A data desensitization method, device, computer device and storage medium

By considering the target time characteristics of the business data during the data desensitization process, a desensitization factor can reflect the changes in the business data is generated, which solves the problem that the desensitization results in the prior art cannot reflect the business changes, and achieves a more realistic camouflage effect.

CN112417498BActive Publication Date: 2025-06-24TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011271587.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-11-13
Publication Date
2025-06-24
Estimated Expiration
2040-11-13

AI Technical Summary

Technical Problem

The existing data desensitization scheme cannot reflect the changes in the sensitive information in the business while ensuring the security of sensitive information, resulting in the desensitization results appearing false and cannot achieve the effect of disguise.

Method used

By determining the service data to be desensitized in the current service, obtaining the target time characteristics of the data type in the service, processing the current time with the target time characteristics to generate a desensitization factor, and desensitizing the service data based on the desensitization factor to generate a desensitization result that can reflect the target time characteristics.

Benefits of technology

While ensuring the security of business data, the desensitization results reflect the changes in the business data of the data type in the business, thereby improving the camouflage effect and making the desensitization results closer to the real sensitive information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112417498B_ABST
    Figure CN112417498B_ABST
Patent Text Reader

Abstract

The present application provides a data desensitization method, apparatus, computer device, and storage medium. It determines the service data to be desensitized in the current service, obtains the target time characteristics of the data type to which the service data belongs in the service, and processes the current time in combination with the target time characteristics to generate a desensitization factor corresponding to the current service data. Since the successively generated desensitization factors corresponding to the service data of the data types that change over time represent the target time characteristics of the data types, the desensitization results obtained by respectively desensitizing the service data in the corresponding data types based on the successively generated desensitization factors can reflect the target time characteristics. Thus, based on the desensitization process of the service data, not only can the security of the service data be ensured, but also the desensitization results of the service data of the data types can reflect the target time characteristics of the data types, that is, reflect the changes of the service data of the data types in the service.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and more specifically, to a data desensitization method, device, computer device, and storage medium. Background Art

[0002] Data desensitization refers to the special processing of the secret or privacy information contained in the data to achieve the effect of data transformation, so that attackers cannot directly obtain sensitive information from it. Data desensitization has a wide range of applications in many industries such as medical, power, finance, telecommunications, video playback, and social networks.

[0003] The existing data desensitization solutions only rely on considering the key information in the sensitive information to achieve data desensitization, and do not consider the situation where the sensitive information changes over time. It is impossible to reflect the changes of the sensitive information in the business while ensuring the security of the sensitive information. Summary of the Invention

[0004] In view of this, to solve the above problems, the present invention provides a data desensitization method, device, computer device, and storage medium, which can reflect the changes of the sensitive information in the business while ensuring the security of the sensitive information. The technical solutions are as follows:

[0005] A data desensitization method includes:

[0006] Determine the first service data to be desensitized in the current service;

[0007] Obtain the target time characteristic of the data type to which the first service data belongs in the service, where the target time characteristic characterizes that the service data of the data type grows over time or the service data of the data type jumps over time;

[0008] Process the current time in combination with the target time characteristic to generate a first desensitization factor, and the first desensitization factor generated in sequence for desensitizing the service data of the data type that changes over time characterizes the target time characteristic;

[0009] Perform data desensitization on the first service data based on the first desensitization factor to obtain the second service data.

[0010] A data desensitization device includes:

[0011] A service data determination unit, configured to determine the first service data to be desensitized in the current service;

[0012] A time characteristic acquisition unit, configured to acquire a target time characteristic of the data type to which the first service data belongs in the service, where the target time characteristic represents that the service data of the data type grows with time or the service data of the data type jumps with time;

[0013] A desensitization factor calculation unit, configured to process the current time in combination with the target time characteristic to generate a first desensitization factor, and the first desensitization factor sequentially generated for desensitizing the service data of the data type that changes with time represents the target time characteristic;

[0014] A desensitization unit, configured to perform data desensitization on the first service data based on the first desensitization factor to obtain second service data.

[0015] A computer device, comprising: a processor and a memory, where the processor and the memory are connected through a communication bus; wherein, the processor is configured to call and execute a program stored in the memory; the memory is configured to store a program, and the program is used to implement the data desensitization method.

[0016] A computer-readable storage medium, on which a computer program is stored, and the computer program is loaded and executed by a processor to implement the steps of the data desensitization method.

[0017] The present application provides a data desensitization method, device, computer device and storage medium, which determine service data to be desensitized in the current service, acquire the target time characteristic of the data type to which the service data belongs in the service, and process the current time in combination with the target time characteristic to generate a desensitization factor corresponding to the current service data; because the desensitization factors sequentially generated corresponding to the service data of the data type that changes with time represent the target time characteristic of the data type, the desensitization results obtained by desensitizing the service data in each data type corresponding to the sequentially generated desensitization factors can reflect the target time characteristic. Therefore, based on the desensitization processing of the service data, not only can the security of the service data be ensured, but also the desensitization results of the service data of the data type can reflect the target time characteristic of the data type, that is, reflect the change situation of the service data of the data type in the service. Description of the Drawings

[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention, and for those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.

