Financial sensitive data desensitization method and device, equipment and storage medium
By identifying sensitive data segments in interface requests, using regular expressions and dynamic identification information for generation and encoding, and combining this with the FPE encryption algorithm, the problems of low efficiency and insufficient security in desensitizing financial sensitive data are solved, achieving efficient and secure data transmission.
Patent Information
- Application Number
- CN202511142048.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-15
- Publication Date
- 2025-11-07
AI Technical Summary
Existing methods for desensitizing sensitive financial data suffer from low efficiency and insufficient security during data transmission. Traditional methods affect data availability and are easily cracked, while FPE technology uses a variable secondary key, making the encryption process easy to crack and untraceable.
By identifying sensitive data segments in the interface request, using preset regular expressions to determine the data to be encrypted, generating dynamic identification information and extracting characters, combining and encoding them in a preset order, and encrypting them using the FPE encryption algorithm to generate desensitized financial data.
It improves the efficiency of desensitizing financial sensitive data, enhances the security of data transmission, ensures data reversibility and availability, supports the secondary use of data, and can track data leaks.
Smart Images

Figure CN120910912A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data security, and in particular to a financial sensitive data desensitization method, device, equipment and storage medium. BACKGROUND
[0002] At present, with the wide application of API (Application Programming Interface, application programming interface), it faces the risk of leakage when transmitting sensitive data (such as personal identity information, financial data, etc.). Although the traditional desensitization method can protect the data, it often adopts fixed rules such as replacement, masking, truncation and other processing methods. Such desensitization processing may change the original format or content of the data more, thereby affecting the usability of the data and the normal operation of the business logic. The desensitized data is irreversible and cannot be used twice. Some desensitization uses FPE technology (Format Preserving Encryption, format preserving encryption technology), but in the use process, the effective use of the secondary key changes, making the encryption process easy to crack, and the data leakage cannot be effectively tracked.
[0003] From the above, how to improve the efficiency and security of data desensitization in the process of financial sensitive data desensitization is a problem to be solved at present. SUMMARY
[0004] Therefore, the purpose of the present application is to provide a financial sensitive data desensitization method, device, equipment and storage medium, which can improve the efficiency of data desensitization in the process of financial sensitive data desensitization, and thus improve the security of data transmission. The specific scheme is as follows:
[0005] In a first aspect, the present application provides a financial sensitive data desensitization method, comprising:
[0006] Identifying the sensitive data segment corresponding to the desensitization financial data in the interface request, obtaining the sensitive data type and the target specific character position, and then determining the data to be encrypted in the desensitization financial data by using a preset regular expression and based on the target specific character position; the sensitive data segment includes a telephone number field, an identity number field, a payment card number field and a network address field;
[0007] Generating dynamic identification information corresponding to the desensitization financial data, and extracting data of a first preset number of bits from the dynamic identification information to obtain a first type of character, and then intercepting data of a second preset number of bits at the end of the desensitization financial data to obtain a second type of character;
[0008] combining and encoding the first type of characters and the second type of characters according to a preset order to obtain an initial character sequence, and performing base conversion on the initial character sequence according to a preset base conversion rule to obtain a target converted character sequence;
[0009] encrypting the to-be-encrypted data based on the target converted character sequence to obtain encrypted data, and performing desensitization processing on the to-be-desensitized financial data based on the encrypted data to obtain desensitized financial data.
[0010] Optionally, the sensitive data segment corresponding to the to-be-desensitized financial data in the identification interface request is obtained, the sensitive data type and the target specific character position are obtained, and then the to-be-encrypted data in the to-be-desensitized financial data is determined by using a preset regular expression and based on the target specific character position, including:
[0011] determining a regular expression matching rule corresponding to each sensitive data type in a preset sensitive data type set; wherein the telephone number matching rule is a legal number segment prefix allocated by all operators and a fixed number of digit sequences; the identity number matching rule is a date coding rule covering different years of issue and a check code verification logic; the payment card number matching rule is a digit sequence starting with a specific identification code; and the network address matching rule is a four-segment dotted decimal format conforming to the Internet Protocol address;
[0012] scanning the to-be-desensitized financial data based on the telephone number matching rule, the identity number matching rule, the payment card number matching rule, and the network address matching rule in sequence by using a regular expression matching engine to obtain the corresponding sensitive data type and the matching rule;
[0013] determining the corresponding target specific character position based on the matching rule, and then determining the to-be-encrypted data in the to-be-desensitized financial data by using a preset regular expression and based on the target specific character position.
[0014] Optionally, the dynamic identification information corresponding to the to-be-desensitized financial data is generated, and a first preset number of bits of data is extracted from the dynamic identification information to obtain the first type of characters, and a second preset number of bits of data at the end of the to-be-desensitized financial data is intercepted to obtain the second type of characters, including:
[0015] generating the dynamic identification information corresponding to the to-be-desensitized financial data according to a preset international standard specification; the dynamic identification information is a mixed coding string including digit characters, lowercase letter characters, and uppercase letter characters and having global uniqueness;
[0016] locating a start position of the dynamic identification information string, and performing character scanning operation on the dynamic identification information string from the start position to obtain a first scanning result; the first scanning result is a character of a number character category;
[0017] extracting a first preset number of digits of number characters from the first scanning result to obtain a first character, and if a second scanning result obtained when scanning to the end of the first scanning result corresponds to a number value smaller than a number value corresponding to the first preset number of digits, performing a missing character supplement operation on the second scanning result by using a preset filling rule to obtain the first character;
[0018] locating an end position of the dynamic identification information string, and scanning the second preset number of digits of the to-be-desensitized financial data from the end position to obtain a second character.
[0019] Optionally, the first character and the second character are combined and encoded according to a preset order to obtain an initial character sequence, and the initial character sequence is converted according to a preset base conversion rule to obtain a target converted character sequence, including:
[0020] combining the first character and the second character according to a preset order to obtain a combined character sequence, and splicing each character in the combined character sequence according to a character arrangement order to obtain a splicing result; the splicing result is a decimal integer with high bits in front and low bits at the back;
[0021] determining a preset base according to the preset base conversion rule, and performing a continuous division operation based on the decimal integer and the preset base to obtain a corresponding quotient and a remainder, and mapping the remainder to a character representation corresponding to the preset base to obtain a mapping result;
[0022] determining the conversion of the splicing result according to the mapping result and the quotient to obtain an initial converted character sequence, and verifying whether a character string length corresponding to the initial converted character sequence satisfies a preset compression bit condition, if the character string length corresponding to the initial converted character sequence satisfies the preset compression bit condition, setting the initial converted character sequence as the target converted character sequence.
