Data Processing Method, Apparatus, Device, and Storage Medium

The method improves sensitivity recognition accuracy by dynamically assessing user and data history to tailor sensitivity detection, allowing authorized users to access unmasked data while maintaining security.

CN114329525BActive Publication Date: 2025-07-15CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111553240.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-17
Publication Date
2025-07-15
Estimated Expiration
2041-12-17

AI Technical Summary

Technical Problem

The existing sensitive data identification methods are not targeted, resulting in poor accuracy of sensitive data identification results and the inability to provide personalized sensitive data identification results based on user situations.

Method used

By obtaining the historical access behavior indicator information of the target user and the historical access information of the file belonging to the to-process data, the sensitivity of the target user and the to-process data is calculated, dynamically determine whether the data is sensitive data, and perform corresponding desensitization processing.

Benefits of technology

It realizes the personalized sensitive data identification results based on user historical access behavior, improves the accuracy of sensitive data identification, and ensures that users can access the required data normally.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114329525B_ABST
    Figure CN114329525B_ABST
Patent Text Reader

Abstract

The present disclosure provides a data processing method, apparatus, device, and storage medium, relating to the field of data security. The method includes: in response to a target user's request to access data to be processed, obtaining historical access behavior metric information of the target user; obtaining the sensitivity of the target user based on the historical access behavior metric information of the target user; obtaining historical access information of the file to which the data to be processed belongs; obtaining the sensitivity of the file to which the data to be processed belongs based on the historical access information of the file to which the data to be processed belongs; determining whether the data to be processed is sensitive data according to the sensitivity of the target user and the sensitivity of the file to which the data to be processed belongs; if it is determined that the data to be processed is sensitive data, performing desensitization processing on the data to be processed so that the target user accesses the desensitized data. This method improves the accuracy of the identification result of sensitive data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of data security technologies, and in particular, to a data processing method, apparatus, device, and readable storage medium. Background Art

[0002] With the advent of the big data era, data has become the core asset of enterprises. The security protection, effective control, and reasonable utilization of data assets are all key concerns of enterprises. The desensitization protection of data is a commonly used processing method for realizing data security. In related technologies, preset sensitive words are adopted and matching methods such as keyword detection and regular expression matching are used for sensitive content detection. The sensitive data recognition results and desensitization processing of this unified sensitive data recognition method are the same for all users. As a result, users who need to view the real data can only see the desensitized data and cannot see the real data. Therefore, the accuracy of this sensitive data recognition method lacking pertinence is relatively poor.

[0003] As described above, how to improve the accuracy of the sensitive data recognition method has become an urgent problem to be solved.

[0004] The above information disclosed in the background art section is only used to enhance the understanding of the background of the present disclosure. Therefore, it may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention

[0005] The purpose of the present disclosure is to provide a data processing method, apparatus, device, and readable storage medium, which can at least improve the accuracy of the sensitive data recognition method to a certain extent.

[0006] Other features and advantages of the present disclosure will become apparent through the following detailed description, or be learned in part through the practice of the present disclosure.

[0007] According to an aspect of the present disclosure, there is provided a data processing method, including: in response to a target user's request to access data to be processed, obtaining the historical access behavior index information of the target user; obtaining the sensitivity of the target user based on the historical access behavior index information of the target user; obtaining the historical access information of the file to which the data to be processed belongs; obtaining the sensitivity of the file to which the data to be processed belongs based on the historical access information of the file to which the data to be processed belongs; determining whether the data to be processed is sensitive data according to the sensitivity of the target user and the sensitivity of the file to which the data to be processed belongs; if it is determined that the data to be processed is sensitive data, performing desensitization processing on the data to be processed so that the target user accesses the desensitized data.

[0008] According to an embodiment of the present disclosure, in response to a target user's request to access data to be processed, obtain the historical access behavior metric information of the target user, including: in response to the target user's request to access the data to be processed, obtain the identifier of the target user; obtain the standard sensitive data volume in the target user's historical access files according to the identifier of the target user; obtain the actual sensitive data volume that has been desensitized for the target user in the target user's historical access files according to the identifier of the target user; obtain the historical access user information of the target user's historical access files; and obtain the historical access behavior metric information of the target user according to the standard sensitive data volume and the actual sensitive data volume in the target user's historical access files, as well as the historical access user information of the target user's historical access files.

[0009] According to an embodiment of the present disclosure, obtain the sensitivity of the target user based on the historical access behavior metric information of the target user, including: obtain the security metric information of the target user according to the identifier of the target user; and obtain the sensitivity of the target user according to the security metric information of the target user and the historical access behavior metric information of the target user.

[0010] According to an embodiment of the present disclosure, the method further includes: in response to the target user's request to access the data to be processed, obtain the identifier of the data to be processed; obtain the standard sensitive data volume in the file to which the data to be processed belongs according to the identifier of the data to be processed; the historical access information of the file to which the data to be processed belongs includes the standard sensitive data volume in the file to which the data to be processed belongs, the actual sensitive data that has been desensitized for its historical access users in the file to which the data to be processed belongs, and the security metric information of the historical access users of the file to which the data to be processed belongs; obtain the historical access information of the file to which the data to be processed belongs, including: obtain the security metric information of the historical access users of the file to which the data to be processed belongs according to the identifier of the data to be processed; obtain the actual sensitive data volume that has been desensitized for its historical access users in the file to which the data to be processed belongs based on the identifier of the data to be processed; and obtain the sensitivity of the file to which the data to be processed belongs based on the historical access information of the file to which the data to be processed belongs, including: obtain the sensitivity of the file to which the data to be processed belongs according to the standard sensitive data volume and the actual sensitive data volume in the file to which the data to be processed belongs, as well as the security metric information of the corresponding historical access users.

[0011] According to an embodiment of the present disclosure, the security metric information of the historical access users of the file to which the data to be processed belongs includes the security metric values of the historical access users of the file to which the data to be processed belongs, the number of historical access users meeting the target conditions, and the average security metric value of the historical access users of the file to which the data to be processed belongs; obtaining the historical access information of the file to which the data to be processed belongs further includes: obtaining the security metric value of the historical access users of the file to which the data to be processed belongs according to the identifier of the data to be processed; obtaining the number of historical access users meeting the target conditions according to the security metric value; and obtaining the average security metric value of the historical access users of the file to which the data to be processed belongs according to the security metric value.

[0012] According to an embodiment of the present disclosure, judging whether the data to be processed is sensitive data according to the sensitivity of the target user and the sensitivity of the file to which the data to be processed belongs includes: judging whether there are historical access users of the file to which the data to be processed belongs whose security metric values are higher than the security metric value of the target user based on the historical access information of the file to which the data to be processed belongs; if there are no historical access users of the file to which the data to be processed belongs whose security metric values are higher than the target user, then when the sensitivity of the target user is less than the sensitivity of the file to which the data to be processed belongs, determining that the data to be processed is sensitive data.

[0013] According to an embodiment of the present disclosure, judging whether the data to be processed is sensitive data according to the sensitivity of the target user and the sensitivity of the file to which the data to be processed belongs further includes: if there are historical access users of the file to which the data to be processed belongs whose security metric values are higher than the target user, obtaining a first user number, where the first user number is the number of historical access users of the file to which the data to be processed belongs whose security metric values are higher than the target user; obtaining the standard sensitive data in the data to be processed; obtaining a second user number among the historical access users of the file to which the data to be processed belongs whose security metric values are higher than the target user and who perform desensitization processing on the standard sensitive data in the data to be processed; and when the product of the sensitivity of the target user and the ratio of the second user number to the first user number is less than the sensitivity of the file to which the data to be processed belongs, determining that the data to be processed is sensitive data.

