Log information output management method and system

By constructing log de-identification strategies and a privacy standard library, and based on the de-identification requirements of terminal devices, it is possible to flexibly configure de-identification strategies in business systems in different countries or regions, solving the problem of unsatisfactory de-identification output effects in existing technologies and improving configuration efficiency.

CN116610650BActive Publication Date: 2025-12-23深圳开鸿数字产业发展有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310453426.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-17
Publication Date
2025-12-23
Estimated Expiration
2043-04-17

AI Technical Summary

Technical Problem

When existing business systems are run in different countries or regions, the requirements for desensitizing privacy information vary from country to country, resulting in unsatisfactory output of existing logs and failing to meet users' flexible configuration needs.

Method used

The device builds a log de-identification policy through policy configuration, the IoT server builds a privacy standard library, and obtains the target log de-identification policy according to the de-identification requirements of the terminal device. The terminal device executes the policy configuration operation and outputs the de-identified log file.

Benefits of technology

It enables flexible configuration of de-identification strategies in business systems in different countries or regions, meeting users' personalized needs and improving the configuration efficiency and effectiveness of log de-identification strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116610650B_ABST
    Figure CN116610650B_ABST
Patent Text Reader

Abstract

The embodiment of the application relates to the technical field of log data management, and specifically provides a log information output management method and system. The method comprises the following steps: a policy configuration device sends a log desensitization policy to an internet-of-things server; the internet-of-things server receives the log desensitization policy, constructs a privacy standard library by using the log desensitization policy, acquires a desensitization demand of a terminal device, acquires a target log desensitization policy from the privacy standard library according to the desensitization demand, and sends the target log desensitization policy to the terminal device; the terminal device executes a policy configuration operation of the target log desensitization policy, and sends configuration feedback information to the internet-of-things server; the internet-of-things server generates configuration response information according to the configuration feedback information, and sends the configuration response information to the policy configuration device, so that the policy configuration device outputs a configuration prompt; the terminal device receives a log output request, desensitizes a target log file corresponding to the log output request according to the target log desensitization policy, and outputs a desensitized log file, thereby realizing flexible configuration of the log desensitization policy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of log data management technology, and in particular to a log information output management method and system. Background Technology

[0002] When maintaining existing business systems, it's common practice to print system logs for better understanding and troubleshooting. However, for systems containing sensitive information, it's crucial to protect users' personal data, such as ID card information, names, mobile phone numbers, bank card numbers, and residential addresses. Directly outputting this information in system logs could lead to the leakage of users' personal privacy.

[0003] When maintaining existing business systems, user privacy information is usually anonymized before log output. Although this solves the problem of privacy information leakage, the current log anonymization output effect is not ideal because different countries or regions have different requirements for privacy information anonymization, or different customers have different needs for log printing output. Summary of the Invention

[0004] The main objective of this application is to provide a log information output management method that aims to protect user privacy while flexibly configuring desensitization strategies to meet different user needs and improve the flexibility and efficiency of desensitization strategy configuration.

[0005] In a first aspect, embodiments of this application provide a log information output management method, applied to a log output management system, the log output management system including a policy configuration device, an IoT server, and terminal devices, the IoT server being communicatively connected to the policy configuration device and the terminal devices, the method including:

[0006] The policy configuration device receives a de-identification policy configuration instruction, constructs a log de-identification policy in response to the de-identification policy configuration instruction, and sends the constructed log de-identification policy to the IoT server.

[0007] The IoT server receives the log de-identification policy sent by the policy configuration device to build a privacy standard library using the log de-identification policy. When the IoT server receives the terminal device deployment completion instruction, it obtains the de-identification requirements adapted to the terminal device according to the deployment completion instruction, obtains the target log de-identification policy adapted to the de-identification requirements from the privacy standard library according to the de-identification requirements, and sends the target log de-identification policy to the terminal device.

[0008] After receiving the target log de-identification policy, the terminal device executes the policy configuration operation of the target log de-identification policy, and sends configuration feedback information to the IoT server after the policy configuration operation is completed.

[0009] The IoT server receives the configuration feedback information, generates configuration response information based on the configuration feedback information, and sends it to the policy configuration device so that the policy configuration device outputs the corresponding configuration prompt.

[0010] When the terminal device receives a log output request, it responds to the log output request by performing desensitization processing on the target log file corresponding to the log output request according to the target log desensitization policy, and outputs the desensitized log file.

[0011] Secondly, embodiments of this application also provide a log output management system, which includes a policy configuration device, an IoT server, and terminal devices. The IoT server is communicatively connected to the policy configuration device and the terminal devices, and includes:

[0012] The policy configuration device receives a de-identification policy configuration instruction, constructs a log de-identification policy in response to the de-identification policy configuration instruction, and sends the constructed log de-identification policy to the IoT server.

[0013] The IoT server receives the log de-identification policy sent by the policy configuration device to build a privacy standard library using the log de-identification policy. When the IoT server receives the terminal device deployment completion instruction, it obtains the de-identification requirements adapted to the terminal device according to the deployment completion instruction, obtains the target log de-identification policy adapted to the de-identification requirements from the privacy standard library according to the de-identification requirements, and sends the target log de-identification policy to the terminal device.

[0014] After receiving the target log de-identification policy, the terminal device executes the policy configuration operation of the target log de-identification policy, and sends configuration feedback information to the IoT server after the policy configuration operation is completed.

[0015] The IoT server receives the configuration feedback information, generates configuration response information based on the configuration feedback information, and sends it to the policy configuration device so that the policy configuration device outputs the corresponding configuration prompt.

[0016] When the terminal device receives a log output request, it responds to the log output request by performing desensitization processing on the target log file corresponding to the log output request according to the target log desensitization policy, and outputs the desensitized log file.

