Shared data desensitization method and system, electronic equipment and product

By establishing data sensitivity levels and user permission levels, classifying shared data, and determining whether the user permission level includes the sensitivity level of the data to be accessed when receiving the data access request, the problem of difficulty in meeting different user permission needs in the prior art is solved, and efficient data desensitization and response speed improvement is achieved.

CN120197218APending Publication Date: 2025-06-24BEIJING BITFEIYANG TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510402206.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-01
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

Existing data desensitization technology is difficult to meet the personalized permission needs of different users, and dynamic desensitization is expensive in high concurrency scenarios, which affects the response speed.

Method used

By establishing data sensitivity levels and user permission levels and classifying shared data based on these levels. When receiving the data access request, it is determined whether the user permission level includes the sensitivity level of the data to be accessed. If included, desensitized data will be extracted from the buffer memory, otherwise it will be extracted from the data source and desensitized.

Benefits of technology

It realizes the provision of different data access and desensitization solutions based on different user permissions, reduces the system's computing burden, improves the response speed, and is suitable for large-scale data sharing scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120197218A_ABST
    Figure CN120197218A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of computers, and aims to provide a shared data desensitization method and system, electronic equipment and a product. According to the method, the data sensitivity level and the user permission level are established in advance, and the shared data in each data source is graded on the basis of the data sensitivity level, and then when the data access request bound with the user identity identifier and the to-be-accessed data identifier is received, the user identity identifier and the to-be-accessed data identifier are accessed. Acquiring a user permission level of the current user and a data sensitivity level of the to-be-accessed data; and then, judging whether a data sensitivity level set corresponding to the user permission level of the current user comprises the data sensitivity level of the to-be-accessed data, if so, obtaining a historical sharing value degree of the to-be-accessed data according to the identifier of the to-be-accessed data, and when the historical sharing value degree is greater than a preset value degree threshold value, sending the to-be-accessed data to the current user. And extracting desensitized data corresponding to the to-be-accessed data from a preset buffer memory. Data requirements of different users can be met, and meanwhile the system response speed can be increased.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of computer technology, and particularly relates to a method, a system, an electronic device and a product for sharing data desensitization. Background Art

[0002] In today's digital age, the sharing of data has become an important means to promote the business development of enterprises, optimize public services, and improve the training effect of artificial intelligence models. However, in the process of data sharing, how to ensure the availability of data while guaranteeing data security and privacy protection has become a key challenge faced by the current technical field.

[0003] In order to prevent the leakage of sensitive information, data desensitization technology is widely used in the control scenarios of data sharing and access. Currently, data desensitization technology mainly includes two categories: static desensitization and dynamic desensitization. Among them, static desensitization usually performs a one-time desensitization process on the original data before data sharing to generate a desensitized copy for use, and dynamic desensitization technology performs desensitization processing in real time during data access to ensure that sensitive information in the query results is dynamically masked.

[0004] However, in the process of using the existing technology, the inventor found that there are at least the following problems in the existing technology: Since static desensitization usually uses fixed rules to uniformly process all users, it is difficult to meet the personalized permission requirements of different users, resulting in some users being unable to obtain high-quality data required for their operations. And dynamic desensitization usually requires permission calculation and desensitization processing every time a user accesses data, with a large computational overhead, especially affecting the response speed in high-concurrency scenarios and prone to performance bottlenecks in large-scale data sharing scenarios. Summary of the Invention

[0005] The present invention aims to solve the above technical problems to at least a certain extent, and provides a method, a system, an electronic device and a product for sharing data desensitization.