[0014] According to another aspect of the present disclosure, there is provided a data processing device, including: an obtaining module, configured to obtain the historical access behavior metric information of the target user in response to a target user's request to access data to be processed; the obtaining module is further configured to obtain the sensitivity of the target user based on the historical access behavior metric information of the target user; the obtaining module is further configured to obtain the historical access information of the file to which the data to be processed belongs; the obtaining module is further configured to obtain the sensitivity of the file to which the data to be processed belongs based on the historical access information of the file to which the data to be processed belongs; a judging module, configured to judge whether the data to be processed is sensitive data according to the sensitivity of the target user and the sensitivity of the file to which the data to be processed belongs; a processing module, configured to, if it is determined that the data to be processed is sensitive data, perform desensitization processing on the data to be processed so that the target user accesses the desensitized data.

[0015] According to an embodiment of the present disclosure, the device further includes: an acquiring module, configured to acquire the identifier of the target user in response to the target user's request to access the data to be processed; the obtaining module is further configured to obtain the standard sensitive data volume in the target user's historical access files according to the identifier of the target user; the obtaining module is further configured to obtain the actual sensitive data volume desensitized for the target user in the target user's historical access files according to the identifier of the target user; the obtaining module is further configured to obtain the historical access user information of the target user's historical access files; the obtaining module is further configured to obtain the historical access behavior metric information of the target user according to the standard sensitive data volume and the actual sensitive data volume in the target user's historical access files, and the historical access user information of the target user's historical access files.

[0016] According to an embodiment of the present disclosure, the obtaining module is further configured to: obtain the security metric information of the target user according to the identifier of the target user; and obtain the sensitivity of the target user according to the security metric information of the target user and the historical access behavior metric information of the target user.

[0017] According to an embodiment of the present disclosure, the obtaining module is further configured to obtain an identifier of the data to be processed in response to the target user's request to access the data to be processed; the acquiring module is further configured to obtain the standard sensitive data volume in the file to which the data to be processed belongs according to the identifier of the data to be processed; the historical access information of the file to which the data to be processed belongs includes the standard sensitive data volume in the file to which the data to be processed belongs, the actual sensitive data desensitized for its historical access users in the file to which the data to be processed belongs, and the security index information of the historical access users of the file to which the data to be processed belongs; the acquiring module is further configured to: obtain the security index information of the historical access users of the file to which the data to be processed belongs according to the identifier of the data to be processed; obtain the actual sensitive data volume desensitized for its historical access users in the file to which the data to be processed belongs based on the identifier of the data to be processed; and obtain the sensitivity of the file to which the data to be processed belongs according to the standard sensitive data volume and the actual sensitive data volume in the file to which the data to be processed belongs, and the corresponding security index information of the historical access users.

[0018] According to an embodiment of the present disclosure, the security index information of the historical access users of the file to which the data to be processed belongs includes the security index value of the historical access users of the file to which the data to be processed belongs, the number of historical access users meeting the target conditions, and the average security index of the historical access users of the file to which the data to be processed belongs; the acquiring module is further configured to: obtain the security index value of the historical access users of the file to which the data to be processed belongs according to the identifier of the data to be processed; obtain the number of historical access users meeting the target conditions according to the security index value; and obtain the average security index of the historical access users of the file to which the data to be processed belongs according to the security index value.

[0019] According to an embodiment of the present disclosure, the judging module is further configured to: judge whether there are historical access users of the file to which the data to be processed belongs whose security index value is higher than the security index value of the target user based on the historical access information of the file to which the data to be processed belongs; if there are no historical access users of the file to which the data to be processed belongs whose security index value is higher than that of the target user, then when the sensitivity of the target user is less than the sensitivity of the file to which the data to be processed belongs, determine that the data to be processed is sensitive data.

[0020] According to an embodiment of the present disclosure, the obtaining module is further configured to, if there are historical access users of the file to which the to-be-processed data of the target user belongs and whose security metric values are higher than those of the target user, obtain a first user number, where the first user number is the number of historical access users of the file to which the to-be-processed data of the target user belongs and whose security metric values are higher than those of the target user; the obtaining module is further configured to obtain standard sensitive data in the to-be-processed data; the obtaining module is further configured to obtain a second user number among the historical access users of the file to which the to-be-processed data of the target user belongs and whose security metric values are higher than those of the target user, and who perform desensitization processing on the standard sensitive data in the to-be-processed data; the determining module is further configured to: when the product of the sensitivity of the target user and the ratio of the second user number to the first user number is less than the sensitivity of the file to which the to-be-processed data belongs, determine that the to-be-processed data is sensitive data.

[0021] According to another aspect of the present disclosure, there is provided a device, including: a memory, a processor, and executable instructions stored in the memory and executable in the processor, where when the processor executes the executable instructions, the methods described above are implemented.

[0022] According to another aspect of the present disclosure, there is provided a computer-readable storage medium, on which computer-executable instructions are stored, and when the executable instructions are executed by a processor, the methods described above are implemented.

[0023] The data processing method provided by the embodiments of the present disclosure responds to a target user's request to access to-be-processed data, obtains target user historical access behavior metric information, obtains the sensitivity of the target user based on the target user historical access behavior metric information, then obtains the historical access information of the file to which the to-be-processed data belongs, obtains the sensitivity of the file to which the to-be-processed data belongs based on the historical access information of the file to which the to-be-processed data belongs, then determines whether the to-be-processed data is sensitive data according to the sensitivity of the target user and the sensitivity of the file to which the to-be-processed data belongs. If it is determined that the to-be-processed data is sensitive data, desensitization processing is performed on the to-be-processed data so that the target user accesses the desensitized data, thereby sensitive data can be identified by integrating the target user historical access behavior metric information and the historical access information of the file to which the to-be-processed data belongs, and different sensitive data identification results can be provided according to different user historical access behavior situations, improving the accuracy of the sensitive data identification result.

[0024] It should be understood that the above general description and the following detailed description are only exemplary and do not limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] By referring to the accompanying drawings and describing its exemplary embodiments in detail, the above and other objectives, features, and advantages of the present disclosure will become more apparent.

[0026] Figure 1 A schematic diagram showing a system structure in an embodiment of the present disclosure.

[0027] Figure 2 A flowchart showing a data processing method in an embodiment of the present disclosure.

[0028] Figure 3 Shows Figure 2 A schematic diagram of the processing procedure of step S202 shown in

[0029] Figure 4 Shows Figure 2 A schematic diagram of the processing procedure of step S204 shown in

[0030] Figure 5 Shows Figure 2 A schematic diagram of the processing procedure of step S206 and step S208 shown in

[0031] Figure 6 Shows Figure 2 A schematic diagram of the processing procedure of step S206 shown in another embodiment

[0032] Figure 7 Shows Figure 2 A schematic diagram of the processing procedure of step S210 shown in

[0033] Figure 8 A block diagram showing a data processing device in an embodiment of the present disclosure.

[0034] Figure 9 A block diagram showing another data processing device in an embodiment of the present disclosure.

[0035] Figure 10 A schematic diagram showing the structure of an electronic device in an embodiment of the present disclosure. Detailed implementation manners

[0036] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art. The drawings are merely schematic illustrations of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and thus their repeated description will be omitted.

