Pseudo-processing method, device and related products for sensitive data in heterogeneous networks
By determining the sensitivity of sensitive data in heterogeneous networks and inserting a set of synonymous abstractions, the security risks of sensitive data caused by multi-cloud deployment are resolved, achieving more efficient data protection.
Patent Information
- Application Number
- CN202111593300.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-23
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2041-12-23
AI Technical Summary
Sensitive data security risks caused by multi-cloud deployment are difficult to effectively protect, especially in heterogeneous networks.
By determining the sensitivity of sensitive data, calculating the sensitivity value of sensitive words or phrases, and inserting them into a pre-built synonym abstract set, the synonym abstract set can be used to reduce or avoid security risks.
It improves the protection of sensitive data and reduces security risks, especially providing higher protection for the security and privacy of sensitive data in heterogeneous networks.
Smart Images

Figure CN114330287B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of heterogeneous technology, and in particular to a pseudo-processing method, device and related products for sensitive data in a heterogeneous network. Background Art
[0002] With the continuous advancement of cloud computing technology, a wide variety of cloud platform products are emerging. Different cloud service providers have launched their own foundational community cloud platform products across private, public, and community clouds. With this increasing choice, more and more cloud computing users are deploying their services across different cloud platforms, demonstrating a trend toward hybrid and multi-cloud deployments. However, multi-cloud deployments pose significant security risks, especially for sensitive data. Summary of the Invention
[0003] Based on the above problems, embodiments of the present application provide a pseudo-processing method, device and related products for sensitive data in a heterogeneous network.
[0004] The embodiments of this application disclose the following technical solutions:
[0005] A pseudo-processing method for sensitive data in a heterogeneous network, comprising:
[0006] Determining the sensitive data targeted by the pseudo-processing method, and collecting statistical data describing the sensitivity of the sensitive data;
[0007] Calculating the sensitivity value of the sensitive word or words in the sensitive data according to the sensitivity description data;
[0008] According to the sensitivity values of the sensitive characters or sensitive words, the sensitive characters or sensitive words are sorted and inserted into a pre-built synonym abstract set.
[0009] Optionally, sorting the sensitive words or sensitive terms according to their sensitivity values and inserting them into a pre-built synonym abstract set includes:
[0010] Determining a hiding degree weight of the corresponding sensitive word or sensitive term according to the sensitivity value of the sensitive word or sensitive term;
[0011] According to the hiding degree weight, the sensitive characters or words are inserted into a pre-built synonym abstract set.
[0012] Optionally, inserting the sensitive characters or sensitive words into a pre-constructed synonymous abstract set according to the hiding degree weight includes: sorting the sensitive characters or sensitive words according to the hiding degree weight to form a sensitive object sequence; and inserting the sensitive object sequence into a pre-constructed synonymous abstract set.
[0013] Optionally, inserting the sensitive object sequence into a pre-built synonymous abstract set includes: determining the semantic position and order of each sensitive character or sensitive word in the sensitive object sequence, and inserting the semantic position and order into the pre-built synonymous abstract set.
[0014] Optionally, inserting the semantic position and order into a pre-built synonymous abstract set includes: using the sensitive character or sensitive word corresponding to the semantic position and order as the key in a key-value pair, using the semantic position and order as the value, and inserting the key-value pair including the key and value into the pre-built synonymous abstract set.
[0015] Optionally, inserting the semantic position and order into a pre-built synonymous abstract set includes: performing a hash operation on the semantic position and order using a random number sequence to obtain a corresponding hash value, and inserting the hash value into the pre-built synonymous abstract set.
[0016] Optionally, the counting of sensitivity description data of the sensitive data includes: extracting sensitive components from the sensitive data, and counting the sensitivity description data of the sensitive data based on the sensitive data.
[0017] Optionally, the step of collecting the sensitivity description data of the sensitive data may include: training a sensitive component extraction model using sensitive data samples;
[0018] The extracting the sensitive components from the sensitive data includes: extracting the sensitive components from the sensitive data based on the sensitive component extraction model.
