Data processing apparatus and method based on shadow computing
By using a data processing device based on shadow computing, and through the collaborative work of the shadow system and the data security gateway, the problems of automatic data forwarding and secure approval are solved, and automated data desensitization and efficient utilization are achieved.
Patent Information
- Application Number
- CN202310232762.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-07
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2043-03-07
AI Technical Summary
In existing technologies, data cannot be forwarded automatically and security approval cannot be performed during the forwarding process, resulting in the data not being able to be used efficiently and reasonably and in compliance with regulations.
A data processing device based on shadow computing is used to create logical business themes and data desensitization tasks through the shadow system, and to verify and approve the data through the data security gateway, thereby realizing automated data desensitization and secure approval.
It has achieved automated data anonymization and secure approval, ensuring that data is used efficiently and in a reasonable and compliant manner.
Smart Images

Figure CN116318956B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of big data, and in particular to a data processing device and method based on shadow computing. BACKGROUND
[0002] In today's development of automobile electrification and intelligence, the data volume reported by the vehicle-mounted equipment is getting larger and larger, and the data types are also getting richer. With the development of digitization, the application range of data is getting wider and wider, and with the formulation and implementation of data security regulations, the security of data is constantly restricting the use of data.
[0003] In related technologies, data forwarding is to push the processed data to the downstream in the form of messages or interfaces through a data forwarding platform, that is, the traditional data gateway is to push the data through offline application and customized development.
[0004] However, the entire response cycle of this method is slow, and the online and offline are disconnected, the security of the pushed content cannot be audited and approved, and the data cannot be reasonably and legally used efficiently by the business, which needs to be solved urgently. SUMMARY
[0005] The present application provides a data processing device and method based on shadow computing to solve the problems that data cannot be automatically forwarded and security cannot be approved during data forwarding, so as to realize the automatic desensitization of data and ensure that the data is reasonably and legally used efficiently.
[0006] The first aspect of the present application provides a data processing device based on shadow computing, comprising:
[0007] A shadow system is configured to create a logical business topic and a data desensitization task corresponding to the logical business topic, receive original data through the logical business topic, and perform a desensitization operation on the original data according to the data desensitization task to obtain at least one desensitized data.
[0008] A data security gateway is configured to push the at least one desensitized data to a target consumption system, and to verify and approve a data synchronization application request and a registration request of a data synchronization callback interface fed back by the target consumption system based on the at least one desensitized data, and to create a data synchronization task after verification and approval.
[0009] According to an embodiment of the present application, the shadow system comprises:
[0010] A shadow channel management component, a shadow computing engine and a data channel medium; wherein,
[0011] The shadow channel management component is configured to create the logical business topic and a data desensitization task corresponding to the logical business topic.
[0012] The shadow computing engine is configured to perform a desensitization operation on the original data according to the data desensitization task based on a preset real-time desensitization data processing strategy of the flink, to obtain at least one desensitized data.
[0013] The data channel medium is a data bus based on kafka.
[0014] According to an embodiment of the present application, the shadow system comprises:
[0015] The first security component is configured to generate a corresponding data security strategy according to a current data security requirement, so that the shadow computing engine performs a desensitization operation on the original data packet according to the data desensitization task based on the data security strategy.
[0016] According to an embodiment of the present application, the logical business topic comprises an inbound topic and an outbound topic, wherein,
[0017] The inbound topic is configured to receive the original data, and the outbound topic is configured to output the desensitized data.
[0018] According to an embodiment of the present application, the data security gateway comprises:
[0019] The second security component is configured to generate a corresponding synchronization security strategy according to a current synchronization requirement.
[0020] The data synchronization task management module is configured to receive the at least one desensitized data, and synchronize the at least one desensitized data based on the synchronization security strategy and then send to a target consumer.
[0021] The gateway service platform is configured to receive a data synchronization application request and a registration request of a data synchronization callback interface sent by the target consumer based on the received at least one desensitized data.
[0022] The data synchronization task data approval system is configured to verify and approve the data synchronization application request and the registration request of the data synchronization callback interface received by the gateway service platform, and after the verification and approval is completed, send an approval pass information to the gateway service platform, so as to create a data synchronization task through the gateway service platform and push a synchronization information to the data synchronization task management module.
