Data Desensitization Method, Apparatus, Device, and Storage Medium

The use of a bytecode manipulation framework (ASM) for recursive data model traversal and caching proxy objects addresses inefficiencies in existing de-sensitization methods, improving execution speed and accuracy.

CN112000986BActive Publication Date: 2025-07-15CHINA PING AN PROPERTY INSURANCE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202010879192.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-08-27
Publication Date
2025-07-15
Estimated Expiration
2040-08-27

AI Technical Summary

Technical Problem

Existing data de-sensitization methods using regular expressions and Java reflection are inefficient and complex, leading to low execution speeds and difficulty in code maintenance.

Method used

A data de-sensitization method utilizing a bytecode manipulation framework (ASM) to recursively parse and cache proxy objects, enabling efficient and accurate de-sensitization by traversing all fields in a data model and applying pre-defined rules.

Benefits of technology

Enhances the efficiency and accuracy of data de-sensitization operations by avoiding field omissions and reducing code redundancy through bytecode manipulation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112000986B_ABST
    Figure CN112000986B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of big data technology, and discloses a data desensitization method, device, equipment and storage medium, which are used to improve the efficiency and accuracy of data desensitization operations. The data desensitization method includes: when receiving a compilation file request, obtaining a data model file according to the compilation file request, compiling the data model file into an initial bytecode file, and running the initial bytecode file; using a bytecode manipulation framework to recursively parse the initial bytecode file running in the program to obtain a proxy object dataset, and caching the proxy object dataset; when receiving a desensitization processing request, determining the data to be desensitized according to the desensitization processing request, and querying the target proxy object from the proxy object dataset; obtaining a preset desensitization rule, and calling the target proxy object to perform a desensitization operation on the data to be desensitized according to the preset desensitization rule. In addition, the present invention also relates to blockchain technology, and the proxy object dataset can be stored in a blockchain node.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of batch updates of big data technology, and particularly to a data desensitization method, device, equipment and storage medium. Background Art

[0002] The protection of user information privacy is an important security risk point of the system. During the user inquiry business process, the transaction object data involves a large amount of personal or group privacy-sensitive data. For example, name, ID number, address, home phone number, mobile phone number, account, email. During the program operation, it is necessary to desensitize the printed log data. If each field is processed by conventional code, a large amount of code with repetitive actions is required, which is not conducive to code reading and maintenance, and it is also easy to miss key fields.

[0003] In the prior art, generally, by serializing the domain model, the fields to be desensitized are matched by regular expressions of strings, and then desensitization processing operations are performed according to the attribute values corresponding to the fields. It is also possible to traverse all fields of the domain model through the traditional Java reflection method, and use a recursive algorithm to find all fields to be desensitized for desensitization processing, which can avoid the problem of code redundancy. However, multiple serialization and deserialization operations, multiple regular matching operations, and the traditional Java reflection method all result in low execution efficiency of the desensitization operation and complex logic. Summary of the Invention

[0004] The main purpose of the present invention is to solve the problem that the existing data desensitization using regular expression matching or traditional Java reflection method has low execution efficiency of desensitization operations.

[0005] To achieve the above object, the first aspect of the present invention provides a data desensitization method, including: when receiving a compilation file request, obtaining a data model file according to the compilation file request, compiling the data model file into an initial bytecode file, and running the initial bytecode file; using a bytecode manipulation framework to recursively parse the initial bytecode file running in the program to obtain a proxy object data set, and caching the proxy object data set; when receiving a desensitization processing request, determining the data to be desensitized according to the desensitization processing request, and querying a target proxy object from the proxy object data set, where the target proxy object is used to call a preset service processing function corresponding to the desensitization processing request; obtaining a preset desensitization rule, and calling the target proxy object to perform a desensitization operation on the data to be desensitized according to the preset desensitization rule.

[0006] Optionally, in the first implementation manner of the first aspect of the present invention, the steps of obtaining a data model file according to the compilation file request, compiling the data model file into an initial bytecode file, and running the initial bytecode file when receiving the compilation file request include: when receiving a compilation request, parsing the parameters of the compilation file request to obtain a parsing result; reading a file identifier from the parsing result, and querying preset configuration information according to the file identifier to obtain a data model file; setting the data model file as a source code file, and calling a preset compiler to compile the source code file into an initial bytecode file; loading the initial bytecode file through a preset virtual machine, and converting the initial bytecode file into machine code and executing it.

[0007] Optionally, in the second implementation manner of the first aspect of the present invention, the steps of recursively parsing the initial bytecode file running in the program by using a bytecode manipulation framework to obtain a proxy object data set and caching the proxy object data set include: loading the initial bytecode file by using the bytecode manipulation framework; recursively parsing the initial bytecode file running in the program to obtain a plurality of proxy class names and a plurality of function names; respectively setting corresponding index subscript values according to the plurality of function names; generating a proxy object data set according to the plurality of proxy class names and the corresponding index subscript values, and storing the proxy object data set in a relational database and a memory database.

