Notation-based desensitization and anti-desensitization processing method and system

By adding desensitization annotations containing encryption algorithms and desensitization rules to sensitive data fields, automatic desensitization and anti-desensitization processing of sensitive data is achieved, solving the problems of code redundancy and low development efficiency in the prior art, and improving the system's maintainability and development efficiency.

CN119939616APending Publication Date: 2025-05-06SHANGHAI YOUKA NETWORK TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411706284.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-11-26
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

When processing sensitive data, developers need to write business logic based on specific desensitization and anti-desensitization needs, resulting in code redundancy, reduced maintenance and reduced development efficiency.

Method used

Desensitization and anti-desensitization treatment methods are adopted based on the annotation, and desensitization annotations are added in advance for fields that require desensitization and anti-desensitization treatment. The annotation includes encryption algorithms and desensitization rules. By judging user requests and annotation information, desensitization or anti-desensitization processing is automatically performed.

Benefits of technology

The universality of desensitization and anti-desensitization is achieved, which reduces development workload, improves development efficiency, reduces code invasiveness, and reduces maintenance costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939616A_ABST
    Figure CN119939616A_ABST
Patent Text Reader

Abstract

The invention provides an annotation-based desensitization and anti-desensitization processing method and system, and relates to the technical field of sensitive data management.The method comprises the steps that a desensitization annotation is added in advance, and the desensitization annotation comprises a field-associated encryption algorithm and a desensitization rule; when a user makes a sensitive data viewing request, if a sensitive field needing to be viewed has a desensitization annotation, desensitization can be carried out, but the user does not make an anti-desensitization request, the stored encrypted sensitive field is decrypted according to an associated encryption algorithm, then desensitization is carried out according to a desensitization rule, and then desensitization data is displayed; if the desensitization annotation exists, desensitization can be carried out, and if the user makes an anti-desensitization request, the stored encrypted sensitive field is decrypted according to an associated encryption algorithm, and then anti-desensitization data is displayed. The method has the beneficial effects that the tedious process of independently developing each business needing desensitization and anti-desensitization can be avoided, the development workload is greatly reduced, the development efficiency is improved, and meanwhile, the code invasiveness is also reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of sensitive data management, and in particular to a method and system for desensitization and anti-desensitization processing based on annotations. Background Art

[0002] With the rapid development of information technology, enterprises have accumulated a large amount of data in their daily operations, including sensitive information of users. This information includes but is not limited to mobile phone numbers, vehicle identification numbers (VIN), ID numbers, etc., which are an important part of user privacy. In order to protect the privacy rights and interests of users and meet business needs, enterprises must take effective data protection measures.

[0003] Data desensitization technology has emerged as an important means to balance data utilization and privacy protection. Currently, in order to process sensitive data, we usually first identify the data items that need to be desensitized according to business needs and traverse the data. Then, we will decrypt the data so that it can be processed according to the established desensitization rules. The desensitization process may include replacement, masking, encryption or other technical means to ensure that sensitive information is not leaked when the data is shared or stored.

[0004] In some specific scenarios, such as auditing, supervision, or specific business needs, it is necessary to view the original sensitive data. At this time, the desensitized data needs to be reversed to restore the original data. To achieve reverse desensitization, that is, to restore the original state of the data, we need to design an additional processing flow. This usually involves storing metadata when desensitizing data. These metadata record the desensitization rules and operations so that the original data can be restored in reverse when necessary. For example, if encryption desensitization is used, the decryption key needs to be retained; if replacement desensitization is used, the mapping relationship between the original data and the desensitized data needs to be retained.

