Electronic device and query conversion method for processing de-identified data in electronic device
The query transformation method addresses inconsistencies in de-identified data processing by using de-identification information to convert queries, ensuring accurate and consistent results for de-identified data sets.
Patent Information
- Application Number
- PCT/KR2025/002863
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-05
- Filing Date
- 2025-03-04
- Publication Date
- 2025-10-09
AI Technical Summary
Conventional database management systems struggle to provide consistent query processing results between original and de-identified data sets, leading to syntax errors and inconsistencies due to differences in data types and domains.
A query transformation method and device that identifies de-identification information, obtains a second conditional clause, and applies correction information to ensure consistent query processing results for de-identified data, using de-identification policy information to convert queries suitable for de-identified data.
Ensures accurate and error-free query processing on de-identified data by transforming queries to account for data type and domain changes, maintaining consistency with original data results.
Smart Images

Figure KR2025002863_09102025_PF_FP_ABST
Abstract
Description
Query transformation method for processing de-identified data in electronic devices and electronic devices
[0001] Various embodiments of the present disclosure relate to devices and methods for processing non-identifiable data.
[0002] Big data has recently emerged as a rapidly growing IT technology trend. Big data can refer to massive sets of structured or unstructured data, as well as the technology for extracting value from such data and analyzing the results. Big data can be utilized across all areas, including politics, society, economics, culture, and science and technology. These diverse data sets can be stored in databases, and a database management system (DBMS) can manage and operate these databases.
[0003] Big data can contain personal information such as resident registration numbers, addresses, phone numbers, height, weight, and age. Beyond personal information, it can also contain information that should not be made public. Recently, database management systems have been developed to manage and operate de-identified data, which is processed (e.g., anonymized) from portions of the original data that require privacy protection or confidentiality, rather than simply using the original data.
[0004] A database management system (DBMS) can perform various data processing functions related to data within a database through a language (e.g., structured query language (SQL)) (hereinafter referred to as a "query") used to access and manipulate the database. For example, when a query is input (or received), the DBMS can perform various data processing functions such as data retrieval (or inquiry), deletion, insertion, modification, creation of a new database, or table creation, depending on the syntax contained in the query.
[0005] Conventional database management systems can process queries regardless of whether the database contains the original data as is (hereinafter also referred to as the "original data DB") or the de-identified data database contains de-identified data that has been partially processed (e.g., anonymized) from the original data (hereinafter also referred to as the "de-identified data DB"). Since the de-identified data DB contains de-identified (or anonymized) data, when the database management system processes a query for the de-identified data DB, the query processing results may be significantly different from those when the query is processed for the original data DB. Even when a query is made for the de-identified data DB, a method may be required that can obtain the same or similar query processing results as when the query is made for the original data DB.
[0006] According to one embodiment of the present disclosure, an electronic device may include an interface, a memory storing instructions, and a processor operatively connected to the input / output interface and the memory. The instructions, when executed by the processor, may be configured to cause the electronic device to receive a first query associated with data analysis for a database through the interface. The instructions, when executed by the processor, may be configured to cause the electronic device to identify a first condition in the first query. The instructions, when executed by the processor, may be configured to cause the electronic device to obtain de-identification information for de-identified data in the database. The instructions, when executed by the processor, may be configured to cause the electronic device to obtain a second condition for the de-identified data corresponding to the first condition using the first condition and the de-identification information. The above instructions, when executed by the processor, may be configured to cause the electronic device to obtain a second query for the de-identified data corresponding to the first query using the second conditional clause and to provide the obtained second query.
[0007] According to one embodiment of the present disclosure, a query transformation method for processing de-identified data in an electronic device may include receiving a first query for a database. The method may include identifying a first condition in the first query. The method may include obtaining de-identification information for de-identified data in the database. The method may include obtaining a second condition for the de-identified data corresponding to the first condition using the first condition and the de-identification information. The method may include obtaining a second query for the de-identified data corresponding to the first query using the second condition. The method may include providing the second query or performing a second query for the database using the second query.
[0008] According to one embodiment of the present disclosure, a non-transitory storage medium storing commands is provided, wherein the commands, when executed by an electronic device, are configured to cause the electronic device to perform at least one operation, wherein the at least one operation may include: receiving a first query for a database; identifying a first conditional clause in the first query; obtaining de-identification information for de-identified data of the database; obtaining a second conditional clause for the de-identified data corresponding to the first conditional clause using the first conditional clause and the de-identification information; obtaining a second query for the de-identified data corresponding to the first query using the second conditional clause; and providing the second query or performing a second query for the database using the second query.
[0009] Figure 1 is a schematic diagram illustrating a data analysis system and a data storage according to one embodiment.
[0010] FIG. 2 is a diagram showing an example of an original data set and an anonymized data set according to one embodiment.
[0011] FIG. 3a is a diagram illustrating an example of an anonymization policy level of an age domain according to one embodiment.
[0012] FIG. 3b is a diagram showing an example of anonymizing a data type (integer) of an age domain into a character type or a range type according to one embodiment.
[0013] FIG. 4a is a diagram illustrating an example of an anonymization policy level of a country domain according to one embodiment.
[0014] FIG. 4b is a diagram showing an example of de-identifying data of a country domain into representative data according to one embodiment.
[0015] FIG. 5a is a diagram illustrating an example of a query result when querying based on original data for anonymized age according to one embodiment.
[0016] FIG. 5b is a diagram showing an example of a query result when querying an anonymized country based on original data according to one embodiment.
[0017] Figure 6 is a block diagram of an electronic device according to one embodiment.
[0018] Figure 7 is a diagram illustrating a query transformation operation according to one embodiment.
[0019] FIG. 8 is a diagram illustrating an example of obtaining a second condition clause for de-identified data corresponding to the first condition clause by using the first condition clause of the first query and de-identified information of the database according to one embodiment.
[0020] FIG. 9 is a diagram illustrating an example of obtaining correction information for correcting an error caused by a second conditional clause for anonymized data according to one embodiment.
[0021] FIG. 10 is a diagram illustrating an example of obtaining a second query for de-identified data using a second condition clause and correction information according to one embodiment.
[0022] FIG. 11 is a diagram illustrating an operation for obtaining query results according to a query processing mode when receiving a first query according to one embodiment.
[0023] In connection with the description of the drawings, the same or similar reference numerals may be used for identical or similar components.
[0024] The terms used in this document are used only to describe specific embodiments and may not be intended to limit the scope of other embodiments. The singular expression may include the plural expression unless the context clearly indicates otherwise. All terms used herein, including technical or scientific terms, may have the same meaning as commonly understood by those of ordinary skill in the art of the present invention. Terms defined in commonly used dictionaries may be interpreted as having the same or similar meaning in the context of the relevant technology, and shall not be interpreted in an idealized or overly formal sense unless explicitly defined in this document. In some cases, even if a term is defined in this document, it cannot be interpreted to exclude embodiments of the present invention.