[0017] This application provides a log information output management method and system. The log information output management method includes a policy configuration device receiving a de-identification policy configuration instruction, constructing a log de-identification policy in response to the instruction, and then sending the log de-identification policy to an IoT server. After receiving the log de-identification policy from the policy configuration device, the IoT server constructs a privacy standard library based on the log de-identification policy. Then, when the IoT server receives a terminal device deployment completion instruction, it can obtain de-identification requirements adapted to the terminal device based on the deployment completion instruction, thereby enabling the IoT server to obtain de-identification requirements adapted to the privacy standard library. The system defines a target log anonymization strategy and sends this strategy to the terminal device. Upon receiving the target log anonymization strategy, the terminal device executes the strategy configuration operation and sends configuration feedback information to the IoT server after completion. The IoT server receives the configuration feedback information, generates a configuration response based on it, and sends it to the strategy configuration device, prompting the device to output the corresponding configuration message. When the terminal device receives a log output request, it responds by anonymizing the target log file according to the target log anonymization strategy and outputs the anonymized log file. This allows the IoT server to obtain a target log anonymization strategy adapted to the terminal device's anonymization needs, enabling the terminal device to perform anonymization processing accordingly. This satisfies user anonymization requirements while also allowing for flexible configuration of the terminal device's log anonymization strategy, thus improving the efficiency of log anonymization strategy configuration. Attached Figure Description

[0018] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0019] Figure 1 This application provides a block diagram of a log output management system as an embodiment of the present application.

[0020] Figure 2 A flowchart illustrating the steps of a log information output management method provided in this application embodiment;

[0021] Figure 3 for Figure 2 A flowchart of one specific implementation of step S2;

[0022] Figure 4 for Figure 2A flowchart of one specific implementation of step S5;

[0023] Figure 5 This is a flowchart illustrating the de-identification process of a target log file provided in a log information output management method according to an embodiment of this application. Detailed Implementation

[0024] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0025] The flowchart shown in the attached diagram is for illustrative purposes only and does not necessarily include all content and operations / steps, nor does it necessarily have to be performed in the order described. For example, some operations / steps can be broken down, combined, or partially merged, so the actual execution order may change depending on the actual situation.

[0026] It should be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the scope of the application. As used in this specification and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms unless the context clearly indicates otherwise.

[0027] This application provides a log information output management method and system. The log information output management method includes a policy configuration device receiving a de-identification policy configuration instruction, constructing a log de-identification policy in response to the instruction, and then sending the log de-identification policy to an IoT server. After receiving the log de-identification policy from the policy configuration device, the IoT server constructs a privacy standard library based on the log de-identification policy. Then, when the IoT server receives a terminal device deployment completion instruction, it can obtain de-identification requirements adapted to the terminal device based on the deployment completion instruction, thereby enabling the IoT server to obtain de-identification requirements adapted to the privacy standard library. The system defines a target log anonymization strategy and sends this strategy to the terminal device. Upon receiving the target log anonymization strategy, the terminal device executes the strategy configuration operation and sends configuration feedback information to the IoT server after completion. The IoT server receives the configuration feedback information, generates a configuration response based on it, and sends it to the strategy configuration device, prompting the device to output the corresponding configuration message. When the terminal device receives a log output request, it responds by anonymizing the target log file according to the target log anonymization strategy and outputs the anonymized log file. This allows the IoT server to obtain a target log anonymization strategy adapted to the terminal device's anonymization needs, enabling the terminal device to perform anonymization processing accordingly. This satisfies user anonymization requirements while also allowing for flexible configuration of the terminal device's log anonymization strategy, thus improving the efficiency of log anonymization strategy configuration.

[0028] The following detailed description of some embodiments of this application is provided in conjunction with the accompanying drawings. Unless otherwise specified, the following embodiments and features can be combined with each other.

[0029] Please refer to Figure 1 , Figure 1 This is a block diagram of a log output management system provided in an embodiment of this application.

[0030] like Figure 1 As shown, the log output management system 100 provided by this invention includes a policy configuration device 10, an IoT server 20, and a terminal device 30. The policy configuration device 10 can be a mobile terminal, including but not limited to mobile phones, tablets, laptops, or smart wearable devices. The IoT server 20 can be a terminal device, which can be a server or a cloud platform; the server can be a standalone server or a server cluster. The terminal device 30 can be a mobile phone, tablet, laptop, desktop computer, personal digital assistant, wearable device, or server; the server can be a standalone server or a server cluster.

[0031] The user operates the policy configuration device 10, which receives the de-identification policy configuration instruction based on the user's operation. The device then constructs a log de-identification policy based on this instruction and sends it to the IoT server 20. Upon receiving the log de-identification policy, the IoT server 20 establishes a privacy standard library based on it. When the IoT server 20 receives the terminal device 30's deployment completion instruction, it determines a target log de-identification policy from the privacy standard library that matches the terminal device 30's de-identification requirements. This target log de-identification policy is then sent to the terminal device 30, enabling it to perform policy configuration operations and thus achieve log de-identification. After the terminal device 30 completes the policy configuration operation according to the target log de-identification policy, the terminal device 30 sends feedback information to the IoT server 20. After receiving the feedback information, the IoT server 20 generates configuration response information and sends the configuration response information to the policy configuration device 10. The policy configuration device 10 generates corresponding prompt information according to the configuration response information, so that the user can obtain the configuration effect of the terminal device 30 according to the target log de-identification policy based on the prompt information.

[0032] For example, a user configures device 10 through an operation policy, generating three log anonymization policies C1, C2, and C3, applicable to countries A, B, and C respectively. The IoT server 20 then establishes a privacy standard library based on these policies and their applicability to countries A, B, and C. At this time, terminal device 30 is deployed in country A. After completing its production deployment in country A, terminal device 30 sends an anonymization request to the IoT server 20. The IoT server 20, based on the terminal device 30's production deployment in country A, determines the target log anonymization policy C1 corresponding to terminal device 30. After the IoT server 20 sends the target log anonymization policy C1 to terminal device 30, terminal device 30 performs policy configuration operations according to the target log anonymization policy C1. This ensures that when terminal device 30 receives an anonymization request, it anonymizes the target log file in the request according to the target log anonymization policy C1 and outputs the anonymized log file. When terminal device 30 completes the policy configuration operation according to the target log de-identification policy C1, it successfully completes the policy configuration operation corresponding to the target log de-identification policy C1 and sends feedback information to IoT server 20. IoT server 20 then generates configuration response information based on the feedback information and sends it to policy configuration device 10. Policy configuration device 10 generates corresponding prompt information based on the configuration response information, such as "Terminal device 30 deployed in country A has successfully configured log de-identification policy C1." Alternatively, if terminal device 30 fails to successfully complete the policy configuration operation corresponding to the target log de-identification policy C1, it will also send feedback information to IoT server 20. IoT server 20 will generate configuration response information based on the feedback information and send it to policy configuration device 10. Policy configuration device 10 generates corresponding prompt information based on the configuration response information, such as "Terminal device 30 deployed in country A has failed to configure log de-identification policy C1, the reason is...".

