Sandbox data isolation and anonymization methods, apparatuses, devices, and media
By building a data isolation strategy in the financial business system and anonymizing sensitive data and obfuscating non-sensitive data, the problems of data leakage and insufficient privacy protection in the sandbox system are solved, and data security and privacy protection are improved.
Patent Information
- Application Number
- CN202411512343.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-28
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2044-10-28
AI Technical Summary
In the existing technology, the sandbox system of the financial business system cannot completely isolate the production environment, and there are problems such as data leakage and insufficient user privacy protection.
By building a data isolation strategy and setting up a sandbox environment, classifying sensitive data and non-sensitive data, anonymizing sensitive data and obfuscating non-sensitive data, data access is monitored in real time and security log records are generated.
Effectively reduce the risk of information leakage, protect user privacy, ensure data security and availability, and provide a reliable security audit basis.
Smart Images

Figure CN119377946B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data security and financial technology, and particularly relates to a sandbox data isolation and anonymization method and device, an electronic device and a computer readable storage medium. BACKGROUND
[0002] Financial business system data isolation and anonymization is an important solution technology in the field of data security technology, mainly used to ensure that the sandbox system is completely isolated from the production environment, and to randomly process sensitive fields in the data to avoid leakage of real user data during testing. The open bank sandbox system is a test platform for simulating a real environment for third-party developers and partners to perform integration testing in the environment, and it is crucial to protect the safety and privacy of user data in this environment.
[0003] Currently, the industry mainly creates isolated container environments to isolate different applications or developers when running on the same physical server, but there are some defects and deficiencies: first, although the sandbox system can simulate some real environment, it cannot completely restore all complexities and risks, so it cannot cover all potential problems and vulnerabilities. Second, although isolation measures are taken, the risk of data leakage or cross-access still exists in some cases. In addition, the anonymization technology of traditional solutions cannot provide comprehensive data protection capabilities, and there are many problems such as destroying the usability and testability of data.
[0004] The existing technology has the problems of low data security and poor user privacy protection function. SUMMARY
[0005] The present application provides a sandbox data isolation and anonymization method, device, electronic device and computer readable storage medium, which mainly aims to solve the problems of low data security and poor user privacy protection function.
[0006] In a first aspect, to achieve the above object, the present application provides a sandbox data isolation and anonymization method, comprising:
[0007] constructing a data isolation strategy according to the obtained financial business data;
[0008] building a sandbox environment according to the data isolation strategy;
[0009] safely classifying the financial business data in the sandbox environment to obtain sensitive data and non-sensitive data;
[0010] anonymizing the sensitive data to obtain anonymous data;
[0011] performing data fuzzing on the non-sensitive data to obtain desensitized data;
[0012] Data access to the anonymous data and the desensitized data is monitored in real time in the sandbox environment to obtain security log records of the sandbox environment.
[0013] In a second aspect, the present invention further provides a sandbox data isolation and anonymization device, the device comprising:
[0014] A policy acquisition module is used to build a data isolation policy based on the acquired financial business data;
[0015] An environment building module, used to build a sandbox environment according to the data isolation strategy;
[0016] A data classification module, configured to perform security classification on the financial business data in the sandbox environment to obtain sensitive data and non-sensitive data;
[0017] A data anonymization module, used to anonymize the sensitive data to obtain anonymous data;
[0018] A data obfuscation module is used to obfuscate the non-sensitive data to obtain desensitized data;
[0019] A real-time monitoring module is used to monitor data access to the anonymous data and the desensitized data in real time in the sandbox environment to obtain security log records of the sandbox environment.
[0020] In a third aspect, the present invention further provides an electronic device, comprising:
[0021] at least one processor; and,
[0022] a memory communicatively connected to the at least one processor; wherein,
[0023] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to perform the sandbox data isolation and anonymization method described above.
[0024] In a fourth aspect, the present invention also provides a computer-readable storage medium, in which at least one computer program is stored. The at least one computer program is executed by a processor in an electronic device to implement the above-mentioned sandbox data isolation and anonymization method.
