System and method for analyzing confidential data
Abstract
The invention related to system and method for analyzing confidential data. Firstly, a first key is used to obtain a first analysis authorization for proceeding a first analysis responsive to an operational model in an encrypted cloud space with a connection of a network. Then, the result of the first analysis is verified. While the verifying of the operational model is pass, a second key is used to obtain a second analysis authorization for proceeding a second analysis responsive to an operational model without the connection of the network. Thereby, the cloud technique for analyzing data can be applied for analyzing confidential data.

Term
No projected expiry on record.
- Priority and filed
- Published
- Today
9 claims: 2 independent, 7 dependent
- 1A method for analyzing sensitive data, which is applied to a cloud host for sub-authorization according to a corresponding first key and a second key, the steps comprising:inputting the first key to the cloud host to obtain a first analysis authorization;A client device is connected to the cloud host and reads a plurality of first data and an operation model into an encrypted cloud space of the cloud host;The cloud host performs a first analysis on the first data according to the operation model to obtain a first analysis result;uploading the first analysis result to the cloud host for verification;When the first analysis result is verified, input the second key into the cloud host to obtain a second analysis authorization;the client device reads the plurality of second data to the encrypted cloud space;and The cloud host performs a second analysis on the second data in the encrypted cloud space according to the operation model to obtain a second analysis result. 一種機敏資料之分析方法,其應用於一雲端主機依據對應之一第一金鑰與一第二金鑰分段授權,步驟包含: 將該第一金鑰輸入至該雲端主機,以取得一第一分析授權; 一用戶端裝置連接至該雲端主機並將複數個第一資料與一運算模型讀取至該雲端主機之一加密雲端空間中; 該雲端主機依據該運算模型對該些個第一資料進行一第一分析而取得一第一分析結果; 上傳該第一分析結果至該雲端主機並進行驗證; 當該第一分析結果驗證通過時,將該第二金鑰輸入該雲端主機,以取得一第二分析授權; 該用戶端裝置將複數個第二資料讀取至該加密雲端空間;以及 該雲端主機依據該運算模型對該些個第二資料在該加密雲端空間中進行一第二分析而取得一第二分析結果。
- 5An analysis system for sensitive data, comprising:at least one encrypted storage unit, storing a plurality of first data and a plurality of second data;a cloud host connected to the at least one encrypted cloud space;and A client device, connected to the cloud host, transmits a first key and a second key to the cloud host respectively, the cloud host sends a first analysis authorization to the client device according to the first key, the The cloud host sends a second analysis authorization to the client device according to the second key, and the client device transmits a plurality of first data and an operation model to the encrypted cloud space according to the first analysis authorization, and the cloud host Performing a first analysis on the first data according to the operation model to obtain a first analysis result, the client device transmits the plurality of second data to the encrypted cloud space according to the second analysis authorization, and the cloud host A second analysis is performed on the plurality of second data according to the operation model to obtain a second analysis result, the cloud host is connected to a network when the first analysis is performed, and the cloud host is disconnected when the second analysis is performed The network, the second data are closed encrypted data. 一種機敏資料之分析系統,其包含: 至少一加密儲存單元,儲存複數個第一資料與複數個第二資料; 一雲端主機,連接該至少一加密雲端空間;以及 一用戶端裝置,連接該雲端主機,分別傳送一第一金鑰與一第二金鑰至該雲端主機,該雲端主機依據該第一金鑰發送一第一分析授權至該用戶端裝置,該雲端主機依據該第二金鑰發送一第二分析授權至該用戶端裝置,該用戶端裝置依據該第一分析授權將複數個第一資料與一運算模型傳送至該加密雲端空間,該雲端主機依據該運算模型對該些個第一資料進行一第一分析而取得一第一分析結果,該用戶端裝置依據該第二分析授權將複數個第二資料傳送至該加密雲端空間,該雲端主機依據該運算模型對該些個第二資料進行一第二分析而取得一第二分析結果,該雲端主機於執行該第一分析時連接一網路,該雲端主機執行該第二分析時斷開該網路,該些個第二資料為封閉加密資料。
Independent claims2
51 paragraphs, as filed
Analysis method and system for sensitive data
System And Method For Analyzing Confidential Data
The present invention relates to an analysis system and method, especially an analysis method and system for sensitive data, which provides a cloud platform to analyze sensitive data with data integrity, confidentiality and privacy, and provides a reliable comparison High analysis results.
