Data desensitization method and device, electronic equipment and storage medium

By performing primary and secondary desensitization of data in cross-institutional and cross-industry data sharing scenarios, the contradiction between data availability and privacy protection is solved, and data security and availability are improved.

CN120493306APending Publication Date: 2025-08-15AGRICULTURAL BANK OF CHINA
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510611338.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-13
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

In cross-institutional and cross-industry data sharing scenarios, existing data desensitization technologies cannot effectively balance the contradiction between data availability and privacy protection, resulting in insufficient security and inability to adapt to differentiated needs in different scenarios, and the standards for desensitization between producers and consumers are not unified.

Method used

By issuing a unified first desensitization model to the data producer corresponding to the data acquisition request, performing the initial desensitization process, and performing secondary desensitization processing on the initial desensitization data, ensuring data privacy and security, and generating target desensitization data.

Benefits of technology

In cross-institutional and cross-industry data sharing, it can not only simulate real business scenarios, carefully characterize business characteristics, but also protect production data privacy and improve the security and availability of data interaction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120493306A_ABST
    Figure CN120493306A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a data desensitization method and device, electronic equipment and a storage medium, and the method comprises the steps: transmitting a first desensitization model to at least one data producer corresponding to a data acquisition request when the data acquisition request sent by a data consumer is received; receiving first desensitization data fed back by at least one data producer, and performing secondary desensitization processing on the first desensitization data to obtain target desensitization data; wherein the first desensitization data is data processed through a first desensitization model; the target desensitization data is fed back to a data consumer, the highly-imitated data subjected to secondary desensitization processing can simulate a real business scene and finely describe business characteristics, the privacy of production data can be protected, the contradiction between data availability and privacy protection is balanced in a cross-mechanism and cross-industry data sharing scene, and the privacy protection efficiency is improved. And the security and availability of cross-mechanism and cross-industry data interaction are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information technology, and in particular to a data desensitization method, device, electronic device, and storage medium. Background Art

[0002] In the context of balancing data sharing and privacy protection, data masking often requires the use of real-world datasets in development, testing, other non-production environments, and outsourced data applications. As a key information protection technology, data masking aims to effectively shield sensitive information, prevent unauthorized access and misuse, and ensure data privacy and compliance without sacrificing data value.

[0003] At present, data security protection can usually be achieved within a single organization through data desensitization technology. For example, data deformation can be performed on certain sensitive information to achieve reliable protection of sensitive data.

[0004] However, many large-scale data analyses, machine learning model training, and even development, testing, and training tasks with special requirements require cross-institutional and cross-industry collaboration. With the aforementioned data desensitization methods, a single institution can only own part of the data it controls. A single data source clearly cannot meet such needs. Failure to securely use data from different institutions and industries will create difficulties for cross-institutional and cross-industry research and development efforts. As can be seen, with the surge in demand for cross-institutional and cross-industry data collaboration, traditional desensitization methods face technical issues such as insufficient security for single-time desensitization, an inability to adapt to the differentiated needs of different scenarios, and inconsistent desensitization standards between producers and consumers. Currently, there is a lack of a more flexible and secure hierarchical desensitization system to balance the contradiction between data availability and privacy protection. Summary of the Invention

[0005] The present invention provides a data desensitization method, device, electronic device and storage medium to achieve a balance between data availability and privacy protection in cross-institutional and cross-industry data sharing scenarios, and improve the security and availability of cross-institutional and cross-industry data interaction.

[0006] In a first aspect, an embodiment of the present invention provides a data desensitization method, the method comprising:

[0007] When receiving a data acquisition request sent by a data consumer, sending the first desensitization model to at least one data producer corresponding to the data acquisition request;

[0008] receiving first desensitized data fed back by the at least one data producer, performing secondary desensitization processing on the first desensitized data to obtain target desensitized data; wherein the first desensitized data is data processed by the first desensitization model;

[0009] Feedback the target desensitized data to the data consumer.

[0010] In a second aspect, an embodiment of the present invention further provides a data desensitization device, the device comprising:

[0011] a desensitizing model sending module, configured to send the first desensitizing model to at least one data producer corresponding to the data acquisition request upon receiving a data acquisition request sent by a data consumer;

[0012] a secondary desensitization processing module, configured to receive the first desensitized data fed back by the at least one data producer, and perform secondary desensitization processing on the first desensitized data to obtain target desensitized data; wherein the first desensitized data is data processed by the first desensitization model;

[0013] The desensitized data feedback module is used to feed back the target desensitized data to the data consumer.

[0014] In a third aspect, an embodiment of the present invention further provides an electronic device, the electronic device comprising:

[0015] one or more processors;

[0016] a storage device for storing one or more programs,

[0017] When one or more programs are executed by one or more processors, the one or more processors implement a data desensitization method as described in any of the embodiments of the present invention.

[0018] In a fourth aspect, an embodiment of the present invention further provides a storage medium comprising computer-executable instructions, which, when executed by a computer processor, are used to perform a data desensitization method such as any of the embodiments of the present invention.

