Data desensitization method, related equipment, storage medium and computer program product
By segmenting and encrypting the desensitized data, and performing desensitization on the second node based on ciphertext, the risk of sensitive data leakage in the prior art is solved, and efficient and secure desensitization transmission of data is achieved.
Patent Information
- Application Number
- CN202411865441.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-17
- Publication Date
- 2025-05-06
AI Technical Summary
The existing data anonymization algorithm has the risk of sensitive data leakage and cannot effectively prevent identity information from being leaked, resulting in security problems during the transmission of sensitive data.
By segmenting the desensitized data on the first node, multiple data blocks are obtained, and the data blocks are encrypted and then sent to the second node. After the second node receives, the encrypted data is assembled based on the assembly function, and desensitized on the ciphertext basis through a preset desensitization algorithm.
It effectively reduces the risk of data leakage, ensures data security, and prevents sensitive information from being leaked during transmission.
Smart Images

Figure CN119939648A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular to a data desensitization method, related equipment, storage medium and computer program product. Background Art
[0002] The purpose of data desensitization technology is to process sensitive data through certain methods to reduce the sensitivity of sensitive data or make sensitive data no longer contain sensitive information. The selection and application of data desensitization algorithms are the core issues of data desensitization technology. Different desensitization algorithms can be selected according to different scenarios, different data types, and different desensitization requirements. Traditional desensitization algorithms include: replacement, simulation, encryption, masking, obfuscation, offset, averaging, etc. In addition, in order to improve the overall privacy security of the data set, effectively reduce the sensitivity of the data, and achieve highly reliable sensitive information protection capabilities, there are more complex data anonymization algorithms, including K-Anonymity, L-Diversity, and T-Closeness.
[0003] However, the above data anonymization algorithm has the risk of sensitive data being leaked, for example, it cannot prevent identity information from being leaked, which may cause security issues in the transmission of sensitive data. Therefore, it is urgent to propose a technical solution that can prevent sensitive data from being leaked. Summary of the invention
[0004] The implementing legislation of this application provides a data desensitization method, related equipment, storage medium and computer program product, which can reduce the risk of data leakage and ensure the security of data.
[0005] The technical solution of the embodiment of the present application is implemented as follows:
[0006] In a first aspect, an embodiment of the present application provides a data desensitization method, which is applied to a first node and includes:
[0007] Acquire first data, wherein the first data includes data to be desensitized;
[0008] The first data is segmented based on a first function to obtain second data; wherein the first function is at least used to segment the first data, and the second data includes N first data blocks, where N is a positive integer;
[0009] The second data is encrypted to obtain third data, and the third data is sent to the second node so that the second node desensitizes the third data.
[0010] In a second aspect, an embodiment of the present application provides a data desensitization method, which is applied to a second node and includes:
[0011] receiving third data sent by the first node; wherein the third data includes the encrypted N first data blocks and the encrypted second data block;
[0012] Performing assembly processing on the third data based on a second function to obtain assembled third data; wherein the second function includes an assembly function;
[0013] The assembled third data is desensitized by using a preset desensitization algorithm to obtain desensitized data.
[0014] In a third aspect, an embodiment of the present application provides a first node, the first node comprising: an acquisition unit, a segmentation unit, an encryption unit, and a sending unit; wherein,
[0015] The acquisition unit is used to acquire first data, wherein the first data includes data to be desensitized;
[0016] The segmentation unit is used to segment the first data based on a first function to obtain second data; wherein the first function is at least used to segment the first data, and the second data includes N first data blocks, where N is a positive integer;
[0017] The encryption unit is used to encrypt the second data to obtain third data;
[0018] The sending unit is used to send the third data to the second node, so that the second node performs desensitization processing on the third data.
[0019] In a fourth aspect, an embodiment of the present application provides a first node, the first node comprising: a first processor and a first memory; wherein:
[0020] The first memory is used to store a computer program that can be run on the processor;
[0021] The first processor is used to execute the data desensitization method as described above when running the computer program.
[0022] In a fifth aspect, an embodiment of the present application provides a second node, the second node comprising: a receiving unit, an assembling unit, and a processing unit; wherein:
[0023] The receiving unit is configured to receive third data sent by the first node; wherein the third data includes the encrypted N first data blocks and the encrypted second data block;
[0024] The assembling unit is used to assemble the third data based on the second function to obtain assembled third data; wherein the second function includes an assembling function;
[0025] The processing unit is used to perform desensitization processing on the assembled third data through a preset desensitization algorithm to obtain desensitized data.
[0026] In a sixth aspect, an embodiment of the present application provides a second node, the second node comprising: a second processor and a second memory; wherein:
[0027] The second memory is used to store a computer program that can be run on the processor;
[0028] The second processor is used to execute the data desensitization method as described above when running the computer program.
[0029] In the seventh aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program code is stored. When the computer program code is executed by a computer, the data desensitization method as described above is implemented.
[0030] In an eighth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the data desensitization method as described above.
[0031] The embodiments of the present application provide a data desensitization method, related equipment, storage medium and computer program product, wherein a first node obtains first data, wherein the first data includes data to be desensitized; the first data is segmented based on a first function to obtain second data; wherein the first function is at least used to segment the first data, and the second data includes N first data blocks, where N is a positive integer; the second data is encrypted to obtain third data, and the third data is sent to a second node; the second node assembles the third data based on the second function to obtain assembled third data; wherein the second function includes an assembling function; the assembled third data is desensitized by a preset desensitization algorithm to obtain desensitized data. It can be seen that after obtaining the first data, the first node can use the first function to split the first data to obtain second data, and the second data can contain N first data blocks, that is, the embodiment of the present application can use the first function to split the first data to obtain N first data blocks, which can be subsequently transmitted in the form of data blocks, thereby effectively reducing the risk of data leakage; then the first node can send the encrypted third data to the second node, and the second node can assemble the third data based on the second function to obtain assembled third data, and desensitize the assembled third data through a preset desensitization algorithm. Since the assembled third data is encrypted data, that is, the data desensitization operation performed by the second node is performed on the basis of ciphertext, thereby ensuring the security of sensitive data. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 Schematic diagram of the data desensitization method proposed in the embodiment of this application Figure 1 ;
[0033] Figure 2 A schematic diagram of data segmentation proposed in an embodiment of the present application;
[0034] Figure 3 Schematic diagram of the data desensitization method proposed in the embodiment of this application Figure 2 ;
[0035] Figure 4 Schematic diagram of the data desensitization method proposed in the embodiment of this application Figure 3 ;
[0036] Figure 5 Schematic diagram of the data desensitization method proposed in the embodiment of this application Figure 4 ;
[0037] Figure 6 Schematic diagram of the data desensitization method proposed in the embodiment of this application Figure 5 ;
[0038] Figure 7Schematic diagram of the composition structure of the first node proposed in the embodiment of the present application Figure 1 ;
[0039] Figure 8 Schematic diagram of the composition structure of the first node proposed in the embodiment of the present application Figure 2 ;
[0040] Fig. 9 The structure diagram of the second node proposed in the embodiment of the present application is shown in FIG. Figure 1 ;
[0041] Fig.10 The structure diagram of the second node proposed in the embodiment of the present application is shown in FIG. Figure 2 . DETAILED DESCRIPTION
[0042] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. It is understood that the specific embodiments described herein are only used to explain the related applications, rather than to limit the applications. It should also be noted that, for ease of description, only the parts related to the related applications are shown in the drawings.