[0023] Optionally, the target converted character sequence is used to encrypt the to-be-encrypted data to obtain encrypted data, and the encrypted data is used to desensitize the to-be-desensitized financial data to obtain desensitized financial data, including:
[0024] Based on preset requirements, an encryption algorithm framework conforming to a security standard format is determined, and a master key corresponding to the data to be encrypted is determined from the encryption algorithm framework. Then, the adjustment parameters corresponding to the target converted character sequence are determined.
[0025] The encryption algorithm framework is used to split each character in the target converted character sequence into character elements, and each character element is converted into a character value with a preset base. Then, the encryption algorithm framework is called and the character values are obfuscated and diffused based on the adjustment parameters to obtain the processed character sequence.
[0026] The processed character sequence is converted into character elements, and each character element is concatenated to obtain a concatenation result. Then, the concatenation result and the master key are used to encrypt the data to be encrypted to obtain encrypted data. The encrypted data is then used to replace the number of characters corresponding to the end of the financial data to be de-identified to obtain de-identified financial data. The number of characters is the number of characters corresponding to the encrypted data.
[0027] Optionally, after performing desensitization processing on the financial data to be desensitized based on the encrypted data to obtain desensitized financial data, the process further includes:
[0028] The sensitive data segment of the financial data to be de-identified is parsed, and the compressed identification information at the end of the sensitive data segment and the replaced intermediate fields are separated.
[0029] Using the encryption algorithm framework and based on the compressed identification information, the preset encryption key, and the intermediate field, the financial data to be de-identified is subjected to a reverse operation to obtain the original character sequence; wherein, the original character sequence has the same format as the financial data to be de-identified.
[0030] The original character sequence is backfilled into the intermediate field data corresponding to the intermediate field in the financial data to be de-identified, and the compressed identifier information is subjected to a number base inverse conversion operation to obtain the inverse conversion result;
[0031] The inverse conversion result is reverse-mapped according to the character position from low to high to obtain the reverse mapping result. The reverse mapping result is then expanded and summed according to the decimal place value to obtain the decimal integer to be processed.
[0032] The integer to be processed is split into a first sub-digit sequence and a second sub-digit sequence according to a preset number of bits, and the first sub-digit sequence and the second sub-digit sequence are converted into characters respectively to obtain the corresponding first type character group and second type character group;
[0033] The second type of character set is used to replace compressed identification information at the end of the to-be-desensitized financial data, to obtain a replacement result, and based on a character combination feature corresponding to the first type of character set, an entry of dynamic identification information containing the same character sequence is searched in a request log record library, and then based on the replacement result and the entry of dynamic identification information, restored data is determined.
[0034] Optionally, the searching, based on the character combination feature corresponding to the first type of character set, of the entry of dynamic identification information containing the same character sequence in the request log record library comprises:
[0035] A request log record library including a plurality of log records is established; the log records include a request time, a request party identifier, a dynamic identification information field, and reference information corresponding to to-be-desensitized financial data;
[0036] The dynamic identification information field in each of the log records is extracted from the request log record library, and an inverted index is established based on a prefix number sequence of the dynamic identification information field, and then the first type of character set is set as a search key value, so as to obtain a corresponding log record set based on the inverted index and the search key value;
[0037] It is judged whether the number of logs in the log record set is greater than one, and if the number of logs in the log record set is greater than one, a filtering operation is performed on the log record set based on a preset time range, to obtain an entry of dynamic identification information containing the same character sequence; the entry of dynamic identification information includes context information corresponding to the interface request.
[0038] In a second aspect, the present application provides a financial sensitive data desensitization device, comprising:
[0039] A sensitive data segment identification module is configured to identify a sensitive data segment corresponding to to-be-desensitized financial data in an interface request, to obtain a sensitive data type and a target specific character position, and then determine to-be-encrypted data in the to-be-desensitized financial data by using a preset regular expression and based on the target specific character position; the sensitive data segment includes a telephone number field, an identification number field, a payment card number field, and a network address field.
[0040] An identification information generation module is configured to generate dynamic identification information corresponding to the to-be-desensitized financial data, and extract data of a first preset number of bits from the dynamic identification information to obtain a first type of character, and then extract data of a second preset number of bits at the end of the to-be-desensitized financial data to obtain a second type of character.
[0041] a preset base conversion module, configured to combine and encode the first type of characters and the second type of characters according to a preset order to obtain an initial character sequence, and convert the initial character sequence according to a preset base conversion rule to obtain a target converted character sequence;
[0042] a data desensitization module, configured to encrypt the to-be-encrypted data based on the target converted character sequence to obtain encrypted data, and perform desensitization processing on the to-be-desensitized financial data based on the encrypted data to obtain desensitized financial data.
[0043] In a third aspect, the present application provides an electronic device, comprising:
[0044] a memory, configured to save a computer program;
[0045] a processor, configured to execute the computer program to implement the financial sensitive data desensitization method.
[0046] In a fourth aspect, the present application provides a computer readable storage medium, configured to save a computer program, wherein the computer program is executed by a processor to implement the financial sensitive data desensitization method.
[0047] As can be seen from the above, before desensitizing the financial sensitive data, the present application needs to identify the sensitive data segment corresponding to the to-be-desensitized financial data in the interface request to obtain the sensitive data type and the target specific character position, and then determine the to-be-encrypted data in the to-be-desensitized financial data by using a preset regular expression and based on the target specific character position; the sensitive data segment includes a telephone number field, an identity number field, a payment card number field and a network address field; dynamic identification information corresponding to the to-be-desensitized financial data is generated, and the first type of characters is obtained by extracting data of a first preset number of bits from the dynamic identification information, and the second type of characters is obtained by intercepting data of a second preset number of bits at the end of the to-be-desensitized financial data; the first type of characters and the second type of characters are combined and encoded according to a preset order to obtain an initial character sequence, and the initial character sequence is converted according to a preset base conversion rule to obtain a target converted character sequence; the to-be-encrypted data is encrypted based on the target converted character sequence to obtain encrypted data, and the to-be-desensitized financial data is desensitized based on the encrypted data to obtain desensitized financial data.
[0048] It can be seen that the application first needs to identify the sensitive data segment corresponding to the to-be-desensitized financial data in the interface request, obtain the sensitive data type and the target specific character position, and then determine the to-be-encrypted data in the to-be-desensitized financial data by using a preset regular expression and based on the target specific character position; then, dynamic identification information corresponding to the to-be-desensitized financial data is generated, and the first preset number of bits of data is extracted from the dynamic identification information to obtain the first type of character, and the second preset number of bits of data at the end of the to-be-desensitized financial data is intercepted to obtain the second type of character; further, the first type of character and the second type of character are combined and encoded in a preset order to obtain an initial character sequence, and the initial character sequence is converted in a preset radix to obtain a target converted character sequence; finally, the to-be-encrypted data is encrypted based on the target converted character sequence to obtain encrypted data, and the to-be-desensitized financial data is desensitized based on the encrypted data to obtain desensitized financial data. In this way, the efficiency of desensitizing data is improved in the process of desensitizing financial sensitive data, and the security of data transmission is improved. BRIEF DESCRIPTION OF DRAWINGS
[0049] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description are only a part of the present application, and for those skilled in the art, other drawings can be obtained without creative labor based on the provided drawings.
