Dynamic Data Encryption and De-identification Method for Data Security Gateway

By introducing verification devices and dynamic verification mechanisms into the database, we realize legality verification of visiting users and real-time monitoring of sensitive data, solving the problem that sensitive data access rights cannot be adjusted in real time in the existing technology, and improving data security and compliance.

CN119989413BActive Publication Date: 2025-07-08JING AN YUNXIN
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510089623.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-07-08
Estimated Expiration
2045-01-21

AI Technical Summary

Technical Problem

The prior art cannot realize real-time monitoring and adjustment of sensitive data in the database, resulting in insufficient security and compliance of sensitive data when accessing.

Method used

Verify the legitimacy of the visiting user through the verification device, generate temporary verification codes and interact with the database, obtain verification time and generate verification time distribution map, combine preset passwords and update keys for secondary verification, dynamically adjust access rights, and desensitize sensitive data.

Benefits of technology

Improve the security and control capabilities of data access, ensure that sensitive data is not leaked during transmission and storage, adapt to diverse security needs, and enhance identity verification and data protection for legitimate users.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989413B_ABST
    Figure CN119989413B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of data encryption, and particularly to a dynamic data encryption and desensitization method for a data security gateway. A validator is used to determine whether a visiting user is a legitimate user, and a temporary verification code is sent to the database. The database verifies the database access rights of the legitimate user, obtains the corresponding verification time and performs preprocessing, generates a verification time distribution map, and compares the map values with the verification time threshold. When the map values are less than the verification time threshold, secondary verification is performed on the legitimate user. When it is determined to open the database access rights for the legitimate user, sensitive data is desensitized and opened. Through dynamic encryption and desensitization processing, not only the security of data access is improved, but also the control ability of data protection is enhanced, ensuring that sensitive data is not leaked during transmission and storage to meet diverse security requirements.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data encryption, and in particular to a dynamic data encryption and desensitization method for a data security gateway. Background Art

[0002] With the frequent occurrence of data leakage incidents, enterprises' attention to data security has been increasing. Existing database security solutions often lack effective encryption and desensitization processing during data transmission, and cannot ensure the security of sensitive data when it is accessed. In addition, the user authorization and access control mechanisms in existing systems are often unable to be configured flexibly, resulting in an increasing risk of illegal access to sensitive data. Therefore, there is an urgent need for a new data security solution to ensure the security and compliance of sensitive data in the database.

[0003] Chinese Patent Authorization Publication No.: CN117763620B discloses a dynamic desensitization method for power big data based on a fully homomorphic encryption algorithm, including: obtaining a power transaction big data set, obtaining a data set to be concealed and a privacy-sensitive data set according to the power transaction big data set, obtaining a concealment protection enhancement coefficient according to the data sets to be concealed and the privacy-sensitive data sets of different power data samples in the power transaction big data set, constructing a perturbation neighbor matrix according to the concealment protection enhancement coefficient, calculating a data perturbation sensitivity coefficient according to the perturbation neighbor matrix, constructing a perturbation sensitivity management quad-tree according to the data perturbation sensitivity coefficient, calculating a noise sensitivity management coefficient based on the perturbation sensitivity management quad-tree, obtaining the power data noise sensitivity according to the noise sensitivity management coefficient, and obtaining the fully homomorphic encryption result of the power data based on the power data noise sensitivity. This application performs full-dynamic encryption on power data through the power data noise sensitivity, improving the quality of power data desensitization.

[0004] Chinese Patent Authorization Publication No.: CN113177223B discloses a highly secure data reversible desensitization algorithm based on a data attribute dynamic factor, including an S1 data desensitization stage, including the following steps: S11 calculating a basic factor based on a key input by a user and an algorithm selected; S12 reading a data source input by the user, selecting data to be desensitized, and converting it into a number of fields; S13 parsing the minimum character unit of the field and converting it into a number of characters; S14 obtaining an attribute group of the characters and calculating an attribute group combination based on the basic factor; S15 calculating a dynamic factor based on the attribute group combination and finally determining a desensitized character; S16 splicing the desensitized character with the already desensitized characters. This invention is applicable to the technical fields of data security, data security governance, data desensitization, and privacy protection, has a high security level, does not reduce the processing performance of desensitized data at the same time, and has higher practicability than encryption performance, thus providing a high-performance desensitization algorithm equivalent to the encryption security level for the secure sharing and reversible desensitization requirements of data.

