Database desensitization method and device, equipment, storage medium and computer program product
By constructing a target syntax tree to identify sensitive fields in database query statements, this technology solves the problems of low efficiency and inaccurate identification in existing desensitization techniques, achieving efficient and accurate database desensitization.
Patent Information
- Application Number
- CN202510871759.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-26
- Publication Date
- 2025-10-17
AI Technical Summary
Existing database desensitizing technology has the problems of low desensitization efficiency and inability to accurately identify sensitive fields.
An abstract syntax tree is constructed by parsing database query statements, which is then converted into a target syntax tree. The dependency relationship between target fields and metadata fields is recorded. The inheritance relationship of sensitive attributes is determined recursively from bottom to top, and desensitization is performed based on preset rules.
It enables accurate identification of sensitive fields without executing query statements, improving the efficiency of data masking and response time, and ensuring data security.
Smart Images

Figure CN120805175A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data processing, in particular to a database desensitization method, a database desensitization device, a database desensitization equipment, a storage medium and a computer program product. BACKGROUND
[0002] In many business scenarios, since the data stored in the database may involve sensitive information such as user privacy or business secrets, it is necessary to implement desensitization processing on the results of database query operations as a necessary security measure.
[0003] Current database desensitization technologies mainly include static desensitization and dynamic desensitization. The static desensitization responds to query requests by pre-storing desensitized data in the data storage medium, but the real-time performance is significantly reduced due to the need to maintain multiple copies of data, making it difficult to adapt to complex and variable business scenario requirements. Dynamic desensitization includes regular matching mode and syntax parsing mode. The existing regular matching mode requires a large number of pre-set rules and cannot effectively parse nested query structures, while the syntax parsing mode has technical defects such as insufficient function semantic analysis capability and missing cross-table blood relationship tracking when facing database query statements containing complex function calculations and multi-table association, resulting in insufficient accuracy of sensitive field identification and sensitive data leakage.
[0004] In summary, the existing desensitization technologies generally have the problems of low desensitization efficiency and inability to accurately desensitize. SUMMARY
[0005] The main purpose of the present application is to provide an invention name, aiming to solve the technical problems of low desensitization efficiency and inability to accurately desensitize of the existing desensitization technologies.
[0006] To achieve the above-mentioned purpose, the present application provides a database desensitization method, which comprises:
[0007] In response to a query request for a target database, a database query statement in the query request is parsed, an abstract syntax tree is constructed based on the database query statement, and the abstract syntax tree is converted into a target syntax tree, wherein the target syntax tree records the dependency relationship between the target field in the database query statement and the metadata field in the target database;
[0008] The nodes of the target syntax tree are traversed, and the sensitive attribute inheritance relationship between the nodes of the target syntax tree is recursively determined from bottom to top to predict the sensitive fields of the target result set obtained after pre-executing the database query statement;
[0009] Desensitization is performed on the sensitive fields based on pre-set desensitization rules, and the desensitized result set is returned to the query request party.
[0010] In an embodiment, the step of converting the abstract syntax tree into a target syntax tree comprises:
[0011] Based on the preset construction rule and the database query statement, an initial syntax tree is constructed;
[0012] By traversing the abstract syntax tree, a function node in the abstract syntax tree is determined;
[0013] Based on the metadata field in the target database, a cross-table inheritance path in the database query statement is determined;
[0014] The mapping relationship between the input field and the output field in the function node and the cross-table inheritance path are written into the node of the initial syntax tree as a dependency relationship, forming a target syntax tree.
[0015] In an embodiment, the step of determining the cross-table inheritance path in the database query statement based on the metadata field in the target database comprises:
[0016] According to the metadata field in the target database, the original table to which each field in the database query statement belongs in the target database is located;
[0017] According to the associated expression in the database query statement, the field mapping relationship in the database query statement is extracted;
[0018] Based on the original table and the field mapping relationship, the cross-table inheritance path in the database query statement is determined.
[0019] In an embodiment, the target syntax tree node comprises leaf nodes representing metadata fields in the target database and non-leaf nodes representing target fields in the database query statement; the step of recursively determining the sensitive attribute inheritance relationship between the nodes of the target syntax tree from bottom to top comprises:
[0020] For a leaf node, the preset sensitive field marking rule is queried, and if the metadata field represented by the current leaf node is a sensitive field, the current leaf node is marked as sensitive;
[0021] For a non-leaf node, if any child node of the non-leaf node has a sensitive mark, the sensitive field of the child node is inherited and the current non-leaf node is marked as sensitive;
[0022] After the recursive completion from bottom to top, the sensitive attribute inheritance relationship between the nodes of the target syntax tree is determined through all the nodes marked as sensitive.
[0023] In an embodiment, after the step of traversing the nodes of the target syntax tree, recursively determining the sensitive attribute inheritance relationship between the nodes of the target syntax tree from bottom to top to predict the sensitive fields of the target result set obtained after pre-executing the database query statement, the method further comprises:
[0024] When it is detected that the database query statement is a preset complex statement, performing field desensitization processing on the sensitive fields of the nodes at the nodes marked as sensitive in the target syntax tree;
[0025] Based on the new nodes after the field desensitization processing, generating a latest database query statement, and obtaining a desensitized result set through the latest database query statement.
[0026] In an embodiment, the method comprises:
[0027] When it is detected that the database query statement queries a data amount less than a preset data amount threshold, executing the database query statement in the target database to obtain an original result set;
[0028] Applying a preset desensitization rule to the sensitive fields in the original result set to perform desensitization, and returning a desensitized result set to the requester.
[0029] In addition, to achieve the above-mentioned purpose, the present application further provides a database desensitization device, which comprises: a conversion module, configured to respond to a query request for a target database, parse a database query statement in the query request, construct an abstract syntax tree based on the database query statement, and convert the abstract syntax tree into a target syntax tree, wherein the target syntax tree records the dependency relationship between a target field in the database query statement and a metadata field in the target database;
[0030] A determination module is configured to traverse the nodes of the target syntax tree, recursively determine the sensitive attribute inheritance relationship between the nodes of the target syntax tree from bottom to top, and predict the sensitive fields of a target result set obtained after pre-executing the database query statement.
