A data processing method and system based on a data security sandbox

By encrypting and de-identifying data within a data security sandbox, combined with mirrored business model testing and symmetric encryption, the contradiction between data security and value release is resolved, achieving data usability without visibility, and ensuring data security and privacy protection.

CN114091015BActive Publication Date: 2026-01-02SHANDONG EVAYINFO TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111416283.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-25
Publication Date
2026-01-02
Estimated Expiration
2041-11-25

AI Technical Summary

Technical Problem

While ensuring data security, how can we unlock the value of data and avoid a one-size-fits-all approach that could lead to unusable data or compromised security?

Method used

We employ data processing methods within a data security sandbox, forming datasets through encryption and de-identification. We then use a mirrored business model for testing to ensure that privacy information is not leaked and to guarantee data security through symmetric encryption algorithms.

Benefits of technology

It achieves data availability and invisibility while ensuring data security, effectively preventing business models from obtaining specific data identifiers and ensuring the security of data storage and retrieval.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114091015B_ABST
    Figure CN114091015B_ABST
Patent Text Reader

Abstract

The application provides a data processing method and system based on a data security sandbox, obtains original data, respectively encrypts the identities to which the original data belongs, performs desensitization processing on the original data, performs shielding or symbolization processing on the private information involved, forms a data set, receives a test application request of a business model, forms an image, tests the image business model based on the test data in the data set, judges whether the image business model converts the private information into a classification result or a judgment result, if yes, the corresponding business model test is passed, receives a data review request, determines the data identity matched in the request, secondarily encrypts the data identity, obtains the classification result or the judgment result by using the business model, and feeds back the classification result or the judgment result to the requester. The application realizes data usability invisibility, releases data value and realizes data isolation under the condition of ensuring data security.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the technical field of big data processing, and particularly relates to a data processing method and system based on a data security sandbox. BACKGROUND

[0002] The statements in this section merely provide background information related to the present application and do not necessarily constitute prior art.

[0003] With the development of big data technology, the value contained in data is increasingly valued. However, some data contains some private values, such as social security, tax, health, etc. It is not appropriate to show them to some clients without reservation, but they need to represent their value or meaning when handling related businesses. How to release the value in the data while ensuring data security has become a problem to be solved.

[0004] Currently, in the absence of technical means to ensure data security, the scene of applying for the above data can only adopt a one-size-fits-all approach, that is, either not allowed to use, the value of the data cannot be played; or the data is directly provided, the security of the data cannot be guaranteed. SUMMARY

[0005] In order to solve at least one technical problem in the background art, the present application provides a data processing method and system based on a data security sandbox. The present application realizes data usability and invisibility, releases data value, and realizes data isolation while ensuring data security.

[0006] In order to achieve the above purpose, the present application adopts the following technical solutions:

[0007] A data processing method based on a data security sandbox is executed in the data security sandbox, comprising the following steps:

[0008] Obtain the original data, and respectively encrypt the identifier to which the original data belongs;

[0009] Perform desensitization processing on the original data, and perform shielding or symbolization processing on the private information involved to form a data set;

[0010] Obtain part of the data in the data set as test data;

[0011] Receive a test application request of a business model, form an image of the business model, test the image business model based on the test data, and judge whether the image business model converts the private information into a classification result or a judgment result. If yes, the corresponding business model test is passed, otherwise, a business model test failure message is sent;

[0012] receiving a data access request, determining an identity to which the data matched in the request belongs, re-encrypting the identity to which the data belongs, processing the private data under the identity to which the data belongs by using the business model that passes the test, obtaining a classification result or a judgment result;

[0013] feeding back the classification result or the judgment result to the requester.

[0014] As an optional implementation, the data security sandbox comprises a test area, a model area, a data area and a monitoring area, the test area is used for testing the business model, the model area is used for storing the business model that passes the test, the data area is used for storing the data set, and the monitoring area is used for storing the access log of the model area and the data area.

[0015] As an optional implementation, a mirror warehouse is arranged between the test area and the model area, and the mirror warehouse is used for forming and storing the mirror of the business model.

[0016] As an optional implementation, a data gateway is arranged between the test area and the data area.

[0017] As an optional implementation, the encryption is performed by using a symmetric encryption algorithm.

[0018] As an optional implementation, before receiving the test application request of the business model, the identity and the authority of the requester are verified, and after the verification, the corresponding steps are performed.