[0005] In short, developers will use the above solution to write corresponding logic according to specific desensitization and anti-desensitization requirements to meet the system's requirements for desensitization and anti-desensitization of sensitive data. However, the above solution involves the development of various business logics, which is highly invasive. If the desensitization algorithm or encryption and decryption algorithm is changed later, all the business logic used needs to be changed, which may lead to code redundancy, reduced maintainability and reduced development efficiency, which will have an adverse impact on the stability of the system, the universality of functional logic and user experience. Summary of the invention

[0006] In view of the problems existing in the prior art, the present invention provides a method for desensitization and anti-desensitization processing based on annotations, which adds desensitization annotations to fields that need to be desensitized and anti-desensitized in advance, and the desensitization annotations contain encryption algorithms and desensitization rules associated with the fields; the method comprises:

[0007] Step S1: when a user makes a request to view sensitive data, it is determined whether the sensitive field that the user needs to view has the desensitizing annotation:

[0008] If not, display the encrypted sensitive fields to the user and then exit;

[0009] If yes, go to step S2;

[0010] Step S2, determining whether the sensitive field can be desensitized:

[0011] If yes, go to step S3;

[0012] If not, go to step S4;

[0013] Step S3, determining whether the user has made an anti-desensitization request for the sensitive field:

[0014] If not, decrypt the stored encrypted sensitive field according to the associated encryption algorithm, and then desensitize the decrypted sensitive field according to the desensitization rule to display the desensitized data to the user, and then exit;

[0015] If yes, go to step S4;

[0016] Step S4, decrypting the stored encrypted sensitive field according to the associated encryption algorithm to display anti-desensitization data to the user.

[0017] In a preferred embodiment of the present invention, step S2 comprises:

[0018] Get the field type of the sensitive field and determine whether the field type is a string:

[0019] If yes, it means that the sensitive field can be desensitized;

[0020] If not, it means that the sensitive field cannot be desensitized.

[0021] In a preferred embodiment of the present invention, when the user makes the anti-desensitization request, an authorization verification process is also included:

[0022] Step A1, generating a verification code and associating it with the corresponding user and then sending it to the system administrator. When the system administrator authorizes an anti-desensitization query, the verification code is sent to the corresponding user for input;

[0023] Step A2: upon receiving the valid verification code input by the user, desensitizing the sensitive field to display the desensitized data to the user.

[0024] In a preferred embodiment of the present invention, before executing step A1, it also includes determining whether the user has the authority to perform an anti-desensitization query:

[0025] If yes, go to step A1;

[0026] If not, the sensitive fields are desensitized to display the desensitized data to the user, and then exit.

[0027] In a preferred embodiment of the present invention, the authorization verification process also includes a user behavior analysis process:

[0028] If the number of times the user makes the anti-desensitization request within the preset time period is greater than the preset number and all authorization verifications are passed, the verification code will not be generated and the anti-desensitization data will be directly displayed to the user.

[0029] In a preferred embodiment of the present invention, a business service cluster is pre-deployed, including a plurality of distributed service nodes. When the user enters a valid verification code, anti-desensitization information is extracted from the anti-desensitization request and broadcast to all the service nodes. When each service node determines that the anti-desensitization information is its own service message, a corresponding anti-desensitization instruction is generated for caching;

[0030] Then, when the user makes the anti-desensitization request, the service node determines whether the anti-desensitization instruction corresponding to the anti-desensitization request is cached:

[0031] If not, desensitizing the sensitive field to display the desensitized data to the user;

[0032] If so, the service node performs lock snatching, and desensitizes the sensitive field when the lock snatching is successful to display the desensitized data to the user, and desensitizes the sensitive field when the lock snatching fails to display the desensitized data to the user.

[0033] In a preferred embodiment of the present invention, before performing desensitization on the sensitive field, the method further includes:

[0034] The sensitive field that needs to be de-desensitized is determined according to the position information contained in the de-desensitization instruction.

[0035] In a preferred embodiment of the present invention, after the sensitive field is desensitized, the method further includes:

[0036] The corresponding anti-desensitization instruction is broadcast to all the service nodes. When each service node determines that the anti-desensitization instruction is its own service message, it clears the corresponding anti-desensitization instruction in the cache.

[0037] In a preferred embodiment of the present invention, the anti-desensitization request includes a uniform resource locator, location information of the sensitive field for which anti-desensitization is requested, and applicant information;

[0038] The anti-desensitization information includes the uniform resource locator and the location information;

[0039] The anti-desensitization instruction includes the location information;

[0040] Each of the service nodes determines whether the anti-massifying information is its own service message based on the uniform resource locator.

