Data Access Method, Device and System in a Distributed System
By automatically determining user access rights in a distributed system and deforming sensitive data, the problems of low data access efficiency, low reliability and low automation in the prior art are solved, and efficient, reliable and automated data access is achieved.
Patent Information
- Application Number
- CN202110593606.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-05-28
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2041-05-28
AI Technical Summary
Data access methods in existing distributed systems rely on manual operations, resulting in low data access efficiency, low reliability and low automation.
By determining the access rights of the target user, using the deformation rule nesting function to deform sensitive data, and output the deformed data, automatic sensitive data access is achieved.
On the basis of ensuring the security and privacy of data access, improve the efficiency and automation of data access, enhance the reliability of data access, and ensure the operational stability of distributed systems.
Smart Images

Figure CN113221177B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of data processing, particularly to the technical field of big data, and specifically to a data access method, apparatus, and system in a distributed system. Background Art
[0002] With the rapid development of distributed system technology, enterprises have begun to adopt high-performance distributed database systems to process massive amounts of data. Inevitably, sensitive data, confidential data, etc. are involved in this data. Due to the different identities of accessing users, their access rights to sensitive data and confidential data in the enterprise's distributed system are also different. Therefore, a one-size-fits-all approach to sensitive data access cannot be adopted, and data obtained under different processing methods needs to be provided according to different user permissions.
[0003] Currently, in the existing data access methods in a distributed system, it is usually necessary to involve at least one level of management personnel to screen the access requests of ordinary users. The management personnel need to judge whether sensitive data can be provided to the accessing user based on the identity information of the accessing user and the permission settings for the accessing user within the enterprise. The management personnel also need to filter or encrypt the sensitive data requested by users without access rights by themselves.
[0004] However, since the existing data access methods in a distributed system rely too much on manual operations of management personnel, the existing data access methods in a distributed system have problems such as low data access efficiency, low reliability, and low automation. Summary of the Invention
[0005] Aiming at the problems in the prior art, the present application provides a data access method, apparatus, and system in a distributed system, which can effectively improve the efficiency and automation of data access in the distributed system on the basis of ensuring the security and privacy of data access in the distributed system, and can effectively improve the reliability of data access in the distributed system.
[0006] To solve the above technical problems, the present application provides the following technical solutions:
[0007] In a first aspect, the present application provides a data access method in a distributed system, including:
[0008] Determine the sensitive data in the target data table in the target database in the specified distributed system by the target user who does not have the sensitive data access permission;
[0009] Perform transformation processing on the sensitive data in the target data table according to the nested function of the transformation rule corresponding to the sensitive data;
[0010] Output the sensitive data after transformation processing and the non-sensitive data in the target data table to the target user.
[0011] Further, before determining the sensitive data in the target data table in the target database within the distributed system currently specified by the target user who does not have the access permission to sensitive data, it further includes:
[0012] Receive a data access request from the target user for the distributed system, where the data access request includes the user identifier of the target user, the identifier of the target database in the distributed system, and the identifier of the target data table in the target database;
[0013] According to the identifier of the target database and the identifier of the target data table, determine whether the distributed system contains the target data table in the target database. If so, obtain the access conditions of the target user;
[0014] According to the access conditions of the target user, determine whether the target user has the access qualification for the target data table. If so, obtain the access permission and sensitive fields of the target data table requested by the target user to access.
[0015] Further, the obtaining of the access conditions of the target user includes:
[0016] Determine the area field corresponding to the user identifier of the target user from a preset user-condition relationship table;
[0017] Determine the area name of the area field corresponding to the target user in a preset area parameter table.
[0018] Further, the determining whether the target user has the access qualification for the target data table according to the access conditions of the target user includes:
[0019] Determine the area field corresponding to the identifier of the target database from a preset condition-permission relationship table;
[0020] Determine the area name of the area field corresponding to the target database in the area parameter table;
[0021] According to the area name corresponding to the target user and the area name corresponding to the target database, determine whether the target user meets the data access qualification within the area for the target database.
[0022] Further, the obtaining of the access conditions of the target user includes:
[0023] Determine the institutional number to which the target user belongs corresponding to the user identifier of the target user from a preset user-condition relationship table;
[0024] Determine the name of the user's affiliated organization corresponding to the user's affiliated organization number of the target user in the preset user's affiliated organization parameter table.
[0025] Further, the judging whether the target user has the access qualification for the target data table according to the access condition of the target user includes:
[0026] Determine the user's affiliated organization number corresponding to the identifier of the target database from the preset condition and permission relationship table;
[0027] Determine the name of the user's affiliated organization corresponding to the user's affiliated organization number of the target database in the user's affiliated organization parameter table;
[0028] Judge whether the target user meets the access qualification of the user's affiliated organization for the target database according to the name of the user's affiliated organization corresponding to the target user and the name of the user's affiliated organization corresponding to the target database.
[0029] Further, the obtaining the access permission and sensitive fields of the target data table requested by the target user to access includes:
[0030] According to the user identifier of the target user, the identifier of the target database in the distributed system, and the identifier of the target data table in the target database, search for the access permission and sensitive fields of the target data table requested by the target user to access in the preset user and sensitive information relationship table.
[0031] Further, the determining the sensitive data in the target data table in the target database of the distributed system currently specified by the target user who does not have the sensitive data access permission includes:
[0032] According to the content of the sensitive fields of the target data table requested by the target user to access, judge whether the data requested by the target user to access contains sensitive data. If so, judge whether the target user has the sensitive data access permission to access the sensitive data in the target data table based on the access permission of the target data table requested by the target user to access;
[0033] If the target user does not have the sensitive data access permission, retrieve the sensitive data in the target data table.
[0034] Further, the performing transformation processing on the sensitive data in the target data table according to the transformation rule nested function corresponding to the sensitive data includes:
[0035] Obtain the transformation indication identifier and transformation rule ID corresponding to the sensitive fields of the target data table from the preset sensitive information list;
[0036] Judge whether it is necessary to transform the sensitive fields of the target data table according to the transformation indication identifier. If so, retrieve the transformation rule nested function corresponding to the transformation rule ID from the preset transformation rules.
[0037] Perform transformation processing on the sensitive data in the target data table based on the transformation rule nested function.
[0038] Further, the outputting the transformed sensitive data and the non-sensitive data in the target data table to the target user includes:
[0039] Generate a data query view containing the transformed sensitive data according to the transformed sensitive data and the non-sensitive data in the target data table, and display the data query view for the target user to query.
[0040] Further, it further includes:
[0041] If the data requested by the target user to access does not contain sensitive data, or if the target user has the access permission for the sensitive data, generate a data query view according to the data in the target data table, and display the data query view for the target user to query.
[0042] In a second aspect, the present application provides a data access device in a distributed system, including:
[0043] A data search module, configured to determine the sensitive data in a target data table in a target database in a distributed system currently specified by a target user who does not have the access permission for sensitive data;
[0044] A data transformation module, configured to perform transformation processing on the sensitive data in the target data table according to the transformation rule nested function corresponding to the sensitive data;
[0045] A data output module, configured to output the transformed sensitive data and the non-sensitive data in the target data table to the target user.
[0046] In a third aspect, the present application provides a data access system, including: a control server, a database server, and a data warehouse;
[0047] The database server is configured to execute the data access method in the distributed system;
[0048] The control server is configured to send the data access request of the target user for the distributed system to the database server, so that the database server determines whether the target user has the access permission for sensitive data according to the data access request;
[0049] The data warehouse is used to store each data table in each database in the distributed system, so that the database server determines the sensitive data in the target data table in the target database in the distributed system currently specified by the target user who does not have the sensitive data access permission from the data warehouse.
[0050] In a fourth aspect, the present application provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the data access method in the distributed system as described above is implemented.
[0051] In a fifth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the data access method in the distributed system as described above is implemented.