[0019] As an optional implementation, before receiving the data access request, the identity and the authority of the requester are verified, and after the verification, the matched business model is found according to the verification information, and the data is processed by using the matched business model.

[0020] A data processing system based on a data security sandbox comprises:

[0021] An encryption module configured to obtain original data and respectively encrypt the identity to which the original data belongs;

[0022] A desensitization module configured to perform desensitization processing on the original data, perform shielding or symbolization processing on the private information, and form a data set;

[0023] A test set construction module configured to obtain part of the data in the data set as test data;

[0024] The business model test module is configured to receive a test application request of a business model, form a mirror image of the business model, test the mirror image business model based on test data, judge whether the mirror image business model converts privacy information into a classification result or a judgment result, if yes, the corresponding business model test is passed, otherwise, a business model test failure message is sent;

[0025] The data processing module is configured to receive a data review request, determine a data belonging identifier matched in the request, perform secondary encryption on the data belonging identifier, process privacy data under the data belonging identifier by using the tested business model, and obtain a classification result or a judgment result.

[0026] The result feedback module is configured to feed back the classification result or the judgment result to a requester.

[0027] A computer readable storage medium has a computer program stored thereon, and the program is executed by a processor to implement the steps in the method.

[0028] A computer device includes a memory, a processor, and a computer program stored on the memory and executable on the processor, and the processor implements the steps in the method when executing the program.

[0029] Compared with the prior art, the present application has the following advantages:

[0030] The present application ensures data security and allows the business model to serve business calls in a controlled model area, and effectively avoids the business model from obtaining specific called data identifiers by gateway encryption and shielding data identifiers, thereby ensuring data security during calling.

[0031] The present application ensures the security of data storage in the data sandbox through data area encryption and desensitization, and further ensures the security of the scheme by using a symmetric encryption algorithm.

[0032] The advantages of the additional aspects of the present application will be partially given in the following description, partially become obvious from the following description, or be learned through the practice of the present application. BRIEF DESCRIPTION OF DRAWINGS

[0033] The drawings accompanying the specification of the present application serve to provide a further understanding of the present application, and the illustrative embodiments of the present application and their descriptions serve to explain the present application, and do not constitute an improper limitation on the present application.

[0034] Figure 1 is an implementation schematic diagram of a data security sandbox in at least one embodiment of the present application. DETAILED DESCRIPTION

[0035] The application will be further described below with reference to the drawings and embodiments.

[0036] It should be noted that the following detailed description is exemplary in nature and is intended to provide further description of the application. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs.

[0037] It should be noted that the terms used herein are only intended to describe specific embodiments and are not intended to limit exemplary embodiments according to the present application. As used herein, the singular form is intended to include the plural form unless the context clearly indicates otherwise, and it should be further understood that when the terms "comprise" and / or "include" are used in the specification, they indicate the presence of the features, steps, operations, devices, components and / or combinations thereof.

[0038] The application proposes a data processing method and system based on a data security sandbox, which can process and display data in the data security sandbox to hide specific data.

[0039] The following will be described in specific embodiments.

[0040] Embodiment one

[0041] The data processing method based on the data security sandbox is executed in the data security sandbox, comprising the following steps:

[0042] Obtain the original data, and respectively encrypt the identifiers to which the original data belongs;

[0043] Desensitize the original data, and shield or symbolize the private information involved to form a data set;

[0044] Obtain part of the data in the data set as test data;

[0045] Receive a test application request of a business model, form an image of the business model, test the image business model based on the test data, and determine whether the image business model converts the private information into a classification result or a judgment result. If yes, the corresponding business model test is passed, otherwise, a business model test failure message is sent;

[0046] Receive a data review request, determine the matching data identifier in the request, re-encrypt the data identifier, process the private data under the data identifier using the tested business model, and obtain a classification result or a judgment result;

[0047] The classification result or the judgment result is fed back to the requester.

[0048] Embodiment two

[0049] The bank loan business application needs to know the tax amount of the previous year of the taxpayer to issue the corresponding loan limit, which is the application scenario. The method provided in Embodiment I is further described.

[0050] The tax amount of the previous year of the taxpayer as private data should not be disclosed to the bank loan business application personnel, but when it is needed to know whether the taxpayer has the ability to repay the loan limit applied for, the method provided in Embodiment I can hide the specific data of the tax amount and only tell the bank loan business application personnel whether the taxpayer has the ability to repay the loan limit of which level.

