A data desensitization method and device
By dividing the Lua and the desensitization counters during the data desensitization process, first cache the data packets and their desensitization locations, the problems of explosive memory and poor real-time performance caused by cached large data volumes in the existing technology are solved, and efficient data desensitization and timely page feedback are achieved.
Patent Information
- Application Number
- CN202311714566.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-13
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2043-12-13
AI Technical Summary
Existing dynamic data desensitization technology can easily lead to memory and page stuttering when cached large data volumes, poor real-time performance, and timely feedback of desensitized pages cannot be made.
During the data desensitization process, it is divided into two handshake parties: Lua and desensitization. First, the data packet and its desensitization position are cached, the target desensitization position is obtained through conversion or splicing, and then the desensitized data packet is received directly to the user, reducing component dependence.
It effectively avoids memory explosion, improves the real-time and efficiency of data desensitization, and ensures the timeliness of page response.
Smart Images

Figure CN117874803B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data processing, and particularly relates to a data desensitization method and device. Background Art
[0002] With the rapid development of information technology and the wide application of data, people are increasingly concerned about issues of personal privacy and data protection. In the past few years, there have been multiple large-scale data leakage incidents, including the leakage of sensitive data such as user personal information, credit card data, and medical records. Data desensitization is a common technology in the field of data security for protecting sensitive information.
[0003] In related technologies, existing desensitization technologies have two methods: static data and dynamic data desensitization. Static desensitization technology requires obtaining the data exported from the database at one time and then desensitizing these data, while dynamic desensitization technology is performed in real time when the data is read. With the development of big data, most current patents adopt the dynamic desensitization method. The dynamic desensitization method will first cache the packets, then extract the desensitization positions, and finally desensitize. The real-time performance of this desensitization sequence is poor. If it is necessary to cache all the time and if the amount of cached data is very large at the end, this will not only cause the process of extracting the desensitization positions to be time-consuming, but also cannot promptly feedback the desensitized page to the user, and there may be a situation of page freezing. Therefore, how to better implement data desensitization has become an urgent problem to be solved. Summary of the Invention
[0004] In view of the above deficiencies of the prior art, the purpose of the invention is to provide a data desensitization method and device. This method reduces the dependencies between various components, can avoid the situation of out-of-memory, and greatly improves the real-time performance, making it more efficient.
[0005] In the first aspect of the present invention, a data desensitization method is proposed. The method is applied to the Lua side and includes: obtaining a plurality of data packets and sending a position request to the desensitization side, where the position request is used to request the desensitization positions of the plurality of data packets; caching the plurality of data packets and the desensitization positions of the plurality of data packets when receiving the desensitization positions of the plurality of data packets; converting or splicing the plurality of data packets to obtain the target desensitization positions of the plurality of data packets, and sending a desensitization request to the desensitization side, where the desensitization request is used to request desensitization of the plurality of data packets; and sending the desensitized plurality of data packets to the user when receiving the desensitized plurality of data packets.
[0006] Further, obtain multiple data packets and send a location request to the desensitization party. The location request is used to request the desensitization location of the multiple data packets, including: obtaining a first data packet for the first time and sending a first location request to the desensitization party. The first location request is used to request the desensitization location of the first data packet; obtaining a second data packet for the second time and sending a second location request to the desensitization party. The second location request is used to request the desensitization location of the second data packet; obtaining a third data packet for the third time and sending a third location request to the desensitization party. The third location request is used to request the desensitization location of the third data packet.
[0007] Further, convert or splice the multiple data packets to obtain the target desensitization location of the multiple data packets, including: converting the desensitization locations of the first data packet and the second data packet to obtain the target desensitization location of the first data packet; splicing the desensitization locations of the second data packet and the third data packet to obtain the spliced data packet and the target desensitization location corresponding to the spliced data packet.