[0008] Optionally, in the third implementation manner of the first aspect of the present invention, the steps of determining data to be desensitized according to the desensitization processing request and querying a target proxy object from the proxy object data set when receiving the desensitization processing request, where the target proxy object is used to call a preset service processing function corresponding to the desensitization processing request include: when receiving a desensitization processing request, parsing the parameters of the desensitization processing request to obtain a proxy class name and an identifier of the object to be desensitized; querying the relational database by using the identifier of the object to be desensitized to obtain the data to be desensitized; querying the proxy object data set in the memory database according to the proxy class name to obtain a query result; determining whether the query result is a null value; if the query result is not a null value, reading object data corresponding to the proxy class name from the query result to obtain a target proxy object, where the target proxy object is used to call a preset service processing function corresponding to the desensitization processing request; if the query result is a null value, reading the proxy object data set from the relational database, reading object data corresponding to the proxy class name from the proxy object data set to obtain a target proxy object, and rewriting the proxy object data set into the memory database.

[0009] Optionally, in the fourth implementation manner of the first aspect of the present invention, the obtaining the preset desensitization rule and invoking the target proxy object to desensitize the data to be desensitized according to the preset desensitization rule includes: obtaining the preset desensitization rule and obtaining the corresponding index subscript value from the target proxy object; determining the corresponding function to be called according to the corresponding index subscript value; and desensitizing the fields to be desensitized in the data to be desensitized according to the preset desensitization rule through the corresponding function to be called.

[0010] Optionally, in the fifth implementation manner of the first aspect of the present invention, after obtaining the preset desensitization rule, invoking the target proxy object, and desensitizing the data to be desensitized according to the preset desensitization rule, the data desensitization method further includes: updating the initial bytecode file through the bytecode manipulation framework to obtain an updated bytecode file; obtaining the updated proxy object dataset from the updated bytecode file, and storing the updated proxy object dataset in a relational database and a memory database.

[0011] Optionally, in the sixth implementation manner of the first aspect of the present invention, after obtaining the preset desensitization rule, invoking the target proxy object, and desensitizing the data to be desensitized according to the preset desensitization rule, the data desensitization method further includes: invoking a preset timing task to detect whether the cached proxy object dataset is null; when the cached proxy object dataset is null, querying the proxy object dataset to be cached from the relational database, and adding the proxy object dataset to be cached to the memory database.

[0012] The second aspect of the present invention provides a data desensitization device, including: a compilation module, configured to obtain a data model file according to the compilation file request when receiving the compilation file request, compile the data model file into an initial bytecode file, and run the initial bytecode file; a parsing module, configured to recursively parse the initial bytecode file running in the program by using a bytecode manipulation framework to obtain a proxy object dataset, and cache the proxy object dataset; a determination module, configured to determine the data to be desensitized according to the desensitization processing request when receiving the desensitization processing request, and query a target proxy object from the proxy object dataset, where the target proxy object is used to call a preset service processing function corresponding to the desensitization processing request; and a desensitization module, configured to obtain a preset desensitization rule, and invoke the target proxy object to desensitize the data to be desensitized according to the preset desensitization rule.

[0013] Optionally, in the first implementation manner of the second aspect of the present invention, the compilation module is specifically configured to: when receiving a compilation request, perform parameter parsing on the compilation file request to obtain a parsing result; read a file identifier from the parsing result, and query preset configuration information according to the file identifier to obtain a data model file; set the data model file as a source code file, and call a preset compiler to compile the source code file into an initial bytecode file; load the initial bytecode file through a preset virtual machine, and convert the initial bytecode file into machine code and execute it.

[0014] Optionally, in the second implementation manner of the second aspect of the present invention, the parsing module is specifically configured to: load the initial bytecode file by using a bytecode manipulation framework; perform recursive parsing on the initial bytecode file running in the program to obtain a plurality of proxy class names and a plurality of function names; set corresponding index subscript values respectively according to the plurality of function names; generate a proxy object data set according to the plurality of proxy class names and the corresponding index subscript values, and store the proxy object data set in a relational database and a memory database.

[0015] Optionally, in the third implementation manner of the second aspect of the present invention, the determination module is specifically configured to: when receiving a desensitization processing request, perform parameter parsing on the desensitization processing request to obtain a proxy class name and an object identifier to be desensitized; query the relational database by using the object identifier to be desensitized to obtain data to be desensitized; query the proxy object data set in the memory database according to the proxy class name to obtain a query result; determine whether the query result is a null value; if the query result is not a null value, read the object data corresponding to the proxy class name from the query result to obtain a target proxy object, and the target proxy object is used to call a preset service processing function corresponding to the desensitization processing request; if the query result is a null value, read the proxy object data set from the relational database, read the object data corresponding to the proxy class name from the proxy object data set to obtain a target proxy object, and rewrite the proxy object data set into the memory database.

[0016] Optionally, in the fourth implementation manner of the second aspect of the present invention, the desensitization module is specifically configured to: obtain a preset desensitization rule, and obtain the corresponding index subscript value from the target proxy object; determine a corresponding function to be called according to the corresponding index subscript value; perform a desensitization operation on the fields to be desensitized in the data to be desensitized according to the preset desensitization rule through the corresponding function to be called.