[0025] The application constructs a data isolation strategy according to obtained financial service data, builds a sandbox environment according to the data isolation strategy, safely classifies the financial service data in the sandbox environment, obtains sensitive data and non-sensitive data, distinguishes the sensitive data from the non-sensitive data, reduces the risk of information leakage when the data is used, anonymizes the sensitive data, obtains anonymous data, randomly generated initial vectors enhance the security of encryption, ensure that even the same sensitive data generates different anonymous data in different encryption processes, thereby preventing attackers from analyzing the anonymous data, performs data fuzzing on the non-sensitive data, obtains desensitized data, retains the statistical characteristics of the data and reduces the risk of leaking personal identity, monitors the data access of the anonymous data and the desensitized data in the sandbox environment in real time, obtains the security log record of the sandbox environment, provides a reliable data basis for subsequent security audit and analysis, effectively improves the data security and better protects the privacy of users. BRIEF DESCRIPTION OF DRAWINGS
[0026] In order to more clearly illustrate the technical solutions of the embodiments of the application, the following will briefly introduce the drawings needed to be used in the description of the embodiments of the application. Obviously, the drawings in the following description are only some embodiments of the application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of these drawings.
[0027] Figure 1 is an application environment diagram of the sandbox data isolation and anonymization method in an embodiment of the application;
[0028] Figure 2 is a flow diagram of the sandbox data isolation and anonymization method provided by an embodiment of the application;
[0029] Figure 3 is a module diagram of the sandbox data isolation and anonymization device provided by an embodiment of the application;
[0030] Figure 4 is a structure diagram of the electronic device for implementing the sandbox data isolation and anonymization method provided by an embodiment of the application;
[0031] Figure 5 is another structure diagram of the electronic device for implementing the sandbox data isolation and anonymization method provided by an embodiment of the application.
[0032] The implementation of the object of the application, the functional characteristics and the advantages will be further described with reference to the embodiments and the drawings. DETAILED DESCRIPTION
[0033] In order to enable those skilled in the art to better understand the technical solutions of the present disclosure, and to fully understand and implement how the present disclosure applies technical means to solve technical problems and achieve the corresponding technical effects, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, not all of the embodiments. The embodiments of the present disclosure and the various features in the embodiments can be combined with each other without conflict, and the technical solutions formed are all within the scope of protection of the present disclosure. Based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in this field without making creative work should fall within the scope of protection of the present disclosure.
[0034] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present disclosure described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, apparatus, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0035] The embodiments of the present application provide a sandbox data isolation and anonymization method, and the execution subject of the sandbox data isolation and anonymization method includes but is not limited to at least one of the electronic devices such as a server, a terminal, etc. that can be configured to execute the device provided by the embodiments of the present application. In other words, the sandbox data isolation and anonymization method can be executed by software or hardware installed on a terminal device or a server device. The server includes but is not limited to: a single server, a server cluster, a cloud server or a cloud server cluster, etc. The server can be an independent server, or it can be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.
[0036] The sandbox data isolation and anonymization method of the embodiment of the present invention can be applied to Figure 1application environment. The client communicates with the server through the network. The server can construct a data isolation strategy based on the financial business data obtained by the client, build a sandbox environment according to the data isolation strategy, perform security classification on the financial business data in the sandbox environment, obtain sensitive data and non-sensitive data, distinguish sensitive data from non-sensitive data, reduce the risk of information leakage when the data is used, anonymize the sensitive data to obtain anonymous data, and obfuscate the non-sensitive data to obtain desensitized data. In the sandbox environment, data access to the anonymous data and the desensitized data is monitored in real time to obtain security log records of the sandbox environment, and the final security log records are fed back to the client. The client can be, but is not limited to, various personal computers, laptops, smart phones, tablet computers and portable wearable devices. The server can be implemented with an independent server or a server cluster consisting of multiple servers. The present invention is described in detail below through specific embodiments.
[0037] Reference Figure 2 FIG. 1 is a flow chart of a sandbox data isolation and anonymization method according to an embodiment of the present invention. In this embodiment, the sandbox data isolation and anonymization method includes:
[0038] S1. Build a data isolation strategy based on the acquired financial business data.
[0039] In an embodiment of the present invention, financial business data is isolated based on the needs of the financial business. Determining the data isolation strategy includes determining the granularity, levels, and boundaries of data isolation. The sensitivity of data required by financial business needs, such as transaction data, user information, and system logs, varies, and the granularity of isolation also varies. Access to data by a visitor can be determined based on the visitor's role, such as developer or application, with different isolation levels corresponding to different roles.
[0040] Data isolation is a key measure for ensuring data security and compliance in financial services, especially when handling sensitive information and adhering to regulatory requirements. To effectively implement data isolation strategies, it's important to clearly define the granularity, layers, and boundaries of data isolation.
