Data Masking Method, Device, Equipment and Medium

By responding to data desensitization instructions in the target system, using steps such as renaming, double writing, cleaning and union operations, the existing data desensitization methods are solved, and efficient and safe data desensitization processing is achieved.

CN114139199BActive Publication Date: 2025-05-30PING AN PAY ELECTRONIC PAYMENT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111441922.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-30
Publication Date
2025-05-30
Estimated Expiration
2041-11-30

AI Technical Summary

Technical Problem

Existing data desensitization methods are costly and risky, and there is a possibility of data loss.

Method used

By responding to data desensitization instructions, the data to be processed in the target system is determined, and the steps such as renaming, double writing, cleaning and union operations are adopted to gradually realize data desensitization.

Benefits of technology

Reduces the cost and risk of data desensitization, avoids data loss, and improves the efficiency of data processing through optimization steps.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114139199B_ABST
    Figure CN114139199B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of data processing, and provides a data desensitization method, device, equipment and medium, which can transform the names of sensitive data in a unified naming format, improve the readability of data and the efficiency of data processing, obtain incremental data from the obtained first intermediate data for dual writing operation to obtain second intermediate data, and ensure that the data can be normally used during the desensitization process by means of plaintext and ciphertext dual writing, reducing the transformation risk. After dual writing, obtain the stock data from the first intermediate data for cleaning operation to obtain third intermediate data. After cleaning, perform union operation on the second intermediate data and the third intermediate data to obtain fourth intermediate data and perform single writing operation, realizing desensitization of data without calling a large number of interfaces, and achieving more optimized desensitization processing of sensitive data. In addition, the present invention also relates to blockchain technology, and the desensitized data corresponding to the data to be processed can be stored in blockchain nodes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and in particular, to a data desensitization method, apparatus, device and medium. Background Art

[0002] With the development and use of increasingly diverse application systems, there is more and more sensitive information such as user data stored in each system.

[0003] For the above sensitive information, it usually needs to be desensitized before it can be used, otherwise it will affect the information security of users.

[0004] However, when performing data desensitization currently, there are still the following problems:

[0005] 1. The scope of business changes is wide, and there are a large number of interfaces that need to be changed and verified, resulting in extremely high transformation labor costs;

[0006] 2. It is usually associated with scenarios where users are more active, and the transformation risk is high;

[0007] 3. There may be a problem of user information loss due to data encryption anomalies. Summary of the Invention

[0008] In view of the above, it is necessary to provide a data desensitization method, apparatus, device and medium, aiming to solve the problems of high cost and high risk in desensitizing sensitive data.

[0009] A data desensitization method, the data desensitization method includes:

[0010] In response to a data desensitization instruction for a target system, determine the data to be processed in the target system;

[0011] Retrieve a naming format, and rename the data to be processed according to the naming format to obtain first intermediate data;

[0012] Obtain incremental data from the first intermediate data, and perform a dual-write operation on the incremental data to obtain second intermediate data;

[0013] When it is detected that the dual-write operation is completed, obtain the stock data from the first intermediate data, and perform a cleaning operation on the stock data to obtain third intermediate data;

[0014] When it is detected that the cleaning operation is completed, perform a union operation on the second intermediate data and the third intermediate data to obtain fourth intermediate data;

[0015] Perform a single-write operation on the fourth intermediate data to obtain the desensitized data corresponding to the data to be processed.

[0016] According to a preferred embodiment of the present invention, the renaming of the data to be processed according to the naming format to obtain the first intermediate data includes:

[0017] Obtain the initial field name of the data to be processed;

[0018] Obtain a preset character from the naming format;

[0019] Concatenate the preset character with the initial field name of the data to be processed to obtain the first intermediate data.

[0020] According to a preferred embodiment of the present invention, the double writing operation and the single writing operation include addition processing, update processing, query processing, and query result return processing. The double writing operation on the incremental data includes:

[0021] When performing the addition processing on the incremental data, obtain the plaintext of the incremental data, the set method of the plaintext field, the set method of the ciphertext field, and the set method of the encryption flag bit;

[0022] Determine the plaintext of the incremental data, the set method of the plaintext field, the set method of the ciphertext field, and the set method of the encryption flag bit as input parameters, and add the incremental data to obtain the ciphertext corresponding to the incremental data;

[0023] Decrypt the ciphertext corresponding to the incremental data to obtain the first decrypted data;

[0024] Verify the consistency between the first decrypted data and the plaintext of the incremental data;

[0025] When the first decrypted data is inconsistent with the plaintext of the incremental data, determine that the verification fails, and separately record the plaintext of the incremental data; or

[0026] When the first decrypted data is consistent with the plaintext of the incremental data, determine that the verification passes, and simultaneously record the plaintext of the incremental data and the ciphertext corresponding to the incremental data.

[0027] According to a preferred embodiment of the present invention, the double writing operation on the incremental data further includes:

[0028] When performing the query processing on the incremental data, detect the execution progress of the addition processing and the update processing;

[0029] When the execution progress shows that the addition processing and the update processing are completed, clear the plaintext of the incremental data, and perform a query using the ciphertext corresponding to the incremental data; or

[0030] When the execution progress indicates that the new processing and the update processing have not been completed, query using the plaintext of the incremental data.

[0031] According to a preferred embodiment of the present invention, the double-writing operation on the incremental data further includes:

[0032] When performing the query result return processing on the incremental data, detect whether the ciphertext corresponding to the incremental data is an empty field;

[0033] When the ciphertext corresponding to the incremental data is not an empty field, decrypt the ciphertext corresponding to the incremental data to obtain second decrypted data;

[0034] Verify the consistency between the second decrypted data and the plaintext of the incremental data;

[0035] When the second decrypted data is inconsistent with the plaintext of the incremental data, determine that the verification fails and return the plaintext of the incremental data; or

[0036] When the second decrypted data is consistent with the plaintext of the incremental data, determine that the verification passes and return the second decrypted data.