Generally speaking, the industry trend is the part that each large enterprise will evaluate in the business development, so the data analyst needs to analyze the data from various aspects, but the analyzed data will inevitably have agile data, so the data analyst will Data analysis is carried out in restricted places. Data analysis files often have many different types or attributes, such as: financial data analysis, manufacturing output analysis, personal income analysis, etc. Data analysts will use computational models to analyze data. Obtain the meaningful outline of the data, for example: count the number of occurrences of attribute value A every day, count the number of times that a certain field value is greater than the set value every day...etc.
Furthermore, in recent years, due to the development of Internet technology, people often provide their personal information to second or third parties whether they are working, studying, shopping, or participating in clubs, etc., but often due to people's negligence. , accidentally leaking these personal data to the outside world endangers the so-called personal information security problem, so it emphasizes the protection of personal information. In order to avoid the loss of the rights and interests of the company and people due to the leakage of personal information, the enterprise will establish a personal information protection mechanism from the inside of the system, such as the current ISO certification, etc. Lay the foundation for all personal data protection efforts. In addition, in order to strengthen personal information security and protect confidential information within the enterprise, preventing the leakage of sensitive information has become an important information security protection work for enterprises.
However, the current data analysis technology is to use hardware devices to prevent the leakage of sensitive data, thus restricting data analysts and data providers from providing data or performing data analysis due to the limitations of hardware devices and the location of the hardware devices. , so that the provision of data or data analysis is limited to the same hardware device location. Although cloud computing technology and big data analysis are more developed today, analysis involving sensitive data still cannot be performed on the cloud computing platform.
Based on the above problems, the present invention provides a method and system for analyzing sensitive data, which uses different keys to perform segmented authorization on a cloud host, and allows users to perform segmental analysis on the cloud, so as to utilize the first authorization of the initial authorization. The first analysis verifies whether the analysis is complete, and then the authorized second analysis obtains the formal analysis result.
The main purpose of the present invention is to provide a method and system for analyzing agile data, which control the cloud host to perform analysis in different authorization analysis processes with different degrees of authorization, so as to improve data security, and can be applied to the analysis of agile data .
The present invention discloses a method for analyzing sensitive data, which is used for a cloud host to authorize by segments according to a corresponding first key and a second key to analyze data in different authorization stages. The first key is input into the cloud host to obtain a first analysis authorization; then a client device transmits a plurality of first data and an operation model to an encrypted cloud space of the cloud host according to the first analysis authorization, the The cloud host performs a first analysis on the first data according to the operation model to obtain a first analysis result; then, verifies the first analysis result; when the first analysis result is verified, the second gold Enter the key into the cloud host to obtain a second analysis authorization; then the client device transmits a plurality of second data to the encrypted cloud space according to the second analysis authorization, and the cloud host analyzes these first data according to the operation model. A second analysis is performed on the two data to obtain a second analysis result. In this way, the present invention allows the cloud host to perform the first analysis under the authorization of the first key, and verify the analysis result, so as to avoid failure in the formal analysis, and make the analysis under the authorization of the second key. The cloud host performs the second analysis of the formal analysis stage when the network is disconnected, and the security of the formal analysis is improved for the analysis of the sensitive data. In this way, the cloud computing technology can be used for the analysis of the sensitive data.
The present invention provides an embodiment, wherein after the second analysis is performed to obtain a second analysis result, a third key is further input into the cloud host to obtain an analysis output authorization, which is then used by the cloud host according to The analysis output authorization outputs the second analysis result as a second analysis data.
The present invention provides an embodiment, wherein in the step of obtaining an analysis output authorization of the cloud host according to a third key, the cloud host further confirms the analysis output authorization according to the authorization provided by one of the second data, to Continue to the next step.