[0006] To achieve the above object, the present invention adopts the following technical solutions: In a first aspect, the present invention provides a method for sharing data desensitization, including: Establishing a data sensitivity level and a user permission level, and classifying the shared data in each data source based on the data sensitivity level; wherein, the number of levels of the data sensitivity level is n, the number of levels of the user permission level is m, different data sensitivity level sets are correspondingly set for each user permission level, and both n and m are natural numbers greater than 1; When receiving a data access request bound with a user identity identifier and a data identifier to be accessed, obtain the user privilege level of the current user according to the user identity identifier, and obtain the data sensitivity level of the data to be accessed that matches the user access request according to the data identifier to be accessed; Determine whether the data sensitivity level set corresponding to the user privilege level of the current user includes the data sensitivity level of the data to be accessed. If so, proceed to the next step; if not, return an access failure message to the current user; Obtain the historical sharing value degree of the data to be accessed according to the data identifier to be accessed, and determine whether the historical sharing value degree is greater than a preset value threshold. If so, extract the desensitized data corresponding to the data to be accessed from a preset buffer memory, and return the desensitized data corresponding to the data to be accessed to the current user. If not, proceed to the next step; wherein, the buffer memory stores the desensitized data of each shared data whose historical sharing value degree is greater than the value threshold; Extract the data to be accessed from the data source corresponding to the data identifier to be accessed, and perform desensitization processing on the data to be accessed according to the data sensitivity level of the data to be accessed, so as to obtain the desensitized data corresponding to the data access request, and then return the desensitized data corresponding to the data to be accessed to the current user.

[0007] In a possible design, the data sensitivity level is: S ∈{ S 1, S 2, S 3}; Wherein, S 1 represents low-sensitivity data, S 2 represents medium-sensitivity data, S 3 represents high-sensitivity data; The user privilege level is: L ∈{ L 1, L 2, L 3}; Wherein, L 1 represents a low-privilege user, and the corresponding data sensitivity level set is { S 1}, L 2 represents an ordinary user, and the corresponding data sensitivity level set is { S 1, S 2}, L 3 represents a high-privilege user, and the corresponding data sensitivity level set is { S 1, S 2, S 3}.

[0008] In a possible design, when classifying the shared data in each data source based on the data sensitivity level, a preset deep learning model is used to implement it.

[0009] In a possible design, obtaining the historical sharing value degree of the data to be accessed according to the data to be accessed identifier includes: According to the data to be accessed identifier, obtaining the total number of users who accessed the data to be accessed within a historical specified time window, the interval duration between the access time of each access to the data to be accessed and the current time, and the total number of data associations between the data to be accessed and the other shared data that have an association relationship; According to the total number of users, each interval duration, and the total number of data associations, obtaining the historical sharing value degree of the data to be accessed.

[0010] In a possible design, the historical sharing value degree of the data to be accessed is: ; In the formula, D i represents the data to be accessed, T k represents the k th interval duration among all interval durations, K represents the total number of all interval durations, M represents the total number of users, R represents the total number of data associations.

[0011] In a possible design, when performing desensitization processing on the data to be accessed according to the data sensitivity level of the data to be accessed, the desensitization function used is: ; Among them, D i represents the data to be accessed, S 1 represents low-sensitivity data, S 2 represents medium-sensitivity data, S 3 represents high-sensitivity data, represents a weak masking function, represents a strong masking function.

[0012] In a possible design, the method further includes: Every preset monitoring duration, that is, obtaining the historical sharing value degree of the shared data corresponding to each access data identifier within a historical specified time window before the current time, and extracting all high-value shared data whose historical sharing value degree is greater than the value degree threshold; Calculate the desensitized data corresponding to each high-value shared data according to the data sensitivity level of each high-value shared data; Store the desensitized data corresponding to each high-value shared data in the buffer memory.