[0031] A desensitization module is configured to perform desensitization on the sensitive fields based on a preset desensitization rule, and return a desensitized result set to the query requester.
[0032] In addition, to achieve the above-mentioned purpose, the present application further provides a database desensitization device, which comprises: a memory, a processor, and a computer program stored on the memory and executable on the processor, the computer program being configured to implement the steps of the database desensitization method as described above.
[0033] In addition, to achieve the above object, the present application further provides a storage medium, which is a computer readable storage medium, and a computer program is stored on the storage medium, and the computer program is executed by a processor to implement the steps of the database desensitization method.
[0034] In addition, to achieve the above object, the present application further provides a computer program product, which comprises a computer program, and the computer program is executed by a processor to implement the steps of the database desensitization method.
[0035] The one or more technical solutions provided by the present application have at least the following technical effects:
[0036] The existing database desensitization has the technical problems of low desensitization efficiency and inaccurate sensitive field identification.
[0037] The technical solution of the present application, after parsing the database query statement in the query request, constructs an abstract syntax tree, and then based on the abstract syntax tree, converts and generates a target syntax tree recording the dependency relationship between the target field and the target database metadata field in the database query statement; then traverses the nodes of the target syntax tree, recursively determines the sensitive attribute inheritance relationship between the nodes of the target syntax tree from bottom to top, to pre-judge the sensitive fields of the target result set obtained after pre-executing the database query statement; in this process, the abstract syntax tree is converted into the target syntax tree, and the sensitive attribute inheritance relationship between the nodes of the target syntax tree is determined, which can establish the sensitive field transmission path between the target field and the metadata field, so as to accurately identify the sensitive field; according to the sensitive attribute inheritance relationship, the sensitive fields of the target result set obtained after pre-executing the database query statement can be pre-judged, and this method can avoid the calculation burden of actual query execution to a certain extent, and can improve the response timeliness of the query, so as to improve the desensitization efficiency. Finally, based on the preset desensitization rule, the actual query data obtained by the latest database query statement is desensitized, and the sensitive fields are pre-identified, which can improve the desensitization efficiency; then the sensitive fields are desensitized, and the desensitized result set is returned to the query request side, which overall achieves the purpose of ensuring data security while significantly improving the response timeliness of complex queries. BRIEF DESCRIPTION OF DRAWINGS
[0038] The accompanying drawings, which are incorporated into and form part of the specification, illustrate embodiments consistent with the present application and, together with the specification, serve to explain the principles of the present application.
[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the accompanying drawings needed to be used in the embodiments or prior art description will be briefly introduced as follows. Obviously, the drawings are only for the purpose of illustrating the embodiments of the present application, and for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative labor.
[0040] Figure 1 The flowchart provided by the embodiment of the database desensitization method of the present application;
[0041] Figure 2 The schematic diagram of the query request involved party in the database desensitization method of the present application;
[0042] Figure 3 The brief flowchart provided by another embodiment of the database desensitization method of the present application;
[0043] Figure 4 The schematic diagram of the sensitive attribute inheritance in the database desensitization method of the present application;
[0044] Figure 5 The desensitization mode schematic diagram of the database desensitization method of the present application;
[0045] Figure 6 The desensitization system schematic diagram loaded in the database desensitization device of the present application;
[0046] Figure 7 The module structure schematic diagram of the database desensitization device of the present application;
[0047] Figure 8 The device structure schematic diagram of the hardware running environment involved in the database desensitization method of the present application.
[0048] The purpose implementation, functional features and advantages of the present application will be further described with reference to the accompanying drawings combined with the embodiments. DETAILED DESCRIPTION
[0049] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application, and are not used to limit the present application.
[0050] In order to better understand the technical solutions of the present application, the following will be described in detail combined with the drawings in the specification and specific embodiments.
[0051] It should be noted that the execution subject of the present embodiment can be a database desensitization device, or a computing service device with data processing, network communication and program running functions, such as tablet computer, personal computer, mobile phone, etc., or an electronic device, processor, etc. capable of realizing the above functions. The following takes the database desensitization device as an example to describe the present embodiment and the following embodiments.
[0052] Based on this, the embodiment of the present application provides a database desensitization method, referring to Figure 1 , Figure 1 This is a flowchart of an embodiment of the database desensitization method of the present application.
[0053] In this embodiment, the database desensitization method includes steps S10 to S30:
[0054] Step S10: In response to a query request to a target database, parsing a database query statement in the query request, constructing an abstract syntax tree based on the database query statement, and converting the abstract syntax tree into a target syntax tree, wherein the target syntax tree records the dependency relationship between the target field in the database query statement and the metadata field in the target database;
[0055] It should be noted that in response to a user's query request to a target database (e.g., MySQL or Derby), the database query statement (i.e., SQL statement) in the query request is first parsed. By performing semantic analysis on the SQL statement, an abstract syntax tree (AST) is constructed. The tree-like structure of the AST breaks down the SQL syntax elements (such as SELECT clauses and JOIN conditions) layer by layer. The AST is then converted into a target syntax tree. This process analyzes field reference relationships, that is, the dependencies between fields in the SQL statement and metadata fields in the target database (for example, parsing the "phone" field in "SELECTa.phone FROM users a" as being derived from the metadata field "phone" in the "users" table). The target syntax tree records the dependencies between the target fields of the database query statement (i.e., the fields in the SQL output, such as "phone") and the metadata fields of the target database (i.e., the original fields stored in the physical table, such as "users.phone"). This dependency is essentially a data lineage link, ensuring that sensitive attributes can be subsequently traced along the path.