[0050] Figure 1 A financial sensitive data desensitization method flowchart disclosed by the present application;
[0051] Figure 2 A specific financial sensitive data desensitization flowchart disclosed by the present application;
[0052] Figure 3 A financial sensitive data desensitization device structure schematic diagram disclosed by the present application;
[0053] Figure 4 A structure diagram of an electronic device disclosed by the present application. DETAILED DESCRIPTION
[0054] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.
[0055] At present, with the wide application of API, it faces the risk of leakage when transmitting sensitive data. Although the traditional desensitization method can protect data, it often adopts fixed rules such as replacement, masking, truncation and other processing methods. Such desensitization processing may change the original format or content of the data more, thereby affecting the usability of the data and the normal operation of the business logic. The desensitized data is irreversible and cannot be used twice. Some desensitization uses FPE technology, but in the use process, the effective use of the secondary key changes, so that the encryption process is easy to crack, and after the data leakage, it cannot be effectively tracked. Therefore, the present application provides a financial sensitive data desensitization method, which can improve the desensitization efficiency of data in the process of financial sensitive data desensitization, thereby improving the security of data transmission.
[0056] Referring to Figure 1 The embodiment of the application discloses a financial sensitive data desensitization method, comprising:
[0057] Step S11, identifying the sensitive data segment corresponding to the desensitization financial data in the interface request, obtaining the sensitive data type and the target specific character position, and then determining the data to be encrypted in the desensitization financial data by using a preset regular expression based on the target specific character position; the sensitive data segment includes a telephone number field, an identity number field, a payment card number field and a network address field.
[0058] In this embodiment, the embodiment of the application needs to construct a sensitive word definition set, that is, the sensitive words in the API request are defined as identity card number, bank card number, mobile phone number and IP address, wherein PHONE represents mobile phone number, IDCARD represents identity card number, CREDIT represents bank card number, and IP represents IP address. In addition, since the sensitive data types such as PHONE, CREDIT and IDCARD have fixed formats, for example, the mobile phone number is 11 digits, which is composed of the operator number segment (the first 3 digits) and the randomly allocated last 8 digits.
[0059] It is worth mentioning that if all the characters in the sensitive field are encrypted using FPE encryption method, the attacker may quickly deduce the data at each position according to these regular numbers or characters. Therefore, the embodiment of the application needs to determine the encryption position of the sensitive data to partially encrypt the sensitive data.
[0060] In a specific embodiment, the encryption position of the sensitive data is defined as follows:
[0061] PHONE: 182 **** 2723
[0062] IDCARD: 1101 ********** 3119
[0063] CREDIT: 6212** **** **34 23
[0064] IP: 192.***.***.121
[0065] In the above data, the "*" marks indicate characters to be encrypted. Subsequently, this embodiment of the application needs to count the amount of plaintext and ciphertext within different sensitive word categories, as shown in Table 1:
[0066] Table 1. Statistics on the Number of Plaintext and Ciphertext Messages
[0067]
[0068] Specifically, the process involves identifying sensitive data segments corresponding to the financial data to be anonymized in the interface request, obtaining the sensitive data types and target specific character positions, and then using preset regular expressions based on the target specific character positions to determine the data to be encrypted within the financial data to be anonymized. This can include: determining the regular expression matching rules corresponding to each sensitive data type in the preset set of sensitive data types; where the telephone number matching rule covers all legal number prefixes allocated by operators and a fixed number of digits; the identity number matching rule covers date encoding rules and check coded verification logic for numbers issued in different years; the payment card number matching rule identifies a number sequence starting with a specific identifier code; and the network address matching rule conforms to the four-segment dotted decimal format of Internet Protocol addresses. A regular expression matching engine is used to scan the financial data to be anonymized sequentially based on the telephone number matching rule, identity number matching rule, payment card number matching rule, and network address matching rule to obtain the corresponding sensitive data types and matching rules; the target specific character positions are determined based on the matching rules; and then the data to be encrypted within the financial data to be anonymized is determined using preset regular expressions based on the target specific character positions.
[0069] Step S12: Generate dynamic identification information corresponding to the financial data to be desensitized, extract a first preset number of data positions from the dynamic identification information to obtain a first type of character, and then extract a second preset number of data positions from the end of the financial data to be desensitized to obtain a second type of character.
[0070] In this embodiment, the present application requires the construction of a sensitive data identification center. In one specific implementation, the fields to be desensitized and the expressions determined by regular expression matching rules are as follows:
[0071] PHONE: '[1](([3][0-9])|([4][5-9])|([5][0-3,5-9])|([6][5,6])|([7][0-8])|([8][0-9])|([9][1,8,9]))[0-9]{8}';
[0072] wherein, [1] represents that the mobile phone number needs to start with the number 1, ([3][0-9]) is used to match 30-39 (mainstream operator number segment), ([4][5-9]) is used to match 45-49 (mainstream operator number segment), ([5][0-3,5-9]) is used to match 50-53 or 55-59 (mainstream operator number segment), ([6][5,6]) is used to match 65 or 66 (virtual operator), ([7][0-8]) is used to match 70-78, ([8][0-9]) is used to match 80-89 (mainstream operator number segment), ([9][1,8,9]) is used to match 91, 98, 99 (virtual operator), and [0-9]{8} represents that the last 8 digits can include any 8 digits of 0-9.
[0073] IDCARD: '([1-9]\d{5}(18|19|(
[23] \d))\d{2}((0[1-9])|(10|11|12))(([0-2][1-9])|10|20|30|31)\d{3}[0-9Xx])';
[0074] wherein, [1-9]\d{5} is an address code, used to represent a non-zero starting region code, 18|19|(
[23] \d))\d{2} is a year code, used to match 1800-2999, 0[1-9])|(10|11|12) is a month code, used to match 01-12, [0-2][1-9])|10|20|30|31 is a date code, used to match 01-31, and \d{3}[0-9Xx] is a sequence code and a check code, the sequence code includes three digits, and the check code includes one digit or X / x.
[0075] CREDIT: '(62[0-9]{14,17})';
[0076] wherein, 62 is the beginning of the card number, and [0-9]{14,17} represents 14 to 17 digits of 0-9.