[0008] Further, converting the desensitization locations of the first data packet and the second data packet to obtain the target desensitization location of the first data packet includes: when it is determined that the value corresponding to the desensitization start position of the second data packet is greater than the packet lengths of all the processed packets, using the desensitization location of the first data packet as the target desensitization location of the first data packet; when it is determined that the value corresponding to the desensitization start position of the second data packet is less than the packet lengths of all the processed packets, converting the desensitization location of the first data packet and using the converted desensitization location as the target desensitization location of the first data packet.
[0009] In a second aspect of the present invention, a data desensitization method is proposed. The method is applied to the desensitization party and includes: receiving a location request sent by the Lua party. The location request is used to request the desensitization locations of multiple data packets; determining the desensitization locations of the multiple data packets and sending the desensitization locations of the multiple data packets to the Lua party; receiving a desensitization request sent by the Lua party. The desensitization request is used to request desensitization of the multiple data packets; desensitizing the multiple data packets according to the desensitization request and sending the desensitized multiple data packets to the Lua party.
[0010] Further, determining the desensitization locations of the multiple data packets includes: obtaining the multiple data packets; determining the desensitization location of each data packet according to the multiple data packets and the desensitization rules.
[0011] Further, desensitizing the multiple data packets according to the desensitization request and sending the desensitized multiple data packets to the Lua side includes: determining the type of data in each data packet; desensitizing each data packet according to the data type and the desensitization algorithm; and sending each desensitized data packet to the Lua side.
[0012] In a third aspect of the present invention, a data desensitization device is provided. The device is applied to the Lua side and includes: an acquisition module, configured to acquire multiple data packets and send a location request to the desensitization side, where the location request is used to request the desensitization location of the multiple data packets; a caching module, configured to cache the multiple data packets and the desensitization locations of the multiple data packets when receiving the desensitization locations of the multiple data packets; a first sending module, configured to convert or splice the multiple data packets to obtain the target desensitization locations of the multiple data packets and send a desensitization request to the desensitization side, where the desensitization request is used to request desensitization of the multiple data packets; and a second sending module, configured to send the desensitized multiple data packets to a user when receiving the desensitized multiple data packets.
[0013] In a fourth aspect of the present invention, a data desensitization device is provided. The device is applied to the desensitization side and includes: a first receiving module, configured to receive a location request sent by the Lua side, where the location request is used to request the desensitization location of multiple data packets; a third sending module, configured to determine the desensitization locations of the multiple data packets and send the desensitization locations of the multiple data packets to the Lua side; a second receiving module, configured to receive a desensitization request sent by the Lua side, where the desensitization request is used to request desensitization of the multiple data packets; and a fourth sending module, configured to desensitize the multiple data packets according to the desensitization request and send the desensitized multiple data packets to the Lua side.
[0014] In a fifth aspect of the present invention, an electronic device is provided, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to execute the method according to any one of the first aspect of the present invention or execute the method according to any one of the second aspect of the present invention.
[0015] The beneficial effects of the present invention are as follows:
[0016] The method and device described in the present invention are divided into two handshake parties during the entire data desensitization process, namely the Lua party for data collection, processing, caching, and position conversion, and the desensitization party for obtaining the desensitization position and performing desensitization. This reduces the dependencies between components. By caching the previous packet and its desensitization position first, the problem that the truncated information cannot obtain the complete desensitization position is solved. Only a very small part of the truncation cases cannot be fully desensitized, but this can avoid out-of-memory situations and greatly improve real-time performance, making it more efficient. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The drawings are only for the purpose of illustrating specific embodiments and are not considered to be a limitation of the present invention. Throughout the drawings, the same reference signs denote the same components. Obviously, the drawings described below are only some embodiments described in the embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings based on these drawings.