[0056] For example, Figure 2 As shown, Figure 2 A schematic diagram of the connection between a requester, a database desensitizing device, and a target database.
[0057] It is understandable that performing step S10 can provide a traceable data source basis for predicting the sensitive attributes of the target field (such as determining whether the phone needs to be desensitized), and solve the core defects of the regular solution being unable to parse nested queries and the traditional syntax parsing lacking cross-table lineage.
[0058] In one embodiment, the step of converting the abstract syntax tree into a target syntax tree in step S10 includes:
[0059] Based on the preset construction rule and the database query statement, an initial syntax tree is constructed;
[0060] By traversing the abstract syntax tree, a function node in the abstract syntax tree is determined;
[0061] Based on the metadata field in the target database, a cross-table inheritance path in the database query statement is determined;
[0062] The mapping relationship between the input field and the output field in the function node and the cross-table inheritance path are written into the node of the initial syntax tree as a dependency relationship, forming a target syntax tree.
[0063] It should be noted that when the database query statement is parsed, according to the type of the target database, a corresponding parsing rule is selected, the database query statement is semantically verified, semantically defined and a context is generated, so as to construct the abstract syntax tree.
[0064] The pre-defined syntax construction rule can be a piece of code written by the user, which can exemplarily include a PostgreSQLParserVisitor (a visitor for syntax analysis), a visitStatementContext (a method for rewriting and processing a syntax analysis node corresponding to a SQL statement such as a SELECT statement and an INSERT statement), a visitClauseContext (a method for processing a clause in a SQL statement such as a WHERE, an ORDERBY, a FROM and the like), a visitExprContext (a method for processing a SQL expression such as a+b, COUNT(*), column_name and the like), and a visitTerminal (a method for processing a leaf node / terminal symbol such as a keyword, an identifier, an operator, a literal and the like in the syntax tree).
[0065] Based on the pre-defined syntax construction rules and the user-submitted database query statement, an initial syntax tree is first generated; then the abstract syntax tree is traversed, the tree structure of the abstract syntax tree is disassembled according to the syntax rules to locate all function nodes (such as CONCAT (phone, name) or SUM (salary)) in the abstract syntax tree, and the mapping logic of the input fields and the output fields in the function (such as the input fields of CONCAT being phone and name, and the output being the merged string) is parsed; at the same time, based on the metadata fields of the target database (system tables storing table structures and field attributes), the cross-table inheritance path is extracted based on the associated expression in the SQL (such as JOIN users ON orders.user_id=users.id), that is, the data lineage link between the original table fields (such as orders.user_id→users.id→users.phone) is established; finally, the field mapping relationship of the function node and the cross-table inheritance path are written into the corresponding nodes of the initial syntax tree as the dependency relationship, and a target syntax tree carrying complete semantics and lineage information is formed, providing a structured basis for subsequent sensitive attribute recursive inheritance.
[0066] In the embodiment, by recording the mapping relationship between the input fields and the output fields in the function node, it is ensured that the sensitive attributes in the function expression are not ignored, and the function semantics are parsed; in addition, based on the metadata fields in the target database, the cross-table inheritance path is determined, which can solve the defect of multi-table association fracture caused by the change of data and the inability to change the field sensitivity in time in the traditional desensitization technical solution.
[0067] Exemplarily, as shown in Figure 3 , first, the database query statement is semantically parsed to obtain an abstract syntax tree, and exemplarily, the tree structure of the abstract syntax tree can be as shown in Figure 3 ; secondly, according to the pre-set construction rule, an initial syntax tree is obtained, and the mapping relationship between the function input fields and the output fields and the cross-table inheritance path are written into the nodes of the initial syntax tree to obtain a target syntax tree.
[0068] In another embodiment, the step of determining the cross-table inheritance path in the database query statement based on the metadata fields in the target database comprises:
[0069] According to the metadata fields in the target database, the original table to which each field in the database query statement belongs in the target database is located;
[0070] According to the associated expression in the database query statement, the field mapping relationship in the database query statement is extracted;
[0071] Based on the original table and field mapping relationship, the cross-table inheritance path in the database query statement is determined.
[0072] It should be noted that, based on the metadata field in the target database (i.e., the table data describing the table structure and field attributes), the physical belonging original table of each field in the database query statement is located (such as when analyzing SELECT user.phone, the metadata field confirms that the phone field belongs to the user table); according to the associated expression in the database query statement (such as JOIN orders ON user.id=orders.user_id or WHERE dept.id=employee.dept_id), the explicit or implicit field mapping relationship (i.e., the associated field pair such as user.id→orders.user_id) is extracted; finally, the located original table (such as the user table and the orders table) and the field mapping relationship are combined to determine the cross-table inheritance path, that is, to establish a complete field-level blood relationship link from the source table to the target table (such as user.id→orders.user_id→orders.amount), which provides data flow basis for subsequent cross-table tracking of sensitive fields.
[0073] In this embodiment, by locating the physical belonging original table of the field in the database query statement through the target database metadata field and analyzing the associated expression in the database query statement to obtain the associated field pair, the existing regular desensitization scheme can be avoided to define a large number of rules; by displaying or implicitly associating through the field mapping relationship, the defect that the traditional desensitization technology cannot establish a blood full-link can be solved, and such cross-table inheritance path can support multi-level cross-table and adapt to complex query scenarios, such as multi-layer nested scenarios.