[0041] The present invention also provides a system for desensitization and anti-desensitization processing based on annotations, applying the above method, the system comprises:

[0042] A database storing a plurality of encrypted fields, wherein a desensitizing annotation is added to the fields that need to be desensitized and desensitized, and the desensitizing annotation includes an encryption algorithm and a desensitizing rule associated with the field;

[0043] Data query interface, used for users to make sensitive data viewing and anti-massification requests;

[0044] A query processing module is connected to the data query interface and the database respectively, and the query processing module includes:

[0045] A first query unit, configured to display the encrypted sensitive field to the user when the user makes a request to view sensitive data and the sensitive field that the user needs to view does not have the desensitizing annotation;

[0046] A second query unit is configured to decrypt the stored encrypted sensitive field according to the associated encryption algorithm when the desensitizing annotation exists in the sensitive field that the user needs to view, but the sensitive field cannot be desensitized or the sensitive field can be desensitized but the user does not make a desensitization request for the sensitive field, so as to display the desensitized data to the user;

[0047] The third query unit is used to decrypt the stored encrypted sensitive field according to the associated encryption algorithm when the sensitive field can be desensitized and the user makes a desensitization request for the sensitive field, and then desensitize the decrypted sensitive field according to the desensitization rule to display the desensitized data to the user.

[0048] The above technical solution has the following advantages or beneficial effects:

[0049] 1) By adding a desensitizing annotation containing an encryption algorithm and desensitizing rules to the field, when it is necessary to view sensitive fields, the sensitive fields can be desensitized based on the encryption algorithm and desensitizing rules and then the desensitized data can be displayed. In addition, the desensitized data can be displayed after the sensitive fields are decrypted based on the encryption algorithm in response to the anti-desensitization request. A general desensitization and anti-desensitization technical solution can be implemented to meet new business function requirements. It is no longer necessary to develop functional logic according to new sensitive data desensitization and anti-desensitization requirements. Business developers can be exempted from the tedious process of independent development for each business that requires desensitization and anti-desensitization, which greatly reduces the development workload, improves development efficiency, and also reduces the intrusiveness of the code.

[0050] 2) Since the coupling degree between business logic and desensitization and anti-desensitization functions is very low, even if the business requirements change, the desensitization rules and encryption algorithms change, it will not have much impact on the implementation of desensitization and anti-desensitization functions, which can keep the code neat and concise and reduce maintenance costs. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1 A schematic flow chart of a method for desensitization and anti-desensitization processing based on annotations in a preferred embodiment of the present invention;

[0052] Figure 2 A flowchart of the authorization verification process in a preferred embodiment of the present invention;

[0053] Figure 3 The present invention is a schematic diagram of the structure of a system for desensitization and anti-desensitization processing based on annotations in a preferred embodiment of the present invention. DETAILED DESCRIPTION

[0054] The present invention is described in detail below in conjunction with the accompanying drawings and specific embodiments. The present invention is not limited to this embodiment, and other embodiments may also fall within the scope of the present invention as long as they conform to the gist of the present invention.

[0055] In a preferred embodiment of the present invention, based on the above-mentioned problems existing in the prior art, a method for desensitization and anti-desensitization processing based on annotations is provided, in which desensitization annotations are added to the fields that need to be desensitized and anti-desensitized in advance, and the desensitization annotations contain encryption algorithms and desensitization rules associated with the fields; Figure 1 As shown, the method includes:

[0056] Step S1: When a user makes a request to view sensitive data, determine whether there is a desensitizing annotation for the sensitive field that the user needs to view:

[0057] If not, show the encrypted sensitive fields to the user and then exit;

[0058] If yes, go to step S2;

[0059] Step S2: Determine whether the sensitive field can be desensitized:

[0060] If yes, go to step S3;

[0061] If not, go to step S4;

[0062] Step S3: determine whether the user has made a request for anti-desensitization for sensitive fields:

[0063] If not, the stored encrypted sensitive fields are decrypted according to the associated encryption algorithm, and then the decrypted sensitive fields are desensitized according to the desensitization rules to display the desensitized data to the user, and then exit;

[0064] If yes, go to step S4;

[0065] Step S4, decrypting the stored encrypted sensitive fields according to the associated encryption algorithm to display the anti-massified data to the user.

