Method and apparatus for identifying sensitive data
By specifying the target data source and sensitive data identification rules on the task creation page, and combining data classification and security level configuration, the problem of low efficiency and low accuracy in identifying sensitive data by financial institutions is solved, and efficient and accurate sensitive data identification and management are achieved.
Patent Information
- Application Number
- CN202411328205.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-23
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2044-09-23
AI Technical Summary
In existing technologies, financial institutions face problems such as low efficiency and accuracy in identifying sensitive data, and difficulty in comprehensively hierarchically managing data tables.
By creating a sensitive data identification task on the task creation page, specifying the target data source and sensitive data identification rules, the target sensitive data is identified from the data to be identified using the target sensitive data identification rules. This includes sequentially traversing multiple identification sub-rules for matching, and combining data classification and security level configuration to ensure the targeting and accuracy of the identification.
It enables efficient and accurate identification of sensitive data, avoids omissions and misjudgments, improves identification efficiency, ensures data security and compliance, and can promptly detect and handle potential data leakage risks.
Smart Images

Figure CN119294402B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of data processing technology, and in particular to a method and apparatus for identifying sensitive data. Background Technology
[0002] With the deepening of digital transformation and the explosive growth of data volume, financial institutions are facing increasingly severe data security challenges. In order to protect customer privacy, comply with strict financial regulatory requirements, and prevent data breaches and misuse, financial institutions must strengthen the identification and management of sensitive data. By accurately identifying sensitive data, financial institutions can formulate targeted protection measures to ensure the security and compliance of data in all aspects of collection, storage, processing, transmission, and sharing. Therefore, accurately identifying sensitive data is of paramount importance. Summary of the Invention
[0003] This disclosure provides a method and apparatus for identifying sensitive data, thereby at least partially addressing one of the technical problems in related technologies. The technical solution of this disclosure is as follows:
[0004] According to a first aspect of the present disclosure, a method for identifying sensitive data is provided, comprising: in response to a task creation operation, creating a sensitive data identification task on a task creation page, wherein the sensitive data identification task includes a target data source and a target sensitive data identification rule, the target sensitive data identification rule being obtained based on target data classification and at least one target data security classification configuration; in response to a triggering operation of a target control on the task creation page, executing the sensitive data identification task to obtain data to be identified from the target data source; and using the target sensitive data identification rule to identify target sensitive data from the data to be identified.
[0005] According to a second aspect of the present disclosure, a sensitive data identification device is provided, comprising: a creation module, configured to create a sensitive data identification task on a task creation page in response to a task creation operation, wherein the sensitive data identification task includes a target data source and a target sensitive data identification rule, the target sensitive data identification rule being obtained based on target data classification and at least one target data security classification configuration; an execution module, configured to execute the sensitive data identification task in response to a trigger operation of a target control on the task creation page, to obtain data to be identified from the target data source; and an identification module, configured to identify target sensitive data from the data to be identified using the target sensitive data identification rule.
[0006] According to a third aspect of the present disclosure, an electronic device is provided, comprising: a processor; and a memory for storing processor-executable instructions; wherein the processor is configured to execute the instructions to implement a sensitive data identification method as described in the first aspect of the present disclosure.
[0007] According to a fourth aspect of the present disclosure, a computer-readable storage medium is provided that, when instructions in the computer-readable storage medium are executed by a processor of an electronic device, enables the electronic device to perform a sensitive data identification method as described in the first aspect of the present disclosure.
[0008] According to a fifth aspect of the present disclosure, a computer program product is provided, comprising: a computer program that, when executed by a processor, implements the sensitive data identification method as described in the first aspect of the present disclosure.
[0009] The technical solutions provided by the embodiments of this disclosure have at least the following beneficial effects:
[0010] In this technical solution, a sensitive data identification task is created on the task creation page in response to a task creation operation. This task includes a target data source and target sensitive data identification rules. These rules are based on target data classification and at least one target data security level configuration. This allows users to flexibly specify the target data source and configure the target sensitive data identification rules based on target data classification and security level on the task creation page, ensuring the targeting and accuracy of the sensitive data identification task. Furthermore, in response to the triggering operation of the target control on the task creation page, the sensitive data identification task is executed to obtain the data to be identified from the target data source. This allows for the initiation of the sensitive data identification task through a simple control triggering operation, quickly obtaining the data to be identified from the target data source, avoiding tedious manual operations and improving work efficiency. Finally, the target sensitive data identification rules are used to identify the target sensitive data from the data to be identified. This achieves efficient and accurate identification of target sensitive data from the data to be identified using the aforementioned target sensitive data identification rules, facilitating the timely discovery and handling of potential threats. This approach addresses the risk of data breaches and ensures the security and compliance of financial institutions' data. Specifically, when the data to be identified consists of fields in various data tables, multiple first identification sub-rules are sequentially traversed to identify sensitive data in each field. This ensures that every possible sensitive data type is fully considered, preventing any omissions in sensitive data identification. Simultaneously, the currently traversed sub-rule is matched with each field in the data to be identified, precisely locating the first target field containing sensitive information. This not only guarantees the accuracy of sensitive data identification but also avoids misjudging non-sensitive data, improving the accuracy and efficiency of sensitive data identification. Furthermore, when identifying sensitive data in data tables within the data to be identified, multiple second identification sub-rules under the sensitive data identification rules are sequentially traversed. The currently traversed second identification sub-rule is matched with each data table and its fields in the data to be identified, improving the accuracy and specificity of sensitive data identification. This not only quickly locates the target data table containing sensitive information but also directly determines which fields in these tables contain sensitive data, thereby achieving secure management of sensitive data and preventing any omissions in sensitive data identification.
[0011] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description
[0012] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure, and are not intended to unduly limit this disclosure.
