A log desensitization method, system, electronic device and storage medium
By intercepting user's data printing requests, extracting annotations of data to be desensitized and performing desensitization based on preset configuration rules, the problem of insufficient desensitization of sensitive data during log printing in the prior art is solved, and efficient and accurate personal information privacy protection is achieved.
Patent Information
- Application Number
- CN202110695741.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-06-23
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2041-06-23
AI Technical Summary
The prior art desensitization of sensitive data during log printing is not fast and accurate enough, and it is easy to miss key fields, resulting in personal information privacy and security risks.
By intercepting the user's data printing request, extracting the annotations of the data to be desensitized, obtaining the type and attribute values of the target object, desensitizing the attribute values based on preset configuration rules, and sending the desensitized data to the printing interface.
It realizes the rapid and accurate desensitization of sensitive data when log printing, avoids personal information privacy data leakage, ensures privacy security, and improves the efficiency and accuracy of desensitization operations.
Smart Images

Figure CN113297622B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and in particular to a log desensitization method, system, electronic device and storage medium. Background Art
[0002] With the rapid development of informatization, computer networks have extended to all areas of work and life. More and more organizations or hackers collect and use personal information, and there have also been illegal collection, abuse, and leakage of personal information, resulting in serious threats to the privacy and security of personal information, especially in the financial field, which directly involves the security of funds. Therefore, when printing the logs of the business system, some sensitive data including name, ID number, bank card number, and mobile phone number need to be desensitized to hide personal information and ensure privacy security.
[0003] In the prior art, a hard numbering method is usually used to desensitize sensitive data in log printing, that is, manual code processing is performed on each sensitive data in the log printing. This not only requires a large amount of code support for repetitive actions, but is also not easy to read and maintain the code, and is prone to missing key fields, resulting in personal information not being hidden, causing personal information privacy and security risks.
[0004] Therefore, how to quickly and accurately desensitize sensitive data when printing logs to ensure the privacy and security of personal information is a major problem that needs to be solved. Summary of the invention
[0005] The purpose of the present invention is to provide a log desensitization method, system, electronic device and storage medium to solve the problems existing in the prior art.
[0006] To achieve the above object, the present invention provides a log desensitization method, the method comprising:
[0007] Intercepting a data printing request sent by a user, and extracting a first annotation in the data printing request; wherein the first annotation is used to characterize the data to be desensitized in the data printing request;
[0008] Acquire the data to be desensitized, and extract the second annotation and the third annotation in the data to be desensitized; wherein the second annotation is used to characterize the type of the target object in the data to be desensitized, and the third annotation is used to characterize the attribute value of the target object in the data to be desensitized;
[0009] Determining a preset configuration rule corresponding to the target object based on the type of the target object;
[0010] After desensitizing the attribute value based on the configuration rule, the data printing request is sent to the printing interface to execute the printing operation.
[0011] Preferably, the determining the preset configuration rule corresponding to the target object based on the type of the target object further includes:
[0012] The configuration rule corresponding to the type of the target object is searched from a preset configuration strategy area; wherein the configuration strategy area pre-stores a correspondence between the type of each target object and the corresponding configuration rule.
[0013] Preferably, the configuration strategy area is constructed by the following steps:
[0014] Compile the data to be desensitized into an initial bytecode file, and run the initial bytecode file;
[0015] Recursively parsing the running initial bytecode file using a bytecode manipulation framework to obtain a target object set, and storing the target object set in the configuration strategy area; wherein the target object set includes the type of the target object and a corresponding index value, and the index value is used to represent the number of the type of the target object;
[0016] Calling a preset configuration rule corresponding to the target object according to the index value;
[0017] The correspondence between the target object set and the corresponding configuration rules is stored in the configuration strategy area.
[0018] Preferably, compiling the data to be desensitized into an initial bytecode file and running the initial bytecode file further includes:
[0019] Based on the first annotation, the data to be desensitized is parsed to obtain a parsing result;
[0020] Reading the second annotation and the third annotation from the parsing result to obtain a data model file;
[0021] Setting the data model file as a source code file, and calling a preset compiler to compile the source code file into the initial bytecode file;
[0022] The initial bytecode file is loaded through a preset virtual machine, and the initial bytecode file is converted into machine code and executed.
[0023] Preferably, the bytecode manipulation framework is used to recursively parse the running initial bytecode file to obtain a target object set, and the target object set is stored in the configuration strategy area; wherein the target object set includes the type of the target object and the corresponding index value, the index value is used to represent the number of the type of the target object, and also includes:
[0024] Using a bytecode manipulation framework to load the initial bytecode file;
[0025] Recursively parsing the initial bytecode file to obtain types of multiple target objects;
[0026] Setting corresponding index values according to the types of the plurality of target objects, and generating a plurality of target object sets according to the types of the plurality of target objects and the corresponding index values;
[0027] The plurality of target object sets are stored in the configuration strategy area respectively.