[0041] Specifically, the data isolation strategy is constructed based on the acquired financial business data, including:
[0042] extracting user level, application level and data classification information from the financial service data;
[0043] Matching customer information in the financial service data to a preset customer service personnel according to the user level to obtain user level isolation granularity;
[0044] Isolating the financial services in the financial service data according to the application level to obtain application level isolation granularity;
[0045] Generating a data classification granularity of the financial business data using the data classification information;
[0046] Extracting employee data from the financial business data;
[0047] Generate data isolation levels and boundaries based on the access rights of the employee data;
[0048] A data isolation policy is constructed using the user-level isolation granularity, the application-level isolation granularity, the data classification granularity, the hierarchy, and the boundary.
[0049] Furthermore, financial companies provide a variety of financial services, including personal loans, investment management, and payment processing. When processing customer data, the following data isolation granularity is set:
[0050] User-level isolation: Customer service representatives can only access loan application data related to their own clients and cannot access information about other clients. Investment advisors can only access their clients' investment account information. Application-level isolation: Data between the loan management system and the investment management system is completely isolated, ensuring that information between the two systems cannot be accessed, thereby avoiding customer trust issues caused by data leaks. Data classification isolation: Data is divided into four categories: public data (such as interest rate information), internal data (such as company policies), sensitive data (such as customers' social security numbers), and highly sensitive data (such as bank card numbers). Highly sensitive data is subject to stricter isolation and protection.
[0051] At the data isolation level, the following measures were taken: Role-based access control (RBAC) was implemented to ensure that employees in different roles could only access data relevant to their work. For example, the compliance department could access all types of data for audits, but ordinary customer service representatives could only access limited information.
[0052] The boundary of data isolation means that personal customer data (such as name, address, contact information) is completely separated from internal company data (such as employee information and company financial data). Customer personal information should not be mixed with internal operational data.
[0053] Data isolation establishes clear access permissions, ensuring that only authorized employees can access specific data categories. For example, only compliance auditors can view sensitive data. Data transmission boundaries also exist: when data transmission is necessary, all transmissions are encrypted and integrity checked during transmission. For example, when loan application data is shared with a third-party credit reporting company, it is transmitted using a secure API and encrypted with HTTPS.
[0054] By extracting user-level, application-level, and data classification information from financial business data, we can precisely isolate customer information from financial services. This isolation not only matches customer information to specific user levels based on pre-defined customer service personnel, ensuring personalized and efficient service, but also enables effective management of different financial services at the application level. Data classification information helps us refine data management and achieve more flexible classification granularity. Furthermore, proactively considering employee data access permissions and establishing appropriate hierarchies and boundaries can strengthen data security and compliance, improving the efficiency and security of data management.
[0055] S2. Build a sandbox environment according to the data isolation strategy.
[0056] In an embodiment of the present invention, a secure testing and development environment is created to facilitate analysis, testing, and application development of the financial business data without affecting the production environment.
[0057] In detail, the sandbox environment is established according to the data isolation strategy, including:
[0058] Utilizing the user-level isolation granularity in the data isolation policy to configure an access environment for the customer service personnel;
[0059] Creating different sandbox containers according to the application-level isolation granularity in the data isolation policy;
[0060] Setting different access policies according to the data classification granularity in the data isolation policy;
[0061] The sandbox environment is built according to the access environment, the sandbox container and the access policy.
[0062] Specifically, the access environment is categorized based on the users and applications in the sandbox environment. Users are grouped, such as developers, testers, and third-party applications. Specific permissions are assigned to each group, and different roles or applications can have different access rights. Specific permissions are configured for each role, such as create, read, update, and delete. Role permissions are dynamically adjusted based on business needs to ensure that each role can only access data within its scope of responsibility. Dynamic permission policies are also set based on visitor attributes, such as role, IP address, time, and device. Different permission levels are configured based on attributes such as time, location, and device type. The configured permission rules are formally applied in the sandbox environment to ensure that all access requests comply with the permission policy. The permissions of each role or application are tested item by item to ensure that permission allocation is accurate.
[0063] S3. Security classification is performed on the financial business data in the sandbox environment to obtain sensitive data and non-sensitive data.
[0064] Extracting sensitive features from the financial business data is crucial. These features may include personal information about customers, transaction records, and more. Using these sensitive features, we can identify sensitive data within the financial business data and classify non-sensitive portions of the standard business data as non-sensitive data, thereby providing a more secure environment for subsequent data analysis and application.
[0065] In an embodiment of the present invention, the security classification of the financial business data in the sandbox environment to obtain sensitive data and non-sensitive data includes:
[0066] Calculating an average value of the financial business data;
[0067] Filling missing values of the financial business data with the average value to obtain standard business data;
[0068] Extracting sensitive features of the standard business data;
[0069] Using the sensitive features to match the standard business data one by one to obtain sensitive data;
[0070] The remaining data in the standard business data except the sensitive data is regarded as non-sensitive data.