[0074] Step S20, traversing the nodes of the target syntax tree, recursively determining the sensitive attribute inheritance relationship between the nodes of the target syntax tree from bottom to top, to pre-judge the sensitive fields of the target result set obtained after pre-executing the database query statement;
[0075] It should be noted that when traversing the nodes of the target syntax tree, a bottom-up recursive strategy is adopted: starting from the leaf nodes (i.e., metadata fields in the target database, such as original table columns) and processing parent nodes (i.e., target fields of the database query statement, such as SELECT output columns) layer by layer upwards. In this process, according to the pre-set sensitive field marking rules (such as marking users.phone as sensitive in the metadata), the sensitive attribute inheritance relationship between nodes is recursively calculated - if a child node (metadata field) is marked as sensitive, the parent node (target field) automatically inherits the sensitive attribute; if a function calculation node (such as CONCAT(phone, name)) is encountered, the sensitivity of the output field is dynamically determined according to the sensitivity of the input field. Finally, the sensitive fields that need to be desensitized in the target result set obtained after pre-executing the database query statement (which is not actually executed, but the execution of the SQL statement is pre-judged through the sensitive attribute inheritance relationship to determine the sensitive fields in the output result) are pre-judged, providing a basis for subsequent accurate desensitization.
[0076] In step S20, the nested sensitive fields that cannot be handled by the regular solution are solved by recursive inheritance, which can accurately identify sensitive fields and improve the accuracy of desensitization; the function node dynamic inheritance mechanism is also used to overcome the semantic discontinuity defect of traditional syntax analysis; in addition, the pre-judgment is completed before the execution of the database query statement, avoiding the overhead of returning the target result set and scanning each row to obtain sensitive fields, thereby improving the desensitization efficiency.
[0077] In step S30, the sensitive fields are desensitized based on the pre-set desensitization rules, and the desensitized result set is returned to the query requestor.
[0078] It should be noted that the sensitive fields that need to be desensitized are located based on the pre-set desensitization rules (such as desensitizing the mobile phone number 11800118000 to 118****8000), and the desensitized result set that does not contain original sensitive information is finally generated and returned to the query requestor.
[0079] By way of example, the pre-set desensitization rules can be function encryption, mask shielding, mask number, and variable replacement, etc. Different desensitization rules can be used according to different desensitization scenarios, specifically, sensitive fields that need to be associated, such as mobile phone numbers, bank card numbers, and ID numbers, use function encryption; text type sensitive fields, such as names, addresses, and email addresses, use mask shielding; mask numbers are used for sensitive information in complex texts; variable replacement can also be used for sensitive information in complex texts.
[0080] In step S30, only the pre-judged sensitive fields are subjected to desensitization rules, reducing the computational burden and improving the desensitization efficiency; at the same time, it can also avoid misprocessing, and desensitizing sensitive fields converts the original sensitive data into a safe and usable desensitized result set, improving the accuracy of desensitization.
[0081] In the embodiment, after parsing the database query statement in the query request, an abstract syntax tree is constructed, and then a target syntax tree recording the dependency relationship between the target field and the target database metadata field in the database query statement is converted and generated based on the abstract syntax tree. Then, the nodes of the target syntax tree are traversed, and the sensitive attribute inheritance relationship between the nodes of the target syntax tree is determined recursively from bottom to top, so as to predict the sensitive fields of the target result set obtained after the pre-execution of the database query statement. In this process, the abstract syntax tree is converted into the target syntax tree, and the sensitive attribute inheritance relationship between the nodes of the target syntax tree is determined, so that the sensitive field transmission path between the target field and the metadata field can be established, and the sensitive fields can be accurately identified. According to the sensitive attribute inheritance relationship, the sensitive fields of the target result set obtained after the pre-execution of the database query statement can be predicted. This method of predicting the sensitive fields without actually executing the database query statement can avoid the calculation burden of actual query execution to a certain extent, improve the response timeliness of the query, and thus improve the desensitization efficiency. Finally, based on the preset desensitization rule, the actual query data obtained by the latest database query statement is desensitized, and the desensitization result set is returned to the query request side, so that the data security is ensured and the response timeliness of the complex query is significantly improved.
[0082] Based on the above embodiments of the application, in another embodiment of the application, the same or similar contents as the above embodiments can be referred to the above description, and will not be described in detail.
[0083] The step of recursively determining the sensitive attribute inheritance relationship between the nodes of the target syntax tree from bottom to top in step S20 includes steps D10-D30.
[0084] The nodes of the target syntax tree include leaf nodes representing the metadata fields in the target database and non-leaf nodes representing the target fields in the database query statement.
[0085] In step D10, for the leaf node, the preset sensitive field marking rule is queried. If the metadata field represented by the current leaf node is a sensitive field, the current leaf node is marked as sensitive.
[0086] It should be noted that for the leaf nodes in the target syntax tree (i.e., the underlying nodes that are directly mapped to the metadata fields in the physical original table of the target database, such as users.phone), the preset sensitive field marking rules are queried (the sensitive attributes of the physical table fields are defined in the metadata management module stored in the desensitizing system); if the metadata field represented by the current leaf node (such as users.phone) is marked as a sensitive field (such as the phone field is defined as PII type in the rule), the leaf node is marked as sensitive. This mark serves as the starting point for the recursive transfer of sensitive attributes, driving the subsequent calculation process of inheriting sensitive attributes from bottom to top layer by layer.
[0087] It is understandable that step D10 can ensure that subsequent cross-table associations (such as JOIN) or function calculations (such as CONCAT()) can be traced back to the sensitive attributes of the metadata fields of the target database.
[0088] Step D20: For non-leaf nodes, if any child node of the non-leaf node has a sensitive flag, the sensitive field of the child node is inherited and the current non-leaf node is marked as sensitive;
[0089] It should be noted that for non-leaf nodes in the target syntax tree (i.e., intermediate fields or final output fields generated by calculations that depend on child nodes, such as phone in SELECT phone or the function CONCAT(phone,name)), the sensitivity marking status of all child nodes of the non-leaf node (directly dependent fields of the current non-leaf node, such as the metadata field users.phone whose child node is phone) is checked. If any child node is marked as sensitive (such as the child node users.phone is already marked sensitive at the leaf level), the current non-leaf node automatically inherits the sensitive attribute and is synchronously marked as sensitive. This operation ensures that the sensitive attribute is seamlessly transmitted from bottom to top along the target syntax tree until all final output fields are covered.
