Data desensitization method and device, equipment and storage medium
By scanning the entity class with desensitization annotations, determining and applying target desensitization rules, the problems of poor scalability of desensitization rules and complex configuration management in the prior art are solved, and efficient and flexible data desensitization processing is achieved.
Patent Information
- Application Number
- CN202510046018.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-10
- Publication Date
- 2025-05-13
AI Technical Summary
The existing dynamic data desensitization methods have problems such as poor scalability of desensitization rules and complex configuration management.
Data desensitization is achieved by scanning the entity class with desensitization annotations, determining the target desensitization rules, and processing the desensitization fields based on the target rules. The method also includes matching the desensitization field with a preset desensitization rule base, generating target desensitization rules, and configuring the desensitization rules through a visual interface.
It improves the flexibility of data desensitization and the scalability of desensitization rules, simplifies the configuration management of desensitization rules, and ensures the accuracy of data desensitization.
Smart Images

Figure CN119989401A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data processing technology, and in particular to a data desensitization method, device, equipment and storage medium. Background Art
[0002] With the development of the digital economy, data has become an important asset for enterprises. Data desensitization is the deformation of sensitive data, and its purpose is to protect the security of private data. Data desensitization technology is mainly divided into static data desensitization and dynamic data desensitization. Among them, dynamic data desensitization is performed during the use of data, that is, while reading or writing data, sensitive data is deformed or masked in real time according to preset rules and policies.
[0003] The existing dynamic data desensitization method adds an additional database proxy layer or application programming interface (API) result set through business code for processing. Each application interface or result set field needs to be manually desensitized. At the same time, desensitization rules are configured by reading the business code.
[0004] However, existing dynamic data desensitization methods have problems such as poor scalability of desensitization rules and complex configuration management. Summary of the invention
[0005] The present application provides a data desensitization method, device, equipment and storage medium to solve the technical problems of poor scalability of desensitization rules and complex configuration management.
[0006] In a first aspect, the present application provides a data desensitization method, comprising:
[0007] Scan the entity class with desensitizing annotations to obtain the fields with desensitizing annotations;
[0008] In response to the user's operation, determining a target desensitization rule;
[0009] Based on the target desensitization rule, the field with the desensitization annotation is desensitized to obtain a desensitization result.
[0010] In one or more embodiments, the method further comprises:
[0011] Match the field with the desensitization annotation with any desensitization rule in a pre-set desensitization rule library to obtain the matching degree corresponding to each desensitization rule;
[0012] The desensitization rule with the highest matching degree is determined as the target desensitization rule.
[0013] In one or more embodiments, before determining the target desensitization rule in response to the user's operation, the method further includes:
[0014] The name of the field with the desensitized annotation is displayed to the user through a visual interface.
[0015] In one or more embodiments, determining the target desensitization rule in response to the user's operation includes:
[0016] Receiving configuration information sent by the user, the configuration information including the total length of the character string, the position of the covered field substring, the number of covered field substrings, and the covered replacement character;
[0017] The target desensitization rule is generated based on the total length of the string, the position of the masked field substring, the number of the masked field substrings and the masked replacement characters.
[0018] In one or more embodiments, the method further comprises:
[0019] The pre-acquired original data is read, and the original data is annotated based on a preset annotation tool, wherein the annotation tool includes a class annotation tool and a field annotation tool.
[0020] In one or more embodiments, reading the pre-acquired raw data and annotating the raw data based on a preset annotation tool includes:
[0021] Annotating the entity class in the original data based on the class annotation tool;
[0022] Based on the field annotation tool, the fields of the annotated entity class are annotated.
[0023] In one or more embodiments, the annotation tool further includes a method annotation tool, and the method further includes:
[0024] Based on the aspect-oriented AOP annotation tool, annotate the entity objects corresponding to the annotated entity classes.
[0025] In a second aspect, the present application provides a data desensitization device, comprising:
[0026] The scanning module is used to scan the entity class with desensitizing annotations to obtain the fields with desensitizing annotations;
[0027] A determination module, used to determine a target desensitization rule in response to a user's operation;
[0028] The processing module is used to perform desensitization processing on the field with the desensitization annotation based on the target desensitization rule to obtain a desensitization result.
[0029] In one or more embodiments, the determining module is further configured to:
[0030] Match the field with the desensitization annotation with any desensitization rule in a pre-set desensitization rule library to obtain the matching degree corresponding to each desensitization rule;
[0031] The desensitization rule with the highest matching degree is determined as the target desensitization rule.