[0071] In detail, sensitive data includes: personal identity information: such as name, address, ID number, date of birth, etc.; financial information: such as bank account information, credit card number, transaction records, assets and liabilities, etc.; health information: if relevant, any data related to the customer's health status; trade secrets: such as internal company financial reports, business plans, etc.
[0072] By calculating the average value of financial business data and filling in missing values, standardized business data is generated. This standardization process helps improve data integrity and consistency, making subsequent analysis more reliable. Extracting and matching sensitive features can effectively identify and protect information involving personal privacy or commercial secrets, distinguishing sensitive data from non-sensitive data, reducing the risk of information leakage during data use, and providing a clear perspective for subsequent business decisions and data analysis.
[0073] S4. Anonymize the sensitive data to obtain anonymous data.
[0074] While ensuring data validity and availability, we protect personal or sensitive information from being leaked. We also design anonymization rules and methods based on financial business needs, data types, and privacy protection objectives. We also design different strategies, such as data masking and encryption, based on varying levels of sensitivity. We encrypt sensitive data requiring high protection using encryption algorithms to ensure that even in the event of a data leak, the plaintext data cannot be directly accessed.
[0075] SM4 (National Secret Algorithm) is a symmetric encryption algorithm primarily used to protect sensitive data. SM4 uses a 128-bit key and processes data in 128-bit blocks, meaning each encrypted or decrypted data block is 16 bytes long. It supports multiple encryption modes, including Electronic Codebook (ECB), Cipher Block Chaining (CBC), and Counter Transmission Control (CTR). The following steps describe how to encrypt data using the SM4 algorithm.
[0076] In the embodiment of the present invention, anonymizing the sensitive data to obtain anonymous data includes:
[0077] Get a randomly generated initial vector;
[0078] generating a symmetric key based on the sensitive data;
[0079] Determine whether the size of the sensitive data meets the preset SM4 block size;
[0080] If the size of the sensitive data does not conform to the preset SM4 block size, padding the sensitive data;
[0081] If the size of the sensitive data meets the preset SM4 block size, the sensitive data is sent to a preset SM4 encryptor using the initial vector and the symmetric key to obtain anonymous data.
[0082] Specifically, the anonymous data is sent to a pre-set, initialized SM4 decryptor using the same key and initialization vector, generating padded sensitive data. Since the sensitive data was padded during encryption, the padding needs to be removed after decryption to restore the original sensitive data. This removal typically uses the same padding scheme used for encryption.
[0083] Randomly generated initialization vectors enhance encryption security, ensuring that even identical sensitive data will generate different anonymized data across different encryption processes, thus preventing attackers from analyzing the anonymized data. By generating a pair of symmetric keys, data access is effectively controlled, ensuring that only users holding the key can decrypt the data. Sensitive data size verification and necessary padding ensure that the data complies with the block size requirements of the SM4 algorithm, enhancing encryption integrity and effectiveness. This not only protects sensitive information but also increases the flexibility and security of the system's data processing, thereby reducing the risk of data leakage.
[0084] S5. Obfuscate the non-sensitive data to obtain desensitized data.
[0085] Data generalization is a common data obfuscation technique that protects privacy by converting specific data into broader categories or ranges. Generalizing non-sensitive data effectively protects user privacy and ensures data security, while also extracting useful information.
[0086] In an embodiment of the present invention, the step of performing data obfuscation on the non-sensitive data to obtain desensitized data includes:
[0087] Generate generalized rules based on non-sensitive data;
[0088] The non-sensitive data is converted according to the generalization rule to obtain desensitized data.
[0089] Specifically, generalization rules are developed based on the data type and application scenario of the non-sensitive data. For example, age can be defined as age groups (e.g., "20-29 years old," "30-39 years old"); geographic location can be converted to a city or province name; and income can be replaced with a specific income range (e.g., "less than 5,000 yuan," "5,000-10,000 yuan").
[0090] Developing generalization rules based on non-sensitive data can effectively transform specific information into broader categories. For example, age can be broken down into age groups, addresses can be simplified into city or province names, and income levels can be broken down into ranges. These generalization rules generate desensitized data during the conversion process, preserving the data's statistical characteristics while reducing the risk of identity disclosure. This ensures privacy protection and data security while providing reliable information support for data analysis and decision-making.
[0091] S6. Perform real-time monitoring on data access to the anonymous data and the desensitized data in the sandbox environment to obtain security log records of the sandbox environment.