[0005] However, the above method has the following problems: it is impossible to realize real-time monitoring and adjustment of sensitive data in the database. Summary of the invention

[0006] To this end, the present invention provides a dynamic data encryption and desensitization method for a data security gateway, so as to overcome the problem in the prior art that it is impossible to realize real-time monitoring and adjustment of sensitive data in a database.

[0007] To achieve the above object, the present invention provides a dynamic data encryption and desensitization method for a data security gateway, comprising:

[0008] When a visiting user accesses the verifier, the corresponding verification password of the visiting user is collected and checked with the preset password to determine whether the visiting user is a legitimate user. If the visiting user is a legitimate user, the verifier sends a temporary verification code to the database;

[0009] The database verifies the database access rights of the corresponding legitimate user according to the temporary verification code, obtains the corresponding verification time, pre-processes the verification time to form corresponding verification data, transfers the verification data to the auxiliary verification model, and generates a corresponding verification time distribution map;

[0010] Compare the graph value in the verification time distribution graph with the verification time threshold to obtain a corresponding comparison result, and determine whether to open the database access right to the legitimate user;

[0011] When the graph value in the verification time distribution graph is less than the verification time threshold, the database sends an update key to the verifier, and the verifier combines the preset password and the update key to generate a corresponding secondary password and sends it to the legal user, performs secondary verification on the legal user, and determines again whether to open the database access right to the legal user;

[0012] When it is determined that the database access permission is to be opened to the legitimate user, the sensitive data in the database is desensitized and opened to the legitimate user;

[0013] The preset password is pre-set by the network administrator and is related to the security requirements and usage scenarios of the data security gateway;

[0014] The temporary verification code is a combination of numbers randomly generated by the verifier and is used to authenticate the database access rights of the legitimate user;

[0015] The verification time is the time required for the legal user to obtain the database access permission;

[0016] The verification time threshold is the minimum value of the time to pass the database access permission, which is related to the security requirements of the data security gateway.

[0017] Further, the step of the validator sending a temporary verification code to the database includes:

[0018] When the visiting user accesses the validator, the validator collects the corresponding user name;

[0019] The validator queries the corresponding preset password according to the user name;

[0020] Compare the preset password with the verification password entered by the visiting user to determine whether the visiting user is a legitimate user.

[0021] Further, when the preset password is consistent with the verification password, it is determined that the visiting user is a legitimate user, and the validator sends the corresponding temporary verification code to the database. When the preset password is inconsistent with the verification password, the validator prompts the visiting user to enter the verification password again. When the preset password is inconsistent with the verification password again, it is determined that the visiting user is not a legitimate user, and the corresponding visiting user is marked as prohibited from accessing the database and the sensitive data is dynamically encrypted.

[0022] Further, the steps for preprocessing the verification time include:

[0023] Cut the verification time according to the standard learning rate to form a number of cut data;

[0024] Normalize the cut data to form the corresponding verification data, where

[0025] The standard learning rate is the learning rate that the auxiliary verification model can recognize, and for a single learning, its corresponding standard learning rate is a single learning rate;

[0026] The normalization process is to converge the cut data according to a preset range.

[0027] Further, the steps for generating a verification time distribution map include:

[0028] Preprocess the verification time to generate the corresponding verification data;

[0029] Generate a corresponding number of learning features according to the verification data;

[0030] The auxiliary verification model learns the verification data and generates the corresponding verification time distribution map;

[0031] Label the verification time distribution map according to the learning features;

[0032] Among them, the learning features include the length of verification time and / or the verification frequency of a single legitimate user;

[0033] The auxiliary verification model is generated by training a verification training set formed by verification data corresponding to the verification time.

[0034] Further, the steps of determining whether to open the database access permission to a legitimate user include:

[0035] Obtain each atlas value in the verification time distribution atlas;

[0036] Compare the atlas value with the verification time threshold, where

[0037] When the atlas value is greater than the verification time threshold, the database marks that the database access permission is open to the legitimate user;

[0038] When the atlas value is less than the verification time threshold, the database sends an update key to the verifier.

[0039] Further, the steps of generating a secondary password include:

[0040] The database obtains the built-in update key and sends it to the verifier;

[0041] The verifier combines the preset password and the update key to obtain a corresponding calculation result;

[0042] Intercept the calculation result, retain it to the preset length, and generate a corresponding secondary password to send to the legitimate user.