[0028] Preferably, the data printing request includes public data and / or data to be desensitized, the data to be desensitized is used to represent private data containing personal information, and the public data is used to represent data not containing personal information;
[0029] The method of intercepting a data printing request sent by a user and extracting a first annotation in the data printing request, wherein the first annotation is used to characterize the data to be desensitized in the data printing request, further comprising:
[0030] If the first annotation is not extracted from the data printing request, the data printing request is sent to a printing interface to perform a printing operation.
[0031] Preferably, the configuration rule includes a desensitization rule and a recovery rule, and the attribute value is desensitized based on the desensitization rule;
[0032] After desensitizing the attribute value based on the configuration rule, sending the data print request to the print interface, and performing the print operation, the method further includes:
[0033] After the desensitized value is restored based on the restoration rule, it is stored in the cache.
[0034] To achieve the above object, the present invention also provides a log desensitization system, comprising:
[0035] An interception unit, configured to intercept a data printing request sent by a user, and extract a first annotation in the data printing request; wherein the first annotation is used to characterize the data to be desensitized in the data printing request;
[0036] An acquisition unit, used for acquiring the data to be desensitized, and extracting a second annotation and a third annotation in the data to be desensitized; wherein the second annotation is used to characterize the type of the target object in the data to be desensitized, and the third annotation is used to characterize the attribute value of the target object in the data to be desensitized;
[0037] A determination unit, configured to determine a preset configuration rule corresponding to the target object based on the type of the target object;
[0038] The desensitizing unit is used to desensitize the attribute value based on the configuration rule, and then send the data printing request to the printing interface to execute the printing operation.
[0039] To achieve the above object, the present invention further provides an electronic device, the electronic device comprising:
[0040] a memory storing at least one instruction; and
[0041] The processor executes the instructions stored in the memory to implement any one of the log desensitization methods described above.
[0042] To achieve the above objectives, the present invention also provides a computer-readable storage medium, in which at least one instruction is stored, and the at least one instruction is executed by a processor in an electronic device to implement the log desensitization method described in any one of the above.
[0043] Beneficial effects of the above technical solution:
[0044] The log desensitization method, system, electronic device and storage medium provided by the present invention, when the input port of the printing interface monitors the user's data printing request, the data printing request sent by the user is intercepted by an interceptor, the first annotation in the data printing request is extracted, the data to be desensitized is obtained, the second annotation and the third annotation in the data to be desensitized are extracted, the preset configuration rule corresponding to the target object is determined based on the type of the target object, and the attribute value is desensitized based on the configuration rule, and the data printing request is sent to the printing interface, and the printing operation is performed, and the output result is the log data that hides the privacy data such as personal information. After the printing operation is completed, the desensitized value is restored based on the recovery rule and stored in the cache, which is convenient for later users to call or query. There is no need to manually code each sensitive data in the log printing during the desensitization process, which effectively prevents the leakage of personal information privacy data and ensures privacy security. At the same time, by matching the regular expression of the public data one by one, it is prevented that the omitted data to be desensitized is not recognized, and the accuracy of desensitization is ensured.
[0045] The present invention automatically generates a target object set through a bytecode manipulation framework (ASM), and uses a recursive algorithm to traverse all data in a data model file to avoid missing data to be desensitized. By caching the correspondence between each target object set and the corresponding configuration rule in a configuration strategy area, when querying the corresponding configuration rule, it can be directly searched from the configuration strategy area, thereby improving the efficiency and accuracy of the data desensitization operation. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] Figure 1Schematic diagram a of the flow chart of the log desensitization method embodiment 1 of the present invention;
[0047] Figure 2 Schematic diagram b of the flow chart of the log desensitization method embodiment 1 of the present invention;
[0048] Figure 3 This is a functional unit diagram of a log desensitization system according to Embodiment 2 of the log desensitization method of the present invention;
[0049] Figure 4 This is a schematic diagram of the structure of an electronic device according to Embodiment 3 of the log desensitization method of the present invention. DETAILED DESCRIPTION
[0050] In order to make the purpose, technical scheme and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0051] It should be noted that the descriptions of "first", "second", etc. in the embodiments of the present application are only for descriptive purposes and cannot be understood as indicating or implying their relative importance or implicitly indicating the number of technical features indicated. Therefore, the features defined as "first" and "second" may explicitly or implicitly include at least one of the features. In addition, the technical solutions between the various embodiments can be combined with each other, but they must be based on the ability of ordinary technicians in the field to implement them. When the combination of technical solutions is contradictory or cannot be implemented, it should be deemed that such combination of technical solutions does not exist and is not within the scope of protection required by this application.