[0017] Optionally, in the fifth implementation manner of the second aspect of the present invention, the data desensitization device further includes: an update module, configured to update the initial bytecode file through the bytecode manipulation framework to obtain an updated bytecode file; a storage module, configured to obtain an updated proxy object dataset from the updated bytecode file and store the updated proxy object dataset in a relational database and a memory database.

[0018] Optionally, in the sixth implementation manner of the second aspect of the present invention, the data desensitization device further includes: a detection module, configured to call a preset timing task to detect whether the cached proxy object dataset is a null value; an addition module, when the cached proxy object dataset is a null value, configured to query a proxy object dataset to be cached from a relational database and add the proxy object dataset to be cached to the memory database.

[0019] The third aspect of the present invention provides a data desensitization device, including: a memory and at least one processor, wherein instructions are stored in the memory; the at least one processor calls the instructions in the memory to enable the data desensitization device to execute the above data desensitization method.

[0020] The fourth aspect of the present invention provides a computer-readable storage medium, in which instructions are stored, and when the instructions are run on a computer, the computer is enabled to execute the above data desensitization method.

[0021] In the technical solution provided by the present invention, when a compilation file request is received, a data model file is obtained according to the compilation file request, the data model file is compiled into an initial bytecode file, and the initial bytecode file is run; a bytecode manipulation framework is used to recursively parse the initial bytecode file running in the program to obtain a proxy object dataset, and the proxy object dataset is cached; when a desensitization processing request is received, the data to be desensitized is determined according to the desensitization processing request, and a target proxy object is queried from the proxy object dataset, and the target proxy object is used to call a preset service processing function corresponding to the desensitization processing request; a preset desensitization rule is obtained, and the target proxy object is called to desensitize the data to be desensitized according to the preset desensitization rule. In the embodiment of the present invention, the bytecode manipulation framework (ASM) proxy method is adopted, and a recursive algorithm is used to traverse all fields of the domain model to avoid omission of fields to be desensitized. By caching proxy objects of each domain model and finding fields to be desensitized for desensitization processing, the efficiency and accuracy of data desensitization operations are improved. Description of the Drawings

[0022] Figure 1 It is a schematic diagram of an embodiment of the data desensitization method in the embodiment of the present invention;

[0023] Figure 2 Another schematic diagram of the data desensitization method in the embodiment of the present invention;

[0024] Figure 3 A schematic diagram of an embodiment of the data desensitization device in the embodiment of the present invention;

[0025] Figure 4 Another schematic diagram of the data desensitization device in the embodiment of the present invention;

[0026] Figure 5 A schematic diagram of an embodiment of the data desensitization device in the embodiment of the present invention. Specific implementation manners

[0027] The embodiments of the present invention provide a data desensitization method, device, equipment and storage medium, which are used to adopt the method of proxy of the bytecode manipulation framework (ASM), traverse all fields of the domain model by using a recursive algorithm to avoid omission of fields to be desensitized, and desensitize the fields to be desensitized by caching proxy objects of each domain model, so as to improve the efficiency and accuracy of data desensitization operations.

[0028] The terms "first", "second", "third", "fourth", etc. (if any) in the description and claims of the present invention and the above drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments described here can be implemented in an order different from that shown or described here. In addition, the terms "comprising" or "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or equipment comprising a series of steps or units does not have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or equipment.

[0029] For ease of understanding, the specific processes of the embodiments of the present invention are described below. Please refer to Figure 1 , an embodiment of the data desensitization method in the embodiment of the present invention includes:

[0030] 101. When receiving a compilation file request, obtain a data model file according to the compilation file request, compile the data model file into an initial bytecode file, and run the initial bytecode file.

[0031] Among them, the data model file is a template file of the.java type, and the preset compiler is the javac compilation tool. The data sources processed by the program mainly include the information input by the user through the program, including sensitive information, such as name, ID number, address, home phone number, mobile phone number, account, and email. During the program writing, the structure of the data will be abstracted to create a batch of data models. These models will have the functions of obtaining and setting data. The obtained proxy object is to dynamically create an object with these similar functions through bytecode. Moreover, the proxy object has more extended functions. For example, the server encodes multiple functions through the proxy object and can execute multiple functions through the encoding. The encoding can be 101 or S001, which is used to indicate the start position of the code for different function runs. Specifically, it is not limited here.

[0032] It can be understood that the execution subject of the present invention can be a data desensitization device, or a terminal or a server. Specifically, it is not limited here. In the embodiments of the present invention, the server is taken as an example of the execution subject for illustration.

[0033] 102. Recursively parse the initial bytecode file running in the program using a bytecode manipulation framework to obtain a proxy object dataset and cache the proxy object dataset.

[0034] Among them, the proxy object dataset includes the class name, function name, and the index value corresponding to the function. Further, the server recursively parses the initial bytecode file running in the program using a bytecode manipulation framework to obtain the class name, multiple function names, and the index value corresponding to the function, and sets the proxy object dataset according to the class name, function name, and the index value corresponding to the function, and stores the proxy object dataset into a relational database and an in-memory database respectively. Among them, the relational database can be the relational database mysql or the relational database oracle. Specifically, it is not limited here. The in-memory database can include the remote service dictionary redis and the mapping map, or other types of databases. Specifically, it is not limited here. In addition, the server can also store the proxy object dataset in the data warehouse tool hive.