[0013] Figure 1This is a flowchart illustrating the sensitive data identification method shown in the first embodiment of this disclosure;
[0014] Figure 2 This is a flowchart illustrating the sensitive data identification method shown in the second embodiment of this disclosure;
[0015] Figure 3 This is a flowchart illustrating the sensitive data identification method shown in the third embodiment of this disclosure;
[0016] Figure 4 This is a flowchart illustrating the sensitive data identification method shown in the fourth embodiment of this disclosure;
[0017] Figure 5 This is a flowchart illustrating the sensitive data identification method shown in the fifth embodiment of this disclosure;
[0018] Figure 6 This is a schematic diagram illustrating the principle of the sensitive data identification method shown in the embodiments of this disclosure;
[0019] Figure 7 This is a schematic diagram of a data classification page as shown in an embodiment of this disclosure;
[0020] Figure 8 This is a schematic diagram of a data hierarchy page as shown in an embodiment of this disclosure;
[0021] Figure 9 This is a schematic diagram of the sensitive data identification rule configuration page shown in the embodiments of this disclosure;
[0022] Figure 10 This is a schematic diagram of the task creation page shown in the embodiments of this disclosure;
[0023] Figure 11 This is a schematic diagram of a data hierarchy supplementary page as shown in an embodiment of this disclosure;
[0024] Figure 12 This is a schematic diagram of the structure of the sensitive data identification device shown in the sixth embodiment of this disclosure;
[0025] Figure 13 This is a schematic diagram of the structure of an electronic device shown in an exemplary embodiment of the present disclosure. Detailed Implementation
[0026] To enable those skilled in the art to better understand the technical solutions of this disclosure, the technical solutions in the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings.
[0027] It should be noted that the terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this disclosure described herein can be implemented in orders other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this disclosure as detailed in the appended claims.
[0028] It should be noted that the collection, storage, use, processing, transmission, provision and disclosure of user personal information involved in the technical solution disclosed herein are all carried out with the consent of the user, and all comply with the provisions of relevant laws and regulations, and do not violate public order and good morals.
[0029] In related technologies, data resources are sorted out according to manually configured classification systems and data security grading control requirements. The elements within the data resources are then compared and archived against the classification system, and security levels are assigned based on the sensitivity of the data to construct a data resource security system. However, this manual method is time-consuming, labor-intensive, and inefficient, requiring significant investment of human and material resources. Data identification is a long-term task that necessitates continuous resource allocation to ensure the accuracy and timeliness of the security system.
[0030] In addition, related technologies can also use security management tools to match data resources with the classification system and hierarchical strategy based on security classification system. The tools can then be combined with hierarchical control requirements to confirm the level, thereby achieving the goal of classifying and hierarchically managing data resources. However, conventional security management tools have greatly reduced the accuracy and completeness of data identification due to factors such as identification algorithms, the complexity of data resources, and the dependence on business elements.
[0031] Furthermore, the security classification of data resources in related technologies is usually based on the field level, which classifies and controls each field of the data table, but cannot provide comprehensive hierarchical management of the data table.
[0032] Therefore, in order to address the above problems, this disclosure proposes a method and apparatus for identifying sensitive data.
[0033] The following describes a method and apparatus for identifying sensitive data according to embodiments of the present disclosure, with reference to the accompanying drawings.
[0034] Figure 1 This is a flowchart illustrating the sensitive data identification method shown in the first embodiment of this disclosure.
[0035] like Figure 1As shown, the method for identifying this sensitive data includes the following steps:
[0036] Step 101: In response to the task creation operation, create a sensitive data identification task on the task creation page.
[0037] The sensitive data identification task includes target data sources and target sensitive data identification rules. The target sensitive data identification rules are obtained based on target data classification and at least one target data security classification configuration.
[0038] To improve the accuracy and efficiency of sensitive data identification, as a possible approach, a sensitive data identification task can be created on the task creation page based on the user's actual needs. By executing the sensitive data identification task, the target sensitive data can be identified.
[0039] As an example, based on the user's actual needs, the target data source and the target sensitive data identification rules configured based on data classification and security level can be specified on the task creation page, thereby generating a sensitive data identification task based on the target data source and the target sensitive data identification rules.
[0040] Step 102: In response to the triggering operation of the target control on the task creation page, execute the sensitive data identification task to obtain the data to be identified from the target data source.
[0041] To improve the efficiency of sensitive data identification, as an example, in response to a user's triggering action on the target control on the task creation page (e.g., clicking the "OK" control on the task creation page), the sensitive data identification task is executed. Based on the target sensitive data identification rules, the data to be identified is obtained from the target data source. The data to be identified can be various data tables in the data source or fields within those data tables.
[0042] Step 103: Use the target sensitive data identification rules to identify target sensitive data from the data to be identified.
[0043] To further improve the accuracy and security of sensitive data identification, as an example, we use target sensitive data identification rules to parse the data to be identified in order to identify the target sensitive data.
[0044] In summary, by responding to the task creation operation, a sensitive data identification task is created on the task creation page. This task includes a target data source and target sensitive data identification rules. These rules are based on target data classification and at least one target data security level configuration. This allows users to flexibly specify the target data source and configure the sensitive data identification rules based on target data classification and security level on the task creation page, ensuring the targeting and accuracy of the sensitive data identification task. Furthermore, by responding to the trigger operation of the target control on the task creation page, the sensitive data identification task is executed to obtain the data to be identified from the target data source. This allows for initiating the identification task through a simple control trigger operation, quickly obtaining the data to be identified from the target data source, avoiding tedious manual operations, and improving the efficiency of sensitive data identification. Finally, by employing the target sensitive data identification rules, the target sensitive data is identified from the data to be identified. This achieves efficient and accurate identification of target sensitive data from the data to be identified, helping to promptly detect and handle potential data leakage risks, and ensuring the security and compliance of financial institutions' data.
[0045] It's important to understand that the data to be identified can be various data tables or fields within those data tables. As an example, when identifying sensitive data in the fields of a data table, the target sensitive data identification rules can include multiple first identification sub-rules for each field. Based on these multiple first identification sub-rules, the target sensitive data is identified from the data to be identified. The following section will combine... Figure 2 The embodiments are described in detail.
[0046] Figure 2 This is a flowchart illustrating the sensitive data identification method shown in the second embodiment of this disclosure.
[0047] like Figure 2 As shown, the method for identifying this sensitive data includes the following steps:
[0048] Step 201: In response to the task creation operation, create a sensitive data identification task on the task creation page.
[0049] The sensitive data identification task includes target data sources and target sensitive data identification rules. The target sensitive data identification rules are obtained based on target data classification and at least one target data security classification configuration.
[0050] Step 202: In response to the triggering operation of the target control on the task creation page, execute the sensitive data identification task to obtain the data to be identified from the target data source.
