Data desensitization processing method and related equipment
By using a proxy device to anonymize data write requests, the problem of sensitive data leakage in the test environment was solved, thereby improving data security and preventing the leakage of sensitive information without modifying the system.
Patent Information
- Application Number
- CN202510940962.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-08
- Publication Date
- 2025-10-31
AI Technical Summary
Existing technologies cannot effectively prevent the leakage of sensitive data in testing environments, and conventional detection strategies are lagging and cannot fully cover the risk of data leakage.
The proxy device receives data write requests, processes the initial data according to the de-identification policy, generates de-identified data, and writes it to the receiving device, thus avoiding the direct storage of sensitive information in the test environment.
Without modifying the application systems of the sending and receiving devices, data anonymization was achieved, improving data security, preventing the leakage of sensitive information in the test environment, and reducing the risk of data leakage.
Smart Images

Figure CN120874109A_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of computer technology, and in particular to a data desensitization processing method and related equipment. Background Technology
[0002] Sensitive data from the production environment should, in principle, not be transferred to the testing environment. This is because sensitive data in production environments typically contains important information such as personal privacy and trade secrets; leakage or misuse could lead to serious economic losses, legal risks, and even social problems. However, testing environments are often used for system development and functional verification, and their security is generally lower than that of production environments. Furthermore, unauthorized access or operations may occur in testing environments; therefore, introducing sensitive production data into testing environments significantly increases the risk of data breaches. To ensure data security, the use of sensitive data in testing environments must be strictly limited.
[0003] The conventional approach typically involves adding detection strategies to the application systems in the test environment, using methods such as manual review or automated tools to periodically check the data in the test environment to determine if there are any sensitive data leaks. However, due to the characteristics of test environments—high data flow and complex usage scenarios—this approach is often lagging and cannot comprehensively cover all possible sensitive data leaks in the test environment. Summary of the Invention
[0004] This specification provides a data anonymization method and related equipment to solve the above-mentioned problems. The technical solution is as follows: In a first aspect, embodiments of this specification provide a data desensitization processing method, the method being executed by a proxy device, the method comprising: Receive a data write request from a transmitting device and directed to a receiving device, the data write request carrying initial data; The initial data is desensitized according to the desensitization processing strategy to obtain desensitized data; A data write request carrying the de-identified data is sent to the receiving device to write the de-identified data into the receiving device.
[0005] Secondly, embodiments of this specification provide a data desensitization processing device, which is disposed on a proxy device, and the device includes: A request sending module is used to receive a data write request from a sending device and for a receiving device, the data write request carrying initial data; The data processing module is used to perform desensitization processing on the initial data according to the desensitization processing strategy to obtain desensitized data; The data writing module is used to send a data writing request carrying the de-identified data to the receiving device, so as to write the de-identified data into the receiving device.
[0006] Thirdly, embodiments of this specification provide a computer storage medium storing a plurality of instructions adapted for loading by a processor and executing the above-described method steps.
[0007] Fourthly, embodiments of this specification provide a computer program product that stores multiple instructions adapted for loading by a processor and executing the above-described method steps.
[0008] Fifthly, embodiments of this specification provide an electronic device that may include: a processor and a memory; wherein the memory stores a computer program adapted to be loaded by the processor and to execute the above-described method steps.
[0009] The beneficial effects of the technical solutions provided in some embodiments of this specification include at least the following: In this specification, the proxy device receives a data write request from the sending device, specifically for the receiving device. This data write request instructs that initial data be written to the receiving device. Further, the proxy device performs de-identification processing on the initial data according to a de-identification strategy to obtain de-identified data. De-identification processing ensures that the initial data retains its original value by replacing or hiding sensitive information, preventing the exposure of true information and thus ensuring the privacy and security of the initial data. Further, the proxy device sends a data write request carrying the de-identified data to the receiving device to write the de-identified data to the receiving device.
[0010] In other words, this specification utilizes a proxy device to process data write requests sent from the sending device to the receiving device. Without modifying the original application systems of the sending and receiving devices, it achieves anonymization of the initial data carried in the data write request. This eliminates the cost of modifying the original application systems and offers greater flexibility in the anonymization process. Furthermore, by anonymizing the initial data before writing it to the receiving device (used as a test environment), it ensures that the data written to the test environment does not contain sensitive information, preventing the leakage of sensitive information in the test environment and improving data security. Attached Figure Description
[0011] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0012] Figure 1 This is a schematic diagram of the architecture of a data desensitization processing method provided in the embodiments of this specification; Figure 2 This is a schematic flowchart of a data desensitization processing method provided in the embodiments of this specification; Figure 3 This is a schematic diagram of a data anonymization processing method provided in the embodiments of this specification; Figure 4 This is a schematic flowchart of a data desensitization processing method provided in the embodiments of this specification; Figure 5 This is a schematic diagram of a process for obtaining de-identified data provided in the embodiments of this specification; Figure 6 This is a schematic flowchart of a data desensitization processing method provided in the embodiments of this specification; Figure 7 This is a schematic diagram of the structure of a data desensitization processing device provided in the embodiments of this specification; Figure 8 This is a schematic diagram of the structure of an electronic device provided in the embodiments of this specification. Detailed Implementation
[0013] The technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this specification.
[0014] In the description of this specification, it should be understood that the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. In the description of this specification, it should be noted that, unless otherwise expressly specified and limited, "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or devices. Those skilled in the art can understand the specific meaning of the above terms in this specification based on the specific circumstances. Furthermore, in the description of this specification, unless otherwise stated, "multiple" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship.
[0015] The present specification will now be described in detail with reference to specific embodiments.