[0037] In addition, the described features, structures, or characteristics may be combined in one or more embodiments in any suitable manner. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present disclosure. However, those skilled in the art will realize that one or more of the specific details may be omitted in practicing the technical solutions of the present disclosure, or other methods, devices, steps, etc. may be adopted. In other cases, well-known structures, methods, devices, implementations, or operations are not shown or described in detail to avoid obscuring various aspects of the present disclosure.

[0038] In addition, terms such as "first", "second", etc. are only used for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first", "second" may explicitly or implicitly include one or more of such features. In the description of the present disclosure, the meaning of "a plurality" is at least two, such as two, three, etc., unless otherwise specifically and clearly defined. The symbol " / " generally indicates that the related objects before and after are in an "or" relationship.

[0039] In the present disclosure, unless otherwise clearly specified and limited, terms such as "connection" should be understood in a broad sense. For example, it may be an electrical connection or may communicate with each other; it may be directly connected or indirectly connected through an intermediate medium. For those of ordinary skill in the art, the specific meanings of the above terms in the present disclosure can be understood according to specific circumstances.

[0040] As described above, in the related art, preset sensitive words are adopted and matching methods such as keyword detection and regular matching are used for sensitive content detection. However, usually, whether data is sensitive is related to the user who views the data. For example, for the same ID number, it is sensitive data for ordinary users and needs to be desensitized, but for service personnel handling business, it can be visible data, that is, no longer regarded as sensitive data. The above-mentioned related art does not consider the user situation when identifying sensitive content and only performs unified identification, which will cause the situation that the user who needs to view the data cannot see the real data, thus affecting the normal work of the user.

[0041] Therefore, the present disclosure provides a data processing method. In response to a target user's request to access data to be processed, historical access behavior metric information of the target user is obtained, and the sensitivity of the target user is obtained based on the historical access behavior metric information of the target user. Then, historical access information of the file to which the data to be processed belongs is obtained, and the sensitivity of the file to which the data to be processed belongs is obtained based on the historical access information of the file to which the data to be processed belongs. Then, it is determined whether the data to be processed is sensitive data according to the sensitivity of the target user and the sensitivity of the file to which the data to be processed belongs. If it is determined that the data to be processed is sensitive data, the data to be processed is desensitized so that the target user can access the desensitized data. Thus, sensitive data can be identified by integrating the historical access behavior metric information of the target user and the historical access information of the file to which the data to be processed belongs, and different sensitive data identification results can be provided according to different historical access behavior situations of users, improving the accuracy of the sensitive data identification method.

[0042] Figure 1 FIG. 10 shows an exemplary system architecture 10 to which the data processing method or data processing apparatus of the present disclosure can be applied.

[0043] As Figure 1 shown, the system architecture 10 may include a terminal device 102, a network 104, and a server 106. The terminal device 102 may be various electronic devices having a display screen and supporting input and output, including but not limited to smart phones, tablet computers, laptop portable computers, desktop computers, wearable devices, virtual reality devices, smart homes, and the like. The network 104 is a medium for providing a communication link between the terminal device 102 and the server 106. The network 104 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc. The server 106 may be a server or a server cluster that provides various services, such as a background processing server, a database server, etc.

[0044] Users can use the terminal device 102 to interact with the server 106 through the network 104 to receive or send data, etc. For example, a user can operate on the terminal device 102 to request access to data to be processed, and the terminal device 102 sends a data access request to the server 106 through the network 104. For another example, the terminal device 102 obtains historical access information of the file to which the data to be processed belongs from the server 106 through the network 104. For yet another example, if the terminal device 102 determines that the data to be processed is sensitive data, it can send the judgment result to the server 106 through the network 104 so that the server 106 desensitizes the data to be processed.

[0045] It should be understood that Figure 1 the numbers of the terminal devices, networks, and servers in FIG. 10 are merely illustrative. According to the implementation requirements, there can be any number of terminal devices, networks, and servers.

[0046] Figure 2 is a flowchart of a data processing method shown according to an exemplary embodiment. As Figure 2 shown, the method can be applied, for example, to the server side of the above system, or to the terminal device of the above system.

[0047] Referring to Figure 2 , the method 20 provided by the embodiments of the present disclosure may include the following steps.

[0048] In step S202, in response to a target user's request to access data to be processed, obtain the historical access behavior metric information of the target user.

[0049] In some embodiments, the target user can operate on the terminal device to request access to the data to be processed. For example, the user can enter a query statement to query the corresponding data. For example, if the user enters "SELECT ID FROM Persons", then "Persons" is the table where the data to be processed is located, and "ID" is the identifier of the data to be processed. Another example is that the user can click (single-click or double-click) D:\Network\log\A.doc (document path), then the A.doc file is the file where the data to be processed is located.

[0050] In some embodiments, in response to a target user's request to access data to be processed, obtain the identifier of the target user, and then obtain the historical access behavior metric information of the target user according to the identifier of the target user. The specific implementation can refer to Figure 3 .

[0051] In step S204, obtain the sensitivity of the target user based on the historical access behavior metric information of the target user.

[0052] In some embodiments, the sensitivity of the target user can be obtained according to the sensitivity of the files historically accessed by the target user. For example, take the average value of the sensitivities of the files historically accessed by the target user as the sensitivity of the target user.

[0053] In other embodiments, the security metric information of the target user can also be obtained, and then the sensitivity of the target user is determined according to the security metric information of the target user and the historical access behavior metric information of the target user. The specific implementation can refer to Figure 4 .

[0054] In step S206, obtain the historical access information of the file to which the data to be processed belongs.

[0055] In some embodiments, the historical access information of the file to which the data to be processed belongs may include the amount of standard sensitive data in the file to which the data to be processed belongs, the actual sensitive data that has been desensitized for the historical access users in the file to which the data to be processed belongs, and the security metric information of the historical access users of the file to which the data to be processed belongs. The methods for obtaining this information can be referred to Figure 5 and Figure 6 .

[0056] In step S208, the sensitivity of the file to which the data to be processed belongs is obtained based on the historical access information of the file to which the data to be processed belongs.

[0057] In some embodiments, the sensitivity of the file can be obtained according to the sensitive level set for the file to which the data to be processed belongs and the security level of the users who have historically accessed the file. For example, the average value of the sensitive level of the file and the security level of the users who have historically accessed the file can be used as the sensitivity of the file.

[0058] In other embodiments, the sensitivity of the file to which the data to be processed belongs can be obtained according to the amount of standard sensitive data and the amount of actual sensitive data in the file to which the data to be processed belongs, as well as the security metric information of the corresponding historical access users. The specific implementation can be referred to Figure 6 .

[0059] In step S210, it is determined whether the data to be processed is sensitive data according to the sensitivity of the target user and the sensitivity of the file to which the data to be processed belongs.

[0060] In some embodiments, if the data to be processed is standard sensitive data, the sensitivity of the target user can be directly compared with the sensitivity of the file to which the data to be processed belongs. When the sensitivity of the target user is less than the sensitivity of the file to which the data to be processed belongs, it indicates that the security level of the target user is not enough to view the file to which the data to be processed belongs, and it is determined that the data to be processed is sensitive data for the target user.

[0061] In other embodiments, it is possible to first check whether there are historical access users of the file to which the data to be processed belongs whose security metric values are higher than those of the target user, and then further check the actual sensitive data in the data to be processed for the historical access users with higher security metric values. Then, based on the sensitivity of the target user and the sensitivity of the file to which the data to be processed belongs, it is determined whether the data to be processed is sensitive data for the target user. The specific implementation can be referred to Figure 7 .