[0019] Optionally, sorting the sensitive characters or sensitive words and inserting them into a pre-built synonymous abstract set includes: sorting the sensitive characters or sensitive words, and inserting the sensitive characters or sensitive words into a pre-built pseudo-synonymous abstract set according to the logical sorting of the sensitive characters or sensitive words.
[0020] A pseudo-processing device for sensitive data in a heterogeneous network, comprising:
[0021] A first processing unit is configured to determine the sensitive data targeted by the pseudo-processing device and collect data describing the sensitivity of the sensitive data;
[0022] a second processing unit, configured to calculate, based on the sensitivity description data, a sensitivity value of a sensitive character or sensitive word in the sensitive data;
[0023] The third processing unit is used to sort the sensitive characters or sensitive words according to their sensitivity values and insert them into a pre-built synonym abstract set.
[0024] Optionally, the third processing unit is specifically configured to:
[0025] Determining a hiding degree weight of the corresponding sensitive word or sensitive term according to the sensitivity value of the sensitive word or sensitive term;
[0026] According to the hiding degree weight, the sensitive characters or words are inserted into a pre-built synonym abstract set.
[0027] Optionally, the third processing unit is specifically configured to: sort the sensitive characters or words according to the hiding degree weight to form a sensitive object sequence; and insert the sensitive object sequence into a pre-constructed synonymous abstract set.
[0028] Optionally, the third processing unit is specifically configured to determine the semantic position and order of each of the sensitive characters or sensitive words in the sensitive object sequence, and insert the semantic position and order into a pre-constructed synonymous abstract set.
[0029] Optionally, the third processing unit is specifically used to: use the sensitive character or sensitive word corresponding to the semantic position and order as the key in the key-value pair, use the semantic position and order as the value, and insert the key-value pair including the key and value into a pre-built synonymous abstract set.
[0030] Optionally, the third processing unit is specifically configured to: perform a hash operation on the semantic position and order using a random number sequence to obtain a corresponding hash value, and insert the hash value into a pre-constructed synonymous abstract set.
[0031] Optionally, the first processing unit is specifically configured to extract sensitive components from the sensitive data, and generate statistical data describing the sensitivity of the sensitive data based on the sensitive data.
[0032] Optionally, the first processing unit is further configured to train a sensitive component extraction model using sensitive data samples before calculating the sensitivity description data of the sensitive data;
[0033] The first processing unit is specifically configured to extract the sensitive components from the sensitive data based on the sensitive component extraction model.
[0034] Optionally, the third processing unit is specifically configured to: sort the sensitive characters or sensitive words, and insert the sensitive characters or sensitive words into a pre-built pseudo-synonymous abstract set according to the logical sorting of the sensitive characters or sensitive words.
[0035] An electronic device comprises: a memory and a processor, wherein the memory stores a computer executable program, and the processor is configured to execute the computer executable program to implement the method described in any one of the embodiments of the present application.
[0036] A computer storage medium, characterized in that a computer executable program is stored on the computer storage medium, and when the computer executable program is executed, it implements the method described in any one of the embodiments of the present application.
[0037] In an embodiment of the present application, the sensitive data targeted by the pseudo-processing method is determined, and sensitivity description data of the sensitive data is counted; based on the sensitivity description data, the sensitivity values of the sensitive characters or sensitive words in the sensitive data are calculated; based on the sensitivity values of the sensitive characters or sensitive words, the sensitive characters or sensitive words are sorted and inserted into a pre-constructed synonymous abstract set, thereby reducing or avoiding security risks, especially for sensitive data. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0039] Figure 1 This is a flow chart of a pseudo-processing method for sensitive data in a heterogeneous network according to an embodiment of the present application;
[0040] Figure 2 This is a schematic diagram of the structure of a pseudo-processing device for sensitive data in a heterogeneous network according to an embodiment of the present application;
[0041] Figure 3 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present application;
[0042] Figure 4 This is a schematic diagram of the hardware structure of the electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0043] The implementation of any technical solution in the embodiments of the present application does not necessarily require achieving all of the above advantages at the same time.