[0043] The purpose of data desensitization technology is to process sensitive data through certain methods to reduce the sensitivity of sensitive data or make sensitive data no longer contain sensitive information. The selection and application of desensitization algorithms are the core issues of data desensitization technology. Different desensitization algorithms can be selected according to different scenarios, different data types, different data characteristics, and different desensitization requirements. Traditional desensitization algorithms include: replacement, simulation, encryption, masking, obfuscation, offset, averaging, etc. In addition, in order to improve the overall privacy security of the data set, effectively reduce the sensitivity of the data, and achieve highly reliable sensitive information protection capabilities, there are more complex data anonymization algorithms, including K-anonymity, L-diversity, T-proximity, etc.
[0044] K-anonymity was first proposed by Samarati and Sweeney in 1998. Its basic idea is that if any record in a public data set cannot be directly distinguished from at least k-1 other records, then the record is said to satisfy K-Anonymity. In this data set, each attribute combination of sensitive data needs to appear in k records at the same time, and the k records that cannot be distinguished are called an equivalence class. Although K-anonymity can anonymize sensitive data, it does not protect the attributes of sensitive data, which makes it easy for the data to be attacked by background knowledge and homogeneous attacks.
[0045] L-diversity means that if the set of sensitive data attributes corresponding to all records in any equal data set (equivalence class) contains at least L "well-represented" values, then the equivalence class is said to satisfy L-Diversity. If all equivalence classes in the data set satisfy L-Diversity, then the data set is said to satisfy L-Diversity. L-diversity is an improvement on K-anonymity in terms of sensitive data attributes. Compared with K-anonymity, L-diversity makes it possible for unauthorized external users to obtain sensitive information content in sensitive data with a probability of at most 1 / L.
[0046] T-closeness is an improvement and enhancement based on L-diversity, adding constraints on the distribution of sensitive attribute values of data. It requires that the difference between the distribution of sensitive attribute values in each equivalence class and the distribution of sensitive attribute values in the entire data table does not exceed the given parameter t, that is, the equivalence class satisfies t-Closeness, so that the statistical distribution of sensitive attribute values in each equivalence class is "close" to the overall distribution of sensitive attribute values in the entire data table, that is, the data table satisfies t-Closeness. Among these three anonymization algorithms, K-anonymity can resist link attacks, but cannot solve the problem of homogeneous attacks; although L-diversity can resist homogeneous attacks, it cannot solve skew attacks and similarity attacks; T-closeness can effectively solve skew attacks and similarity attacks, but T-closeness cannot prevent identity leakage, so sometimes K-anonymity and T-closeness may be needed at the same time. In addition, T-closeness does not guarantee that homogeneous attacks and background attacks against the K-anonymity algorithm will never occur, but it guarantees that if such attacks occur in such tables, similar attacks can occur even if a completely generalized table is used.
[0047] In summary, the above data anonymization algorithms still have the risk of sensitive data being leaked, which may lead to security issues in the transmission of sensitive data. Therefore, it is urgent to propose a technical solution that can prevent sensitive data leakage.
[0048] In order to solve the current problem of risk of sensitive data leakage, the embodiments of the present application provide a data desensitization method, related equipment, storage medium and computer program product, wherein a first node obtains first data, wherein the first data includes data to be desensitized; the first data is segmented based on a first function to obtain second data; wherein the first function is at least used to segment the first data, and the second data includes N first data blocks, N is a positive integer; the second data is encrypted to obtain third data, and the third data is sent to a second node; the second node assembles the third data based on the second function to obtain assembled third data; wherein the second function includes an assembling function; the assembled third data is desensitized by a preset desensitization algorithm to obtain desensitized data. It can be seen that after obtaining the first data, the first node can use the first function to split the first data to obtain second data, and the second data can contain N first data blocks, that is, the embodiment of the present application can use the first function to split the first data to obtain N first data blocks, which can be subsequently transmitted in the form of data blocks, thereby effectively reducing the risk of data leakage; then the first node can send the encrypted third data to the second node, and the second node can assemble the third data based on the second function to obtain assembled third data, and desensitize the assembled third data through a preset desensitization algorithm. Since the assembled third data is encrypted data, that is, the data desensitization operation performed by the second node is performed on the basis of ciphertext, thereby ensuring the security of sensitive data.
[0049] The technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application.
[0050] The embodiment of the present application provides a data desensitization method, which is applied to a first node. Figure 1 Schematic diagram of the data desensitization method proposed in the embodiment of this application Figure 1 ,like Figure 1 As shown, the data desensitization method may include the following steps:
[0051] Step 101: Obtain first data, wherein the first data includes data to be desensitized.
[0052] In an embodiment of the present application, the first node may obtain the first data.
[0053] It should be noted that, in the embodiments of the present application, the first node may be a client node, and the present application does not specifically limit the type of the first node.
[0054] It should be noted that, in the embodiments of the present application, the first data may include data to be desensitized, and the data to be desensitized may be data of any type. The present application does not specifically limit the number and type of data included in the first data.
[0055] Step 102: segment the first data based on the first function to obtain second data; wherein the first function is at least used to segment the first data, and the second data includes N first data blocks, where N is a positive integer.
[0056] In an embodiment of the present application, after acquiring the first data, the first node may segment the first data based on the first function to obtain the second data.
[0057] It should be noted that in the embodiment of the present application, the first function may be a partition function. Within a specified range, the value range and the definition domain of the partition function can form a one-to-one mapping. For example, the partition function may be Y=2 x , this application does not specifically limit the type of the first function.