[0025] FIG. 1 is a schematic diagram illustrating a data analysis system (10) and a data storage (20) according to one embodiment.
[0026] Referring to FIG. 1, a data analysis system (10) according to one embodiment may perform query processing on data stored in a data storage (20) based on receiving a query (hereinafter also referred to as a 'first query') from a data analyst (or an electronic device corresponding to a data analyst) and provide the result of performing the first query to the data analyst.
[0027] A data analysis system (10) according to an embodiment may include a query transformation device (12), a database management device (14), and a de-identification policy information storage device (16). The data analysis system (10) according to an embodiment is not limited to the query transformation device (12), the database management device (14), and the de-identification policy information storage device (16), and may further include other components (e.g., hardware or software)(s). A data storage (20) according to an embodiment may include an original data database (DB) (22) and a de-identified data DB (24). The original data DB (22) according to an embodiment may store a set of original data. The de-identified data DB (24) according to an embodiment may store a set of de-identified data obtained by de-identifying (or anonymizing) some or all of the original data based on predetermined or specified de-identification policy information. The de-identified data DB (24) according to one embodiment can store de-identified data by changing the data domain of the original data of the original data DB (22) or changing the data type. Each of the original data DB (22) and the de-identified data DB (24) according to one embodiment is configured as a minimum unit called a table, and this table can be configured with one or more columns and rows. The data storage (20) according to one embodiment is not limited to the original data DB (22) and the de-identified data DB (24), and can be configured to further include other components (e.g., hardware or software).
[0028] A query transformation device (12) according to an embodiment may receive a first query related to analysis of data stored in a data storage (20). The first query according to an embodiment may be a structured query language. The first query according to an embodiment may include a command related to data retrieval (or selection or extraction). The first query according to an embodiment may include a select command or a select count command. For example, the select command may be a command to retrieve (or select or extract) at least some data from a database, and the select count command may be a command to count the number of retrieved data after retrieving (or selecting or extracting) at least some data from the database.
[0029] A query transformation device (12) according to an embodiment may identify a first condition clause in a received first query. The first condition clause according to an embodiment may include a where condition clause. For example, the where condition clause may include a conditional expression indicating a condition corresponding to a command. For example, the where condition clause may be configured to include logical operators such as = (equal), > (greater than), < (less than), >= (greater than or equal to), <= (less than or equal to), <> or != (not equal to), BETWEEN (between a range of values), LIKE (search for a pattern), and / or IN (search for multiple values).
[0030] A query transformation device (12) according to an embodiment can obtain de-identification information for de-identified data of a de-identified data DB (24). A query transformation device (12) according to an embodiment can obtain de-identification information by analyzing data included in a de-identified data DB (24). A query transformation device (12) according to an embodiment can obtain de-identification information indicating how a data domain (e.g., a data item name) has been de-identified (e.g., represented) or how a data type (e.g., a data type) has been de-identified (e.g., converted from a numerical value to a character value or converted from a numerical value to a numerical range value) by examining a data domain or a data type of data included in a de-identified data DB (24). A query transformation device (12) according to one embodiment can obtain de-identification policy information (data domain de-identification policy information or data type de-identification policy information) for data of an original data DB (22) stored in a de-identification policy information storage device (16), and obtain the de-identification information using the de-identification policy information.
[0031] A query transformation device (12) according to an embodiment can obtain a second conditional clause for de-identified data corresponding to the first conditional clause by using a first conditional clause and de-identification information. A query transformation device (12) according to an embodiment can obtain a second query for de-identified data corresponding to the first query by using the second conditional clause. A query transformation device (12) according to an embodiment can obtain correction information for correcting an error between a query processing result using the second conditional clause for de-identified data and a first query processing result for the original data of the de-identified data, and obtain a second query for de-identified data by applying the second conditional clause and the correction information to the first query. The correction information according to an embodiment can include probability information on the de-identified data being original data.
[0032] A query transformation device (12) according to one embodiment can provide the acquired second query to a database management device (14).
[0033] A database management device (14) according to one embodiment may perform a second query processing on de-identified data stored in a de-identified data DB (24) using a second query for de-identified data. The database management device (14) according to one embodiment may provide (or output) the second query execution result (to a data analyst (or an electronic device corresponding to a data analyst)).
[0034] FIG. 2 is a diagram showing an example of an original data set and an anonymized data set according to one embodiment.
[0035] Referring to FIG. 2, an original data DB (22) according to an embodiment may store an original data set (220) composed of one or more columns and rows based on a table. An anonymized data DB (24) according to an embodiment may store an anonymized data set (240) that is anonymized by changing the data domain or data type of at least some data of the original data set (220).
[0036] FIG. 2 illustrates an example in which an original data set (220) includes data including numbers or characters for a gender domain (or attribute), an age domain (or attribute), a marital-status domain (or attribute), an education domain (or attribute), and a native-country domain (or attribute). In one embodiment, a de-identified data set (240) may de-identify (or anonymize) the values of each data by representing, characterizing, or ranging them so that the numbers or values for age, marital status, education level, and country in the original data set (220) are not accurately identified according to a de-identification policy specified for each domain (or attribute).
[0037] FIG. 3a is a diagram showing an example of an anonymization policy level of an age domain according to one embodiment, and FIG. 3b is a diagram showing an example of anonymizing a data type (integer) of an age domain into a character type or a range type according to one embodiment.
[0038] First, referring to FIG. 3A, the data de-identification policy of the age domain (or attribute) according to one embodiment may be determined as one of de-identification policies (310 to 350) of multiple levels (e.g., level-0, level-1, level-2, level-3, level-4). For example, the higher the level, the greater the degree of de-identification. Level-0 (310) may be a policy that maintains original data that is not de-identified, level-1 (320) may be a policy that applies the first level of de-identification that represents age in a range of 5 units, level-2 (330) may be a policy that applies more de-identification than the first level that represents age in a range of 10 units, level-3 (340) may be a policy that applies more de-identification than the second level that represents age in a range of 20 units, and level-4 (350) may be a policy that applies de-identification that makes it impossible to know age at all.
[0039] Referring to FIG. 3b, if the data type of the age domain (or attribute) of the original data set (220) according to one embodiment is a number (e.g., integer) (360), the de-identification policy may be determined as either a de-identification policy that changes the data type from an integer to a character representing a range including integers or a de-identification policy that changes the data type from an integer to a range including integers. If the de-identification policy (370) that changes the data type from an integer to a character representing a range including integers is applied, the integer value (e.g., 28) of the age domain (or attribute) may be de-identified (370) as a character [21, 30] (character varying) representing a range including the integer. When a de-identification policy that changes a data type from an integer to a range including an integer is applied, an integer value (e.g., 28) of the age domain (or attribute) can be de-identified (380) to a range including an integer [21, 31]. In the present disclosure, the de-identification policy is explained as an example of a de-identification policy that changes an integer to a character representing a range including an integer or a de-identification policy that changes an integer to a range including an integer, but it is to be understood that other integer value de-identification policies may be used.
