Data desensitization method and system of power system

Through the method of real-time interception and dynamic acquisition of desensitization rules, the problem of complex configuration and insufficient flexibility of existing data desensitization solutions is solved, and efficient, flexible and easy-to-configure data desensitization technology is realized to ensure the security of sensitive data and the real-time and accuracy of desensitization processing.

CN119989383APending Publication Date: 2025-05-13JIANGSU FRONTIER ELECTRIC TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510089531.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

Existing data desensitization solutions are complex in configuration and lack flexibility, difficult to adapt to changing business scenarios, and rely on hard coding, resulting in low system maintenance and poor responsiveness.

Method used

A data desensitization method based on real-time interception and dynamic acquisition of desensitization rules is adopted. Through the tangent-oriented programming mechanism and Java reflection mechanism, data types are identified and pre-set desensitization rules are applied to ensure that the format and structure of the desensitization data are consistent with the original data.

Benefits of technology

It realizes efficient, flexible and easy-to-configure data desensitization technology to ensure the security of sensitive data, simplify the desensitization processing process, improves the flexibility and adaptability of desensitization rules, intercepts and dynamically obtains desensitization rules, and ensures the real-time and accuracy of data desensitization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989383A_ABST
    Figure CN119989383A_ABST
Patent Text Reader

Abstract

The invention discloses a data analysis method and system of a power system, and belongs to the technical field of information security. Based on the received data access request, executing service logic and returning original data as an access result; the method comprises the following steps: intercepting original data in real time before returning the original data to obtain intercepted data; obtaining a desensitization rule corresponding to the intercepted data from preset desensitization rules according to the obtained path of the current interface of the power system; identifying the type of the intercepted data, and performing data desensitization on the intercepted data according to the type of the intercepted data and a corresponding desensitization rule to obtain desensitized data; and performing data recombination on the desensitized data to obtain new original data with the same format and structure as the original data, and continuing to return the new original data as an access result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a data desensitization method and system for a power system. Background Art

[0002] With the rapid development of information technology, data has undoubtedly become one of the core assets of modern enterprises. In today's business environment, the collection, storage, transmission and use of data are indispensable parts of daily operations. However, as the scale of data continues to expand, the risk of sensitive data leakage is also increasing. This phenomenon not only poses a serious threat to personal privacy, but also poses a great challenge to corporate information security and even the stable development of the entire industry. In this context, data desensitization technology, as an effective protection measure, has become increasingly important and has been widely used and practiced in many industries such as finance, medical care, electricity, and the Internet.

[0003] Despite this, existing data desensitization solutions have exposed some problems and limitations during application. First, the configuration process of these solutions is often complicated and requires professional technicians to perform detailed settings, which not only increases the operation and maintenance costs of the enterprise, but also reduces the popularity of data desensitization. Secondly, existing data desensitization technologies generally lack sufficient flexibility and are difficult to adapt to changing business scenarios and needs, which to a certain extent limits their effectiveness in practical applications. Furthermore, many data desensitization solutions rely on hard-coding to implement, which not only reduces the maintainability of the system, but also makes it difficult to make quick adjustments and responses when facing new security threats, affecting the normal use of the client. Summary of the invention

[0004] The purpose of the present invention is to overcome the deficiencies in the prior art and to provide a data desensitization method and system for an electric power system, which ensures the security of sensitive data in each link through a more efficient, flexible and easy-to-configure data desensitization technology, thereby providing a solid data security guarantee for the development of the enterprise.

[0005] To achieve the above object, the present invention is implemented by adopting the following technical solutions: On the one hand, the present invention provides a data desensitization method for a power system, which executes business logic and returns original data as an access result based on a received data access request; the method comprises: Before returning the original data, the original data is intercepted in real time to obtain intercepted data; According to the acquired path of the current interface of the power system, a desensitization rule corresponding to the intercepted data is acquired from the pre-set desensitization rules; Identify the type of the intercepted data, and perform data desensitization on the intercepted data according to the type of the intercepted data and a corresponding desensitization rule to obtain desensitized data; The desensitized data is reorganized to obtain new original data having the same format and structure as the original data, and the new original data is returned as the access result.

[0006] Optionally, by utilizing an aspect-oriented programming mechanism, the original data is intercepted in real time before being returned to obtain intercepted data.

[0007] Optionally, the path of the current interface of the power system is obtained by requesting a mapping processor.

[0008] Optionally, based on the acquired path of the current interface of the power system, real-time communication is performed through the Java open source framework or messages in the message queue of the open source stream processing platform are consumed, and desensitization rules corresponding to the intercepted data are obtained from the pre-set desensitization rules.