[0018] Figure 1 is a hardware structure block diagram of a terminal device for a data desensitization method according to an embodiment of the present invention;
[0019] Figure 2 is a flowchart of a data desensitization method according to an embodiment of the present invention;
[0020] Figure 3 is a flowchart of a data desensitization method according to another embodiment of the present invention;
[0021] Figure 4 is a schematic diagram of a data desensitization method according to a specific embodiment of the present invention;
[0022] Figure 5 is a structure block diagram of a data desensitization device according to an embodiment of the present invention;
[0023] Figure 6 is a structure block diagram of a data desensitization device according to another embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0024] In order to enable those skilled in the art to better understand the technical solutions in the embodiments of the present invention, the technical solutions of the present invention will be clearly and completely described below in conjunction with the drawings. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. It should be understood that these descriptions are only exemplary and are not used to limit the scope of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.
[0025] In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily obscuring the concepts disclosed in the present invention.
[0026] In the description of the present invention, it should be noted that unless otherwise clearly specified and limited, the orientation or positional relationship indicated by terms such as "center", "upper", "lower", "left", "right", "vertical", "horizontal", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation to the present invention. In addition, the terms "first", "second", and "third" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance. The terms "mounted", "connected", and "connected" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0027] Here, exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. On the contrary, they are merely examples of methods and systems consistent with some aspects of the present invention as detailed in the appended claims.
[0028] According to one aspect of an embodiment of the present invention, a data desensitization method is provided, and the data desensitization method can be executed in a terminal device or a similar computing device. Taking running on a terminal device as an example, Figure 1 is a hardware structure block diagram of an electronic device for a data desensitization method according to an embodiment of the present invention. As Figure 1 shown, the terminal device may include one or more ( Figure 1 only one is shown in the figure) processors 102 (the processor 102 may include, but is not limited to, a microprocessor (abbreviated as MPU) or a programmable logic device (abbreviated as PLD)) and a memory 104 for storing data. In an exemplary embodiment, the above terminal device may further include a transmission device 106 for communication functions and an input / output device 108. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only schematic and does not limit the structure of the above terminal device. For example, the terminal device may further include more thanFigure 1 more or fewer components as shown, or having the same functions as Figure 1 shown or different configurations with more functions than Figure 1 shown.
[0029] The memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the level determination method in the embodiments of the present invention. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implements the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely disposed relative to the processor 102, and these remote memories can be connected to the terminal device through a network. Examples of the above network include but are not limited to the Internet, enterprise intranets, local area networks, mobile communication networks, and combinations thereof.
[0030] The transmission device 106 is used to receive or send data via a network. Specific examples of the above network may include a wireless network provided by a communication provider of a switching device. In one instance, the transmission device 106 includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one instance, the transmission device 106 may be a radio frequency (Radio Frequency, abbreviated as RF) module, which is used to communicate with the Internet wirelessly.
[0031] In the related art, a Web Application Firewall (WAF) is a firewall specifically used to protect Web applications. OpenResty is a powerful Web platform, which is based on Nginx and a series of selected modules, including Lua script modules for high concurrency, non-blocking I / O, and dynamic content generation. OpenResty is often used as a reverse proxy, a load balancer, and many other uses. And now many WAFs are implemented based on OpenResty.
[0032] However, if the response page after Nginx reverse proxy is directly returned to the user, it may lead to the leakage of sensitive information. Moreover, with the rapid development of information technology and the extensive application of data, people are also paying more and more attention to the issues of personal privacy and data protection. In the past few years, there have been many large-scale data leakage incidents, including the leakage of sensitive data such as user personal information, credit card data, and medical records. Therefore, it is generally necessary to desensitize the returned response page now. Data desensitization is a common technology in the field of data security for protecting sensitive information. It processes the original data by replacement, masking, randomization or other means to reduce the risk of data leakage.
[0033] The existing desensitization technologies include static data and dynamic data desensitization. Static desensitization technology requires obtaining the data exported from the database at one time and then desensitizing these data, while dynamic desensitization technology is performed in real time when the data is read. With the development of big data, most current patents adopt the dynamic desensitization method. CN112541196A proposes a dynamic data desensitization method and system, which performs desensitization operations on different types of data in real time according to the data access requirements and the identity of the visitor, and sets different desensitization degrees according to different access levels, so as to realize the access permission control of sensitive data by different visitors. CN108683643A proposes a data desensitization system based on streaming processing and its desensitization method, which includes an acquisition module for acquiring data, a desensitization module for desensitizing the data, and a sending module for sending the desensitized data, and also includes: a cache module; a judgment module, where the judgment module is used to judge whether one or more currently received data packets contain a complete record row, and store the one or more collected data packets in the cache module.