[0032] In one or more embodiments, before determining the target desensitization rule in response to the user's operation, the determination module is further configured to:
[0033] The name of the field with the desensitized annotation is displayed to the user through a visual interface.
[0034] In one or more embodiments, the determining module is specifically configured to:
[0035] Receiving configuration information sent by the user, the configuration information including the total length of the character string, the position of the covered field substring, the number of covered field substrings, and the covered replacement character;
[0036] The target desensitization rule is generated based on the total length of the string, the position of the masked field substring, the number of the masked field substrings, and the masked replacement characters. In one or more embodiments,
[0037] In one or more embodiments, the processing module is further configured to:
[0038] The pre-acquired original data is read, and the original data is annotated based on a preset annotation tool, wherein the annotation tool includes a class annotation tool and a field annotation tool.
[0039] In one or more embodiments, the pre-acquired original data is read, and the original data is annotated based on a preset annotation tool, and the processing module is specifically used to:
[0040] Annotating the entity class in the original data based on the class annotation tool;
[0041] Based on the field annotation tool, the fields of the annotated entity class are annotated.
[0042] In one or more embodiments, the annotation tool further includes a method annotation tool, and the processing module is further used to:
[0043] Based on the aspect-oriented AOP annotation tool, annotate the entity objects corresponding to the annotated entity classes.
[0044] In a third aspect, the present application provides an electronic device, including:
[0045] a processor, and a memory communicatively connected to the processor;
[0046] The memory stores computer-executable instructions;
[0047] The processor executes the computer-executable instructions stored in the memory to implement the method described in the first aspect and any one of the embodiments above.
[0048] In a fourth aspect, the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are executed by a processor, they are used to implement the method described in the first aspect and any one of the embodiments.
[0049] In a fifth aspect, the present application provides a computer program product, including a computer program, which, when executed by a processor, is used to implement the data desensitization method as described in the first aspect and various possible implementation methods of the first aspect.
[0050] The data desensitization method, device, equipment and storage medium provided by the present application, the method first scans the entity class with desensitization annotations to obtain the fields with desensitization annotations; then, in response to the user's operation, the target desensitization rules are determined; finally, based on the target desensitization rules, the fields with desensitization annotations are desensitized to obtain the desensitization results. In the above method, by scanning the entity class with desensitization annotations, according to the desensitization annotations, and then identifying all the fields with desensitization annotations, the fields to be desensitized can be efficiently and accurately identified; according to the user's input or needs, the desensitization rules can be flexibly selected, and the target desensitization rules corresponding to the user operation are determined, which improves the flexibility of data desensitization for different scenarios and diversified needs, and the scalability of the desensitization rules; based on the set target desensitization rules, the fields with desensitization annotations are desensitized according to the content of the desensitization rules, which can ensure the accuracy of data desensitization. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0052] Figure 1 Schematic diagram of the data desensitization method provided in the embodiment of the present application Figure 1 ;
[0053] Figure 2 Schematic diagram of the data desensitization method provided in the embodiment of the present application Figure 2 ;
[0054] Figure 3Schematic diagram of the data desensitization method provided in the embodiment of the present application Figure 3 ;
[0055] Figure 4 Schematic diagram of the data desensitization method provided in the embodiment of the present application Figure 4 ;
[0056] Figure 5 A schematic diagram of the structure of a data desensitization device provided in an embodiment of the present application;
[0057] Figure 6 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application.
[0058] The above drawings have shown clear embodiments of the present application, which will be described in more detail later. These drawings and text descriptions are not intended to limit the scope of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION
[0059] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the present application. Instead, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0060] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0061] First, the terms used in this application are explained:
[0062] Entity class: refers to the class used to model the information and related behaviors that must be stored. The instance of the entity class is the entity object, which is used to save and update the relevant information of some phenomena;
[0063] Annotation: refers to a special modifier that can be used in class, method, parameter, constructor and package declarations to explain and comment on these elements. Through the annotations marked in the code, the program can perform some annotation-based processing at compile time;
[0064] Reflection technology: refers to the ability to dynamically obtain type information, access object members (such as properties, methods, fields, etc.), and call object methods when the program is running;
[0065] Aspect Oriented Programming (AOP) technology: refers to a technology that achieves unified maintenance of program functions through pre-compilation and dynamic proxy during runtime. It aims to improve the modularity of code by separating cross-cutting concerns. Its core idea is to separate common behaviors across multiple modules, such as logging, transaction management, security checks, etc., from business logic code to improve the maintainability and reusability of the code;
[0066] Pointcut: refers to a specific point used to specify the application of aspect logic during program execution;
[0067] Aspect: A collection of advice and pointcuts. It defines where and how specific operations are performed. A aspect can contain multiple advices and can be applied to multiple pointcuts.