[0037] According to a preferred embodiment of the present invention, the cleaning operation on the stock data includes:

[0038] Obtain a pre-established configuration file, where the configuration file is used to store the cleaning methods for each database table;

[0039] Obtain a to-be-executed JOB, and obtain multiple database tables corresponding to the to-be-executed JOB, and use them as multiple target database tables;

[0040] Query the cleaning method for each target database table in the configuration file as the target method for each target database table;

[0041] Obtain the primary key ID when the to-be-executed JOB was last executed from each target database table;

[0042] Obtain a pre-maintained ID range, and obtain multiple threads from a pre-established thread pool, where the number of the multiple threads is the same as the number of the multiple target database tables;

[0043] Starting from the primary key ID of each target database table, within the ID range, execute the to-be-executed JOB in parallel based on the target method and the multiple threads;

[0044] After the to-be-executed JOB is executed, collect the elapsed time and the amount of data processed;

[0045] Update the ID range according to the time consumption and the data processing volume.

[0046] According to a preferred embodiment of the present invention, the performing a single write operation on the fourth intermediate data to obtain the desensitized data corresponding to the data to be processed includes:

[0047] Obtain the ciphertext corresponding to the fourth intermediate data;

[0048] Perform the addition processing, and / or the update processing, and / or the query processing, and / or the query result return processing by using the ciphertext corresponding to the fourth intermediate data;

[0049] During the execution, when it is detected that the ciphertext is inconsistent with the corresponding plaintext, an exception is thrown and a call failure is returned;

[0050] After the single write operation is completed, clear the plaintext of the fourth intermediate data to obtain the desensitized data corresponding to the data to be processed.

[0051] A data desensitization device, the data desensitization device includes:

[0052] A determination unit, configured to determine the data to be processed in the target system in response to a data desensitization instruction for the target system;

[0053] A naming unit, configured to retrieve a naming format and rename the data to be processed according to the naming format to obtain first intermediate data;

[0054] A dual write unit, configured to obtain incremental data from the first intermediate data and perform a dual write operation on the incremental data to obtain second intermediate data;

[0055] A cleaning unit, configured to, when it is detected that the dual write operation is completed, obtain the stock data from the first intermediate data and perform a cleaning operation on the stock data to obtain third intermediate data;

[0056] An operation unit, configured to, when it is detected that the cleaning operation is completed, perform a union operation on the second intermediate data and the third intermediate data to obtain fourth intermediate data;

[0057] A single write unit, configured to perform a single write operation on the fourth intermediate data to obtain the desensitized data corresponding to the data to be processed.

[0058] A computer device, the computer device includes:

[0059] A memory, storing at least one instruction; and

[0060] A processor, configured to execute the instruction stored in the memory to implement the data desensitization method.

[0061] A computer-readable storage medium stores at least one instruction, and the at least one instruction is executed by a processor in a computer device to implement the data desensitization method.

[0062] As can be seen from the above technical solutions, the present invention can respond to a data desensitization instruction for a target system, determine the data to be processed in the target system, retrieve a naming format, and rename the data to be processed according to the naming format to obtain first intermediate data. By reforming the names of sensitive data according to a unified naming format, the readability of the data is improved, which is convenient for subsequent calls and improves the efficiency of data processing. Incremental data is obtained from the first intermediate data, and a dual-write operation is performed on the incremental data to obtain second intermediate data. By means of dual-writing of plaintext and ciphertext, it is ensured that the data can be used normally during the desensitization process, reducing the transformation risk and preventing data loss. When it is detected that the dual-write operation is completed, the stock data is obtained from the first intermediate data, and a cleaning operation is performed on the stock data to obtain third intermediate data. When it is detected that the cleaning operation is completed, a union operation is performed on the second intermediate data and the third intermediate data to obtain fourth intermediate data. A single-write operation is performed on the fourth intermediate data to obtain the desensitized data corresponding to the data to be processed, and the desensitization of the data can be realized without calling a large number of interfaces, achieving a more optimized desensitization process for sensitive data. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] Figure 1 is a flowchart of a preferred embodiment of the data desensitization method of the present invention.

[0064] Figure 2 is a functional module diagram of a preferred embodiment of the data desensitization device of the present invention.

[0065] Figure 3 is a schematic structural diagram of a computer device of a preferred embodiment for implementing the data desensitization method of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0066] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be described in detail below with reference to the accompanying drawings and specific embodiments.

[0067] As Figure 1 shown, it is a flowchart of a preferred embodiment of the data desensitization method of the present invention. According to different requirements, the order of the steps in this flowchart can be changed, and some steps can be omitted.

[0068] The data desensitization method is applied to one or more computer devices. A computer device is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions. Its hardware includes, but is not limited to, microprocessors, application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.

[0069] The computer device can be any electronic product that can interact with users. For example, personal computers, tablets, smartphones, personal digital assistants (PDAs), game consoles, Internet Protocol Televisions (IPTVs), smart wearable devices, etc.

[0070] The computer device may also include network devices and / or user devices. Among them, the network devices include, but are not limited to, a single network server, a server group composed of multiple network servers, or a cloud composed of a large number of hosts or network servers based on cloud computing.

[0071] The server can be an independent server or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.

[0072] Among them, artificial intelligence (AI) is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use knowledge to obtain the best results.

[0073] Artificial intelligence basic technologies generally include technologies such as sensors, dedicated artificial intelligence chips, cloud computing, distributed storage, big data processing technologies, operation / interaction systems, and mechatronics. Artificial intelligence software technologies mainly include several major directions such as computer vision technology, robotics, biometric technology, speech processing technology, natural language processing technology, and machine learning / deep learning.

[0074] The network where the computer device is located includes, but is not limited to, the Internet, wide area network, metropolitan area network, local area network, virtual private network (VPN), etc.

[0075] S10. In response to a data desensitization instruction for a target system, determine the data to be processed in the target system.

[0076] In this embodiment, the target system includes a business system with data desensitization requirements, such as: online shopping malls associated with various enterprises, etc.

[0077] In this embodiment, the data desensitization instruction can be triggered by relevant staff, configured to be triggered regularly, or automatically triggered when data updates are detected. The present invention does not limit this.

[0078] In this embodiment, the data to be processed refers to sensitive data that needs to be desensitized, such as personal information like ID numbers, mobile phone numbers, bank card numbers, customer numbers, etc.

[0079] Specifically, obtain sensitive data such as ID numbers and mobile phone numbers from the target system, and determine the obtained data as the data to be processed.