[0016] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.), and signals involved in the embodiments of this specification are all authorized by the user or fully authorized by all parties, and the collection, use, and processing of related data must comply with the relevant laws, regulations, and standards of the relevant countries and regions. For example, the features, information, and data involved in this specification were all obtained under full authorization.
[0017] Sensitive data from the production environment should, in principle, not be transferred to the testing environment. This is because sensitive data in production environments typically contains important information such as personal privacy and trade secrets; leakage or misuse could lead to serious economic losses, legal risks, and even social problems. However, testing environments are often used for system development and functional verification, and their security is generally lower than that of production environments. Furthermore, unauthorized access or operations may occur in testing environments; therefore, introducing sensitive production data into testing environments significantly increases the risk of data breaches. To ensure data security, the use of sensitive data in testing environments must be strictly limited.
[0018] The conventional approach typically involves adding detection strategies to the application systems in the test environment, using methods such as manual review or automated tools to periodically check the data in the test environment to determine if there are any sensitive data leaks. However, due to the characteristics of test environments—high data flow and complex usage scenarios—this approach is often lagging and cannot comprehensively cover all possible sensitive data leaks in the test environment.
[0019] Therefore, embodiments of this specification provide a data anonymization method to solve the above-mentioned problems. For example... Figure 1 As shown, Figure 1 This is a schematic diagram of the architecture of a data desensitization processing method provided in the embodiments of this specification. Figure 1 It includes at least a proxy device 102 that performs a data desensitization processing method, at least a sending device 102 that sends a data write request, and at least a receiving device 103 that is used for writing data.
[0020] Understandable Figure 1 The number of transmitting devices 101 and receiving devices 103 shown is merely illustrative, and this specification does not impose any limitations on the embodiments thereof.
[0021] The aforementioned sending device 101, proxy device 102, and receiving device 103 can be individual server devices, such as rack-mounted, blade, tower, or cabinet-type server devices, or hardware devices with strong computing capabilities such as workstations or mainframe computers; or they can be server clusters composed of multiple servers. The servers in the service cluster can be composed in a symmetrical manner, where each server is functionally and hierarchically equivalent in the transaction link, and each server can provide services to the outside world independently. Providing services independently can be understood as not requiring the assistance of other servers.
[0022] For example, a server can be multiple physical servers, each with independent hardware. Alternatively, a server can be multiple virtual servers deployed within the same hardware resource pool. Virtual server deployment methods include, but are not limited to, VMware, VirtualBox, and Virtual PC.
[0023] It is understood that the sending device 101, the proxy device 102, and the receiving device 103 also possess other service capabilities and functions to complete the tasks described in the following embodiments. For example, the proxy device 102 may also provide portal services, resource management services, and CI / CD services.
[0024] The transmitting device 101, the agent device 102, and the receiving device 103 may also be, but are not limited to, the following electronic devices: wearable devices, handheld devices, personal computers, tablets, in-vehicle devices, smartphones, computing devices, or other processing devices connected to a wireless modem. Electronic devices may have different names in different networks, such as: user equipment, access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user device, cellular phone, cordless phone, personal digital assistant (PDA), electronic devices in 5G networks or future evolved networks, etc.
[0025] In the embodiments of this specification, a display device may also be installed on the transmitting device 101 or other electronic equipment. The display device can be any device capable of displaying functions, such as a cathode ray tube display (CR), a light-emitting diode display (LED), an electronic ink screen, a liquid crystal display (LCD), or a plasma display panel (PDP). For example, a user can use the display device on the transmitting device 101 to send a data write request to the receiving device 103 via the proxy device 102. This data write request carries initial data. In other words, the user requests that initial data be written to the receiving device 103 via this data write request.
[0026] The transmitting device 101, the proxy device 102, and the receiving device 103 can communicate via a communication link established through a communication protocol. For example, the network can be a wireless network or a wired network. Wireless networks include, but are not limited to, cellular networks, wireless LANs, infrared networks, or Bluetooth networks. Wired networks include, but are not limited to, Ethernet, universal serial bus (USB), or controller area networks. In one or more embodiments of the specification, technologies and / or formats including Hyper Text Markup Language (HTML), Extensible Markup Language (XML), etc., are used to represent data exchanged over the network (such as target compressed packets). Furthermore, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), and Internet Protocol Security (IPsec) can be used to encrypt all or some of the links. In other embodiments, customized and / or dedicated data communication technologies can be used to replace or supplement the aforementioned data communication technologies.
[0027] In one embodiment, such as Figure 2 The diagram shown is a flowchart illustrating a data anonymization method provided in an embodiment of this specification. The method is executed by a proxy device. This method can be implemented using a computer program and can run on a data anonymization processing device based on the von Neumann architecture. This computer program can be integrated into an application or run as a standalone utility application.
[0028] Specifically, the data anonymization method includes: S102, Receive a data write request from the transmitting device and directed to the receiving device, the data write request carrying initial data.
[0029] The proxy device receives data write requests from the application system of the sending device. This can be understood as the proxy device's system receiving write operations initiated by the sending device's system, with the goal of storing the initial data into the receiving device's database system.
[0030] Data write requests are typically transmitted via network protocols such as TCP / IP, HTTP, and MQTT. The sending device uses these protocols to pass the request data to the proxy device. The proxy device's system listens on a specific port or API interface, waiting to receive data write requests from the sending device.
[0031] A data write request is an instruction that carries the requirement for the receiving device to store data. It typically includes the target storage location of the data, the content of the data to be written, the writing method (such as overwrite, append, etc.), and related metadata (such as timestamp, request ID, etc.).