[0043] Further, the steps of determining again whether to open the database access permission to a legitimate user include:

[0044] Collect the secondary verification time when the legitimate user passes the secondary verification;

[0045] Preprocess the secondary verification time to generate corresponding secondary verification data;

[0046] According to the learning features, use the auxiliary verification model to learn the secondary verification data and generate a corresponding secondary verification time distribution atlas;

[0047] Use the verification time threshold to perform secondary screening on the legitimate user;

[0048] Among them, when the legitimate user fails the secondary verification, the corresponding legitimate user is filtered.

[0049] Further, the steps of using the verification time threshold to perform secondary screening on legal users include:

[0050] Obtain each test value of the secondary verification time distribution map;

[0051] Compare the test value with the verification time threshold, where

[0052] When the test value is greater than the verification time threshold, the database marks that the database access permission is open to the legal user;

[0053] When the test value is less than the verification time threshold, mark the corresponding legal user as prohibited from accessing the database and dynamically encrypt the sensitive data.

[0054] Further, when it is determined to open the database access permission to the legal user, the database performs dynamic desensitization on the sensitive data, forms corresponding desensitized data, and opens it to the legal user.

[0055] Compared with the prior art, the present invention determines whether the visiting user is a legal user through a validator, and sends a temporary verification code to the database. The database verifies the database access permission of the legal user, obtains the corresponding verification time and performs preprocessing, generates a verification time distribution map, and compares the map value with the verification time threshold. When the map value is less than the verification time threshold, secondary verification is performed on the legal user. When it is determined to open the database access permission to the legal user, desensitization processing is performed on the sensitive data and opened. Through dynamic encryption and desensitization processing, not only the security of data access is improved, but also the control ability of data protection is enhanced, ensuring that sensitive data is not leaked during transmission and storage to meet diverse security requirements.

[0056] Further, the validator uses the username and password to verify the identity of the visiting user and decides whether to send a temporary verification code to the database, which reflects the importance of verifying the identity of the visiting user and provides strict access control for the entire data security gateway process. It not only enhances security but also lays a foundation for subsequent dynamic verification and data protection.

[0057] Further, by comparing the preset password and the verification password, legal users are screened and illegal users are filtered, effectively distinguishing legal users from illegal users, restricting and protecting data for illegal users. It not only enhances security but also provides a reliable guarantee for data protection, preventing illegal access and data tampering, and effectively preventing malicious attacks.

[0058] Furthermore, by cutting and normalizing the verification time data, it can be effectively recognized and processed by the auxiliary verification model. This preprocessing method not only improves the standardization degree of the verification time data, but also enhances the adaptability and compatibility of the auxiliary verification model, enabling the data security gateway to process the verification requests of legitimate users more efficiently, and further enhancing the security and reliability.

[0059] Furthermore, through the preprocessing, feature extraction, model learning, and atlas annotation of the verification time, a verification time distribution atlas is generated, which not only enhances the ability to analyze the behaviors of legitimate users, but also improves the efficiency of monitoring and decision-making through visualization tools, providing a dynamic, intelligent, and visual auxiliary verification mechanism for the data security gateway.

[0060] Furthermore, by comparing the verification time distribution atlas with the verification time threshold, the dynamic control of the access rights of legitimate users is realized. It can not only accurately identify the anomalies in the behaviors of legitimate users, but also dynamically adjust the access policy by updating the key, ensuring the flexibility and security of identification.

[0061] Furthermore, through the dynamic update of the key and the two-factor password mechanism, a method for enhancing identity verification is provided for the data security gateway. The generation process of the two-factor password combines the preset password and the dynamic key, ensuring the security and dynamics of the password.

[0062] Furthermore, through the collection, preprocessing, model learning, and threshold comparison of the two-factor verification time, the secondary screening and access rights control of legitimate users are realized, which not only enhances the security of the identity verification of legitimate users, but also further improves the overall security by dynamically encrypting sensitive data.