[0051] Step 203: Iterate through the multiple first identification sub-rules under the target sensitive data identification rule in sequence.
[0052] It is important to understand that the target sensitive data identification rules may include first identification sub-rules for multiple fields. The first identification sub-rules may include corresponding content identification sub-rules and field matching sub-rules. The content identification sub-rules include custom regular expression sub-rules and custom structured query language sub-rules, etc., while the field matching sub-rules include specified field sub-rules and field fuzzy matching sub-rules, etc.
[0053] To avoid missing the identification of sensitive data, as an example, multiple first identification sub-rules under the target sensitive data identification rule are sequentially traversed and applied to identify sensitive data.
[0054] Step 204: Match the first identification sub-rule currently being traversed with each field in the data to be identified to obtain the matching result of the first identification sub-rule currently being traversed.
[0055] To improve the accuracy and comprehensiveness of sensitive data identification, as an example, the first identification sub-rule currently being traversed is compared and matched one by one with each field in the data to be identified, so as to obtain the matching results between the first identification sub-rule currently being traversed and each field.
[0056] Step 205: In response to the matching result indication of the first identification sub-rule currently being traversed, the first target field is stored in each field, and the first target field is obtained from each field.
[0057] The first target field is the field that matches the first identification sub-rule currently being traversed.
[0058] To quickly locate sensitive data, as an example, if the matching result of the first identification sub-rule being traversed indicates that there is a first target field in each field that matches the first identification sub-rule being traversed, then the first target field is retrieved from each field.
[0059] Step 206: Determine the target sensitive data based on the first target field and the field values under the first target field.
[0060] To avoid misjudging non-sensitive data and improve the accuracy of sensitive data identification, one possible approach is to determine suspected sensitive data based on the first target field and the field values under the first target field, and then determine the target sensitive data based on the audit results of the suspected sensitive data.
[0061] As an example, the first target field and the field values under the first target field are regarded as suspected sensitive data; the suspected sensitive data is dispatched to the target review object to review the suspected sensitive data and obtain the review result; the review result sent by the target review object is received, and the target sensitive data is determined from the suspected sensitive data according to the review result.
[0062] In other words, the first target field and its value obtained by matching are marked as suspected sensitive data; then, this suspected sensitive data is sent to the relevant target review object for review; after the review is completed, the review result returned by the target review object is received, and based on the review result, the real target sensitive data is accurately filtered out from the original suspected sensitive data.
[0063] It should be noted that the execution process of steps 201 to 202 can be implemented in any of the embodiments of this disclosure. This disclosure does not limit this and will not elaborate further.
[0064] In summary, by sequentially traversing multiple first identification sub-rules under the target sensitive data identification rule; matching the currently traversed first identification sub-rule with each field in the data to be identified to obtain the matching result of the currently traversed first identification sub-rule; responding to the matching result of the currently traversed first identification sub-rule indicating that each field contains a first target field, the first target field is obtained from each field; where the first target field is the field that matches the currently traversed first identification sub-rule; based on the first target field and the field values under the first target field, the target sensitive data is determined. Thus, by sequentially traversing multiple first identification sub-rules, every possible sensitive data type is fully considered, avoiding the omission of sensitive data identification. At the same time, matching the currently traversed sub-rule with each field in the data to be identified can accurately locate the first target field containing sensitive information, which not only ensures the accuracy of sensitive data but also avoids misjudgment of non-sensitive data, improving the accuracy and efficiency of sensitive data identification.
[0065] As another example, when identifying sensitive data in data tables within the data to be identified, the target sensitive data identification rules may include multiple data tables and second identification sub-rules for multiple fields within those tables. Target sensitive data is then identified from the data to be identified based on these multiple second identification sub-rules. The following section combines... Figure 3 The embodiments are described in detail.
[0066] Figure 3 This is a flowchart illustrating the sensitive data identification method shown in the third embodiment of this disclosure.
[0067] like Figure 3 As shown, the method for identifying this sensitive data includes the following steps:
[0068] Step 301: In response to the task creation operation, create a sensitive data identification task on the task creation page.
[0069] The sensitive data identification task includes target data sources and target sensitive data identification rules. The target sensitive data identification rules are obtained based on target data classification and at least one target data security classification configuration.
[0070] Step 302: In response to the triggering operation of the target control on the task creation page, execute the sensitive data identification task to obtain the data to be identified from the target data source.
[0071] Step 303: Iterate through the multiple second identification sub-rules under the sensitive data identification rule in sequence.
[0072] It should be noted that the target sensitive data identification rules may include multiple data tables and multiple fields in the data tables as second identification sub-rules. The rules of the second identification sub-rules are different from those of the first identification sub-rules.
[0073] To avoid missing the identification of sensitive data, as an example, multiple second identification sub-rules under the target sensitive data identification rule are sequentially traversed and applied to identify sensitive data.
[0074] Step 304: Match the currently traversed second identification sub-rule with each data table and multiple fields in the data to be identified to obtain the matching result of the currently traversed second identification sub-rule.
[0075] To improve the accuracy and comprehensiveness of sensitive data identification, as an example, the second identification sub-rule currently being traversed is compared and matched one by one with each data table and multiple fields in the data to be identified, so as to obtain the matching results of the second identification sub-rule currently being traversed with each data table and multiple fields in each data table.
[0076] Step 305: In response to the matching result of the second identification sub-rule currently being traversed indicating the existence of a target data table in the data to be identified, the target sensitive data is determined based on multiple second target fields in the target data table.
[0077] Among them, the target data table and multiple second target fields in the target data table match the second identification sub-rule currently being traversed.
[0078] To quickly locate sensitive data, as an example, if the matching result of the second identification sub-rule being traversed indicates that a target data table exists in the data to be identified, the target sensitive data is determined based on multiple second target fields in the target data table, wherein the target data table and multiple second target fields in the target data table match the second identification sub-rule being traversed.
[0079] As an example, the target data table and the field values of multiple second target fields under the target data table are regarded as suspected sensitive data; the suspected sensitive data is dispatched to the target audit object for auditing, and the audit results are obtained; the audit results sent by the target audit object are received, and the target sensitive data is determined from the suspected sensitive data based on the audit results.
[0080] It should be noted that the execution process of steps 301 to 302 can be implemented in any of the embodiments of this disclosure. This disclosure does not limit this and will not elaborate further.
