Private information isolation based bilateral recruitment matching method and system
Patent Information
- Application Number
- CN202610650129.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-12
- Publication Date
- 2026-08-28
AI Technical Summary
该类系统虽然能够提高搜索效率,但是求职方和招聘方之间仍需要大量人工沟通来确认隐藏条件是否匹配
[0035]This invention stores the private auxiliary information of both the job seeker and the recruiter separately through separate layers, preventing the intelligent agents of the job seeker and recruiter from accessing each other's private auxiliary information layers and thus reducing the risk of leakage of private auxiliary information during the recruitment matching process. Through structured parsing and quantitative mapping, the private auxiliary information is transformed into anonymized matching parameters, allowing it to participate in intelligent matching while preventing the original content of the private auxiliary information from entering the bilateral interactive data. Therefore, the system can improve the consistency between recruitment matching results and the true intentions of both parties without exposing the original content of the private auxiliary information. Through structured interaction between the two intelligent agents, the intelligent agents of the job seeker and the recruiter interact based on publicly available information and anonymized matching parameters, replacing a large amount of inefficient manual communication. The system generates interview confirmation trigger information when the bilateral intention judgment results meet preset confirmation conditions, reducing invalid communication that does not meet hidden constraints. By implementing desensitized output verification, cross-side access blocking records, and intelligent proxy access audit records, the system further restricts the entry of private auxiliary information and reversibly identifiable content into interactive output, and provides traceability data for abnormal call behavior, thereby improving the data security and controllability of the recruitment matching process.
Smart Images

Figure CN122656574A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of electronic digital data processing, data security, privacy protection, artificial intelligence, machine learning, and Internet data services. It further relates to a bilateral recruitment matching method and system based on private information isolation, de-identified matching parameter generation, field-level gated transcription, and bilateral intelligent agent structured interaction. Specifically, it is a bilateral recruitment matching method and system based on private information isolation. Background Technology
[0002] Online recruitment platforms typically match job seekers' publicly available information with employers' publicly available job postings. Job seekers' information usually includes work experience, educational background, skills tags, project experience, desired position, and desired location. Employers' job postings usually include job title, job responsibilities, job requirements, salary range, work location, and work style. Existing recruitment matching systems mostly use keyword matching, vector similarity matching, semantic model matching, or manual screening by employers to generate candidate recommendation lists or job recommendation lists.
[0003] While the aforementioned methods can establish matching relationships between publicly available information, they still have significant shortcomings. On the one hand, job seekers often possess confidential supplementary information that is unsuitable for public disclosure, such as minimum salary expectations, tolerance for overtime, commuting restrictions, work environment preferences, reasons for leaving previous jobs, non-compete agreements, and family arrangements. On the other hand, recruiters may also possess confidential supplementary information that is unsuitable for public disclosure, such as salary flexibility, team style preferences, implicit hiring restrictions, preferences for candidate stability, and the urgency of the position. This confidential supplementary information has a substantial impact on recruitment matching results, but existing systems typically cannot include this confidential supplementary information in the matching process while protecting its privacy.
[0004] On the other hand, existing intelligent recruitment assistants mostly operate from a one-sided perspective. For example, the system recommends candidates to recruiters or positions to job seekers. While such systems can improve search efficiency, a significant amount of human communication is still required between job seekers and recruiters to confirm whether hidden criteria match. When hidden criteria conflict, the system often only reveals the mismatch late in the communication process, resulting in ineffective communication, inefficient screening, and privacy risks. Furthermore, simply encrypting or anonymizing private information does not solve the problem of private information participating in the matching process. If private information is not involved in the calculation, the matching results are prone to deviating from the true intentions; if private information is included in the intelligent agent's interaction content in its original form, it may lead to the leakage of private information from either the job seeker or the recruiter.
[0005] Therefore, existing technologies require a recruitment matching process that allows job seekers' and recruiters' private auxiliary information to participate in intelligent matching inference in an isolated state, while ensuring that the interaction data does not expose the original content of the private auxiliary information. Summary of the Invention
[0006] The purpose of this invention is to provide a bilateral recruitment matching method and system with privacy information isolation to address the shortcomings of existing technologies. The aim is to enable the private auxiliary information of job seekers and recruiters to participate in intelligent matching reasoning in an isolated state, and to ensure that the interactive data does not expose the original content of the private auxiliary information.
[0007] A bilateral recruitment matching method that isolates private information includes the following steps:
[0008] Information Acquisition Steps: The recruitment matching server acquires publicly available job seeker information, private auxiliary information of job seekers, publicly available job postings from recruiters, and private auxiliary information of recruiters; Isolation Storage Steps: The recruitment matching server writes the private auxiliary information of job seekers into a private auxiliary information isolation layer, and also writes the private auxiliary information of recruiters into a private auxiliary information isolation layer; Proxy Configuration Steps: The recruitment matching server configures a smart proxy for job seekers based on their publicly available information, and configures a smart proxy for recruiters based on their publicly available job postings; Authorized Invocation Steps: After receiving a recruitment matching task, the recruitment matching server controls the smart proxy for job seekers to generate de-identified matching parameters from the private auxiliary information isolation layer for job seekers, and controls the smart proxy for recruiters to... The agent generates anonymized matching parameters for the recruiter from the recruiter's private auxiliary information isolation layer; Agent interaction steps: The recruitment matching server controls the job seeker's intelligent agent and the recruiter's intelligent agent to perform bilateral intelligent agent structured interaction based on the job seeker's publicly available information, the recruiter's publicly available job information, the job seeker's anonymized matching parameters, and the recruiter's anonymized matching parameters to obtain bilateral interaction data; Intention determination step: The recruitment matching server generates job seeker intention score and recruiter intention score based on the bilateral interaction data, and generates bilateral intention determination results based on the job seeker intention score and recruiter intention score; Confirmation trigger step: When the bilateral intention determination results meet preset confirmation conditions, the recruitment matching server generates interview confirmation trigger information.
[0009] In another alternative approach: the field-level gated transcription unit can be located within the recruitment matching server, situated between the internal inference context and the external interaction context. The internal inference context can be understood as the data space used by the recruitment matching server during matching calculations, storing both the job seeker's and recruiter's anonymized matching parameters. The external interaction context can be understood as the data space used by the job seeker's and recruiter's intelligent agents during bilateral intelligent agent structured interactions, generating bilateral interaction data. After generating the job seeker's and recruiter's anonymized matching parameters, the recruitment matching server does not allow direct copying of these parameters to the external interaction context. Instead, the recruitment matching server first inputs the job seeker's and recruiter's anonymized matching parameters into the field-level gated transcription unit. The field-level gated transcription unit performs field-level identification on each anonymized matching parameter, determining whether it belongs to the salary, location, work style, start date, team style, stability, or other preset types. The field-level gated transcription unit then converts the anonymized matching parameters into structured intention data that can be used for external interaction.
[0010] For example, the anonymized matching parameter for job seekers could indicate "low salary matching degree." The field-level gated transcription unit does not output the job seeker's minimum salary offer or the specific range corresponding to that offer. Instead, it transcribes it into structured intention data such as "insufficient salary intention matching degree" or "moderate salary intention matching degree." Similarly, the anonymized matching parameter for recruiters could indicate "insufficient actual salary space for recruiters." The field-level gated transcription unit does not output the recruiter's actual budget or its range. Instead, it transcribes it into structured intention data such as "insufficient salary space matching degree for recruiters." The inputs to the field-level gated transcription unit are the anonymized matching parameters for both job seekers and recruiters. The outputs are the structured intention data for both job seekers and recruiters. This structured intention data can enter the external interaction context and participate in bilateral intelligent agent structured interactions. When the job seeker's and recruiter's de-identified matching parameters are written to the external interaction context in their original field values, the recruitment matching server should refuse the write operation and return the rejection result to the field-level gated transcribing unit, causing the field-level gated transcribing unit to re-execute the transcribing process.
[0011] This processing method allows both job seeker and employer-side anonymized matching parameters to participate in internal inference, but the external interaction context only receives structured intent data after field-level gating. This process prevents the original values of the anonymized matching parameter fields from entering the bilateral interaction data, thereby reducing the risk of reverse identification of private auxiliary information through the bilateral interaction data.