[0090] It is understandable that step D20, by having non-leaf nodes inherit the sensitive attributes of their child nodes, can break through the sensitive tracking of various scenarios such as nested queries, function calculations, and table joins in traditional desensitizing technology solutions.
[0091] In step D30 , after the bottom-up recursion is completed, the sensitive attribute inheritance relationship between the nodes of the target syntax tree is determined through all nodes marked as sensitive.
[0092] It should be noted that after the completion of the bottom-up recursive traversal process, the system dynamically constructs a complete sensitive attribute inheritance link from the basic sensitive source to the final output result by summarizing all the end nodes marked as sensitive (i.e., leaf nodes directly associated with the original sensitive table field) and their inherited sensitive attribute marks in the recursive path, combined with the structural dependency relationship between the syntax tree nodes (such as the dependency of function calculation nodes on input fields or the binding of cross-table connection nodes on associated fields), thereby systematically determining the technical judgment relationship of whether the sensitivity carried by each node in the target syntax tree is inherited from the lower layer node, whether it is transformed by function operation, or whether it is transmitted across table connection, forming a sensitive attribute topology network covering all syntax tree nodes.
[0093] In the present embodiment, the leaf node at the bottom layer, i.e., the metadata field, is marked based on the preset sensitive field marking rule, and then the non-leaf node inherits the sensitive state of the child node, so that the sensitive marking can also be automatically obtained through the sensitive attribute inheritance relationship of the complex query statement, forming a bottom-up sensitive conduction path. Finally, the sensitive attribute inheritance relationship between each node in the target syntax tree can be obtained, and the sensitive inheritance path between each node can be accurately obtained, providing an accurate sensitive field basis for subsequent desensitization, rooting out the desensitization omission risk caused by the breakage of sensitive attribute transmission from the source, while avoiding the damage to data value caused by excessive desensitization, and realizing the optimal balance between security protection and data utility.
[0094] Exemplarily, as shown in Figure 4 , the present application supports field sensitivity transmission through the above-mentioned embodiments, wherein the sensitive field can be calculated in the scenarios of where condition, function operation, multi-layer function nesting, subquery, mathematical operation, logical operation, distinct, case when, multi-table join, etc. At the same time, for the scenarios of insert, update, delete, create, etc., the sensitive level transmission between tables is also realized. The sensitive inheritance scenarios mainly include the following:
[0095] Through the DML (Insert / Update / Delete, etc.) statement, the sensitivity of another table data is changed, as shown in Figure 4 , before the execution of the database query statement, table A is a non-sensitive table, and table B is a sensitive table; after the execution of the database query statement (insert into A select xx from B), since part of the data in the non-sensitive table A is obtained from the sensitive table B, the table A also becomes a sensitive table.
[0096] Through the DDL (Create / Drop / Rename, etc.) statement, the table operation sensitivity transmission is caused, as shown in Figure 4In (b) shown in the figure, table C is a sensitive table before the execution of the database query statement; after the execution of the database query statement (create D select xxfrom C), since table D is created based on the data in the sensitive table C, table D also becomes a sensitive table, i.e., inherits the sensitive attribute of table C.
[0097] In an embodiment, after the step of traversing the nodes of the target syntax tree, recursively determining the sensitive attribute inheritance relationship between the nodes of the target syntax tree from bottom to top, to pre-judge the sensitive fields of the target result set obtained after the pre-execution of the database query statement, the step further comprises:
[0098] When it is detected that the database query statement is a preset complex statement, field-level desensitization processing is performed on the sensitive fields of the nodes marked as sensitive in the target syntax tree;
[0099] Based on the new nodes after the field-level desensitization processing, a latest database query statement is generated, and a desensitized result set is obtained through the latest database query statement.
[0100] It should be noted that after the sensitive fields of the target result set are pre-judged through the analysis of the target syntax tree, when it is detected that the database query statement queries a data volume greater than or equal to a preset data volume threshold (for example, the data volume threshold can be set to 10,000), i.e., it is detected that the database query statement is a preset complex statement (such as containing multiple nested queries or aggregation functions), field-level desensitization processing (for example, replacing the identity card number node with a hash operation expression) will be performed on the nodes marked as sensitive in the constructed target syntax tree; then, the logical structure of the database query statement is reconstructed based on the nodes updated by the field-level desensitization, i.e., the SQL statement is rewritten, and a latest SQL statement (such as replacing the original SELECT phone with SELECT MASK(phone)) that can be directly executed in the database engine is generated, and a desensitized result set is directly returned at the database level through the execution of the latest SQL statement, so that the security of sensitive data is ensured while the query performance is maintained.
[0101] In the embodiment, when the preset complex statement is detected, the nodes marked as sensitive in the syntax tree are located based on the recursively determined sensitive attribute inheritance relationship, and desensitization rules are directly injected at the node level; then, a latest database query statement is generated, so that the desensitization operation is completed when the latest database query statement is executed; the security risks and performance bottlenecks in the secondary processing of the result set obtained by the complex statement in the traditional scheme are avoided, the sensitive fields in complex scenarios such as nested queries and multi-table association are completely covered at the database level, high desensitization efficiency is achieved by using the native computing capability of the database engine, and the system response performance in high-concurrency scenarios is maintained on the premise of ensuring data security.
[0102] In another embodiment, the database desensitization method comprises:
[0103] When it is detected that the data quantity queried by the database query statement is less than the preset data quantity threshold, the database query statement is executed in the target database to obtain an original result set;
[0104] The preset desensitization rule is applied to the sensitive fields in the original result set to perform desensitization, and a desensitized result set is returned to the requester.