[0023] According to the data processing device based on shadow computing provided in the embodiments of the present application, a logical business topic and a data desensitization task corresponding to the topic are created by a shadow system, original data is received through the logical business topic, and desensitization is performed on the original data according to the data desensitization task, to obtain at least one desensitized data; the at least one desensitized data is pushed to a target consumption system through a data security gateway, a data synchronization application request and a registration request of a data synchronization callback interface fed back by the target consumption system based on the at least one desensitized data are received and verified and approved, and a data synchronization task is created after the verification and approval. In this way, the problems that data cannot be automatically forwarded and security approval cannot be performed in the data forwarding process are solved, automatic desensitization of data is implemented, and data is reasonably and compliantly used efficiently.
[0024] The second aspect of the embodiments of the present application provides a data processing method based on shadow computing, which adopts the data processing device based on shadow computing of the first aspect of the embodiments, and the method comprises the following steps:
[0025] A logical business topic and a data desensitization task corresponding to the logical business topic are created by the shadow system, and original data is received through the logical business topic, and desensitization is performed on the original data according to the data desensitization task, to obtain at least one desensitized data;
[0026] The at least one desensitized data is pushed to a target consumption system through the data security gateway, a data synchronization application request and a registration request of a data synchronization callback interface fed back by the target consumption system based on the at least one desensitized data are received and verified and approved, and a data synchronization task is created after the verification and approval.
[0027] According to one embodiment of the present application, the logical business topic and the data desensitization task corresponding to the logical business topic are created by the shadow system, and the original data is received through the logical business topic, and desensitization is performed on the original data according to the data desensitization task, to obtain at least one desensitized data, which comprises:
[0028] The logical business topic and the data desensitization task corresponding to the logical business topic are created by a shadow channel management component;
[0029] Desensitization is performed on the original data according to the data desensitization task based on a preset real-time desensitization data processing strategy of flink through a shadow computing engine, to obtain at least one desensitized data.
[0030] According to one embodiment of the present application, desensitization is performed on the original data according to the data desensitization task, to obtain at least one desensitized data, which further comprises:
[0031] The first security component generates a corresponding data security policy according to a current data security requirement, so that the shadow computing engine performs a desensitization operation on the original data message according to the data desensitization task based on the data security policy.
[0032] According to an embodiment of the present application, the logical business topic includes an inbound topic and an outbound topic, wherein,
[0033] The inbound topic is used to receive the original data, and the outbound topic is used to output the desensitized data.
[0034] According to an embodiment of the present application, the at least one desensitized data is pushed to a target consumer system through the data security gateway, and a data synchronization application request and a registration request of a data synchronization callback interface fed back by the target consumer system based on the at least one desensitized data are received for verification and approval, and after verification and approval, a data synchronization task is created, including:
[0035] A second security component generates a corresponding synchronization security policy according to a current synchronization requirement;
[0036] A data synchronization task management module receives the at least one desensitized data, and sends the at least one desensitized data to a target consumer after synchronizing the at least one desensitized data based on the synchronization security policy;
[0037] A gateway service platform receives the data synchronization application request and the registration request of the data synchronization callback interface sent by the target consumer based on the received at least one desensitized data;
[0038] A data synchronization task data approval system verifies and approves the data synchronization application request and the registration request of the data synchronization callback interface received by the gateway service platform, and after verification and approval is completed, sends approval information to the gateway service platform, so as to create a data synchronization task through the gateway service platform and push synchronization information to the data synchronization task management module.
[0039] According to the data processing method based on shadow computing provided by the embodiment of the application, a logical business theme and a data desensitization task corresponding to the logical business theme are created through a shadow system, and the shadow system receives original data through the logical business theme, and performs a desensitization operation on the original data according to the data desensitization task, to obtain at least one desensitized data; the at least one desensitized data is pushed to a target consumption system through a data security gateway, and a data synchronization application request and a registration request of a data synchronization callback interface that are fed back by the target consumption system based on the at least one desensitized data are received and verified and approved, and after the verification and approval, a data synchronization task is created. Therefore, the problems that data cannot be automatically forwarded and security approval cannot be performed in the data forwarding process are solved, automatic desensitization of data is realized, and data is reasonably and compliantly used efficiently.
