A desensitization verification method and device, electronic equipment and storage medium

By generating a sensitive data feature library and obtaining front-end content through browser access URLs, combined with passive data sources for desensitization verification, the problem of ignoring plaintext transmitted data in existing technologies is solved, and comprehensive and accurate desensitization verification of WEB business data is achieved.

CN115906171BActive Publication Date: 2026-05-26HUBEI TIANRONGXIN NETWORK SECURITY TECH CO LTD +3
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HUBEI TIANRONGXIN NETWORK SECURITY TECH CO LTD
Filing Date
2022-12-05
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Existing de-identification verification methods mainly rely on the identification of plaintext transmitted content, which cannot meet the de-identification verification requirements of web business data after changes in encoding and rendering methods such as HTTPS, leading to the neglect of plaintext transmitted data.

Method used

By generating a sensitive data feature library containing sensitive data features and URL addresses, comprehensive desensitization verification of plaintext and encrypted transmitted data is achieved. The front-end content is obtained by accessing the URL address through a browser and desensitization detection is performed. Accurate verification is then performed in conjunction with passive data sources.

Benefits of technology

It achieves comprehensive desensitization verification of web business data, ensuring accurate detection and protection of sensitive data during plaintext and encrypted transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115906171B_ABST
    Figure CN115906171B_ABST
Patent Text Reader

Abstract

This application provides a method, apparatus, electronic device, and storage medium for de-identification verification. The de-identification verification method includes: generating a sensitive data feature library, which includes: sensitive data features, actively identified URL addresses, and passive data sources; responding to an active detection request, obtaining front-end content returned by the server corresponding to the URL address, and performing de-identification verification on the front-end content based on the sensitive data features; and responding to a passive detection request, performing de-identification verification on the passive data source based on the sensitive data features. Implementing the above embodiments achieves comprehensive de-identification verification of web business data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data anonymization technology, and more specifically, to an anonymization verification method, apparatus, electronic device, and storage medium. Background Technology

[0002] In the context of cybersecurity and compliance requirements, data security and protection have become paramount. Throughout the data lifecycle, it is necessary to classify and classify data and effectively protect important and sensitive data. Data masking, as a technical means of protecting important and sensitive data, uses specific masking rules to mask, replace, or interfere with sensitive data, achieving reliable protection for this sensitive and important data. Currently, masking technology itself has become a relatively mature technique. Existing or traditional masking verification methods mainly judge based on whether data has been leaked or whether sensitive data has been transmitted in plaintext, defining the rationality and effectiveness of masking by the final result of sensitive data protection. With the popularization of HTTPS and changes in data transmission encoding and rendering methods, traditional data masking verification methods based on simple plaintext transmission content authentication can no longer meet the data masking verification needs of web applications. Summary of the Invention

[0003] In view of this, the purpose of this application is to provide a de-identification verification method, apparatus, electronic device and storage medium that can realize comprehensive de-identification verification of WEB business data.

[0004] In a first aspect, embodiments of this application provide a de-identification verification method, including:

[0005] Generate a sensitive data feature library, which includes: sensitive data features and actively identified URL addresses and passive data sources;

[0006] In response to an active detection request, the front-end content returned by the server corresponding to the URL address is obtained based on the URL address, and the front-end content is de-identified and verified based on the sensitive data characteristics;

[0007] In response to a passive detection request, the passive data source is de-identified and verified based on the sensitive data characteristics.

[0008] In the above implementation process, the sensitive data feature library includes sensitive data features, actively identified URL addresses, and passive data sources. Based on the sensitive data features, both plaintext and ciphertext data can be anonymized and verified, but not all sensitive data is completely removed. The content of the front-end can be obtained through the URL address, and the plaintext content of the front-end can be anonymized and verified. The ciphertext content of the back-end can be anonymized and detected through the passive data source. If sensitive data is detected based on the sensitive data features, it indicates that the server's anonymization algorithm is not accurate enough. Existing technologies typically only anonymize and verify the ciphertext-transmitted back-end data, but do not pay attention to plaintext data. Therefore, based on this implementation method, comprehensive anonymization and verification of server data can be achieved.