[0013] In a second aspect, the present invention provides a shared data desensitization system, including: A level division module, configured to establish a data sensitivity level and a user permission level, and perform level division on the shared data in each data source based on the data sensitivity level; wherein, the number of levels of the data sensitivity level is n, the number of levels of the user permission level is m, different data sensitivity level sets are correspondingly set for each user permission level, and both n and m are natural numbers greater than 1; A request receiving module, communicatively connected to the level division module, configured to receive a data access request bound with a user identity identifier and a to-be-accessed data identifier, obtain the user permission level of the current user according to the user identity identifier, and obtain the data sensitivity level of the to-be-accessed data matching the user access request according to the to-be-accessed data identifier; A data extraction module, communicatively connected to the request receiving module, configured to determine whether the data sensitivity level set corresponding to the user permission level of the current user includes the data sensitivity level of the to-be-accessed data. If so, obtain the historical sharing value degree of the to-be-accessed data according to the to-be-accessed data identifier, and when the historical sharing value degree is greater than a preset value threshold, extract the desensitized data corresponding to the to-be-accessed data from a preset buffer memory, and then return the desensitized data corresponding to the to-be-accessed data to the current user. Also, when the historical sharing value degree is not greater than the preset value threshold, extract the to-be-accessed data from the data source corresponding to the to-be-accessed data identifier, and perform desensitization processing on the to-be-accessed data according to the data sensitivity level of the to-be-accessed data, so as to obtain the desensitized data corresponding to the data access request, and then return the desensitized data corresponding to the to-be-accessed data to the current user; if not, return an access failure message to the current user; wherein, the buffer memory stores the desensitized data of each shared data whose historical sharing value degree is greater than the value threshold.

[0014] In a third aspect, the present invention provides an electronic device, including: A memory, configured to store computer program instructions; and, A processor, configured to execute the computer program instructions to complete the operations of a shared data desensitization method as described in any one of the above.

[0015] Fourthly, the present invention provides a computer program product, including a computer program or instructions, which, when executed by a computer, implement a shared data desensitization method as described in any one of the above.

[0016] The beneficial effects of the present invention are as follows: The present invention discloses a shared data desensitization method, system, electronic device and product, which can meet the data requirements of different users and improve the system response speed at the same time. Specifically, in the implementation process of the present invention, a data sensitivity level and a user permission level are established in advance, and the shared data in each data source is classified based on the data sensitivity level. Then, when a data access request bound with a user identity identifier and a data identifier to be accessed is received, the user permission level of the current user is obtained according to the user identity identifier, and the data sensitivity level of the data to be accessed that matches the user access request is obtained according to the data identifier to be accessed. Subsequently, it is determined whether the data sensitivity level set corresponding to the user permission level of the current user includes the data sensitivity level of the data to be accessed. If so, the historical sharing value degree of the data to be accessed is obtained according to the data identifier to be accessed, and when the historical sharing value degree is greater than a preset value threshold, the desensitized data corresponding to the data to be accessed is extracted from a preset buffer memory, and the desensitized data corresponding to the data to be accessed is returned to the current user. Based on this, the present invention combines the user permission and the data sensitivity classification strategy, and can provide different shared data access and desensitization solutions according to the user permission levels of different users. At the same time, the present invention stores the desensitized data corresponding to the shared data with a historical sharing value degree greater than the value threshold in the buffer memory in advance, and can quickly return the corresponding desensitized data when the user accesses the shared data, thereby reducing the computing burden of the system when the user makes a data request, improving the system performance, making the response speed faster, and providing a better solution for large-scale data sharing scenarios.

[0017] Other beneficial effects of the present invention will be further described in the specific implementation manner. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 is a flowchart of a shared data desensitization method in an embodiment; Figure 2 is a block diagram of a shared data desensitization system in an embodiment; Figure 3 is a block diagram of an electronic device in an embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0019] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the present invention in combination with the accompanying drawings and the descriptions of the embodiments or the prior art. Obviously, the following descriptions of the structures of the accompanying drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other accompanying drawings can be obtained based on these drawings without creative efforts. It should be noted here that the descriptions of these embodiments are used to help understand the present invention, but do not constitute a limitation to the present invention.

[0020] Embodiment 1: This embodiment discloses a method for desensitizing shared data, which can be, but is not limited to, executed by a computer device or virtual machine with certain computing resources, such as executed by an electronic device such as a personal computer, smartphone, personal digital assistant, or wearable device, or executed by a virtual machine.

[0021] As Figure 1 shown, a method for desensitizing shared data can, but is not limited to, include the following steps: S1. Establish a data sensitivity level and a user permission level, and classify the shared data in each data source based on the data sensitivity level; wherein, the number of levels of the data sensitivity level is n, the number of levels of the user permission level is m, and different data sensitivity level sets are correspondingly set for each user permission level, that is, the data sensitivity level sets corresponding to the data that users with each user permission level can access are different, and both n and m are natural numbers greater than 1.