[0012] In another alternative approach: the transcription rule table can be pre-stored in the recruitment matching server, or it can be loaded by the recruitment matching server at the start of each recruitment matching task. The transcription rule table specifies the output granularity that different anonymized matching parameters should adopt before entering the external interaction context. The transcription rule table includes at least the anonymized matching parameter type, allowed output granularity, prohibited output granularity, and corresponding reason category identifier. The anonymized matching parameter type identifies which matching dimension the parameter to be transcribed belongs to. For example, the anonymized matching parameter type may include salary matching parameter type, commuting matching parameter type, work style matching parameter type, arrival time matching parameter type, team style matching parameter type, and stability matching parameter type. The allowed output granularity specifies the expression level that can enter the external interaction context. For example, the allowed output granularity can be three levels of matching degree: "high," "medium," and "low," or three states: "matched," "pending confirmation," and "not matched." The prohibited output granularity specifies the expression level that cannot enter the external interaction context. For example, the prohibited output granularity may include specific salary values, specific budget values, specific commuting addresses, specific reasons for leaving the previous job, specific non-compete clauses, etc. The corresponding reason category identifier is used to replace the original output content when the prohibited output granularity is matched. When the field-level gated transcription unit performs transcription processing, it first reads the desensitization matching parameter type of the desensitization matching parameter to be transcribed, and then looks up the corresponding allowed output granularity and prohibited output granularity from the transcription rule table. If the output content belongs to the allowed output granularity, the field-level gated transcription unit generates the corresponding structured intention data and writes it into the external interaction context. If the output content belongs to the prohibited output granularity, the field-level gated transcription unit does not generate the original granularity content, but instead generates the corresponding reason category identifier and writes the reason category identifier into the external interaction context.
[0013] For example, the allowed output granularity for the salary matching parameter type can be "high salary matching degree, medium salary matching degree, low salary matching degree," while the prohibited output granularity can be "the job seeker's minimum salary requirement and the recruiter's maximum budget requirement." When the field-level gated transcription unit determines that the output content will reveal the specific salary value, it replaces the output content with "salary condition reason category identifier." This reason category identifier can continue to participate in subsequent intention determination, but it will not reveal the specific salary value. As another example, the allowed output granularity for the commuting matching parameter type can be "commuting condition matched, commuting condition pending confirmation, commuting condition mismatch," while the prohibited output granularity can be "job seeker's home address, specific commuting route, minimum specific commuting time." When the field-level gated transcription unit determines that the output content may indirectly locate the job seeker's residence or commuting restrictions, it outputs "location condition reason category identifier" instead of the specific address or commuting route.
[0014] By using a transcription rule table, field-level gated transcription units no longer simply delete sensitive content, but instead perform controlled transcription based on the desensitization matching parameter type and output granularity. This approach preserves the reason categories required for structured interactions while preventing external interaction contexts from accessing prohibited output granular content.
[0015] In another alternative approach, a gating rollback step is used to handle the risk of reverse inference that may still exist after field-level gating transcription. After the proxy interaction step, the recruitment matching server performs leakage verification on the external interaction context. The goal of leakage verification is not to re-check whether the original private auxiliary information appears, but rather to check whether the structured intent data already written into the external interaction context can be used to infer the job seeker's or recruiter's anonymized matching parameters. Pre-configured reverse inference conditions can be pre-configured by the recruitment matching server. These pre-configured reverse inference conditions may include the following scenarios: a one-to-one correspondence exists between the structured intent data and a single anonymized matching parameter; the structured intent data, combined with a small amount of publicly available information, can deduce the type of anonymized matching parameter; the numerical range contained in the structured intent data is too narrow, allowing the deonymized matching parameter version to be inferred; the structured intent data, combined with the reason category identifier, can locate the source dimension of the private auxiliary information. These pre-configured reverse inference conditions can be implemented through rule matching, similarity calculation, field mapping table verification, or combined field checks.
[0016] For example, if the external interaction context contains structured intent data stating "salary requirement below 15,000 yuan leads to mismatch," even without directly outputting the job seeker's minimum salary requirement, this content can still infer their minimum salary. When the recruitment matching server detects that this structured intent data meets the preset inference conditions, it removes the structured intent data and reverts it to a "salary requirement reason category identifier" through a field-level gating transcription unit. The reverted external interaction context no longer contains structured intent data from which specific values can be inferred. As another example, if the external interaction context contains content such as "candidate cannot join a company in the same industry due to non-compete restrictions," this content may inversely expose the non-compete restrictions in the job seeker's private supplementary information. After the recruitment matching server detects that this content meets the preset inference conditions, it removes the content and reverts it to either a "job availability reason category identifier" or a "compliance reason category identifier." The inputs to the gating revert step are the external interaction context, the job seeker's anonymized matching parameters, and the recruiter's anonymized matching parameters. The output of the gating revert step is the reverted external interaction context. Even after rollback, the external interaction context retains the cause category identifier, so subsequent intent determination steps can still identify a certain type of condition conflict. However, it cannot deduce the original value of the private parameter field, the type of the masked matching parameter, or the version identifier of the masked matching parameter from the external interaction context. This approach ensures that the leakage verification result is not simply deleted, but rather replaced by a field-level gated transcription unit, keeping the external interaction context usable while reducing the risk of reverse inference.
[0017] In another alternative approach: After generating the rollback external interaction context, the recruitment matching server regenerates both the job seeker's private constraint conflict vector and the recruiter's private constraint conflict vector. This regeneration process prevents the intention determination step from continuing to use the old conflict calculation results after the original structured intention data is withdrawn, thus avoiding inconsistencies between the bilateral intention determination results and the rollback external interaction context. The job seeker's private constraint conflict vector can represent the conflict between the job seeker's anonymized matching parameters and the recruiter's publicly available job information. Each conflict vector can include multiple dimensions, such as salary conflict dimension, location conflict dimension, work style conflict dimension, start date conflict dimension, team style conflict dimension, and stability conflict dimension. Each dimension can record the conflict state, conflict intensity, and conflict category. The conflict state can be either present or absent; the conflict intensity can be high, medium, or low; and the conflict category can be either a hard conflict category or a preference conflict category. When the gating rollback step reverts a structured intention data point to a cause category identifier, the recruitment matching server should use the reverted external interaction context as the new external interaction basis. For example, if the original external interaction context contained structured intention data that could be used to infer specific salary values, and this structured intention data was reverted to a salary condition cause category identifier, the recruitment matching server should regenerate the salary conflict dimension. During regeneration, the recruitment matching server no longer calculates the conflict intensity based on the revoked structured intention data, but instead recalculates the conflict intensity based on the cause category identifier and the desensitized matching parameters in the internal inference context. When recalculating the job seeker's intention score and the recruiter's intention score, the recruitment matching server can first read the regenerated job seeker's private constraint conflict vector and the recruiter's private constraint conflict vector, and then correct the job seeker's intention score and the recruiter's intention score respectively. If the reverted cause category identifier represents a hard conflict, the score correction will be larger; if the reverted cause category identifier represents a preference conflict, the score correction will be smaller. The score correction result should cover the old score result before the gating rollback.
[0018] This process creates a closed loop, involving gating rollback, conflict vector regeneration, and intention score recalculation. When the external interaction context is modified, the intention determination result is updated synchronously, preventing situations where the interaction output has been desensitized and rolled back, but the score is still generated based on the old sensitive expressions.
[0019] In another alternative approach: during the confirmation triggering step, if a reason category identifier exists in the external interaction context after rollback, the recruitment matching server does not directly ignore the reason category identifier, but instead uses it as the input for the confirmation trigger constraint. This ensures that sensitive expressions that have been rolled back do not lose their impact on the recruitment matching results. The reason category identifier can be pre-configured as a hard conflict category or a preference conflict category according to business attributes and conflict intensity. A hard conflict category indicates that if the conditions corresponding to the reason category are not met, neither party is suitable to continue into the interview confirmation process. For example, compliance condition reason category identifiers, non-compete reason category identifiers, infeasibility of employment reason category identifiers, and severe salary mismatch reason category identifiers can be configured as hard conflict categories. A preference conflict category indicates that although the conditions corresponding to the reason category are mismatched, it is still possible to determine whether to continue based on the scoring results. For example, work style preference reason category identifiers, team style preference reason category identifiers, and commuting comfort reason category identifiers can be configured as preference conflict categories. When a reason category identifier exists in the external interaction context after rollback, the recruitment matching server reads the category configuration corresponding to the reason category identifier. If the reason category identifier corresponds to a hard conflict category, the recruitment matching server generates a non-triggered interaction termination message. The non-triggered interaction termination message may include result markers such as "Matching conditions not met" or "Continuing communication is not recommended at this time," but it will not output the private original text that caused the termination, nor will it output the original values of the specific anonymized matching parameter fields. If the reason category marker corresponds to a preference conflict category, the recruitment matching server will not directly terminate the process, but will instead read the recalculated job seeker intention scores and recruiter intention scores. The recruitment matching server will generate a bilateral intention judgment result based on the recalculated job seeker intention scores and recruiter intention scores. If both parties' scores still meet the preset confirmation conditions, an interview confirmation trigger message can be generated; if both parties' scores do not meet the preset confirmation conditions, a non-triggered interaction termination message can be generated.
