Sensitive data protection method and device, equipment and storage medium

By verifying the user's preset role information and permission information in sensitive data protection, and weighting and blurring the sensitive data based on the preset weight determined by character position, the problems of poor flexibility and low security in the prior art are solved, and more efficient sensitive data protection is achieved.

CN120046182APending Publication Date: 2025-05-27XIAN SECLOVER INFORMATION TECH CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510043032.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-10
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

The prior art has poor flexibility and low security in sensitive data protection, and cannot dynamically adjust the degree of data blurring according to different scenarios or user roles, and there is a risk of leakage without user permission verification.

Method used

By obtaining the current sensitive data in the user interface, and after verifying the user's preset role information and preset permission information, the current sensitive data is weighted and fuzzed using the preset weight to obtain the blurring result. The preset weight is determined based on the influence of the character position corresponding to each character in the current sensitive data on the degree of blurring, and the data after the blurring process is displayed on the user interface.

Benefits of technology

Effectively prevent user privacy data leakage, improve the security of current sensitive data, and achieve flexible and accurate protection of sensitive data through weighted fuzzification processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120046182A_ABST
    Figure CN120046182A_ABST
Patent Text Reader

Abstract

The invention discloses a sensitive data protection method and device, equipment and a storage medium, and the method comprises the steps: obtaining current sensitive data in a user interface, carrying out the weighted fuzzification processing of the current sensitive data through employing a preset weight after the verification of preset role information and preset authority information of a user is passed, obtaining a fuzzification processing result, and storing the fuzzification processing result in a server; wherein the preset weight is determined according to the influence of the character position corresponding to each character in the current sensitive data on the fuzzification degree, and displaying the data after the fuzzification processing result on the user interface. According to the scheme, the preset role information and the preset permission information of the user are verified, so that leakage of privacy data of the user is effectively prevented, and the security of the current sensitive data is improved; in addition, the current sensitive data is subjected to weighted fuzzification processing by adopting the preset weight, so that each character can be fuzzified accurately and flexibly according to the influence of the character position corresponding to each character on the fuzzification degree.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of artificial intelligence technology, and in particular to a method, device, equipment and storage medium for protecting sensitive data. Background Art

[0002] With the progress of the information society, the protection of sensitive data has become increasingly important. Sensitive data includes users' personal identity information, financial information, contact information, etc. If such information is leaked, it may pose a serious threat to personal privacy and enterprise security. In modern Internet applications, the display of sensitive data is a common requirement, and how to effectively protect the privacy of these data on the front end has become an urgent problem to be solved.

[0003] Currently, when protecting sensitive data, the existing technology only uses simple static protection means to protect sensitive data, such as directly displaying sensitive fields as asterisks or hiding some characters.

[0004] However, the above-mentioned sensitive data protection method has problems of poor flexibility and low security. Summary of the Invention

[0005] This application aims to at least solve the technical problems existing in the prior art. To this end, a first aspect of this application proposes a method for protecting sensitive data, which includes:

[0006] Obtain the current sensitive data in the user interface;

[0007] After verifying the preset role information and preset permission information of the user, perform weighted fuzzification processing on the current sensitive data using a preset weight to obtain a fuzzification processing result; wherein, the preset weight is determined according to the influence of the character positions corresponding to each character in the current sensitive data on the fuzzification degree;

[0008] Display the data after the fuzzification processing result on the user interface.

[0009] In a possible implementation manner, the method further includes:

[0010] Obtain the user's user login authentication information;

[0011] Determine the preset role information of the user based on the user login authentication information;

[0012] Based on the preset correspondence relationship between the role and the permission level, determine the preset permission information corresponding to the preset role information;

[0013] Perform verification processing on the preset role information and preset permission information to obtain a verification result; wherein, the verification result includes verification passed.

[0014] In a possible implementation, weighted fuzzification processing is performed on the current sensitive data using a preset weight to obtain a fuzzification processing result, including:

[0015] Obtain a preset data sensitivity classification standard and determine the current sensitivity corresponding to the current sensitive data;

[0016] Perform weighted fuzzification processing on the current sensitive data based on a preset fuzzification calculation formula and a preset fuzzification strategy to obtain a fuzzification processing result; wherein, the preset fuzzification strategy is determined based on the user's preset role information and the current sensitivity.

[0017] In a possible implementation, the method further includes:

[0018] For each character in the current sensitive data, obtain the character position corresponding to the character;

[0019] Based on a preset weight coefficient and the character position, determine a preset fuzzification calculation formula.