[0052] As can be seen from the above technical solutions, a data access method, device, and system in a distributed system provided by the present application. The method includes: determining the sensitive data in the target data table in the target database in the distributed system currently specified by the target user who does not have the sensitive data access permission; performing transformation processing on the sensitive data in the target data table according to the transformation rule nested function corresponding to the sensitive data; outputting the transformed sensitive data and the non-sensitive data in the target data table to the target user. By setting that if the target data table contains sensitive data, the sensitive data in the target data table is subjected to transformation processing according to the transformation rule nested function corresponding to the sensitive field of the sensitive data, the participation of higher-level managers is not required, and the secure access of sensitive data can be automatically realized. Furthermore, on the basis of ensuring the security and privacy of data access in the distributed system, the efficiency and automation degree of data access in the distributed system can be effectively improved, and the reliability of data access in the distributed system can be effectively improved to effectively ensure the operation stability of the distributed system. Description of the Drawings
[0053] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0054] Figure 1 It is a schematic structural diagram of the data access system in the embodiment of the present application.
[0055] Figure 2 It is a first flow schematic diagram of the data access method in the distributed system in the embodiment of the present application.
[0056] Figure 3 It is the second process schematic diagram of the data access method in the distributed system in the embodiment of the present application.
[0057] Figure 4 It is the first process schematic diagram of step 030 in the data access method in the distributed system in the embodiment of the present application.
[0058] Figure 5 It is the third process schematic diagram of the data access method in the distributed system in the embodiment of the present application.
[0059] Figure 6 It is the second process schematic diagram of step 030 in the data access method in the distributed system in the embodiment of the present application.
[0060] Figure 7 It is the fourth process schematic diagram of the data access method in the distributed system in the embodiment of the present application.
[0061] Figure 8 It is the fifth process schematic diagram of the data access method in the distributed system in the embodiment of the present application.
[0062] Figure 9 It is the sixth process schematic diagram of the data access method in the distributed system in the embodiment of the present application.
[0063] Figure 10 It is the seventh process schematic diagram of the data access method in the distributed system in the embodiment of the present application.
[0064] Figure 11 It is the eighth process schematic diagram of the data access method in the distributed system in the embodiment of the present application.
[0065] Figure 12 It is the structural schematic diagram of the data access device in the distributed system in the embodiment of the present application.
[0066] Figure 13 It is the execution logic process schematic diagram of the data access system provided by the application example of the present application.
[0067] Figure 14 It is the specific function schematic diagram of the refined query view provided by the data access device in the distributed system provided by the application example of the present application.
[0068] Figure 15 It is the structural schematic diagram of the electronic device in the embodiment of the present application. Detailed implementation manners
[0069] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this application. Apparently, the described embodiments are some but not all of the embodiments of this application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the scope of protection of this application.
[0070] It should be noted that the data access methods, devices, and systems disclosed in this application in the distributed system can be used in the field of big data technology, and can also be used in any field other than the big data technology field. The application fields of the data access methods, devices, and systems disclosed in this application in the distributed system are not limited.
[0071] Taking the Hadoop platform as an example of the distributed system, the Hive data warehouse on the Hadoop platform is a highly reliable and high-performance distributed database system, and Hive can be used to store massive amounts of data. Using this feature, various enterprises have successively used the Hadoop platform to store and process large-scale data. When users access the massive data in the data warehouse, there are extremely high requirements for data permissions and sensitivity. The existing Hadoop platform implements permission management based on the secret key authentication (Kerberos) method. However, as the capacity of the Hadoop platform continues to expand, the number of service components continues to increase, the amount of data continues to rise, and the number of users continues to increase, the refined data permission control of the big data platform has become a necessity. Currently, for the existing massive data permission control methods, especially in the banking and large financial fields, there are some gaps in the management of data sensitivity and user-table level access permissions. That is to say, in the existing data access methods in the distributed system, for access requests to sensitive data, higher-level basic management personnel are required to make judgments and handle them. Therefore, the existing data access methods in the distributed system have problems such as low data access efficiency, low reliability, and low automation.
[0072] Based on the above content, this application manages the data permissions on the big data platform at the user-table level granularity, and integrates the user's permission control for sensitive information to form a set of big data permission management and control devices. By providing a visual interface, it supports the automatic management and control function of the access permissions of ordinary permission users by the data access device in the distributed system. It provides operability for the refined data permission control of the massive data in the distributed system. It is especially applicable to the big data permission management of the Hive data warehouse on the Hadoop platform.
[0073] In view of the problems of low data access efficiency, low reliability, and low automation in the existing data access methods in distributed systems, the embodiments of the present application respectively provide a data access method in a distributed system, a data access device in a distributed system, a data access system, an electronic device, and a computer-readable storage medium, which determine the sensitive data in the target data table in the target database in the currently specified distributed system of a target user who does not have the sensitive data access permission; perform transformation processing on the sensitive data in the target data table according to the transformation rule nested function corresponding to the sensitive data; output the transformed sensitive data and the non-sensitive data in the target data table to the target user. By setting that if the target data table contains sensitive data, the sensitive data in the target data table is subjected to transformation processing according to the transformation rule nested function corresponding to the sensitive fields of the sensitive data, the secure access of sensitive data can be automatically realized without the participation of higher-level management personnel. Furthermore, on the basis of ensuring the security and privacy of data access in the distributed system, the efficiency and automation degree of data access in the distributed system can be effectively improved, and the reliability of data access in the distributed system can be effectively improved to effectively ensure the operation stability of the distributed system.
[0074] In one or more embodiments of the present application, the distributed system may refer to a big data service cloud or an HBase cluster, etc. Among them, the HBase cluster (Hadoop Database) refers to a highly reliable, high-performance, column-oriented, scalable distributed storage system, which consists of a master node Master and slave nodes Region Server. Among them, Master can also be specifically written as HMaster, and Region Server can also be written as HRegionServer or RegionServer, etc.
[0075] Based on the above content, the present application further provides a data access system for implementing the data access method in the distributed system provided in one or more embodiments of the present application. See Figure 1, the data access system includes a control server, a database server, and a data warehouse. Among them, the database server can specifically be the data access device in the distributed system mentioned in one or more embodiments of the present application. The data access device in the distributed system can communicate with the client devices held by each user, the data warehouse in the big data service cloud, and each control server accessing the big data service cloud on its own or through a third-party server, etc. The data access device in the distributed system can be a kind of server, receiving data access requests for the distributed system in the big data service cloud from the client devices or each control server, and can also obtain various rule configuration files preset by users from the client devices, third-party databases, or locally, such as at least one of the user information table, region parameter table, professional institution parameter table (user affiliated institution parameter table), sensitive information list, transformation rules, user-sensitive information relationship table (user and sensitive information relationship table), condition-permission relationship table (condition and permission relationship table), and user-condition relationship table (user and condition relationship table) mentioned in one or more embodiments of the present application. The control server is used to send the data access request of the target user for the distributed system to the database server, so that the database server determines whether the target user has the sensitive data access permission according to the data access request; the data warehouse is used to store each data table in each database in the distributed system, so that the database server determines the sensitive data in the target data table in the target database in the distributed system currently specified by the target user who does not have the sensitive data access permission from the data warehouse.
[0076] It can be understood that the client device can include a smart phone, a tablet electronic device, a network set-top box, a portable computer, a desktop computer, a personal digital assistant (PDA), a vehicle-mounted device, a smart wearable device, etc. Among them, the smart wearable device can include smart glasses, smart watches, smart bracelets, etc.
[0077] The above-mentioned client device can have a communication module (i.e., a communication unit) and can communicate with a remote server to realize data transmission with the server. The server can include the server on the task scheduling center side. In other implementation scenarios, it can also include the server of the intermediate platform, such as the server of the third-party server platform with a communication link to the task scheduling center server. The server can include a single computer device, or a server cluster composed of multiple servers, or a server structure of a distributed device.