[0052] In the description of the present application, it should be understood that the numerical labels before the steps do not indicate the order in which the steps are executed, but are only used to facilitate the description of the present application and to distinguish each step, and therefore should not be understood as a limitation on the present application.
[0053] Embodiment 1
[0054] See also Figure 1 , which is a flow chart a of the log desensitization method embodiment 1 of this embodiment. As can be seen from the figure, it specifically includes the following steps:
[0055] S100: intercepting a data printing request sent by a user, and extracting a first annotation in the data printing request; wherein the first annotation is used to characterize the data to be desensitized in the data printing request.
[0056] In this embodiment, the data printing request is a log data printing request. Network devices, systems, service programs, etc., will generate an event record called a log when they are in operation, and each line of the log records the description of relevant operations such as date, time, user, and action. In order to facilitate understanding of the operating status of network devices, systems, service programs, etc., the logs in the operating system of network devices, systems, service programs, etc. can be printed out to intuitively track the operation of network devices, systems, service programs, etc., and facilitate intuitively finding the cause of the error when a fault occurs, saving a lot of repair time.
[0057] In an exemplary embodiment, the data printing request includes public data and / or data to be desensitized. The desensitized data is used to represent private data containing personal information (e.g., name, ID number, mobile phone number, address, etc.), and the public data is used to represent data that does not contain personal information.
[0058] The user selects log data (public data and / or data to be desensitized) and sends a data print request to the input port of the print interface to print the log data. When the input port of the print interface monitors the data print request of the user, the interceptor is called to intercept the data print request and identify the log data in the data print request to prevent the log data from being directly input into the print interface for print output, and to avoid the log data containing the data to be desensitized being directly output without desensitization, thereby causing personal information privacy security risks.
[0059] When the interceptor intercepts the data printing request, the log data is automatically identified. If the interceptor identifies the first annotation in the data printing request, it indicates that the data printing request contains data to be desensitized, and the interceptor intercepts the data printing request containing the data to be desensitized at the input port of the printing interface to avoid direct output of the data to be desensitized, which may lead to leakage of personal information privacy.
[0060] If the interceptor does not recognize the first annotation from the data printing request, it indicates that the data printing request does not contain the data to be desensitized but only contains public data. Then, the data printing request that does not contain the data to be desensitized is sent to the input port of the printing interface through the interceptor, and the printing operation is executed and then output.
[0061] S200: Obtain the data to be desensitized, and extract the second annotation and the third annotation in the data to be desensitized; wherein the second annotation is used to characterize the type of the target object in the data to be desensitized, and the third annotation is used to characterize the attribute value of the target object in the data to be desensitized.
[0062] In this embodiment, the data to be desensitized includes multiple types of target objects. Among them, a target object may include multiple attribute values, but one attribute value corresponds to only one target object. It can be understood that the types of the target objects may include: name class, mobile phone number class, address class, etc.; the attribute values of the target objects corresponding to the name class may include: Zhang San, Wang Xiaohua, etc., the attribute values of the target objects corresponding to the mobile phone number class may include: 13355667788, 18866223399, etc., and the attribute values of the target objects corresponding to the address class may include: 999, Building 9, No. 99, Jiangsu Road, Changning District, Shanghai, 888, Building 8, No. 88, Xueyuan Road, Haidian District, Beijing, etc. That is, a target object of the name class includes Zhang San and Wang Xiaohua, but Zhang San can only correspond to the target object of the name class, and cannot correspond to the target object of the mobile phone number class.
[0063] In an exemplary embodiment, when the interceptor intercepts the data printing request and extracts the first annotation, the data to be desensitized is obtained according to the first annotation, and the second annotation and the third annotation in the data to be desensitized are extracted by the interceptor to obtain the type of each target object in the data to be desensitized and the corresponding attribute value. Preferably, the present invention uses an AOP (aspect-oriented programming) interceptor. The characteristics of object-oriented programming are inheritance, polymorphism and encapsulation, allowing different classes to design different methods, facilitating the code to be dispersed into classes, reducing the coupling between various types of code, and improving the reusability of classes. No specific restrictions are made here.
[0064] Specifically, the above-mentioned annotation information can be marked in advance by business development personnel, and according to different businesses, business development personnel can customize the data to be desensitized. Usually, different annotation information is used for marking according to the different meanings of the annotation information, so as to distinguish when extracting the annotation information. For example: the first annotation uses @OffSensitive, which is marked on the data to be desensitized, and is used to represent the data to be desensitized in the data printing request; the second annotation uses @Shield, which is marked on the target object, and is used to represent the type of the target object in the data to be desensitized; the third annotation uses @NShield, which is marked on the attribute value, and is used to represent the attribute value of the target object in the data to be desensitized.
