Data Masking Method and Device
By encrypting and replacing medical data, the problem of privacy leakage in medical data sharing is solved, and data sharing and original image recovery are realized without revealing user privacy.
Patent Information
- Application Number
- CN202410816340.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-24
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-06-24
AI Technical Summary
Since medical data cannot be shared in plain text due to the privacy of patients involved, and the sharing of cipher text cannot establish an association, making it difficult to realize the value and purpose of medical data.
By obtaining the image to be desensitized and the matching parameters, the desensitization information is encrypted using the substitution table generated based on the key and the number of encryption iterations, and replaced with the encryption result information to generate the target image after the data is desensitized.
Sharing of medical data is achieved without revealing user privacy information, and the key holder can restore the original image.
Smart Images

Figure CN119249465B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and in particular, to a data desensitization method and apparatus. Background Art
[0002] Medical data sharing can improve diagnostic accuracy, facilitate technical exchanges within the industry, improve medical quality, promote medical informatization, etc. By realizing the sharing of medical data among medical institutions and breaking information silos, patients can obtain more comprehensive medical services.
[0003] However, since medical data involves patients' personal privacy, hospitals or medical units cannot share medical data in plain text. If shared in ciphertext, it is impossible to establish the correlation between different medical data, and it is difficult to realize the value and use of medical data. For example, for various medical images of a certain patient taken in multiple hospitals, if each hospital encrypts them separately and shares them in ciphertext, it is impossible to establish the correlation between the medical data of this patient among different hospitals.
[0004] Based on this, there is an urgent need for a data desensitization method that can realize the sharing of medical data without disclosing users' privacy information and can also restore the original information when necessary. Summary of the Invention
[0005] The purpose of this application is to provide a data desensitization method and apparatus for realizing the sharing of medical data without disclosing users' privacy information, and allowing the holder of the key to restore the original image from the target image after data desensitization.
[0006] This application provides a data desensitization method, including:
[0007] Obtaining an image to be desensitized and matching parameters; the matching parameters include: at least one substitution table corresponding to the information type of the information to be desensitized included in the image to be desensitized, and the number of encryption iterations; the substitution table is generated based on a key; encrypting the information to be desensitized based on the matching parameters to obtain encrypted result information, and replacing the information to be desensitized with the encrypted result information to obtain a target image after data desensitization; wherein, the number of encryption iterations is used to indicate the number of cyclic transformations of encryption, and in the cyclic transformation process, the at least one substitution table is used to encrypt the information to be desensitized in a preset order.
[0008] Optionally, the obtaining the image to be desensitized and the matching parameters includes: obtaining the image to be desensitized, and identifying the information to be desensitized in the image to be desensitized; identifying the information type of the information to be desensitized, and generating at least one substitution table corresponding to the information type of the information to be desensitized.
[0009] Optionally, the information types of the desensitized information include: English characters, numeric characters, and Chinese characters; the substitution table corresponding to the English characters is the first substitution table; the substitution table corresponding to the Chinese characters is the second substitution table; the substitution table corresponding to the numeric characters is the third substitution table;.
[0010] Optionally, encrypting the information to be desensitized based on the matching parameter to obtain encrypted result information includes: when the information type of the desensitized information is the English characters, encrypting the information to be desensitized based on a preset encryption algorithm and at least one first substitution table to obtain the encrypted result information; or, when the information type of the desensitized information is the Chinese characters, encrypting the information to be desensitized based on a preset encryption algorithm and at least one second substitution table to obtain the encrypted result information; or, when the information type of the desensitized information is the numeric characters, encrypting the information to be desensitized based on a preset encryption algorithm and at least one third substitution table to obtain the encrypted result information.
[0011] Optionally, the first substitution table includes: a single-letter substitution table; the value ranges of the input value and the output value of the single-letter substitution table are [0, 25]; the third substitution table includes: a single-digit substitution table; the value ranges of the input value and the output value of the single-digit substitution table are [0, 9]; encrypting the information to be desensitized based on a preset encryption algorithm and at least one substitution table to obtain the encrypted result information includes: encrypting the information to be desensitized based on a preset encryption algorithm and at least one single-letter substitution table, or at least one single-digit substitution table to obtain the encrypted result information.
[0012] Optionally, the first substitution table includes: a single-letter substitution table and a double-letter substitution table; the value ranges of the input values and output values of the single-letter substitution table are from [0, 25]; the value ranges of the input values and output values of the double-letter substitution table are from [0, 675]; the third substitution table includes: a single-digit substitution table and a double-digit substitution table; the value ranges of the input values and output values of the single-digit substitution table are from [0, 9]; the value ranges of the input values and output values of the double-digit substitution table are from [0, 99]; encrypting the information to be desensitized based on a preset encryption algorithm and at least one substitution table to obtain the encrypted result information, including: when the number of characters in the information to be desensitized is even, encrypting the information to be desensitized based on a preset encryption algorithm and at least one double-digit substitution table, or at least one double-letter substitution table to obtain the encrypted result information; or, when the number of characters in the information to be desensitized is odd, encrypting the information to be desensitized based on a preset encryption algorithm and a first mixed substitution table, or a second mixed substitution table to obtain the encrypted result information; wherein, the first mixed substitution table includes: a single-digit substitution table for encrypting and calculating the highest or lowest bit of the characters in the information to be desensitized, and at least one double-digit substitution table for encrypting and calculating the other characters in the information to be desensitized except the characters calculated by the single-digit substitution table; the second mixed substitution table includes: a single-letter substitution table for encrypting and calculating the highest or lowest bit of the characters in the information to be desensitized, and at least one double-letter substitution table for encrypting and calculating the other characters in the information to be desensitized except the characters calculated by the single-letter substitution table.
[0013] Optionally, the preset encryption algorithm includes: obtaining the flag values corresponding to each character among the multiple characters included in the information to be desensitized; based on the flag values of each character, cyclically using multiple substitution tables in a preset order to encrypt each character among the multiple characters in turn to obtain the encrypted result information corresponding to the information to be desensitized; wherein, the multiple substitution tables are: at least one substitution table; the encrypted result information is obtained based on the encrypted result sub-information corresponding to each character among the multiple characters.