[0040] FIG. 4a is a diagram showing an example of an anonymization policy level of a country domain according to one embodiment, and FIG. 4b is a diagram showing an example of anonymization of data of a country domain into representative data according to one embodiment.
[0041] First, referring to FIG. 4A, a data de-identification policy of a country domain according to an embodiment may be determined as one of de-identification policies (410 to 450) of multiple levels (e.g., level 0, level 1, level 2, level 3, level 4). According to an embodiment, the higher the level, the greater the degree of de-identification. Level 0 (410) according to an embodiment may be a policy that maintains original data that is not de-identified. For example, Level 0 (410) may be a policy that maintains original data including country names (e.g., Haiti, Jamica, Honduras, Nicaragua, Chile, Colombia, Canada, and USA). Level 1 (420) according to an embodiment may be a policy to which a first-stage de-identification is applied, in which each country name is represented by a subregion representing each country name. For example, level 1 (420) may be a policy that performs a first-stage de-identification that represents Haiti and Jamica as a Caribbean subregion, Honduras and Nicaragua as a Central America subregion, Chile and Colombia as a South America subregion, and Canada and the USA as a North America subregion. Level 2 (430) according to an embodiment may be a policy that applies a second-stage de-identification that represents each country name as a representative mid-region. For example, level 2 (430) may be a policy that performs a second-stage de-identification that represents Haiti, Jamica, Honduras, Nicaragua, Chile, and Colombia as a Latin America and the Caribbean mid-region. Level 3 (440) according to an embodiment may be a policy that applies a de-identification that represents each country name as a representative continent.For example, level 3 (440) may be a policy that performs the third level of anonymization, representing Haiti, Jamica, Honduras, Nicaragua, Chile, Colombia, Canada, and the USA as the Americas continent. Level 4 (450) according to one embodiment may be a policy that applies anonymization, representing each country name as World so that the country name cannot be known. For example, level 4 (450) may be a policy that performs the fourth level of anonymization, representing Haiti, Jamica, Honduras, Nicaragua, Chile, Colombia, Canada, and the USA as World.
[0042] Referring to FIG. 4b, if the country domain of the original data set (220) according to one embodiment is a country name, a de-identification policy may be used, such as a de-identification policy (460) that maintains the country names, or a de-identification policy (470) that maintains some of the country names as country names or changes some of the country names to continental names. If a de-identification policy (470) that maintains some of the country names as country names or changes some of the country names to continental names is used, for example, some countries (united-states) may be maintained as country names (united-states) and other countries (Honduras, Guatemala, Dominican-Republic, Puerto-Rico, Mexico) may be changed to continental names (north America). Although the present disclosure has described a de-identification policy (470) that maintains some of the country names as country names or changes some of the country names to continental names as an example, it should be understood that other types of country name de-identification policies may be used.
[0043] FIG. 5a is a diagram illustrating an example of a query result when querying based on original data for anonymized age according to one embodiment.
[0044] Referring to FIG. 5A, a database management device according to an embodiment (e.g., database management device (14) of FIG. 1) may receive a query (530) for de-identified age data (e.g., de-identified data (510) in which an integer corresponding to age is converted into a character representing a range including the integer, or de-identified data (520) in which an integer corresponding to age is converted into a range including the integer). For example, the query (530) may be a query based on original data, such as “select count(*) FROM original_adult WHERE age>=21 AND age<30.”
[0045] In one embodiment, the database management device (14) may indicate that a first syntax error (540) has occurred due to incompatibility between the data type (varchar) of the de-identified data (510) and the data type (integer) of the query (530) when a query (530) based on the original data is performed on the de-identified data (510) in which the integer is converted to a character. For example, the database management device (14) may provide a first syntax error (540) such as “ERROR: No operator: character varying >= integer LINE 3: WHERE age>=21 AND age<30 HINT: No operator matching the specified name and argument type. An explicit type caster may need to be added. ERROR: No operator: character varying >= integer SQL state: 42883 Character 51.”
[0046] In one embodiment, the database management device (14) may indicate that a second syntax error (550) has occurred due to incompatibility between the data type (range) of the de-identified data (520) and the data type (integer) of the query (530) when a query (530) based on the original data is performed on the de-identified data (520) converted to a range containing integers. For example, the database management device (14) may provide a second syntax error (550) such as “ERROR: No operator found: int4range >= integer LINE 3: WHERE age>=21 AND age<30 HINT: No operator found that matches the specified name and argument type. An explicit type cast may need to be added. ERROR: No operator found: int4range >= integer SQL state: 42883 Character 46.”
[0047] FIG. 5b is a diagram showing an example of a query result when querying based on original data for an anonymized country name according to one embodiment.
[0048] Referring to FIG. 5b, a database management device (e.g., database management device (14) of FIG. 1) according to an embodiment may receive a query (570) for de-identified country name data (e.g., de-identified data in which some of the country names are maintained as country names or some of the country names are converted into continent names) (560). For example, the query (570) may be a query based on original data, such as “select count(*) FROM original_adult WHERE “native-country” = 'mexico'.” When the database management device (14) according to an embodiment performs a query (570) based on original data on de-identified country name data (560), it may indicate that a syntax error (580) occurred because continent names were not properly processed.
[0049] A query conversion device (12) according to one embodiment can convert a query based on original data into a query suitable for de-identified data and provide it. The query conversion device (12) according to one embodiment can include an electronic device.
[0050] Figure 6 is a block diagram of an electronic device according to one embodiment.
[0051] Referring to FIG. 6, an electronic device (601) according to one embodiment (e.g., a query conversion device (12) of FIG. 1) may include an interface (610), a processor (620), and a memory (630).
[0052] An interface (610) according to one embodiment may support one or more designated protocols that may be used to directly or wirelessly connect an electronic device (601) with an external electronic device (e.g., a database management device (14) or an anonymization policy information storage device (16)). According to one embodiment, the interface (610) may include, for example, a high definition multimedia interface (HDMI), a universal serial bus (USB) interface, or an SD card interface, but other interfaces may also be possible as long as they are interfaces used for connecting computing devices.
[0053] According to one embodiment, the processor (620) may control at least one other component (e.g., hardware or software component) of the electronic device (601) connected to the processor (620) by executing, for example, software (e.g., a program (not shown)), and may perform various data processing or operations. According to one embodiment, as at least a part of the data processing or operation, the processor (620) may process a query (e.g., a command or data) received through the interface (610), and store and output the resulting data (via a display module (not shown)) or provide it (to a database management device (14)) via the interface (610) or a communication module (not shown).