[0063] Furthermore, through the dynamic desensitization mechanism, after confirming the identity of legitimate users, sensitive data is processed in real time to generate desensitized data for users to access, which not only ensures the availability of the data, but also further enhances the security of the data and prevents the leakage of sensitive information. Description of the Drawings

[0064] Figure 1 It is a flowchart of the dynamic data encryption and desensitization method for the data security gateway according to the embodiment of the present invention;

[0065] Figure 2 It is a flowchart of the verifier sending a temporary verification code to the database according to the embodiment of the present invention;

[0066] Figure 3 It is a flowchart of generating a verification time distribution atlas according to the embodiment of the present invention;

[0067] Figure 4 It is a flowchart of generating a two-factor password according to the embodiment of the present invention. Detailed Implementation Manner

[0068] In order to make the objectives and advantages of the present invention more clearly understood, the present invention will be further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0069] The preferred implementation manners of the present invention will be described below with reference to the accompanying drawings. Those skilled in the art should understand that these implementation manners are only used to explain the technical principles of the present invention and do not limit the protection scope of the present invention.

[0070] It should be noted that in the description of the present invention, the terms indicating directions or positional relationships such as "upper", "lower", "left", "right", "inner", "outer", etc. are based on the directions or positional relationships shown in the drawings. This is only for convenience of description and does not indicate or imply that the device or element must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the present invention.

[0071] In addition, it should also be noted that in the description of the present invention, unless otherwise clearly specified and limited, the terms "installation", "connection", and "connection" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two elements. For those skilled in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0072] Please refer to Figure 1 As shown, it is a flowchart of the dynamic data encryption and desensitization method for a data security gateway according to an embodiment of the present invention, including:

[0073] Step S1, when a visiting user accesses the validator, collect the verification password of the corresponding visiting user and compare it with a preset password to determine whether the visiting user is a legitimate user. When the visiting user is a legitimate user, the validator sends a temporary verification code to the database;

[0074] Step S2, the database verifies the database access permission of the corresponding legitimate user according to the temporary verification code, obtains the corresponding verification time, preprocesses the verification time to form corresponding verification data, and passes the verification data into an auxiliary verification model to generate a corresponding verification time distribution map;

[0075] Step S3, compare the map values in the verification time distribution map with a verification time threshold to obtain a corresponding comparison result and determine whether to open the database access permission to the legitimate user;

[0076] Step S4, when the graph value in the verification time distribution graph is less than the verification time threshold, the database sends an update key to the verifier. The verifier combines the preset password and the update key to generate a corresponding secondary password and sends it to the legitimate user for secondary verification to determine again whether to grant the legitimate user access to the database.

[0077] Step S5, when it is determined to grant the legitimate user access to the database, desensitize the sensitive data in the database and grant access to the legitimate user.

[0078] Among them, the preset password is set in advance by the network administrator and is related to the security requirements and usage scenarios of the data security gateway.

[0079] The temporary verification code is a randomly generated digital combination by the verifier for authenticating the access rights of the legitimate user to the database.

[0080] The verification time is the time required for the legitimate user to obtain database access rights.

[0081] The verification time threshold is the minimum value of the time to obtain database access rights, which is related to the security requirements of the data security gateway.

[0082] In a specific implementation, the access rights of the visiting user are managed through the data security product configuration page, supporting fine-grained access control based on user roles. Only authorized users can access the database through the gateway.

[0083] The verifier determines whether the visiting user is a legitimate user and sends a temporary verification code to the database. The database verifies the database access rights of the legitimate user, obtains the corresponding verification time and performs preprocessing, generates a verification time distribution graph, compares the graph value with the verification time threshold. When the graph value is less than the verification time threshold, secondary verification is performed on the legitimate user. When it is determined to grant the legitimate user access to the database, the sensitive data is desensitized and opened. Through dynamic encryption and desensitization processing, not only the security of data access is improved, but also the control ability of data protection is enhanced, ensuring that sensitive data is not leaked during transmission and storage to meet diverse security requirements.

[0084] Please refer to Figure 2 as shown, which is the flowchart of the verifier sending a temporary verification code to the database in the embodiment, including:

[0085] Step S11, when the visiting user accesses the verifier, the verifier collects the corresponding user name.

[0086] Step S12, the verifier queries the corresponding preset password according to the user name.

[0087] Step S13: Compare the preset password with the verification password entered by the visiting user to determine whether the visiting user is a legitimate user.

