Batch data desensitization method for operation risk prevention and data operation management platform
By implementing two-person operation and approval process management methods on the data operation management platform, the problems of operation risks and data leakage risks during batch data desensitization are solved, the security and integrity of data operations are achieved, and complex desensitization strategies can be met.
Patent Information
- Application Number
- CN202411992998.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-05-09
AI Technical Summary
The prior art has operational risks and data leakage risks in the process of batch data desensitization, and the data operation platform has failed to effectively prevent operational risks, making it difficult to cope with the needs of complex desensitization strategies.
A batch data desensitization method for operational risk prevention is adopted to realize two-person operation and approval process management through the data operation management platform to ensure the safety and integrity of data desensitization operations. The specific steps include the main record data desensitization operator and the audit operator login to the platform separately, desensitization scheme and tasks, and ensure permissions and operations compliance through digital signatures and two-person operating modes.
It effectively reduces the operational risks and data leakage risks during batch data desensitization, ensures the security and integrity of data operations, and can cope with the needs of complex desensitization strategies.
Smart Images

Figure CN119961966A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of IT system operation and maintenance, and specifically relates to a batch data desensitization method and a data operation management platform for preventing operational risks. Background Art
[0002] Data desensitization is used to ensure that sensitive data is not leaked. There are two types of application scenarios. One is the desensitization of sensitive data in applications. In this case, it is basically an online transaction application scenario, such as customer card numbers and account numbers in online banking and mobile banking; or customer names, mobile phone numbers, addresses and other data on express delivery bills, which will be displayed in a desensitized manner. This type of data desensitization is implemented by the application system itself within the system. Another type of application scenario is that due to the needs of application system testing or external business cooperation, large quantities of data need to be desensitized and taken out of the production system for application.
[0003] When batch desensitizing data from production systems, due to the uncertainty of the data use scenarios of data demanders, the data range involved is relatively large, and the demand for desensitization strategies is also diverse. In this case, there are currently two main methods for batch data desensitization.
[0004] 1. Most of them are achieved by manually organizing various data desensitization software tools.
[0005] 2. A small part is achieved through data operation platforms in conjunction with various data desensitizing software.
[0006] The main problems with the current method are as follows:
[0007] 1. Since batch data desensitization faces the problem of operating production data, manually organizing various desensitizing software tools can easily bring operational risks and data leakage risks to production data.
[0008] 2. The data operation platform software that currently supports data desensitization is designed to support the completion of data desensitization needs. It only considers functional support and does not consider operational risk prevention issues.
[0009] 3. The data operation platform software that currently supports data desensitization does not fully consider the support for various desensitization strategies and is unable to cope with the complex desensitization strategy needs in reality.
[0010] Therefore, how to overcome the shortcomings of existing technologies is an urgent problem to be solved in the field of IT system operation and maintenance technology. Summary of the invention
[0011] The purpose of the present invention is to solve the deficiencies of the prior art and to provide a batch data desensitization method and a data operation management platform for preventing operational risks.
[0012] To achieve the above purpose, the technical solution adopted by the present invention is as follows:
[0013] A batch data desensitization method for preventing operational risks comprises the following steps:
[0014] Step (1), two data desensitization operators log in to the data operation management platform on their respective machines; the two data desensitization operators are the main data desensitization operator and the review operator;
[0015] Step (2): The main recording data desensitization operator forms an SQL file for all SQL statements that need to be desensitized, and determines the name of the desensitization file and the desensitization description for this time, forming a data operation task; then the data operation task is sent to the SQL management module, and a desensitization policy definition request is sent;
[0016] Step (3), the SQL management module receives the desensitization policy definition request, analyzes the SQL statement in the data operation task, parses out the database, table and field, and then calls the data desensitization module; the data desensitization module compares the database, table and field list that needs to be desensitized pre-stored in the data desensitization module according to the database, table and field passed by the SQL management module, obtains the database, table and field list that needs to be desensitized this time, and returns it to the SQL management module; the SQL management module generates a structure file based on this;
[0017] Step (4), the main recording data desensitization operator defines the desensitization scheme file according to the structure file returned by the SQL management module; in the desensitization scheme file, it is necessary to select a specific desensitization strategy for each desensitized field; after completing the definition of the desensitization scheme file, the main recording data desensitization operator submits the desensitization task file to the SQL management module;
[0018] Step (5), after the SQL management module receives the desensitizing task file, it first calls the security management module to attach the digital signature of the operator who records the desensitizing data to the desensitizing task file; then it checks the operator's two-person status from the session information managed by the SQL management module (refers to the storage object established for each user on the server side, which is established when the user logs in and destroyed when the user logs out, and can save various types of information). If it is found that there is no two-person status information, the two-person operation management module is called, and the input parameters are the database, table and corresponding operation information obtained by analyzing the SQL statement, and the output parameters are the two-person status information and other information, including whether the operation involved in the desensitizing task belongs to the key data operation The information of the operation defined by the two-person strategy needs to start the two-person operation; the two-person operation management module is called again, and the main recording data desensitization operator selects and confirms the two-person operation mode and the second data desensitization operator; the two-person operation management module returns the two-person operation mode and the second data desensitization operator to the SQL management module; the SQL management module, the second data desensitization operator, modifies the two-person status of the main recording data desensitization operator in the session information, and saves the two-person operation mode and the second data desensitization operator information in the session information of the second data desensitization operator; wherein, the two-person operation mode is the main recording auxiliary review mode; the second data desensitization operator is the review operator;