[0032] Data write requests typically have a standard format, which can be JSON, XML, Protobuf, etc., depending on the system design. For example, in HTTP requests, data write requests usually use the POST or PUT method and carry the initial data in the request body.
[0033] The initial data carried in a data write request may be structured or unstructured, depending on the specific transaction requirements. Common types of initial data include text (such as strings), numbers, binary data (such as image, audio, and video files), and structured data in JSON or XML format. For example, the initial data carried in a data write request might be: Zhang San, phone number 1234567, address x province x city x district.
[0034] S104. Desensitize the initial data according to the desensitization strategy to obtain desensitized data.
[0035] Anonymization strategies can be understood as a series of protection measures for sensitive data, aiming to prevent the leakage of sensitive information by transforming or hiding the true value of the data. Anonymization strategies include a series of processing methods aimed at modifying the original sensitive data in accordance with the anonymization strategy without affecting the usability and integrity of the data, making it unrecognizable or unrecoverable by external personnel or users without proper authorization.
[0036] Desensitization strategies can include various methods for desensitizing initial data. For example, desensitization methods can include: data masking, which achieves desensitization by hiding or replacing a portion of sensitive data; data substitution, which replaces sensitive data with non-sensitive virtual data; data encryption, which encrypts data so that even if the data is leaked, unauthorized personnel cannot decipher its content; data deletion, which completely deletes sensitive data, such as deleting ID card information, bank account information, etc.; and data hashing, which uses a one-way hash algorithm (such as SHA-256) to process sensitive data, converting it into an irreversible "digest" value, ensuring data privacy as the hashed data cannot be recovered. Desensitization methods can also be a combination of the above methods or other methods, and this specification does not impose any limitations on these methods.
[0037] In one embodiment, the desensitization method corresponding to the initial data received is determined based on the correlation between the format of the data write request and the desensitization method in the desensitization strategy. Since data write requests typically have a standard format, such as JSON, XML, or Protobuf, the corresponding desensitization method can be matched in the desensitization strategy according to the format of the data write request. Furthermore, the initial data carried by the data write request is processed based on this desensitization method to obtain desensitized data.
[0038] In one embodiment, the desensitization method corresponding to the received initial data is determined based on the correlation between the format of the initial data and the desensitization method in the desensitization strategy. For example, the format of the initial data can be text (simple strings or log information), image (such as PNG, JPEG), audio (such as MP3, WAV, etc.), database, table, object (such as JSON, XML), or a mixed format. The desensitization method corresponding to the format of the initial data can be matched in the desensitization strategy, and then the initial data carried in the data write request is further processed based on the desensitization method to obtain desensitized data.
[0039] In another embodiment, the desensitization processing method corresponding to the initial data received is determined based on the association between the identifier of the sending device and the desensitization processing method in the desensitization processing strategy. The identifier of the sending device uniquely identifies the sending device, and the proxy device can uniquely identify the sending device based on the identifier. The desensitization processing method corresponding to the initial data received is determined according to the pre-defined association between the identifier of the sending device and the desensitization processing method in the desensitization processing strategy. For example, for a data write request sent by sending device A, the desensitization processing method corresponding to sending device A is determined; for a data write request sent by sending device B, the desensitization processing method corresponding to sending device B is determined.
[0040] In another embodiment, the desensitization processing method corresponding to the initial data is determined based on the association between the identifier of the receiving device and the desensitization processing method in the desensitization processing strategy. The identifier of the receiving device uniquely identifies the receiving device, and the proxy device can uniquely identify the receiving device based on the identifier. The desensitization processing method corresponding to the initial data is determined based on the pre-defined association between the identifier of the receiving device and the desensitization processing method in the desensitization processing strategy. For example, for a data write request sent by the sending device to the receiving device C, the desensitization processing method corresponding to the receiving device C is determined; for a data write request sent by the sending device to the receiving device D, the desensitization processing method corresponding to the receiving device D is determined.
[0041] In one embodiment, after receiving a data write request from a sending device and for a receiving device, before performing de-identification processing on the initial data according to the de-identification processing strategy to obtain de-identified data, the method further includes: in response to the data write request, sending a policy retrieval request to a policy storage device; and receiving a de-identification processing strategy sent by the policy storage device in response to the policy retrieval request.
[0042] Specifically, in this embodiment, the policy storage device stores the de-identification processing policy. The policy storage device can be a standalone server device, such as a rack-mounted, blade, tower, or cabinet-type server device, or a workstation, mainframe, or other hardware device with strong computing power; it can also be a server cluster composed of multiple servers, with the servers in the service cluster arranged symmetrically; it can also be a wearable device, handheld device, personal computer, tablet computer, in-vehicle device, smartphone, computing device, or other processing device connected to a wireless modem, etc.
[0043] When the agent device receives a data write request from the sending device, it sends a policy retrieval request to the policy storage device via the communication link. The policy retrieval request instructs the policy storage device to send the de-identification processing policy to the agent device.
[0044] In other words, policy retrieval requests are typically transmitted via network protocols (such as TCP / IP, HTTP, MQTT, etc.). The agent device uses these protocols to pass the request data to the policy storage device. The policy storage device's system listens on specific ports or API interfaces, waiting to receive policy retrieval requests from the agent device.
[0045] In response to a policy retrieval request, the policy storage device sends a de-identification policy to the agent device. The agent device then de-identifies the initial data carried in the data write request based on this policy.
[0046] In this embodiment, when the agent device receives a data write request, it obtains the de-identification processing policy from the policy storage device in real time to obtain the latest version of the de-identification processing policy, thereby de-identifying the initial data based on the de-identification processing policy, which can improve the security of the de-identified data obtained after de-identifying the initial data.