[0105] It should be noted that when it is detected that the data quantity involved in the current database query statement is less than the preset threshold (such as 10,000), the original database query statement is first executed in the target database to obtain an unprocessed original result set (i.e., a two-dimensional data table structure containing sensitive fields); then, the preset desensitization rule library is used to apply real-time desensitization conversion to the sensitive fields in the original result set that have been pre-judgment marked (such as uniformly replacing the ID number field value with a mask rule of the first six and the last four), which is equivalent to a result set rewriting desensitization, and finally, the security result set after the field-level desensitization processing is directly returned to the query requester.
[0106] In the embodiment, since the original result set is obtained by first executing the database query statement, and then the original result set needs to be desensitized, a large amount of memory is required. Based on the data quantity threshold, the need for desensitization of a large amount of data is avoided, the desensitization action is accurately performed in the memory calculation layer for small data quantity, and the balance between security protection and response efficiency is achieved.
[0107] Exemplarily, the mixed desensitization mode of the application is as shown in Figure 5 As shown in (a) in Figure 5 , it is a result set rewriting desensitization mode. Specifically, for the scene of small query quantity and simple desensitization rule implementation, after the query requester initiates a query request, the database query statement in the query request is executed to directly obtain an original result set from the target database, and based on the preset desensitization rule library, the sensitive fields in the original result set that have been pre-judgment marked are obtained to obtain a desensitized result set.
[0108] Figure 5(b) shows a SQL statement rewriting and desensitizing method. Specifically, for scenarios with large query volume and complex desensitization rule implementation, the database query statement in the query request is parsed, an abstract syntax tree is constructed based on the database query statement, and the abstract syntax tree is converted into a target syntax tree. The nodes of the target syntax tree are traversed, and the sensitive attribute inheritance relationship between the nodes of the target syntax tree is recursively determined from the bottom to the top to predict the sensitive fields of the target result set obtained after pre-executing the database query statement; a desensitizing function is added to the sensitive field, and the target syntax tree is restored to the latest database query statement, which is equivalent to rewriting the database query statement, and then the latest database query, that is, the database query statement with the desensitizing function, is executed to directly obtain the desensitized result set from the target database.
[0109] It is understandable that when two desensitizing methods are used to desensitize data obtained from the same SQL statement, the resulting desensitized result sets are consistent.
[0110] After the query requester initiates a query request, the database query statement in the query request is executed, and the original result set is obtained directly from the target database. The sensitive fields that have been pre-marked in the original result set are desensitized based on the preset desensitization rule library to obtain the desensitized result set.
[0111] For example, in the database desensitization device, a desensitization system is installed to execute the database desensitization method. Please refer to Figure 6 , Figure 6 A schematic diagram of a desensitization system is provided, specifically:
[0112] The desensitizing system uses a front-end and back-end separated business architecture, allowing users to access the target database through customer queries and external applications such as RESTful APIs or JDBC. Administrators can also configure and manage the desensitizing system using front-end visualization tools.
[0113] Among them, the front-end visualization part of the desensitizing system provides configuration management tools for administrators and a configuration query page for users. It mainly includes basic functions such as sensitive field lineage display, function configuration whitelist, sensitivity level adjustment, table configuration whitelist, and desensitizing rule modification.
[0114] The query API part of the desensitizing system is responsible for providing external query interfaces, including API queries, long-connection TCP queries, JDBC driver connection queries, etc.
[0115] The metadata management part of the desensitization system mainly provides source database metadata synchronization, sensitive information synchronization, metadata preservation, metadata query and storage functions for data dynamic desensitization application. Specifically, the synchronization metadata mainly includes: data table metadata information collection of the source data, including source table information and sensitive information collection, source view processing link collection and analysis; field sensitive level marking and desensitization rule data blood relationship inheritance.
[0116] The syntax analysis and syntax tree construction part of the desensitization system is mainly responsible for constructing and converting the abstract syntax tree into the target syntax tree, and judging the sensitive information inheritance of the database query statement based on the metadata field. It is mainly responsible for supporting the basic support of the database query syntax, including the analysis of the database function and the analysis of the database DQL / DCL / DDL / DML syntax. At the same time, it is responsible for the construction of the sensitive field blood relationship, which is used to predict whether the SQL output result is sensitive.
[0117] The desensitization rule execution part of the desensitization system is mainly responsible for executing the desensitization of the sensitive field according to the output sensitivity of the syntax analysis and syntax tree construction. There are two types of current desensitization rule execution methods: result set rewriting desensitization and SQL statement rewriting desensitization. The former is suitable for small query volume and simple desensitization rule implementation, and the latter can utilize the computing power of the query database and is suitable for large query volume and complex desensitization rule implementation.
[0118] It should be noted that the above examples are only used to understand the present application and do not constitute a limitation on the database desensitization method of the present application. More forms of simple transformation based on this technical concept, such as interaction and combination of various embodiments, are within the protection scope of the present application.
[0119] The present application also provides a database desensitization device, please refer to Figure 7 , the database desensitization device comprises:
[0120] The conversion module 10 is configured to parse a database query statement in a query request for a target database, construct an abstract syntax tree based on the database query statement, and convert the abstract syntax tree into a target syntax tree in response to the query request, wherein the target syntax tree records a dependency relationship between a target field in the database query statement and a metadata field in the target database;
[0121] The determination module 20 is configured to traverse nodes of the target syntax tree, and recursively determine a sensitive attribute inheritance relationship between the nodes of the target syntax tree from bottom to top, so as to predict sensitive fields of a target result set obtained by pre-executing the database query statement;
[0122] The desensitization module 30 is configured to desensitize the sensitive fields based on a preset desensitization rule, and return a desensitized result set to a query request party.
[0123] The conversion module 10 is further configured to construct an initial syntax tree based on the preset construction rule and the database query statement;
[0124] The function node in the abstract syntax tree is determined by traversing the abstract syntax tree;
[0125] The cross-table inheritance path in the database query statement is determined based on the metadata field in the target database;
[0126] The mapping relationship between the input field and the output field in the function node and the cross-table inheritance path are written into the node of the initial syntax tree as a dependency relationship to form a target syntax tree.