[0019] Step (6), the SQL management module provides the audit operator with the desensitizing task information that needs to be reviewed and confirmed according to the requirements of the main recording and auxiliary review mode; the desensitizing task information includes a desensitizing task file with a digital signature of the main recording data desensitizing operator attached;
[0020] Step (7), after the audit operator completes the audit, the audit description is added to the desensitization task file to confirm that the audit has passed; the SQL management module appends the digital signature of the audit operator to the desensitization task file;
[0021] Step (8), the SQL management module calls the security management module, and the security management module compares the permission type of the data desensitization operator and its role for query operations on the database and table and the operations on the database and table involved in the SQL statement in the SQL file, and determines whether the data desensitization operator has the permission to execute the data operation task file;
[0022] Step (9), the security management module finds that the database table query operation for important data in the desensitization task file only has applications from personnel with application rights, but no approval from personnel with approval rights, and returns the approval required and the corresponding approval process code information;
[0023] Step (10), the SQL management module uses the desensitized task file and approval process coding information processed in step (7) as parameters to call the approval process management module;
[0024] Step (11), the approval process management module starts the corresponding approval process according to the approval process code. When the data desensitization approver approves and agrees, the approval description is added to the desensitization task file, and the digital signature of the data desensitization approver is attached to the desensitization task file; then the desensitization task file with the signature is returned to the SQL management module;
[0025] Step (12), the SQL management module calls the security management module to check whether the permission requirements are met;
[0026] Step (13), after checking, the security management module finds that the query operation for important data has both the application of the personnel with application rights and the approval of the personnel with approval rights, the query execution authority is complete, and the query for other data has the query authority, and returns the information that the authority meets the requirements to the SQL management module; if the authority requirements are not met, it returns the authority check failure and the specific reason code and information;
[0027] Step (14), the SQL management module calls the data source management module to execute the data desensitization task according to the task attributes of the desensitization task;
[0028] Step (15), the data source management module executes the data query, and after receiving the query results, saves the results as a set of data files, and then calls the data desensitization module, which completes the data desensitization and file reassembly; after the reassembly is completed, the data desensitization module notifies the data source management module that the desensitization task is completed, and the data source management module notifies the SQL management module that the desensitization task is completed;
[0029] Step (16), the SQL management module notifies the main recording data desensitization operator that the desensitization task is completed, and the main recording data desensitization operator obtains the desensitized data file, and the data desensitization task is completed.
[0030] Furthermore, preferably, in step (2), the main data desensitizing operator uses an SQL generator to assist in generating SQL statements for querying the data to be desensitized, or manually writes SQL statements for querying the data to be desensitized, or imports SQL statements for querying the data to be desensitized from external files.
[0031] Furthermore, preferably, in step (3), the structure file includes a query field list and field identifiers that need to be desensitized.
[0032] Furthermore, preferably, in step (4), the main recording data desensitization operator saves the defined desensitization scheme file as a desensitization scheme template.
[0033] Furthermore, preferably, in step (4), the desensitizing task file includes a data operation task and a desensitizing solution file.
[0034] Furthermore, preferably, in step (5), the two-person operation management module is called for the first time and returns the two-person strategy for key data operation required for the desensitization task according to the setting of the two-person operation strategy and the library, table, and operation information; when called for the second time, the main recording data desensitization operator in the SQL management module call is confirmed as the main recording data desensitization operator, the currently logged-in data desensitization operator is searched, and the main recording data desensitization operator is provided with an optional operation mode and a list of desensitization operators for optional review data, and the main recording data desensitization operator is asked to confirm the operation mode and the second data desensitization operator; after the main recording data desensitization operator confirms, the two-person operation management module returns the two-person operation mode and the information of the second data desensitization operator to the SQL management module.
[0035] Furthermore, preferably, in step (11), if the approval process is implemented by connecting to an external system, the external system will be required to return a list of approvers, and the SQL management module will be responsible for attaching the digital signature of the data desensitizing approver.
[0036] Furthermore, preferably, in step (14), the task attribute is to be executed immediately or within a specified time period.
[0037] The present invention also provides a data operation management platform for operational risk prevention, including an SQL management module, a two-person operation management module, an approval process management module, a security management module, a data desensitization module and a data source management module;
[0038] The data operation management platform executes the steps of the batch data desensitization method for operational risk prevention as described in any one of Rights 1 to Rights 8.
[0039] Furthermore, preferably, it further comprises:
[0040] The user management module is used to manage the user's basic information, group, and role information, and also uses multi-factor authentication and certificate authentication;
[0041] The permission management module is used to manage the user's operation permissions on resources;
[0042] Import and export module, used to import and export data files;
[0043] The audit log module is used to log all data operation tasks and to query and retrieve logs.
[0044] The present invention discloses a batch data desensitization method for preventing operational risks, which provides support for the application of such batch desensitization.
[0045] The present invention is implemented based on a data operation management platform for operational risk prevention. A data operation management platform for operational risk prevention can complete all data operation functions of relational databases involved in daily operation and maintenance. A unified interface, centralized management, and centralized authorization are used for data operations of various mainstream databases, reducing the operational risks of using multiple operating tools. It also provides functions such as two-person operation, integrated approval operations, and audit logs. The present invention is deeply integrated with the data operation management platform to provide a batch data desensitization function with operational risk prevention capabilities.