[0019] The technical solution of the embodiment of the present invention, when receiving a data acquisition request sent by a data consumer, sends the first desensitization model to at least one data producer corresponding to the data acquisition request, thereby receiving the first desensitized data fed back by at least one data producer, performing secondary desensitization processing on the first desensitized data, obtaining target desensitized data, wherein the first desensitized data is the data processed by the first desensitization model, and finally feeding back the target desensitized data to the data consumer. The technical solution of this embodiment, by issuing a unified data desensitization model to the data producer associated with the data acquisition request, the data producer completes the initial desensitization of the original data according to the agreed data desensitization model. This initial desensitization processing method lays a technical foundation for cross-institutional and cross-industry data sharing, and then uniformly performs secondary desensitization processing on the data after the initial desensitization, further ensuring the privacy security of the original data. In this way, the high-imitation data that has undergone secondary desensitization processing can simulate real business scenarios, accurately portray business characteristics, and protect the privacy of production data. In cross-institutional and cross-industry data sharing scenarios, it balances the contradiction between data availability and privacy protection, and improves the security and availability of cross-institutional and cross-industry data interaction. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] To more clearly illustrate the technical solutions of the exemplary embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings introduced here only illustrate some of the embodiments to be described by the present invention, and are not exhaustive. A person skilled in the art can derive other drawings based on these drawings without inventive effort.

[0021] Figure 1 A flowchart of a data desensitization method provided by an embodiment of the present invention;

[0022] Figure 2 A flowchart of another data desensitization method provided by an embodiment of the present invention;

[0023] Figure 3 A schematic diagram of the system architecture of the data desensitization method provided in this embodiment;

[0024] Figure 4 A schematic structural diagram of a data desensitization device provided by an embodiment of the present invention;

[0025] Figure 5 The present invention provides a schematic structural diagram of an electronic device. DETAILED DESCRIPTION

[0026] The present invention will be further described in detail below with reference to the accompanying drawings and examples. It will be understood that the specific embodiments described herein are intended only to illustrate the present invention and are not intended to limit the present invention. It should also be noted that, for ease of description, the accompanying drawings only illustrate portions relevant to the present invention, not all structures.

[0027] It should be noted that similar reference numerals and letters represent similar items in the following figures. Therefore, once an item is defined in one figure, it does not need to be further defined or explained in subsequent figures. Furthermore, in the description of the present invention, the terms "first," "second," etc. are used only to distinguish descriptions and should not be understood to indicate or imply relative importance. The acquisition, storage, use, and processing of data in the technical solution of this application comply with the relevant provisions of national laws and regulations.

[0028] It should be noted that in the embodiments of the present application, certain software, components, models and other existing solutions in the industry may be mentioned. They should be regarded as exemplary. Their purpose is only to illustrate the feasibility of implementing the technical solution of the present application, but it does not mean that the applicant has or will necessarily use the solution.

[0029] The acquisition, storage, use, and processing of data in this application's technical solution comply with relevant national laws and regulations.

[0030] Below, the present application is further described in conjunction with the accompanying drawings and specific implementation methods. It should be noted that, under the premise of no conflict, the various embodiments or technical features described below can be arbitrarily combined to form new embodiments.

[0031] Before introducing this technical solution, we can first illustrate an example application scenario. This technical solution can be applied in scenarios where cross-industry and cross-institutional data exchange is required, and data desensitization is performed to protect data security.

[0032] Currently, data desensitization technology is widely used within single enterprises, but research on its use in open and shared cross-industry and cross-institutional scenarios is lacking. This scenario is quite common. For example, in the micro-loan sector, financial institutions must cross-verify sales, logistics, finance, warehousing, tax, and other information to conduct accurate credit reviews. However, financial institutions typically only have basic data provided by the loan applicant and historical business data. However, other raw data often contains sensitive data such as customer information, and there are still many issues with data ownership and privacy protection. Improper handling can lead to serious leaks and even legal disputes for businesses and customers. Under these circumstances, finding data that can both reflect real business scenarios and protect customer privacy is a worthy research question.

[0033] The embodiment of the present invention provides a solution for obtaining high-simulation data by performing secondary desensitization processing on the original data. It can not only simulate real business scenarios and accurately depict business characteristics, but also protect the privacy of production data, providing technical support for cross-industry and cross-institutional data openness and sharing.

[0034] Figure 1 This is a flow chart of a data desensitization method provided in an embodiment of the present invention. This embodiment is applicable to situations where data needs to be desensitized in cross-industry and cross-institutional data interaction scenarios to protect data security. The method can be executed by a data desensitization device, which can be implemented in the form of software and / or hardware. The hardware can be an electronic device, such as a mobile terminal, PC or server.

[0035] like Figure 1 As shown, the data desensitization method includes:

[0036] S110. When a data acquisition request sent by a data consumer is received, the first desensitizing model is sent to at least one data producer corresponding to the data acquisition request.

[0037] The data desensitization method provided in this embodiment can be encapsulated as a data processing component and deployed on a data management service platform, wherein the data management service platform can interact with data consumers and data producers.