[0080] S11. Retrieve the naming format, and rename the data to be processed according to the naming format to obtain first intermediate data.

[0081] In at least one embodiment of the present invention, the renaming the data to be processed according to the naming format to obtain first intermediate data includes:

[0082] Obtain the initial field name of the data to be processed;

[0083] Obtain a preset character from the naming format;

[0084] Concatenate the preset character with the initial field name of the data to be processed to obtain the first intermediate data.

[0085] For example: when the preset character is "enc", and there is a data item in the data to be processed with an initial field name of "XXX", according to the naming format, it can be named "enc_xxx".

[0086] Through the above implementation, the name of sensitive data is transformed according to a unified naming format, improving the readability of the data, facilitating subsequent calls, and improving the efficiency of data processing.

[0087] S12. Obtain incremental data from the first intermediate data, and perform a dual-write operation on the incremental data to obtain second intermediate data.

[0088] In this embodiment, obtaining incremental data from the first intermediate data includes:

[0089] Obtaining the data with changes within a preset time range;

[0090] Determining the data with changes as the incremental data.

[0091] Among them, the preset time range can be custom-configured, such as within 1 month.

[0092] In this embodiment, first perform incremental transformation on sensitive data, that is, the dual-write operation, then perform inventory cleaning, and finally perform single-write operation, so as to realize the desensitization of sensitive data.

[0093] Specifically, each operation in this embodiment can be implemented based on the JAVA8 Consumer language and the corresponding interfaces, and the present invention is not limited.

[0094] In at least one embodiment of the present invention, the dual-write operation and the single-write operation include add processing, update processing, query processing, and query result return processing. The dual-write operation on the incremental data includes:

[0095] When performing the add processing on the incremental data, obtain the plaintext of the incremental data, the set method of the plaintext field, the set method of the ciphertext field, and the set method of the encryption flag bit;

[0096] Determine the plaintext of the incremental data, the set method of the plaintext field, the set method of the ciphertext field, and the set method of the encryption flag bit as input parameters, and add the incremental data to obtain the ciphertext corresponding to the incremental data;

[0097] Decrypt the ciphertext corresponding to the incremental data to obtain the first decrypted data;

[0098] Verify the consistency between the first decrypted data and the plaintext of the incremental data;

[0099] When the first decrypted data is inconsistent with the plaintext of the incremental data, determine that the verification fails, and separately record the plaintext of the incremental data; or

[0100] When the first decrypted data is consistent with the plaintext of the incremental data, determine that the verification passes, and simultaneously record the plaintext of the incremental data and the ciphertext corresponding to the incremental data.

[0101] In the above embodiment, by verifying the consistency between the first decrypted data and the plaintext, it is possible to perform downgrade processing when an exception is captured, and only use the plaintext for related business processing, avoiding the recording of inconsistent ciphertexts resulting in data errors and affecting the business, with higher accuracy.

[0102] It should be noted that during the execution of the double-writing operation, the operation methods of the update process and the addition process are similar, except that the input parameters are different and need to be changed accordingly, which will not be elaborated here.

[0103] Furthermore, the double-writing operation on the incremental data further includes:

[0104] When performing the query process on the incremental data, detect the execution progress of the addition process and the update process;

[0105] When the execution progress indicates that the addition process and the update process are completed, clear the plaintext of the incremental data and perform the query using the ciphertext corresponding to the incremental data; or

[0106] When the execution progress indicates that the addition process and the update process are not completed, perform the query using the plaintext of the incremental data.

[0107] Through the above implementation manners, it is possible to avoid the incremental data being used for data query before being transformed completely, which may lead to query errors.

[0108] Furthermore, the double-writing operation on the incremental data further includes:

[0109] When performing the query result return process on the incremental data, detect whether the ciphertext corresponding to the incremental data is an empty field;

[0110] When the ciphertext corresponding to the incremental data is not an empty field, decrypt the ciphertext corresponding to the incremental data to obtain the second decrypted data;

[0111] Verify the consistency between the second decrypted data and the plaintext of the incremental data;

[0112] When the second decrypted data is inconsistent with the plaintext of the incremental data, determine that the verification fails and return the plaintext of the incremental data; or

[0113] When the second decrypted data is consistent with the plaintext of the incremental data, determine that the verification passes and return the second decrypted data.

[0114] Through the above implementation manners, it is possible to perform degradation processing during anomalies, directly return the plaintext as the query result, and avoid incorrect ciphertexts from causing errors in data query and affecting the correctness of data query.

[0115] In this embodiment, by means of double-writing of plaintext and ciphertext, it is ensured that the data can be used normally during the desensitization process, the transformation risk is reduced, and data loss will not occur.

[0116] S13. When it is detected that the double-writing operation is completed, obtain the stock data from the first intermediate data, and perform a cleaning operation on the stock data to obtain third intermediate data.

[0117] In this embodiment, the stock data refers to the data that has been historically stored and has not been modified within the preset time range.

[0118] In at least one embodiment of the present invention, the cleaning operation on the stock data includes:

[0119] Obtain a pre-established configuration file, where the configuration file is used to store the cleaning methods for each database table.

[0120] Obtain the to-be-executed JOB, and obtain multiple database tables corresponding to the to-be-executed JOB, and use them as multiple target database tables.

[0121] Query the cleaning method for each target database table in the configuration file as the target method for each target database table.

[0122] Obtain the primary key ID when the to-be-executed JOB was last executed from each target database table.

[0123] Obtain the pre-maintained ID range, and obtain multiple threads from a pre-established thread pool, where the number of the multiple threads is the same as the number of the multiple target database tables.

[0124] Starting from the primary key ID of each target database table, within the ID range, execute the to-be-executed JOB in parallel based on the target method and the multiple threads.

[0125] After the to-be-executed JOB is executed, collect the elapsed time and the data processing volume.

[0126] Update the ID range according to the elapsed time and the data processing volume.

[0127] In the above implementation, by configuring the ID range, it is possible to effectively reduce the data processing volume on the premise of ensuring accuracy, thereby improving efficiency.