[0054] According to one embodiment, a processor (620) may receive a first query (e.g., a query based on original data) related to database data analysis. According to one embodiment, the first query may be a structured query language. According to one embodiment, the first query may include a command related to data retrieval (or selection or extraction). According to one embodiment, the first query may include a select command or a select count command. For example, the select command may be a command to retrieve (or select or extract) at least some data from a database, and the select count command may be a command to retrieve (or select or extract) at least some data from the database and then count the number of retrieved data.
[0055] According to an embodiment, the processor (620) may identify a first condition clause in the received first query. According to an embodiment, the first condition clause may include a where condition clause. For example, the where condition clause may include a conditional expression indicating a condition corresponding to a command. For example, the where condition clause may be configured to include logical operators such as = (equal), > (greater than), < (less than), >= (greater than or equal to), <= (less than or equal to), <> or != (not equal to), BETWEEN (between a range of values), LIKE (search for a pattern), and / or IN (search for multiple values).
[0056] A processor (620) according to an embodiment can obtain de-identification information for data in a database (e.g., de-identified data DB (24)). A processor (620) according to an embodiment can obtain de-identification information by analyzing data included in the de-identified data DB (24). A processor (620) according to an embodiment can obtain de-identification information indicating how a data domain (e.g., a data item name) has been de-identified (e.g., represented) or how a data type (e.g., a data type) has been de-identified (e.g., converted from a numerical value to a character value or converted from a numerical value to a numerical range value) by examining a data domain or a data type of the data included in the de-identified data DB (24). A query transformation device (12) according to one embodiment can obtain de-identification policy information (data domain de-identification policy information or data type de-identification policy information) for data of an original data DB (22) stored in a de-identification policy information storage device (16), and obtain the de-identification information using the de-identification policy information.
[0057] According to an embodiment, a processor (620) may obtain a second conditional clause for de-identified data corresponding to the first conditional clause using a first conditional clause and de-identification information. According to an embodiment, a processor (620) may obtain a second query for de-identified data corresponding to the first query using the second conditional clause. According to an embodiment, a processor (620) may obtain correction information for correcting an error between a query processing result using the second conditional clause for de-identified data and a first query processing result for the original data of the de-identified data, and may obtain a second query for de-identified data by applying the second conditional clause and the correction information to the first query. According to an embodiment, the correction information may include information on the probability that the de-identified data is the original data.
[0058] The processor (620) according to one embodiment may provide the acquired second query to the database management device (14). The database management device (14) according to one embodiment may perform second query processing on the de-identified data stored in the de-identified data DB (24) using the second query for the de-identified data. The database management device (14) according to one embodiment may provide (or output) the result of performing the second query (to a data analyst (or an electronic device corresponding to the data analyst)). The processor (620) according to one embodiment may also perform second query processing on the de-identified data directly stored in the de-identified data DB (24) using the acquired second query.
[0059] According to one embodiment, the processor (620) may include a main processor (e.g., a central processing unit or application processor) or an auxiliary processor that can operate independently or in conjunction with the main processor. For example, if the electronic device (601) includes a main processor and an auxiliary processor, the auxiliary processor may be configured to use less power than the main processor or to be specialized for a given function. The auxiliary processor may be implemented separately from the main processor or as part of the main processor.
[0060] According to one embodiment, the auxiliary processor (e.g., a neural network processing unit) may include a hardware structure specialized for processing an artificial intelligence model. The artificial intelligence model may be generated through machine learning. Such learning may be performed, for example, in the electronic device (601) itself on which the artificial intelligence model is executed, or may be performed through a separate server (e.g., a server (not shown)). The learning algorithm may include, for example, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning, but is not limited to the examples described above. The artificial intelligence model may include a plurality of artificial neural network layers. The artificial neural network may be one of a deep neural network (DNN), a convolutional neural network (CNN), a recurrent neural network (RNN), a restricted Boltzmann machine (RBM), a deep belief network (DBN), a bidirectional recurrent deep neural network (BRDNN), a deep Q-network, or a combination of two or more of the above, but is not limited to the examples described above. In addition to, or alternatively to, a hardware structure, an artificial intelligence model may include a software structure.
[0061] The memory (630) according to one embodiment may store various data used by at least one component of the electronic device (601). The data may include, for example, input data or output data for software (e.g., a program) and commands related thereto. The memory (630) according to one embodiment may store instructions set to perform operations corresponding to the query transformation method of the present disclosure when executed by the processor (620). The memory (630) according to one embodiment may include volatile memory or non-volatile memory. The program may be stored as software in the memory (630) and may include, for example, an operating system, middleware, or an application.
[0062] An electronic device (601) according to an embodiment may be configured to include various components (e.g., hardware) other than the interface (610), processor (620), and memory (630). For example, the electronic device (601) may further include an input module, a display, or a communication module, and may further include additional modules for other additional functions.
[0063] An input module according to one embodiment may receive commands or data to be used in a component of the electronic device (601) (e.g., a processor (620)) from an external source (e.g., a user) of the electronic device (601). The input module may include, for example, a microphone, a mouse, a keyboard, keys (e.g., buttons), or a digital pen (e.g., a stylus pen).
[0064] A display module according to one embodiment can visually provide information to an external device (e.g., a user) of an electronic device (601). The display module can include, for example, a display, a holographic device, or a projector and a control circuit for controlling the device. According to one embodiment, the display module can include a touch sensor configured to detect a touch, or a pressure sensor configured to measure the intensity of a force generated by the touch.
[0065] A communication module according to an embodiment may support the establishment of a direct (e.g., wired) communication channel or a wireless communication channel between an electronic device (601) and an external electronic device (e.g., an external database management device (14) or an external anonymized data policy information author device (16)), and performing communication through the established communication channel. The communication module may operate independently from a processor (620) (e.g., a CPU) and may include one or more communication processors that support direct (e.g., wired) communication or wireless communication. According to an embodiment, the communication module may include a wireless communication module (e.g., a cellular communication module, a short-range wireless communication module, or a global navigation satellite system (GNSS) communication module) or a wired communication module (194) (e.g., a local area network (LAN) communication module, or a power line communication module). Any of these communication modules may communicate with an external electronic device via a first network (198) (e.g., a short-range communication network such as Bluetooth, wireless fidelity (WiFi) direct, or infrared data association (IrDA)) or a second network (199) (e.g., a long-range communication network such as a legacy cellular network, a 5G network, a next-generation communication network, the Internet, or a computer network (e.g., a local area network or a wide area network)). These various types of communication modules may be integrated into a single component (e.g., a single chip) or implemented as multiple separate components (e.g., multiple chips). The wireless communication module may identify or authenticate the electronic device (601) within the communication network by using subscriber information stored in the subscriber identification module (e.g., an international mobile subscriber identity (IMSI)).