[0047] In one embodiment, before desensitizing the initial data according to the desensitization processing strategy to obtain the desensitized data, the method further includes: receiving an update request for the initial desensitization processing strategy, updating the multiple desensitization processing methods included in the initial desensitization processing strategy, and obtaining the desensitization processing strategy.
[0048] An update request can be understood as an update to the multiple masking methods included in the initial masking strategy, and also as an update to the association between each masking method and the initial data and / or data write requests. Updating the initial masking strategy yields the final masking strategy.
[0049] For example, an update request can delete, modify, or add multiple desensitization methods included in the initial desensitization strategy. It can also modify desensitization methods that match the format of the initial data, such as changing desensitization method f1 that matches the initial data in text format to desensitization method f2.
[0050] In this embodiment, the update request can be obtained by the proxy device system through an external interface based on user input, or it can be periodically triggered by the proxy device system through an internal program, or it can be obtained in other ways.
[0051] In this embodiment, by updating and optimizing the de-identification strategy once or multiple times through update requests, the de-identification strategy can be enriched, covering more de-identification scenarios and improving the security of the de-identified data obtained after de-identifying the initial data.
[0052] S106. Send a data writing request carrying de-identified data to the receiving device to write the de-identified data to the receiving device.
[0053] The proxy device desensitizes the initial data according to the desensitization processing policy to obtain desensitized data, modifies the data write request carrying the initial data into a data write request carrying the desensitized data based on the desensitized data, and forwards the data write request to the receiving device to write the desensitized data into the receiving device.
[0054] For example, the initial data included in the data write request is "Zhang San, phone number 1234567, address x province x city x district", and the desensitized data obtained by desensitizing the initial data is "Zhang San, phone number 123***7, address E8C636D0C0486378BF".
[0055] Writing data into the receiving device can be achieved in different ways, depending on the requirements and the technology stack of the database. For example, use the SQL INSERT statement to insert single or multiple records. For example, INSERT INTO users(name, phone number, address) VALUES ("Zhang San", 123***7, "E8C636D0C0486378BF"). Another example is to update the data in the receiving device through the UPDATE statement. For example, UPDATE users SET number = 123***7 WHERE name = "Zhang San".
[0056] As Figure 3 shown, Figure 3 is a schematic diagram of the scenario of a data desensitization processing method provided by an embodiment of this specification. The application system 201 in the production environment sends a data write request to the data proxy service system 2021 of the proxy device. The data write request carries the initial data, and data is written for the database system 201 in the test environment.
[0057] The data proxy service system 2021 receives the data write request, and the detection & processing system 2022 detects multiple sub-data included in the initial data carried in the data write request. The detection & processing system 2022 obtains the sensitive processing policy through the sensitive information identification system 2023, and thus desensitizes the multiple sub-data included in the initial data according to the sensitive processing policy to obtain desensitized data.
[0058] The data proxy service system 2021 obtains the desensitized data, generates a data write request carrying the desensitized data, and sends the data write request carrying the desensitized data to the database system 201 in the test environment.
[0059] In this specification, the proxy device receives a data write request from the sending device, specifically for the receiving device. This data write request instructs that initial data be written to the receiving device. Further, the proxy device performs de-identification processing on the initial data according to a de-identification strategy to obtain de-identified data. De-identification processing ensures that the initial data retains its original value by replacing or hiding sensitive information, preventing the exposure of true information and thus ensuring the privacy and security of the initial data. Further, the proxy device sends a data write request carrying the de-identified data to the receiving device to write the de-identified data to the receiving device.
[0060] In other words, this specification utilizes a proxy device to process data write requests sent from the sending device to the receiving device. Without modifying the original application systems of the sending and receiving devices, it achieves anonymization of the initial data carried in the data write request. This eliminates the cost of modifying the original application systems and offers greater flexibility in the anonymization process. Furthermore, by anonymizing the initial data before writing it to the receiving device (used as a test environment), it ensures that the data written to the test environment does not contain sensitive information, preventing the leakage of sensitive information in the test environment and improving data security.
[0061] In one embodiment, such as Figure 4 The diagram shown is a flowchart illustrating a data anonymization method provided in an embodiment of this specification. The method is executed by a proxy device. This method can be implemented using a computer program and can run on a data anonymization processing device based on the von Neumann architecture. This computer program can be integrated into an application or run as a standalone utility application.
[0062] Specifically, the data anonymization method includes: S302, Receive a data write request from the sending device and directed to the receiving device, the data write request carrying initial data.
[0063] See S102 above, which will not be repeated here.
[0064] S304. Based on the multiple desensitization methods included in the desensitization strategy, match the desensitization method corresponding to each of the multiple sub-data included in the initial data.
[0065] In this embodiment, the initial data includes multiple sub-data, and the multiple desensitization processing methods included in the desensitization processing strategy are pre-correlated with the multiple sub-data.
[0066] In one embodiment, the initial data is segmented according to the segmentation method corresponding to the de-identification strategy, resulting in multiple sub-data items included in the initial data. In the field of natural language processing, segmenting the initial data can be understood as dividing a continuous piece of text data into smaller units, such as dividing the initial data into sub-data items based on words.
[0067] In this embodiment, the initial data is first cleaned using basic methods, such as removing noisy characters (e.g., punctuation marks, special characters) or converting between simplified and traditional Chinese characters. Next, a suitable word segmentation tool is selected based on the segmentation method corresponding to the anonymization strategy. For example, tools like jieba, THULAC, and HanLP can be used for Chinese text segmentation, while NLTK and spaCy are common tools for English text. Finally, the selected word segmentation tool is used to divide the initial data into several sub-data items consisting of words or phrases. For example, if the initial data includes "Zhang San, phone number 1234567, address x province x city x district", the resulting data would be "Zhang San", "phone number 1234567", and "address x province x city x district".