[0040] Additional aspects and advantages of the application will be set forth in part in the description which follows, and in part will become apparent to those skilled in the art upon examination of the following and / or can be learned by practice of the application. BRIEF DESCRIPTION OF DRAWINGS
[0041] The above and / or additional aspects and advantages of the application will become apparent and be readily appreciated from the following description, taken in conjunction with the accompanying drawings, in which:
[0042] Figure 1 A block schematic diagram of a data processing apparatus based on shadow computing according to an embodiment of the application is provided;
[0043] Figure 2 A schematic diagram of the overall device composition architecture according to an embodiment of the application is provided;
[0044] Figure 3 A schematic diagram of the architecture of a shadow system according to an embodiment of the application is provided;
[0045] Figure 4 A schematic diagram of the architecture of a data security gateway according to an embodiment of the application is provided;
[0046] Figure 5 A flowchart of a data processing method based on shadow computing according to an embodiment of the application is provided. DETAILED DESCRIPTION
[0047] The embodiments of the application are described in detail below, and examples of the embodiments are shown in the accompanying drawings, in which the same or similar reference signs represent the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by reference to the accompanying drawings are exemplary and are intended to explain the application, and cannot be understood as limiting the application.
[0048] The data processing device and method based on shadow computing according to the embodiments of the present application are described below with reference to the accompanying drawings. In view of the problems of the data unable to be automatically forwarded and the security approval unable to be performed during the data forwarding process mentioned in the background, the present application provides a data processing device based on shadow computing. The shadow system creates a logical business topic and a data desensitization task corresponding to the logical business topic, receives original data through the logical business topic, and performs desensitization operation on the original data according to the data desensitization task to obtain at least one desensitized data. The data security gateway pushes the at least one desensitized data to a target consumption system, receives a data synchronization application request and a registration request of a data synchronization callback interface based on the at least one desensitized data feedback by the target consumption system and performs verification and approval, and after the verification and approval, creates a data synchronization task. Thus, the problems of the data unable to be automatically forwarded and the security approval unable to be performed during the data forwarding process are solved, the automatic desensitization of the data is realized, and the data is reasonably and compliantly used efficiently.
[0049] Specifically, Figure 1 A block schematic diagram of the data processing device based on shadow computing provided by the embodiments of the present application is shown.
[0050] As Figure 1 shown, the data processing device based on shadow computing 10 includes a shadow system 100 and a data security gateway 200.
[0051] The shadow system 100 is configured to create a logical business topic and a data desensitization task corresponding to the logical business topic, receive original data through the logical business topic, and perform desensitization operation on the original data according to the data desensitization task to obtain at least one desensitized data. The data security gateway 200 is configured to push the at least one desensitized data to a target consumption system, receive a data synchronization application request and a registration request of a data synchronization callback interface based on the at least one desensitized data feedback by the target consumption system and perform verification and approval, and after the verification and approval, create a data synchronization task.
[0052] Specifically, as Figure 2 shown, Figure 2 a schematic diagram of the overall device composition architecture according to one embodiment of the present application is shown. A user can create a data channel based on a kafka topic through the device, create an accompanying desensitization task based on the channel, and perform data desensitization task calculation. According to the request feedback by a downstream target consumption system, a data governance team can perform data verification and approval through the device, and after the data request is passed, automatically create a data synchronization service.
[0053] Further, in some embodiments, the shadow system 100 comprises a shadow channel management component, a shadow computing engine, a data channel medium, and a first security component. Among them, the shadow channel management component is used to create a logical business topic and a data desensitization task corresponding to the logical business topic; the shadow computing engine is used to perform desensitization operation on the original data according to the data desensitization task based on a preset real-time desensitization data processing strategy of flink, to obtain at least one desensitized data; the data channel medium is a data bus based on kafka; and the first security component is used to generate a corresponding data security strategy according to the current data security requirement, so that the shadow computing engine performs desensitization operation on the original data packet according to the data desensitization task based on the data security strategy.
[0054] Among them, in some embodiments, the logical business topic comprises an inbound topic and an outbound topic, wherein the inbound topic is used to receive original data, and the outbound topic is used to output desensitized data.