[0038] Data consumers are organizations or systems (such as data analysis platforms and third-party partners) that need to access and use data. They have data needs but should not have access to raw sensitive data. Data acquisition requests are structured query requests initiated by data consumers to the data management service platform, containing metadata such as the type of data required and its intended purpose. The first desensitization model is a set of primary desensitization rules dynamically configured by the data management service platform. Data producers are the holders of raw data.

[0039] In this embodiment, a list of available data can be displayed in the service system corresponding to the data consumer. The list can include data association information corresponding to multiple data packets. The data association information corresponding to each data packet includes information such as the packet type, packet identification code, packet description information, effective time, the name of the producer to which the packet belongs, and the producer identification code. When a data consumer needs to obtain data content held by one or more data producers, he or she can select the selection control corresponding to certain data packets from the available data display list and click the data acquisition control. At this time, a data acquisition request is generated. The producers corresponding to these selected data packets are the at least one data producer corresponding to the data acquisition request. When the data management service platform receives a standardized data acquisition request sent by the data consumer through the API interface, the platform first performs compliance verification and risk assessment on the request. Then, it generates a first desensitization model based on the preset policy matching. The first desensitization model is then dynamically distributed to the multiple data producers associated with the request through an encrypted channel. After receiving the first desensitization model, each data producer can load the first desensitization model in a local secure environment and use the first desensitization model to perform standardized primary desensitization processing on the original data.

[0040] Optionally, when receiving a data acquisition request sent by a data consumer, a specific implementation method of sending the first desensitization model to at least one data producer corresponding to the data acquisition request may include:

[0041] When receiving a data acquisition request sent by a data consumer, the data acquisition request is parsed and processed to obtain data attribute information corresponding to the data to be acquired and producer identification information corresponding to at least one data producer;

[0042] Determining a first desensitization model from at least one first desensitization model to be selected based on data attribute information corresponding to the data to be acquired;

[0043] Based on the producer identification information corresponding to at least one data producer, the first desensitizing model is sent to at least one data producer respectively, so that when the at least one data producer receives the first desensitizing model, it performs a first desensitizing process on the original data held by the data producer based on the first desensitizing model.

[0044] Data attribute information refers to the metadata set parsed from the data acquisition request and used to describe the characteristics of the data to be acquired. It mainly includes structured information in the following dimensions:

[0045] First, the data content feature dimension, which mainly includes field composition, such as: fields containing name, identity identification code, etc.; data type, such as structured or semi-structured; sensitive field identification information, etc.;

[0046] Second, the business scenario feature dimension mainly includes data usage, such as scientific research analysis, commercial cooperation, or regulatory reporting; usage scenarios, such as internal use, cross-institutional sharing, or cross-border transmission; and compliance level information.

[0047] Third, the dimension of data security requirements mainly includes desensitization strength, such as complete anonymization and reversible desensitization; retention accuracy, for example, geographic information must be at the district / street level; special constraints, such as not allowing the full date of birth to be displayed, etc.

[0048] The producer identification information refers to the metadata code used to uniquely identify and locate the data producer. The first candidate desensitization model refers to a pre-built, dynamically selectable set of standardized desensitization processing solutions.

[0049] More specifically, at least one first candidate desensitization model includes: a replacement desensitization model, a mask desensitization model, an encryption desensitization model, a perturbation desensitization model, a data segmentation desensitization model, a pseudo-data generation desensitization model, a data shielding desensitization model, a virtualization desensitization model, a data classification desensitization model, and a data partitioning desensitization model. The replacement desensitization model is one of the most intuitive and widely used strategies in the field of desensitization algorithms. It primarily targets directly identifiable sensitive information, such as personal identification and contact information. The specific operation involves replacing specific characters or character sequence numbers with other characters or specific strings. The mask desensitization model is similar to the replacement desensitization model, but is more flexible and is particularly suitable for sensitive data in a fixed format. The mask desensitization model typically retains some of the data's features to maintain its basic structure. The encryption mask desensitization model uses complex mathematical algorithms to encode sensitive data, making it indecipherable without authorization. Encryption not only prevents direct access to data but also enables fine-grained security control through key management and access control mechanisms. The perturbation desensitization model is a statistically based desensitization technique that introduces small random variations into a dataset, making individual data points difficult to identify while preserving the overall data distribution, correlations, and trends. The data segmentation desensitization model breaks sensitive data into components and stores them in different physical or logical locations. This decentralized storage reduces the risk of data breaches caused by a single attack. The pseudo-data generation desensitization model creates fake data that is statistically similar to real data but has no actual correspondence. This data can be generated completely randomly or through a combination of distortion and hybrid desensitization. The data masking desensitization model is a policy-based desensitization method that defines data access permissions and rules to limit user access and operations on sensitive data. Virtualization is a method of replacing real data with virtual data in non-production environments. Virtualization desensitization models can generate virtual data content randomly or through sampling, distortion, or hybrid desensitization based on real datasets. Data classification desensitization models classify data based on its sensitivity and then apply corresponding desensitization technologies and management measures to the data at different levels. The data partitioning desensitization model refers to dividing sensitive data into multiple logical or physical partitions and adopting different desensitization strategies for different areas.