[0078] Any suitable network protocol can be used for communication between the above-mentioned server and the client device, including network protocols that have not been developed as of the filing date of this application. The network protocol can include, for example, TCP / IP protocol, UDP / IP protocol, HTTP protocol, HTTPS protocol, etc. Of course, the network protocol can also include, for example, RPC protocol (Remote Procedure Call Protocol) and REST protocol (Representational State Transfer) used on top of the above-mentioned protocols, etc.
[0079] Specifically, detailed descriptions are given respectively through the following various embodiments and application examples.
[0080] To solve the problems of low data access efficiency, low reliability, and low automation in the existing data access methods in distributed systems, an embodiment of a data access method in a distributed system is provided in this application. Refer to Figure 2 The data access method in the distributed system executed by the data access device in the distributed system specifically includes the following content:
[0081] Step 100: Determine the sensitive data in the target data table in the target database in the distributed system currently specified by the target user who does not have the sensitive data access permission.
[0082] In step 100, the user can first submit a query request. The device checks whether the query permission exists. If it exists, the corresponding query view name is extracted and the query is performed in the big data platform, and the query result is returned; if it does not exist, it returns that there is no query permission and ends this query. Then, the data access device in the distributed system determines whether the query request meets the data application qualification within the administrative region. If it does not meet, the application is rejected. If it meets, it determines whether sensitive information needs to be queried.
[0083] It can be understood that the user's access rights to data include: querying non-sensitive information views and querying sensitive information views. When querying non-sensitive information views, the access view filters sensitive information from the query target data, and there can be one or more filtering conditions; similarly, when querying sensitive information views, the access view does not filter sensitive information from the query target data. The user's access rights to views correspond one by one.
[0084] In one or more embodiments of the present application, the target user can be a super administrator user, an administrator user, a general user, etc., and the permissions corresponding to each type of user identity are different. The super administrator user can control the permissions of all data. The first-level administrator user divides different data management permissions according to the organization. For example, for different data sources such as bank data risk, credit, finance and accounting, asset management, and human resources, there are corresponding query approval permissions and view creation permissions. The second-level administrator user has different query approval permissions in different organizations within the scope of each administrative region. The general user belongs to one or more of the above different organizations within the scope and belongs to the scope of one administrative region. When the user has the right to use the data, the user needs to apply for data permissions from the relevant institutional administrator.
[0085] Step 200: According to the deformation rule nested function corresponding to the sensitive data, perform deformation processing on the sensitive data in the target data table.
[0086] In step 200, different fields in different tables can be pre-annotated to form a list of sensitive information. The sensitive information deformation function is uploaded to the big data platform, and a view of the source table is created in the big data platform to form a table view nested with the sensitive information deformation function. There are multiple views of the same source table due to different permission scopes.
[0087] Step 300: Output the deformed sensitive data and the non-sensitive data in the target data table to the target user.
[0088] From the above description, it can be seen that in the data access method provided by the embodiment of the present application in the distributed system, if the target data table contains sensitive data, according to the deformation rule nested function corresponding to the sensitive field of the sensitive data, the sensitive data in the target data table is deformed. This setting does not require the participation of higher-level management personnel, and can automatically achieve the secure access of sensitive data. Furthermore, on the basis of ensuring the security and privacy of data access in the distributed system, it can effectively improve the efficiency and automation of data access in the distributed system, and can effectively improve the reliability of data access in the distributed system to effectively ensure the stable operation of the distributed system.
[0089] In order to improve the effectiveness and reliability of data access in the distributed system, in an embodiment of the data access method provided by the present application in the distributed system, see Figure 3 , before step 100 in the data access method in the distributed system, the following specific content is further included:
[0090] Step 010: Receive a data access request from a target user for a distributed system. The data access request includes the user identifier of the target user, the identifier of a target database in the distributed system, and the identifier of a target data table in the target database.
[0091] Step 020: According to the identifier of the target database and the identifier of the target data table, determine whether the distributed system contains the target data table in the target database. If so, execute Step 030.
[0092] Step 030: Obtain the access conditions of the target user.
[0093] In Step 020, according to the identifier of the target database and the identifier of the target data table, determine whether the distributed system contains the target data table in the target database. If the distributed system does not contain the target data table in the target database, send a notification message to the target user indicating that the distributed system does not contain the target data table in the target database, and end the current process.
[0094] Step 040: Determine whether the target user has the access qualification for the target data table according to the access conditions of the target user. If so, execute Step 050.
[0095] Step 050: Obtain the access permission and sensitive fields of the target data table requested by the target user to access.
[0096] As can be seen from the above description, in the data access method for a distributed system provided by an embodiment of the present application, by automatically determining whether the distributed system contains the target data table in the target database and automatically determining whether the target user has the access qualification for the target data table, the effectiveness and reliability of data access in the distributed system can be effectively improved.
[0097] To provide an effective data basis for determining whether the target user meets the data access qualification within the region for the target database, in an embodiment of the data access method for a distributed system provided by the present application, see Figure 4 , the specific content of Step 030 in the data access method for the distributed system includes the following:
[0098] Step 031: Determine the region field corresponding to the user identifier of the target user from a preset user-condition relationship table.
[0099] Step 032: Determine the region name of the region field corresponding to the target user in a preset region parameter table.
[0100] Specifically, obtain the pre-stored user-condition relationship table, and look up the region field corresponding to the target user in the user-condition relationship table according to the user identifier of the target user. Among them, the user-condition relationship table stores the association relationships between users, regions, and the institutions to which the users belong. Store the user ID, the region code where the user is located, and the institution code of the user. For example: user 01, 1301, 003. Obtain the preset region parameter table, and obtain the region name corresponding to the region field according to the region field corresponding to the target user in the region parameter table. The region parameter table is used to store administrative region information, including provincial, municipal, and county levels. Store: region code, region name. For example: Hebei Branch of the banking system (region code: 1300), Shijiazhuang Branch (region code: 1301).
[0101] As can be seen from the above description, in the data access method of the distributed system provided by the embodiments of the present application, by defining the access condition as the region name, it can provide an effective data basis for determining whether the target user meets the qualification for accessing data within the region of the target database, and further can effectively improve the effectiveness and reliability of determining whether the target user has the qualification to access the target data table according to the access condition of the target user.
[0102] To improve the effectiveness of determining whether the target user has the qualification to access the target data table according to the access condition of the target user, in an embodiment of the data access method of the distributed system provided by the present application, based on step 031 and step 032, see Figure 5 , the specific content of step 040 in the data access method of the distributed system includes the following:[[]]END]]
[0103] Step 041: Determine the region field corresponding to the identifier of the target database from the preset condition-permission relationship table;
[0104] Step 042: Determine the region name of the region field corresponding to the target database in the region parameter table;
[0105] Step 043: Determine whether the target user meets the qualification for accessing data within the region of the target database according to the region name corresponding to the target user and the region name corresponding to the target database.
[0106] Specifically, determine whether the target user meets the qualification for accessing data within the region of the target database according to the region name corresponding to the target user and the region name corresponding to the target database. If not, send a notification message to the target user indicating that the target user does not meet the qualification for accessing data within the region of the target database, and end the current process.
[0107] As can be seen from the above description, in the data access method of the distributed system provided by the embodiments of the present application, by determining whether the target user meets the qualification for accessing data within the region of the target database, the effectiveness and reliability of determining whether the target user has the qualification to access the target data table according to the access conditions of the target user can be further effectively improved.
[0108] To provide an effective data basis for determining whether the target user meets the qualification for accessing data within the region of the target database, in an embodiment of the data access method of the distributed system provided by the present application, refer to Figure 6 in which, step 030 in the data access method of the distributed system may further specifically include the following content:
[0109] Step 033: Determine the organization number to which the user corresponding to the user identifier of the target user belongs from a preset user-condition relationship table.
[0110] Step 034: Determine the organization name of the organization to which the user corresponding to the user identifier of the target user belongs in a preset user organization parameter table.