The present invention provides an embodiment, wherein before the step of obtaining a first analysis authorization of the cloud host according to the first key, the cloud host first receives a plurality of initial data of a large data database; The initial data are de-identified to generate the corresponding second data; and the cloud host randomly samples according to the format of the second data to generate the corresponding first data.
The present invention further discloses an analysis system for sensitive data, which includes at least one encrypted storage unit, a cloud host and a client device. connecting the at least one encrypted cloud space, wherein the at least one encrypted cloud space stores a plurality of first data and a plurality of second data; and the cloud host provides a first analysis authorization to the client device according to the first key , the cloud host provides a second analysis authorization to the client device according to the second key, the client device transmits a plurality of first data and an operation model to the encrypted cloud space according to the first analysis authorization, the The cloud host performs a first analysis according to an operation model to obtain a first analysis result, the client device transmits a plurality of second data to the encrypted cloud space according to the second analysis authorization, and the cloud host performs the operation according to the operation model. A second analysis is performed to obtain a second analysis result, the cloud host is connected to a network when the first analysis is performed, and the cloud host is disconnected from the network when the second analysis is performed. In this way, the first analysis for testing purposes can be verified through the segmentation authorization, so the second analysis of the formal analysis is further performed after the verification is completed, so as to apply the smart data analysis to the cloud technology.
The present invention provides another embodiment, wherein the client device further uploads a third key to the cloud host, the cloud host provides an analysis output authorization according to the third key, and the cloud host according to the analysis output authorization The second analysis result is output as a second analysis data.
The present invention provides another embodiment, wherein the cloud host further confirms the analysis output authorization according to one of the second data, so as to output the second analysis result as the second analysis data.
The present invention provides another embodiment, wherein the client device further uploads a third key to the cloud host, and the cloud host provides an analysis output authorization according to one of the second data and the third key , the cloud host outputs the second analysis result as a second analysis data according to the analysis output authorization.
The present invention provides another embodiment, wherein the cloud host is further connected to a data capture device, the data capture device captures a plurality of initial data of a large data database to the at least one encrypted cloud space, and the cloud host The initial data are de-identified to generate the corresponding second data and stored in the at least one encrypted cloud space. The cloud host randomly samples the first data according to the second data and stores the first data in the the at least one encrypted cloud space; the cloud host stores the second analysis result in the at least one encrypted cloud space.
In order to enable your examiners to have a further understanding and understanding of the features of the present invention and the effects achieved, I would like to add examples and explanations as follows:
In view of the problem that conventional smart data analysis cannot be applied to cloud technology, the present invention proposes a method and system for analyzing smart data to solve the problem that conventional smart data analysis cannot be applied to cloud technology.
Hereinafter, the present invention will further describe the characteristics and matching structures of an analysis method for sensitive data and its system:
First, please refer to FIG. 1 A, which is a flowchart of an embodiment of the present invention. As shown in the figure, the analytical method of the sensitive data of the present invention, its steps comprise:
Step S100: Input the first key into the cloud host to obtain the first analysis authorization;
Step S110: Send the first data and the computing model to the encrypted cloud space;
Step S115: the cloud host performs a first analysis on the first data according to the computing model to obtain a first analysis result;
Step S120: whether the first analysis result verification is passed;
Step S130: Input the second key into the cloud host to obtain the second analysis authorization;
Step S140: Send the second data to the encrypted cloud space; and
Step S145: The cloud host performs a second analysis on the second data according to the operation model to obtain a second analysis result.
Please refer to the second figure A to the second figure C together, which are schematic diagrams of steps of an embodiment of the present invention. The smart data analysis system 1 of the present invention includes at least one encrypted storage unit 10 and a cloud host 20, the cloud host 20 is connected to the encrypted storage unit 10, and the encrypted storage unit 10 stores a plurality of first data D1 and a plurality of first data D1 For the second data D2, the cloud host 20 is provided with an encrypted cloud space 22, and the cloud host 20 corresponds to a first key KEY1 and a second key KEY2. In this embodiment, a single encrypted storage unit 10 is used as an example. In addition, the cloud host 20 can be further connected to a data acquisition device 30 to connect to a large data database 40 .