[0068] Furthermore, the results of word segmentation can be post-processed and optimized. The multiple sub-data as the word segmentation results may contain some errors or inaccurate segments, especially when dealing with complex sentences, ambiguous words or new words. The word segmentation effect can be optimized by combining dictionaries, adding custom vocabulary, adjusting the word segmentation model, etc.
[0069] like Figure 5 As shown, Figure 5 This is a schematic diagram of a process for obtaining de-identified data provided in an embodiment of this specification. In this embodiment, based on the word segmentation method corresponding to the de-identification processing strategy 302, the initial data 301 is segmented to obtain multiple sub-data. The multiple sub-data include at least sub-data 3011, sub-data 3012, sub-data 3013, sub-data 3014, and sub-data 3015.
[0070] After obtaining the initial data, which includes multiple sub-data items, the corresponding de-identification processing method is matched to each sub-data item according to the multiple de-identification processing methods included in the de-identification processing strategy. For example... Figure 5 As shown, sub-data 3011 corresponds to desensitization processing method 3021, sub-data 3012 corresponds to desensitization processing method 3022, sub-data 3013 corresponds to desensitization processing method 3023, sub-data 3014 corresponds to desensitization processing method 3024, and sub-data 3015 corresponds to desensitization processing method 3025.
[0071] In one embodiment, the method of matching the desensitization processing corresponding to the sub-data includes: determining the data types corresponding to the multiple sub-data included in the initial data; and matching the desensitization processing method corresponding to the sub-data according to the data type corresponding to the sub-data among the multiple desensitization processing methods included in the desensitization processing strategy.
[0072] The system retrieves the data type and content of the sub-data. Different data types require different anonymization methods, and the anonymization method can also be matched based on the specific content of the sub-data. For example, for string-type sub-data, anonymization methods typically include masking (e.g., replacing some characters with asterisks), encryption, and truncation (keeping only the first or last part). For instance, if the sub-data is a string containing ID card information, the numbers in the middle can be replaced with asterisks "***", keeping only the first and last few characters. For date and time-type sub-data, anonymization methods typically include obfuscation (e.g., keeping only the year and removing the month and day) and replacing the date with a random date.
[0073] For example, given the initial data "Zhang San, phone number 1234567, address x province x city x district", after de-identification processing, the de-identified data becomes "Zhang San, phone number 123***7, address E8C636D0C0486378BF". Specifically, the sub-data "Zhang San" is not processed; the sub-data "1234567" is de-identified using a mask; and the sub-data "x province x city x district" is de-identified using a hash calculation.
[0074] In this embodiment, the initial data is anonymized by using the data types corresponding to multiple sub-data, which can greatly improve the security of the anonymized data, reduce the risk of leakage of sensitive information in the initial data, and protect data security.
[0075] In one embodiment, the method of matching the desensitization processing corresponding to the sub-data includes: determining the labels corresponding to the multiple sub-data included in the initial data; and matching the desensitization processing method corresponding to the sub-data according to the labels corresponding to the sub-data among the multiple desensitization processing methods included in the desensitization processing strategy.
[0076] The desensitization strategy pre-defines the association between multiple desensitization methods and tags. Based on the specific content of each tag and each sub-data item, the sub-data is associated with each tag, thereby matching the desensitization method associated with the tag to the sub-data. For example, the tag for sub-data with the specific content "phone number 1234567" is "phone number", and the desensitization method corresponding to this tag is masking.
[0077] S306. Perform desensitization processing on the sub-data based on the desensitization processing method corresponding to the sub-data until desensitized data is obtained.
[0078] like Figure 5 As shown, sub-data 3011 corresponds to desensitization processing method 3021, sub-data 3012 corresponds to desensitization processing method 3022, sub-data 3013 corresponds to desensitization processing method 3023, sub-data 3014 corresponds to desensitization processing method 3024, and sub-data 3015 corresponds to desensitization processing method 3025. Further desensitization processing is performed on the sub-data based on the desensitization processing methods corresponding to the multiple sub-data, resulting in desensitized data 304.
[0079] For example, the initial data is "Zhang San, phone number 1234567, address x province x city x district". After desensitizing the initial data, the desensitized data is "Zhang San, phone number 123***7, address E8C636D0C0486378BF".
[0080] S306. Send a data writing request carrying de-identified data to the receiving device to write the de-identified data to the receiving device.
[0081] See S106 above, which will not be repeated here.
[0082] This manual utilizes a proxy device to handle data write requests sent from the sending device to the receiving device. Without modifying the original application systems of the sending and receiving devices, it achieves data anonymization of the initial data carried in the write request. This eliminates the cost of modifying the original application systems and offers greater flexibility in the anonymization process. Furthermore, by anonymizing the initial data before writing it to the receiving device (used as a test environment), it ensures that the data written to the test environment does not contain sensitive information, preventing the leakage of sensitive information in the test environment and improving data security.
[0083] In one embodiment, such as Figure 6 The diagram shown is a flowchart illustrating a data anonymization method provided in an embodiment of this specification. The method is executed by a proxy device. This method can be implemented using a computer program and can run on a data anonymization processing device based on the von Neumann architecture. This computer program can be integrated into an application or run as a standalone utility application.
[0084] Specifically, the data anonymization method includes: S302, Receive a data write request from the sending device and directed to the receiving device, the data write request carrying initial data.
[0085] See S102 above, which will not be repeated here.
[0086] S304. Perform sensitive data detection on the initial data, remove the target sub-data that is considered non-sensitive data from the initial data, and obtain the preprocessed data.