[0020] In a possible implementation, the preset role information includes ordinary users, the current sensitivity includes low sensitivity, medium sensitivity, and high sensitivity, and the preset fuzzification strategy includes a first fuzzification strategy corresponding to low sensitivity, a second fuzzification strategy corresponding to medium sensitivity, and a third fuzzification strategy corresponding to high sensitivity; wherein, the number of fuzzy characters corresponding to the first fuzzification strategy is less than the number of fuzzy characters corresponding to the second fuzzification strategy, and the number of fuzzy characters corresponding to the second fuzzification strategy is less than the number of fuzzy characters corresponding to the third fuzzification strategy.

[0021] In a possible implementation, performing weighted fuzzification processing on the current sensitive data based on a preset fuzzification calculation formula and a preset fuzzification strategy to obtain a fuzzification processing result, including:

[0022] Obtain the user's current behavior information; wherein, the current behavior information includes access frequency and operation duration;

[0023] Adjust the preset fuzzification strategy of the current sensitive data based on the current behavior information to obtain a new preset fuzzification strategy;

[0024] Perform weighted fuzzification processing on the current sensitive data based on the preset fuzzification calculation formula and the new preset fuzzification strategy to obtain a fuzzification processing result.

[0025] In a possible implementation, obtaining the current sensitive data in the user interface includes:

[0026] Obtain the encrypted data processed by a preset encryption algorithm transmitted from the backend;

[0027] After decrypting the encrypted data, the current sensitive data is obtained.

[0028] The second aspect of this application proposes a sensitive data protection device, which includes:

[0029] An acquisition module, configured to acquire the current sensitive data in the user interface;

[0030] A processing module, configured to, after verifying the preset role information and preset permission information of the user, perform weighted fuzzification processing on the current sensitive data using a preset weight to obtain a fuzzification processing result; wherein, the preset weight is determined according to the influence of the character positions corresponding to the characters in the current sensitive data on the fuzzification degree;

[0031] A display module, configured to display the data after the fuzzification processing result on the user interface.

[0032] In a possible implementation manner, the above-mentioned sensitive data protection device is further configured to:

[0033] Acquire the user login authentication information of the user;

[0034] Determine the preset role information of the user based on the user login authentication information;

[0035] Based on the preset correspondence between roles and permission levels, determine the preset permission information corresponding to the preset role information;

[0036] Perform verification processing on the preset role information and preset permission information to obtain a verification result; wherein, the verification result includes verification passed.

[0037] In a possible implementation manner, the above-mentioned processing module is specifically configured to:

[0038] Acquire the preset data sensitivity classification standard, and determine the current sensitivity corresponding to the current sensitive data;

[0039] Based on the preset fuzzification calculation formula and preset fuzzification strategy, perform weighted fuzzification processing on the current sensitive data to obtain a fuzzification processing result; wherein, the preset fuzzification strategy is determined based on the preset role information of the user and the current sensitivity.

[0040] In a possible implementation manner, the above-mentioned sensitive data protection device is further configured to:

[0041] For each character in the current sensitive data, acquire the character position corresponding to the character;

[0042] Based on the preset weight coefficient and the character position, determine the preset fuzzification calculation formula.

[0043] In a possible implementation, the preset role information includes ordinary users, the current sensitivity includes low sensitivity, medium sensitivity, and high sensitivity, and the preset fuzzification strategy includes a first fuzzification strategy corresponding to low sensitivity, a second fuzzification strategy corresponding to medium sensitivity, and a third fuzzification strategy corresponding to high sensitivity; wherein, the number of fuzzy characters corresponding to the first fuzzification strategy is less than the number of fuzzy characters corresponding to the second fuzzification strategy, and the number of fuzzy characters corresponding to the second fuzzification strategy is less than the number of fuzzy characters corresponding to the third fuzzification strategy.

[0044] In a possible implementation, the above processing module is further configured to:

[0045] Obtain the current behavior information of the user; wherein, the current behavior information includes access frequency and operation duration;

[0046] Adjust the preset fuzzification strategy of the current sensitive data based on the current behavior information to obtain a new preset fuzzification strategy;

[0047] Perform weighted fuzzification processing on the current sensitive data based on the preset fuzzification calculation formula and the new preset fuzzification strategy to obtain a fuzzification processing result.

[0048] In a possible implementation, the above acquisition module is specifically configured to:

[0049] Obtain the encrypted data processed by a preset encryption algorithm transmitted from the backend;

[0050] After decrypting the encrypted data, obtain the current sensitive data.

[0051] A third aspect of this application proposes an electronic device, which includes a processor and a memory. At least one instruction, at least one program, a code set, or an instruction set is stored in the memory, and the at least one instruction, the at least one program, the code set, or the instruction set is loaded and executed by the processor to implement the sensitive data protection method as described in the first aspect.