[0046] The present invention adds a data desensitization module to the data operation management platform. The data desensitization module provides a list definition function for libraries, tables, and fields that need to be desensitized. Various data desensitization strategy plug-ins implemented through standard interfaces include various plug-ins such as shielding, deformation, and character replacement. The desensitization scheme template and the desensitization scheme file define the desensitization plug-in list corresponding to the library, table, and field. The data desensitization module receives the data files, structure files, and desensitization scheme files that need to be desensitized, disassembles the data files according to the structure files, calls the data desensitization strategy plug-in according to the desensitization strategy defined in the desensitization scheme file, desensitizes the field information, and re-assembles the desensitized data files after completing the field desensitization.
[0047] The present invention adds a data desensitization interface to the SQL management module of the data operation management platform, and adds operations related to desensitization on the basis of the data query operation interface. The main control function of the SQL management module increases the information of the library, table, field and identification that need to be desensitized from the data desensitization module.
[0048] The present invention adds a function of calling a data desensitization module to perform data desensitization for the data source management module of the data operation management platform. The data query and desensitization tasks (including structure files and desensitization scheme files) of the SQL management module are received, the database query is executed, the query results are saved as a group of data files, the data desensitization module is called to implement desensitization, and the information of the completion of the data query and desensitization tasks of the SQL management module and the storage location of the desensitized files are returned.
[0049] In terms of role and authority management, the present invention adds the roles of data desensitization operator and data desensitization approver, and seamlessly integrates them into the authority management system of the original data operation management platform. The data desensitization operator is granted the authority related to data desensitization. For important desensitization operations that require approval before execution, the query application right for important libraries and tables is granted, and the query execution right is granted for other libraries and tables involved in desensitization. The data desensitization approver is granted the query approval right for important libraries and tables, and the process code corresponding to the approval needs to be configured. No other authority is granted to these two roles.
[0050] The present invention does not need to adjust the user management, two-person operation management, approval process management, security management, audit log management and other modules of the existing data operation management platform, but only adds specific work to serve the batch data desensitization task.
[0051] Compared with the prior art, the present invention has the following beneficial effects:
[0052] 1. By integrating the data operation management platform and batch data desensitization functions, the data operation management platform is used to provide complete operational risk prevention and control functions for production data, so that the implementation of batch data desensitization functions has the maximum operational risk prevention and control capabilities.
[0053] 2. Various data desensitization strategies and methods are integrated through standard interfaces and plug-in modes, realizing program docking between the data operation platform and various desensitization strategies and methods, reducing manual operations and operational risks.
[0054] 3. Through standard interfaces and plug-in modes, it provides support for various data desensitization strategies and methods, ensuring that the data desensitization function can support various data desensitization application requirements. Through plug-in development, it provides low-cost and extremely fast support capabilities for data desensitization requirements that may arise in the future. BRIEF DESCRIPTION OF THE DRAWINGS
[0055] Figure 1 It is a schematic diagram of the architecture of the data operation management platform used for operational risk prevention in the present invention. DETAILED DESCRIPTION
[0056] The present invention is further described in detail below in conjunction with embodiments.
[0057] Those skilled in the art will appreciate that the following examples are only used to illustrate the present invention and should not be considered to limit the scope of the present invention. If no specific techniques or conditions are specified in the examples, the techniques or conditions described in the literature in the art or the product specifications are used. If the manufacturer of the materials or equipment used is not specified, they are all conventional products that can be purchased.
[0058] It will be understood by those skilled in the art that, unless expressly stated, the singular forms "a", "an", "said" and "the" used herein may also include plural forms. It should be further understood that the term "comprising" used in the specification of the present invention refers to the presence of the features, integers, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof. It should be understood that when we refer to an element as being "connected" to another element, it may be directly connected to the other element, or there may be intermediate elements. The term "and / or" used herein includes any unit and all combinations of one or more associated listed items.
[0059] In the description of the present invention, unless otherwise specified, "plurality" means two or more than two. The terms "inside", "upper", "lower", etc., indicating positions or state relationships, are based on the positions or state relationships shown in the drawings, and are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific position, be constructed and operate in a specific position, and therefore cannot be understood as limiting the present invention.
[0060] In the description of the present invention, it should be noted that, unless otherwise clearly specified and limited, the terms "installed", "connected", and "provided with" should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium. For ordinary technicians in this field, the specific meanings of the above terms in the present invention will be understood according to specific circumstances.
[0061] It will be understood by those skilled in the art that, unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as those generally understood by those skilled in the art in the art to which the present invention belongs. It should also be understood that terms such as those defined in common dictionaries should be understood to have meanings consistent with the meanings in the context of the prior art, and will not be interpreted with idealized or overly formal meanings unless defined as herein.
