Sensitive data differentiation shielding method and device

By identifying and differentiating the sensitive data in the display page in product demonstration, the problem that a single blocking method in the prior art affects the demonstration effect is solved, and effective blocking of sensitive data and complete display of product functions is achieved.

CN120068115APending Publication Date: 2025-05-30BEIJING ANTIY NETWORK SAFETY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510146519.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The prior art uses a single blocking method to block sensitive data in scenarios such as product demonstration, resulting in a demonstration effect that affects product functions.

Method used

A method and device for differentiating sensitive data is provided. By identifying sensitive data in the page to be displayed and using a pre-set masking strategy, differentiating masking processing is performed on different data types, so that the data type of sensitive data being masked is recognizable.

Benefits of technology

Through differentiated blocking processing, the data type of sensitive data after blocking can be identified, ensuring the demonstration effect of product functions, and avoiding sensitive data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068115A_ABST
    Figure CN120068115A_ABST
Patent Text Reader

Abstract

The invention discloses a sensitive data differentiation shielding method and device, and belongs to the technical field of data security. The method comprises the following steps: in response to a sensitive data shielding instruction, identifying sensitive data in each to-be-displayed page of a target product in a demonstration process; performing differential shielding processing on the sensitive data according to different data types by using a preset shielding strategy, so that the data type of the shielded sensitive data has identifiability; and displaying the page to be displayed after the shielding processing. The demonstration effect of the product function can be ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and particularly to a method and device for differentially masking sensitive data. Background Art

[0002] In scenarios such as product demonstrations, visiting tours, and briefly leaving the office machine, it is easy to cause the leakage problem of sensitive data. In the related art, the " * " replacement method is usually used to mask sensitive data. However, this masking method will affect the demonstration effect of product functions. Summary of the Invention

[0003] The present invention provides a method and device for differentially masking sensitive data, which can solve the problem that the single masking method in the related art affects the demonstration effect of product functions. The technical solutions are as follows:

[0004] On the one hand, a method for differentially masking sensitive data is provided. The method includes:

[0005] In response to a sensitive data masking instruction, identifying sensitive data in each page to be displayed during the demonstration of the target product;

[0006] Using a pre-set masking strategy, performing differential masking processing on the sensitive data according to different data types, so that the data types of the masked sensitive data are distinguishable;

[0007] Displaying the page to be displayed after the masking process.

[0008] On the other hand, a device for differentially masking sensitive data is provided. The device includes:

[0009] An identification unit, configured to identify sensitive data in each page to be displayed during the demonstration of the target product in response to a sensitive data masking instruction;

[0010] A masking unit, configured to perform differential masking processing on the sensitive data according to different data types using a pre-set masking strategy, so that the data types of the masked sensitive data are distinguishable;

[0011] A display unit, configured to display the page to be displayed after the masking process.

[0012] On the other hand, a computer device is provided. The computer device includes a memory and a processor. The memory is used to store a computer program, and the processor is used to execute the computer program stored on the memory to implement the steps of the above-mentioned method for differentially masking sensitive data.

[0013] On the other hand, a computer-readable storage medium is provided, in which a computer program is stored, and when the computer program is executed by a processor, the steps of the above-mentioned sensitive data differential shielding method are implemented.

[0014] On the other hand, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, the steps of the above-mentioned sensitive data differential shielding method are implemented.

[0015] The technical solution provided by the present invention can at least bring the following beneficial effects:

[0016] During the product demonstration process, it is implemented in the form of a display page. Sensitive data may exist in each display page. By responding to the sensitive data shielding instruction, the sensitive data in the page to be displayed can be identified, and then the sensitive data is differentially shielded according to different data types by using the shielding strategy, so that the data types of the shielded sensitive data are identifiable. Since there are differences in the shielding processing methods for sensitive data of different data types, based on this difference, the data types of the sensitive data after shielding processing can be identified, and thus the demonstration effect of the product function can be guaranteed. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0018] Figure 1 is a flowchart of a sensitive data differential shielding method provided by an embodiment of the present invention;

[0019] Figure 2 is a structural diagram of a sensitive data differential shielding device provided by an embodiment of the present invention;

[0020] Figure 3 is a hardware architecture diagram of a computer device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0021] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.