[0052] A fourth aspect of this application proposes a computer-readable storage medium, in which at least one instruction, at least one program, a code set, or an instruction set is stored, and the at least one instruction, the at least one program, the code set, or the instruction set is loaded and executed by a processor to implement the sensitive data protection method as described in the first aspect.

[0053] The embodiments of this application have the following beneficial effects:

[0054] The sensitive data protection method provided by the embodiment of the present application includes: obtaining the current sensitive data in the user interface, and after verifying the preset role information and preset permission information of the user, performing weighted fuzzification processing on the current sensitive data by using a preset weight to obtain a fuzzification processing result, where the preset weight is determined according to the influence of the character positions corresponding to the characters in the current sensitive data on the fuzzification degree, and displaying the data after the fuzzification processing result on the user interface. This solution effectively prevents the leakage of user privacy data and improves the security of the current sensitive data by verifying the preset role information and preset permission information of the user; in addition, by performing weighted fuzzification processing on the current sensitive data by using a preset weight, each character can be accurately and flexibly fuzzified according to the influence of the character positions corresponding to the characters on the fuzzification degree. Description of the Drawings

[0055] Figure 1 It is a block diagram of a computer device provided by the embodiment of the present application;

[0056] Figure 2 It is a step flowchart of a sensitive data protection method provided by the embodiment of the present application;

[0057] Figure 3 It is a step flowchart of obtaining the current sensitive data provided by the embodiment of the present application;

[0058] Figure 4 It is a step flowchart of obtaining the current sensitive data provided by the embodiment of the present application;

[0059] Figure 5 It is a step flowchart of obtaining the fuzzification processing result provided by the embodiment of the present application;

[0060] Figure 6 It is a step flowchart of obtaining the fuzzification processing result provided by the embodiment of the present application;

[0061] Figure 7 It is another step flowchart of obtaining the fuzzification processing result provided by the embodiment of the present application;

[0062] Figure 8 It is a structural block diagram of a sensitive data protection device provided by the embodiment of the present application. Detailed Embodiments

[0063] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0064] Currently, when protecting sensitive data, the prior art only protects sensitive data through simple static obfuscation means. For example, directly displaying sensitive fields as asterisks (such as displaying a bank card number as "****1234"), or hiding some characters. However, there are obvious defects, including: the existing solutions usually adopt static obfuscation processing and cannot dynamically adjust the obfuscation degree of data according to different scenarios or user roles. When viewing some sensitive information, users may need more flexibility and customized display rules, and a single obfuscation method cannot meet these needs. Although the prior art has achieved data obfuscation, there is still a risk of leakage without user permission verification.

[0065] Based on this, the present application proposes a sensitive data protection method, which includes: obtaining the current sensitive data in the user interface, and after verifying the preset role information and preset permission information of the user, performing weighted obfuscation processing on the current sensitive data by using a preset weight to obtain an obfuscation processing result, where the preset weight is determined according to the influence of the character positions corresponding to the characters in the current sensitive data on the obfuscation degree, and displaying the data after the obfuscation processing result on the user interface. This solution effectively prevents the leakage of user privacy data by verifying the preset role information and preset permission information of the user, and improves the security of the current sensitive data; in addition, by performing weighted obfuscation processing on the current sensitive data by using a preset weight, each character can be accurately and flexibly obfuscated according to the influence of the character position corresponding to each character on the obfuscation degree.

[0066] Hereinafter, the terms "first" and "second" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the embodiments of the present disclosure, unless otherwise stated, the meaning of "a plurality" is two or more. In addition, the use of "based on" or "according to" means open and inclusive, because a process, step, calculation or other action "based on" or "according to" one or more of the stated conditions or values may in practice be based on additional conditions or values beyond the stated ones.

[0067] The sensitive data protection method provided by the present application can be applied to a computer device (electronic device). The computer device can be a server or a terminal. Among them, the server can be a single server or a server cluster composed of multiple servers. The embodiments of the present application do not make specific limitations in this regard. The terminal can be but is not limited to various personal computers, laptop computers, smart phones, tablet computers, and portable wearable devices.

[0068] Taking the computer device as a server as an example, Figure 1 A block diagram of a server is shown. As Figure 1 shown, the server may include a processor and a memory connected by a system bus. Among them, the processor of the server is used to provide computing and control capabilities. The memory of the server includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. When the computer program is executed by the processor, it realizes a sensitive data protection method.

[0069] Those skilled in the art can understand that Figure 1 the structure shown in

[0070] is only a block diagram of a part of the structure related to the solution of this application, and does not constitute a limitation on the server to which the solution of this application is applied. Optionally, the server may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0071] Figure 2 is a step flow chart of a sensitive data protection method provided by an embodiment of this application. As Figure 2 shown, the method includes the following steps:

[0072] Step 202, obtain the current sensitive data in the user interface.