[0062] Example 1
[0063] A batch data desensitization method for preventing operational risks comprises the following steps:
[0064] Step (1), two data desensitization operators log in to the data operation management platform on their respective machines; the two data desensitization operators are the main data desensitization operator and the review operator;
[0065] Step (2): The main recording data desensitization operator forms an SQL file for all SQL statements that need to be desensitized, and determines the name of the desensitization file and the desensitization description for this time, forming a data operation task; then the data operation task is sent to the SQL management module, and a desensitization policy definition request is sent;
[0066] Step (3), the SQL management module receives the desensitization policy definition request, analyzes the SQL statement in the data operation task, parses out the database, table and field, and then calls the data desensitization module; the data desensitization module compares the database, table and field list that needs to be desensitized pre-stored in the data desensitization module according to the database, table and field passed by the SQL management module, obtains the database, table and field list that needs to be desensitized this time, and returns it to the SQL management module; the SQL management module generates a structure file based on this;
[0067] Step (4), the main recording data desensitization operator defines the desensitization scheme file according to the structure file returned by the SQL management module; in the desensitization scheme file, it is necessary to select a specific desensitization strategy for each desensitized field; after completing the definition of the desensitization scheme file, the main recording data desensitization operator submits the desensitization task file to the SQL management module;
[0068] Step (5), after the SQL management module receives the desensitizing task file, it first calls the security management module to attach the digital signature of the main recording data desensitizing operator to the desensitizing task file; then checks the two-person status of the operator from the session information managed by the SQL management module. If no two-person status information is found, the two-person operation management module is called, and the input parameters are the database, table and corresponding operation information obtained by analyzing the SQL statement, and the output parameters are the two-person status information and other information, including the information that the operation involved in the desensitizing task belongs to the operation defined by the two-person strategy for key data operations, and the two-person operation needs to be started; the two-person operation management module is called again, and the main recording data desensitizing operator selects and confirms the two-person operation mode and the second data desensitizing operator; the two-person operation management module returns the two-person operation mode and the second data desensitizing operator to the SQL management module; the second data desensitizing operator in the SQL management module modifies the two-person status of the main recording data desensitizing operator in the session information, and saves the two-person operation mode and the second data desensitizing operator information in the session information of the second data desensitizing operator; wherein the two-person operation mode is the main recording auxiliary review mode; the second data desensitizing operator is the review operator;
[0069] Step (6), the SQL management module provides the audit operator with the desensitizing task information that needs to be reviewed and confirmed according to the requirements of the main recording and auxiliary review mode; the desensitizing task information includes a desensitizing task file with a digital signature of the main recording data desensitizing operator attached;
[0070] Step (7), after the audit operator completes the audit, the audit description is added to the desensitization task file to confirm that the audit has passed; the SQL management module appends the digital signature of the audit operator to the desensitization task file;
[0071] Step (8), the SQL management module calls the security management module, and the security management module compares the permission type of the data desensitization operator and its role for query operations on the database and table and the operations on the database and table involved in the SQL statement in the SQL file, and determines whether the data desensitization operator has the permission to execute the data operation task file;
[0072] Step (9), the security management module finds that the database table query operation for important data in the desensitization task file only has applications from personnel with application rights, but no approval from personnel with approval rights, and returns the approval required and the corresponding approval process code information;
[0073] Step (10), the SQL management module uses the desensitized task file and approval process coding information processed in step (7) as parameters to call the approval process management module;
[0074] Step (11), the approval process management module starts the corresponding approval process according to the approval process code. When the data desensitization approver approves and agrees, the approval description is added to the desensitization task file, and the digital signature of the data desensitization approver is attached to the desensitization task file; then the desensitization task file with the signature is returned to the SQL management module;
[0075] Step (12), the SQL management module calls the security management module to check whether the permission requirements are met;
[0076] Step (13), after checking, the security management module finds that the query operation for important data has both the application of the personnel with application rights and the approval of the personnel with approval rights, the query execution authority is complete, and the query for other data has the query authority, and returns the information that the authority meets the requirements to the SQL management module; if the authority requirements are not met, it returns the authority check failure and the specific reason code and information;
[0077] Step (14), the SQL management module calls the data source management module to execute the data desensitization task according to the task attributes of the desensitization task;
[0078] Step (15), the data source management module executes the data query, and after receiving the query results, saves the results as a set of data files, and then calls the data desensitization module, which completes the data desensitization and file reassembly; after the reassembly is completed, the data desensitization module notifies the data source management module that the desensitization task is completed, and the data source management module notifies the SQL management module that the desensitization task is completed;
[0079] Step (16), the SQL management module notifies the main recording data desensitization operator that the desensitization task is completed, and the main recording data desensitization operator obtains the desensitized data file, and the data desensitization task is completed.