[0050] Specifically, when the data management service platform receives a data acquisition request sent by a data consumer through a standardized API interface, it first performs a structured analysis of the request message through the request parsing engine, extracts data attribute information including data sensitivity level, field range and purpose of use, and identifies the data producer identification information associated with the data acquisition request; then, the platform uses the rule matching engine to filter out the first desensitizing model that meets the current scenario from the preset desensitizing model library based on the data attribute information; finally, the data management service platform pushes the instantiated first desensitizing model to each data producer system through a secure channel, and the data producer executes the desensitizing operation defined by the model on the original data it holds in a local security environment, generates primary desensitized data that conforms to the standard format, and obtains the first desensitized data, completing the first stage of processing for secure data circulation.

[0051] S120: Receive first desensitized data fed back by at least one data producer, perform secondary desensitization processing on the first desensitized data, and obtain target desensitized data.

[0052] The first desensitized data refers to data processed by the first desensitizing model. This can be understood as intermediate data generated by the data producer after receiving the first desensitizing model and performing initial processing on the local raw data according to the model's rules. The target desensitized data refers to the data form that meets both security and business requirements after undergoing double desensitization and is ultimately delivered to the data consumer.

[0053] Specifically, after the data producer receives the first desensitizing model issued by the data management service platform, the processing process for each data producer is consistent. In order to clearly introduce the present technical solution, any one of the data producers is taken as the current data producer, and the current data producer can be used as an example in the following introduction. The current data producer performs the desensitization operation defined by the first desensitizing model on the original data it holds in a local security environment, and generates primary desensitized data that conforms to the standard format. These data are the first desensitized data. After completing the first desensitization process, the current data producer can feed back the first desensitized data to the data management service platform. For the data management service platform, when the data management service platform receives the first desensitized data transmitted by at least one data producer through a secure channel, it first verifies the data integrity and desensitization compliance through the data verification module; then, the first desensitized data can be subjected to a secondary desensitization process through a pre-configured preset desensitization model to obtain the target desensitized data.

[0054] Optionally, performing secondary desensitization processing on the first desensitized data to obtain target desensitized data may include: determining a second desensitization model from at least one second selected desensitization model based on the data usage scenario information corresponding to the data consumer; performing secondary desensitization processing on the first desensitized data based on the second desensitization model to obtain target desensitized data.

[0055] Data usage scenario information refers to a set of metadata used to define the specific business purposes and compliance requirements of data consumers. Specifically, data usage scenario information may include: scientific research and analysis scenarios, commercial application scenarios, regulatory compliance verification scenarios, etc. The second candidate desensitization model refers to a pluggable processing rule set designed specifically for secondary desensitization and oriented towards the final use scenario. The second desensitization model is the desensitization model ultimately selected for secondary desensitization.

[0056] In this embodiment, after the data management service platform obtains the first desensitized data fed back by each data producer, it first uses the scenario analysis engine to extract the data usage scenario information in the data acquisition request. It then calls the intelligent matching engine to screen a candidate model that meets the requirements from at least one second candidate desensitizing model. This model is the second desensitizing model, which contains field-level processing rules. After the second desensitizing model is determined, a distributed processing cluster performs batch secondary desensitization processing on the first desensitized data, ultimately generating the target desensitized data.

[0057] S130: Feedback the target desensitized data to the data consumer.

[0058] In this embodiment, after the target desensitized data is generated, the data management service platform first checks its compliance and availability, such as the integrity of key fields, through the data quality verification module; then selects a secure transmission method according to the data consumer's agreement and feeds back the target desensitized data to the data consumer.

[0059] The technical solution of the embodiment of the present invention, when receiving a data acquisition request sent by a data consumer, sends the first desensitization model to at least one data producer corresponding to the data acquisition request, thereby receiving the first desensitized data fed back by at least one data producer, performing secondary desensitization processing on the first desensitized data, obtaining target desensitized data, wherein the first desensitized data is the data processed by the first desensitization model, and finally feeding back the target desensitized data to the data consumer. The technical solution of this embodiment, by issuing a unified data desensitization model to the data producer associated with the data acquisition request, the data producer completes the initial desensitization of the original data according to the agreed data desensitization model. This initial desensitization processing method lays a technical foundation for cross-institutional and cross-industry data sharing, and then uniformly performs secondary desensitization processing on the data after the initial desensitization, further ensuring the privacy security of the original data. In this way, the high-imitation data that has undergone secondary desensitization processing can simulate real business scenarios, accurately portray business characteristics, and protect the privacy of production data. In cross-institutional and cross-industry data sharing scenarios, it balances the contradiction between data availability and privacy protection, and improves the security and availability of cross-institutional and cross-industry data interaction.

[0060] Example 2

[0061] Figure 2 This is a schematic diagram of a data desensitization method provided by an embodiment of the present invention. Based on the above embodiment, S120 is further refined. Its specific implementation method can be found in the technical solution of this embodiment. Among them, technical terms that are the same or corresponding to the above embodiment are not repeated here.