[0065] Preferably, since the above-mentioned annotation information is marked in advance by business development personnel, there may be omissions or insufficient markings, resulting in the interceptor being unable to obtain all the data to be desensitized in the log data. For other data that are not marked with annotation information (here it can be understood as the above-mentioned public data), regular expression rules are used to match one by one. When suspected data to be desensitized is identified, the data printing request is suspended, and an exception message is sent to the user's sending end to remind the user that there is unmarked data to be desensitized in the selected log data. The user queries the unmarked data to be desensitized according to the exception information, and after marking it with the annotation information, the data printing request can be continued. By matching the public data one by one with regular expressions, it is prevented that the omitted data to be desensitized is not identified, resulting in personal information not being hidden, causing personal information privacy security risks.
[0066] S300: Determine a preset configuration rule corresponding to the target object based on the type of the target object.
[0067] In an exemplary embodiment, the configuration rule corresponding to the type of the target object is found from a preset configuration strategy area; wherein the configuration strategy area pre-stores the correspondence between the types of each target object and the corresponding configuration rule.
[0068] See also Figure 2 , which is a flow chart b of the log desensitization method embodiment 1 of this embodiment. It can be seen from the figure that the construction steps of the configuration strategy area include:
[0069] S301: Compile the data to be desensitized into an initial bytecode file, and run the initial bytecode file.
[0070] During the compilation process, the original data structure of the data to be desensitized will be abstracted, and a batch of data models will be created to generate data model files. Among them, the data models in the data model files will have the functions of obtaining and setting data. For example: obtaining multiple target objects, numbering multiple target objects, and distinguishing the types of multiple target objects according to the numbers.
[0071] Specifically, based on the first annotation, the data to be desensitized is parsed to obtain the parsing result, the second annotation and the third annotation are read from the parsing result, each target object is obtained, the original data structure of each target object is abstracted, a batch of data models are created, and a data model file is generated. The data model file can use a .java type template file. Among them, if the original data structure of two or more target objects is the same, a data model is created, and different data models are created for different original data structures. It can be understood that: among the three target objects, two are target objects of the name class, then a data model of the name class is created according to the original data structure of the two target objects of the name class, and the other is a target object of the mobile phone number class, then another data model of the mobile phone number class is created according to the original data structure of the target object of the mobile phone number class.
[0072] At the same time, the data model file is set as a source code file, and a preset compiler is called to compile the source code file into the initial bytecode file, the initial bytecode file is loaded through a preset virtual machine, and finally the initial bytecode file is converted into machine code and executed. Among them, the preset compiler is a javac compilation tool (for example: a front-end compiler), the file extension of the initial bytecode file is .class, the preset virtual machine is a java virtual machine (JVM), and the machine code that can be recognized by the java virtual machine is binary data, which is not specifically limited here.
[0073] In an exemplary embodiment, the source code file is compiled into the initial bytecode file using a front-end compiler, which specifically includes the following steps:
[0074] (1) Lexical and grammatical analysis. The lexical analyzer and grammatical analyzer in the front-end compiler convert the character stream in the source code file into a set of tokens, and construct an abstract syntax tree based on the set of tokens. The token is the smallest element in the compilation process; each node of the abstract syntax tree is used to represent a grammatical structure in the source code file. For example: package, type, operator, modifier, etc.
[0075] (2) Filling the symbol table. The symbol table is a table constructed by multiple sets of symbol addresses and symbol information. It can be understood that the symbol information is the attribute value (variable) of the target object, the symbol address is the type of the target object, and the symbol table stores the one-to-one correspondence between the target object attribute value and the corresponding type.
[0076] (3) Annotation processing: The second annotation and the third annotation are parsed by the annotation processor in the front-end compiler, and the corresponding information (attribute value and type of the target object) is read from the abstract syntax tree.
[0077] (4) Semantic analysis: Based on the symbol table, check whether each variable has a corresponding data structure (type).
[0078] (5) Generate bytecode file: Convert the abstract syntax tree and symbol table into bytecode and output .class file.
[0079] After the bytecode file is generated, the .class file is converted into machine code through a JIT compiler (Just-in-time compiler) so that a Java Virtual Machine (JVM) can run the machine code.
[0080] S302: Use a bytecode manipulation framework to recursively parse the running initial bytecode file to obtain a target object set, and store the target object set in the configuration strategy area; wherein the target object set includes the type of the target object and the corresponding index value; the index value is used to represent the number of the type of the target object.