[0066] Specifically, in this embodiment, each field is stored in the database in the form of ciphertext, and a data query interface is provided for users to make sensitive data viewing requests and anti-desensitization requests, and to display encrypted sensitive fields, or sensitive data, or anti-desensitization data to users.

[0067] Furthermore, by adding desensitizing annotations to the fields that need to be desensitized and de-desensitized, the desensitization and de-desensitization functions of the corresponding fields are realized. When the user does not make a de-desensitization request, the corresponding fields can be desensitized according to the desensitizing annotations, and then the desensitized data can be displayed to the user. When the user makes a de-desensitization request, the corresponding fields can be de-desensitized according to the desensitizing annotations, and then the de-desensitized data can be displayed to the user. Among them, annotations are to add some information to the program to modify other code elements immediately behind it, such as classes, interfaces, fields, methods, parameters in methods, constructors, etc.; annotations can be used by compilers, program runtimes, and other tools to enhance or modify program behavior, etc.

[0068] To be more specific, when a user makes a request to view sensitive data through the data query interface, it is first determined whether the sensitive field to be viewed has a desensitizing annotation added in advance. If no desensitizing annotation is added, it means that the sensitive field can neither be desensitized nor desensitized. Only the encrypted sensitive field is displayed to the user, that is, the original ciphertext data stored in the database, to achieve privacy protection of the stored data.

[0069] In the case where a desensitizing annotation is added to the sensitive field that needs to be viewed, it is necessary to further determine whether the field can be desensitized. If the field itself cannot be desensitized, it can only display the original stored encrypted sensitive field to the user or display the unencrypted sensitive field to the user, that is, the anti-desensitized data. Whether to display the original stored encrypted sensitive field or the unencrypted sensitive field to the user depends on whether the user has applied for anti-desensitization. If the user has applied for anti-desensitization, it is necessary to display the unencrypted sensitive field to the user, that is, the anti-desensitized data. At this time, the encryption algorithm in the desensitizing annotation can be used to decrypt the original stored encrypted sensitive field. If the user has not applied for anti-desensitization and the field that needs to be viewed currently cannot be desensitized, it is necessary to display the original stored encrypted sensitive field to the user to achieve privacy protection of the stored data.

[0070] If the field can be desensitized, it can display desensitized data or anti-desensitized data to the user, which also depends on whether the user has applied for anti-desensitization. If the user has applied for anti-desensitization, it is necessary to display the unencrypted sensitive field to the user, that is, anti-desensitized data. At this time, the original stored encrypted sensitive field can be decrypted based on the encryption algorithm in the desensitization annotation. If the user has not applied for anti-desensitization, it is necessary to display the desensitized field to the user. At this time, the original stored encrypted sensitive field can be decrypted based on the encryption algorithm in the desensitization annotation, and then the decrypted sensitive field can be desensitized based on the desensitization rules in the desensitization annotation.

[0071] Among them, the above encryption algorithms include but are not limited to the AES encryption algorithm and the SM4 encryption algorithm, and the above desensitization algorithms include but are not limited to regular expressions. Taking the encryption algorithm in the desensitization annotation as the SM4 encryption algorithm and the desensitization algorithm as regular matching as an example, if the sensitive field to be viewed can be desensitized and the user has not applied for anti-desensitization, then M(A) = "13838389909" is recorded as R, where A is the ciphertext data and M is the decryption algorithm. Because its desensitization rule is regular matching, and because it satisfies the mobile phone number regularity, P(R) = "138****9909", P is the mobile phone number desensitization algorithm, and finally desensitization is achieved, and the desensitized data displayed to the user is "138****9909".