[0128] For example: when querying data, if you want to query 10 pieces of data, you can configure the ID range to within 100 pieces of data. In this way, querying 10 pieces of data within 100 pieces of data can surely effectively reduce the query time compared with querying in the original stored hundreds of millions of pieces of data. At the same time, it can also ensure that there is sufficient data as support, without affecting the accuracy of data query, and also reducing the impact on the normal operation of the system.

[0129] In the above-described embodiment, by using multiple threads to perform asynchronous callbacks and streaming processing on each database table, the efficiency of data processing can be further improved, while reducing the mutual influence between different database tables.

[0130] In the above-described embodiment, after each JOB execution, the elapsed time and the amount of data processed are collected, and the ID range is updated accordingly to optimize the next processing method, further improving the effect of data cleaning.

[0131] Further, when maintaining the ID range, the amount of data processed can be continuously increased until the elapsed time reaches a threshold, and the ID range is determined according to the current amount of data processed.

[0132] The configuration of the configuration file, multiple threads, and ID range also facilitates the unified management and cleaning of data.

[0133] S14. When it is detected that the cleaning operation is completed, a union operation is performed on the second intermediate data and the third intermediate data to obtain fourth intermediate data.

[0134] In the above-described embodiment, the data obtained after performing the dual-write operation and the inventory cleaning operation is combined to obtain the fourth intermediate data for subsequent execution of the single-write operation.

[0135] S15. A single-write operation is performed on the fourth intermediate data to obtain the desensitized data corresponding to the data to be processed.

[0136] In at least one embodiment of the present invention, the performing a single-write operation on the fourth intermediate data to obtain the desensitized data corresponding to the data to be processed includes:

[0137] Obtaining the ciphertext corresponding to the fourth intermediate data;

[0138] Performing the new processing, and / or the update processing, and / or the query processing, and / or the query result return processing by using the ciphertext corresponding to the fourth intermediate data;

[0139] During the execution, when it is detected that there is a ciphertext that is inconsistent with the corresponding plaintext, an exception is thrown and the call fails is returned;

[0140] After the single-write operation is completed, the plaintext of the fourth intermediate data is cleared to obtain the desensitized data corresponding to the data to be processed.

[0141] Through the above-described embodiment, desensitization of data can be achieved without calling a large number of interfaces, realizing a more optimized desensitization process for sensitive data.

[0142] In other embodiments, according to pre-configured requirements, an index can also be added before the recorded ciphertext. In this way, the line where the ciphertext is located can be directly located through the index, improving the retrieval efficiency.

[0143] For example: according to the requirements of relevant business personnel, an index is added when recording mobile phone numbers, so that the corresponding mobile phone numbers can be queried more efficiently.

[0144] It should be noted that in order to further improve the security of data and prevent data from being maliciously tampered with, the desensitized data corresponding to the data to be processed can be stored in a blockchain node.

[0145] From the above technical solutions, it can be seen that the present invention can respond to a data desensitization instruction for a target system, determine the data to be processed in the target system, retrieve the naming format, and rename the data to be processed according to the naming format to obtain first intermediate data. By reforming the names of sensitive data according to a unified naming format, the readability of the data is improved, facilitating subsequent calls and improving the efficiency of data processing. Incremental data is obtained from the first intermediate data, and a dual-write operation is performed on the incremental data to obtain second intermediate data. By means of dual-writing of plaintext and ciphertext, it is ensured that the data can be used normally during the desensitization process, reducing the transformation risk and preventing data loss. When it is detected that the dual-write operation is completed, the stock data is obtained from the first intermediate data, and a cleaning operation is performed on the stock data to obtain third intermediate data. When it is detected that the cleaning operation is completed, a union operation is performed on the second intermediate data and the third intermediate data to obtain fourth intermediate data. A single-write operation is performed on the fourth intermediate data to obtain the desensitized data corresponding to the data to be processed. Without calling a large number of interfaces, data desensitization can be achieved, realizing more optimized desensitization processing of sensitive data.

[0146] As Figure 2 shown, it is a functional module diagram of a preferred embodiment of the data desensitization device of the present invention. The data desensitization device 11 includes a determination unit 110, a naming unit 111, a dual-write unit 112, a cleaning unit 113, an operation unit 114, and a single-write unit 115. The modules / units referred to in the present invention refer to a series of computer program segments that can be executed by a processor 13 and can complete fixed functions, and are stored in a memory 12. In this embodiment, the functions of each module / unit will be described in detail in subsequent embodiments.

[0147] In response to a data desensitization instruction for a target system, the determination unit 110 determines the data to be processed in the target system.

[0148] In this embodiment, the target system includes a business system with data desensitization requirements, such as: online shopping malls associated with various enterprises, etc.

[0149] In this embodiment, the data desensitization instruction can be triggered by relevant staff, configured to be triggered regularly, or automatically triggered when data updates are detected. The present invention does not limit this.

[0150] In this embodiment, the data to be processed refers to sensitive data that needs to be desensitized, such as personal information like ID numbers, mobile phone numbers, bank card numbers, customer numbers, etc.

[0151] Specifically, sensitive data such as ID numbers and mobile phone numbers are obtained from the target system, and the obtained data is determined as the data to be processed.

[0152] The naming unit 111 retrieves the naming format and renames the data to be processed according to the naming format to obtain the first intermediate data.

[0153] In at least one embodiment of the present invention, the naming unit 111 renaming the data to be processed according to the naming format to obtain the first intermediate data includes:

[0154] Obtain the initial field name of the data to be processed;

[0155] Obtain the preset character from the naming format;

[0156] Concatenate the preset character with the initial field name of the data to be processed to obtain the first intermediate data.

[0157] For example: when the preset character is enc, and there is a data with an initial field name of XXX in the data to be processed, according to the naming format, it can be named enc_xxx.

[0158] Through the above implementation method, the name of sensitive data is transformed according to a unified naming format, improving the readability of the data, facilitating subsequent calls, and improving the efficiency of data processing.

[0159] The double-writing unit 112 obtains the incremental data from the first intermediate data and performs a double-writing operation on the incremental data to obtain the second intermediate data.

[0160] In this embodiment, the obtaining the incremental data from the first intermediate data includes:

[0161] Obtain the data with changes within a preset time range;

[0162] Determine the data with changes as the incremental data.

[0163] Among them, the preset time range can be customized, such as within 1 month.