[0080] Example 2
[0081] A batch data desensitization method for preventing operational risks comprises the following steps:
[0082] Step (1), two data desensitization operators log in to the data operation management platform on their respective machines; the two data desensitization operators are the main data desensitization operator and the review operator;
[0083] Step (2): The main recording data desensitization operator forms an SQL file for all SQL statements that need to be desensitized, and determines the name of the desensitization file and the desensitization description for this time, forming a data operation task; then the data operation task is sent to the SQL management module, and a desensitization policy definition request is sent;
[0084] Step (3), the SQL management module receives the desensitization policy definition request, analyzes the SQL statement in the data operation task, parses out the database, table and field, and then calls the data desensitization module; the data desensitization module compares the database, table and field list that needs to be desensitized pre-stored in the data desensitization module according to the database, table and field passed by the SQL management module, obtains the database, table and field list that needs to be desensitized this time, and returns it to the SQL management module; the SQL management module generates a structure file based on this;
[0085] Step (4), the main recording data desensitization operator defines the desensitization scheme file according to the structure file returned by the SQL management module; in the desensitization scheme file, it is necessary to select a specific desensitization strategy for each desensitized field; after completing the definition of the desensitization scheme file, the main recording data desensitization operator submits the desensitization task file to the SQL management module;
[0086] Step (5), after the SQL management module receives the desensitizing task file, it first calls the security management module to attach the digital signature of the main recording data desensitizing operator to the desensitizing task file; then checks the two-person status of the operator from the session information managed by the SQL management module. If no two-person status information is found, the two-person operation management module is called, and the input parameters are the database, table and corresponding operation information obtained by analyzing the SQL statement, and the output parameters are the two-person status information and other information, including the information that the operation involved in the desensitizing task belongs to the operation defined by the two-person strategy for key data operations, and the two-person operation needs to be started; the two-person operation management module is called again, and the main recording data desensitizing operator selects and confirms the two-person operation mode and the second data desensitizing operator; the two-person operation management module returns the two-person operation mode and the second data desensitizing operator to the SQL management module; the second data desensitizing operator in the SQL management module modifies the two-person status of the main recording data desensitizing operator in the session information, and saves the two-person operation mode and the second data desensitizing operator information in the session information of the second data desensitizing operator; wherein the two-person operation mode is the main recording auxiliary review mode; the second data desensitizing operator is the review operator;
[0087] Step (6), the SQL management module provides the audit operator with the desensitizing task information that needs to be reviewed and confirmed according to the requirements of the main recording and auxiliary review mode; the desensitizing task information includes a desensitizing task file with a digital signature of the main recording data desensitizing operator attached;
[0088] Step (7), after the audit operator completes the audit, the audit description is added to the desensitization task file to confirm that the audit has passed; the SQL management module appends the digital signature of the audit operator to the desensitization task file;
[0089] Step (8), the SQL management module calls the security management module, and the security management module compares the permission type of the data desensitization operator and its role for query operations on the database and table and the operations on the database and table involved in the SQL statement in the SQL file, and determines whether the data desensitization operator has the permission to execute the data operation task file;
[0090] Step (9), the security management module finds that the database table query operation for important data in the desensitization task file only has applications from personnel with application rights, but no approval from personnel with approval rights, and returns the approval required and the corresponding approval process code information;
[0091] Step (10), the SQL management module uses the desensitized task file and approval process coding information processed in step (7) as parameters to call the approval process management module;
[0092] Step (11), the approval process management module starts the corresponding approval process according to the approval process code. When the data desensitization approver approves and agrees, the approval description is added to the desensitization task file, and the digital signature of the data desensitization approver is attached to the desensitization task file; then the desensitization task file with the signature is returned to the SQL management module;
[0093] Step (12), the SQL management module calls the security management module to check whether the permission requirements are met;
[0094] Step (13), after checking, the security management module finds that the query operation for important data has both the application of the personnel with application rights and the approval of the personnel with approval rights, the query execution authority is complete, and the query for other data has the query authority, and returns the information that the authority meets the requirements to the SQL management module; if the authority requirements are not met, it returns the authority check failure and the specific reason code and information;
[0095] Step (14), the SQL management module calls the data source management module to execute the data desensitization task according to the task attributes of the desensitization task;
[0096] Step (15), the data source management module executes the data query, and after receiving the query results, saves the results as a set of data files, and then calls the data desensitization module, which completes the data desensitization and file reassembly; after the reassembly is completed, the data desensitization module notifies the data source management module that the desensitization task is completed, and the data source management module notifies the SQL management module that the desensitization task is completed;
[0097] Step (16), the SQL management module notifies the main recording data desensitization operator that the desensitization task is completed, and the main recording data desensitization operator obtains the desensitized data file, and the data desensitization task is completed.
[0098] In step (2), the main data desensitization operator uses the SQL generator to assist in generating SQL statements for querying the data to be desensitized, or manually writes SQL statements for querying the data to be desensitized, or imports SQL statements for querying the data to be desensitized from external files.
[0099] In step (3), the structure file includes a list of query fields and identifiers of fields that need to be desensitized.
[0100] In step (4), the main recording data desensitization operator saves the defined desensitization plan file as a desensitization plan template.
[0101] In step (4), the desensitization task file includes a data operation task and a desensitization solution file.
[0102] In step (5), the two-person operation management module is called for the first time and returns the two-person strategy for key data operation required for the desensitization task according to the setting of the two-person operation strategy and the library, table, and operation information; the module is called for the second time to confirm the main recording data desensitization operator in the SQL management module call as the main recording data desensitization operator, find the data desensitization operator who has currently logged in, provide the main recording data desensitization operator with an optional operation mode and a list of desensitization operators for optional review data, and ask the main recording data desensitization operator to confirm the operation mode and the second data desensitization operator; after the main recording data desensitization operator confirms, the two-person operation management module returns the two-person operation mode and the information of the second data desensitization operator to the SQL management module.
[0103] In step (11), if the approval process is implemented by connecting to an external system, the external system will be required to return a list of approvers, and the SQL management module will be responsible for attaching the digital signature of the data desensitizing approver.
[0104] In step (14), the task attributes are immediate execution or execution within a specified time period.
[0105] Example 3
[0106] like Figure 1 A data operation management platform for operational risk prevention is shown, including an SQL management module, a two-person operation management module, an approval process management module, a security management module, a data desensitization module and a data source management module;
[0107] The data operation management platform executes the steps of the batch data desensitization method for operational risk prevention described in Example 1 or Example 2.