[0051] In this embodiment, for the convenience of understanding, the tax amount of 5000 is taken as an example for description. If the tax amount is equal to 5000, it means that the taxpayer is qualified to obtain the corresponding level of loan, i.e., within 5000 is level 1 and above 5000 is level 2.

[0052] Of course, the above-mentioned amount and application scenario are only exemplary descriptions and do not represent that the present application is limited to the protection of this scheme.

[0053] Firstly, the data security sandbox is introduced, as shown in FIG. 1, which includes a test area, a model area, a data area and a monitoring area. The test area and the model area are provided with a mirror warehouse, and the test area and the data area are provided with a data gateway. Figure 1

[0054] Specifically, the test area is used for model development team to test the model, and the model passing the test is submitted to the mirror warehouse;

[0055] The model area pulls the mirror from the mirror warehouse, starts the container service and interface calling, and the model in the container can only call the data area API to obtain the encrypted and desensitized data, which is only used for in-memory calculation.

[0056] The data area is responsible for storing the desensitized and encrypted data, and provides data calling service for the model through the data API gateway, and the model area cannot access the original data.

[0057] The monitoring area records the calling log and uploads it to the blockchain to prevent illegal tampering of the accessed data, which is used for regular data calling audit.

[0058] The external business team can only directly touch the test area and indirectly touch the model area, and cannot touch the data area and the monitoring area. The opening of the test area is conducive to the development and test of the business model.

[0059] The internal operation team is responsible for the deployment of the model area, the maintenance of the data area and the maintenance of the monitoring area, and the team separation effectively safeguards the internal data security.

[0060] ​When the request passes through the model gateway, the data identifier symmetric encryption algorithm is automatically completed, and the request parameter received by the model is ciphertext. The model cannot reverse the called data identifier according to the request parameter.

[0061] When the model calls the data gateway API, the data gateway uses the encryption machine in the model area to decrypt and then uses the encryption machine in the model area to encrypt, so as to prevent the model area secret key from being leaked and affecting the data security of the data area. At the same time, the result returned by the data gateway API does not contain the data identifier, which effectively avoids data leakage caused by the model recording the data identifier and returning the result.

[0062] The original data is not stored on the disk, and only the encrypted and desensitized data is stored in the data area. Even if the database is leaked, the user information will not be leaked without decryption by the encryption machine in the data area.

[0063] The application calls the business model interface, and the business model calls the data interface, which need to be applied in advance. After authorization, the corresponding interface can be accessed. The model interface permission control is to the business application, and the data interface permission control is to the business model, realizing fine-grained interface access permission control.

[0064] The interface calling log records the input parameters and return values, response time and other information, and packs the data and uploads it to the block chain, ensuring the non-tamperability of the access record and ensuring the effectiveness of the access log audit.

[0065] Specifically, when responding to the business application, the following steps are included:

[0066] Step 1, the data operation and maintenance team obtains the original data of the taxpayer's tax, processes the taxpayer's detailed data. The identity card number (data identifier) is encrypted by calling the symmetric algorithm built-in the encryption machine in the data area, and the name of the taxpayer and other information is desensitized, such as the name only keeping the surname and the rest being desensitized by the *** symbol. The original value of the tax amount is stored. After processing the monthly tax data, it is stored in the data mart in the data area.

[0067] Step 2, the data operation and maintenance team configures a data interface that returns the tax details according to the taxpayer's data identifier and year. Publish to the data gateway in the data area, and generate a simulation API interface in the test area.

[0068] Step 3, the business model development team (bank loan business party) applies for a test space and applies for the permission of the model calling interface, and develops and tests the model in the test area.

[0069] Step 4, the data operation and maintenance team tests the applied business model, and after the test is passed, the model container containing the model is published as an image and submitted to the image warehouse. And submit the model online application, submit the model description and code for model review.

[0070] Step 5, after the audit is passed, the data operation team pulls the image from the mirror warehouse, runs the container containing the model in the model area, and publishes the model interface to the model gateway.

[0071] Step 6, the business model development team applies for the right to call the model interface.

[0072] Step 7, after the data operation team audits the legitimacy of the model calling party, the business application is authorized to call the model interface.

[0073] After steps 1-7, the business model development team can return the processed results without touching the government data, realizing the availability and invisibility of data.