[0072] If the sensitive field to be viewed can be desensitized and the user applies for anti-desensitization, M(A) = "13838389909" is recorded as R, where A is the ciphertext data and M is the decryption algorithm. The anti-desensitized data finally displayed to the user is "13838389909".

[0073] It can be seen that the method of desensitization and anti-desensitization processing of the present invention is universal. If a new field needs to be desensitized and anti-desensitized, it is only necessary to add a desensitization annotation for it, and there is no need to develop functional logic for the new sensitive data desensitization and anti-desensitization requirements. This can exempt business developers from the tedious process of independent development for each business that requires desensitization and anti-desensitization, greatly reducing the development workload, improving development efficiency, and also reducing the intrusiveness of the code.

[0074] In a preferred embodiment of the present invention, in step S2, judging whether the sensitive field can be desensitized based on the field type of the sensitive field specifically includes:

[0075] Get the field type of the sensitive field and determine whether the field type is a string:

[0076] If yes, it means the sensitive field can be desensitized;

[0077] If not, it means that sensitive fields cannot be desensitized.

[0078] The string type here can be String or List. <string>In other words, the field type of the sensitive field is String or List <string>, it indicates that the sensitive field can be desensitized. The field type of the sensitive field can be obtained through reflection technology.

[0079] In a preferred embodiment of the present invention, when a user makes a request for anti-desensitization, Figure 2 As shown, the authorization verification process is also included:

[0080] Step A1, generate a verification code and associate it with the corresponding user and then send it to the system administrator. When the system administrator authorizes anti-desensitization query, the verification code is sent to the corresponding user for input;

[0081] Step A2, when receiving a valid verification code input by the user, desensitize the sensitive fields to display the desensitized data to the user.

[0082] Specifically, in this embodiment, in order to further protect data while realizing the anti-desensitization function, when the user makes an anti-desensitization request, the anti-desensitization data can only be viewed with the authorization of the system administrator. Among them, when the user makes an anti-desensitization request, a verification code is first randomly generated and associated with the corresponding user, and then the verification code is sent to the system administrator by email or text message. The system administrator checks which user has requested anti-desensitization based on the content of the email or text message, and whether manual control allows the user's anti-desensitization request this time. If allowed, the system administrator sends the verification code to the user, and the user enters the received verification code into the anti-desensitization request interface. If the user enters the verification code within the preset time limit and the verification code is consistent with the generated verification code, the verification code is considered valid, and then the anti-desensitization operation is performed on the sensitive field, and the anti-desensitization data can be displayed to the user.

[0083] In a preferred embodiment of the present invention, before executing step A1, it also includes determining whether the user has the authority to perform an anti-desensitization query:

[0084] If yes, go to step A1;

[0085] If not, the sensitive fields are desensitized to display the desensitized data to the user and then exit.

[0086] Specifically, in this embodiment, in order to further protect the stored data, not all anti-desensitization applications submitted by users need to be responded to through permission restrictions. Users can be given the authority to conduct anti-desensitization queries by managing the permissions of registered users. Only users with anti-desensitization query permissions will submit anti-desensitization applications, and then the above-mentioned anti-desensitization processing will be performed.

[0087] Furthermore, although the existence of the above authorization verification process can achieve effective data protection, if a single user needs to frequently view sensitive fields, or needs to view sensitive fields in batches, if a verification code must be generated each time an anti-desensitization application is made, and then the verification code is received and then entered for verification and viewing, the operation is relatively cumbersome and may affect the user's query experience. Based on this, in a preferred embodiment of the present invention, the authorization verification process also includes a user behavior analysis process:

[0088] If the number of times a user makes anti-desensitization requests within the preset time period exceeds the preset number and all authorization verifications are passed, no verification code will be generated and the anti-desensitization data will be displayed directly to the user.