[0088] In specific implementation, the user name is unique to ensure that the corresponding preset password can be accurately queried. The validator needs to verify the user name entered by the user to prevent illegal characters or injection attacks. The storage of the preset password needs to adopt a secure method, such as encrypted storage, to prevent the leakage of the preset password. The query process needs to be efficient and secure to avoid the tampering or stealing of the preset password due to query vulnerabilities. The comparison between the preset password and the verification password entered by the visiting user needs to adopt a secure algorithm to avoid the risks brought by plaintext comparison. This process is the basis of the entire security verification system and needs to balance user experience and system efficiency while ensuring security.

[0089] The validator uses the user name and password to verify the identity of the visiting user and decides whether to send a temporary verification code to the database, which reflects the importance of verifying the identity of the visiting user and provides strict access control for the entire data security gateway process. It not only enhances security but also lays a foundation for subsequent dynamic verification and data protection.

[0090] Specifically, when the preset password is consistent with the verification password, it is determined that the visiting user is a legitimate user, and the validator sends the corresponding temporary verification code to the database. When the preset password is inconsistent with the verification password, the validator prompts the visiting user to enter the verification password again. When the preset password is inconsistent with the verification password again, it is determined that the visiting user is not a legitimate user, and the corresponding visiting user is marked as prohibited from accessing the database and the sensitive data is dynamically encrypted.

[0091] In specific implementation, if the preset password is inconsistent with the verification password, the system will prompt the visiting user to re-enter the verification password. This fault tolerance mechanism is to prevent the visiting user from entering incorrectly.

[0092] Handling after the second verification fails:

[0093] Mark as prohibited from accessing: If the user enters the wrong password again, the system marks the user as an illegal user and prohibits it from accessing the database.

[0094] By comparing the preset password and the verification password, legitimate users are screened and illegal users are filtered, effectively distinguishing between legitimate users and illegal users, restricting illegal users and protecting data. It not only enhances security but also provides a reliable guarantee for data protection, preventing illegal access and data tampering, and effectively preventing malicious attacks.

[0095] Specifically, the steps for preprocessing the verification time include:

[0096] Cut the verification time at the standard learning rate to form several pieces of cut data;

[0097] Perform normalization processing on the cut data to form corresponding verification data, where

[0098] the standard learning rate is the learning rate that the auxiliary verification model can recognize, and for a single learning, its corresponding standard learning rate is a single learning rate;

[0099] Normalization processing is to converge the cut data within a preset range.

[0100] Preferably, setting the standard sampling rate to 7000 per second has a better learning effect on the verification data, and for the method described in this application, its corresponding analysis effect is optimal.

[0101] In specific implementation, cutting the verification time at the standard learning rate means cutting the verification time at a certain interval (or frequency) according to the standard learning rate to form several sub-data segments, that is, the cut data, which helps to reduce the complexity of the data while retaining key information. A single learning corresponding to a single learning rate ensures that a fixed learning rate is used for each cutting operation, which can ensure the consistency of the verification data.

[0102] Normalization processing means scaling the cut verification time within a preset range to make it converge within the preset range. Preferably, the preset range is [0, 1] or [-1, 1].

[0103] Normalization processing can eliminate the dimensional difference and numerical range difference between different verification data, improve the convergence speed of the auxiliary verification model, enhance the generalization ability of the auxiliary verification model, and reduce the abnormal fluctuation of the verification data, making it easier for the auxiliary verification model to learn and identify data features.

[0104] By cutting and normalizing the verification time data, it can be effectively recognized and processed by the auxiliary verification model. Through this preprocessing method, not only the standardization degree of the verification time data is improved, but also the adaptability and compatibility of the auxiliary verification model are enhanced, enabling the data security gateway to process the verification requests of visiting users more efficiently, and further improving the security and reliability.

[0105] Please refer to Figure 3 as shown, which is the flowchart for generating the verification time distribution map in the embodiment of the present invention, including:

[0106] Step St1, preprocess the verification time to generate corresponding verification data;

[0107] Step St2, generate corresponding several learning features according to the verification data;

[0108] Step St3, the auxiliary verification model learns from the verification data and generates a corresponding verification time distribution map;

[0109] Step St4, label the verification time distribution map according to the learning features;

[0110] Among them, the learning features include the length of the verification time and / or the verification frequency of a single legitimate user;

[0111] The auxiliary verification model is generated by training a verification training set formed by verification data corresponding to the verification time.