[0019] Figure 1Flowchart of a data desensitization method provided by an embodiment of the present application;

[0020] Figure 2 Another flowchart of a data desensitization method provided by an embodiment of the present application;

[0021] Figure 3 Schematic diagram of a magnification time formula provided by an embodiment of the present application;

[0022] Figure 4 Another flowchart of a data desensitization method provided by an embodiment of the present application;

[0023] Figure 5 Schematic diagram of the structure of a data desensitization device provided by an embodiment of the present application;

[0024] Figure 6 Hardware structure block diagram of an electronic device applicable to a data desensitization method provided by an embodiment of the present application. Detailed implementation manners

[0025] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0026] Existing data desensitization solutions only rely on considering key information in sensitive information to achieve data desensitization. For example, how to hide the key information in sensitive information, but they do not consider the situation where sensitive information changes over time. It is impossible to make the desensitization result of sensitive information reflect the changes in sensitive information in the business while ensuring the security of sensitive information, resulting in a very fake desensitization result and thus failing to achieve the disguise effect.

[0027] In view of this, the embodiments of the present application provide a data desensitization method, device, computer device, and storage medium to achieve the purpose of making the desensitization result of sensitive information reflect the changes in sensitive information in the business while ensuring the security of sensitive information.

[0028] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific implementation manners.

[0029] A data desensitization method provided by an embodiment of the present application can be used to desensitize sensitive information in many industries such as medical, power, finance, telecommunications, video playback, and online social networking. Among them, the social networking industry may specifically involve the live broadcast industry, short video industry, instant messaging industry, online social networking industry involving text, etc., which are not limited here.

[0030] Exemplarily, regardless of which industry the computer application is specifically applied to, the computer application can provide one or more services, and provide services for users based on these one or more services. In the process of providing services for users, the computer application may involve the display of sensitive information. For example, the number of live viewers, page views, article views, video views, etc.

[0031] However, all the data of a computer application is confidential and an asset to the computer application. If the real data is exposed, it is easy to be taken away by competitors for analysis. Desensitization is a means to protect confidentiality. The existing data desensitization methods only rely on considering the sensitive data in the sensitive information to desensitize the sensitive information, and the desensitization result is obviously false and can be seen as fake data at a glance, thus failing to achieve the effect of disguise.

[0032] The data desensitization method provided by the embodiment of the present application can not only desensitize the sensitive information, but also make the desensitization result of the sensitive information reflect the situation of the sensitive information changing over time. In this way, not only the security of the sensitive information can be guaranteed, but also the desensitization result is closer to the real sensitive information, improving the disguise effect.

[0033] Specifically, Figure 1 is a flowchart of a data desensitization method provided by an embodiment of the present application.

[0034] As Figure 1 shown, the method includes:

[0035] S101. Determine the first service data to be desensitized in the current service;

[0036] Exemplarily, during the operation of the service in the computer application on the terminal, it may involve the display of service data of one or more data types. Taking one data type as an example, the service data of this data type may be updated over time.

[0037] If the business data of a certain data type in a business is sensitive information, it means that the business data of this data type cannot be directly displayed on the terminal. Instead, data desensitization needs to be performed on the business data of this data type to display the desensitization result of the business data on the terminal. In this case, it is necessary to obtain the business data of this data type (for the convenience of distinction, the business data to be desensitized currently can be called the first business data), perform data desensitization processing on the obtained business data to obtain the desensitization result (for the convenience of distinction, the desensitization result of the first business data can be called the second business data), and then based on the method of not displaying the obtained business data on the terminal but displaying the desensitization result of the business data on the terminal, the protection of business data is realized.

[0038] A data desensitization method provided by an embodiment of the present application is described from the perspective of performing data desensitization on the business data of the current data type. It should be understood that generally, the data desensitization method provided by an embodiment of the present application is based on the data type as a unit, and it can realize real-time desensitization of each business data generated in sequence for a data type.

[0039] S102. Obtain the target time characteristic of the data type to which the first business data belongs in the business, where the target time characteristic characterizes that the business data of the data type grows with time or the business data of the data type jumps with time;

[0040] In an embodiment of the present application, a business can provide one or more data types, and for one or more data types provided by the business, one or several of them can be preset as the data types for which business data desensitization needs to be performed.

[0041] In this way, for the data types that need to be desensitized in the business, the current business data of this data type can be determined as the first business data to be desensitized, and the time characteristic of this data type in the business can be obtained. For the convenience of distinction, the time characteristic of this data type in the business can be called the target time characteristic.

[0042] In an embodiment of the present application, two time characteristics are preset. One time characteristic characterizes that the business data of the data type grows with time, and the other time characteristic characterizes that the business data of the data type jumps with time. For example, taking the data type of the number of live viewers as an example, the business data of this data type jumps with time; taking the data type of the page view volume as an example, the business data of this data type grows with time; taking the data type of the article view volume as an example, the business data of this data type grows with time; taking the data type of the video view volume as an example, the business data of this data type grows with time.

[0043] Exemplarily, if the time characteristic of the data type in the service indicates that the service data of the data type increases over time, the data type can be referred to as a monotonically increasing time-based data type; if the time characteristic of the data type in the service indicates that the service data of the data type jumps over time, the data type can be referred to as a jitter time-based data type.

[0044] In the embodiment of the present application, after determining the first service data to be desensitized in the current service, the time characteristic of the data type to which the first service data belongs in the service can be obtained. If the time characteristic of the data type to which the first service data belongs in the service indicates that the service data of the data type increases over time, it can be considered that the data type is a monotonically increasing time-based data type; if the time characteristic of the data type to which the first service data belongs in the service indicates that the service data of the data type jumps over time, it can be considered that the data type is a jitter time-based data type.