[0034] However, 1) Using the method of caching streaming data packets and then desensitizing them to avoid the situation where truncated information cannot be desensitized is a common idea, but the existing solutions judge whether to stop caching based on the integrity of the received data packets. The problem with this is that if an attacker deliberately sends a packet in several parts, or if each received streaming packet is truncated and divided into two packets before and after, then this will lead to "infinite" caching. The worst case is that all packets need to be cached before desensitization, which is no different from static desensitization, and if the packets are very large, it may also lead to out-of-memory situations; 2) Caching the packets first, then extracting the desensitization positions, and finally desensitizing, the real-time performance of this desensitization order is poor. If continuous caching is required and the amount of cached data is very large in the end, this will not only make the process of extracting desensitization positions time-consuming, but also cannot timely feedback the desensitized page to the user, and there may be a situation of page freezing.
[0035] To this end, the present invention proposes a data desensitization method, apparatus and electronic device.
[0036] In this embodiment, a data desensitization method is provided. The method can be applied to the above terminal device or can be configured in a server. Among them, the terminal device can be a PC or a mobile terminal. The embodiments of the present application do not make any limitations in this regard. Figure 2 It is a flowchart of the data desensitization method according to an embodiment of the present invention. The process includes the following steps:
[0037] S210, obtain multiple data packets and send a location request to the desensitization party. The location request is used to request the desensitization location of the multiple data packets.
[0038] In the embodiment of the present invention, the data in the multiple data packets can be understood as security data about information such as private data. For example, sensitive data such as personal identity information, mobile phone numbers, and bank card information collected by institutions and enterprises.
[0039] Among them, multiple data packets can be obtained through the Lua side.
[0040] Specifically, the Lua side can obtain the first data packet for the first time and send a first location request to the desensitization party. The first location request is used to request the desensitization location of the first data packet; obtain the second data packet for the second time and send a second location request to the desensitization party. The second location request is used to request the desensitization location of the second data packet; obtain the third data packet for the third time and send a third location request to the desensitization party. The third location request is used to request the desensitization location of the third data packet.
[0041] S220, in the case of receiving the desensitization locations of the multiple data packets, cache the multiple data packets and the desensitization locations of the multiple data packets.
[0042] That is to say, when the Lua side obtains multiple data packets and sends a location request to the desensitization party, the desensitization party can determine the desensitization locations of the multiple data packets based on the location request. Furthermore, the desensitization party sends the desensitization locations of the multiple data packets to the Lua side so that the Lua side receives the desensitization locations of the multiple data packets and caches the multiple data packets and the desensitization locations of the multiple data packets.
[0043] S230, convert or splice the multiple data packets to obtain the target desensitization locations of the multiple data packets, and send a desensitization request to the desensitization party. The desensitization request is used to request desensitization of the multiple data packets.
[0044] In an embodiment of the present invention, when caching multiple data packets and the desensitization positions of multiple data packets, the desensitization position of the first data packet and the desensitization position of the second data packet are converted to obtain the target desensitization position of the first data packet; the desensitization position of the second data packet and the desensitization position of the third data packet are spliced to obtain the spliced data packet and the target desensitization position corresponding to the spliced data packet.
[0045] Wherein, when it is determined that the value corresponding to the desensitization start position of the second data packet is greater than the packet lengths of all the processed packets, the desensitization position of the first data packet is used as the target desensitization position of the first data packet; when it is determined that the value corresponding to the desensitization start position of the second data packet is less than the packet lengths of all the processed packets, the desensitization position of the first data packet is converted, and the converted desensitization position is used as the target desensitization position of the first data packet.