[0058] It should be noted that, in an embodiment of the present application, when the first node splits the first data based on the first function to obtain the second data, the first data can be input into the first function to obtain N first data blocks; wherein the first function includes M parameter information, and the parameter information is used to control the attribute information of the first data block, and the attribute information includes one or more of the size and quantity of the first data block, and M is a positive integer.
[0059] It should be noted that, in the embodiments of the present application, the attribute information may include the size and quantity of the first data block, and may also include other attributes. The present application does not specifically limit the type and quantity of information included in the attribute information.
[0060] For example, in the embodiments of the present application, Figure 2 The data segmentation diagram proposed in the embodiment of the present application is as follows: Figure 2 As shown, the process of dividing the data by the first function is shown. Assuming that the first function is Y=2 x In this function, k is a segmentation unit in data segmentation, x is the serial number of the current data block, and y is the size of the current data block. According to the established function, the data can be segmented into N data blocks of different sizes.
[0061] That is to say, in an embodiment of the present application, the first node may split the first data based on the first function, so that when the data is subsequently transmitted to the second node, it is transmitted in the form of data blocks, thereby reducing the risk of data leakage.
[0062] Step 103: encrypt the second data to obtain third data, and send the third data to the second node so that the second node desensitizes the third data.
[0063] In an embodiment of the present application, after the first node splits the first data based on the first function to obtain the second data, it can encrypt the second data to obtain the third data, and send the third data to the second node so that the second node desensitizes the third data.
[0064] It should be noted that, in the embodiments of the application, the second node may be a server node, and the application does not specifically limit the type of the second node.
[0065] It should be noted that in an embodiment of the application, when the first node encrypts the second data to obtain the third data, the second data block can be added to the second data; wherein the second data block contains an interference factor; and then the N first data blocks and the second data blocks can be encrypted based on a preset encryption algorithm to obtain the third data.
[0066] It should be noted that, in the embodiment of the application, the second data block may include an interference factor, and the present application does not specifically limit the type of data included in the second data block.
[0067] It should be noted that in the embodiment of the application, when the first node adds the second data block to the second data, it can add the interference factor to each data block in the N first data blocks respectively. This application does not specifically limit the method of adding the second data block.
[0068] It should be noted that, in the embodiment of the application, the first node adds the second data block to the second data, which can effectively prevent information leakage caused by differential.
[0069] It should be noted that, in the embodiment of the application, after adding the second data block to the second data, the first node can encrypt the N first data blocks and the second data blocks based on a preset encryption algorithm to obtain the third data.
[0070] It should be noted that in the embodiments of the application, the preset encryption algorithm may include an asymmetric homomorphic encryption algorithm or other types of encryption algorithms. This application does not specifically limit the type of the preset encryption algorithm.
[0071] It should be noted that in the embodiment of the application, after the first node encrypts N first data blocks and second data blocks based on a preset encryption algorithm to obtain the third data, the third data can be sent to the second node so that the second node desensitizes the third data.
[0072] It should be noted that, in the embodiment of the application, the first node can receive the desensitized data sent by the second node; and then the desensitized data can be decrypted to obtain the desensitized plaintext data.
[0073] It should be noted that in the embodiment of the application, if the data is uploaded to the server (i.e., the second node) for data desensitization, the data needs to be transmitted to the cloud server, and then the server will perform data desensitization, but in this case, the sensitive data will be exposed on the cloud server. The homomorphic encryption algorithm can solve this problem. The embodiment of the application can encrypt the data before transmitting the data, and the server (i.e., the second node) desensitizes the data after receiving the data, but the desensitization operation is performed on the basis of the ciphertext, thereby ensuring the security of the data.
[0074] To summarize, after obtaining the first data, the first node can input the first data into the first function to obtain second data, where the second data includes N first data blocks, that is, the first node in the embodiment of the present application can split the first data based on the first function, so that when the data is subsequently transmitted to the second node, it is transmitted in the form of data blocks, thereby reducing the risk of data leakage; then the first node can add the second data block to the second data, and can encrypt the N first data blocks and the second data blocks based on a preset encryption algorithm to obtain third data, and then can send the third data to the second node so that the second node can desensitize the third data.
[0075] The embodiment of the present application provides a data desensitization method, which is applied to a first node, and the method includes: obtaining first data, wherein the first data includes data to be desensitized; segmenting the first data based on a first function to obtain second data; wherein the first function is at least used to segment the first data, and the second data includes N first data blocks, N being a positive integer; encrypting the second data to obtain third data, and sending the third data to the second node, so that the second node desensitizes the third data. It can be seen that after obtaining the first data, the first node can use the first function to segment the first data to obtain the second data, and the second data can include N first data blocks, that is, the embodiment of the present application can use the first function to segment the first data to obtain N first data blocks, which can be subsequently transmitted in the form of data blocks, thereby effectively reducing the risk of data leakage; then the first node can send the encrypted third data to the second node, so that the second node desensitizes the third data.
[0076] Based on the above embodiment, another embodiment of the present application provides a data desensitization method, which is applied to a second node. Figure 3Schematic diagram of the data desensitization method proposed in the embodiment of this application Figure 2 ,like Figure 3 As shown, the data desensitization method may include the following steps:
[0077] Step 201: Receive third data sent by a first node; wherein the third data includes N encrypted first data blocks and an encrypted second data block.
[0078] In an embodiment of the present application, the second node may receive the third data sent by the first node.
[0079] It should be noted that, in the embodiments of the application, the second node may be a server node, and the application does not specifically limit the type of the second node.
[0080] It should be noted that, in an embodiment of the present application, the third data may include N encrypted first data blocks and an encrypted second data block, and the present application does not specifically limit the type of data included in the third data.
[0081] Step 202: assemble the third data based on the second function to obtain assembled third data; wherein the second function includes an assembling function.
[0082] In an embodiment of the present application, after receiving the third data sent by the first node, the second node may assemble the third data based on the second function to obtain assembled third data.
[0083] It should be noted that, in the embodiments of the present application, the second function may include an assembly function, and the present application does not specifically limit the type of the second function.
[0084] It should be noted that in the embodiments of the present application, the assembly function corresponds to the segmentation function, and the assembly function needs to be used when assembling data blocks; generally speaking, the assembly function is different from the segmentation function and should be uniquely determined by the segmentation function, which can ensure that all segmentation functions have corresponding assembly functions. The set of these functions can be stored in the desensitizing system as a function library, and the present application does not specifically limit the storage location of the function library.
