are derived from the platform's operational data statistics for three consecutive months in the medical and health scenario of this embodiment. All statistical indicators were set in accordance with the requirements of relevant medical data security protection specifications. The data shows that the method of this invention significantly outperforms traditional data protection methods in six core security indicators: unauthorized access blocking, abnormal behavior identification, key management compliance, audit log protection, full-process closed-loop control, and privacy leakage risk prevention. This invention constructs a complete privacy protection closed-loop system through a layered key management system, refined attribute access control, and a full-process chain audit mechanism, effectively meeting the high-level security protection needs of medical and health data.
[0060] refer to Figure 1This diagram illustrates the complete business loop of the multimodal big data privacy de-identification protection of this invention. The process begins with the acquisition and splitting of the original multimodal dataset. Through standardized processing of four modalities—text, image, audio, and video—it enters the privacy feature extraction and hierarchical classification stage. Subsequently, the system constructs a linked key system based on national cryptographic algorithms and generates differentiated de-identification rules. Core processing steps include precise location of privacy regions, de-identification processing, and layered encryption. Finally, by constructing an attribute-based access control system and a full-process audit log, end-to-end privacy protection management is achieved from data input to controlled access.
[0061] Reference Figure 2 This diagram details the feature extraction paths for different modalities of data. The system performs named entity recognition to extract identity information from text; object segmentation and character recognition to extract facial and document features from images; speech-to-text conversion and voiceprint extraction from audio; and keyframe extraction and inter-frame correlation analysis from video. Through cross-correlation mapping of multimodal features, the system can identify the distribution of the same subject across different modalities of data. After deduplication, the system enters the risk quantification value into the feature library, providing accurate spatial positioning and attribute support for subsequent differentiated desensitization.
[0062] Reference Figure 3 This diagram illustrates the secure key architecture based on Chinese national cryptographic algorithms. The system employs a hierarchical management model: the top layer uses a hardware encryption machine to offline store the root key pair based on the SM2 algorithm, which is used to protect the lower-level keys; the middle layer generates modal working keys, task working keys, and user working keys based on the SM4 algorithm. The system establishes a unique binding relationship between keys and data, tasks, and subjects, and implements full lifecycle management. Through preset periodic automatic updates and re-encryption mechanisms, high-strength security of multimodal data is ensured during storage and transfer.
[0063] Reference Figure 4 This diagram illustrates the adaptation logic and feedback optimization mechanism of the de-identification rules. The system employs targeted processing methods such as masking, Gaussian blurring, voice changing, and keyframe occlusion, tailored to the physical characteristics of text, images, audio, and video, supporting both reversible and irreversible modes. After processing, the system initiates a usability verification module to evaluate the de-identified data's performance in dimensions such as semantic integrity, business analysis usability, and visual continuity. If the threshold is not met, the processing parameters are automatically adjusted, and the process is re-executed while maintaining the protection strength, ensuring a balance between privacy protection and data value.
[0064] refer to Figure 5This diagram illustrates the system's access control and security auditing mechanisms. When a subject initiates a request, the system collects multi-dimensional attributes such as identity, role, environment, and time, and calculates a metric value for permission matching. Decryption permission is granted only when the matching degree is higher than a threshold; otherwise, it is denied and an alert is issued. Simultaneously, the auditing module uses the SM3 algorithm to ensure log immutability and builds an abnormal behavior model based on machine learning. Through real-time monitoring of high-frequency access and unauthorized operations, the system can automatically trigger blocking and risk-linked handling, ensuring the compliance and traceability of the entire de-identification protection system.
[0065] The above are merely preferred embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.
Claims
1. A multi-modal encrypted big data privacy desensitization protection method, characterized in that, Includes the following steps: A multimodal dataset to be processed is obtained, and the dataset is subjected to data type identification and structured splitting to obtain four basic modal data units: text, image, audio, and video. Standardized format conversion and invalid data cleaning are then performed on each modal data unit. Construct a multi-dimensional privacy data feature library, extract user identity features, behavioral trajectory features, location information features, biometric features and business-sensitive features from various modal data units, standardize and classify privacy features, and establish a mapping relationship between privacy features and desensitization levels; Based on the attribute characteristics and corresponding privacy levels of each modal data unit, differentiated desensitization rules adapted to the characteristics of each modal data are generated; at the same time, a multimodal linkage encryption key system is constructed based on the national cryptographic encryption algorithm system to generate encryption keys and decryption keys that correspond one-to-one with each modal data. According to the differentiated desensitization rules, the privacy feature regions in each modal data unit are located and corresponding levels of desensitization processing are performed. Based on the aforementioned multimodal linkage encryption key system, the anonymized data of each modality, the anonymization rule mapping table, and the privacy feature classification table are encrypted in layers to obtain the encrypted anonymized multimodal dataset. Construct an attribute-based access control system, set multi-dimensional access control hierarchical rules, verify the identity attributes, access scenarios and business permissions of the access subject, and match the corresponding data decryption and access permissions; log and audit the operations of data access, de-identification processing and key management.
2. The multi-modal encrypted big data privacy desensitization protection method of claim 1, characterized in that, It also includes preprocessing and precise identification of privacy features for multimodal big data sets. Specifically, for each modal data unit after format conversion and invalid data cleaning, feature enhancement processing of the corresponding modality is performed; for text data, word segmentation and named entity recognition are performed to extract privacy entity features. For image data, target region segmentation and optical character recognition are performed to extract image features; for audio data, speech-to-text processing and voiceprint feature extraction are performed; for video data, keyframe extraction and inter-frame correlation analysis are performed, simultaneously extracting image privacy features and audio privacy features from the video, and deduplication and correlation construction are performed on all extracted privacy features.