[0111] Specifically, obtain the pre-stored user-condition relationship table, and search for the organization number to which the target user belongs corresponding to the user identifier of the target user in this user-condition relationship table; obtain the preset user organization parameter table, and obtain the organization name corresponding to the organization number of the user according to the organization number to which the target user belongs in the user organization parameter table.
[0112] Among them, the user organization parameter table is used to store information about different user organizations. It includes department codes and department names. For example: the credit department (001), the risk control department (002), the finance and accounting department (003), etc. in the banking system.
[0113] As can be seen from the above description, in the data access method of the distributed system provided by the embodiments of the present application, by limiting the access condition to the organization name of the user, an effective data basis can be provided for determining whether the target user meets the qualification for accessing the target database by the user organization, and further, the comprehensiveness, effectiveness, and reliability of determining whether the target user has the qualification to access the target data table according to the access conditions of the target user can be further effectively improved.
[0114] To improve the effectiveness of determining whether the target user has the qualification to access the target data table according to the access conditions of the target user, in an embodiment of the data access method of the distributed system provided by the present application, based on steps 033 and 034, refer to Figure 7, step 040 in the data access method in the distributed system further specifically includes the following content:
[0115] Step 044: Determine the organization number to which the user corresponding to the identifier of the target database belongs from the pre-set condition and permission relationship table.
[0116] Step 045: Determine the organization name to which the user corresponding to the organization number of the target database belongs in the user organization parameter table of the user.
[0117] Step 046: Determine whether the target user meets the access qualification of the organization to which the target database belongs according to the organization name to which the target user belongs and the organization name to which the target database belongs.
[0118] Specifically, determine whether the target user meets the access qualification of the organization to which the target database belongs according to the organization name to which the target user belongs and the organization name to which the target database belongs. If not, send a notification message indicating that the target user does not meet the access qualification of the organization to which the target database belongs to the target user, and end the current process.
[0119] As can be seen from the above description, in the data access method in the distributed system provided by the embodiment of the present application, by determining whether the target user meets the access qualification of the organization to which the target database belongs, the comprehensiveness, effectiveness, and reliability of determining whether the target user has the access qualification of the target data table according to the access conditions of the target user can be further effectively improved.
[0120] In order to improve the efficiency and automation of obtaining the access permission and sensitive fields of the target data table of the target user in the target database, in an embodiment of the data access method in the distributed system provided by the present application, see Figure 8 , step 050 in the data access method in the distributed system further specifically includes the following content:
[0121] Step 051: According to the user identifier of the target user, the identifier of the target database in the distributed system, and the identifier of the target data table in the target database, search for the access permission and sensitive fields of the target data table in the target database requested by the target user from the pre-set user and sensitive information relationship table.
[0122] Specifically, obtain the pre-stored user-sensitive information relationship table, and based on the user identifier of the target user, the identifier of the target database in the distributed system, and the identifier of the target data table in the target database, look up the access permission and sensitive fields of the target user for the target data table in the target database in the user-sensitive information relationship table.
[0123] Among them, the user-sensitive information relationship table is used to store the association relationship between sensitive information and users. It stores user ID, database name, table name, permission, and sensitive fields. For example, user 01, database a, table A, permission is 1 (1 - granted permission, 0 - no permission), and sensitive fields are (name, telephone, address, and the field names that need to nest sensitive fields are separated by commas).
[0124] As can be seen from the above description, in the data access method of the distributed system provided by the embodiments of the present application, by using the user-sensitive information relationship table, the efficiency and automation degree of obtaining the access permission and sensitive fields of the target user for the target data table in the target database can be effectively improved, and further, the efficiency and automation degree of data access in the distributed system can be improved.
[0125] In order to improve the efficiency and automation degree of identifying the access permission of the target user, in an embodiment of the data access method of the distributed system provided by the present application, see Figure 9 , step 100 in the data access method of the distributed system specifically includes the following content:
[0126] Step 110: According to the content of the sensitive fields of the target data table requested by the target user to access, determine whether the data requested by the target user to access contains sensitive data. If so, based on the access permission of the target data table requested by the target user, determine whether the target user has the sensitive data access permission to access the sensitive data in the target data table.
[0127] Step 120: If the target user does not have the sensitive data access permission, retrieve the sensitive data in the target data table.
[0128] Specifically, according to the sensitive fields of the target data table in the target database requested by the target user to access, determine whether the data to be accessed by the target user contains sensitive data (for example, if the sensitive field is empty or "0", it means that the data to be accessed by the target user does not contain sensitive data; if the sensitive field is "telephone", it means that the data to be accessed by the target user contains the sensitive data of telephone number).
[0129] As can be seen from the above description, in the data access method of the distributed system provided by the embodiments of the present application, by determining whether the target user has the access permission to the sensitive data according to the sensitive fields and access permissions, the efficiency and automation degree of identifying the access permissions of the target user can be effectively improved, and further, the efficiency and automation degree of data access in the distributed system can be further improved.
[0130] To improve the efficiency and automation degree of the transformation processing of the sensitive data in the target data table, in an embodiment of the data access method of the distributed system provided by the present application, refer to Figure 10 , step 200 in the data access method of the distributed system specifically includes the following contents:
[0131] Step 210: Obtain the transformation indication identifier and transformation rule ID corresponding to the sensitive fields of the target data table from a preset sensitive information list.
[0132] Step 220: Determine whether it is necessary to transform the sensitive fields of the target data table according to the transformation indication identifier. If so, retrieve the transformation rule nested function corresponding to the transformation rule ID from the preset transformation rules.
[0133] Step 230: Perform transformation processing on the sensitive data in the target data table based on the transformation rule nested function.
[0134] Specifically, obtain a preset sensitive information list, and obtain the corresponding transformation indication identifier and transformation rule ID from this sensitive information list according to the sensitive fields of the target data table.
[0135] Among them, the sensitive information list is used to store the table ID, library name, table name, field name, whether to transform (0 - no, 1 - yes), transformation rule ID (the name transformation rule is 1, the mobile phone number transformation rule is 2, the address transformation rule is 3, the email transformation rule is 4, etc.). On the contrary, if a certain field does not involve sensitive information, the whether to transform field is 0 and the transformation rule ID is empty. For example: the table ID is 001, the library name is a, the table name is A, the field name is c1, whether to transform is 1, and the transformation rule is 1. Determine whether it is necessary to transform the sensitive fields of the target data table according to the transformation indication identifier. If so, obtain the preset transformation rules, and obtain the corresponding transformation rule nested function from this transformation rule according to the transformation rule ID corresponding to the target data table.
[0136] Among them, the transformation rules are used to store the transformation rule nested functions corresponding to the transformation logics. Store the transformation rule ID and transformation function. For example, if the name transformation rule is 1, the transformation function is name($x), and $x is the identifier of the field name.
[0137] As can be seen from the above description, in the data access method of the distributed system provided by the embodiments of the present application, by obtaining the deformation indication identifier and the deformation rule ID corresponding to the sensitive fields of the target data table from a preset sensitive information list, and invoking the deformation rule nested function corresponding to the deformation rule ID in the preset deformation rules, the efficiency and automation degree of the deformation processing of the sensitive data in the target data table can be effectively improved, and further, the efficiency and automation degree of data access in the distributed system can be further improved.
[0138] To improve the reliability and automation degree of the output of the sensitive data in the target data table, in an embodiment of the data access method of the distributed system provided by the present application, refer to Figure 11 , the specific content of step 300 in the data access method of the distributed system is as follows:
[0139] Step 310: Generate a data query view containing the deformed sensitive data according to the deformed sensitive data and the non-sensitive data in the target data table, and display the data query view to enable the target user to query.
[0140] As can be seen from the above description, in the data access method of the distributed system provided by the embodiments of the present application, by generating a data query view containing the deformed sensitive data according to the deformed sensitive data and the non-sensitive data in the target data table, the reliability and automation degree of the output of the sensitive data in the target data table can be effectively improved, and the convenience and intuitiveness of the target user's query access to data can be effectively improved, and the user experience of the access user can be effectively improved, and further, the convenience and intelligence degree of data access in the distributed system can be further improved.