[0068] Secondly, the technical background technology involved in this application is described as follows:
[0069] With the development of the digital economy, data has become an important asset for enterprises. In their daily operations, enterprises need to process a large amount of data, including customer information, order information, etc. While these data create value for enterprises, they also bring data security issues. In order to meet data security challenges and protect data security, enterprises need to take necessary measures to ensure that data is effectively protected. Data desensitization is the deformation of sensitive data, and its purpose is to protect the security of private data.
[0070] Existing data desensitization technologies are mainly divided into two types: static data desensitization and dynamic data desensitization. Static data desensitization is to transform sensitive data before moving or copying the data to another environment. It is generally used in testing or data outbound scenarios, and its characteristic is that data needs to be processed in batches. Dynamic data desensitization performs desensitization processing during the use of data, that is, while reading or writing data, sensitive data is deformed or masked in real time according to preset rules and policies. Dynamic data desensitization is used in scenarios that directly connect to production data, and its characteristic is that data needs to be processed in real time.
[0071] The existing dynamic data desensitization method uses the business code to add an additional database proxy layer or application programming interface (API) result set for processing, which requires manual desensitization of each application interface or result set field, and desensitization rules are configured by reading the business code. However, the existing dynamic data desensitization method is somewhat business-invasive, and there are problems such as poor scalability of desensitization rules and complex configuration and management of desensitization rules.
[0072] The data desensitization method provided by the present application is intended to solve the above technical problems of the prior art. The inventive concept of the present application is as follows: users can customize annotations for data that needs to be desensitized according to the needs of different scenarios, and mark different desensitization processing methods for different types of classes or fields, so as to perform targeted data desensitization processing; at the same time, for fields with desensitization annotations, users can modify or update the desensitization rules through customized desensitization rules to improve the scalability of the desensitization rules; for different fields with desensitization annotations, the desensitization rules corresponding to each field can be configured through a visual interface to simplify the configuration management of the desensitization rules.
[0073] The technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems are described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0074] Figure 1 Schematic diagram of the data desensitization method provided in the embodiment of the present application Figure 1 .like Figure 1 As shown, the data desensitization method includes the following steps:
[0075] S110. Scan the entity class with the desensitizing annotation to obtain the field with the desensitizing annotation.
[0076] In this step, the entity class that needs to be desensitized has a desensitizing annotation, and the entity class with the desensitizing annotation contains the field that needs to be desensitized. The field that needs to be desensitized has a desensitizing annotation. The entity class with the desensitizing annotation is scanned according to the desensitizing annotation to obtain the field with the desensitizing annotation.
[0077] In one possible implementation, all class files are first scanned to obtain entity classes with desensitizing annotations. Reflection technology can then be used to scan entity classes with desensitizing annotations. All fields in the entity classes with desensitizing annotations are obtained, and it is checked whether the fields have desensitizing annotations. Then all fields with desensitizing annotations in the entity classes with desensitizing annotations are obtained and output, so that the fields with desensitizing annotations can be obtained.
[0078] For example, in the defined entity class user with desensitizing annotations, it contains the id (number) field, name (name) field, phone (number) field and age (age) field, among which the name field and the phone field have desensitizing annotations. First, scan the entity class user to obtain all the fields in the entity class user, namely the id field, name field, phone field and age field. For each field, check whether the field has a desensitizing annotation, and then output the name field and the phone field with the desensitizing annotation. The output result is the field name with the desensitizing annotation, namely name and phone.
[0079] S120. Determine a target desensitization rule in response to a user operation.
[0080] In this step, the user can customize the desensitization rules for the fields with desensitization annotations. According to the user's operation, the desensitization rules corresponding to the fields with desensitization annotations set by the user are determined, that is, the target desensitization rules.
[0081] In a possible implementation, the user's operation can be based on a visual interface, different desensitization rules are set for different fields with desensitization annotations, and the determined target desensitization rules can be desensitization rules pre-saved in a desensitization rule library.
[0082] Exemplarily, the user may set different desensitization rules for different data formats or data contents in the visualization interface, and the desensitization rule may include the name of the desensitization rule and the content of the desensitization rule.