[0014] Optionally, based on the flag values of each character, the characters in the multiple characters are encrypted one by one using multiple substitution tables in a cyclic order according to a preset order to obtain the encrypted result information corresponding to the information to be desensitized, including: obtaining the flag value corresponding to the first ciphertext character used in the current round, and performing a modulo operation on the target sum and the number of arguments of the substitution table used in the current round to obtain the first secret value in the current round; the target sum is: the sum of the flag value corresponding to the first ciphertext character and the second secret value calculated in the previous round; searching in the substitution table used in the current round for the secret value corresponding to the first secret value as the second secret value in the current round, and replacing the first ciphertext character with the second ciphertext character corresponding to the second secret value; wherein, in the case where the current round is the first round, a preset secret value is used as the second secret value calculated in the previous round; the first ciphertext character and the second ciphertext character are characters obtained by encrypting the original character.
[0015] The present application also provides a data desensitization device, including:
[0016] An information acquisition module, configured to acquire an image to be desensitized and matching parameters; the matching parameters include: at least one substitution table corresponding to the information type of the information to be desensitized included in the image to be desensitized, and the encryption iteration times; the substitution table is generated based on a key; an information encryption module, configured to encrypt the information to be desensitized based on the matching parameters to obtain encrypted result information, and replace the information to be desensitized with the encrypted result information to obtain a target image after data desensitization; wherein, the encryption iteration times are used to indicate the number of cyclic transformations of encryption, and in the cyclic transformation process, the at least one substitution table is used to encrypt the information to be desensitized in a preset order.
[0017] Optionally, the acquisition module is specifically configured to acquire the image to be desensitized and identify the information to be desensitized in the image to be desensitized; the acquisition module is specifically further configured to identify the information to be desensitized, determine the information type of the information to be desensitized, and generate at least one substitution table corresponding to the information type of the information to be desensitized.
[0018] Optionally, the information types of the desensitized information include: English characters, digital characters, Chinese characters; the substitution table corresponding to the English characters is the first substitution table; the substitution table corresponding to the Chinese characters is the second substitution table; the substitution table corresponding to the digital characters is the third substitution table.
[0019] Optionally, the information encryption module is specifically configured to encrypt the information to be desensitized based on a preset encryption algorithm and at least one first substitution table to obtain the encrypted result information when the information type of the desensitized information is the English character; the information encryption module is further specifically configured to encrypt the information to be desensitized based on a preset encryption algorithm and at least one second substitution table to obtain the encrypted result information when the information type of the desensitized information is the Chinese character; the information encryption module is further specifically configured to encrypt the information to be desensitized based on a preset encryption algorithm and at least one third substitution table to obtain the encrypted result information when the information type of the desensitized information is the numerical character.
[0020] Optionally, the first substitution table includes: a single-letter substitution table; the value ranges of the input value and the output value of the single-letter substitution table are [0, 25]; the third substitution table includes: a single-digit substitution table; the value ranges of the input value and the output value of the single-digit substitution table are [0, 9]; the information encryption module is specifically configured to encrypt the information to be desensitized based on a preset encryption algorithm and at least one single-letter substitution table, or at least one single-digit substitution table to obtain the encrypted result information.
[0021] Optionally, the first substitution table includes: a single-letter substitution table and a double-letter substitution table; the value ranges of the input values and output values of the single-letter substitution table are [0, 25]; the value ranges of the input values and output values of the double-letter substitution table are [0, 675]; the third substitution table includes: a single-digit substitution table and a double-digit substitution table; the value ranges of the input values and output values of the single-digit substitution table are [0, 9]; the value ranges of the input values and output values of the double-digit substitution table are [0, 99]; the information encryption module is specifically configured to, when the number of characters of the information to be desensitized is even, encrypt the information to be desensitized based on a preset encryption algorithm and at least one double-digit substitution table, or at least one double-letter substitution table, to obtain the encrypted result information; the information encryption module is specifically further configured to, when the number of characters of the information to be desensitized is odd, encrypt the information to be desensitized based on a preset encryption algorithm and a first mixed substitution table, or a second mixed substitution table, to obtain the encrypted result information; wherein, the first mixed substitution table includes: a single-digit substitution table for encrypting and calculating the highest or lowest bit of the characters of the information to be desensitized, and at least one double-digit substitution table for encrypting and calculating the other characters of the information to be desensitized except the characters calculated by the single-digit substitution table; the second mixed substitution table includes: a single-letter substitution table for encrypting and calculating the highest or lowest bit of the characters of the information to be desensitized, and at least one double-letter substitution table for encrypting and calculating the other characters of the information to be desensitized except the characters calculated by the single-letter substitution table.
[0022] Optionally, the information acquisition module is further configured to acquire the flag values corresponding to each of the multiple characters included in the information to be desensitized; the information encryption module is specifically configured to, based on the flag values of each character, sequentially encrypt each of the multiple characters by cyclically using multiple substitution tables in a preset order to obtain the encrypted result information corresponding to the information to be desensitized; wherein, the multiple substitution tables are: at least one substitution table; and the encrypted result information is obtained based on the encrypted result sub-information corresponding to each of the multiple characters.
[0023] Optionally, the information encryption module is specifically configured to obtain a flag value corresponding to the first ciphertext symbol used in the current round, and perform a modulo operation on the target sum and the number of arguments of the substitution table used in the current round to obtain a first secret value in the current round; the target sum is: the sum of the flag value corresponding to the first ciphertext symbol and the second secret value calculated in the previous round; the information encryption module is further specifically configured to look up, in the substitution table used in the current round, a secret value corresponding to the first secret value as the second secret value in the current round, and replace the first ciphertext symbol with the second ciphertext symbol corresponding to the second secret value; wherein, when the current round is the first round, a preset secret value is used as the second secret value calculated in the previous round; the first ciphertext symbol and the second ciphertext symbol are characters obtained by encrypting the original character.
[0024] The present application further provides a computer program product, including a computer program / instructions, which when executed by a processor, implement the steps of the data desensitization method as described in any one of the above.
[0025] The present application further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the program, the steps of the data desensitization method as described in any one of the above are implemented.
[0026] The present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the data desensitization method as described in any one of the above are implemented.
[0027] The data desensitization method and device provided by the present application first obtain a to-be-desensitized image and matching parameters; the matching parameters include: at least one substitution table corresponding to the information type of the to-be-desensitized information included in the to-be-desensitized image, and the encryption iteration times; the substitution table is generated based on a key; then, encrypt the to-be-desensitized information based on the matching parameters to obtain encrypted result information, and replace the to-be-desensitized information with the encrypted result information to obtain a target image after data desensitization; wherein, the encryption iteration times are used to indicate the number of cyclic transformations of encryption, and in the cyclic transformation process, the at least one substitution table is sequentially used to encrypt the to-be-desensitized information according to a preset order. In this way, medical data sharing can be realized without disclosing user privacy information. Since the encryption method can be reversed, the original image information can be restored from the target image after data desensitization when necessary. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] To more clearly illustrate the technical solutions in the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0029] Figure 1 is one of the schematic flowcharts of the data desensitization method provided by the present application;
[0030] Figure 2 is another schematic flowchart of the data desensitization method provided by the present application;
[0031] Figure 3 is the schematic structural diagram of the data desensitization device provided by the present application;
[0032] Figure 4 is the schematic structural diagram of the electronic device provided by the present application. Detailed implementation manners
[0033] To make the objectives, technical solutions and advantages of the present application clearer, the following will clearly and completely describe the technical solutions in the present application with reference to the drawings in the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present application.