[0033] Please see Figure 2 , Figure 2 This application provides a log information output management method.

[0034] like Figure 2 As shown, the log information output management method is applied to the aforementioned log output management system 100, and the log information output management method includes steps S1 to S5.

[0035] Step S1: The policy configuration device 10 receives the de-identification policy configuration instruction, and responds to the de-identification policy configuration instruction to build a log de-identification policy, and sends the completed log de-identification policy to the IoT server 20.

[0036] For example, a user sets rules for de-identification policy configuration in the policy configuration device 10. After the user completes the rule settings for de-identification policy configuration in the policy configuration device 10, the policy configuration device 10 receives a de-identification policy configuration instruction. The policy configuration device 10 constructs a log de-identification policy according to the de-identification policy configuration instruction and sends the constructed log de-identification policy to the IoT server 20.

[0037] For example, the policy configuration device 10 includes a display and templates for de-identification policy configuration. Different templates require different de-identification policies. Users can select a suitable de-identification policy configuration template according to their needs on the display of the policy configuration device 10. Then, users fill in the policy information according to the template. After completing the template policy information, the user clicks the "OK" button on the display of the policy configuration device 10. The policy configuration device 10 then receives a de-identification policy configuration instruction, which includes the de-identification policy configuration template and the relevant content filled in by the user within the template. The policy configuration device 10 performs data structuring based on the de-identification policy configuration template and the relevant content filled in by the user to obtain the log de-identification policy.

[0038] Optionally, the desensitization strategy configuration template can be customized according to desensitization requirements.

[0039] In some implementations, constructing a log de-identification policy in response to a de-identification policy configuration instruction includes: the policy configuration device 10 determining the privacy data de-identification level and the privacy de-identification method corresponding to the de-identification policy configuration instruction based on the de-identification policy configuration instruction; and the policy configuration device 10 determining the log de-identification policy based on the privacy data de-identification level and the privacy de-identification method.

[0040] For example, when a user configures a desensitization policy on the policy configuration device 10, the content of the file to be desensitized in the terminal device 30 is divided according to the privacy risk level to obtain the privacy data desensitization level. Different privacy data desensitization levels correspond to different privacy desensitization methods, thereby enabling the content of the file to be desensitized in the terminal device 30 to be desensitized more flexibly according to the needs.

[0041] For example, during operation, terminal device 30 needs to print logs for maintenance and data analysis. Some logs are simply for resolving operational issues and do not involve user privacy; therefore, the privacy data anonymization level can be set to level 1, with the corresponding anonymization method being direct display without anonymization. However, some logs are for collecting user preferences, which involves user privacy, such as ID numbers, phone numbers, and Taobao accounts. Directly displaying such logs would leak user privacy; therefore, the privacy data anonymization level can be set to level 2, with the corresponding anonymization method being garbled display. Garbled display can be achieved by setting random numbers to generate strings, which then replace the user's privacy information with these strings for display. For example, if the log information is "User A, Name Zhang San, ID number 12345678910", and the random number generates the string uh**ig, OIUYG-THJF, then the de-identified log information will be "User A, Name uh**ig, ID number OIUYG-THJF".

[0042] For example, the policy configuration device 10 can classify privacy data anonymization levels based on text classification. Log information is divided into corresponding privacy data anonymization level categories, such as Level 1, Level 2, and Level 3, according to a text classification model. Training data for Levels 1, 2, and 3 is collected respectively. The text classification model is trained based on the training data. Then, when the terminal device 30 receives an anonymization request, it classifies the target anonymized file according to the text classification model to obtain a text classification category, and then performs anonymization processing on the target anonymized file according to the privacy anonymization method corresponding to the text classification category.

[0043] In some implementations, the policy configuration device 10 determines the log de-identification policy based on the privacy data de-identification level and the privacy de-identification method, including: the policy configuration device 10 obtaining the first keyword corresponding to the privacy data de-identification level; the policy configuration device 10 establishing a privacy mapping table based on the first keyword and the privacy data de-identification level; and the policy configuration device 10 determining the log de-identification policy based on the privacy mapping table and the privacy de-identification method.

[0044] For example, the policy configuration device 10 obtains the privacy data desensitization level and the first keyword corresponding to the privacy data desensitization level according to the desensitization policy configuration instruction. The policy configuration device 10 establishes a privacy mapping table based on the first keyword and the privacy data desensitization level. That is, when the first keyword is detected in the log information to be desensitized, the privacy data desensitization level corresponding to the log information to be desensitized can be obtained according to the first keyword and the privacy mapping table, and then the log desensitization policy can be determined according to the privacy desensitization method corresponding to the privacy data desensitization level.

[0045] For example, the policy configuration device 10 obtains privacy data anonymization levels including: non-sensitive information, sensitive information, moderately sensitive information, and private information, corresponding to the keywords Public, Protect, Sensitive, and Private, respectively. The privacy anonymization methods for non-sensitive information, sensitive information, moderately sensitive information, and private information are no anonymization, partial fuzzy anonymization, fuzzy anonymization, and password anonymization, respectively. Therefore, a privacy mapping table can be suggested based on the privacy data anonymization levels of non-sensitive information, sensitive information, moderately sensitive information, and private information, and their corresponding keywords Public, Protect, Sensitive, and Private. Then, the corresponding privacy data anonymization level can be determined based on the keywords, and the privacy anonymization method can be determined based on the privacy data anonymization level.

[0046] In addition, the keyword "Automatic" can be set. When the same information to be de-identified is de-identified in different regions, the information to be de-identified corresponding to "Automatic" can be de-identified according to the privacy data de-identification level set in the log de-identification strategy, based on the regional requirements.

