Management method and device based on IP phone address book management platform
By identifying the requesting party's permission level for preliminary desensitization evaluation, building a field semantic path map for secondary desensitization, solving the problem of insufficient desensitization quality assessment in the traditional IP phone address book management platform, and achieving higher information security and privacy protection.
Patent Information
- Application Number
- CN202510723021.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-30
- Publication Date
- 2025-08-29
AI Technical Summary
The traditional IP phone address book management platform lacks an effective desensitization quality assessment mechanism, which leads to the potential risk of privacy leakage. Attackers may use desensitization vulnerabilities to obtain complete address book information.
By identifying the requesting party's authority level, performing preliminary desensitization, calculating the desensitization chaos score, and performing secondary desensitization if it fails, constructing a field semantic path map for structural disturbance and semantic dispersion, and then passing information after determining whether the desensitization intensity reaches the requirements.
Effectively evaluate the quality of desensitization, reduce potential privacy leakage risks, and ensure that address book information is safe and controllable under different permission levels.
Smart Images

Figure CN120567976A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of information management, and in particular to a management method and device based on an IP phone address book management platform. Background Art
[0002] An IP phone address book management platform is a platform designed to maintain and manage address book information within an enterprise or organization using an IP phone system. This platform not only stores basic information such as employee names, positions, departments, and phone numbers, but also manages access control, updates, maintenance, and security for this data. With the digitization and networking of enterprise communications, IP phone address books have become a critical resource for internal communication. Therefore, their management must ensure data accuracy and timeliness, as well as the security of sensitive information, ensuring that information can be effectively utilized in various scenarios while preventing misuse or leakage. To address the need for sensitive information protection in these management processes, most enterprises currently incorporate data masking technology into their IP phone address book management platforms to prevent unauthorized access and misuse. Masking technology replaces, masks, or distorts field content, rendering the original sensitive information unreadable or unrecoverable when displayed to users, thereby reducing the risk of leakage. This technology is often used in conjunction with access rights policies, allowing different users to access address book data at varying granularity based on their permission levels, thereby implementing the principle of "minimum available".
[0003] However, in practical applications, traditional desensitization methods often lack an effective evaluation mechanism to measure whether their "desensitization quality" meets the standards. They often assume that the desensitization quality has met the standards and send it directly to the user's display interface, resulting in the continued existence of potential privacy leakage risks. This may cause some attackers to exploit these vulnerabilities to obtain more complete address book information, causing privacy leaks for enterprises or organizations. Summary of the Invention
[0004] The purpose of the present invention is to solve the above-mentioned problems and provide a management method and device based on an IP phone address book management platform.
[0005] In a first aspect of the present invention, a management method based on an IP phone address book management platform is first proposed, the method comprising:
[0006] When receiving a request to view contact information, identify the preset permission level of the requester, and query the desensitization operation based on the preset permission level of the requester to perform preliminary desensitization of the contact information data;
[0007] According to the address book information after preliminary desensitization, each field corresponds to The desensitization confusion score is calculated based on the frequency of occurrence of characters and the number of inconsistencies in the corresponding characters in adjacent fields, which is used to evaluate the degree of discreteness of the character distribution and the degree of diversity of field semantic disturbance in the initial desensitization.
[0008] When the desensitization confusion score is less than the preset desensitization confusion score threshold, the contact information is desensitized twice;
[0009] Construct a semantic path diagram for the address book information fields, perform structural perturbation and semantic desensitization steps, implement secondary desensitization, and determine whether the secondary desensitization is successful;
[0010] If the secondary desensitization is successful, the secondary desensitized address book information will be transmitted to the requesting party for display, thus realizing the management of the IP phone address book.
[0011] Optionally, the desensitization confusion score is calculated as follows:
[0012] Concatenate all desensitized field strings into a field string and count the occurrence frequencies of all characters in the corresponding field string;
[0013] Get the total number of characters in the field string Divide the frequency of each character by the total number of characters to obtain the relative frequency of each character;
[0014] Calculated based on the relative frequency of all characters Standard deviation, which evaluates the dispersion of character distribution in the initial desensitization;
[0015] For two adjacent fields in the field string The number of different characters in adjacent fields is used as the edit distance between adjacent fields;
[0016] Calculate the rate of change between adjacent edit distances and calculate the mean of all change rates Evaluate the semantic perturbation diversity of the initial desensitization fields;
[0017] The mean was divided by the standard deviation to obtain the desensitization confusion score.
[0018] 3. A management method based on an IP phone address book management platform according to claim 1, characterized in that if the desensitization confusion score is not less than a preset desensitization confusion score threshold, it means that the character distribution discreteness of the initial desensitization is small and the field semantic disturbance diversity is large, which means that the initial desensitization is qualified and no secondary desensitization is required; the desensitized address book information is directly transmitted to the requesting party for display, thereby realizing the management of the IP phone address book.
[0019] Optionally, construct a semantic path graph of the address book information field, and perform structural perturbation and semantic desensitization steps as follows:
[0020] Obtain a set of structured data fields to be desensitized and construct a field dependency graph, where the fields serve as nodes and the structural and semantic associations between fields serve as edges.
[0021] Take any two adjacent fields in the field dependency graph as a field pair and calculate the edge weight of any field pair. The edge weight includes the field co-occurrence frequency and semantic similarity.
[0022] Based on the field dependency graph, the DFS algorithm is used to search for paths and identify the path set between fields.
[0023] The sum of the edge weights of each path in the path set is compared with the preset threshold. If it is not less than the preset threshold, the corresponding path is recorded as a sensitive path;
[0024] Random perturbation processing is performed on the fields in the sensitive path. The random perturbation processing types include field order reordering, redundant field insertion and field group reconstruction, and field word vector replacement; achieving secondary desensitization.
[0025] Optionally, the steps for determining whether the secondary desensitization is successful are:
[0026] Obtain the sensitive path fragmentation rate of secondary desensitization and evaluate the degree of random perturbation of fields in the sensitive path.
[0027] Obtain the semantic change degree of the secondary desensitized field and evaluate the intensity of the disturbance of the semantic content of the field in the sensitive path;
[0028] Obtain the cluster structure change value of the secondary desensitization and evaluate the magnitude of the change in the cluster structure of the field semantic vector set in the sensitive path;
[0029] Normalize the sensitive path fragmentation rate, field semantic change degree, and cluster structure change value to a value between 0 and 1. Take the weighted sum of the normalized sensitive path fragmentation rate, field semantic change degree, and cluster structure change value to obtain a desensitization strength score. This is used to evaluate the strength of the secondary desensitization and determine whether the secondary desensitization is successful based on the desensitization strength score.