[0055] Specifically, as shown in Figure 3 , the shadow channel management component (i.e. the shadow channel management system) can construct a topic topic based on kafka middleware, and create a channel topicA (i.e. a logical business topic) through the system, wherein the logical business topic comprises an inbound topic (e.g. inboud_topicA of Figure 3 ) and an outbound topic (e.g. outbound_topicA of Figure 3 ), which can be used to receive original data (i.e. upstream original message data) and output desensitized data respectively, in addition, the creation of the logical business topic topicA can also create a data desensitization task (e.g. topicA_dataMasking of Figure 3 ); the shadow computing engine is a set of real-time desensitization data processing engine based on flink, which is preset with a desensitization data processing strategy, can receive and implement the execution, monitoring and destruction of the desensitization task created by the system, therefore, topicA_dataMasking can receive the data of inboud_topicA, and push the desensitized data to outbound_topicA through the shadow computing engine based on the preset desensitization data processing strategy, so as to realize the desensitization operation of data from inboud_topicA to outbound_topicA; the first security component (e.g. security_component of Figure 3The data security personnel can complete the definition of the desensitization rule of the sensitive attribute through the component, that is, the user can set the data security policy as needed, and the real-time desensitization operation and data forwarding processing can be performed through the policy. When the topicA_dataMasking is started, the data security policy can be synchronized, and the data security policy is applied to the data desensitization process from the inboud_topicA to the outbound_topicA, so that the real-time desensitized data including the original data message rawData and the desensitized data message secData is pushed into the shadow channel of the outbound_topicA.
[0056] Further, in some embodiments, the data security gateway 200 comprises a second security component, a data synchronization task management module, a network management service platform and a data synchronization task data approval system. The second security component is configured to generate a corresponding synchronization security policy according to the current synchronization requirement; the data synchronization task management module is configured to receive at least one desensitized data and send the at least one desensitized data to a target consumer after synchronization based on the synchronization security policy; the gateway service platform is configured to receive a data synchronization application request and a registration request of a data synchronization callback interface sent by the target consumer based on the received at least one desensitized data; and the data synchronization task data approval system is configured to verify and approve the data synchronization application request and the registration request of the data synchronization callback interface received by the gateway service platform, and send an approval pass information to the gateway service platform after the verification and approval is completed, so as to create a data synchronization task and push a synchronization information to the data synchronization task management module through the gateway service platform.
[0057] Specifically, as shown in Figure 4 the second security component (such as Figure 4 the security policy platform) can generate a corresponding synchronization security policy according to the current synchronization requirement; the data synchronization task management module can receive the desensitized data and push the data to the downstream target consumer system (such as Figure 4 the data consumer) according to the synchronization security policy; the network management service platform can receive a data request sent by the target consumer based on the desensitized data, that is, a data synchronization application request and a registration request of a data synchronization callback interface; and the data synchronization task data approval system can verify and approve the data request. After the request is passed (that is, after the verification and approval is completed), the gateway service platform can automatically create a data synchronization task, and the data synchronization task synchronizes the security policy, reassembles the data, and synchronizes the data to the data applicant through the callback interface, that is, pushes the synchronization information to the data synchronization task management module.
[0058] According to the data processing method based on shadow computing provided in the embodiments of the present application, the logical business theme and the data desensitization task corresponding to the logical business theme are created through the shadow system, the original data is received through the logical business theme, and the original data is desensitized according to the data desensitization task to obtain at least one desensitized data; the at least one desensitized data is pushed to the target consumption system through the data security gateway, the data synchronization application request and the registration request of the data synchronization callback interface fed back by the target consumption system based on the at least one desensitized data are received and verified and approved, and after the verification and approval, the data synchronization task is created. Therefore, the problems that data cannot be automatically forwarded and security approval cannot be performed in the data forwarding process are solved, the automatic desensitization of data is realized, and the data is reasonably and compliantly used efficiently.
[0059] Secondly, the data processing method based on shadow computing provided in the embodiments of the present application is described with reference to the accompanying drawings.
[0060] Figure 5 is a flowchart of the data processing method based on shadow computing of the embodiments of the present application. The method uses the data processing device based on shadow computing shown in the embodiments of the present application. Figure 1 The data processing device based on shadow computing shown in the embodiments of the present application.
[0061] As shown in the data processing method based on shadow computing shown in the embodiments of the present application. Figure 5 The data processing method based on shadow computing includes the following steps:
[0062] In step S501, the logical business theme and the data desensitization task corresponding to the logical business theme are created through the shadow system, the original data is received through the logical business theme, and the original data is desensitized according to the data desensitization task to obtain at least one desensitized data.
[0063] Further, in some embodiments, the logical business theme and the data desensitization task corresponding to the logical business theme are created through the shadow system, the original data is received through the logical business theme, and the original data is desensitized according to the data desensitization task to obtain at least one desensitized data, including:
[0064] The logical business theme and the data desensitization task corresponding to the logical business theme are created through the shadow channel management component;
[0065] The original data is desensitized according to the data desensitization task to obtain at least one desensitized data through the shadow computing engine based on the preset real-time desensitization data processing strategy of flink.