3. The multi-modal encrypted big data privacy desensitization protection method of claim 1, wherein, It also includes quantitative calculation steps for privacy data classification and grading. Specifically, for each extracted privacy feature, a quantitative calculation of the privacy risk value is performed from three core dimensions: sensitivity level, scope of diffusion, and impact dimension. The calculation method is as follows: ; wherein, is a privacy risk quantification value of a single privacy feature, is an inherent sensitivity level quantification value of a privacy feature, is a diffusible range quantification value of a privacy feature, is an impact dimension quantification value after a privacy feature is leaked, , , are weight coefficients corresponding to the sensitivity level, the diffusible range, and the impact dimension respectively, and satisfy + + = 1, based on the calculated privacy risk quantification value, the privacy feature is divided into four levels of low risk, medium risk, high risk, and extremely high risk, and corresponding first, second, third, and fourth desensitization levels are generated.
4. The multi-modal encrypted big data privacy desensitization protection method of claim 1, wherein, It also includes a layered construction step for a multimodal linkage encryption key system, specifically: generating a root key pair based on the national cryptographic SM2 asymmetric encryption algorithm, wherein the root key pair includes a root public key and a root private key, the root private key is stored and managed offline by a hardware encryption machine, and the root public key is used for the encryption protection of upper-layer working keys; generating a corresponding modal working key for each type of modal data, a corresponding task working key for each independent de-identification processing task, and a corresponding user working key for each access subject based on the national cryptographic SM4 symmetric encryption algorithm; all working keys are encrypted and stored through the root public key, and a unique binding relationship is established between the working key and the corresponding modal data, de-identification task, and access subject; the entire process of key generation, distribution, update, and destruction is subject to operation recording and permission verification.
5. The multi-modal encrypted big data privacy desensitization protection method of claim 1, wherein, It also includes a differentiated desensitization rule generation step adapted to the characteristics of multimodal data. Specifically, for text data, based on the desensitization level of privacy features, four desensitization processing methods are set: replacement, masking, generalization, and emptying. For image data, based on the localization results of privacy feature regions, four desensitization processing methods are set: pixelation, Gaussian blurring, feature replacement, and region cropping. For audio data, based on the localization results of privacy features, four desensitization processing methods are set: voice changing, sensitive content muting, voiceprint feature perturbation, and content replacement. For video data, based on the privacy feature localization results of inter-frame correlation, four desensitization processing methods are set: dynamic face blurring, sensitive audio muting, subtitle content masking, and trajectory feature generalization.
6. The multi-modal encrypted big data privacy desensitization protection method of claim 1, wherein, It also includes an attribute-based access permission precise matching and verification step, specifically: when the accessing subject initiates a data access request, the attribute information of the accessing subject is obtained, and a multi-dimensional attribute set is constructed; the multi-dimensional attribute set is matched with a preset access permission level rule, and the permission matching degree is calculated, the calculation method being: ; Wherein, is the access request permission matching quantization value, is the compliance matching value of the access subject identity attribute, is the matching value of the access subject role and the business permission, is the security level matching value of the access environment, is the compliance matching value of the access time and the business scenario, , , , are the weight coefficients corresponding to the identity attribute, the business permission, the access environment and the access time respectively, and satisfy + + + =1.
7. The multi-modal encrypted big data privacy desensitization protection method of claim 1, wherein, It also includes reversible control and data restoration steps for de-identification processing, specifically: setting two processing modes for business scenarios, reversible de-identification and irreversible de-identification; performing generalization, emptying or feature perturbation processing on privacy features in the irreversible de-identification mode, and destroying the corresponding original privacy feature data; performing replacement or masking processing on privacy features in the reversible de-identification mode, establishing a mapping relationship table between the original privacy features and the de-identified features, and encrypting and storing the mapping relationship table using a modal working key; verifying the identity and approving the operation of access subjects with corresponding permissions, granting decryption permission to the mapping relationship table after approval, and performing de-identified data restoration. The restore operation is logged and audited in real time, and the mapping table is encrypted and access is locked after the operation is completed.
8. The multi-modal encrypted big data privacy desensitization protection method of claim 1, wherein, It also includes full-process operation behavior auditing and abnormal risk warning steps, specifically: logging the entire data processing operation, storing the audit logs in an immutable manner, and verifying the log integrity through the national cryptographic SM3 hash algorithm; Construct a machine learning-based abnormal behavior identification model to identify and determine the risk level of high-frequency repeated access, cross-permission access, unauthorized modification of de-identification rules, unauthorized key management, and abnormal access behavior from different locations; For high-risk abnormal operations, implement operation blocking, account permission locking, and early warning information push, and record abnormal behavior information in the audit log.
9. The multi-modal encrypted big data privacy desensitization protection method of claim 1, wherein, It also includes usability verification and optimization steps for de-identified multimodal data, specifically: performing multi-dimensional data usability verification on the multimodal dataset after de-identification and encryption; for text data, verifying the semantic integrity and consistency of business statistical characteristics of the de-identified text; for image data, verifying the integrity of the non-privacy areas of the de-identified image and its usability for business analysis; and for audio data, verifying the intelligibility and semantic integrity of the non-sensitive audio content after de-identification. For video data, verify the continuity of the video footage and the integrity of non-sensitive content after anonymization. When the verification result does not meet the preset availability threshold, the processing parameters of the corresponding desensitization rule are automatically adjusted and the desensitization process is re-executed while maintaining the privacy protection strength, until the verification result meets the availability requirements.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a multimodal encrypted big data privacy desensitization protection program, which, when executed by a processor, implements the multimodal encrypted big data privacy desensitization protection method as described in any one of claims 1 to 9.