[0062] In step S212, if it is determined that the data to be processed is sensitive data, the data to be processed is desensitized so that the target user can access the desensitized data.

[0063] In some embodiments, if it is determined that the data to be processed is not sensitive data, the data to be processed is not desensitized, so that the target user can access the original data.

[0064] According to the data processing method provided by the embodiments of the present disclosure, in response to a target user's request to access the data to be processed, obtain the historical access behavior index information of the target user, and obtain the sensitivity of the target user based on the historical access behavior index information of the target user. Then, obtain the historical access information of the file to which the data to be processed belongs, and obtain the sensitivity of the file to which the data to be processed belongs based on the historical access information of the file to which the data to be processed belongs. Then, determine whether the data to be processed is sensitive data according to the sensitivity of the target user and the sensitivity of the file to which the data to be processed belongs. If it is determined that the data to be processed is sensitive data, desensitize the data to be processed so that the target user can access the desensitized data. Thus, sensitive data can be identified by integrating the historical access behavior index information of the target user and the historical access information of the file to which the data to be processed belongs, and different sensitive data identification results can be provided according to different historical access behavior situations of different users, improving the accuracy of the sensitive data identification result.

[0065] In the related art, regardless of the user, standard sensitive data will be desensitized. The method provided by the embodiments of the present disclosure dynamically determines whether to desensitize it according to the sensitivity of the current target user. That is to say, whether the standard sensitive data is the final sensitive data is not certain. For each standard sensitive data in the data to be processed, it is determined whether the standard sensitive data is sensitive data for the current target user according to the sensitivity of the target user and the sensitivity of the file to which the data to be processed belongs, and the data finally determined to be sensitive is desensitized. The method provided by the embodiments of the present disclosure dynamically identifies sensitive data based on the user identity, so that for the same data, whether it is sensitive data has different conclusions for different users, solving the problem in the related art that the user situation is not considered and only unified identification is performed, resulting in the users who need to view the data not being able to see the real data, thus affecting the normal work.

[0066] Figure 3 Shows Figure 2 The schematic diagram of the processing process of step S202 in an embodiment shown in Figure 3 As shown in

[0067] Step S302, in response to a target user's request to access the data to be processed, obtain the identifier of the target user.

[0068] In some embodiments, the identifier of the target user can be obtained according to the operation of the target user's request to access the data to be processed. For example, the identifier of the target user can be the user name for the target user to log in to the data access system.

[0069] Step S304: Obtain the standard sensitive data volume in the files historically accessed by the target user according to the identifier of the target user.

[0070] In some embodiments, the files historically accessed by the target user can be obtained according to the identifier of the target user. A file is the smallest storage unit, such as a word document, a txt document, an Excel document, etc. If it is data in a database, then the file in this step can refer to a data table.

[0071] In some embodiments, the standard sensitive data can be sensitive data determined at the time of data generation. As long as one user is sensitive to it, the data is standard sensitive data. For example, an ID number is sensitive data for ordinary users, so it is standard sensitive data. At this time, whether the data is sensitive to the current target user is not considered. Identification methods such as keyword matching in related technologies can be used to obtain the standard sensitive data.

[0072] In some embodiments, the number n1 of standard sensitive data in each historically accessed file of the target user can be statistically obtained. If there is a file with the number of standard sensitive data being 0, that is, there is no sensitive data in the file, then the file is excluded from the set of files historically accessed by the target user in the method provided by the embodiments of the present disclosure. That is, the files historically accessed by the target user in the embodiments of the present disclosure include at least 1 standard sensitive data.

[0073] Step S306: Obtain the actual sensitive data volume for desensitization processing of the target user in the files historically accessed by the target user according to the identifier of the target user.

[0074] In some embodiments, the standard sensitive data is not necessarily sensitive data for the target user. That is, when the target user historically accessed the file, some standard sensitive data was desensitized as the final sensitive data, but some standard sensitive data may not have been desensitized as the final sensitive data. The actual sensitive data volume n2 for desensitization processing of the target user when the target user accessed the file can be obtained.

[0075] Step S308: Obtain the historical access user information of the files historically accessed by the target user.

[0076] In some embodiments, the historical access user information of the target user's historical access files may be the security level A2 of the historical access user of the target user's historical access files. For a file, the security level of the user accessing it can reflect the sensitivity of the file. For example, if a file is only accessible to those with an administrator or higher status, it means that ordinary users do not have permission to access it, so the sensitivity of the file is relatively high. If the historical access users of a file include users of various identities, it indicates that the sensitivity of the file is relatively low.

[0077] Step S310, obtain the target user's historical access behavior metric information according to the standard sensitive data volume and the actual sensitive data volume in the target user's historical access files, and the historical access user information of the target user's historical access files.

[0078] In some embodiments, the target user's historical access behavior metric information may be the behavior level B of the target user, and the behavior level B of the target user can be obtained by the following formula:

[0079]

[0080] where i is the serial number identifier of the target user's historical access files, i can be a positive integer or a letter, etc.; n1 i is the standard sensitive data volume of the i-th target user's historical access file, n2 i is the actual sensitive data volume actually desensitized for the i-th target user's historical access file, A2 i is the security level of the historical access user (there may be multiple) of the i-th target user's historical access file, max{A2 i} is the maximum security level of the historical access user of the i-th target user's historical access file, and B is the behavior level of the target user. The behavior level can be a numerical value, and the larger the numerical value, the higher the sensitivity of the data that has been accessed, that is, the higher the security requirements for the target user's historical access files.

[0081] According to the method provided by the embodiments of the present disclosure, the sensitivity of the files accessed by the target user is characterized based on the historical behavior of the target user. If most of the files accessed by the target user are relatively sensitive, that is, data with a relatively high security level, it indicates that the access permission of the target user is relatively high, that is, the target user can access more data with a relatively high security level. A relatively high access permission also means that the consideration of the security requirements for the data this time will be relatively reduced, because generally, the target user has permission to access all data, and all data is no longer regarded as sensitive data. Therefore, by using the behavior level to characterize the sensitivity level of the target user's historical access files and using it as a reference in turn to identify whether the data to be processed is sensitive to the target user, the accuracy of the sensitive data identification result can be improved.

[0082] Figure 4 shows Figure 2 a schematic diagram of the processing procedure of step S204 shown in in one embodiment. As Figure 4 shown, in the embodiments of the present disclosure, the above step S204 may further include the following steps.

[0083] Step S402, obtaining security metric information of a target user according to an identifier of the target user.

[0084] In some embodiments, the security metric information of the target user may be a security level A of the target user. The security level may be a numerical value, for example, it may be an integer from 1 to 10, and the higher the number, the higher the security level may indicate, that is, it indicates that the target user corresponding to the identifier can view more and / or more sensitive sensitive data.

[0085] In some embodiments, the security level may be determined when the user registers, for example, configured for the identifier of the target user by a person with security level configuration authority; or, it may be obtained by conversion according to the identity corresponding to the identifier of the target user (such as an ordinary administrator, a senior administrator, etc.), for example, the security level of a senior administrator is 10, and the security level of an ordinary administrator is 8, etc.

[0086] Step S404, obtaining the sensitivity of the target user according to the security metric information of the target user and the historical access behavior metric information of the target user.