[0045] S103. Process the current time in combination with the target time characteristic to generate a first desensitization factor. The first desensitization factor sequentially generated for desensitizing the service data of the data type that changes over time represents the target time characteristic;

[0046] Exemplarily, if the target time characteristic of the data type to which the first service data belongs in the service indicates that the service data of the data type increases over time, that is, the data type to which the first service data belongs is a monotonically increasing time-based data type, then a processing method related to the monotonically increasing time-based data type can be used to generate a first desensitization factor that matches the current time.

[0047] Exemplarily, if the target time characteristic of the data type to which the first service data belongs in the service indicates that the service data of the data type jumps over time, that is, the data type to which the first service data belongs is a jitter time-based data type, then a processing method related to the jitter time-based data type can be used to generate a first desensitization factor that matches the current time.

[0048] However, regardless of whether the data type to which the first service data belongs is a monotonically increasing time-based data type or a jitter time-based data type, the first desensitization factor sequentially generated for desensitizing the service data of the data type that changes over time represents the target time characteristic. That is, when performing data desensitization on each service data in sequence according to the generation order of the service data of the data type to which the first service data belongs, each sequentially generated first desensitization factor represents the target time characteristic.

[0049] S104. Perform data desensitization on the first service data based on the first desensitization factor to obtain the second service data.

[0050] Exemplarily, when determining the first service data to be desensitized in the current service, obtaining the target time characteristic of the data type to which the first service data belongs in the service, and generating a first desensitization factor by processing the current time in combination with the target time characteristic, the first service data can be desensitized based on the first desensitization factor to obtain the second service data (i.e., the desensitization result).

[0051] In the embodiments of the present application, a second desensitization factor is preset. First, the first service data can be desensitized according to the second desensitization factor to generate an intermediate result, and then the intermediate result can be desensitized using the first desensitization factor to generate the second service data.

[0052] Exemplarily, the second desensitization factor may include any one or more of a base value and an expansion ratio. Taking the second desensitization factor including a base value and an expansion ratio as an example, the method of desensitizing the first service data according to the second desensitization factor to generate an intermediate result may be: calculating the cumulative result of the first service data and the base value, and taking the product between the cumulative result and the expansion ratio as the intermediate result.

[0053] The above is only a preferred implementation manner for desensitizing the first service data according to the second desensitization factor to generate an intermediate result provided by the embodiments of the present application. For the specific implementation manner of this process, the inventor can set it according to his own needs and is not limited herein.

[0054] The present application provides a data desensitization method, which determines the service data to be desensitized in the current service, obtains the target time characteristic of the data type to which the service data belongs in the service, and generates a desensitization factor corresponding to the current service data by processing the current time in combination with the target time characteristic; because the desensitization factors sequentially generated for the service data of the data types that change over time represent the target time characteristics of the data types, the desensitization results obtained by desensitizing the service data in each data type based on the respective sequentially generated desensitization factors can reflect the target time characteristics. Thus, based on the desensitization processing of the service data, not only the security of the service data can be ensured, but also the desensitization results of the service data of the data types can reflect the target time characteristics of the data types, that is, reflect the changes of the service data of the data types in the service.

[0055] Next, taking the target time characteristic representing the growth of the service data of the data type over time as an example, a data desensitization method provided by the embodiments of the present application will be described in detail. For details, please refer to Figure 2 .

[0056] As Figure 2 shown, the method includes:

[0057] S201. Determine the first service data to be desensitized in the current service;

[0058] S202. Obtain the target time characteristic of the data type to which the first service data belongs in the service, where the target time characteristic characterizes that the service data of the data type grows with time or the service data of the data type jumps with time;

[0059] The execution processes of steps S201 - S202 provided in the embodiments of the present application are the same as those of steps S101 - S102 provided in the above embodiments. For the specific execution manners of steps S201 - S202, please refer to the detailed descriptions of steps S101 - S102, and will not be elaborated here.

[0060] S203. If the target time characteristic characterizes that the service data of the data type grows with time, determine the time interval between the current time and the creation time of the data to which the first service data belongs;

[0061] In the embodiments of the present application, if the data type to which the first service data belongs is a single - increasing time - related data type, the time interval between the current time and the creation time of the data to which the first service data belongs can be determined, and the first desensitization factor can be calculated according to this time interval.

[0062] Exemplarily, a computer application usually creates data to record service data. Usually, a piece of data may include service data of one or more data types. Correspondingly, the data to which the first service data belongs can be considered as a certain piece of data in the computer application (this piece of data is used to store the first service data), and the creation time of this piece of data by the computer application can be considered as the creation time of the data to which the first service data belongs.

[0063] S204. Perform logarithmic processing on the time interval to generate a first desensitization factor, and the larger the time interval, the larger the generated first desensitization factor;

[0064] In the embodiments of the present application, the first desensitization factor generated in sequence for desensitizing the service data of the data type that changes with time characterizes the target time characteristic.

[0065] If the target time characteristic characterizes that the service data of the data type grows with time, the time interval between the current time and the creation time of the data to which the first service data belongs can be determined, and the first data representing this time interval can be determined, where the first data is in years; process the first data to generate a second data; perform logarithmic processing on the second data to generate a first desensitization factor.