[0081] Among them, the initial bytecode file is used to represent the file abstractly created from the original data structure of the data to be desensitized, including multiple data models with acquisition functions and data setting functions. For example: obtaining the type of the target object is to dynamically create an object with similar functions through bytecode, and expand more functions to the object. It can be understood that after obtaining multiple target objects, classifying the multiple target objects, defining a new type for the classified target objects, numbering different types of target objects, and automatically identifying the type of the target object according to the number.
[0082] In this embodiment, the number is set as the index value of the type of the target object, and a target object set is generated according to the type of the target object and the corresponding index value, and stored in the configuration strategy area. If there are multiple types of target objects in the data to be desensitized, they can be distinguished by the index value. For example: the index value of the target object of the name type is 1, and the index value of the target object of the mobile phone number type is 2.
[0083] Specifically, a bytecode manipulation framework is used to load the initial bytecode file, and the initial bytecode file is recursively parsed to obtain the types of multiple target objects, and then corresponding index values are set according to the types of the multiple target objects, and multiple target object sets are generated according to the types of the multiple target objects and the corresponding index values, and finally the multiple target object sets are respectively stored in the configuration strategy area.
[0084] S303: Calling a preset configuration rule corresponding to the target object according to the index value. In an exemplary embodiment, the configuration rules are numbered in advance, and the preset configuration rule corresponding to the target object is called according to the index value. For example, the configuration rule of the name type is numbered 1, and the index value of the target object of the name type is also 1. The configuration rule corresponding to the target object can be called by matching the number with the index value.
[0085] In an exemplary embodiment, at least one desensitization rule corresponding to the index value is searched from a preset configuration file according to the index value to form the configuration rule. The configuration file pre-stores the correspondence between each index value and the corresponding desensitization rule. For example, an Excel file or the like can be used to store the correspondence between each index value and the corresponding desensitization rule, and multiple desensitization rules corresponding to the index value can be searched from the Excel file.
[0086] Or, each desensitization rule is numbered in advance, and multiple desensitization rules corresponding to the target object are called according to the index value. For example, the desensitization rules of the mobile phone number type include: masking algorithm desensitization rule 1a and pseudonym algorithm desensitization rule 1b, and the index value of the target object of the name type is 1, then the multiple desensitization rules corresponding to the target object can be called by matching the number 1 with the first characters of 1a and 1b.
[0087] It can be understood that there is more than one desensitization rule corresponding to an index value, that is, a target object, and different desensitization rules are adapted according to different desensitization requirements. For example: the type of the target object is a mobile phone number. When a running error requires checking the log data for printing, the masking algorithm can be selected as the adapted desensitization rule; when an outsourced or third-party service provider needs log data or the test development environment needs to maintain the relationship between fields for printing, the pseudonym algorithm can be selected as the adapted desensitization rule, that is, randomly generate a virtual mobile phone number that complies with the mobile phone number encoding rules to ensure the normal operation of the business.
[0088] For the same target object type, the business personnel select the corresponding desensitization rules based on the printing requirements. For example, when the printing requirement is to check the log data for printing due to a running error, the masking algorithm is used as the adapted desensitization rule; when the printing requirement is that the outsourcing or third-party service provider needs log data or the test development environment needs to maintain the relationship between fields for printing, the pseudonym algorithm is used as the adapted desensitization rule.
[0089] Specifically, the data printing request is preset to be marked according to different printing requirements, and the corresponding desensitization rules are adapted according to the marks according to the different printing requirements. For example: when the printing requirement is to check the log data for printing due to a running error, the data printing request is marked with a; when the log data is needed for outsourcing or a third-party service provider or the test development environment needs to maintain the relationship between fields for printing, the data printing request is marked with b. After obtaining the corresponding multiple desensitization rules according to the index value, one is selected from the multiple desensitization rules as the adapted desensitization rule according to the mark of the data printing request to form the configuration rule.
[0090] S304: storing the correspondence between the target object set and the corresponding configuration rules in the configuration strategy area.
[0091] The target object set is automatically generated through the bytecode manipulation framework (ASM), and a recursive algorithm is used to traverse all data in the data model file to avoid missing the data to be desensitized. By caching the correspondence between each target object set and the corresponding configuration rules in the configuration strategy area, when querying the corresponding configuration rules, it can be directly searched from the configuration strategy area, which improves the efficiency and accuracy of data desensitization operations.
[0092] S400: After desensitizing the attribute value based on the configuration rule, the data printing request is sent to the printing interface to execute the printing operation.