[0077] IP: '(?:(?:25[0-5]|2[0-4][0-9]|
[01] ?[0-9][0-9]?)\.){3}(?:25[0-5]|2[0-4][0-9]|
[01] ?[0-9][0-9]?)';
[0078] Wherein, 25[0-5] is used to match 250-255, 2[0-4][0-9] is used to match 200-249,
[01] ?[0-9][0-9]? is used to match 0-199 (supporting leading zeros, such as 001 can be converted to 1), (regular\.){3} regular means repeating 3 times "number + dot" (such as 192.168.1.), and the last segment is not added with a dot. It is worth mentioning that?: represents a non-capturing group (Non-capturing Group), which is a special form of grouping in regular expressions, used to save memory when calculating, in addition, the non-capturing group refers to the grouping using parentheses ( ), but it does not store the matching content of the group, and the syntax is (?:...).
[0079] Subsequently, the Alphabat dictionary table set of the embodiment of the application is set to R={('0'-'9')}, wherein each tuple in the set corresponds to a character set that may appear in different sensitive fields, for example, ('0'-'9') contains character combinations that may appear in mobile phones, bank cards, ID cards and IP addresses.
[0080] In a specific embodiment, the embodiment of the application uses an FPE encryption process using FF1 standard to encrypt plaintext, and keeps the data length and character type unchanged, uses AES as a permutation function, the number of rounds is 10, and the key length is 16 Bytes. The pseudo-expression corresponding to the FPE encryption process is as follows:
[0081] C = FF1-Encrypt(K, T, X, radix)
[0082] Wherein, K is an encryption key (usually 128 or 256 bits), T is an adjustment value (Tweak), X is the input plaintext (number or character sequence), radix is the base (used to determine the size of the character set), and C is the output ciphertext (consistent with the format and length of X).
[0083] Further, since the UUID is unique, the embodiment of the application uses the UUID of each request as a watermark of the request. Wherein, the format of the UUID is a 128-bit identifier, usually represented as a 36-character string, divided into five segments by hyphens, thereby obtaining a 32-character in the form of 8-4-4-4-12. In addition, in order to ensure the expressiveness of the data, the generated characters of the UUID contain {0-3, a-z, A-Z}, such as: f10ac33b-tycc-r232-adrg-0e02b2c3d1dg.
[0084] Subsequently, the embodiment of the present application extracts the first four numerical type characters A{0-3} from the UUID, then divides the four characters into two parts, and combines the two parts with the plaintext respectively, to obtain the combination result as the partial value of the Tweak. Since the value of the UUID changes every time it is requested, the encrypted data changes every time.
[0085] Specifically, the dynamic identification information corresponding to the to-be-desensitized financial data is generated, and the first preset number of bits of data is extracted from the dynamic identification information to obtain the first type of characters, and then the second preset number of bits of data at the end of the to-be-desensitized financial data is intercepted to obtain the second type of characters, which can include: generating dynamic identification information corresponding to the to-be-desensitized financial data according to a preset international standard specification; the dynamic identification information is a mixed encoding string including numerical characters, lowercase letter characters and uppercase letter characters and has global uniqueness; locating the starting position of the dynamic identification information string, and performing character scanning operation on the dynamic identification information string from the starting position to obtain the first scanning result; the first scanning result is a character of the numerical character type; the first preset number of bits of numerical characters is continuously extracted from the first scanning result to obtain the first type of characters, if the second scanning result obtained when scanning to the end of the first scanning result corresponds to a number of bits corresponding to a value less than the number of bits corresponding to the first preset number of bits, then the second scanning result is supplemented with a missing character according to a preset filling rule to obtain the first type of characters; locating the end position of the dynamic identification information string, and scanning the second preset number of bits of to-be-desensitized financial data from the end position to obtain the second type of characters.
[0086] Step S13, combining and encoding the first type of characters and the second type of characters according to a preset order to obtain an initial character sequence, and performing base conversion on the initial character sequence according to a preset base conversion rule to obtain a target converted character sequence.
[0087] In this embodiment, the embodiment of the present application needs to construct the value of Tweak, wherein the value of Tweak determines the result of desensitization encryption, that is, in order to ensure that the result of desensitization encryption is different each time, the value of Tweak needs to be changed each time desensitization is performed. Therefore, the embodiment of the present application sets the value of Tweak as a value composed of two variable characters combined with the last two bits of plaintext of the sensitive field.
[0088] In a specific embodiment, the Tweak is composed of 4-bit characters consisting of 2 groups of 62-bit data, using a variable 4-bit character set T{0-3}, wherein the four characters respectively contain the last four characters D{0-3} of the field that needs to be desensitized and A{0-3} selected from the watermark, and then the application embodiment needs to combine D and A, and encode the combined result based on the 62-bit base, and the specific process is as shown in Figure 2
[0089] It is worth noting that the conversion process of the Tweak key is as follows: first, the four characters in the Tweak are regarded as a four-digit decimal number (range 0000-9999), and the obtained decimal number is converted into a two-bit 62-bit number (0-9+a-z+A-Z). Among them, 0-9 represents 0-9, a-z represents 10-35, and A-Z represents 36-61. In this way, the information represented by the original 4-bit character is compressed into a 2-bit character through the form of base conversion.
[0090] Specifically, the first type of character and the second type of character are combined and encoded according to a preset order to obtain an initial character sequence, and the initial character sequence is converted according to a preset base conversion rule to obtain a target converted character sequence, which can include: combining the first type of character and the second type of character according to a preset order to obtain a combined character sequence, and splicing each character in the combined character sequence according to the character arrangement order to obtain a splicing result; the splicing result is a decimal integer with high bits in front and low bits at the back; determine a preset base based on the preset base conversion rule, and perform a continuous division operation based on the decimal integer and the preset base to obtain a corresponding quotient and a remainder, and map the remainder to a character representation corresponding to the preset base to obtain a mapping result; determine the base conversion of the splicing result based on the mapping result and the quotient to obtain an initial converted character sequence, and verify whether the string length corresponding to the initial converted character sequence meets a preset compression bit condition, if the string length corresponding to the initial converted character sequence meets the preset compression bit condition, the initial converted character sequence is set as the target converted character sequence.
[0091] Step S14, based on the target converted character sequence, the data to be encrypted is encrypted to obtain encrypted data, and the encrypted data is used to desensitize the financial data to be desensitized to obtain desensitized financial data.
[0092] In this embodiment, the embodiments of the present application can use the obtained Tweak (T{0-3}) as a second key to encrypt the specified position content corresponding to the data characters that need to be de-identified in the FPE encryption process using the second key, thereby obtaining the encrypted numerical value C{0-(n-1)}, wherein n is the length of the de-identified character segment. At the same time, the embodiments of the present application can replace the last 4 characters of the data to be de-identified with Tweak (T{0-3}) characters, and display the integrated new data externally.