[0066] As a preferred implementation provided by the embodiments of the present application, the current timestamp can be determined, and the creation timestamp of the data to which the first service data belongs can be determined. Usually, both the current timestamp and the creation timestamp of the data to which the first service data belongs are in seconds. Subtract the creation timestamp of the data to which the first service data belongs from the current timestamp to obtain a time interval in seconds, and convert this time interval into a time interval in years. The converted time interval can be regarded as the first data.

[0067] As another preferred implementation provided by the embodiments of the present application, the current timestamp can be determined, and the creation timestamp of the data to which the first service data belongs can be determined. Usually, both the current timestamp and the creation timestamp of the data to which the first service data belongs are in seconds. Convert the current timestamp into a timestamp in years to obtain the current timestamp converted to years; convert the creation timestamp of the data to which the first service data belongs into a timestamp in years to obtain the creation timestamp of the data to which the first service data belongs converted to years; subtract the creation timestamp of the data to which the first service data belongs converted to years from the current timestamp converted to years to obtain the first data.

[0068] In the embodiments of the present application, the first data can be processed to generate the second data; a preset base is determined. When the first data is 0, the second data is the same as the preset base; correspondingly, the first desensitization factor is the logarithm of the second data with the preset base as the base.

[0069] Exemplarily, if the target time characteristic represents that the service data of the data type grows with time, the method for generating the first desensitization factor by processing the current time in combination with the target time characteristic can be seen in the following formula 1:

[0070] , where is the current timestamp converted to years, is the creation timestamp of the data to which the first service data belongs converted to years, can be regarded as the first data, can be regarded as the second data, is the first desensitization factor.

[0071] S205. Perform data desensitization on the first service data based on the first desensitization factor to obtain the second service data.

[0072] In the embodiments of the present application, data desensitization can be performed on the first service data according to the second desensitization factor to generate an intermediate result; the intermediate result is desensitized using the first desensitization factor to generate the second service data.

[0073] Exemplarily, the method for performing data desensitization on the first service data based on the first desensitization factor to obtain the second service data can be seen in formula 2:

[0074] , where is the first service data, and the second desensitization factor consists of base and ratio. Base is the base value, and ratio is the magnification factor. is the second service data.

[0075] In the embodiments of the present application, the base value can be considered as the value directly added to the true value. For example, if the true value is 13 and the base value is 200, the result is 213; the magnification factor can be considered as the approximate multiple of the false data to the true data. For example, if the true value is 16 and the magnification factor is 1.5, the result is 24.

[0076] The above are only the preferred contents of the base value and the magnification factor provided by the embodiments of the present application. Regarding the specific values of the base value and the magnification factor, the inventor can set them according to his own needs and is not limited herein.

[0077] It should be noted that if the service data characterizing the data type of the target time characteristic grows with time, the first desensitization factor generated by processing the current time in combination with the target time characteristic can be considered as the magnification time, and Formula 1 can be considered as the magnification time formula.

[0078] There are two purposes for designing the magnification time formula: on the one hand, adding this formula can make the camouflage result (desensitization result) not so "linear", so as to effectively counter-predict and make the true service data not so easy to be detected; on the other hand, this formula is time-based, and as time increases, the result will automatically grow naturally, making the desensitization result look more real and active.

[0079] Moreover, in combination with the above magnification time formula, the method for generating the first desensitization factor by processing the current time in combination with the target time characteristic provided by the embodiments of the present application can be seen in Formula 3:

[0080] , where is the magnification time formula, x is the first service data, base is the base value, ratio is the magnification factor, now is the current timestamp converted to years, and timeStart is the creation timestamp of the data to which the first service data belongs converted to years. is the second service data.

[0081] It should be noted that other functions can also be selected for the magnification time formula, and the parameters in the magnification time formula can also be designed in other ways, such as power functions, polynomial functions, etc., which are not limited herein.

[0082] Combined with Figure 3A schematic diagram of a magnification-time formula is provided. The magnification-time formula is adopted because: 1) it is monotonically increasing; 2) the growth rate gradually slows down over time. Additionally, the characteristics of this magnification-time formula are: 1) the result is 1 at the moment of startup; 2) the result is 2 in the second year after startup. In this way, without changing the real data, the desensitization result will naturally and slowly increase over time, meeting the purpose of a real and active desensitization result.

[0083] Taking the example of business data of a data type characterized by target time characteristics that jumps over time as an example, a data desensitization method provided by an embodiment of the present application will be described in detail. Specifically, please refer to Figure 4 。

[0084] As Figure 4 shown, the method includes:

[0085] S401. Determine the first business data to be desensitized in the current business;

[0086] S402. Obtain the target time characteristics of the data type to which the first business data belongs in the business, where the target time characteristics characterize the growth of business data of the data type over time or the jump of business data of the data type over time;

[0087] The execution processes of steps S401 - S402 provided by the embodiment of the present application are the same as those of steps S101 - S102 provided by the above embodiment. For the specific execution manners of steps S401 - S402, please refer to the detailed description of steps S101 - S102, and no further elaboration will be made here.

[0088] S403. Generate a first data sequence composed of a preset number of random numbers, where the random numbers in the first data sequence represent the time intervals of the jumps of the business data of the data type that are closest to the last jump in the jump distance related to the random number sorting;

[0089] In the embodiment of the present application, the preset number can be 5, 8, 12, 15, etc. The specific value of the preset number can be set by the inventor according to his own needs and is not limited here.