[0092] In this sandbox environment, all data operations are monitored in real time to ensure that any access to sensitive data is recorded and any abnormal operations or potential data leaks are detected promptly. Key monitoring points include data read and write operations, data transmission, user authentication, and encryption and decryption of sensitive data.
[0093] In an embodiment of the present invention, the real-time monitoring of data access to the anonymous data and the desensitized data in the sandbox environment to obtain a security log record of the sandbox environment includes:
[0094] Monitoring operation records of the anonymous data and the desensitized data;
[0095] Determining whether the operation record is a preset abnormal event;
[0096] If the operation record is not a preset abnormal event, continue to monitor the operation records of the anonymous data and the desensitized data;
[0097] If the operation record is a preset abnormal event, identifying the level of the abnormal event;
[0098] If the level of the abnormal event is a preset low level, an alarm is triggered and real-time monitoring continues;
[0099] If the level of the abnormal event is the preset medium level, the account of the abnormal event is automatically locked;
[0100] If the level of the abnormal event is a preset high level, immediately disconnect the terminal connection of the abnormal event;
[0101] The normal events and the abnormal events are aggregated to obtain a security log record of the sandbox environment.
[0102] Recording and analyzing operations on anonymous and desensitized data not only enables real-time monitoring and response to potential security threats, but also enables the implementation of appropriate countermeasures based on the severity of abnormal events, ensuring effective management of low-, medium-, and high-level threats. For example, triggering alerts for continuous monitoring of low-level events, automatically locking accounts for medium-level events, and immediately disconnecting terminals for high-level events can quickly mitigate potential losses. Furthermore, aggregating log records of both normal and abnormal events provides a reliable data foundation for subsequent security audits and analysis, helping organizations continuously optimize security strategies and enhance their protection capabilities.
[0103] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0104] like Figure 3 , which is a functional module diagram of a sandbox data isolation and anonymization device provided by one embodiment of the present invention.
[0105] In the embodiment of the present disclosure, a sandbox data isolation and anonymization device is provided, which corresponds one-to-one with the sandbox data isolation and anonymization method of the above embodiment. Figure 3 As shown, the sandbox data isolation and anonymization device 100 can be installed in an electronic device. According to the functions to be implemented, the sandbox data isolation and anonymization device 100 includes a policy acquisition module 101, an environment construction module 102, a data classification module 103, a data anonymization module 104, a data obfuscation module 105, and a real-time monitoring module 106. The functional modules are described in detail as follows:
[0106] A policy acquisition module 101 is used to construct a data isolation policy based on the acquired financial business data;
[0107] An environment building module 102 is used to build a sandbox environment according to the data isolation strategy;
[0108] A data classification module 103 is used to perform security classification on the financial business data in the sandbox environment to obtain sensitive data and non-sensitive data;
[0109] The data anonymization module 104 is used to anonymize the sensitive data to obtain anonymous data;
[0110] A data obfuscation module 105 is used to obfuscate the non-sensitive data to obtain desensitized data;
[0111] The real-time monitoring module 106 is used to monitor data access to the anonymous data and the desensitized data in real time in the sandbox environment to obtain security log records of the sandbox environment.
[0112] In one embodiment, when constructing a data isolation policy based on acquired financial service data, the policy acquisition module 101 is configured to:
[0113] extracting user level, application level and data classification information from the financial service data;
[0114] Matching customer information in the financial service data to a preset customer service personnel according to the user level to obtain user level isolation granularity;
[0115] Isolating the financial services in the financial service data according to the application level to obtain application level isolation granularity;
[0116] Generating a data classification granularity of the financial business data using the data classification information;
[0117] Extracting employee data from the financial business data;
[0118] Generate data isolation levels and boundaries based on the access rights of the employee data;
[0119] A data isolation policy is constructed using the user-level isolation granularity, the application-level isolation granularity, the data classification granularity, the hierarchy, and the boundary.
[0120] In one embodiment, when executing the construction of the sandbox environment according to the data isolation policy, the environment construction module 102 is used to:
[0121] Utilizing the user-level isolation granularity in the data isolation policy to configure an access environment for the customer service personnel;
[0122] Creating different sandbox containers according to the application-level isolation granularity in the data isolation policy;
[0123] Setting different access policies according to the data classification granularity in the data isolation policy;
[0124] The sandbox environment is built according to the access environment, the sandbox container and the access policy.