[0009] Further, the front-end content includes: displaying a webpage; the step of obtaining the front-end content returned by the server corresponding to the URL address based on the URL address includes:

[0010] Send an access request to the URL address through the browser;

[0011] Obtain the webpage returned by the server based on the access request.

[0012] In the above implementation process, the browser actively accesses the URL address, causing the server corresponding to the URL address to return the corresponding display webpage. The display webpage is content transmitted in plaintext. Based on this implementation method, the desensitization verification of plaintext transmission content can be achieved.

[0013] Furthermore, the step of performing de-identification verification on the front-end content includes:

[0014] Obtain the image of the webpage to be displayed;

[0015] Identify the text data in the image;

[0016] The text data is desensitized and verified based on the sensitive data features in the sensitive data feature library.

[0017] In the above implementation process, by recognizing the images on the webpage, the text data in the webpage can be extracted, and the text data can be further de-identified and verified.

[0018] Furthermore, the active detection request includes: the target browser;

[0019] The steps of sending an access request to the URL address through a browser include:

[0020] The target browser sends an access request to the URL address.

[0021] In the above implementation process, it was taken into account that different users use different clients and browsers, so the format and content of the displayed web pages are also different. In order to perform accurate de-identification verification, the target browser is added to the active detection request, and the corresponding data is obtained through the target browser, thereby obtaining the corresponding web pages under different target browsers.

[0022] Furthermore, the sensitive data features include: sensitive data processing rules and de-identified data features;

[0023] The step of desensitizing and verifying the front-end content based on the sensitive data characteristics includes:

[0024] The front-end content is identified according to the sensitive data processing rules to obtain a first processing result;

[0025] The first processing result is desensitized and verified based on the desensitized data characteristics.

[0026] The step of performing de-identification verification on the passive data source based on the sensitive data characteristics includes:

[0027] The passive data source is desensitized and verified according to the sensitive data processing rules to obtain the second processing result;

[0028] In the above implementation process, the desensitization verification of passive source data is achieved through reverse verification. The above process directly compares the sensitive data processing rules and sensitive data characteristics, which can accurately determine whether the front-end content and passive data source contain sensitive data, thereby achieving accurate desensitization verification.

[0029] Furthermore, the passive detection request includes: execution conditions;

[0030] The step of performing de-identification verification on the passive data source based on the sensitive data characteristics in response to the passive detection request includes:

[0031] In response to the passive detection request, when the execution condition is met, the passive data source is de-identified and verified based on the sensitive data characteristics.

[0032] In the above implementation process, by setting execution conditions, it is possible to achieve precise adjustment of the actual detection and realize refined and accurate desensitization verification.

[0033] Furthermore, the passive detection request includes target information from the data source;

[0034] The step of performing passive de-identification verification based on sensitive data features in the sensitive data feature library includes:

[0035] Filter the data source corresponding to the target information from the data source;

[0036] Passive desensitization verification is performed on the data source corresponding to the target information.

[0037] Secondly, embodiments of this application provide a desensitization verification device, comprising:

[0038] A generation module is used to generate a sensitive data feature library, which includes: sensitive data features and actively identified URL addresses;

[0039] The response module is used to respond to active detection requests, obtain the front-end content returned by the server corresponding to the URL address, and perform active de-identification verification on the front-end content; the response module is also used to respond to passive detection requests, and perform passive de-identification verification on the sensitive data features in the sensitive data feature library.

[0040] Thirdly, an electronic device provided in this application includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the method as described in any of the first aspects.

[0041] Fourthly, embodiments of this application provide a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the method described in any of the first aspects.