[0020] This approach ensures that the cause category identifier is not merely a de-identified replacement text, but rather a control input confirming the triggering step. Through this control logic, the system avoids the leakage of private causes while preserving the binding effect of privacy constraints on the final triggering result.
[0021] In another alternative approach: A gated transcription identifier ensures that the field-level gated transcription process can only be executed under the correct recruitment matching task, the correct interaction round, the correct anonymized matching parameter version, and the correct transcription rule table version. The recruitment matching server can generate an interaction round identifier at the start of each round of bilateral intelligent agent structured interaction. The interaction round identifier indicates which round of bilateral intelligent agent structured interaction is currently in progress. The anonymized matching parameter version identifier indicates the versions of the job seeker's and recruiter's anonymized matching parameters currently being used. The transcription rule table version identifier indicates the version of the transcription rule table currently used by the field-level gated transcription unit.
[0022] The recruitment matching server binds the interaction round identifier, the de-identified matching parameter version identifier, and the transcription rule table version identifier to generate a gated transcription identifier. The binding method can be implemented using string concatenation followed by hashing, message authentication codes, unique database indexes, or unique mapping tables within the task. After the gated transcription identifier is generated, before executing each transcription process, the field-level gated transcription unit first reads the interaction round identifier, the de-identified matching parameter version identifier, and the transcription rule table version identifier from the current recruitment matching task, and then performs a consistency check with the gated transcription identifier carried in the transcription request to be executed. If the gated transcription identifier matches the current recruitment matching task, it means that the de-identified matching parameters, the transcription rule table, and the interaction round to be transcribed belong to the same recruitment matching task, and the field-level gated transcription unit can continue to execute the transcription process. If the gated transcription identifier does not match the current recruitment matching task, it indicates that there may be cross-task reuse, cross-round reuse, expired de-identified matching parameter versions, or inconsistent transcription rule table versions. In this case, the field-level gated transcription unit refuses to transcribe the de-identified matching parameters in the internal inference context to the external interaction context.
[0023] For example, in the first round of interaction, a job matching task uses the first version of the transcription rule table to generate a gated transcription identifier. If the second round of interaction has updated to the second version of the transcription rule table, but the request to be transcribed still carries the gated transcription identifier corresponding to the first version of the transcription rule table, the field-level gated transcription unit should refuse to transcribe. As another example, if a job seeker's anonymized matching parameters have been updated after the task update, the old version of the anonymized matching parameters cannot continue to enter the external interaction context based on the old gated transcription identifier.
[0024] This processing method can prevent the de-identified matching parameters from being incorrectly rewritten across tasks, rounds, or rule versions, and avoid old parameters or incorrect rules causing external interaction contexts to generate content that can be reversed.
[0025] In another alternative approach: When the recruitment matching server detects a mismatch in the gated transcription identifier within the same recruitment matching task, it does not directly terminate the entire recruitment matching process. Instead, it performs an external write freeze on the corresponding intelligent agent. External write freeze refers to suspending the corresponding intelligent agent from writing structured intent data, reason category identifiers, one-way explicit summaries, or other external interaction content to the external interaction context. External write freeze does not affect the corresponding intelligent agent's ability to read authorized de-identified matching parameters from the internal inference context. Retaining the internal inference context read permission allows the corresponding intelligent agent to regenerate candidate structured intent data within the internal inference context. Candidate structured intent data is temporary data that has not yet been written to the external interaction context. The recruitment matching server can request the corresponding intelligent agent to regenerate candidate structured intent data based on the currently valid de-identified matching parameter version, the currently valid transcription rule table version, and the current interaction round. After the candidate structured intent data is generated, the recruitment matching server inputs it into the field-level gated transcription unit. The field-level gated transcription unit re-verifies the gated transcription identifier, transcription rule table, and preset backpropagation conditions. If the candidate structured intent data passes the field-level gated transcription unit verification, the recruitment matching server restores the corresponding intelligent agent's external interaction context write permissions and allows the candidate structured intent data to be written to the external interaction context. If the candidate structured intent data fails the field-level gated transcription unit verification, the recruitment matching server maintains the external write freeze state and can generate a reason category identifier or an interaction termination message. The technical effect of this process is that when a gated transcription identifier mismatch occurs, the system will not allow incorrect versions of desensitized matching parameters or incorrect transcription rules to enter the external interaction context; at the same time, the system does not have to completely stop internal inference processing. External writing is frozen, but internal inference can still continue until the regenerated data passes the field-level gated transcription unit verification before external writing is restored. This mechanism can reduce the probability of the matching task being completely interrupted while ensuring privacy and security.
[0026] In another alternative approach: a one-way explicit summary is used instead of directly displaying the complete combination of structured intention data, reason category identifiers, and intention score ranges. The recruitment matching server generates one-way explicit summaries for both the job seeker's intelligent agent and the recruiter's intelligent agent. The one-way explicit summary corresponding to the job seeker's intelligent agent can be read by the recruiter's intelligent agent; conversely, the one-way explicit summary corresponding to the recruiter's intelligent agent can be read by the job seeker's intelligent agent. The one-way explicit summary is generated from the corresponding structured intention data, the corresponding reason category identifier, and the corresponding intention score range. The structured intention data represents data that can be interactively accessed after field-level gating. The reason category identifier represents the categorized reason generated due to prohibited output granularity or gating fallback. The intention score range represents the range to which the intention score belongs, such as a high matching range, a medium matching range, or a low matching range. The intention score range does not directly output specific scores, thereby reducing the risk of inferring internal constraint scores from specific scores. When generating the one-way explicit summary, the recruitment matching server should remove the anonymized matching parameter type and anonymized matching parameter version identifiers. The reason is that while the anonymized matching parameter type and version identifier may not necessarily contain the original private text, they can reveal which type of matching judgment the private auxiliary information participated in, or which version of the anonymized matching parameter was used in a particular round of interaction. If the opposing intelligent agent obtains this information, it may combine publicly available data and interaction results to make reverse inferences.
[0027] For example, a one-way explicit summary for job seekers could be written as "Job seeker's overall interest in the position is in the medium matching range, with a work style reason category identifier present." This summary does not output "Job seeker's overtime acceptance parameter type" or "Job seeker's overtime acceptance parameter version identifier." A one-way explicit summary for recruiters could be written as "Recruiter's overall interest in the candidate is in the high matching range, with an on-the-job condition reason category identifier present." This summary does not output the recruiter's internal specific restrictions on on-the-job time parameter type and version identifier. The recruitment matching server controls the intelligent agents of job seekers and recruiters to conduct bilateral intelligent agent structured interaction based on the one-way explicit summaries. That is, both intelligent agents see the explicit summary, not the other party's anonymized matching parameters, anonymized matching parameter types, or anonymized matching parameter version identifiers. This method further reduces the risk of reverse identification of private auxiliary information through the interaction process.
[0028] In another alternative approach: scoring channel isolation separates the scoring information visible to external interactions from the scoring information used for internal inference. The recruitment matching server generates public interaction scores based on the one-way explicit summary. Public interaction scores reflect publicly expressible matching information within the external interaction context, such as public skill matching, public job requirement matching, public location requirement matching, and the intention score range in the one-way explicit summary. Public interaction scores can be used for visible feedback in bilateral intelligent agent structured interactions. Simultaneously, the recruitment matching server generates internal constraint scores based on the job seeker's and recruiter's anonymized matching parameters within the internal inference context. Internal constraint scores reflect the true impact of private auxiliary information from both parties on the matching results. Internal constraint scores can include salary internal constraint scores, location internal constraint scores, work style internal constraint scores, arrival time internal constraint scores, team style internal constraint scores, etc. Internal constraint scores are not included in the external interaction context. The recruitment matching server writes the public interaction scores and internal constraint scores into different scoring channels. The public interaction score channels can be read by the agent interaction module to generate content related to external interactions. The internal constraint scoring channel can be read by the intention determination module to generate bilateral intention determination results. The public interaction scoring channel cannot directly read the scoring details from the internal constraint scoring channel; the external interaction context also cannot output internal constraint scores. Scoring channel merging rules are used to merge public interaction scores and internal constraint scores when generating bilateral intention determination results. Scoring channel merging rules can employ weighted merging, threshold merging, hierarchical merging, or hard-condition priority merging. For example, if the public interaction score is high but the internal constraint score is below a preset internal constraint threshold, the scoring channel merging rule can lower the bilateral intention determination result level. Another example is when the public interaction score is in the medium matching range, but the internal constraint score is in the high matching range; the scoring channel merging rule can maintain the bilateral intention determination result in a state where it can continue to be confirmed. The scoring channel merging rule does not output internal constraint scores to the external interaction context. The external interaction context can at most receive the merged bilateral intention determination results or the publicly available intention score range. This ensures that internal constraint scores participate in the final determination but are not directly read by the job seeker's intelligent agent or the recruiter's intelligent agent through external interaction content. By isolating the scoring channels, the system can avoid the risk of privacy leaks caused by mixing public interactive scoring and internal constraint scoring, while ensuring that the internal constraint scoring formed by private auxiliary information has a substantial impact on the final bilateral intention determination result.