[0022] As described above, during the product demonstration process, sensitive data in the display page is masked by using "*" replacement. However, after masking, the demonstration effect of the product function will be affected.

[0023] Regarding the problems existing in the related technology, it is because the sensitive data is masked in a "one-size-fits-all" manner by using the "*" replacement method, making it difficult for viewers to determine the data type from the masked data content. Based on this, the inventive concept of the present invention lies in: in order to ensure the demonstration effect of the product function, after masking the sensitive data in the display page, it is necessary to ensure that the data type can be identified based on the masked content, thereby ensuring the demonstration effect of the product function.

[0024] The following describes the specific implementation manners of the above concept.

[0025] Please refer to Figure 1 , a method for differentially masking sensitive data provided by an embodiment of the present invention includes:

[0026] Step 100, in response to a sensitive data masking instruction, identify sensitive data in each page to be displayed during the demonstration of the target product;

[0027] Step 102, use a pre-set masking strategy to perform differential masking processing on the sensitive data according to different data types, so that the data types of the masked sensitive data are identifiable;

[0028] Step 104, display the page to be displayed after the masking process.

[0029] In an embodiment of the present invention, the product is implemented in the form of a display page during the demonstration process. Sensitive data may exist in each display page. By responding to the sensitive data masking instruction, the sensitive data in the page to be displayed can be identified, and then the masking strategy is used to perform differential masking processing on the sensitive data according to different data types, so that the data types of the masked sensitive data are identifiable. Since there are differences in the masking processing methods for sensitive data of different data types, the data type of the masked sensitive data can be identified based on this difference, and thus the demonstration effect of the product function can be ensured.

[0030] The following describes Figure 1 the execution manners of each step shown in

[0031] First, for step 100, in response to a sensitive data masking instruction, identify sensitive data in each page to be displayed during the demonstration of the target product.

[0032] In an embodiment of the present invention, the execution entity may be a computer device with a display interface, such as a client, a server, etc., which can be used to mask sensitive data in the display content on the display interface.

[0033] Furthermore, the sensitive data differential masking method provided by the embodiment of the present invention can be applied to the scenario of product demonstration. In this case, the execution entity is a computer device for product demonstration, which is used to differentially mask sensitive data on the display page during the product demonstration process. The target product may be a local software product installed on the computer device, or may be based on the BS architecture and realize product operations through the browser on the computer device. Among them, the target product may be a network security product or other products.

[0034] During the product demonstration process, there may be sensitive data in the data content of the display page. To ensure data security and prevent the leakage of sensitive data, it is necessary to mask the sensitive data on the display page.

[0035] In an embodiment of the present invention, the initiation methods of the sensitive data masking instruction may at least include the following two types:

[0036] The first method: If it is detected that the target product is logged in, determine whether the current logged-in account is a demonstration account; if so, actively initiate a sensitive data masking instruction.

[0037] The second method: A masking function is set on the display interface of the target product; the user can initiate a sensitive data masking instruction based on the masking function.

[0038] Based on the above two methods, in an embodiment of the present invention, when it is detected that the target product is logged in, determine whether the current logged-in account is a demonstration account; if so, actively initiate a sensitive data masking instruction; if it is a non-demonstration account, the sensitive data may not be masked, but when the non-demonstration account initiates a sensitive data masking instruction through the masking function, the sensitive data masking process is performed.

[0039] In the first method, if the account logged in to the product is a demonstration account, then the purpose of logging in to the product with the demonstration account is to conduct a product demonstration. Thus, a sensitive data masking instruction can be directly initiated when the product is logged in. After the computer device receives the sensitive data masking instruction, it responds to the sensitive data masking instruction to mask the sensitive data on the display page in the subsequent process.