[0141] To perform output processing on the accessed data in a differentiated manner, in an embodiment of the data access method of the distributed system provided by the present application, the data access method of the distributed system further specifically includes the following content:
[0142] If it is determined in step 110 that the data requested by the target user to access does not contain sensitive data, or if the target user has the sensitive data access permission, then execute step 400: Generate a data query view according to the data in the target data table, and display the data query view to enable the target user to query.
[0143] As can be seen from the above description, in the data access method provided by the embodiment of the present application for a distributed system, if the data requested by the target user for access does not contain sensitive data, or if the target user has the sensitive data access permission, a data query view is directly generated based on the data in the target data table, which can differentially output the accessed data. Furthermore, on the basis of ensuring data access security, the efficiency and convenience of the target user's querying and accessing data can be further improved, the user experience of the accessing user can be effectively improved, and further the efficiency and convenience of data access in the distributed system can be improved.
[0144] From a software perspective, in order to solve the problems of low data access efficiency, low reliability, and low automation degree in the existing data access methods in a distributed system, the present application provides an embodiment of a data access device in a distributed system for executing all or part of the content of the data access method in the distributed system. Refer to Figure 12 , the data access device in the distributed system specifically includes the following content:
[0145] A data search module 10, configured to determine the sensitive data in the target data table in the target database in the distributed system currently specified by a target user who does not have the sensitive data access permission.
[0146] In the data search module 10, the user can first submit a query request, and the device checks whether the query permission exists. If it exists, the corresponding query view name is extracted, and a query is performed in the big data platform and the query result is returned; if it does not exist, it returns that there is no query permission and ends this query. Then, the data access device in the distributed system determines whether the query request meets the data application qualification within the administrative region. If it does not meet the qualification, the application is rejected; if it meets the qualification, it determines whether sensitive information needs to be queried.
[0147] A data transformation module 20, configured to perform a transformation process on the sensitive data in the target data table according to the transformation rules corresponding to the sensitive data and nested functions.
[0148] In the data transformation module 20, different tables and different field contents can be pre-annotated in advance to form a sensitive information list. The sensitive information transformation function is uploaded to the big data platform, and a view of the source table is created in the big data platform to form a table view nested with the sensitive information transformation function. There are multiple views of the same source table due to the different scopes of permissions.
[0149] A data output module 30, configured to output the transformed sensitive data and the non-sensitive data in the target data table to the target user.
[0150] The embodiment of the data access device in the distributed system provided by this application can specifically be used to execute the processing flow of the embodiment of the data access method in the distributed system in the above embodiment. Its functions will not be elaborated here and can be referred to the detailed description of the above method embodiment.
[0151] As can be seen from the above description, for the data access device in the distributed system provided by the embodiment of this application, if the target data table contains sensitive data, the sensitive data in the target data table is deformed by setting a nested function according to the deformation rule corresponding to the sensitive field of the sensitive data. Without the participation of higher-level management personnel, the secure access of sensitive data can be automatically realized. Furthermore, on the basis of ensuring the security and privacy of data access in the distributed system, the efficiency and automation degree of data access in the distributed system can be effectively improved, and the reliability of data access in the distributed system can be effectively improved to effectively ensure the operation stability of the distributed system.
[0152] To further illustrate this solution, this application also provides a specific application example of the data access method in the distributed system implemented by a data access system applying the fine-grained management function of mass data permissions. The application example of this application manages data permissions at the user-table level based on the big data platform and integrates the user's permission control for sensitive information to form a set of big data permission management control devices. By providing a visual interface, it supports the automatic management and control function of the access permissions of ordinary permission users by the data access device in the distributed system, providing operability for the fine-grained permission control of the mass data in the distributed system. The database user access permission management method and data processing process of the application example of this application are especially applicable to the big data permission management of the banking industry in the Hive data warehouse of the Hadoop platform.
[0153] The execution logic flow of the data access system is shown in Figure 13 , where the control server is used to send the data access request of the target user for the distributed system to the database server, so that the database server determines whether the target user has the sensitive data access permission according to the data access request; the Hive data warehouse or other databases are used to store each data table in each database in the distributed system, so that the database server determines the sensitive data in the target data table in the target database in the distributed system specified by the target user who does not have the sensitive data access permission from the data warehouse.
[0154] The database server therein can specifically be the data access device in the distributed system mentioned in the foregoing embodiment. The specific function of the fine-grained query view provided by this data access device in the distributed system is shown in Figure 14 .
[0155] The specific functions of the data access system are as follows:
[0156] I. Permission control logic
[0157] The permission control logic is applied to the database server and involves user information, conditions (region + professional institution), sensitive information, user-sensitive information relationships, condition-permission relationships, user-condition relationships, and query views Figure 7 for a total of seven modules.
[0158] 1. User information module.
[0159] The user information table stores user information, including basic user information such as user ID, username, user password, user address, and user mobile phone number. For example, the personal information of Zhang San with user ID 001 is stored in the user information table.
[0160] 2. Condition module. It includes the region where the user is located and the professional institution where the user is located.
[0161] (1) Region module.
[0162] The region parameter table stores administrative region information, including provincial, municipal, and county levels. It stores: region number and region name. For example, in the banking system, the Hebei Provincial Branch (region number: 1300) and the Shijiazhuang Branch (region number: 1301).
[0163] (2) Professional institution module.
[0164] The professional institution parameter table stores information on different professional institutions. It includes department code and department name. For example, in the banking system, the credit department (001), the risk control department (002), the finance and accounting department (003), etc.
[0165] 3. Sensitive information permission module. It includes a sensitive information list and transformation rules.
[0166] (1) Sensitive information list.
[0167] It stores the list of database tables and the list of sensitive information that require permission control, that is, it stores table ID, database name, table name, field name, whether to transform (0 - no, 1 - yes), and transformation rule ID (the name transformation rule is 1, the mobile phone number transformation rule is 2, the address transformation rule is 3, the email transformation rule is 4, etc.). Conversely, if a certain field does not involve sensitive information, the whether to transform field is 0 and the transformation rule ID is empty. For example, table ID is 001, database name is a, table name is A, field name is c1, whether to transform is 1, and the transformation rule is 1.
[0168] (2) Transformation rules.
[0169] Stores the transformation rule nested function corresponding to the transformation logic. Stores the transformation rule ID and transformation function. If the name transformation rule is 1, the transformation function is name($x), where $x is the identifier of the field name.
[0170] 4. User-sensitive information relationship table.
[0171] User-sensitive information relationship table, storage table including the relationship between sensitive information and users. Store user ID, library name, table name, permissions, sensitive fields. For example, user 01, library a, table A, permission 1 (1-granted, 0-ungranted), sensitive fields (name, telephome, address, field names that need to be nested with sensitive fields separated by commas).
[0172] 5. Condition-authority relationship table.
[0173] Condition-authority relationship table, which stores the relationship between data tables and regions and professional institutions. It contains the storage name, table name, region field, region field screening logic (backup), and professional institution number. For example: library a, table A, region field (zoneno), region field screening logic (substr(zoneno,2,4)), and professional institution number (003).
[0174] 6. User-condition relationship table.
[0175] User-condition relationship table, which stores the relationship between users, regions, and professional institutions. It stores user ID, user region code, and user institution code. For example: user 01, 1301, 003.
[0176] 7. Query view.
[0177] When a user queries a table, tables 4 / 5 / 6 are associated twice to form a query view statement. For example, user 01 queries table aA, obtains sensitive fields c1, c2, c3 according to the user-sensitive information relationship table, associates the sensitive information module, and nests the sensitive fields into a deformation function. Associate the 6 user condition relationship table with the 5 condition permission relationship table to form the user's regional and professional institution access range conditions for the query table. Form a query view statement.