[0087] Sensitive data detection is performed on the initial data, which involves classifying and processing the initial data to distinguish between data that may reveal sensitive information and data that will not. Non-sensitive information can be publicly available data, such as press releases and published research papers; it can also be general information, such as publicly available city names, weather data, and some statistical data; and it can also be non-personalized data, such as product numbers, equipment status, temperature, and inventory quantities.
[0088] The process involves sensitive data detection of the initial data, removing target sub-data that is considered non-sensitive data, and word segmentation of the initial data to obtain multiple sub-data items. Further, based on the specific content or tags corresponding to each sub-data item, it is determined whether the sub-data item is sensitive data or a target sub-data item that is not sensitive data.
[0089] For example, if the initial data is "Zhang San, phone number 1234567, address x province x city x district", the target sub-data that is non-sensitive data in the initial data is "Zhang San". After removing the target sub-data from the initial data, the preprocessed data is "phone number 1234567, address x province x city x district".
[0090] S306. Perform desensitization processing on the preprocessed data according to the desensitization processing strategy to obtain desensitized data; wherein, the desensitized data includes target sub-data.
[0091] Desensitized data includes desensitized sub-data and unprocessed target sub-data. For example, the initial data is "Zhang San, phone number 1234567, address x province x city x district". The target sub-data in the initial data that is not sensitive is "Zhang San". After removing the target sub-data from the initial data, the preprocessed data is "phone number 1234567, address x province x city x district". Desensitizing the preprocessed data results in desensitized data "Zhang San, phone number 123***7, address E8C636D0C0486378BF", where the desensitized data includes the target sub-data "Zhang San".
[0092] In this embodiment, the initial data is identified to determine which sub-data is non-sensitive. These target sub-data can then be filtered out and removed from the initial data. This non-sensitive data does not require special protection and can be used publicly or for further analysis. Removing non-sensitive data yields preprocessed data, which is then anonymized to obtain de-identified data. This not only helps protect privacy but also simplifies data storage and processing, preventing the leakage of redundant information.
[0093] S308. Send a data writing request carrying de-identified data to the receiving device to write the de-identified data to the receiving device.
[0094] See S106 above, which will not be repeated here.
[0095] This manual utilizes a proxy device to handle data write requests sent from the sending device to the receiving device. Without modifying the original application systems of the sending and receiving devices, it achieves data anonymization of the initial data carried in the write request. This eliminates the cost of modifying the original application systems and offers greater flexibility in the anonymization process. Furthermore, by anonymizing the initial data before writing it to the receiving device (used as a test environment), it ensures that the data written to the test environment does not contain sensitive information, preventing the leakage of sensitive information in the test environment and improving data security.
[0096] The following are embodiments of the apparatus described in this specification, which can be used to execute the embodiments of the methods described in this specification. For details not disclosed in the apparatus embodiments of this specification, please refer to the embodiments of the methods described in this specification.
[0097] Please see Figure 7 This diagram illustrates the structure of a data anonymization processing apparatus provided in an exemplary embodiment of this specification. The data anonymization processing apparatus can be implemented as all or part of a device through software, hardware, or a combination of both. The device includes a request sending module 401, a data processing module 402, and a data writing module 403.
[0098] Request sending module 401 is used to receive a data write request from a sending device and for a receiving device, the data write request carrying initial data; Data processing module 402 is used to perform desensitization processing on the initial data according to the desensitization processing strategy to obtain desensitized data; The data writing module 403 is used to send a data writing request carrying the de-identified data to the receiving device so as to write the de-identified data into the receiving device.
[0099] In one embodiment, the data processing module 402 includes: The first processing unit is used to match the desensitization processing method corresponding to the multiple desensitization processing methods included in the desensitization processing strategy to the multiple sub-data included in the initial data respectively. The second processing unit is used to perform desensitization processing on the sub-data based on the desensitization processing method corresponding to the sub-data until desensitized data is obtained.
[0100] In one embodiment, the data desensitization processing apparatus further includes: The desensitization detection module is used to perform sensitive data detection on the initial data, remove target sub-data that are non-sensitive data from the initial data, and obtain preprocessed data. Data processing module 402 includes: The third processing module is used to perform desensitization processing on the preprocessed data according to the desensitization processing strategy to obtain desensitized data; wherein the desensitized data includes the target sub-data.
[0101] In one embodiment, the first processing unit includes: The type determination subunit is used to determine the data types corresponding to the multiple sub-data included in the initial data; The desensitization matching subunit is used to match the desensitization processing method corresponding to the sub-data with the data type corresponding to the sub-data among the multiple desensitization processing methods included in the desensitization processing strategy.
[0102] In one embodiment, the data processing module 402 includes: The third processing unit is used to perform word segmentation on the initial data according to the word segmentation method corresponding to the desensitization processing strategy, so as to obtain multiple sub-data included in the initial data.
[0103] In one embodiment, the data desensitization processing apparatus further includes: The policy acquisition module is used to send a policy acquisition request to the policy storage device in response to the data write request; The policy receiving module is used to receive the de-identification processing policy sent by the policy storage device in response to the policy acquisition request.
[0104] In one embodiment, the data desensitization processing apparatus further includes: The strategy update module is used to receive update requests for the initial de-identification processing strategy, update the multiple de-identification processing methods included in the initial de-identification processing strategy, and obtain the de-identification processing strategy.