[0125] In one embodiment, when the data classification module 103 performs security classification on the financial business data in the sandbox environment to obtain sensitive data and non-sensitive data, it is configured to:
[0126] Calculating an average value of the financial business data;
[0127] Filling missing values of the financial business data with the average value to obtain standard business data;
[0128] Extracting sensitive features of the standard business data;
[0129] Using the sensitive features to match the standard business data one by one to obtain sensitive data;
[0130] The remaining data in the standard business data except the sensitive data is regarded as non-sensitive data.
[0131] In one embodiment, when the data anonymization module 104 performs anonymization on the sensitive data to obtain anonymous data, it is configured to:
[0132] Get a randomly generated initial vector;
[0133] generating a symmetric key based on the sensitive data;
[0134] Determine whether the size of the sensitive data meets the preset SM4 block size;
[0135] If the size of the sensitive data does not conform to the preset SM4 block size, padding the sensitive data;
[0136] If the size of the sensitive data meets the preset SM4 block size, the sensitive data is sent to a preset SM4 encryptor using the initial vector and the symmetric key to obtain anonymous data.
[0137] In one embodiment, when the data obfuscation module 105 performs data obfuscation on the non-sensitive data to obtain desensitized data, it is configured to:
[0138] Generate generalized rules based on non-sensitive data;
[0139] The non-sensitive data is converted according to the generalization rule to obtain desensitized data.
[0140] In one embodiment, when the real-time monitoring module 106 performs real-time monitoring of data access to the anonymous data and the desensitized data in the sandbox environment and obtains a security log record of the sandbox environment, it is configured to:
[0141] Monitoring operation records of the anonymous data and the desensitized data;
[0142] Determining whether the operation record is a preset abnormal event;
[0143] If the operation record is not a preset abnormal event, continue to monitor the operation records of the anonymous data and the desensitized data;
[0144] If the operation record is a preset abnormal event, identifying the level of the abnormal event;
[0145] If the level of the abnormal event is a preset low level, an alarm is triggered and real-time monitoring continues;
[0146] If the level of the abnormal event is the preset medium level, the account of the abnormal event is automatically locked;
[0147] If the level of the abnormal event is a preset high level, immediately disconnect the terminal connection of the abnormal event;
[0148] The normal events and the abnormal events are aggregated to obtain a security log record of the sandbox environment.
[0149] In the present invention, for sandbox data isolation and anonymization, first, a data isolation strategy is constructed based on the acquired financial business data, and a sandbox environment is built according to the data isolation strategy. Then, the financial business data is securely classified in the sandbox environment to obtain sensitive data and non-sensitive data, and sensitive data is distinguished from non-sensitive data, so that the risk of information leakage is reduced when the data is used. The sensitive data is anonymized to obtain anonymous data. The randomly generated initial vector enhances the security of encryption, ensuring that even the same sensitive data will generate different anonymous data in different encryption processes, thereby preventing attackers from analyzing through anonymous data. The non-sensitive data is obfuscated to obtain desensitized data, which not only retains the statistical characteristics of the data but also reduces the risk of personal identity disclosure. Finally, data access to the anonymous data and the desensitized data is monitored in real time in the sandbox environment to obtain security log records of the sandbox environment, providing a reliable data basis for subsequent security audits and analysis, effectively improving data security and better protecting user privacy. The specific limitations of the sandbox data isolation and anonymization device can be found in the limitations of the sandbox data isolation and anonymization method above, which will not be repeated here. Each module in the aforementioned sandbox data isolation and anonymization device may be implemented in whole or in part through software, hardware, or a combination thereof. Each module may be embedded in or independent of a processor in a computer device in hardware form, or may be stored in a computer device memory in software form, so that the processor can call and execute the corresponding operations of each module.
[0150] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 4 As shown. The computer device includes a processor, memory, network interface and database connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes non-volatile and / or volatile storage media and internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external client via a network connection. When the computer program is executed by the processor, it implements the functions or steps on the server side of the sandbox data isolation and anonymization method.
[0151] In one embodiment, a computer device is provided. The computer device may be a client, and its internal structure diagram may be as follows: Figure 5As shown. The computer device includes a processor, memory, a network interface, a display screen, and an input device connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external server via a network connection. When executed by the processor, the computer program implements the client-side functions or steps of the sandbox data isolation and anonymization method.
[0152] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the following steps are performed:
[0153] Build data isolation strategies based on acquired financial business data;
[0154] Building a sandbox environment according to the data isolation strategy;
[0155] Security classification of the financial business data in the sandbox environment to obtain sensitive data and non-sensitive data;
[0156] Anonymizing the sensitive data to obtain anonymous data;
[0157] Obfuscating the non-sensitive data to obtain desensitized data;
[0158] Data access to the anonymous data and the desensitized data is monitored in real time in the sandbox environment to obtain security log records of the sandbox environment.