[0009] Optionally, the desensitization rules include: According to the data security requirements of the power system, select the interface to be desensitized and its corresponding fields; By using a partial mask strategy, desensitization rules are set for the interface to be desensitized and its corresponding fields to obtain the set desensitization rules.

[0010] Optionally, use the Java reflection mechanism to obtain the type of intercepted data and its corresponding field name; The types of intercepted data include at least data of a single object structure, data of a collection object structure, data of an array object structure and data of a tree object structure.

[0011] Optionally, according to the type of the intercepted data and the corresponding desensitization rule, performing data desensitization on the intercepted data to obtain desensitized data includes: If the intercepted data is of a single object structure, check whether each field in the single object structure has a corresponding desensitization rule and whether each field supports desensitization; if so, perform data desensitization on each field to obtain desensitized data; otherwise, execute recursively until each field is a Java basic type or each field is a type that does not support desensitization; If the type of the intercepted data is data of a non-single object structure, data desensitization is performed on each element in the data of a non-single object structure according to the data desensitization steps of a single object structure to obtain desensitized data.

[0012] Optionally, the desensitized data is reorganized according to the hierarchical relationship of modules, control classes, interfaces, and fields to obtain new original data having the same format and structure as the original data, and the new original data is returned as the access result.

[0013] Optionally, also include: storing the new raw data in a database or caching it in a power system; The new original data at least includes the interface address, field name, and field attribute of the power system.

[0014] On the other hand, the present invention also provides a data desensitization system for a power system, which executes business logic and returns original data as an access result based on a received data access request; the system comprises: A data interception module, used for intercepting the original data in real time before returning the original data to obtain intercepted data; A desensitization rule acquisition module is used to acquire a desensitization rule corresponding to the intercepted data from a preset desensitization rule according to the acquired path of the current interface of the power system; A data desensitization module, used for identifying the type of the intercepted data, and desensitizing the intercepted data according to the type of the intercepted data and the corresponding desensitization rule to obtain desensitized data; The data reorganization module is used to reorganize the desensitized data to obtain new original data with the same format and structure as the original data, and return the new original data as the access result.

[0015] Compared with the prior art, the present invention has the following beneficial effects: The present invention ensures the security of sensitive data in each link through a more efficient, flexible and easy-to-configure data desensitization technology, realizes the seamless connection between the power system and the desensitization service, simplifies the desensitization processing flow, adopts intelligent desensitization and pre-set desensitization rules, and improves the flexibility and adaptability of the desensitization rules; intercepts data in real time and dynamically obtains desensitization rules to ensure the real-time and accuracy of data desensitization; and keeps the original format and structure of the data unchanged without affecting the normal use of the client. Such technology can not only effectively reduce the risk of data leakage, but also enhance the data processing capabilities of the enterprise, thereby providing a solid data security guarantee for the development of the enterprise. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 The figure is a schematic flow chart of a data desensitization method for a power system according to an embodiment of the present invention; Figure 2 The figure is a schematic flow chart of the data desensitization method for the power system of the present invention in the second embodiment; Figure 3 Shown is a flow chart of the data desensitization method for the power system of the present invention in the third embodiment. DETAILED DESCRIPTION

[0017] The technical solution of the present invention is described in detail below through the accompanying drawings and specific embodiments. It should be understood that the embodiments of the present invention and the specific features in the embodiments are detailed descriptions of the technical solution of the present invention, rather than limitations on the technical solution of the present invention. The embodiments of the present invention and the technical features in the embodiments may be combined with each other unless there is a conflict.

[0018] The term "and / or" is only a description of the association relationship between related objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " generally indicates that the related objects are in an "or" relationship.

[0019] Example 1

[0020] like Figure 1 As shown, this embodiment introduces a data desensitization method for a power system, which desensitizes user data in a power system management platform to protect user privacy during data analysis, report sharing or system debugging. The user data includes sensitive information such as user name, account number, home address, contact information, etc., including a preprocessing step, i.e., an integration step, an initialization step, a configuration step, a request acceptance and interception step, a desensitization processing step, and a desensitized data return step.

[0021] That is, based on the received data access request, the business logic is executed and the original data is returned as the access result, such as Figure 2 and Figure 3 As shown, the method specifically comprises the following steps: Step 1: Integrate the Software Development Kit (SDK) in the business system of the power system. The SDK is loaded when the business system is started, registers the Application Programming Interface (API) as a data interception and processing module, and initializes the SDK. The SDK has an intelligent parsing function, can identify the business interface and its corresponding field information, and report its parsing results to the desensitizing server.

[0022] Step 2: According to the data security requirements of the power system, select the interface to be desensitized and its corresponding fields, such as the account name, account number, home address, contact information and other fields in the user personal information interface; Desensitization rules are set for the interface to be desensitized and its corresponding fields to obtain the set desensitization rules, using a partial mask strategy or other feasible strategies.