[0046] Wherein, when it is determined that the value corresponding to the desensitization start position of the second data packet is equal to the packet lengths of all the processed packets, assuming the packet length is 20 and the desensitization position of the second data packet is [20, 23], since the offset starts from 0, when the value corresponding to the desensitization start position of the second data packet is equal to the packet lengths of all the processed packets, it is equivalent to the position of the second data packet.
[0047] That is to say, when determining the target desensitization position of the data packet, a desensitization request can be sent to the desensitization party.
[0048] S240, when receiving multiple desensitized data packets, send the multiple desensitized data packets to the user.
[0049] In an embodiment of the present invention, when sending a desensitization request to the desensitization party, the desensitization party can desensitize multiple data packets based on the desensitization request and send the multiple desensitized data packets to the Lua party. When the Lua party receives the multiple desensitized data packets, the multiple desensitized data packets are sent to the user in real time.
[0050] For those in the art to more easily understand the present invention, as Figure 3 shown, another data desensitization method is provided. The method can be applied to the above terminal device or can be configured in a server. The terminal device can be a PC or a mobile terminal. The embodiments of the present application do not make any limitations in this regard. Figure 3 is a flowchart of the data desensitization method according to an embodiment of the present invention. The process includes the following steps:
[0051] S310, receive a position request sent by the Lua party. The position request is used to request the desensitization positions of multiple data packets.
[0052] In an embodiment of the present invention, the Lua party can send a location request for requesting the desensitization locations of multiple data packets to the desensitization party, so that the desensitization party receives the location request sent by the Lua party.
[0053] S320. Determine the desensitization locations of the multiple data packets and send the desensitization locations of the multiple data packets to the Lua party.
[0054] In an embodiment of the present invention, when the desensitization party receives the location request sent by the Lua party, the desensitization party can determine the desensitization locations of the multiple data packets based on the location request and send the desensitization locations of the multiple data packets to the Lua party.
[0055] Wherein, the location request sent by the Lua party carries multiple data packets.
[0056] In an embodiment of the present invention, obtain multiple data packets; determine the desensitization location of each data packet according to the multiple data packets and the desensitization rules. For example, the data packets can be matched with the desensitization rules, and then the desensitization location of each data packet can be determined.
[0057] S330. Receive the desensitization request sent by the Lua party, where the desensitization request is used to request desensitization of multiple data packets.
[0058] In an embodiment of the present invention, when the desensitization party determines the desensitization location of each data packet, the desensitization party can send the desensitization location of each data packet to the Lua party. When the Lua party receives the desensitization location of each data packet, the Lua party can send a desensitization request to the desensitization party, and then the desensitization party receives the desensitization request sent by the Lua party.
[0059] S340. Desensitize the multiple data packets according to the desensitization request and send the desensitized multiple data packets to the Lua party.
[0060] In an embodiment of the present invention, when the desensitization party receives the desensitization request sent by the Lua party, the desensitization party can desensitize the multiple data packets according to the desensitization request and send the desensitized multiple data packets to the Lua party.
[0061] According to the data desensitization method of the embodiments of the present invention, multiple data packets are obtained, and a location request is sent to the desensitization party. The location request is used to request the desensitization locations of the multiple data packets; in the case of receiving the desensitization locations of the multiple data packets, the multiple data packets and the desensitization locations of the multiple data packets are cached; the multiple data packets are converted or spliced to obtain the target desensitization locations of the multiple data packets, and a desensitization request is sent to the desensitization party. The desensitization request is used to request desensitization of the multiple data packets; in the case of receiving the desensitized multiple data packets, the desensitized multiple data packets are sent to the user. This method divides the entire data desensitization process into two handshake parties, the Lua party for data collection, processing, caching, and location conversion, and the desensitization party for obtaining desensitization locations and performing desensitization, thus reducing the dependencies between components. And by caching the previous packet and its desensitization location first, the problem that the truncated information cannot obtain the complete desensitization location is solved. Only a very small part of the truncation cases cannot be completely desensitized, but this can avoid the out-of-memory situation and greatly improve the real-time performance, making it more efficient.