[0085] It should be noted that, in an embodiment of the present application, when the second node assembles the third data based on the second function to obtain the assembled third data, it can remove the encrypted second data blocks in the third data to obtain the removed third data; wherein the removed third data includes the encrypted N first data blocks; and then the encrypted N first data blocks can be assembled based on the second function to obtain the assembled third data.
[0086] That is to say, in an embodiment of the present application, after receiving the third data sent by the first node, the second node can first eliminate the encrypted second data block in the third data. The second data block contains an interference factor, that is, the encrypted interference factor data block in the third data can be eliminated, and then the encrypted N first data blocks can be assembled based on the second function to obtain the assembled third data.
[0087] Step 203: Desensitize the assembled third data using a preset desensitization algorithm to obtain desensitized data.
[0088] In an embodiment of the present application, after the second node assembles the third data based on the second function to obtain the assembled third data, it can desensitize the assembled third data using a preset desensitization algorithm to obtain the desensitized data.
[0089] It should be noted that, in the embodiments of the present application, the preset desensitization algorithm may include any type of desensitization algorithm, such as masking, confusion, offset, and averaging, etc. The present application does not specifically limit the type of the preset desensitization algorithm.
[0090] It should be noted that, in the embodiments of the present application, Figure 4 Schematic diagram of the data desensitization method proposed in the embodiment of this application Figure 3 ,like Figure 4 As shown, after the second node performs desensitization processing on the assembled third data by using a preset desensitization algorithm to obtain the desensitized data, that is, after step 203, the following steps may also be included:
[0091] Step 204: Send the desensitized data to the first node, so that the first node decrypts the desensitized data to obtain the desensitized plaintext data.
[0092] That is to say, in an embodiment of the present application, when the second node desensitizes the assembled third data through a preset desensitizing algorithm, it desensitizes the encrypted N first data blocks, so that the desensitization operation of the second node is performed on the basis of the ciphertext, thereby ensuring the security of the data.
[0093] To summarize, after receiving the third data sent by the first node, the second node can remove the encrypted second data block in the third data to obtain the removed third data; wherein the removed third data includes the N encrypted first data blocks; then the N encrypted first data blocks can be assembled based on the second function to obtain the assembled third data, and then the assembled third data can be desensitized by a preset desensitizing algorithm to obtain the desensitized data, that is, the desensitizing operation of the second node on the data is performed on the basis of the ciphertext, thereby ensuring the security of the data.
[0094] The embodiment of the present application provides a data desensitization method, which is applied to a second node, and the method includes: the second node receives the third data sent by the first node; wherein the third data includes N encrypted first data blocks and encrypted second data blocks; the third data is assembled based on the second function to obtain the assembled third data; wherein the second function includes an assembly function; the assembled third data is desensitized by a preset desensitization algorithm to obtain the desensitized data. It can be seen that the second node can assemble the third data based on the second function to obtain the assembled third data, and desensitize the assembled third data by a preset desensitization algorithm. Since the assembled third data is encrypted data, that is, the data desensitization operation of the second node is performed on the basis of ciphertext, thereby ensuring the security of sensitive data.
[0095] Based on the above embodiment, another embodiment of the present application provides a data desensitization method, which is applied to a first node and a second node. Figure 5 Schematic diagram of the data desensitization method proposed in the embodiment of this application Figure 4 ,like Figure 5 As shown, the data desensitization method may include the following steps:
[0096] Step 301: The first node obtains first data, wherein the first data includes data to be desensitized.
[0097] It should be noted that, in the embodiments of the present application, the first node may be a client node, and the present application does not specifically limit the type of the first node.
[0098] It should be noted that, in the embodiments of the present application, the first data may include data to be desensitized, and the data to be desensitized may be data of any type. The present application does not specifically limit the number and type of data included in the first data.
[0099] Step 302: The first node performs segmentation processing on the first data based on the first function to obtain second data; wherein the first function is at least used to perform segmentation processing on the first data, and the second data includes N first data blocks, where N is a positive integer.
[0100] It should be noted that in the embodiment of the present application, the first function may be a partition function. Within a specified range, the value range and the definition domain of the partition function can form a one-to-one mapping. For example, the partition function may be Y=2 x , this application does not specifically limit the type of the first function.
[0101] It should be noted that, in an embodiment of the present application, when the first node splits the first data based on the first function to obtain the second data, the first data can be input into the first function to obtain N first data blocks; wherein the first function includes M parameter information, and the parameter information is used to control the attribute information of the first data block, and the attribute information includes one or more of the size and quantity of the first data block, and M is a positive integer.
[0102] It should be noted that, in the embodiments of the present application, the attribute information may include the size and quantity of the first data block, and may also include other attributes. The present application does not specifically limit the type and quantity of information included in the attribute information.
[0103] For example, in the embodiments of the present application, Figure 2 As shown, the process of dividing the data by the first function is shown. Assuming that the first function is Y=2 x In this function, k is a segmentation unit in data segmentation, x is the serial number of the current data block, and y is the size of the current data block. According to the established function, the data can be segmented into N data blocks of different sizes.
[0104] That is to say, in an embodiment of the present application, the first node may split the first data based on the first function, so that when the data is subsequently transmitted to the second node, it is transmitted in the form of data blocks, thereby reducing the risk of data leakage.
[0105] Step 303: The first node encrypts the second data to obtain third data, and sends the third data to the second node.
[0106] It should be noted that, in the embodiments of the application, the second node may be a server node, and the application does not specifically limit the type of the second node.
[0107] It should be noted that in an embodiment of the application, when the first node encrypts the second data to obtain the third data, the second data block can be added to the second data; wherein the second data block contains an interference factor; and then the N first data blocks and the second data blocks can be encrypted based on a preset encryption algorithm to obtain the third data.
[0108] It should be noted that, in the embodiment of the application, the second data block may include an interference factor, and the present application does not specifically limit the type of data included in the second data block.
[0109] It should be noted that in the embodiment of the application, when the first node adds the second data block to the second data, it can add the interference factor to each data block in the N first data blocks respectively. This application does not specifically limit the method of adding the second data block.
[0110] It should be noted that, in the embodiment of the application, the first node adds the second data block to the second data, which can effectively prevent information leakage caused by differential.