[0042] Other features and advantages disclosed in this application will be set forth in the following description, or some features and advantages may be inferred from the description or determined without doubt, or may be learned by practicing the above-described technology disclosed in this application.

[0043] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description

[0044] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0045] Figure 1 A flowchart illustrating the desensitization verification method provided in this application embodiment;

[0046] Figure 2 This is a schematic diagram of the desensitization verification device provided in the embodiments of this application;

[0047] Figure 3 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0048] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.

[0049] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0050] Example 1

[0051] See Figure 1 This application provides a de-identification verification method, including:

[0052] S101: Generate a sensitive data feature library, which includes: sensitive data features, actively identified URLs, and passive data sources;

[0053] The sensitive data feature library includes sensitive data features, actively identified URLs, and passive data sources. Based on these features, both plaintext and encrypted data can be anonymized and verified. If sensitive data is detected based on these features, it indicates that the server's anonymization algorithm is not precise enough and has not completely removed the sensitive data. The URL allows access to the front-end content, enabling anonymization verification of the plaintext content transmitted on the front-end. The passive data source allows for anonymization detection of the encrypted content transmitted on the back-end.

[0054] In existing technologies, the backend data transmitted in encrypted form is usually directly de-identified and verified. However, no attention is paid to the data transmitted in plaintext. Therefore, this step can prepare for the subsequent de-identification and verification of the frontend content.

[0055] The URLs are added based on experience and can be request addresses corresponding to key business operations, requests for important data, or addresses where staff deem other important data located. For example, staff create a database, with a separate table to store URLs and another table to store sensitive data characteristics, thus generating a sensitive data characteristic database. Passive data sources are server-generated log files, which can be manually imported in batches or sent in batches by the server. Sensitive data characteristics and passive data sources can be added and deleted as needed.

[0056] S102: In response to the active detection request, obtain the front-end content returned by the server corresponding to the URL address, and perform desensitization verification on the front-end content based on the sensitive data characteristics;

[0057] By responding to proactive detection requests, customized detection of the front-end content corresponding to the target URL can be achieved, enabling comprehensive verification of anonymized data.

[0058] In one possible implementation, the URL address is divided into multiple categories according to the business; the active detection request includes the target category among the multiple categories; S102 includes: obtaining the front-end content returned by the server corresponding to the target URL address according to the URL address of the target category, and actively verifying the front-end content.

[0059] In the above implementation process, considering that the project development is carried out according to modules and business, the URL address is divided into multiple categories according to the business. During the project development process, data desensitization verification can be performed in real time according to the progress of the project development.

[0060] In one possible implementation, the front-end content includes: displaying a webpage; S102 includes: sending an access request to a URL address through a browser; and obtaining the webpage to be displayed returned by the server based on the access request.

[0061] In the above implementation process, the browser sends an access request to the server corresponding to the URL, and the server returns the corresponding display webpage. The display webpage transmits data in plaintext. In existing technologies, the detection of plaintext transmission data is usually ignored. Therefore, the above method can achieve complete data de-verification.

[0062] In one possible implementation, the active detection request includes: a target browser, and the step of sending an access request to a URL address through the browser, including: sending an access request to a URL address through the target browser.

[0063] In the above implementation process, it was considered that different users use different clients and browsers, resulting in different formats and content of the displayed web pages. To perform accurate de-identification verification, the target browser can be added to the active detection request. Data is then obtained through the target browser to retrieve the corresponding web pages for different target browsers. It is understood that the target browser can include one or more browsers, such as Firefox, Google Chrome, and Microsoft Chrome.

[0064] In one possible implementation, the step of proactively de-identifying and verifying the content on the front end includes: acquiring an image of the displayed webpage; identifying text data in the image; and de-identifying and verifying the text data according to sensitive data features in a sensitive data feature library.

[0065] OCR can be used to recognize text data in images.