[0047] For example, the privacy data anonymization level corresponding to the keyword "Public" is non-sensitive information, in which case the information to be anonymized can be displayed directly in plaintext. The privacy data anonymization level corresponding to the keyword "Protect" is sensitive information, in which case the privacy anonymization method is partial fuzzy anonymization, for example, the user's name "Zhang Sanfeng" will be displayed as "Zhang*Feng" after partial fuzzy anonymization. The privacy data anonymization level corresponding to the keyword "Sensitive" is relatively sensitive information, in which case the privacy anonymization method is fuzzy anonymization, replacing characters with asterisks (*), for example, the user's ID card number "123456789" will be displayed as "*********" after fuzzy anonymization. The privacy data anonymization level corresponding to the keyword "Private" is confidential information, in which case the privacy anonymization method is password anonymization, that is, the information to be anonymized is encrypted before display. The privacy data anonymization level corresponding to the keyword "Automatic" is the privacy data anonymization level set according to the log anonymization strategy. For example, consider two log anonymization strategies, A and B. In strategy A, the keyword "Automatic" corresponds to sensitive information, and the encryption method is fuzzy anonymization. In strategy B, the keyword "Automatic" corresponds to relatively sensitive information, and the encryption method is password anonymization. Therefore, in strategy A, the keyword "Automatic" corresponds to sensitive information, and the encryption method is fuzzy anonymization; in strategy B, the keyword "Automatic" corresponds to relatively sensitive information, and the encryption method is password anonymization.

[0048] In some implementations, privacy desensitization methods include fuzzy desensitization and encrypted desensitization. Fuzzy desensitization is used to replace characters in the data to be desensitized, thereby achieving data desensitization. Encrypted desensitization is used to encrypt the data to be desensitized, thereby achieving data desensitization.

[0049] For example, when performing data anonymization on data to be anonymized, if the data only needs to protect user privacy from leakage, a fuzzy anonymization method can be used, which involves replacing characters in the data to achieve data anonymization. If the data not only protects user privacy from leakage, but also allows developers to analyze user behavior based on user activity data to provide better services, then an encrypted anonymization method can be used.

[0050] For example, using RSA asymmetric encryption, developers generate public and private keys internally and use the public key for encryption. The private key is delivered with the product and kept by the customer. This means that only the customer has the ability to decrypt the encrypted data in the logs. This protects user privacy while also allowing analysis of user behavior data to provide better services to users.

[0051] Step S2: The IoT server 20 receives the log de-identification policy sent by the policy configuration device 10, and uses the log de-identification policy to build a privacy standard library. When the IoT server 20 receives the deployment completion instruction from the terminal device 30, it obtains the de-identification requirements adapted to the terminal device 30 according to the deployment completion instruction, and obtains the target log de-identification policy adapted to the de-identification requirements from the privacy standard library according to the de-identification requirements, and sends the target log de-identification policy to the terminal device 30.

[0052] For example, the IoT server 20 receives the log de-identification policy sent by the policy configuration device 10 and then builds a privacy standard library based on the log de-identification policy, so as to obtain a matching target log de-identification policy according to different de-identification requirements in the terminal device 30.

[0053] For example, after the terminal device 30 is developed, it may be deployed in different regions. The desensitization requirements for the desensitized data are different in different regions. After the terminal device 30 is deployed, it sends the deployment region information to the IoT server 20 to obtain the target log desensitization strategy of the terminal device 30 under the region information.

[0054] Alternatively, the terminal device 30 may include multiple device types, each with a different log de-identification strategy. Therefore, after the terminal device 30 is deployed, the device type information of the terminal device 30 is sent to the IoT server 20 to obtain the target log de-identification strategy of the terminal device 30 under the device type information.

[0055] Please refer to Figure 3 In some implementations, the IoT server 20 receives the log de-identification policy sent by the policy configuration device 10 to build a privacy standard library using the log de-identification policy. Step S2 includes steps S21 to S22.

[0056] Step S21: After receiving the log de-identification policy sent by the policy configuration device 10, the IoT server 20 obtains the environmental requirements for log de-identification, which at least include de-identification requirements.

[0057] Step S22: The IoT server 20 constructs a privacy standard library based on the log anonymization strategy and environmental requirements.

[0058] For example, the log anonymization strategy is used to characterize the log anonymization rules used in the data to be anonymized in the terminal device 30. When obtaining the log anonymization strategy, the IoT server 20 obtains the environmental requirements required for the log anonymization strategy to be applied to the terminal device 30. These environmental requirements include at least anonymization needs, such as the deployment area information of the terminal device 30, the device model information of the terminal device 30, and the privacy level requirements of the terminal device 30. Then, the IoT server 20 constructs a privacy standard library based on the log anonymization strategy and environmental requirements to support the terminal device 30 in subsequently obtaining a log anonymization strategy matching its own anonymization needs from the privacy standard library.

[0059] For example, taking regional information as an example, country A prohibits printing / disclosing the MAC address of terminal device 30, country B allows fuzzy printing of the MAC address, such as 00-FF-0C-DA-07-19, or 00-***-19, and country C allows printing the entire MAC address. Therefore, a privacy standard library can be constructed by matching the log anonymization policy of terminal device 30 with the regional information. For example, the privacy standard library includes the following: Terminal device 30 - Country A - Log anonymization policy A, Terminal device 30 - Country B - Log anonymization policy B.

[0060] In some implementations, a target log de-identification strategy that matches the de-identification requirement is obtained from a privacy standard library based on the de-identification requirement. This includes: the IoT server 20 determining the requirement keywords corresponding to the de-identification requirement based on the de-identification requirement; and the IoT server 20 selecting target log de-identification strategies that match the de-identification requirement from the privacy standard library based on the requirement keywords.

[0061] For example, the IoT server 20 obtains the corresponding requirement keywords for the relevant fields from the protocol, and then selects the target log de-identification strategy that matches the requirement keywords based on the environmental requirements of the requirement keywords in the privacy standard library.