[0105] In this specification, the proxy device receives a data write request from the sending device, specifically for the receiving device. This data write request instructs that initial data be written to the receiving device. Further, the proxy device performs de-identification processing on the initial data according to a de-identification strategy to obtain de-identified data. De-identification processing ensures that the initial data retains its original value by replacing or hiding sensitive information, preventing the exposure of true information and thus ensuring the privacy and security of the initial data. Further, the proxy device sends a data write request carrying the de-identified data to the receiving device to write the de-identified data to the receiving device.
[0106] This manual utilizes a proxy device to handle data write requests sent from the sending device to the receiving device. Without modifying the original application systems of the sending and receiving devices, it achieves data anonymization of the initial data carried in the write request. This eliminates the cost of modifying the original application systems and offers greater flexibility in the anonymization process. Furthermore, by anonymizing the initial data before writing it to the receiving device (used as a test environment), it ensures that the data written to the test environment does not contain sensitive information, preventing the leakage of sensitive information in the test environment and improving data security.
[0107] It should be noted that the data desensitization processing device provided in the above embodiments is only illustrated by the division of the above functional modules when executing the data desensitization processing method. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the data desensitization processing device and the data desensitization processing method embodiments provided in the above embodiments belong to the same concept, and the implementation process is detailed in the method embodiments, which will not be repeated here.
[0108] The example numbers in this specification are for descriptive purposes only and do not represent the superiority or inferiority of the examples.
[0109] This specification also provides a computer storage medium that can store multiple instructions adapted to be loaded and executed by a processor as described above. Figure 1 - Figure 6 The data anonymization processing method of the illustrated embodiment can be found in the following documentation for a detailed execution process: Figure 1 - Figure 6 The specific details of the illustrated embodiments will not be elaborated here.
[0110] This specification also provides a computer program product that stores at least one instruction, which is loaded and executed by a processor as described above. Figure 1 - Figure 6 The data anonymization processing method of the illustrated embodiment can be found in the following documentation for a detailed execution process: Figure 1 - Figure 6 The specific details of the illustrated embodiments will not be elaborated here.
[0111] Please see Figure 8 This document provides a schematic diagram of the structure of a proxy device as an embodiment of the present specification. Figure 8 As shown, the agent device 500 may include: at least one processor 501, at least one network interface 504, user interface 503, memory 505, and at least one communication bus 502.
[0112] The communication bus 502 is used to enable communication between these components.
[0113] The user interface 503 may include a display screen and a camera. Optionally, the user interface 503 may also include a standard wired interface and a wireless interface.
[0114] The network interface 504 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface).
[0115] The processor 501 may include one or more processing cores. The processor 501 connects to various parts of the server 500 using various interfaces and lines, and performs various functions and processes data by running or executing instructions, programs, code sets, or instruction sets stored in the memory 505, and by calling data stored in the memory 505. Optionally, the processor 501 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). The processor 501 may integrate one or a combination of several of the following: a Central Processing Unit (CPU), a Graphics Processing Unit (GPU), and a modem. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the content to be displayed on the screen; and the modem handles wireless communication. It is understood that the modem may also not be integrated into the processor 501 and may be implemented as a separate chip.
[0116] The memory 505 may include random access memory (RAM) or read-only memory. Optionally, the memory 505 may include a non-transitory computer-readable storage medium. The memory 505 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 505 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-described method embodiments, etc.; the data storage area may store data involved in the above-described method embodiments, etc. Optionally, the memory 505 may also be at least one storage device located remotely from the aforementioned processor 501. Figure 8 As shown, the memory 505, which serves as a computer storage medium, may include an operating system, a network communication module, a user interface module, and a data processing application program.
[0117] exist Figure 8 In the agent device 500 shown, the user interface 503 is mainly used to provide an input interface for the user and to obtain the user's input data; while the processor 501 can be used to call the data processing application stored in the memory 505 and specifically perform the following operations: Receive a data write request from a transmitting device and directed to a receiving device, the data write request carrying initial data; The initial data is desensitized according to the desensitization processing strategy to obtain desensitized data; A data write request carrying the de-identified data is sent to the receiving device to write the de-identified data into the receiving device.
[0118] In one embodiment, the processor 501 performs desensitization processing on the initial data according to the desensitization processing strategy to obtain desensitized data, specifically by: Based on the multiple desensitization methods included in the desensitization strategy, the initial data includes multiple sub-data, each matched with a desensitization method corresponding to the sub-data. The sub-data is de-identified based on the de-identification processing method corresponding to the sub-data until de-identified data is obtained.
[0119] In one embodiment, after the processor 501 executes the data write request received from the transmitting device and for the receiving device, before performing de-identification processing on the initial data according to the de-identification processing strategy to obtain de-identified data, the following is further executed: Sensitive data detection is performed on the initial data to remove target sub-data that are considered non-sensitive data, thus obtaining preprocessed data; The step of performing desensitization processing on the initial data according to the desensitization processing strategy to obtain desensitized data includes: The preprocessed data is desensitized according to the desensitization processing strategy to obtain desensitized data; wherein, the desensitized data includes the target sub-data.
[0120] In one embodiment, the processor 501 executes multiple de-identification processing methods included in the de-identification processing strategy, matching the de-identification processing method corresponding to each of the multiple sub-data included in the initial data, specifically executing: Determine the data types corresponding to the multiple sub-data included in the initial data; Among the multiple desensitization methods included in the desensitization strategy, the desensitization method corresponding to the sub-data is matched according to the data type corresponding to the sub-data.
[0121] In one embodiment, before the processor 501 executes the multiple de-identification processing methods included in the de-identification processing strategy, and matches the de-identification processing method corresponding to each of the multiple sub-data included in the initial data, it further executes: Based on the word segmentation method corresponding to the desensitization processing strategy, the initial data is segmented to obtain multiple sub-data items included in the initial data.