[0040] In the traditional technology, data decentralization is adopted to set the access permission of non-sensitive data for the demonstration account, which may lead to the situation of "empty data" or "incomplete data" during the demonstration process, resulting in the inability to fully display the function usage and security operation achievements, thus reducing the demonstration and visit effects. In the embodiments of the present invention, the highest permission can be granted to the demonstration account, and by differentially shielding the sensitive data in the display page, the leakage of sensitive data can be avoided and the demonstration effect of the product function can be ensured.

[0041] In the second method, if the account logged in to the product is a non-demonstration account, then when the product is logged in, it may be a normal operation of the operator on the product. Therefore, when the product is logged in, if the non-demonstration account does not initiate a sensitive data shielding instruction, the sensitive data is not shielded.

[0042] In the second method, if there is a on-site requirement from the interviewee for the non-demonstration account to conduct a product demonstration, the non-demonstration account can initiate a sensitive data shielding instruction based on the shielding function set on the product display interface, and then shield the sensitive data on the display page in the subsequent process.

[0043] In the embodiments of the present invention, the target product is realized based on one display page after another during the demonstration process, and there may be sensitive data in the display page. Therefore, it is necessary to identify the sensitive data in the display page to be shown.

[0044] The display page to be shown includes static elements and dynamic elements; the dynamic elements are composed of at least one data structure of structured data, semi-structured data, and unstructured data; therefore, in the embodiments of the present invention, a combined identification method can be used to identify the sensitive data with different data structures in the display page to be shown.

[0045] Specifically:

[0046] First, for structured data and static elements

[0047] In the embodiments of the present invention, multiple tags are configured in the structured data and static elements, and the sensitive tags can be marked in advance or the sensitive fields in the tags can be marked. During the page loading process, the sensitive tags or the sensitive fields in the tags can be identified through the marking, and the data content belonging to the sensitive tags and the data content belonging to the sensitive fields are determined as the sensitive data to be shielded.

[0048] For example, the internal IP address under the IP address tag is pre-marked as a sensitive field. When there is an IP address tag on the display page, it is also necessary to perform secondary verification on all fields under the IP address tag to verify whether the field under the IP address tag is an internal IP address or an attacker's IP address. If it is an internal IP address, it is determined as a sensitive field; if it is an attacker's IP address, it is determined not to be a sensitive field. Another example is that the URL field under the URL tag may also include a field of the internal IP address. Therefore, the internal IP address under the URL tag can also be marked as a sensitive field. When there is a URL tag on the display page, the URL field under the URL tag can be secondarily verified to check whether the URL field includes an internal IP address. If it includes an internal IP address, the internal IP address included in the URL field is determined as a sensitive field.

[0049] Second, for unstructured data

[0050] In the embodiments of the present invention, for unstructured data, sensitive data can be identified by superimposing regular expressions, text preprocessing, machine learning, OCR (Optical Character Recognition), and other tools.

[0051] Among them, through the regular expression tool, sensitive data with a fixed format can be identified in unstructured data such as documents. For example, IP class sensitive data can be identified through the regular expression (\d{1,3}\.){3}\d{1,3}, and by adjusting the regular matching strategy, sensitive IPs within a specified range can be identified.

[0052] Before regular expression matching, the data content with a specified data format can also be preprocessed to perform regular expression matching on the preprocessed data content. For example, for mobile phone numbers, there may be various sensitive data in different formats such as 137-888-888-888, 13788888888, +86 13788888888, etc. At this time, a preprocessing tool can be used to perform character normalization, remove irrelevant characters, text segmentation, remove stop words, encoding conversion, etc. to preprocess the data content to obtain 13788888888 which is easier to identify.

[0053] Furthermore, a machine learning model can also be trained to use the trained machine learning model to identify sensitive data in unstructured data to obtain sensitive data that cannot be matched by regular expressions due to the unfixed format. For example, organizational structures, this type of data does not have a unified standard format, and only regular matching will result in the problem of missing sensitive data.