[0081] In summary, by sequentially traversing multiple second identification sub-rules under the sensitive data identification rule, and matching the currently traversed second identification sub-rule with each data table and multiple fields in the data to be identified, the matching result of the currently traversed second identification sub-rule is obtained. Responding to the matching result of the currently traversed second identification sub-rule indicating the existence of a target data table in the data to be identified, the target sensitive data is determined based on multiple second target fields in the target data table. Specifically, the target data table and its multiple second target fields match the currently traversed second identification sub-rule. Therefore, by sequentially traversing multiple second identification sub-rules under the sensitive data identification rule, and matching the currently traversed second identification sub-rule with each data table and its fields in the data to be identified, the accuracy and targeting of sensitive data identification are improved. This not only allows for the rapid location of target data tables containing sensitive information but also directly determines which fields in these tables are sensitive data, thereby achieving secure management of sensitive data and avoiding the omission of sensitive data identification.
[0082] To clearly illustrate how the above embodiments are configured to obtain the target sensitive data identification rules, this disclosure proposes another method for identifying sensitive data.
[0083] Figure 4 This is a flowchart illustrating the sensitive data identification method shown in the fourth embodiment of this disclosure.
[0084] like Figure 4 As shown, based on any of the above embodiments, the target sensitive data identification rules can be configured using the following steps:
[0085] Step 401: In response to the data classification selection operation, select the target data category from multiple candidate data categories in the sensitive data identification rule configuration page.
[0086] Among them, target data classification is used to indicate the data category to which the target sensitive data to be identified belongs.
[0087] To improve the flexibility of sensitive data identification, as an example, users can explicitly specify the specific category (i.e., target data classification) of the sensitive data to be identified on the sensitive data identification rule configuration page according to their actual needs. This ensures that the sensitive data identification process is more accurate and helps with subsequent data processing and compliance management.
[0088] Step 402: In response to the data classification selection operation, select at least one target data security classification from multiple candidate data security classifications under at least one classification system in the sensitive data identification rule configuration page.
[0089] Among them, the target data security classification is used to indicate the security level of the target sensitive data under the corresponding classification system.
[0090] To enable differentiated data protection measures for sensitive data at different security levels, as an example, users can select the target data security level from at least one hierarchical system, such as confidential, secret, or internal use, on the sensitive data identification rule configuration page. This allows sensitive data to be assigned corresponding security levels based on its importance and sensitivity, which helps to implement differentiated data protection measures, ensures that critical sensitive data receives a higher level of protection, and also promotes the efficient utilization and management of data resources.
[0091] It should be noted that, in order to select the target data category and target data security level on the sensitive data identification rule configuration page, before selecting the target data category from multiple candidate data categories on the sensitive data identification rule configuration page, and before selecting the target data security level from at least one hierarchical system and multiple candidate data security levels under at least one hierarchical system, it is necessary to configure multiple candidate data categories, at least one hierarchical system, and multiple candidate data security levels under at least one hierarchical system.
[0092] As an example, in response to the data classification configuration operation, multiple candidate data classifications are configured on the data classification page; the multiple candidate data classifications are synchronized to the sensitive data identification rule configuration page; in response to the data grading configuration operation, at least one grading system and multiple candidate data security grades under at least one grading system are configured on the data grading page; the at least one grading system and multiple candidate data security grades under at least one grading system are synchronized to the sensitive data identification rule configuration page.
[0093] In other words, users perform data classification configuration operations on the data classification page to configure multiple candidate data categories. These candidate data categories differentiate data based on factors such as data nature, purpose, or source. After the candidate data category configuration is completed, it is automatically synchronized to the sensitive data identification rule configuration page. Next, through the data grading configuration operation, at least one grading system is set on the data grading page. Each grading system is configured with multiple candidate data security grades. These at least one grading system and the candidate data security grades under it are used to further refine the sensitivity of the data, enabling the implementation of corresponding levels of protection measures. After configuration, the grading system and its candidate data security grades are synchronized to the sensitive data identification rule configuration page. This process ensures the flexibility and consistency of data classification and grading, providing a foundation for subsequent security measures such as sensitive data identification, storage, de-identification, and access control.
[0094] Step 403: In response to the identification condition configuration operation, configure the identification conditions for the target sensitive data on the sensitive data identification rule configuration page.
[0095] It should be noted that the identification conditions are used to define and determine which data meets the standards for sensitive data, such as keyword matching, format verification, and data source verification. In order to improve the accuracy and efficiency of sensitive data identification, as an example, the identification conditions for target sensitive data are configured on the sensitive data identification rule configuration page. Based on the identification conditions configured in the sensitive data identification rules, data items that meet the sensitive data standards can be automatically and quickly filtered out, thereby improving the efficiency of sensitive data identification.
[0096] Step 404: Generate sensitive data identification rules for target data based on the target data classification, at least one target data security level, and identification conditions in the sensitive data identification rule configuration page.
[0097] To improve the comprehensiveness and accuracy of sensitive data identification, as an example, on the sensitive data identification rule configuration page, target sensitive data identification rules are generated by selecting the target data category, target data security level, and configuring identification conditions.
[0098] To improve data security, as an example, after identifying target sensitive data from the data to be identified using target sensitive data identification rules, the sensitive data is stored in the storage system corresponding to the target data classification and target data security level, so as to retrieve the target sensitive data from the storage system and perform de-identification processing on the target sensitive data.
[0099] In other words, after efficiently identifying target sensitive data from the data to be identified using target sensitive data identification rules, the target sensitive data is automatically stored in the corresponding storage system according to the predefined target data classification and corresponding security level. Subsequently, when it is necessary to further analyze or use the target sensitive data from these storage systems, the data is subjected to strict desensitization processing to eliminate or reduce the sensitive information in the data, thereby protecting data privacy and security while meeting the needs of data utilization.
[0100] In addition, it should be noted that for some manually identified sensitive data, or sensitive data with irregular patterns, the classification, grading and archiving of sensitive data can be completed through manual labeling to achieve secure management of data resources.