[0090] Exemplarily, a numerical range can be generated according to the preset number and a preset value, and then a first data sequence within this numerical range is randomly generated, where the random numbers in the first data sequence are different from each other. Among them, the preset value can be used as the starting point of the numerical range, calculate the sum result of the preset value and the preset number, and use the result obtained by subtracting 1 from the sum result as the end point of the numerical range. The numerical range is composed of the starting point and the end point of the numerical range. It should be noted that both the preset number and the preset value are positive integers.

[0091] For example, when the preset number is 11, if the preset value is 2, the starting point of the numerical range is 2, and the ending point of the numerical range is 12. The data range 2 - 12 is formed by the starting point and the ending point of the numerical range, and a permutation of this numerical range is randomly generated, which can be regarded as the first data sequence.

[0092] Exemplarily, if a permutation of 2 - 12 (i.e., the first data sequence) randomly generated is: 2, 8, 3, 9, 10, 6, 4, 7, 11, 12, 5; then it can be determined that the meaning of this first data sequence is to jump once every 2 seconds, then jump once every 8 seconds, then jump once every 3 seconds, jump once every 9 seconds, then jump once every 10 seconds, then jump once every 6 seconds, then jump once every 4 seconds, then jump once every 7 seconds, then jump once every 11 seconds, then jump once every 12 seconds, then jump once every 5 seconds. At this time, a round of jumps is completed, and then jump once every 2 seconds again, then jump once every 8 seconds again, then jump once every 3 seconds... and so on.

[0093] In the embodiments of the present application, taking a random number in the first data sequence as an example, the jump related to the sorting of this random number can be regarded as the Nth jump. , where is the sorting serial number of this random number in the first data sequence, n is an integer greater than or equal to 0, and b is the preset number. Exemplarily, taking the preset number as 11, if the random number is the 3rd random number in the first data sequence, then the sorting serial number of this random number in the first data sequence is 3, and N can be 3, 14, 25, 36...

[0094] In the embodiments of the present application, the first data sequence can also be generated in other ways. For example, a fixed random number sequence can be used instead of full permutation, which is not limited herein.

[0095] S404. Determine the total time interval required to complete a round of jumps according to the first data sequence;

[0096] In the embodiments of the present application, the accumulated result of all random numbers in the first data sequence can be used as the total time interval required to complete a round of jumps. Still taking the above first data sequence 2, 8, 3, 9, 10, 6, 4, 7, 11, 12, 5 as an example, the total time interval required for this first data sequence to complete a round of jumps is 77 seconds.

[0097] S405. Use the current time to perform a modulo operation on the total time interval to determine the target data matching the current time;

[0098] In the embodiments of the present application, the third data of each random number in the first data sequence can be determined, and the third data of the random number is generated by all the random numbers in the first data sequence whose sorting is not later than the random number; obtain a second data sequence successively composed of the third data of each random number in the first data sequence; perform a modulo operation on the total time interval using the current time to obtain a modulo result; determine the target data matching the modulo result from the second data sequence.

[0099] Still taking the above first data sequence 2, 8, 3, 9, 10, 6, 4, 7, 11, 12, 5 as an example, in the first data sequence, the third data of the random number 2 is 2, the third data of the random number 8 is 10, the third data of the random number 3 is 13, the third data of the random number 9 is 22, the third data of the random number 10 is 32, the third data of the random number 6 is 38, the third data of the random number 4 is 42, the third data of the random number 7 is 49, the third data of the random number 11 is 60, the third data of the random number 12 is 72, and the third data of the random number 5 is 77. Then the generated second data sequence is: 2, 10, 13, 22, 32, 38, 42, 49, 60, 72, 77.

[0100] Exemplarily, according to the random numbers in the second data sequence, they are usually in seconds. Therefore, the calculated total time interval can be considered to be in seconds, and the current timestamp is also usually in seconds. Performing a modulo operation on the total time interval using the current timestamp can obtain a modulo result, and determine the target data matching the current time according to the modulo result.

[0101] Taking the above second data sequence 2, 10, 13, 22, 32, 38, 42, 49, 60, 72, 77 as an example, it can be seen that: a large loop will occur every 77 seconds. Therefore, for the current timestamp, the current timestamp mod 77 is the relative time. By which interval this value falls in the second data sequence, the target data at this time can be judged. For example, if the timestamp of the current time is 1598254954, and its mod 77 gets 65, it can be found that 65 falls in the interval of 60 - 72. So the target data (seed base number) here is 60.

[0102] S406. Generate a first desensitization factor according to the target data;

[0103] In the embodiments of the present application, the first desensitization factor successively generated for desensitizing service data of data types that change with time represents the target time characteristic. Specifically, a pseudo-random number generator is constructed using the target data; determine the target random number within the random number range output by the pseudo-random number generator according to the random number range, and the target random number is the first desensitization factor.

[0104] Exemplarily, a pre-set processing method can be used to process target data (seed base number) to obtain processed target data, and the processed target data is used as a random seed. A pseudo-random generator is constructed using the random seed, and then a target random number within the random number range output by the pseudo-random generator is determined. This target random number can be regarded as the first desensitization factor.

[0105] In the embodiments of the present application, the calculation method of the random number range can be: determining an intermediate result generated by performing data desensitization on the first service data according to the second desensitization factor, and calculating the random number range according to the intermediate result and a pre-set floating range. For example, if the intermediate result is 10,000 and the pre-set floating range is plus or minus 0.5%, the random number range is greater than or equal to -50 and less than or equal to 50.