[0034] The terms "first", "second", etc. in the description and claims of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. are generally of the same type, and the number of objects is not limited. For example, the first object can be one or more. In addition, "and / or" in the description and claims means at least one of the connected objects, and the character " / " generally means an "or" relationship between the associated objects before and after.
[0035] Medical imaging photos, such as X-ray films, CT photos, magnetic resonance imaging photos, etc., occupy an extremely important position in medical data and are also important content for data exchange and medical research. These medical imaging images are generally stored or transmitted in the form of electronic data files. Information such as patient name, hospital admission number, patient's date of birth, etc. is usually recorded on these images. In particular, the name and hospital admission number are the main privacy of the patient. Based on artificial intelligence search and clipping capabilities, the name and hospital admission number on the film can be directly smeared out, and the image without the name and hospital admission number can be shared freely within the medical system.
[0036] However, if a certain patient has visited multiple hospitals in recent years and taken dozens or even hundreds of images such as X-rays, B-ultrasounds, CTs or MRIs, as well as some images of gastroscopes, colonoscopes, bone density, and electrocardiograms saved in image form. Researchers need to collect and compare and analyze multiple or all the films of this patient. If the name and hospital admission number are simply erased from each image, the images of a specific patient cannot be concentrated together through retrieval and merging with patients with the same name.
[0037] In view of the above technical problems existing in the related art, the embodiments of the present application provide a data desensitization method that can retain the original data format. This method can replace sensitive text or numbers on the image with other text or numbers. When the key is determined and unchanged, the same name is always encrypted into the same string of text, and the same hospital admission number is encrypted into the same string of numbers.
[0038] The following combines the drawings and details the data desensitization method provided by the embodiments of the present application through specific embodiments and their application scenarios.
[0039] As Figure 1 shown, a data desensitization method provided by the embodiments of the present application may include the following steps 101 and 102.
[0040] Step 101, obtain the image to be desensitized and matching parameters.
[0041] Among them, the matching parameters include: at least one substitution table corresponding to the information type of the information to be desensitized included in the image to be desensitized, and the number of encryption iterations. Different information types of the information to be desensitized use different substitution tables. The number of encryption iterations and the number of substitution tables can be the same or different.
[0042] Exemplarily, the above image to be desensitized is a medical image containing sensitive information such as patient name, hospital admission number, date of birth, etc. The above substitution table is used to encrypt characters by looking up the table during the encryption process.
[0043] Exemplarily, the information types of the desensitized information include: English characters, numeric characters, and Chinese characters; the substitution table corresponding to the English characters is the first substitution table; the substitution table corresponding to the Chinese characters is the second substitution table; and the substitution table corresponding to the numeric characters is the third substitution table.
[0044] Exemplarily, taking English characters as an example, the form of the first substitution table corresponding to English characters is shown in Table 1 below:
[0045]
[0046]
[0047] Table 1
[0048] Among them, the flag value is used to represent the natural sorting of each letter; the order of the first secret value and the flag value can be the same or different; the order of the first secret value and the flag value can be the same or different; the second secret value has a one-to-one correspondence with the first secret value.
[0049] It should be noted that in the actual application process, the flag value can be input into the substitution table to directly obtain the output result, that is, the above-mentioned second secret value. In the embodiments of the present application, for the convenience of understanding, the description of the ciphertext symbol and the first secret value is added to the substitution table to more clearly illustrate the relationship between the ciphertext symbol, the flag value, the first secret value, and the second secret value.
[0050] Specifically, step 101 may further include the following steps 101a1 and 101a2.
[0051] Step 101a1: Obtain the image to be desensitized, and identify the information to be desensitized in the image to be desensitized.
[0052] Exemplarily, the above-mentioned information to be desensitized includes sensitive information such as patient name, hospital admission number, and date of birth.
[0053] Step 102a2: Identify the information to be desensitized, determine the information type of the information to be desensitized, and generate at least one substitution table corresponding to the information type of the information to be desensitized.
[0054] Exemplarily, in the embodiments of the present application, the information to be desensitized and the information type of the information to be desensitized in the image to be desensitized can be identified by means of image recognition, and a corresponding substitution table can be generated according to the information type of the information to be desensitized. At the same time, the number of substitution tables can be reasonably selected according to the information type and the set security level. If encrypting numbers, if a 10-element substitution table (substituting numbers between 0-9 with numbers between 0-9) is used, the exhaustive amount of each substitution table is 10! = 3628800 ≈ 2 21.79。If 6 ten - yuan substitution tables are used, the total amount of substitution table information is (10!) 6 ≈2 130.75 。The key amount reaches no less than 2 128 ,Therefore, 6 ten - yuan substitution tables can meet the basic security requirements. If one 100 - yuan substitution table (substituting numbers between 0 - 99 with numbers between 0 - 99) and one ten - yuan substitution table are used, the exhaustive search amount of the 100 - yuan substitution table is 100! ≈ 2 524.76 ,which not only meets the basic security, but also reaches the advanced security requirement that the key amount is no less than 2 256 。If encrypting English letters, the exhaustive search amount of two 26 - letter substitution tables is (26!) 2 ≈2 176.76 , two 26 - letter substitution tables can meet the basic security requirements. Three 26 - letter substitution tables can meet the advanced security requirements. If encrypting Chinese characters, there are about 7000 common Chinese characters. Because the substitution table is large, one table can meet the advanced security requirements.
[0055] It should be noted that the above - mentioned encryption iteration times can be preset or adjusted according to security requirements. The higher the security requirements, the larger the encryption iteration times.
[0056] Step 102: Encrypt the information to be desensitized based on the matching parameters to obtain encrypted result information, and replace the information to be desensitized with the encrypted result information to obtain the target image after data desensitization.
[0057] Among them, the encryption iteration times are used to indicate the number of cyclic transformations in the encryption process, and in the cyclic transformation process, at least one substitution table is used to encrypt the information to be desensitized in a preset order.