[0029] A bilateral recruitment matching system with privacy information isolation, corresponding to the aforementioned bilateral recruitment matching method, includes: an information acquisition module, an isolation storage module, an intelligent agent configuration module, an authorization call module, an agent interaction module, an intention determination module, and a confirmation trigger module.
[0030] In another alternative approach: the field-level gated transcription unit in the proxy interaction module can be deployed as an independent software module, or as a subroutine, function interface, or service component within the proxy interaction module. The input to the field-level gated transcription unit includes the de-identified matching parameters for job seekers and recruiters from the internal inference context. The output of the field-level gated transcription unit includes the structured intention data for both job seekers and recruiters. During system runtime, the authorization call module first generates the de-identified matching parameters for both job seekers and recruiters and writes them into the internal inference context. The proxy interaction module then calls the field-level gated transcription unit. The field-level gated transcription unit reads the de-identified matching parameter type and output granularity restrictions according to the transcription rule table, transcribing the de-identified matching parameters for both job seekers and recruiters into their structured intention data. The field-level gated transcription unit does not allow the original values of the de-identified matching parameter fields to be written into the external interaction context. The content written to the external interaction context by the field-level gated transcription unit must be structured intention data or reason category identifiers. For example, a field-level gated transcription unit can output "medium salary matching degree," but cannot output the original value of the job seeker's minimum salary or the recruiter's maximum budget. A field-level gated transcription unit can output "reason category identifier for on-the-job conditions," but cannot output specific non-compete clauses or specific on-the-job obstacles. The field-level gated transcription unit can generate a transcription record for each transcription process. The transcription record can include the recruitment matching task identifier, interaction round identifier, anonymized matching parameter version identifier, transcription rule table version identifier, transcription result type, and transcription time. The transcription record is used for internal system auditing and is not output to the external interaction context. Through this module setting, system items can correspond to field-level gated transcription processes in the method flow, ensuring that the overall system structure has a clear input, processing, and output relationship.
[0031] In another alternative approach, the gated rollback submodule can be integrated within the proxy interaction module, communicating with the field-level gated transcription unit. The inputs to the gated rollback submodule include the external interaction context, job seeker anonymization matching parameters, recruiter anonymization matching parameters, and preset reverse conditions. The output of the gated rollback submodule includes the external interaction context after rollback. During system operation, the field-level gated transcription unit first transcribes the anonymization matching parameters into structured intent data or reason category identifiers and writes them into the external interaction context. Subsequently, the gated rollback submodule reads the structured intent data from the external interaction context and determines whether the structured intent data satisfies the preset reverse conditions with the job seeker's or recruiter's anonymization matching parameters. When the gated rollback submodule determines that the structured intent data satisfies the preset reverse conditions, it sends a reversal command to the proxy interaction module. The proxy interaction module then deletes or marks the corresponding structured intent data according to the reversal command. The gated rollback submodule then calls the field-level gated transcription unit to roll back the corresponding structured intention data to the corresponding cause category identifier, and writes the cause category identifier into the external interaction context. In this way, after rollback, the external interaction context still retains the categorical information that can be used for subsequent judgment, but no longer retains the structured intention data that can be used to deduce the de-identified matching parameters.
[0032] For example, if the external interaction context contains structured intention data that could potentially reveal the recruiter's actual salary range, the gated rollback submodule, upon detecting the risk of such a reversal, will retract the structured intention data and write a "salary condition reason category identifier" through the field-level gated transcription unit. As another example, if the external interaction context contains structured intention data that could potentially reveal a job seeker's specific commuting restrictions, the gated rollback submodule will revert this structured intention data to a "location condition reason category identifier." By working in conjunction with the field-level gated transcription unit, the gated rollback submodule allows the system to perform secondary security controls after output generation. This module is not a typical sensitive word filtering module; rather, it forms a reversal and rollback link with the field-level gated transcription unit, reducing the risk of reverse inference while preserving the usability of the interaction.
[0033] In another alternative approach: the scoring channel isolation submodule can be placed within the intention determination module. This submodule is used to generate, save, and controllably merge public interaction scores and internal constraint scores separately. The inputs to the scoring channel isolation submodule include a one-way explicit summary, de-identified matching parameters for job seekers and recruiters within the internal inference context. The output of the scoring channel isolation submodule is a merged scoring result used to generate bilateral intention determination results. The scoring channel isolation submodule first generates a public interaction score based on the one-way explicit summary. This summary has undergone field-level gating, cause category identifier replacement, and prohibited field removal, ensuring that the public interaction score does not directly contain detailed internal private parameters. The public interaction score can be written into the public interaction score channel. This channel can be provided to the proxy interaction module to form explicit interactive feedback. The scoring channel isolation submodule then generates an internal constraint score based on the de-identified matching parameters for job seekers and recruiters within the internal inference context. This internal constraint score can be written into the internal constraint score channel. The internal constraint scoring channel is only available for internal use by the intention determination module and is not directly output to the proxy interaction module, nor is it written to the external interaction context. When the scoring channel isolation submodule executes the scoring channel merging rule, it can read the public interaction scores from the public interaction scoring channel and the internal constraint scores from the internal constraint scoring channel. After merging the two types of scores, the scoring channel isolation submodule obtains a merged scoring result used to generate a two-sided intention determination result. The merged scoring result can be further converted into a two-sided intention determination result, such as "recommend interview confirmation," "recommend continuing communication," or "not recommend continuing communication." The scoring channel merging rule does not output the internal constraint score to the external interaction context. That is, the external interaction context can only obtain the merged result or the public interaction scoring range and cannot read the specific score, specific dimension, or specific source of the internal constraint score. This setting can prevent the proxy interaction module from using scoring details to reverse-identify the job seeker's or recruiter's private auxiliary information. Through the scoring channel isolation submodule, the system can separate the externally visible interaction logic and the internal private constraint determination logic, allowing private auxiliary information to affect the final result while preventing the internal constraint score from being leaked through the external interaction context.
[0034] The beneficial effects of this invention are:
[0035] This invention stores the private auxiliary information of both the job seeker and the recruiter separately through separate layers, preventing the intelligent agents of the job seeker and recruiter from accessing each other's private auxiliary information layers and thus reducing the risk of leakage of private auxiliary information during the recruitment matching process. Through structured parsing and quantitative mapping, the private auxiliary information is transformed into anonymized matching parameters, allowing it to participate in intelligent matching while preventing the original content of the private auxiliary information from entering the bilateral interactive data. Therefore, the system can improve the consistency between recruitment matching results and the true intentions of both parties without exposing the original content of the private auxiliary information. Through structured interaction between the two intelligent agents, the intelligent agents of the job seeker and the recruiter interact based on publicly available information and anonymized matching parameters, replacing a large amount of inefficient manual communication. The system generates interview confirmation trigger information when the bilateral intention judgment results meet preset confirmation conditions, reducing invalid communication that does not meet hidden constraints. By implementing desensitized output verification, cross-side access blocking records, and intelligent proxy access audit records, the system further restricts the entry of private auxiliary information and reversibly identifiable content into interactive output, and provides traceability data for abnormal call behavior, thereby improving the data security and controllability of the recruitment matching process. Attached Figure Description
[0036] Figure 1 This is a schematic flowchart of the method steps of the present invention.
[0037] Figure 2 This is a schematic block diagram of the overall system structure of the present invention. Detailed Implementation
[0038] The technical solutions in the embodiments of the present invention will now be clearly and completely described in conjunction with the accompanying drawings.
[0039] like Figures 1-2 As shown, this invention provides a bilateral recruitment matching method and a bilateral recruitment matching system with privacy information isolation.
[0040] In one embodiment, the bilateral recruitment matching method with privacy information isolation is executed by a recruitment matching server. The recruitment matching server can be a computing device deployed on a cloud server, enterprise server, distributed server cluster, or recruitment platform backend system. The recruitment matching server includes a processor, memory, communication interface, and program instructions. When the processor executes the program instructions in the memory, it implements the information acquisition step, isolation storage step, proxy configuration step, authorization invocation step, proxy interaction step, intention determination step, and confirmation triggering step described in this invention.