[0164] In this embodiment, the sensitive data is first incrementally transformed, i.e., the dual-write operation, then the stock cleaning is performed, and finally the single-write operation is performed, thereby realizing the desensitization of the sensitive data.

[0165] Specifically, each operation in this embodiment can be implemented based on the JAVA8 Consumer language and the corresponding interfaces, and the present invention is not limited.

[0166] In at least one embodiment of the present invention, the dual-write operation and the single-write operation include add processing, update processing, query processing, and query result return processing. The dual-write unit 112 performs a dual-write operation on the incremental data, including:

[0167] When performing the add processing on the incremental data, obtain the plaintext of the incremental data, the set method of the plaintext field, the set method of the ciphertext field, and the set method of the encryption flag bit;

[0168] Determine the plaintext of the incremental data, the set method of the plaintext field, the set method of the ciphertext field, and the set method of the encryption flag bit as input parameters, and add the incremental data to obtain the ciphertext corresponding to the incremental data;

[0169] Decrypt the ciphertext corresponding to the incremental data to obtain the first decrypted data;

[0170] Verify the consistency between the first decrypted data and the plaintext of the incremental data;

[0171] When the first decrypted data is inconsistent with the plaintext of the incremental data, determine that the verification fails, and separately record the plaintext of the incremental data; or

[0172] When the first decrypted data is consistent with the plaintext of the incremental data, determine that the verification passes, and simultaneously record the plaintext of the incremental data and the ciphertext corresponding to the incremental data.

[0173] In the above embodiment, by verifying the consistency between the first decrypted data and the plaintext, it is possible to perform a degradation process when an exception is captured, and only use the plaintext for the processing of related services, avoiding the recording of inconsistent ciphertexts resulting in data errors and affecting the services, with higher accuracy.

[0174] It should be noted that during the execution of the dual-write operation, the operation mode of the update processing is similar to that of the add processing, except that the input parameters are different and corresponding changes need to be made, which will not be elaborated here.

[0175] Furthermore, the dual-write unit 112 performing a dual-write operation on the incremental data further includes:

[0176] When performing the query processing on the incremental data, detect the execution progress of the new addition processing and the update processing;

[0177] When the execution progress indicates that the new addition processing and the update processing are completed, clear the plaintext of the incremental data, and perform the query using the ciphertext corresponding to the incremental data; or

[0178] When the execution progress indicates that the new addition processing and the update processing are not completed, perform the query using the plaintext of the incremental data.

[0179] Through the above implementation manners, it is possible to avoid the incremental data being used for data query before being transformed completely, which may cause query errors.

[0180] Further, the dual-writing operation of the incremental data by the dual-writing unit 112 further includes:

[0181] When performing the query result return processing on the incremental data, detect whether the ciphertext corresponding to the incremental data is an empty field;

[0182] When the ciphertext corresponding to the incremental data is not an empty field, decrypt the ciphertext corresponding to the incremental data to obtain the second decrypted data;

[0183] Verify the consistency between the second decrypted data and the plaintext of the incremental data;

[0184] When the second decrypted data is inconsistent with the plaintext of the incremental data, determine that the verification fails, and return the plaintext of the incremental data; or

[0185] When the second decrypted data is consistent with the plaintext of the incremental data, determine that the verification passes, and return the second decrypted data.

[0186] Through the above implementation manners, it is possible to perform degradation processing during anomalies, directly return the plaintext as the query result, and avoid incorrect ciphertexts from causing errors in data query, which affects the correctness of data query.

[0187] In this embodiment, by means of dual-writing of plaintext and ciphertext, it is ensured that the data can be used normally during the desensitization process, the transformation risk is reduced, and data loss will not occur.

[0188] When it is detected that the dual-writing operation is completed, the cleaning unit 113 obtains the stock data from the first intermediate data, and performs a cleaning operation on the stock data to obtain the third intermediate data.

[0189] In this embodiment, the stock data refers to the data that has been historically stored and has not been modified within the preset time range.

[0190] In at least one embodiment of the present invention, the cleaning operation of the cleaning unit 113 on the stock data includes:

[0191] Obtain a pre-established configuration file, wherein the configuration file is used to store the cleaning methods of each database table;

[0192] Obtain the JOB to be executed, and obtain multiple database tables corresponding to the JOB to be executed, and use them as multiple target database tables;

[0193] Query the cleaning method of each target database table in the configuration file as the target method of each target database table;

[0194] Obtain the primary key ID when the JOB to be executed was last executed from each target database table;

[0195] Obtain a pre-maintained ID range, and obtain multiple threads from a pre-established thread pool, wherein the number of the multiple threads is the same as the number of the multiple target database tables;

[0196] Starting from the primary key ID of each target database table, within the ID range, execute the JOB to be executed in parallel based on the target method and the multiple threads;

[0197] After the JOB to be executed is completed, collect the elapsed time and the data processing volume;

[0198] Update the ID range according to the elapsed time and the data processing volume.

[0199] In the above embodiment, by configuring the ID range, it is possible to effectively reduce the data processing volume on the premise of ensuring accuracy, thereby improving efficiency.

[0200] For example: when querying data, if you want to query 10 pieces of data, you can configure the ID range within 100 pieces of data. In this way, querying 10 pieces of data within 100 pieces of data can effectively reduce the query time compared with querying in the original stored hundreds of millions of pieces of data. At the same time, it can also ensure that there is sufficient data as support, which will not affect the accuracy of data query and also reduce the impact on the normal operation of the system.

[0201] In the above embodiment, using multiple threads to perform asynchronous callback and streaming processing on each database table can further improve the data processing efficiency and reduce the mutual influence between different database tables.

[0202] In the above embodiment, after each JOB is completed, collect the elapsed time and the data processing volume, and update the ID range accordingly to optimize the next processing method, further improving the data cleaning effect.

[0203] Furthermore, when maintaining the ID range, the data processing volume can be continuously increased until the time consumption reaches the threshold, and then the ID range is determined according to the current data processing volume.

[0204] The configuration of the configuration file, multi-threading, and ID range also facilitates the unified management and cleaning of data.

[0205] When it is detected that the cleaning operation is completed, the operation unit 114 performs a union operation on the second intermediate data and the third intermediate data to obtain fourth intermediate data.