[0093] Specifically, based on the target converted character sequence, the data to be encrypted is encrypted to obtain encrypted data, and based on the encrypted data, the financial data to be de-identified is de-identified to obtain de-identified financial data, which can include: determining an encryption algorithm framework conforming to a security standard format based on a predetermined requirement, and determining a master key corresponding to the data to be encrypted from the encryption algorithm framework, and then determining an adjustment parameter corresponding to the target converted character sequence; using the encryption algorithm framework to split each character in the target converted character sequence into a character element, and convert each character element into a character value of a predetermined base, then call the encryption algorithm framework and perform confusion and diffusion operations on the character value based on the adjustment parameter to obtain a processed character sequence; convert the processed character sequence into a character element, and concatenate each character element to obtain a concatenation result, then use the concatenation result and the master key to encrypt the data to be encrypted to obtain encrypted data, and use the encrypted data to replace a number of characters corresponding to the tail of the data to be de-identified financial data to obtain de-identified financial data; the number of characters is the number of characters corresponding to the encrypted data.
[0094] In this embodiment, after obtaining the de-identified financial data, the embodiments of the present application need to obtain the corresponding encryption field according to the sensitive word type corresponding to the de-identified financial data, and obtain the Tweak field in the data, to decode the encryption field based on Tweak and using FPE encryption method, to obtain the data before encryption, and replace the data in the corresponding position. That is, the Tweak characters are divided into the first two and the last two for inverse operation respectively, to convert the 62 binary data to decimal, thereby obtaining two 4-digit decimal data B1[0-3] and B2[0-3], then, the decimal data B1 and B2 are split by characters, and the split characters B1[2-3] and B2[2-3] are replaced in the position of the Tweak in the data to restore the de-identified financial data.
[0095] Specifically, after the desensitization of the financial data to be desensitized based on the encrypted data is completed and the desensitized financial data is obtained, the method can further include: parsing the sensitive data segment of the financial data to be desensitized, and separating the compressed identification information located at the end of the sensitive data segment and the replaced intermediate field; performing reverse operation on the financial data to be desensitized based on the compressed identification information, the preset encryption key and the intermediate field by using the encryption algorithm framework to obtain an original character sequence; wherein the original character sequence is consistent with the format corresponding to the desensitized financial data; backfilling the original character sequence to the intermediate field data corresponding to the intermediate field in the financial data to be desensitized, and performing binary reverse conversion operation on the compressed identification information to obtain a reverse conversion result; performing reverse mapping on the reverse conversion result in the order of character position from low to high to obtain a reverse mapping result, and sequentially performing expansion summation on the reverse mapping result according to the decimal bit weight to obtain a decimal integer to be processed; splitting the integer to be processed into a first sub-digit sequence and a second sub-digit sequence according to the preset number of bits, and performing character conversion on the first sub-digit sequence and the second sub-digit sequence respectively to obtain a corresponding first character group and a second character group; replacing the compressed identification information at the end of the financial data to be desensitized with the second character group to obtain a replacement result, and searching for a dynamic identification information entry containing the same character sequence in the request log record library based on the character combination feature corresponding to the first character group, and then determining the restored data based on the replacement result and the dynamic identification information entry.
[0096] It is worth mentioning that the embodiments of the present application can obtain the request entry containing the UUID with numbers from the request log based on B1[0-1] and B2[0-1], to obtain the user information and time information of the request from the request entry, and track the data based on the user information and time information. Specifically, searching for a dynamic identification information entry containing the same character sequence in the request log record library based on the character combination feature corresponding to the first character group can include: establishing a request log record library including a plurality of log records; the log record includes request time, request party identification, dynamic identification information field and reference information corresponding to the financial data to be desensitized; extracting the dynamic identification information field in each log record from the request log record library, and establishing an inverted index based on the prefix digit sequence of the dynamic identification information field, and then setting the first character group as a search key value to obtain a corresponding log record set based on the inverted index and the search key value; judging whether the number of logs in the log record set is greater than one, if the number of logs in the log record set is greater than one, filtering the log record set based on a preset time range to obtain a dynamic identification information entry containing the same character sequence; the dynamic identification information entry includes context information corresponding to the interface request.
[0097] As can be seen from the above, before the financial sensitive data desensitization is performed, the embodiment of the application first needs to identify the sensitive data segment corresponding to the to-be-desensitized financial data in the interface request, obtain the sensitive data type and the target specific character position, and then determine the to-be-encrypted data in the to-be-desensitized financial data by using a preset regular expression and based on the target specific character position; then, dynamic identification information corresponding to the to-be-desensitized financial data is generated, and the first preset number of bits of data is extracted from the dynamic identification information to obtain the first type of character, and the second preset number of bits of data at the end of the to-be-desensitized financial data is intercepted to obtain the second type of character; further, the first type of character and the second type of character are combined and encoded in a preset order to obtain an initial character sequence, and the initial character sequence is converted in a preset radix to obtain a target converted character sequence; finally, the to-be-encrypted data is encrypted based on the target converted character sequence to obtain encrypted data, and the to-be-desensitized financial data is desensitized based on the encrypted data to obtain desensitized financial data. In this way, the efficiency of desensitizing the data is improved in the process of desensitizing the financial sensitive data, and the security of data transmission is improved.
[0098] Correspondingly, referring to Figure 3 The application further provides a financial sensitive data desensitization device, which comprises:
[0099] A sensitive data segment identification module 11 is configured to identify the sensitive data segment corresponding to the to-be-desensitized financial data in the interface request, obtain the sensitive data type and the target specific character position, and then determine the to-be-encrypted data in the to-be-desensitized financial data by using a preset regular expression and based on the target specific character position; the sensitive data segment comprises a telephone number field, an identification number field, a payment card number field, and a network address field;
[0100] An identification information generation module 12 is configured to generate dynamic identification information corresponding to the to-be-desensitized financial data, and extract the first preset number of bits of data from the dynamic identification information to obtain the first type of character, and then intercept the second preset number of bits of data at the end of the to-be-desensitized financial data to obtain the second type of character;
[0101] A radix conversion module 13 is configured to combine and encode the first type of character and the second type of character in a preset order to obtain an initial character sequence, and convert the initial character sequence in a preset radix to obtain a target converted character sequence;
[0102] A data desensitization module 14 is configured to encrypt the to-be-encrypted data based on the target converted character sequence to obtain encrypted data, and desensitize the to-be-desensitized financial data based on the encrypted data to obtain desensitized financial data.