[0062] For example, according to the protocol defined in the de-identification requirements between IoT server 20 and terminal device 30, when the de-identification requirement style is {"country":"Japan", "style":"wristband device"}, it indicates a wristband device deployed in Japan. The requirement keywords are deployment region: Japan, device type: wristband device. Then, based on the deployment region: Japan, device type: wristband device, the appropriate target log de-identification strategy is selected from the environmental requirements.

[0063] Step S3: After receiving the target log desensitization policy, the terminal device 30 executes the policy configuration operation of the target log desensitization policy, and sends configuration feedback information to the IoT server 20 after the policy configuration operation is completed.

[0064] For example, when the terminal device 30 receives the target log de-identification policy, it can restart the terminal device 30, thereby enabling the terminal device 30 to perform data de-identification according to the target log de-identification policy. After the terminal device 30 restarts, it sends configuration feedback information to the IoT server 20.

[0065] Optionally, the policy configuration operation can be a restart operation or a call to the corresponding interface to complete the configuration of the target log de-identification policy in the terminal device 30. There are no specific restrictions on the specific policy configuration operation; it can be set according to requirements.

[0066] Step S4: The IoT server 20 receives the configuration feedback information, generates configuration response information based on the configuration feedback information, and sends it to the policy configuration device 10 so that the policy configuration device 10 outputs the corresponding configuration prompt.

[0067] For example, after receiving the configuration feedback information, the IoT server 20 generates configuration response information corresponding to the configuration feedback information and then sends the configuration response information to the policy configuration device 10 so that the policy configuration device 10 outputs the corresponding configuration prompt.

[0068] For example, when terminal device 30 receives the target log de-identification policy, it restarts terminal device 30 and successfully configures the target log de-identification policy, thereby generating a configuration success feedback message. Then, after receiving the configuration feedback message, IoT server 20 generates a configuration response message "Terminal device 30 successfully configured the target log de-identification policy" and sends it to policy configuration device 10. Policy configuration device 10 can generate a configuration prompt based on the configuration response message "Terminal device 30 successfully configured the target log de-identification policy". The configuration prompt can be a voice prompt, a dialog box prompt, etc., thereby reminding the user of the current status of the target log de-identification policy configuration of terminal device 30.

[0069] In some implementations, the method further includes: when the terminal device 30 fails to perform policy configuration operation according to the target log desensitization policy, the policy configuration device 10 determines the reason for the policy configuration failure of the terminal device 30 according to the configuration response information; the policy configuration device 10 corrects the target log desensitization policy according to the reason for the policy configuration failure, and reissues the desensitization policy configuration instruction until the target log desensitization policy corresponding to the terminal device 30 is set.

[0070] For example, when terminal device 30 receives the target log desensitization policy, if restarting terminal device 30 fails or applying the target log desensitization policy fails, configuration failure feedback information can be generated to indicate the reason for the configuration failure. Upon receiving this feedback, IoT server 20 generates a configuration response message, "Terminal device 30 failed to configure the target log desensitization policy, reason: ***," and sends it to policy configuration device 10. Policy configuration device 10 can generate a configuration prompt based on this response message. This prompt could be a warning, an audible warning, etc., reminding the user that the current terminal device 30's target log desensitization policy configuration has failed and needs to be resolved based on the reason for the failure. This allows policy configuration device 10 to correct the target log desensitization policy based on the reason for the failure and reissue the desensitization policy configuration command until the target log desensitization policy for terminal device 30 is successfully set.

[0071] Step S5: When the terminal device 30 receives a log output request, it responds to the log output request by performing desensitization processing on the target log file corresponding to the log output request according to the target log desensitization policy, and outputs the desensitized log file.

[0072] For example, when the terminal device 30 receives a log output request, it determines the target log file corresponding to the log output request, and then performs desensitization processing on the target log file according to the target log desensitization strategy, and outputs the desensitized log file.

[0073] Please refer to Figure 4 In some implementations, when the terminal device 30 receives a log output request, it responds to the log output request by performing desensitization processing on the target log file corresponding to the log output request according to the target log desensitization strategy, and outputs the desensitized log file. Step S5 includes steps S51 to S54.

[0074] Step S51: Terminal device 30 parses the log output request to obtain the target log file in the log output request.

[0075] Step S52: The terminal device 30 performs keyword identification on the target log file according to the target log desensitization strategy, and then determines the second keyword in the target log file.

[0076] Step S53: The terminal device 30 determines the target privacy data desensitization level corresponding to the target log file based on the second keyword and the target log desensitization strategy, and determines the target privacy desensitization method based on the target privacy data desensitization level.

[0077] Step S54: The terminal device 30 performs log desensitization on the target log file according to the target privacy desensitization method to obtain a desensitized log file, and then the terminal device 30 outputs the desensitized log file as a log.

[0078] For example, the terminal device 30 parses the log output request to obtain the target log file corresponding to the log output request, and then performs keyword recognition on the target log file to determine the second keyword in the target log file. Based on the second keyword and the target log desensitization strategy, the terminal device 30 determines the target privacy data desensitization level corresponding to the target log file, and determines the target privacy desensitization method based on the target privacy data desensitization level. The terminal device 30 performs log desensitization on the target log file according to the target privacy desensitization method to obtain the desensitized log file, and then the terminal device 30 outputs the desensitized log file as a log.

[0079] For example, if the target log file contains keywords such as Private, Sensitive, Protect, and Public, regular expression matching can be used to identify the keywords, thereby determining the second keyword in the target log file. The second keyword is then used to query the target log desensitization strategy to obtain the target privacy data desensitization level corresponding to the second keyword and the target privacy data desensitization method corresponding to the target privacy data desensitization level. The terminal device 30 then performs log desensitization on the target log file according to the target privacy desensitization method to obtain a desensitized log file, and finally, the terminal device 30 outputs the desensitized log file as a log.

[0080] In some implementations, a keyword converter is used to adjust the privacy data anonymization level. The terminal device 30 determines the target privacy data anonymization level corresponding to the target log file based on the second keyword and the target log anonymization strategy. This includes: the terminal device 30 converts the second keyword into a third keyword using the keyword converter; and the terminal device 30 determines the target privacy data anonymization level corresponding to the target log file based on the third keyword and the target log anonymization strategy.