[0054] Further, for unstructured data such as pictures, it is necessary to pre-utilize an OCR tool to recognize the text content in the picture, and then use methods such as text preprocessing, regular expressions, and machine learning to identify sensitive data in the text content recognized by the OCR tool.

[0055] Third, for semi-structured data

[0056] In the embodiments of the present invention, for semi-structured data such as HTML, XML, JSON, etc., it is possible to load (import) a trusted general code library and search for possible sensitive data through pre-encapsulated methods (functions) in the library.

[0057] Then, for step 102, using a pre-set masking strategy, the sensitive data is differentially masked according to different data types, so that the data types of the masked sensitive data are identifiable.

[0058] In the embodiments of the present invention, in order to ensure that the data types of the masked sensitive data are identifiable, a differential masking processing method can be used to mask sensitive data of different data types. Specifically: for sensitive data of different data types, different characters are used to replace the data content of the sensitive data, and when the data type corresponding to the sensitive data is implemented by a delimiter, the delimiter is retained during the masking process; the replacement methods include at least: specified content replacement and random content replacement.

[0059] Taking the target product as a network security product as an example, the data types of sensitive s data can include: asset information, threat information, statistical indicators; among them,

[0060] The asset information includes at least one or more of internal network IP addresses, domain names, asset names, device names, user names, accounts, file information, path information, and organizational structures;

[0061] The threat information includes at least one or more of the external network IP address of the attacker and the attribution location;

[0062] The statistical indicator is the statistical number of the product for various risks.

[0063] In the embodiments of the present invention, when the data type is an internal network IP address, file information, or path information in the asset information, the masking strategy can be to retain the delimiter in the internal network IP address, file information, or path information, and replace at least part of the content other than the delimiter with a first specific character; for example, the first specific character is "*";

[0064] When the data type is the domain name in the asset information, the masking policy can be to retain the delimiter in the domain name and replace at least part of the digits other than the delimiter with a second specific character; for example, the second specific character is "#".

[0065] When the data type is the asset name, device name, user name, or organization in the asset information, the masking policy can be to replace the asset name, device name, user name, or organization with a third specific character; or, the masking policy is to pre-generate a fictional name configured for the asset name, device name, user name, or organizational structure, and use the configured fictional name to replace the corresponding asset name, device name, user name, or organizational structure.

[0066] When the data type is the account number in the asset information, the masking policy can be to replace the account number with a fourth specific character; for example, the letter A.

[0067] When the data type is the external network IP address in the threat information, the masking policy can be to retain the delimiter in the external network IP address and replace at least part of the digits other than the delimiter with a fifth specific character; for example, the fifth specific character is "&".

[0068] When the data type is the attribution location in the threat information, the masking policy can be to replace the attribution location with a sixth specific character; for example, the sixth specific character is "%".

[0069] When the data type is the statistical number in the statistical metrics, the masking policy can be to replace the statistical number with a seventh specific character; for example, the seventh specific character is "@".

[0070] In one embodiment of the present invention, the masking process is at least to mask part of the content in the sensitive data, and after masking part of the content, it is impossible to obtain the original data based on the masked data content.

[0071] For example, for the attribution location in the threat information, if it is country-region-detailed address, then only the detailed address can be masked; for another example, if the organization name is region-name-Co., Ltd., then only the "name" item can be masked; in such cases, it is impossible to obtain the original data based on the masked data content.

[0072] In one embodiment of the present invention, when the data attribute corresponding to the sensitive data is text, the content of the replaced data conforms to the context logic.

[0073] For example, regarding the attribution location in the threat information, if the original data is "the United States", the replaced data content will be "a certain country". After such data content replacement, it conforms to the context logic. If the sensitive data is located in a sentence or paragraph, it is necessary to ensure that the replaced data content conforms to the context logic in that sentence after the data content replacement.