[0178] 2. Query call
[0179] The query call function is applied to the front-end server, mainly to realize the function call of the above module of the database server, form the query view statement, realize the query data in the massive data permission control database, obtain the returned results and display them.
[0180] The specific process of the data access system implementing the data access method in the distributed system is as follows:
[0181] S1: Receive a data access request from a target user for a distributed system. The data access request contains the user identification of the target user, the identification of a target database in the distributed system, and the identification of a target data table in the target database.
[0182] S2: Based on the identification of the target database and the identification of the target data table, determine whether the target data table in the target database is included in the distributed system. If not, execute step S3; if so, execute step S4.
[0183] S3: Send a notification message to the target user indicating that the target data table in the target database is not included in the distributed system, and end the current process.
[0184] S4: Obtain a pre-stored user-condition relationship table, and search for the region field and the user's affiliated institution number corresponding to the target user in the user-condition relationship table according to the user identification of the target user;
[0185] Among them, the user-condition relationship table stores the association relationships between users, regions, and users' affiliated institutions. It stores user IDs, user region codes, and user institution numbers. For example: user 01, 1301, 003.
[0186] S5: Obtain a preset region parameter table, and obtain the region name corresponding to the region field according to the region field corresponding to the target user in the region parameter table.
[0187] Among them, the region parameter table is used to store administrative region information, including provincial, municipal, and county levels. It stores: region code, region name. For example: Hebei Branch (region code: 1300), Shijiazhuang Branch (region code: 1301) in the banking system.
[0188] S6: Obtain a preset user's affiliated institution parameter table, and obtain the user's affiliated institution name corresponding to the user's affiliated institution number according to the user's affiliated institution number corresponding to the target user in the user's affiliated institution parameter table.
[0189] Among them, the user's affiliated institution parameter table is used to store information on different users' affiliated institutions. It includes department codes and department names. For example: Credit Department (001), Risk Control Department (002), Accounting Department (003), etc. in the banking system.
[0190] S7: Obtain a pre-stored condition-permission relationship table, and search for the region field and the user's affiliated institution number corresponding to the target database in the condition-permission relationship table according to the identification of the target database;
[0191] Among them, the condition-permission relationship table is used to store the association relationships between the data table and the region and the organization to which the user belongs. The repository name, table name, region field, region field filtering logic (backup), and the organization number to which the user belongs are stored. For example: library a, table A, region field (zoneno), region field filtering logic (substr(zoneno,2,4)), and the organization number to which the user belongs (003).
[0192] S8: Obtain a preset region parameter table, and obtain the region name corresponding to the region field according to the region field corresponding to the target database in the region parameter table.
[0193] S9: Obtain a preset parameter table of the organization to which the user belongs, and obtain the name of the organization to which the user belongs corresponding to the organization number to which the user belongs according to the organization number to which the user belongs corresponding to the target database in the parameter table of the organization to which the user belongs.
[0194] Among them, the execution order between the above S4-S6 and S7-S9 can be first-first, last-first, or executed simultaneously, which is specifically set according to the actual application scenario, and this application does not limit this.
[0195] S10: According to the region name corresponding to the target user obtained in S5 and the region name corresponding to the target database obtained in S8, determine whether the target user meets the qualification for accessing data within the region for the target database. If not, execute S11; if so, execute S12.
[0196] S11: Send a notification message to the target user indicating that the target user does not meet the qualification for accessing data within the region for the target database, and end the current process.
[0197] S12: According to the name of the organization to which the target user belongs obtained in S6 and the name of the organization to which the target database belongs obtained in S9, determine whether the target user meets the qualification for accessing the organization to which the target database belongs. If not, execute S13; if so, execute S14.
[0198] S13: Send a notification message to the target user indicating that the target user does not meet the qualification for accessing the organization to which the target database belongs, and end the current process.
[0199] S14: Obtain a pre-stored user-sensitive information relationship table, and according to the user identifier of the target user, the identifier of the target database in the distributed system, and the identifier of the target data table in the target database, search for the access permission and sensitive fields of the target user in the target data table of the target database that the target user requests to access from the user-sensitive information relationship table.
[0200] Among them, the user-sensitive information relationship table is used to store the association relationship between sensitive information and users. It stores user IDs, database names, table names, permissions, and sensitive fields. For example, user 01, database a, table A, permission is 1 (1 - granting permission, 0 - not granting permission), and sensitive fields are (name, telephone, address, and field names that need to nest sensitive fields are separated by commas).
[0201] S15: According to the sensitive fields of the target data table in the target database that the target user requests to access, determine whether the data to be accessed by the target user contains sensitive data (for example, if the sensitive field is empty or "0", it means that the data to be accessed by the target user does not contain sensitive data; if the sensitive field is "telephone", it means that the data to be accessed by the target user contains the sensitive data of telephone number). If not, execute S16; if so, execute S17.
[0202] S16: Retrieve the data in the target data table and generate a corresponding first query view without sensitive data, and display the first query view for the target user to query.
[0203] S17: According to the access permission of the target data table in the target database that the target user requests to access, determine whether the target user has the permission to access the sensitive data in the target data table. If so, execute S18; if not, execute S19.
[0204] S18: Retrieve the data in the target data table and generate a corresponding second query view with sensitive data, and display the second query view for the target user to query.
[0205] S19: Obtain a preset sensitive information list, and obtain the corresponding deformation indication identifier and deformation rule ID from the sensitive information list according to the sensitive fields of the target data table.
[0206] Among them, the sensitive information list is used to store table IDs, database names, table names, field names, whether to deform (0 - no, 1 - yes), and deformation rule IDs (the name deformation rule is 1, the mobile phone number deformation rule is 2, the address deformation rule is 3, the email deformation rule is 4, etc.). On the contrary, if a certain field does not involve sensitive information, the whether to deform field is 0 and the deformation rule ID is empty. For example: table ID is 001, database name is a, table name is A, field name is c1, whether to deform is 1, and the deformation rule is 1.
[0207] S20: Determine whether it is necessary to deform the sensitive fields of the target data table according to the deformation indication identifier. If not, execute S21; if so, execute S22.
[0208] S21 (Same as S18): Retrieve the data in the target data table and generate a corresponding second query view with sensitive data, and display the second query view for the target user to query.
[0209] S22: Obtain the preset transformation rules, and obtain the corresponding transformation rule nested function from the transformation rules according to the transformation rule ID corresponding to the target data table.
[0210] Among them, the transformation rules are used to store the transformation rule nested functions corresponding to the transformation logic. Store the transformation rule ID and the transformation function. For example, if the name transformation rule is 1, the transformation function is name($x), where $x is the identifier of the field name.
[0211] S23: Perform transformation processing on the sensitive fields in the target data table according to the transformation rule nested function corresponding to the target data table, and then retrieve the transformed sensitive fields and the non-sensitive data in the target data table to generate a corresponding third query view containing the transformed sensitive data, and display the third query view for the target user to query.
[0212] Based on this, in a specific example of a user accessing data in a distributed system, the specific process implemented based on the Hive of the Hadoop platform is as follows:
[0213] 1. User query process
[0214] The user submits a query request. The data access device in the distributed system checks whether the query permission exists. If it exists, it extracts the corresponding query view name, queries in the big data platform, and returns the query result; if it does not exist, it returns that there is no query permission and ends this query.
[0215] 2. User permission judgment process
[0216] The user submits a query permission application request. The device judges whether it meets the qualification for data application within the administrative region. If it does not meet, the application is rejected. If it meets, it judges whether it is necessary to query sensitive information.
[0217] The data access device in the distributed system judges whether it is necessary to query sensitive information. If it is not necessary to query, the approval is passed and the user-view relationship mapping is created and returned to the user. If it is necessary to query sensitive information, it judges whether the sensitive information view meets the user's query requirements.
[0218] The data access device in the distributed system judges whether the existing view meets the requirements. If it meets, the approval is passed and the user-view relationship mapping is created. If it does not meet, a new view is created in the big data platform and new sensitive information fields are associated.