[0083] For example, for a user's contact number, the name of the desensitization rule may be "contact number", and the content of the desensitization rule may be "display the first 3 and last 4 characters; the remaining characters are masked"; for a user's name, the name of the desensitization rule may be "user name", and the content of the desensitization rule may be "when the total length of the string is less than 4, display the first character; when the total length of the characters is equal to 4, display the first 2 characters; the remaining characters are masked"; for a user's address, the name of the desensitization rule may be "address", and the content of the desensitization rule may be "when the total length of the string is greater than 3 and less than 6, display the first 3 characters; when the total length of the string is greater than 6, display the first 6 characters; the remaining characters are masked".
[0084] S130. Based on the target desensitization rule, desensitize the field with the desensitization annotation to obtain a desensitization result.
[0085] In this step, the fields with desensitizing annotations are matched according to the content of the target desensitizing rules, and the fields with desensitizing annotations are specifically masked according to the content of the target desensitizing rules to obtain the masked fields, that is, the desensitizing results.
[0086] In one possible implementation, the desensitization processing can be based on the rule content of the target desensitization rule, using regular expressions to match the characters that need to be masked in the field, and based on the rule content, searching and matching the characters that need to be processed in the field with desensitization annotations corresponding to the rule content according to a specific pattern.
[0087] For example, if the contact number is specified to be 11 digits, for the user's contact number "12312312312", and the corresponding desensitization rule is "display the first 3 and last 4 characters; the remaining characters are masked", the user's contact number is matched by a regular expression. First, the first 3 digits of the contact number "123" are matched and captured, and then the middle 4 digits "1231" are matched for character masking. The masking process can be to use the desensitization symbol "*" to replace characters, and then the last 4 digits of the contact number "2312" are matched and captured. The final desensitization result is "123****2312".
[0088] In a possible implementation, before step S120, the data desensitization method further includes: displaying the name of the field with the desensitization annotation to the user through a visual interface.
[0089] For example, after obtaining the fields with desensitized annotations, the names of the fields can be determined based on the field information, and the names of the fields can be arranged and displayed in sequence on the visual interface in the order in which the fields with desensitized annotations are scanned. They can be intuitively displayed in the form of tables, lists, etc., and users can view the names of the fields with desensitized annotations on the visual interface.
[0090] The data desensitization method provided in the embodiment of the present application first scans the entity class with the desensitization annotation to obtain the field with the desensitization annotation; then, in response to the user's operation, the target desensitization rule is determined; finally, based on the target desensitization rule, the field with the desensitization annotation is desensitized to obtain the desensitization result. In this embodiment, by scanning the entity class with the desensitization annotation, according to the desensitization annotation, and then identifying all the fields with the desensitization annotation, the desensitized fields can be efficiently and accurately identified; according to the user's input or needs, the desensitization rules can be flexibly selected, and the target desensitization rules corresponding to the user operation are determined, which improves the flexibility of data desensitization for different scenarios and diversified needs, and the scalability of the desensitization rules; based on the set target desensitization rules, the fields with the desensitization annotation are desensitized according to the content of the desensitization rules, which can ensure the accuracy of data desensitization.
[0091] Based on the above embodiments, Figure 2 Schematic diagram of the data desensitization method provided in the embodiment of the present application Figure 2 .like Figure 2 As shown, the data desensitization method also includes the following steps:
[0092] S210. Match the field with the desensitization annotation with any desensitization rule in a pre-set desensitization rule library to obtain the matching degree corresponding to each desensitization rule.
[0093] In this step, the name and content of the field are obtained based on the field with the desensitizing annotation. Based on the name and content of the field, they are matched with the name and content of the desensitizing rules in the pre-set desensitizing rule library. According to the degree of matching, the matching degree between the field with the desensitizing annotation and each desensitizing rule in the desensitizing rule library is further obtained.
[0094] In a possible implementation, the desensitization rules are uniformly recorded in a pre-set desensitization rule library, which may include default desensitization rules and user-defined desensitization rules. The default desensitization rules and user-defined desensitization rules are standardized to obtain desensitization rules with a unified format, which may include the name of the desensitization rule and the content of the desensitization rule.