[0030] Optionally, the steps for calculating the sensitive path breakup rate are:
[0031] Extract all sensitive paths from the field dependency graph: Obtain the random perturbation processing types corresponding to all fields in each sensitive path during the secondary desensitization process, and assign different processing weights to different random perturbation processing types as the processing score for the corresponding field pairs.
[0032] Calculate the average processing score of all field pairs in each sensitive path as the processing score of the corresponding sensitive path;
[0033] The mean of the processing scores of all sensitive paths is calculated, and the mean is set at the preset minimum processing score to obtain the sensitive path dispersion rate.
[0034] Optionally, the steps for calculating the field semantic change degree are:
[0035] For each field of the secondary desensitization, obtain the semantic vector of the field before desensitization and the corresponding semantic vector after desensitization; for each field, calculate the distance between the semantic vectors before and after desensitization as the semantic jump distance;
[0036] The jump distances of all field values are combined into a set, and the mean of all jump distances in the set is calculated. and standard deviation , and calculate the coefficient of variation based on the mean and standard deviation , the calculation formula is: ; The value is , used to prevent division by 0;
[0037] The field semantic variation is calculated based on the median jump distance and coefficient of variation of all field values. The calculation formula is: , where is the semantic change degree of the field, is the median jump distance.
[0038] Optionally, the steps for calculating the cluster structure change value are:
[0039] For each field of the secondary desensitization, obtain the semantic vector of the field before desensitization and the corresponding semantic vector after desensitization; use the same clustering algorithm and parameters to cluster the original and desensitized field semantic vector sets separately:
[0040] The silhouette coefficient is calculated as the clarity of the semantic clustering structure before and after desensitization;
[0041] Calculate the absolute difference in the clarity of the semantic clustering structure before and after desensitization as the change in clustering structure;
[0042] The cluster structure change value is obtained by dividing the cluster structure change by the clarity of the semantic cluster structure before desensitization.
[0043] Optionally, the steps of judging whether the secondary desensitization is successful based on the desensitization intensity score after the secondary desensitization are:
[0044] The desensitization strength score is compared with the preset desensitization strength score threshold. If the desensitization strength score is not less than the preset desensitization strength score threshold, it means that the secondary desensitization is successful. The secondary desensitized address book information is then transmitted to the requesting party for display, thereby realizing the management of the IP phone address book.
[0045] If the desensitization strength score is less than the preset desensitization strength score threshold, it means that the secondary desensitization is unsuccessful and the secondary desensitization is performed again until the desensitization strength score is not less than the preset desensitization strength score threshold. The address book information after the secondary desensitization is transmitted to the requesting party for display, thereby realizing the management of the IP phone address book.
[0046] In a second aspect of the present invention, a management device based on an IP phone address book management platform is provided, the device comprising:
[0047] Initial desensitization module: When receiving a request to view contact information, it identifies the preset permission level of the requester and queries the desensitization operation based on the preset permission level of the requester to perform initial desensitization of the contact information data;
[0048] Desensitization confusion scoring module: According to the address book information after preliminary desensitization, each field corresponds to The desensitization confusion score is calculated based on the frequency of occurrence of characters and the number of inconsistencies in the corresponding characters in adjacent fields, which is used to evaluate the degree of discreteness of the character distribution and the degree of diversity of field semantic disturbance in the initial desensitization.
[0049] Secondary desensitization module: When the desensitization confusion score is less than the preset desensitization confusion score threshold, the address book information is desensitized for the second time
[0050] Judgment module: Builds a semantic path diagram for the address book information field, performs structural perturbation and semantic desensitization steps, implements secondary desensitization, and determines whether the secondary desensitization is successful;
[0051] Management module: If the secondary desensitization is successful, the secondary desensitized address book information will be transmitted to the requesting party for display, thus realizing the management of the IP phone address book.
[0052] Beneficial effects of the present invention:
[0053] The present invention proposes a management method and device based on an IP phone address book management platform. When a request to view address book information is received, the preset authority level of the requesting party is identified, and a desensitization operation is queried according to the preset authority level of the requesting party to perform preliminary desensitization of the address book information data; based on the desensitization confusion score of the preliminary desensitization, it is judged whether to perform secondary desensitization according to the desensitization confusion score; if secondary desensitization is required, a semantic path diagram of the address book information field is constructed, and structural perturbation and semantic desensitization steps are performed to achieve secondary desensitization, and whether the secondary desensitization is successful is judged based on the desensitization intensity score after the secondary desensitization; if successful, the address book information after the secondary desensitization is transmitted to the requesting party for display, thereby realizing the management of the IP phone address book. Through the above-mentioned method, the desensitization quality of the address book information can be evaluated, and it is judged whether secondary desensitization is required. If necessary, secondary desensitization is performed, and the address book information after the secondary desensitization is displayed, thereby reducing the potential risk of privacy leakage and reducing the risk of privacy leakage of the address book information of an enterprise or organization. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] The present invention will be further described below with reference to the accompanying drawings.
[0055] Figure 1 It is a flow chart of a management method based on an IP phone address book management platform;
[0056] Figure 2 This is a framework diagram of a management device based on an IP phone address book management platform. DETAILED DESCRIPTION
[0057] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0058] The embodiment of the present invention provides a management method based on an IP phone address book management platform. Figure 1 , Figure 1 A flowchart of a management method based on an IP phone address book management platform is provided in an embodiment of the present invention. The method includes the following steps:
[0059] When receiving a request to view contact information, identify the preset permission level of the requester, and query the desensitization operation based on the preset permission level of the requester to perform preliminary desensitization of the contact information data;
[0060] According to the address book information after preliminary desensitization, each field corresponds to The desensitization confusion score is calculated based on the frequency of occurrence of characters and the number of inconsistencies in the corresponding characters in adjacent fields, which is used to evaluate the degree of discreteness of the character distribution and the degree of diversity of field semantic disturbance in the initial desensitization.
[0061] When the desensitization confusion score is less than the preset desensitization confusion score threshold, the contact information is desensitized twice;
[0062] Construct a semantic path diagram for the address book information fields, perform structural perturbation and semantic desensitization steps, implement secondary desensitization, and determine whether the secondary desensitization is successful;
[0063] If the secondary desensitization is successful, the secondary desensitized address book information will be transmitted to the requesting party for display, thus realizing the management of the IP phone address book.