[0074] Finally, for step 104, display the to-be-displayed page after the shielding process.

[0075] In one implementation manner of the present invention, in another implementation manner when loading a page, in order to improve the page loading speed, an asynchronous recognition method can be adopted to recognize sensitive data in advance. Specifically, determine the sub-pages of the currently displayed page, use each sub-page as the to-be-displayed page to recognize sensitive data respectively, and perform the differential shielding process to obtain the shielded sub-page corresponding to each sub-page; when a loading instruction for the target sub-page in the currently displayed page is detected, display the shielded sub-page corresponding to the target sub-page. In this way, the recognition and shielding processes are completed before the loading process, which can quickly achieve page loading and make the product display effect smoother.

[0076] Please refer to Figure 2 , the embodiments of the present invention provide a sensitive data differential shielding device, and the device includes:

[0077] An identification unit 200, configured to identify sensitive data in each to-be-displayed page during the demonstration of the target product in response to a sensitive data shielding instruction;

[0078] A shielding unit 202, configured to perform differential shielding processing on the sensitive data according to different data types by using a pre-set shielding strategy, so that the data types of the shielded sensitive data are distinguishable;

[0079] A display unit 204, configured to display the to-be-displayed page after the shielding process.

[0080] In one embodiment of the present invention, the initiation methods of the sensitive data shielding instruction at least include:

[0081] If it is detected that the target product is logged in, determine whether the currently logged-in account is a demonstration account; if so, actively initiate a sensitive data shielding instruction;

[0082] Or,

[0083] A shielding function is set on the display interface of the target product; the user can initiate a sensitive data shielding instruction based on the shielding function.

[0084] In one embodiment of the present invention, the shielding unit is specifically configured to: for sensitive data of different data types, use different characters to replace the data content of the sensitive data, and when the data type corresponding to the sensitive data is implemented by a delimiter, the delimiter is retained during the shielding process; the replacement methods include at least: specified content replacement and random content replacement.

[0085] In one embodiment of the present invention, the shielding process is at least to shield part of the content in the sensitive data, and after shielding part of the content, the original data cannot be obtained based on the shielded data content;

[0086] and / or,

[0087] When the data attribute corresponding to the sensitive data is text, the replaced data content conforms to the context logic.

[0088] In one embodiment of the present invention, the target product is a network security product, and the data types of the sensitive data include at least one or more of: asset information, threat information, and statistical indicators; where

[0089] The asset information includes at least one or more of: internal network IP address, domain name, asset name, device name, user name, account, file information, path information, and organization;

[0090] The threat information includes at least one or more of: the external network IP address of the attacker and the attribution location;

[0091] The statistical indicator is the statistical number of the product for various risks.

[0092] In one embodiment of the present invention, the recognition unit is further configured to: determine the sub-pages of the current display page, use each sub-page as a page to be displayed to identify sensitive data, and perform the differential shielding process to obtain a shielded sub-page corresponding to each sub-page; when a loading instruction for the target sub-page in the current display page is detected, trigger the display unit to display the shielded sub-page corresponding to the target sub-page.

[0093] It should be noted that: for the sensitive data differential shielding device provided in the above embodiments, only the above-mentioned division of each functional module is used for illustration. In practical applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the sensitive data differential shielding device provided in the above embodiments and the embodiments of the sensitive data differential shielding method belong to the same concept, and the specific implementation process is detailed in the method embodiments and will not be repeated here.

[0094] Embodiments of the present application also provide a computer device. Please refer to Figure 3 , the computer device includes a processor and a memory. At least one instruction, at least one program, a code set or an instruction set is stored in the memory. The at least one instruction, at least one program, the code set or the instruction set is loaded and executed by the processor to implement the sensitive data differential masking method provided by each of the above method embodiments.