[0159] In the several embodiments provided by the present invention, it should be understood that the disclosed devices and apparatuses can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For example, the module division is merely a logical function division, and actual implementation may employ other division methods.
[0160] In addition, the functional modules in various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or hardware plus software functional modules.
[0161] Therefore, the embodiments should be considered in all respects as illustrative and non-restrictive, and the scope of the invention is defined by the appended claims rather than the foregoing description, and all changes that come within the meaning and range of equivalents of the claims are intended to be embraced therein. Any reference to a figure in a claim should not be construed as limiting the claim to which it relates.
[0162] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.
[0163] In some implementations of this embodiment, a computer-readable storage medium is provided, on which a computer program is stored, characterized in that when the computer program is executed by a processor, the steps of the method described in the above embodiment are implemented.
[0164] The readable storage medium of the present invention stores a computer program, which, when executed by a processor of an electronic device, can implement:
[0165] Build data isolation strategies based on acquired financial business data;
[0166] Building a sandbox environment according to the data isolation strategy;
[0167] Security classification of the financial business data in the sandbox environment to obtain sensitive data and non-sensitive data;
[0168] Anonymizing the sensitive data to obtain anonymous data;
[0169] Obfuscating the non-sensitive data to obtain desensitized data;
[0170] Data access to the anonymous data and the desensitized data is monitored in real time in the sandbox environment to obtain security log records of the sandbox environment.
[0171] It should be noted that the above functions or steps that can be implemented by the computer-readable storage medium or computer device can be found in the relevant descriptions of the server side and the client side in the aforementioned method embodiment. To avoid repetition, they will not be described one by one here.
[0172] The computer-readable storage medium may also store at least one computer-executable program / instruction, such as a computer-readable instruction. Computer-readable storage media include, but are not limited to, volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Computer-readable storage media may include, for example, read-only memory (ROM), a hard disk, a flash memory, etc. For example, a non-transitory computer-readable storage medium may be connected to a computing device such as a computer, and then, when the computing device executes the computer-readable instructions stored on the computer-readable storage medium, the various methods described above may be performed.
[0173] In addition, the computer device may also include (but is not limited to) a data bus, an input / output (I / O) bus, a display, and input / output devices (eg, keyboard, mouse, speaker, etc.).
[0174] The processor can communicate with external devices via an I / O bus via a wired or wireless network.
[0175] In one embodiment, the at least one computer executable instruction may also be compiled into or constitute a software product / computer program product, wherein one or more computer executable instructions are executed by a processor to perform the various functions and / or method steps in the embodiments described in the present technology.
[0176] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).
[0177] Those skilled in the art will clearly understand that for the sake of convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.
[0178] In the embodiments provided by the present disclosure, it should be understood that the disclosed apparatus and method can also be implemented in other manners. The embodiments described above are merely exemplary for describing the present disclosure. For example, the flowcharts and block diagrams in the accompanying drawings show the possible implementation architectures, functions and operation of the apparatus, method and computer program product according to the embodiments of the present disclosure. In this regard, each block in the flowcharts and block diagrams can represent a module, a program segment or a part of code, which contains one or more executable instructions for implementing the specified logic function. It should also be noted that, in some alternative implementations, the functions noted in the blocks can occur in different orders from those noted in the accompanying drawings. For example, two consecutive blocks can actually be executed substantially in parallel, and sometimes they can be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and the combination of blocks in the block diagrams and / or flowcharts, can be implemented by a special-purpose hardware-based system for implementing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.
[0179] It should be noted that, in the present disclosure, the term "comprising" or "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article or device. Without more limitations, the element limited by the statement "including a" does not exclude the presence of additional same elements in the process, method, article or device including the element.
[0180] The above-described embodiments are merely used to illustrate the technical solutions of the present disclosure, rather than limit them; although the present disclosure has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: the technical solutions recorded in the foregoing embodiments can be modified, or some technical features can be replaced by equivalent replacements; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present disclosure, and should be included in the protection scope of the present disclosure.
[0181] It should be noted that, in the embodiments of the present disclosure, if non-company software tools or components appear, they are only used for example introduction, and do not represent actual use.