[0064] Based on a management method based on an IP phone address book management platform provided by an embodiment of the present invention, the desensitization quality of the address book information can be evaluated through the above method to determine whether secondary desensitization is required. If necessary, secondary desensitization is performed and the address book information after secondary desensitization is used as the address book information, thereby reducing the potential risk of privacy leakage and reducing the risk of privacy leakage of the address book information of an enterprise or organization.
[0065] In one embodiment, when a request to view contact information is received, the preset permission level of the requesting party is identified, and a desensitization operation is queried based on the preset permission level of the requesting party to perform preliminary desensitization of the contact information data;
[0066] When a request to view contact information is received, the system first identifies the requester's identity (such as account ID, role, IP address, and access terminal type). The system then queries the user's corresponding permission level, such as "Staff," "Middle Manager," "Department Head," or "Administrator." Desensitization policies are set for different permission levels, specifying which fields require full desensitization, partial desensitization, or full access. Based on the identified permission level, the corresponding desensitization policy is invoked to perform preliminary desensitization on the data fields in the contact list.
[0067] For example, if the requester is a "general employee," whose permission level only allows them to view the last name, department prefix, and the first three and last four digits of a contact's phone number, the address book data will be masked as follows: the name "Zhang San" will be processed as "Zhang*," the phone number "13812345678" will be processed as "138**5678," and the department "Marketing Strategy Department" will be processed as "Marketing**." Fields such as job title, email address, and landline number will be completely masked with "*." If the requester is a "department manager," whose permission level allows them to view the full name, job title, and contact information of employees within their department, but only the masked information for employees in other departments, the visible field range will be dynamically adjusted, and the address book will be subjected to differentiated initial masking. This approach implements dynamic masking control based on the requester's permission level, ensuring data security while ensuring on-demand access to information.
[0068] In one embodiment, whether to perform secondary desensitization is determined based on the desensitization confusion score of the initial desensitization;
[0069] Specifically, the calculation steps for the desensitization confusion score are as follows:
[0070] Suppose the field set after field desensitization is ,in, Indicates the first Bar fields;
[0071] Connect all the desensitized field strings into a field string, that is, the set All the field strings in the string are concatenated into one big string: , count the occurrence frequency of all characters (numbers, letters) in the corresponding field string, and let the full set of characters be ,in, is the total number of different characters;
[0072] Count the occurrence frequency of all characters in the corresponding field string ; Get the total number of characters in the field string, the total number of characters is ; Divide the frequency of each character by the total number of characters to get the relative frequency of each character , ;
[0073] Calculate the standard deviation based on the relative frequencies of all characters , where For all Mean; evaluate the degree of dispersion of character distribution in the initial desensitization;
[0074] For two adjacent fields in the field string and , the number of different characters in adjacent fields is used as the edit distance between adjacent fields ; Define edit distance ,common distances;
[0075] Calculate the rate of change between adjacent edit distances , , calculate the mean of all rates of change , ; Evaluate the semantic perturbation diversity of the initial desensitization fields;
[0076] The mean Divide by the standard deviation , and obtain the desensitization confusion score.
[0077] It should be noted that, for example, assuming that the mobile phone number fragment obtained after desensitization is as follows:
[0078] V=["135****2345","137****2347","193****7312","183****2345"], the numeric character part (ignoring the asterisk *) is:
[0079] ["1352345","1372347","1937312","1832345"], extract all the numbers and spell them into a large string: 1352345137234719373121832345"; the total number of characters is 27, and the number of character 1 is 27. =6 / 27, calculate the standard deviation of the probability of all characters appearing; if the frequency of some characters is particularly high, the standard deviation is large, indicating that the distribution is not sufficient and the rule may be guessed. If the frequency of all characters is similar, the standard deviation is small, indicating that it is relatively safe. and , assuming is "1352345", For "1372347", 1352345→1372347, only two numbers are changed, and the edit distance is 2. "1372347" and "1937312", change the two digits to 5, the edit distance is 5, It is 1.5; if the edit distance between all fields changes very little (for example, the difference is 1~2), it means that the field structures are highly similar and the desensitization effect is poor; if the jump between fields is large, it means that the disturbance is sufficient and it is not easy to restore, and the desensitization effect is good.
[0080] It's important to note that the desensitization chaos score, as a core metric for measuring the effectiveness of initial desensitization, essentially assesses the security, irreversibility, and resilience of desensitized data. Using the example of mobile phone number desensitization, we can understand that the desensitization chaos score is measured from two key perspectives: character distribution dispersion and semantic perturbation diversity. Character distribution dispersion primarily focuses on whether the frequency of occurrence of different characters (such as numbers) in the desensitized field is uniform. For example, if the character strings "1352345" and "1372347" are concatenated into the overall string "1352345137234719373121832345," and then the character frequencies are counted, if a character (such as "1" or "3") appears much more frequently than others, the standard deviation increases, indicating structural patterns or skewness in the data. Attackers could use character frequency analysis to infer the true structure of sensitive fields, thereby threatening information privacy. Conversely, if the distribution of characters is uniform and the frequency differences are small, the standard deviation is small, indicating a more random distribution, making it more difficult for attackers to guess the original information, thereby improving the strength of the desensitization. Secondly, the diversity of semantic perturbations is reflected by calculating the rate of change of the edit distance between adjacent fields. Continuing with the mobile phone number example, the edit distance between "1352345" and "1372347" is 2, while the edit distance between "1372347" and "1937312" is 5, with a rate of change of 1.5. This significant fluctuation in the rate of change indicates inconsistent and unpredictable perturbations between fields, resulting in a high degree of overall randomness in the desensitized data structure, making it difficult to restore the fields using a unified model, thereby improving the security of the desensitization. On the other hand, if the differences between two adjacent fields are very small and the rate of change is close to the same (for example, all 1 or 2), the field changes are limited, making them easier to restore using rule matching or clustering algorithms, and the desensitization effect is poor. Therefore, the desensitization confusion score is a comprehensive value obtained by multiplying the "character distribution standard deviation" and the "edit distance change rate mean." A higher value indicates that the desensitized field has a more uniform character distribution and more severe structural perturbations, effectively suppressing attacks such as pattern recognition and reverse recovery, resulting in better desensitization results and higher security. Conversely, a low desensitization confusion score indicates that the desensitized data still has a high degree of structural consistency or character skewness. This will determine that the current initial desensitization strategy is insecure, and the system will automatically enter a secondary desensitization process involving structural perturbations and semantic fragmentation to further enhance data irreversibility.