[0044] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0045] In an embodiment of the present application, the sensitive data targeted by the pseudo-processing method is determined, and sensitivity description data of the sensitive data is counted; based on the sensitivity description data, the sensitivity values of the sensitive characters or sensitive words in the sensitive data are calculated; based on the sensitivity values of the sensitive characters or sensitive words, the sensitive characters or sensitive words are sorted and inserted into a pre-constructed synonymous abstract set, thereby reducing or avoiding security risks, especially for sensitive data.
[0046] In the following embodiments of the present application, the execution entity of the method may be a server.
[0047] Figure 1 This is a flowchart of a pseudo-processing method for sensitive data in a heterogeneous network according to an embodiment of the present application; Figure 1 As shown, it includes:
[0048] S101, determining the sensitive data targeted by the pseudo-processing method, and collecting data describing the sensitivity of the sensitive data;
[0049] In this embodiment, the sensitive data can be determined by constructing a filter. Specifically, the filter is a model that can identify sensitive data, or a filter that performs regular matching based on a regular expression.
[0050] Specifically, in this embodiment, the model capable of identifying sensitive data may be, for example, a neural network model, such as a neural network model that processes text, such as a fasttext model.
[0051] Specifically, the regular matching is based on a constructed regular expression, which includes a number of regular keywords and logical relationship characteristics between these regular keywords, so that the sensitive data can be quickly determined.
[0052] Furthermore, in this embodiment, the counting of sensitivity description data of the sensitive data includes: extracting sensitive components from the sensitive data, and counting the sensitivity description data of the sensitive data based on the sensitive data.
[0053] Specifically, the sensitive component is determined according to the requirements of the application scenario, for example, it can be a telephone number, ID number, name, etc.
[0054] It should be noted here that the classification of sensitive components is not absolute and can be flexibly defined by those skilled in the art.
[0055] Therefore, when performing the above-mentioned model training or regular expression construction, the construction or training is performed based on these potentially extractable sensitive components, that is, using sensitive data samples that include these potentially sensitive components to perform model training or regular expression construction.
[0056] Specifically, in this embodiment, the statistical analysis of the sensitivity description data of the sensitive data includes: using sensitive data samples to train a sensitive component extraction model;
[0057] The extracting the sensitive components from the sensitive data includes: extracting the sensitive components from the sensitive data based on the sensitive component extraction model.
[0058] In this embodiment, the sensitive data samples can be classified into two groups, one group for training and the other group for testing the accuracy of the model.
[0059] When training the sensitive component extraction model, the sensitive data is input into the sensitive component extraction model and convolved with the set weight parameters to obtain the predicted sensitive components, which are then compared with the actual sensitive components of the sensitive data samples to calculate the information entropy reduction. Based on the information entropy reduction, the search direction and adjustment target of the weight parameters are determined to adjust the weight parameters until the information entropy reduction satisfies the set entropy reduction function.
[0060] Specifically, the entropy reduction function uses the predicted sensitive components obtained from two consecutive trainings as independent variables, calculates the entropy of the two, and thus obtains energy loss. The smaller the energy loss, the more accurate the sensitive component extraction model.
[0061] S102. Calculate the sensitivity value of the sensitive word or words in the sensitive data according to the sensitivity description data;
[0062] In this embodiment, the sensitivity description data includes several dimensions to describe the sensitivity of the sensitive data from different dimensions. For example, if based on color management, the sensitivity description data may include sensitive saturation data, sensitive color data, sensitive brightness data, etc. To this end, different weight indices are assigned to the sensitive saturation data, sensitive color data, and sensitive brightness data, and then the sensitivity description data is multiplied by the weight index matrix to obtain a sensitivity value.
[0063] Specifically, in this embodiment, the sensitive data is segmented into characters to obtain sensitive characters or sensitive words, and the sensitivity description data is assigned to the sensitive characters or sensitive words, so that based on the sensitivity description data corresponding to the sensitive characters or sensitive words, and the weight index matrix, a sensitivity value based on the sensitive characters or sensitive words is obtained, and the sensitivity values of these sensitive characters or sensitive words are superimposed to obtain a final sensitivity value to participate in the processing of step S103.