[0219] Based on the above technical solution, the data access method implemented by the data access system provided in the application example of the present application manages permissions for massive data at the table-user granularity, and has the following beneficial effects:
[0220] 1. It breaks through the problem that it is impossible to map permissions one by one for massive tables - massive users in the existing mode;
[0221] 2. It realizes user permission management by organization and by administrative region.
[0222] From the hardware level, in order to solve the problems of low data access efficiency, low reliability, and low automation degree in the existing data access method in a distributed system, the present application provides an embodiment of an electronic device for implementing all or part of the content in the data access method in the distributed system. The electronic device specifically includes the following content:
[0223] Figure 15 It is a schematic block diagram of the system composition of the electronic device 9600 according to an embodiment of the present application. As Figure 15 shown, the electronic device 9600 may include a central processing unit 9100 and a memory 9140; the memory 9140 is coupled to the central processing unit 9100. It should be noted that this Figure 15 is exemplary; other types of structures may also be used to supplement or replace this structure to implement telecommunication functions or other functions.
[0224] In one embodiment, the data access function in the distributed system may be integrated into the central processing unit. Among them, the central processing unit may be configured to perform the following controls:
[0225] Step 100: Determine the sensitive data in the target data table in the target database in the distributed system currently specified by the target user who does not have the sensitive data access permission.
[0226] In step 100, the user may first submit a query request, and the device checks whether the query permission exists. If it exists, the corresponding query view name is extracted, and the query is performed in the big data platform and the query result is returned; if it does not exist, it returns that there is no query permission and ends this query. Then, the data access device in the distributed system determines whether the query request meets the data application qualification within the administrative region. If it does not meet, the application is rejected; if it meets, it determines whether it is necessary to query sensitive information.
[0227] Step 200: Perform deformation processing on the sensitive data in the target data table according to the deformation rule nested function corresponding to the sensitive data.
[0228] In step 200, different fields of different tables can be pre-annotated to form a list of sensitive information. The sensitive information transformation function is uploaded to the big data platform, and a view of the source table is created in the big data platform to form a table view nested with the sensitive information transformation function. There are multiple views of the same source table due to different permission scopes.
[0229] Step 300: Output the transformed sensitive data and the non-sensitive data in the target data table to the target user.
[0230] As can be seen from the above description, for the electronic device provided in the embodiment of the present application, if the target data table contains sensitive data, the sensitive data in the target data table is transformed according to the transformation rule nesting function corresponding to the sensitive field of the sensitive data. This setting does not require the participation of higher-level management personnel, and can automatically achieve secure access to sensitive data. Furthermore, on the basis of ensuring the security and privacy of data access in the distributed system, it can effectively improve the efficiency and automation of data access in the distributed system, and can effectively improve the reliability of data access in the distributed system to effectively ensure the operation stability of the distributed system.
[0231] In another embodiment, the data access device in the distributed system can be separately configured from the central processing unit 9100. For example, the data access device in the distributed system can be configured as a chip connected to the central processing unit 9100, and the data access function in the distributed system is realized through the control of the central processing unit.
[0232] As Figure 15 shown, the electronic device 9600 may further include: a communication module 9110, an input unit 9120, an audio processor 9130, a display 9160, and a power supply 9170. It should be noted that the electronic device 9600 does not necessarily have to include all the components shown in Figure 15 ; in addition, the electronic device 9600 may further include components not shown in Figure 15 , and reference can be made to the prior art.
[0233] As Figure 15 shown, the central processing unit 9100 is sometimes also referred to as a controller or an operation control, and may include a microprocessor or other processor devices and / or logic devices. The central processing unit 9100 receives inputs and controls the operations of the various components of the electronic device 9600.
[0234] Among them, the memory 9140 can be, for example, one or more of a buffer, a flash memory, a hard drive, a removable medium, a volatile memory, a non-volatile memory, or other suitable devices. The above information related to failures can be stored, and in addition, a program for executing relevant information can also be stored. And the central processing unit 9100 can execute the program stored in the memory 9140 to implement information storage or processing, etc.
[0235] The input unit 9120 provides an input to the central processing unit 9100. The input unit 9120 is, for example, a key or a touch input device. The power supply 9170 is used to supply power to the electronic device 9600. The display 9160 is used to display display objects such as images and texts. The display can be, for example, an LCD display, but is not limited thereto.
[0236] The memory 9140 can be a solid-state memory. For example, it can be a read-only memory (ROM), a random access memory (RAM), a SIM card, etc. It can also be a memory that stores information even when powered off, can be selectively erased, and has more data. An example of this memory is sometimes called an EPROM, etc. The memory 9140 can also be some other type of device. The memory 9140 includes a buffer memory 9141 (sometimes called a buffer). The memory 9140 can include an application / function storage unit 9142, which is used to store application programs and function programs or the processes for operating the electronic device 9600 through the central processing unit 9100.
[0237] The memory 9140 can also include a data storage unit 9143, which is used to store data, such as contacts, digital data, pictures, sounds, and / or any other data used by the electronic device. The driver storage unit 9144 of the memory 9140 can include various drivers for the communication function of the electronic device and / or for executing other functions of the electronic device (such as a messaging application, an address book application, etc.).
[0238] The communication module 9110 is a transmitter / receiver 9110 that transmits and receives signals via the antenna 9111. The communication module (transmitter / receiver) 9110 is coupled to the central processing unit 9100 to provide an input signal and receive an output signal, which can be the same as in the case of a conventional mobile communication terminal.
[0239] Based on different communication technologies, in the same electronic device, multiple communication modules 9110 can be provided, such as a cellular network module, a Bluetooth module, and / or a wireless local area network module, etc. The communication module (transmitter / receiver) 9110 is also coupled to a speaker 9131 and a microphone 9132 via an audio processor 9130 to provide an audio output via the speaker 9131 and receive an audio input from the microphone 9132, thereby implementing normal telecommunication functions. The audio processor 9130 can include any suitable buffers, decoders, amplifiers, etc. Additionally, the audio processor 9130 is also coupled to a central processor 9100, enabling recording on the device through the microphone 9132 and playing back the sounds stored on the device through the speaker 9131.
[0240] Embodiments of the present application also provide a computer-readable storage medium capable of implementing all the steps in the data access method in the distributed system in the above embodiments. A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, it implements all the steps of the data access method in the distributed system where the execution entity is a server or a client in the above embodiments. For example, when the processor executes the computer program, the following steps are implemented:
[0241] Step 100: Determine the sensitive data in the target data table in the target database in the distributed system currently specified by the target user who does not have the permission to access sensitive data.
[0242] In step 100, the user can first submit a query request. The device checks whether the query permission exists. If it exists, the corresponding query view name is extracted, and the query is performed in the big data platform and the query result is returned; if it does not exist, it returns that there is no query permission and ends the current query. Then, the data access device in the distributed system determines whether the query request meets the data application qualification within the administrative region. If it does not meet the qualification, the application is rejected; if it meets the qualification, it determines whether it is necessary to query sensitive information.
[0243] Step 200: Perform transformation processing on the sensitive data in the target data table according to the transformation rule nested function corresponding to the sensitive data.
[0244] In step 200, different tables and different field contents can be pre-annotated in advance to form a list of sensitive information. The sensitive information transformation function is uploaded to the big data platform, and a view of the source table is created in the big data platform to form a table view nested with the sensitive information transformation function. There are multiple views of the same source table due to different permission scopes.
[0245] Step 300: Output the transformed sensitive data and the non-sensitive data in the target data table to the target user.
[0246] As can be seen from the above description, for the computer-readable storage medium provided by the embodiments of the present application, if the target data table contains sensitive data, the sensitive data in the target data table is deformed by setting a nested function according to the deformation rule corresponding to the sensitive field of the sensitive data. Without the participation of higher-level management personnel, the secure access to sensitive data can be automatically realized. Furthermore, on the basis of ensuring the security and privacy of data access in the distributed system, the efficiency and automation degree of data access in the distributed system can be effectively improved, and the reliability of data access in the distributed system can be effectively improved to effectively ensure the operation stability of the distributed system.