[0101] In summary, in response to the data classification selection operation, a target data category is selected from multiple candidate data categories in the sensitive data identification rule configuration page; wherein, the target data category indicates the data category to which the target sensitive data to be identified belongs. In response to the data level selection operation, at least one target data security level is selected from multiple candidate data security levels under at least one level system in the sensitive data identification rule configuration page; wherein, the target data security level indicates the security level of the target sensitive data under the corresponding level system. In response to the identification condition configuration operation, the identification conditions for the target sensitive data are configured in the sensitive data identification rule configuration page. Based on the target data category, at least one target data security level, and identification conditions in the sensitive data identification rule configuration page, a target sensitive data identification rule is generated. Thus, based on the data classification selection, data level selection, and identification condition configuration, a target sensitive data identification rule is generated in the sensitive data identification rule configuration page. Using this target sensitive data identification rule for sensitive data identification improves the comprehensiveness and accuracy of sensitive data identification, while also improving data management efficiency and enhancing data protection security.
[0102] To clearly illustrate how the above embodiments respond to the task creation operation and create a sensitive data identification task on the task creation page, this disclosure proposes another method for identifying sensitive data.
[0103] Figure 5 This is a flowchart illustrating the sensitive data identification method shown in the fifth embodiment of this disclosure.
[0104] like Figure 5 As shown, the method for identifying sensitive data includes the following steps:
[0105] Step 501: In response to the data source selection operation, select the target data source from multiple candidate data sources on the task creation page.
[0106] Among them, the candidate data source is the data source associated with financial institutions.
[0107] To improve the flexibility of sensitive data identification, as an example, users can select one or more candidate data sources as the target data source from multiple candidate data sources provided on the task creation page. The candidate data sources are data sources associated with financial institutions, such as business data, information of various units within the financial institution, and customer information within the financial institution.
[0108] Step 502: In response to the rule selection operation, select the target sensitive data identification rule from multiple candidate sensitive data identification rules in the task creation page.
[0109] To identify sensitive data based on user needs, as an example, users can select the target sensitive data identification rule that meets their needs from multiple candidate sensitive data identification rules on the task creation page.
[0110] Step 503: Generate a sensitive data identification task based on the target data source and the target sensitive data identification rules.
[0111] To improve the targeting, accuracy, and timeliness of sensitive data identification, one possible approach is to automatically generate and configure sensitive data identification tasks based on the user-selected target data source, sensitive data identification rules, execution cycle, and data scanning method, so as to achieve periodic or on-demand sensitive data identification.
[0112] As an example, in response to the execution cycle selection operation, a target task execution cycle is selected from multiple candidate task execution cycles on the task creation page; wherein, the target task execution cycle is used to indicate the frequency of performing the sensitive data identification task; in response to the scanning method selection operation, a target data scanning method is selected from multiple candidate data scanning methods on the task creation page; the sensitive data identification task is generated based on the target data source, the target sensitive data identification rules, the target task execution cycle, and the target data scanning method.
[0113] In other words, during task creation, users first select a target task execution cycle from multiple candidate task execution cycles based on their actual needs. This target task execution cycle defines the frequency at which the sensitive data identification task will be automatically executed, such as daily, weekly, monthly, or at specific time intervals, to meet the need for continuous monitoring and identification of sensitive data. Next, users choose from multiple candidate data scanning methods provided on the task creation page to determine the target data scanning method. The choice of target scanning method depends on factors such as data storage location, data format, data access permissions, and system resources. For example, users can choose a full scan to cover all data in the target data source, or an incremental scan to focus only on data that has changed since the last scan, thereby improving scanning efficiency and reducing system load. Finally, by combining the above information—target data source, target sensitive data identification rules, target task execution cycle, and target data scanning method—a complete sensitive data identification task is generated. During the execution of this sensitive data identification task, sensitive data in the target data source can be identified and detected periodically or as needed, according to the user-specified execution cycle and scanning method.
[0114] Step 504: In response to the triggering operation of the target control on the task creation page, execute the sensitive data identification task to obtain the data to be identified from the target data source.
[0115] Step 505: Use the target sensitive data identification rules to identify target sensitive data from the data to be identified.
[0116] It should be noted that the execution process of steps 504 to 505 can be implemented in any of the embodiments of this disclosure. This disclosure does not limit this and will not elaborate further.
[0117] In summary, by responding to the data source selection operation, a target data source is selected from multiple candidate data sources on the task creation page; by responding to the rule selection operation, a target sensitive data identification rule is selected from multiple candidate sensitive data identification rules on the task creation page; and a sensitive data identification task is generated based on the target data source and the target sensitive data identification rule. Therefore, by generating a sensitive data identification task using the target data source and the target sensitive data identification rule selected on the task creation page, the targeting and efficiency of the identification task are improved. Consequently, by executing the sensitive data identification task and using the target sensitive data identification rule to identify the target sensitive data, the accuracy and efficiency of the target sensitive data identification are improved.
[0118] Based on any embodiment of this disclosure, such as Figure 6 As shown, the sensitive data identification method of this disclosure embodiment can also be implemented based on the following steps:
[0119] Step 1: Gather metadata resources
[0120] As an example, an inventory and sorting of data resources within an organization can be conducted to form a unified data resource list.
[0121] Step 2: Definition of Cross-Industry Safety Classification System
[0122] The data classification system is based on the actual business operations of enterprises and institutions, and categorizes business data according to the principles of ease of management and use in actual business operations. For example... Figure 7 As shown, multiple candidate data categories can be configured on the data classification page.
[0123] Step 3: Construct a multi-system security hierarchy
[0124] Based on relevant requirements and internal data security management procedures, generated or collected data is classified, graded, and labeled. A security grading system typically involves multiple grading systems, with data security levels defined for each system based on the granularity of security grading and data control objectives required by different management organizations. For example... Figure 8 As shown, at least one hierarchical system and multiple candidate data security classifications under at least one hierarchical system are configured on the data classification page.
[0125] Step 4: Define sensitive data identification rules
[0126] Defining the granularity of data classification is a key element in identification and classification. Based on the established data security classification and grading system, keyword information of sensitive data information is determined. The scanned object is based on the metadata resource list, and sensitive information matching is performed on table, field names, remarks and other elements. This is one of the important means of sensitive data identification. Another approach is to scan the data content and use data matching and identification algorithms such as regular expressions to match and benchmark the data content in the data table to discover suspected sensitive data tables and sensitive field items.
[0127] As an example, such as Figure 9 As shown, target sensitive data identification rules are generated based on the target data category selected in the sensitive data identification rule configuration page, at least one target data security level, and the configured identification conditions.