[0022] In step S1, when both m and n are set to 3, the data sensitivity level is: S ∈{ S 1, S 2, S 3}; Among them, S 1 represents low-sensitivity data, S 2 represents medium-sensitivity data, S 3 represents high-sensitivity data; The user permission level is: L ∈{ L 1, L 2, L 3}; Among them, L 1 represents a low-privilege user, and the corresponding data sensitivity level set is { S 1}, that is, the low-privilege user L 1 can only access low-sensitivity data S 1, L 2 represents an ordinary user, and the corresponding data sensitivity level set is {S 1, S 2}, that is, ordinary users L 1 can access low-sensitivity data S 1 and medium-sensitivity data S 2, L 3 represents a high-privilege user, and the corresponding set of data sensitivity levels is { S 1, S 2, S 3}, that is, high-privilege users L 2 can access low-sensitivity data S 1, medium-sensitivity data S 2 and high-sensitivity data S 3.

[0023] Specifically, in step S1, when classifying the shared data in each data source based on the data sensitivity level, a preset deep learning model is used to implement. Among them, the deep learning model is implemented by models such as LSTM (Long Short-Term Memory) and BERT (Bidirectional Encoder Representations from Transformers), etc., which are not limited here.

[0024] It should be noted that the data administrator can also manually mark the sensitivity level of each piece of shared data to implement the classification of the shared data in each data source. In this embodiment, multiple sample data are used to train the deep learning model in advance so that it can implement the classification of data, which can help save the workload of users.

[0025] S2. When receiving a data access request bound with a user identity identifier and a data identifier to be accessed, obtain the user privilege level of the current user according to the user identity identifier, and obtain the data sensitivity level of the data to be accessed that matches the user access request according to the data identifier to be accessed. It should be noted that in this embodiment, corresponding user privilege levels are assigned to each user in advance according to different user roles.

[0026] As an example, this embodiment is applied to a data sharing and exchange platform. To meet the continuous operation requirements of the platform party, the user role can be determined according to whether the user pays and the amount of payment. For example, the user role corresponding to a low-privilege user is a free trial user, and the user roles corresponding to ordinary users and high-privilege users are both paying users. Moreover, the payment amount of ordinary users is lower than that of high-privilege users. In the actual application process, the user can adjust their user privilege level by further paying or other means according to their own data usage needs. For example, if a user is a trial user and wants to access more data, they can convert to a paying user by paying. At this time, their user privilege level can be further changed to an ordinary user or a high-privilege user.

[0027] S3. Determine whether the data sensitivity level set corresponding to the user privilege level of the current user includes the data sensitivity level of the data to be accessed. If so, proceed to the next step; if not, return an access failure message to the current user.

[0028] S4. Obtain the historical sharing value degree of the data to be accessed according to the data to be accessed identifier, and determine whether the historical sharing value degree is greater than a preset value degree threshold. If so, extract the desensitized data corresponding to the data to be accessed from a preset buffer memory and return the desensitized data corresponding to the data to be accessed to the current user. If not, proceed to the next step; wherein, the buffer memory stores the desensitized data of each shared data whose historical sharing value degree is greater than the value degree threshold.

[0029] In step S4, obtaining the historical sharing value degree of the data to be accessed according to the data to be accessed identifier includes: S401. According to the data to be accessed identifier, obtain the total number of users who accessed the data to be accessed within a historical specified time window, the interval duration between the access time of each access to the data to be accessed and the current time, and the total number of data associations between the data to be accessed and other shared data that have an association relationship; Specifically, in this embodiment, the historical specified time window is a time period of a specified duration before the current time, and the specified duration can be determined according to the user activity of the data sharing and exchange platform. As an example, the higher the user activity, the smaller the specified duration.

[0030] S402. Obtain the historical sharing value degree of the data to be accessed according to the total number of users, each interval duration, and the total number of data associations.