[0106] In the embodiments of the present application, the above is only the preferred content of the floating range provided by the embodiments of the present application. For the specific content of the floating range, those skilled in the art can set it according to their own needs and are not limited herein.

[0107] S407. Perform data desensitization on the first service data based on the first desensitization factor to obtain the second service data.

[0108] In the embodiments of the present application, data desensitization can be performed on the first service data according to the second desensitization factor to generate an intermediate result, and data desensitization is performed on the intermediate result using the first desensitization factor to generate the second service data. Exemplarily, the product result of the intermediate result and the first desensitization factor can be used as the second service data.

[0109] Taking the number of live viewers as an example, based on the data desensitization method provided by the embodiments of the present application as Figure 4 shown, data desensitization is performed on the number of live viewers, realizing a slow and natural jump of the desensitization result, and making the desensitization result of the number of viewers in the live broadcast room as real as possible.

[0110] Based on the above as Figure 2 、 4As can be seen from the data desensitization method shown, the embodiments of the present application propose two different dynamic numerical desensitization and camouflage algorithms for time-based services, which have the following properties: 1. Desensitize service data to prevent competitors from inferring the real service data; 2. Desensitize and camouflage time-based services, and the camouflage results change naturally, making them look more natural and real to users; 3. Applicable to two different types of time-based data, monotonically increasing time-based data types and jitter time-based data types; 4). Each platform in the prior art (for example, each live broadcast platform) uses its own special algorithm, while the data desensitization method provided by the embodiments of the present application uses a "general" algorithm. The same is true for the view counts of articles and videos. Each platform may use its own algorithm to modify the data, but the data desensitization method provided by the embodiments of the present application is a general dynamic desensitization for the data middle layer, which is widely applicable to various related services. It can be used in the data middle layer, and only need to configure parameters without custom development each time.

[0111] The following will detail a data desensitization method provided by the embodiments of the present application in combination with specific implementation scenarios.

[0112] In the live broadcast service scenario, users can install a computer application providing live broadcast services on the terminal. The service data of the data type "number of live viewers" in the live broadcast service is sensitive information. Correspondingly, before the service data of the data type "number of live viewers" is displayed on the terminal, it is necessary to first use the data desensitization method as Figure 4 shown to desensitize the service data of the data type "number of live viewers" that needs to be displayed on the terminal currently to obtain a desensitization result, and then protect the service data by displaying the desensitization result instead of the service data on the terminal.

[0113] Moreover, the data desensitization method as Figure 4 shown depends on the first data sequence representing the time interval of each jump in a round of jumps. In this way, the first desensitization factor used to desensitize the service data can be determined by taking the modulus operation of the total time interval of a round of jumps according to the current time.

[0114] Thus, as time goes by, the current time is constantly changing while the total time interval remains unchanged. As the current time changes, the modulo result of the current time with respect to the total time interval is constantly changing, making the first desensitization factor corresponding to the service data at different moments in the live broadcast service scenario different, achieving the change of the first desensitization factor corresponding to the service data at different moments in the live broadcast service scenario. In this way, the adjustment intensity of the service data at different moments is different, not only realizing the desensitization of the service data, but also realizing the natural jump of the service data as time goes by. Moreover, in the process of determining the first desensitization factor, the output of the first desensitization factor by the pseudo-random generator is controlled in combination with the floating range, and the floating range is related to the service data. In this way, the desensitization result jump of the service data can be made not out of line. For example, the service data can be made to jump slowly to more conform to the real change of the number of live broadcast viewers in the live broadcast service.

[0115] In the video service scenario, users can install a computer application that provides video playback services on the terminal. The service data of the data type "video click volume" in the video service is sensitive information. Correspondingly, before the service data of the data type "video click volume" is displayed on the terminal, it is necessary to first use the data desensitization method as Figure 2 shown to desensitize the service data of the data type "video click volume" that needs to be displayed on the terminal currently to obtain a desensitization result, and then, by the way of not displaying the service data on the terminal but displaying the desensitization result, the protection of the service data is realized.

[0116] Moreover, the data desensitization method as Figure 2 shown depends on the time interval between the current time and the creation time of the data to which the service data to be desensitized belongs. By performing a logarithmic process on this time interval, a first desensitization factor for desensitizing the service data to be desensitized can be generated.

[0117] Because, as time goes by, the current time is constantly changing while the creation time of the data to which the service data to be desensitized belongs is fixed and unchanged. Therefore, as the current time changes, the time interval between the current time and the creation time of the data to which the service data to be desensitized belongs is constantly changing and constantly increasing.

[0118] By performing a logarithmic process on the time interval, it can be ensured that as time increases, the first desensitization factor generated according to the time interval is increasing, and the growth rate slows down as time increases, which is more in line with the real user's click situation on the video. Specifically, for a video, as time goes by, the click volume of the video gradually increases and it is impossible for the click volume to decrease. Moreover, the longer the time, the slower the click volume may increase.

[0119] In this way, for the same video, as time goes by, the first allergy factor generated successively not only shows a monotonically increasing trend, but also the growth rate gradually slows down over time. As a result, the desensitization result of the business data of the data type "video click volume" for this video also grows naturally and slowly over time, and the desensitization result is more real and active. By "active", it can be understood that after a long time of growth, it doesn't mean that there are no new click volumes, but just that the click volumes become fewer and fewer.