[0093] In an exemplary embodiment, the configuration rules include desensitization rules and recovery rules. The attribute value is desensitized based on the desensitization rules. The desensitization rules can preset processing rules for each desensitized data according to business needs. For example, taking the masking algorithm desensitization rule as an example, the first M bits and the last N bits of the attribute value data in the desensitized data can be retained, and the other bits of the attribute value data in the desensitized data can be replaced by the corresponding ones, where M and N are both integers greater than 1. For example: for the desensitization rule for the target object of the mobile phone number type, M is 3, N is 4, the corresponding one is *, and the attribute value is 13355667788, then the desensitized value is 133****7788.
[0094] After desensitization is completed, the data printing request is sent to the printing interface to execute the printing operation. The output result is the log data that hides private data such as personal information, effectively preventing the leakage of personal information and private data and ensuring privacy security.
[0095] After the printing operation is completed, the desensitized value is restored based on the recovery rule and stored in the cache. Among them, the recovery rule corresponds to the desensitization rule, and when desensitization is performed based on the desensitization rule, the corresponding recovery rule is automatically generated. For example: the desensitization rule for the target object of the mobile phone number type is: M is 3, N is 4, the match is *, the attribute value is 13355667788, then the desensitized value is 133****7788. The automatically generated recovery rule is: retain the first 3 digits and the last 4 digits of the attribute value data in the desensitized data, and replace the other digits in the desensitized value data with 5566 to restore the desensitized value, and store it in the cache for later users to call or query.
[0096] Embodiment 2
[0097] like Figure 3 As shown, it is a functional unit diagram of the log desensitization system of Example 2 of the log desensitization method of this embodiment.
[0098] The system includes an interception unit 31, an acquisition unit 32, a determination unit 33 and a desensitization unit 34. The unit referred to in the present invention refers to a series of computer program segments that can be executed by a processor and can complete fixed functions, which are stored in a memory. In this embodiment, the functions of each unit will be described in detail in subsequent embodiments.
[0099] The interception unit 31 is used to intercept a data printing request sent by a user and extract a first annotation in the data printing request; wherein the first annotation is used to represent the data to be desensitized in the data printing request.
[0100] In an exemplary embodiment, when the input port of the printing interface monitors the data printing request of the user, the interception unit 31 is called to intercept the data printing request, and the log data in the data printing request is identified to prevent the log data from being directly input into the printing interface for printout, and to avoid the risk of personal information privacy security caused by the direct output of log data containing data to be desensitized without desensitization.
[0101] The acquisition unit 32 is used to acquire the data to be desensitized and extract the second annotation and the third annotation in the data to be desensitized; wherein the second annotation is used to characterize the type of the target object in the data to be desensitized, and the third annotation is used to characterize the attribute value of the target object in the data to be desensitized.
[0102] In an exemplary embodiment, when the interception unit 31 intercepts the data printing request and extracts the first annotation, the data to be desensitized is acquired through the acquisition unit 32, and the second annotation and the third annotation in the data to be desensitized are extracted through the interception unit 31, and the type of each target object in the data to be desensitized and the corresponding attribute value are acquired through the acquisition unit 32.
[0103] If the acquisition unit 32 does not identify the first annotation from the data printing request, it indicates that the data printing request does not contain the data to be desensitized but only contains public data. Then, the data printing request that does not contain the data to be desensitized is sent to the input port of the printing interface and output after the printing operation is executed.
[0104] The determining unit 33 is configured to determine a preset configuration rule corresponding to the target object based on the type of the target object.
[0105] In an exemplary embodiment, the determination unit 33 searches for the configuration rule corresponding to the type of the target object from a preset configuration strategy area; wherein the configuration strategy area pre-stores the correspondence between the types of each target object and the corresponding configuration rule.
[0106] Specifically, the data to be desensitized is compiled into an initial bytecode file, and the initial bytecode file is run; a bytecode manipulation framework is used to recursively parse the initial bytecode file to obtain a target object set, and the target object set is stored in the configuration strategy area; wherein the target object set includes the type of the target object and the corresponding index value; the index value is used to characterize the number of the type of the target object; the preset configuration rule corresponding to the target object is called according to the index value; and the correspondence between the target object set and the corresponding configuration rule is stored in the configuration strategy area.
[0107] The desensitizing unit 34 is used to desensitize the attribute value based on the configuration rule, and then send the data printing request to the printing interface to execute the printing operation.
[0108] In an exemplary embodiment, after the desensitization is completed, a data printing request is sent to the printing interface to execute the printing operation, and the output result is the log data that hides the privacy data such as personal information, effectively preventing the leakage of personal information privacy data and ensuring privacy security. At the same time, after the printing operation is completed, the desensitized value is restored based on the recovery rule and stored in the cache, which is convenient for later users to call or query.
[0109] Embodiment 3
[0110] like Figure 4, which is a schematic diagram of the structure of an electronic device of Example 3 of the log desensitization method of this embodiment.