[0206] In the above embodiment, the data obtained after performing the dual writing operation and the inventory cleaning operation is combined to obtain the fourth intermediate data for subsequent execution of the single writing operation.

[0207] The single writing unit 115 performs a single writing operation on the fourth intermediate data to obtain the desensitized data corresponding to the data to be processed.

[0208] In at least one embodiment of the present invention, the single writing unit 115 performing a single writing operation on the fourth intermediate data to obtain the desensitized data corresponding to the data to be processed includes:

[0209] Obtaining the ciphertext corresponding to the fourth intermediate data;

[0210] Performing the new processing, and / or the update processing, and / or the query processing, and / or the query result return processing by using the ciphertext corresponding to the fourth intermediate data;

[0211] During the execution, when it is detected that there is an inconsistency between the ciphertext and the corresponding plaintext, an exception is thrown and the call fails is returned;

[0212] After the single writing operation is completed, the plaintext of the fourth intermediate data is cleared to obtain the desensitized data corresponding to the data to be processed.

[0213] Through the above embodiment, desensitization of data can be achieved without calling a large number of interfaces, realizing more optimized desensitization processing of sensitive data.

[0214] In other embodiments, according to the pre-configured requirements, an index can also be added before the recorded ciphertext. In this way, the row where the ciphertext is located can be directly located through the index, improving the retrieval efficiency.

[0215] For example: according to the requirements of relevant business personnel, an index is added when recording the mobile phone number, so that the corresponding mobile phone number can be queried more efficiently.

[0216] It should be noted that, in order to further improve data security and prevent data from being maliciously tampered with, the desensitized data corresponding to the data to be processed can be stored in a blockchain node.

[0217] As can be seen from the above technical solutions, the present invention can respond to a data desensitization instruction for a target system, determine the data to be processed in the target system, retrieve a naming format, and rename the data to be processed according to the naming format to obtain first intermediate data. By reforming the names of sensitive data according to a unified naming format, the readability of the data is improved, facilitating subsequent calls and enhancing the efficiency of data processing. The incremental data is obtained from the first intermediate data, and a dual-write operation is performed on the incremental data to obtain second intermediate data. By means of dual-writing plaintext and ciphertext, it is ensured that the data can be normally used during the desensitization process, reducing the transformation risk and preventing data loss. When it is detected that the dual-write operation is completed, the stock data is obtained from the first intermediate data, and a cleaning operation is performed on the stock data to obtain third intermediate data. When it is detected that the cleaning operation is completed, a union operation is performed on the second intermediate data and the third intermediate data to obtain fourth intermediate data. A single-write operation is performed on the fourth intermediate data to obtain the desensitized data corresponding to the data to be processed. Desensitization of the data can be achieved without calling a large number of interfaces, realizing a more optimized desensitization process for sensitive data.

[0218] As Figure 3 shown, it is a schematic structural diagram of a computer device according to a preferred embodiment of the method for implementing data desensitization of the present invention.

[0219] The computer device 1 may include a memory 12, a processor 13, and a bus, and may also include a computer program stored in the memory 12 and executable on the processor 13, such as a data desensitization program.

[0220] Those skilled in the art can understand that the schematic diagram is only an example of the computer device 1 and does not constitute a limitation on the computer device 1. The computer device 1 can be either a bus structure or a star structure. The computer device 1 may also include more or fewer other hardware or software than shown, or different component arrangements. For example, the computer device 1 may also include input / output devices, network access devices, etc.

[0221] It should be noted that the computer device 1 is only an example, and other existing or future electronic products that can be adapted to the present invention should also be included within the protection scope of the present invention and are hereby incorporated by reference.

[0222] Among them, the memory 12 includes at least one type of readable storage medium, and the readable storage medium includes flash memory, mobile hard disks, multimedia cards, card-type memories (such as SD or DX memories, etc.), magnetic memories, magnetic disks, optical disks, etc. In some embodiments, the memory 12 can be an internal storage unit of the computer device 1, such as the mobile hard disk of the computer device 1. In other embodiments, the memory 12 can also be an external storage device of the computer device 1, such as a plug-in mobile hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. equipped on the computer device 1. Further, the memory 12 can also include both an internal storage unit and an external storage device of the computer device 1. The memory 12 can not only be used to store application software installed in the computer device 1 and various types of data, such as the code of the data desensitization program, etc., but also be used to temporarily store data that has been output or will be output.

[0223] In some embodiments, the processor 13 can be composed of integrated circuits. For example, it can be composed of a single packaged integrated circuit, or can be composed of multiple integrated circuits with the same or different functions packaged, including a combination of one or more Central Processing Units (CPUs), microprocessors, digital processing chips, graphics processors, and various control chips, etc. The processor 13 is the control core (Control Unit) of the computer device 1, connecting various components of the entire computer device 1 through various interfaces and circuits. By running or executing programs or modules stored in the memory 12 (such as executing the data desensitization program, etc.), and calling data stored in the memory 12, it performs various functions of the computer device 1 and processes data.

[0224] The processor 13 executes the operating system of the computer device 1 and various installed application programs. The processor 13 executes the application programs to implement the steps in the above embodiments of each data desensitization method, such as Figure 1 the steps shown.

[0225] Exemplarily, the computer program may be divided into one or more modules / units, which are stored in the memory 12 and executed by the processor 13 to implement the present invention. The one or more modules / units may be a series of computer-readable instruction segments capable of performing specific functions, and these instruction segments are used to describe the execution process of the computer program in the computer device 1. For example, the computer program may be divided into a determination unit 110, a naming unit 111, a duplicate writing unit 112, a cleaning unit 113, an arithmetic unit 114, and a single writing unit 115.

[0226] The integrated units implemented in the form of software function modules may be stored in a computer-readable storage medium. The above-mentioned software function modules stored in a storage medium include several instructions for causing a computer device (which may be a personal computer, a computer device, or a network device, etc.) or a processor to execute a part of the data desensitization method according to each embodiment of the present invention.