[0120] Taking a video as an example, the creation time of the data to which the business data of the data type "video click volume" belongs can be understood as follows: The video data of this video can be regarded as the data to which the business data of the data type "video click volume" belongs. Correspondingly, the creation time of the video data of this video can be considered as the creation time of the data to which the business data of the data type "video click volume" belongs.

[0121] Figure 5 It is a schematic structural diagram of a data desensitization device provided by an embodiment of the present application.

[0122] As Figure 5 shown, the device includes:

[0123] A service data determination unit 51, configured to determine first service data to be desensitized in the current service;

[0124] A time characteristic acquisition unit 52, configured to acquire a target time characteristic of the data type to which the first service data belongs in the service, where the target time characteristic represents that the service data of the data type grows over time or the service data of the data type jumps over time;

[0125] A desensitization factor calculation unit 53, configured to process the current time in combination with the target time characteristic to generate a first desensitization factor, and the first desensitization factor generated successively for desensitizing the service data of the data type that changes over time represents the target time characteristic;

[0126] A desensitization unit 54, configured to perform data desensitization on the first service data based on the first desensitization factor to obtain second service data.

[0127] As an implementation manner of an embodiment of the present application, the desensitization factor calculation unit includes:

[0128] A time interval determination unit, configured to determine the time interval between the current time and the creation time of the data to which the first service data belongs;

[0129] A desensitization factor generation unit, configured to perform logarithmic processing on the time interval to generate a first desensitization factor, and the larger the time interval, the larger the generated first desensitization factor.

[0130] Correspondingly, the desensitization factor generation unit includes:

[0131] The first data determination unit is used to determine the first data representing the time interval, and the first data is in years;

[0132] The second data generation unit is used to process the first data to generate the second data;

[0133] The first desensitization factor generation unit is used to perform logarithmic processing on the second data to generate the first desensitization factor.

[0134] As another implementation manner of the embodiment of the present application, the desensitization factor calculation unit includes:

[0135] The first data sequence generation unit is used to generate a first data sequence composed of a preset number of random numbers, and the random numbers in the first data sequence represent the time interval of the last jump of the service data of the data type related to the jump distance related to the random number sorting;

[0136] The total time interval calculation unit is used to determine the total time interval required to complete one round of jumps according to the first data sequence;

[0137] The target data determination unit is used to perform modulo processing on the total time interval using the current time to determine the target data matching the current time;

[0138] The second desensitization factor generation unit is used to generate the first desensitization factor according to the target data.

[0139] Correspondingly, the target data generation unit includes:

[0140] The third data determination unit is used to determine the third data of each random number in the first data sequence, and the third data of the random number is generated by all the random numbers in the first data sequence whose sorting is not later than the random number;

[0141] The second data sequence acquisition unit is used to acquire a second data sequence successively composed of the third data of each random number in the first data sequence;

[0142] The modulo result generation unit is used to perform modulo processing on the total time interval using the current time to obtain the modulo result;

[0143] The target data generation subunit is used to determine the target data matching the modulo result from the second data sequence.

[0144] Correspondingly, the second desensitization factor generation unit includes:

[0145] The pseudo-random number generator construction unit is used to construct a pseudo-random number generator using the target data;

[0146] A target random number output unit, configured to determine a target random number within a random number range output by a pseudo-random generator according to a random number range, where the target random number is a first desensitization factor.

[0147] In an embodiment of the present application, preferably, the desensitization unit includes:

[0148] A first desensitization unit, configured to perform data desensitization on first service data according to a second desensitization factor to generate an intermediate result;

[0149] A second desensitization unit, configured to perform data desensitization on the intermediate result by using the first desensitization factor to generate second service data.

[0150] A data desensitization method provided in an embodiment of the present application is applied to a computer device, as Figure 6 shown, which is a structural diagram of an implementation manner of a computer device provided in an embodiment of the present application. The computer device includes:

[0151] A memory 601, configured to store a program;

[0152] A processor 602, configured to execute the program, and the program is specifically used for:

[0153] Determine first service data to be desensitized in the current service;

[0154] Obtain a target time characteristic of a data type to which the first service data belongs in the service, where the target time characteristic represents that the service data of the data type grows with time or the service data of the data type jumps with time;

[0155] Process the current time in combination with the target time characteristic to generate a first desensitization factor, and the first desensitization factor sequentially generated for desensitizing the service data of the data type that changes with time represents the target time characteristic;

[0156] Perform data desensitization on the first service data based on the first desensitization factor to obtain second service data.

[0157] The processor 602 may be a central processing unit CPU or a specific integrated circuit ASIC (Application Specific Integrated Circuit).

[0158] The control device may further include a communication interface 603 and a communication bus 604. Among them, the memory 601, the processor 602, and the communication interface 603 complete mutual communication through the communication bus 604.

[0159] In an embodiment of the present application, the computer device may be a terminal or a server.

[0160] The terminal can be any kind of electronic product that can interact with users in one or more ways such as through a keyboard, touchpad, touch screen, remote control, voice interaction, or handwriting device. Exemplarily, the terminal can be a mobile phone, tablet computer, laptop computer, handheld computer, personal computer, smart speaker, wearable device, smart TV, smart watch, etc., but is not limited thereto.

[0161] The server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms.