[0089] Specifically, in this embodiment, the anti-desensitization permission policy is automatically adjusted by analyzing the user behavior, and the anti-desensitization permission policy that requires waiting for receiving and entering the verification code each time an anti-desensitization application is made is adjusted to the process in which the user directly performs anti-desensitization processing when making an anti-desensitization application, skips the generation of the verification code, and sends the verification code to the system administrator for authorization. For example, if a user frequently performs legal (i.e., each time an anti-desensitization request is made, the authorization verification is passed) anti-desensitization operations within a period of time, and there is no security risk, such as entering an incorrect verification code, etc., then the anti-desensitization permission policy of the user can be automatically expanded, that is, when the user makes an anti-desensitization application again, the anti-desensitization processing is directly performed, which can achieve effective data protection while improving user query efficiency and query experience.

[0090] It is understandable that if the user is subsequently found to have abnormal anti-desensitization request behavior, such as entering an incorrect verification code, etc., his permissions can be automatically restricted, such as restoring the authorization verification requirement for each anti-desensitization request, or suspending his anti-desensitization permissions, such as temporarily configuring the user to not have anti-desensitization permissions, which is not limited here.

[0091] It can be seen that by analyzing user behavior during the authorization verification process, real-time monitoring of desensitization and anti-desensitization operations can be achieved, including but not limited to monitoring the frequency of anti-desensitization requests, source IP addresses, ports, requested data ranges, and other information, so that potential security risks can be discovered in a timely manner. If a certain IP address is found to frequently request anti-desensitization data in a short period of time, an alarm can be automatically triggered and its anti-desensitization permissions can be further restricted, or its anti-desensitization permissions can be suspended.

[0092] Furthermore, real-time monitoring here also includes recording all desensitization and anti-desensitization operations in detail in the security audit log, including operation time, operator, data content of the operation (before and after desensitization), etc. These logs can be used for compliance checks, security incident tracing, etc. In the event of a data leak, the possible source of the leak and the relevant responsible persons can be quickly located through the audit log.

[0093] In a preferred embodiment of the present invention, a business service cluster is pre-deployed, including multiple distributed service nodes. When a user enters a valid verification code, anti-desensitization information is extracted from the anti-desensitization request and broadcast to all service nodes. When each service node determines that the anti-desensitization information is its own service message, it generates a corresponding anti-desensitization instruction for caching;

[0094] Then, when the user makes an anti-desensitization request, the service node determines whether the anti-desensitization instruction corresponding to the anti-desensitization request is cached:

[0095] If not, the sensitive fields are desensitized to display desensitized data to the user;

[0096] If so, the service node performs lock grabbing, and desensitizes the sensitive fields when the lock grabbing succeeds to display the desensitized data to the user, and desensitizes the sensitive fields when the lock grabbing fails to display the desensitized data to the user.

[0097] Specifically, in this embodiment, by pre-deploying a business service cluster, each service node can execute the desensitization and anti-desensitization processing method of the present invention in a distributed manner, thereby effectively improving processing efficiency. Among them, the anti-desensitization information can be sent to a message queue (Message Queue, MQ), and then the anti-desensitization information can be broadcast to all service nodes through the message queue.

[0098] The anti-massification request includes the uniform resource locator, the location information of the sensitive field for which anti-massification is requested, and the applicant information;

[0099] The anti-massaging information contains uniform resource locators and location information;

[0100] The anti-desensitization instructions contain location information.

[0101] Furthermore, each service node determines whether the anti-desensitization information is its own service message based on the uniform resource locator. If it is not its own service message, the anti-desensitization information is discarded. If it is its own service message, the anti-desensitization instruction is cached.

[0102] The location information in the anti-desensitization instruction includes but is not limited to a field in a certain page, row, column, and field, such as page 2, row 3, column 3, and field named phone. When the user makes an anti-desensitization request and the service node caches the anti-desensitization instruction corresponding to the anti-desensitization request, the field that needs to be de-desensitized can be accurately located based on the location information in the anti-desensitization instruction, thereby performing the anti-desensitization operation based on the encryption algorithm in the desensitization annotation, without traversing the entire database to locate sensitive fields, thereby improving processing efficiency.