[0227] If the integrated module / unit of the computer device 1 is implemented in the form of a software function unit and sold or used as an independent product, it may be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above-mentioned embodiment methods of the present invention, it may also be completed by a computer program instructing relevant hardware devices. The computer program may be stored in a computer-readable storage medium, and when the computer program is executed by a processor, the steps of the above-mentioned various method embodiments may be implemented.

[0228] Among them, the computer program includes computer program code, and the computer program code may be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium may include: any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a mobile hard disk, a magnetic disk, an optical disc, a computer memory, a read-only memory (ROM, Read-Only Memory), a random access memory, etc.

[0229] Furthermore, the computer-readable storage medium mainly includes a program storage area and a data storage area. Among them, the program storage area may store an operating system, application programs required for at least one function, etc.; the data storage area may store data created according to the use of the blockchain node, etc.

[0230] The blockchain referred to in the present invention is a new application mode of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithm. Blockchain, in essence, is a decentralized database, a string of data blocks generated by using cryptographic methods. Each data block contains information about a batch of network transactions, which is used to verify the validity of the information (anti-counterfeiting) and generate the next block. The blockchain can include the blockchain underlying platform, the platform product service layer, and the application service layer, etc.

[0231] The bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, in Figure 3 it is only represented by a single straight line, but it does not mean that there is only one bus or one type of bus. The bus is arranged to implement the connection and communication between the memory 12 and at least one processor 13, etc.

[0232] Although not shown, the computer device 1 may further include a power supply (such as a battery) for powering each component. Preferably, the power supply can be logically connected to the at least one processor 13 through a power management device, so as to implement functions such as charge management, discharge management, and power consumption management through the power management device. The power supply may further include any components such as one or more DC or AC power supplies, a recharge device, a power failure detection circuit, a power converter or inverter, and a power status indicator. The computer device 1 may further include a variety of sensors, a Bluetooth module, a Wi-Fi module, etc., which will not be elaborated here.

[0233] Furthermore, the computer device 1 may further include a network interface. Optionally, the network interface may include a wired interface and / or a wireless interface (such as a WI-FI interface, a Bluetooth interface, etc.), which is usually used to establish a communication connection between the computer device 1 and other computer devices.

[0234] Optionally, the computer device 1 may further include a user interface, which may be a display, an input unit (such as a keyboard), and optionally, the user interface may also be a standard wired interface or a wireless interface. Optionally, in some embodiments, the display may be an LED display, a liquid crystal display, a touch liquid crystal display, and an OLED (Organic Light-Emitting Diode) toucher, etc. Among them, the display may also be appropriately referred to as a display screen or a display unit, which is used to display the information processed in the computer device 1 and to display a visual user interface.

[0235] It should be understood that the above embodiments are only for illustrative purposes and are not limited by this structure in the scope of the patent application.

[0236] Figure 3 Only the computer device 1 with components 12 - 13 is shown. Those skilled in the art can understand that Figure 3 the shown structure does not limit the computer device 1, and it may include fewer or more components than shown, or combine some components, or have different component arrangements.

[0237] Combined with Figure 1 , the memory 12 in the computer device 1 stores a plurality of instructions to implement a data desensitization method, and the processor 13 can execute the plurality of instructions to implement:

[0238] In response to a data desensitization instruction for a target system, determine the data to be processed in the target system;

[0239] Retrieve a naming format, and rename the data to be processed according to the naming format to obtain first intermediate data;

[0240] Obtain incremental data from the first intermediate data, and perform a dual-write operation on the incremental data to obtain second intermediate data;

[0241] When it is detected that the dual-write operation is completed, obtain the stock data from the first intermediate data, and perform a cleaning operation on the stock data to obtain third intermediate data;

[0242] When it is detected that the cleaning operation is completed, perform a union operation on the second intermediate data and the third intermediate data to obtain fourth intermediate data;

[0243] Perform a single-write operation on the fourth intermediate data to obtain the desensitized data corresponding to the data to be processed.

[0244] Specifically, for the specific implementation method of the above instructions by the processor 13, reference can be made toFigure 1 Descriptions of relevant steps in corresponding embodiments are not elaborated here.

[0245] In several embodiments provided by the present invention, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division, and there may be other division methods in actual implementation.

[0246] The present invention can be used in numerous general-purpose or special-purpose computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multi-processor systems, microprocessor-based systems, set-top boxes, programmable consumer electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and so on. The present invention can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present invention can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.

[0247] The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0248] In addition, in each embodiment of the present invention, the functional modules can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a hardware plus software functional module.

[0249] For those skilled in the art, it is obvious that the present invention is not limited to the details of the above-described exemplary embodiments, and without departing from the spirit or basic characteristics of the present invention, the present invention can be implemented in other specific forms.

[0250] Therefore, in any aspect, the embodiments should be regarded as exemplary and non-limiting. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the claims are intended to be embraced by the present invention. Any reference signs in the claims should not be construed as limiting the claims concerned.

[0251] In addition, it is obvious that the word "comprising" does not exclude other elements or steps, and the singular does not exclude the plural. A plurality of elements or devices described in the present invention can also be implemented by one element or device through software or hardware. The terms "first", "second", etc. are used to denote names and do not denote any particular order.

[0252] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention.