[0035] It should be noted that the bytecode manipulation framework ASM provides some general bytecode conversion and analysis algorithms. ASM has high execution efficiency. By using ASM to dynamically generate bytecode files, the server can solve the problem of low execution efficiency when traditional java reflection is used to obtain model attributes.

[0036] 103. When receiving a desensitization processing request, determine the data to be desensitized according to the desensitization processing request, and query the target proxy object from the proxy object dataset. The target proxy object is used to call the preset business processing function corresponding to the desensitization processing request.

[0037] Among them, the desensitization processing request includes an object identifier to be desensitized and a proxy object identifier. The object identifier to be desensitized is used to indicate the operation log or data table, and specifically, it is not limited here. For example, the proxy object identifier can be the name of the proxy object or a unique code, and generally, it is named with characters such as numbers, letters, or underscores, and specifically, it is not limited here. The name of the proxy object can be the name of the class to be called. For example, the name of the class to be called can be class_A.

[0038] Specifically, the server receives the desensitization processing request; the server obtains the object identifier to be desensitized and the proxy object identifier from the desensitization processing request; the server determines the data to be desensitized according to the object identifier to be desensitized. The object identifier to be desensitized is the operation log file path information. For example, the object identifier to be desensitized is http: / / localhost / file / log.txt. The server queries the target proxy object from the cached proxy object dataset (the proxy object dataset in the in-memory database) according to the proxy object identifier. The target proxy object is used to call the preset business processing function corresponding to the desensitization processing request. Among them, the corresponding preset business processing function is used to perform desensitization processing operations on the data to be desensitized according to the preset desensitization fields.

[0039] 104. Obtain the preset desensitization rules, and call the target proxy object to perform desensitization operations on the data to be desensitized according to the preset desensitization rules.

[0040] Among them, the preset desensitization rules include replacing the address field or the remarks field in the data to be desensitized with "Ping An of China", replacing the first two characters of the user name field with "Ping An", and replacing the last six digits of the phone number with "123456". There can also be other replacement rules, and specifically, it is not limited here. Through data desensitization operations, the server can effectively avoid the leakage of user information and ensure the security of user information.

[0041] Specifically, the server reads the preset desensitization rules from the preset configuration file or the preset configuration information table; the server sets the preset desensitization rules and the data to be desensitized as input parameters and inputs them into the target function corresponding to the target object; the server executes the target function corresponding to the target object to perform desensitization operations on the fields to be desensitized of the data to be desensitized, and obtains the desensitized data.

[0042] In the embodiment of the present invention, the bytecode manipulation framework (ASM) proxy method is adopted. The recursive algorithm is used to traverse all fields of the domain model to avoid omission of fields to be desensitized. By caching the proxy objects of each domain model and finding the fields to be desensitized for desensitization processing, the efficiency and accuracy of data desensitization operations are improved.

[0043] Please refer to Figure 2, another embodiment of the data desensitization method in the embodiments of the present invention includes:

[0044] 201. When a compilation file request is received, obtain a data model file according to the compilation file request, compile the data model file into an initial bytecode file, and run the initial bytecode file.

[0045] Among them, the data model file is a file of the.java type, and the data model file includes a logical interface for abstract attribute desensitization processing, which can facilitate the expansion of new field desensitization processing. For different fields, if there is the same desensitization logic, public logic code is used for processing to avoid the problem of code redundancy.

[0046] Optionally, when the server receives a compilation request, the server parses the parameters of the compilation file request to obtain a parsing result; the server reads a file identifier from the parsing result and queries preset configuration information according to the file identifier to obtain a data model file; the server sets the data model file as a source code file, and the server calls a preset compiler to compile the source code file into an initial bytecode file. Among them, the file extension of the initial bytecode file is.class, and the preset compiler can be a javac compilation tool or other compilation tools, which are not specifically limited here; the server loads the initial bytecode file through a preset virtual machine and converts the initial bytecode file into machine code and executes it. Among them, the preset virtual machine can be a Java virtual machine JVM, and the machine code recognizable by the Java virtual machine can be binary data, which are not specifically limited here.

[0047] 202. Recursively parse the initial bytecode file running in the program using a bytecode manipulation framework to obtain a proxy object dataset and cache the proxy object dataset.

[0048] Among them, the initial bytecode file is used to indicate a file abstractly created from a preset data structure and includes multiple functions with data acquisition and setting functions. During the process of the server generating the proxy object dataset, the server numbers each function so that each function has a corresponding number, that is, the index subscript value corresponding to each function. Optionally, the server uses a bytecode manipulation framework to load the initial bytecode file; the server recursively parses the initial bytecode file running in the program to obtain multiple proxy class names and multiple function names; the server sets corresponding index subscript values according to the multiple function names; the server generates a proxy object dataset according to the multiple proxy class names and the corresponding index subscript values and stores the proxy object dataset in a relational database and a memory database.