[0111] It should be noted that, in the embodiment of the application, after adding the second data block to the second data, the first node can encrypt the N first data blocks and the second data blocks based on a preset encryption algorithm to obtain the third data.
[0112] It should be noted that in the embodiments of the application, the preset encryption algorithm may include an asymmetric homomorphic encryption algorithm or other types of encryption algorithms. This application does not specifically limit the type of the preset encryption algorithm.
[0113] It should be noted that in the embodiment of the application, after the first node encrypts N first data blocks and second data blocks based on a preset encryption algorithm to obtain the third data, the third data can be sent to the second node so that the second node desensitizes the third data.
[0114] It should be noted that, in the embodiment of the application, the first node can receive the desensitized data sent by the second node; and then the desensitized data can be decrypted to obtain the desensitized plaintext data.
[0115] It should be noted that in the embodiment of the application, if the data is uploaded to the server (i.e., the second node) for data desensitization, the data needs to be transmitted to the cloud server, and then the server will perform data desensitization, but in this case, the sensitive data will be exposed on the cloud server. The homomorphic encryption algorithm can solve this problem. The embodiment of the application can encrypt the data before transmitting the data, and the server (i.e., the second node) desensitizes the data after receiving the data, but the desensitization operation is performed on the basis of the ciphertext, thereby ensuring the security of the data.
[0116] Step 304: The second node assembles the third data based on the second function to obtain assembled third data; wherein the second function includes an assembling function.
[0117] It should be noted that, in the embodiment of the application, the third data may include N encrypted first data blocks and an encrypted second data block, and the present application does not specifically limit the type of data and the amount of data included in the third data.
[0118] It should be noted that, in the embodiments of the present application, the second function may include an assembly function, and the present application does not specifically limit the type of the second function.
[0119] It should be noted that in the embodiments of the present application, the assembly function corresponds to the segmentation function, and the assembly function needs to be used when assembling data blocks; generally speaking, the assembly function is different from the segmentation function and should be uniquely determined by the segmentation function, which can ensure that all segmentation functions have corresponding assembly functions. The set of these functions can be stored in the desensitizing system as a function library, and the present application does not specifically limit the storage location of the function library.
[0120] It should be noted that, in an embodiment of the present application, when the second node assembles the third data based on the second function to obtain the assembled third data, it can remove the encrypted second data blocks in the third data to obtain the removed third data; wherein the removed third data includes the encrypted N first data blocks; and then the encrypted N first data blocks can be assembled based on the second function to obtain the assembled third data.
[0121] That is to say, in an embodiment of the present application, after receiving the third data sent by the first node, the second node can first eliminate the encrypted second data block in the third data. The second data block contains an interference factor, that is, the encrypted interference factor data block in the third data can be eliminated, and then the encrypted N first data blocks can be assembled based on the second function to obtain the assembled third data.
[0122] Step 305: The second node performs desensitization processing on the assembled third data by using a preset desensitization algorithm to obtain desensitized data.
[0123] It should be noted that, in the embodiments of the present application, the preset desensitization algorithm may include any type of desensitization algorithm, such as masking, confusion, offset, and averaging, etc. The present application does not specifically limit the type of the preset desensitization algorithm.
[0124] It should be noted that, in the embodiments of the present application, Figure 4 As shown, after the second node desensitizes the assembled third data through a preset desensitizing algorithm and obtains the desensitized data, the desensitized data can be sent to the first node so that the first node decrypts the desensitized data to obtain the desensitized plaintext data.
[0125] That is to say, in an embodiment of the present application, when the second node desensitizes the assembled third data through a preset desensitizing algorithm, it desensitizes the encrypted N first data blocks, so that the desensitization operation of the second node is performed on the basis of the ciphertext, thereby ensuring the security of the data.
[0126] To summarize, after obtaining the first data, the first node can input the first data into the first function to obtain the second data, and the second data includes N first data blocks, that is, the first node in the embodiment of the present application can divide the first data based on the first function, so that when the data is subsequently transmitted to the second node, it is transmitted in the form of data blocks, thereby reducing the risk of data leakage; then the first node can add the second data block to the second data, and can encrypt the N first data blocks and the second data blocks based on a preset encryption algorithm to obtain the third data, and then send the third data to the second node, the second node can remove the encrypted second data block in the third data to obtain the removed third data; wherein the removed third data includes the encrypted N first data blocks; then the encrypted N first data blocks can be assembled based on the second function to obtain the assembled third data, and then the assembled third data can be desensitized by a preset desensitization algorithm to obtain the desensitized data, that is, the second node's operation of desensitizing the data is performed on the basis of the ciphertext, thereby ensuring the security of the data.
[0127] An embodiment of the present application provides a data desensitization method, which is applied to a first node and a second node, the first node obtains first data, wherein the first data includes data to be desensitized; the first data is segmented based on a first function to obtain second data; wherein the first function is at least used to segment the first data, the second data includes N first data blocks, N is a positive integer; the second data is encrypted to obtain third data, and the third data is sent to the second node; the second node assembles the third data based on the second function to obtain assembled third data; wherein the second function includes an assembling function; the assembled third data is desensitized by a preset desensitization algorithm to obtain desensitized data. It can be seen that after obtaining the first data, the first node can use the first function to split the first data to obtain second data, and the second data can contain N first data blocks, that is, the embodiment of the present application can use the first function to split the first data to obtain N first data blocks, which can be subsequently transmitted in the form of data blocks, thereby effectively reducing the risk of data leakage; then the first node can send the encrypted third data to the second node, and the second node can assemble the third data based on the second function to obtain assembled third data, and desensitize the assembled third data through a preset desensitization algorithm. Since the assembled third data is encrypted data, that is, the data desensitization operation performed by the second node is performed on the basis of ciphertext, thereby ensuring the security of sensitive data.
[0128] Based on the above embodiments, another embodiment of the present application provides a data desensitization method. Figure 6 Schematic diagram of the data desensitization method proposed in the embodiment of this application Figure 5 ,like Figure 6 As shown, the client (i.e., the first node) is a system used by users to initiate data desensitization, which mainly provides functions such as preprocessing of data to be desensitized, generation and storage of segmentation functions (i.e., the first function) and interference factors (i.e., the second data block), segmentation of data to be desensitized, encryption, ciphertext transmission, desensitized information transmission, and storage; the server (i.e., the second node) is a system for desensitizing data, which mainly has functions such as removing interference factors, assembling data to be desensitized, and data desensitization.