[0162] The embodiment of the present application also provides a readable storage medium, on which a computer program is stored. The computer program is loaded and executed by a processor to implement the steps of the above data desensitization method. The specific implementation process can refer to the description of the corresponding part of the above embodiment, and this embodiment will not be elaborated.

[0163] The present application also proposes a computer program product or computer program. The computer program product or computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the methods provided in various optional implementation manners in terms of the above data desensitization method or data desensitization device. The specific implementation process can refer to the description of the corresponding embodiment above and will not be elaborated.

[0164] The present application provides a data desensitization method, device, computer device, and storage medium. Determine the service data to be desensitized in the current service, obtain the target time characteristic of the data type to which the service data belongs in the service, and process the current time in combination with the target time characteristic to generate a desensitization factor corresponding to the current service data; because the sequentially generated desensitization factors corresponding to the service data of the data types that change over time represent the target time characteristic of the data type, the desensitization results obtained by desensitizing the service data in each data type corresponding to each sequentially generated desensitization factor can reflect the target time characteristic. Thus, based on the desensitization processing of the service data, not only can the security of the service data be ensured, but also the desensitization results of the service data of the data type can reflect the target time characteristic of the data type, that is, reflect the change situation of the service data of the data type in the service.

[0165] The above has introduced in detail a data desensitization method, device, computer device and storage medium provided by the present invention. Specific examples are used in this article to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.

[0166] It should be noted that the embodiments in this specification are all described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method part.

[0167] It should also be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes the inherent elements thereof, or further includes the elements inherent to these process, method, article or device. Without more limitations, the element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.

[0168] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A data desensitization method, characterized in that, Including: Determine the first service data to be desensitized in the current service; Obtain the target time characteristic of the data type to which the first service data belongs in the service, where the target time characteristic characterizes that the service data of the data type grows with time or the service data of the data type jumps with time; Process the current time in combination with the target time characteristic to generate a first desensitization factor, and the first desensitization factor generated in sequence for desensitizing the service data of the data type that changes with time characterizes the target time characteristic; Perform data desensitization on the first service data based on the first desensitization factor to obtain second service data.

2. The method according to claim 1, characterized in that If the target time characteristic characterizes that the service data of the data type grows with time, the processing of the current time in combination with the target time characteristic to generate a first desensitization factor includes: Determine the time interval between the current time and the creation time of the data to which the first service data belongs; Perform logarithmic processing on the time interval to generate a first desensitization factor, and the larger the time interval, the larger the generated first desensitization factor.

3. The method according to claim 2, wherein The performing logarithmic processing on the time interval to generate a first desensitization factor includes: Determine the first data representing the time interval, where the first data is in years; Process the first data to generate second data; Perform logarithmic processing on the second data to generate a first desensitization factor.

4. The method according to claim 1, wherein If the target time characteristic characterizes that the service data of the data type jumps with time, the processing of the current time in combination with the target time characteristic to generate a first desensitization factor includes: Generate a first data sequence composed of a preset number of random numbers, where the random numbers in the first data sequence represent the time intervals of the service data of the data type at the time of the most recent jump related to the sorting of the random numbers; Determine the total time interval required to complete one round of jumps according to the first data sequence; Perform modulo processing on the total time interval using the current time to determine the target data matching the current time; Generate a first desensitization factor according to the target data.

5. The method according to claim 4, characterized in that, The performing modulo processing on the total time interval using the current time to determine the target data matching the current time includes: Determine the third data of each random number in the first data sequence, where the third data of the random number is generated by all the random numbers in the first data sequence whose sorting is not later than the random number; Obtain a second data sequence successively composed of the third data of each random number in the first data sequence; Perform modulo processing on the total time interval using the current time to obtain a modulo result; Determine the target data matching the modulo result from the second data sequence.

6. The method according to claim 5, wherein The generating a first desensitization factor according to the target data includes: Construct a pseudo-random number generator using the target data; Determine the target random number within the random number range output by the pseudo-random number generator according to the random number range, and the target random number is the first desensitization factor.

7. The method according to claim 1, characterized in that, The performing data desensitization on the first service data based on the desensitization factor to obtain second service data includes: Generate an intermediate result by performing data desensitization on the first service data according to the second desensitization factor; Perform data desensitization on the intermediate result using the first desensitization factor to generate second service data.

8. A data desensitization device, characterized in that, It includes: A service data determination unit for determining the first service data to be desensitized in the current service; A time characteristic acquisition unit for acquiring the target time characteristic of the data type to which the first service data belongs in the service, where the target time characteristic represents that the service data of the data type grows with time or the service data of the data type jumps with time; A desensitization factor calculation unit for processing the current time in combination with the target time characteristic to generate a first desensitization factor, and the first desensitization factor sequentially generated for desensitizing the service data of the data type that changes with time represents the target time characteristic; A desensitization unit for performing data desensitization on the first service data based on the first desensitization factor to obtain second service data.

9. A computer device, characterized in that, It includes: A processor and a memory, and the processor and the memory are connected through a communication bus; among them, the processor is used to call and execute the program stored in the memory; The memory is used to store a program, and the program is used to implement the data desensitization method described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, A computer program is stored thereon, and the computer program is loaded and executed by a processor to implement the steps of the data desensitization method described in any one of claims 1-7.

Citation Information

Patent Citations

  • Data desensitization processing method and device and electronic equipment

    CN109583226A

  • Intelligent data desensitization method and device, computer equipment and storage medium

    CN110232291A