[0049] It is understandable that the server adopts a recursive algorithm when dynamically generating the proxy object dataset. That is, the server obtains all subordinate models under the top-level data model from the initial bytecode file and recursively obtains all subordinate models of the subordinate models to generate proxy objects (proxy object dataset) for all data models. The server's adoption of the recursive algorithm can effectively avoid the omission of desensitization fields.

[0050] Furthermore, the server can adopt the map data structure (in-memory database) to set key-value pairs for the proxy object dataset. These key-value pairs use hash values and are entered into a preset hash table. Among them, map belongs to a computer data structure composed of multiple key-value pairs. There are various implementation methods of map in Java. What the server can use is the hash table hashmap provided by the Java Development Kit (JDK). That is, it uses the hash table to find values for caching. Therefore, when the server performs reflection processing using the bytecode manipulation framework, it first obtains the proxy class, and then obtains all the contents in the.class file (initial bytecode file), including attributes, constructors, and ordinary functions. Attributes are represented by the Filed class, constructors are represented by the Constructor, and ordinary functions are represented by the Method. And it generates and stores the proxy object dataset according to the actual business requirements. For example, it uses map.put to store the proxy object dataset. Furthermore, the server can associate and retrieve through the fully qualified class name (proxy class name) in the data model file and the proxy object (for example, the corresponding index subscript value). This can not only save usage space but also reduce frequent access to the hard disk or database, improving data processing efficiency.

[0051] 203. When receiving a desensitization processing request, determine the data to be desensitized according to the desensitization processing request, and query the target proxy object from the proxy object dataset. The target proxy object is used to call the preset business processing function corresponding to the desensitization processing request.

[0052] It should be noted that when the server receives a desensitization processing request, the server judges whether there is a target proxy object in the cached proxy object dataset. If there is a target proxy object in the cached proxy object dataset, the server directly obtains the target proxy object; if there is no target proxy object in the cached proxy object dataset, it recaches its proxy object dataset.

[0053] Optionally, when the server receives a desensitization request, the server parses the parameters of the desensitization request to obtain the proxy class name and the identifier of the object to be desensitized; the server queries the relational database using the identifier of the object to be desensitized to obtain the data to be desensitized; the server queries the proxy object dataset in the in-memory database according to the proxy class name to obtain a query result; the server determines whether the query result is a null value; if the query result is not a null value, the server reads the object data corresponding to the proxy class name from the query result to obtain the target proxy object, and the target proxy object is used to call the preset business processing function corresponding to the desensitization request; if the query result is a null value, the server reads the proxy object dataset from the relational database, reads the object data corresponding to the proxy class name from the proxy object dataset to obtain the target proxy object, and rewrites the proxy object dataset into the in-memory database. Further, the server can query the cached proxy object dataset with the efficient index of the map. For example, the server searches for the target proxy object (i.e., the value) according to the attribute type name (i.e., the key) in the data model file through a preset query method (e.g., map.get).

[0054] It can be understood that the target proxy object provides a proxy for other business objects to control the access to a certain object. So that in some cases, when the target terminal cannot directly access another object, the target proxy object can play a connecting role between the target terminal and other business objects, and the target proxy object can also have additional operations, which are not specifically limited here.

[0055] 204. Obtain a preset desensitization rule, and call the target proxy object to perform a desensitization operation on the data to be desensitized according to the preset desensitization rule.

[0056] Among them, the desensitization rule can expand the processing rules corresponding to each desensitization field according to business requirements, improving the reuse rate and expandability of the desensitization rule. After the server finds the target proxy object, it finds the function to be called through the number of each function, that is, the index subscript value, and performs desensitization processing on the fields to be desensitized in the data transfer object (data to be desensitized) through the function to be called, and replaces the fields to be desensitized with the field content data.

[0057] Optionally, the server obtains a preset desensitization rule and obtains the corresponding index subscript value from the target proxy object; the server determines the corresponding function to be called according to the corresponding index subscript value; the server performs a desensitization operation on the fields to be desensitized in the data to be desensitized according to the preset desensitization rule through the corresponding function to be called. For example, the server directly replaces the ID card of the user in the desensitization field with 000000 according to the preset desensitization rule, effectively avoiding the leakage of customer information and protecting the privacy and security of customers. It can also be replaced with other content, which is not specifically limited here.

[0058] Furthermore, the server saves the desensitized data to a preset data table. When receiving a data printing request, the server parses the data printing request to obtain the data identifier to be printed. The server queries the desensitized data according to the data identifier to be printed, converts the desensitized data into a file to be printed, and the server invokes a preset printing service to enable the preset printing service to connect to a target printer and print the file to be printed according to preset printing parameters. It should be noted that the file extension of the target printing file can be.jpg,.pdf or.word, or other file formats, which are not specifically limited here. The preset printing parameters include the number of copies to be printed and the paper size to be printed, and also include printing page information, which are not specifically limited here.

[0059] 205. Update the initial bytecode file through a bytecode manipulation framework to obtain an updated bytecode file.

[0060] The initial bytecode file runs in the program. The server updates the initial bytecode file through a bytecode manipulation framework to obtain an updated bytecode file. Specifically, the server uses a first preset function (class reading function ClassReader) to read and parse the initial bytecode file (a compiled class bytecode file); the server sets the information to be updated and uses a second preset function (class writing function ClassWriter) to rebuild and compile the information to be updated and then write it into the initial bytecode file in the form of a byte array to obtain an updated bytecode file. For example, the server uses ASM to dynamically generate intercepted proxy class information of a class.