[0111] In an exemplary embodiment, the electronic device 4 includes, but is not limited to, a memory 41, a processor 42, and a computer program stored in the memory 41 and executable on the processor, such as a log desensitization program. It can be understood by those skilled in the art that the schematic diagram is only an example of an electronic device and does not constitute a limitation on the electronic device. The electronic device may include more or fewer components than shown in the figure, or may combine certain components, or different components. For example, the electronic device may also include input and output devices, network access devices, buses, etc.
[0112] The memory 41 includes at least one type of computer-readable storage medium, and the readable storage medium includes flash memory, hard disk, multimedia card, card-type memory (for example, SD or DX memory, etc.), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, disk, optical disk, etc. In some embodiments, the memory 41 can be an internal storage module of an electronic device, such as a hard disk or memory of the electronic device. In other embodiments, the memory 41 can also be an external storage device of an electronic device, such as a plug-in hard disk equipped on the electronic device, a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (Flash Card), etc. Of course, the memory 41 can also include both the internal storage module of the electronic device and its external storage device. In this embodiment, the memory 41 is generally used to store the operating system and various application software installed on the electronic device. In addition, the memory 41 can also be used to temporarily store various types of data that have been output or are to be output.
[0113] The processor 42 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc. The processor 42 is the computing core and control center of the electronic device, and uses various interfaces and lines to connect various parts of the entire electronic device, and execute the operating system of the electronic device and various installed applications, program codes, etc.
[0114] The processor 42 executes the operating system of the electronic device and various installed applications. The processor 42 executes the application to implement the steps in the above-mentioned log desensitization method embodiments, for example Figure 1 Steps S100, S200, S300, S400 are shown.
[0115] Embodiment 4
[0116] The present embodiment also provides a computer-readable storage medium, such as a flash memory, a hard disk, a multimedia card, a card-type memory (for example, an SD or DX memory, etc.), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a disk, an optical disk, a server, an App application store, etc., on which a computer program is stored, and the program implements the corresponding function when executed by the processor. The computer-readable storage medium of the present embodiment is used to store a computer program that implements the log desensitization method, and when executed by the processor 42, the log desensitization method of embodiment one, two, or three is implemented.
Claims
1. A log desensitization method, characterized in that, the method includes: Intercept the data printing request sent by the user, and extract the first annotation in the data printing request; wherein, the first annotation is used to characterize the data to be desensitized in the data printing request; Obtain the data to be desensitized, and extract the second annotation and the third annotation in the data to be desensitized; wherein, the second annotation is used to characterize the type of the target object in the data to be desensitized, and the third annotation is used to characterize the attribute value of the target object in the data to be desensitized; Determine the preset configuration rule corresponding to the target object based on the type of the target object; After desensitizing the attribute value based on the configuration rule, send the data printing request to the printing interface to perform the printing operation; The determining the preset configuration rule corresponding to the target object based on the type of the target object further includes: Find out the configuration rule corresponding to the type of the target object from the preset configuration policy area; wherein, the correspondence between the types of each target object and the corresponding configuration rules is pre-stored in the configuration policy area; The configuration policy area is constructed through the following steps: Compile the data to be desensitized into an initial bytecode file, and run the initial bytecode file; wherein, the source code file is compiled into the initial bytecode file by using a front-end compiler; Compiling the source code file into the initial bytecode file by using a front-end compiler specifically includes the following steps: Through the lexical analyzer and syntax analyzer in the front-end compiler, convert the character stream in the source code file into a token set, and construct an abstract syntax tree according to the token set; wherein, the token is the smallest element in the compilation process; each node of the abstract syntax tree is used to characterize a syntax structure in the source code file; Fill the symbol table; wherein, the symbol table is a table constructed by multiple groups of symbol addresses and symbol information, the symbol information is the attribute value of the target object, the symbol address is the type of the target object, and the symbol table stores the one-to-one correspondence between the attribute value of the target object and the corresponding type; Through the annotation processor in the front-end compiler, parse the second annotation and the third annotation, and read the type of the target object corresponding to the second annotation and the attribute value of the target object corresponding to the second annotation from the abstract syntax tree; Convert the abstract syntax tree and the symbol table into bytecode, and output the bytecode file; Use the bytecode manipulation framework to recursively parse the running of the initial bytecode file to obtain a target object set, and store the target object set in the configuration policy area; wherein, the target object set includes the type of the target object and the corresponding index value, and the index value is used to characterize the number of the type of the target object; Call the preset configuration rule corresponding to the target object according to the index value; Store the correspondence between the target object set and the corresponding configuration rules in the configuration policy area.