[0112] In a specific implementation, several learning features are generated from the verification data, including the length of the verification time and / or the verification frequency of a single legitimate user, which is convenient for extracting information from the verification data and used for the learning and analysis of the auxiliary verification model. These features can reflect the regularity of user behavior. The length of the verification time can reflect the frequency of user operations, and the verification frequency can reflect the activity of user behavior.

[0113] Labeling the verification time distribution map according to the learning features is to enhance the readability and practicability of the verification time distribution map. Through labeling, the regions or behavior patterns corresponding to different features can be more clearly displayed.

[0114] By preprocessing the verification time, feature extraction, model learning, and map labeling, a verification time distribution map is generated, which not only enhances the ability to analyze the behavior of legitimate users, but also improves the efficiency of monitoring and decision-making through visualization tools, providing a dynamic, intelligent, and visual auxiliary verification mechanism for the data security gateway.

[0115] Specifically, the steps to determine whether to open the database access permission to legitimate users include:

[0116] Obtain each map value in the verification time distribution map;

[0117] Compare the map value with the verification time threshold, where,

[0118] When the map value is greater than the verification time threshold, the database marks that the database access permission is open to legitimate users;

[0119] When the map value is less than the verification time threshold, the database sends an updated key to the verifier.

[0120] In a specific implementation, the verification time threshold is a preset reference value used to determine whether a user's behavior conforms to the characteristics of a legitimate user. If the graph value is greater than the verification time threshold, it indicates that the user's behavior is as expected. If the graph value is less than the verification time threshold, it indicates that the user's behavior is abnormal, and the user may be an illegal user or further verification is required. The verification mechanism based on time distribution can effectively identify abnormal behaviors. For example, it can prevent brute force cracking or attacks.

[0121] The verification time threshold is dynamically adjusted according to the system operation conditions. For example, it is adjusted according to changes in user behavior patterns or attack frequencies.

[0122] The process of updating the key needs to ensure security. In a specific implementation, the system prevents key leakage through methods such as encrypted communication and multi-factor authentication.

[0123] By comparing the verification time distribution graph with the verification time threshold, dynamic control of the access rights of legitimate users is achieved. It can not only accurately identify abnormalities in the behaviors of legitimate users, but also dynamically adjust the access policy by updating the key, ensuring the flexibility and security of identification.

[0124] Please refer to Figure 4 as shown, which is the flowchart for generating a secondary password in an embodiment of the present invention, including:

[0125] Step Sp1, the database obtains the built-in updated key and sends it to the verifier;

[0126] Step Sp2, the verifier combines the preset password and the updated key to obtain the corresponding calculation result;

[0127] Step Sp3, intercept the calculation result, retain it to the preset length, and generate the corresponding secondary password to send to the legitimate user.

[0128] In a specific implementation, the updated key is dynamically generated for subsequent secondary password calculations. The updated key in each verification process may be different, which makes the secondary password dynamic and difficult to predict or crack. The verifier combines the preset password with the updated key and calculates a calculation result through a hash function or encryption algorithm. The calculation result is intercepted to the preset length to generate the secondary password and send it to the legitimate user. The secondary password combines the preset password and the dynamic key, increasing the complexity and security of the secondary password. Even if the preset password is leaked, the attacker cannot directly utilize it because the dynamic key is also required. By intercepting the calculation result to the preset length, the standardization and consistency of the secondary password can be ensured, while reducing unnecessary information exposure.

[0129] By means of dynamic key update and two-factor authentication mechanism, a method for enhancing authentication is provided for the data security gateway. The generation process of the two-factor authentication combines a preset password and a dynamic key, ensuring the security and dynamics of the password.

[0130] Specifically, the steps of re-determining whether to open database access permissions to legitimate users include:

[0131] Collect the two-factor authentication time when legitimate users pass the two-factor authentication;

[0132] Preprocess the two-factor authentication time to generate corresponding two-factor authentication data;

[0133] According to the learning features, use the auxiliary verification model to learn the two-factor authentication data and generate the corresponding two-factor verification time distribution map;

[0134] Use the verification time threshold to perform a secondary screening of legitimate users;

[0135] Among them, when legitimate users fail the two-factor authentication, the corresponding legitimate users are filtered.