[0095] In one possible implementation, a field with a desensitizing annotation is matched with any desensitizing rule in a pre-set desensitizing rule library. The name of the field with the desensitizing annotation is matched with the name of any desensitizing rule in the desensitizing rule library to calculate the name matching score; then, based on a regular expression, the content of the field with the desensitizing annotation is matched with the content of any desensitizing rule in the desensitizing rule library to obtain the content matching score; the name matching score and the content matching score are averaged to obtain the final matching score, which is the matching degree corresponding to each desensitizing rule.
[0096] For example, the name of the field with the desensitization annotation is "number", and the content is "45678987654" (a total of 11 digits). In the desensitization rule library, the name of desensitization rule 1 is "contact number", and the content is "display the first 3 digits of the 11-digit number", and the name of desensitization rule 2 is "identification number", and the content is "display the first 2 digits and the last 2 digits of the 8-digit number". If the field with the desensitization annotation is matched with desensitization rule 1 and desensitization rule 2 respectively, the matching scores of the field with the desensitization annotation and the names of desensitization rule 1 and desensitization rule 2 are the same; the matching scores of the field with the desensitization annotation and the content of desensitization rule 1 are higher than the matching scores of the content of desensitization rule 2. Finally, according to the matching scores of the names and the contents, matching scores A and B are obtained, which are the matching scores corresponding to desensitization rule 1 and desensitization rule 2.
[0097] S220: Determine the desensitization rule with the highest matching degree as the target desensitization rule.
[0098] In this step, the matching degree of each desensitization rule is compared to obtain the desensitization rule with the highest matching degree. For fields with desensitization annotations, the desensitization rule with the highest matching degree can achieve accurate desensitization processing of the fields. The desensitization rule with the highest matching degree can be determined as the target desensitization rule for subsequent processing.
[0099] In a possible implementation, each desensitization rule may be sorted from high to low according to the matching degree of the desensitization rule, to obtain the desensitization rule with the highest matching degree, and then determine the target desensitization rule.
[0100] For example, based on the above example, the name of the field with the desensitization annotation is "Number", and the content is "45678987654" (11 digits in total). The matching score A of desensitization rule 1 is greater than the matching score B of desensitization rule 2, that is, the matching degree corresponding to desensitization rule 1 is higher than the matching degree corresponding to desensitization rule 2. Desensitization rule 1 is used as the target desensitization rule for the field with the desensitization annotation.
[0101] The data desensitization method provided in the embodiment of the present application first matches the field with the desensitization annotation with any desensitization rule in the pre-set desensitization rule library to obtain the matching degree corresponding to each desensitization rule; then the desensitization rule with the highest matching degree is determined as the target desensitization rule. In this embodiment, by pre-setting the desensitization rule library, the desensitization rules are uniformly managed, and the desensitization rule library can be expanded and updated according to user needs, thereby improving the flexibility of data desensitization rule configuration; by calculating the matching degree of each desensitization rule with the field with the desensitization annotation, the most suitable desensitization rule is determined according to the matching degree, which can ensure that the selected desensitization rule is in line with the content and format of the field with the desensitization annotation to the greatest extent, thereby improving the efficiency of data desensitization.
[0102] Based on the above embodiments, Figure 3 Schematic diagram of the data desensitization method provided in the embodiment of the present application Figure 3 .like Figure 3 As shown, a possible implementation of the above step S120 also includes the following steps:
[0103] S310, receiving configuration information sent by a user;
[0104] The configuration information includes the total length of the string, the position of the masked field substring, the number of the masked field substrings, and the masked replacement characters.
[0105] In this step, the user sends the configuration information for the characters and corresponding fields, including the total length of the character string, the position of the covered field substring, the number of covered field substrings and the covered replacement character information, and the configuration information sent by the user is received.
[0106] In a possible implementation, the user can send corresponding configuration information according to the data content. The total length information content of the string can be the total length of all characters of the string to be covered; the covered field substring position information content can be the starting position of the character substring of the specified field to be covered; the covered field substring number information content can be the number of characters of the character substring to be covered in the specified field; the covered replacement character can be the character used for replacement.
[0107] For example, for the user's contact number, the total length of the string can be set to 11 characters, the masked field substring position can be masked starting from position 3, the number of masked field substrings is 4 characters, and the masked replacement character information is "*" masking; for the user's name, the total length of the string can be set to 3 characters, the masked field substring position can be masked starting from position 2, the number of masked field substrings is 2 characters, and the masked replacement character information is "-" masking.
[0108] For example, for the user's contact number "12345678991", masking starts from position 3, that is, character "4" is masked, and the number of masked field substrings is 4 characters, that is, characters "4567" are masked and replaced with "****".