[0074] Step 8, the business application calls the tax model interface on the model gateway, and inputs the data identifier of the taxpayer (in this embodiment, it can be the taxpayer's ID number, for example, 37xxx).

[0075] Step 9, after receiving the calling request, the model gateway encrypts the taxpayer's data identifier (37xxx) using the symmetric encryption algorithm built into the encryption machine in the model area, and the encrypted data identifier becomes (MXJMxxx), and the encrypted data identifier is replaced. Parameter input into the business model.

[0076] Step 10, the business model receives the data identifier (MXJMxxx), directly calls the data API interface using the data identifier, so the encryption does not affect the operation of the business model, and the encrypted model cannot use the encrypted data identifier to deduce the ID number, which can effectively avoid the illegal leakage of sensitive data recorded by the model.

[0077] Step 11, after receiving the data request, the data gateway decrypts the taxpayer's data identifier (MXJMxxx) to the taxpayer's data identifier (37xxx) using the model area encryption machine, and then uses the symmetric encryption algorithm built into the model area encryption machine to complete the second encryption of the taxpayer's data identifier (SJJMxxx). The same secret key and the same encryption algorithm are used in the data preparation stage to realize the correspondence of the data identifier.

[0078] This embodiment uses a double encryption machine double secret key system, which greatly reduces the risk of database leakage,

[0079] Step 12, the data development API queries the corresponding taxpayer data and returns the taxpayer detail list, and shields the data identifier column.

[0080] Step 13, the data gateway records the data interface calling log, because there is no sensitive information, the input parameter and return value can be directly recorded, and the chain data is recorded for subsequent audit and error correction.

[0081] Step 14, the business model gets the data of the tax detail list, sums up the monthly tax amount, and compares it with 5000. If it is less than 5000, return 1, and if it is greater than or equal to 5000, return 2. The business model cannot infer which specific taxpayer the data belongs to through the return value of the parameter and data interface call, which technically ensures the availability and invisibility of government data.

[0082] Step 15, the model gateway records data interface call logs, as there is no sensitive information that can be directly recorded into parameters and return values, and the data is chained for subsequent auditing and error correction.

[0083] Step 16, the platform operation team regularly inspects the running of individual models through access logs, and can execute unloading processing for suspicious models.

[0084] The above ensures the availability and invisibility of government data from both management and technical aspects. At the same time, the access log on the blockchain also effectively ensures the effectiveness of access data auditing.

[0085] Of course, in other embodiments, the symmetric algorithm can be replaced by SM1\SM3\DES\AES symmetric encryption algorithm according to specific circumstances.

[0086] Embodiment three

[0087] A data processing system based on a data security sandbox, comprising:

[0088] An encryption module configured to obtain original data and separately encrypt the identification to which the original data belongs;

[0089] A desensitization module configured to perform desensitization processing on the original data, and to shield or symbolize processing on private information involved, forming a data set;

[0090] A test set construction module configured to obtain part of the data in the data set as test data;

[0091] A business model test module configured to receive a test application request of a business model, form an image of the business model, test the image business model based on the test data, and determine whether the image business model converts private information into a classification result or a judgment result. If so, the corresponding business model test is passed, otherwise, a business model test failure message is sent;

[0092] A data processing module configured to receive a data review request, determine the identification to which the matching data belongs in the request, perform secondary encryption on the identification to which the data belongs, process the private data under the identification to which the data belongs using the business model that has passed the test, and obtain a classification result or a judgment result;

[0093] The result feedback module is configured to feed back the classification result or the judgment result to the requester.

[0094] Embodiment four

[0095] The embodiment provides a computer readable storage medium, and a computer program is stored on the computer readable storage medium. The computer program is executed by a processor to implement the steps in the embodiment one or the embodiment two.

[0096] Embodiment five

[0097] The embodiment provides an electronic device, which comprises a memory, a processor, and a computer program stored in the memory and executable on the processor. The processor implements the steps in the embodiment one or the embodiment two when executing the program.

[0098] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products of the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams and the combination of the flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to produce a machine, so that the instructions executed by the computer or other programmable data processing devices produce a device that implements the functions specified in the flowcharts and / or block diagrams. Figure 1 The device for implementing the functions specified in one flow or multiple flows and / or blocks. Figure 1 The device for implementing the functions specified in one flow or multiple flows and / or blocks.