[0136] Specifically, the steps of using the verification time threshold to perform a secondary screening of legitimate users include:

[0137] Obtain each test value of the two-factor verification time distribution map;

[0138] Compare the test value with the verification time threshold, where

[0139] When the test value is greater than the verification time threshold, the database marks that the database access permission is open to legitimate users;

[0140] When the test value is less than the verification time threshold, mark the corresponding legitimate users as prohibited from accessing the database and dynamically encrypt the sensitive data.

[0141] In a specific implementation, the two-factor authentication time refers to the specific time when legitimate users complete the two-factor authentication. Through the two-factor authentication mechanism, the complexity of legitimate user authentication is increased, and the possibility of illegal users passing the two-factor authentication is reduced. Further screening legitimate users through time features enhances the accuracy of legitimate user identity confirmation. For legitimate users who fail the two-factor authentication, dynamic encryption of sensitive data is performed, reducing the risk of sensitive data leakage.

[0142] Through the collection, preprocessing, model learning, and threshold comparison of the two-factor authentication time, the secondary screening and access permission control of legitimate users are realized, which not only enhances the security of legitimate user authentication but also further improves the overall security by dynamically encrypting sensitive data.

[0143] Specifically, when determining to open database access permissions to legitimate users, the database dynamically desensitizes sensitive data and makes the corresponding desensitized data available to legitimate users.

[0144] In specific implementation, the main goal of dynamic desensitization technology is to meet the access needs of legitimate users while ensuring data security. Administrators can configure dynamic policies through the data security product page, and these policies define how to process sensitive data. The main contents include the following:

[0145] (1)Selection and processing rules of data fields:

[0146] Determine which fields contain sensitive data (such as ID card numbers, bank card numbers, user passwords, etc.).

[0147] Define the processing rules for these fields, such as partial hiding, replacement, or formatting.

[0148] (2)Configuration of encryption algorithms and desensitization methods:

[0149] Select a suitable encryption algorithm (such as AES, RSA, etc.) to encrypt sensitive data.

[0150] Define desensitization methods, for example: Partial desensitization: Display part of the data and hide the rest (such as showing the first 6 digits and the last 4 digits of the ID card number). Formatting desensitization: Replace the data with virtual data that conforms to the format. Random desensitization: Randomize the data while retaining the data type and format.

[0151] (3)Dynamic scenario configuration:

[0152] Dynamically adjust the desensitization policy according to conditions such as access time, IP address, user role, etc.

[0153] For example, allow internal IP addresses to access more detailed data, while external IP addresses can only access desensitized data.

[0154] (4)Response data parsing and modification:

[0155] During data transmission, parse and modify the response data returned to the user to ensure that sensitive data is correctly desensitized.

[0156] Through the dynamic desensitization mechanism, after confirming the identity of legitimate users, sensitive data is processed in real time to generate desensitized data for users to access, which not only ensures the availability of data but also further enhances data security and prevents the leakage of sensitive information.

[0157] So far, the technical solution of the present invention has been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, those skilled in the art can easily understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present invention.

[0158] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent substitution, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A dynamic data encryption and desensitization method for a data security gateway, characterized in that include: When a visiting user accesses the verifier, the corresponding verification password of the visiting user is collected and checked with the preset password to determine whether the visiting user is a legitimate user. If the visiting user is a legitimate user, the verifier sends a temporary verification code to the database; The database verifies the database access rights of the corresponding legitimate user according to the temporary verification code, obtains the corresponding verification time, pre-processes the verification time to form corresponding verification data, transfers the verification data to the auxiliary verification model, and generates a corresponding verification time distribution map; Compare the graph value in the verification time distribution graph with the verification time threshold to obtain a corresponding comparison result, and determine whether to open the database access right to the legitimate user; When the graph value in the verification time distribution graph is less than the verification time threshold, the database sends an update key to the verifier, and the verifier combines the preset password and the update key to generate a corresponding secondary password and sends it to the legal user, performs secondary verification on the legal user, and determines again whether to open the database access right to the legal user; When it is determined that the database access permission is to be opened to the legitimate user, the sensitive data in the database is desensitized and opened to the legitimate user; The preset password is pre-set by the network administrator and is related to the security requirements and usage scenarios of the data security gateway; The temporary verification code is a combination of numbers randomly generated by the verifier and is used to authenticate the database access rights of the legitimate user; The verification time is the time required for the legal user to obtain the database access permission; The verification time threshold is the minimum time required to pass the database access permission, which is related to the security requirements of the data security gateway; The steps to generate the calibration time distribution map include: Preprocessing the verification time to generate corresponding verification data; Generate a number of corresponding learning features according to the verification data; The auxiliary verification model learns the verification data and generates a corresponding verification time distribution map; Annotating the verification time distribution map according to the learning feature; Wherein, the learning characteristics include the length of verification time and / or the verification frequency of a single legitimate user; The auxiliary verification model is generated by training a verification training set formed by the verification data corresponding to the verification time.