[0081] It should be noted that the benefits of calculating the desensitization confusion score are: it is not only a security scoring mechanism for existing desensitization results, but also a key judgment basis in the intelligent desensitization decision-making process. It realizes the paradigm shift from "whether to desensitize" to "whether the desensitization is sufficient", and is an important quantitative support in the dynamic sensitive data protection system.
[0082] In one embodiment, the steps of determining whether to perform secondary desensitization based on the desensitization confusion score of the initial desensitization are:
[0083] The desensitization confusion score of the initial desensitization is compared with the preset desensitization confusion score threshold. If the desensitization confusion score is not less than the preset desensitization confusion score threshold, it means that the initial desensitization is qualified and no secondary desensitization is required; the desensitized address book information is directly transmitted to the requesting party for display, realizing the management of the IP phone address book;
[0084] If the desensitization confusion score is less than the preset desensitization confusion score threshold, it means that the initial desensitization is not qualified and a second desensitization is required.
[0085] It should be noted that after the initial masking of address book data, a masking chaos score is calculated to determine whether the current masking meets security requirements. This score is then compared to a preset masking chaos score threshold. The masking chaos score reflects the degree of perturbation of sensitive fields in the data and the balance of character distribution, and is an important indicator for evaluating the effectiveness of masking. If the score is below the preset threshold, the masked data is sufficiently chaotic and difficult to restore, and the initial masking is deemed satisfactory. The masked address book information can then be directly delivered to the requesting party for use, thereby enabling secure address book management for IP phones. However, if the masking chaos score is above or equal to the threshold, it indicates that the initial masking process may have insufficient differentiation between fields or excessive retention of sensitive information features, posing a security risk of restoration. The initial masking will be deemed unsatisfactory, and a secondary masking operation must be performed to further perturb, mask, or replace the relevant fields to further improve the data's unrecognizableness and security, ensuring that the masked data meets privacy protection and information security standards.
[0086] In one embodiment, if secondary desensitization is required, a semantic path diagram of the address book information field is constructed, and structural perturbation and semantic desensitization steps are performed to achieve secondary desensitization. The success of the secondary desensitization is determined based on the desensitization strength score after the secondary desensitization.
[0087] Specifically, the steps for constructing a semantic path graph of the address book information fields and performing structural perturbation and semantic desensitization are as follows:
[0088] Obtain a set of structured data fields to be desensitized and construct a field dependency graph, where the fields serve as nodes and the structural and semantic associations between fields serve as edges.
[0089] Take any two adjacent fields in the field dependency graph as a field pair and calculate the edge weight of any field pair. The edge weight includes the field co-occurrence frequency and semantic similarity.
[0090] Based on the field dependency graph, the DFS algorithm is used to search for paths and identify the path set between fields.
[0091] The sum of the edge weights of each path in the path set is compared with the preset threshold. If it is not less than the preset threshold, the corresponding path is recorded as a sensitive path;
[0092] Random perturbation processing is performed on fields in sensitive paths. The types of random perturbation processing include field order reordering, redundant field insertion and field group reconstruction, and field word vector replacement; thus achieving secondary desensitization.
[0093] In one implementation, the steps for obtaining a set of structured data fields to be desensitized and constructing a field dependency graph, in which the fields serve as nodes and the structural and semantic associations between the fields serve as edges, are as follows:
[0094] Step 1: First, build a dependency graph between fields to reflect the structural relationship and semantic association between fields in the address book. This graph is an undirected graph. , where the node Represents all fields (such as name, employee number, department, position, office phone number, mobile phone number, etc.); edge set Represents any two fields and Semantic or structural co-occurrence (i.e., if two fields often appear together in a large number of address book records, or their meanings have some logical, business or linguistic associations, an undirected edge is constructed between them to indicate that there is a field coupling relationship between them. For example, "Technology Department" → "Backend Engineer", "Marketing Department" → "Brand Manager", "Position" - "Office Phone", etc., it is observed that and Frequently appearing together (such as "Technical Department" and "Development Engineer") and having a natural logical connection, they are considered as field dependencies, edges are added to the field graph, and the weight of the edge is calculated); each edge Incidental weight , used to measure the degree of coupling between fields.
[0095] Take any two adjacent fields in the field dependency graph as a field pair and calculate the edge weight of any field pair. The edge weight includes the field co-occurrence frequency and semantic similarity as follows:
[0096] Weight The calculation formula is: , where and Represents fields respectively and The co-occurrence frequency and semantic similarity of fields; and are the weights of the co-occurrence frequency and the semantic similarity of the fields, respectively, and ;
[0097] Field co-occurrence frequency It is used to characterize the binding strength between fields at the structural level. The calculation method is: , where Representation field The number of occurrences, Representation field The number of occurrences, Representation field The number of times a field appears in the same record. For example, in 10,000 address book records, the "Office Phone" field appears 9,000 times, the "Extension Number" field appears 8,500 times, and both appear 8,000 times. Then: ;
[0098] Field semantic similarity is used to identify semantic relationships between different fields. Its calculation process includes the following key steps. First, a vocabulary of typical values for each field is collected. For example, a "Position" field might include "Development Engineer," "Test Specialist," "Technical Manager," while a "Job Tag" field might include "Backend Development," "Quality Assurance," "Team Leader," and so on. Next, these words or phrases are converted into semantic vectors using a semantic encoding model (such as Word2Vec or BERT). If the field value is a phrase (such as "Technical Lead"), BERT can be used to obtain its overall representation or to average the vectors of each word within it. Next, all word vectors for a given field are averaged to obtain the semantic center vector for that field, which represents the overall distribution of the field in the semantic space. Finally, two fields are selected, their center vectors are taken, and the cosine similarity between them is calculated to measure their proximity in the semantic space.
[0099] Assumption Field For "position", its typical value set is: "Developer", "System Analyst", "Architect"; field For "position labels," typical values include "backend development," "technical planning," and "system design." After converting all words into vectors using BERT, the word vectors in each field are averaged to obtain the following: ; , and then through cosine similarity Calculated fields The semantic similarity between them reflects their semantic coupling and is used as the field semantic similarity.
[0100] In one implementation, the second step is to perform a path search using a DFS algorithm based on the field dependency graph to identify a set of paths between fields. The steps are:
[0101] For the constructed field graph Perform path search using the DFS algorithm to identify field paths with potential semantic or structural associations and form a path set , each path The weight of is defined as the sum of all edge weights in the path: The DFS algorithm can identify all semantically or structurally connected field paths in the field graph, including long paths. The paths identified by the DFS algorithm will not be broken, making the identified paths more complete.