[0031] Specifically, in step S402, the historical sharing value degree of the data to be accessed is: ; In the formula,D i represents the data to be accessed T k represents the k th interval duration among all interval durations K represents the total number of all interval durations M represents the total number of users R represents the total number of data associations

[0032] It should be noted that during the implementation process, if a shared data is accessed by more users, has a greater association with other shared data, and has a shorter access interval duration, it indicates that the shared value degree of this shared data is higher. Based on this, in this embodiment, according to the total number of users, each interval duration, and the total number of data associations, the historical shared value degree of the data to be accessed is obtained.

[0033] S5. Extract the data to be accessed from the data source corresponding to the identifier of the data to be accessed, and perform desensitization processing on the data to be accessed according to the data sensitivity level of the data to be accessed, so as to obtain desensitized data corresponding to the data access request, and then return the desensitized data corresponding to the data to be accessed to the current user.

[0034] In step S5, when performing desensitization processing on the data to be accessed according to the data sensitivity level of the data to be accessed, the desensitization function used is: ; wherein D i represents the data to be accessed S 1 represents low-sensitivity data S 2 represents medium-sensitivity data S 3 represents high-sensitivity data represents a weak masking function represents a strong masking function

[0035] It should be noted that the weak masking function can, when the data sensitivity level of the data to be accessed is medium-sensitivity data, play a role in desensitizing (such as replacing, masking) some sensitive fields in the data to be accessed; the strong masking function can, when the data sensitivity level of the data to be accessed is high-sensitivity data, play a role in desensitizing most of the sensitive fields in the data to be accessed.

[0036] As an example, the weak masking function can be implemented using the AES-128 encryption algorithm. Correspondingly, the strong masking function is implemented using the AES-256 encryption algorithm. It should be noted that since the AES (Advanced Encryption Standard) encryption algorithm has high security and fast encryption and decryption speeds, it can meet the requirements of resisting various cryptographic attacks for medium-sensitive data and high-sensitive data during the data sharing process based on this embodiment.

[0037] In this embodiment, the method further includes: A1. Every preset monitoring duration, obtain the historical sharing value degrees of the shared data corresponding to each access data identifier within the historical specified time window before the current moment, and extract all the high-value shared data whose historical sharing value degrees are greater than the value degree threshold. It should be noted that the historical specified time window is used to specify the time range for monitoring the data sharing value degree, and the length of the historical specified time window can be dynamically adjusted according to actual needs. Specifically, in this embodiment, the length of the historical specified time window is dynamically adjusted according to the system load to improve the accuracy and real-time performance of the data sharing value degree monitoring.

[0038] A2. Calculate the desensitized data corresponding to each high-value shared data according to the data sensitivity level of each high-value shared data.

[0039] A3. Store the desensitized data corresponding to each high-value shared data into the buffer memory.

[0040] It should be noted that in step S4 of this embodiment, when the historical sharing value degree of the data to be accessed is greater than the preset value degree threshold, the data to be accessed is the high-value shared data, and the desensitized data corresponding to the data to be accessed is pre-stored in the buffer memory.

[0041] It should also be noted that the historical sharing value degrees of each shared data reflect its value to users to a certain extent. In this embodiment, the shared data with historical sharing value degrees greater than the value degree threshold is pre-extracted, and the desensitized data corresponding to it is calculated in advance according to its data sensitivity level, and then stored in the buffer memory. This can ensure that the shared data with high sharing value degrees can be accessed quickly, which is beneficial to reducing the dynamic calculation overhead of the system, improving the data query efficiency of users, and providing a better user experience.