[0128] Step 5: Identify Task Management and Execution
[0129] It's important to understand that data resources expand dynamically as business operations evolve, and the discovery and identification of sensitive data is also a dynamic process. Defined sensitive data discovery rules require ad-hoc or periodic scans based on data update frequency, importance, and scope of use to ensure that sensitive elements of newly added data resources are discovered promptly, preventing the omission of sensitive data and thus avoiding data security issues.
[0130] As an example, such as Figure 10 As shown, the definition of the sensitive data identification task is defined, and the execution cycle (year, month, day, etc.), execution time, scanning rules, and the source and range of the scanned data are set to meet the timeliness requirements for sensitive data discovery.
[0131] Step 6: Identification and verification of data resource classification and grading results.
[0132] As an example, the identification rules identify a list of suspected sensitive data after task execution. According to the identification rule definition, the rules recommend security classification and security level for archiving, including recommended de-identification algorithms. After manual review and labeling, a data resource security classification and grading resource library is formed, providing a control basis and benchmark for data collection, data development, and data services. In different data application scenarios, users with different security levels are provided with equivalent data access rights and de-identification algorithm support.
[0133] Step 7: Supplement the data grading model through manual calibration
[0134] like Figure 11 As shown, in the daily process of sensitive data identification, sensitive data identified by humans or sensitive data with irregular patterns can be classified, graded and archived by manual labeling. By using multiple methods, the security classification and grading management of data resources can be maximized, and comprehensive data resource security management can be achieved.
[0135] Step 8: Column correlation identification strategy for data tables
[0136] Multi-source data fusion technology refers to the technique of integrating all information obtained from investigation and analysis using relevant methods, conducting a unified evaluation of the information, and finally obtaining unified information. The purpose of this technology is to synthesize various different data information, absorb the characteristics of different data sources, and then extract unified information that is better and richer than single data. Based on this technical theory, for fields in the same data table, different security levels of each field are evaluated at the table level using a combination of two or more fields. Combining the correlation between column data, the security level of the data table is reclassified to ensure data security. Specifically, it employs multiple data tables and secondary identification sub-rules for multiple fields in the target sensitive data identification rules to identify the target data table from the data to be identified, and determines the target sensitive data based on multiple secondary target fields in the target data table.
[0137] 9. Data anonymization
[0138] The target sensitive data is stored in the storage system corresponding to the target data classification and target data security level, so as to obtain the target sensitive data from the storage system and perform desensitization processing on the target sensitive data using relevant desensitization rules.
[0139] Corresponding to the sensitive data identification method provided in the above embodiments, this disclosure also provides a sensitive data identification device. Since the sensitive data identification device provided in this disclosure corresponds to the sensitive data identification method provided in the above embodiments, the implementation of the sensitive data identification method is also applicable to the sensitive data identification device provided in this disclosure, and will not be described in detail in this disclosure.
[0140] Figure 12 This is a schematic diagram of the structure of the sensitive data identification device shown in the sixth embodiment of this disclosure.
[0141] like Figure 12 As shown, the sensitive data identification device 1200 includes: a creation module 1210, an execution module 1220, and an identification module 1230.
[0142] The creation module 1210 is used to create a sensitive data identification task on the task creation page in response to a task creation operation. The sensitive data identification task includes a target data source and target sensitive data identification rules, which are obtained based on target data classification and at least one target data security level configuration. The execution module 1220 is used to execute the sensitive data identification task in response to a trigger operation of a target control on the task creation page to obtain the data to be identified from the target data source. The identification module 1230 is used to identify target sensitive data from the data to be identified using the target sensitive data identification rules.
[0143] As one possible implementation of this disclosure, the target sensitive data identification rule includes a first identification sub-rule with multiple fields. The identification module 1230 is used to sequentially traverse the multiple first identification sub-rules under the target sensitive data identification rule; match the currently traversed first identification sub-rule with each field in the data to be identified to obtain the matching result of the currently traversed first identification sub-rule; in response to the matching result of the currently traversed first identification sub-rule indicating that each field contains a first target field, obtain the first target field from each field; wherein, the first target field is the field that matches the currently traversed first identification sub-rule; and determine the target sensitive data based on the first target field and the field value under the first target field.
[0144] As one possible implementation of this disclosure, the identification module 1230 is used to identify the first target field and the field values under the first target field as suspected sensitive data; to schedule the suspected sensitive data to the target review object for review and obtain the review result; to receive the review result sent by the target review object, and to determine the target sensitive data from the suspected sensitive data based on the review result.
[0145] As one possible implementation of this disclosure, the target sensitive data identification rule includes multiple data tables and multiple fields in the data tables as second identification sub-rules. The identification module 1230 is used to sequentially traverse the multiple second identification sub-rules under the target sensitive data identification rule; match the currently traversed second identification sub-rules with each data table and multiple fields in the data to be identified to obtain the matching result of the currently traversed second identification sub-rules; in response to the matching result of the currently traversed second identification sub-rules indicating that a target data table exists in the data to be identified, determine the target sensitive data according to the multiple second target fields in the target data table; wherein, the target data table and the multiple second target fields in the target data table match the currently traversed second identification sub-rules.
[0146] As one possible implementation of this disclosure, the target sensitive data identification rule is configured using the following steps: In response to a data classification selection operation, a target data category is selected from multiple candidate data categories in the sensitive data identification rule configuration page; wherein, the target data category is used to indicate the data category to which the target sensitive data to be identified belongs; In response to a data level selection operation, at least one target data security level is selected from multiple candidate data security levels under at least one level system in the sensitive data identification rule configuration page; wherein, the target data security level is used to indicate the security level of the target sensitive data under the corresponding level system; In response to an identification condition configuration operation, identification conditions for the target sensitive data are configured in the sensitive data identification rule configuration page; and a target sensitive data identification rule is generated based on the target data category, at least one target data security level, and identification conditions in the sensitive data identification rule configuration page.
[0147] As one possible implementation of this disclosure, the sensitive data identification device 1200 further includes a storage module.
[0148] The storage module is used to store target sensitive data into a storage system corresponding to the target data classification and target data security level, so as to retrieve target sensitive data from the storage system and perform desensitization processing on the target sensitive data.
[0149] As one possible implementation of this disclosure, the sensitive data identification device 1200 further includes a synchronization module.