[0129] It should be noted that in the embodiments of the present application, the split function (i.e., the first function) can be a built-in function in the system or a user-defined function. It can be used normally as long as the client and the server agree on the function information to be used. This application does not specifically limit the type of split function.
[0130] It should be noted that, in the embodiments of the present application, the addition of interference factors can effectively prevent differential attacks, and can prevent information leakage to a certain extent even when the security of the partitioning function is not high enough.
[0131] It should be noted that in an embodiment of the present application, the segmented data block (i.e., the first data block) will be encrypted and transmitted by the processing program of the client (i.e., the first node); after receiving the ciphertext information, the server (i.e., the second node) will decrypt the ciphertext, propose the interference factor, and assemble the information according to the assembly function corresponding to the segmentation function, and then desensitize the assembled data.
[0132] It should be noted that in the embodiment of the present application, the specific use process of the segmentation function (i.e., the first function) is as follows: (1) the client segments the data to be desensitized (i.e., the first data): after the user inputs the data to be desensitized, the client will segment the data to be desensitized through the segmentation function and encrypt it after adding interference factors. The input item of the function is the data to be desensitized, and the output item is the information after segmentation. The number of segmented data blocks and the order of assembly are uniquely determined by the function and maintained by the desensitization system. The function itself is equivalent to the key to open the target file. Only by using the specified function to assemble all data blocks in the correct order can the correct original text be obtained; there is no specified requirement for the function used to segment the data to be desensitized, but it needs to meet one condition, that is, within the specified range, the value range and definition domain of the function can form a one-to-one mapping; corresponding to the segmentation function, the assembly function (i.e., the second function) needs to be used when assembling the data blocks. Generally speaking, the assembly function is different from the segmentation function and should be uniquely determined by the segmentation function. Due to the existence of the above conditions, it can be ensured that all segmentation functions have corresponding assembly functions. The collection of these functions can be stored as a function library in the desensitization system. When desensitizing data, the client selects a function to segment the data and records the required assembly function; (2) Add interference factors: After segmenting the data, it is necessary to add interference factors (i.e., the second data block) to the segmented data set (i.e., the second data) to prevent information leakage caused by differential analysis; (3) Information encryption: Information encryption is mainly completed by the client's processing program. This step is responsible for encrypting the data blocks generated by the segmentation function and the interference factor data blocks into ciphertext to ensure the security of data transmission. In order to improve the processing efficiency of data desensitization on the server side, an asymmetric homomorphic encryption algorithm (i.e., the preset encryption algorithm) can be used for encryption.
[0133] For example, in the embodiment of the present application, in the process of segmenting the data to be desensitized, the value ranges of the size and quantity of the data blocks after segmentation can be listed as the definition domain or value range of the segmentation function, with the function Y=2 x For example, the specific segmentation method can be as follows Figure 2As shown, the process of function segmentation of data is demonstrated. In this function, k is a segmentation unit in data segmentation, x is the serial number of the current data block, and y is the size of the current data block. According to the established function, the data can be segmented into n data blocks of different sizes (i.e., the second data); its corresponding combination function (i.e., the second function) can sort and assemble the data according to the size of the data block, thereby obtaining the complete original data. The above functions are only reference examples. In the embodiments of the present application, the data segmentation function (i.e., the first function) is not limited to the exponential function, and the function is not just the relationship between the data block serial number and the current data block size; at the same time, the segmentation function can also add specific parameters to control the size and quantity of the data blocks.
[0134] It should be noted that in the embodiments of the present application, homomorphic encryption may refer to encrypting plaintext m to obtain ciphertext c, satisfying f(c) is the ciphertext of f(m), where f is any function belonging to a certain function family F, and the plaintext may be a single plaintext or a plaintext vector, corresponding to a single ciphertext and a ciphertext vector. The corresponding function family F may be a homomorphic function family, that is, the set of all supported functions that can be calculated homomorphically. For example, f(x) = x+2, and the encrypted c is the ciphertext of the plaintext m, then f(c) = c+2, which is the ciphertext of m+2.
[0135] That is to say, in the embodiments of the present application, with the help of homomorphic encryption, the effect of operating directly on the ciphertext and operating on the plaintext and then encrypting is the same. If the data is uploaded to the server for data desensitization, it is necessary to transfer the data to the cloud server, and then the server will desensitize the data. However, in this case, the sensitive data is exposed on the cloud server. Homomorphic encryption solves this problem. The data is encrypted before transmission, and the server desensitizes the data after receiving the data. However, the desensitization operation is performed on the basis of the ciphertext. After the result is obtained, the ciphertext of the result is returned, and the client decrypts the ciphertext to obtain the final result.
[0136] To summarize, after obtaining the first data, the first node can input the first data into the first function to obtain the second data, and the second data includes N first data blocks, that is, the first node in the embodiment of the present application can divide the first data based on the first function, so that when the data is subsequently transmitted to the second node, it is transmitted in the form of data blocks, thereby reducing the risk of data leakage; then the first node can add the second data block to the second data, and can encrypt the N first data blocks and the second data blocks based on a preset encryption algorithm to obtain the third data, and then send the third data to the second node, the second node can remove the encrypted second data block in the third data to obtain the removed third data; wherein the removed third data includes the encrypted N first data blocks; then the encrypted N first data blocks can be assembled based on the second function to obtain the assembled third data, and then the assembled third data can be desensitized by a preset desensitization algorithm to obtain the desensitized data, that is, the second node's operation of desensitizing the data is performed on the basis of the ciphertext, thereby ensuring the security of the data.
[0137] An embodiment of the present application provides a data desensitization method, which is applied to a first node and a second node, the first node obtains first data, wherein the first data includes data to be desensitized; the first data is segmented based on a first function to obtain second data; wherein the first function is at least used to segment the first data, the second data includes N first data blocks, N is a positive integer; the second data is encrypted to obtain third data, and the third data is sent to the second node; the second node assembles the third data based on the second function to obtain assembled third data; wherein the second function includes an assembling function; the assembled third data is desensitized by a preset desensitization algorithm to obtain desensitized data. It can be seen that after obtaining the first data, the first node can use the first function to split the first data to obtain second data, and the second data can contain N first data blocks, that is, the embodiment of the present application can use the first function to split the first data to obtain N first data blocks, which can be subsequently transmitted in the form of data blocks, thereby effectively reducing the risk of data leakage; then the first node can send the encrypted third data to the second node, and the second node can assemble the third data based on the second function to obtain assembled third data, and desensitize the assembled third data through a preset desensitization algorithm. Since the assembled third data is encrypted data, that is, the data desensitization operation performed by the second node is performed on the basis of ciphertext, thereby ensuring the security of sensitive data.