[0087] In some embodiments, the sensitivity SU of the target user may be obtained as SU = B / A, where, according to Equation (1), the behavior level B of the target user characterizes the comprehensive situation of the sensitivity of the historical access data of the target user. Therefore, the sensitivity SU of the target user characterizes the comprehensive sensitivity of the historical access data of the target user relative to the security level A of the target user.

[0088] Figure 5 shows Figure 2 a schematic diagram of the processing procedure of step S206 and step S208 shown in in one embodiment. As Figure 5 shown, in the embodiments of the present disclosure, the data processing method may further include the following steps.

[0089] Step S502, in response to a request from the target user to access data to be processed, obtaining an identifier of the data to be processed.

[0090] In some embodiments, the identifier of the data to be processed (which may also be referred to as the data to be accessed) can be an identifier characterizing the data to be accessed. For example, if the data to be accessed is a column in a certain table, then the identifier of the data to be accessed can be table name -> column name; for another example, if the data to be accessed is a certain table, then the identifier of the data to be accessed can be the table name; for yet another example, if the data to be accessed is a document, then the identifier of the data to be accessed can be the document path.

[0091] In some embodiments, there can also be multiple ways to obtain the identifier of the data to be accessed. If the user inputs a query statement, then the identifier of the data to be accessed is obtained according to the query statement. For example: if the user inputs SELECT ID FROM Persons, then Persons -> ID (table name -> column name) is the identifier of the data to be accessed. For another example: if the user inputs SELECT * FROM Persons, then Persons (table name) is the identifier of the data to be accessed.

[0092] In some other embodiments, if the identifier of the data to be accessed is the document path, then the file to which the data to be accessed belongs is the file at the end of the path. For example, if the user double-clicks on the file D:\Network\Log\A.doc, then D:\Network\Log\A.doc (document path) is the identifier of the data to be accessed, and A.doc is the file name of the file to which the data to be accessed belongs.

[0093] Step S504, obtain the standard sensitive data volume in the file to which the data to be processed belongs according to the identifier of the data to be processed.

[0094] In some embodiments, the file to which the data to be processed belongs can be obtained first according to the identifier of the data to be processed, and then the standard sensitive data in the file to which the data to be processed belongs is determined. The meaning of the standard sensitive data in the file to which the data to be processed belongs can be the same as the meaning of the standard sensitive data in the target user's historical access files. The specific implementation manner can refer to step S310. The standard sensitive data volume in the file to which the data to be processed belongs can be represented as n3.

[0095] Step S506, obtain the security metric information of the historical access users of the file to which the data to be processed belongs according to the identifier of the data to be processed.

[0096] In some embodiments, after obtaining the file to which the data to be processed belongs according to the identifier of the data to be processed, the identifier of the historical access users of the file to which the data to be processed belongs can be obtained, and then the security metric information of these historical access users can be obtained according to the user identifier. The security metric information of the historical access users of the file to which the data to be processed belongs may include the security metric values of the historical access users of the file to which the data to be processed belongs, the number of historical access users meeting the target conditions, and the average security metric of the historical access users of the file to which the data to be processed belongs. For the specific implementation manners of obtaining these security metric information, reference can be made to Figure 6 .

[0097] Step S508: Based on the identifier of the data to be processed, obtain the actual amount of sensitive data for which desensitization processing is performed on the historical access users in the file to which the data to be processed belongs.

[0098] In some embodiments, after obtaining the file to which the data to be processed belongs according to the identifier of the data to be processed, the identifier of the historical access users of the file to which the data to be processed belongs can be obtained, and then the actual amount of sensitive data for which desensitization processing is performed on these historical access users can be obtained according to the user identifier. The actual amount of sensitive data for which desensitization processing is performed on the historical access users in the file to which the data to be processed belongs can be represented as n4. The meaning of the actual sensitive data can be referred to in step S306.

[0099] Step S510: Obtain the sensitivity of the file to which the data to be processed belongs according to the standard amount of sensitive data and the actual amount of sensitive data in the file to which the data to be processed belongs, and the security metric information of the corresponding historical access users.

[0100] In some embodiments, with reference to Figure 6 , the sensitivity SD of the file to which the data to be processed belongs can be obtained according to the following formula:

[0101]

[0102] In the formula, j is the serial number identifier of the historical access users of the file to which the data to be processed belongs, j can be a positive integer, or a letter, etc.; n4 j is the actual amount of sensitive data of the j-th historical access user who accesses the file to which the data to be processed belongs, A3 j is the security level of the j-th historical access user who accesses the file to which the data to be processed belongs, is the average security level of all historical access users of the file to which the data to be processed belongs.

[0103] As can be seen from Equation (2), the sensitivity SD of the file to which the data to be processed belongs can be designed to be proportional to the ratio of the actual sensitive data n4 to the standard sensitive data quantity n3, and the number H1 of historical access users with the highest security level, and inversely proportional to the number H2 of historical access users with the highest security level and the historical access users H3 at different levels. The more sensitive data there is, it indicates that the file to which the data to be processed belongs contains a lot of sensitive content, which increases the sensitivity of the data to be processed. The higher the highest security level of the historical access users, it represents that the security level of the users who accessed the file to which the data to be processed belongs historically is relatively high, and the security level of the file to which the data to be processed belongs is relatively high. The greater the span of the levels of the historical visitors, it shows that the requirements for the visitors are relatively low, that is, users of various security levels can access, then the security level of the file to which the data to be processed belongs is reduced. The lower the highest security level of the historical visitors, it represents that the security level of the users who accessed the file to which the data to be processed belongs historically is relatively low, and the security level of the file to which the data to be processed belongs is relatively low, that is, the sensitivity is relatively low.

[0104] Figure 6 shows Figure 2 a schematic diagram of the processing procedure of step S206 shown in another embodiment. As Figure 6 shown, in the embodiments of the present disclosure, Figure 2 step S206 shown in can further include the following steps.

[0105] Step S602, obtaining the security index value of the historical access users of the file to which the data to be processed belongs according to the identifier of the data to be processed.

[0106] In some embodiments, after obtaining the identifiers of the historical access users of the file to which the data to be processed belongs according to the identifier of the data to be processed, the security index values corresponding to these user identifiers can be obtained. The security index value of the historical access users of the file to which the data to be processed belongs can be the security level A3 of these historical access users. The meaning of the security level A3 can refer to the security level A2 of the historical access users of the target user's historical access file, and the specific implementation manner can refer to step S308.

[0107] Step S604, obtaining the number of historical access users meeting the target conditions according to the security index value.

[0108] In some embodiments, the target condition may be that among the historical access users of the file to which the data to be processed belongs, the security metric value is the highest, the lowest, different in value, etc. The number H1 of historical access users with the highest security level, the number H2 of historical access users with the lowest security level, and the number H3 of historical access users at different levels can be statistically obtained according to the security level A3 of each historical access user. For example, if there are 5 historical access users of the file to which the data to be processed belongs, and their security levels are 10, 8, 10, 4, and 4 respectively, then H1 is the number 2 of historical access users with the highest security level of 10, H2 is the number 2 of historical access users with the lowest security level of 4, and H3 is the number 3 of different security levels 10, 8, and 4.

[0109] Step S606: Obtain the average security metric of the historical access users of the file to which the data to be processed belongs according to the security metric value.

[0110] In some embodiments, the average security metric of all historical access users of the file to which the data to be processed belongs may be the average security level. For example, if there are 5 historical access users of the file to which the data to be processed belongs, and their security levels are 10, 8, 10, 4, and 4 respectively, then it is (10 + 8 + 10 + 4 + 4) / 5 = 7.2.