2. The dynamic data encryption and desensitization method for a data security gateway according to claim 1, characterized in that, The steps for the verifier to send a temporary verification code to the database include: When the visiting user accesses the verifier, the verifier collects the corresponding user name; The verifier queries the corresponding preset password according to the user name; The preset password is compared with the verification password input by the visiting user to determine whether the visiting user is a legitimate user.

3. The dynamic data encryption and desensitization method for a data security gateway according to claim 2, characterized in that, When the preset password is consistent with the verification password, it is determined that the visiting user is a legitimate user, and the validator sends the corresponding temporary verification code to the database. When the preset password is inconsistent with the verification password, the validator prompts the visiting user to enter the verification password again. When the preset password is inconsistent with the verification password again, it is determined that the visiting user is not a legitimate user, and the corresponding visiting user is marked as prohibited from accessing the database and the sensitive data is dynamically encrypted.

4. The dynamic data encryption and desensitization method for a data security gateway according to claim 3, characterized in that, The steps for preprocessing the verification time include: Cutting the verification time at the standard learning rate to form several pieces of cut data; Normalizing the cut data to form corresponding verification data, where The standard learning rate is the learning rate that the auxiliary verification model can recognize, and for a single learning, its corresponding standard learning rate is a single learning rate; The normalization process is to converge the cut data within a preset range.

5. The dynamic data encryption and desensitization method for a data security gateway according to claim 4, characterized in that, The steps for determining whether to grant database access rights to legitimate users include: Obtaining each graph value in the verification time distribution graph; Comparing the graph value with the verification time threshold, where When the graph value is greater than the verification time threshold, the database marks that the database access rights are granted to the legitimate user; When the graph value is less than the verification time threshold, the database sends an update key to the validator.

6. The dynamic data encryption and desensitization method for a data security gateway according to claim 5, characterized in that, The steps for generating a secondary password include: The database obtains the built-in update key and sends it to the validator; The validator combines the preset password and the update key to obtain a corresponding calculation result; Intercept the calculation result and retain it to the preset length, and generate a corresponding secondary password and send it to the legitimate user.

7. The dynamic data encryption and desensitization method for a data security gateway according to claim 6, wherein The steps for determining again whether to grant database access rights to legitimate users include: Collecting the secondary verification time when the legitimate user passes the secondary verification; Preprocessing the secondary verification time to generate corresponding secondary verification data; According to the learning characteristics, using the auxiliary verification model to learn the secondary verification data and generating a corresponding secondary verification time distribution graph; Using the verification time threshold to perform a secondary screening on the legitimate user; Among them, when the legitimate user fails the secondary verification, the corresponding legitimate user is filtered.

8. The dynamic data encryption and desensitization method for a data security gateway according to claim 7, wherein The steps for using the verification time threshold to perform a secondary screening on legitimate users include: Obtaining each test value in the secondary verification time distribution graph; Comparing the test value with the verification time threshold, where When the test value is greater than the verification time threshold, the database marks that the database access rights are granted to the legitimate user; When the test value is less than the verification time threshold, the corresponding legitimate user is marked as prohibited from accessing the database and the sensitive data is dynamically encrypted.

9. The dynamic data encryption and desensitization method for a data security gateway according to claim 8, characterized in that When it is determined to grant the database access rights to the legitimate user, the database performs dynamic desensitization on the sensitive data to form corresponding desensitized data and opens it to the legitimate user.

Citation Information

Patent Citations

  • A highly secure data reversible desensitization method based on dynamic factors of data attributes

    CN113177223B

  • Dynamic desensitization method for power big data based on fully homomorphic encryption algorithm

    CN117763620B

  • Sensitive data access method and device, computer equipment and storage medium

    CN112597481A

  • Dynamic desensitization method for relational database

    CN112749376A