Claims

1. A data desensitization method, characterized in that, the data desensitization method includes: responding to a data desensitization instruction for a target system, determining the data to be processed in the target system; retrieving a naming format, and renaming the data to be processed according to the naming format to obtain first intermediate data; obtaining incremental data from the first intermediate data, and performing a dual-write operation on the incremental data to obtain second intermediate data; when it is detected that the dual-write operation is completed, obtaining stock data from the first intermediate data, and performing a cleaning operation on the stock data to obtain third intermediate data; when it is detected that the cleaning operation is completed, performing a union operation on the second intermediate data and the third intermediate data to obtain fourth intermediate data; performing a single-write operation on the fourth intermediate data to obtain the desensitized data corresponding to the data to be processed; the performing a dual-write operation on the incremental data further includes: when performing a query process on the incremental data, detecting the execution progress of the new addition process and the update process; when the execution progress indicates that the new addition process and the update process are completed, clearing the plaintext of the incremental data, and performing a query using the ciphertext corresponding to the incremental data; or when the execution progress indicates that the new addition process and the update process are not completed, performing a query using the plaintext of the incremental data; the performing a dual-write operation on the incremental data further includes: when performing a query result return process on the incremental data, detecting whether the ciphertext corresponding to the incremental data is an empty field; when the ciphertext corresponding to the incremental data is not an empty field, decrypting the ciphertext corresponding to the incremental data to obtain second decrypted data; verifying the consistency between the second decrypted data and the plaintext of the incremental data; when the second decrypted data is inconsistent with the plaintext of the incremental data, determining that the verification fails, and returning the plaintext of the incremental data; or when the second decrypted data is consistent with the plaintext of the incremental data, determining that the verification passes, and returning the second decrypted data; the performing a single-write operation on the fourth intermediate data to obtain the desensitized data corresponding to the data to be processed includes: obtaining the ciphertext corresponding to the fourth intermediate data; performing the new addition process, and / or the update process, and / or the query process, and / or the query result return process using the ciphertext corresponding to the fourth intermediate data; during the execution process, when it is detected that there is an inconsistency between the ciphertext and the corresponding plaintext, throwing an exception and returning a call failure; after the single-write operation is completed, clearing the plaintext of the fourth intermediate data to obtain the desensitized data corresponding to the data to be processed.

2. The data desensitization method according to claim 1, characterized in that, the renaming the data to be processed according to the naming format to obtain first intermediate data includes: obtaining the initial field name of the data to be processed; obtaining a preset character from the naming format; concatenating the preset character and the initial field name of the data to be processed to obtain the first intermediate data.

3. The data desensitization method according to claim 1, characterized in that, The double writing operation and the single writing operation include addition processing, update processing, query processing, and query result return processing. The double writing operation on the incremental data includes: When performing the addition processing on the incremental data, obtain the plaintext of the incremental data, the set method of the plaintext fields, the set method of the ciphertext fields, and the set method of the encryption flag bit; Determine the plaintext of the incremental data, the set method of the plaintext fields, the set method of the ciphertext fields, and the set method of the encryption flag bit as input parameters, and add the incremental data to obtain the ciphertext corresponding to the incremental data; Decrypt the ciphertext corresponding to the incremental data to obtain the first decrypted data; Verify the consistency between the first decrypted data and the plaintext of the incremental data; When the first decrypted data is inconsistent with the plaintext of the incremental data, determine that the verification fails and separately record the plaintext of the incremental data; or When the first decrypted data is consistent with the plaintext of the incremental data, determine that the verification passes and simultaneously record the plaintext of the incremental data and the ciphertext corresponding to the incremental data.

4. The data desensitization method according to claim 1, characterized in that The cleaning operation on the stock data includes: Obtain a pre-established configuration file, where the configuration file is used to store the cleaning methods of each database table; Obtain the to-be-executed JOB, and obtain multiple database tables corresponding to the to-be-executed JOB, and use them as multiple target database tables; Query the cleaning method of each target database table in the configuration file as the target method of each target database table; Obtain the primary key ID when the to-be-executed JOB was last executed from each target database table; Obtain a pre-maintained ID range, and obtain multiple threads from a pre-established thread pool, where the number of the multiple threads is the same as the number of the multiple target database tables; Starting from the primary key ID of each target database table, within the ID range, execute the to-be-executed JOB in parallel based on the target method and the multiple threads; After the to-be-executed JOB is executed, collect the elapsed time and the data processing volume; Update the ID range according to the elapsed time and the data processing volume.

5. A data desensitization device, characterized in that The data desensitization device includes: A determination unit, configured to determine the data to be processed in the target system in response to a data desensitization instruction for the target system; A naming unit, configured to retrieve a naming format and rename the data to be processed according to the naming format to obtain first intermediate data; A double writing unit, configured to obtain incremental data from the first intermediate data and perform a double writing operation on the incremental data to obtain second intermediate data; A cleaning unit, configured to, when detecting that the double writing operation is completed, obtain stock data from the first intermediate data and perform a cleaning operation on the stock data to obtain third intermediate data; An operation unit, configured to, when detecting that the cleaning operation is completed, perform a union operation on the second intermediate data and the third intermediate data to obtain fourth intermediate data; A single-write unit for performing a single-write operation on the fourth intermediate data to obtain the desensitized data corresponding to the data to be processed; The double-write operation of the double-write unit on the incremental data further includes: When performing a query process on the incremental data, detecting the execution progress of the new addition process and the update process; When the execution progress indicates that the new addition process and the update process are completed, clearing the plaintext of the incremental data and performing a query using the ciphertext corresponding to the incremental data; or When the execution progress indicates that the new addition process and the update process are not completed, performing a query using the plaintext of the incremental data; The double-write operation of the double-write unit on the incremental data further includes: When performing a query result return process on the incremental data, detecting whether the ciphertext corresponding to the incremental data is an empty field; When the ciphertext corresponding to the incremental data is not an empty field, decrypting the ciphertext corresponding to the incremental data to obtain second decrypted data; Verifying the consistency between the second decrypted data and the plaintext of the incremental data; When the second decrypted data is inconsistent with the plaintext of the incremental data, determining that the verification fails and returning the plaintext of the incremental data; or When the second decrypted data is consistent with the plaintext of the incremental data, determining that the verification passes and returning the second decrypted data; The single-write operation of the single-write unit on the fourth intermediate data to obtain the desensitized data corresponding to the data to be processed includes: Obtaining the ciphertext corresponding to the fourth intermediate data; Performing the new addition process, and / or the update process, and / or the query process, and / or the query result return process using the ciphertext corresponding to the fourth intermediate data; During the execution process, when it is detected that there is an inconsistency between the ciphertext and the corresponding plaintext, throwing an exception and returning a call failure; After the single-write operation is completed, clearing the plaintext of the fourth intermediate data to obtain the desensitized data corresponding to the data to be processed.

6. A computer device, Characterized in that, The computer device includes: A memory storing at least one instruction; and A processor executing the instructions stored in the memory to implement the data desensitization method according to any one of claims 1 to 4.

7. A computer-readable storage medium, Characterized in that: At least one instruction is stored in the computer-readable storage medium, and the at least one instruction is executed by a processor in a computer device to implement the data desensitization method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Systems and methods for data desensitization

    CN106233315A

  • Method and system of data masking

    CN106778288A