[0066] A wireless communication module according to an embodiment may support a 5G network and next-generation communication technologies following a 4G network, such as NR access technology (new radio access technology). NR access technology may support high-speed transmission of high-capacity data (eMBB (enhanced mobile broadband)), minimizing terminal power and connecting multiple terminals (mMTC (massive machine type communications)), or high reliability and low latency communications (URLLC (ultra-reliable and low-latency communications)). The wireless communication module (192) may support, for example, a high-frequency band (e.g., mmWave band) to achieve a high data transmission rate. The wireless communication module (192) can support various technologies for securing performance in high frequency bands, such as beamforming, massive multiple-input and multiple-output (MIMO), full dimensional MIMO (FD-MIMO), array antenna, analog beam-forming, or large scale antenna. The wireless communication module can support various requirements specified in the electronic device (601), external electronic device, or network system. According to one embodiment, the wireless communication module (192) can support peak data rate (e.g., 20 Gbps or more) for realizing eMBB, loss coverage (e.g., 164 dB or less) for realizing mMTC, or U-plane latency (e.g., 0.5 ms or less for downlink (DL) and uplink (UL), or 1 ms or less for round trip) for realizing URLLC.
[0067] At least some of the above components can be interconnected and exchange signals (e.g., commands or data) with each other via a communication method between peripheral devices (e.g., a bus, GPIO (general purpose input and output), SPI (serial peripheral interface), or MIPI (mobile industry processor interface)).
[0068] An electronic device (e.g., a query transformation device (14) of FIG. 1 or an electronic device (601) of FIG. 6) according to an embodiment may include an interface (650), a memory (630) storing instructions, and a processor (620) operatively connected to the input / output interface and the memory. The instructions according to an embodiment may be configured to cause the electronic device, when executed by the processor, to receive a first query associated with data analysis for a database through the interface. The instructions may be configured to identify a first conditional clause in the first query. The instructions may be configured to obtain de-identification information for de-identified data of the database. The instructions may be configured to obtain a second conditional clause for the de-identified data corresponding to the first conditional clause using the first conditional clause and the de-identification information. The above instructions may be configured to obtain a second query for the de-identified data corresponding to the first query using the second conditional clause and to provide the obtained second query.
[0069] According to one embodiment, the instructions, when executed by the processor, may further be configured to cause the electronic device to obtain correction information for correcting an error between a query processing result using the second condition clause for the de-identified data and a first query processing result for the original data. The instructions may further be configured to obtain a second query for the de-identified data by applying the second condition clause and the correction information to the first query.
[0070] According to one embodiment, the correction information can be obtained using the probability that the de-identified data is the original data.
[0071] According to one embodiment, the first query may be a structured query language.
[0072] The first query according to one embodiment may include a command associated with data retrieval.
[0073] According to one embodiment, the first query may include a select command or a select count command, and the first condition clause may include a where condition clause.
[0074] The instructions according to one embodiment may further be configured to cause the electronic device, when executed by the processor, to analyze data included in the database to obtain the de-identified information.
[0075] The instructions according to one embodiment may be further configured to cause the electronic device, when executed by the processor, to obtain de-identification policy information of the database and to obtain the de-identification information using the de-identification policy information.
[0076] The instructions according to one embodiment may be further configured to, when executed by the processor, cause the electronic device to identify one of a data operation type that is a complete match, a data operation type that is a probabilistic match, and a data operation type that is a partial match when the first query is received. The instructions may be further configured to perform a data operation corresponding to the first query based on the identified data operation type.
[0077] The instructions according to one embodiment may further be configured to cause the electronic device, when executed by the processor, to perform a second query on the database using the second query.
[0078] Figure 7 is a diagram illustrating a query transformation operation according to one embodiment.
[0079] Referring to FIG. 7, a processor (620) of an electronic device (e.g., a query conversion device (12) of FIG. 1 or an electronic device (601) of FIG. 6) according to one embodiment may perform at least one of operations 710 to 750.
[0080] In operation 710, a processor (620) according to an embodiment may receive a first query (e.g., a query based on original data) related to database data analysis. The first query according to an embodiment may be a structured query language. The first query according to an embodiment may include a command related to data retrieval (or selection or extraction). The first query according to an embodiment may include a select command or a select count command. For example, the select command may be a command to retrieve (or select or extract) at least some data from a database, and the select count command may be a command to count the number of retrieved data after retrieving (or selecting or extracting) at least some data from the database.
[0081] In operation 720, the processor (620) according to an embodiment may identify a first condition clause in the received first query. The first condition clause according to an embodiment may include a where condition clause. For example, the where condition clause may include a conditional expression indicating a condition corresponding to a command. For example, the where condition clause may be configured to include logical operators such as = (equal), > (greater than), < (less than), >= (greater than or equal to), <= (less than or equal to), <> or != (not equal to), BETWEEN (between a range of values), LIKE (search for a pattern), and / or IN (search for multiple values).
[0082] In operation 730, the processor (620) according to one embodiment can obtain de-identification information for data in a database (e.g., de-identified data DB (24)). The processor (620) according to one embodiment can obtain de-identification information by analyzing data included in the de-identified data DB (24). The processor (620) according to one embodiment can examine a data domain or a data type of data included in the de-identified data DB (24) to obtain de-identification information indicating how a data domain (e.g., a data item name) has been de-identified (e.g., represented) or how a data type (e.g., a data type) has been de-identified (e.g., converted from a numerical value to a character value or converted from a numerical value to a numerical range value). A query transformation device (12) according to one embodiment can obtain de-identification policy information (data domain de-identification policy information or data type de-identification policy information) for data of an original data DB (22) stored in a de-identification policy information storage device (16), and obtain the de-identification information using the de-identification policy information.
[0083] In operation 740, a processor (620) according to an embodiment may obtain a second conditional clause for de-identified data corresponding to the first conditional clause using the first conditional clause and de-identified information.
[0084] In operation 750, the processor (620) according to an embodiment may obtain a second query for de-identified data corresponding to the first query using a second condition clause and provide the obtained second query. The processor (620) according to an embodiment may obtain correction information for correcting an error between a query processing result using the second condition clause for the de-identified data and a first query processing result for the original data of the de-identified data, and may obtain a second query for the de-identified data by applying the second condition clause and the correction information to the first query. The correction information according to an embodiment may include probability information that the de-identified data is the original data. The processor (620) according to an embodiment may provide the obtained second query to the database management device (14). The database management device (14) according to an embodiment may perform a second query processing on the de-identified data stored in the de-identified data DB (24) using the second query for the de-identified data. A database management device (14) according to one embodiment may provide (or output) a second query execution result (to a data analyst (or an electronic device corresponding to a data analyst)). A processor (620) according to one embodiment may perform a second query process on de-identified data directly stored in a de-identified data DB (24) using the acquired second query and provide a second query processing execution result.