[0138] Based on the above embodiment, the embodiment of the present application provides a first node, Figure 7The structure diagram of the first node Figure 1 ,like Figure 7 As shown, the first node 10 includes: an acquisition unit 11, a segmentation unit 12, an encryption unit 13, and a sending unit 14; wherein,
[0139] The acquisition unit 11 is used to acquire first data, wherein the first data includes data to be desensitized;
[0140] The segmentation unit 12 is used to segment the first data based on a first function to obtain second data; wherein the first function is at least used to segment the first data, and the second data includes N first data blocks, where N is a positive integer;
[0141] The encryption unit 13 is used to encrypt the second data to obtain third data;
[0142] The sending unit 14 is used to send the third data to the second node, so that the second node performs desensitization processing on the third data.
[0143] In the embodiments of the present application, further, Figure 8 The structure diagram of the first node Figure 2 ,like Figure 8 As shown, the first node 10 proposed in the embodiment of the present application may also include a first processor 15, a first memory 16 storing executable instructions of the first processor 15, and further, the first node 10 may also include a first communication interface 17, and a first bus 18 for connecting the first processor 15, the first memory 16 and the first communication interface 17.
[0144] In the embodiment of the present application, the first processor 15 may be at least one of an Application Specific Integrated Circuit (ASIC), a Digital Signal Processor (DSP), a Digital Signal Processing Device (DSPD), a Programmable Logic Device (PLD), a Field Programmable Gate Array (FPGA), a Central Processing Unit (CPU), a controller, a microcontroller, and a microprocessor. It can be understood that for different devices, the electronic device used to implement the above-mentioned processor function may also be other, and the embodiment of the present application is not specifically limited. The first node 10 may also include a first memory 16, which may be connected to the first processor 15, wherein the first memory 16 is used to store executable program code, the program code includes computer operation instructions, and the first memory 16 may include a high-speed RAM memory, and may also include a non-volatile memory, for example, at least two disk memories.
[0145] In the embodiment of the present application, the first bus 18 is used to connect the first communication interface 17, the first processor 15 and the first memory 16, and the mutual communication between these devices.
[0146] In the embodiment of the present application, the first memory 16 is used to store instructions and data.
[0147] Further, in an embodiment of the present application, the above-mentioned first processor 15 is used to obtain first data, wherein the first data includes data to be desensitized; the first data is segmented based on a first function to obtain second data; wherein the first function is at least used to segment the first data, and the second data includes N first data blocks, where N is a positive integer; the second data is encrypted to obtain third data, and the third data is sent to the second node so that the second node desensitizes the third data.
[0148] In practical applications, the first memory 16 may be a volatile memory, such as a random access memory (RAM); or a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD); or a combination of the above types of memories, and provide instructions and data to the first processor 15.
[0149] The embodiment of the present application provides a first node, the first node obtains the first data, wherein the first data includes the data to be desensitized; the first data is segmented and processed based on the first function to obtain the second data; wherein the first function is at least used to segment the first data, and the second data includes N first data blocks, N is a positive integer; the second data is encrypted to obtain the third data, and the third data is sent to the second node, so that the second node performs desensitization on the third data. It can be seen that after obtaining the first data, the first node can use the first function to segment the first data to obtain the second data, and the second data can include N first data blocks, that is, the embodiment of the present application can use the first function to segment the first data to obtain N first data blocks, which can be subsequently transmitted in the form of data blocks, thereby effectively reducing the risk of data leakage; then the first node can send the encrypted third data to the second node, so that the second node performs desensitization on the third data.
[0150] An embodiment of the present application provides a computer-readable storage medium having a program stored thereon, which implements the data desensitization method as described above when executed by a processor.
[0151] Specifically, a program instruction corresponding to a data desensitization method in this embodiment can be stored on a storage medium such as a CD, a hard disk, or a USB flash drive. When a program instruction corresponding to a data desensitization method in the storage medium is read or executed by an electronic device, the following steps are included:
[0152] Acquire first data, wherein the first data includes data to be desensitized;
[0153] The first data is segmented based on a first function to obtain second data; wherein the first function is at least used to segment the first data, and the second data includes N first data blocks, where N is a positive integer;
[0154] The second data is encrypted to obtain third data, and the third data is sent to the second node so that the second node desensitizes the third data.
[0155] The embodiment of the present application further provides a computer program product, including a computer program, and the computer program can be executed by the first processor 15 of the first node 10 to complete the steps of any of the aforementioned methods.
[0156] In the embodiments of the present application, further, Fig. 9 The structure diagram of the second node Figure 1 ,like Fig. 9 As shown, the second node 20 includes: a receiving unit 21, an assembling unit 22, and a processing unit 23; wherein,
[0157] The receiving unit 21 is used to receive third data sent by the first node; wherein the third data includes the encrypted N first data blocks and the encrypted second data block;
[0158] The assembling unit 22 is used to assemble the third data based on the second function to obtain assembled third data; wherein the second function includes an assembling function;
[0159] The processing unit 23 is used to perform desensitization processing on the assembled third data through a preset desensitization algorithm to obtain desensitized data.
[0160] In the embodiments of the present application, further, Fig.10 The structure diagram of the second node Figure 2 ,like Fig.10 As shown, the second node 20 proposed in the embodiment of the present application may also include a second processor 24, a second memory 25 storing executable instructions of the second processor 24, and further, the second node 20 may also include a second communication interface 26, and a second bus 27 for connecting the second processor 24, the second memory 25 and the second communication interface 26.
[0161] In the embodiment of the present application, the second processor 24 can be at least one of an application-specific integrated circuit (ASIC), a digital signal processor (DSP), a digital signal processing device (DSPD), a programmable logic device (PLD), a field programmable gate array (FPGA), a central processing unit (CPU), a controller, a microcontroller, and a microprocessor. It can be understood that for different devices, the electronic device used to implement the above-mentioned processor function can also be other, and the embodiment of the present application is not specifically limited. The second node 20 can also include a second memory 25, which can be connected to the second processor 24, wherein the second memory 25 is used to store executable program code, the program code includes computer operation instructions, and the second memory 25 may include a high-speed RAM memory, and may also include a non-volatile memory, for example, at least two disk memories.