[0081] For example, to flexibly configure the de-identification effect of the same target log file under different requirements, an Automatic field can be set in the target log file. Then, the Automatic field can be converted into the third keyword corresponding to Automatic in the target log de-identification strategy using a keyword converter. Finally, the target privacy data de-identification level corresponding to the target log file can be determined based on the third keyword and the target log de-identification strategy.

[0082] For example, if the target log anonymization strategy is divided into strategy A and strategy B, where the "Automatic" field in strategy A corresponds to the "Private" keyword and the "Automatic" field in strategy B corresponds to the "Sensitive" keyword, then when the target log anonymization strategy is strategy A, the "Automatic" field in the target log file will be converted to the "Private" keyword after passing through a keyword converter; conversely, when the target log anonymization strategy is strategy B, the "Automatic" field in the target log file will be converted to the "Sensitive" keyword after passing through a keyword converter. This allows for dynamic configuration of the privacy level.

[0083] For example, such as Figure 5 As shown, the target log file is obtained, keywords are identified within it, and when a keyword converter is needed, the target log file is converted using the keyword converter. Then, based on the converted keywords, the logs are de-identified according to the target log de-identification strategy. This results in a de-identified log file.

[0084] It is understandable that setting the Automatic field in the target log file is one approach in this application embodiment. Alternatively, other fields can be set in the target log file to achieve dynamic configuration of privacy levels for desensitization.

[0085] As the social environment develops, the requirements of the terminal device 30 for log de-identification strategies will change. Therefore, this application also includes updating the log de-identification strategy of the terminal device 30.

[0086] In some implementations, the terminal device 30 proactively sends an update log de-identification method request to the IoT server 20. The IoT server 20 determines an update log de-identification policy that matches the terminal device 30 from the privacy standard library based on the update log de-identification method request. When the update log de-identification policy is inconsistent with the target log de-identification policy currently running on the terminal device 30, the IoT server 20 sends the update log de-identification policy to the terminal device 30 so that the terminal device 30 updates its log de-identification policy according to the update log de-identification policy.

[0087] For example, terminal device 30 proactively sends an update log de-identification method request to IoT server 20. IoT server 20 determines the log de-identification policy to be updated that matches terminal device 30 from the privacy standard library based on the update log de-identification method request. If the log de-identification policy to be updated has not changed from the target log de-identification policy currently running on terminal device 30, then IoT server 20 simply sends the matching information (no update required) to terminal device 30. If the update log de-identification policy is inconsistent with the target log de-identification policy currently running on terminal device 30, then IoT server 20 sends an update log de-identification policy to terminal device 30, so that terminal device 30 updates its log de-identification policy accordingly.

[0088] Alternatively, when the IoT server 20 receives a request for an update log desensitization method, it determines whether the update log desensitization policy is consistent with the target log desensitization policy currently running on the terminal device 30, based on whether the target log desensitization policy currently running on the terminal device 30 has been modified, and then determines whether the IoT server 20 should send an update instruction to the terminal device 30.

[0089] In some implementations, the method further includes the following steps: after receiving an update instruction from the policy configuration device 10 to update the log de-identification policy in the privacy standard library, the IoT server 20 responds to the update instruction by determining the log de-identification policy to be updated from the privacy standard library and obtaining the update policy data, and then uses the update policy data to update the log de-identification policy to be updated to obtain the updated log de-identification policy.

[0090] For example, a user updates the log anonymization policy in the privacy standard library through the policy configuration device 10, so that the log anonymization policy can be changed according to actual needs. When the IoT server 20 receives the update instruction from the policy configuration device 10 to update the log anonymization policy in the privacy standard library, the IoT server 20 determines the log anonymization policy to be updated and obtains the update policy data from the privacy standard library according to the update instruction, and then uses the update policy data to update the log anonymization policy to be updated. The means of updating include, but are not limited to, adding, modifying, and deleting.

[0091] In some implementations, after the log de-identification policy is updated, the IoT server 20 determines the target terminal device to be updated based on the updated log de-identification policy, and sends the updated log de-identification policy to the target terminal device so that the target terminal device performs the policy configuration update operation.

[0092] For example, after a user updates the log de-identification policy in the privacy standard library through the policy configuration device 10, the terminal device 30 passively receives the updated log de-identification policy from the IoT server 20. The IoT server 20 obtains the current terminal device 30 that was executing the updated log de-identification policy before the update, and determines it as the target terminal device to be updated. Then, it sends the updated log de-identification policy to the target terminal device so that the target terminal device can perform log de-identification according to the updated log de-identification policy.

[0093] refer to Figure 1 This application embodiment also provides a log output management system 100, which includes a policy configuration device 10, an IoT server 20, and a terminal device 30. The IoT server 20 is communicatively connected to the policy configuration device 10 and the terminal device 30.

[0094] The policy configuration device 10 receives the de-identification policy configuration instruction, and responds to the de-identification policy configuration instruction to build a log de-identification policy, and sends the built log de-identification policy to the IoT server 20.

[0095] The IoT server 20 receives the log de-identification policy sent by the policy configuration device 10, and uses the log de-identification policy to build a privacy standard library. When the IoT server 20 receives the deployment completion instruction from the terminal device 30, it obtains the de-identification requirements adapted to the terminal device 30 according to the deployment completion instruction, and obtains the target log de-identification policy adapted to the de-identification requirements from the privacy standard library according to the de-identification requirements, and sends the target log de-identification policy to the terminal device 30.

[0096] After receiving the target log desensitization policy, the terminal device 30 executes the policy configuration operation of the target log desensitization policy, and sends configuration feedback information to the IoT server 20 after the policy configuration operation is completed.

[0097] The IoT server 20 receives configuration feedback information, generates configuration response information based on the configuration feedback information, and sends it to the policy configuration device 10 so that the policy configuration device 10 outputs the corresponding configuration prompt.

[0098] When the terminal device 30 receives a log output request, it responds to the log output request by performing desensitization processing on the target log file corresponding to the log output request according to the target log desensitization policy, and outputs the desensitized log file.

[0099] In some implementations, a log de-identification policy is constructed in response to a de-identification policy configuration instruction, including:

[0100] The policy configuration device 10 determines the privacy data desensitization level and the privacy desensitization method corresponding to the desensitization policy configuration instruction based on the desensitization policy configuration instruction.