[0073] Among them, when obtaining the current sensitive data in the user interface, the current sensitive data can be automatically captured through the combination of the front-end Document Object Model (DOM) and JavaScript with regular expressions. Usually, the current sensitive data may include, but is not limited to, bank card numbers, ID card numbers, telephone numbers, email addresses, etc.

[0074] Optionally, the potential sensitive data can be identified by first scanning the DOM elements in the user interface. When the front-end application is rendered, it usually displays sensitive information such as the user's personal information and transaction data, and these sensitive information mostly appears in the interface in the form of HyperText Markup Language (HTML) elements such as forms, text boxes, and paragraphs. Through JavaScript, the entire DOM tree in the interface can be traversed to find the elements that may contain sensitive data, so as to obtain the current sensitive data in the user interface.

[0075] Specifically, document.querySelectorAll() or other methods can be used to find all possible input boxes, text nodes, or other elements. For example, scan the values of all input fields, text boxes, buttons, and other elements on the page. Thus, all form elements can be obtained through the class.sensitive-data of the elements containing sensitive data, which are the current sensitive data, such as bank card numbers, passwords, phone numbers, etc.

[0076] In some alternative embodiments, such as Figure 3 shown Figure 3 FIG. is a flowchart of steps for obtaining the current sensitive data provided by an embodiment of the present application, including:

[0077] Step 302: Obtain the encrypted data processed by a preset encryption algorithm transmitted from the backend.

[0078] Step 304: After decrypting the encrypted data, obtain the current sensitive data.

[0079] Among them, to further ensure security, during the process of the backend transmitting sensitive data to the frontend, the sensitive data can be first additionally encrypted by a preset encryption algorithm to obtain encrypted data, and then the encrypted data is transmitted to the frontend. After the frontend decrypts the encrypted data, the current sensitive data can be obtained. The embodiment of the present application does not specifically limit the preset encryption algorithm. For example, it can be the Advanced Encryption Standard (AES for short).

[0080] Optionally, during the data transmission process, the HTTPS protocol can be used to ensure the encrypted transmission of data and avoid man-in-the-middle attacks. Whenever the user interface loads data, the system can also verify whether it is a legitimate user request and can verify the integrity of the data to ensure that the data rendered on the frontend will not be tampered with.

[0081] Step 204: After the preset role information and preset permission information of the user are verified, perform weighted fuzzification processing on the current sensitive data using a preset weight to obtain a fuzzification processing result.

[0082] Among them, after obtaining the current sensitive data, it can be determined whether these data are truly sensitive data, and they can be classified according to the sensitivity level to obtain the current sensitivity level corresponding to the current sensitive data. Optionally, regular expressions and pattern matching-based techniques can be used to identify the data.

[0083] Based on a preset data sensitivity classification standard, the current sensitivity can include low sensitivity, medium sensitivity, and high sensitivity. Exemplarily, bank card numbers, credit card numbers, passwords, etc. belong to highly sensitive data, personal names, email addresses, etc. belong to medium-sensitive data, and public information such as gender, date of birth, etc. is low-sensitive data.

[0084] After classifying the current sensitivity, the user's preset role information and preset permission information can be verified, such as Figure 4 shown Figure 4 is a flowchart of steps for obtaining current sensitive data provided by an embodiment of the present application, including:

[0085] Step 402, obtain the user's user login authentication information.

[0086] Step 404, determine the user's preset role information based on the user login authentication information.

[0087] Step 406, based on the preset correspondence between roles and permission levels, determine the preset permission information corresponding to the preset role information.

[0088] Step 408, perform verification processing on the preset role information and preset permission information to obtain a verification result.

[0089] Among them, when obtaining the user's user login authentication information, the user login authentication information can be obtained through the relevant information of the user recorded in the authentication mechanism (JSON Web Token, abbreviated as JWT token) or the session mechanism that records the session state of the server and the client.

[0090] Next, the user's preset role information can be determined based on the user login authentication information. The preset role information can include ordinary users and administrators. Different roles will have different permission levels. For example, ordinary users can only view the obfuscated data, while administrators can view the complete sensitive data. Therefore, the preset permission information corresponding to the preset role information can be determined based on the preset correspondence between roles and permission levels. Finally, verification processing is performed on the preset role information and preset permission information to obtain a verification result, where the verification result can include verification passed and verification failed.

[0091] After the verification of the user's preset role information and preset permission information passes, a preset weight can be used to perform weighted obfuscation processing on the current sensitive data to obtain an obfuscation processing result, where the preset weight is determined according to the influence of the character positions corresponding to each character in the current sensitive data on the obfuscation degree.