[0041] Job seeker's publicly available information refers to data that job seekers allow to be disclosed and used in the recruitment matching process. This information may include name, work experience, education, project experience, skill tags, desired position, desired city, expected salary range, and available start date. Job seeker's private supplementary information refers to data that job seekers do not wish to disclose directly to recruiters but wish to use in the recruitment matching process. This information may include minimum salary requirement, commute time restrictions, overtime tolerance, preferred work environment, preferred team management style, reasons for leaving previous jobs, non-compete restrictions, and family schedule. Recruiter's publicly available job posting information refers to data that recruiters allow to be disclosed to job seekers and used in the recruitment matching process. This information may include job title, job responsibilities, job requirements, job location, expected salary range, work style, number of openings, required skills, education, and experience. Recruiter's private supplementary information refers to data that recruiters do not wish to disclose directly to job seekers but wish to use in the recruitment matching process. The recruiter's confidential supplementary information may include actual salary flexibility, job urgency, team style preferences, candidate stability preferences, candidate background preferences, onboarding restrictions, and internal budget constraints.
[0042] In the information acquisition step, the recruitment matching server can obtain publicly available job seeker information and private auxiliary information through the job seeker's client, and publicly available job posting information and private auxiliary information through the recruiter's client. Alternatively, it can read this data from pre-registered user databases, job posting databases, and private auxiliary information databases. After acquiring this data, the recruitment matching server creates a task identifier for each recruitment matching task. The task identifier is used to associate publicly available job seeker information, private auxiliary information, publicly available job posting information, and private auxiliary information.
[0043] In the isolated storage step, the recruitment matching server writes the job seeker's private auxiliary information to the job seeker's private auxiliary information isolation layer, and also writes the recruiter's private auxiliary information to the recruiter's private auxiliary information isolation layer. The job seeker's private auxiliary information isolation layer and the recruiter's private auxiliary information isolation layer can be isolated through different database partitions, different access namespaces, different storage buckets, different encryption keys, or different service access interfaces. The job seeker's private auxiliary information isolation layer is used to accept authorized calls from the job seeker's intelligent agent and is not exposed to the recruiter's intelligent agent. The recruiter's private auxiliary information isolation layer is used to accept authorized calls from the recruiter's intelligent agent and is not exposed to the job seeker's intelligent agent.
[0044] In one possible implementation, the recruitment matching server can encrypt and store the private auxiliary information of both job seekers and recruiters. The encrypted storage can employ symmetric encryption to save the private content and key encapsulation to save the encryption key. Integrity verification data can be stored along with the private content to detect whether the private content has been tampered with. The encryption algorithm, key length, key update cycle, and storage fields can be set according to the system security level. Encrypted storage is not the only implementation method of this invention; as long as the job seeker's private auxiliary information isolation layer and the recruiter's private auxiliary information isolation layer are logically isolated from each other, the basic technical effect of this invention can be achieved.
[0045] In the agent configuration step, the job matching server configures the job seeker's intelligent agent based on the job seeker's publicly available information. The job seeker's intelligent agent can be an AI inference program running on the job matching server, or it can be an agent program that calls a large language model, classification model, ranking model, or rule-based inference engine. The job seeker's intelligent agent uses the job seeker's publicly available information as its basic identity context to represent the job seeker in the job matching interaction. The job matching server also configures the recruiter's intelligent agent based on the recruiter's publicly available job posting information. The recruiter's intelligent agent uses the recruiter's publicly available job posting information as its basic identity context to represent the recruiter in the job matching interaction.
[0046] The configuration data for the job seeker's intelligent agent can include a summary of the job seeker's publicly available information, job preferences, constraints on the job seeker's publicly expressed intentions, interaction strategies, and the job seeker's identity. The configuration data for the recruiter's intelligent agent can include a summary of the recruiter's publicly available job postings, job skill requirements, constraints on the recruiter's publicly expressed intentions, interaction strategies, and the recruiter's identity. Both the job seeker's and recruiter's intelligent agents can run as service processes, container tasks, agent sessions, or model invocation sessions, respectively. During operation, both agents forward structured interaction data through the recruitment matching server.
[0047] During the authorized invocation step, after receiving the recruitment matching task, the recruitment matching server controls the job seeker's intelligent agent to generate anonymized matching parameters from the job seeker's private auxiliary information isolation layer, and also controls the recruiter's intelligent agent to generate anonymized matching parameters from the recruiter's private auxiliary information isolation layer. The job seeker's intelligent agent cannot directly read the original content within the recruiter's private auxiliary information isolation layer.
[0048] The anonymized matching parameters for job seekers are machine-calculated parameters derived from their confidential supplementary information. These parameters can be ratings, weights, constraint flags, level labels, risk labels, or Boolean results. Similarly, the anonymized matching parameters for recruiters are machine-calculated parameters derived from their confidential supplementary information. These parameters can also be ratings, weights, constraint flags, level labels, risk labels, or Boolean results. These anonymized matching parameters are used in subsequent intelligent matching decisions and are not intended to reveal the original content of the confidential supplementary information to the other party.
[0049] In one specific implementation, the recruitment matching server first performs structured parsing on the job seeker's private auxiliary information. Structured parsing refers to converting the private auxiliary information expressed in natural language into standardized fields. For example, if the job seeker's private auxiliary information is "cannot accept leaving get off work after 9 PM," the recruitment matching server can parse this content into a work duration preference field and an upper limit field for leaving get off work. As another example, if the job seeker's private auxiliary information is "minimum acceptable salary is 15,000 yuan," the recruitment matching server can parse this content into a minimum salary field. These structured private fields are not output as the original text to the recruiter's intelligent agent; instead, they undergo quantitative mapping processing.
[0050] Quantitative mapping refers to converting structured, confidential fields into de-identified matching parameters that can be used for matching calculations. For example, a minimum salary field can be mapped to a salary matching score or a salary constraint flag; a work duration preference field can be mapped to a work environment matching score; a commuting time restriction field can be mapped to a location matching penalty weight; and a non-compete restriction field can be mapped to a feasibility flag for on-the-job availability. The recruiter's confidential supplementary information can also be structured and quantitatively mapped in the same way. For example, the recruiter's actual salary flexibility can be mapped to a recruiter's salary space matching parameter, team style preference can be mapped to a recruiter's team style matching parameter, and onboarding restrictions can be mapped to a recruiter's hiring restriction matching parameter.
[0051] When generating anonymized matching parameters for job seekers and recruiters, the recruitment matching server can save an anonymized matching parameter identifier. This identifier is used in access audit logs to indicate that corresponding confidential auxiliary information has been included in the calculation, but it does not contain the original content of the confidential auxiliary information. This allows the system to retain call records without leaking confidential auxiliary information through audit logs.
[0052] During the authorization call step, the recruitment matching server can also establish binding call relationships. These binding call relationships represent the authorized call correspondence between the job seeker's intelligent agent and the job seeker's private auxiliary information isolation layer, as well as the authorized call correspondence between the recruiter's intelligent agent and the recruiter's private auxiliary information isolation layer. Binding call relationships can be implemented using identity identifiers, task identifiers, service tokens, access policies, access control lists, or process permissions. When the job seeker's intelligent agent initiates a call, the recruitment matching server checks whether the call request originates from the job seeker's intelligent agent and whether the call target is the job seeker's private auxiliary information isolation layer. Similarly, when the recruiter's intelligent agent initiates a call, the recruitment matching server checks whether the call request originates from the recruiter's intelligent agent and whether the call target is the recruiter's private auxiliary information isolation layer.
[0053] In the blocking record step, when the recruitment matching server detects a request from a job seeker's intelligent agent to invoke the recruiter's private auxiliary information isolation layer, the recruitment matching server blocks the corresponding invocation request and generates a cross-side access blocking record. The cross-side access blocking record may include the request source, target private auxiliary information isolation layer, blocking time, task identifier, exception type, and processing result. The cross-side access blocking record does not store the original content of the private auxiliary information.
[0054] In the agent interaction step, the recruitment matching server controls the intelligent agents of job seekers and recruiters to conduct bilateral intelligent agent structured interaction. Bilateral intelligent agent structured interaction means that the intelligent agents of job seekers and recruiters do not primarily use free text chat as the data carrier, but instead output interactive data according to a system-preset structure. Interaction data may include confirmation of public conditions, ability matching conclusions, location matching conclusions, salary matching conclusions, feasibility conclusions for employment, intention scores, and categories of reasons for anonymization. Bilateral interaction data can be stored in the form of key-value pairs, structured text, tabular records, message objects, or database records. During the bilateral intelligent agent structured interaction process, the intelligent agent of job seekers can, based on the publicly available information and anonymized matching parameters of job seekers, raise job-related inquiries to the intelligent agent of recruiters or output structured intention data of job seekers. The intelligent agent of recruiters can, based on publicly available job information and anonymized matching parameters of recruiters, raise candidate-related inquiries to the intelligent agent of job seekers or output structured intention data of recruiters. The structured intention data of job seekers and recruiters does not include the original content of the private supplementary information of job seekers and recruiters.