[0102] like If the value is not less than the preset threshold, the path is recorded as a sensitive path, and the sensitive path set is obtained. ;
[0103] For example, if the path weight W of the path "name→department→position→mobile phone number" is 0.85+0.78+0.89=2.52, and the threshold is set to 2.0, then the path is a sensitive path and requires secondary desensitization processing.
[0104] In one implementation method, the third step is to randomly perturb the fields in the sensitive path. The types of random perturbation processing include field reordering, redundant field insertion, field grouping reconstruction, and field word vector replacement to achieve secondary desensitization.
[0105] Field order reordering, redundant field insertion, and field grouping reconstruction are structural perturbation processes, specifically:
[0106] The goal of structural perturbation is to disrupt the structural dependencies between fields, making it difficult for attackers to use the order or adjacency of fields to restore sensitive paths.
[0107] Specifically, fields in sensitive paths are structurally perturbed to break the structural dependencies between existing fields, thereby reducing the possibility of attackers recovering sensitive information based on field associations. Specifically, the original order of sensitive fields can be altered by reordering the fields, disrupting the logical relationships between them. For example, the order of "department-position-phone number" can be changed to "phone number-department-position," thereby interfering with external reasoning paths. Secondly, redundant fields (such as "workstation number," "region," or "organization code") are inserted between sensitive field pairs to expand the field context and increase the learning complexity of the attack model. These redundant fields can be externally generated, template-matched, or derived from non-sensitive fields in historical data. Finally, field grouping and reconstruction can be used to merge multiple fields with strong dependencies into a new abstract field or label field. For example, "department + position" can be merged into "position role label," or "phone number + office phone number" can be combined into "contact information." This weakens the separability and correspondence between the original fields. The synergistic effect of these structural perturbation methods is to effectively reduce the coupling strength between fields by changing the field arrangement structure, disrupting the explicit semantic boundaries and confusing the original field meaning, thereby enhancing the irreversibility and privacy protection effect of desensitized data, and creating a higher-intensity desensitization foundation for subsequent semantic fragmentation processing.
[0108] In one implementation, the fourth step is to replace the field word vector with a semantic fragmentation process, including semantic distance screening and word quantity replacement. Specifically:
[0109] For fields in sensitive paths, obtain their semantic vector representations based on pre-trained word vector models (such as Word2Vec and BERT).
[0110] From a vocabulary of the same type of field values, candidate words whose semantic distance from the original value is within a certain threshold are screened out; this threshold can be flexibly set according to the strength of privacy protection to ensure that the replaced words have a certain degree of semantic relevance but are not easy to restore.
[0111] From the candidate words filtered by semantic distance, a word is randomly selected or selected according to the desensitization strategy to replace the original field value, breaking the original semantic consistency.
[0112] Original field value: "Senior Engineer", candidate set: {"Senior Consultant", "Technical Manager", "R&D Director"} The replacement result may be: "R&D Director"
[0113] It should be noted that the above-mentioned secondary desensitization can destroy the semantic and structural relationship between the original fields, greatly enhancing the privacy protection effect and preventing sensitive paths from being restored by reasoning. For example:
[0114] In the IP phone address book management platform, assume the original data is: "Name: Zhang Wei, Employee Number: 1001, Department: Technology Department, Position: Senior Engineer, Office Phone: 010-88990001, Mobile Number: 13800001111, Extension Number: 101, Office Address: Chaoyang District, Beijing." After the initial masking, it might look like: "Name: Zhang*, Employee Number: *, Department: Technology Department, Position: Senior Engineer, Office Phone: 010-0001, Mobile Number: 1381111, Extension Number: 101, Office Address: ** District, Beijing." Although some field values are masked, the field structure remains unchanged. An attacker can infer the identity based on "Technology Department + 101 + Chaoyang District." After secondary desensitization, the format might be: "Employee Number: ***, Position Label: Technical Position - Level A2, Extension: 89X, Office Area: North District Office Building, Floor C, Contact: 010-**3927, Name: Zhang, Address:". The order of the fields is disrupted, the fields are grouped, and semantically fragmented and replaced. This destroys the semantic and structural relationships between the original fields, greatly enhancing privacy protection and preventing sensitive paths from being inferred and restored.
[0115] In one embodiment, the steps for determining whether the secondary desensitization is successful are:
[0116] Obtain the sensitive path fragmentation rate of secondary desensitization and evaluate the degree of random perturbation of fields in the sensitive path.
[0117] Obtain the semantic change degree of the secondary desensitized field and evaluate the intensity of the disturbance of the semantic content of the field in the sensitive path;
[0118] Obtain the cluster structure change value of the secondary desensitization and evaluate the magnitude of the change in the cluster structure of the field semantic vector set in the sensitive path;
[0119] Normalize the sensitive path fragmentation rate, field semantic change degree, and cluster structure change value to a value between 0 and 1. Take the weighted sum of the normalized sensitive path fragmentation rate, field semantic change degree, and cluster structure change value to obtain a desensitization strength score. This is used to evaluate the strength of the secondary desensitization and determine whether the secondary desensitization is successful based on the desensitization strength score.
[0120] The formula for calculating the desensitization intensity score is: , where Score the intensity of desensitization. They are the sensitive path breakup rate, field semantic change degree and clustering structure change value after normalization.
[0121] It should be noted that, in general, the weighted summation of the normalized sensitive path breakup rate, field semantic change degree, and cluster structure change value is equal, and the sum of the weights is 1.
[0122] In one embodiment, the steps for calculating the sensitive path breakup rate are as follows:
[0123] Extract all sensitive paths from the field dependency graph , : Obtain the disturbance types of all field pairs in each sensitive path during the secondary desensitization process, and assign different disturbance weights to different disturbance types as the processing score of the corresponding field pairs;
[0124] Calculate the mean perturbation score of all field pairs in each sensitive path as the processing score of the corresponding sensitive path;
[0125] The mean of the processing scores of all sensitive paths is calculated, and the mean is set at the preset minimum processing score to obtain the sensitive path dispersion rate.