[0127] The conversion module 10 is further configured to locate the original table to which each field in the database query statement belongs in the target database according to the metadata field in the target database;
[0128] The field mapping relationship in the database query statement is extracted according to the associated expression in the database query statement;
[0129] The cross-table inheritance path in the database query statement is determined based on the original table and the field mapping relationship.
[0130] The determination module 20 is further configured to, for a leaf node, query a preset sensitive field marking rule, and if the metadata field represented by the current leaf node is a sensitive field, mark the current leaf node as sensitive;
[0131] For a non-leaf node, if any child node of the non-leaf node has a sensitive mark, the sensitive field of the child node is inherited and the current non-leaf node is marked as sensitive;
[0132] After the bottom-up recursion is completed, the sensitive attribute inheritance relationship between the nodes of the target syntax tree is determined through all the nodes marked as sensitive.
[0133] The determination module 20 is further configured to, when it is detected that the database query statement is a preset complex statement, perform field desensitization processing on the sensitive field of the node at the node marked as sensitive in the target syntax tree;
[0134] A latest database query statement is generated based on the new node after the field desensitization processing, and a desensitization result set is obtained through the latest database query statement.
[0135] The database desensitization apparatus further includes a result set desensitization module configured to, when it is detected that the data queried by the database query statement is less than a preset data amount threshold, execute the database query statement in the target database to obtain an original result set;
[0136] Apply preset desensitization rules to the sensitive fields in the original result set to desensitize, and return the desensitized result set to the requester.
[0137] The database desensitization device provided by the present application adopts the database desensitization method in the above embodiment, and can solve the technical problems of low desensitization efficiency and inaccurate desensitization of the existing desensitization technology. Compared with the prior art, the database desensitization device provided by the present application has the same beneficial effects as the database desensitization method provided by the above embodiment, and other technical features in the database desensitization device are the same as the features disclosed in the above embodiment method, which will not be repeated here.
[0138] The present application provides a database desensitization device, which comprises at least one processor and a memory connected in communication with the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the database desensitization method in the first embodiment.
[0139] Reference will now be made to the drawings, in which Figure 8 which shows a structural diagram of a database desensitization device suitable for implementing the embodiments of the present application. The database desensitization device in the embodiments of the present application can include, but is not limited to, mobile terminals such as mobile phones, notebook computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), and the like, as well as fixed terminals such as digital TVs, desktop computers, and the like. Figure 8 The database desensitization device shown is only an example, and should not bring any limitation to the functions and use range of the embodiments of the present application.
[0140] As Figure 8As shown, the database desensitization device can include a processing apparatus 1001 (for example, a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to programs stored in a read-only memory 1002 or programs loaded from a storage apparatus 1003 to a random access memory 1004. In the random access memory 1004, various programs and data required for the operation of the database desensitization device are also stored. The processing apparatus 1001, the read-only memory 1002, and the random access memory 1004 are connected to each other by a bus 1005. An input / output interface 1006 is also connected to the bus. Generally, the following systems can be connected to the input / output interface 1006: an input apparatus 1007 including, for example, a touch screen, a touch pad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output apparatus 1008 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; the storage apparatus 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication apparatus 1009. The communication apparatus 1009 can allow the database desensitization device to communicate with other devices wirelessly or by wire to exchange data. Although the database desensitization device with various systems is shown in the figure, it should be understood that all the systems shown are not required to be implemented or possessed. More or fewer systems can be alternatively implemented or possessed.
[0141] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product comprising a computer program carried on a computer readable medium, the computer program containing program codes for executing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network through the communication apparatus, or installed from the storage apparatus 1003, or installed from the read-only memory 1002. When the computer program is executed by the processing apparatus 1001, the above-mentioned functions defined in the methods of the embodiments disclosed in the present application are executed.
[0142] The database desensitization device provided by the present application adopts the database desensitization method in the above-mentioned embodiments, and can solve the technical problems of low desensitization efficiency and inability to accurately desensitize in the prior art. Compared with the prior art, the beneficial effects of the database desensitization device provided by the present application are the same as those of the database desensitization method provided by the above-mentioned embodiments, and other technical features in the database desensitization device are the same as those disclosed in the above-mentioned embodiment method, which will not be described here.
[0143] It should be understood that parts of the present application can be realized by hardware, software, firmware or a combination thereof. In the description of the above-mentioned embodiments, specific features, structures, materials or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0144] The above merely provides a specific implementation of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
[0145] The present application provides a computer readable storage medium having computer readable program instructions (i.e. computer programs) stored thereon, which are used to execute the database desensitization method in the above embodiments.
[0146] The computer readable storage medium provided by the present application may, for example, be a U disk, but is not limited to an electric, magnetic, optical, electromagnetic, infrared, or semiconductor system or device, or any combination of the above. More specific examples of the computer readable storage medium can include, but are not limited to, an electric connection with one or more conductive wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present embodiment, the computer readable storage medium can be any tangible medium containing or storing a program, which can be used by or in combination with an instruction execution system or device. The program code contained on the computer readable storage medium can be transmitted by any suitable medium, including but not limited to an electric wire, an optical cable, an RF (Radio Frequency), etc., or any suitable combination of the above.
[0147] The above computer readable storage medium can be contained in the database desensitization device; or can exist separately without being assembled into the database desensitization device.
[0148] The computer readable storage medium described above carries one or more programs, when the one or more programs are executed by the database desensitization device, cause the database desensitization device to: in response to a query request for a target database, parse a database query statement in the query request, construct an abstract syntax tree based on the database query statement, and convert the abstract syntax tree into a target syntax tree, wherein the target syntax tree records a dependency relationship between a target field in the database query statement and a metadata field in the target database; traverse nodes of the target syntax tree, recursively determine a sensitive attribute inheritance relationship between nodes of the target syntax tree from bottom to top, to pre-judge sensitive fields of a target result set obtained after pre-execution of the database query statement; perform desensitization on the sensitive fields based on a preset desensitization rule, and return a desensitized result set to a query request party.