[0092] In some alternative embodiments, such as Figure 5 shown Figure 5A flowchart of steps for obtaining a fuzzification result provided by an embodiment of the present application includes:

[0093] Step 502: Obtain a preset data sensitivity classification standard and determine the current sensitivity corresponding to the current sensitive data.

[0094] Step 504: Perform weighted fuzzification processing on the current sensitive data based on a preset fuzzification calculation formula and a preset fuzzification strategy to obtain a fuzzification result.

[0095] Among them, after obtaining the current sensitivity corresponding to the current sensitive data, weighted fuzzification processing can be performed on the current sensitive data based on a preset fuzzification calculation formula and a preset fuzzification strategy to obtain a fuzzification result. The preset fuzzification strategy is determined based on the preset role information of the user and the current sensitivity.

[0096] In some optional embodiments, as Figure 6 shown, Figure 6 A flowchart of steps for obtaining a fuzzification result provided by an embodiment of the present application includes:

[0097] Step 602: For each character in the current sensitive data, obtain the character position corresponding to the character.

[0098] Step 604: Determine a preset fuzzification calculation formula based on a preset weight coefficient and the character position.

[0099] Among them, the preset fuzzification calculation formula is as shown in formula (1), and the preset weight coefficient determines the influence of the character position on the fuzzification degree and can be pre-customized through experience.

[0100]

[0101] Where i is the character position, and a and b are preset weight coefficients.

[0102] Thus, weighted fuzzification processing can be performed on the current sensitive data based on a preset fuzzification calculation formula and a preset fuzzification strategy to obtain a fuzzification result. That is, each character in the current sensitive data is weighted fuzzified through formula (1) to obtain the fuzzification result of each character, and finally the fuzzification result of the current sensitive data is obtained by combining the fuzzification results of each character.

[0103] In some optional embodiments, the preset role information includes ordinary users, the current sensitivity includes low sensitivity, medium sensitivity, and high sensitivity, and the preset fuzzification strategy includes a first fuzzification strategy corresponding to low sensitivity, a second fuzzification strategy corresponding to medium sensitivity, and a third fuzzification strategy corresponding to high sensitivity. Among them, the number of fuzzy characters corresponding to the first fuzzification strategy is less than the number of fuzzy characters corresponding to the second fuzzification strategy, and the number of fuzzy characters corresponding to the second fuzzification strategy is less than the number of fuzzy characters corresponding to the third fuzzification strategy.

[0104] Exemplarily, if the preset role information is an ordinary user, for the bank card number "123456789876 5432" with high sensitivity, a higher preset weight coefficient can be assigned to the first 12 digits of the bank card, while the last four digits have a lower degree of fuzzification and a lower preset weight coefficient can be assigned. After fuzzification, it can become "****1234". The preset fuzzification strategy used in this process is regarded as the third fuzzification strategy. It should be noted that the specific numbers "1234" retained here are only an example, only to illustrate that four plaintext digits can be retained, and the other 12 digits have been fuzzified.

[0105] Exemplarily again, if the preset role information is an ordinary user, for the user name with medium sensitivity, only the name can be fuzzified, for example, the output is "Zhang**".

[0106] Exemplarily again, if the preset role information is an ordinary user, for the date of birth with low sensitivity, only one digit in the date can be fuzzified, for example, the output is "2001-02-1*".

[0107] In some optional embodiments, if the preset role information is an administrator and the super administrator function is enabled in advance, there is no need to fuzzify the current sensitive data, and the full amount of data is displayed to the administrator.

[0108] If the preset role information is an administrator and the super administrator function is not enabled in advance, the fuzzification process can be carried out according to the fuzzification process of ordinary users, and the specific process will not be elaborated here.

[0109] In some optional embodiments, the preset fuzzification strategy can be dynamically adjusted by monitoring the user's current behavior information. As Figure 7 shown, Figure 7 Another flowchart of steps for obtaining the fuzzification processing result provided by the embodiment of the present application includes:

[0110] Step 702, obtain the user's current behavior information.

[0111] Step 704: Adjust the preset fuzzification strategy for the current sensitive data based on the current behavior information to obtain a new preset fuzzification strategy.

[0112] Step 706: Perform weighted fuzzification processing on the current sensitive data based on the preset fuzzification calculation formula and the new preset fuzzification strategy to obtain the fuzzification processing result.

[0113] Among them, the current behavior information may include the access frequency and the operation duration, so that the preset fuzzification strategy for the current sensitive data can be adjusted based on the current behavior information to obtain a new preset fuzzification strategy.

[0114] Exemplarily, if the access frequency is too high, it indicates that the user is frequently accessing the current sensitive data. If the current sensitivity of the current sensitive data is high sensitivity, since there can be multiple third fuzzification strategies corresponding to the high sensitivity, the above fuzzification of the bank card number "1234 5678 9876 5432" to "****1234" is only one of the third fuzzification strategies.