[0058] Exemplarily, after obtaining the above - mentioned matching parameters and the information to be desensitized, the information to be desensitized can be encrypted using the matching parameters to obtain encrypted result information. Then, a specific deep - learning network model can be used to replace the information to be desensitized in the image to be desensitized with the encrypted result information and generate a new target image.
[0059] Specifically, in step 102 above, for the information type of the information to be desensitized, it can include any one of the following steps 102a, 102b, and 102c.
[0060] Step 102a: When the information type of the desensitized information is the English character, encrypt the information to be desensitized based on a preset encryption algorithm and at least one first substitution table to obtain the encrypted result information.
[0061] Step 102b: When the information type of the desensitized information is the Chinese characters, encrypt the information to be desensitized based on a preset encryption algorithm and at least one second replacement table to obtain the encryption result information.
[0062] Step 102c: when the information type of the desensitized information is the numeric characters, encrypt the information to be desensitized based on a preset encryption algorithm and at least one third replacement table to obtain the encryption result information.
[0063] For example, in the embodiment of the present application, the above Table 1 is used as an example to encrypt the desensitized information based on the matching parameters in the implementation of the present application to obtain the encrypted result information. If there is a name "Zhang San" in the form of Chinese pinyin in the image, several first replacement tables are generated in the above steps, and the number of first replacement tables is the same as the number of encryption iterations. For example, 3 26-element replacement tables (not distinguishing between uppercase and lowercase English letters) are used, and the number of encryption iterations is 5, that is, each character position is encrypted and replaced 5 times.
[0064] When replacing the first letter Z in the string "Zhang San", because no ciphertext symbol (i.e., the letter obtained in the last replacement) has been generated, at this time, the value 0 can be used as the flag value corresponding to the ciphertext symbol obtained in the last replacement. The flag value of the letter Z is 25. Using the flag value of Z and the flag value corresponding to the ciphertext symbol obtained in the last replacement, we can get 25+0mod 26=25 (i.e., the first secret value shown in Table 1). Use the first secret value 25 to find the corresponding second secret value from the first 26-element replacement table. Assuming that the second secret value corresponding to the first secret value 25 found in the replacement table is 10, then based on the second secret value and the flag value, the letter corresponding to the flag value 25 that matches the second secret value 25 is k. That is, the letter obtained after the letter Z is replaced is k.
[0065] After that, the second letter h (with a flag value of 7) is replaced, and the flag value 10 of the ciphertext symbol k obtained by the previous replacement is calculated to obtain the first secret value corresponding to the letter h: 7+10mod 26=17. The first secret value 17 is used to find the corresponding second secret value from the second 26-element replacement table. Assuming that the second secret value corresponding to the first secret value 17 is 18 found in the replacement table, based on the second secret value and the flag value, the letter corresponding to the flag value 18 that matches the second secret 18 is s, that is, the letter obtained after the letter h is replaced is s.
[0066] Next, replace the third letter 'a' (flag value is 0). Calculate using the flag value 18 of the ciphertext symbol s obtained from the previous replacement. The first secret value corresponding to this letter 'a' can be obtained as: 0 + 18 mod 26 = 26. Use this first secret value 26 to look up the corresponding second secret value in the third 26 - element substitution table. Assume that the second secret value found in this substitution table corresponding to the first secret value 26 is 20. Then, based on the matching of this second secret value and the flag value, the letter corresponding to the flag value 20 that matches this second secret 20 is 'u'. That is, the letter obtained after replacing the letter 'a' is 'u'.
[0067] After that, replace the fourth letter 'n' (flag value is 13). Calculate using the flag value 20 of the ciphertext symbol 'u' obtained from the previous replacement. The first secret value corresponding to this letter 'n' can be obtained as: 13 + 20 mod 26 = 7. Use this first secret value 7 to look up the corresponding second secret value in the first 26 - element substitution table (since there are a total of three substitution tables and they need to be used in turn). Assume that the second secret value found in this substitution table corresponding to the first secret value 7 is 24. Then, based on the matching of this second secret value and the flag value, the letter corresponding to the flag value 24 that matches this second secret value 24 is 'y'. That is, the letter obtained after replacing the letter 'n' is 'y'.
[0068] Replace each letter in turn according to the above steps until replacing the eighth letter 'n' (flag value is 13). Assume that the letter obtained after replacing this letter 'n' is 'c' (flag value is 2). Next, perform the second - round substitution. Replace the first letter 'k' (flag value is 10) after the previous - round substitution. The flag value 2 of the last ciphertext symbol 'c' in the previous time, …… until the fifth - round substitution is completed. Take the finally obtained 8 ciphertext symbols as the ciphertext of the string "Zhang San", where the first and sixth letters can be in uppercase (maintaining the case position of the plaintext). The above is described by taking the example of using 3 26 - element substitution tables. When using 2 26 - element substitution tables, the exhaustive hypothesis amount of the table is (26!)^2≈2 176.76 , which is also secure enough.
[0069] For example, if using a double - letter substitution table, using only one 676 - element substitution table is secure enough. Divide "ZhangSan" into 4 parts with flag values: 'Zh' corresponding to the value 657, 'an' corresponding to the value 13, 'gS' corresponding to the value 174, and 'an' corresponding to the value 13. According to the logical architecture shown in Figure 2 , with (657, 13, 174, 13) as the initial input state, perform N - round iterative transformation. After converting the finally obtained flag values (c1, c2, c3, c4) into letters, use them as the ciphertext of the string "Zhang San".
[0070] It should be noted that there are more than 7,000 common Chinese characters. One or more substitution tables corresponding to the character set can be set by the secret key. And using a method similar to the above, encrypt the Chinese name of the patient according to the above steps. If the number of elements in the substitution table is 7,030, the modulus for addition is 7,030. If there is a rare Chinese character in a patient's name that is not among the 7,030 Chinese characters, let it remain unchanged (equivalent to substituting itself with itself).
[0071] Optionally, in the embodiments of the present application, when encrypting digital characters, a single-digit substitution table and a double-digit substitution table can be used for encryption.
[0072] Exemplarily, the third substitution table includes: a single-digit substitution table and a double-digit substitution table; the value ranges of the input values and output values of the single-digit substitution table are [0, 9], that is, {0, 1, 2, 3, 4, 5, 6, 7, 8, 9}; the value ranges of the input values and output values of the double-digit substitution table are [0, 99], that is, {0, 1, 2, 3…, 99}.
[0073] It should be noted that the above third substitution table can also include a multi-digit substitution table, that is, the input values and output values of the substitution table can be three-digit or multi-digit numbers. For example, when the input value is 2,345, the output value can be 6,572.