[0085] According to an embodiment, a query transformation method for processing de-identified data in an electronic device (e.g., the query transformation device (12) of FIG. 1 or the electronic device (601) of FIG. 6) may include an operation of receiving a first query for a database. The method may include an operation of identifying a first conditional clause in the first query. The method may include an operation of obtaining de-identification information for de-identified data of the database. The method may include an operation of obtaining a second conditional clause for the de-identified data corresponding to the first conditional clause using the first conditional clause and the de-identification information. The method may include an operation of obtaining a second query for the de-identified data corresponding to the first query using the second conditional clause. The method may include an operation of providing the second query or performing a second query for the database using the second query.
[0086] According to one embodiment, the method may further include an operation of obtaining correction information for correcting an error between a query processing result using the second condition clause for the de-identified data and a first query processing result for the original data. The method may further include an operation of obtaining a second query for the de-identified data by applying the second condition clause and the correction information to the first query.
[0087] In the method according to one embodiment, the correction information may be information obtained using the probability that the de-identified data is the original data.
[0088] In the method according to one embodiment, the first query may be a structured query language.
[0089] In the method according to one embodiment, the first query may include a command associated with data retrieval.
[0090] In the method according to one embodiment, the first query may include a select command or a select count command, and the first condition clause may include a where condition clause.
[0091] The method according to one embodiment may further include an operation of analyzing data included in the database to obtain the de-identified information.
[0092] According to one embodiment, the method may further include an operation of obtaining anonymization policy information of the database. The method may further include an operation of obtaining the anonymization information using the anonymization policy information.
[0093] According to one embodiment, the method may further include an operation of identifying one of a data operation type that is a complete match, a data operation type that is a probabilistic match, and a data operation type that is a partial match when the first query is received. The method may further include an operation of performing a data operation corresponding to the first query based on the identified data operation type.
[0094] FIG. 8 is a diagram illustrating an example of obtaining a second condition clause for de-identified data corresponding to the first condition clause by using the first condition clause of the first query and de-identified information of the database according to one embodiment.
[0095] Referring to FIG. 8, a processor (630) according to an embodiment may receive a first query (810). For example, the first query (810) may be a query based on original data and may include "SELECT COUNT(*) FROM original_adult WHERE age=30." The processor (630) according to an embodiment may identify a first conditional clause (812) in the first query (810). The first conditional clause (812) according to an embodiment may include a where conditional clause. For example, the where conditional clause may include a conditional expression indicating a condition corresponding to a command. For example, the where conditional clause may be configured to include logical operators such as = (equal), > (greater than), < (less than), >= (greater than or equal to), <= (less than or equal to), <> or != (not equal to), BETWEEN (between a range of values), LIKE (search for a pattern), and / or IN (search for multiple values). The processor (630) may identify “WHERE age=30” as the first conditional clause (812) in the first query (810). The processor (620) according to one embodiment may obtain de-identified information for age data (804) of a database (e.g., de-identified data DB (24)). According to one embodiment, the processor (620) may analyze age data (804) to obtain de-identification information or obtain de-identification policy information for original data from a separate de-identification policy information storage device (e.g., de-identification policy information storage device (16)) and obtain de-identification information using the de-identification policy information.For example, the processor (620) may obtain de-identification information indicating that an integer of the age data (804) has been converted into a string having a range that includes the integer.
[0096] According to an embodiment, a processor (620) may obtain a second conditional clause (814) for de-identified data corresponding to the first conditional clause (812) using the first conditional clause (812) and de-identified information. According to an embodiment, the processor (620) may obtain conditions "age=[26, 30], age=[21, 30], age=[21, 40],*" that have a probability of corresponding to the "age=30" condition according to the de-identified information from "WHERE age=30" corresponding to the first conditional clause (812), and may obtain a second conditional clause (814) including conditions that have a probability of corresponding to the "age=30" condition. The second conditional clause (814) is a condition that has a probability of being equivalent to the "age=30" condition, and may not exactly match the "age=30" condition. Therefore, there may be an error in the result of the first query processing on the original data, and correction may be required.
[0097] FIG. 9 is a diagram illustrating an example of obtaining correction information for correcting an error caused by a second conditional clause for anonymized data according to one embodiment.
[0098] Referring to FIG. 9, a processor (620) according to one embodiment can obtain correction information by using the probability that the “age=30” condition may correspond to each of the conditions (910, 920) that may correspond to the “age=30” condition.
[0099] For example, the processor (620) according to one embodiment may obtain correction information to determine the probability that 30 exists between 21 and 30 (e.g., the probability value that 30 will be counted) for the [21, 30] condition (910) as 1 / 10 and to multiply the obtained count value (30 years old = p1 (people)) for the [21, 30] condition (910) by 1 / 10. The processor (620) according to one embodiment may obtain correction information to determine the probability that 30 exists between 21 and 40 (e.g., the probability value that 30 will be counted) for the [21, 40] condition (920) as 1 / 20 and to multiply the obtained count value (30 years old = p2 (people)) for the [21, 40] condition (920) by 1 / 20.
[0100] As another example, a processor (620) according to one embodiment may obtain correction information to determine a probability of a population of 30 years old between the ages of 21 and 30 in the age-specific population distribution (e.g., the percentage of the population of 30 years old between the ages of 21 and 30 in the age-specific population distribution, which may vary depending on the population distribution) using a previously investigated (or acquired) age-specific population distribution for a [21, 30] condition (910), and multiply the probability of a population of 30 years old between the ages of 21 and 30 by the probability of a population of 30 years old between the ages of 21 and 30 in the age-specific population distribution for a [21, 30] condition (910). In one embodiment, a processor (620) may obtain correction information to determine the number of people aged 30 between the ages of 21 and 40 using the age-based population distribution for the [21, 40] condition (920) (e.g., the percentage of the population aged 30 between the ages of 21 and 40 in the age-based population distribution, which may vary depending on the population distribution), and multiply the probability of the number of people aged 30 between the ages of 21 and 40 for the [21, 40] condition (920).
[0101] FIG. 10 is a diagram illustrating an example of obtaining a second query for de-identified data using a second condition clause and correction information according to one embodiment.
[0102] Referring to FIG. 10, a processor (620) according to one embodiment can obtain a second query for non-identifiable data by applying the conditions of the second condition clause (814) (e.g., “age=[26, 30], age=[21, 30], age=[21, 40], *”) and the counting probability values for each condition. According to an embodiment, the processor (620) may identify a probability of 1 / 5 corresponding to the condition of "age=30" in response to the condition of "age=[26, 30]", a probability of 1 / 10 corresponding to the condition of "age=30" in response to the condition of "age=[21, 30]", a probability of 1 / 20 corresponding to the condition of "age=30" in response to the condition of "age=[21, 40]", and a probability of 1 / 120 corresponding to the condition of "age=30" in response to the condition of "*", and may obtain a second query (1010) by applying the second condition clause (814) and the probabilities. For example, the second query (1010) may be obtained as shown in Table 1 below.