[0062] like Figure 2 As shown, the method specifically includes the following steps:

[0063] S210: When receiving a data listing request sent by a data producer, perform a data quality check on the data to be listed held by the data producer based on preset authentication conditions to determine a data authentication result.

[0064] A data listing request refers to a request submitted by a data producer to the data management service platform to include their data to be shared in the list of publicly available data. Pre-set certification conditions refer to a set of pre-set, standardized rules used to assess whether the data to be listed meets quality, compliance, and security requirements. Data to be listed refers to raw or pre-processed data submitted by a data producer to the data management service platform that has not yet been certified and publicly disclosed. This data must undergo the platform's quality inspection, compliance review, and other certification processes before it can be officially included in the list of publicly available data, or "listed," for data consumers to query and request. The data certification result refers to the final review conclusion generated by the data management service platform after verifying the quality, compliance, and security of the data to be listed based on the pre-set certification conditions. This result determines whether the data to be listed can be officially added to the list of publicly available data for data consumers to view and request.

[0065] In this embodiment, when the data management service platform receives a data listing request submitted by the data producer, it will first extract the data set to be listed and its metadata information contained in the request, such as data format, field description, sensitivity level identification, etc., and then call the preset authentication condition rule engine to verify the integrity, accuracy, consistency and compliance of the data item by item, such as checking whether there are missing values in key fields, verifying whether the data values ​​comply with business logic, checking whether the association relationship between data is established, and whether the data complies with regulatory requirements such as privacy protection; at the same time, through quality assessment algorithms, such as outlier detection algorithms, duplicate data identification algorithms, etc., a data quality score is generated, and finally the pass status of all inspection items is comprehensively considered to output a data authentication result of "authentication passed" or "authentication failed".

[0066] S220: If the data authentication result is authentication passed, the data to be put on the shelf is added to the available data display list.

[0067] The "Accessible Data Display List" refers to a directory of data resources that have been officially released to the public after passing authentication. It presents data consumers with information about currently available datasets in a structured format, such as a data table or file list, but does not directly include the raw data content. Essentially, this list serves as a secure intermediary directory connecting data producers and consumers.

[0068] Specifically, when the data authentication result is "authentication passed", the data to be put on the shelf can be added to the available data display list, so that the data consumer can trigger a preset event through the available data display list, such as clicking the application button, to generate a data acquisition request, and finally obtain the target data after subsequent hierarchical desensitization processing.

[0069] S230: Publishing the available data display list to at least one data consumer, so that the at least one data consumer triggers a preset event for the available data display list and generates a data acquisition request.

[0070] Among them, preset events refer to standardized interactive actions pre-defined by the platform that are triggered when data consumers view the "available data display list" in the data sharing process. This action will automatically generate a structured data acquisition request.

[0071] In this embodiment, after completing the update step for the available data display list, the data management service platform pushes the approved available data display list to each data consumer. When a data consumer browses the available data display list and selects the required data, a pre-defined platform interaction event, such as clicking the "Request Data" button, is triggered. This event automatically collects the necessary application information, such as the purpose, required fields, and expiration date, and generates a structured data acquisition request in a standard format. This request is then submitted to the data management service platform, initiating the subsequent data desensitization and delivery process.

[0072] S240. When a data acquisition request sent by a data consumer is received, the first desensitizing model is sent to at least one data producer corresponding to the data acquisition request.

[0073] S250: Send the first desensitized data to an authoritative third party, so that the authoritative third party performs secondary desensitization processing on the first desensitized data to determine target desensitized data.

[0074] Among them, an authoritative third party refers to an independent institution / organization with legal qualifications or industry-recognized professional capabilities.

[0075] In this embodiment, after obtaining the first desensitized data fed back by at least one data producer, the first desensitized data that has undergone the initial desensitization processing by the data producer can be transmitted to an independent third-party organization with legal qualifications or industry certification, such as an information security level protection certification organization; the authoritative third party implements deep desensitization operations based on stricter privacy protection standards to generate target desensitized data that fully meets circulation requirements, forming a secure data set that can both ensure data utility and completely eliminate the risk of re-identification.

[0076] S260: Receive the target desensitized data fed back by the authoritative third party, and feed back the target desensitized data to the data consumer.

[0077] In this embodiment, when the authoritative third party completes the secondary desensitization processing of the first desensitized data and obtains the target desensitized data, the target desensitized data can be fed back to the data management service platform. Thus, the data management service platform can feed back these target desensitized data to the data consumer who initiated the corresponding data acquisition request.

[0078] Next, a specific example is used to illustrate the data desensitization method provided in this embodiment. For example, Figure 3 This is a schematic diagram of the system architecture of the data desensitization method provided in this embodiment. The system of the data desensitization method includes data producers, data consumers and a data management service platform. The data management service platform is divided into a client and a server. The server is divided into a producer service module and a consumer service module. The two modules are deployed in different areas and adopt different security protection strategies. The producer service module is close to the data producer and processes the first desensitized data; while the consumer service module stores the target desensitized data that has undergone secondary desensitization and is ready to be sent to the data consumer. The first client for the data producer can be deployed on the server side of each data producer; the second client for the data consumer can be deployed on the server side of each data consumer; that is, the client program issued by the data management service platform can be technically embedded in the service system of the data producer or the data consumer.