[0103] As can be seen from the above, before the financial sensitive data desensitization is performed, the embodiment of the application first needs to identify the sensitive data segment corresponding to the to-be-desensitized financial data in the interface request, obtain the sensitive data type and the target specific character position, and then determine the to-be-encrypted data in the to-be-desensitized financial data by using a preset regular expression and based on the target specific character position; then, dynamic identification information corresponding to the to-be-desensitized financial data is generated, and the first preset number of bits of data is extracted from the dynamic identification information to obtain the first type of character, and the second preset number of bits of data at the end of the to-be-desensitized financial data is intercepted to obtain the second type of character; further, the first type of character and the second type of character are combined and encoded in a preset order to obtain an initial character sequence, and the initial character sequence is converted in a preset radix to obtain a target converted character sequence; finally, the to-be-encrypted data is encrypted based on the target converted character sequence to obtain encrypted data, and the to-be-desensitized financial data is desensitized based on the encrypted data to obtain desensitized financial data. In this way, the efficiency of desensitizing the data is improved in the process of desensitizing the financial sensitive data, and the security of data transmission is improved.
[0104] In some specific embodiments, the sensitive data segment identification module 11 can specifically include:
[0105] The matching rule determination unit is configured to determine a regular expression matching rule corresponding to each sensitive data type in a preset sensitive data type set; wherein the phone number matching rule is a prefix of a legal number segment allocated by all operators and a fixed number of digit sequences; the identity number matching rule is a date coding rule and a check code verification logic covering different years of issued numbers; the payment card number matching rule is a digit sequence starting with a specific identification code; and the network address matching rule is a four-segment dotted decimal format conforming to the Internet Protocol address.
[0106] The matching rule scanning unit is configured to use a regular expression matching engine to scan the to-be-desensitized financial data based on the phone number matching rule, the identity number matching rule, the payment card number matching rule, and the network address matching rule in sequence to obtain the corresponding sensitive data type and the matching rule.
[0107] The to-be-encrypted data determination unit is configured to determine the target specific character position based on the matching rule, and then determine the to-be-encrypted data in the to-be-desensitized financial data by using a preset regular expression and based on the target specific character position.
[0108] In some specific embodiments, the identification information generation module 12 can specifically include:
[0109] The identification information generation subunit is configured to generate dynamic identification information corresponding to the to-be-desensitized financial data according to a preset international standard specification; the dynamic identification information is a hybrid encoding string including numerical characters, lowercase letter characters, and uppercase letter characters and has global uniqueness.
[0110] The character scanning unit is configured to locate a starting position of the dynamic identification information string, and perform character scanning operations on the dynamic identification information string in sequence from the starting position to obtain a first scanning result; the first scanning result is a numerical character category character.
[0111] The character supplement unit is configured to extract a first preset number of numerical characters from the first scanning result in sequence to obtain a first type of character, and if a second scanning result obtained when scanning to the end of the first scanning result corresponds to a numerical value smaller than a numerical value corresponding to the first preset number of positions, perform a missing character supplement operation on the second scanning result by using a preset filling rule to obtain a first type of character.
[0112] The financial data scanning unit is configured to locate an end position of the dynamic identification information string, and scan the to-be-desensitized financial data in sequence from the end position for a second preset number of positions to obtain a second type of character.
[0113] In some specific embodiments, the radix conversion module 13 can specifically include:
[0114] The splicing result generation unit is configured to combine the first type of character and the second type of character in a preset order to obtain a combined character sequence, and splice each character in the combined character sequence in a character arrangement order to obtain a splicing result; the splicing result is a decimal integer with high bits in front and low bits at the back.
[0115] The mapping result determination unit is configured to determine a preset radix based on the preset radix conversion rule, and perform a continuous division operation based on the decimal integer and the preset radix to obtain a corresponding quotient and a remainder, and map the remainder to a character representation corresponding to the preset radix to obtain a mapping result.
[0116] The splicing result radix conversion unit is configured to determine radix conversion of the splicing result based on the mapping result and the quotient to obtain an initial converted character sequence, and verify whether a string length corresponding to the initial converted character sequence satisfies a preset compression bit number condition; if the string length corresponding to the initial converted character sequence satisfies the preset compression bit number condition, the initial converted character sequence is set as a target converted character sequence.
[0117] In some embodiments, the data desensitization module 14 can specifically include:
[0118] A master key determination unit is configured to determine an encryption algorithm framework conforming to a security standard format based on preset requirements, determine a master key corresponding to the data to be encrypted from the encryption algorithm framework, and then determine an adjustment parameter corresponding to the target converted character sequence;
[0119] A character splitting unit is configured to split each character in the target converted character sequence into a character element using the encryption algorithm framework, convert each character element into a character value of a preset base, then call the encryption algorithm framework and perform confusion and diffusion operations on the character value based on the adjustment parameter to obtain a processed character sequence;
[0120] A data replacement unit is configured to convert the processed character sequence into a character element, splice each character element to obtain a splicing result, encrypt the data to be encrypted using the splicing result and the master key to obtain encrypted data, and replace a number of data corresponding to a character at the end of the financial data to be desensitized with the encrypted data to obtain desensitized financial data; the number of characters is the number of characters corresponding to the encrypted data.
[0121] In some embodiments, the financial sensitive data desensitization device can further include:
[0122] A sensitive data segment analysis unit is configured to analyze a sensitive data segment of the financial data to be desensitized, and separate compressed identification information located at the end of the sensitive data segment and an intermediate field that is replaced;
[0123] A data reverse operation unit is configured to perform a reverse operation on the financial data to be desensitized using the encryption algorithm framework and based on the compressed identification information, a preset encryption key, and the intermediate field to obtain an original character sequence; wherein the original character sequence is consistent with the format of the desensitized financial data;
[0124] A reverse conversion result determination unit is configured to backfill the original character sequence to an intermediate field data corresponding to the intermediate field in the financial data to be desensitized, and perform a base reverse conversion operation on the compressed identification information to obtain a reverse conversion result;
[0125] A reverse mapping result determination unit is configured to perform reverse mapping on the reverse conversion result in order from low to high character position to obtain a reverse mapping result, and sequentially perform expansion summation on the reverse mapping result according to the bit weight of the decimal system to obtain a decimal integer to be processed;
[0126] The digital sequence character conversion unit is configured to split the integer to be processed into a first sub-digital sequence and a second sub-digital sequence according to a preset bit number, and perform character conversion on the first sub-digital sequence and the second sub-digital sequence respectively to obtain a first character group and a second character group.
[0127] The replacement result acquisition unit is configured to replace compressed identification information at the end of the financial data to be desensitized by using the second character group to obtain a replacement result, search for a dynamic identification information entry containing the same character sequence in a request log record library based on a character combination feature corresponding to the first character group, and then determine the restored data based on the replacement result and the dynamic identification information entry.