[0042] This embodiment can meet the data requirements of different users and improve the system response speed. Specifically, during the implementation of this embodiment, a data sensitivity level and a user permission level are established in advance, and the shared data in each data source is classified based on the data sensitivity level. Then, when a data access request bound with a user identity identifier and a data identifier to be accessed is received, the user permission level of the current user is obtained according to the user identity identifier, and the data sensitivity level of the data to be accessed that matches the user access request is obtained according to the data identifier to be accessed. Subsequently, it is determined whether the data sensitivity level set corresponding to the user permission level of the current user includes the data sensitivity level of the data to be accessed. If so, the historical sharing value degree of the data to be accessed is obtained according to the data identifier to be accessed. When the historical sharing value degree is greater than a preset value threshold, the desensitized data corresponding to the data to be accessed is extracted from a preset buffer memory, and the desensitized data corresponding to the data to be accessed is returned to the current user. Based on this, this embodiment combines the user permission and the data sensitivity classification strategy, and can provide different shared data access and desensitization solutions according to the user permission levels of different users. At the same time, in this embodiment, the desensitized data corresponding to the shared data with a historical sharing value degree greater than the value threshold is stored in the buffer memory in advance, so that when the user accesses the shared data, the corresponding desensitized data can be quickly returned, thereby reducing the computational burden of the system when the user makes a data request, improving the system performance, making the response speed faster, and providing a better solution for large-scale data sharing scenarios.

[0043] Embodiment 2: This embodiment discloses a shared data desensitization system for implementing the shared data desensitization method in Embodiment 1; as Figure 2 shown, the shared data desensitization system includes: A level classification module, configured to establish a data sensitivity level and a user permission level, and classify the shared data in each data source based on the data sensitivity level; wherein, the number of levels of the data sensitivity level is n, the number of levels of the user permission level is m, different data sensitivity level sets are correspondingly set for each user permission level, and both n and m are natural numbers greater than 1; A request receiving module, communicatively connected to the level classification module, configured to receive a data access request bound with a user identity identifier and a data identifier to be accessed, obtain the user permission level of the current user according to the user identity identifier, and obtain the data sensitivity level of the data to be accessed that matches the user access request according to the data identifier to be accessed; A data extraction module, communicatively connected to the request receiving module, is configured to determine whether the data sensitivity level of the data to be accessed is included in the set of data sensitivity levels corresponding to the user privilege level of the current user. If so, the historical sharing value degree of the data to be accessed is obtained according to the data to be accessed identifier, and when the historical sharing value degree is greater than a preset value degree threshold, the desensitized data corresponding to the data to be accessed is extracted from a preset buffer memory, and then the desensitized data corresponding to the data to be accessed is returned to the current user. Also, when the historical sharing value degree is not greater than the preset value degree threshold, the data to be accessed is extracted from the data source corresponding to the data to be accessed identifier, and the data to be accessed is desensitized according to the data sensitivity level of the data to be accessed, so as to obtain the desensitized data corresponding to the data access request, and then the desensitized data corresponding to the data to be accessed is returned to the current user; if not, an access failure message is returned to the current user; wherein, the buffer memory stores the desensitized data of each shared data with a historical sharing value degree greater than the value degree threshold.

[0044] It should be noted that for the working process, working details and technical effects of the shared data desensitization system provided in this Embodiment 2, reference can be made to Embodiment 1, which will not be elaborated here.

[0045] Embodiment 3: Based on Embodiment 1 or 2, this embodiment discloses an electronic device, which may be a smart phone, a tablet computer, a laptop computer or a desktop computer, etc. The electronic device may be referred to as a user terminal, a portable terminal, a desktop terminal, etc. As Figure 3 shown, the electronic device includes: A memory, configured to store computer program instructions; and, A processor, configured to execute the computer program instructions to complete the operations of a shared data desensitization method as described in any one of Embodiment 1.

[0046] Specifically, the processor 301 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 301 may be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), or PLA (Programmable Logic Array). The processor 301 may also include a main processor and a coprocessor. The main processor is a processor used to process data in the wake state, also known as the CPU (Central Processing Unit); the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, the processor 301 may be integrated with a GPU (Graphics Processing Unit), and the GPU is responsible for rendering and drawing the content to be displayed on the display screen.

[0047] The memory 302 may include one or more computer-readable storage media, and the computer-readable storage media may be non-transitory. The memory 302 may also include high-speed random access memory and non-volatile memory, such as one or more disk storage devices and flash storage devices. In some embodiments, the non-transitory computer-readable storage media in the memory 302 is used to store at least one instruction, and the at least one instruction is used to be executed by the processor 301 to implement the shared data desensitization method provided in Embodiment 1 of the present application.