[0066] Further, in some embodiments, the original data is desensitized according to the data desensitization task to obtain at least one desensitized data, and the method further includes:
[0067] The first security component generates a corresponding data security policy according to the current data security requirement, so that the shadow computing engine performs a desensitization operation on the original data message according to the data desensitization task based on the data security policy.
[0068] Further, in some embodiments, the logical business topics include inbound topics and outbound topics, wherein,
[0069] The inbound topics are used to receive original data, and the outbound topics are used to output desensitized data.
[0070] In step S502, at least one desensitized data is pushed to the target consumer system through the data security gateway, and a data synchronization application request and a registration request of a data synchronization callback interface based on the at least one desensitized data feedback by the target consumer system are received and verified and approved, and after verification and approval, a data synchronization task is created.
[0071] Further, in some embodiments, at least one desensitized data is pushed to the target consumer system through the data security gateway, and a data synchronization application request and a registration request of a data synchronization callback interface based on the at least one desensitized data feedback by the target consumer system are received and verified and approved, and after verification and approval, a data synchronization task is created, including:
[0072] A corresponding synchronization security policy is generated by the second security component according to the current synchronization requirement;
[0073] The data synchronization task management module receives at least one desensitized data, and after synchronizing the at least one desensitized data based on the synchronization security policy, sends it to the target consumer;
[0074] The gateway service platform receives a data synchronization application request and a registration request of a data synchronization callback interface sent by the target consumer based on the received at least one desensitized data;
[0075] The data synchronization task data approval system verifies and approves the data synchronization application request and the registration request of the data synchronization callback interface received by the gateway service platform, and after verification and approval is completed, sends approval information to the gateway service platform, so as to create a data synchronization task through the gateway service platform and push synchronization information to the data synchronization task management module.
[0076] It should be noted that the foregoing explanation and description of the embodiment of the shadow computing-based data processing device also apply to the shadow computing-based data processing method of the embodiment, which will not be described here.
[0077] According to the data processing method based on shadow computing provided in the embodiments of the present application, a logical business theme and a data desensitization task corresponding to the logical business theme are created through a shadow system, and the original data is received through the logical business theme, and the original data is desensitized according to the data desensitization task, to obtain at least one desensitized data; the at least one desensitized data is pushed to a target consumption system through a data security gateway, and a data synchronization application request and a registration request of a data synchronization callback interface fed back by the target consumption system based on the at least one desensitized data are received and verified and approved, and after the verification and approval, a data synchronization task is created. Therefore, the problems that data cannot be automatically forwarded and security approval cannot be performed in the data forwarding process are solved, automatic desensitization of data is realized, and data is reasonably and compliantly used efficiently.
[0078] In the description of the present specification, the description of the terms "one embodiment", "some embodiments", "an example", "a specific example", or "some examples" and the like means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In the present specification, the illustrative description of the above terms is not necessarily directed to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or N embodiments or examples in a suitable manner. In addition, the person skilled in the art can combine and combine the different embodiments or examples described in the present specification and the features of the different embodiments or examples without contradiction.
[0079] In addition, the terms "first", "second" are only for descriptive purposes, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of indicated technical features. Therefore, the features limited by "first", "second" can explicitly or implicitly include at least one feature. In the description of the present application, the meaning of "N" is at least two, for example, two, three, etc., unless otherwise specifically limited.
[0080] Any process or method descriptions in flow charts or otherwise described herein, represent an example of executable instructions, code, or modules for performing a software and / or hardware operation, and the preferred embodiments of the present application include additional or fewer steps, or combinations of steps, or the same steps in a different order, or with one or more modified items, as long as the functions described are not changed, which should be understood by those skilled in the art of the embodiments of the present application.
[0081] Although the embodiments of the present application have been shown and described above, it is understood that the above-described embodiments are exemplary and are not to be construed as limiting the present application, and that changes, modifications, substitutions and variations can be made by those skilled in the art without departing from the scope of the present application.