[0103] SELECT(SELECT COUNT(*)FROM anonymized_adultWHERE age= '30')*1 +(SELECT COUNT(*)FROM anonymized_adultWHERE age= '[26, 30]')*1.0 / 5 +(SELECT COUNT(*)FROM anonymized_adultWHERE age= '[21, 30]')*1.0 / 10 +(SELECT COUNT(*)FROM anonymized_adultWHERE age= '[21, 40]')*1.0 / 20 +(SELECT COUNT(*)FROM anonymized_adultWHERE age= '*')*1.0 / 120AS total_count
[0104] A processor (620) according to an embodiment may provide a second query (1010) as in Table 1 to a database management device (14). The second query (1010) of Table 1 is merely an example, and various other queries may be obtained depending on the command and condition contents. A database management device (14) according to an embodiment may perform second query processing on de-identified data stored in a de-identified data DB (24) using the second query (1010) for de-identified data. A database management device (14) according to an embodiment may provide (or output) a second query execution result (1020) (to a data analyst (or an electronic device corresponding to a data analyst)). According to one embodiment, the processor (620) may perform second query processing on de-identified data stored in the de-identified data DB (24) using the acquired second query (1010) and provide a second query processing result (1020). The error between the result (1020) of performing the second query processing on the de-identified data according to one embodiment and the result (1010) of performing the first query processing on the original data may be approximately 4%, which may be significantly lower than the error of 438% resulting from the result (1002) of performing the query processing by replacing the first condition clause (812) with the second condition clause (814) in the first query (810) on the de-identified data. The processor (620) according to one embodiment may select whether to convert the first query (810) into a second query (1010) when receiving the first query (810), and may perform a query conversion operation if the first query is to be converted into the second query (1010) and used, and may not perform the query conversion operation if the second query (1010) is to be used.According to one embodiment, the processor (620) may select one of a query processing mode based on completely matched data, a query processing mode based on probabilistically matched data, or a query processing mode based on partially matched data when receiving a first query (810), and may process the first query (810) or the second query (1010) based on the selected query processing mode.
[0105] FIG. 11 is a diagram illustrating an operation for obtaining query results according to a query processing mode when receiving a first query according to one embodiment.
[0106] Referring to FIG. 11, a processor (620) of an electronic device (e.g., a query conversion device (12) of FIG. 1 or an electronic device (601) of FIG. 6) according to an embodiment may perform at least one of operations 1110 to 1142.
[0107] In operation 1110, a processor (620) according to an embodiment may receive a first query (e.g., a query based on original data) related to database data analysis. The first query according to an embodiment may be a structured query language. The first query according to an embodiment may include a command related to data retrieval (or selection or extraction). The first query according to an embodiment may include a select command or a select count command. For example, the select command may be a command to retrieve (or select or extract) at least some data from a database, and the select count command may be a command to retrieve (or select or extract) at least some data from the database and then count the number of retrieved data.
[0108] In operation 1120, the processor (620) according to one embodiment can identify whether the query processing mode is a fully matched data-based query processing mode based on the reception of the first query.
[0109] In operation 1122, the processor (620) according to one embodiment may obtain a data result value that completely matches the first query regardless of whether the data is anonymized when in a query processing mode based on data that completely matches. For example, the processor (620) may obtain a false value as a result value when issuing a command to search for age data of 23 years old for age data in the range of 20-29 years old, and may obtain a false value as a result value when issuing a command to search for male gender for data representing all genders.
[0110] In operation 1130, the processor (620) according to one embodiment can identify whether the query processing mode is a probabilistically matching data-based mode based on the reception of the first query.
[0111] In operation 1132, the processor (620) according to one embodiment may obtain a second query for de-identified data corresponding to the first query by using the first condition clause of the first query and de-identified information about data in the database in a probabilistically matched data-based query processing mode.
[0112] In operation 1134, the processor (620) according to one embodiment may obtain a data result value that probabilistically matches the first query by using the second query. For example, when a command to search for age data of 23 years old is issued for age data in the range of 20-29 years old, the processor (620) may reflect a probability value (e.g., 1 / 10) that a 23-year-old exists in the data value of the range of 20-29 years old as a result value, and when a command to search for male gender is issued for data representing all genders, the processor (620) may reflect a probability value (e.g., 0.512) that a male exists in all genders as a result value.
[0113] In operation 1140, the processor (620) according to one embodiment may identify whether the query processing mode is a partially matching data-based mode based on the reception of the first query.
[0114] In operation 1142, the processor (620) according to one embodiment may obtain data result values that match or are likely to match the first query, regardless of whether the data is anonymized, in a query processing mode based on partially matching data. For example, the processor (620) may obtain a true value as a result value when issuing a command to search for age data of 23 years old for age data in the range of 20-29 years old, and may obtain a true value as a result value when issuing a command to search for male gender for data representing all genders.
[0115] Electronic devices according to various embodiments disclosed in this document may take various forms. Electronic devices may include, for example, portable communication devices (e.g., smartphones), computer devices, portable multimedia devices, portable medical devices, cameras, wearable devices, or home appliances. Electronic devices according to embodiments of the present disclosure are not limited to the aforementioned devices.
[0116] The various embodiments of the present disclosure and the terminology used therein are not intended to limit the technical features described in this document to specific embodiments, but should be understood to include various modifications, equivalents, or substitutes of the embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar or related components. The singular form of a noun corresponding to an item may include one or more of the items, unless the context clearly indicates otherwise. In this document, each of the phrases "A or B," "at least one of A and B," "at least one of A or B," "A, B, or C," "at least one of A, B, and C," and "at least one of A, B, or C" can include any one of the items listed together in the corresponding phrase among those phrases, or all possible combinations thereof. Terms such as "first," "second," or "first" or "second" may be used merely to distinguish one component from another, and do not limit the components in any other respect (e.g., importance or order). When a component (e.g., a first component) is referred to as "coupled" or "connected" to another (e.g., a second component), with or without the terms "functionally" or "communicatively," it means that the component can be connected to the other component directly (e.g., wired), wirelessly, or through a third component.
[0117] The term "module" as used herein may include a unit implemented in hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be an integral component, or a minimum unit or part of such a component that performs one or more functions. For example, according to one embodiment, a module may be implemented in the form of an application-specific integrated circuit (ASIC).
[0118] Various embodiments of the present disclosure may be implemented as software (e.g., a program (140)) including one or more commands stored in a storage medium (e.g., an internal memory (136) or an external memory (138)) readable by a machine (e.g., an electronic device (101)). For example, a processor (e.g., a processor (120)) of the machine (e.g., an electronic device (101)) may call at least one command among the one or more commands stored from the storage medium and execute it. This enables the machine to operate to perform at least one function according to the at least one command called. The one or more commands may include code generated by a compiler or code executable by an interpreter. The machine-readable storage medium may be provided in the form of a non-transitory storage medium. Here, 'non-transitory' simply means that the storage medium is a tangible device and does not contain signals (e.g., electromagnetic waves), and the term does not distinguish between cases where data is stored semi-permanently or temporarily on the storage medium.