In step S100, the user uses a client device 50 to connect to the cloud host 20, so that the cloud host 20 receives the first key KEY1 input from the user, thus obtains a first analysis authorization A1, and continues to execute Step S110. In step S110, the cloud host 20 reads the pieces of the first data D1 in the encrypted storage unit 10 to the encrypted cloud space 22 according to the first analysis authorization A1, so step S115 is then executed to allow the cloud host 20 to store the encrypted cloud space in the encrypted cloud space 22. In 22, a first analysis A11 is performed on the first data D1 according to the calculation model M, thereby obtaining a first analysis result R1, wherein the cloud host 20 is connected when executing the first analysis A11 in the encrypted cloud space 22 A network NET, whereby the calculation model M is further set through the network NET, and since the calculation model M corresponds to the artificial neural network road algorithm (for example: Graph Neural Networks (GNN), Convolutional Neural Networks (CNN)), so the encrypted cloud space 22 will train the calculation model M when the first analysis A11 is performed; continue in step S120 In the above, the cloud host 20 verifies the first analysis result R1 according to the verification rule corresponding to the calculation model M. When the verification result is successful, the step S130 is executed. When the verification result is a failure, the step S115 is executed. The modified calculation model M performs the first analysis A11 again. In step S130, the cloud host 20 receives the second key KEY2 input from the user, and thus obtains a second analysis authorization A2, and then proceeds to step S140.
Continuing the above, in step S140, the cloud host 20 reads the second data D2 in the encrypted storage unit 10 to the encrypted cloud space 22, so that the cloud host 20 in the encrypted cloud space 22 according to the calculation model M to the encrypted cloud space 22 Some pieces of the second data D2 perform a second analysis A21, thereby obtaining a second analysis result R2, wherein the cloud host 20 disconnects the network NET when the second analysis A21 is performed, and the pieces of the second data D2 In order to close the encrypted data, that is, even if the second data D2 is downloaded, it cannot be directly read and displayed. Therefore, when the second data D2 are sensitive data, the cloud host 20 performs the second analysis. Data cannot be leaked during A21, thus improving data security during cloud data analysis. Furthermore, since the cloud host 20 can further destroy the encrypted cloud space 22 after the second analysis result R2 is generated, the data security is improved.
Referring back to Figure A, the method for analyzing sensitive data of the present invention, the steps further include:
Step S150: Input the third key into the cloud host to obtain the analysis output authorization; and
Step S160: The cloud host outputs the second analysis result as second analysis data according to the analysis output authorization.
In step S150, further referring to the second D diagram, the cloud host 20 receives the third key KEY3 input by the user through the client device 50, thereby allowing the user to obtain the authorization of the third stage of the cloud host 20, that is, The analysis and output authorization A3 allows the user to output the second analysis result R2 generated in the step S140 to the outside of the cloud host 20. In addition, the cloud host 20 can further provide the authorization AD2 according to one of the second data D2 Confirming the validity of the analysis output authorization A3, in addition, in this step S150, the authorization provided by one of the second data D2 and the third key KEY3 can be directly simultaneously provided to confirm the validity of the analysis output authorization A3, so that the cloud host 20 The user is allowed to output the second analysis result R2 generated in the step S140 to the outside of the cloud host 20 . In step S160, further referring to the second diagram D, the cloud host 20 will provide the output method of the second analysis result R2 according to the analysis output authorization A3. In this embodiment, a download link L is generated as an example to transmit to the user. The terminal device 50 , but the present invention is not limited thereto, and may be an email attachment or a fax image for the user to obtain the second analysis result R2 outside the cloud host 20 .
As shown in Figure 1 B, the steps of the method for analyzing sensitive data of the present invention further include:
Step S10: the cloud host receives the initial data of the big data database;
Step S20: the cloud host de-identifies the initial data to generate the corresponding second data; and
Step S30: The cloud host randomly samples the format of the second data to generate the corresponding first data.