Claims
1. A data processing apparatus based on shadow computing, characterized by, The method comprises the following steps: a shadow system is used to create a logical business topic and a data desensitization task corresponding to the logical business topic, receive original data through the logical business topic, and perform a desensitization operation on the original data according to the data desensitization task to obtain at least one desensitized data; a data security gateway is used to push the at least one desensitized data to a target consumer system, receive a data synchronization application request and a registration request of a data synchronization callback interface based on the at least one desensitized data and feedback by the target consumer system, and perform verification and approval, and after the verification and approval, a data synchronization task is created; the shadow system comprises: a shadow channel management component, a shadow computing engine and a data channel medium; wherein the shadow channel management component is used to create the logical business topic and the data desensitization task corresponding to the logical business topic; the shadow computing engine is used to perform a desensitization operation on the original data according to the data desensitization task based on a preset real-time desensitization data processing strategy of flink to obtain at least one desensitized data; the data channel medium is a data bus based on kafka; the logical business topic comprises an inbound topic and an outbound topic, wherein the inbound topic is used to receive the original data, and the outbound topic is used to output the desensitized data.
2. The apparatus of claim 1, wherein, The shadow system comprises: a first security component is used to generate a corresponding data security strategy according to current data security requirements, so that the shadow computing engine performs a desensitization operation on the original data packet according to the data desensitization task based on the data security strategy.
3. The apparatus of claim 1, wherein, The data security gateway comprises: a second security component is used to generate a corresponding synchronization security strategy according to current synchronization requirements; a data synchronization task management module is used to receive the at least one desensitized data, and send the at least one desensitized data to a target consumer after synchronizing the at least one desensitized data based on the synchronization security strategy; a gateway service platform is used to receive the data synchronization application request and the registration request of the data synchronization callback interface sent by the target consumer based on the received at least one desensitized data; a data synchronization task data approval system is used to verify and approve the data synchronization application request and the registration request of the data synchronization callback interface received by the gateway service platform, and after the verification and approval is completed, send an approval passing information to the gateway service platform to create a data synchronization task and push a synchronization information to the data synchronization task management module through the gateway service platform.
4. A data processing method based on shadow computing, characterized in that, The method comprises the following steps: a shadow system is used to create a logical business topic and a data desensitization task corresponding to the logical business topic, receive original data through the logical business topic, and perform a desensitization operation on the original data according to the data desensitization task to obtain at least one desensitized data; The data security gateway pushes the at least one desensitized data to a target consumption system, receives a data synchronization application request and a registration request of a data synchronization callback interface based on the at least one desensitized data feedback of the target consumption system, and performs verification and approval, and after the verification and approval, a data synchronization task is created; The shadow system creates a logical business topic and a data desensitization task corresponding to the logical business topic, receives original data through the logical business topic, and performs desensitization operation on the original data according to the data desensitization task to obtain at least one desensitized data, including: The shadow channel management component creates the logical business topic and the data desensitization task corresponding to the logical business topic; The shadow computing engine is used for performing desensitization operation on the original data according to the data desensitization task based on a preset real-time desensitization data processing strategy of flink to obtain at least one desensitized data; The logical business topic includes an inbound topic and an outbound topic, wherein, The inbound topic is used to receive the original data, and the outbound topic is used to output the desensitized data.
5. The method of claim 4, wherein, The shadow computing engine is used for performing desensitization operation on the original data according to the data desensitization task based on a preset real-time desensitization data processing strategy of flink to obtain at least one desensitized data; The first security component generates a corresponding data security strategy according to the current data security requirement, so that the shadow computing engine performs desensitization operation on the original data packet according to the data desensitization task based on the data security strategy.
6. The method of claim 4, wherein, The data security gateway pushes the at least one desensitized data to a target consumption system, receives a data synchronization application request and a registration request of a data synchronization callback interface based on the at least one desensitized data feedback of the target consumption system, and performs verification and approval, and after the verification and approval, a data synchronization task is created; The second security component generates a corresponding synchronization security strategy according to the current synchronization requirement; The data synchronization task management module receives the at least one desensitized data, and synchronizes the at least one desensitized data based on the synchronization security strategy and then sends to a target consumer; The gateway service platform receives the data synchronization application request and the registration request of the data synchronization callback interface sent by the target consumer based on the received at least one desensitized data; The data synchronization task data approval system performs verification and approval on the data synchronization application request and the registration request of the data synchronization callback interface received by the gateway service platform, and after the verification and approval is completed, sends approval information to the gateway service platform, so that the gateway service platform creates a data synchronization task and pushes synchronization information to the data synchronization task management module.
Citation Information
Patent Citations
Data gateway device and big data system
CN105515963A