[0055] For example, if a job seeker's private information states "cannot accept long hours of overtime," the recruitment matching server will not output the original text of "cannot accept long hours of overtime" in the bilateral interaction data. Instead, it can output a work environment matching score or a work style matching level. As another example, if a recruiter's private information states "budget up to 30,000 yuan but does not wish to disclose it," the recruitment matching server will not output the original text of the maximum budget in the bilateral interaction data. Instead, it can output a salary range matching score or a salary negotiation feasibility level. Through these methods, private information can influence the matching judgment, but it will not be revealed to the other party in its original form.
[0056] The recruitment matching server controls the intelligent agents of job seekers and recruiters to conduct multi-round automatic conversations during the agent interaction steps. In each round of automatic conversation, the recruitment matching server generates a round identifier based on the current recruitment matching task. The intelligent agents of both the job seeker and recruiter generate corresponding structured questions, structured responses, and stage-specific intention data based on the job seeker's publicly available information, the recruiter's publicly available job information, the job seeker's structured intention data, the recruiter's structured intention data, and the bilateral interaction data from the previous round of conversation. The recruitment matching server summarizes the structured questions, structured responses, and stage-specific intention data output from each round of automatic conversation to obtain the round conversation results, and writes the results of multiple rounds of conversations into the external interaction context. The recruitment matching server terminates the multi-round automatic conversation when the preset number of rounds is reached, the stage-specific intention data of both parties tends to stabilize, or any round conversation result triggers a hard conflict category. It then generates a bilateral intention judgment result based on the final round conversation result, the job seeker's structured intention data, the recruiter's structured intention data, the publicly available interaction score, and the internal constraint score. Through the aforementioned multi-round automatic conversations, the job seeker's intelligent agent and the recruiter's intelligent agent can confirm the matching status round by round based on job skills, salary range, work method, arrival time, location conditions, and other matching dimensions, enabling the recruitment matching server to complete the matching judgment between the job seeker and the recruiter based on the conversation results.
[0057] When controlling the intelligent agents of job seekers and recruiters to conduct multi-round automatic conversations, the recruitment matching server also generates indirect inquiry strategies based on the anonymized matching parameters of both parties. These indirect inquiry strategies are used to laterally confirm the content of interest to both parties without exposing the original content of the private auxiliary information of either the job seeker or the recruiter. Based on the structured intention data and reason category identifiers output by the field-level gated transcription unit, the recruitment matching server determines the dimensions of interest that need to be confirmed in each round of automatic conversation and generates structured inquiry content for the corresponding intelligent agent that does not contain the original values of the private parameter fields. For example, when the anonymized matching parameters of the job seeker indicate a potential conflict in their work style, the intelligent agent for the job seeker does not directly output the job seeker's acceptable overtime level from their private supplementary information. Instead, it generates structured questions based on the job's work pace, project urgency, regular off-hours, and flexible work arrangements. Similarly, when the anonymized matching parameters of the recruiter indicate a potential conflict in salary space, the intelligent agent for the recruiter does not directly output the recruiter's actual budget ceiling from their private supplementary information. Instead, it generates structured questions based on salary structure, performance-based pay, salary adjustment cycles, and job level ranges. The recruitment matching server parses the structured responses obtained during the automated conversation, associates the structured responses with corresponding dimensions of interest, and updates the public interaction score, internal constraint score, and bilateral intention determination results. Through this indirect questioning strategy, the system can confirm the matching status round by round based on the content of interest to both parties, while avoiding the direct exposure of private supplementary information in the automated conversation.
[0058] In the anonymization verification step, the recruitment matching server performs anonymization output verification on the bilateral interactive data. Anonymization output verification can include original text fragment comparison, sensitive word fragment comparison, numerical reverse inference detection, templated reason detection, and reversible content recognition detection. Original text fragment comparison compares the similarity of text fragments in the bilateral interactive data with the private auxiliary information of both job seekers and recruiters. When the similarity exceeds a preset comparison threshold, the recruitment matching server deletes the corresponding text fragment or replaces it with an anonymization reason category. Sensitive word fragment comparison detects whether the bilateral interactive data contains the same key content as the private auxiliary information. Numerical reverse inference detection detects whether the bilateral interactive data directly outputs precise values that can be used to infer private content such as minimum salary, maximum budget, and non-compete agreements.
[0059] Reversibly identifiable content refers to content that, while not the original private auxiliary information, allows the recipient to reverse-engineer the private auxiliary information based on the output content. For example, outputting "The candidate is unable to join the competing company due to a non-compete clause from their previous company" might allow the recruiter to reverse-engineer the candidate's non-compete situation; outputting "The company's budget cap is 30,000 yuan" might allow the candidate to reverse-engineer the recruiter's private salary range. When the recruitment matching server detects reversibly identifiable content, it deletes the corresponding content or converts it to an irreversibly anonymized category, such as "Limited feasibility of employment" or "Medium salary range matching degree."
[0060] After the anonymized output verification is completed, the recruitment matching server receives the verified bilateral interaction data. If the bilateral interaction data does not contain the original private auxiliary information or reversibly identifiable content, the verified bilateral interaction data can be the same as the original bilateral interaction data. If the bilateral interaction data contains content that needs to be deleted or replaced, the verified bilateral interaction data will be used as input for subsequent intention determination steps.
[0061] In the intention assessment step, the recruitment matching server generates job seeker intention scores and recruiter intention scores based on bilateral interaction data, and then generates a bilateral intention assessment result based on these scores. The job seeker intention score indicates the degree of match between the job and the job seeker. The recruiter intention score indicates the degree of match between the job seeker and the recruiter's job requirements. The bilateral intention assessment result can include states such as both sides meeting the requirements, the job seeker not meeting the requirements, the recruiter not meeting the requirements, both sides not meeting the requirements, and requiring manual review.
[0062] In one specific implementation, the recruitment matching server first generates a public matching score based on publicly available information from job seekers, publicly available job postings from recruiters, and bilateral interactive data. The public matching score can be calculated based on dimensions of publicly available information, such as skill matching, job experience matching, education matching, location matching, salary range matching, and work style matching. The recruitment matching server then generates a private constraint score based on anonymized matching parameters from both the job seeker and recruiter. The private constraint score indicates the degree to which the private constraints of both parties affect the public matching result.
[0063] The job matching server applies a two-sided correction to the public matching score based on privacy constraint scores. Two-sided correction means adjusting the public matching score from both the job seeker's and recruiter's perspectives. From the job seeker's perspective, when the job seeker's anonymized matching parameters indicate a mismatch between their privacy constraints and the recruiter's publicly available job information, the job matching server applies a privacy constraint correction to the job seeker's intention score. For example, if the public matching score is high, but the job seeker's anonymized matching parameters indicate that their commute time exceeds their acceptable range, the job matching server lowers the job seeker's intention score. From the recruiter's perspective, when the recruiter's anonymized matching parameters indicate a mismatch between their privacy constraints and the job seeker's publicly available information, the job matching server applies a recruiter's privacy constraint correction to the recruiter's intention score. For example, if the job seeker's skills match the publicly available job requirements, but the recruiter's anonymized matching parameters indicate that their start date does not meet the urgency of the job, the job matching server lowers the recruiter's intention score.
[0064] The correction amount for privacy constraints can be a preset deduction value, a preset weight coefficient, a level adjustment, or a correction value output by the model. The recruitment matching server can set different correction intensities based on different types of privacy constraints. For example, hard constraints correspond to higher correction intensities, while preference constraints correspond to lower correction intensities. Hard constraints can include non-compete agreements, infeasibility of employment, and significant mismatch in minimum salary requirements. Preference constraints can include team style preferences, work pace preferences, and work style preferences. The above correction methods allow both public information matching and privacy constraint matching to simultaneously influence the bilateral intention determination results.
[0065] In the confirmation trigger step, the recruitment matching server determines whether the bilateral intention assessment results meet preset confirmation conditions. These preset confirmation conditions may include: the job seeker's intention score reaching a job seeker's intention threshold, the recruiter's intention score reaching a recruiter's intention threshold, both sides meeting the intention assessment results, and the anonymized output validation passing. When the bilateral intention assessment results meet the preset confirmation conditions, the recruitment matching server generates interview confirmation trigger information. This information can be sent to the job seeker's client, the recruiter's client, the recruiter's management backend, or the platform's interview scheduling module. The interview confirmation trigger information may include a summary of the candidate's publicly available information, a summary of the job posting's publicly available information, a suggested interview time, a contact information confirmation entry point, and the interview confirmation status.
[0066] When the mutual interest assessment results do not meet the preset confirmation conditions, the recruitment matching server generates a non-triggered interaction termination message. This message includes a non-triggered result identifier, such as "Continuing communication is not recommended," "Matching failed," or "Supplementary public information required." The non-triggered interaction termination message does not include non-triggered reasons directly generated from the job seeker's or recruiter's private supplementary information. For example, the system will not output "Job seeker does not accept overtime" or "Recruiter's actual salary budget is insufficient" to the recruiter. The system may output a neutral result identifier, such as "Matching conditions for both parties were not met."