[0079] The above data management service platform, when used in practice, mainly includes the following steps:

[0080] S1. The data consumer triggers the selection of available data displayed in the available data display list on the second client and makes a data acquisition request.

[0081] S2. The consumer service module in the data management service platform can monitor data acquisition requests.

[0082] S3. The producer service module receives the data acquisition request, selects a suitable first desensitizing algorithm, encrypts the first desensitizing algorithm and sends it to the first client of each data producer associated with the data acquisition application.

[0083] S4. The corresponding data producer completes the initial data desensitization processing locally according to the issued first desensitization algorithm, and sends the desensitized first desensitized data to the producer service module in the data management service platform.

[0084] S5. The producer service module receives the first desensitized data fed back by the data producer, and may perform secondary desensitization processing on the first desensitized data locally in the producer service module, or may send the first desensitized data to an authoritative third party, so that the authoritative third party performs secondary desensitization processing on the first desensitized data to obtain target desensitized data;

[0085] S6. Feedback the target desensitized data to data consumers through the consumer service module in the data management service platform.

[0086] In addition, when a data producer has a data listing requirement, that is, when a data producer needs to list new available data, it can submit a data listing request to the producer service module through the first client. At this time, the producer service module can perform a data quality check on the data to be listed held by the data producer according to the preset authentication conditions, determine the data authentication result, and if the data authentication result is authentication passed, add the data to be listed to the available data display list, and display the available data display list through the consumer service module. For example, an example table of the available data display list is shown in Table 1.

[0087] Table 1 Example table of available data display list

[0088]

[0089] As shown in Table 2, the available data display list can contain data association information corresponding to multiple data packets. The data association information corresponding to each data packet includes: the name of the producer to which the data packet belongs, the producer identification code, the data packet type, the data packet identification code, the data packet description information, the effective time, and other information.

[0090] According to the technical solution of an embodiment of the present invention, when a data producer has a demand for data listing, a data listing request can be submitted to the producer service module through the first client. At this time, the producer service module can perform data quality inspection on the data to be listed held by the data producer according to preset authentication conditions, determine the data authentication result, and if the data authentication result is authentication passed, add the data to be listed to the obtainable data display list, so that at least one data consumer triggers a preset event for the obtainable data display list and generates a data acquisition request. The above method ensures that the basic quality of the listed data is controllable through automated quality inspection of preset authentication conditions, thereby reducing the risk of consumers obtaining inefficient or illegal data. When the first desensitized data is subjected to a secondary desensitization process to obtain the target desensitized data, the first desensitized data can be sent to an authoritative third party so that the authoritative third party can perform a secondary desensitization process on the first desensitized data to determine the target desensitized data. The above method introduces an authoritative third party to perform a secondary desensitization process. The standardized desensitization process provided by the authoritative third party not only ensures the balance between data utility and privacy protection, but also provides authoritative endorsement for data circulation, thereby enhancing consumer trust. In addition, this method not only protects the original data rights and interests of the producer, but also realizes the separation of desensitization responsibilities through the intervention of a third party, so that the data sharing process has a complete compliance audit chain, and establishes a reliable technical support for cross-institutional and cross-industry data circulation.

[0091] Example 3

[0092] Figure 4This is a structural diagram of a data desensitization device provided by an embodiment of the present invention, which includes: a desensitization model sending module 310, a secondary desensitization processing module 320 and a desensitized data feedback module 330.

[0093] The desensitization model sending module 310 is configured to send the first desensitization model to at least one data producer corresponding to the data acquisition request upon receiving the data acquisition request sent by the data consumer;

[0094] The secondary desensitization processing module 320 is configured to receive first desensitized data fed back by at least one data producer and perform secondary desensitization on the first desensitized data to obtain target desensitized data; wherein the first desensitized data is data processed by the first desensitization model;

[0095] The desensitized data feedback module 330 is used to feed back the target desensitized data to the data consumer.

[0096] The technical solution of the embodiment of the present invention, when receiving a data acquisition request sent by a data consumer, sends the first desensitization model to at least one data producer corresponding to the data acquisition request, thereby receiving the first desensitized data fed back by at least one data producer, performing secondary desensitization processing on the first desensitized data, obtaining target desensitized data, wherein the first desensitized data is the data processed by the first desensitization model, and finally feeding back the target desensitized data to the data consumer. The technical solution of this embodiment, by issuing a unified data desensitization model to the data producer associated with the data acquisition request, the data producer completes the initial desensitization of the original data according to the agreed data desensitization model. This initial desensitization processing method lays a technical foundation for cross-institutional and cross-industry data sharing, and then uniformly performs secondary desensitization processing on the data after the initial desensitization, further ensuring the privacy security of the original data. In this way, the high-imitation data that has undergone secondary desensitization processing can simulate real business scenarios, accurately portray business characteristics, and protect the privacy of production data. In cross-institutional and cross-industry data sharing scenarios, it balances the contradiction between data availability and privacy protection, and improves the security and availability of cross-institutional and cross-industry data interaction.