[0108] Example 4
[0109] like Figure 1 A data operation management platform for operational risk prevention is shown, including an SQL management module, a two-person operation management module, an approval process management module, a security management module, a data desensitization module and a data source management module;
[0110] The data operation management platform executes the steps of the batch data desensitization method for operational risk prevention described in Example 1 or Example 2.
[0111] Also includes:
[0112] The user management module is used to manage the user's basic information, group, and role information, and also uses multi-factor authentication and certificate authentication;
[0113] The permission management module is used to manage the user's operation permissions on resources;
[0114] Import and export module, used to import and export data files;
[0115] The audit log module is used to log all data operation tasks and to query and retrieve logs.
[0116] Application Examples
[0117] This example provides a batch data desensitization method for operational risk prevention. The architecture of the data operation management platform for operational risk prevention in this example is as follows: Figure 1 shown.
[0118] We take the batch data desensitization that requires two people to operate as an example to illustrate the specific implementation method of the present invention.
[0119] Scenario description: The project implementation of building a new business system has entered the user testing phase. The project team needs a batch of data for testing. After research, it is decided to use desensitized production data for testing. The operation and maintenance personnel have received a work order to export the desensitized production data.
[0120] System related information before operation:
[0121] 1. The data desensitization operator (role, assumed by the operation and maintenance personnel) has the right to query and apply for important database tables of the production system corresponding to the new business system, and has the right to query and execute other database tables. The data desensitization approver (role) has the right to query and approve important database tables of the production system corresponding to the new business system.
[0122] 2. The operational risk administrator (role) has turned off the global mandatory two-person strategy. Currently, the two-person strategy for key data operations is in effect. A two-person operation mode has been set for all operations of all tables in the production system corresponding to the new business system, with one main recorder and one reviewer.
[0123] 3. The security risk manager (role) has completed the definition of the list of libraries, tables, and fields that need to be desensitized. (These two roles do not appear in the following method. Is it true that these two roles do not appear in the entire method? Relatively independent managers are used to set up the overall system environment and formulate rules, and do not appear in daily tasks.)
[0124] 4. The main recording data desensitization operator contacts the review operator offline to discuss the operation task time. Report the operation task status to the data desensitization approver (role) in advance. (This step is not necessary, and whether to report can be determined based on the actual situation)
[0125] Task execution process:
[0126] 1. Two data desensitization operators log in to the data operation management platform on their respective machines. The two data desensitization operators are the main data desensitization operator and the review operator;
[0127] 2. The main recording data desensitization operator uses the SQL generator to help generate SQL statements for querying the data to be desensitized (SQL statements can also be written manually or imported from external files). All SQL statements that need to query desensitization form SQL files. The main recording data desensitization operator specifies the name of the desensitization file (usually there are multiple files, most of which correspond to the table name and can be modified), provides the desensitization instructions, and forms a data operation task; then sends the data operation task to the SQL management module and sends a desensitization policy definition request;
[0128] 3. The SQL management module receives the desensitization policy definition request, analyzes the SQL statements in the data operation task, parses out the database, table, and field, and calls the data desensitization module. The data desensitization module compares the database, table, and field passed by the SQL management module with the list of libraries, tables, and fields that have been defined and stored in the data desensitization module, obtains the list of libraries, tables, and fields that need to be desensitized this time, and returns it to the SQL management module. The SQL management module generates a structure file based on this.
[0129] 4. The main recording data desensitization operator returns the structure file (including the query field list and the field identifiers that need to be desensitized) according to the SQL management module, and defines the desensitization plan file based on the existing desensitization plan template or starting from scratch according to the actual needs of the project. In the desensitization plan file, you need to select a specific desensitization strategy for each desensitized field. If it is a character replacement, you need to give the replacement character. The main recording data desensitization operator can save the defined desensitization plan file as a desensitization plan template. In this step, we give the selection of the desensitization strategy to the main recording data desensitization operator, who will select and define it according to the actual desensitization needs. (In the process of defining the desensitization plan file, the main recording data desensitization operator is not allowed to modify the SQL file for querying desensitized data. If the main recording data desensitization operator clicks the modify button to explicitly modify it, it is necessary to resubmit and then submit the SQL file for analysis and inspection, and redefine the desensitization plan file). After completing the definition of the desensitization plan file, the main recording data desensitization operator submits the desensitization task and desensitization task file to the SQL management module;
[0130] 5. After receiving the desensitization task, the SQL management module first calls the security management module to attach the digital signature of the current user (the one who submitted the task and the main data desensitization operator) to the desensitization task file. Then, the two-person status of the operator is checked from the session information managed by the SQL management module (refers to the storage object established for each user on the server side, which is established when the user logs in and destroyed when the user logs out, and can save various types of information). If no two-person status information is found, the two-person operation management module is called, and the input parameters are the database, table and corresponding operation information obtained by analyzing the SQL statement, and the output parameters are the two-person status information and other information, including the information that the operation involved in the desensitization task belongs to the operation defined by the two-person strategy for key data operations, and the two-person operation needs to be started; the two-person operation management module is called again, and the main recording data desensitization operator selects and confirms the two-person operation mode and the second data desensitization operator; the two-person operation management module returns the two-person operation mode and the second data desensitization operator to the SQL management module; the second data desensitization operator of the SQL management module modifies the two-person status of the main recording data desensitization operator in the session information, and saves the two-person operation mode and the second data desensitization operator information in the session information of the second data desensitization operator; wherein, the two-person operation mode is the main recording auxiliary review mode; the second data desensitization operator is the review operator;
[0131] 6. The two-person operation management module is called for the first time and returns the two-person strategy for key data operations required for the task based on the two-person operation strategy settings and the database, table, and operation information. The second time it is called, the data desensitizing operator in the SQL management module call is confirmed as the main data desensitizing operator, and the currently logged-in data desensitizing operator is searched for, and the main data desensitizing operator is provided with an optional operation mode and a list of available audit data desensitizing operators. The main data desensitizing operator is asked to confirm the operation mode and the second data desensitizing operator (audit operator). After the main data desensitizing operator confirms, the two-person operation management module returns the two-person operation mode and the second data desensitizing operator's information to the SQL management module.