[0126] It's important to note that the sensitive path breakup rate reflects the degree to which field paths with strong structural and semantic coupling in the field dependency graph are "broken up" or "structurally altered" after desensitization. In other words, the degree of random perturbation applied to the fields. Its essential purpose is to assess the system's ability to disrupt the associations between sensitive fields, ensuring that even if data is illegally restored or inferred, it is difficult to establish strong semantic or structural connections between sensitive fields. Sensitive paths are paths where multiple fields are tightly connected structurally and highly semantically related, such as "name → phone number → address." If maliciously exploited, these paths could lead to the complete restoration of user privacy. Therefore, breaking up the structural and semantic coupling of these paths is a key task in desensitization. In actual calculations, perturbations are performed on each field pair in a sensitive path, such as reordering the fields (weak perturbation), inserting redundant fields (medium perturbation), or regrouping the fields (strong perturbation). Different weights are assigned to the perturbation types, and a path perturbation score is calculated. This score is then aggregated into a breakup rate metric. A high fragmentation rate indicates that most sensitive paths have been sufficiently perturbed, weakening or destroying the direct dependencies between original field pairs within the path, thereby enhancing data irreversibility and anonymity. For example, in an IP phone address book management platform, a sensitive path such as "contact name → department → phone number" could allow attackers to identify users through the fixed patterns of these fields. If secondary desensitization is performed by randomizing the field order, inserting redundant fields such as department number, and separating name and phone number information into different groups, the desensitized data structure will destroy the direct connectivity between the original fields, resulting in a "contact number → department number → obfuscated phone number" structure, significantly reducing the risk of inference attacks. A higher fragmentation rate means that sensitive paths are more difficult to recover and the probability of information re-identification is lowered. Therefore, an increase in the fragmentation rate of sensitive paths directly corresponds to a stronger secondary desensitization of the data, meaning that the data can be more securely transmitted to the requesting party for display and use, thereby achieving intelligent and secure management of IP phone address books without compromising user privacy.
[0127] In one implementation, analyzing the sensitive path breakup rate for determining the success of secondary masking offers the following advantages: it quantifies the extent to which coupling between sensitive fields has been weakened, providing a direct indicator of secondary masking effectiveness. Compared to simply determining field changes, the sensitive path breakup rate not only considers perturbations between field pairs but also comprehensively assesses the structural and semantic discontinuities of the entire sensitive path, offering stronger global sensitivity identification capabilities. This metric effectively identifies residual high-risk field combination paths, avoiding false redactions such as "partial redaction without path breakage," and improving the comprehensiveness of the redaction process. Furthermore, this metric provides adjustable redaction strength criteria, facilitating flexible control of redaction policies based on actual security needs. For example, in IP phone address book management, breaking up sensitive paths such as "name-department-landline" significantly reduces the likelihood of user identity inference, thereby ensuring controllable and compliant data display. Therefore, the sensitive path breakup rate is not only a crucial component of the redaction strength score but also provides reliable decision-making support for automated redaction.
[0128] In one embodiment, the steps for calculating the field semantic variation are:
[0129] For each field of the secondary desensitization, obtain the semantic vector of the field before desensitization and the corresponding semantic vector after desensitization; for each field, calculate the distance between the semantic vectors before and after desensitization as the semantic jump distance. The calculation formula is: , where and Respectively Semantic vectors of fields before and after desensitization;
[0130] Set the jump distances of all field values , ,in Indicates the total number of disturbed field samples;
[0131] Calculation Set The mean of all jump distances in and standard deviation , and calculate the coefficient of variation based on the mean and standard deviation , the calculation formula is: ; is the minimum value, and the value is Used to prevent division by 0;
[0132] The field semantic variation is calculated based on the median jump distance and coefficient of variation of all field values. The calculation formula is: , where is the semantic change degree of the field, is the median jump distance.
[0133] It should be noted that the degree of field semantic change refers to the extent of change in the semantics of each field during the secondary desensitization process. It is used to measure the degree of jump between the original semantics of the field and the desensitized semantics. In other words, the intensity of the perturbation of the semantic content of each field without changing the overall structure. Its essence is to measure the effectiveness of "semantic perturbation": whether the desensitized field is effectively deviated from the original semantic context, thereby interrupting the potential semantic reasoning link between fields. The greater the degree of field semantic change, the farther the field is offset in the semantic space. This means that even if the field remains in place structurally, it is difficult for an attacker to infer the true information through the original understanding of the field semantics. Therefore, the higher the degree of semantic change, the stronger the desensitization process and the more significant the privacy protection effect. Especially in the IP phone address book management scenario, for example, after the "Position" field of the original field "Technical Department Manager" is replaced with "Product Consultant" or "Outsourcing Coordinator" through semantic fragmentation, not only is the semantic deviation large, but it can also effectively obscure sensitive information such as identity level and organizational structure carried by the original field, making it impossible for attackers to reconstruct user portraits through high-frequency combinations such as names and positions, thereby achieving a strong anti-inference desensitization effect.
[0134] In one implementation, because the calculation of semantic variation combines the median jump and the coefficient of variation, it reflects both the overall degree of disturbance and the unique jump characteristics of locally sensitive fields, enabling a more refined assessment of whether the desensitized field possesses sufficient "semantic unfamiliarity." Therefore, in practical systems, field semantic variation is an essential core metric in desensitization strength scoring. A significant increase in its value provides a strong basis for determining whether data should be passed to the requesting party, effectively supporting security decisions regarding externally displayed data in IP phone address book platforms.
[0135] In one embodiment, the steps for calculating the cluster structure change value are:
[0136] For each field in the secondary masking, obtain the semantic vector before and after masking. Use the same clustering algorithm and parameters (such as K-Means with a fixed k value) to cluster the original and masked field semantic vector sets separately:
[0137] The clarity of the semantic clustering structure before and after desensitization is calculated by calculating the silhouette coefficient and ;
[0138] calculate and The absolute difference is used as the change in cluster structure;
[0139] Divide the change in cluster structure by the clarity of the semantic cluster structure before desensitization , and obtain the clustering structure change value.