[0097] Based on the above device, optionally, the desensitization model issuing module 310 includes:

[0098] A request parsing unit, configured to parse a data acquisition request sent by a data consumer upon receiving the request, and obtain data attribute information corresponding to the data to be acquired and producer identification information corresponding to at least one data producer;

[0099] a desensitization model determining unit, configured to determine a first desensitization model from at least one first candidate desensitization model based on data attribute information corresponding to the data to be acquired;

[0100] The desensitizing model sending unit is used to send the first desensitizing model to at least one data producer based on the producer identification information corresponding to at least one data producer, so that when at least one data producer receives the first desensitizing model, it performs the first desensitizing processing on the original data held by the data producer based on the first desensitizing model.

[0101] Based on the above-mentioned device, optionally, at least one first selected desensitization model includes: replacement desensitization model, mask desensitization model, encryption desensitization model, perturbation desensitization model, data segmentation desensitization model, pseudo data generation desensitization model, data shielding desensitization model, virtualization desensitization model, data classification desensitization model and data partitioning desensitization model.

[0102] On the basis of the above-mentioned device, optionally, a secondary desensitization processing module 320 is specifically used to determine a second desensitization model from at least one second selected desensitization model based on the data usage scenario information corresponding to the data consumer; perform secondary desensitization processing on the first desensitized data based on the second desensitization model to obtain target desensitized data.

[0103] Based on the above device, optionally, the secondary desensitization processing module 320 is also used to send the first desensitized data to an authoritative third party, so that the authoritative third party performs secondary desensitization processing on the first desensitized data to determine the target desensitized data; and receive the target desensitized data fed back by the authoritative third party.

[0104] Based on the above device, optionally, the data desensitization device also includes:

[0105] The data authentication module is used to, upon receiving a data listing request from a data producer, perform a data quality check on the data to be listed held by the data producer based on preset authentication conditions and determine the data authentication result;

[0106] The data listing module is used to add the data to be listed to the available data display list when the data authentication result is passed;

[0107] The data list publishing module is used to publish the available data display list to at least one data consumer, so that at least one data consumer triggers a preset event for the available data display list and generates a data acquisition request.

[0108] The data desensitization device provided in the embodiment of the present invention can execute the data desensitization method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0109] It is worth noting that the various units and modules included in the above system are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of the embodiments of the present invention.

[0110] Example 4

[0111] Figure 5 The present invention provides a schematic structural diagram of an electronic device. Figure 5 A block diagram of an exemplary electronic device 40 suitable for implementing exemplary embodiments of the present invention is shown. Figure 5 The electronic device 40 shown is only an example and should not limit the functionality and scope of use of the embodiments of the present invention.

[0112] like Figure 5 As shown, electronic device 40 is a general-purpose computing device. Components of electronic device 40 may include, but are not limited to, one or more processors or processing units 401, system memory 402, and a bus 403 connecting various system components (including system memory 402 and processing unit 401).

[0113] Bus 403 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processor, or a local bus using any of a variety of bus architectures. Examples of these architectures include, but are not limited to, the Industry Standard Architecture (ISA) bus, the Micro Channel Architecture (MAC) bus, the Enhanced ISA bus, the Video Electronics Standards Association (VESA) local bus, and the Peripheral Component Interconnect (PCI) bus.

[0114] The electronic device 40 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by the electronic device 40, including volatile and non-volatile media, removable and non-removable media.

[0115] System memory 402 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) 404 and / or cache memory 405. Electronic device 40 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 406 may be used to read and write non-removable, non-volatile magnetic media ( Figure 5 Not shown, often called a "hard drive"). Although Figure 5Not shown, a disk drive for reading and writing to a removable non-volatile disk (e.g., a "floppy disk"), and an optical disk drive for reading and writing to a removable non-volatile optical disk (e.g., a CD-ROM, DVD-ROM, or other optical media) may be provided. In these cases, each drive may be connected to bus 403 via one or more data medium interfaces. Memory 402 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of various embodiments of the present invention.

[0116] A program / utility 408 having a set (at least one) of program modules 407 may be stored, for example, in memory 402. Such program modules 407 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data, each of which, or some combination thereof, may include an implementation of a network environment. Program modules 407 generally perform the functions and / or methods of the embodiments described herein.

[0117] The electronic device 40 may also communicate with one or more external devices 409 (e.g., keyboard, pointing device, display 810, etc.), and may also communicate with one or more devices that enable a user to interact with the electronic device 40, and / or communicate with any device that enables the electronic device 40 to communicate with one or more other computing devices (e.g., network card, modem, etc.). Such communication may be performed through an input / output (I / O) interface 411. Furthermore, the electronic device 40 may also communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter 412. As shown, the network adapter 412 communicates with other modules of the electronic device 40 via the bus 403. It should be understood that although Figure 5 Not shown, other hardware and / or software modules may be used in conjunction with the electronic device 40, including but not limited to microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0118] The processing unit 401 executes various functional applications and page processing by running the programs stored in the system memory 402, such as implementing the data desensitization method provided in the embodiment of the present invention.