[0095] Embodiments of the present application also provide a computer-readable storage medium. At least one instruction, at least one program, a code set or an instruction set is stored on the computer-readable storage medium. The at least one instruction, at least one program, the code set or the instruction set is loaded and executed by the processor to implement the sensitive data differential masking method provided by each of the above method embodiments.

[0096] Embodiments of the present application also provide a computer program product. The computer program product includes a computer program. The processor of the computer device reads the computer program from the computer-readable storage medium, and the processor executes the computer program, so that the computer device executes the sensitive data differential masking method described in any one of the above embodiments.

[0097] For convenience of description, when describing the above system or device, various modules or units are described separately according to functions. Of course, when implementing the present application, the functions of each unit can be implemented in one or more software and / or hardware.

[0098] From the description of the above embodiments, those skilled in the art can clearly understand that the present application can be implemented by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. The computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disc, etc., and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments of the present application.

[0099] Finally, it should also be noted that in this text, relational terms such as first, second, third, and fourth are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprising", "including", or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article, or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the said element.

[0100] The above are only the preferred embodiments of the present application. It should be pointed out that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.

Claims

1. A method for differentially shielding sensitive data, characterized in that: The method comprises: In response to the sensitive data shielding instruction, identifying sensitive data in each to-be-displayed page of the target product during the demonstration process; Using a pre-set shielding strategy, the sensitive data is shielded differently according to different data types, so that the data type of the shielded sensitive data is identifiable; Display the page to be displayed after the shielding process.

2. The method according to claim 1, characterized in that The initiation method of the sensitive data shielding instruction at least includes: If it is detected that the target product is logged in, determine whether the current login account is a demo account; if so, actively initiate a sensitive data shielding instruction; or, A shielding function is provided on the display interface of the target product; a user can initiate a sensitive data shielding instruction based on the shielding function.

3. The method according to claim 1, characterized in that The method of using a preset shielding strategy to perform differentiated shielding processing on the sensitive data according to different data types so that the data type of the shielded sensitive data is identifiable includes: For sensitive data of different data types, different characters are used to replace the data content of the sensitive data. When the data type corresponding to the sensitive data is implemented with a separator, the separator is retained during the shielding process. The replacement methods include at least: specified content replacement and random content replacement.

4. The method according to claim 3, characterized in that The shielding process is to shield at least part of the sensitive data, and after shielding part of the sensitive data, the original data cannot be obtained based on the shielded data content; and / or, When the data attribute corresponding to the sensitive data is text, the replaced data content conforms to the context logic.

5. The method according to claim 4, characterized in that The target product is a network security product, and the data type of sensitive data includes at least one or more of asset information, threat information and statistical indicators; The asset information includes at least one or more of an intranet IP address, a domain name, an asset name, a device name, a user name, an account number, file information, path information, and an organization; The threat information includes at least one or more of the attacker's external IP address and home location; The statistical indicators are the statistical numbers of the product for various risks.

6. The method according to any one of claims 1 to 5, characterized in that: The method further comprises: Determine the subpages of the current display page, use each subpage as a page to be displayed to identify sensitive data, and perform the differential shielding process to obtain a shielded subpage corresponding to each subpage; When a loading instruction for a target sub-page in the currently displayed page is detected, the shielded sub-page corresponding to the target sub-page is displayed.

7. A sensitive data differential shielding device, characterized in that: The device comprises: an identification unit, for identifying sensitive data in each to-be-displayed page of the target product during the demonstration process in response to the sensitive data shielding instruction; A shielding unit, configured to perform differentiated shielding processing on the sensitive data according to different data types by using a preset shielding strategy, so that the data type of the shielded sensitive data is identifiable; The display unit is used to display the page to be displayed after the shielding process.

8. A computer device, characterized in that: The computer device includes a memory and a processor, the memory is used to store a computer program, and the processor is used to execute the computer program stored in the memory to implement the steps of any one of the methods described in claims 1-6.

9. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method described in any one of claims 1 to 6 are implemented.

10. A computer program product, characterized in that The method comprises a computer program, wherein when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.