[0111] Figure 7 shows Figure 2 a schematic diagram of the processing procedure of step S210 shown in one embodiment. As Figure 7 shown, in the embodiments of the present disclosure, the above step S210 may further include the following steps.

[0112] Step S702: Based on the historical access information of the file to which the data to be processed belongs, determine whether there is a historical access user of the file to which the data to be processed belongs whose security metric value is higher than that of the target user.

[0113] In some embodiments, the security metric value may be the above security level. Among the historical access users of the file to which the data to be processed belongs, check whether there is a historical access user whose security level is greater than the security level A of the target user.

[0114] Step S704: If there is no historical access user of the file to which the data to be processed belongs whose security metric value is higher than that of the target user, then when the sensitivity of the target user is less than the sensitivity of the file to which the data to be processed belongs, determine that the data to be processed is sensitive data.

[0115] In some embodiments, if there is no historical access user whose security level is higher than the security level A of the target user, then if the sensitivity SU of the target user is greater than or equal to the sensitivity SD of the file to which the data to be processed belongs, it is determined that the data to be processed is non-sensitive data and no desensitization processing is performed; otherwise, it is determined to be sensitive data and desensitization processing is performed.

[0116] Step S7062, if there is a historical access user of the file to which the data to be processed belongs and whose security index value is higher than that of the target user, obtain the first user number, where the first user number is the number of historical access users of the file to which the data to be processed belongs and whose security index value is higher than that of the target user.

[0117] Step S7064, obtain the standard sensitive data in the data to be processed.

[0118] Step S7066, obtain the second user number among the historical access users of the file to which the data to be processed belongs and whose security index value is higher than that of the target user, and who perform desensitization processing on the standard sensitive data in the data to be processed.

[0119] Step S7068, when the product of the sensitivity of the target user and the ratio of the second user number to the first user number is less than the sensitivity of the file to which the data to be processed belongs, determine that the data to be processed is sensitive data.

[0120] In some embodiments, if there is a historical access user whose security level is higher than the security level A of the target user, then for each standard sensitive data, determine the number n5 of historical access users whose security level is higher than A, and the number n6 of users who perform desensitization processing on the standard sensitive data among the historical access users whose security level is higher than A. If the sensitivity SU of the target user * n6 / n5 is greater than or equal to the sensitivity SD of the file to which the data to be processed belongs, determine that the standard sensitive data is non-sensitive data and no desensitization processing is performed; otherwise, determine that the standard sensitive data is sensitive data and perform desensitization processing.

[0121] The following is an illustration according to Figures 2 to 7 One embodiment is provided for illustration.

[0122] After the target user C double-clicks on the D:\Network\Log\A.doc file on the terminal device, the process of the present disclosure embodiment is entered:

[0123] Step 1, obtain the identifier of the target user C and the identifier A.doc of the data to be processed.

[0124] Step 2, determine the sensitivity of the target user according to the target user identifier.

[0125] 1) Determine that the security level A of the target user C = 8.

[0126] 2) If target user C has accessed file B.doc and file C.txt, where B.doc contains 10 standard sensitive data such as ID number, address, and phone number, then n1 B = 10; C.txt contains 5 standard sensitive data, then n1 C = 5.

[0127] When target user C accessed B.doc, 5 out of the 10 standard sensitive data were desensitized, and the other 5 were not desensitized, then n2 B = 5. When target user C accessed C.txt, the 5 standard sensitive data were not desensitized, then n2 C = 0.

[0128] In addition to being accessed by target user C, file B.doc has also been accessed by user F, and the security level of user F is 6, then A2 B = 6. C.txt has only been accessed by target user C, then A2 C = 0.

[0129] Then according to formula (1), the behavior level B of target user C = [(n2 B / n1 B )+(n2 C / n1 C )]*max{A2 B ,A2 C} = [(5 / 10)+(0 / 5)]*6 = (1 / 2)*6 = 3.

[0130] 3) According to step S404, the sensitivity SU of target user C can be obtained as 3 / 8.

[0131] Step 3, determine the sensitivity of the file to which the data to be processed belongs according to the identifier of the data to be processed.

[0132] 1) According to step S502 and step S504, if the file A.doc to which the data to be processed belongs is obtained, and then the number of standard sensitive data n3 = 2 is obtained.

[0133] 2) The user who has historically accessed A.doc is user E, and the security level A3 of user E E = 8.

[0134] 3) If when user E accessed A.doc, one of the two standard sensitive data was desensitized (such as standard sensitive data 1 was desensitized), and the other was not desensitized (such as standard sensitive data 2 was not desensitized), then n4 E = 1.

[0135] 4) Since there is only 1 historical access user for the file A.doc to which the data to be processed belongs, the highest-level quantity H1 = 1, the lowest-level quantity H2 = 1, and the quantity H3 for different levels = 1.

[0136] 5) According to Equation (2), the sensitivity of the file A.doc to which the data to be processed belongs can be obtained.

[0137] Step 4: Determine whether the data to be processed is sensitive data based on the sensitivity of the target user and the sensitivity of the file to which the data to be processed belongs.

[0138] 1) Determine all the standard sensitive data included in the data to be accessed, such as standard sensitive data 1 and standard sensitive data 2.

[0139] 2) For standard sensitive data 1:

[0140] There is a historical access user E among the historical access users whose security level is equal to the security level A of the target user C. That is, the security level A3 of user E E = 8, and the security level A of user C = 8.

[0141] Then the number of historical access users with a security level higher than A, n5 = 1, and the number of historical access users with a security level higher than A who perform desensitization processing on this standard sensitive data, n6 = 1 (that is, standard sensitive data 1 is desensitized). Then SU * n6 / n5 = 3 / 8 * 1 = 3 / 8, which is less than SD = 1 / 2. It is determined that standard sensitive data 1 is sensitive data and desensitization processing is performed.

[0142] 3) For standard sensitive data 2:

[0143] There is a historical access user E among the historical access users whose security level is equal to the security level A of the target user C. That is, the security level A3 of user E E = 8, and the security level A of user C = 8.

[0144] Then the number of historical access users with a security level higher than A, n5 = 1, and the number of historical access users with a security level higher than A who perform desensitization processing on this standard sensitive data, n6 = 0 (that is, standard sensitive data 2 is not desensitized). Then SU * n6 / n5 = 3 / 8 * 0 = 0, which is less than SD = 1 / 2. It is determined that standard sensitive data 2 is not sensitive data and no desensitization processing is performed.

[0145] Figure 8 It is a block diagram of a data processing device shown according to an exemplary embodiment. As Figure 8 shown, the device can be applied, for example, to the server side of the above system or to the terminal device of the above system.

[0146] Reference Figure 8 , the device 80 provided by the embodiments of the present disclosure may include an obtaining module 802, a judging module 804, and a processing module 806.

[0147] The obtaining module 802 may be configured to obtain target user historical access behavior metric information in response to a target user request to access data to be processed.

[0148] The obtaining module 802 may also be configured to obtain the sensitivity of the target user based on the target user historical access behavior metric information.

[0149] The obtaining module 802 may also be configured to obtain historical access information of the file to which the data to be processed belongs.

[0150] The obtaining module 802 may also be configured to obtain the sensitivity of the file to which the data to be processed belongs based on the historical access information of the file to which the data to be processed belongs.

[0151] The judging module 804 may be configured to judge whether the data to be processed is sensitive data according to the sensitivity of the target user and the sensitivity of the file to which the data to be processed belongs.