[0064] In this embodiment, based on the sensitivity value of the sensitive character or sensitive word, the granularity of determining the sensitivity is increased, so that the determined sensitivity is more accurate.
[0065] S103: Sort the sensitive words or sensitive terms according to their sensitivity values, and insert them into a pre-built synonym abstract set.
[0066] In this embodiment, sorting the sensitive words or sensitive terms according to their sensitivity values and inserting them into a pre-built synonym abstract set includes:
[0067] Determining a hiding degree weight of the corresponding sensitive word or sensitive term according to the sensitivity value of the sensitive word or sensitive term;
[0068] According to the hiding degree weight, the sensitive characters or words are inserted into a pre-built synonym abstract set.
[0069] In this embodiment, the synonymous abstract set is a combination of synonyms with a predetermined degree of the sensitive character or sensitive word. The synonymous abstract set can form a matrix as a whole. To this end, the insertion is achieved, for example, through a convolution operation, thereby ensuring that the sensitive data does not lose its meaning and realizing decryption processing at the same time.
[0070] Specifically, in this embodiment, the sensitive characters or sensitive words are inserted into a pre-constructed synonymous abstract set according to the hiding degree weight, including: sorting the sensitive characters or sensitive words according to the hiding degree weight to form a sensitive object sequence; inserting the sensitive object sequence into the pre-constructed synonymous abstract set. Based on the sensitive object sequence, batch insertion can be quickly implemented, which improves the speed of data processing and ensures that disorder will not occur.
[0071] Furthermore, inserting the sensitive object sequence into a pre-constructed synonymous abstract set includes: determining the semantic position and order of each sensitive character or sensitive word in the sensitive object sequence, and inserting the semantic position and order into the pre-constructed synonymous abstract set, so that the sensitive object sequence is inserted into the synonymous abstract set while maintaining its original semantic meaning based on the semantic position and order.
[0072] Furthermore, the inserting of the semantic position and order into a pre-built synonymous abstract set includes: using the sensitive character or sensitive word corresponding to the semantic position and order as the key in a key-value pair, using the semantic position and order as the value, and inserting the key-value pair including the key and value into the pre-built synonymous abstract set. Based on the key-value pair method, the sensitive character or sensitive word can be accurately and simply inserted into the synonymous abstract set.
[0073] Furthermore, the inserting of the semantic position and order into a pre-built synonymous abstract set includes: using a random number sequence to perform a hash operation on the semantic position and order to obtain a corresponding hash value, and inserting the hash value into the pre-built synonymous abstract set. The hash operation further enhances security and ensures that the data will not be tampered with when inserted into the synonymous abstract set.
[0074] Optionally, sorting the sensitive characters or sensitive words and inserting them into a pre-built set of pseudo-synonymous abstract words includes sorting the sensitive characters or sensitive words and inserting them into a pre-built set of pseudo-synonymous abstract words according to their logical order. The logical order is generated, for example, based on the semantics and position described above.
[0075] Figure 2 This is a schematic diagram of the structure of a pseudo-processing device for sensitive data in a heterogeneous network according to an embodiment of the present application; Figure 2 As shown, it includes:
[0076] The first processing unit 201 is configured to determine the sensitive data targeted by the pseudo-processing device and collect data describing the sensitivity of the sensitive data;
[0077] A second processing unit 202 is configured to calculate the sensitivity value of the sensitive character or sensitive word in the sensitive data according to the sensitivity description data;
[0078] The third processing unit 203 is configured to sort the sensitive characters or sensitive words according to their sensitivity values and insert them into a pre-built synonym abstract set.
[0079] Optionally, the third processing unit is specifically configured to:
[0080] Determining a hiding degree weight of the corresponding sensitive word or sensitive term according to the sensitivity value of the sensitive word or sensitive term;
[0081] According to the hiding degree weight, the sensitive characters or words are inserted into a pre-built synonym abstract set.
[0082] Optionally, the third processing unit is specifically configured to: sort the sensitive characters or words according to the hiding degree weight to form a sensitive object sequence; and insert the sensitive object sequence into a pre-constructed synonymous abstract set.