[0101] The policy configuration device 10 determines the log de-identification policy based on the privacy data de-identification level and privacy de-identification method.

[0102] In some implementations, the policy configuration device 10 determines the log de-identification policy based on the privacy data de-identification level and the privacy de-identification method, including:

[0103] The strategy configuration device 10 obtains the first keyword corresponding to the privacy data anonymization level;

[0104] The policy configuration device 10 establishes a privacy mapping table based on the first keyword and the privacy data anonymization level;

[0105] The policy configuration device 10 determines the log de-identification policy based on the privacy mapping table and the privacy de-identification method.

[0106] In some implementations, privacy desensitization methods include fuzzy desensitization and encrypted desensitization. Fuzzy desensitization is used to replace characters in the data to be desensitized, thereby achieving data desensitization. Encrypted desensitization is used to encrypt the data to be desensitized, thereby achieving data desensitization.

[0107] In some implementations, the IoT server 20 receives a log de-identification policy sent by the policy configuration device 10, and uses the log de-identification policy to build a privacy standard library, including:

[0108] After receiving the log de-identification policy sent by the policy configuration device 10, the IoT server 20 obtains the environmental requirements for log de-identification, and the environmental requirements include at least the de-identification requirements.

[0109] The IoT server 20 builds a privacy standard library based on log anonymization strategies and environmental requirements.

[0110] In some implementations, a target log anonymization strategy adapted to the anonymization requirements is obtained from a privacy standard library, including:

[0111] The IoT server 20 determines the corresponding keyword requirements based on the de-identification needs.

[0112] The IoT server 20 selects target log de-identification strategies that match the de-identification requirements from the privacy standard library based on the required keywords.

[0113] In some implementations, when the terminal device 30 receives a log output request, it responds to the log output request by performing de-identification processing on the target log file corresponding to the log output request according to the target log de-identification policy, and outputs the de-identified log file, including:

[0114] Terminal device 30 parses the log output request to obtain the target log file in the log output request;

[0115] Terminal device 30 performs keyword identification on the target log file according to the target log desensitization strategy, and then determines the second keyword in the target log file;

[0116] Terminal device 30 determines the target privacy data desensitization level corresponding to the target log file based on the second keyword and the target log desensitization strategy, and determines the target privacy desensitization method based on the target privacy data desensitization level;

[0117] Terminal device 30 performs log desensitization on the target log file according to the target privacy desensitization method to obtain a desensitized log file, and then terminal device 30 outputs the desensitized log file as a log.

[0118] In some implementations, the keyword converter is used to adjust the privacy data anonymization level. The terminal device 30 determines the target privacy data anonymization level corresponding to the target log file based on the second keyword and the log anonymization strategy, including:

[0119] Terminal device 30 uses a keyword converter to convert the second keyword into a third keyword;

[0120] Terminal device 30 determines the target privacy data anonymization level corresponding to the target log file based on the third keyword and the log anonymization strategy.

[0121] In some implementations, the method further includes:

[0122] Terminal device 30 actively sends an update log de-identification method request to IoT server 20. IoT server 20 determines the update log de-identification strategy that matches terminal device 30 from the privacy standard library based on the update log de-identification method request.

[0123] When the update log de-identification policy is inconsistent with the target log de-identification policy currently running on the terminal device 30, the IoT server 20 sends the update log de-identification policy to the terminal device 30 in a matching manner.

[0124] In some implementations, the method further includes:

[0125] After receiving the update instruction from the policy configuration device 10 to update the log de-identification policy in the privacy standard library, the IoT server 20 responds to the update instruction by determining the log de-identification policy to be updated from the privacy standard library and obtaining the update policy data. It then uses the update policy data to update the log de-identification policy to be updated, thereby obtaining the updated log de-identification policy.

[0126] In some implementations, after the log de-identification policy is updated, the IoT server 20 determines the target terminal device to be updated based on the updated log de-identification policy, and sends the updated log de-identification policy to the target terminal device so that the target terminal device performs the policy configuration update operation.

[0127] In some implementations, the method further includes:

[0128] When terminal device 30 fails to perform policy configuration operation according to the target log desensitization policy, policy configuration device 10 determines the reason for the policy configuration failure of terminal device 30 based on the configuration response information.

[0129] The policy configuration device 10 corrects the target log de-identification policy according to the reason for the policy configuration failure, and reissues the de-identification policy configuration instruction until the target log de-identification policy corresponding to the terminal device 30 is set.

[0130] It should be noted that those skilled in the art will understand that, for the sake of convenience and brevity, the specific working process of the log output management system 100 described above can be referred to the corresponding process in the aforementioned log information output management method embodiment, and will not be repeated here.

[0131] It should be understood that the term "and / or" as used in this specification and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes such combinations. It should be noted that, herein, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or system that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or system. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or system that includes that element.

[0132] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments. The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A log information output management method, applied to a log output management system, the log output management system comprising a policy configuration device, an IoT server, and terminal devices, wherein the IoT server is communicatively connected to the policy configuration device and the terminal devices, characterized in that, The method includes: The policy configuration device receives a de-identification policy configuration instruction, and responds to the de-identification policy configuration instruction to construct a log de-identification policy, and sends the constructed log de-identification policy to the IoT server; The IoT server receives the log de-identification policy sent by the policy configuration device to build a privacy standard library using the log de-identification policy. When the IoT server receives the terminal device deployment completion instruction, it obtains the de-identification requirements adapted to the terminal device according to the deployment completion instruction, obtains the target log de-identification policy adapted to the de-identification requirements from the privacy standard library according to the de-identification requirements, and sends the target log de-identification policy to the terminal device. After receiving the target log desensitization policy, the terminal device executes the policy configuration operation of the target log desensitization policy, and sends configuration feedback information to the IoT server after the policy configuration operation is completed. The IoT server receives the configuration feedback information, generates configuration response information based on the configuration feedback information, and sends it to the policy configuration device so that the policy configuration device outputs the corresponding configuration prompt. When the terminal device receives a log output request, it responds to the log output request by performing desensitization processing on the target log file corresponding to the log output request according to the target log desensitization policy, and outputs the desensitized log file.