[0149] Computer program code for carrying out operations of the present application can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).
[0150] The flow and block diagrams in the drawings show architectural, functional, and operational representations of possible implementations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flow and block diagrams can represent a module, a segment, or a portion of code, which comprises one or more executable instructions for implementing the specified logical function(s). It should also be noted that in some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently or the blocks may
[0151] The modules described in the embodiments of the present application can be implemented in the form of software or in the form of hardware. In some cases, the names of the modules do not constitute a limitation on the modules themselves.
[0152] The readable storage medium provided by the present application is a computer readable storage medium, which stores computer readable program instructions (i.e., a computer program) for executing the above-mentioned database desensitization method, and can solve the technical problems of low desensitization efficiency and inability to accurately desensitize of the existing desensitization technology. Compared with the prior art, the computer readable storage medium provided by the present application has the same beneficial effects as the database desensitization method provided by the above-mentioned embodiments, and will not be described here.
[0153] The present application also provides a computer program product comprising a computer program, which, when executed by a processor, implements the steps of the above-mentioned database desensitization method.
[0154] The computer program product provided by the present application can solve the technical problems of low desensitization efficiency and inability to accurately desensitize of the existing desensitization technology. Compared with the prior art, the computer program product provided by the present application has the same beneficial effects as the database desensitization method provided by the above-mentioned embodiments, and will not be described here.
[0155] The above only describes some embodiments of the present application, and does not limit the patent scope of the present application. Any equivalent structural transformation, direct / indirect application in other related technical fields based on the technical concept of the present application, and the content of the specification and drawings are included in the patent protection scope of the present application.
Claims
1. A database desensitization method, characterized in that: The database desensitization method includes: In response to a query request to a target database, parsing a database query statement in the query request, constructing an abstract syntax tree based on the database query statement, and converting the abstract syntax tree into a target syntax tree, wherein the target syntax tree records a dependency relationship between a target field in the database query statement and a metadata field in the target database; Traversing the nodes of the target syntax tree, recursively determining the sensitive attribute inheritance relationship between the nodes of the target syntax tree from bottom to top, so as to predict the sensitive fields of the target result set obtained after pre-executing the database query statement; The sensitive fields are desensitized based on the preset desensitization rules, and the desensitized result set is returned to the query requester.
2. The method according to claim 1, wherein The step of converting the abstract syntax tree into a target syntax tree comprises: Constructing an initial syntax tree based on preset construction rules and the database query statement; Determine a function node in the abstract syntax tree by traversing the abstract syntax tree; Determining a cross-table inheritance path in the database query statement based on metadata fields in the target database; The mapping relationship between the input field and the output field in the function node and the cross-table inheritance path are written into the nodes of the initial syntax tree as dependency relationships to form a target syntax tree.
3. The method according to claim 2, wherein The step of determining the cross-table inheritance path in the database query statement based on the metadata field in the target database includes: Locating the original table to which each field in the database query statement belongs in the target database according to the metadata fields in the target database; Extracting the field mapping relationship in the database query statement according to the association expression in the database query statement; Based on the original table and the field mapping relationship, a cross-table inheritance path in the database query statement is determined.
4. The method according to claim 1, wherein The target syntax tree nodes include leaf nodes representing metadata fields in the target database and non-leaf nodes representing target fields in the database query statement; and the step of recursively determining the sensitive attribute inheritance relationship between the nodes of the target syntax tree from bottom to top includes: For leaf nodes, the preset sensitive field marking rules are queried. If the metadata field represented by the current leaf node is a sensitive field, the current leaf node is marked as sensitive. For non-leaf nodes, if any child node of the non-leaf node has a sensitive mark, the sensitive field of the child node is inherited and the current non-leaf node is marked as sensitive; After the bottom-up recursion is completed, the sensitive attribute inheritance relationship between the nodes of the target syntax tree is determined through all the nodes marked as sensitive.
5. The method according to claim 4, wherein After the step of traversing the nodes of the target syntax tree and recursively determining the sensitive attribute inheritance relationship between the nodes of the target syntax tree from bottom to top to predict the sensitive fields of the target result set obtained after pre-executing the database query statement, the method further includes: When it is detected that the database query statement is a preset complex statement, performing field desensitization processing on the sensitive fields of the node at the node marked as sensitive in the target syntax tree; Based on the new node after the field desensitization processing, the latest database query statement is generated, and the desensitized result set is obtained through the latest database query statement.
6. The method according to claim 1, wherein The method comprises: When it is detected that the amount of data queried by the database query statement is less than a preset data amount threshold, executing the database query statement in the target database to obtain an original result set; Apply preset desensitization rules to the sensitive fields in the original result set to perform desensitization, and return the desensitized result set to the requester.
7. A database desensitization device, characterized in that: The database desensitizing device includes: a conversion module, configured to, in response to a query request to a target database, parse a database query statement in the query request, construct an abstract syntax tree based on the database query statement, and convert the abstract syntax tree into a target syntax tree, wherein the target syntax tree records a dependency relationship between a target field in the database query statement and a metadata field in the target database; A determination module, configured to traverse the nodes of the target syntax tree and recursively determine the sensitive attribute inheritance relationship between the nodes of the target syntax tree from bottom to top, so as to predict the sensitive fields of the target result set obtained after pre-executing the database query statement; The desensitization module is used to desensitize the sensitive fields based on preset desensitization rules and return the desensitized result set to the query requester.
8. A database desensitization device, characterized in that: The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the database desensitization method according to any one of claims 1 to 6.
9. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the database desensitization method according to any one of claims 1 to 6 are implemented.
10. A computer program product, characterized in that The computer program product includes a computer program, and when the computer program is executed by a processor, the steps of the database desensitization method according to any one of claims 1 to 6 are implemented.