[0083] Optionally, the third processing unit is specifically configured to determine the semantic position and order of each of the sensitive characters or sensitive words in the sensitive object sequence, and insert the semantic position and order into a pre-constructed synonymous abstract set.
[0084] Optionally, the third processing unit is specifically used to: use the sensitive character or sensitive word corresponding to the semantic position and order as the key in the key-value pair, use the semantic position and order as the value, and insert the key-value pair including the key and value into a pre-built synonymous abstract set.
[0085] Optionally, the third processing unit is specifically configured to: perform a hash operation on the semantic position and order using a random number sequence to obtain a corresponding hash value, and insert the hash value into a pre-constructed synonymous abstract set.
[0086] Optionally, the first processing unit is specifically configured to extract sensitive components from the sensitive data, and generate statistical data describing the sensitivity of the sensitive data based on the sensitive data.
[0087] Optionally, the first processing unit is further configured to train a sensitive component extraction model using sensitive data samples before calculating the sensitivity description data of the sensitive data;
[0088] The first processing unit is specifically configured to extract the sensitive components from the sensitive data based on the sensitive component extraction model.
[0089] Optionally, the third processing unit is specifically configured to: sort the sensitive characters or sensitive words, and insert the sensitive characters or sensitive words into a pre-built pseudo-synonymous abstract set according to the logical sorting of the sensitive characters or sensitive words.
[0090] An embodiment of the present application further provides a computer storage medium, on which a computer executable program is stored. When the computer executable program is executed, the method described in any one of the embodiments of the present application is implemented.
[0091] An embodiment of the present application further provides a computer program product, wherein a computer executable program is stored on the computer program product, and when the computer executable program is executed, the method described in any one of the embodiments of the present application is implemented.
[0092] Figure 3 This is a schematic diagram of the electronic device structure according to the embodiment of the present application; Figure 3 As shown, it includes: a memory 301 and a processor 302, the memory stores a computer executable program, and the processor is used to execute the computer executable program to implement the method described in any embodiment of the present application.
[0093] Figure 4 Schematic diagram of the hardware structure of the electronic device according to the embodiment of the present application; Figure 4 As shown, the hardware structure of the electronic device may include: a processor 401, a communication interface 402, a computer-readable medium 403 and a communication bus 404;
[0094] The processor 401, the communication interface 402, and the computer-readable medium 403 communicate with each other via a communication bus 404;
[0095] Optionally, the communication interface 402 may be an interface of a communication module, such as an interface of a GSM module;
[0096] The processor 401 may be specifically configured to run an executable program stored in the memory, thereby executing all or part of the processing steps of any of the above method embodiments.
[0097] The processor 401 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor.
[0098] The electronic devices of the embodiments of the present application exist in various forms, including but not limited to:
[0099] (1) Mobile communication devices: These devices are characterized by their mobile communication capabilities and are primarily designed to provide voice and data communications. These terminals include smartphones (e.g., iPhones), multimedia phones, feature phones, and low-end phones.
[0100] (2) Ultra-mobile personal computer devices: These devices fall under the category of personal computers, have computing and processing capabilities, and generally also have mobile Internet access. These terminals include PDAs, MIDs, and UMPCs, such as the iPad.
[0101] (3) Portable entertainment devices: These devices can display and play multimedia content. These devices include audio and video players (such as iPods), handheld game consoles, e-books, smart toys, and portable car navigation devices.
[0102] (4) Server: A device that provides computing services. The server consists of a processor 710, a hard disk, memory, a system bus, etc. The server is similar to a general computer architecture, but because it needs to provide highly reliable services, it has higher requirements in terms of processing power, stability, reliability, security, scalability, and manageability.
[0103] (5) Other electronic devices with data interaction functions.
[0104] It should be pointed out that, according to the needs of implementation, the various components / steps described in the embodiments of the present application can be split into more components / steps, or two or more components / steps or partial operations of components / steps can be combined into new components / steps to achieve the purpose of the embodiments of the present application.