[0128] In some specific embodiments, the data desensitization module 14 can specifically include:
[0129] The reference information determination unit is configured to establish a request log record library including a plurality of log records; the log records include a request time, a request party identification, dynamic identification information fields, and reference information corresponding to the financial data to be desensitized.
[0130] The log record set acquisition unit is configured to extract the dynamic identification information fields in each log record from the request log record library, establish an inverted index based on a prefix digital sequence of the dynamic identification information fields, and then set the first character group as a search key value to obtain a corresponding log record set based on the inverted index and the search key value.
[0131] The identification information entry determination unit is configured to determine whether the number of logs in the log record set is greater than one, and if the number of logs in the log record set is greater than one, perform a filtering operation on the log record set based on a preset time range to obtain a dynamic identification information entry containing the same character sequence; the dynamic identification information entry includes context information corresponding to the interface request.
[0132] Further, the present application also discloses an electronic device, Figure 4 is an electronic device 20 structure diagram according to an exemplary embodiment, the content in the figure cannot be considered as any limitation on the use range of the present application. The electronic device 20 can specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25 and a communication bus 26. Wherein, the memory 22 is used for storing a computer program, the computer program is loaded and executed by the processor 21, to realize the related steps in the financial sensitive data desensitization method disclosed in any of the preceding embodiments. In addition, the electronic device 20 in the embodiment can be an electronic computer.
[0133] In this embodiment, the power supply 23 is configured to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 is configured to create a data transmission channel between the electronic device 20 and external devices, and the communication protocol followed by the communication interface 24 can be any communication protocol applicable to the technical solution of the present application, which will not be specifically limited herein; the input and output interface 25 is configured to obtain external input data or output data to the outside, and the specific interface type can be selected according to the specific application needs, which will not be specifically limited herein.
[0134] In addition, the memory 22 as a carrier for storing resources can be a read-only memory, a random access memory, a magnetic disk or an optical disk, etc., and the resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage mode can be temporary storage or permanent storage.
[0135] The operating system 221 is configured to manage and control each hardware device on the electronic device 20 and the computer program 222, and can be Windows Server, Netware, Unix, Linux, etc. In addition to the computer program capable of completing the financial sensitive data desensitization method executed by the electronic device 20 disclosed in any of the preceding embodiments, the computer program 222 can further include a computer program capable of completing other specific work.
[0136] Further, the present application also discloses a computer readable storage medium for storing a computer program; wherein the computer program is executed by a processor to implement the financial sensitive data desensitization method disclosed above. For the specific steps of the method, please refer to the corresponding contents disclosed in the preceding embodiments, which will not be described here.
[0137] Each embodiment in the specification is described in a progressive manner, and each embodiment focuses on the difference from other embodiments. For the same or similar parts between the embodiments, please refer to each other. For the device disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple, and please refer to the method part for the relevant part.
[0138] The skilled person can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized by electronic hardware, computer software or a combination of both. In order to clearly show the interchangeability of hardware and software, the components and steps of each example have been described in the above description. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0139] The steps of a method or algorithm described in connection with the embodiments disclosed herein can be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. A software module can reside in RAM, flash memory, ROM, electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), registers, hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. The processor can be configured to execute the software module.
[0140] Finally, it should be noted that the terms "first", "second", and the like, herein do not denote any order, quantity, combination, or importance, but rather are used to distinguish one element from another, and are not necessarily intended to denote the temporal or chronological sequence of the execution of the respective steps. Moreover, the terms "comprises", "comprising", or any other variations thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can also include other elements not expressly listed or inherent to such process, method, article, or apparatus. An element proceeded by "comprises... a" does not, without further constraints, exclude the presence of additional identical elements in the process, method, article, or apparatus that comprises the element.
[0141] The above detailed description of the technical solutions provided by the present application has been described in detail, and the principles and implementation modes of the present application have been described by applying specific examples; the above description of the embodiments is only for the purpose of helping to understand the method of the present application and its core idea; at the same time, for those skilled in the art, according to the idea of the present application, the specific implementation mode and application range will be changed; in view of the above, the content of the specification should not be understood as a limitation of the present application.
Claims
1. A method for desensitizing financial sensitive data, characterized in that, The method comprises the following steps: identifying a sensitive data segment corresponding to the to-be-desensitized financial data in the interface request, obtaining a sensitive data type and a target specific character position, and then determining to-be-encrypted data in the to-be-desensitized financial data by using a preset regular expression and based on the target specific character position; the sensitive data segment comprises a telephone number field, an identification number field, a payment card number field, and a network address field; generating dynamic identification information corresponding to the to-be-desensitized financial data, extracting a first preset number of bits of data from the dynamic identification information to obtain a first type of character, and then extracting a second preset number of bits of data from the end of the to-be-desensitized financial data to obtain a second type of character; combining and encoding the first type of character and the second type of character in a preset order to obtain an initial character sequence, and performing radix conversion on the initial character sequence according to a preset radix conversion rule to obtain a target converted character sequence; encrypting the to-be-encrypted data based on the target converted character sequence to obtain encrypted data, and desensitizing the to-be-desensitized financial data based on the encrypted data to obtain desensitized financial data.
2. The financial sensitive data desensitization method of claim 1, wherein, The method comprises the following steps: determining a regular expression matching rule corresponding to each sensitive data type in a preset sensitive data type set; wherein the telephone number matching rule is a prefix of a legal number segment allocated by all operators and a fixed number of digit sequences; the identification number matching rule is a date coding rule and a check code verification logic covering identification numbers issued in different years; the payment card number matching rule is a digit sequence starting with a specific identification code; and the network address matching rule is a four-segment decimal format conforming to the Internet Protocol address; scanning the to-be-desensitized financial data based on the telephone number matching rule, the identification number matching rule, the payment card number matching rule, and the network address matching rule in sequence by using a regular expression matching engine to obtain a corresponding sensitive data type and a matching rule; determining a corresponding target specific character position based on the matching rule, and then determining to-be-encrypted data in the to-be-desensitized financial data by using a preset regular expression and based on the target specific character position.
3. The method of claim 1, wherein, The method comprises the following steps: generating dynamic identification information corresponding to the to-be-desensitized financial data according to a preset international standard specification; the dynamic identification information is a mixed coding string comprising digit characters, lowercase letter characters, and uppercase letter characters and having global uniqueness; extracting a first preset number of bits of data from the dynamic identification information to obtain a first type of character, and then extracting a second preset number of bits of data from the end of the to-be-desensitized financial data to obtain a second type of character. Position the starting position of the dynamic identification information string, and perform character scanning operation on the dynamic identification information string from the starting position to obtain a first scanning result; the first scanning result is a character of a number character category; Extract a first preset number of digits of the number character from the first scanning result to obtain a first character, and if a second scanning result obtained when scanning to the end of the first scanning result corresponds to a number value smaller than a number value corresponding to the first preset number of digits, perform a missing character supplement operation on the second scanning result using a preset filling rule to obtain the first character; Position the end position of the dynamic identification information string, and scan the second preset number of the to-be-de-sensitized financial data from the end position to obtain a second character.