[0109] S320. Generate a target desensitization rule based on the total length of the string, the position of the masked field substring, the number of the masked field substrings, and the masked replacement characters.
[0110] In this step, the total length of the string, the position of the masked field substring, the number of masked field substrings, and the masked replacement characters in the configuration information are combined to generate the target desensitization rule.
[0111] In one possible implementation, the user can customize the total length of the string, the position of the masked field substring, the number of masked field substrings, and the masked replacement characters in the configuration information in the visual interface according to different data masking requirements, and then generate customized target masking rules.
[0112] For example, for string data, the configuration information sent by the user is that the total length of the string is 10, the masked field substring position information is to mask starting from position 3, the number of masked field substrings is to mask 4 characters, the masked replacement character information is the character "-" mask or "*" mask, etc., then the generated target desensitization rule can be "For a string with a total length of 10, display the first 3 and last 3 characters."
[0113] The data desensitization method provided in the embodiment of the present application first receives the configuration information sent by the user, wherein the configuration information includes the total length of the string, the position of the substring of the covered field, the number of the substring of the covered field, and the character of the covered replacement; then based on the total length of the string, the position of the substring of the covered field, the number of the substring of the covered field, and the character of the covered replacement, the target desensitization rule is generated. In this embodiment, by receiving the configuration information such as the total length of the string sent by the user, the position of the substring of the covered field, the number of the substring of the covered field, and the character of the covered replacement, the rules of data desensitization can be dynamically adjusted according to the input of each user or the different needs of the same user for data desensitization, and different inputs can have different desensitization rules, which enhances the flexibility of data desensitization. The details of the desensitization rules can be determined by the configuration content sent by the user, and the user can adjust the desensitization rules in real time by modifying the configuration content sent, which simplifies the complexity of the desensitization rule configuration management in data desensitization, and can effectively improve the efficiency of data desensitization processing.
[0114] Based on the above embodiment, the data desensitization method further includes:
[0115] Step 1: Read the pre-acquired original data and annotate the original data based on a preset annotation tool;
[0116] Among them, annotation tools include class annotation tools and field annotation tools.
[0117] In this step, annotation tools including a class annotation tool and a field annotation tool are pre-set, and after reading the classes and fields in the pre-acquired original data, the preset annotation tools are used to annotate the classes and fields in the original data respectively for subsequent processing.
[0118] In one possible implementation, Figure 4 Schematic diagram of the data desensitization method provided in the embodiment of the present application Figure 4 .like Figure 4 As shown, a possible implementation of the above step 1 may include:
[0119] S410. Annotate the entity class in the original data based on the class annotation tool.
[0120] In this step, for the entity classes contained in the original data, based on the class annotation tool, the entity classes that need to be desensitized are annotated to obtain entity classes with desensitized annotations.
[0121] In a possible implementation, the original data includes multiple entity classes, and a desensitizing annotation is performed on at least one entity class among the multiple entity classes, indicating that data in the entity class needs to be desensitized.
[0122] For example, the original data includes entity classes such as user, customer, and order. Desensitization annotations can be made for the entity classes user and customer, indicating that the data in the entity classes user and customer need to be desensitized.
[0123] S420. Based on the field annotation tool, annotate the fields of the annotated entity class.
[0124] In this step, for the fields of the annotated entity class, based on the field annotation tool, the fields that need to be desensitized are annotated to obtain fields with desensitized annotations for subsequent processing.
[0125] In one possible implementation, the field annotation tool annotates at the field level to specify which fields need to be desensitized or encrypted. The field annotation tool contains default desensitization rules corresponding to commonly used fields, and can also perform extensible custom desensitization annotations, and users can dynamically add custom annotations.
[0126] For example, users can use custom annotations to mark fields that need to be desensitized. First, use keywords to define a custom annotation. The custom annotation can include the name of the annotation, the parameters of the annotation, and the parameter type of the annotation. For example, the custom annotation name is "MyAnnotation" and contains two parameters: parameter value(), type is "string", and the default value is "default value"; parameter count(), type is "int", and the default value is 1.
[0127] In a possible implementation, the annotation tool further includes a method annotation tool, and the data desensitization method further includes:
[0128] Based on the aspect-oriented AOP annotation tool, annotate the entity objects corresponding to the annotated entity classes.
[0129] In a possible implementation, the aspect-oriented AOP annotation tool annotates methods in entity classes based on AOP technology.