[0066] In the above implementation process, the existing technology directly performs desensitization verification on the encrypted data. However, some data is transmitted in plaintext. Therefore, the existing desensitization verification is not comprehensive enough. Based on the above implementation method, the plaintext data in the image can be desensitized and verified, making the desensitization more comprehensive.

[0067] In one possible implementation, S102 can be implemented as follows: an active detection task is generated based on an active detection request, the active detection request including the execution conditions of the active detection task, the active detection task is triggered when the execution conditions are met, the active detection task is used to open a process, drive the process to obtain the front-end content returned by the server corresponding to the URL address according to the URL address, and perform desensitization verification on the front-end content according to the sensitive data characteristics.

[0068] Furthermore, the execution conditions include, but are not limited to: adding sensitive data features in batches to the desensitized data feature library, and the desensitized data features in the desensitized data feature library reaching a preset number.

[0069] In the above implementation process, considering that the characteristics of sensitive data are accumulated as the machine learning model is continuously output, and some machine learning models are constantly running, the characteristics of sensitive data are constantly generated. Therefore, a desensitization verification can be performed when the desensitized data characteristics are updated to a preset number.

[0070] Furthermore, the desensitization verification of front-end content based on sensitive data characteristics can be achieved in the following way: the front-end content is identified according to sensitive data processing rules to obtain a first processing result; the first processing result is desensitized and verified according to the desensitized data characteristics.

[0071] For example, the processing rule for ID cards is to mask the data in the middle of the ID card. The data characteristics of the de-identified ID card are that the middle digits are replaced with asterisks (*), and the preceding digits are the regional code. First, the text data in the front-end content is processed according to the ID card processing rule to obtain the first processing result. It is then determined whether the first processing result conforms to the characteristic that the middle digits are replaced with asterisks (*) and the preceding digits are the regional code. If so, it indicates that the de-identification effect is not good.

[0072] It should be noted that the front-end content contains various types of privacy data, and different privacy data correspond to different de-identified data characteristics. If it is an address, the de-identified data characteristic is the de-identified address. A matching algorithm can be used to match multiple de-identified addresses with the first processing result to obtain a matching score. The matching score is then used to determine whether the front-end content contains sensitive data.

[0073] S103: In response to a passive detection request, perform desensitization verification on the passive data source based on the characteristics of sensitive data.

[0074] The data feature database stores encrypted data, which is also a passive verification data source. Encrypted data is transmitted based on protocols and is not directly displayed on web pages. The server generates logs during operation, which can be used as a data source.

[0075] S103 includes: desensitization verification of passive data sources based on sensitive data features in the sensitive data feature library.

[0076] In the above embodiments, the sensitive data features include corresponding regular expressions and keywords, and different types of sensitive data have different regular expressions and keywords.

[0077] In one possible implementation, S103 includes: in response to a passive detection request, performing desensitization verification on the passive data source based on sensitive data characteristics when the execution conditions are met.

[0078] Furthermore, the execution condition can be that the capacity of the passive data source reaches a preset threshold.

[0079] For example, since the files generated by the server are based on the business volume, a large amount of business data is needed to verify whether the server has desensitized all types of data. Therefore, the execution condition can make the capacity of the passive data source reach a preset threshold, or make a passive detection request every preset time (one day, one week, one month).

[0080] In one possible implementation, the passive detection request includes target information in the data source; S103 includes: filtering out the data source corresponding to the target information in the data source; and performing passive desensitization verification on the data source corresponding to the target information.

[0081] In the above embodiments, the target information can be a passive data source generated for a specific IP address or port.

[0082] In one possible implementation, S103 includes: performing desensitization verification on the passive data source according to sensitive data processing rules to obtain a second processing result; and performing desensitization verification on the second processing result according to the desensitized data characteristics.