[0152] The processing module 806 may be configured to perform desensitization processing on the data to be processed if it is determined that the data to be processed is sensitive data, so that the target user can access the desensitized data.

[0153] Figure 9 is a block diagram of another data processing device shown according to an exemplary embodiment. As Figure 9 shown, the device may be applied, for example, to the server side of the above system, or may also be applied to the terminal device of the above system.

[0154] Reference Figure 9 , the device 90 provided by the embodiments of the present disclosure may include an acquisition module 902, an obtaining module 904, a judging module 906, and a processing module 908.

[0155] The acquisition module 902 may be configured to obtain the identifier of the target user in response to a target user request to access data to be processed.

[0156] The acquisition module 902 may also be configured to obtain the identifier of the data to be processed in response to a target user request to access data to be processed.

[0157] The acquisition module 902 may also be configured to obtain standard sensitive data in the data to be processed.

[0158] The obtaining module 904 may be configured to obtain target user historical access behavior metric information in response to a target user request to access data to be processed.

[0159] The obtaining module 904 can also be used to obtain the standard sensitive data volume in the historical access files of the target user according to the identifier of the target user.

[0160] The obtaining module 904 can also be used to obtain the actual sensitive data volume that has been desensitized for the target user in the historical access files of the target user according to the identifier of the target user.

[0161] The obtaining module 904 can also be used to obtain the historical access user information of the historical access files of the target user.

[0162] The obtaining module 904 can also be used to obtain the historical access behavior metric information of the target user according to the standard sensitive data volume and the actual sensitive data volume in the historical access files of the target user, as well as the historical access user information of the historical access files of the target user.

[0163] The obtaining module 904 can also be used to obtain the sensitivity of the target user based on the historical access behavior metric information of the target user.

[0164] The obtaining module 904 can also be used to: obtain the security metric information of the target user according to the identifier of the target user; obtain the sensitivity of the target user according to the security metric information of the target user and the historical access behavior metric information of the target user.

[0165] The obtaining module 904 can also be used to obtain the number of second users who desensitize the standard sensitive data in the to-be-processed data among the historical access users of the file to which the to-be-processed data belongs and whose security metric values are higher than those of the target user.

[0166] The obtaining module 904 can also be used to obtain the historical access information of the file to which the to-be-processed data belongs.

[0167] The historical access information of the file to which the to-be-processed data belongs may include the standard sensitive data volume in the file to which the to-be-processed data belongs, the actual sensitive data that has been desensitized for its historical access users in the file to which the to-be-processed data belongs, and the security metric information of the historical access users of the file to which the to-be-processed data belongs.

[0168] The security metric information of the historical access users of the file to which the to-be-processed data belongs may include the security metric values of the historical access users of the file to which the to-be-processed data belongs, the number of historical access users who meet the target conditions, and the average security metric value of the historical access users of the file to which the to-be-processed data belongs.

[0169] The obtaining module 904 can also be used to obtain the standard sensitive data volume in the file to which the to-be-processed data belongs according to the identifier of the to-be-processed data.

[0170] The obtaining module 904 can also be used to obtain the sensitivity of the file to which the to-be-processed data belongs based on the historical access information of the file to which the to-be-processed data belongs.

[0171] The obtaining module 904 can also be used to: obtain the security metric information of the historical access users of the file to which the data to be processed belongs according to the identifier of the data to be processed; obtain the actual sensitive data volume for desensitizing the historical access users in the file to which the data to be processed belongs based on the identifier of the data to be processed; obtain the sensitivity of the file to which the data to be processed belongs according to the standard sensitive data volume and the actual sensitive data volume in the file to which the data to be processed belongs, and the security metric information of the corresponding historical access users.

[0172] The obtaining module 904 can also be used to: obtain the security metric value of the historical access users of the file to which the data to be processed belongs according to the identifier of the data to be processed; obtain the number of historical access users who meet the target conditions according to the security metric value; obtain the average security metric value of the historical access users of the file to which the data to be processed belongs according to the security metric value.

[0173] The obtaining module 904 can also be used to, if there are historical access users of the file to which the data to be processed belongs whose security metric values are higher than those of the target user, obtain the first user quantity, where the first user quantity is the number of historical access users of the file to which the data to be processed belongs whose security metric values are higher than those of the target user.

[0174] The determining module 906 can be used to determine whether the data to be processed is sensitive data according to the sensitivity of the target user and the sensitivity of the file to which the data to be processed belongs.

[0175] The determining module 906 can also be used to: determine whether there are historical access users of the file to which the data to be processed belongs whose security metric values are higher than those of the target user based on the historical access information of the file to which the data to be processed belongs; if there are no historical access users of the file to which the data to be processed belongs whose security metric values are higher than those of the target user, then when the sensitivity of the target user is less than the sensitivity of the file to which the data to be processed belongs, determine that the data to be processed is sensitive data.

[0176] The determining module 906 can also be used to: when the product of the sensitivity of the target user and the ratio of the second user quantity to the first user quantity is less than the sensitivity of the file to which the data to be processed belongs, determine that the data to be processed is sensitive data.

[0177] The processing module 908 can be used to, if it is determined that the data to be processed is sensitive data, perform desensitization processing on the data to be processed so that the target user can access the desensitized data.

[0178] The specific implementation of each module in the device provided by the embodiments of the present disclosure can refer to the content in the above method, which will not be elaborated here.

[0179] Figure 10The structural schematic diagram of an electronic device in an embodiment of the present disclosure is shown. It should be noted that Figure 10 The device shown is only an example of a computer system, and should not impose any restrictions on the functions and usage scope of the embodiments of the present disclosure.

[0180] As Figure 10 shown, the device 1000 includes a central processing unit (CPU) 1001, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 1002 or the program loaded from the storage section 1008 into the random access memory (RAM) 1003. In the RAM 1003, various programs and data required for the operation of the device 1000 are also stored. The CPU 1001, ROM 1002, and RAM 1003 are connected to each other via a bus 1004. The input / output (I / O) interface 1005 is also connected to the bus 1004.

[0181] The following components are connected to the I / O interface 1005: an input section 1006 including a keyboard, a mouse, etc.; an output section 1007 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 1008 including a hard disk, etc.; and a communication section 1009 including a network interface card such as a LAN card, a modem, etc. The communication section 1009 performs communication processing via a network such as the Internet. A drive 1010 is also connected to the I / O interface 1005 as required. A removable medium 1011, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 1010 as required, so that the computer program read from it can be installed into the storage section 1008 as required.

[0182] Specifically, according to the embodiments of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments of the present disclosure include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes program codes for performing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication section 1009, and / or installed from the removable medium 1011. When the computer program is executed by the central processing unit (CPU) 1001, the above functions defined in the system of the present disclosure are executed.

[0183] It should be noted that the computer-readable medium shown in the present disclosure can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of a computer-readable storage medium can include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, a computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present disclosure, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on a computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.

[0184] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in a flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or by a combination of dedicated hardware and computer instructions.

[0185] The modules involved in the embodiments of the present disclosure can be implemented in software or in hardware. The described modules can also be provided in a processor. For example, it can be described as: a processor includes an obtaining module, a determining module, and a processing module. Among them, the names of these modules do not constitute a limitation to the module itself in some cases. For example, the obtaining module can also be described as "a module for obtaining information related to the data to be processed of the user-related information".