[0162] In the embodiment of the present application, the second bus 27 is used to connect the second communication interface 26, the second processor 24 and the second memory 25, and the mutual communication between these devices.
[0163] In the embodiment of the present application, the second memory 25 is used to store instructions and data.
[0164] Further, in an embodiment of the present application, the above-mentioned second processor 24 is used to receive third data sent by the first node; wherein the third data includes N encrypted first data blocks and encrypted second data blocks; the third data is assembled based on the second function to obtain assembled third data; wherein the second function includes an assembly function; the assembled third data is desensitized by a preset desensitization algorithm to obtain desensitized data.
[0165] In practical applications, the second memory 25 may be a volatile memory, such as a random access memory (RAM); or a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD); or a combination of the above types of memories, and provide instructions and data to the second processor 24.
[0166] The embodiment of the present application provides a second node, the second node receives the third data sent by the first node; wherein the third data includes N encrypted first data blocks and an encrypted second data block; the third data is assembled based on the second function to obtain the assembled third data; wherein the second function includes an assembly function; the assembled third data is desensitized by a preset desensitization algorithm to obtain the desensitized data. It can be seen that the second node can assemble the third data based on the second function to obtain the assembled third data, and desensitize the assembled third data by a preset desensitization algorithm. Since the assembled third data is encrypted data, that is, the data desensitization operation of the second node is performed on the basis of ciphertext, thereby ensuring the security of sensitive data.
[0167] An embodiment of the present application provides a computer-readable storage medium having a program stored thereon, which implements the data desensitization method as described above when executed by a processor.
[0168] Specifically, a program instruction corresponding to a data desensitization method in this embodiment can be stored on a storage medium such as a CD, a hard disk, or a USB flash drive. When a program instruction corresponding to a data desensitization method in the storage medium is read or executed by an electronic device, the following steps are included:
[0169] receiving third data sent by the first node; wherein the third data includes the encrypted N first data blocks and the encrypted second data block;
[0170] Performing assembly processing on the third data based on a second function to obtain assembled third data; wherein the second function includes an assembly function;
[0171] The assembled third data is desensitized by using a preset desensitization algorithm to obtain desensitized data.
[0172] The embodiment of the present application further provides a computer program product, including a computer program, and the computer program can be executed by the second processor 24 of the second node 20 to complete the steps of any of the aforementioned methods.
[0173] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of hardware embodiments, software embodiments, or embodiments in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage and optical storage, etc.) that contain computer-usable program code.
[0174] The present application is described with reference to implementation flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the process in the flowchart. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0175] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device, which is implemented in the implementation flow diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0176] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing the steps in the flowchart. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0177] The above description is only a preferred embodiment of the present application and is not intended to limit the protection scope of the present application.
Claims
1. A data desensitization method, characterized in that: The method is applied to a first node, and the method comprises: Acquire first data, wherein the first data includes data to be desensitized; The first data is segmented based on a first function to obtain second data; wherein the first function is at least used to segment the first data, and the second data includes N first data blocks, where N is a positive integer; The second data is encrypted to obtain third data, and the third data is sent to the second node so that the second node desensitizes the third data.
2. The method according to claim 1, characterized in that The step of segmenting the first data based on the first function to obtain second data includes: The first data is input into the first function to obtain the N first data blocks; wherein the first function includes M parameter information, and the parameter information is used to control the attribute information of the first data blocks, and the attribute information includes one or more of the size and quantity of the first data blocks, and M is a positive integer.
3. The method according to claim 1, characterized in that The encrypting the second data to obtain the third data includes: Adding a second data block to the second data; wherein the second data block includes an interference factor; The N first data blocks and the second data block are encrypted based on a preset encryption algorithm to obtain the third data.
4. The method according to claim 1, characterized in that: The method further comprises: Receiving the desensitized data sent by the second node; The desensitized data is decrypted to obtain desensitized plaintext data.
5. A data desensitization method, characterized in that: The method is applied to the second node, and the method includes: receiving third data sent by the first node; wherein the third data includes the encrypted N first data blocks and the encrypted second data block; Performing assembly processing on the third data based on a second function to obtain assembled third data; wherein the second function includes an assembly function; The assembled third data is desensitized by using a preset desensitization algorithm to obtain desensitized data.
6. The method according to claim 5, characterized in that The assembling process of the third data based on the second function to obtain assembled third data includes: Eliminating the encrypted second data block in the third data to obtain eliminated third data; wherein the eliminated third data includes the encrypted N first data blocks; The encrypted N first data blocks are assembled based on the second function to obtain the assembled third data.
7. The method according to claim 5, characterized in that After performing desensitization processing on the assembled third data by using a preset desensitization algorithm to obtain desensitized data, the method further includes: The desensitized data is sent to the first node, so that the first node decrypts the desensitized data to obtain the desensitized plaintext data.
8. A first node, characterized in that: The first node includes: an acquisition unit, a segmentation unit, an encryption unit, and a sending unit; wherein, The acquisition unit is used to acquire first data, wherein the first data includes data to be desensitized; The segmentation unit is used to segment the first data based on a first function to obtain second data; wherein the first function is at least used to segment the first data, and the second data includes N first data blocks, where N is a positive integer; The encryption unit is used to encrypt the second data to obtain third data; The sending unit is used to send the third data to the second node, so that the second node performs desensitization processing on the third data.
9. A first node, characterized in that: The first node includes: a first processor and a first memory; wherein, The first memory is used to store a computer program that can be run on the processor; The first processor is configured to execute the method according to any one of claims 1 to 4 when running the computer program.
10. A second node, characterized in that: The second node includes: a receiving unit, an assembling unit, and a processing unit; wherein, The receiving unit is configured to receive third data sent by the first node; wherein the third data includes the encrypted N first data blocks and the encrypted second data block; The assembling unit is used to assemble the third data based on the second function to obtain assembled third data; wherein the second function includes an assembling function; The processing unit is used to perform desensitization processing on the assembled third data through a preset desensitization algorithm to obtain desensitized data.
11. A second node, characterized in that: The second node includes: a second processor and a second memory; wherein, The second memory is used to store a computer program that can be run on the processor; The second processor is configured to execute the method according to any one of claims 5 to 7 when running the computer program.
12. A computer-readable storage medium, characterized in that: The storage medium stores computer program codes, which, when executed by a computer, execute the method described in any one of claims 1 to 4 or 5 to 7.
13. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the computer program implements the method according to any one of claims 1-4 or 5-7.