[0074] Specifically, when using the single-digit substitution table to encrypt the information to be desensitized, step 102c above can further include the following step 102c1.
[0075] Step 102c1: Encrypt the information to be desensitized based on a preset encryption algorithm and at least one single-digit substitution table to obtain the encrypted result information.
[0076] Exemplarily, if a string of numbers is to be encrypted and a 10-element substitution table with multiple 0-9 as the input and output is used to encrypt it, the encryption can be performed in the encryption manner in the above example.
[0077] Exemplarily, when using the double-digit substitution table to encrypt the information to be desensitized, the parity of the number of characters of the information to be desensitized needs to be considered. When the number of characters of the information to be desensitized is even, the double-digit substitution table can be used alone to encrypt the information to be desensitized; when the number of characters of the information to be desensitized is odd, the double-digit substitution table and the single-digit substitution table can be used in combination to encrypt the information to be desensitized.
[0078] Specifically, step 102c above can further include the following step 102c2 or step 102c3.
[0079] Step 102c2: When the number of characters of the information to be desensitized is even, encrypt the information to be desensitized based on a preset encryption algorithm and at least one even-number substitution table to obtain the encrypted result information.
[0080] Step 102c3: When the number of characters of the information to be desensitized is odd, encrypt the information to be desensitized based on a preset encryption algorithm and at least one mixed substitution table to obtain the encrypted result information.
[0081] Among them, the mixed substitution table includes: a single-number substitution table for transforming the highest or lowest bit of the characters of the information to be desensitized, and at least one even-number substitution table for transforming the remaining characters of the characters of the information to be desensitized.
[0082] Exemplarily, if the length of the encrypted digital string is odd, it can be agreed that the highest or lowest bit uses a 10-element substitution table (i.e., the above single-number substitution table), and every two bits of the other bits are regarded as a change unit, using a 100-element substitution table (i.e., the above even-number substitution table). If all use the 10-element substitution table, at least 6 10-element tables should be set, otherwise the key change amount may be insufficient. When using a 100-element substitution table that can process two digits at a time, only one 100-element substitution table can be used to provide 100! ≈ 2 524.76 of the exhaustive calculation amount.
[0083] Specifically, the preset encryption algorithm used in the above step 102 may include the following steps 102d and 102e.
[0084] Step 102d: Obtain the flag value corresponding to each character among the multiple characters included in the information to be desensitized.
[0085] Step 102e: Based on the flag values of each character, cyclically use multiple substitution tables in a preset order to encrypt each character among the multiple characters in turn to obtain the encrypted result information corresponding to the information to be desensitized.
[0086] Among them, the multiple substitution tables are: at least one substitution table; the encrypted result information is obtained based on the encrypted result sub-information corresponding to each character among the multiple characters.
[0087] Specifically, based on the encryption steps described in the above example, the above step 102e may further include the following steps 102e1 and 102e2.
[0088] Step 102e1: Obtain the flag value corresponding to the first ciphertext character used in the current round, and perform a modulo operation on the sum of the flag value corresponding to the first ciphertext character and the second secret value calculated in the previous round with the number of variables of the substitution table used in the current round to obtain the first secret value of the current round.
[0089] Exemplarily, the substitution tables used in different rounds may be the same or different.
[0090] Step 102e2: Search for the secret value corresponding to the first secret value from the substitution table used in the current round as the second secret value of the current round, and replace the first ciphertext symbol with the second ciphertext symbol corresponding to the second secret value.
[0091] Wherein, when the current round is the first round, a preset secret value is used as the second secret value calculated in the previous round; the first ciphertext symbol and the second ciphertext symbol are characters obtained by encrypting the original characters.
[0092] Exemplarily, after encrypting the information to be desensitized according to the above steps 102e1 and 102e2, the ciphertext symbols corresponding to each character can be obtained, and the encrypted result information can be obtained after combination. Then, the encrypted digital text or digital result can be converted into text or numbers in the form of pictures and pasted to the corresponding positions of the pictures being processed.
[0093] It should be noted that in the data desensitization method in the embodiments of the present application, with the same key, the same substitution table as that in encryption can be generated. Decryption is achieved by starting from the last encrypted character in reverse order, searching the substitution table in reverse, and subtracting the value of the previous ciphertext character from the found result.
[0094] It should be noted that in addition to processing medical image photos or pictures, prescriptions in the pharmacy can also be processed. A prescription is usually saved as a file, such as in the word, wps or excel format, etc. Hospital staff can open the file, check or modify the information, and then save the file again. Today's artificial intelligence technology can fully imitate human behavior, open the file with a suitable format tool, find the information involving privacy such as name, outpatient number or inpatient number, encrypt these sensitive information while retaining the format, and then save the document again. If the information such as name, outpatient number or inpatient number is simply erased or adjusted to the symbol *, it will be inconvenient for subsequent statistical analysis. For example, randomly select 100 patients and calculate the number of times each person has prescribed medicine and the cumulative amount of medicine fees in the past three years. The above encryption method can ensure that the same name is encrypted into the same encrypted name, and the names of two different encrypted names are different after decryption.
[0095] The data desensitization method provided by the embodiment of the present application first obtains a to-be-desensitized image and matching parameters; the matching parameters include at least one substitution table corresponding to the information type of the to-be-desensitized information contained in the to-be-desensitized image, and the number of encryption iterations; the substitution table is generated based on a key; then, encrypts the to-be-desensitized information based on the matching parameters to obtain encrypted result information, and replaces the to-be-desensitized information with the encrypted result information to obtain a target image after data desensitization; wherein, the number of encryption iterations is used to indicate the number of cyclic transformations of encryption, and in the cyclic transformation process, the at least one substitution table is used to encrypt the to-be-desensitized information in a preset order. In this way, the sharing of medical data can be realized without disclosing the user's private information, and the original image can be restored from the target image after data desensitization by the holder of the key.
[0096] It should be noted that for the data desensitization method provided by the embodiment of the present application, the execution subject may be a data desensitization device, or a control module in the data desensitization device for executing the data desensitization method. In the embodiment of the present application, the data desensitization method executed by the data desensitization device is taken as an example to illustrate the data desensitization device provided by the embodiment of the present application.
[0097] It should be noted that in the embodiment of the present application, the data desensitization methods shown in the above-mentioned various method drawings are all exemplified by combining one drawing in the embodiment of the present application. Specifically, when implemented, the data desensitization methods shown in the above-mentioned various method drawings can also be implemented in combination with any other drawings that can be combined as shown in the above-mentioned embodiments, which will not be elaborated here.