[0115] When the user frequently accesses the current sensitive data, other third fuzzification strategies can be used to fuzzify the bank card number "1234 5678 9876 5432". For example, a higher preset weight coefficient can be assigned to the first 11 digits of the bank card, while the last five digits have a lower degree of fuzzification and can be assigned a lower preset weight coefficient. After fuzzification processing, it can become "***1 2345". It should also be noted that the retained number "12345" here is only an example, only to illustrate that five plaintext digits can be retained, and the other 11 digits have been fuzzified. In addition, since the third fuzzification strategy is still used, the condition that the number of fuzzy characters corresponding to the third fuzzification strategy is greater than the number of fuzzy characters corresponding to the second fuzzification strategy still needs to be satisfied.

[0116] In this embodiment, by collecting and analyzing user interaction data, the preset fuzzification strategy is dynamically adjusted according to the usage scenario, so that the degree of fuzzification can be intelligently weakened to improve the user experience, and the fluency of user operations and the adaptability of data display are improved, and the consumption of system resources is reduced.

[0117] Step 206: Display the data after the fuzzification processing result on the user interface.

[0118] Among them, after obtaining the fuzzification processing result, the data after the fuzzification processing result can be displayed on the user interface, and the specific process of displaying the data can refer to the prior art and will not be elaborated here.

[0119] The present application provides a sensitive data protection method, which includes: obtaining the current sensitive data in the user interface, and after verifying the preset role information and preset permission information of the user, performing weighted blurring processing on the current sensitive data using a preset weight to obtain a blurred processing result, where the preset weight is determined according to the influence of the character positions corresponding to the characters in the current sensitive data on the degree of blurring, and displaying the data after the blurred processing result on the user interface. This solution effectively prevents the leakage of user privacy data and improves the security of the current sensitive data by verifying the preset role information and preset permission information of the user; in addition, by performing weighted blurring processing on the current sensitive data using a preset weight, each character can be blurred accurately and flexibly according to the influence of the character positions corresponding to the characters on the degree of blurring.

[0120] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same moment, but can be executed at different moments. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.

[0121] Figure 8 It is a structural block diagram of a sensitive data protection device provided by an embodiment of the present application.

[0122] As Figure 8 shown, the sensitive data protection device 800 includes:

[0123] An acquisition module 802, configured to acquire the current sensitive data in the user interface.

[0124] A processing module 804, configured to perform weighted blurring processing on the current sensitive data using a preset weight to obtain a blurred processing result after verifying the preset role information and preset permission information of the user; where the preset weight is determined according to the influence of the character positions corresponding to the characters in the current sensitive data on the degree of blurring.

[0125] A display module 806, configured to display the data after the blurred processing result on the user interface.

[0126] Regarding the device in the above embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments related to the method, and will not be elaborated herein. Each module in the above sensitive data protection device can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in the processor of the computer device in hardware form or independent thereof, or stored in the memory of the computer device in software form, so as to facilitate the processor to call and execute the operations of each of the above modules.

[0127] In an embodiment of the present application, a computer device is provided. The computer device includes a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the following steps are implemented:

[0128] Obtain the current sensitive data in the user interface;

[0129] After verifying the preset role information and preset permission information of the user, perform weighted fuzzification processing on the current sensitive data using a preset weight to obtain a fuzzification processing result; wherein, the preset weight is determined according to the influence of the character positions corresponding to each character in the current sensitive data on the fuzzification degree;

[0130] Display the data after the fuzzification processing result on the user interface.

[0131] In an embodiment of the present application, when the processor executes the computer program, the following steps are further implemented:

[0132] Obtain the user login authentication information of the user;

[0133] Determine the preset role information of the user based on the user login authentication information;

[0134] Based on the preset corresponding relationship between the role and the permission level, determine the preset permission information corresponding to the preset role information;

[0135] Perform verification processing on the preset role information and preset permission information to obtain a verification result; wherein, the verification result includes verification passed.

[0136] In an embodiment of the present application, when the processor executes the computer program, the following steps are further implemented:

[0137] Obtain the preset data sensitivity classification standard, and determine the current sensitivity corresponding to the current sensitive data;

[0138] Based on the preset fuzzification calculation formula and preset fuzzification strategy, perform weighted fuzzification processing on the current sensitive data to obtain a fuzzification processing result; wherein, the preset fuzzification strategy is determined based on the preset role information of the user and the current sensitivity.

[0139] In one embodiment of the present application, when the processor executes the computer program, the following steps are further implemented:

[0140] For each character in the current sensitive data, obtain the character position corresponding to the character;

[0141] Based on the preset weight coefficient and the character position, determine the preset fuzzification calculation formula.