2. The method according to claim 1, characterized in that, The step of constructing a log de-identification policy in response to the de-identification policy configuration command includes: The policy configuration device determines the privacy data desensitization level corresponding to the desensitization policy configuration instruction and the privacy desensitization method corresponding to the privacy data desensitization level according to the desensitization policy configuration instruction. The policy configuration device determines the log de-identification policy based on the privacy data de-identification level and the privacy de-identification method.

3. The method according to claim 2, characterized in that, The policy configuration device determines the log de-identification policy based on the privacy data de-identification level and the privacy de-identification method, including: The strategy configuration device obtains the first keyword corresponding to the privacy data anonymization level; The policy configuration device establishes a privacy mapping table based on the first keyword and the privacy data anonymization level; The policy configuration device determines the log de-identification policy based on the privacy mapping table and the privacy de-identification method.

4. The method according to claim 3, characterized in that, The privacy desensitization method includes a fuzzy desensitization method and an encrypted desensitization method. The fuzzy desensitization method is used to replace characters in the data to be desensitized, thereby achieving data desensitization of the data to be desensitized. The encrypted desensitization method is used to encrypt the data to be desensitized, thereby achieving data desensitization of the data to be desensitized.

5. The method according to claim 1, characterized in that, The IoT server receives the log de-identification policy sent by the policy configuration device, and uses the log de-identification policy to build a privacy standard library, including: After receiving the log de-identification policy sent by the policy configuration device, the IoT server obtains the environmental requirements for log de-identification, and the environmental requirements include at least the de-identification requirements. The IoT server constructs the privacy standard library based on the log anonymization strategy and the environmental requirements.

6. The method according to claim 1, characterized in that, Based on the stated de-identification requirements, a target log de-identification strategy adapted to the stated de-identification requirements is obtained from the privacy standard library, including: The IoT server determines the corresponding keyword for the de-identification requirement based on the de-identification requirement. The IoT server selects target log de-identification strategies that match the de-identification requirements from the privacy standard library based on the required keywords.

7. The method according to claim 1, characterized in that, When the terminal device receives a log output request, it responds to the log output request by performing desensitization processing on the target log file corresponding to the log output request according to the target log desensitization policy, and outputs the desensitized log file, including: The terminal device parses the log output request to obtain the target log file in the log output request; The terminal device performs keyword recognition on the target log file according to the target log desensitization strategy, and then determines the second keyword in the target log file; The terminal device determines the target privacy data anonymization level corresponding to the target log file based on the second keyword and the target log anonymization strategy, and determines the target privacy anonymization method based on the target privacy data anonymization level; The terminal device performs log desensitization on the target log file according to the target privacy desensitization method to obtain a desensitized log file, and then the terminal device outputs the desensitized log file as a log.

8. The method according to claim 7, characterized in that, The keyword converter is used to adjust the level of privacy data anonymization. The terminal device determines the target privacy data anonymization level corresponding to the target log file based on the second keyword and the target log anonymization strategy, including: The terminal device converts the second keyword into a third keyword using a keyword converter. The terminal device determines the target privacy data anonymization level corresponding to the target log file based on the third keyword and the target log anonymization strategy.

9. The method according to any one of claims 1-8, characterized in that, The method further includes: The terminal device actively sends an update log de-identification method request to the IoT server, and the IoT server determines an update log de-identification strategy matching the terminal device from the privacy standard library according to the update log de-identification method request. When the update log de-identification policy is inconsistent with the target log de-identification policy currently running on the terminal device, the IoT server sends the update log de-identification policy to the terminal device so that the terminal device updates its log de-identification policy according to the update log de-identification policy.

10. The method according to any one of claims 1-8, characterized in that, The method further includes: After receiving an update instruction from the policy configuration device to update the log de-identification policy in the privacy standard library, the IoT server responds to the update instruction by determining the log de-identification policy to be updated and obtaining the update policy data from the privacy standard library, and uses the update policy data to update the log de-identification policy to be updated, thereby obtaining the updated log de-identification policy.

11. The method according to claim 10, characterized in that, After the log de-identification policy is updated, the IoT server determines the target terminal device to be updated based on the updated log de-identification policy, and sends the updated log de-identification policy to the target terminal device so that the target terminal device performs the policy configuration update operation.

12. The method according to claim 1, characterized in that, The method further includes: When the terminal device fails to perform the policy configuration operation according to the target log desensitization policy, the policy configuration device determines the reason for the policy configuration failure of the terminal device based on the configuration response information. The policy configuration device corrects the target log de-identification policy according to the reason for the policy configuration failure, and reissues the de-identification policy configuration instruction until the target log de-identification policy corresponding to the terminal device is set.

13. A log output management system, comprising a policy configuration device, an IoT server, and terminal devices, wherein the IoT server is communicatively connected to the policy configuration device and the terminal devices, characterized in that, include: The policy configuration device receives a de-identification policy configuration instruction, and responds to the de-identification policy configuration instruction to construct a log de-identification policy, and sends the constructed log de-identification policy to the IoT server; The IoT server receives the log de-identification policy sent by the policy configuration device to build a privacy standard library using the log de-identification policy. When the IoT server receives the terminal device deployment completion instruction, it obtains the de-identification requirements adapted to the terminal device according to the deployment completion instruction, obtains the target log de-identification policy adapted to the de-identification requirements from the privacy standard library according to the de-identification requirements, and sends the target log de-identification policy to the terminal device. After receiving the target log desensitization policy, the terminal device executes the policy configuration operation of the target log desensitization policy, and sends configuration feedback information to the IoT server after the policy configuration operation is completed. The IoT server receives the configuration feedback information, generates configuration response information based on the configuration feedback information, and sends it to the policy configuration device so that the policy configuration device outputs the corresponding configuration prompt. When the terminal device receives a log output request, it responds to the log output request by performing desensitization processing on the target log file corresponding to the log output request according to the target log desensitization policy, and outputs the desensitized log file.

Citation Information

Patent Citations

  • Log desensitization method, device and equipment and storage medium

    CN112685771A

  • Log desensitization method and device, computer equipment and storage medium

    CN112784298A