[0150] The synchronization module is used to respond to data classification configuration operations by configuring multiple candidate data categories on the data classification page; synchronizing multiple candidate data categories to the sensitive data identification rule configuration page; responding to data grading configuration operations by configuring at least one grading system and multiple candidate data security grades under at least one grading system on the data grading page; and synchronizing at least one grading system and multiple candidate data security grades under at least one grading system to the sensitive data identification rule configuration page.
[0151] As one possible implementation of this disclosure, the creation module 1210 is configured to, in response to a data source selection operation, select a target data source from a plurality of candidate data sources in the task creation page; wherein the candidate data source is a data source associated with a financial institution; in response to a rule selection operation, select a target sensitive data identification rule from a plurality of candidate sensitive data identification rules in the task creation page; and generate the sensitive data identification task based on the target data source and the target sensitive data identification rule.
[0152] As one possible implementation of this disclosure, the sensitive data identification task further includes a target task execution cycle and a target data scanning method. The creation module 1210 is used to select a target task execution cycle from multiple candidate task execution cycles in the task creation page in response to an execution cycle selection operation; wherein the target task execution cycle indicates the frequency of executing the sensitive data identification task; and to select a target data scanning method from multiple candidate data scanning methods in response to a scanning method selection operation; and to generate a sensitive data identification task based on the target data source, target sensitive data identification rules, target task execution cycle, and target data scanning method.
[0153] The sensitive data identification device of this disclosure creates a sensitive data identification task on a task creation page in response to a task creation operation. The sensitive data identification task includes a target data source and target sensitive data identification rules. These rules are configured based on target data classification and at least one target data security level. This allows users to flexibly specify the target data source and the target sensitive data identification rules based on target data classification and security level on the task creation page, ensuring the targeting and accuracy of the sensitive data identification task. Furthermore, in response to the triggering operation of a target control on the task creation page, the sensitive data identification task is executed to obtain the data to be identified from the target data source. This allows for the initiation of the sensitive data identification task through a simple control triggering operation, quickly obtaining the data to be identified from the target data source, avoiding tedious manual operations and improving work efficiency. Finally, by employing the target sensitive data identification rules, the device identifies target sensitive data from the data to be identified. This achieves efficient and accurate identification of target sensitive data from the data to be identified using the aforementioned target sensitive data identification rules, helping to promptly detect and handle potential data leakage risks and ensuring the security and compliance of financial institutions' data.
[0154] In an exemplary embodiment, an electronic device is also proposed.
[0155] The electronic devices include:
[0156] processor;
[0157] Memory used to store processor-executable instructions;
[0158] The processor is configured to execute instructions to implement the sensitive data identification method proposed in any of the foregoing embodiments.
[0159] As an example, Figure 13 This is a schematic diagram of the structure of an electronic device 1300 as shown in an exemplary embodiment of this disclosure, as follows: Figure 13As shown, the aforementioned electronic device 1300 may further include:
[0160] The memory 1310 and the processor 1320 are connected by a bus 1330, which connects different components (including the memory 1310 and the processor 1320). The memory 1310 stores a computer program, and when the processor 1320 executes the program, it implements the sensitive data identification method described in the embodiments of this disclosure.
[0161] Bus 1330 represents one or more of several bus architectures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the various bus architectures. For example, these architectures include, but are not limited to, the Industry Standard Architecture (ISA) bus, the Micro Channel Architecture (MAC) bus, the Enhanced ISA bus, the Video Electronics Standards Association (VESA) local bus, and the Peripheral Component Interconnect (PCI) bus.
[0162] Electronic device 1300 typically includes a variety of electronic device readable media. These media can be any available media that can be accessed by electronic device 1300, including volatile and non-volatile media, removable and non-removable media.
[0163] Memory 1310 may also include computer system readable media in the form of volatile memory, such as random access memory (RAM) 1340 and / or cache memory 1350. Electronic device 1300 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 1360 may be used to read and write non-removable, non-volatile magnetic media (… Figure 13 Not shown; usually referred to as a "hard drive"). Although Figure 13 As not shown, a disk drive for reading and writing to a removable non-volatile disk (e.g., a "floppy disk") and an optical disk drive for reading and writing to a removable non-volatile optical disk (e.g., a CD-ROM, DVD-ROM, or other optical media) may be provided. In these cases, each drive may be connected to bus 1330 via one or more data media interfaces. Memory 1310 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the embodiments of this disclosure.
[0164] A program / utility 1380 having a set (at least one) of program modules 1370 may be stored, for example, in memory 1310. Such program modules 1370 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. Program modules 1370 typically perform the functions and / or methods described in the embodiments of this disclosure.
[0165] Electronic device 1300 can also communicate with one or more external devices 1390 (e.g., keyboard, pointing device, display 1391, etc.), and with one or more devices that enable a user to interact with electronic device 1300, and / or with any device that enables electronic device 1300 to communicate with one or more other computing devices (e.g., network card, modem, etc.). This communication can be performed via input / output (I / O) interface 1392. Furthermore, electronic device 1300 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 1393. As shown, network adapter 1393 communicates with other modules of electronic device 1300 via bus 1330. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 1300, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0166] The processor 1320 performs various functional applications and data processing by running programs stored in the memory 1310.
[0167] It should be noted that the implementation process and technical principles of the electronic device in this embodiment are explained in the foregoing description of the sensitive data identification method of the present disclosure embodiment, and will not be repeated here.
[0168] In an exemplary embodiment, a computer-readable storage medium including instructions is also provided, such as a memory including instructions, which can be executed by a processor of an electronic device to perform the sensitive data identification method proposed in any of the above embodiments. Optionally, the computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.
[0169] In an exemplary embodiment, a computer program product is also provided, including a computer program / instructions, characterized in that the computer program / instructions, when executed by a processor, implement the sensitive data identification method proposed in any of the above embodiments.
[0170] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the following claims.
[0171] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.