2. The log desensitization method according to claim 1, characterized in that, The compiling the data to be desensitized into an initial bytecode file and running the initial bytecode file further includes: Based on the first annotation, parse the data to be desensitized to obtain a parsing result; Read the second annotation and the third annotation from the parsing result to obtain a data model file; Set the data model file as a source code file, and call a preset compiler to compile the source code file into the initial bytecode file; Load the initial bytecode file through a preset virtual machine, and convert the initial bytecode file into machine code and execute it.
3. The log desensitization method according to claim 1, wherein, using a bytecode manipulation framework to recursively parse the running of the initial bytecode file to obtain a set of target objects, and storing the set of target objects in the configuration policy area; wherein, the set of target objects includes the type of the target object and the corresponding index value, the index value is used to represent the number of the type of the target object, and further includes: Load the initial bytecode file using a bytecode manipulation framework; Recursively parse the initial bytecode file to obtain the types of multiple target objects; Set corresponding index values according to the types of multiple target objects, and generate multiple sets of target objects according to the types of multiple target objects and the corresponding index values; Store multiple sets of target objects in the configuration policy area respectively.
4. The log desensitization method according to claim 1, wherein, The data printing request includes public data and / or data to be desensitized, the data to be desensitized is used to represent privacy data containing personal information, and the public data is used to represent data that does not contain personal information; Intercept the data printing request sent by the user, and extract the first annotation in the data printing request; wherein, the first annotation is used to represent the data to be desensitized in the data printing request, and further includes: If the first annotation is not extracted from the data printing request, send the data printing request to the printing interface to perform a printing operation.
5. The log desensitization method according to claim 1, wherein, The configuration rule includes a desensitization rule and a recovery rule, and desensitize the attribute value based on the desensitization rule; After desensitizing the attribute value based on the configuration rule and sending the data printing request to the printing interface to perform a printing operation, further includes: Restore the desensitized attribute value based on the recovery rule and store it in the cache.
6. A log desensitization system, wherein, including: An interception unit for intercepting a data printing request sent by a user and extracting the first annotation in the data printing request; wherein, the first annotation is used to represent the data to be desensitized in the data printing request; An acquisition unit for acquiring the data to be desensitized and extracting the second annotation and the third annotation in the data to be desensitized; wherein, the second annotation is used to represent the type of the target object in the data to be desensitized, and the third annotation is used to represent the attribute value of the target object in the data to be desensitized; A determination unit, configured to determine a preset configuration rule corresponding to the target object based on the type of the target object; the determining the preset configuration rule corresponding to the target object based on the type of the target object further includes: finding out the configuration rule corresponding to the type of the target object from a preset configuration policy area; wherein, the correspondence between the types of all the target objects and the corresponding configuration rules is pre-stored in the configuration policy area; the configuration policy area is constructed through the following steps: compiling the data to be desensitized into an initial bytecode file, and running the initial bytecode file; wherein, a front-end compiler is used to compile the source code file into the initial bytecode file; the compiling the source code file into the initial bytecode file by the front-end compiler specifically includes the following steps: converting the character stream in the source code file into a token set through a lexical analyzer and a syntax analyzer in the front-end compiler, and constructing an abstract syntax tree according to the token set; wherein, the token is the smallest element in the compilation process; each node of the abstract syntax tree is used to represent a syntax structure in the source code file; filling a symbol table; wherein, the symbol table is a table constructed by multiple groups of symbol addresses and symbol information, the symbol information is the attribute value of the target object, the symbol address is the type of the target object, and the symbol table stores the one-to-one correspondence between the attribute value of the target object and the corresponding type; parsing the second annotation and the third annotation through an annotation processor in the front-end compiler, and reading the type of the target object corresponding to the second annotation and the attribute value of the target object corresponding to the second annotation from the abstract syntax tree; converting the abstract syntax tree and the symbol table into bytecode, and outputting a bytecode file; recursively parsing the running of the initial bytecode file by using a bytecode manipulation framework to obtain a target object set, and storing the target object set into the configuration policy area; wherein, the target object set includes the type of the target object and the corresponding index value, and the index value is used to represent the number of the type of the target object; calling the preset configuration rule corresponding to the target object according to the index value; storing the correspondence between the target object set and the corresponding configuration rule into the configuration policy area; A desensitization unit, configured to desensitize the attribute value based on the configuration rule, and then send the data printing request to a printing interface to perform a printing operation.
7. An electronic device, characterized in that, the electronic device includes: a memory, storing at least one instruction; and a processor, executing the instruction stored in the memory to implement the log desensitization method according to any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that, at least one instruction is stored in the computer-readable storage medium, and the at least one instruction is executed by a processor in an electronic device to implement the log desensitization method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Data desensitization method, device and equipment and storage medium
CN112000986A