[0083] For example, the processing rule for ID cards is to mask the data in the middle of the ID card. The data characteristics of the de-identified ID card are that the middle digits are replaced with asterisks (*), and the preceding digits are the regional code. First, the text data in the front-end content is processed according to the ID card processing rule to obtain a second processing result. It is then determined whether the second processing result conforms to the characteristic that the middle digits are replaced with asterisks (*) and the preceding digits are the regional code. If so, it indicates that the de-identification effect is not good.

[0084] It should be noted that the front-end content contains various types of privacy data, and different privacy data correspond to different de-identified data characteristics. If it is an address, the de-identified data characteristic is the de-identified address. A matching algorithm can be used to match multiple de-identified addresses with the second processing result to obtain a matching score. The matching score is used to determine whether the front-end content contains sensitive data.

[0085] Example 2

[0086] See Figure 2 This application provides a desensitization verification device, comprising:

[0087] Module 1 generates a sensitive data feature library using language. The sensitive data feature library includes: sensitive data features and actively identified URLs and passive data sources.

[0088] Response module 2 is used to respond to active detection requests, obtain the front-end content returned by the server according to the URL address, and perform desensitization verification on the front-end content based on sensitive data characteristics;

[0089] Response module 2 is also used to respond to passive detection requests and perform desensitization verification on the passive data source based on the characteristics of sensitive data.

[0090] In one possible implementation, the front-end content includes: displaying a webpage; the response module 2 is also used to send an access request to the URL address via a browser;

[0091] Retrieve the webpage displayed by the server in response to the access request.

[0092] In one possible implementation, the response module 2 is further configured to acquire an image of the webpage to be displayed; identify text data in the image; and perform desensitization verification on the text data based on sensitive data features in the sensitive data feature library.

[0093] In one possible implementation, the active detection request includes: a target browser; the response module 2 is also used to send an access request to the URL address through the target browser.

[0094] In one possible implementation, the sensitive data features include: sensitive data processing rules and desensitized data features; the response module 2 is further configured to identify the front-end content according to the sensitive data processing rules to obtain a first processing result; perform desensitization verification on the first processing result according to the desensitized data features; perform desensitization verification on the passive data source according to the sensitive data processing rules to obtain a second processing result; and perform desensitization verification on the second processing result according to the desensitized data features.

[0095] In one possible implementation, the passive detection request includes: an execution condition; the response module 2 is further configured to, in response to the passive detection request, perform desensitization verification on the passive data source based on the sensitive data characteristics when the execution condition is fulfilled.

[0096] In one possible implementation, the passive detection request includes target information in the data source; the response module 2 is also used to filter out the data source corresponding to the target information in the data source; and to perform passive desensitization verification on the data source corresponding to the target information.

[0097] This application also provides an electronic device, please refer to [link to application]. Figure 3 , Figure 3 This is a structural block diagram of an electronic device provided in an embodiment of this application. The electronic device may include a processor 31, a communication interface 32, a memory 33, and at least one communication bus 34. The communication bus 34 is used to enable direct communication between these components. In this embodiment, the communication interface 32 of the electronic device is used for signaling or data communication with other node devices. The processor 31 may be an integrated circuit chip with signal processing capabilities.

[0098] The processor 31 described above can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an off-the-shelf programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor, or the processor 31 can be any conventional processor.

[0099] The memory 33 may be, but is not limited to, Random Access Memory (RAM), Read Only Memory (ROM), Programmable Read-Only Memory (PROM), Erasable Programmable Read-Only Memory (EPROM), Electrically Erasable Programmable Read-Only Memory (EEPROM), etc. The memory 33 stores computer-readable instructions. When these computer-readable instructions are executed by the processor 31, the electronic device can perform the various steps involved in the above method embodiments.

[0100] Alternatively, the electronic device may also include a storage controller and an input / output unit.

[0101] The memory 33, memory controller, processor 31, peripheral interface, and input / output unit are electrically connected directly or indirectly to achieve data transmission or interaction. For example, these components can be electrically connected to each other through one or more communication buses 34. The processor 31 is used to execute executable modules stored in the memory 33, such as software function modules or computer programs included in electronic devices.