[0067] In the access auditing step, the recruitment matching server records the call time, call result, and anonymized matching parameter identifier of the job seeker's intelligent agent calling the job seeker's private auxiliary information isolation layer, and also records the call time, call result, and anonymized matching parameter identifier of the recruiter's intelligent agent calling the recruiter's private auxiliary information isolation layer, thus obtaining the intelligent agent access audit record. The intelligent agent access audit record is used to trace the process of private auxiliary information participating in the matching process. The intelligent agent access audit record does not save the original content of the private auxiliary information. The call result can include states such as call success, call failure, call blocked, anonymization successful, and anonymization verification failed. The anonymized matching parameter identifier can be used to locate the corresponding anonymized matching parameter version without exposing the original content of the private auxiliary information.
[0068] In one system embodiment, the privacy-isolated bilateral recruitment matching system includes an information acquisition module, an isolated storage module, an intelligent agent configuration module, an authorization invocation module, an agent interaction module, an intention determination module, and a confirmation trigger module. These modules can be deployed on the same recruitment matching server or on multiple server nodes. Data transmission between modules occurs through application programming interfaces (APIs), message queues, remote procedure calls, or database read / write operations.
[0069] The information acquisition module receives publicly available information and confidential supplementary information from job seekers' clients, and publicly available job postings and confidential supplementary information from recruiters' clients, and generates the information acquisition results. These results are then transmitted to the isolated storage module and the intelligent agent configuration module.
[0070] After receiving the data and obtaining the results, the isolated storage module writes the job seeker's private auxiliary information into the job seeker's private auxiliary information isolation layer, and the recruiter's private auxiliary information into the recruiter's private auxiliary information isolation layer. The isolated storage module can call the encryption processing program to encrypt and save the private auxiliary information, and it can also call the access policy program to establish corresponding isolation layer access rules.
[0071] After receiving publicly available information from job seekers and publicly available job postings from recruiters, the intelligent agent configuration module generates intelligent agents for both job seekers and recruiters. The job seeker's intelligent agent uses the publicly available information as its public context, while the recruiter's intelligent agent uses the publicly available job postings as its public context. The intelligent agent configuration module can create a set of job seeker and recruiter intelligent agent sessions for each recruitment matching task.
[0072] After receiving a recruitment matching task, the authorization invocation module invokes both the job seeker's private auxiliary information isolation layer and the recruiter's private auxiliary information isolation layer to generate de-identified matching parameters. The authorization invocation module can include a structured parsing submodule and a quantitative mapping submodule. The structured parsing submodule performs structured parsing on both the job seeker's and recruiter's private auxiliary information to obtain structured private fields for both parties. The quantitative mapping submodule performs quantitative mapping on both fields to obtain de-identified matching parameters for both parties.
[0073] The authorization module can also establish binding call relationships to restrict the job seeker's intelligent agent from generating anonymized matching parameters from the recruiter's private auxiliary information isolation layer. When the binding call relationship is violated, the authorization module blocks the call request and generates a cross-side access blocking record.
[0074] The agent interaction module receives publicly available information from job seekers, publicly available job postings from recruiters, and anonymized matching parameters from both parties. It then controls the intelligent agents for both job seekers and recruiters to engage in structured bilateral agent-based interaction, generating bilateral interaction data. The agent interaction module further ensures that the bilateral interaction data includes structured intention data for both job seekers (generated from their anonymized matching parameters) and recruiters (generated from their anonymized matching parameters), while excluding the original content of either party's private supplementary information.
[0075] After receiving bilateral interaction data, the intention determination module generates job seeker intention scores and recruiter intention scores. The intention determination module can include a public matching scoring submodule, a private constraint scoring submodule, and a two-sided correction submodule. The public matching scoring submodule generates a public matching score based on publicly available job seeker information, publicly available job posting information, and bilateral interaction data. The private constraint scoring submodule generates a private constraint score based on anonymized matching parameters for both the job seeker and the recruiter. The two-sided correction submodule performs two-sided corrections on the public matching score based on the private constraint score to obtain the job seeker intention score and the recruiter intention score.
[0076] After receiving the bilateral intention assessment results, the confirmation trigger module determines whether the results meet preset confirmation conditions. If the preset conditions are met, the confirmation trigger module generates interview confirmation trigger information. If the bilateral intention assessment results do not meet the preset conditions, the confirmation trigger module generates non-triggered interaction termination information. This non-triggered interaction termination information includes a non-triggered result identifier but does not include the reason for non-triggered interaction directly generated by the job seeker's or recruiter's private auxiliary information.
[0077] Through the above specific implementation method, the private auxiliary information of job seekers and recruiters is stored in an isolation layer. The intelligent agents for job seekers and recruiters respectively generate anonymized matching parameters from the corresponding private auxiliary information isolation layer. The structured interaction between the two intelligent agents is completed based on publicly available information and the anonymized matching parameters. The bilateral intention determination result is generated based on the interaction data and the bilateral correction results. This process allows private auxiliary information to participate in recruitment matching calculations while preventing the original content of the private auxiliary information from entering the bilateral interaction data, thus achieving a balance between privacy protection and improved recruitment matching efficiency.
Claims
1. A bilateral recruitment matching method with privacy information isolation, characterized in that, Includes the following steps: Information acquisition steps: The recruitment matching server acquires publicly available information of job seekers, their private supplementary information, publicly available job postings from recruiters, and their private supplementary information. Isolation storage step: The recruitment matching server writes the job seeker's private auxiliary information into the job seeker's private auxiliary information isolation layer, and also writes the recruiter's private auxiliary information into the recruiter's private auxiliary information isolation layer; Proxy configuration steps: The recruitment matching server configures a smart proxy for job seekers based on their publicly available information, and configures a smart proxy for recruiters based on their publicly available job posting information. Authorization call steps: After receiving the recruitment matching task, the recruitment matching server controls the job seeker's intelligent agent to generate the job seeker's de-identified matching parameters from the job seeker's private auxiliary information isolation layer, and controls the recruiter's intelligent agent to generate the recruiter's de-identified matching parameters from the recruiter's private auxiliary information isolation layer; Agent interaction steps: The recruitment matching server controls the job seeker's intelligent agent and the recruiter's intelligent agent to conduct bilateral intelligent agent structured interaction based on the job seeker's publicly available information, the recruiter's publicly available job information, the job seeker's de-identified matching parameters, and the recruiter's de-identified matching parameters to obtain bilateral interaction data.
2. The bilateral recruitment matching method with privacy information isolation according to claim 1, characterized in that, Following the proxy interaction steps are: Intention determination step: The recruitment matching server generates job seeker intention scores and recruiter intention scores based on the bilateral interaction data, and generates bilateral intention determination results based on the job seeker intention scores and recruiter intention scores; Confirmation triggering step: When the bilateral intention judgment results meet the preset confirmation conditions, the recruitment matching server generates interview confirmation triggering information; The authorized call steps are as follows: the recruitment matching server performs structured parsing on both the job seeker's private auxiliary information and the recruiter's private auxiliary information to obtain structured private fields for both the job seeker and the recruiter; the recruitment matching server performs quantitative mapping on both the job seeker's structured private fields and the recruiter's structured private fields to obtain de-identified matching parameters for both the job seeker and the recruiter; wherein, the de-identified matching parameters for both the job seeker and the recruiter do not contain the original text content of the job seeker's private auxiliary information and the recruiter's private auxiliary information. In the authorized call step: the recruitment matching server establishes a binding call relationship between the job seeker's intelligent agent and the job seeker's private auxiliary information isolation layer, and also establishes a binding call relationship between the recruiter's intelligent agent and the recruiter's private auxiliary information isolation layer; the binding call relationship is used to restrict the job seeker's intelligent agent from generating the recruiter's de-identified matching parameters from the recruiter's private auxiliary information isolation layer, and also to restrict the recruiter's intelligent agent from generating the job seeker's de-identified matching parameters from the job seeker's private auxiliary information isolation layer.
3. The bilateral recruitment matching method with privacy information isolation according to claim 2, characterized in that, Following the authorization call step are: Blocking record steps: When the recruitment matching server detects that the job seeker's intelligent agent requests to call the recruiter's private auxiliary information isolation layer, or when the recruiter's intelligent agent requests to call the job seeker's private auxiliary information isolation layer, it blocks the corresponding call request and generates a cross-side access blocking record containing the request source, the target private auxiliary information isolation layer, and the blocking time. In the proxy interaction steps: When the recruitment matching server controls the job seeker's intelligent agent and the recruiter's intelligent agent to conduct bilateral intelligent agent structured interaction, the bilateral interaction data includes the job seeker's structured intention data generated by the job seeker's desensitized matching parameters and the recruiter's structured intention data generated by the recruiter's desensitized matching parameters, and the bilateral interaction data does not include the original text of the job seeker's private auxiliary information and the original text of the recruiter's private auxiliary information. Following the proxy interaction steps are: De-identification verification step: The recruitment matching server performs de-identification output verification on the bilateral interaction data; when the bilateral interaction data contains text fragments that are the same as the job seeker's private assistance information or the recruiter's private assistance information, or contains reversibly identifiable content that can be reverse-located to the job seeker's private assistance information or the recruiter's private assistance information, the recruitment matching server deletes the corresponding text fragments or the corresponding reversibly identifiable content to obtain the verified bilateral interaction data.