[0142] In one embodiment of the present application, the preset role information includes ordinary users, the current sensitivity includes low sensitivity, medium sensitivity, and high sensitivity, and the preset fuzzification strategy includes a first fuzzification strategy corresponding to low sensitivity, a second fuzzification strategy corresponding to medium sensitivity, and a third fuzzification strategy corresponding to high sensitivity; wherein, the number of fuzzy characters corresponding to the first fuzzification strategy is less than the number of fuzzy characters corresponding to the second fuzzification strategy, and the number of fuzzy characters corresponding to the second fuzzification strategy is less than the number of fuzzy characters corresponding to the third fuzzification strategy.

[0143] In one embodiment of the present application, when the processor executes the computer program, the following steps are further implemented:

[0144] Obtain the current behavior information of the user; wherein, the current behavior information includes the access frequency and the operation duration;

[0145] Based on the current behavior information, adjust the preset fuzzification strategy of the current sensitive data to obtain a new preset fuzzification strategy;

[0146] Based on the preset fuzzification calculation formula and the new preset fuzzification strategy, perform weighted fuzzification processing on the current sensitive data to obtain a fuzzification processing result.

[0147] In one embodiment of the present application, when the processor executes the computer program, the following steps are further implemented:

[0148] Obtain the encrypted data processed by the preset encryption algorithm transmitted from the backend;

[0149] After decrypting the encrypted data, obtain the current sensitive data.

[0150] The computer device provided by the embodiments of the present application has the same implementation principle and technical effects as the above method embodiments, and will not be elaborated here.

[0151] In one embodiment of the present application, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0152] Obtain the current sensitive data in the user interface;

[0153] After verifying the preset role information and preset permission information of the user, perform weighted fuzzification processing on the current sensitive data using a preset weight to obtain a fuzzification processing result; wherein, the preset weight is determined according to the influence of the character position corresponding to each character in the current sensitive data on the degree of fuzzification;

[0154] Display the data after the fuzzification processing result on the user interface.

[0155] In an embodiment of the present application, when the computer program is executed by a processor, the following steps are further implemented:

[0156] Obtain the user login authentication information of the user;

[0157] Determine the preset role information of the user based on the user login authentication information;

[0158] Based on the preset correspondence between the role and the permission level, determine the preset permission information corresponding to the preset role information;

[0159] Perform verification processing on the preset role information and preset permission information to obtain a verification result; wherein, the verification result includes verification passed.

[0160] In an embodiment of the present application, when the computer program is executed by a processor, the following steps are further implemented:

[0161] Obtain the preset data sensitivity classification standard, and determine the current sensitivity corresponding to the current sensitive data;

[0162] Based on the preset fuzzification calculation formula and the preset fuzzification strategy, perform weighted fuzzification processing on the current sensitive data to obtain a fuzzification processing result; wherein, the preset fuzzification strategy is determined based on the preset role information of the user and the current sensitivity.

[0163] In an embodiment of the present application, when the computer program is executed by a processor, the following steps are further implemented:

[0164] For each character in the current sensitive data, obtain the character position corresponding to the character;

[0165] Based on the preset weight coefficient and the character position, determine the preset fuzzification calculation formula.

[0166] In an embodiment of the present application, the preset role information includes ordinary users, the current sensitivity includes low sensitivity, medium sensitivity, and high sensitivity, and the preset fuzzification strategy includes a first fuzzification strategy corresponding to low sensitivity, a second fuzzification strategy corresponding to medium sensitivity, and a third fuzzification strategy corresponding to high sensitivity; wherein, the number of fuzzy characters corresponding to the first fuzzification strategy is less than the number of fuzzy characters corresponding to the second fuzzification strategy, and the number of fuzzy characters corresponding to the second fuzzification strategy is less than the number of fuzzy characters corresponding to the third fuzzification strategy.

[0167] In an embodiment of the present application, when the computer program is executed by a processor, the following steps are further implemented:

[0168] Obtain the current behavior information of the user; wherein, the current behavior information includes access frequency and operation duration;

[0169] Adjust the preset fuzzification strategy of the current sensitive data based on the current behavior information to obtain a new preset fuzzification strategy;

[0170] Perform weighted fuzzification processing on the current sensitive data based on the preset fuzzification calculation formula and the new preset fuzzification strategy to obtain a fuzzification processing result.

[0171] In an embodiment of the present application, when the computer program is executed by a processor, the following steps are further implemented:

[0172] Obtain the encrypted data processed by a preset encryption algorithm transmitted from the backend;

[0173] After decrypting the encrypted data, obtain the current sensitive data.