Claims
1. A method for identifying sensitive data, characterized in that, include: In response to the task creation operation, a sensitive data identification task is created on the task creation page. The sensitive data identification task includes a target data source and target sensitive data identification rules. The target sensitive data identification rules are obtained based on target data classification and at least one target data security level configuration. The target data security level corresponds to the importance and sensitivity of the target sensitive data to be identified. In response to the triggering operation of the target control in the task creation page, the sensitive data identification task is executed to obtain the data to be identified from the target data source; Using the aforementioned target sensitive data identification rules, target sensitive data is identified from the data to be identified, and the target sensitive data is stored in a storage system corresponding to the target data classification and the target data security level, so as to retrieve the target sensitive data from the storage system and perform desensitization processing on the target sensitive data; The data to be identified includes a target data table. Based on the security classification of multiple fields in the target data table, the multiple fields are combined for evaluation to obtain an evaluation result. According to the correlation between the evaluation result and the field values of the multiple fields, the security level of the data table is reclassified to determine the target sensitive data from the target data table.
2. The method according to claim 1, characterized in that, The target sensitive data identification rules include first identification sub-rules for multiple fields. The step of identifying target sensitive data from the data to be identified using target sensitive data identification rules includes: The multiple first identification sub-rules under the target sensitive data identification rule are traversed sequentially. The first identification sub-rule currently being traversed is matched with each field in the data to be identified to obtain the matching result of the first identification sub-rule currently being traversed. In response to the matching result indication of the first identification sub-rule currently being traversed, indicating that a first target field exists in each of the fields, the first target field is obtained from each of the fields; wherein, the first target field is the field that matches the first identification sub-rule currently being traversed; The target sensitive data is determined based on the first target field and the field values under the first target field.
3. The method according to claim 2, characterized in that, The step of determining the target sensitive data based on the first target field and the field values under the first target field includes: The first target field and the field values under the first target field are considered as suspected sensitive data. The suspected sensitive data is dispatched to the target audit object for auditing, and the audit results are obtained. Receive the audit result sent by the target audit object, and determine the target sensitive data from the suspected sensitive data based on the audit result.
4. The method according to claim 1, characterized in that, The target sensitive data identification rules include multiple data tables and second identification sub-rules for multiple fields in the data tables. The step of identifying target sensitive data from the data to be identified using target sensitive data identification rules includes: The multiple second identification sub-rules under the target sensitive data identification rule are traversed sequentially. The second identification sub-rule currently being traversed is matched with each data table in the data to be identified and multiple fields in each data table to obtain the matching result of the second identification sub-rule currently being traversed. In response to the matching result of the currently traversed second identification sub-rule indicating the existence of a target data table in the data to be identified, the target sensitive data is determined based on multiple second target fields in the target data table; wherein the target data table and the multiple second target fields in the target data table match the currently traversed second identification sub-rule.
5. The method according to claim 1, characterized in that, The target sensitive data identification rules are configured using the following steps: In response to the data classification selection operation, the target data classification is selected from multiple candidate data classifications in the sensitive data identification rule configuration page; wherein, the target data classification is used to indicate the data category to which the target sensitive data to be identified belongs; In response to the data classification selection operation, among multiple candidate data security classifications under at least one classification system in the sensitive data identification rule configuration page, a target data security classification under the at least one classification system is selected; wherein, the target data security classification is used to indicate the security level of the target sensitive data under the corresponding classification system; In response to the identification condition configuration operation, the identification conditions for the target sensitive data are configured on the sensitive data identification rule configuration page; The target sensitive data identification rules are generated based on the target data classification, the at least one target data security level, and the identification conditions in the sensitive data identification rule configuration page.
6. The method according to claim 5, characterized in that, The method further includes: The target sensitive data is stored in a storage system corresponding to the target data classification and the target data security level, so as to retrieve the target sensitive data from the storage system and perform de-identification processing on the target sensitive data.
7. The method according to claim 5, characterized in that, The method further includes: In response to the data classification configuration operation, multiple candidate data classifications can be configured on the data classification page; The multiple candidate data categories are synchronized to the sensitive data identification rule configuration page; In response to the data classification configuration operation, at least one classification system and multiple candidate data security classifications under the at least one classification system are configured on the data classification page; The at least one hierarchical system and the security classification of multiple candidate data under the at least one hierarchical system are synchronized to the sensitive data identification rule configuration page.
8. The method according to claim 1, characterized in that, The process of creating a sensitive data identification task on the task creation page in response to the task creation operation includes: In response to the data source selection operation, the target data source is selected from multiple candidate data sources in the task creation page; wherein, the candidate data source is a data source associated with a financial institution; In response to the rule selection operation, the target sensitive data identification rule is selected from multiple candidate sensitive data identification rules in the task creation page; The sensitive data identification task is generated based on the target data source and the target sensitive data identification rules.
9. The method according to claim 8, characterized in that, The sensitive data identification task also includes the target task execution cycle and the target data scanning method. The step of generating the sensitive data identification task based on the target data source and the target sensitive data identification rules includes: In response to the execution cycle selection operation, a target task execution cycle is selected from multiple candidate task execution cycles on the task creation page; wherein, the target task execution cycle is used to indicate the frequency of performing the sensitive data identification task; In response to the scan method selection operation, the target data scan method is selected from multiple candidate data scan methods on the task creation page; The sensitive data identification task is generated based on the target data source, the target sensitive data identification rules, the target task execution cycle, and the target data scanning method.
10. A device for identifying sensitive data, characterized in that, include: A creation module is used to create a sensitive data identification task on the task creation page in response to a task creation operation. The sensitive data identification task includes a target data source and target sensitive data identification rules. The target sensitive data identification rules are obtained based on target data classification and at least one target data security level configuration. The target data security level corresponds to the importance and sensitivity of the target sensitive data to be identified. An execution module is used to respond to the triggering operation of the target control in the task creation page, execute the sensitive data identification task, and obtain the data to be identified from the target data source; The identification module is used to identify target sensitive data from the data to be identified using the target sensitive data identification rules, and to store the target sensitive data in a storage system corresponding to the target data classification and the target data security level, so as to obtain the target sensitive data from the storage system and perform desensitization processing on the target sensitive data; The data to be identified includes a target data table. Based on the security classification of multiple fields in the target data table, the multiple fields are combined for evaluation to obtain an evaluation result. According to the correlation between the evaluation result and the field values of the multiple fields, the security level of the data table is reclassified to determine the target sensitive data from the target data table.
Citation Information
Patent Citations
Sensitive data processing method and device
CN115080827A
Database data desensitization method, machine readable storage medium and computer equipment
CN115658735A
Data processing method, device and equipment and computer readable storage medium
CN118228308A