[0061] It should be noted that ClassReader reads the entire class file as an element class in the visitor pattern, while ClassWrite, as an implementation class in the visitor pattern, implements the processing of class elements.

[0062] 206. Obtain an updated proxy object dataset from the updated bytecode file and store the updated proxy object dataset in a relational database and a memory database.

[0063] That is, when the server executes step 202, it can generate an updated proxy object dataset from the updated bytecode file, and then store the updated proxy object dataset in a relational database and a memory database.

[0064] Further, the server invokes a preset timing task to detect whether the cached proxy object dataset is null. Specifically, the server reads the cached proxy object dataset through the preset timing task and compares the cached proxy object dataset with null. When the cached proxy object dataset is not equal to null, the server determines that the cached proxy object dataset is not null. When the cached proxy object dataset is equal to null, the server determines that the cached proxy object dataset is null. When the cached proxy object dataset is null, the server queries the proxy object dataset from the relational database and adds the proxy object dataset to the in-memory database.

[0065] In the embodiment of the present invention, the bytecode manipulation framework (ASM) proxy method is adopted, and a recursive algorithm is used to traverse all fields of the domain model to avoid omission of fields to be desensitized. By caching proxy objects of each domain model, the fields to be desensitized are found for desensitization processing, which improves the efficiency and accuracy of data desensitization operations.

[0066] The data desensitization method in the embodiment of the present invention has been described above. Next, the data desensitization device in the embodiment of the present invention will be described. Please refer to Figure 3 , an embodiment of the data desensitization device in the embodiment of the present invention includes:

[0067] The compilation module 301 is used to obtain the data model file according to the compilation file request when receiving the compilation file request, compile the data model file into an initial bytecode file, and run the initial bytecode file;

[0068] The parsing module 302 is used to recursively parse the initial bytecode file running in the program by using the bytecode manipulation framework to obtain the proxy object dataset and cache the proxy object dataset;

[0069] The determination module 303 is used to determine the data to be desensitized according to the desensitization processing request when receiving the desensitization processing request, and query the target proxy object from the proxy object dataset. The target proxy object is used to call the preset service processing function corresponding to the desensitization processing request;

[0070] The desensitization module 304 is used to obtain the preset desensitization rule, call the target proxy object, and desensitize the data to be desensitized according to the preset desensitization rule.

[0071] In the embodiment of the present invention, the bytecode manipulation framework (ASM) proxy method is adopted, and a recursive algorithm is used to traverse all fields of the domain model to avoid omission of fields to be desensitized. By caching proxy objects of each domain model, the fields to be desensitized are found for desensitization processing, which improves the efficiency and accuracy of data desensitization operations.

[0072] Please refer to Figure 4, Another embodiment of the data desensitization device in the embodiments of the present invention includes:

[0073] A compilation module 301, when receiving a compilation file request, is used to obtain a data model file according to the compilation file request, compile the data model file into an initial bytecode file, and run the initial bytecode file;

[0074] A parsing module 302, which is used to recursively parse the initial bytecode file running in the program by using a bytecode manipulation framework to obtain a proxy object dataset and cache the proxy object dataset;

[0075] A determination module 303, when receiving a desensitization processing request, is used to determine the data to be desensitized according to the desensitization processing request, and query a target proxy object from the proxy object dataset, where the target proxy object is used to call a preset service processing function corresponding to the desensitization processing request;

[0076] A desensitization module 304, which is used to obtain a preset desensitization rule, call the target proxy object, and perform a desensitization operation on the data to be desensitized according to the preset desensitization rule.

[0077] Optionally, the compilation module 301 may also be specifically used for:

[0078] When receiving a compilation request, perform parameter parsing on the compilation file request to obtain a parsing result;

[0079] Read a file identifier from the parsing result, and query preset configuration information according to the file identifier to obtain a data model file;

[0080] Set the data model file as a source code file, and call a preset compiler to compile the source code file into an initial bytecode file;

[0081] Load the initial bytecode file through a preset virtual machine, and convert the initial bytecode file into machine code and execute it.

[0082] Optionally, the parsing module 302 may also be specifically used for:

[0083] Load the initial bytecode file by using a bytecode manipulation framework;

[0084] Recursively parse the initial bytecode file running in the program to obtain multiple proxy class names and multiple function names;

[0085] Set corresponding index subscript values according to the multiple function names respectively;

[0086] Generate a proxy object dataset according to the multiple proxy class names and the corresponding index subscript values, and store the proxy object dataset in a relational database and a memory database.