[0105] The above-mentioned method according to the embodiment of the present application can be implemented in hardware, firmware, or be implemented as software or computer code that can be stored in a recording medium (such as CD ROM, RAM, floppy disk, hard disk or magneto-optical disk), or be implemented as a computer code originally stored in a remote recording medium or a non-temporary machine-readable medium downloaded through a network and stored in a local recording medium, so that the method described herein can be stored in such software processing on a recording medium using a general-purpose computer, a special-purpose processor or programmable or special-purpose hardware (such as ASIC or FPGA). It can be understood that a computer, a processor, a microprocessor controller or programmable hardware includes a storage component (for example, RAM, ROM, flash memory, etc.) that can store or receive software or computer code, and when the software or computer code is accessed and executed by a computer, a processor or hardware, the verification code generation method described herein is implemented. In addition, when a general-purpose computer accesses the code for implementing the verification code generation method shown here, the execution of the code converts the general-purpose computer into a special-purpose computer for executing the verification code generation method shown here.
[0106] Those skilled in the art will appreciate that the units and method steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the embodiments of this application.
[0107] The above implementation methods are only used to illustrate the embodiments of the present application, and are not intended to limit the embodiments of the present application. Ordinary technicians in the relevant technical field can make various changes and modifications without departing from the spirit and scope of the embodiments of the present application. Therefore, all equivalent technical solutions also fall within the scope of the embodiments of the present application, and the scope of patent protection of the embodiments of the present application should be defined by the claims.
Claims
1. A pseudo-processing method for sensitive data in a heterogeneous network, characterized in that: include: Determining the sensitive data targeted by the pseudo-processing method, and collecting statistical data describing the sensitivity of the sensitive data; Calculating the sensitivity value of the sensitive word or words in the sensitive data according to the sensitivity description data; Sort the sensitive words or sensitive terms according to their sensitivity values and insert them into a pre-built synonym abstract set; The synonymous abstract set is a combination of synonyms with a predetermined degree of the sensitive character or sensitive word. The synonymous abstract set can form a matrix as a whole. For this purpose, the insertion is achieved through a convolution operation, thereby ensuring that the sensitive data does not lose its meaning and achieving decryption processing at the same time. Wherein, determining the sensitive data targeted by the pseudo-processing method includes determining the sensitive data by constructing a filter, wherein the filter is a model capable of identifying sensitive data; the model capable of identifying sensitive data includes a neural network model for processing text, specifically a fasttext model; The counting of the sensitivity description data of the sensitive data includes: extracting sensitive components from the sensitive data, and counting the sensitivity description data of the sensitive data based on the sensitive data; The sensitive components are determined according to the requirements of the application scenario. When performing model training, the model is constructed or trained based on the extracted sensitive components, that is, the model is trained using sensitive data samples including sensitive components; The method of collecting the sensitivity description data of the sensitive data includes: using sensitive data samples to train a sensitive component extraction model; The extracting the sensitive components from the sensitive data includes: extracting the sensitive components from the sensitive data based on the sensitive component extraction model; The sensitive data samples can be classified into two groups, one group for training and the other group for testing the accuracy of the model. When training the sensitive component extraction model, the sensitive data is input into the sensitive component extraction model and convolved with the set weight parameters to obtain predicted sensitive components, which are then compared with the actual sensitive components of the sensitive data samples to calculate information entropy reduction. Based on the information entropy reduction, the search direction and adjustment target of the weight parameters are determined to adjust the weight parameters until the information entropy reduction satisfies the set entropy reduction function. The entropy reduction function uses the predicted sensitive components obtained from two consecutive trainings as independent variables, calculates the entropy of the two, and thus obtains energy loss. The smaller the energy loss, the more accurate the sensitive component extraction model.
2. The method according to claim 1, characterized in that The step of sorting the sensitive words or sensitive terms according to their sensitivity values and inserting them into a pre-built synonym abstract set includes: Determining a hiding degree weight for the corresponding sensitive word or sensitive term based on the sensitivity value of the sensitive word or sensitive term; According to the hiding degree weight, the sensitive characters or words are inserted into a pre-built synonym abstract set.