[0023] This embodiment implements a configuration mechanism on the desensitizing service end, which is used to accurately configure the interface fields that need to be desensitized in the business system, so as to clarify which data fields should be desensitized during the data desensitization process.

[0024] Step 3: The power system receives a query request from the client, such as querying a user's electricity usage; the business system executes the query operation and prepares to return the original data containing sensitive information.

[0025] The SDK uses the aspect-oriented programming (SpringAop) mechanism to perform real-time interception before the original data is returned, obtain the intercepted data, and ensure that the data is properly desensitized before being returned.

[0026] Step 4: Parse the intercepted data returned by the business interface, and use the Java reflection mechanism to obtain the type of the intercepted data and its corresponding field name; the type of the intercepted data includes at least data of a single object structure, data of a collection object structure, data of an array object structure, and data of a tree object structure.

[0027] The SDK obtains the paths of all interfaces of the power system through the request mapping processor (RequestMappingHandlerMapping). According to the path of the current interface of the power system, it uses the Java open source framework (Netty) for real-time communication or consumes messages in the message queue of the open source stream processing platform (Kafka). It sends a request to the desensitizing server and obtains the desensitizing rules corresponding to the intercepted data from the pre-set desensitizing rules to ensure the real-time and accuracy of the desensitizing rules. The desensitizing server retrieves the corresponding desensitizing rules based on the request and responds to the SDK with the results.

[0028] In this embodiment, the SDK and the desensitizing server support two efficient reporting modes: one is to use the Netty service for real-time communication, and send the parsed information to the desensitizing server through Http request; the other is to use the message queue for asynchronous communication, and store the parsed interface information in the Kafka message queue to achieve reliable data transmission.

[0029] Step 5: Desensitize the intercepted data according to the type of the intercepted data and the corresponding desensitization rules to obtain desensitized data to ensure data security, specifically: If the type of the intercepted data is data with a single object structure, check whether there is a corresponding data masking rule for each field in the data with the single object structure and whether each field supports data masking; for example, for field types such as Object and Integer, without considering the context semantics, their meanings are not clear by themselves, so there is no need to perform data masking, that is, they do not support data masking; If there is and supports data masking, perform data masking on each field to obtain masked data; Otherwise, further determine whether the field type is a complex type, and recursively execute until each field is a Java basic type or each field is a type that does not support data masking.

[0030] In a specific embodiment: For the household number, the original electricity meter number "123456XXX123456" becomes "************3456" after data masking; For the user name, the original user name "Zhang X" becomes "Zhang *" after data masking; For the contact information, the original contact information "138XXXX8000" becomes "1***********000" after data masking; For the home address, the original address "XX Province XX City XX District XX Street XX No." becomes "XX Province XX City XX District XX Street ****" after data masking.

[0031] If the type of the intercepted data is data with a non-single object structure, such as: data with a collection object structure, data with an array object structure, and data with a tree object structure, then perform data masking on each element in the data with the non-single object structure according to the data masking steps for the data with a single object structure to obtain masked data.

[0032] This embodiment can provide an intelligent matching function for the data of the fields in the interface, can automatically select applicable built-in data masking algorithms for different fields, and at the same time supports the business system to implement custom data masking algorithms according to specific requirements to enhance the flexibility and adaptability of the business system.

[0033] Step Six: The SDK reorganizes the masked data according to the hierarchical relationship of module, control class, interface, and field to obtain new original data with the same format and structure as the original data, and continues to return the new original data as the access result.

[0034] Step 7: SDK returns the new raw data to the client in its original format and structure; after receiving the new raw data, the client can perform normal operations such as electricity bill query and statistical analysis without accessing sensitive information of the original data. This ensures that the format and structure of the original data remain unchanged, thus not affecting the client's normal parsing and use of the data.

[0035] At the same time, the SDK communicates the new original data in real time through Netty or consumes messages in the Kafka message queue, and reports it to the desensitizing server. The desensitizing server stores the new original data in the database or caches it in the power system for persistent storage to facilitate subsequent data desensitization processing; the new original data includes at least the interface address, field name, and field attributes of the power system.

[0036] When this embodiment is applied, it is possible to achieve transparent desensitization of sensitive data without changing the original logic, and it is possible to ensure that the desensitization process does not leak sensitive information while maintaining data availability and consistency of business logic.