[0098] The data desensitization device provided by the present application will be described below, and the description below can be mutually referred to the data desensitization method described above.
[0099] Figure 3 is a schematic structural diagram of the data desensitization device provided by the embodiment of the present application, as Figure 3 shown, and specifically includes the following content.
[0100] An information acquisition module 301 for acquiring a to-be-desensitized image and matching parameters; the matching parameters include at least one substitution table corresponding to the information type of the to-be-desensitized information contained in the to-be-desensitized image, and the number of encryption iterations; the substitution table is generated based on a key; an information encryption module 302 for encrypting the to-be-desensitized information based on the matching parameters to obtain encrypted result information, and replacing the to-be-desensitized information with the encrypted result information to obtain a target image after data desensitization; wherein, the number of encryption iterations is used to indicate the number of cyclic transformations of encryption, and in the cyclic transformation process, the at least one substitution table is used to encrypt the to-be-desensitized information in a preset order.
[0101] Optionally, the obtaining module is specifically configured to obtain the image to be desensitized and identify the information to be desensitized in the image to be desensitized; the obtaining module is further specifically configured to identify the information to be desensitized, determine the information type of the information to be desensitized, and generate at least one substitution table corresponding to the information type of the information to be desensitized.
[0102] Optionally, the information types of the desensitization information include: English characters, numeric characters, and Chinese characters; the substitution table corresponding to the English characters is the first substitution table; the substitution table corresponding to the Chinese characters is the second substitution table; the substitution table corresponding to the numeric characters is the third substitution table.
[0103] Optionally, when the information type of the desensitization information is the English characters, the information encryption module 302 is specifically configured to encrypt the information to be desensitized based on a preset encryption algorithm and at least one first substitution table to obtain the encrypted result information; when the information type of the desensitization information is the Chinese characters, the information encryption module 302 is further specifically configured to encrypt the information to be desensitized based on a preset encryption algorithm and at least one second substitution table to obtain the encrypted result information; when the information type of the desensitization information is the numeric characters, the information encryption module 302 is further specifically configured to encrypt the information to be desensitized based on a preset encryption algorithm and at least one third substitution table to obtain the encrypted result information.
[0104] Optionally, the first substitution table includes: a single-letter substitution table; the value ranges of the input value and the output value of the single-letter substitution table are [0, 25]; the third substitution table includes: a single-digit substitution table; the value ranges of the input value and the output value of the single-digit substitution table are [0, 9]; the information encryption module 302 is specifically configured to encrypt the information to be desensitized based on a preset encryption algorithm and at least one single-letter substitution table, or at least one single-digit substitution table to obtain the encrypted result information.
[0105] Optionally, the first substitution table includes: a single-letter substitution table and a double-letter substitution table; the value ranges of the input values and output values of the single-letter substitution table are [0, 25]; the value ranges of the input values and output values of the double-letter substitution table are [0, 675]; the third substitution table includes: a single-digit substitution table and a double-digit substitution table; the value ranges of the input values and output values of the single-digit substitution table are [0, 9]; the value ranges of the input values and output values of the double-digit substitution table are [0, 99]; the information encryption module 302 is specifically configured to, when the number of characters in the information to be desensitized is even, encrypt the information to be desensitized based on a preset encryption algorithm and at least one double-digit substitution table, or at least one double-letter substitution table, to obtain the encrypted result information; the information encryption module 302 is further specifically configured to, when the number of characters in the information to be desensitized is odd, encrypt the information to be desensitized based on a preset encryption algorithm and the first mixed substitution table, or the second mixed substitution table, to obtain the encrypted result information; wherein, the first mixed substitution table includes: a single-digit substitution table for encrypting and calculating the highest or lowest bit of the characters in the information to be desensitized, and at least one double-digit substitution table for encrypting and calculating the other characters in the information to be desensitized except the characters calculated by the single-digit substitution table; the second mixed substitution table includes: a single-letter substitution table for encrypting and calculating the highest or lowest bit of the characters in the information to be desensitized, and at least one double-letter substitution table for encrypting and calculating the other characters in the information to be desensitized except the characters calculated by the single-letter substitution table.
[0106] Optionally, the information acquisition module 301 is further configured to acquire the flag value corresponding to each character in the multiple characters included in the information to be desensitized; the information encryption module 302 is specifically configured to, based on the flag value of each character, sequentially encrypt each character in the multiple characters by cyclically using multiple substitution tables in a preset order to obtain the encrypted result information corresponding to the information to be desensitized; wherein, the multiple substitution tables are: at least one substitution table; and the encrypted result information is obtained based on the encrypted result sub-information corresponding to each character in the multiple characters.
[0107] Optionally, the information encryption module 302 is specifically configured to obtain a flag value corresponding to a first ciphertext symbol used in the current round, and perform a modulo operation on the target sum and the number of arguments of the substitution table used in the current round to obtain a first secret value in the current round; the target sum is: the sum of the flag value corresponding to the first ciphertext symbol and the second secret value calculated in the previous round; the information encryption module 302 is specifically further configured to look up, in the substitution table used in the current round, a secret value corresponding to the first secret value as the second secret value in the current round, and replace the first ciphertext symbol with a second ciphertext symbol corresponding to the second secret value; wherein, when the current round is the first round, a preset secret value is used as the second secret value calculated in the previous round; the first ciphertext symbol and the second ciphertext symbol are characters obtained by encrypting the original character.
[0108] The data desensitization device provided in this application first obtains a to-be-desensitized image and matching parameters; the matching parameters include: at least one substitution table corresponding to the information type of the to-be-desensitized information included in the to-be-desensitized image, and the encryption iteration times; the substitution table is generated based on a key; then, encrypts the to-be-desensitized information based on the matching parameters to obtain encrypted result information, and replaces the to-be-desensitized information with the encrypted result information to obtain a target image after data desensitization; wherein, the encryption iteration times are used to indicate the number of cyclic transformations of encryption, and in the cyclic transformation process, the at least one substitution table is sequentially used to encrypt the to-be-desensitized information according to a preset order. In this way, medical data can be shared without disclosing user privacy information, and the original image can be restored from the target image after data desensitization by the holder of the key.