3. The method according to claim 2, characterized in that The method of inserting the sensitive characters or sensitive words into a pre-constructed synonymous abstract set according to the hiding degree weight includes: sorting the sensitive characters or sensitive words according to the hiding degree weight to form a sensitive object sequence; and inserting the sensitive object sequence into the pre-constructed synonymous abstract set.
4. The method according to claim 3, characterized in that Inserting the sensitive object sequence into a pre-built synonymous abstract set includes: determining the semantic position and order of each sensitive character or sensitive word in the sensitive object sequence, and inserting the semantic position and order into the pre-built synonymous abstract set.
5. A pseudo-processing device for sensitive data in a heterogeneous network, characterized in that: include: A first processing unit is configured to determine the sensitive data targeted by the pseudo-processing device and collect data describing the sensitivity of the sensitive data; a second processing unit, configured to calculate, based on the sensitivity description data, a sensitivity value of a sensitive character or sensitive word in the sensitive data; a third processing unit, configured to sort the sensitive characters or sensitive words according to their sensitivity values and insert them into a pre-built synonym abstract set; The synonymous abstract set is a combination of synonyms with a predetermined degree of the sensitive character or sensitive word. The synonymous abstract set can form a matrix as a whole. For this purpose, the insertion is achieved through a convolution operation, thereby ensuring that the sensitive data does not lose its meaning and achieving decryption processing at the same time. Wherein, determining the sensitive data targeted by the pseudo-processing method includes determining the sensitive data by constructing a filter, wherein the filter is a model capable of identifying sensitive data; the model capable of identifying sensitive data includes a neural network model for processing text, specifically a fasttext model; The counting of the sensitivity description data of the sensitive data includes: extracting sensitive components from the sensitive data, and counting the sensitivity description data of the sensitive data based on the sensitive data; The sensitive components are determined according to the requirements of the application scenario. When performing model training, the model is constructed or trained based on the extracted sensitive components, that is, the model is trained using sensitive data samples including sensitive components; The method of collecting the sensitivity description data of the sensitive data includes: using sensitive data samples to train a sensitive component extraction model; The extracting the sensitive components from the sensitive data includes: extracting the sensitive components from the sensitive data based on the sensitive component extraction model; The sensitive data samples can be classified into two groups, one group for training and the other group for testing the accuracy of the model. When training the sensitive component extraction model, the sensitive data is input into the sensitive component extraction model and convolved with the set weight parameters to obtain predicted sensitive components, which are then compared with the actual sensitive components of the sensitive data samples to calculate information entropy reduction. Based on the information entropy reduction, the search direction and adjustment target of the weight parameters are determined to adjust the weight parameters until the information entropy reduction satisfies the set entropy reduction function. The entropy reduction function uses the predicted sensitive components obtained from two consecutive trainings as independent variables, calculates the entropy of the two, and thus obtains energy loss. The smaller the energy loss, the more accurate the sensitive component extraction model.
6. The device according to claim 5, characterized in that The third processing unit is specifically configured to: Determining a hiding degree weight for the corresponding sensitive word or sensitive term based on the sensitivity value of the sensitive word or sensitive term; According to the hiding degree weight, the sensitive characters or words are inserted into a pre-built synonym abstract set.
7. The device according to claim 6, characterized in that The third processing unit is specifically used to: sort the sensitive characters or sensitive words according to the hiding degree weight to form a sensitive object sequence; and insert the sensitive object sequence into a pre-constructed synonym abstract set.
8. The device according to claim 7, characterized in that The third processing unit is specifically used to determine the semantic position and order of each sensitive character or sensitive word in the sensitive object sequence, and insert the semantic position and order into a pre-constructed synonym abstract set.
9. An electronic device, characterized in that: include: A memory and a processor, wherein the memory stores a computer executable program, and the processor is configured to execute the computer executable program to implement the method according to any one of claims 1 to 4.
10. A computer storage medium, characterized in that The computer storage medium stores a computer executable program, and the computer executable program implements the method according to any one of claims 1 to 4 when executed.
Citation Information
Patent Citations
Search word recommendation method and device
CN106777217A
Data grading method and device, and related equipment
CN110941956A