[0119] Example 5

[0120] An embodiment of the present invention further provides a storage medium containing computer-executable instructions. When the computer-executable instructions are executed by a computer processor, the computer-executable instructions are used to perform a data desensitization method, the method comprising:

[0121] When receiving a data acquisition request sent by a data consumer, sending the first desensitization model to at least one data producer corresponding to the data acquisition request;

[0122] receiving first desensitized data fed back by the at least one data producer, performing secondary desensitization processing on the first desensitized data to obtain target desensitized data; wherein the first desensitized data is data processed by the first desensitization model;

[0123] Feedback the target desensitized data to the data consumer.

[0124] The computer storage medium of the embodiment of the present invention may adopt any combination of one or more computer-readable media. The computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or component, or any combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this document, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system, device or device.

[0125] A computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0126] Program code embodied on a computer readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0127] Computer program code for performing the operations of embodiments of the present invention can be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0128] Note that the above are only preferred embodiments of the present invention and the technical principles employed. Those skilled in the art will appreciate that the present invention is not limited to the specific embodiments herein, and that various obvious changes, readjustments, and substitutions are possible for those skilled in the art without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments and may include many other equivalent embodiments without departing from the scope of the present invention. The scope of the present invention is determined by the scope of the appended claims.

Claims

1. A data desensitization method, characterized in that: include: When receiving a data acquisition request sent by a data consumer, sending the first desensitization model to at least one data producer corresponding to the data acquisition request; receiving first desensitized data fed back by the at least one data producer, performing secondary desensitization processing on the first desensitized data to obtain target desensitized data; wherein the first desensitized data is data processed by the first desensitization model; Feedback the target desensitized data to the data consumer.

2. The method according to claim 1, characterized in that When receiving a data acquisition request sent by a data consumer, sending the first desensitization model to at least one data producer corresponding to the data acquisition request includes: When receiving a data acquisition request sent by a data consumer, parsing the data acquisition request to obtain data attribute information corresponding to the data to be acquired and producer identification information corresponding to at least one data producer; Determining a first desensitization model from at least one first desensitization model to be selected based on data attribute information corresponding to the data to be acquired; Based on the producer identification information corresponding to the at least one data producer, the first desensitizing model is sent to the at least one data producer respectively, so that when the at least one data producer receives the first desensitizing model, it performs the first desensitizing processing on the original data held by the data producer based on the first desensitizing model.

3. The method according to claim 2, characterized in that The at least one first desensitization model to be selected includes: a replacement desensitization model, a mask desensitization model, an encryption desensitization model, a perturbation desensitization model, a data segmentation desensitization model, a pseudo data generation desensitization model, a data shielding desensitization model, a virtualization desensitization model, a data classification desensitization model, and a data partitioning desensitization model.

4. The method according to claim 1, wherein The performing secondary desensitization processing on the first desensitized data to obtain target desensitized data includes: Determining a second desensitization model from at least one second to-be-selected desensitization model based on the data usage scenario information corresponding to the data consumer; The first desensitized data is subjected to secondary desensitization processing based on the second desensitization model to obtain target desensitized data.

5. The method according to claim 1, wherein The performing secondary desensitization processing on the first desensitized data to obtain target desensitized data includes: Sending the first desensitized data to an authoritative third party, so that the authoritative third party performs secondary desensitization processing on the first desensitized data to determine target desensitized data; Receive the target anonymized data fed back by the authoritative third party.

6. The method according to claim 1, characterized in that The method further comprises: Upon receiving a data listing request from a data producer, the data producer performs a data quality check on the data to be listed based on preset authentication conditions and determines the data authentication result; If the data authentication result is that the authentication is passed, the data to be put on the shelf is added to the available data display list; The obtainable data display list is published to at least one data consumer, so that the at least one data consumer triggers a preset event for the obtainable data display list and generates the data acquisition request.

7. A data desensitization device, characterized in that: The device includes: a desensitizing model sending module, configured to send the first desensitizing model to at least one data producer corresponding to the data acquisition request upon receiving a data acquisition request sent by a data consumer; a secondary desensitization processing module, configured to receive the first desensitized data fed back by the at least one data producer, and perform secondary desensitization processing on the first desensitized data to obtain target desensitized data; wherein the first desensitized data is data processed by the first desensitization model; The desensitized data feedback module is used to feed back the target desensitized data to the data consumer.

8. The device according to claim 7, characterized in that The device further comprises: The data authentication module is used to, upon receiving a data listing request from a data producer, perform a data quality check on the data to be listed held by the data producer based on preset authentication conditions and determine a data authentication result; A data listing module is configured to add the data to be listed to a list of available data for display if the data authentication result is that the authentication is passed; The data list publishing module is used to publish the obtainable data display list to at least one data consumer, so that the at least one data consumer triggers a preset event for the obtainable data display list and generates the data acquisition request.

9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can perform the data desensitization method according to any one of claims 1 to 6.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the data desensitization method according to any one of claims 1 to 6 when executed.

Citation Information

Cited By

  • Three-dimensional physical examination system sharing system patient information privacy protection method

    CN121167787A