[0247] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, apparatus, or computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer-usable program code. The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (apparatus), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the flows and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one or more of these flows Figure 1 or blocks or a combination of multiple blocks. These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that implements the functions specified in Figure 1 one or more of these flows Figure 1 or blocks or a combination of multiple blocks.
[0248] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one or more of these flows Figure 1 or blocks or a combination of multiple blocks.
[0249] In the present invention, specific embodiments are used to illustrate the principle and implementation manner of the present invention. The description of the above embodiments is only for helping to understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. A data access method in a distributed system, characterized in that, Including: Determine the sensitive data in the target data table in the target database within the specified distributed system by the target user who does not have the access permission to sensitive data; According to the deformation rules nested functions corresponding to the sensitive data, perform deformation processing on the sensitive data in the target data table; Output the deformed sensitive data and the non-sensitive data in the target data table to the target user; Before determining the sensitive data in the target data table in the target database within the specified distributed system by the target user who does not have the access permission to sensitive data, it further includes: Receive a data access request from the target user for the distributed system, where the data access request includes the user identifier of the target user, the identifier of the target database in the distributed system, and the identifier of the target data table in the target database; According to the identifier of the target database and the identifier of the target data table, determine whether the distributed system contains the target data table in the target database. If so, obtain the access conditions of the target user; the access conditions include the association relationship between the user, the region where the user is located, and the organization to which the user belongs; Judge whether the target user has the access qualification for the target data table according to the access conditions of the target user. If so, obtain the access permission and sensitive fields of the target data table requested by the target user to access; The obtaining the access permission and sensitive fields of the target data table requested by the target user to access includes: According to the user identifier of the target user, the identifier of the target database in the distributed system, and the identifier of the target data table in the target database, search for the access permission and sensitive fields of the target data table in the target database requested by the target user from the preset user and sensitive information relationship table; the user and sensitive information relationship table is used to store the association relationship between sensitive information and users, store user ID, database name, table name, permission, sensitive fields, and the field names that need to nest sensitive fields are separated by commas.
2. The data access method in a distributed system according to claim 1, characterized in that, The obtaining the access conditions of the target user includes: Determine the region field corresponding to the user identifier of the target user from the preset user and condition relationship table; Determine the region name of the region field corresponding to the target user in the preset region parameter table.
3. The data access method in a distributed system according to claim 2, characterized in that, The judging whether the target user has the access qualification for the target data table according to the access conditions of the target user includes: Determine the region field corresponding to the identifier of the target database from the preset condition and permission relationship table; Determine the region name of the region field corresponding to the target database in the region parameter table; Judge whether the target user meets the data access qualification within the region for the target database according to the region name corresponding to the target user and the region name corresponding to the target database.
4. The data access method in a distributed system according to claim 1, characterized in that, The obtaining the access conditions of the target user includes: Determine the organization number to which the target user belongs corresponding to the user identifier of the target user from the preset user and condition relationship table; Determine the organization name to which the target user belongs corresponding to the organization number to which the target user belongs in the preset organization parameter table for the target user.
5. The data access method in a distributed system according to claim 4, characterized in that, Determining whether the target user has access qualification to the target data table according to the access conditions of the target user includes: Determining the organization number to which the user belongs corresponding to the identifier of the target database from a preset condition and permission relationship table; Determining the organization name to which the user belongs corresponding to the organization number of the user to which the target database belongs in the user organization parameter table of the user; Judging whether the target user meets the access qualification of the organization to which the user belongs for the target database according to the organization name to which the target user belongs and the organization name to which the target database belongs.
6. The data access method in a distributed system according to any one of claims 1 to 5, characterized in that, Determining the sensitive data in the target data table in the target database in the distributed system currently specified by the target user who does not have the sensitive data access permission includes: Judging whether the data requested by the target user to access contains sensitive data according to the content of the sensitive fields of the target data table requested by the target user to access. If so, judging whether the target user has the sensitive data access permission to access the sensitive data in the target data table based on the access permission of the target data table requested by the target user to access; If the target user does not have the sensitive data access permission, retrieving the sensitive data in the target data table.
7. The data access method in a distributed system according to claim 6, characterized in that, Performing transformation processing on the sensitive data in the target data table according to the transformation rule nested function corresponding to the sensitive data includes: Obtaining the transformation indication identifier and the transformation rule ID corresponding to the sensitive field of the target data table from a preset sensitive information list; Judging whether it is necessary to transform the sensitive field of the target data table according to the transformation indication identifier. If so, retrieving the transformation rule nested function corresponding to the transformation rule ID in the preset transformation rules; Performing transformation processing on the sensitive data in the target data table based on the transformation rule nested function.
8. The data access method in a distributed system according to claim 1, characterized in that, Outputting the transformed sensitive data and the non-sensitive data in the target data table to the target user includes: Generating a data query view containing the transformed sensitive data according to the transformed sensitive data and the non-sensitive data in the target data table, and displaying the data query view for the target user to query.
9. The data access method in a distributed system according to claim 6, characterized in that, Further includes: If the data requested by the target user to access does not contain sensitive data, or if the target user has the sensitive data access permission, generating a data query view according to the data in the target data table, and displaying the data query view for the target user to query.
10. A data access device in a distributed system, characterized in that, Includes: A data search module for determining the sensitive data in the target data table in the target database in the distributed system currently specified by the target user who does not have the sensitive data access permission; A data transformation module for performing transformation processing on the sensitive data in the target data table according to the transformation rule nested function corresponding to the sensitive data; A data output module for outputting the transformed sensitive data and the non-sensitive data in the target data table to the target user; Before determining the sensitive data in the target data table in the target database within the specified distributed system for which the target user does not have access rights to sensitive data, it further includes: Receiving a data access request from the target user for the distributed system, where the data access request includes the user identifier of the target user, the identifier of the target database in the distributed system, and the identifier of the target data table in the target database; Based on the identifier of the target database and the identifier of the target data table, determining whether the distributed system contains the target data table in the target database. If so, obtaining the access conditions of the target user; the access conditions include the association relationship between the user, the user's location, and the user's affiliated institution; Determining whether the target user has the access qualification for the target data table based on the access conditions of the target user. If so, obtaining the access rights and sensitive fields of the target data table requested by the target user to access; The obtaining of the access rights and sensitive fields of the target data table requested by the target user to access includes: Based on the user identifier of the target user, the identifier of the target database in the distributed system, and the identifier of the target data table in the target database, searching for the access rights and sensitive fields of the target data table in the target database requested by the target user from a preset user and sensitive information relationship table; the user and sensitive information relationship table is used to store the association relationship between sensitive information and users, and stores user ID, database name, table name, permissions, and sensitive fields. The field names that need to nest sensitive fields are separated by commas.
11. A data access system, characterized in that, It includes: A control server, a database server, and a data warehouse; The database server is used to execute the data access method in the distributed system according to any one of claims 1 to 9; The control server is used to send the data access request of the target user for the distributed system to the database server, so that the database server determines whether the target user has access rights to sensitive data according to the data access request; The data warehouse is used to store each data table in each database in the distributed system, so that the database server determines the sensitive data in the target data table in the target database within the specified distributed system for which the target user does not have access rights to sensitive data from the data warehouse.
12. An electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the data access method in the distributed system according to any one of claims 1 to 9.
13. A computer-readable storage medium, on which a computer program is stored, characterized in that, When the computer program is executed by the processor, it implements the data access method in the distributed system according to any one of claims 1 to 9.
Citation Information
Patent Citations
Sensitive information desensitization method, system and device, and readable storage medium
CN107704770A
A remote collection method and collection device for database performance
CN109815081A
Partition permission management method based on distributed database
CN112257097A