[0109] Figure 4 An example of a schematic physical structure diagram of an electronic device is shown in Figure 4As shown in the figure, the electronic device may include: a processor 410, a communications interface 420, a memory 430, and a communication bus 440. Among them, the processor 410, the communications interface 420, and the memory 430 complete communication with each other through the communication bus 440. The processor 410 may call the logical instructions in the memory 430 to execute a data desensitization method, which includes: obtaining an image to be desensitized and matching parameters; the matching parameters include: at least one substitution table corresponding to the information type of the information to be desensitized included in the image to be desensitized, and the number of encryption iterations; the substitution table is generated based on a key; encrypting the information to be desensitized based on the matching parameters to obtain encrypted result information, and replacing the information to be desensitized with the encrypted result information to obtain a target image after data desensitization; where the number of encryption iterations is used to indicate the number of cyclic transformations of encryption, and in the cyclic transformation process, the at least one substitution table is used to encrypt the information to be desensitized in a preset order.
[0110] In addition, when the logical instructions in the above-mentioned memory 430 are implemented in the form of software functional units and sold or used as an independent product, they may be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, may be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.
[0111] On the other hand, the present application also provides a computer program product, which includes a computer program stored on a computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the data desensitization method provided by each of the above methods. The method includes: obtaining a to-be-desensitized image and matching parameters; the matching parameters include: at least one substitution table corresponding to the information type of the to-be-desensitized information included in the to-be-desensitized image, and the encryption iteration times; the substitution table is generated based on a key; encrypting the to-be-desensitized information based on the matching parameters to obtain encrypted result information, and replacing the to-be-desensitized information with the encrypted result information to obtain a target image after data desensitization; wherein, the encryption iteration times are used to indicate the number of cyclic transformations of encryption, and in the cyclic transformation process, the at least one substitution table is sequentially used to encrypt the to-be-desensitized information according to a preset order.
[0112] In another aspect, the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it is configured to execute the data desensitization method provided by each of the above. The method includes: obtaining a to-be-desensitized image and matching parameters; the matching parameters include: at least one substitution table corresponding to the information type of the to-be-desensitized information included in the to-be-desensitized image, and the encryption iteration times; the substitution table is generated based on a key; encrypting the to-be-desensitized information based on the matching parameters to obtain encrypted result information, and replacing the to-be-desensitized information with the encrypted result information to obtain a target image after data desensitization; wherein, the encryption iteration times are used to indicate the number of cyclic transformations of encryption, and in the cyclic transformation process, the at least one substitution table is sequentially used to encrypt the to-be-desensitized information according to a preset order.
[0113] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0114] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0115] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, and are not intended to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A data desensitization method, characterized in that, Including: Obtaining an image to be desensitized and matching parameters; The matching parameters include: at least one substitution table corresponding to the information type of the information to be desensitized included in the image to be desensitized, and the number of encryption iterations; the substitution table is generated based on a key; Encrypting the information to be desensitized based on the matching parameters to obtain encrypted result information, and replacing the information to be desensitized with the encrypted result information to obtain a target image after data desensitization; Wherein, the number of encryption iterations is used to indicate the number of cyclic transformations of encryption, and in the cyclic transformation process, the at least one substitution table is sequentially used to encrypt the information to be desensitized according to a preset order; the information types of the desensitized information include: English characters, numerical characters; the substitution table corresponding to the English characters is the first substitution table; the substitution table corresponding to the numerical characters is the third substitution table; the first substitution table includes: a single-letter substitution table and a double-letter substitution table; the third substitution table includes: a single-digit substitution table and a double-digit substitution table; The encrypting the information to be desensitized based on the matching parameters to obtain encrypted result information includes: When the number of characters of the information to be desensitized is even, encrypting the information to be desensitized based on a preset encryption algorithm and at least one double-digit substitution table, or at least one double-letter substitution table to obtain the encrypted result information; Or, When the number of characters of the information to be desensitized is odd, encrypting the information to be desensitized based on a preset encryption algorithm and a first mixed substitution table, or a second mixed substitution table to obtain the encrypted result information; Wherein, the first mixed substitution table includes: a single-digit substitution table for encrypting and calculating the highest or lowest bit of the characters of the information to be desensitized, and at least one double-digit substitution table for encrypting and calculating the other characters of the information to be desensitized except the characters calculated by the single-digit substitution table; the second mixed substitution table includes: a single-letter substitution table for encrypting and calculating the highest or lowest bit of the characters of the information to be desensitized, and at least one double-letter substitution table for encrypting and calculating the other characters of the information to be desensitized except the characters calculated by the single-letter substitution table.
2. The method according to claim 1, wherein The obtaining the image to be desensitized and matching parameters includes: Obtaining the image to be desensitized and identifying the information to be desensitized in the image to be desensitized; Identifying the information to be desensitized, determining the information type of the information to be desensitized, and generating at least one substitution table corresponding to the information type of the information to be desensitized.
3. The method according to claim 1 or 2, characterized in that The information types of the desensitized information further include: Chinese characters; the substitution table corresponding to the Chinese characters is the second substitution table.
4. The method according to claim 3, wherein The encrypting the information to be desensitized based on the matching parameters to obtain encrypted result information includes: When the information type of the desensitized information is the English characters, encrypting the information to be desensitized based on a preset encryption algorithm and at least one first substitution table to obtain the encrypted result information; Or, When the information type of the desensitized information is the Chinese character, encrypt the information to be desensitized based on a preset encryption algorithm and at least one second substitution table to obtain the encrypted result information; Or, When the information type of the desensitized information is the numeric character, encrypt the information to be desensitized based on a preset encryption algorithm and at least one third substitution table to obtain the encrypted result information.
5. The method according to claim 4, wherein The first substitution table includes: a single-letter substitution table; the value ranges of the input value and the output value of the single-letter substitution table are [0, 25]; the third substitution table includes: a single-digit substitution table; the value ranges of the input value and the output value of the single-digit substitution table are [0, 9]; The encrypting the information to be desensitized based on a preset encryption algorithm and at least one substitution table to obtain the encrypted result information includes: Encrypting the information to be desensitized based on a preset encryption algorithm and at least one single-letter substitution table, or at least one single-digit substitution table to obtain the encrypted result information.
6. The method according to claim 4, characterized in that, The value ranges of the input value and the output value of the single-letter substitution table are [0, 25]; the value ranges of the input value and the output value of the double-letter substitution table are [0, 675]; the value ranges of the input value and the output value of the single-digit substitution table are [0, 9]; The value ranges of the input value and the output value of the double-digit substitution table are [0, 99].
7. The method according to any one of claims 4 to 6, characterized in that The preset encryption algorithm includes: Obtaining the flag value corresponding to each character in the multiple characters included in the information to be desensitized; Based on the flag values of each character, cyclically use multiple substitution tables in a preset order to encrypt each character in the multiple characters in turn to obtain the encrypted result information corresponding to the information to be desensitized; Wherein, the multiple substitution tables are: at least one substitution table; the encrypted result information is obtained based on the encrypted result sub-information corresponding to each character in the multiple characters.