[0130] For example, based on the aspect-oriented AOP annotation tool, annotate the method in the annotated entity class to indicate that the method needs to be desensitized. By pre-defining and setting a section, all fields with desensitized annotations are intercepted from the cut point corresponding to the section before the method is executed or when the return result is called after the method is executed.
[0131] The data desensitization method provided in the embodiment of the present application reads the original data acquired in advance, and annotates the original data based on a preset annotation tool; wherein the annotation tool includes a class annotation tool and a field annotation tool. In this embodiment, the classes and fields in the original data are flexibly annotated by the preset annotation tool, so that the subsequent automatic processing of the original data can be realized; through the combination of class annotation and field annotation, different processing logics can be specified for different classes and fields, so that in the subsequent data desensitization processing, different classes and fields can be processed accordingly according to the annotations.
[0132] Based on the above embodiments, the following are device embodiments involved in this application:
[0133] Figure 5 This is a schematic diagram of the structure of the data desensitization device provided in the embodiment of the present application. Figure 5 As shown, the data desensitization device 500 includes:
[0134] The scanning module 510 is used to scan the entity class with the desensitizing annotation to obtain the field with the desensitizing annotation;
[0135] A determination module 520, configured to determine a target desensitization rule in response to a user operation;
[0136] The processing module 530 is used to perform desensitization processing on the fields with desensitization annotations based on the target desensitization rules to obtain desensitization results.
[0137] In an optional embodiment, the determination module 520 is further configured to:
[0138] Match the field with the desensitization annotation with any desensitization rule in the pre-set desensitization rule library to obtain the matching degree corresponding to each desensitization rule;
[0139] The desensitization rule with the highest matching degree is determined as the target desensitization rule.
[0140] In an optional embodiment, before determining the target desensitization rule in response to the user's operation, the determination module 520 is further used to:
[0141] The names of fields with desensitized annotations are displayed to users through a visual interface.
[0142] In an optional embodiment, the determination module 520 is specifically configured to:
[0143] Receive configuration information sent by the user, the configuration information including the total length of the string, the position of the masked field substring, the number of the masked field substrings, and the masked replacement character;
[0144] Generate target desensitization rules based on the total length of the string, the position of the masked field substring, the number of masked field substrings, and the masked replacement characters.
[0145] In an optional embodiment, the processing module 530 is further configured to:
[0146] The pre-acquired original data is read and annotated based on a preset annotation tool. The annotation tool includes a class annotation tool and a field annotation tool.
[0147] In an optional embodiment, the pre-acquired original data is read, and the original data is annotated based on a preset annotation tool. The processing module 530 is specifically used to:
[0148] Annotate the entity classes in the original data based on the class annotation tool;
[0149] Based on the field annotation tool, annotate the fields of the annotated entity class.
[0150] In an optional embodiment, the annotation tool further includes a method annotation tool, and the processing module 530 is further used to:
[0151] Based on the aspect-oriented AOP annotation tool, annotate the entity objects corresponding to the annotated entity classes.
[0152] Based on the above embodiments, Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Figure 6 As shown, the electronic device 600 includes: a processor 610, a memory 620 and a bus 630;
[0153] The memory 620 is used to store computer-executable instructions of the processor 610;
[0154] The processor 610 is configured to execute the technical solution of any of the aforementioned method embodiments by executing computer execution instructions.
[0155] Optionally, the memory 620 may be independent or integrated with the processor 610 .
[0156] Optionally, the memory 620 may include a random access memory (Random Access Memory, RAM), and may also include a non-volatile memory (Non-volatile Memory, NVM), such as at least one disk memory.
[0157] The bus 630 may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in the drawings of the present application, but it does not mean that there is only one bus or one type of bus.
[0158] The above-mentioned processor can be a general-purpose processor, including a central processing unit CPU, a network processor (NP), etc.; it can also be a digital signal processor DSP, an application-specific integrated circuit ASIC, a field programmable gate array FPGA or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0159] The electronic device is used to execute the technical solution of any of the aforementioned method embodiments, and its implementation principle and technical effect are similar and will not be repeated here.
[0160] An embodiment of the present application also provides a computer-readable storage medium on which computer execution instructions are stored. When the computer execution instructions are executed by a processor, they are used to implement the technical solution provided by any of the above method embodiments.
[0161] An embodiment of the present application also provides a computer program product, including a computer program, which includes computer instructions stored in a computer-readable storage medium. When the computer program is executed by a processor, it is used to implement the technical solution provided by any of the above method embodiments.