[0062] In a specific embodiment of the present invention, taking entering the body_filter three times as an example, as Figure 4 shown, when the Lua party first enters the body_filter, it first obtains the current response body block packet1 (assuming the packet length is 20), and then sends a location request to the desensitization party to request the desensitization location LOC of the first data packet.
[0063] Where body_filter is a stage for processing the HTTP response body.
[0064] In the case of receiving the location request, the desensitization party can match the first data packet with the desensitization rule to obtain the desensitization location of the first data packet, and send the desensitization location of the first data packet to the Lua party.
[0065] For example, the desensitization location of the first data packet is a two-dimensional array. The first column represents the desensitization start position (from), and the second dimension represents the desensitization end position (to). That is, the desensitization location LOC of the first data packet (i.e., loc1): [{0,11},{-1,-1}]. It should be noted that the last {-1,-1} is set to enable the Lua party to perform more efficient conversion and replacement when converting the positions of two data packets. Only one pair of {-1,-1} is set because for the packet with truncation, there is only one case for the final desensitization location, and only this value needs to be directly replaced, so as to reduce memory waste and improve performance.
[0066] When the Lua side receives the desensitization position of the first data packet sent by the desensitization side, it can cache the first data packet and the desensitization position of the first data packet. And when the Lua side enters the body_filter for the second time and requests the desensitization position of the second data packet (assumed to be packet2) from the desensitization side again, upon receiving the position request, the desensitization side can determine the desensitization position of the second data packet according to the position request and send the desensitization position of the second data packet to the Lua side. For example, the desensitization position of the second data packet LOC(loc2): [{17,29},{-1,-1}]. It should be noted that all desensitization positions are offsets relative to the entire response page, not the offset of the current packet.
[0067] When the Lua side receives the desensitization position LOC(loc1) of the first data packet and the desensitization position LOC(loc2) of the second data packet, it processes LOC(loc1) and LOC(loc2). Here are two cases: Case 1, if the value corresponding to the desensitization start position in the first from_to of LOC(loc2) is greater than the packet lengths of all previously processed packets, then the desensitization position of the cached data packet remains LOC(loc1); Case 2, if the value corresponding to the desensitization start position in the first from_to of LOC(loc2) is less than the packet lengths of all processed packets, then this from_to needs to be converted. For example, the target desensitization position of the first data packet here, that is, the final desensitization position of packet1 is: [{0,11},{17,20}], and LOC(loc2) is processed as: [{20,29},{-1,-1}]. That is to say, since the position of LOC(loc2) is [{17,29},{-1,-1}] and the packet length is 20, it means that the position that needs to be desensitized by the first data packet LOC(loc1) is included in [17,29]. Then take out the first from_to of LOC(loc2) and divide it into two parts with the packet length as the boundary, that is, [17,20] and [20,29]. It should be noted here that the desensitization position of this from_to is left-closed and right-open, that is, the 20th bit is not desensitized for the first data packet LOC(loc1).
[0068] The Lua side sends the converted data packet and the corresponding target desensitization position of the data packet to the desensitization side to request desensitization. After desensitizing according to the target desensitization position of the first data packet, the desensitization side returns the desensitized first data packet to the Lua side, and then the Lua side sends the desensitized first data packet to the user.
[0069] Lua enters the body_filter for the third time and requests the desensitization position of the third data packet (assumed to be packet3) from the desensitization party again. When the desensitization party receives the position request, it can determine the desensitization position of the third data packet according to the position request and send the desensitization position of the third data packet to Lua. For example, the desensitization position LOC (loc3) of the third data packet: [{37, 49}, {-1, -1}]. Then Lua also splices the processed LOC (loc2) and LOC (loc3) to get: [{20, 29}, {37, 49}, {-1, -1}]. Then the spliced data packet and the corresponding target desensitization position of the spliced data packet are returned to the desensitization party. The desensitization party performs desensitization according to the spliced data packet and the corresponding target desensitization position of the spliced data packet, and returns the desensitized packet to Lua. Lua sends the desensitized data packet to the user.