[0103] When a user makes a request for desensitization, and the service node has the desensitization instruction corresponding to the desensitization request cached, because each service node is deployed in a distributed manner and there are multiple service clusters, the current service node grabs the desensitization instruction cache lock. If the lock is obtained, the desensitization operation is performed; if the lock is not obtained, the desensitization operation is performed. This ensures that in a distributed scenario, the corresponding field can only be desensitized by the service node that successfully grabs the lock, that is, for each desensitization request, the corresponding field can only be desensitized once.

[0104] In a preferred embodiment of the present invention, before performing desensitization on the sensitive field, the following steps are also included:

[0105] The sensitive fields that need to be de-massified are determined according to the position information contained in the de-massification instruction.

[0106] In a preferred embodiment of the present invention, after the sensitive field is desensitized, the method further includes:

[0107] The corresponding anti-desensitization instruction is broadcast to all service nodes. When each service node determines that the anti-desensitization instruction is its own service message, it clears the corresponding anti-desensitization instruction in the cache.

[0108] Specifically, in this embodiment, after the sensitive field is desensitized, the desensitization instruction is also sent to the message queue (MQ), and then the desensitization instruction is broadcast to all service nodes through the message queue, so that the corresponding service node can clear the cache in time after executing the desensitization instruction, avoiding the problem of multiple desensitization of other nodes in the cluster.

[0109] The present invention also provides a system for desensitization and anti-desensitization processing based on annotations, applying the above method, such as Figure 3 As shown, the system includes:

[0110] Database 1 stores multiple encrypted fields, among which fields that need to be desensitized and de-desensitized are added with desensitization annotations, which contain encryption algorithms and desensitization rules associated with the fields;

[0111] Data query interface 2, used for users to make sensitive data viewing requests and anti-massification requests;

[0112] The query processing module 3 is connected to the data query interface 2 and the database 1 respectively, and the query processing module includes:

[0113] The first query unit 31 is used to display the encrypted sensitive field to the user when the user makes a sensitive data viewing request and the sensitive field that the user needs to view does not have a desensitizing annotation;

[0114] The second query unit 32 is used to decrypt the stored encrypted sensitive field according to the associated encryption algorithm to display the desensitized data to the user when there is a desensitization annotation for the sensitive field that the user needs to view, but the sensitive field cannot be desensitized or the sensitive field can be desensitized but the user does not make a desensitization request for the sensitive field;

[0115] The third query unit 33 is used to decrypt the stored encrypted sensitive field according to the associated encryption algorithm when the sensitive field can be desensitized and the user makes a request for anti-desensitization for the sensitive field, and then desensitize the decrypted sensitive field according to the desensitization rule to display the desensitized data to the user.

[0116] The above description is only a preferred embodiment of the present invention, and does not limit the implementation mode and protection scope of the present invention. For those skilled in the art, it should be aware that all solutions obtained by equivalent substitutions and obvious changes made using the contents of this specification and illustrations should be included in the protection scope of the present invention.< / string> < / string>

Claims

1. A method for desensitization and anti-desensitization processing based on annotation, characterized in that: Add a desensitizing annotation to the field that needs to be desensitized and desensitized in advance, and the desensitizing annotation contains the encryption algorithm and desensitizing rules associated with the field; the method includes: Step S1: when a user makes a request to view sensitive data, it is determined whether the sensitive field that the user needs to view has the desensitizing annotation: If not, display the encrypted sensitive fields to the user and then exit; If yes, go to step S2; Step S2, determining whether the sensitive field can be desensitized: If yes, go to step S3; If not, go to step S4; Step S3, determining whether the user has made an anti-desensitization request for the sensitive field: If not, decrypt the stored encrypted sensitive field according to the associated encryption algorithm, and then desensitize the decrypted sensitive field according to the desensitization rule to display the desensitized data to the user, and then exit; If yes, go to step S4; Step S4, decrypting the stored encrypted sensitive field according to the associated encryption algorithm to display anti-desensitization data to the user.