[0102] Input / output units are used to enable users to create tasks and set optional start periods or preset execution times for those tasks, facilitating user-server interaction. Input / output units can be, but are not limited to, a mouse and keyboard.

[0103] Understandable. Figure 3 The structure shown is for illustrative purposes only; the electronic device may also include components that are more advanced than those shown. Figure 3 The more or fewer components shown, or having the same Figure 3 The different configurations shown. Figure 3The components shown can be implemented using hardware, software, or a combination thereof.

[0104] This application also provides a computer-readable storage medium storing instructions. When the instructions are executed on a computer, the computer program is executed by a processor to implement the method of the method embodiment. To avoid repetition, the details will not be repeated here.

[0105] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can also be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code, which contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0106] In addition, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0107] If a function is implemented as a software module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0108] The above are merely embodiments of this application and are not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application. It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0109] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0110] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes the element.

Claims

1. A method for desensitization verification, characterized in that, include: Generate a sensitive data feature library, which includes: sensitive data features, actively identified URL addresses, and passive data sources; In response to an active detection request, the front-end content returned by the server corresponding to the URL address is obtained based on the URL address, and the front-end content is de-identified and verified based on the sensitive data characteristics; In response to a passive detection request, the passive data source is de-identified and verified based on the sensitive data characteristics. The front-end content includes: displaying a webpage; the active detection request includes: the target browser; The step of obtaining the front-end content returned by the server corresponding to the URL address includes: The target browser sends an access request to the URL address. Obtain the webpage returned by the server based on the access request.

2. The desensitization verification method according to claim 1, characterized in that, The step of performing de-identification verification on the front-end content includes: Obtain the image of the webpage to be displayed; Identify the text data in the image; The text data is desensitized and verified based on the sensitive data features in the sensitive data feature library.

3. The desensitization verification method according to claim 1, characterized in that, The sensitive data features include: sensitive data processing rules and de-identified data features; The step of desensitizing and verifying the front-end content based on the sensitive data characteristics includes: The front-end content is identified according to the sensitive data processing rules to obtain a first processing result; The first processing result is desensitized and verified based on the desensitized data characteristics. The step of performing de-identification verification on the passive data source based on the sensitive data characteristics includes: The passive data source is processed according to the sensitive data processing rules to obtain a second processing result; The second processing result is then de-identified based on the de-identified data characteristics.

4. The desensitization verification method according to claim 1, characterized in that, The passive detection request includes: execution conditions; The step of performing de-identification verification on the passive data source based on the sensitive data characteristics in response to the passive detection request includes: In response to the passive detection request, when the execution condition is met, the passive data source is de-identified and verified based on the sensitive data characteristics.

5. The desensitization verification method according to claim 1, characterized in that, The passive detection request includes target information from the data source; the target information includes a passive data source generated for a specified IP or a specified port. The step of performing passive de-identification verification based on sensitive data features in the sensitive data feature library includes: The target information is filtered out from the data source; The target information is passively desensitized and verified.

6. A desensitization verification device, characterized in that, include: The generation module generates a sensitive data feature library using a language. The sensitive data feature library includes: sensitive data features and actively identified URL addresses and passive data sources. The response module is used to respond to the active detection request, obtain the front-end content returned by the server corresponding to the URL address, and perform desensitization verification on the front-end content according to the sensitive data characteristics. The response module is also used to respond to a passive detection request and perform desensitization verification on the passive data source based on the sensitive data characteristics; The front-end content includes: displaying a webpage; the active detection request includes: the target browser; The response module is also used to: send an access request to the URL address through the target browser; and obtain the display webpage returned by the server based on the access request.

7. An electronic device, characterized in that, include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the steps of the method as described in any one of claims 1-5.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed on a computer, cause the computer to perform the method as described in any one of claims 1-5.