[0048] In some embodiments, the terminal may optionally further include: a communication interface 303 and at least one peripheral device. The processor 301, the memory 302, and the communication interface 303 may be connected through a bus or signal lines. Each peripheral device may be connected to the communication interface 303 through a bus, signal lines, or a circuit board. Specifically, the peripheral device includes at least one of a radio frequency circuit 304, a display screen 305, and a power supply 306.

[0049] The communication interface 303 can be used to connect at least one peripheral device related to I / O (Input / Output) to the processor 301 and the memory 302. In some embodiments, the processor 301, the memory 302, and the communication interface 303 are integrated on the same chip or circuit board; in some other embodiments, any one or two of the processor 301, the memory 302, and the communication interface 303 may be implemented on a separate chip or circuit board, and this embodiment does not limit this.

[0050] The radio frequency circuit 304 is used to receive and transmit RF (Radio Frequency) signals, also known as electromagnetic signals. The radio frequency circuit 304 communicates with the communication network and other communication devices through electromagnetic signals.

[0051] The display screen 305 is used to display the UI (User Interface). The UI can include any combination of graphics, text, icons, and videos.

[0052] The power supply 306 is used to supply power to each component in the electronic device.

[0053] Embodiment 4: Based on any one of Embodiments 1 to 3, this embodiment discloses a computer program product, including a computer program or instructions, and the computer program or the instructions, when executed by a computer, implement a shared data desensitization method as described in any one of Embodiments 1. Among them, the computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices.

[0054] Obviously, those skilled in the art should understand that the above-mentioned modules or steps of the present invention can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed on a network composed of multiple computing devices. Optionally, they can be implemented by program codes executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module to implement. In this way, the present invention is not limited to any specific combination of hardware and software.

[0055] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments or perform equivalent replacements for some of the technical features. And these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A shared data desensitization method, characterized in that: include: Establish data sensitivity levels and user authority levels, and classify the shared data in each data source based on the data sensitivity levels; wherein the number of data sensitivity levels is n, the number of user authority levels is m, each user authority level is correspondingly provided with a different data sensitivity level set, and n and m are both natural numbers greater than 1; When receiving a data access request bound to a user identity and an identifier of data to be accessed, obtaining the user authority level of the current user according to the user identity, and obtaining the data sensitivity level of the data to be accessed that matches the user access request according to the identifier of the data to be accessed; Determine whether the data sensitivity level set corresponding to the user authority level of the current user includes the data sensitivity level of the data to be accessed, if yes, proceed to the next step, if no, return access failure information to the current user; Obtain the historical shared value of the data to be accessed according to the identifier of the data to be accessed, and determine whether the historical shared value is greater than a preset value threshold. If so, extract the desensitized data corresponding to the data to be accessed from a preset buffer memory, and return the desensitized data corresponding to the data to be accessed to the current user. If not, proceed to the next step; wherein the buffer memory stores the desensitized data of the shared data whose historical shared value is greater than the value threshold; The data to be accessed is extracted from a data source corresponding to the identifier of the data to be accessed, and the data to be accessed is desensitized according to the data sensitivity level of the data to be accessed, so as to obtain desensitized data corresponding to the data access request, and then the desensitized data corresponding to the data to be accessed is returned to the current user.

2. A shared data desensitization method according to claim 1, characterized in that: The data sensitivity levels are: S ∈{ S 1, S 2, S 3}; in, S 1 indicates low sensitivity data, S 2 indicates medium sensitive data, S 3 indicates highly sensitive data; The user authority levels are: L ∈{ L 1, L 2, L 3}; in, L 1 represents a low-privilege user, and its corresponding data sensitivity level set is { S 1}, L 2 represents ordinary users, and the corresponding data sensitivity level set is { S 1, S 2}, L 3 represents a high-privilege user, and its corresponding data sensitivity level set is { S 1, S 2, S 3}.