[0087] Optionally, the determination module 303 can also be specifically used for:

[0088] When receiving a desensitization processing request, parse the parameters of the desensitization processing request to obtain the proxy class name and the identifier of the object to be desensitized;

[0089] Query the relational database using the identifier of the object to be desensitized to obtain the data to be desensitized;

[0090] Query the proxy object dataset in the in-memory database according to the proxy class name to obtain the query result;

[0091] Determine whether the query result is a null value;

[0092] If the query result is not a null value, read the object data corresponding to the proxy class name from the query result to obtain the target proxy object, and the target proxy object is used to call the preset business processing function corresponding to the desensitization processing request;

[0093] If the query result is a null value, read the proxy object dataset from the relational database, read the object data corresponding to the proxy class name from the proxy object dataset to obtain the target proxy object, and rewrite the proxy object dataset to the in-memory database.

[0094] Optionally, the desensitization module 304 can also be specifically used for:

[0095] Obtain the preset desensitization rule and obtain the corresponding index subscript value from the target proxy object;

[0096] Determine the corresponding function to be called according to the corresponding index subscript value;

[0097] Through the corresponding function to be called, desensitize the fields to be desensitized in the data to be desensitized according to the preset desensitization rule.

[0098] Optionally, the data desensitization device further includes:

[0099] An update module 305, configured to update the initial bytecode file through a bytecode manipulation framework to obtain an updated bytecode file;

[0100] A storage module 306, configured to obtain the updated proxy object dataset from the updated bytecode file, and store the updated proxy object dataset in the relational database and the in-memory database.

[0101] Optionally, the data desensitization device further includes:

[0102] A detection module 307, configured to call a preset timing task to detect whether the cached proxy object dataset is a null value;

[0103] An adding module 308 is used to query the proxy object dataset to be cached from a relational database and add the proxy object dataset to be cached to the in-memory database when the cached proxy object dataset is null.

[0104] In the embodiment of the present invention, the bytecode manipulation framework (ASM) proxy method is adopted, and a recursive algorithm is used to traverse all fields of the domain model to avoid omission of fields to be desensitized. By caching proxy objects of each domain model, the fields to be desensitized are found for desensitization processing, which improves the efficiency and accuracy of data desensitization operations.

[0105] Above Figure 3 And Figure 4 The data desensitization device in the embodiment of the present invention is described in detail from the perspective of modularization. Next, the data desensitization device in the embodiment of the present invention is described in detail from the perspective of hardware processing.

[0106] Figure 5 FIG. is a schematic structural diagram of a data desensitization device provided by an embodiment of the present invention. The data desensitization device 500 may vary greatly due to configuration or performance, and may include one or more processors (central processing units, CPUs) 510 (for example, one or more processors) and a memory 520, and one or more storage media 530 (for example, one or more mass storage devices) for storing application programs 533 or data 532. Among them, the memory 520 and the storage media 530 may be transient storage or persistent storage. The program stored in the storage media 530 may include one or more modules (not shown in the figure), and each module may include a series of instruction operations on the data desensitization device 500. Further, the processor 510 may be configured to communicate with the storage media 530 and execute a series of instruction operations in the storage media 530 on the data desensitization device 500.

[0107] The data desensitization device 500 may further include one or more power supplies 540, one or more wired or wireless network interfaces 550, one or more input / output interfaces 560, and / or one or more operating systems 531, such as Windows Serve, Mac OS X, Unix, Linux, FreeBSD, etc. Those skilled in the art can understand that Figure 5 The shown data desensitization device structure does not limit the data desensitization device, and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0108] The present invention also provides a computer-readable storage medium, which may be a non-volatile computer-readable storage medium or a volatile computer-readable storage medium. Instructions are stored in the computer-readable storage medium. When the instructions are run on a computer, the computer is caused to execute the steps of the data desensitization method.

[0109] The present invention also provides a data desensitization device. The data desensitization device includes a memory and a processor. Instructions are stored in the memory. When the instructions are executed by the processor, the processor is caused to execute the steps of the data desensitization method in the foregoing embodiments.

[0110] Further, the computer-readable storage medium may mainly include a program storage area and a data storage area. Among them, the program storage area may store an operating system, application programs required for at least one function, etc.; the data storage area may store data created according to the use of blockchain nodes, etc.

[0111] The blockchain referred to in the present invention is a new application mode of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithm. Blockchain, in essence, is a decentralized database, a string of data blocks generated by using cryptographic methods. Each data block contains information about a batch of network transactions, which is used to verify the validity (anti-counterfeiting) of the information and generate the next block. The blockchain may include a blockchain underlying platform, a platform product service layer, an application service layer, etc.

[0112] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the systems, devices, and units described above may refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.

[0113] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it may be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, may be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in various embodiments of the present invention. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc that can store program codes.

[0114] As described above, the above embodiments are only used to illustrate the technical solutions of the present invention, rather than limiting it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still update the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these updates or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A data desensitization method, characterized in that, The data desensitization method includes: When a compilation file request is received, obtain a data model file according to the compilation file request, compile the data model file into an initial bytecode file, and run the initial bytecode file; Use a bytecode manipulation framework to recursively parse the initial bytecode file running in the program to obtain a proxy object dataset, and cache the proxy object dataset; When a desensitization processing request is received, determine the data to be desensitized according to the desensitization processing request, and query a target proxy object from the proxy object dataset. The target proxy object is used to call a preset service processing function corresponding to the desensitization processing request; Obtain a preset desensitization rule, and call the target proxy object to perform a desensitization operation on the data to be desensitized according to the preset desensitization rule; The step of using a bytecode manipulation framework to recursively parse the initial bytecode file running in the program to obtain a proxy object dataset, and cache the proxy object dataset includes: loading the initial bytecode file using a bytecode manipulation framework; recursively parsing the initial bytecode file running in the program to obtain a plurality of proxy class names and a plurality of function names; setting corresponding index subscript values according to the plurality of function names; generating a proxy object dataset according to the plurality of proxy class names and the corresponding index subscript values, and storing the proxy object dataset in a relational database and a memory database.