[0140] It should be noted that the cluster structure change value refers to the magnitude of the change in the cluster structure of the field semantic vector set during the secondary masking process. It is used to measure the stability and variability of the overall semantic distribution structure of the field before and after masking. The core concept is: if a group of fields is clustered into clearly structured and well-defined semantic clusters before masking, and the semantic vectors of these fields are perturbed after masking, causing the original cluster structure to be disrupted, reconstructed, or even blurred, then the masking operation has caused sufficient perturbation at the global semantic distribution level, enhancing the ability to resist inference attacks. The cluster structure change value quantifies the degree of perturbation of the global semantic distribution by comparing the cluster silhouette coefficient before and after masking, calculating its standard deviation, and normalizing it. A larger cluster structure change value indicates that the original field clustering characteristics in the semantic space have been significantly destroyed. This generally means that attackers cannot restore the original semantic categories, user groups, or job organizational structure by clustering similar fields, further enhancing the anonymity of the data in the logical semantic dimension. For example, in an IP phone address book platform, if original fields such as "Marketing Manager," "Sales Director," or "Advertising Consultant" contain semantic fields related to job titles, they would form a "Marketing Position" cluster in the semantic space. However, after desensitization, these fields become non-standardized semantic fields such as "Temporary Coordinator," "Product Agent," and "External Liaison Assistant." This reduces the clarity (silhouette coefficient) of the original cluster and blurs the classification boundaries, making it difficult for attackers to identify the actual job titles or organizational structure through semantic grouping. This type of cluster destruction is crucial in preventing social engineering attacks.
[0141] In one implementation, the cluster structure change value is a key indicator of the effectiveness of semantic-level perturbation. Higher values indicate deeper semantic disguise, lower classification discernibility, and stronger desensitization. This allows the platform to more securely use secondary desensitized contact data for external display and business sharing, achieving the dual goals of protecting privacy and ensuring usability.
[0142] In one embodiment, the steps for determining whether the secondary desensitization is successful based on the desensitization intensity score after the secondary desensitization are:
[0143] The desensitization strength score is compared with the preset desensitization strength score threshold. If the desensitization strength score is not less than the preset desensitization strength score threshold, it means that the secondary desensitization is successful. The secondary desensitized address book information is then transmitted to the requesting party for display, thereby realizing the management of the IP phone address book.
[0144] If the desensitization strength score is less than the preset desensitization strength score threshold, it means that the secondary desensitization is unsuccessful and the secondary desensitization is performed again until the desensitization strength score is not less than the preset desensitization strength score threshold. The address book information after the secondary desensitization is transmitted to the requesting party for display, thereby realizing the management of the IP phone address book.
[0145] It should be noted that if the score is at least the threshold, the secondary desensitization process has achieved acceptable perturbation strength across all three dimensions: structural perturbation, semantic perturbation, and clustering perturbation. This is sufficient to break the inherent connections and semantic identifiability between the original sensitive fields, thus deeming the secondary desensitization successful. The system can then securely transmit the desensitized address book information to the requesting party, ensuring both data availability and user privacy. If the score is below the threshold, however, it indicates that the current desensitization process has failed to effectively weaken the implicit connections or semantic clustering between fields, posing a risk of information re-identification. In this case, the system will automatically re-execute the secondary desensitization process until the perturbation strength meets the required level. This iterative process offers significant advantages: on the one hand, it ensures that each data export is fully evaluated before export, avoiding the risk of information leakage caused by insufficient one-time processing; on the other hand, it drives decisions based on quantitative criteria, making desensitization quality controllable and reproducible, thereby enhancing the data security credibility and engineering automation level of the entire IP phone address book management system. For example, even if an attacker tries to use semantic reasoning or cluster analysis to infer the true identity or department structure, the effective reconstruction path will be lost due to sufficient disturbance intensity, cutting off the potential sensitive information leakage channel from the root.
[0146] Based on the same inventive concept, the present invention also provides a management device based on the IP phone address book management platform. Figure 2 , Figure 2 A framework diagram of a management device based on an IP phone address book management platform provided in an embodiment of the present invention, the device comprising:
[0147] Initial desensitization module: When receiving a request to view contact information, it identifies the preset permission level of the requester and queries the desensitization operation based on the preset permission level of the requester to perform initial desensitization of the contact information data;
[0148] Desensitization confusion scoring module: According to the address book information after preliminary desensitization, each field corresponds to The desensitization confusion score is calculated based on the frequency of occurrence of characters and the number of inconsistencies in the corresponding characters in adjacent fields, which is used to evaluate the degree of discreteness of the character distribution and the degree of diversity of field semantic disturbance in the initial desensitization.
[0149] Secondary desensitization module: When the desensitization confusion score is less than the preset desensitization confusion score threshold, the address book information is desensitized for the second time
[0150] Judgment module: Builds a semantic path diagram for the address book information field, performs structural perturbation and semantic desensitization steps, implements secondary desensitization, and determines whether the secondary desensitization is successful;
[0151] Management module: If the secondary desensitization is successful, the secondary desensitized address book information will be transmitted to the requesting party for display, thus realizing the management of the IP phone address book.
[0152] A management device based on an IP phone address book management platform provided by an embodiment of the present invention can evaluate the desensitization quality of address book information in the above manner, determine whether secondary desensitization is required, perform secondary desensitization if necessary, and use the address book information after secondary desensitization as the address book information, thereby reducing the potential risk of privacy leakage and reducing the risk of privacy leakage of address book information of enterprises or organizations.
[0153] The above is a detailed description of an embodiment of the present invention, but the content is only a preferred embodiment of the present invention and should not be considered to limit the scope of the present invention. All equivalent changes and improvements made within the scope of the present invention should still fall within the scope of the patent coverage of the present invention.
Claims
1. A management method based on an IP phone address book management platform, characterized in that: The following steps are involved: When receiving a request to view contact information, identify the preset permission level of the requester, and query the desensitization operation based on the preset permission level of the requester to perform preliminary desensitization of the contact information data; According to the address book information after preliminary desensitization, each field corresponds to The desensitization confusion score is calculated based on the frequency of occurrence of characters and the number of inconsistencies in the corresponding characters in adjacent fields, which is used to evaluate the degree of discreteness of the character distribution and the degree of diversity of field semantic disturbance in the initial desensitization. When the desensitization confusion score is less than the preset desensitization confusion score threshold, the contact information is desensitized twice; Construct a semantic path diagram for the address book information fields, perform structural perturbation and semantic desensitization steps, implement secondary desensitization, and determine whether the secondary desensitization is successful; If the secondary desensitization is successful, the secondary desensitized address book information will be transmitted to the requesting party for display, thus realizing the management of the IP phone address book.