[0070] It can be seen from this that the above process only caches the previous data packet and its desensitization position, and only splices the penultimate packet at the end. And each time the desensitized data is obtained, it is directly returned to the user. This not only greatly improves the real-time performance of the page response, but also can well handle the situation where the truncated sensitive information cannot be desensitized, and well avoids the situation of out-of-memory. Even though this may cause some truncated sensitive information not to be completely desensitized (because even if a sensitive information is sent in many body_filters, the penultimate packet with this sensitive information can still be desensitized), the present invention believes that this impact is very small, because even if a sensitive information is sent in many body_filters, the penultimate packet with this sensitive information can still be desensitized, only the desensitization is incomplete (but still desensitized to a certain extent), and this has a very small impact on the entire response page.
[0071] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions for causing a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods of the various embodiments of the present application.
[0072] Figure 5 is a structural block diagram of a data desensitization device according to an embodiment of the present invention; the device is applied to Lua, as Figure 5 shown, including:
[0073] An acquisition module 510, configured to acquire a plurality of data packets and send a location request to a desensitization party, where the location request is used to request the desensitization location of the plurality of data packets;
[0074] A cache module 520, configured to cache the plurality of data packets and the desensitization locations of the plurality of data packets when the desensitization locations of the plurality of data packets are received;
[0075] A first sending module 530, configured to convert or splice the plurality of data packets to obtain the target desensitization locations of the plurality of data packets, and send a desensitization request to the desensitization party, where the desensitization request is used to request desensitization of the plurality of data packets;
[0076] A second sending module 540, configured to send the desensitized plurality of data packets to a user when the desensitized plurality of data packets are received.
[0077] Further, the acquisition module 510 is specifically configured to acquire a first data packet for the first time and send a first location request to the desensitization party, where the first location request is used to request the desensitization location of the first data packet; acquire a second data packet for the second time and send a second location request to the desensitization party, where the second location request is used to request the desensitization location of the second data packet; acquire a third data packet for the third time and send a third location request to the desensitization party, where the third location request is used to request the desensitization location of the third data packet.
[0078] Further, the first sending module 530 is specifically configured to convert the desensitization locations of the first data packet and the second data packet to obtain the target desensitization location of the first data packet; splice the desensitization locations of the second data packet and the third data packet to obtain a spliced data packet and the target desensitization location corresponding to the spliced data packet.
[0079] Further, the first sending module 530 is specifically configured to use the desensitization location of the first data packet as the target desensitization location of the first data packet when it is determined that the value corresponding to the desensitization start position of the second data packet is greater than the packet lengths of all the processed packets; and convert the desensitization location of the first data packet and use the converted desensitization location as the target desensitization location of the first data packet when it is determined that the value corresponding to the desensitization start position of the second data packet is less than the packet lengths of all the processed packets.
[0080] Figure 6 It is a structural block diagram of a device for intelligent partitioning of load information according to an embodiment of the present invention; the device is applied to a desensitization party, such as Figure 6 shown, and includes:
[0081] The first receiving module 610 is configured to receive a location request sent by the Lua side, where the location request is used to request the desensitized locations of multiple data packets.
[0082] The third sending module 620 is configured to determine the desensitized locations of the multiple data packets and send the desensitized locations of the multiple data packets to the Lua side.
[0083] The second receiving module 630 is configured to receive a desensitization request sent by the Lua side, where the desensitization request is used to request desensitization of the multiple data packets.
[0084] The fourth sending module 640 is configured to desensitize the multiple data packets according to the desensitization request and send the desensitized multiple data packets to the Lua side.
[0085] Further, the third sending module 620 is specifically configured to obtain the multiple data packets; determine the desensitized location of each data packet according to the multiple data packets and the desensitization rules.