4. The method of claim 1, wherein, The first character and the second character are combined and encoded in a preset order to obtain an initial character sequence, and the initial character sequence is converted in a preset base to obtain a target converted character sequence, including: The first character and the second character are combined in a preset order to obtain a combined character sequence, and each character in the combined character sequence is spliced according to a character arrangement order to obtain a spliced result; the spliced result is a decimal integer with high bits in front and low bits at the back; A preset base is determined based on the preset base conversion rule, and a corresponding quotient and remainder are obtained by performing a continuous division operation based on the decimal integer and the preset base; and the remainder is mapped to a character representation corresponding to the preset base to obtain a mapping result; Based on the mapping result and the quotient, the spliced result is converted in a base to obtain an initial converted character sequence, and it is verified whether a string length corresponding to the initial converted character sequence satisfies a preset compression bit condition; if the string length corresponding to the initial converted character sequence satisfies the preset compression bit condition, the initial converted character sequence is set as the target converted character sequence.
5. The method of claim 1 to 4, wherein, The target converted character sequence is used to encrypt the to-be-encrypted data to obtain encrypted data, and the encrypted data is used to de-sensitize the to-be-de-sensitized financial data to obtain de-sensitized financial data, including: An encryption algorithm framework conforming to a security standard format is determined based on a preset requirement, a master key corresponding to the to-be-encrypted data is determined from the encryption algorithm framework, and an adjustment parameter corresponding to the target converted character sequence is determined; The encryption algorithm framework is used to split each character in the target converted character sequence into a character element, and each character element is converted into a character value of a preset base; then the encryption algorithm framework is called and the character value is subjected to confusion and diffusion operations based on the adjustment parameter to obtain a processed character sequence; The processed character sequence is converted into character elements, and the character elements are spliced to obtain a splicing result, and then the splicing result and the main key are used to encrypt the to-be-encrypted data to obtain encrypted data, and the encrypted data is used to replace a number of characters corresponding to the tail part in the to-be-desensitized financial data to obtain desensitized financial data, wherein the number of characters is the number of characters corresponding to the encrypted data.
6. The method of claim 5, wherein, After the desensitization processing of the to-be-desensitized financial data based on the encrypted data is performed, the desensitized financial data is obtained, and the method further comprises: Analyzing a sensitive data segment of the to-be-desensitized financial data, and separating compressed identification information located at the end position in the sensitive data segment and an intermediate field that is replaced; Using the encryption algorithm framework and based on the compressed identification information, a preset encryption key, and the intermediate field, performing an inverse operation on the to-be-desensitized financial data to obtain an original character sequence; wherein the original character sequence is consistent with the format corresponding to the desensitized financial data; The original character sequence is backfilled to the intermediate field data corresponding to the intermediate field in the to-be-desensitized financial data, and a binary inverse conversion operation is performed on the compressed identification information to obtain an inverse conversion result; The inverse conversion result is reversely mapped in the order of character positions from low to high to obtain a reverse mapping result, and the reverse mapping result is sequentially unfolded and summed according to the bit weight of the decimal to obtain a to-be-processed integer in decimal; The to-be-processed integer is split into a first sub-digit sequence and a second sub-digit sequence according to a preset number of bits, and the first sub-digit sequence and the second sub-digit sequence are respectively subjected to character conversion to obtain a first character group and a second character group corresponding to the first character group; The second character group is used to replace the compressed identification information at the end of the to-be-desensitized financial data to obtain a replacement result, and based on the character combination feature corresponding to the first character group, a dynamic identification information entry containing the same character sequence is retrieved in a request log record library, and then based on the replacement result and the dynamic identification information entry, the restoration data is determined.
7. The method of claim 6, wherein, The dynamic identification information entry containing the same character sequence is retrieved in the request log record library based on the character combination feature corresponding to the first character group, comprising: A request log record library including a plurality of log records is established; the log records include request time, request party identification, dynamic identification information field, and reference information corresponding to the to-be-desensitized financial data; The dynamic identification information field in each log record is extracted from the request log record library, and an inverted index is established based on the prefix digit sequence of the dynamic identification information field, and then the first character group is set as a retrieval key value to obtain a corresponding log record set based on the inverted index and the retrieval key value; determining whether the number of logs in the log record set is greater than one, and if the number of logs in the log record set is greater than one, performing a filtering operation on the log record set based on a preset time range to obtain a dynamic identification information entry containing the same character sequence; the dynamic identification information entry includes context information corresponding to the interface request.
8. A financial sensitive data desensitization apparatus characterized by comprising: Comprise: a sensitive data segment identification module, configured to identify a sensitive data segment corresponding to to-be-desensitized financial data in an interface request, obtain a sensitive data type and a target specific character position, and then determine to-be-encrypted data in the to-be-desensitized financial data by using a preset regular expression and based on the target specific character position; the sensitive data segment includes a telephone number field, an identification number field, a payment card number field, and a network address field; an identification information generation module, configured to generate dynamic identification information corresponding to the to-be-desensitized financial data, extract a first preset number of bits of data from the dynamic identification information to obtain a first type of character, and then extract a second preset number of bits of data at the end of the to-be-desensitized financial data to obtain a second type of character; a base conversion module, configured to combine and encode the first type of character and the second type of character in a preset order to obtain an initial character sequence, and perform base conversion on the initial character sequence according to a preset base conversion rule to obtain a target converted character sequence; a data desensitization module, configured to encrypt the to-be-encrypted data based on the target converted character sequence to obtain encrypted data, and perform desensitization processing on the to-be-desensitized financial data based on the encrypted data to obtain desensitized financial data.
9. An electronic device, comprising: Comprise: a memory, configured to save a computer program; a processor, configured to execute the computer program to implement the financial sensitive data desensitization method in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, a memory, configured to save a computer program; a processor, configured to execute the computer program to implement the financial sensitive data desensitization method in any one of claims 1 to 7.
Citation Information
Cited By
Work order demand identification method and platform fused with big data analysis
CN121214453A
Data grading classification and dynamic desensitization method for adaptive sensitivity identification
CN122133195A
A data classification and dynamic desensitization method based on adaptive sensitivity identification
CN122133195B
High-throughput real-time data desensitization method
CN122286838A