Claims
1. A sandbox data isolation and anonymization method, characterized in that: The method comprises: Build data isolation strategies based on acquired financial business data; Building a sandbox environment according to the data isolation strategy; Security classification of the financial business data in the sandbox environment to obtain sensitive data and non-sensitive data; Anonymizing the sensitive data to obtain anonymous data; Obfuscating the non-sensitive data to obtain desensitized data; Performing real-time monitoring of data access to the anonymous data and the desensitized data in the sandbox environment to obtain security log records of the sandbox environment; Among them, the constructing of a data isolation strategy based on the acquired financial business data includes: extracting user level, application level and data classification information from the financial business data; matching customer information in the financial business data to a preset customer service personnel according to the user level to obtain user level isolation granularity; isolating the financial business in the financial business data according to the application level to obtain application level isolation granularity; generating data classification granularity of the financial business data using the data classification information; extracting employee data from the financial business data; generating data isolation levels and boundaries based on the access rights of the employee data; and constructing a data isolation strategy using the user level isolation granularity, the application level isolation granularity, the data classification granularity, the levels and the boundaries.
2. The sandbox data isolation and anonymization method according to claim 1, characterized in that: The step of establishing a sandbox environment according to the data isolation strategy includes: Utilizing the user-level isolation granularity in the data isolation policy to configure an access environment for the customer service personnel; Creating different sandbox containers according to the application-level isolation granularity in the data isolation policy; Setting different access policies according to the data classification granularity in the data isolation policy; The sandbox environment is built according to the access environment, the sandbox container and the access policy.
3. The sandbox data isolation and anonymization method according to claim 1, characterized in that: The security classification of the financial business data in the sandbox environment to obtain sensitive data and non-sensitive data includes: Calculating an average value of the financial business data; Filling missing values of the financial business data with the average value to obtain standard business data; Extracting sensitive features of the standard business data; Using the sensitive features to match the standard business data one by one to obtain sensitive data; The remaining data in the standard business data except the sensitive data is regarded as non-sensitive data.
4. The sandbox data isolation and anonymization method according to claim 1, characterized in that: The anonymizing of the sensitive data to obtain anonymous data includes: Get a randomly generated initial vector; generating a symmetric key based on the sensitive data; Determine whether the size of the sensitive data meets the preset SM4 block size; If the size of the sensitive data does not conform to the preset SM4 block size, padding the sensitive data; If the size of the sensitive data meets the preset SM4 block size, the sensitive data is sent to a preset SM4 encryptor using the initial vector and the symmetric key to obtain anonymous data.
5. The sandbox data isolation and anonymization method according to claim 1, characterized in that: The step of performing data obfuscation on the non-sensitive data to obtain desensitized data includes: Generate generalized rules based on non-sensitive data; The non-sensitive data is converted according to the generalization rule to obtain desensitized data.
6. The sandbox data isolation and anonymization method according to claim 1, characterized in that: The real-time monitoring of data access to the anonymous data and the desensitized data in the sandbox environment to obtain security log records of the sandbox environment includes: Monitoring operation records of the anonymous data and the desensitized data; Determining whether the operation record is a preset abnormal event; If the operation record is not a preset abnormal event, continue to monitor the operation records of the anonymous data and the desensitized data; If the operation record is a preset abnormal event, identifying the level of the abnormal event; If the level of the abnormal event is a preset low level, an alarm is triggered and real-time monitoring continues; If the level of the abnormal event is the preset medium level, the account of the abnormal event is automatically locked; If the level of the abnormal event is a preset high level, immediately disconnect the terminal connection of the abnormal event; Normal events and abnormal events are aggregated to obtain security log records of the sandbox environment.
7. A sandbox data isolation and anonymization device, used to implement the sandbox data isolation and anonymization method according to any one of claims 1 to 6, characterized in that: The device comprises: A policy acquisition module is used to build a data isolation policy based on the acquired financial business data; An environment building module, used to build a sandbox environment according to the data isolation strategy; A data classification module, configured to perform security classification on the financial business data in the sandbox environment to obtain sensitive data and non-sensitive data; A data anonymization module, used to anonymize the sensitive data to obtain anonymous data; A data obfuscation module is used to obfuscate the non-sensitive data to obtain desensitized data; A real-time monitoring module is used to monitor data access to the anonymous data and the desensitized data in real time in the sandbox environment to obtain security log records of the sandbox environment.
8. An electronic device, characterized in that: The electronic device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to perform the sandbox data isolation and anonymization method according to any one of claims 1 to 6.
9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the sandbox data isolation and anonymization method according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Sandbox type code extension isolation device and method
CN117874749A
Efficient unsupervised anomaly detection on homomorphically encrypted data
US20210092137A1