[0132] 7. The SQL management module provides the audit operator with the desensitization task information (including data desensitization instructions) that needs to be reviewed and confirmed in accordance with the requirements of the two-person operation mode (main recording and auxiliary review mode). The desensitization task information includes the desensitization task file with the digital signature of the main recording data desensitization operator.
[0133] 8. After the audit operator completes the audit on the computer he / she logs in to, he / she adds the audit description to the desensitization task file to confirm that the audit has passed. The SQL management module attaches the digital signature of the audit operator to the desensitization task file.
[0134] 9. The SQL management module calls the security management module to check whether the permission requirements are met.
[0135] 10. The security management module finds that the database table query operation for important data in the desensitizing task file only has applications from personnel with application rights, but no approval from personnel with approval rights, and returns the information that requires approval and the corresponding approval process coding information.
[0136] 11. The SQL management module takes the data desensitization task-related information and approval process coding information as parameters and calls the approval process management module.
[0137] 12. The approval process management module starts the approval process. When the data desensitization approver (role) approves and agrees, the approval instructions are added to the data desensitization task file, and the digital signature of the data desensitization approver is attached to the data desensitization task file. (If the approval process is implemented by connecting with an external system, when defining the interface between systems, the external system will be required to return the list of approvers, and the SQL management module will be responsible for attaching the digital signature of the data desensitization approver.) Then the desensitization task file with the signature is returned to the SQL management module;
[0138] 13. The SQL management module calls the security management module to check whether the permission requirements are met.
[0139] 14. After checking, the security management module found that the query operation for important data had both application by personnel with application rights and approval by personnel with approval rights, the query execution authority was complete, and the query for other data had query authority. The information that the authority meets the requirements was returned to the SQL management module; if the authority requirements are not met, the authority check failed and the specific reason code and information are returned.
[0140] 15. The SQL management module calls the data source management module to perform the data desensitization task based on the task attributes (execute immediately or within a specified time period).
[0141] 16. The data source management module executes data query, and after receiving the query results, saves the results as a set of data files, and then calls the data desensitization module, which completes the data desensitization and file reassembly; after the reassembly is completed, the data desensitization module notifies the data source management module that the desensitization task is completed, and the data source management module notifies the SQL management module that the desensitization task is completed;
[0142] 17. The SQL management module notifies the main recording data desensitizing operator that the desensitizing task is completed. The main recording data desensitizing operator obtains the desensitized data file, and the data desensitizing task is completed.
[0143] The above shows and describes the basic principles, main features and advantages of the present invention. It should be understood by those skilled in the art that the present invention is not limited to the above embodiments, and the above embodiments and descriptions are only for explaining the principles of the present invention. Without departing from the spirit and scope of the present invention, the present invention may have various changes and improvements, which fall within the scope of the present invention to be protected. The scope of protection of the present invention is defined by the attached claims and their equivalents.
Claims
1. A batch data desensitization method for operational risk prevention, characterized in that: The steps include: Step (1): Two data desensitization operators log in to the data operation management platform on their respective machines; the two data desensitization operators are the main data desensitization operator and the review operator; Step (2): The main recording data desensitization operator forms an SQL file for all SQL statements that need to be desensitized, and determines the name of the desensitization file and the desensitization description for this time, forming a data operation task; Then send the data operation task to the SQL management module and send a desensitization policy definition request; Step (3), the SQL management module receives the desensitization policy definition request, analyzes the SQL statement in the data operation task, parses the database, table and field, and then calls the data desensitization module; The data desensitization module compares the database, table and field list that needs to be desensitized in advance in the data desensitization module according to the database, table and field passed by the SQL management module, obtains the database, table and field list that needs to be desensitized this time, and returns it to the SQL management module; The SQL management module generates a structure file based on this; Step (4), the main recording data desensitization operator defines the desensitization solution file according to the structure file returned by the SQL management module; In the desensitization solution file, you need to select a specific desensitization strategy for each desensitization field; After completing the definition of the desensitization solution file, the main recording data desensitization operator submits the desensitization task file to the SQL management module; Step (5), after receiving the desensitization task file, the SQL management module first calls the security management module to add the digital signature of the main data desensitization operator to the desensitization task file; Then, the two-person status of the operator is checked from the session information managed by the SQL management module. If no two-person status information is found, the two-person operation management module is called. The input parameters are the database, table and corresponding operation information obtained by analyzing the SQL statement, and the output parameters are the two-person status information and other information, including the information that the operation involved in the desensitization task belongs to the operation defined by the two-person strategy for key data operations, and the two-person operation needs to be started; the two-person operation management module is called again, and the main recording data desensitization operator selects and confirms the two-person operation mode and the second data desensitization operator; the two-person operation management module returns the two-person operation mode and the second data desensitization operator to the SQL management module; The second data desensitization operator of the SQL management module modifies the two-person status of the main recording data desensitization operator in the session information, and saves the two-person operation mode and the second data desensitization operator information in the session information of the second data desensitization