2. The method according to claim 1, characterized in that The step S2 comprises: Get the field type of the sensitive field and determine whether the field type is a string: If yes, it means that the sensitive field can be desensitized; If not, it means that the sensitive field cannot be desensitized.

3. The method according to claim 1, characterized in that When the user makes the anti-desensitization request, the authorization verification process is also included: Step A1, generating a verification code and associating it with the corresponding user and then sending it to the system administrator. When the system administrator authorizes an anti-desensitization query, the verification code is sent to the corresponding user for input; Step A2: upon receiving the valid verification code input by the user, desensitizing the sensitive field to display the desensitized data to the user.

4. The method according to claim 3, characterized in that Before executing step A1, it is also included to determine whether the user has the authority to perform anti-desensitization query: If yes, go to step A1; If not, the sensitive fields are desensitized to display the desensitized data to the user, and then exit.

5. The method according to claim 3, characterized in that: The authorization verification process also includes a user behavior analysis process: If the number of times the user makes the anti-desensitization request within the preset time period is greater than the preset number and all authorization verifications are passed, the verification code will not be generated and the anti-desensitization data will be directly displayed to the user.

6. The method according to claim 3, characterized in that It also includes pre-deploying a business service cluster, including multiple distributed service nodes. When the user enters a valid verification code, it also includes extracting anti-desensitization information from the anti-desensitization request and broadcasting it to all the service nodes. When each service node determines that the anti-desensitization information is its own service message, it generates a corresponding anti-desensitization instruction for caching; Then, when the user makes the anti-desensitization request, the service node determines whether the anti-desensitization instruction corresponding to the anti-desensitization request is cached: If not, desensitizing the sensitive field to display the desensitized data to the user; If so, the service node performs lock snatching, and desensitizes the sensitive field when the lock snatching is successful to display the desensitized data to the user, and desensitizes the sensitive field when the lock snatching fails to display the desensitized data to the user.

7. The method according to claim 6, characterized in that Before desensitizing the sensitive field, the following steps are also included: The sensitive field that needs to be de-desensitized is determined according to the position information contained in the de-desensitization instruction.

8. The method according to claim 6, characterized in that After the sensitive fields are desensitized, the following steps are also included: The corresponding anti-desensitization instruction is broadcast to all the service nodes. When each service node determines that the anti-desensitization instruction is its own service message, it clears the corresponding anti-desensitization instruction in the cache.

9. The method according to claim 6, characterized in that The anti-massification request includes a uniform resource locator, location information of the sensitive field for which anti-massification is requested, and applicant information; The anti-desensitization information includes the uniform resource locator and the location information; The anti-desensitization instruction includes the location information; Each of the service nodes determines whether the anti-massifying information is its own service message based on the uniform resource locator.

10. A system for desensitization and anti-desensitization processing based on annotations, characterized in that: The method according to any one of claims 1 to 9 is applied, wherein the system comprises: A database storing a plurality of encrypted fields, wherein a desensitizing annotation is added to the fields that need to be desensitized and desensitized, and the desensitizing annotation includes an encryption algorithm and a desensitizing rule associated with the field; Data query interface, used for users to make sensitive data viewing and anti-massification requests; A query processing module is connected to the data query interface and the database respectively, and the query processing module includes: A first query unit, configured to display the encrypted sensitive field to the user when the user makes a request to view sensitive data and the sensitive field that the user needs to view does not have the desensitizing annotation; A second query unit is configured to decrypt the stored encrypted sensitive field according to the associated encryption algorithm when the desensitizing annotation exists in the sensitive field that the user needs to view, but the sensitive field cannot be desensitized or the sensitive field can be desensitized but the user does not make a desensitization request for the sensitive field, so as to display the desensitized data to the user; The third query unit is used to decrypt the stored encrypted sensitive field according to the associated encryption algorithm when the sensitive field can be desensitized and the user makes a desensitization request for the sensitive field, and then desensitize the decrypted sensitive field according to the desensitization rule to display the desensitized data to the user.