[0119] According to one embodiment, the method according to the various embodiments disclosed in the present document may be provided as included in a computer program product. The computer program product may be traded as a product between a seller and a buyer. The computer program product may be distributed in the form of a machine-readable storage medium (e.g., compact disc read only memory (CD-ROM)), or may be distributed online (e.g., downloaded or uploaded) via an application store (e.g., Play Store™) or directly between two user devices (e.g., smartphones). In the case of online distribution, at least a portion of the computer program product may be temporarily stored or temporarily generated in a machine-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or an intermediary server.
[0120] According to various embodiments, each component (e.g., a module or a program) of the above-described components may include a single or multiple entities. According to various embodiments, one or more components or operations of the aforementioned components may be omitted, or one or more other components or operations may be added. Alternatively or additionally, a plurality of components (e.g., a module or a program) may be integrated into a single component. In such a case, the integrated component may perform one or more functions of each of the plurality of components identically or similarly to those performed by the corresponding component among the plurality of components prior to the integration. According to various embodiments, the operations performed by a module, program, or other component may be executed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations may be executed in a different order, omitted, or one or more other operations may be added.
[0121] According to one embodiment, a non-transitory storage medium storing commands is provided, wherein the commands, when executed by an electronic device, are configured to cause the electronic device to perform at least one operation, wherein the at least one operation may include: receiving a first query for a database; identifying a first conditional clause in the first query; obtaining de-identification information for de-identified data of the database; obtaining a second conditional clause for the de-identified data corresponding to the first conditional clause using the first conditional clause and the de-identification information; obtaining a second query for the de-identified data corresponding to the first query using the second conditional clause; and providing the second query or performing a second query for the database using the second query.
[0122] And the embodiments of the present invention disclosed in this specification and drawings are merely specific examples presented to easily explain the technical contents according to the embodiments of the present invention and to help understand the embodiments of the present invention, and are not intended to limit the scope of the embodiments of the present invention. Therefore, the scope of the various embodiments of the present invention should be interpreted as including all changes or modified forms derived based on the technical idea of the various embodiments of the present invention in addition to the embodiments invented herein.
Claims
1. In the electronic device (12, 601), interface (650); Memory (630) for storing instructions; and A processor (620) operatively connected to the interface and the memory, The above instructions, when individually or collectively executed by the at least one processor, cause the electronic device to: Receive a first query related to data analysis on a database through the above interface, Identify the first conditional clause in the first query above, Obtaining de-identified information about de-identified data in the above database, Obtaining a second condition for the de-identified data corresponding to the first condition using the first condition and the de-identified information, and An electronic device that obtains a second query for the de-identified data corresponding to the first query using the second condition clause and provides the obtained second query.
2. In paragraph 1, The above instructions, when individually or collectively executed by the at least one processor, cause the electronic device to: Obtaining correction information for correcting errors between the query processing result using the second condition clause for the de-identified data and the first query processing result for the original data, and An electronic device that obtains a second query for the de-identified data by applying a second condition and the correction information to the first query.
3. In paragraph 2, The above correction information is an electronic device obtained by using the probability that the anonymized data is the original data.
4. In paragraph 1, An electronic device wherein the first query comprises a structured query language or a command associated with data retrieval.
5. In paragraph 4, An electronic device wherein the first query includes a select command or a select count command, and the first condition clause includes a where condition clause.
6. In paragraph 1, The above instructions, when individually or collectively executed by the at least one processor, cause the electronic device to: An electronic device that analyzes data included in the database to obtain the de-identified information, obtains de-identified policy information of the database, and obtains the de-identified information using the de-identified policy information.
7. In paragraph 1, The above instructions, when individually or collectively executed by the at least one processor, cause the electronic device to: When receiving the first query, identify one of the data operation types among the fully matching data operation types, the probabilistically matching data operation types, and the partially matching data operation types, and An electronic device that performs a data operation corresponding to the first query based on the identified data operation type.
8. In paragraph 1, The above instructions, when individually or collectively executed by the at least one processor, cause the electronic device to: An electronic device that performs a second query on the database using the second query.
9. In a query transformation method for processing non-identifiable data in an electronic device (12, 601), The action of receiving a first query to a database; An action of identifying a first conditional clause in the first query; An action to obtain de-identified information about de-identified data of the above database; An operation of obtaining a second conditional clause for the de-identified data corresponding to the first conditional clause using the first conditional clause and the de-identified information; An operation of obtaining a second query for the de-identified data corresponding to the first query using the second condition clause; and A method comprising providing the second query or performing a second query on the database using the second query.
10. In paragraph 9, An operation of obtaining correction information for correcting an error between the query processing result using the second condition clause for the de-identified data and the first query processing result for the original data; and A method further comprising an action of obtaining a second query for the de-identified data by applying the second condition clause and the correction information to the first query.
11. In paragraph 10, The above correction information is a method in which information is obtained by using the probability that the de-identified data is the original data.
12. In paragraph 9, A method wherein the first query comprises a structured query language or a command associated with data retrieval.
13. In paragraph 9, A method further comprising an action of obtaining the de-identified information by analyzing data included in the database or obtaining the de-identified information by using the de-identification policy information.
14. In paragraph 9, An operation for identifying one of a data operation type that is a complete match, a probabilistic match, and a partial match when receiving the first query; and A method further comprising an action of performing a data operation corresponding to the first query based on the identified data operation type.
15. In a non-transitory storage medium storing commands, The above commands, when executed by an electronic device, are configured to cause the electronic device to perform at least one action, wherein the at least one action is: The action of receiving a first query to a database; An action of identifying a first conditional clause in the first query; An action to obtain de-identified information about de-identified data of the above database; An operation of obtaining a second conditional clause for the de-identified data corresponding to the first conditional clause using the first conditional clause and the de-identified information; An operation of obtaining a second query for the de-identified data corresponding to the first query using the second condition clause; and A storage medium comprising an operation of providing the second query or performing a second query on the database using the second query.
Citation Information
Patent Citations
Query Transformation for Masking Data Within Database Objects
US20130086088A1
Access control for nested data fields
US20190155794A1
Data management method and registration method for an anonymous data sharing system, as well as data manager and anonymous data sharing system
US20190213356A1
Dynamically Inserting Guard Conditions into a Database Query to Protect Privacy and Confidentiality and Prevent Data Leak
US20240078333A1
Enforcing Data Access Policies at a Database Client Interface to Protect Privacy and Confidentiality and Prevent Data Leak
US20240086566A1