2. The data desensitization method according to claim 1, wherein The step of when a compilation file request is received, obtaining a data model file according to the compilation file request, compiling the data model file into an initial bytecode file, and running the initial bytecode file includes: When a compilation request is received, perform parameter parsing on the compilation file request to obtain a parsing result; Read a file identifier from the parsing result, and query preset configuration information according to the file identifier to obtain a data model file; Set the data model file as a source code file, and call a preset compiler to compile the source code file into an initial bytecode file; Load the initial bytecode file through a preset virtual machine, and convert the initial bytecode file into machine code and execute it.

3. The data desensitization method according to claim 1, wherein The step of when a desensitization processing request is received, determining the data to be desensitized according to the desensitization processing request, and querying a target proxy object from the proxy object dataset. The target proxy object is used to call a preset service processing function corresponding to the desensitization processing request includes: When a desensitization processing request is received, perform parameter parsing on the desensitization processing request to obtain a proxy class name and an identifier of the object to be desensitized; Query the relational database using the identifier of the object to be desensitized to obtain the data to be desensitized; Query the proxy object dataset in the memory database according to the proxy class name to obtain a query result; Determine whether the query result is a null value; If the query result is not a null value, read the object data corresponding to the proxy class name from the query result to obtain a target proxy object. The target proxy object is used to call a preset service processing function corresponding to the desensitization processing request; If the query result is a null value, read the proxy object dataset from the relational database, read the object data corresponding to the proxy class name from the proxy object dataset to obtain a target proxy object, and rewrite the proxy object dataset into the in-memory database.

4. The data desensitization method according to claim 1, characterized in that, The obtaining of a preset desensitization rule and the calling of the target proxy object to desensitize the data to be desensitized according to the preset desensitization rule include: Obtain a preset desensitization rule and obtain the corresponding index subscript value from the target proxy object; Determine the corresponding function to be called according to the corresponding index subscript value; Perform a desensitization operation on the fields to be desensitized in the data to be desensitized according to the preset desensitization rule through the corresponding function to be called.

5. The data desensitization method according to any one of claims 1-4, characterized in that, After the obtaining of a preset desensitization rule and the calling of the target proxy object to desensitize the data to be desensitized according to the preset desensitization rule, the data desensitization method further includes: Update the file of the initial bytecode file through the bytecode manipulation framework to obtain an updated bytecode file; Obtain the updated proxy object dataset from the updated bytecode file, and store the updated proxy object dataset in the relational database and the in-memory database.

6. The data desensitization method according to any one of claims 1-4, characterized in that After the obtaining of a preset desensitization rule and the calling of the target proxy object to desensitize the data to be desensitized according to the preset desensitization rule, the data desensitization method further includes: Call a preset timing task to detect whether the cached proxy object dataset is a null value; When the cached proxy object dataset is a null value, query the proxy object dataset to be cached from the relational database, and add the proxy object dataset to be cached to the in-memory database.

7. A data desensitization device, characterized in that, The data desensitization device includes: A compilation module, when receiving a compilation file request, is used to obtain a data model file according to the compilation file request, compile the data model file into an initial bytecode file, and run the initial bytecode file; A parsing module, which is used to recursively parse the initial bytecode file running in the program by using a bytecode manipulation framework to obtain a proxy object dataset, and cache the proxy object dataset; A determination module, when receiving a desensitization processing request, is used to determine the data to be desensitized according to the desensitization processing request, and query a target proxy object from the proxy object dataset, where the target proxy object is used to call a preset service processing function corresponding to the desensitization processing request; A desensitization module, which is used to obtain a preset desensitization rule and call the target proxy object to desensitize the data to be desensitized according to the preset desensitization rule; The parsing module is specifically configured to: load the initial bytecode file by using a bytecode manipulation framework; recursively parse the initial bytecode file running in the program to obtain a plurality of proxy class names and a plurality of function names; set corresponding index subscript values according to the plurality of function names; generate a proxy object data set according to the plurality of proxy class names and the corresponding index subscript values, and store the proxy object data set in a relational database and a memory database.

8. A data desensitization device, characterized in that, The data desensitization device includes: a memory and at least one processor, and instructions are stored in the memory; The at least one processor invokes the instructions in the memory so that the data desensitization device executes the data desensitization method according to any one of claims 1-6.

9. A computer-readable storage medium having instructions stored thereon, characterized in that, When the instructions are executed by the processor, the data desensitization method according to any one of claims 1-6 is implemented.

Citation Information

Patent Citations

  • Database dynamic masking method and system based on multi-agent mechanism

    CN108288003A

  • Log desensitization data processing method and device

    CN111339559A