8. The method according to claim 7, characterized in that The cyclically using multiple substitution tables in a preset order to encrypt each character in the multiple characters based on the flag values of each character to obtain the encrypted result information corresponding to the information to be desensitized includes: Obtaining the flag value corresponding to the first ciphertext character used in the current round, and performing a modulo operation on the target sum and the number of arguments of the substitution table used in the current round to obtain the first secret value in the current round; the target sum is: the sum of the flag value corresponding to the first ciphertext character and the second secret value calculated in the previous round; Searching in the substitution table used in the current round for the secret value corresponding to the first secret value as the second secret value in the current round, and replacing the first ciphertext character with the second ciphertext character corresponding to the second secret value; Wherein, when the current round is the first round, a preset secret value is used as the second secret value calculated in the previous round; the first ciphertext character and the second ciphertext character are characters obtained by encrypting the original character.
9. A data desensitization device, characterized in that, The device includes: An information acquisition module, configured to acquire an image to be desensitized and matching parameters; the matching parameters include: at least one substitution table corresponding to the information type of the information to be desensitized included in the image to be desensitized, and the number of encryption iterations; the substitution table is generated based on a key. An information encryption module, configured to encrypt the information to be desensitized based on the matching parameters to obtain encrypted result information, and replace the information to be desensitized with the encrypted result information to obtain a target image after data desensitization. Wherein, the number of encryption iterations is used to indicate the number of cyclic transformations of encryption, and in the cyclic transformation process, the at least one substitution table is sequentially used to encrypt the information to be desensitized according to a preset order; the information types of the desensitized information include: English characters, numerical characters; the substitution table corresponding to the English characters is the first substitution table; the substitution table corresponding to the numerical characters is the third substitution table; the first substitution table includes: a single-letter substitution table and a double-letter substitution table; the third substitution table includes: a single-digit substitution table and a double-digit substitution table. The information encryption module is specifically configured to, when the number of characters of the information to be desensitized is even, encrypt the information to be desensitized based on a preset encryption algorithm and at least one double-digit substitution table, or at least one double-letter substitution table, to obtain the encrypted result information. The information encryption module is specifically further configured to, when the number of characters of the information to be desensitized is odd, encrypt the information to be desensitized based on a preset encryption algorithm and a first mixed substitution table, or a second mixed substitution table, to obtain the encrypted result information. Wherein, the first mixed substitution table includes: a single-digit substitution table for encrypting and calculating the highest or lowest bit of the characters of the information to be desensitized, and at least one double-digit substitution table for encrypting and calculating the other characters of the characters of the information to be desensitized except the characters calculated by the single-digit substitution table; the second mixed substitution table includes: a single-letter substitution table for encrypting and calculating the highest or lowest bit of the characters of the information to be desensitized, and at least one double-letter substitution table for encrypting and calculating the other characters of the characters of the information to be desensitized except the characters calculated by the single-letter substitution table.
10. The device according to claim 9, wherein The acquisition module is specifically configured to acquire the image to be desensitized and identify the information to be desensitized in the image to be desensitized. The acquisition module is specifically further configured to identify the information to be desensitized, determine the information type of the information to be desensitized, and generate at least one substitution table corresponding to the information type of the information to be desensitized.
11. The device according to claim 9 or 10, characterized in that, The information types of the desensitized information further include: Chinese characters; the substitution table corresponding to the Chinese characters is the second substitution table.
12. The device according to claim 11, wherein The information encryption module is specifically configured to, when the information type of the desensitized information is the English characters, encrypt the information to be desensitized based on a preset encryption algorithm and at least one first substitution table, to obtain the encrypted result information. The information encryption module is further configured to, when the information type of the desensitized information is the Chinese character, encrypt the information to be desensitized based on a preset encryption algorithm and at least one second substitution table to obtain the encrypted result information; The information encryption module is further configured to, when the information type of the desensitized information is the numeric character, encrypt the information to be desensitized based on a preset encryption algorithm and at least one third substitution table to obtain the encrypted result information.
13. The device according to claim 12, characterized in that, The first substitution table includes: a single-letter substitution table; the value ranges of the input value and the output value of the single-letter substitution table are [0, 25]; the third substitution table includes: a single-digit substitution table; the value ranges of the input value and the output value of the single-digit substitution table are [0, 9]; The information encryption module is specifically configured to encrypt the information to be desensitized based on a preset encryption algorithm and at least one single-letter substitution table or at least one single-digit substitution table to obtain the encrypted result information.
14. The device according to claim 12, characterized in that, The value ranges of the input value and the output value of the single-letter substitution table are [0, 25]; the value ranges of the input value and the output value of the double-letter substitution table are [0, 675]; the value ranges of the input value and the output value of the single-digit substitution table are [0, 9]; The value ranges of the input value and the output value of the double-digit substitution table are [0, 99].
15. The device according to any one of claims 12 to 14, wherein The information acquisition module is further configured to acquire a flag value corresponding to each character among the multiple characters included in the information to be desensitized; The information encryption module is specifically configured to, based on the flag values of the respective characters, cyclically use a plurality of substitution tables in a preset order to encrypt each of the plurality of characters in turn to obtain the encrypted result information corresponding to the information to be desensitized; wherein, the plurality of substitution tables are: at least one substitution table; and the encrypted result information is obtained based on encrypted result sub-information corresponding to each of the plurality of characters.
16. The device according to claim 15, wherein The information encryption module is specifically configured to acquire the flag value corresponding to the first ciphertext character used in the current round, and perform a modulo operation on the target sum and the number of arguments of the substitution table used in the current round to obtain the first secret value of the current round; the target sum is: the sum of the flag value corresponding to the first ciphertext character and the second secret value calculated in the previous round; The information encryption module is further specifically configured to find, from the substitution table used in the current round, the secret value corresponding to the first secret value as the second secret value of the current round, and replace the first ciphertext character with the second ciphertext character corresponding to the second secret value; wherein, when the current round is the first round, a preset secret value is used as the second secret value calculated in the previous round; the first ciphertext character and the second ciphertext character are characters obtained by encrypting the original character.
17. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the steps of the data desensitization method according to any one of claims 1 to 8.
18. A computer-readable storage medium, characterized in that, A computer program is stored thereon. When the computer program is executed by a processor, it implements the steps of the data desensitization method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Desensitization and restoration method and system for webpage screenshots
CN113806806A
Information processing method and device
CN115391826A
Data processing method and device, equipment and medium
CN118133323A