3. A shared data desensitization method according to claim 1, characterized in that: When the shared data in each data source is graded based on the data sensitivity level, a preset deep learning model is used for implementation.

4. A shared data desensitization method according to claim 1, characterized in that: Obtaining the historical sharing value of the data to be accessed according to the identifier of the data to be accessed includes: According to the identifier of the data to be accessed, the total number of users who accessed the data to be accessed within a specified historical time window, the interval between each access time of the data to be accessed and the current time, and the total number of data associations in other shared data that have an association relationship with the data to be accessed are obtained; The historical sharing value of the to-be-accessed data is obtained according to the total number of users, the duration of each interval and the total number of data associations.

5. A shared data desensitization method according to claim 4, characterized in that: The historical sharing value of the data to be accessed is: ; In the formula, D i represents the data to be accessed, T k Indicates the first of all interval durations k The interval duration, K Represents the total length of all intervals. M represents the total number of users, R Indicates the total number of data associations.

6. A shared data desensitization method according to claim 1, characterized in that: When desensitizing the data to be accessed according to the data sensitivity level of the data to be accessed, the desensitizing function used is: ; in, D i represents the data to be accessed, S 1 indicates low sensitivity data, S 2 indicates medium sensitive data, S 3 indicates highly sensitive data, represents a weak mask function, Represents a strong masking function.

7. A shared data desensitization method according to claim 1, characterized in that: The method further comprises: The preset monitoring time is used for each interval, that is, the historical sharing value of the shared data corresponding to each access data identifier in the historical specified time window before the current moment is obtained, and all high-value shared data whose historical sharing value is greater than the value threshold are extracted; According to the data sensitivity level of each high-value shared data, calculate the desensitized data corresponding to each high-value shared data; The desensitized data corresponding to each high-value shared data is stored in the buffer memory.

8. A shared data desensitization system, characterized in that: include: A level classification module, used to establish data sensitivity levels and user authority levels, and to classify the shared data in each data source based on the data sensitivity levels; wherein the number of data sensitivity levels is n, the number of user authority levels is m, each user authority level is correspondingly provided with a different data sensitivity level set, and n and m are both natural numbers greater than 1; a request receiving module, which is in communication connection with the level classification module, and is used to receive a data access request bound to a user identity identifier and a data identifier to be accessed, and obtain the user authority level of the current user according to the user identity identifier, and obtain the data sensitivity level of the data to be accessed that matches the user access request according to the data identifier to be accessed; A data extraction module, which is in communication connection with the request receiving module, is used to determine whether the data sensitivity level set corresponding to the user authority level of the current user includes the data sensitivity level of the data to be accessed. If so, the historical sharing value of the data to be accessed is obtained according to the identifier of the data to be accessed, and when the historical sharing value is greater than a preset value threshold, the desensitized data corresponding to the data to be accessed is extracted from a preset buffer memory, and then the desensitized data corresponding to the data to be accessed is returned to the current user. When the historical sharing value is not greater than the preset value threshold, the data to be accessed is extracted from a data source corresponding to the identifier of the data to be accessed, and the data to be accessed is desensitized according to the data sensitivity level of the data to be accessed, so as to obtain the desensitized data corresponding to the data access request, and then the desensitized data corresponding to the data to be accessed is returned to the current user; if not, access failure information is returned to the current user; wherein the buffer memory stores the desensitized data of each shared data whose historical sharing value is greater than the value threshold.

9. An electronic device, characterized in that: include: a memory for storing computer program instructions; as well as, A processor, used to execute the computer program instructions to complete the operation of a shared data desensitization method as described in any one of claims 1 to 7.

10. A computer program product comprising a computer program or instructions, characterized in that When executed by a computer, the computer program or the instruction implements a shared data desensitization method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Private information access control method and device based on ontology reasoning

    CN113378193A

  • Data access management method and device

    CN118138256A

  • Data management method and system based on multi-party security computing

    CN118364505A

  • Fuel data sharing system and method

    CN119249466A

  • Data Access Monitoring and Control

    US20220188437A1