[0162] It should be noted that, for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the present application is not limited by the described order of actions, because according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily required by the present application.
[0163] It should be further noted that, although the various steps in the flowchart are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps is not strictly limited in order, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowchart may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these sub-steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.
[0164] It should be understood that the above-mentioned device embodiments are only illustrative, and the device of the present application can also be implemented in other ways. For example, the division of units / modules in the above-mentioned embodiments is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units, modules or components can be combined, or can be integrated into another system, or some features can be ignored or not executed.
[0165] In addition, unless otherwise specified, each functional unit / module in each embodiment of the present application may be integrated into one unit / module, each unit / module may exist physically separately, or two or more units / modules may be integrated together. The above-mentioned integrated unit / module may be implemented in the form of hardware or in the form of a software program module.
[0166] If the integrated unit / module is implemented in the form of hardware, the hardware may be a digital circuit, an analog circuit, etc. The physical implementation of the hardware structure includes but is not limited to transistors, memristors, etc. Unless otherwise specified, the processor may be any appropriate hardware processor, such as a CPU, a GPU, an FPGA, a DSP, an ASIC, etc. Unless otherwise specified, the storage unit may be any appropriate magnetic storage medium or magneto-optical storage medium, such as a resistive random access memory (RRAM), a dynamic random access memory (DRAM), a static random access memory (SRAM), an enhanced dynamic random access memory (EDRAM), a high-bandwidth memory (HBM), a hybrid memory cube (HMC), etc.
[0167] If the integrated unit / module is implemented in the form of a software program module and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a memory, including a number of instructions to enable a computer device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned memory includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, disk or optical disk and other media that can store program codes.
[0168] In the above embodiments, the description of each embodiment has its own emphasis. For parts not described in detail in a certain embodiment, please refer to the relevant description of other embodiments. The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, all possible combinations of the technical features in the above embodiments are not described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0169] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the invention disclosed herein. The present application is intended to cover any modification, use or adaptation of the present application, which follows the general principles of the present application and includes common knowledge or customary techniques in the art that are not disclosed in the present application. The specification and examples are intended to be exemplary only, and the true scope and spirit of the present application are indicated by the following claims.
[0170] It should be understood that the present application is not limited to the precise structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.
Claims
1. A data desensitization method, characterized in that: include: Scan the entity class with desensitizing annotations to obtain the fields with desensitizing annotations; In response to the user's operation, determining a target desensitization rule; Based on the target desensitization rule, the field with the desensitization annotation is desensitized to obtain a desensitization result.
2. The method according to claim 1, characterized in that The method further comprises: Match the field with the desensitization annotation with any desensitization rule in a pre-set desensitization rule library to obtain the matching degree corresponding to each desensitization rule; The desensitization rule with the highest matching degree is determined as the target desensitization rule.
3. The method according to claim 1, characterized in that Before determining the target desensitization rule in response to the user's operation, the method further includes: The name of the field with the desensitized annotation is displayed to the user through a visual interface.
4. The method according to claim 3, characterized in that The step of determining the target desensitization rule in response to the user's operation includes: Receiving configuration information sent by the user, the configuration information including the total length of the character string, the position of the covered field substring, the number of covered field substrings, and the covered replacement character; The target desensitization rule is generated based on the total length of the string, the position of the masked field substring, the number of the masked field substrings and the masked replacement characters.
5. The method according to any one of claims 1 to 4, characterized in that: The method further comprises: The pre-acquired original data is read, and the original data is annotated based on a preset annotation tool, wherein the annotation tool includes a class annotation tool and a field annotation tool.
6. The method according to claim 5, characterized in that The step of reading the pre-acquired original data and annotating the original data based on a preset annotation tool includes: Annotating the entity class in the original data based on the class annotation tool; Based on the field annotation tool, the fields of the annotated entity class are annotated.
7. The method according to claim 6, characterized in that The annotation tool also includes a method annotation tool, and the method further includes: Based on the aspect-oriented AOP annotation tool, annotate the entity objects corresponding to the annotated entity classes.
8. A data desensitization device, characterized in that: include: The scanning module is used to scan the entity class with desensitizing annotations to obtain the fields with desensitizing annotations; A determination module, used to determine a target desensitization rule in response to a user's operation; The processing module is used to perform desensitization processing on the field with the desensitization annotation based on the target desensitization rule to obtain a desensitization result.
9. An electronic device, characterized in that: include: a processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 7 when executed by a processor.