4. The bilateral recruitment matching method with privacy information isolation according to claim 3, characterized in that, The intention determination steps are as follows: the recruitment matching server generates a public matching score based on the job seeker's publicly available information, the recruiter's publicly available job information, and the bilateral interaction data; the recruitment matching server generates a private constraint score based on the job seeker's anonymized matching parameters and the recruiter's anonymized matching parameters; the recruitment matching server performs bilateral correction on the public matching score based on the private constraint score to obtain the job seeker's intention score and the recruiter's intention score; the recruitment matching server generates the bilateral intention determination result based on the job seeker's intention score and the recruiter's intention score. In the intention determination step: when the job seeker's anonymized matching parameters, which indicate that the job seeker's privacy constraints do not match the job seeker's publicly available job information, the recruitment matching server applies a job seeker privacy constraint correction amount to the job seeker's intention score; when the job seeker's anonymized matching parameters, which indicate that the job seeker's privacy constraints do not match the job seeker's publicly available information, the recruitment matching server applies a job seeker privacy constraint correction amount to the job seeker's intention score.
5. The bilateral recruitment matching method with privacy information isolation according to claim 4, characterized in that, Following the authorization call step are: Access auditing steps: The recruitment matching server records the call time, call result, and de-identified matching parameter identifier of the job seeker's intelligent agent calling the job seeker's private auxiliary information isolation layer, and also records the call time, call result, and de-identified matching parameter identifier of the recruiter's intelligent agent calling the recruiter's private auxiliary information isolation layer, thus obtaining the intelligent agent access audit record; In the confirmation triggering step: when the bilateral intention judgment result does not meet the preset confirmation condition, the recruitment matching server generates non-triggered interaction termination information; the non-triggered interaction termination information includes a non-triggered result identifier and does not include non-triggered reason content directly generated by the job seeker's private auxiliary information or the recruiter's private auxiliary information.
6. The bilateral recruitment matching method with privacy information isolation according to claim 5, characterized in that, In the proxy interaction steps: The recruitment matching server sets up a field-level gated transcribing unit between the internal inference context and the external interaction context; the internal inference context includes the job seeker's de-identified matching parameters and the recruiter's de-identified matching parameters; the external interaction context is used to generate the bilateral interaction data; the field-level gated transcribing unit receives the job seeker's de-identified matching parameters and the recruiter's de-identified matching parameters, transcribs the job seeker's de-identified matching parameters and the recruiter's de-identified matching parameters into the job seeker's structured intention data and the recruiter's structured intention data respectively, and prohibits the job seeker's de-identified matching parameters and the recruiter's de-identified matching parameters from being written into the external interaction context in their original field values; The field-level gated transcription unit performs transcription processing according to the transcription rule table; The transcription rule table includes the desensitization matching parameter type, allowed output granularity, prohibited output granularity, and corresponding reason category identifier; When the output content corresponding to the desensitization matching parameter type belongs to the allowed output granularity, the field-level gated transcription unit generates corresponding structured intention data; when the output content corresponding to the desensitization matching parameter type belongs to the prohibited output granularity, the field-level gated transcription unit generates corresponding reason category identifier and writes the reason category identifier into the external interaction context.
7. The bilateral recruitment matching method with privacy information isolation according to claim 6, characterized in that, In the proxy interaction steps: The recruitment matching server generates an interaction round identifier for the field-level gated transcription unit, and binds the interaction round identifier, the desensitized matching parameter version identifier, and the transcription rule table version identifier to generate a gated transcription identifier; When the gated transcription identifier is inconsistent with the current recruitment matching task, the field-level gated transcription unit refuses to transcribe the de-identified matching parameters in the internal reasoning context to the external interaction context. When the recruitment matching server detects a mismatch in the gated transcription identifier within the same recruitment matching task, it freezes the external interaction context write permission of the corresponding smart agent while retaining the internal inference context read permission of the corresponding smart agent. The recruitment matching server regenerates candidate structured intention data based on the internal inference context, and restores the external interaction context writing permission of the corresponding smart agent after the regenerated candidate structured intention data passes the field-level gated transcription unit verification.
8. The bilateral recruitment matching method with privacy information isolation according to claim 7, characterized in that, Following the proxy interaction steps are: Gated rollback step: The recruitment matching server performs leakage verification on the external interaction context; when the structured intention data in the external interaction context meets the preset reverse calculation condition with the job seeker's desensitized matching parameters or the recruiter's desensitized matching parameters, the recruitment matching server cancels the corresponding structured intention data, and rolls back the corresponding structured intention data to the corresponding reason category identifier through the field-level gating transcription unit to obtain the rolled-back external interaction context; In the intention determination step: after generating the rollback external interaction context, the recruitment matching server regenerates the job seeker's private constraint conflict vector and the recruiter's private constraint conflict vector based on the rollback external interaction context, and recalculates the job seeker's intention score and the recruiter's intention score based on the regenerated job seeker's private constraint conflict vector and the recruiter's private constraint conflict vector. In the confirmation triggering step: when the reason category identifier exists in the external interaction context after the rollback, the recruitment matching server uses the reason category identifier as the confirmation triggering constraint input; when the reason category identifier corresponds to a hard conflict category, the recruitment matching server generates non-triggered interaction termination information; when the reason category identifier corresponds to a preference conflict category, the recruitment matching server generates the bilateral intention judgment result based on the recalculated job seeker intention score and the recruiter intention score.
9. The bilateral recruitment matching method with privacy information isolation according to claim 8, characterized in that, In the agent interaction step: the recruitment matching server generates one-way explicit summaries for both the job seeker's intelligent agent and the recruiter's intelligent agent; the one-way explicit summaries are generated from corresponding structured intention data, corresponding reason category identifiers, and corresponding intention scoring ranges; the recruitment matching server controls the job seeker's intelligent agent and the recruiter's intelligent agent to perform bilateral intelligent agent structured interaction based on the one-way explicit summaries, and prohibits either of the one-way explicit summaries from containing the corresponding de-identified matching parameter type and the corresponding de-identified matching parameter version identifier; In the intention determination step: the recruitment matching server generates a public interaction score based on the one-way explicit summary, and generates an internal constraint score based on the job seeker's de-identified matching parameters and the recruiter's de-identified matching parameters in the internal inference context; the recruitment matching server writes the public interaction score and the internal constraint score into different scoring channels respectively, and merges the public interaction score and the internal constraint score according to the scoring channel merging rule when generating the two-sided intention determination result; wherein, the scoring channel merging rule does not output the internal constraint score to the external interaction context.
10. A bilateral recruitment matching system with privacy information isolation, characterized in that, include: The information acquisition module is used to acquire publicly available information and private supplementary information of job seekers, as well as publicly available job postings and private supplementary information of recruiters, and output the data acquisition results. An isolated storage module is used to receive the data acquisition results, write the job seeker's private assistance information into the job seeker's private assistance information isolation layer, and write the recruiter's private assistance information into the recruiter's private assistance information isolation layer. The intelligent agent configuration module is used to receive the publicly available information of the job seeker and the publicly available job information of the recruiter, configure the intelligent agent of the job seeker based on the publicly available information of the job seeker, and configure the intelligent agent of the recruiter based on the publicly available job information of the recruiter. The authorization call module is used to control the job seeker's intelligent agent to generate de-identified matching parameters from the job seeker's private auxiliary information isolation layer after receiving the recruitment matching task, and to control the recruiter's intelligent agent to generate de-identified matching parameters from the recruiter's private auxiliary information isolation layer. The agent interaction module is used to receive publicly available information from job seekers, publicly available job information from recruiters, de-identified matching parameters from job seekers, and de-identified matching parameters from recruiters, and to control the intelligent agents of job seekers and recruiters to perform bilateral intelligent agent structured interaction to obtain bilateral interaction data. The intention determination module is used to receive the bilateral interaction data, generate job seeker intention scores and recruiter intention scores based on the bilateral interaction data, and generate a bilateral intention determination result based on the job seeker intention scores and recruiter intention scores. The confirmation trigger module is used to receive the bilateral intention determination results and generate interview confirmation trigger information when the bilateral intention determination results meet the preset confirmation conditions.