[0122] In one embodiment, after the processor 501 executes the data write request received from the transmitting device and for the receiving device, before performing de-identification processing on the initial data according to the de-identification processing strategy to obtain de-identified data, the following is further executed: In response to the data write request, a policy retrieval request is sent to the policy storage device; Receive the de-identification processing policy sent by the policy storage device in response to the policy retrieval request.
[0123] In one embodiment, before the processor 501 performs the desensitization processing on the initial data according to the desensitization processing strategy to obtain the desensitized data, it also performs the following: Receive an update request for the initial desensitization processing strategy, update the multiple desensitization processing methods included in the initial desensitization processing strategy, and obtain the desensitization processing strategy.
[0124] In this specification, the proxy device receives a data write request from the sending device, specifically for the receiving device. This data write request instructs that initial data be written to the receiving device. Further, the proxy device performs de-identification processing on the initial data according to a de-identification strategy to obtain de-identified data. De-identification processing ensures that the initial data retains its original value by replacing or hiding sensitive information, preventing the exposure of true information and thus ensuring the privacy and security of the initial data. Further, the proxy device sends a data write request carrying the de-identified data to the receiving device to write the de-identified data to the receiving device.
[0125] This manual utilizes a proxy device to handle data write requests sent from the sending device to the receiving device. Without modifying the original application systems of the sending and receiving devices, it achieves data anonymization of the initial data carried in the write request. This eliminates the cost of modifying the original application systems and offers greater flexibility in the anonymization process. Furthermore, by anonymizing the initial data before writing it to the receiving device (used as a test environment), it ensures that the data written to the test environment does not contain sensitive information, preventing the leakage of sensitive information in the test environment and improving data security.
[0126] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the methods described above. The storage medium can be a magnetic disk, optical disk, read-only memory, or random access memory, etc.
[0127] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0128] The above-disclosed embodiments are merely preferred embodiments of this specification and should not be construed as limiting the scope of this specification. Therefore, any equivalent variations made in accordance with the claims of this specification shall still fall within the scope of this specification.
Claims
1. A data anonymization processing method, the method being executed by a proxy device, the method comprising: Receive a data write request from a transmitting device and directed to a receiving device, the data write request carrying initial data; The initial data is desensitized according to the desensitization processing strategy to obtain desensitized data; A data write request carrying the de-identified data is sent to the receiving device to write the de-identified data into the receiving device.
2. The data desensitization processing method according to claim 1, wherein the step of desensitizing the initial data according to the desensitization processing strategy to obtain desensitized data includes: Based on the multiple desensitization methods included in the desensitization strategy, the initial data includes multiple sub-data, each matched with a desensitization method corresponding to the sub-data. The sub-data is de-identified based on the de-identification processing method corresponding to the sub-data until de-identified data is obtained.
3. The data desensitization processing method according to claim 1, further comprising, after receiving a data write request from a sending device and for a receiving device, and before performing desensitization processing on the initial data according to a desensitization processing strategy to obtain desensitized data: Sensitive data detection is performed on the initial data to remove target sub-data that are considered non-sensitive data, thus obtaining preprocessed data; The step of performing desensitization processing on the initial data according to the desensitization processing strategy to obtain desensitized data includes: The preprocessed data is desensitized according to the desensitization processing strategy to obtain desensitized data; wherein, the desensitized data includes the target sub-data.
4. The data desensitization processing method according to claim 2, wherein matching the desensitization processing method corresponding to each of the multiple sub-data included in the initial data with the desensitization processing method according to the multiple desensitization processing methods included in the desensitization processing strategy, comprises: Determine the data types corresponding to the multiple sub-data included in the initial data; Among the multiple desensitization methods included in the desensitization strategy, the desensitization method corresponding to the sub-data is matched according to the data type corresponding to the sub-data.
5. The data desensitization processing method according to claim 2, before matching the desensitization processing method corresponding to the multiple sub-data included in the initial data according to the multiple desensitization processing methods included in the desensitization processing strategy, the method further includes: Based on the word segmentation method corresponding to the desensitization processing strategy, the initial data is segmented to obtain multiple sub-data items included in the initial data.
6. The data desensitization processing method according to claim 1, further comprising, after receiving a data write request from a sending device and for a receiving device, and before performing desensitization processing on the initial data according to a desensitization processing strategy to obtain desensitized data: In response to the data write request, a policy retrieval request is sent to the policy storage device; Receive the de-identification processing policy sent by the policy storage device in response to the policy retrieval request.
7. The data desensitization processing method according to claim 1, further comprising, before performing desensitization processing on the initial data according to the desensitization processing strategy to obtain desensitized data: Receive an update request for the initial desensitization processing strategy, update the multiple desensitization processing methods included in the initial desensitization processing strategy, and obtain the desensitization processing strategy.
8. A data desensitization processing apparatus, wherein the desensitization processing apparatus is disposed on a proxy device, the apparatus comprising: A request sending module is used to receive a data write request from a sending device and for a receiving device, the data write request carrying initial data; The data processing module is used to perform desensitization processing on the initial data according to the desensitization processing strategy to obtain desensitized data; The data writing module is used to send a data writing request carrying the de-identified data to the receiving device, so as to write the de-identified data into the receiving device.
9. A computer program product storing a plurality of instructions adapted for loading by a processor and executing the method steps of any one of claims 1 to 7.
10. A computer storage medium storing a plurality of instructions adapted for loading by a processor and executing the method steps of any one of claims 1 to 7.
11. An electronic device, comprising: A processor and a memory; wherein the memory stores a computer program adapted to be loaded by the processor and executed the method steps as claimed in any one of claims 1 to 7.