[0186] As another aspect, the present disclosure also provides a computer-readable medium, which can be included in the device described in the above embodiments; or it can exist alone without being assembled into the device. The above computer-readable medium carries one or more programs. When the above one or more programs are executed by the device, the device includes:

[0187] In response to a target user's request to access the data to be processed, obtain the target user's historical access behavior metric information; obtain the sensitivity of the target user based on the target user's historical access behavior metric information; obtain the historical access information of the file to which the data to be processed belongs; obtain the sensitivity of the file to which the data to be processed belongs based on the historical access information of the file to which the data to be processed belongs; determine whether the data to be processed is sensitive data according to the sensitivity of the target user and the sensitivity of the file to which the data to be processed belongs; if it is determined that the data to be processed is sensitive data, desensitize the data to be processed so that the target user can access the desensitized data.

[0188] The above specifically shows and describes the exemplary embodiments of the present disclosure. It should be understood that the present disclosure is not limited to the detailed structure, setting method or implementation method described here; on the contrary, the present disclosure intends to cover various modifications and equivalent settings included in the spirit and scope of the appended claims.

Claims

1. A data processing method, characterized in that, Including: In response to a target user's request to access data to be processed, obtaining the historical access behavior metric information of the target user; Obtaining the sensitivity of the target user based on the historical access behavior metric information of the target user; Obtaining the historical access information of the file to which the data to be processed belongs; Obtaining the sensitivity of the file to which the data to be processed belongs based on the historical access information of the file to which the data to be processed belongs; Judging whether the data to be processed is sensitive data according to the sensitivity of the target user and the sensitivity of the file to which the data to be processed belongs; If it is determined that the data to be processed is sensitive data, performing desensitization processing on the data to be processed so that the target user can access the desensitized data; In response to a target user's request to access data to be processed, obtaining the historical access behavior metric information of the target user, including: In response to the target user's request to access the data to be processed, obtaining the identifier of the target user; Obtaining the standard sensitive data volume in the historical access files of the target user according to the identifier of the target user; Obtaining the actual sensitive data volume desensitized for the target user in the historical access files of the target user according to the identifier of the target user; Obtaining the historical access user information of the historical access files of the target user; Obtaining the historical access behavior metric information of the target user according to the standard sensitive data volume and actual sensitive data volume in the historical access files of the target user, and the historical access user information of the historical access files of the target user.

2. The method according to claim 1, wherein Obtaining the sensitivity of the target user based on the historical access behavior metric information of the target user, including: Obtaining the security metric information of the target user according to the identifier of the target user; Obtaining the sensitivity of the target user according to the security metric information of the target user and the historical access behavior metric information of the target user.

3. The method according to claim 1, wherein Also including: In response to the target user's request to access the data to be processed, obtaining the identifier of the data to be processed; Obtaining the standard sensitive data volume in the file to which the data to be processed belongs according to the identifier of the data to be processed; The historical access information of the file to which the data to be processed belongs includes the standard sensitive data volume in the file to which the data to be processed belongs, the actual sensitive data desensitized for its historical access users in the file to which the data to be processed belongs, and the security metric information of the historical access users of the file to which the data to be processed belongs; Obtaining the historical access information of the file to which the data to be processed belongs, including: Obtaining the security metric information of the historical access users of the file to which the data to be processed belongs according to the identifier of the data to be processed; Obtaining the actual sensitive data volume desensitized for its historical access users in the file to which the data to be processed belongs based on the identifier of the data to be processed; Obtaining the sensitivity of the file to which the data to be processed belongs based on the historical access information of the file to which the data to be processed belongs, including: Obtaining the sensitivity of the file to which the data to be processed belongs according to the standard sensitive data volume and actual sensitive data volume in the file to which the data to be processed belongs, and the security metric information of the corresponding historical access users.

4. The method according to claim 3, wherein The security metric information of the historical access users of the file to which the data to be processed belongs includes the security metric values of the historical access users of the file to which the data to be processed belongs, the number of historical access users meeting the target conditions, and the average security metric of the historical access users of the file to which the data to be processed belongs; Obtaining the historical access information of the file to which the data to be processed belongs further includes: Obtaining the security metric value of the historical access users of the file to which the data to be processed belongs according to the identifier of the data to be processed; Obtaining the number of historical access users meeting the target conditions according to the security metric value; Obtaining the average security metric of the historical access users of the file to which the data to be processed belongs according to the security metric value.

5. The method according to claim 1, wherein Judging whether the data to be processed is sensitive data according to the sensitivity of the target user and the sensitivity of the file to which the data to be processed belongs includes: Judging whether there are historical access users of the file to which the data to be processed belongs whose security metric values are higher than the security metric value of the target user based on the historical access information of the file to which the data to be processed belongs; If there are no historical access users of the file to which the data to be processed belongs whose security metric values are higher than the target user, when the sensitivity of the target user is less than the sensitivity of the file to which the data to be processed belongs, determining that the data to be processed is sensitive data.

6. The method according to claim 5, characterized in that, Judging whether the data to be processed is sensitive data according to the sensitivity of the target user and the sensitivity of the file to which the data to be processed belongs further includes: If there are historical access users of the file to which the data to be processed belongs whose security metric values are higher than the target user, obtaining a first user number, where the first user number is the number of historical access users of the file to which the data to be processed belongs whose security metric values are higher than the target user; Obtaining the standard sensitive data in the data to be processed; Obtaining a second user number, which is the number of historical access users of the file to which the data to be processed belongs whose security metric values are higher than the target user and who perform desensitization processing on the standard sensitive data in the data to be processed; When the product of the sensitivity of the target user and the ratio of the second user number to the first user number is less than the sensitivity of the file to which the data to be processed belongs, determining that the data to be processed is sensitive data.

7. A data processing device, characterized in that, Including: An obtaining module, configured to obtain the historical access behavior metric information of the target user in response to a request from the target user to access the data to be processed; The obtaining module is further configured to obtain the sensitivity of the target user based on the historical access behavior metric information of the target user; The obtaining module is further configured to obtain the historical access information of the file to which the data to be processed belongs; The obtaining module is further configured to obtain the sensitivity of the file to which the data to be processed belongs based on the historical access information of the file to which the data to be processed belongs; An obtaining module, configured to obtain the identifier of the target user in response to the request from the target user to access the data to be processed; The obtaining module is further configured to obtain the amount of standard sensitive data in the historical access files of the target user according to the identifier of the target user; The obtaining module is further configured to obtain the actual amount of sensitive data that has been desensitized for the target user in the historical access files of the target user according to the identifier of the target user; The obtaining module is further configured to obtain the historical access user information of the historical access files of the target user; The obtaining module is further configured to obtain the historical access behavior metric information of the target user according to the standard amount of sensitive data and the actual amount of sensitive data in the historical access files of the target user, and the historical access user information of the historical access files of the target user; The determining module is configured to determine whether the data to be processed is sensitive data according to the sensitivity of the target user and the sensitivity of the file to which the data to be processed belongs; The processing module is configured to, if it is determined that the data to be processed is sensitive data, perform desensitization processing on the data to be processed so that the target user can access the desensitized data.

8. An apparatus, comprising: A memory, a processor, and executable instructions stored in the memory and executable on the processor, wherein when the processor executes the executable instructions, the method according to any one of claims 1-6 is implemented.

9. A computer-readable storage medium having computer-executable instructions stored thereon, characterized in that, When the executable instructions are executed by the processor, the method according to any one of claims 1-6 is implemented.

Citation Information

Patent Citations

  • Private data access method and device

    CN115994377A

  • Sensitive data identification method and device

    CN116108409A