[0099] The above only describes the preferred embodiments of the present application and is not used to limit the present application. For those skilled in the art, the present application can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the present application should be included in the protection scope of the present application.

Claims

1. A data processing method based on a data security sandbox, executed within a data security sandbox, characterized by: Includes the following steps: Obtain the raw data and encrypt the identifiers belonging to the raw data separately; The original data is anonymized, and information involving privacy is obscured or symbolized to form a dataset; Obtain a portion of the dataset as test data; Receive a test application request for a business model, and create a mirror image of the business model. Test the mirror business model based on the test data, and determine whether the mirror business model converts privacy information into classification results or judgment results. If so, the corresponding business model test passes; otherwise, send a business model test failure message. Upon receiving a data query request, the system determines the matching data identifier in the request, performs secondary encryption on the data identifier, and processes the private data under the data identifier using a tested business model to obtain a classification result or judgment result. Specifically, the business application calls the model interface on the model gateway and passes in the data identifier. After receiving the call request, the model gateway encrypts the data identifier using the symmetric encryption algorithm built into the encryption machine in the model area, and passes the encrypted data identifier to the business model as a parameter replacement. The business model receives the data identifier and directly uses the data identifier to call the data interface. After receiving the data request, the data gateway decrypts the encrypted data identifier using the encryption machine in the model area and then calls the symmetric encryption algorithm built into the encryption machine in the model area to complete the secondary encryption of the data identifier. The classification or judgment results will be fed back to the requesting party.

2. The data processing method based on a data security sandbox as described in claim 1, characterized in that: The data security sandbox includes a test area, a model area, a data area, and a monitoring area. The test area is used to test business models, the model area is used to store successfully tested business models, the data area is used to store datasets, and the monitoring area is used to store access logs for the model area and the data area.

3. The data processing method based on a data security sandbox as described in claim 2, characterized in that: A mirror repository is set up between the test area and the model area. The mirror repository is used to form and store mirror images of business models, thus forming mirror business models.

4. The data processing method based on a data security sandbox as described in claim 2, characterized in that: A data gateway is provided between the test area and the data area.

5. The data processing method based on a data security sandbox as described in claim 1, characterized in that: The encryption is performed using a symmetric encryption algorithm.

6. The data processing method based on a data security sandbox as described in claim 1, characterized in that: Before receiving a test request from a business model, verify the identity and permissions of the requester. Only after successful verification should the corresponding steps be executed.

7. A data processing method based on a data security sandbox as described in claim 1, characterized in that: in Before receiving a data access request, the system verifies the requester's identity and permissions. After verification, it finds a matching business model based on the verification information and uses the matching business model for data processing.

8. A data processing system based on a data security sandbox, characterized in that: include: The encryption module is configured to acquire the original data and encrypt the identifiers belonging to the original data separately. The data anonymization module is configured to anonymize the original data, and to mask or symbolize information involving privacy to form a dataset. The test set building module is configured to retrieve a portion of the dataset as test data. The business model testing module is configured to receive test application requests for business models, form a mirror image of the business model, test the mirror business model based on test data, and determine whether the mirror business model converts privacy information into classification results or judgment results. If so, the corresponding business model test passes; otherwise, a business model test failure message is sent. The data processing module is configured to receive data query requests, determine the matching data identifier in the request, perform secondary encryption on the data identifier, and process the privacy data under the data identifier using a tested business model to obtain classification or judgment results. Specifically, the business application calls the model interface on the model gateway and passes in the data identifier. After receiving the call request, the model gateway encrypts the data identifier using the symmetric encryption algorithm built into the encryption machine in the model area, and passes the encrypted data identifier to the business model as a parameter replacement. The business model receives the data identifier and directly uses the data identifier to call the data interface. After receiving the data request, the data gateway decrypts the encrypted data identifier using the encryption machine in the model area and then calls the symmetric encryption algorithm built into the encryption machine in the model area to complete the secondary encryption of the data identifier. The results feedback module is configured to return the classification or judgment results to the requester.

9. A computer-readable storage medium, characterized in that: It stores a computer program that, when executed by a processor, implements the steps of the method as described in any one of claims 1-7.

10. A computer device, characterized by: It includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, implements the steps of the method as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Service data request processing method and device and electronic equipment

    CN112270016A

  • Implementation method and system using government affair open sensitive data

    CN112487458A