[0037] Example 2

[0038] This embodiment introduces a data parsing system for a power system, which executes business logic and returns original data as an access result based on a received data access request; the system includes: A data interception module, used for intercepting the original data in real time before returning the original data to obtain intercepted data; A desensitization rule acquisition module, used to acquire a desensitization rule corresponding to the intercepted data from a preset desensitization rule according to the acquired path of the current interface of the power system; A data desensitization module, used for identifying the type of the intercepted data, and desensitizing the intercepted data according to the type of the intercepted data and the corresponding desensitization rule to obtain desensitized data; The data reorganization module is used to reorganize the desensitized data to obtain new original data with the same format and structure as the original data, and return the new original data as the access result.

[0039] Example 3

[0040] A computer-readable storage medium having a computer program stored thereon, characterized in that the computer program implements the method described in Example 1 when executed by a processor.

[0041] Example 4

[0042] This embodiment introduces a computer device, including a processor and a storage medium; The storage medium is used to store instructions; The processor is used to operate according to the instructions to execute the method described in Example 1.

[0043] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.

[0044] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0045] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0046] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0047] The embodiments of the present invention are described above in conjunction with the accompanying drawings, but the present invention is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the enlightenment of the present invention, ordinary technicians in this field can also make many forms without departing from the scope of protection of the purpose of the present invention and the claims, which all fall within the protection of the present invention.

Claims

1. A data desensitization method for a power system, characterized in that: Based on the received data access request, executing business logic and returning original data as the access result; the method comprises: Before returning the original data, the original data is intercepted in real time to obtain intercepted data; According to the acquired path of the current interface of the power system, a desensitization rule corresponding to the intercepted data is acquired from the pre-set desensitization rules; Identify the type of the intercepted data, and perform data desensitization on the intercepted data according to the type of the intercepted data and a corresponding desensitization rule to obtain desensitized data; The desensitized data is reorganized to obtain new original data having the same format and structure as the original data, and the new original data is returned as the access result.

2. The data desensitization method for the power system according to claim 1, characterized in that: By utilizing the aspect-oriented programming mechanism, the original data is intercepted in real time before being returned to obtain intercepted data.

3. The data desensitization method for the power system according to claim 1, characterized in that: The path of the current interface of the power system is obtained by requesting the mapping processor.

4. The data desensitization method for the power system according to claim 1, characterized in that: According to the obtained path of the current interface of the power system, real-time communication is carried out through the Java open source framework or the messages in the message queue of the open source stream processing platform are consumed, and the desensitization rules corresponding to the intercepted data are obtained in the pre-set desensitization rules.

5. The data desensitization method for the power system according to claim 1, characterized in that: The desensitization rules include: According to the data security requirements of the power system, select the interface to be desensitized and its corresponding fields; By using a partial mask strategy, desensitization rules are set for the interface to be desensitized and its corresponding fields to obtain the set desensitization rules.

6. The data desensitization method for the power system according to claim 1, characterized in that: Use Java reflection mechanism to obtain the type of intercepted data and its corresponding field name; The types of intercepted data include at least data of a single object structure, data of a collection object structure, data of an array object structure and data of a tree object structure.

7. The data desensitization method for the power system according to claim 6, characterized in that: According to the type of the intercepted data and the corresponding desensitization rule, the intercepted data is desensitized to obtain desensitized data, including: If the intercepted data is of a single object structure, check whether each field in the single object structure has a corresponding desensitization rule and whether each field supports desensitization; if so, perform data desensitization on each field to obtain desensitized data; otherwise, execute recursively until each field is a Java basic type or each field is a type that does not support desensitization; If the type of the intercepted data is data of a non-single object structure, data desensitization is performed on each element in the data of a non-single object structure according to the data desensitization steps of a single object structure to obtain desensitized data.

8. The data desensitization method for the power system according to claim 1, characterized in that: The desensitized data is reorganized according to the hierarchical relationship of modules, control classes, interfaces, and fields to obtain new original data having the same format and structure as the original data, and the new original data is returned as the access result.

9. The data desensitization method for the power system according to claim 1, characterized in that: Also includes: storing the new raw data in a database or caching it in a power system; The new original data at least includes the interface address, field name, and field attribute of the power system.

10. A data desensitization system for a power system, characterized in that: Based on the received data access request, the business logic is executed and the original data is returned as the access result; the system comprises: A data interception module, used for intercepting the original data in real time before returning the original data to obtain intercepted data; A desensitization rule acquisition module is used to acquire a desensitization rule corresponding to the intercepted data from a preset desensitization rule according to the acquired path of the current interface of the power system; A data desensitization module, used for identifying the type of the intercepted data, and desensitizing the intercepted data according to the type of the intercepted data and the corresponding desensitization rule to obtain desensitized data; The data reorganization module is used to reorganize the desensitized data to obtain new original data with the same format and structure as the original data, and return the new original data as the access result.