[0086] Further, the fourth sending module 640 is specifically configured to determine the type of data in each data packet; desensitize each data packet according to the data type and the desensitization algorithm; send the desensitized each data packet to the Lua side.
[0087] The present invention provides a computer-readable storage medium, on which a computer program is stored, and the computer program can be loaded and executed by a processor to implement the data desensitization method described in the first aspect or the data desensitization method described in the second aspect.
[0088] The applicant of the present invention has made a detailed description and illustration of the embodiments of the present invention in combination with the accompanying drawings of the specification. However, those skilled in the art should understand that the above embodiments are only the preferred implementation schemes of the present invention, and the detailed description is only to help readers better understand the spirit of the present invention, rather than a limitation on the protection scope of the present invention. On the contrary, any improvement or modification based on the spirit of the present invention should fall within the protection scope of the present invention.
[0089] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the embodiments of the present invention, rather than to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention. Any changes or replacements that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered by the protection scope of the present invention.
Claims
1. A data desensitization method, which is applied to the Lua side, characterized in that, Including: S1. Obtain multiple data packets and send a location request to the desensitization party, where the location request is used to request the desensitization location of the multiple data packets; S2. Cache the multiple data packets and the desensitization locations of the multiple data packets when receiving the desensitization locations of the multiple data packets; S3. Transform or splice the multiple data packets to obtain the target desensitization locations of the multiple data packets, and send a desensitization request to the desensitization party, where the desensitization request is used to request desensitization of the multiple data packets; S4. Send the desensitized multiple data packets to the user when receiving the desensitized multiple data packets.
2. The data desensitization method according to claim 1, wherein Obtain multiple data packets and send a location request to the desensitization party, where the location request is used to request the desensitization location of the multiple data packets, including: Obtain a first data packet for the first time and send a first location request to the desensitization party, where the first location request is used to request the desensitization location of the first data packet; Obtain a second data packet for the second time and send a second location request to the desensitization party, where the second location request is used to request the desensitization location of the second data packet; Obtain a third data packet for the third time and send a third location request to the desensitization party, where the third location request is used to request the desensitization location of the third data packet.
3. The data desensitization method according to claim 2, wherein Transform or splice the multiple data packets to obtain the target desensitization locations of the multiple data packets, including: Transform the desensitization location of the first data packet and the desensitization location of the second data packet to obtain the target desensitization location of the first data packet; Splice the desensitization location of the second data packet and the desensitization location of the third data packet to obtain a spliced data packet and the target desensitization location corresponding to the spliced data packet.
4. The data desensitization method according to claim 3, wherein Transform the desensitization location of the first data packet and the desensitization location of the second data packet to obtain the target desensitization location of the first data packet, including: When determining that the value corresponding to the desensitization start position of the second data packet is greater than the packet lengths of all processed packets, use the desensitization location of the first data packet as the target desensitization location of the first data packet; When determining that the value corresponding to the desensitization start position of the second data packet is less than the packet lengths of all processed packets, transform the desensitization location of the first data packet and use the transformed desensitization location as the target desensitization location of the first data packet.
5. A data desensitization device, the device is applied to the Lua side, and is characterized in that, Including: An obtaining module, configured to obtain multiple data packets and send a location request to the desensitization party, where the location request is used to request the desensitization location of the multiple data packets; A caching module, configured to cache the multiple data packets and the desensitization locations of the multiple data packets when receiving the desensitization locations of the multiple data packets; A first sending module, configured to transform or splice the multiple data packets to obtain the target desensitization locations of the multiple data packets, and send a desensitization request to the desensitization party, where the desensitization request is used to request desensitization of the multiple data packets; A second sending module, configured to send the desensitized multiple data packets to the user when receiving the desensitized multiple data packets.
Citation Information
Patent Citations
Data masking system based on streaming and masking method thereof
CN108683643A
Dynamic data desensitization method and system
CN112541196A
User data desensitization method and device, electronic equipment and storage medium
CN112329055A