2. A management method based on an IP phone address book management platform according to claim 1, characterized in that: The calculation steps of the desensitization confusion score are as follows: Concatenate all desensitized field strings into a field string and count the occurrence frequencies of all characters in the corresponding field string; Get the total number of characters in the field string, divide the occurrence frequency of each character by the total number of characters, and use it as the relative frequency of each character; Calculated based on the relative frequency of all characters Standard deviation, which evaluates the dispersion of character distribution in the initial desensitization; For two adjacent fields in the field string, the number of different characters in the adjacent fields is used as the edit distance between the adjacent fields; Calculate the rate of change between adjacent edit distances, calculate the mean of all change rates, and evaluate the diversity of semantic perturbations in the initial desensitization field. The mean was divided by the standard deviation to obtain the desensitization confusion score.
3. A management method based on an IP phone address book management platform according to claim 1, characterized in that: If the desensitization confusion score is not less than the preset desensitization confusion score threshold, it means that the character distribution dispersion of the initial desensitization is small and the field semantic disturbance diversity is large, which means that the initial desensitization is qualified and no secondary desensitization is required; the desensitized address book information is directly transmitted to the requesting party for display, realizing the management of the IP phone address book.
4. A management method based on an IP phone address book management platform according to claim 1, characterized in that: The steps for constructing a semantic path graph of the address book information fields and performing structural perturbation and semantic desensitization are as follows: Obtain a set of structured data fields to be desensitized and construct a field dependency graph, where the fields serve as nodes and the structural and semantic associations between fields serve as edges. Take any two adjacent fields in the field dependency graph as a field pair and calculate the edge weight of any field pair. The edge weight includes the field co-occurrence frequency and semantic similarity. Based on the field dependency graph, the DFS algorithm is used to search for paths and identify the path set between fields. The sum of the edge weights of each path in the path set is compared with the preset threshold. If it is not less than the preset threshold, the corresponding path is recorded as a sensitive path; Random perturbation processing is performed on the fields in the sensitive path. The random perturbation processing types include field order reordering, redundant field insertion and field group reconstruction, and field word vector replacement; achieving secondary desensitization.
5. A management method based on an IP phone address book management platform according to claim 4, characterized in that: The steps to determine whether the secondary desensitization is successful are: Obtain the sensitive path fragmentation rate of secondary desensitization and evaluate the degree of random perturbation of fields in the sensitive path. Obtain the semantic change degree of the secondary desensitized field and evaluate the intensity of the disturbance of the semantic content of the field in the sensitive path; Obtain the cluster structure change value of the secondary desensitization and evaluate the magnitude of the change in the cluster structure of the field semantic vector set in the sensitive path; Normalize the sensitive path fragmentation rate, field semantic change degree, and cluster structure change value to a value between 0 and 1. Take the weighted sum of the normalized sensitive path fragmentation rate, field semantic change degree, and cluster structure change value to obtain a desensitization strength score. This is used to evaluate the strength of the secondary desensitization and determine whether the secondary desensitization is successful based on the desensitization strength score.
6. A management method based on an IP phone address book management platform according to claim 5, characterized in that: The calculation steps of the sensitive path break-up rate are as follows: Extract all sensitive paths from the field dependency graph: Obtain the random perturbation processing types corresponding to all fields in each sensitive path during the secondary desensitization process, and assign different processing weights to different random perturbation processing types as the processing score for the corresponding field pairs. Calculate the average processing score of all field pairs in each sensitive path as the processing score of the corresponding sensitive path; The mean of the processing scores of all sensitive paths is calculated, and the mean is set at the preset minimum processing score to obtain the sensitive path dispersion rate.
7. A management method based on an IP phone address book management platform according to claim 5, characterized in that: The calculation steps of the field semantic change degree are as follows: For each field of the secondary desensitization, obtain the semantic vector of the field before desensitization and the corresponding semantic vector after desensitization; for each field, calculate the distance between the semantic vectors before and after desensitization as the semantic jump distance; The jump distances of all field values are combined into a set, and the mean of all jump distances in the set is calculated. and standard deviation , and calculate the coefficient of variation based on the mean and standard deviation , the calculation formula is: ; The value is , used to prevent division by 0; The field semantic variation is calculated based on the median jump distance and coefficient of variation of all field values. The calculation formula is: , where is the semantic change degree of the field, is the median jump distance.
8. A management method based on an IP phone address book management platform according to claim 5, characterized in that: The calculation steps of the cluster structure change value are: For each field of the secondary desensitization, obtain the semantic vector of the field before desensitization and the corresponding semantic vector after desensitization; use the same clustering algorithm and parameters to cluster the original and desensitized field semantic vector sets separately: The silhouette coefficient is calculated as the clarity of the semantic clustering structure before and after desensitization; Calculate the absolute difference in the clarity of the semantic clustering structure before and after desensitization as the change in clustering structure; The cluster structure change value is obtained by dividing the cluster structure change by the clarity of the semantic cluster structure before desensitization.
9. A management method based on an IP phone address book management platform according to claim 1, characterized in that: The steps to judge whether the secondary desensitization is successful based on the desensitization intensity score after the secondary desensitization are: The desensitization strength score is compared with the preset desensitization strength score threshold. If the desensitization strength score is not less than the preset desensitization strength score threshold, it means that the secondary desensitization is successful. The secondary desensitized address book information is then transmitted to the requesting party for display, thereby realizing the management of the IP phone address book. If the desensitization strength score is less than the preset desensitization strength score threshold, it means that the secondary desensitization is unsuccessful and the secondary desensitization is performed again until the desensitization strength score is not less than the preset desensitization strength score threshold. The address book information after the secondary desensitization is transmitted to the requesting party for display, thereby realizing the management of the IP phone address book.
10. A management device based on an IP phone address book management platform, used to implement the management method based on an IP phone address book management platform according to any one of claims 1 to 9, characterized in that: The device comprises: Initial desensitization module: When receiving a request to view contact information, it identifies the preset permission level of the requester and queries the desensitization operation based on the preset permission level of the requester to perform initial desensitization of the contact information data; Desensitization confusion scoring module: According to the address book information after preliminary desensitization, each field corresponds to The desensitization confusion score is calculated based on the frequency of occurrence of characters and the number of inconsistencies in the corresponding characters in adjacent fields, which is used to evaluate the degree of discreteness of the character distribution and the degree of diversity of field semantic disturbance in the initial desensitization. Secondary desensitization module: When the desensitization confusion score is less than the preset desensitization confusion score threshold, the address book information is desensitized for the second time Judgment module: Builds a semantic path diagram for the address book information field, performs structural perturbation and semantic desensitization steps, implements secondary desensitization, and determines whether the secondary desensitization is successful; Management module: If the secondary desensitization is successful, the secondary desensitized address book information will be transmitted to the requesting party for display, thus realizing the management of the IP phone address book.