Therefore, the method for analyzing sensitive data of the present invention further includes steps S10 to S30 before step S100 . Referring to the second figure A, in step S10 , the cloud host 20 receives the big data database through a data capture device 30 . A plurality of initial data D0 of 40 are stored in the encrypted storage unit 10 . In step S20 , the cloud host 20 de-identifies the initial data D0 in the encrypted storage unit 10 , thereby generating second data D2 with de-identified data or personalized data and stored in the encrypted storage unit 10 . In step S30 , the cloud host 20 randomly samples the second data D2 according to the format of the second data D2 to generate the first data D1 and store them in the encrypted storage unit 10 .
In addition to the above-mentioned random sampling according to the format of the second data D2 to generate the corresponding first data, it is also possible to perform data simulation according to the format of the second data D2 to generate the corresponding first data. Please refer to the first figure C, this The steps of the inventive method for analyzing sensitive data further include:
Step S10: the cloud host receives the initial data of the big data database;
Step S20: the cloud host de-identifies the initial data to generate the corresponding second data; and
Step S35: The cloud host performs simulation according to the format of the second data to generate the corresponding first data.
Steps S10 to S20 will not be described again. In the previous embodiment, step S20 is followed by step S30, and in this embodiment, step S20 is followed by step S35. In step S35, the cloud host is based on the second data D2 The format is simulated, and the first data D1 are generated. At this time, the first data D1 are regarded as simulated data.
To sum up, the method and system for analyzing sensitive data of the present invention use different keys to perform segment authorization on a cloud host, so as to perform data analysis for encrypted cloud spaces with different encryption levels, and randomize the data according to the second data. The first data formed by sampling is used to analyze the first data in the first analysis for testing according to the calculation model, and then the calculation model is verified according to the first analysis result. ) of the second analysis, thereby obtaining the second analysis result corresponding to the second data, thereby improving the data security of the real data; and further providing a key for data output to further protect data leakage.
Therefore, the present invention is indeed novel, progressive and available for industrial use, and it should meet the requirements of patent application in my country's patent law.
However, the above descriptions are only preferred embodiments of the present invention, and are not intended to limit the scope of implementation of the present invention. All changes and modifications made in accordance with the shape, structure, features and spirit described in the scope of the patent application of the present invention are equivalent. , shall be included in the scope of the patent application of the present invention.
<p>1: Analysis System <br /> 10: Encrypted storage unit <br /> 20: Cloud hosting <br /> 22: Encrypted cloud space <br /> 30: Data Capture Device <br /> 40: Big Data Repository <br /> 50: Client Device <br /> A1: First Analysis Authorization <br /> A11: First Analysis <br /> A2: Second Analysis Authorization <br /> A21: Second Analysis <br /> A3: Analysis Output Authorization <br /> AD2: Provide authorization <br /> D0: Initial data <br /> D1: First information <br /> D2: Second data <br /> KEY1: the first key <br /> KEY2: the second key <br /> KEY3: the third key <br /> L: download link <br /> M: Calculus Model <br /> NET: network <br /> R1: The first analysis result <br /> R2: Second analysis result <br /> S10-S30: Steps <br /> S100-S160: Steps </p>
The first A to the first B: it is a flow chart of an embodiment of the present invention; and <br /> Figure 2 A to Figure D: These are schematic diagrams of steps of an embodiment of the present invention.
<bio-deposit /><sequence-list-text />
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
4 members in 2 offices
Members4
| Document | Office | Kind | |
|---|---|---|---|
| TWI737368B | Taiwan Province of China | B | |
| US2021406393A1 | United States of America | A1 | |
| TW202201256AThis record | Taiwan Province of China | A | |
| US11537739B2 | United States of America | B2 |
Numbers
- Publication
- 202201256
- Application
- 109121904
Titles3
- English
- SYSTEM AND METHOD FOR ANALYZING CONFIDENTIAL DATA
- Chinese
- 機敏資料之分析方法及其系統
- English
- Analysis method and system for sensitive data
Classification
- CPC, 7
- H04L63/0428
- G06F21/6227
- H04L63/10
- G06F21/6245
- H04L9/0894
- H04L9/14
- H04L63/123
- IPC, 2
- G06F21 60
- H04L9 32