[0174] The computer-readable storage medium provided in this embodiment has the same implementation principle and technical effects as the above method embodiment, and will not be elaborated here.

[0175] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0176] After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily conceive of other embodiments of the present disclosure. This application is intended to cover any variations, uses, or adaptations of the present disclosure, which follow the general principles of the present disclosure and include known common knowledge or conventional technical means in the technical field not disclosed in the present disclosure. The specification and embodiments are only regarded as exemplary, and the true scope and spirit of the present disclosure are pointed out by the following claims.

[0177] It should be understood that the present disclosure is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present disclosure is only limited by the appended claims.

Claims

1. A sensitive data protection method, characterized in that: The method comprises: Get the current sensitive data in the user interface; After the preset role information and preset permission information of the user are verified, the current sensitive data is subjected to weighted fuzzification processing using preset weights to obtain a fuzzification processing result; wherein the preset weights are determined according to the influence of the character positions corresponding to each character in the current sensitive data on the degree of fuzzification; The data after the fuzzy processing result is displayed on the user interface.

2. The method according to claim 1, characterized in that The method further comprises: Obtaining user login authentication information of the user; Determining the preset role information of the user based on the user login authentication information; Based on a preset correspondence between roles and authority levels, determining the preset authority information corresponding to the preset role information; The preset role information and the preset authority information are verified to obtain a verification result; wherein the verification result includes verification passed.

3. The method according to claim 1 or 2, characterized in that: The step of performing weighted fuzzification processing on the current sensitive data by using preset weights to obtain a fuzzification processing result includes: Obtaining a preset data sensitivity classification standard to determine the current sensitivity corresponding to the current sensitive data; Based on a preset fuzzification calculation formula and a preset fuzzification strategy, weighted fuzzification processing is performed on the current sensitive data to obtain a fuzzification processing result; wherein the preset fuzzification strategy is determined based on the user's preset role information and the current sensitivity.

4. The method according to claim 3, characterized in that The method further comprises: For each character in the current sensitive data, obtaining a character position corresponding to the character; Based on the preset weight coefficient and the character position, the preset fuzzy calculation formula is determined.

5. The method according to claim 3, characterized in that: The preset role information includes ordinary users, the current sensitivity includes low sensitivity, medium sensitivity and high sensitivity, and the preset fuzzification strategy includes a first fuzzification strategy corresponding to the low sensitivity, a second fuzzification strategy corresponding to the medium sensitivity, and a third fuzzification strategy corresponding to the high sensitivity; wherein, the number of fuzzy characters corresponding to the first fuzzification strategy is smaller than the number of fuzzy characters corresponding to the second fuzzification strategy, and the number of fuzzy characters corresponding to the second fuzzification strategy is smaller than the number of fuzzy characters corresponding to the third fuzzification strategy.

6. The method according to claim 5, characterized in that The weighted fuzzification processing is performed on the current sensitive data based on the preset fuzzification calculation formula and the preset fuzzification strategy to obtain the fuzzification processing result, including: Acquire the current behavior information of the user; wherein the current behavior information includes access frequency and operation duration; Adjusting the preset fuzzification strategy of the current sensitive data based on the current behavior information to obtain a new preset fuzzification strategy; Based on the preset fuzzification calculation formula and the new preset fuzzification strategy, weighted fuzzification processing is performed on the current sensitive data to obtain the fuzzification processing result.

7. The method according to claim 1 or 2, characterized in that: The obtaining of current sensitive data in the user interface includes: Obtain the encrypted data transmitted by the backend after being processed by the preset encryption algorithm; After decrypting the encrypted data, the current sensitive data is obtained.

8. A sensitive data protection device, characterized in that: The device comprises: The acquisition module is used to obtain the current sensitive data in the user interface; A processing module, used to perform weighted fuzzification processing on the current sensitive data using preset weights after the preset role information and preset permission information of the user are verified, to obtain a fuzzification processing result; wherein the preset weights are determined according to the influence of the character position corresponding to each character in the current sensitive data on the degree of fuzzification; A display module is used to display the fuzzy processed data on the user interface.

9. An electronic device, characterized in that: The electronic device includes a processor and a memory, wherein the memory stores at least one instruction, at least one program, a code set or an instruction set, and the at least one instruction, the at least one program, the code set or the instruction set is loaded and executed by the processor to implement the sensitive data protection method as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that: The storage medium stores at least one instruction, at least one program, a code set or an instruction set, and the at least one instruction, the at least one program, the code set or the instruction set is loaded and executed by the processor to implement the sensitive data protection method as described in any one of claims 1-7.

Citation Information

Cited By

  • Data display method, system and equipment for interaction security and storage medium

    CN120973272A

  • Data display method, system and device for interaction security and storage medium

    CN120973272B