operator; wherein the two-person operation mode is the main recording auxiliary review mode; the second data desensitization operator is the review operator; Step (6), the SQL management module provides the audit operator with the desensitizing task information that needs to be reviewed and confirmed according to the requirements of the main recording and auxiliary review mode; the desensitizing task information includes a desensitizing task file with a digital signature of the main recording data desensitizing operator attached; Step (7), after the audit operator completes the audit, the audit description is added to the desensitization task file to confirm that the audit has passed; the SQL management module appends the digital signature of the audit operator to the desensitization task file; Step (8), the SQL management module calls the security management module, and the security management module compares the permission type of the data desensitization operator and his role for query operations on the database and table and the operations on the database and table involved in the SQL statement in the SQL file, and determines whether the data desensitization operator has the permission to execute the data operation task file; Step (9), the security management module finds that the database table query operation for important data in the desensitization task file only has applications from personnel with application rights, but no approval from personnel with approval rights, and returns the information that needs approval and the corresponding approval process code; Step (10), the SQL management module uses the desensitized task file processed in step (7) and the approval process coding information as parameters to call the approval process management module; Step (11), the approval process management module starts the corresponding approval process according to the approval process code. When the data desensitization approver approves and agrees, the approval description is added to the desensitization task file, and the digital signature of the data desensitization approver is attached to the desensitization task file; then the desensitization task file with the signature is returned to the SQL management module; Step (12), the SQL management module calls the security management module to check whether the permission requirements are met; Step (13), after checking, the security management module finds that the query operation for important data has both the application of the personnel with application rights and the approval of the personnel with approval rights, and the query execution authority is complete. The query for other data has the query authority, and returns the information that the authority meets the requirements to the SQL management module; if the authority requirements are not met, it returns the authority check failure and the specific reason code and information; Step (14), the SQL management module calls the data source management module to execute the data desensitization task according to the task attributes of the desensitization task; Step (15), the data source management module executes the data query, and after receiving the query results, saves the results as a set of data files, and then calls the data desensitization module, which completes the data desensitization and file reassembly; after the reassembly is completed, the data desensitization module notifies the data source management module that the desensitization task is completed, and the data source management module notifies the SQL management module that the desensitization task is completed; Step (16), the SQL management module notifies the main recording data desensitization operator that the desensitization task is completed, and the main recording data desensitization operator obtains the desensitized data file, and the data desensitization task is completed.
2. The batch data desensitization method for operational risk prevention according to claim 1 is characterized in that: In step (2), the main data desensitization operator uses the SQL generator to assist in generating SQL statements for querying the data to be desensitized, or manually writes SQL statements for querying the data to be desensitized, or imports SQL statements for querying the data to be desensitized from an external file.
3. The batch data desensitization method for operational risk prevention according to claim 1 is characterized in that: In step (3), the structure file includes a list of query fields and identifiers of fields that need to be desensitized.
4. The batch data desensitization method for operational risk prevention according to claim 1 is characterized in that: In step (4), the main recording data desensitization operator saves the defined desensitization plan file as a desensitization plan template.
5. The batch data desensitization method for operational risk prevention according to claim 1 is characterized in that: In step (4), the desensitization task file includes a data operation task and a desensitization solution file.
6. The batch data desensitization method for operational risk prevention according to claim 1 is characterized in that: In step (5), the two-person operation management module is called for the first time to return the two-person operation strategy required to use the key data operation two-person strategy for the desensitization task according to the settings of the two-person operation strategy and the library, table, and operation information; The second time it is called, the main record data desensitization operator in the SQL management module call is confirmed as the main record data desensitization operator, the currently logged in data desensitization operator is searched, and the main record data desensitization operator is provided with an optional operation mode and a list of desensitization operators for selecting to review the data, and the main record data desensitization operator is asked to confirm the operation mode and the second data desensitization operator; After the main data desensitizing operator confirms, the two-person operation management module returns the two-person operation mode and the information of the second data desensitizing operator to the SQL management module.
7. The batch data desensitization method for operational risk prevention according to claim 1 is characterized in that: In step (11), if the approval process is implemented by connecting to an external system, the external system will be required to return a list of approvers, and the SQL management module will be responsible for attaching the digital signature of the data desensitizing approver.
8. The batch data desensitization method for operational risk prevention according to claim 1, characterized in that: In step (14), the task attributes are immediate execution or execution within a specified time period.
9. A data operation management platform for operational risk prevention, characterized in that: Including SQL management module, two-person operation management module, approval process management module, security management module, data desensitization module and data source management module; The data operation management platform executes the steps of the batch data desensitization method for operational risk prevention as described in any one of Rights 1 to Rights 8.
10. The data operation management platform for preventing operational risks according to claim 9, characterized in that: Also includes: The user management module is used to manage the user's basic information, group, and role information, and also uses multi-factor authentication and certificate authentication; The permission management module is used to manage the user's operation permissions on resources; Import and export module, used to import and export data files; The audit log module is used to log all data operation tasks and to query and retrieve logs.